国家信息安全漏洞(请务必保持cipherKey密钥唯一性)
This commit is contained in:
@ -85,6 +85,10 @@ public class ShiroConfig
|
||||
@Value("${shiro.cookie.maxAge}")
|
||||
private int maxAge;
|
||||
|
||||
// 设置cipherKey密钥
|
||||
@Value("${shiro.cookie.cipherKey}")
|
||||
private String cipherKey;
|
||||
|
||||
// 登录地址
|
||||
@Value("${shiro.user.loginUrl}")
|
||||
private String loginUrl;
|
||||
@ -328,7 +332,7 @@ public class ShiroConfig
|
||||
{
|
||||
CookieRememberMeManager cookieRememberMeManager = new CookieRememberMeManager();
|
||||
cookieRememberMeManager.setCookie(rememberMeCookie());
|
||||
cookieRememberMeManager.setCipherKey(Base64.decode("fCq+/xW488hMTCD+cmJ3aQ=="));
|
||||
cookieRememberMeManager.setCipherKey(Base64.decode(cipherKey));
|
||||
return cookieRememberMeManager;
|
||||
}
|
||||
|
||||
|
Reference in New Issue
Block a user