要实现 EMQX 用户校验,并要求动态添加删除用户以及验证用户名、密码,同时对 clientid 进行前缀验证,你可以利用 EMQX 4.1 版本中的 HTTP 认证 和 EMQX 认证/授权插件 功能。以下是详细步骤:
1. 启用 HTTP 认证插件
编辑 EMQX 配置文件 emqx.conf,启用 emqx_auth_http 插件:
$ emqx_ctl plugins load emqx_auth_http2. 配置 HTTP 认证
在 emqx_auth_http.conf 文件中配置 HTTP 认证请求:
## HTTP API Auth Endpoint
auth.http.auth_req = http://localhost:8080/mqtt/auth
## Superuser Auth Endpoint
auth.http.super_req = http://localhost:8080/mqtt/superuser
## HTTP Headers
auth.http.header.content_type = application/json3. 实现 HTTP 认证服务
你需要一个 HTTP 服务来处理认证请求。以下是一个使用 Go 实现的简单示例:
package main
import (
"encoding/json"
"fmt"
"net/http"
"strings"
)
// User represents a user with username, password, and clientid prefix
type User struct {
Username string `json:"username"`
Password string `json:"password"`
ClientIDPrefix string `json:"clientid_prefix"`
}
// Users database (in-memory for this example)
var users = map[string]User{
"user_a": {"user_a", "password_a", "usera"},
"user_b": {"user_b", "password_b", "userb"},
}
// AuthRequest represents the request body for authentication
type AuthRequest struct {
Username string `json:"username"`
Password string `json:"password"`
ClientID string `json:"clientid"`
}
// AuthResponse represents the response body for authentication
type AuthResponse struct {
Result string `json:"result"`
}
func authHandler(w http.ResponseWriter, r *http.Request) {
var authReq AuthRequest
err := json.NewDecoder(r.Body).Decode(&authReq)
if err != nil {
http.Error(w, "Invalid request", http.StatusBadRequest)
return
}
user, ok := users[authReq.Username]
if !ok || user.Password != authReq.Password {
http.Error(w, "Unauthorized", http.StatusUnauthorized)
return
}
if !strings.HasPrefix(authReq.ClientID, user.ClientIDPrefix) {
http.Error(w, "Invalid clientid prefix", http.StatusUnauthorized)
return
}
resp := AuthResponse{Result: "allow"}
json.NewEncoder(w).Encode(resp)
}
func main() {
http.HandleFunc("/mqtt/auth", authHandler)
fmt.Println("Starting server on :8080")
http.ListenAndServe(":8080", nil)
}4. 动态添加删除用户
你可以扩展这个服务,添加用户管理的 API。例如:
// AddUserHandler adds a new user
func addUserHandler(w http.ResponseWriter, r *http.Request) {
var user User
err := json.NewDecoder(r.Body).Decode(&user)
if err != nil {
http.Error(w, "Invalid request", http.StatusBadRequest)
return
}
users[user.Username] = user
w.WriteHeader(http.StatusCreated)
}
// DeleteUserHandler deletes a user
func deleteUserHandler(w http.ResponseWriter, r *http.Request) {
username := r.URL.Query().Get("username")
if username == "" {
http.Error(w, "Username required", http.StatusBadRequest)
return
}
delete(users, username)
w.WriteHeader(http.StatusOK)
}
func main() {
http.HandleFunc("/mqtt/auth", authHandler)
http.HandleFunc("/users/add", addUserHandler)
http.HandleFunc("/users/delete", deleteUserHandler)
fmt.Println("Starting server on :8080")
http.ListenAndServe(":8080", nil)
}总结
通过上述步骤,你可以在 EMQX 4.1 中实现用户认证,包括动态添加删除用户,并对用户名、密码和 clientid 前缀进行校验。确保你的 HTTP 服务正确响应认证请求,返回适当的状态码和响应体来处理认证结果。