spring boot:配置druid資料庫連線池使用log4j2做非同步日誌(spring boot 2.3.2)
一,druid資料庫連線池的功能?
1,Druid是阿里巴巴開發的號稱為監控而生的資料庫連線池
它的優點包括:
可以監控資料庫訪問效能
SQL執行日誌
SQL防火牆
2,druid的官方站:
https://github.com/alibaba/druid/
說明:劉巨集締的架構森林是一個專注架構的部落格,地址:https://www.cnblogs.com/architectforest
對應的原始碼可以訪問這裡獲取:https://github.com/liuhongdi/
說明:作者:劉巨集締 郵箱: [email protected]
二,演示專案的相關資訊:
1,專案地址:
https://github.com/liuhongdi/druid
2, 專案功能說明:
為druid配置log4j2作為日誌記錄工具,
演示mybatis程式碼中#和$變數的區別
3, 專案結構:如圖:
三,配置檔案說明
1,pom.xml
<dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-web</artifactId> <exclusions> <exclusion> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-logging</artifactId> </exclusion> </exclusions> </dependency> <!--druid begin--> <dependency> <groupId>com.alibaba</groupId> <artifactId>druid-spring-boot-starter</artifactId> <version>1.1.23</version> </dependency> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-log4j2</artifactId> </dependency> <dependency> <groupId>com.lmax</groupId> <artifactId>disruptor</artifactId> <version>3.4.2</version> </dependency> <!--druid end--> <!--mybatis begin--> <dependency> <groupId>org.mybatis.spring.boot</groupId> <artifactId>mybatis-spring-boot-starter</artifactId> <version>2.1.3</version> </dependency> <!--mybatis end--> <!--mysql begin--> <dependency> <groupId>mysql</groupId> <artifactId>mysql-connector-java</artifactId> <scope>runtime</scope> </dependency> <!--mysql end--> <!--pagehelper begin--> <dependency> <groupId>com.github.pagehelper</groupId> <artifactId>pagehelper-spring-boot-starter</artifactId> <version>1.2.13</version> </dependency> <!--pagehelper end-->
說明:關閉了spring-boot-starter-web自帶的log功能,
用druid-spring-boot-starter引入druid,
disruptor這個依賴也需要引入,是log4j2使用非同步日誌中必需的
2,application.properties
#error server.error.include-stacktrace=always #error logging.level.org.springframework.web=trace # 資料來源基本配置 spring.datasource.username = root spring.datasource.password = lhddemo spring.datasource.driver-class-name = com.mysql.cj.jdbc.Driver spring.datasource.url = jdbc:mysql://127.0.0.1:3306/store?serverTimezone=UTC spring.datasource.type = com.alibaba.druid.pool.DruidDataSource # Druid資料來源配置 spring.datasource.druid.initialSize = 5 spring.datasource.druid.minIdle = 5 spring.datasource.druid.maxActive = 20 spring.datasource.druid.maxWait = 60000 spring.datasource.druid.timeBetweenEvictionRunsMillis = 60000 spring.datasource.druid.minEvictableIdleTimeMillis = 300000 spring.datasource.druid.validationQuery = SELECT 1 FROM DUAL spring.datasource.druid.testWhileIdle = true spring.datasource.druid.testOnBorrow = false spring.datasource.druid.testOnReturn = false spring.datasource.druid.poolPreparedStatements = true # 配置監控統計攔截的filters,去掉後監控介面sql無法統計,'wall'用於防火牆 spring.datasource.druid.filters = stat,wall,log4j2 spring.datasource.druid.maxPoolPreparedStatementPerConnectionSize = 20 spring.datasource.druid.useGlobalDataSourceStat = true spring.datasource.druid.connectionProperties = druid.stat.mergeSql=true;druid.stat.slowSqlMillis=500 #druid sql firewall monitor spring.datasource.druid.filter.wall.enabled=true #druid sql monitor spring.datasource.druid.filter.stat.enabled=true spring.datasource.druid.filter.stat.log-slow-sql=true spring.datasource.druid.filter.stat.slow-sql-millis=10000 spring.datasource.druid.filter.stat.merge-sql=true #druid uri monitor spring.datasource.druid.web-stat-filter.enabled=true spring.datasource.druid.web-stat-filter.url-pattern=/* spring.datasource.druid.web-stat-filter.exclusions=*.js,*.gif,*.jpg,*.bmp,*.png,*.css,*.ico,/druid/* #druid session monitor spring.datasource.druid.web-stat-filter.session-stat-enable=true spring.datasource.druid.web-stat-filter.profile-enable=true #druid spring monitor spring.datasource.druid.aop-patterns=com.druid.* #druid login user config spring.datasource.druid.stat-view-servlet.login-username=root spring.datasource.druid.stat-view-servlet.login-password=root #monintor spring.datasource.druid.stat-view-servlet.enabled=true #spring.datasource.druid.stat-view-servlet.url-pattern="/druid/*" #mybatis mybatis.mapper-locations=classpath:/mapper/*Mapper.xml mybatis.type-aliases-package=com.example.demo.mapper mybatis.configuration.log-impl=org.apache.ibatis.logging.stdout.StdOutImpl logging.config = classpath:log4j2.xml
說明:除了druid的配置,指定了log的配置檔案為: log4j2.xml
如果需要檢視監控介面,需要設定以下一項:
spring.datasource.druid.stat-view-servlet.enabled=true
大家如果在生產環境中,可以設定它為false,只檢視日誌檔案
使用log4j2日誌時,注意spring.datasource.druid.filters 設定為 stat,wall,log4j2
3,log4j2.xml
<?xml version="1.0" encoding="UTF-8"?> <configuration status="OFF"> <appenders> <Console name="Console" target="SYSTEM_OUT"> <ThresholdFilter level="DEBUG" onMatch="ACCEPT" onMismatch="DENY"/> <PatternLayout pattern="%d{yyyy-MM-dd HH:mm:ss.SSS} [%thread] [%file:%line] %-5level %logger{35} - %msg %n"/> </Console> <!--處理INFO級別的日誌,寫入到logs/info.log檔案--> <RollingFile name="RollingFileInfo" fileName="./logs/info.log" filePattern="logs/$${date:yyyy-MM}/info-%d{yyyy-MM-dd}-%i.log.gz"> <Filters> <ThresholdFilter level="INFO"/> <ThresholdFilter level="WARN" onMatch="DENY" onMismatch="NEUTRAL"/> </Filters> <PatternLayout pattern="%d{yyyy-MM-dd HH:mm:ss.SSS} [%thread] [%file:%line] %-5level %logger{35} - %msg %n"/> <Policies> <SizeBasedTriggeringPolicy size="500 MB"/> <TimeBasedTriggeringPolicy/> </Policies> </RollingFile> <!--處理WARN級別的日誌,寫入到logs/warn.log檔案--> <RollingFile name="RollingFileWarn" fileName="./logs/warn.log" filePattern="logs/$${date:yyyy-MM}/warn-%d{yyyy-MM-dd}-%i.log.gz"> <Filters> <ThresholdFilter level="WARN"/> <ThresholdFilter level="ERROR" onMatch="DENY" onMismatch="NEUTRAL"/> </Filters> <PatternLayout pattern="%d{yyyy-MM-dd HH:mm:ss.SSS} [%thread] [%file:%line] %-5level %logger{35} - %msg %n"/> <Policies> <SizeBasedTriggeringPolicy size="500 MB"/> <TimeBasedTriggeringPolicy/> </Policies> </RollingFile> <!--處理error級別的日誌,寫入到logs/error.log檔案--> <RollingFile name="RollingFileError" fileName="./logs/error.log" filePattern="logs/$${date:yyyy-MM}/error-%d{yyyy-MM-dd}-%i.log.gz"> <ThresholdFilter level="ERROR"/> <PatternLayout pattern="%d{yyyy-MM-dd HH:mm:ss.SSS} [%thread] [%file:%line] %-5level %logger{35} - %msg %n"/> <Policies> <SizeBasedTriggeringPolicy size="500 MB"/> <TimeBasedTriggeringPolicy/> </Policies> </RollingFile> <!--druid的日誌記錄追加器--> <RollingFile name="druidSqlRollingFile" fileName="./logs/druid-sql.log" filePattern="logs/$${date:yyyy-MM}/api-%d{yyyy-MM-dd}-%i.log.gz"> <PatternLayout pattern="%d{yyyy-MM-dd HH:mm:ss.SSS} [%thread] [%file:%line] %-5level %logger{35} - %msg %n"/> <Policies> <SizeBasedTriggeringPolicy size="500 MB"/> <TimeBasedTriggeringPolicy/> </Policies> </RollingFile> </appenders> <loggers> <AsyncRoot level="info"> <appender-ref ref="Console"/> <appender-ref ref="RollingFileInfo"/> <appender-ref ref="RollingFileWarn"/> <appender-ref ref="RollingFileError"/> </AsyncRoot> <!--記錄druid-sql的記錄--> <AsyncLogger name="druid.sql.Statement" level="debug" additivity="false"> <appender-ref ref="druidSqlRollingFile"/> </AsyncLogger> </loggers> </configuration>
說明:這裡只是舉例,直接把日誌放到了當前目錄,生產環境中建議為日誌配置專門的目錄
4,資料表的結構:
CREATE TABLE `user` ( `userId` int(11) NOT NULL AUTO_INCREMENT COMMENT 'id', `username` varchar(200) NOT NULL DEFAULT '' COMMENT 'name', `password` varchar(100) NOT NULL DEFAULT '' COMMENT 'pass', PRIMARY KEY (`userId`), UNIQUE KEY `username` (`username`) ) ENGINE=InnoDB AUTO_INCREMENT=0 DEFAULT CHARSET=utf8mb4 COLLATE=utf8mb4_0900_ai_ci COMMENT='user'
四,java程式碼說明:
1,UserController.java
@RestController @RequestMapping("/user") public class UserController { @Resource private UserService userService; //mybatis使用#變數 @GetMapping("/login") public Object login(@RequestParam("username") String username, @RequestParam("password") String password ) { User userOne = userService.getOneUserByUsernamePassword(username,password); if (userOne == null) { System.out.println("user is null"); } return userOne; } //mybatis使用$變數 @GetMapping("/login2") public Object login2(@RequestParam("username") String username, @RequestParam("password") String password ) { User userOne = userService.getOneUserByUsernamePassword2(username,password); if (userOne == null) { System.out.println("user is null"); } return userOne; } }
說明:mybatis在mapper檔案中,如果使用$時,屬於拼接sql語句,有sql注入的危險,
我們用來檢測druid的sql注入檢測是否生效
2,UserServiceImpl.java
@Service public class UserServiceImpl implements UserService { @Resource private UserMapper userMapper; //mybatis使用#變數 @Override public User getOneUserByUsernamePassword(String username,String password) { User userOne = userMapper.selectOneUserByUsernamePassword(username,password); System.out.println(userOne); return userOne; } //mybatis使用$變數 @Override public User getOneUserByUsernamePassword2(String username,String password) { User userOne = userMapper.selectOneUserByUsernamePassword2(username,password); System.out.println(userOne); return userOne; } }
3,UserMapper.xml
<?xml version="1.0" encoding="UTF-8" ?> <!DOCTYPE mapper PUBLIC "-//mybatis.org//DTD Mapper 3.0//EN" "http://mybatis.org/dtd/mybatis-3-mapper.dtd"> <mapper namespace="com.druid.demo.mapper.UserMapper"> <select id="selectOneUserByUsernamePassword" parameterType="String" resultType="com.druid.demo.pojo.User"> select * from user where username=#{username} and password=#{password} </select> <select id="selectOneUserByUsernamePassword2" parameterType="String" resultType="com.druid.demo.pojo.User"> select * from user where username=${username} and password=${password} </select> </mapper>
4,User.java
public class User { //使用者id private String userId; public String getUserId() { return userId; } //使用者名稱 private String username; public String getUsername() { return this.username; } public void setUsername(String username) { this.username = username; } }
五,測試效果
1,開啟druid監控介面:
http://127.0.0.1:8080/druid/login.html
輸入我們在配置檔案中的定義的使用者和密碼 root/root
登入後可以看到druid的介面:
2,測試sql的注入,檢查druid的防火牆效果
http://127.0.0.1:8080/user/login?username=1&password=2 or 1=1 limit 1
返回為空,
檢視控制檯:
==> Preparing: select * from user where username=? and password=?
==> Parameters: 1(String), 2 or 1=1 limit 1(String)
<== Total: 0
可見在mybatis使用#我們輸入的注入語句也被作為引數的一部分,
因為mybatis把輸入的內容解析為一個 JDBC 預編譯語句(prepared statement)的引數標記符,
一個 #{ } 被解析為一個引數佔位符,
所以注入是失敗的
訪問:
http://127.0.0.1:8080/user/login2?username=1&password=2 or 1=1 limit 1
返回:
mybatis在使用$時,是通過拼接字串來構造sql,
可見我們的sql注入已生效,但因為druid的防火牆機制,導致丟擲sql injection violation
說明druid的防sql注入防火牆是有效的
3,測試過sql注入後,再檢視druid中的防火牆頁面:
我們使用的注入sql已被新增到了黑名單
六,檢視spring boot的版本:
. ____ _ __ _ _ /\\ / ___'_ __ _ _(_)_ __ __ _ \ \ \ \ ( ( )\___ | '_ | '_| | '_ \/ _` | \ \ \ \ \\/ ___)| |_)| | | | | || (_| | ) ) ) ) ' |____| .__|_| |_|_| |_\__, | / / / / =========|_|==============|___/=/_/_/_/ :: Spring Boot :: (v2.3.2.RELEASE)