gRPC & High Performance APIs · Leçon

Intercepteurs pour la sécurité

Utilisez les intercepteurs gRPC pour centraliser les aspects de sécurité, comme l’authentification et la journalisation, entre les services.

Leçon 3 sur 411 étapes

Intercepteurs pour la sécurité est une leçon gRPC & High Performance APIs gratuite sur CoddyKit. Ceci est la leçon 3 sur 4. Tu peux lire la leçon complète ci-dessous gratuitement — puis la pratiquer en direct dans le navigateur avec un éditeur de code intégré et un tuteur IA 24/7. Elle fait partie du parcours d'apprentissage gRPC & High Performance APIs, et ta progression se synchronise sur le web et l'application CoddyKit. Le cours gRPC & High Performance APIs comprend 4 leçons au total.

Certaines parties de cette leçon n'ont pas encore été traduites et s'affichent en anglais.

Intro to gRPC Interceptors

Interceptors are a powerful feature in gRPC, acting like middleware that can inspect and modify requests and responses. They allow you to centralize common logic that applies to multiple service calls.

Think of them as gates or checkpoints your requests pass through.

Why Use Interceptors?

Interceptors are perfect for handling cross-cutting concerns. Instead of repeating code in every service method, you can manage things like:

  • Authentication
  • Authorization
  • Logging & Monitoring
  • Request validation

This keeps your core service logic clean and focused.

Server Interceptors

A server interceptor sits between the gRPC server and your actual service implementation. It runs logic before your service method is called, allowing you to:

  • Validate incoming requests
  • Check authentication tokens
  • Add request context

Client Interceptors

A client interceptor operates on the client side, executing logic before a request is sent to the server. This is useful for:

  • Adding authentication tokens to outgoing requests
  • Injecting tracing headers
  • Implementing retry logic
  • Modifying request metadata

Server Interceptor Structure

On the server, an interceptor wraps the ServerCallHandler. It receives the ServerCall and Metadata, and can decide to proceed with the call or terminate it. Here's a conceptual view:

class AuthInterceptor implements ServerInterceptor {
  public <ReqT, RespT> ServerCall.Listener<ReqT>
      interceptCall(ServerCall<ReqT, RespT> call,
                    Metadata headers,
                    ServerCallHandler next) {
    // Check headers for auth token
    if (isValid(headers)) {
      return next.startCall(call, headers);
    } else {
      call.close(Status.UNAUTHENTICATED, headers);
      return new ServerCall.Listener<ReqT>() {}; // Block call
    }
  }
}

Client Interceptor Structure

On the client, an interceptor typically implements ClientInterceptor. It allows you to modify the CallOptions or Metadata before the actual RPC call is made.

class ApiKeyInterceptor implements ClientInterceptor {
  public <ReqT, RespT> ClientCall<ReqT, RespT>
      interceptCall(MethodDescriptor<ReqT, RespT> method,
                    CallOptions callOptions,
                    Channel next) {
    return new ForwardingClientCall.SimpleForwardingClientCall<ReqT, RespT>(
        next.newCall(method, callOptions)) {
      @Override
      public void start(ClientCall.Listener<RespT> responseListener,
                        Metadata headers) {
        // Add API key to headers
        headers.put(API_KEY_METADATA_KEY, "my-secret-key");
        super.start(responseListener, headers);
      }
    };
  }
}

Simulated Server Auth Check

Let's simulate a server interceptor checking for an authentication token. If the token is missing or invalid, the 'request' is blocked and the service method isn't called.

public class Main {
    // Simulate an interceptor's core logic
    static void authInterceptor(String metadata, Runnable nextCall) {
        System.out.println("Interceptor: Checking metadata...");
        if (metadata != null && metadata.contains("auth_token:valid")) {
            System.out.println("Interceptor: Authentication successful!");
            nextCall.run(); // Proceed to the actual service method
        } else {
            System.out.println("Interceptor: Authentication failed! Request blocked.");
        }
    }

    // Simulate the actual service method
    static void actualServiceMethod() {
        System.out.println("Service: Request processed successfully!");
    }

    public static void main(String[] args) {
        System.out.println("--- Valid Request ---");
        authInterceptor("auth_token:valid", Main::actualServiceMethod);

        System.out.println("\n--- Invalid Request ---");
        authInterceptor("auth_token:invalid", Main::actualServiceMethod);

        System.out.println("\n--- Missing Token ---");
        authInterceptor(null, Main::actualServiceMethod);
    }
}

Simulated Client API Key

Now, let's simulate a client interceptor that automatically adds an API key to the request metadata before it's sent to the server. This ensures every call includes necessary credentials.

public class Main {
    // Simulate an interceptor that adds metadata
    static String addApiKeyInterceptor(String existingMetadata, String apiKey, String methodName) {
        System.out.println("Client Interceptor: Adding API key for " + methodName);
        return (existingMetadata != null ? existingMetadata + ", " : "") + "api_key:" + apiKey;
    }

    // Simulate sending a request
    static void sendRequest(String metadata, String methodName) {
        System.out.println("Client: Sending request to " + methodName + " with metadata: [" + metadata + "]");
        // In a real gRPC call, this metadata would be sent to the server
    }

    public static void main(String[] args) {
        String initialMetadata = "user_id:123";
        String apiKey = "my_secret_key_123";
        String targetMethod = "/MyService/SayHello";

        // Apply client interceptor
        String finalMetadata = addApiKeyInterceptor(initialMetadata, apiKey, targetMethod);

        // Send the request with enhanced metadata
        sendRequest(finalMetadata, targetMethod);
    }
}

Chaining Interceptors

You can apply multiple interceptors to a gRPC channel or server. They form a chain, executing in the order they are added. This allows for modular and layered processing of requests.

  • The first interceptor processes, then passes to the second.
  • The second processes, then passes to the service (or the next interceptor).
  • The order in which you add interceptors matters!

Interceptor Use Cases

Interceptors are highly versatile for enhancing your gRPC services. Which of these are common security-related use cases for gRPC interceptors?

Recap: Interceptors for Security

Interceptors provide a powerful, centralized way to inject logic into your gRPC request and response flow. They are invaluable for implementing security features like authentication, authorization, and auditing, keeping your service code clean and focused on business logic.

By using interceptors, you build more robust, maintainable, and secure gRPC applications.

Gratuit pour commencer

Apprends gRPC & High Performance APIs avec un tuteur IA — gratuit

Écris et exécute du vrai code dans ton navigateur, obtiens de l'aide instantanée d'un tuteur IA disponible 24h/24, et reprends là où tu t'es arrêté sur le web ou dans l'app.

Cours
12
Leçons
48

Questions Fréquemment Posées

La leçon « Intercepteurs pour la sécurité » est-elle gratuite ?

Oui — le texte complet de « Intercepteurs pour la sécurité » est gratuit à lire ici sur le web. Pour la pratiquer de manière interactive (un éditeur de code intégré et un tuteur IA 24/7) et déverrouiller le reste du cours gRPC & High Performance APIs, passe à CoddyKit PRO. Le cours gRPC & High Performance APIs comprend 4 leçons au total.

Qu'est-ce que j'apprendrai dans « Intercepteurs pour la sécurité » ?

Utilisez les intercepteurs gRPC pour centraliser les aspects de sécurité, comme l’authentification et la journalisation, entre les services. Tu pratiques gRPC & High Performance APIs avec du code pratique que tu exécutes directement dans le navigateur, et un tuteur IA 24/7 répond à tes questions au fur et à mesure que tu avances dans la leçon.

Dois-je avoir de l'expérience pour commencer gRPC & High Performance APIs ?

Aucune expérience préalable n'est requise. gRPC & High Performance APIs sur CoddyKit est structuré pour les débutants jusqu'aux apprenants avancés, donc tu peux commencer ici ou depuis le début et avancer à ton rythme. Ceci est la leçon 3 sur 4.

Combien de temps prend la leçon « Intercepteurs pour la sécurité » ?

La plupart des leçons CoddyKit prennent environ 5–10 minutes. Chacune est courte et interactive, tu progresses régulièrement et tu repiques exactement où tu t'es arrêté sur le web et l'app.

Peux-tu écrire et exécuter du code dans cette leçon gRPC & High Performance APIs ?

Oui. Chaque leçon gRPC & High Performance APIs inclut un éditeur de code intégré, tu écris et exécutes du vrai code directement dans ton navigateur et tu reçois des retours IA instantanés — aucune configuration locale requise.

Toutes les leçons de ce cours

  1. TLS/SSL pour gRPC
  2. Authentification et autorisation
  3. Intercepteurs pour la sécurité
  4. TLS mutuel (mTLS) pour l’authentification entre services
← Retour à gRPC & High Performance APIs