Skip to content
CAI
Software that uses CAICheck a score

dromara/Sa-Token

31.9

Weak · 25 September 2026

100.5k

lines of production code

JavaScript

with Java, TypeScript

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Sa-Token is a lightweight Java authentication framework that provides session management, permission validation, and single sign-on capabilities. It supports diverse deployment environments through plugins for Redis, JWT, and various web frameworks, while offering extensible hooks for custom security logic and OAuth2 integration.

How it got here

2020–2022 — Spring Boot 4 support and core refactoring

66 changes.

This period focused on modernizing the Sa-Token framework with official support for Spring Boot 4 and WebFlux, alongside a comprehensive refactoring of the core module to decouple it from the Servlet API. Significant architectural changes included introducing a centralized component registry, an event-driven listener system, and a pluggable strategy layer to enhance security and extensibility. The release also expanded the ecosystem with new plugins for OAuth2, JWT, and various web frameworks, supported by extensive demo applications and standardized error handling.

2023–2025 — Spring Boot 3 and Jakarta EE migration

101 changes.

This period focused on migrating the framework and its ecosystem to support Spring Boot 3 and the Jakarta EE namespace, including new Servlet adapters and auto-configuration mechanisms. It significantly expanded the demo suite to cover modern stacks like WebFlux, Solon, and various frontend architectures, while introducing a modular plugin system for serialization, HTTP clients, and authentication extensions.

2026 — Spring Boot 4 and VitePress migration

61 changes.

The project focused on extending compatibility to Spring Boot 4, introducing dedicated starters, plugins, and demo applications for both MVC and WebFlux stacks. Concurrently, the documentation site was rebuilt using VitePress to enhance SEO and user experience, while new serialization plugins and isolated Redis caching options were added to broaden integration capabilities.

Features

Add Http Basic authentication support in sa-token-core

The sa-token-core module now includes a new Http Basic authentication implementation under the cn.dev33.satoken.httpauth.basic package. This adds the SaHttpBasicAccount model, the SaHttpBasicTemplate for validation logic, and the SaHttpBasicUtil convenience class, enabling applications to authenticate requests using the standard HTTP Basic scheme.

sa-token-core/src/main/java/cn/dev33/satoken/httpauth/basic · high confidence

Add Jackson 3 JSON serialization plugin with type-safe deserialization

Introduces the sa-token-jackson3 plugin, providing a new JSON implementation for Jackson 3 that supports polymorphic serialization via the @class property. To prevent unsafe deserialization, it enforces a global type whitelist defined by SaJsonStrategy, ensuring that only allowed types can be deserialized during polymorphic processing.

sa-token-jackson3 · high confidence

Add Redisx-based session storage implementation

A new \SaTokenDaoForRedisx\ class has been added to the \sa-token-redisx\ module, providing a session data access object backed by the \org.noear.redisx\ client. This implementation supports JSON serialization for storing session data and exposes standard session operations including get, set, update, delete, timeout management, and key search, allowing users to integrate Sa-Token with the Redisx library.

sa-token-redisx · high confidence

Add SSO NoSdk client demo with manual ticket validation and replay protection

The demo application now implements the SSO NoSdk mode, handling single sign-on without relying on the Sa-Token SDK. It provides endpoints for login (validating tickets via the SSO server), logout, and retrieving user info, while also listening for push callbacks to handle remote session invalidation. To secure these manual interactions, the implementation includes signature verification with timestamp drift checks and nonce-based anti-replay protection.

sa-token-demo/sa-token-demo-sso/sa-token-demo-sso3-client-nosdk · high confidence

Add Sa-Token Quick-Login demo application

Introduces a new standalone Spring Boot demo application for the Sa-Token Quick-Login plugin. This module provides a pre-configured setup with default credentials (user: sa, password: 123456) and a simple test controller that displays a resource page requiring login. It includes startup logging that prints the application name, port, and login details, along with configuration options for enabling/disabling global authentication and customizing the login page title.

sa-token-demo/sa-token-demo-caffeine, sa-token-demo/sa-token-demo-quick-login · high confidence

Add Sa-Token and Beetl integration demo

A new demo application has been added to showcase the integration of Sa-Token with the Beetl template engine. This example includes a Spring Boot application configured to expose Sa-Token's authentication and authorization methods (such as login status, roles, and permissions) directly within Beetl templates via a custom function package. It provides a complete reference implementation featuring a login/logout controller, a global exception handler, and a sample view that demonstrates conditional rendering based on user identity and access rights.

sa-token-demo/sa-token-demo-beetl, sa-token-demo/sa-token-demo-dubbo/sa-token-demo-dubbo3-consumer, sa-token-demo/sa-token-demo-dubbo/sa-token-demo-dubbo3-provider, sa-token-demo/sa-token-demo-freemarker · high confidence

Add Sa-Token integration for the LoveQQ framework

This change introduces the \sa-token-loveqq-boot-starter\, providing automatic configuration and bean wiring for Sa-Token within applications built on the LoveQQ framework. It registers core components such as authentication filters, CORS handling, and context management, while also supporting advanced modules including API Key authentication, OAuth2 server capabilities, SSO (Single Sign-On), and API parameter signing. The starter ensures Sa-Token operates correctly in both synchronous and reactive (Reactor) environments by adapting request and response models to the LoveQQ infrastructure.

sa-token-starter/sa-token-loveqq-boot-starter · high confidence

Add Sa-Token with Redisson Spring Boot demo application

Introduces a new demonstration project for integrating Sa-Token with Redisson in a Spring Boot environment. The application provides a complete example including a login controller for authentication, global exception handling for security-related errors, and configuration files for Sa-Token and Redis connectivity, serving as a reference implementation for users.

sa-token-demo/sa-token-demo-springboot-redisson · high confidence

Add SaToken Jackson 3 JSON serialization plugin

A new plugin module for SaToken is introduced that integrates Jackson 3 as the JSON serialization backend. When installed, it automatically registers itself as the JSON template if no custom implementation has been set, allowing users to leverage Jackson 3 for session and token data serialization. The module includes comprehensive tests covering basic conversion, session type handling, whitelist enforcement, and exception wrapping to ensure reliable JSON processing.

sa-token-plugin/sa-token-jackson3 · high confidence

Add SaToken Jackson JSON plugin with low-priority auto-installation

A new plugin, SaTokenPluginForJackson, is introduced to automatically register Jackson as the JSON serialization provider for SaToken. This plugin is designed with low priority, meaning it only activates if no custom JSON template has already been configured by the user, ensuring that explicit custom configurations take precedence over the default Jackson implementation.

sa-token-plugin/sa-token-jackson/src/main/java/cn/dev33/satoken/plugin · high confidence

Add Snack3 JSON serialization plugin for Sa-Token

Introduces a new plugin that allows users to switch Sa-Token's JSON serialization to the Snack3 library. This includes a new \SaJsonTemplateForSnack3\ for object-to-JSON conversion, a customized \SaSessionForSnack3Customized\ that handles session data deserialization using Snack3's \ONode\, and the necessary plugin registration to wire these components into the Sa-Token framework.

sa-token-plugin/sa-token-snack3/src/main · high confidence

Add Snack4 JSON serialization plugin

Introduces a new JSON implementation for the Snack4 library, enabling users to serialize and deserialize Sa-Token session data and other objects using Snack4. This plugin supports polymorphic deserialization with a configurable global type whitelist to ensure security, and provides specific error handling to distinguish between missing dependencies and blocked types.

sa-token-snack4 · high confidence

Add Snack4 JSON serialization plugin for Sa-Token sessions

Introduces a new plugin that integrates the Snack4 library as the JSON serialization backend for Sa-Token. This replaces the default JSON handling with Snack4's ONode-based converter and switches session storage to a customized session class that leverages Snack4 for type-safe model retrieval from session data. The plugin is auto-registered via the standard Java SPI mechanism, allowing users to easily switch their session serialization format to Snack4.

sa-token-plugin/sa-token-snack4 · high confidence

Add Solon integration demo application

A new demo application entry point (SaTokenDemoApp) has been added to demonstrate the integration of Sa-Token with the Solon framework. This file serves as the main class to start the Solon application and prints the current Sa-Token configuration upon startup.

sa-token-demo/sa-token-demo-solon/src/main/java/com/pj · high confidence

Add Spring Boot 3 demo for Sa-Token Quick Login

Introduces a new demo application under sa-token-demo-quick-login-sb3 that demonstrates Sa-Token Quick Login functionality on Spring Boot 3. The demo includes a startup component that logs application details, a test controller serving a resource page, and an application configuration file setting up the quick login credentials and server port.

sa-token-demo/sa-token-demo-quick-login-sb3 · high confidence

Add Spring Boot 4 demo with separated Redis caches

A new demo module for Sa-Token on Spring Boot 4 is added, demonstrating the 'alone-redis' plugin that separates permission caching from business data caching. The module configures two distinct Redis connections: one dedicated to Sa-Token (using database index 2) and another for application business data (using database index 0), with a test controller illustrating login and business cache operations.

sa-token-demo/sa-token-demo-alone-redis-sb4 · high confidence

Add Spring Boot demo application entry point

The Spring Boot demo application now includes a main entry point class that initializes the application and prints the current Sa-Token configuration to the console upon successful startup.

sa-token-demo/sa-token-demo-springboot/src/main/java/com/pj · high confidence

Add TOTP two-factor authentication support

This change introduces a new TOTP (Time-based One-Time Password) module to the core library, enabling users to implement two-factor authentication. The new \SaTotpTemplate\ and \SaTotpUtil\ classes provide utilities to generate random secret keys, create TOTP codes, and validate user-entered codes with configurable time windows. It also supports generating QR code strings compatible with Google Authenticator, including an optional issuer field for better identification in authenticator apps.

sa-token-core/src/main/java/cn/dev33/satoken/secure/totp · high confidence

Add Vue 3 login page with 'Remember Me' functionality

Introduces a new Vue 3-based login interface for the 'remember-me' demo. The page allows users to authenticate with a username and password, and includes a 'Remember Me' toggle that persists the authentication token in localStorage when enabled, or uses sessionStorage otherwise. The implementation handles login state checking and logout, utilizing Element Plus for UI components and axios for backend communication.

_sa-token-demo/sa-token-demo-remember-me/page\project · high confidence

Add WebFlux demo with reactive filter context handling and permission configuration

The WebFlux demo now includes a custom WebFilter (MyFilter) that demonstrates how to call Sa-Token's synchronous API in a reactive environment by manually managing the context via SaReactorSyncHolder. It also provides a configuration class (SaTokenConfigure) registering the global SaReactorFilter for authentication and error handling, and an implementation (SttpInterfaceImpl) defining mock permission and role lists for authorization.

sa-token-demo/sa-token-demo-webflux/src/main/java/com/pj/satoken · high confidence

Add anonymous SSO client demo application

A new demo application for Sa-Token SSO Mode 3 (anonymous client) has been added. This Spring Boot app runs on port 9006 and connects to the SSO server at http://sa-sso-server.com:9000 without a specific client identifier. It provides endpoints for login, logout (single-app and single-browser), and retrieving user info, utilizing Redis (database 6) for session storage and configuring a unique token name to prevent conflicts with other demo modes.

sa-token-demo/sa-token-demo-sso/sa-token-demo-sso3-client-anon · high confidence

Add bug-reproduce sandbox module

A new temporary sandbox module has been added to reproduce specific issues. It provides a minimal Spring Boot application running on port 8092 with a health check endpoint at /ok, allowing developers to isolate and test bug cases without affecting the main demo.

sa-token-demo/sa-token-demo-bug-reproduce · high confidence

Add commented-out examples for custom OAuth2 scope handlers

The demo project now includes two new Java files, CustomOidcScopeHandler and UserinfoScopeHandler, which serve as commented-out reference implementations for extending OAuth2 scope behavior. CustomOidcScopeHandler demonstrates how to append extra fields (such as uid, nickname, and email) to an OIDC ID token, while UserinfoScopeHandler shows how to customize the data returned for the 'userinfo' scope in access tokens. These files are provided as documentation aids and are not active components.

_sa-token-demo/sa-token-demo-oauth2/sa-token-demo-oauth2-server/src/main/java/com/pj/oauth2/custom\scope · high confidence

Add custom CheckAccount annotation for demo authentication

The Solon demo now includes a custom \@CheckAccount\ annotation that requires specific username and password parameters to access annotated methods. A corresponding handler validates incoming request parameters against the values defined in the annotation, throwing an exception if they do not match.

_sa-token-demo/sa-token-demo-solon/src/main/java/com/pj/satoken/custom\annotation · high confidence

Add first-run demo to guide initial setup

A new demo module has been added to help users with the initial setup of the project. This example application forces the inclusion of optional modules (apikey, sso, oauth2, sign) to ensure that the necessary plugins are compiled before running other demos. It runs on port 8099 and prints the Sa-Token configuration upon successful startup.

sa-token-demo/sa-token-demo-first-run · high confidence

Add gRPC-based secondary context demo for authentication state synchronization

This change introduces a new gRPC-based demo application that demonstrates how to synchronize authentication state (login status and tokens) between a client and a server using the Sa-Token framework. The client application exposes HTTP endpoints that interact with a gRPC service to perform login operations and check login status, while the server implements the corresponding gRPC service to handle these requests and manage the session context. This allows developers to see how secondary contexts can be maintained across service boundaries in a microservices architecture.

sa-token-demo/sa-token-demo-grpc/client, sa-token-demo/sa-token-demo-grpc/server · high confidence

Added H5 SSO client integration example for separated front-end and back-end architectures

The SSO demo now includes a new H5 client example designed for separated front-end and back-end scenarios. This addition provides a Spring Boot controller (H5Controller) that implements specific endpoints for checking login status, retrieving the SSO authentication URL, and logging in via a ticket, alongside a configuration class (SaTokenConfigure) that sets up CORS handling to support cross-origin requests from the front end.

sa-token-demo/sa-token-demo-sso/sa-token-demo-sso3-client/src/main/java/com/pj/h5 · high confidence

Added JWT authentication demo endpoints and global exception handling

The demo application now includes a TestJwtController with endpoints for login, token info, session management, and a protected test route, demonstrating JWT-based authentication and extra parameter handling. Additionally, a GlobalException handler has been added to standardize error responses for authentication and authorization failures.

sa-token-demo/sa-token-demo-jwt/src/main/java/com/pj/test · high confidence

Added SSO Client 1 demo application

A new standalone demo application for the Sa-Token SSO Client (Mode 1) has been added, providing a concrete example of how to integrate and configure a client-side service. This demo runs on port 9001 and includes a Spring Boot entry point, a REST controller for handling login and logout flows (including single-device and full-end sign-out), and an application configuration file that sets up the SSO client identifier, server URL, and a dedicated Redis connection for session management.

sa-token-demo/sa-token-demo-sso/sa-token-demo-sso1-client, sa-token-demo/sa-token-demo-webflux/src/main/java/com/pj · high confidence

Added SSO client demo for separated front-end and back-end architectures

The SSO client demo now includes a new package for handling separated front-end and back-end scenarios. This adds an H5 controller that provides endpoints to check login status, retrieve the SSO authentication URL, and perform login via a ticket. Additionally, a configuration class is introduced to handle CORS (Cross-Origin Resource Sharing) using Sa-Token's filter mechanism, ensuring proper cross-domain access for the client application.

sa-token-demo/sa-token-demo-sso/sa-token-demo-sso2-client/src/main/java/com/pj/h5 · high confidence

Added SSO server support for separated frontend/backend architectures

The SSO server demo now includes a new \com.pj.h5\ package containing \H5Controller\ and \SaTokenConfigure\ to support separated frontend/backend integration. \H5Controller\ exposes \/sso/isLogin\ and \/sso/getRedirectUrl\ endpoints to handle login status checks and redirect URL construction for clients, while \SaTokenConfigure\ registers a CORS filter to manage cross-origin requests, enabling the demo to function correctly in a separated architecture.

sa-token-demo/sa-token-demo-sso/sa-token-demo-sso-server/src/main/java/com/pj/h5 · high confidence

Added Sa-Token demo application entry point

A new Spring Boot application entry point (SaTokenApplication) has been added to the test module. It initializes the application context and prints the current Sa-Token configuration to the console upon startup, serving as a demonstration of how to integrate and verify the library's settings.

sa-token-demo/sa-token-demo-test/src/main/java/com/pj · high confidence

Added Sa-Token demo for Dubbo 3 RPC integration

This change introduces a new demo application for the sa-token-dubbo3 plugin, providing a consumer (port 8081) and a provider (port 8080) to demonstrate RPC-based authentication. The demo illustrates how Sa-Token session states are propagated between services, allowing users to see how login status is shared or maintained across Dubbo service boundaries.

sa-token-demo/sa-token-demo-dubbo/sa-token-demo-dubbo-consumer, sa-token-demo/sa-token-demo-dubbo/sa-token-demo-dubbo-provider · high confidence

Added SaRequest and SaStorage adapters for loveqq-framework integration

The starter now includes \LoveqqSaRequest\ and \LoveqqSaStorage\ classes that implement Sa-Token's \SaRequest\ and \SaStorage\ interfaces. These adapters bridge the \loveqq-framework\'s \ServerRequest\ to Sa-Token, enabling request parameter, header, and cookie access, as well as request-scoped attribute storage, which is necessary for proper context compatibility and authentication handling within the loveqq environment.

sa-token-loveqq-boot-starter · high confidence

Added Solon-based SSO client demo application

A new demo application for the Sa-Token SSO Client (Mode 1) using the Solon framework has been added. This includes the main entry point, a configuration class for Redis-backed session storage, and a controller that demonstrates login, single-browser logout, and full logout flows via the SSO server.

sa-token-demo/sa-token-demo-sso-for-solon/sa-token-demo-sso1-client-solon · high confidence

Added Spring Boot 3 and Redis demo application

Introduced a new demo application (SaTokenSpringBoot3Application) that integrates Sa-Token with Spring Boot 3 and Redis, serving as a reference implementation for this specific technology stack.

sa-token-demo/sa-token-demo-springboot3-redis/src/main/java/com/pj · high confidence

Added Spring Boot 3 auto-configuration for standalone Redis plugin

The standalone Redis plugin now includes the necessary metadata files to support Spring Boot 3's new auto-configuration mechanism. By adding the \AutoConfiguration.imports\ file alongside the legacy \spring.factories\, the \SaAloneRedisInject\ component is automatically registered, ensuring compatibility with Spring Boot 3 applications while maintaining backward compatibility.

sa-token-plugin/sa-token-alone-redis/src/main/resources · high confidence

Added Spring Boot low-version demo for Sa-Token

Added a new demo application (\sa-token-demo-springboot-low-version\) designed to resolve compatibility issues with older Spring Boot versions (specifically \<2.2.0). This demo includes a complete setup with a main application class, a global exception handler, and a security configuration that registers Sa-Token interceptors and servlet filters. The configuration also sets up security headers (X-Frame-Options, XSS protection) and CORS policies, alongside a login controller demonstrating authentication flows and an \application.yml\ configuring Sa-Token and Redis connections.

sa-token-demo/sa-token-demo-springboot-low-version · high confidence

Added Vue 3 + Vite demo project scaffolding

The \sa-token-demo-remember-me\ location now includes a new frontend project scaffolded with Vue 3 and Vite. This addition provides the necessary entry point (\index.html\), build configuration (\vite.config.js\ with a proxy to localhost:80), and standard project files (\.gitignore\, \README.md\) to run the remember-me demo page locally.

sa-token-demo/sa-token-demo-remember-me · high confidence

Added commented-out OAuth2 custom grant type handlers and phone login controller

The OAuth2 server demo now includes three new Java files—CustomPasswordGrantTypeHandler, PhoneCodeGrantTypeHandler, and PhoneLoginController—located in the custom\_grant\_type package. These files contain fully commented-out code that demonstrates how to implement a custom password grant type, a phone code-based grant type, and a phone login endpoint for sending verification codes. As the code is currently inactive (commented out), these additions serve as documentation or reference examples for users to understand how to extend the OAuth2 server with custom authentication flows, rather than introducing new active functionality.

_sa-token-demo/sa-token-demo-oauth2/sa-token-demo-oauth2-server/src/main/java/com/pj/oauth2/custom\_grant\type · high confidence

Added global exception handling and 404 error handling examples

The demo application now includes a global exception handler that intercepts Sa-Token specific exceptions (such as not logged in, missing permissions/roles, or account bans) and returns structured JSON responses, along with a dedicated handler for 404 errors that returns a standardized JSON result instead of a default HTML page.

sa-token-demo/sa-token-demo-springboot/src/main/java/com/pj/current · high confidence

Added jQuery 3.4.1 static asset

The SSO server demo now includes the jQuery 3.4.1 library in its static resources directory, making it available for client-side scripts within the demo application.

sa-token-demo/sa-token-demo-sso/sa-token-demo-sso-server/src/main/resources/static · high confidence

Added jQuery 3.4.1 static asset to SSO server demo

The SSO server demo for Solon now includes the jQuery 3.4.1 library (jquery.min.js) in its static resources directory (WEB-INF/static/sa-res). This addition provides the frontend with a specific JavaScript version for DOM manipulation and event handling within the demo application.

sa-token-demo/sa-token-demo-sso-for-solon/sa-token-demo-sso-server-solon/src/main/resources · high confidence

Added native H5 SSO client demo for separated front-end/back-end mode

The SSO client demo now includes a new native HTML5 implementation for the separated front-end/back-end architecture. This addition provides a standalone login redirect page (sso-login.html) and a main test page (index.html) that interact with the backend via JavaScript fetch calls, enabling users to test single-sign-on flows, logout strategies (single-app, single-device, and full logout), and user info retrieval in a pure client-side environment.

sa-token-demo/sa-token-demo-sso/sa-token-demo-sso-client-h5 · high confidence

Adds current-demo test utilities and exception handling

This change introduces new support files for the current-demo test module: a global exception handler (GlobalException) that maps Sa-Token authentication/authorization errors to specific JSON responses, a 404 error controller (NotFoundHandle) returning structured JSON, and utility classes (AjaxJson for standardized API responses and Ttime for performance timing). These additions improve how the demo application handles errors and measures performance during testing.

sa-token-demo/sa-token-demo-test/src/main/java/com/pj/current · high confidence

Adds exception handling and utility classes to the Spring Boot Redis demo

This change introduces new Java classes within the \com.pj.current\ and \com.pj.util\ packages to support the Spring Boot Redis demo application. It adds a \GlobalException\ handler that intercepts authentication and authorization errors (such as not logged in, missing roles/permissions, or account bans) and returns structured JSON responses. It also includes a \NotFoundHandle\ to manage 404 errors, an \AjaxJson\ utility for standardizing API response formats, and a \Ttime\ helper for measuring execution duration.

sa-token-demo/sa-token-demo-springboot-redis/src/main/java/com/pj/current · high confidence

Documentation site rebuilt with VitePress and ECharts upgraded to 5.4.3

The documentation site has been rebuilt using VitePress, replacing the previous static structure. This update includes the addition of the ECharts library (version 5.4.3) to the public assets, enabling interactive charting capabilities for the documentation content, such as the GitHub stars comparison visualization.

sa-token-doc-new/public/a · high confidence

Expanded annotation-based security controls with new HTTP auth and service disable checks

The annotation package now includes new \@SaCheckDisable\ and \@SaIgnore\ annotations, allowing developers to restrict access based on account service bans and explicitly bypass interceptor/AOP security checks. Existing annotations have been enhanced: \@SaCheckHttpBasic\ and \@SaCheckHttpDigest\ are introduced for HTTP authentication, \@SaCheckOr\ enables flexible OR-logic across multiple security checks, and \@SaCheckPermission\ now supports an \orRole\ field for combined permission/role validation. All annotations support a \type\ field to scope checks within multi-account systems.

sa-token-core/src/main/java/cn/dev33/satoken/annotation · high confidence

Initial Solon integration demo for Sa-Token

Adds a new demonstration application for integrating Sa-Token with the Solon framework. This includes configuration classes for setting up authentication interceptors and custom permission interfaces, utility classes for standardized AJAX JSON responses and timing, and logging adapters that route Sa-Token logs to both SLF4J and Solon's native logging system.

sa-token-demo/sa-token-demo-solon/src/main/java/com/pj/satoken · high confidence

Initial setup of Sa-Token JWT demo application and utility classes

This change introduces the core structure for the Sa-Token JWT demonstration module. It adds the main Spring Boot application entry point (SaTokenJwtDemoApplication) which initializes the application and prints the current Sa-Token configuration upon startup. Additionally, it includes a utility class (AjaxJson) designed to standardize API responses by encapsulating status codes, messages, and data payloads, providing convenient static methods for common response scenarios such as success, error, warning, and authentication failures.

sa-token-demo/sa-token-demo-jwt/src/main/java/com/pj · high confidence

Introduce SaRouter for chainable HTTP request matching

Added the SaRouter utility class and its supporting SaRouterStaff builder, along with the SaHttpMethod enum, to enable chainable routing and HTTP method matching. This allows developers to define path and method-based rules (e.g., match, notMatch, check) in a fluent style, primarily for use in global interceptors or filters to perform route-based authentication and authorization.

sa-token-core/src/main/java/cn/dev33/satoken/router · high confidence

Introduce raw session management via value-based lookup

Sa-Token v1.42.0 adds a new raw session mechanism that allows sessions to be identified and retrieved by a custom value ID rather than a generated session ID. This change introduces the SaRawSessionDelegator and SaRawSessionUtil classes, which provide utilities to check for session existence, retrieve or create sessions by value ID, and delete sessions by value ID, enabling applications to manage sessions tied to specific business identifiers.

sa-token-core/src/main/java/cn/dev33/satoken/session/raw · high confidence

Introduce remember-me login demo with per-session token isolation

A new demo application is added to illustrate the 'remember-me' login flow using the sa-token framework. The server exposes endpoints for login, logout, and state checking, where the login endpoint accepts a 'remember' flag to control token persistence. Configuration sets the token timeout to 30 days and explicitly disables token sharing (is-share: false), ensuring that each login session generates a unique token rather than sharing one across concurrent sessions.

sa-token-demo/sa-token-demo-remember-me/sa-token-demo-remember-me-server · high confidence

Introduction of a unified Sa-Token filter interface for extensible request handling

Sa-Token now exposes a new \SaFilter\ interface in the core module, providing a standardized way to configure which request paths are intercepted or excluded. This interface allows users to define custom authentication logic via \setAuth\, handle errors with \setError\, and execute pre-authentication hooks via \setBeforeAuth\, all supporting lambda-style implementations through the new \SaFilterAuthStrategy\ and \SaFilterErrorStrategy\ functional interfaces. This change abstracts the filter execution model, enabling more flexible and consistent integration across different web frameworks.

sa-token-core/src/main/java/cn/dev33/satoken/filter · high confidence

Introduction of new utility classes in sa-token-core

The \sa-token-core\ module now includes several new utility classes to support internal operations and API responses. \SaFoxUtil\ provides core helper methods including secure random string generation, date formatting, and URL handling. \SaHexUtil\ adds capabilities for converting between byte arrays and hexadecimal strings. \SaResult\ offers a standardized, fluent API for constructing JSON-formatted API responses with status codes and messages. Additionally, \SaSugar\ introduces lambda execution helpers, \SaValue2Box\ provides a container for paired values, \StrFormatter\ handles string placeholder replacement, \SaTokenConsts\ centralizes global constants like version numbers and session types, and \SaTtlMethods\ defines default behaviors for token time-to-live calculations.

sa-token-core/src/main/java/cn/dev33/satoken/util · high confidence

Introduction of pluggable HTTP request handler module

sa-token now includes a new HTTP request processing module within the core library, introducing the SaHttpTemplate interface and a default implementation that throws an exception if used without a provider. Users can now perform GET and POST (form-data) requests via the new SaHttpUtil static methods, which delegate to the configured template, allowing integration with external HTTP libraries like OkHttps through the SaManager.

sa-token-core/src/main/java/cn/dev33/satoken/http · high confidence

Introduction of plugin lifecycle hook interface

A new functional interface, SaTokenPluginHookFunction, has been added to the core library to support hook functions for plugin installation and uninstallation. This interface allows developers to define custom execution logic that runs when a SaTokenPlugin is installed or removed, enabling extensibility in plugin management.

sa-token-core/src/main/java/cn/dev33/satoken/fun/hooks · high confidence

JWT authentication integration via StpLogic configuration

The demo application now supports JWT-based authentication by registering the \StpLogicJwtForSimple\ implementation in \SaTokenConfigure\. This configuration enables JWT token handling for the registered \SaInterceptor\, allowing the application to validate requests using JSON Web Tokens instead of the default session-based approach.

sa-token-demo/sa-token-demo-jwt/src/main/java/com/pj/satoken · high confidence

Jakarta Servlet adapter for Sa-Token request, response, and storage models

This module introduces Jakarta Servlet-specific implementations of Sa-Token's core request, response, and storage abstractions. The new \SaRequestForServlet\, \SaResponseForServlet\, and \SaStorageForServlet\ classes wrap \jakarta.servlet.http.HttpServletRequest\ and \HttpServletResponse\ to provide Sa-Token with a unified API for reading parameters, headers, cookies, and managing request-scoped attributes. A dedicated context utility (\SaTokenContextJakartaServletUtil\) manages the lifecycle of these wrapped objects, ensuring the context is properly set and cleared. Additionally, a new \SaJakartaServletOperateUtil\ provides a helper for writing results to the response stream, and a \SaServletErrorCode\ interface defines specific error codes for forward and redirect failures. Comprehensive unit tests are included to verify the behavior of these adapters.

sa-token-starter/sa-token-jakarta-servlet · high confidence

Jakarta Servlet integration for Spring Boot 3/4

This module introduces Jakarta Servlet-based components for Sa-Token in Spring Boot 3 and 4 environments. It registers essential filters (context initialization, CORS, and firewall checks) and a Spring MVC interceptor for annotation-based authentication via auto-configuration. The implementation uses Jakarta Servlet APIs and provides a dedicated context handler to ensure request context is correctly initialized and cleared, including support for async operations.

sa-token-starter/sa-token-spring-boot-webmvc-v3v4-common · high confidence

New API Key authentication demo application

A new standalone demo application (sa-token-demo-apikey) has been added to demonstrate the Sa-Token API Key module. It provides a complete Spring Boot setup including a login controller, API Key management endpoints (create, update, delete, list), and resource controllers protected by the @SaCheckApiKey annotation with scope-based access control. The demo includes a mock data loader for testing, a static HTML/JS interface for managing keys and testing API access, and configuration for Redis and API Key prefixes.

sa-token-demo/sa-token-demo-apikey · high confidence

New API parameter signature verification plugin

The API parameter signature module has been extracted into a standalone plugin package (sa-token-sign). This adds the @SaCheckSign annotation for verifying request signatures to prevent tampering and replay attacks, along with the SaSignManager, SaSignTemplate, and SaSignUtil classes that handle signature generation, timestamp/nonce validation, and multi-instance configuration support.

sa-token-plugin/sa-token-sign/src/main · high confidence

New Apache Fory JSON serialization plugin for Sa-Token

This change introduces a new plugin that allows Sa-Token to use Apache Fory for JSON serialization and deserialization. It provides a custom \SaJsonTemplate\ implementation and a specialized \SaSession\ class that leverages Fory for high-performance data conversion, enabling users to switch their session storage backend to Fory by simply installing the plugin.

sa-token-plugin/sa-token-fory-json · high confidence

New Caffeine-based in-memory DAO plugin

A new \sa-token-caffeine\ plugin is introduced, providing an in-memory data access object (DAO) implementation backed by Caffeine. This allows users to replace the default persistence layer with a fast, JVM-local cache that supports object storage with configurable timeouts and automatic expiration, though data is lost upon system restart. The plugin includes a dedicated \SaTokenDaoForCaffeine\ implementation, a \SaMapPackageForCaffeine\ wrapper for the underlying cache, and a plugin installer that swaps the global DAO instance, accompanied by comprehensive unit tests for the new components.

sa-token-plugin/sa-token-caffeine · high confidence

New Forest-based HTTP client plugin for Sa-Token

The sa-token-forest module introduces a new plugin that integrates the Forest HTTP client library into Sa-Token. This allows users to replace the default HTTP request handler with Forest by simply installing the plugin, which automatically configures Forest (disabling its default logging) and registers the new template globally. The change includes the implementation of the Forest-specific HTTP template, the plugin registration via SPI, and corresponding unit tests to verify the installation behavior and HTTP request functionality.

sa-token-plugin/sa-token-forest · high confidence

New Freemarker dialect plugin for Sa-Token template tags

This change introduces the \sa-token-freemarker\ plugin, adding a new Freemarker dialect that exposes Sa-Token authentication and authorization checks directly in templates. It registers twelve new template directives under the \sa\ namespace: \login\ and \notLogin\ for session state, \hasRole\, \hasRoleAnd\, \hasRoleOr\, \notRole\, and \lackRole\ for role-based checks, and \hasPermission\, \hasPermissionAnd\, \hasPermissionOr\, \notPermission\, and \lackPermission\ for permission-based checks. The implementation includes \SaTokenTemplateModel\ to manage these directives and \SaTokenTemplateDirectiveModel\ to handle the conditional rendering logic, along with comprehensive unit tests verifying the correct display and hiding of template content based on login status, roles, and permissions.

sa-token-plugin/sa-token-freemarker · high confidence

New HTTP client plugins for RestClient and RestTemplate

SaToken now provides optional plugins to switch its internal HTTP request handling to specific client implementations. The new \SaTokenPluginForRestClient\ and \SaTokenPluginForRestTemplate\ modules allow users to replace the default HTTP template with Spring's RestTemplate or the Alibaba RestClient, respectively. Installing these plugins automatically registers the chosen implementation as the global HTTP handler, enabling SaToken's HTTP features to work with the user's preferred client library.

sa-token-plugin/sa-token-rest-client, sa-token-plugin/sa-token-rest-template · high confidence

New HTTP request plugins for RestTemplate and RestClient

Sa-Token now provides two new HTTP request extension plugins that allow the framework to perform internal HTTP calls using either the legacy RestTemplate or the modern RestClient. This enables SSO client applications to validate tickets and exchange data with the SSO server using the HTTP client implementation that best fits their Spring Boot version and preferences.

sa-token-demo/sa-token-demo-sso/sa-token-demo-sso3-client--sb4, sa-token-rest-client, sa-token-rest-template · high confidence

New Http Digest Authentication module

Sa-Token introduces a new Http Digest authentication module (SaHttpDigestTemplate, SaHttpDigestModel, SaHttpDigestUtil) that allows applications to authenticate users using the HTTP Digest Access scheme. This includes parsing the Authorization header, calculating MD5-based response digests, and handling 401 challenges. The implementation specifically addresses a bug where URI query parameters containing '=' characters caused parsing failures, ensuring requests with query strings are authenticated correctly.

sa-token-core/src/main/java/cn/dev33/satoken/httpauth/digest · high confidence

New Hutool TimedCache plugin for Sa-Token persistence

A new plugin is available that integrates Hutool's TimedCache as the data persistence layer for Sa-Token. This allows applications to use an in-memory cache with automatic expiration and scheduled pruning instead of the default persistence mechanism. Note that data stored in this cache is lost upon system restart. Users can enable this by installing the plugin, which registers the new DAO implementation.

sa-token-plugin/sa-token-hutool-timed-cache/src/main · high confidence

New JFinal plugin for Sa-Token authentication and session management

This release introduces the \sa-token-jfinal-plugin\, providing first-class integration between Sa-Token and the JFinal web framework. The plugin includes a custom \ActionHandler\ (\SaTokenActionHandler\) to manage the Sa-Token context lifecycle during request dispatching, a \PathAnalyzer\ for efficient route matching with support for wildcards and path variables, and a \SaAnnotationInterceptor\ to enforce annotation-based security checks (e.g., \@SaCheckLogin\). It also features a Redis-backed token storage implementation (\SaTokenDaoRedis\) using a dedicated JDK serializer (\SaJdkSerializer\) to ensure consistent data handling, along with a path-based filter (\SaTokenPathFilter\) for flexible include/exclude routing rules. Comprehensive unit tests are included for all core components.

sa-token-starter/sa-token-jfinal-plugin · high confidence

New JWT-based temporary token plugin

The sa-token-temp-jwt module now provides a new plugin that implements temporary token generation and validation using JWTs. Users can enable this by configuring the jwtSecretKey; the plugin registers a SaTempTemplateForJwt implementation that creates stateless tokens containing value and expiration claims, parses them back, and reports remaining timeout. Because JWTs are stateless, deleteToken and getTempTokenList are disabled and throw specific errors. Tests verify token creation, parsing, expiration handling, and plugin installation.

sa-token-plugin/sa-token-temp-jwt · high confidence

New JaCoCo coverage summary report with detailed metrics

A new custom report generator has been added to the sa-token-coverage module that processes JaCoCo CSV data to produce an HTML summary page. This report displays comprehensive coverage percentages for instructions, branches, lines, complexity, methods, and classes, and allows users to view aggregated metrics grouped by module or package.

sa-token-testing/sa-token-coverage · high confidence

New Jboot plugin for Sa-Token authentication and caching

This release introduces the \sa-token-jboot-plugin\, providing first-class support for the Jboot framework. It includes a path analyzer for route matching, an annotation interceptor for method-level security checks, and a path filter for URL-based access control. The plugin also features a Redis-backed cache implementation (\SaRedisCache\ and \SaTokenCacheDao\) that uses a custom JDK serializer to ensure consistent data handling, along with a context handler that integrates Sa-Token's request/response objects with Jboot's servlet environment.

sa-token-starter/sa-token-jboot-plugin · high confidence

New OAuth2 client demo application with interactive test UI

This change introduces a new Spring Boot-based OAuth2 client demo application (running on port 8002) that provides a complete, interactive test interface for OAuth2 flows. The included HTML template allows users to test Authorization Code, Implicit, Password, and Client Credentials grant types, as well as token refresh and user info retrieval. The application is configured with a specific token name (satoken-client) and includes utility classes to support the demo's data handling.

sa-token-demo/sa-token-demo-oauth2/sa-token-demo-oauth2-client · high confidence

New OAuth2 demo pages for client testing and server-side separation

The OAuth2 demo module now includes a new client-side test page (sa-token-demo-oauth2-client-h5) that allows users to manually configure and test all four OAuth2 grant flows (Authorization Code, Implicit, Password, and Client Credentials) directly in the browser. Additionally, a new server-side demo (sa-token-demo-oauth2-server-h5) has been added, featuring a separated frontend interface for the OAuth2 authorization server that handles login and explicit user consent/authorization confirmation.

sa-token-demo/sa-token-demo-oauth2 · high confidence

New OAuth2 server controller for separated front-end and back-end scenarios

A new REST controller, SaOAuth2ServerH5Controller, has been added to the OAuth2 server module to support front-end and back-end separation. This controller exposes a POST endpoint at /oauth2/getRedirectUri, which handles the core authorization logic for both the Authorization Code and Implicit grant types. It manages user login checks, scope contract validation, and manual authorization confirmation, returning the appropriate redirect URI with the authorization code or access token upon successful completion.

sa-token-demo/sa-token-demo-oauth2/sa-token-demo-oauth2-server/src/main/java/com/pj/oauth2/h5 · high confidence

New OkHttps plugin for HTTP requests

This release introduces the sa-token-okhttps plugin, providing an implementation of the HTTP request handler using the OkHttps library. Users can now register this plugin to replace the default HTTP template, enabling Sa-Token to perform internal HTTP calls (GET and POST with form data) via OkHttps. The plugin is auto-discovered via the META-INF service loader and includes unit tests to verify the installation behavior and HTTP operations.

sa-token-plugin/sa-token-okhttps · high confidence

New SSM (Spring MVC) demo for Sa-Token integration

Added a new demonstration project for integrating Sa-Token into non-Spring Boot SSM (Spring MVC) applications. This includes the necessary configuration files (web.xml, Spring XML configs), a custom SaTokenContextFilter to manage context via ThreadLocal, manual bean injection setup for Sa-Token components, and sample controllers demonstrating login, logout, and annotation-based authorization checks.

sa-token-demo/sa-token-demo-ssm · high confidence

New SSO client demo applications for modes 2 and 3

The demo project now includes dedicated Spring Boot application entry points for Single Sign-On (SSO) Mode 2 and Mode 3 clients. These new files, SaSso2ClientApplication and SaSso3ClientApplication, initialize the respective client configurations and provide console output with test URLs and credentials, allowing users to easily start and verify the specific client-side implementations for these SSO modes.

sa-token-demo/sa-token-demo-sso/sa-token-demo-sso2-client/src/main/java/com/pj, sa-token-demo/sa-token-demo-sso/sa-token-demo-sso3-client/src/main/java/com/pj · high confidence

New SSO server H5 demo for platform-center mode

The SSO server H5 demo now includes a new platform-center mode example for the front-end and back-end separation architecture. This adds a set of static files (HTML, CSS, JS) that provide a login page and a home page, allowing users to test SSO authentication flows with multiple client systems in a separated deployment scenario.

sa-token-demo/sa-token-demo-sso/sa-token-demo-sso-server-h5 · high confidence

New Sa-Token Redis Cluster and Sentinel demo application

Added a new standalone demo application that integrates Sa-Token with Redis using both cluster and sentinel topologies. The project includes a Spring Boot entry point, a test controller demonstrating login and business cache operations, and a utility class for standardized JSON responses. Configuration files are provided for both Redis cluster mode (connecting to nodes 127.0.0.1:3000-3002) and Redis sentinel mode, allowing users to explore Sa-Token's session management in high-availability Redis environments.

sa-token-demo/sa-token-demo-alone-redis-cluster · high confidence

New Sa-Token demo application with comprehensive authentication examples

The sa-token-demo-case module has been added as a new Spring Boot application demonstrating Sa-Token capabilities. It includes controllers for login, logout, and session management, as well as examples for annotation-based authorization, role and permission checks, and multi-account authentication. The demo also covers advanced features such as temporary tokens, account disabling, mutex login, remember-me functionality, secondary authentication, identity switching, and HTTP Basic authentication. Additionally, it provides a global exception handler for Sa-Token exceptions and a configuration class for setting up the Sa-Token interceptor and CORS handling.

sa-token-demo/sa-token-demo-case · high confidence

New Sa-Token demo configuration and integration components

The demo application now includes a dedicated configuration class (SaTokenConfigure) that registers the Sa-Token interceptor and servlet filter, sets up security response headers (X-Frame-Options, X-XSS-Protection, X-Content-Type-Options), and provides a default CORS handling strategy. It also introduces a custom logging bridge (SaLogForSlf4j) to route Sa-Token logs to SLF4J, a custom permission interface implementation (StpInterfaceImpl) for defining roles and permissions, and an updated StpUserUtil tool class that supports the new SaLoginParameter and SaLogoutParameter models for finer control over login and logout behaviors.

sa-token-demo/sa-token-demo-test/src/main/java/com/pj/satoken · high confidence

New Sa-Token demo using BOM for dependency management

A new demo module has been added that demonstrates how to integrate Sa-Token using a Bill of Materials (BOM) to align versions. The application runs on port 8081 and includes a global exception handler, a test controller for login and authentication checks, and a configuration that enables concurrent logins while disabling token sharing (is-share: false). It also configures Sa-Token with JWT support and connects to a local Redis instance.

sa-token-demo/sa-token-demo-bom-import · high confidence

New Sa-Token standalone Redis demo application

Added a new standalone Spring Boot demo application that integrates Sa-Token with Redis for session management. The application includes a main entry point, a utility class for standardized AJAX JSON responses, and a test controller demonstrating login functionality via Sa-Token and basic Redis operations.

sa-token-demo/sa-token-demo-alone-redis/src/main/java · high confidence

New Sa-Token standalone Redis plugin for cache separation

A new \sa-token-alone-redis\ plugin is introduced, allowing users to configure a dedicated Redis connection for Sa-Token's permission cache, separate from the application's business cache. This is achieved via the \SaAloneRedisInject\ component, which reads configuration from the \sa-token.alone-redis\ prefix and supports single, cluster, sentinel, socket, and AWS ElastiCache connection patterns, as well as connection pool tuning.

sa-token-plugin/sa-token-alone-redis/src/main/java · high confidence

New SaCheckEL annotation for SpEL-based authorization

The sa-token-spring-el plugin introduces the @SaCheckEL annotation, allowing developers to define authorization rules using Spring Expression Language (SpEL) on methods or classes. This feature enables dynamic checks by evaluating expressions against method arguments, session data, Spring beans, and Sa-Token's StpLogic (e.g., stp.checkLogin()). The plugin auto-configures the necessary AOP aspect and provides a root context for expressions, including a NEED() helper for assertions.

sa-token-plugin/sa-token-spring-el · high confidence

New SaToken plugin for Spring Boot 4 enables separate Redis caching

Introduced the \sa-token-alone-redis-by-spring-boot4\ plugin, which allows Spring Boot 4 applications to configure a dedicated Redis connection for SaToken's permission and data caching, distinct from the application's main business cache. The plugin supports standalone, cluster, sentinel, socket, and AWS ElastiCache connection patterns via the \sa-token.alone-redis\ configuration prefix, and includes a fix to ensure exceptions during injection are explicitly wrapped and thrown rather than silently swallowed.

sa-token-alone-redis-by-spring-boot4 · high confidence

New Solon-Redisson demo application for Sa-Token

Adds a new demo project (\sa-token-demo-solon-redisson\) that integrates Sa-Token with the Solon framework and Redisson. This demo provides a complete reference implementation including Solon-specific configuration classes (\SaTokenConfigure\), custom logging adapters for Solon and SLF4J, and a global exception filter to handle Sa-Token exceptions. It also includes test controllers demonstrating login, logout, role/permission checks, session management, SSO, and stress testing, all configured to use Redis for session storage via \SaTokenDaoForRedisson\.

sa-token-demo/sa-token-demo-solon-redisson, sa-token-demo/sa-token-demo-sse · high confidence

New Spring Boot 3 WebFlux demo with reactive Sa-Token context handling

Adds a new demo application for Sa-Token integrated with Spring Boot 3 WebFlux. It demonstrates how to manage Sa-Token's synchronous API within a reactive environment by using \SaReactorSyncHolder\ to set and clear context in custom filters and route definitions, and \SaReactorHolder.sync\ to wrap API calls in controllers and services that may switch threads or operate within reactive streams.

sa-token-demo/sa-token-demo-webflux-springboot3/src/main/java · high confidence

New Spring Boot 3 demo for Sa-Token with Redisson

A new standalone demo application has been added for Sa-Token running on Spring Boot 3, demonstrating the integration with the 'alone-redisson' plugin to separate permission caching from business caching. The demo includes a Spring Boot 3 application entry point, a test controller that exercises both Sa-Token login caching and direct Redisson business caching, and an application configuration that defines two distinct Redisson connections: one dedicated to Sa-Token (on Redis database 2) and another for general business use (on Redis database 0).

sa-token-demo/sa-token-demo-alone-redisson-sb3 · high confidence

New Spring Boot 4 Reactor starter module with auto-configuration

This change introduces the \sa-token-reactor-spring-boot4-starter\ module, providing integration for Spring Boot 4 with reactive (Reactor) applications. It includes the \SaTokenContextRegister\ auto-configuration class, registered via the standard Spring Boot 4 \AutoConfiguration.imports\ file, and a \Placeholder\ class to serve as a structural anchor for the new starter. Tests verify that the auto-configuration is correctly declared and loadable.

sa-token-starter/sa-token-reactor-spring-boot4-starter · high confidence

New Spring Boot 4 WebFlux demo for Sa-Token integration

Added a new example application under sa-token-demo-webflux-springboot4 that demonstrates how to integrate Sa-Token with Spring Boot 4 using the reactive WebFlux stack. The demo includes configuration for the SaReactorFilter, a custom WebFilter for context synchronization, and functional routing examples showing how to handle authentication, session management, and permission checks within reactive Mono/Flux chains.

sa-token-demo/sa-token-demo-webflux-springboot4 · high confidence

New Spring Boot 4 and Redis demo application

Adds a new demo application under \sa-token-demo-springboot4-redis\ that demonstrates integrating Sa-Token with Spring Boot 4 and Redis. This example includes a complete setup with a main application class, Sa-Token configuration (including security headers and interceptors), custom permission/role interfaces, and controllers for login, logout, annotation-based authorization (login, role, permission, safe, and HTTP basic checks), global exception handling, and a stress test for login performance.

sa-token-demo/sa-token-demo-springboot4-redis · high confidence

New Spring Boot 4 demo with separated Redisson caches

A new standalone demo application has been added for Sa-Token on Spring Boot 4, demonstrating the 'alone-redisson' plugin to separate permission caching from business caching. The demo configures two distinct Redisson connections via YAML: one for Sa-Token (database 2) and another for business data (database 0). It includes a test controller that validates this separation by logging into Sa-Token and setting a business cache entry independently.

sa-token-demo/sa-token-demo-alone-redisson-sb4 · high confidence

New Spring Boot 4 plugin for separate Sa-Token Redis caching

The new \sa-token-alone-redis-by-spring-boot4\ plugin enables Spring Boot 4 applications to configure a dedicated, independent Redis instance for Sa-Token's permission and data caching. By registering the \SaAloneRedisInject\ auto-configuration, the plugin ensures that Sa-Token's internal cache is isolated from the application's primary business Redis connection, supporting standalone, sentinel, and cluster topologies via the \sa-token.alone-redis\ configuration prefix. Comprehensive tests verify that the plugin correctly initializes this separate connection and validates error handling for missing or invalid configurations.

sa-token-plugin/sa-token-alone-redis-by-spring-boot4 · high confidence

New Spring WebSocket authentication demo added

A new demo module, sa-token-demo-websocket-spring, has been added to showcase integrating Sa-Token with Spring's WebSocket support. This example includes a login controller for obtaining tokens, a WebSocket configuration class, and a custom interceptor that validates the Sa-Token during the handshake phase to ensure only authenticated users can establish a connection.

sa-token-demo/sa-token-demo-websocket-spring · high confidence

New Thymeleaf integration demo with Sa-Token dialect

A new demo application has been added for integrating Sa-Token with Thymeleaf. It includes a Spring Boot configuration that registers the Sa-Token Thymeleaf dialect and exposes the session logic as a global variable, allowing templates to use specific tags (like sa:login, sa:hasRole) for permission checks. The demo also provides a test controller for login/logout actions and a sample index page demonstrating these tag features.

sa-token-demo/sa-token-demo-thymeleaf · high confidence

New Vue 2 and Vue 3 SSO client demos and ReSdk Java demo added

The demo suite now includes dedicated single-sign-on client examples for both Vue 2 and Vue 3, alongside a new Java ReSdk-based client. The Vue 2 demo uses the standard Vue CLI setup, while the Vue 3 demo leverages Vite and the Composition API; both provide frontend interfaces for login, logout, and account info retrieval. Additionally, a new Java Spring Boot demo (\sa-token-demo-sso3-client-resdk\) demonstrates SSO integration using the ReSdk library with custom session handling.

sa-token-demo/sa-token-demo-sso/sa-token-demo-sso-client-vue2 · high confidence

New asynchronous usage demo for Sa-Token

A new demo application has been added to demonstrate how to use Sa-Token in asynchronous scenarios, including standard threads, thread pools, Spring's @Async, and scheduled tasks. The demo includes a configuration class to register Sa-Token interceptors and filters, a global exception handler, and a test controller that illustrates how to manually propagate token context using SaTokenContextMockUtil when switching threads, addressing common issues with InheritableThreadLocal in async environments.

sa-token-demo/sa-token-demo-async · high confidence

New auto-implementation interfaces for SaTokenDao reduce boilerplate

Three new interfaces—SaTokenDaoBySessionFollowObject, SaTokenDaoByStringFollowObject, and SaTokenDaoByObjectFollowString—have been added to the core module to simplify custom cache implementations. SaTokenDaoBySessionFollowObject provides default session operations that delegate to object-level methods, while SaTokenDaoByStringFollowObject and SaTokenDaoByObjectFollowString offer complementary defaults for string and object storage patterns respectively. These interfaces allow developers to implement only the storage layer relevant to their use case, with the framework handling the translation between sessions, objects, and strings automatically.

sa-token-core/src/main/java/cn/dev33/satoken/dao/auto · high confidence

New demo application integrating Sa-Token with Hutool TimedCache

Adds a new Spring Boot demo project (\sa-token-demo-hutool-timed-cache\) that demonstrates how to integrate the Sa-Token authentication framework with Hutool's TimedCache for session storage. The demo includes a complete configuration setup (\SaTokenConfigure\) with security headers, a custom permission/role interface (\StpInterfaceImpl\), global exception handling for auth errors, and controllers for login/logout testing and performance stress testing.

sa-token-demo/sa-token-demo-hutool-timed-cache · high confidence

New device-lock demo application with H5 frontend

Adds a new demo application under sa-token-demo-device-lock that demonstrates device-lock security. The backend (Spring Boot) includes a login controller that checks device trust via Sa-Token, utilizing utility classes for device-user mapping and simulated phone-code verification, while the H5 frontend provides the corresponding login, device-auth, and index pages to interact with these endpoints.

sa-token-demo/sa-token-demo-device-lock · high confidence

New emoji-based Base64 serializer plugin

The sa-token-serializer-features module now includes a new serializer implementation that encodes token data using a custom Base64 scheme where the 64 standard characters are replaced by a specific set of 64 emoji characters (U+1F600 to U+1F63F). This allows users to serialize session tokens into a string composed entirely of emojis, which may be useful for specific display or compatibility requirements.

sa-token-serializer-features · high confidence

New functional interfaces and utility class in the core fun package

The core library now includes a set of new functional interfaces—SaFunction, SaParamFunction, SaParamRetFunction, SaRetFunction, SaRetGenericFunction, and SaTwoParamFunction—along with the IsRunFunction utility and SaRouteFunction. These additions provide standardized, lambda-friendly interfaces for various parameter and return-value combinations, enabling developers to write more concise and expressive code when integrating with the framework's routing and execution logic.

sa-token-core/src/main/java/cn/dev33/satoken/fun · high confidence

New functional strategy interfaces for extensible authentication and session management

The core library now exposes a comprehensive set of functional interfaces in the \cn.dev33.satoken.fun.strategy\ package, allowing developers to customize internal behaviors via lambda expressions. Key additions include \SaAutoRenewFunction\ for custom token auto-renewal logic, \SaCorsHandleFunction\ for unified cross-origin request handling, and \SaFirewallCheckFunction\ for custom firewall validation. Session and token lifecycle management can be tailored using \SaCreateSessionFunction\, \SaCreateTokenFunction\, and \SaGenerateUniqueTokenFunction\. Additionally, annotation-based security is now more flexible with interfaces like \SaCheckElementAnnotationFunction\ and \SaGetAnnotationFunction\, while request context creation is customizable through \SaCreateSaRequestFunction\, \SaCreateSaResponseFunction\, and \SaCreateSaStorageFunction\. This refactoring shifts many internal implementation details into pluggable strategies.

sa-token-core/src/main/java/cn/dev33/satoken/fun/strategy · high confidence

New gRPC plugin for automatic session and authentication context propagation

A new gRPC integration module has been added to automatically propagate Sa-Token session context across RPC calls. The plugin uses Spring Boot auto-configuration to register client and server interceptors that transparently attach authentication tokens to outgoing requests and bind them to the local context on incoming requests, ensuring consistent user identity and session state across gRPC services without manual token handling.

sa-token-plugin/sa-token-grpc/src/main · high confidence

New global application-scoped storage via SaApplication

The core library introduces a new \SaApplication\ class and supporting interfaces (\SaGetValueInterface\, \SaSetValueInterface\) in the \cn.dev33.satoken.application\ package, enabling global, application-wide key-value storage. This new API allows users to store and retrieve data that persists across the application's lifecycle (and within Redis if integrated), distinct from session or user-specific storage. It provides type-safe collection reading methods (\getList\, \getSet\, \getMap\) and utility methods for managing global variables, effectively replacing or supplementing previous ad-hoc global state management patterns.

sa-token-core/src/main/java/cn/dev33/satoken/application · high confidence

New integration demos for JFinal and loveqq-framework

Added two new demonstration projects to the sa-token-demo suite: a JFinal integration example (sa-token-demo-jfinal) and a loveqq-framework integration example (sa-token-demo-loveqq-boot). The JFinal demo provides a complete setup including configuration, global exception handling, and controllers for login, logout, and annotation-based permission/role checks. The loveqq-framework demo showcases Sa-Token integration within a reactive (Reactor) environment, demonstrating context management, login flows, and service-layer interactions using the loveqq framework's annotations and utilities.

sa-token-demo/sa-token-demo-loveqq-boot · high confidence

New mock context utilities for unit testing

Added mock implementations for the request, response, and storage context interfaces (SaRequest, SaResponse, SaStorage) along with a utility class (SaTokenContextMockUtil) to easily set up and tear down these mock contexts. This allows developers to write unit tests for Sa-Token logic without needing a real servlet container or HTTP request/response objects.

sa-token-core/src/main/java/cn/dev33/satoken/context/mock · high confidence

New plugin system with lifecycle hooks and SPI support

Sa-Token introduces a new plugin architecture (v1.41.0) centered on the SaTokenPlugin interface, which defines install and destroy lifecycle hooks. The SaTokenPluginHolder manages plugin loading via the SPI mechanism (reading from META-INF/satoken/), allowing plugins to be automatically discovered and initialized. This change enables developers to extend Sa-Token by implementing the SaTokenPlugin interface and registering hook functions for installation and destruction events.

sa-token-core/src/main/java/cn/dev33/satoken/plugin · high confidence

New quick-login web controller for login UI and API

The sa-token-quick-login module now includes a dedicated web controller (SaQuickController) that serves the login page at /saLogin and handles login submissions via POST /doLogin. This enables users to access a built-in login interface and submit credentials through the standard quick-login flow.

sa-token-plugin/sa-token-quick-login/src/main/java/cn/dev33/satoken/quick/web · high confidence

New sa-token-serializer-features plugin for custom Base64 serialization

The new \sa-token-serializer-features\ plugin introduces a set of custom Base64 serializers that allow developers to replace the standard character set with alternative encodings. This includes built-in implementations using Chinese characters (TianGan/DiZhi), the periodic table of elements, special symbols, and emojis, as well as a base class for fully custom character sets. The plugin is designed to be opt-in; it does not register any serializer by default, requiring developers to manually install the desired implementation via \SaManager.setSaSerializerTemplate\.

sa-token-plugin/sa-token-serializer-features · high confidence

New serialization template with JDK, Base64, Hex, and ISO-8859-1 options

The serializer module now includes a new \SaSerializerTemplate\ interface that adds \objectToBytes\ and \bytesToObject\ methods alongside the existing string-based serialization. This enables new serialization implementations, including a JDK-based serializer that can be configured with Base64, Hex, or ISO-8859-1 encoding strategies, providing users with more flexible options for serializing objects to byte arrays and strings.

sa-token-core/src/main/java/cn/dev33/satoken/serializer · high confidence

New standalone API Key authentication plugin

The API Key module has been extracted into a new independent plugin package (sa-token-apikey). This change introduces a dedicated plugin architecture for API Key management, including the SaCheckApiKey annotation for method-level scope validation, a configurable prefix and expiration model, and a pluggable data loader interface for custom storage backends.

sa-token-plugin/sa-token-apikey/src/main · high confidence

New standalone Redisson connection plugin for Sa-Token

A new \sa-token-alone-redisson\ plugin has been added, allowing users to configure a dedicated Redisson client for Sa-Token's session storage. This separates permission caching from the application's main Redis cache. Users can configure this independent connection via Spring Boot properties (\sa-token.alone-redisson.config\ for inline YAML or \sa-token.alone-redisson.file\ for a path to a Redisson YAML file). The plugin automatically registers a \SaTokenDao\ backed by this separate Redisson instance, ensuring token data is stored in a distinct Redis namespace/connection.

sa-token-plugin/sa-token-alone-redisson · high confidence

New standalone Redisson demo applications for Sa-Token

Added two new Spring Boot demo applications that integrate Sa-Token with the standalone Redisson plugin. The \sa-token-demo-alone-redisson\ example demonstrates separating Sa-Token's permission cache from application business cache using distinct Redis connections on a single server. The \sa-token-demo-alone-redisson-cluster\ example extends this pattern to a cluster environment, configuring Sa-Token to use a Redisson cluster connection while the application's business cache continues to use a separate single-node Redis connection.

sa-token-demo/sa-token-demo-alone-redisson, sa-token-demo/sa-token-demo-alone-redisson-cluster · high confidence

New standalone Spring Boot Redis demo application

A new standalone demo application has been added at \sa-token-demo/sa-token-demo-springboot-redis\ to demonstrate Sa-Token integration with Spring Boot and Redis. The entry point \SaTokenDemoApplication\ initializes the Spring Boot context and prints the active Sa-Token configuration upon startup, providing a concrete reference for users setting up session management with Redis storage.

sa-token-demo/sa-token-demo-springboot-redis/src/main/java/com/pj · high confidence

New static assets for the Sa-Token documentation site

The documentation site now includes a suite of new client-side static files to support its new features. A new 'Cases' showcase page is introduced, backed by \cases.js\, \cases.css\, and data sources (\cases.json\, \cases--by-awesome-sa-token.js\, \cases--by-github-used-by.js\) that aggregate and display community projects. A new 'Access Report' script (\ar.js\) is added to track page views and user engagement, dynamically loaded by the new \all-version-common.js\ which also manages the documentation version selector. Additionally, a 'Chapter Lock' plugin (\doc-lock-plugin.js\) is added to gate access to specific documentation sections (like SSO and OAuth2) behind a verification step.

sa-token-doc-new/public/static · high confidence

New static site assets for the Sa-Token documentation and cases pages

The public directory now includes the static HTML, CSS, and assets for the new documentation site, including a dedicated cases page, a 404 error page, and a document index page that redirects to the new structure. The site also features an llms.txt file for AI/LLM reference rules and a robots.txt file to manage search engine indexing and sitemap location.

sa-token-doc-new/public · high confidence

New temporary token validation module for short-lived access

Introduces a new temporary token module in sa-token-core, providing short-lived tokens designed for one-time API protection and brief resource access. The module adds SaTempTemplate and SaTempUtil classes, enabling users to create tokens with specific values and timeouts, parse tokens to retrieve associated values, and optionally record indexes to look up tokens by their value. It supports namespace isolation for multi-instance scenarios and includes methods to manage token lifecycles and retrieve remaining validity periods.

sa-token-core/src/main/java/cn/dev33/satoken/temp · high confidence

New timed cache implementation with lazy expiration and background cleanup

The core library now includes a new timed cache implementation (SaTimedCache) in the timedcache package, featuring lazy expiration checks on access and an optional background thread for periodic cleanup of expired keys. This change introduces a new abstraction (SaMapPackage) to wrap underlying map implementations, with an initial concrete implementation for ConcurrentHashMap, allowing for more flexible and efficient cache management within the SaTokenDao layer.

sa-token-core/src/main/java/cn/dev33/satoken/dao/timedcache · high confidence

OAuth2 Server Demo Application Entry Point

The OAuth2 server demo application now includes a dedicated Spring Boot entry point class (SaOAuth2ServerApplication) to launch the server. This class initializes the application context and prints the current Sa-Token OAuth2 server configuration to the console upon successful startup, providing a clear starting point for running the OAuth2 server demo.

sa-token-demo/sa-token-demo-oauth2/sa-token-demo-oauth2-server/src/main/java/com/pj · high confidence

OAuth2 client demo adds controller for authorization flows

The sa-token-demo-oauth2-client module now includes a SaOAuthClientController that demonstrates how to interact with an OAuth2 server. It provides endpoints for code-based login, token refresh, password-based login, client credentials grant, user info retrieval, and logout, handling the exchange of authorization codes and tokens via HTTP calls to the configured server.

sa-token-demo-oauth2-client · high confidence

Redisson integration now auto-configures via Spring Boot starters

The Redisson plugin now automatically registers the SaTokenDaoForRedisson bean when Spring Boot detects Redisson on the classpath. This is achieved through new auto-configuration classes and Spring Boot 3-compatible metadata files, removing the need for manual bean registration and ensuring seamless integration with Redis-backed session storage.

sa-token-plugin/sa-token-redisson-spring-boot-starter · high confidence

SPI registration for JSON serialization plugins

The Fastjson, Fastjson2, and Jackson plugins now register their implementations via Java Service Provider Interface (SPI) files. This allows the framework to automatically discover and load the respective JSON serialization handlers without requiring manual configuration by the user.

sa-token-plugin/sa-token-fastjson/src/main/resources, sa-token-plugin/sa-token-fastjson2/src/main/resources, sa-token-plugin/sa-token-jackson/src/main/resources · high confidence

SSO server application entry point and startup logging

The SSO server demo now includes a dedicated Spring Boot application entry point (SaSsoServerApplication) that initializes the application context and prints key configuration details upon startup, including the unified authentication login URL (http://sa-sso-server.com:9000/sso/auth) and test credentials.

sa-token-demo/sa-token-demo-sso/sa-token-demo-sso-server/src/main/java/com/pj · high confidence

Sa-Token OAuth2 module introduces annotation-based access control and OIDC support

The OAuth2 plugin now provides \@SaCheckAccessToken\, \@SaCheckClientToken\, and \@SaCheckClientIdSecret\ annotations, allowing developers to enforce scope-based and client-credential validation directly on methods or classes. The module also adds OpenID Connect (OIDC) configuration via \SaOAuth2OidcConfig\ to support standard OIDC flows, and introduces a new \SaOAuth2Manager\ central controller to manage OAuth2 components like data loaders, converters, and DAOs through a unified interface.

sa-token-plugin/sa-token-oauth2/src/main · high confidence

Sa-Token Quick-Login plugin adds Http Basic authentication support

The sa-token-quick-login module now supports Http Basic authentication. When a request includes Http Basic credentials, the plugin's authentication filter will attempt to log in the user using those credentials via a configurable login handle function, rather than only falling back to the standard login page. This allows applications to authenticate quick-login users via Http Basic headers in addition to the existing form-based flow.

sa-token-plugin/sa-token-quick-login/src/main/java/cn/dev33/satoken/quick · high confidence

Sa-Token Spring AOP plugin now supports custom annotation authentication

The Sa-Token Spring AOP plugin has been refactored to allow users to register custom annotation handlers for authentication. By implementing the \SaAnnotationHandlerInterface\ and registering it as a Spring bean, developers can extend the AOP pointcut to intercept and validate methods annotated with their own custom annotations, in addition to the built-in checks like \@SaCheckLogin\. This change includes a new \SaAopPointcutAdvisorBeanRegister\ that dynamically builds AspectJ expressions based on both framework-internal and user-provided handlers, ensuring custom checks are woven into the application context automatically.

sa-token-plugin/sa-token-spring-aop · high confidence

Sa-Token core configuration and Same-Token inter-service authentication

The core module introduces a centralized configuration model (SaTokenConfig) that exposes granular controls for session management, including multi-device login strategies (replacedLoginExitMode, maxLoginCount, overflowLogoutMode), session creation timing (rightNowCreateTokenSession), and token persistence (autoRenew, isLastingCookie). It also adds a dedicated SaCookieConfig to manage browser cookie security attributes (secure, httpOnly, sameSite) and custom attributes. Additionally, the module adds the Same-Token feature (SaSameUtil/SaSameTemplate), providing a mechanism for authenticating calls between same-origin microservices or gateways via a shared, refreshable token header.

sa-token-core/src/main/java/cn/dev33/satoken/config · high confidence

Sa-Token documentation site launches dedicated blog with community articles and enhanced SEO

The documentation site now includes a dedicated blog section at /blog, featuring a curated sidebar of featured posts and essays, a list of community articles from platforms like WeChat and CSDN, and static HTML pages for individual articles. This section is styled with a distinct blue theme and includes SEO enhancements such as JSON-LD structured data, Open Graph tags, and semantic URL structures. The blog also supports code syntax highlighting via Prism.js and provides copy-to-clipboard functionality for code blocks.

sa-token-doc-new/public/blog · high confidence

Sa-Token introduces a modular firewall hook system for request validation

The firewall strategy now uses a pluggable hook mechanism (SaFirewallCheckHook) to validate incoming requests, allowing users to configure specific security checks via dedicated hook implementations. This update adds built-in hooks for validating HTTP methods, host headers, request headers, and request parameters, as well as checking request paths against blacklists, whitelists, directory traversal patterns, banned characters, and dangerous characters. The system also provides a method to remove specific hook types, giving developers fine-grained control over which validation rules are active.

sa-token-core/src/main/java/cn/dev33/satoken/strategy/hooks · high confidence

Sa-Token v1.46.0 release with multi-language documentation and Apache 2.0 license

The project has been updated to version 1.46.0, introducing a comprehensive set of multi-language README files (English, Japanese, Korean, Russian, and Traditional Chinese) to support global users. The repository now includes an Apache License 2.0 file, standardizing the licensing terms for the work. Additionally, a \.gitignore\ file has been added to exclude local development artifacts, IDE configurations, and build outputs from version control.

(repo-wide) · high confidence

Solon plugin adds automatic bean injection and modularized integration

The Solon plugin now supports automatic injection of Sa-Token components, allowing users to provide custom implementations (such as SaTokenDao, StpInterface, and SaTokenContext) via Solon's dependency injection without manual wiring. The plugin has been restructured into modular bean registration and injection classes for core authentication, SSO, OAuth2, API Key, and signature features, ensuring a consistent integration experience with the Spring Boot version.

sa-token-starter/sa-token-solon-plugin · high confidence

Security

Jackson JSON plugin secured with type whitelist and improved Map deserialization

The Jackson JSON plugin now enforces a global type whitelist (SaJsonStrategy) to prevent polymorphic deserialization vulnerabilities, restricting allowed types to those explicitly registered. Additionally, deserialization of simple JSON strings into Map objects is fixed by using a separate ObjectMapper instance that does not enforce type information, resolving previous failures when parsing plain JSON without @class metadata.

sa-token-plugin/sa-token-jackson/src/main/java/cn/dev33/satoken/json · high confidence

Behavioural changes

Adds Spring Boot 3-compatible exception handling and utility classes

This change introduces new Java classes to support the Spring Boot 3 environment in the demo application. It adds a global exception handler (GlobalException) that intercepts Sa-Token specific exceptions (such as NotLoginException, NotRoleException, NotPermissionException, and DisableServiceException) and returns structured JSON responses. It also includes a custom error controller (NotFoundHandle) to manage 404 errors by returning a standardized JSON result, a utility class (AjaxJson) for constructing consistent API response payloads with status codes and messages, and a simple timing utility (Ttime) for measuring execution duration.

sa-token-demo/sa-token-demo-springboot3-redis/src/main/java/com/pj/current, sa-token-demo/sa-token-demo-springboot3-redis/src/main/java/com/pj/util · high confidence

Annotation handlers refactored to use a common interface

The annotation processing logic in sa-token-core has been refactored to use a new \SaAnnotationHandlerInterface\ instead of the previous abstract class. All specific handlers (such as \SaCheckLoginHandler\, \SaCheckRoleHandler\, \SaCheckPermissionHandler\, \SaCheckOrHandler\, etc.) now implement this interface, standardizing how annotation checks are executed. This change also updates the copyright domain from sa-token.cc to sa-token.com.

sa-token-core/src/main/java/cn/dev33/satoken/annotation/handler · high confidence

Centralized SEO domain verification files in public/file-ver

SEO domain verification files for Google, Baidu, Bing, Sogou, 360, and IndexNow are now centralized in the \public/file-ver\ directory. These files are automatically copied to the distribution root during the build process, ensuring that search engine verification remains consistent and is no longer manually managed in the deployment root.

sa-token-doc-new/public/file-ver · high confidence

Configurable quick-login authentication with path filtering

The Sa-Quick-Login plugin now exposes a configuration model (SaQuickConfig) that allows users to customize the quick-login behavior. Users can enable or disable global login checks, set custom credentials (or enable auto-generation), and define specific URL patterns to include or exclude from interception. Additionally, the default login handling logic is exposed as a configurable function, allowing developers to override the default username/password comparison logic.

sa-token-plugin/sa-token-quick-login/src/main/java/cn/dev33/satoken/quick/config · high confidence

Configures Sa-Token authentication with global security headers and custom permissions

The Spring Boot Redis demo now explicitly configures Sa-Token authentication via a new \SaTokenConfigure\ class that registers a global \SaServletFilter\ and an \SaInterceptor\. The global filter applies security response headers (X-Frame-Options, X-XSS-Protection, X-Content-Type-Options) to all requests and defines error handling, while the interceptor enables annotation-based permission checks across all paths. Additionally, a new \StpInterfaceImpl\ component provides the custom permission and role lists (e.g., 'admin', 'user-add') used by the authentication system.

sa-token-demo/sa-token-demo-springboot-redis/src/main/java/com/pj/satoken · high confidence

Core context models decoupled from Servlet API

The core context model classes (SaCookie, SaRequest, SaResponse, SaStorage) have been refactored into framework-agnostic interfaces and models, removing direct dependencies on the Servlet API. This allows Sa-Token to operate in non-Servlet environments (such as WebFlux or other reactive frameworks) by providing a unified abstraction layer for request, response, and storage operations, while maintaining backward compatibility through existing implementations.

sa-token-core/src/main/java/cn/dev33/satoken/context/model · high confidence

Default session storage now includes automatic expiration cleanup

The default implementation of the SaTokenDao interface (SaTokenDaoDefaultImpl) now initializes a background thread that periodically cleans up expired session data. Previously, the in-memory ConcurrentHashMap-based storage did not automatically remove stale entries; users relying on the default storage will now benefit from automatic memory management without needing to manually purge expired sessions.

sa-token-core/src/main/java/cn/dev33/satoken/dao · high confidence

Demo model entities now implement SaJsonType for serialization

The demo application's entity classes (SysUser, SysRole) now implement the SaJsonType interface. This change ensures that these models are handled correctly by the framework's JSON serialization and deserialization logic, which is necessary for features like session storage to work properly with these entity types.

sa-token-demo/sa-token-demo-test/src/main/java/com/pj/model · high confidence

Documentation site rebuilt on VitePress with enhanced SEO and blog features

The documentation site has been migrated from Docsify to VitePress, introducing a new build system and configuration in \.vitepress/\. This update significantly improves SEO by automatically generating meta descriptions, keywords, and JSON-LD structured data for pages, while also adding a dedicated script to submit URLs to Bing via IndexNow. A new blog category index generator creates dedicated pages for blog sections and updates the sitemap accordingly. The site now uses a custom Shiki syntax highlighting theme to match the previous look, and legacy entry points like \/doc.html\ are handled with JavaScript redirects to the new structure. Additionally, reserved plugins from the old site (such as progress bars and chapter locks) are ported but disabled by default.

sa-token-doc-new/.vitepress · high confidence

Fastjson plugin now supports install/uninstall hooks and customized session handling

The Fastjson integration has been refactored to support plugin lifecycle management via install/uninstall hooks. The new SaTokenPluginForFastjson implementation automatically registers the Fastjson JSON template and configures the session strategy to use SaSessionForFastjsonCustomized. This customized session class overrides the getModel method to leverage Fastjson's JSONObject for more efficient type conversion when retrieving session data, improving compatibility and performance for applications using Fastjson.

sa-token-plugin/sa-token-fastjson/src/main/java · high confidence

Fastjson2 plugin now uses a custom session implementation

The Fastjson2 integration has been refactored to use a dedicated session class (SaSessionForFastjson2Customized) instead of the default. This change ensures that session data retrieval (getModel) leverages Fastjson2's native parsing for type conversion, providing more consistent serialization behavior for users switching to the Fastjson2 JSON library.

sa-token-plugin/sa-token-fastjson2/src/main/java · high confidence

Granular control over login replacement and logout behavior

The login and logout parameter classes now expose detailed configuration options for managing concurrent sessions and session termination. For login, you can specify how to handle duplicate logins via \replacedLoginExitMode\ (choosing whether the old or new device is disconnected), define the scope of replacement with \replacedRange\, and control overflow behavior using \overflowLogoutMode\. Additionally, a new \cookie\ configuration object allows per-login cookie settings, and \rightNowCreateTokenSession\ lets you defer Token-Session creation until first use. For logout, the new \SaLogoutParameter\ enables precise targeting by device type or ID, defines the logout scope (token vs. account), and offers options to preserve frozen operations or retain the Token-Session after logout.

sa-token-core/src/main/java/cn/dev33/satoken/stp/parameter · high confidence

Introduction of SaManager as the central global component registry

The \SaManager\ class has been introduced in the core module to serve as the single point for managing and accessing all global Sa-Token components, including configuration (\SaTokenConfig\), persistence (\SaTokenDao\), context (\SaTokenContext\), JSON serialization (\SaJsonTemplate\), and temporary token handling (\SaTempTemplate\). This change centralizes the lifecycle management of these components, providing static getters and setters that handle initialization and registration with the event center, effectively replacing scattered global state access patterns with a unified manager interface.

sa-token-core/src/main/java/cn/dev33/satoken · high confidence

Introduction of account ban module and login parameter refactoring

The core authentication module now includes a new account ban feature, introducing the \SaDisableWrapperInfo\ model to track ban status, duration, and level, and extending the \StpInterface\ with an \isDisabled\ method for custom ban logic. Additionally, the login configuration API has been refactored: the legacy \SaLoginModel\ and \SaLoginConfig\ classes are now deprecated in favor of the new \SaLoginParameter\ class, which serves as the standard parameter object for login operations.

sa-token-core/src/main/java/cn/dev33/satoken/stp · high confidence

Localizes frontend resources and switches Redis integration method

The OAuth2 server demo now bundles frontend assets (such as jQuery) locally within the static directory instead of relying on external CDNs, ensuring the demo works offline and reduces external dependencies. Additionally, the commit indicates a change in how the server integrates with Redis, though the specific implementation details of this backend change are not visible in the provided static file diff.

sa-token-demo/sa-token-demo-oauth2/sa-token-demo-oauth2-server/src/main/resources/static · medium confidence

New JSON abstraction layer with safe multi-type serialization

The core module now introduces a dedicated JSON conversion interface (SaJsonTemplate) and a default implementation that throws an exception if no specific JSON library is configured, ensuring developers explicitly provide a serializer. To address security risks associated with Jackson's DefaultTyping, the framework adds a SaJsonType marker interface and a global type whitelist (SaJsonStrategy), allowing only explicitly marked classes to participate in multi-type polymorphic serialization and deserialization, thereby preventing potential RCE vulnerabilities when storing objects in sessions or Redis.

sa-token-core/src/main/java/cn/dev33/satoken/json · high confidence

New SSO client demo with centralized exception handling

The SSO client demo now includes a GlobalExceptionHandler to standardize error responses across the application. The SsoClientController has been updated to expose specific endpoints for single-application logout (/sso/logoutByAlone) and user info retrieval (/sso/myInfo), which utilizes the new message push mechanism to fetch data from the SSO server.

sa-token-demo/sa-token-demo-sso/sa-token-demo-sso2-client/src/main/java/com/pj/sso · high confidence

New VitePress documentation theme components

The documentation site has been rebuilt using VitePress, introducing a new set of theme components in the \.vitepress/theme/components\ directory. This includes \SiteHeader\ for the top navigation bar (with version selection, search, and theme switching), \SiteSidebar\ for the left-hand navigation, \SiteOutline\ for the right-hand table of contents, \SiteFooter\ for page footers and edit links, \DocPrevNext\ for previous/next article navigation, and \AdAside\/\AdBanner\ for displaying commercial version advertisements with user-dismissal logic.

sa-token-doc-new/.vitepress/theme/components · high confidence

New VitePress documentation theme with improved navigation and layout

The documentation site has been rebuilt using VitePress, introducing a custom layout that features a collapsible sidebar, a right-side outline, and a new 'Previous/Next' navigation bar at the bottom of each document page. The theme includes smooth scrolling for anchor links, image zooming capabilities, and specific styling for custom blocks and tabs to align with the previous site's appearance. It also handles legacy scripts for features like translation and version selection while ensuring static pages like the homepage and blog trigger full page loads instead of SPA navigation.

sa-token-doc-new/.vitepress/theme · high confidence

New secure utility classes and deprecation of legacy encryption methods

The \sa-token-core\ secure package now includes dedicated utility classes for Base32 (\SaBase32Util\) and Base64 (\SaBase64Util\) encoding, alongside an expanded \SaSecureUtil\ that adds SHA-384 and SHA-512 hashing capabilities. Additionally, the BCrypt implementation has been marked as deprecated, signaling that users should migrate to the newer, supported encryption standards provided in this update.

sa-token-core/src/main/java/cn/dev33/satoken/secure · high confidence

OAuth2 demo server now includes local login and authorization confirmation pages

The OAuth2 demo server now provides its own local frontend templates for the login and authorization confirmation flows. Users will see a dedicated login page (with test credentials sa/123456) and a confirmation page that displays the client ID and requested scopes, allowing them to explicitly approve or deny authorization requests. This change localizes the frontend resources for the demo, replacing any previous external or missing UI assets.

sa-token-demo/sa-token-demo-oauth2/sa-token-demo-oauth2-server/src/main/resources/templates · high confidence

OAuth2 server demo adds CORS support and annotation-based authentication

The OAuth2 server demo now includes a global exception handler to return standardized error responses and a configuration class that enables annotation-based authentication via a Sa-Token interceptor. Additionally, the configuration sets up a global servlet filter to handle Cross-Origin Resource Sharing (CORS) by allowing all origins, methods, and headers, ensuring the demo server can be accessed from different domains during testing.

sa-token-demo/sa-token-demo-oauth2/sa-token-demo-oauth2-server/src/main/java/com/pj/satoken · high confidence

OAuth2 server demo now uses in-memory client mock data

The OAuth2 server demo has replaced its previous data loading mechanism with a new in-memory mock implementation (SaClientMockDao). This change pre-configures three sample OAuth2 clients (IDs 1001, 1002, 1003) with specific scopes (openid, unionid, etc.) and grant types directly in the application code, simplifying the setup for demonstration purposes by removing the need for external database or file-based client configuration.

sa-token-demo/sa-token-demo-oauth2/sa-token-demo-oauth2-server/src/main/java/com/pj/mock · high confidence

OAuth2 server demo now uses separated resource and authentication controllers

The OAuth2 server demo has been restructured to clearly separate the authentication server logic from the resource server logic. A new SaOAuth2ResourcesController provides a dedicated endpoint for resource access (e.g., /oauth2/userinfo), while the SaOAuth2ServerController handles all OAuth2 protocol requests (e.g., /oauth2/\*). Additionally, a new SaOAuth2DataLoaderImpl component is introduced to handle client data loading via a mock DAO, replacing previous inline or default data loading mechanisms.

sa-token-demo/sa-token-demo-oauth2/sa-token-demo-oauth2-server/src/main/java/com/pj/oauth2 · high confidence

Reactor starter for Spring Boot 3 adopts Spring Boot 3 auto-configuration

The Reactor starter now registers its context via the Spring Boot 3 auto-configuration mechanism (META-INF/spring/org.springframework.boot.autoconfigure.AutoConfiguration.imports), ensuring SaTokenContextRegister is automatically wired in Spring Boot 3 applications. A placeholder class and corresponding tests were added to support this setup.

sa-token-starter/sa-token-reactor-spring-boot3-starter · high confidence

Rebuilt Reactor integration with new context handling and filters

The \sa-token-reactor-spring-boot-starter\ has been completely refactored to support modern Spring WebFlux and Spring Boot 3.x environments. This change introduces a new context management system using \SaReactorHolder\ and \SaReactorSyncHolder\ to bridge Reactor's asynchronous context with Sa-Token's ThreadLocal-based storage, ensuring request data is correctly propagated through the reactive chain. The starter now registers dedicated WebFilters for context initialization (\SaTokenContextFilterForReactor\), CORS handling (\SaTokenCorsFilterForReactor\), and firewall checks (\SaFirewallCheckFilterForReactor\), replacing the previous monolithic filter approach. Additionally, a \SpringBootVersionCompatibilityChecker\ is now included to prevent startup in incompatible Spring Boot versions, and the \SaRequest\ implementation has been updated to correctly handle multiple cookies with the same name.

sa-token-starter/sa-token-reactor-spring-boot-starter · high confidence

Redis persistence layer refactored with JDK serialization and TTL update fixes

The \sa-token-redis-template-jdk-serializer\ plugin now provides a dedicated \SaTokenDaoForRedisTemplateUseJdkSerializer\ implementation that uses Java's native JDK serialization for object storage, allowing users to persist complex objects without custom converters. The core \SaTokenDaoForRedisTemplate\ has been refactored to use the Redis \SET KEEPTTL\ command for updates, which preserves the original time-to-live when modifying values and eliminates TTL calculation drift. Additionally, the \searchData\ method now uses the \SCAN\ command instead of \KEYS\, ensuring compatibility with lower versions of Spring Data Redis and preventing potential performance issues during key searches.

sa-token-plugin/sa-token-redis-template-jdk-serializer/src/main/java · high confidence

Redis persistence layer refactored with SCAN support and customizable key prefixes

The Sa-Token Redis persistence implementation has been updated to improve compatibility and flexibility. The data search operation now uses the SCAN command instead of KEYS, preventing potential blocking issues on large datasets and ensuring compatibility with older Spring Data Redis versions. Additionally, the key wrapping mechanism is now exposed via a protected \wrapKey\ method, allowing users to easily override it to add custom key prefixes. The update operation also leverages Redis's KEEPTTL feature to preserve existing time-to-live values when modifying data.

sa-token-plugin/sa-token-redis-template/src/main/java · high confidence

Redis template plugins now use Spring Boot 3 auto-configuration

The \sa-token-redis-template\ and \sa-token-redis-template-jdk-serializer\ plugins have been updated to support Spring Boot 3's new auto-configuration mechanism. Instead of relying on the legacy \spring.factories\ file, these modules now register their \SaTokenDao\ implementations (\SaTokenDaoForRedisTemplate\ and \SaTokenDaoForRedisTemplateUseJdkSerializer\) via the standard \META-INF/spring/org.springframework.boot.autoconfigure.AutoConfiguration.imports\ file. This change ensures compatibility with Spring Boot 3 applications while maintaining the same functional behavior for Redis-backed session storage.

sa-token-plugin/sa-token-redis-template-jdk-serializer/src/main/resources, sa-token-plugin/sa-token-redis-template/src/main/resources · high confidence

Refactored Solon SSO server demo with new configuration and controller structure

The Solon-based SSO server demo has been restructured to improve code organization and fix a bug where SaSsoClientInfo could not be retrieved. The application entry point is now SaSsoServerApp, and configuration is split into SaConfig (for Redis DAO setup) and SaTokenConfigure (for CORS handling). New controllers include SsoServerController for core SSO logic (login, redirect, userinfo), HomeController for the platform center UI, H5Controller for frontend separation support, and GlobalExceptionFilter for error handling.

sa-token-demo/sa-token-demo-sso-for-solon/sa-token-demo-sso-server-solon/src/main/java · high confidence

Refactored Spring Boot auto-configuration with modular bean registration and injection

The Spring Boot integration for Sa-Token has been restructured to separate bean registration from injection, resolving potential circular dependency issues. The \SaBeanRegister\ class now handles the creation of core configuration beans (such as \SaTokenConfig\ and \ApplicationContextPathLoading\), while \SaBeanInject\ manages the injection of runtime components like loggers, DAOs, and listeners. This modular approach extends to specific feature modules—API Key, OAuth2, SSO, and API Signature—each with dedicated \\*BeanRegister\ and \\*BeanInject\ classes that are conditionally loaded based on classpath presence. Additionally, the framework now includes an \ApplicationContextPathLoading\ runner to automatically normalize and apply server context and servlet paths to the route prefix, and provides utility holders for Spring's \PathMatcher\ and \PathPatternParser\ to ensure consistent routing behavior across different Spring Boot versions.

sa-token-starter/sa-token-spring-boot-webmvc-reactor-v2v3v4-common · high confidence

Refactored Spring Boot demo with new security headers and utility classes

The Spring Boot demo application has been restructured to include a centralized configuration class (SaTokenConfigure) that registers the Sa-Token interceptor and a global servlet filter. This filter now enforces security response headers (X-Frame-Options, X-XSS-Protection, X-Content-Type-Options) on all requests via a BeforeAuth hook, ensuring these protections are applied regardless of include/exclude lists. Additionally, the demo introduces a custom StpInterface implementation to define mock roles and permissions, and adds utility classes (AjaxJson for standardized API responses and Ttime for performance testing) to support the demonstration.

sa-token-demo/sa-token-demo-springboot/src/main/java/com/pj/satoken · high confidence

Refactored context handling with new SaHolder API and ThreadLocal implementation

The core context package has been restructured to decouple from specific Servlet APIs and introduce a unified access point via the new SaHolder class, which provides static methods to retrieve SaRequest, SaResponse, SaStorage, and the global SaApplication. The underlying context management now relies on a new SaTokenContext interface with a dedicated ThreadLocal-based implementation (SaTokenContextForThreadLocal) that stores request data in a ThreadLocal box, replacing previous mechanisms. Additionally, a read-only context interface (SaTokenContextForReadOnly) and a default implementation that throws exceptions if used incorrectly have been added to enforce proper initialization.

sa-token-core/src/main/java/cn/dev33/satoken/context · high confidence

Refactored exception hierarchy and expanded error scenarios

The exception classes in the core module have been reorganized to improve clarity and error handling. The base exception is now SaTokenException, which introduces a structured error code mechanism via a 'code' field and utility methods like notTrue and notEmpty. Several specific exceptions have been added or updated: NotLoginException now includes new scenario codes for frozen tokens (-6) and missing token prefixes (-7); InvalidContextException is deprecated in favor of SaTokenContextException; and new exceptions cover specific failure modes such as ApiDisabledException, DisableServiceException, FirewallCheckException, NotHttpBasicAuthException, NotHttpDigestAuthException, NotImplException, NotSafeException, NotWebContextException, RequestPathInvalidException, SaJsonConvertException, SaTokenPluginException, SameTokenInvalidException, StopMatchException, and TotpAuthException. This provides more granular error information for developers.

sa-token-core/src/main/java/cn/dev33/satoken/exception · high confidence

SSO client demo now uses centralized exception handling and explicit logout endpoints

The SSO client demo application now includes a global exception handler that returns standardized error responses for uncaught exceptions, improving error visibility for users. Additionally, the client controller exposes distinct logout endpoints: a single-application logout at /sso/logoutByAlone and a single-browser logout at /sso/logout with a singleDeviceIdLogout parameter, allowing users to control the scope of their session termination more precisely.

sa-token-demo/sa-token-demo-sso/sa-token-demo-sso3-client/src/main/java/com/pj/sso · high confidence

SSO server demo restructured with centralized exception handling and platform home page

The SSO server demo now includes a GlobalExceptionHandler to standardize error responses via SaResult, a HomeController that serves a platform-style landing page with links to client systems, and a refactored SsoServerController that centralizes SSO request routing and configures login and userinfo message handling.

sa-token-demo/sa-token-demo-sso/sa-token-demo-sso-server/src/main/java/com/pj/sso · high confidence

Sa-Token Dubbo integration now correctly propagates session context and tokens

The Sa-Token integration for both Dubbo and Dubbo3 has been refactored to fix issues where RPC context was not properly handled or required unnecessarily. The new implementation uses dedicated filters to manage the lifecycle of the SaTokenContext: the Consumer filter now attaches the session token to the RPC call and retrieves the response token, while the Provider filter initializes the context from the incoming RPC context and ensures it is cleared afterwards. This ensures that authentication state is correctly passed across service boundaries without forcing a context requirement on every call.

sa-token-plugin/sa-token-dubbo/src/main, sa-token-plugin/sa-token-dubbo3/src/main · high confidence

Sa-Token SSO module restructured with new configuration and message handling architecture

The sa-token-sso module has been refactored to introduce a centralized configuration model via SaSsoManager, separating server and client settings into distinct SaSsoServerConfig and SaSsoClientConfig classes. This change adds new configuration capabilities such as anonymous client support (allowAnonClient), per-client secret keys, and automatic ticket timeout renewal (autoRenewTimeout). Additionally, the module implements a new message handling framework using SaSsoMessageHolder and specific handlers (e.g., SaSsoMessageCheckTicketHandle, SaSsoMessageSignoutHandle) to manage SSO interactions like ticket validation and single sign-out, replacing previous ad-hoc logic with a structured, extensible strategy.

sa-token-plugin/sa-token-sso · high confidence

Sa-Token Spring Boot Starter refactored with dedicated filters and Spring Boot 3 compatibility check

The Spring Boot starter has been restructured to use dedicated, pluggable Servlet filters for context initialization, CORS handling, and firewall checks, replacing the previous monolithic approach. This change introduces a new \SpringBootVersionCompatibilityChecker\ that blocks application startup if an incompatible Spring Boot version (3.x or 4.x) is detected, directing users to the appropriate starter. Additionally, the \SaInterceptor\ now supports a \beforeAuth\ hook for pre-authorization logic, and the \SaServletFilter\ ensures its \beforeAuth\ runs for all requests regardless of include/exclude lists.

sa-token-starter/sa-token-spring-boot-starter · high confidence

Sa-Token Thymeleaf dialect refactored with new XML configuration and processor classes

The Sa-Token Thymeleaf plugin has been refactored to use a new XML-based dialect configuration file (Sa-Token-Dialect.xml) and dedicated Java classes (SaTokenDialect.java, SaTokenTagProcessor.java) for handling authentication tags. This change introduces a structured way to define attribute processors for login status (sa:login, sa:notLogin), role checks (sa:hasRole, sa:hasRoleAnd, sa:hasRoleOr, sa:notRole, sa:lackRole), and permission checks (sa:hasPermission, sa:hasPermissionAnd, sa:hasPermissionOr, sa:notPermission, sa:lackPermission). The new implementation uses a generic SaTokenTagProcessor that evaluates a boolean function against the attribute value to decide whether to keep or remove the HTML element, replacing the previous inline logic. Tests confirm the correct registration of 13 processors and the proper rendering behavior for all defined tags.

sa-token-plugin/sa-token-thymeleaf · high confidence

Sa-Token core strategy refactoring and security hardening

The core strategy layer has been restructured into dedicated strategy classes (SaAnnotationStrategy, SaFirewallStrategy, SaJsonStrategy, SaStrategy) to replace the previous monolithic approach. This introduces a hook-based firewall mechanism allowing flexible registration and ordering of security checks (e.g., path, header, parameter validation), and adds a global JSON type whitelist to prevent polymorphic deserialization RCE vulnerabilities. Additionally, annotation handling is now extensible via a new handler interface, and the framework supports custom token generation, session creation, and request/response strategies.

sa-token-core/src/main/java/cn/dev33/satoken/strategy · high confidence

Sa-Token listener module refactored into event-driven architecture

The listener subsystem in sa-token-core has been restructured from a direct callback model to a publish-subscribe event system. This introduces the SaTokenEventCenter as the central dispatcher for security events (login, logout, kickout, disable, etc.) and defines the SaTokenListener interface for custom event handling. A built-in SaTokenListenerForLog implementation now provides standardized, colored console logging for all authentication lifecycle events, while SaTokenListenerForSimple offers a convenient base class for developers to implement only the specific events they need.

sa-token-core/src/main/java/cn/dev33/satoken/listener · high confidence

SaSession model expanded with terminal metadata and new session utilities

The SaSession class now includes fields for session type, login type, login ID, and associated token, providing richer context for session management. A new SaTerminalInfo model tracks detailed login device information, including device type, unique device ID, and custom extra data. Additionally, a SaSessionCustomUtil class has been introduced to simplify the creation, retrieval, and deletion of custom sessions by ID.

sa-token-core/src/main/java/cn/dev33/satoken/session · high confidence

SaToken Redisson DAO now supports custom codecs and atomic TTL-preserving updates

The SaToken Redisson persistence implementation has been refactored to allow specifying a custom Redisson Codec (defaulting to StringCodec) to isolate session data serialization from the application's global Redis configuration. Additionally, the update method now uses the Redis SET KEEPTTL command (available in Redis 6.0+) to atomically modify values while preserving the original expiration time, improving data consistency for existing sessions.

sa-token-redisson · high confidence

Servlet request, response, and storage models now use pluggable creation strategies

The sa-token-servlet module now delegates the creation of SaRequest, SaResponse, and SaStorage implementations to a configurable strategy (SaStrategy). This allows the framework to instantiate the correct Servlet-specific wrappers (SaRequestForServlet, SaResponseForServlet, SaStorageForServlet) dynamically, decoupling the core context logic from the Servlet API. The change also introduces dedicated error codes for forward and redirect failures, and adds a utility for writing results to the response stream with sensible default content types.

sa-token-starter/sa-token-servlet · high confidence

Solon SSO Client demo updated to SSO mode 2

The Solon-based SSO client demo has been refactored to implement SSO mode 2, introducing a new client application structure with dedicated configuration, controllers, and utilities for handling single sign-on flows. This includes a new main application entry point, a configuration class for Redis-based token storage, and controllers for managing login, logout, and user info retrieval via SSO tickets. The demo now supports both traditional web and front-end/back-end separated architectures, with specific controllers for H5-style SSO interactions and global exception handling. Configuration is managed through app.yml, specifying the SSO server URL, client identifier, and Redis connection details.

sa-token-demo/sa-token-demo-sso-for-solon/sa-token-demo-sso2-client-solon · high confidence

Spring Boot 3 auto-configuration migration for quick-login plugin

The quick-login plugin now registers its auto-configuration class, \cn.dev33.satoken.quick.SaQuickInject\, using the Spring Boot 3 standard \META-INF/spring/org.springframework.boot.autoconfigure.AutoConfiguration.imports\ file, replacing the legacy \spring.factories\ mechanism. This change ensures the plugin correctly initializes within Spring Boot 3 applications.

sa-token-plugin/sa-token-quick-login/src/main/resources · high confidence

Spring Boot 3 compatible Sa-Token configuration and security headers

The demo application now includes a Sa-Token configuration class tailored for Spring Boot 3, registering a global servlet filter that enforces security response headers (X-Frame-Options, X-XSS-Protection, X-Content-Type-Options) on all requests via a BeforeAuth hook. Additionally, a custom permission interface implementation is provided to simulate role and permission lookups for the demo.

sa-token-demo/sa-token-demo-springboot3-redis/src/main/java/com/pj/satoken · high confidence

Standardized error code definitions in SaErrorCode interface

The \sa-token-core\ module now includes a centralized \SaErrorCode\ interface that defines specific integer codes for various exception scenarios, such as authentication failures (e.g., token expired, kicked offline), session errors (e.g., invalid session ID), and cryptographic issues (e.g., SHA-256/512 errors). This change replaces or supplements previous ad-hoc error handling with a structured, consistent set of status codes for developers to identify and handle specific error conditions programmatically.

sa-token-core/src/main/java/cn/dev33/satoken/error · high confidence

Updated Solon SSO client demo with new configuration and controller structure

The Solon SSO client demo has been refactored to provide a clearer integration example. A new \SaConfig\ class handles Redis DAO initialization, while \SaSso3ClientApp\ serves as the entry point. The \SsoClientController\ now manages SSO endpoints (login, logout, ticket validation) and includes a dedicated \H5Controller\ for handling front-end separation scenarios, such as checking login status and building authentication URLs. Additionally, \SaTokenConfigure\ implements CORS handling, and \GlobalExceptionFilter\ provides centralized error response rendering. The \app.yml\ configuration has been updated to define the SSO client identity, server URL, and Redis connection details for this specific demo instance.

sa-token-demo/sa-token-demo-sso-for-solon/sa-token-demo-sso3-client-solon · high confidence

sa-token-jwt module refactored into Util + Template architecture with new error codes and validation

The \sa-token-jwt\ module has been restructured into a \Util\ + \Template\ pattern, introducing \SaJwtTemplate\ for core JWT operations and \SaJwtUtil\ as a static facade. This change adds strict validation to prevent \extraData\ from overwriting JWT reserved fields (like \loginType\, \loginId\, \eff\), defines specific error codes in \SaJwtErrorCode\ (e.g., \CODE\_30207\ for reserved field conflicts), and improves exception handling by catching \JSONException\ during parsing to fallback on non-expired status when the \eff\ field is missing. The refactoring also standardizes the domain from \sa-token.cc\ to \sa-token.com\ in license headers.

sa-token-plugin/sa-token-jwt/src/main · high confidence

Fixes

Add regression demos for JSON deserialization security fixes

Added two demo applications (\sa-token-demo-json-typing-security\ for Spring Boot/Jackson and \sa-token-demo-json-typing-security-for-solon\ for Solon/Snack4) that verify the \SaJsonStrategy\ global type whitelist. These demos simulate malicious JSON payloads with \@type\/\@class\ fields in Redis to confirm that unauthorized types are blocked with a \SaJsonConvertException\, preventing remote code execution via polymorphic deserialization.

sa-token-demo/sa-token-demo-json-typing-security, sa-token-demo/sa-token-demo-json-typing-security-for-solon · high confidence

Test coverage

Add WebFlux demo application with reactive authentication endpoints; Added OAuth2 token management and annotation-based authorization test endpoints; Added Spring Boot 2 integration tests for Sa-Token; Added Spring Boot 3 demo controllers for authentication and stress testing; Added Spring Boot Redis demo test controllers; Added Spring Boot demo controllers for authentication and authorization testing; Added demo controllers for authentication, login, and stress testing; Added integration tests for JBoot authentication and authorization; Added integration tests for OAuth2 and SSO modules; Added integration tests for Sa-Token gRPC context propagation; Added integration tests for Sa-Token on the LoveQQ framework; Added integration tests for Sa-Token with Dubbo 2.x; Added integration tests for Sa-Token with Dubbo 3; Added integration tests for Sa-Token with Spring Boot 2 WebFlux; Added integration tests for Solon authentication and bean injection; Added integration tests for Spring Boot 2 bean injection; Added integration tests for Spring Boot 3 and 4 WebFlux differences; Added integration tests for Spring Boot 3 compatibility; Added placeholder classes and auto-configuration tests for Spring Boot 3 and 4 starters; Added test for sa-token-redis-jackson aggregation package; Added test infrastructure for SaHttpTemplate implementations; Added test support modules for JSON and Redis DAO validation; Added tests for Sa-Token Redis plugin injection and DAO implementations; Added tests for SaToken Redis Template fallback behavior; Added tests for SaTokenDaoForRedisTemplate SCAN deduplication and key wrapping; Added unit and integration tests for the quick-login plugin; Added unit tests for Dubbo RPC context and filter behavior; Added unit tests for Dubbo3 plugin filters and context models; Added unit tests for Fastjson, Fastjson2, and Snack3 JSON plugin integrations; Added unit tests for Hutool Timed Cache DAO and plugin; Added unit tests for Jackson JSON plugin behavior and internal error handling; Added unit tests for SaTokenDaoForRedisTemplate and SaTokenDaoForRedisTemplateUseJdkSerializer; Added unit tests for the OAuth2 plugin core components; Added unit tests for the Sa-Token API Key plugin; Added unit tests for the gRPC context and interceptor plugin; Added unit tests for the sa-token-sign plugin; Comprehensive unit test coverage for sa-token-core; Solon-based Sa-Token demo application with authentication and stress testing.

Dependencies

Sa-Token 1.46.0 release with Spring Boot 4 support and demo restructuring

Sa-Token version 1.46.0 is now available, introducing official support for Spring Boot 4 through new starters like \sa-token-spring-boot4-starter\ and \sa-token-reactor-spring-boot4-starter\. The release also includes a comprehensive restructuring of the demo project, adding new examples for Spring Boot 4, Redisson, and various integration scenarios, while updating the core parent POM to use Maven Central Portal for publishing and standardizing Java compilation to release 8.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 26 → 32 (+5.9)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 59 → 38 (-21.1)
  • Architecture 79 → 82 (+3.0)
  • Maturity 55 → 62 (+7.6)
  • Readiness 14 → 16 (+1.8)
  • Security 25 → 56 (+30.7)
  • Accessibility 31 → 41 (+10.0)

Resolved (92)

  • Coverage not included — suite not readable by the collector
  • Critical CVE: [GHSA redacted] (sa-token-demo/sa-token-demo-sso/sa-token-demo-sso-client-vue2/package-lock.json)
  • Critical CVE: [GHSA redacted] (sa-token-demo/sa-token-demo-sso/sa-token-demo-sso-client-vue2/package-lock.json)
  • Critical CVE: [GHSA redacted] (sa-token-demo/sa-token-demo-sso/sa-token-demo-sso-client-vue2/package-lock.json)
  • Critical CVE: [GHSA redacted] (sa-token-demo/sa-token-demo-sso/sa-token-demo-sso-client-vue2/package-lock.json)
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Duplicated block (10 lines × 3) (sa-token-demo/sa-token-demo-oauth2/sa-token-demo-oauth2-client/src/main/java/com/pj/oauth2/SaOAuthClientController.java)
  • Duplicated block (11 lines × 2) (sa-token-demo/sa-token-demo-oauth2/sa-token-demo-oauth2-client/src/main/java/com/pj/oauth2/SaOAuthClientController.java)
  • Duplicated block (12 lines × 2) (sa-token-demo/sa-token-demo-oauth2/sa-token-demo-oauth2-server/src/main/java/com/pj/mock/SaClientMockDao.java)
  • Duplicated block (13 lines × 2) (sa-token-plugin/sa-token-oauth2/src/main/java/cn/dev33/satoken/oauth2/processor/SaOAuth2ServerProcessor.java)
  • Duplicated block (5 lines × 2) (sa-token-core/src/main/java/cn/dev33/satoken/util/SaFoxUtil.java)
  • Duplicated block (7 lines × 2) (sa-token-core/src/main/java/cn/dev33/satoken/secure/SaSecureUtil.java)
  • Duplicated block (7 lines × 2) (sa-token-demo/sa-token-demo-sso-for-solon/sa-token-demo-sso-server-solon/src/main/java/com/pj/SaSsoServerApp.java)
  • Duplicated block (7 lines × 2) (sa-token-demo/sa-token-demo-sso/sa-token-demo-sso3-client-nosdk/src/main/java/com/pj/SaSsoClientNoSdkApplication.java)
  • Duplicated block (7 lines × 7) (sa-token-demo/sa-token-demo-sso-for-solon/sa-token-demo-sso1-client-solon/src/main/java/com/pj/SaSso1ClientApp.java)
  • Further orphaned files (smaller)
  • Further sole-owners (lower concentration)
  • High CVE: [GHSA redacted] (sa-token-demo/sa-token-demo-sso/sa-token-demo-sso-client-vue2/package-lock.json)
  • High CVE: [GHSA redacted] (sa-token-demo/sa-token-demo-sso/sa-token-demo-sso-client-vue2/package-lock.json)
  • High CVE: [GHSA redacted] (sa-token-demo/sa-token-demo-sso/sa-token-demo-sso-client-vue2/package-lock.json)
  • …and 72 more

New (536)

  • Critical CVE: [GHSA redacted] (sa-token-demo/sa-token-demo-sso/sa-token-demo-sso-client-vue2/package-lock.json)
  • Critical CVE: [GHSA redacted] (sa-token-demo/sa-token-demo-sso/sa-token-demo-sso-client-vue2/package-lock.json)
  • Critical CVE: [GHSA redacted] (sa-token-demo/sa-token-demo-sso/sa-token-demo-sso-client-vue2/package-lock.json)
  • Critical CVE: [GHSA redacted] (sa-token-demo/sa-token-demo-sso/sa-token-demo-sso-client-vue2/package-lock.json)
  • Dependency hygiene PARTLY measured — Maven/Gradle declarations read, no dependency graph resolved
  • Duplicated block (10 lines × 5) (sa-token-demo/sa-token-demo-oauth2/sa-token-demo-oauth2-client/src/main/java/com/pj/oauth2/SaOAuthClientController.java)
  • Duplicated block (11 lines × 2) (sa-token-demo/sa-token-demo-case/src/main/java/com/pj/satoken/custom_annotation/handler/CheckAccountHandler.java)
  • Duplicated block (11 lines × 2) (sa-token-demo/sa-token-demo-sso-for-solon/sa-token-demo-sso1-client-solon/src/main/java/com/pj/sso/SsoClientController.java)
  • Duplicated block (11–12 lines × 2) (sa-token-demo/sa-token-demo-oauth2/sa-token-demo-oauth2-server/src/main/java/com/pj/mock/SaClientMockDao.java)
  • Duplicated block (12 lines × 2) (sa-token-demo/sa-token-demo-dubbo/sa-token-demo-dubbo-consumer/src/main/java/com/pj/controller/TestController.java)
  • Duplicated block (12 lines × 6) (sa-token-demo/sa-token-demo-sso-for-solon/sa-token-demo-sso2-client-solon/src/main/java/com/pj/sso/SsoClientController.java)
  • Duplicated block (13 lines × 2) (sa-token-demo/sa-token-demo-dubbo/sa-token-demo-dubbo-consumer/src/main/java/com/pj/controller/TestController.java)
  • Duplicated block (14 lines × 2) (sa-token-demo/sa-token-demo-sso/sa-token-demo-sso3-client-nosdk/src/main/java/com/pj/sso/SsoSignUtil.java)
  • Duplicated block (1428 lines × 3) (sa-token-demo/sa-token-demo-case/src/main/java/com/pj/satoken/StpUserUtil.java)
  • Duplicated block (15 lines × 2) (sa-token-demo/sa-token-demo-oauth2/sa-token-demo-oauth2-client/src/main/java/com/pj/oauth2/SaOAuthClientController.java)
  • Duplicated block (15 lines × 9) (sa-token-demo/sa-token-demo-hutool-timed-cache/src/main/java/com/pj/util/AjaxJson.java)
  • Duplicated block (15–16 lines × 4) (sa-token-demo/sa-token-demo-apikey/src/main/java/com/pj/satoken/SaTokenConfigure.java)
  • Duplicated block (16 lines × 2) (sa-token-demo/sa-token-demo-json-typing-security-for-solon/src/main/java/com/pj/poc/Snack4RceGadget.java)
  • Duplicated block (16 lines × 2) (sa-token-demo/sa-token-demo-loveqq-boot/src/main/java/com/pj/satoken/SaTokenConfigure.java)
  • Duplicated block (16 lines × 2) (sa-token-demo/sa-token-demo-oauth2/sa-token-demo-oauth2-client/src/main/java/com/pj/utils/SoMap.java)
  • …and 516 more

Changes since last survey

  • 300 commits — 267 feature/other, 33 fixes

By area

  • sa-token-doc/blog — 32 commits
  • (root) — 29 commits
  • sa-token-core/src — 28 commits
  • sa-token-doc-new/public — 26 commits
  • sa-token-doc-new/.vitepress — 13 commits
  • sa-token-doc-new/docs — 11 commits
  • sa-token-doc/more — 11 commits
  • sa-token-doc/static — 8 commits
  • sa-token-plugin/sa-token-sso — 6 commits
  • sa-token-doc/index.html — 5 commits
  • sa-token-plugin/sa-token-oauth2 — 5 commits
  • sa-token-plugin/sa-token-redis-template-jdk-serializer — 5 commits
  • sa-token-doc/doc.html — 4 commits
  • sa-token-doc/oauth2 — 4 commits
  • sa-token-doc/sso — 4 commits
  • sa-token-testing/sa-token-integration-boot2 — 4 commits
  • sa-token-doc/plugin — 3 commits
  • sa-token-plugin/sa-token-jwt — 3 commits
  • sa-token-starter/sa-token-jfinal-plugin — 3 commits
  • (repo) — 2 commits

Notable commits

  • fix: !359 fix: 修复线程安全问题 - 使用 ConcurrentHashMap 替换非线程安全集合
  • fix: chore(demo): bug-reproduce 归零
  • fix: fix(bom): 补齐 sa-token-caffeine 与 sa-token-loveqq-boot-starter
  • fix: fix(core): isLastingCookie 为 null 时 getCookieTimeout 不再 NPE
  • fix: fix(core): isUrl 支持 IPv6 方括号地址并拒绝裸 IPv6
  • fix: fix(demo-ssm): 适配 v1.42.0+ 上下文机制
  • fix: fix(doc): 修复博客导航链接路径
  • fix: fix(doc): 案例页筛选保留 URL 上的其它参数
  • fix: fix(json): 修复 Jackson DefaultTyping 多态反序列化 RCE,新增 SaJsonStrategy 全局类型白名单
  • fix: fix(jwt): SaJwtTemplate 补捕获 JSONException,eff 字段为空时按未超时兜底
  • fix: fix(oauth2): expiresTime 为 -1 时按永久有效存储 Token
  • fix: fix(oauth2, sso): 修复 redirect 参数绕过 allow-url 校验的安全漏洞
  • fix: fix(oauth2-demo): 拒绝授权时回传 state,并修复 joinParam 漏点
  • fix: fix(plugin): SaAloneRedisInject 静默吞异常改为显式包装抛出
  • fix: fix(plugin): 修复 dubbo、dubbo3、grpc 的 RPC 上下文传递
  • fix: fix(reactor): 修复 Boot3+ WebFlux/Gateway setStatus NoSuchMethodError
  • fix: fix(redis): 修复 jdk-serializer KEEPTTL 泛型编译错误
  • fix: fix(redis-template): searchData 由 KEYS 改为 SCAN,兼容低版本 Spring Data Redis
  • fix: fix(sa-token-json): JSON 反序列化容错优化
  • fix: fix(sa-token-sso): 增强 SSO 重定向 URL 编码/解码健壮性
  • …and 280 more

Architecture

  • Containers 0 added · 0 removed · contexts 12 added · 1 removed · edges 11 added · 0 removed

Added bounded contexts (12)

  • sa-token-alone-redis-by-spring-boot4
  • sa-token-core
  • sa-token-demo-oauth2-client
  • sa-token-integration-sso
  • sa-token-jackson3
  • sa-token-loveqq-boot-starter
  • sa-token-redisson
  • sa-token-redisx
  • sa-token-rest-client
  • sa-token-rest-template
  • sa-token-serializer-features
  • sa-token-snack4

Removed bounded contexts (1)

  • sa-token-temp-jwt-test

Added dependency edges (11)

  • sa-token-alone-redis-by-spring-boot4 → sa-token-core
  • sa-token-demo-oauth2-client → sa-token-core
  • sa-token-integration-sso → sa-token-core
  • sa-token-jackson3 → sa-token-core
  • sa-token-loveqq-boot-starter → sa-token-core
  • sa-token-redisson → sa-token-core
  • sa-token-redisx → sa-token-core
  • sa-token-rest-client → sa-token-core
  • sa-token-rest-template → sa-token-core
  • sa-token-serializer-features → sa-token-core
  • sa-token-snack4 → sa-token-core

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

dromara/Sa-Token was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 25 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 82ac10271f97ae7ac92ea3296a18ac7255fc0452 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-f917f263222d.