Skip to content
JackSparrow414

Using Shiro

From login, remember-me, and sessions to password encryption, tokens, JWT, and Spring Boot integration.

8 posts · In reading order

  1. Using Shiro: A Basic Login Flow

    This article introduces a basic login flow with Shiro and Spring MVC, including filter configuration, authentication in a custom Realm, and redirects after successful login. Missing accounts, incorrect passwords, and locked accounts illustrate authentication-code and login-URL configuration considerations.

  2. Using Shiro Remember Me and Automatic Login: Fixing a deleteMe Cookie

    Introduces Shiro rememberMe configuration and automatic login on a later visit, and records a source-code investigation of cookies containing deleteMe. Making the User object used in authentication implement Serializable resolves the serialization failure that breaks the remember-me feature.

  3. Using Shiro: Basic Session Management

    This article covers Shiro session management, including session ID generation, cookie storage, SessionDAO, and expired-session cleanup. It also describes periodic validation with Quartz and disabling session ID URL rewriting to avoid exposing IDs after redirects.

  4. Using Shiro: Password Hashing and Salting, with Authentication Troubleshooting

    This article walks through password hashing, salted storage, and login verification in Shiro and uses its source code to explain credential comparison. It also covers troubleshooting passwords still stored as plaintext and authentication failures after salting, including the roles of the algorithm, salt, and hash iteration count.

  5. Using Shiro: A Primer on Tokens and Why to Use Them

    Starting from login validation in traditional web applications, this article discusses the differences between sessions and tokens in storage, sharing across distributed systems, and request authentication. It compares validation approaches using a database, Redis, or no token storage to clarify design considerations for implementing token authentication with Shiro.

  6. Using Shiro with Tokens

    A custom Shiro filter validates tokens on incoming requests. The article covers returning a token after login, adding the filter to the authentication chain, and tracing filter execution order in the source code, then discusses token expiry and distributed authentication that the example has not yet implemented.

  7. Using Shiro: Integrating JWT for More Capable Tokens

    JWT is integrated with Shiro and Spring Boot to issue tokens after login and parse, validate, and check them for expiry on subsequent requests. This article explains the JWT utility, authentication filter, and configuration properties, and traces a dependency-injection failure caused by constructing the filter manually.

  8. Using Shiro: Complete Spring Boot Integration Code

    The main code for integrating Shiro, Spring Boot, and JWT: the Shiro configuration, a custom Realm, an authentication filter, and a JWT utility. Together, these four pieces show login authentication, request interception, and token creation and validation, with a look back at the session-management choices made during integration.