Implementation of Permission Management Framework Based on Token through Shiro
Shulin Yang, Jieping Hu, Shaopeng Wang, Cai Hongwei · 2017 International Conference on Computer Technology, Electronics and Communication (ICCTEC) · 2017
Traditional permission management based on Session has many problems, such as high memory cost, unsuitable for mobile application, and not convenient for cross domain resource sharing. The permission management based on Token can solve the above problems better. Through the analysis of Token authentication process and the research of Apache Shiro architecture, a set of universal and easy access control model based on RBAC (Role-Based Access Control) is designed. JWT (JSON Web Token) is integrated and a security authentication framework based on Token is implemented. The practical application shows that the security authentication framework is flexible, which is easy to expand and transplant.