要实现 EMQX 用户校验,并要求动态添加删除用户以及验证用户名、密码,同时对 clientid 进行前缀验证,你可以利用 EMQX 4.1 版本中的 HTTP 认证 和 EMQX 认证/授权插件 功能。以下是详细步骤:

1. 启用 HTTP 认证插件

编辑 EMQX 配置文件 emqx.conf,启用 emqx_auth_http 插件:

$ emqx_ctl plugins load emqx_auth_http

2. 配置 HTTP 认证

在 emqx_auth_http.conf 文件中配置 HTTP 认证请求:

## HTTP API Auth Endpoint
auth.http.auth_req = http://localhost:8080/mqtt/auth
 
## Superuser Auth Endpoint
auth.http.super_req = http://localhost:8080/mqtt/superuser
 
## HTTP Headers
auth.http.header.content_type = application/json

3. 实现 HTTP 认证服务

你需要一个 HTTP 服务来处理认证请求。以下是一个使用 Go 实现的简单示例:

package main
 
import (
	"encoding/json"
	"fmt"
	"net/http"
	"strings"
)
 
// User represents a user with username, password, and clientid prefix
type User struct {
	Username    string `json:"username"`
	Password    string `json:"password"`
	ClientIDPrefix string `json:"clientid_prefix"`
}
 
// Users database (in-memory for this example)
var users = map[string]User{
	"user_a": {"user_a", "password_a", "usera"},
	"user_b": {"user_b", "password_b", "userb"},
}
 
// AuthRequest represents the request body for authentication
type AuthRequest struct {
	Username string `json:"username"`
	Password string `json:"password"`
	ClientID string `json:"clientid"`
}
 
// AuthResponse represents the response body for authentication
type AuthResponse struct {
	Result string `json:"result"`
}
 
func authHandler(w http.ResponseWriter, r *http.Request) {
	var authReq AuthRequest
	err := json.NewDecoder(r.Body).Decode(&authReq)
	if err != nil {
		http.Error(w, "Invalid request", http.StatusBadRequest)
		return
	}
 
	user, ok := users[authReq.Username]
	if !ok || user.Password != authReq.Password {
		http.Error(w, "Unauthorized", http.StatusUnauthorized)
		return
	}
 
	if !strings.HasPrefix(authReq.ClientID, user.ClientIDPrefix) {
		http.Error(w, "Invalid clientid prefix", http.StatusUnauthorized)
		return
	}
 
	resp := AuthResponse{Result: "allow"}
	json.NewEncoder(w).Encode(resp)
}
 
func main() {
	http.HandleFunc("/mqtt/auth", authHandler)
	fmt.Println("Starting server on :8080")
	http.ListenAndServe(":8080", nil)
}

4. 动态添加删除用户

你可以扩展这个服务,添加用户管理的 API。例如:

// AddUserHandler adds a new user
func addUserHandler(w http.ResponseWriter, r *http.Request) {
	var user User
	err := json.NewDecoder(r.Body).Decode(&user)
	if err != nil {
		http.Error(w, "Invalid request", http.StatusBadRequest)
		return
	}
 
	users[user.Username] = user
	w.WriteHeader(http.StatusCreated)
}
 
// DeleteUserHandler deletes a user
func deleteUserHandler(w http.ResponseWriter, r *http.Request) {
	username := r.URL.Query().Get("username")
	if username == "" {
		http.Error(w, "Username required", http.StatusBadRequest)
		return
	}
 
	delete(users, username)
	w.WriteHeader(http.StatusOK)
}
 
func main() {
	http.HandleFunc("/mqtt/auth", authHandler)
	http.HandleFunc("/users/add", addUserHandler)
	http.HandleFunc("/users/delete", deleteUserHandler)
	fmt.Println("Starting server on :8080")
	http.ListenAndServe(":8080", nil)
}

总结

通过上述步骤,你可以在 EMQX 4.1 中实现用户认证,包括动态添加删除用户,并对用户名、密码和 clientid 前缀进行校验。确保你的 HTTP 服务正确响应认证请求,返回适当的状态码和响应体来处理认证结果。