Posts
All the articles I've posted.
Using Shiro with Tokens
A custom Shiro filter validates tokens on incoming requests. The article covers returning a token after login, adding the filter to the authentication chain, and tracing filter execution order in the source code, then discusses token expiry and distributed authentication that the example has not yet implemented.
Using Shiro: A Primer on Tokens and Why to Use Them
Starting from login validation in traditional web applications, this article discusses the differences between sessions and tokens in storage, sharing across distributed systems, and request authentication. It compares validation approaches using a database, Redis, or no token storage to clarify design considerations for implementing token authentication with Shiro.
Using Shiro: Password Hashing and Salting, with Authentication Troubleshooting
This article walks through password hashing, salted storage, and login verification in Shiro and uses its source code to explain credential comparison. It also covers troubleshooting passwords still stored as plaintext and authentication failures after salting, including the roles of the algorithm, salt, and hash iteration count.
Using Shiro: Basic Session Management
This article covers Shiro session management, including session ID generation, cookie storage, SessionDAO, and expired-session cleanup. It also describes periodic validation with Quartz and disabling session ID URL rewriting to avoid exposing IDs after redirects.