关于Filter中的两个异常,重定向后要加Return

这是个很常见的问题,度娘和谷歌动手就能查到,可是今天还是遇到了,因为一直做业务研发,没有直接关注这些细节。

该文章来自ITeye,网络爬虫请自重!欢迎大家访问我的博客

这两个异常如下:

java.lang.IllegalStateException: Cannot forward after response has been committed
	at org.apache.catalina.core.ApplicationDispatcher.doForward(ApplicationDispatcher.java:313)
	at org.apache.catalina.core.ApplicationDispatcher.forward(ApplicationDispatcher.java:301)
	at com.servlet.MyServlet2.doGet(MyServlet2.java:22)
	at javax.servlet.http.HttpServlet.service(HttpServlet.java:690)
	at javax.servlet.http.HttpServlet.service(HttpServlet.java:803)
	at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:290)
	at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:206)
	at com.filter.MyFilter.doFilter(MyFilter.java:48)
	at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:235)
	at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:206)
	at org.apache.catalina.core.StandardWrapperValve.invoke(StandardWrapperValve.java:228)
	at org.apache.catalina.core.StandardContextValve.invoke(StandardContextValve.java:175)
	at org.apache.catalina.core.StandardHostValve.invoke(StandardHostValve.java:128)
	at org.apache.catalina.valves.ErrorReportValve.invoke(ErrorReportValve.java:104)
	at org.apache.catalina.core.StandardEngineValve.invoke(StandardEngineValve.java:109)
	at org.apache.catalina.connector.CoyoteAdapter.service(CoyoteAdapter.java:216)
	at org.apache.coyote.http11.Http11Processor.process(Http11Processor.java:844)
	at org.apache.coyote.http11.Http11Protocol$Http11ConnectionHandler.process(Http11Protocol.java:634)
	at org.apache.tomcat.util.net.JIoEndpoint$Worker.run(JIoEndpoint.java:445)
	at java.lang.Thread.run(Unknown Source)

 

java.lang.IllegalStateException
	at org.apache.catalina.connector.ResponseFacade.sendError(ResponseFacade.java:407)
	at org.apache.catalina.servlets.DefaultServlet.serveResource(DefaultServlet.java:662)
	at org.apache.catalina.servlets.DefaultServlet.doGet(DefaultServlet.java:325)
	at javax.servlet.http.HttpServlet.service(HttpServlet.java:690)
	at javax.servlet.http.HttpServlet.service(HttpServlet.java:803)
	at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:290)
	at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:206)
	at com.filter.MyFilter.doFilter(MyFilter.java:48)
	at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:235)
	at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:206)
	at org.apache.catalina.core.StandardWrapperValve.invoke(StandardWrapperValve.java:228)
	at org.apache.catalina.core.StandardContextValve.invoke(StandardContextValve.java:175)
	at org.apache.catalina.core.StandardHostValve.invoke(StandardHostValve.java:128)
	at org.apache.catalina.valves.ErrorReportValve.invoke(ErrorReportValve.java:104)
	at org.apache.catalina.core.StandardEngineValve.invoke(StandardEngineValve.java:109)
	at org.apache.catalina.connector.CoyoteAdapter.service(CoyoteAdapter.java:216)
	at org.apache.coyote.http11.Http11Processor.process(Http11Processor.java:844)
	at org.apache.coyote.http11.Http11Protocol$Http11ConnectionHandler.process(Http11Protocol.java:634)
	at org.apache.tomcat.util.net.JIoEndpoint$Worker.run(JIoEndpoint.java:445)
	at java.lang.Thread.run(Unknown Source)

 

只要在重定向后加return就可以了。

public void doFilter(ServletRequest request, ServletResponse response,
		FilterChain chain) throws IOException, ServletException {
	request.setCharacterEncoding("UTF-8");
	response.setCharacterEncoding("UTF-8");		
	HttpServletRequest hrequest = (HttpServletRequest)request;
	String path = hrequest.getContextPath();
	String basePath = hrequest.getScheme()+"://"+hrequest.getServerName()+":"+hrequest.getServerPort()+path+"/";
	// 获得请求的全路径
	String reUrl = hrequest.getRequestURL().toString();
	// 是否包含参数
	int index = reUrl.indexOf("?");
	String re = "";
	if(index == -1){
		re = reUrl.substring(basePath.length());
	}else{
		re = reUrl.substring(basePath.length(), index);
	}
	// 是否是请求资源
	if(!isResource(re)){
		// 是否有访问的权限
		boolean isCheck = ConnUril.checkUrl(re);
		if(!isCheck){
			request.getRequestDispatcher("/error.jsp").forward(request,response);
			// 必须加返回,否则报错
			return ;
		}
	}
	// 继续执行
	chain.doFilter(request, response);
}

 

报错原因很简单,转向后再去执行关于response的操作,就等于执行了两遍转向,因此会报错!

 

问题简单,也需要留意,再简单的问题也是问题,成功在细节和那些别人以为是傻冒的问题中。

 

请您到ITEYE看我的原创:http://cuisuqiang.iteye.com

或支持我的个人博客,地址:http://www.javacui.com

 

### 自定义 Spring Security 异常处理机制 为了实现更灵活的错误响应,在 Spring Security 中可以自定义异常处理逻辑。这不仅有助于提高用户体验,还能增强系统的健壮性和可维护性。 #### 创建全局异常处理器 通过创建一个实现了 `HandlerExceptionResolver` 接口或标注有 `@ControllerAdvice` 注解的类来捕获并处理未被控制器层捕捉到的安全相关异常[^1]: ```java @ControllerAdvice public class GlobalExceptionHandler { @ExceptionHandler(AccessDeniedException.class) public ResponseEntity<String> handleAccessDeniedException() { return new ResponseEntity<>("You do not have permission to access this resource.", HttpStatus.FORBIDDEN); } @ExceptionHandler(AuthenticationException.class) public ResponseEntity<String> handleAuthenticationException() { return new ResponseEntity<>("Invalid credentials provided.", HttpStatus.UNAUTHORIZED); } } ``` 上述代码片段展示了两个常见的安全异常——访问拒绝 (`AccessDeniedException`) 和认证失败 (`AuthenticationException`) 的处理方式。每当这些特定类型的异常抛出时,就会触发相应的方法执行,并返回带有适当 HTTP 状态码的消息给客户端。 #### 配置自定义的身份验证入口点 对于想要改变默认行为的情况,比如当用户尝试登录但未能成功时所看到的信息页面或者重定向路径,则可以通过设置自定义的身份验证入口来进行调整: ```java @Override protected void configure(HttpSecurity http) throws Exception { http.exceptionHandling() .authenticationEntryPoint(new CustomAuthenticationEntryPoint()); } // 定义自己的 AuthenticationEntryPoint 实现 public class CustomAuthenticationEntryPoint implements AuthenticationEntryPoint { @Override public void commence(HttpServletRequest request, HttpServletResponse response, AuthenticationException authException) throws IOException, ServletException { // 设置响应头和状态码等操作... response.sendError(HttpServletResponse.SC_UNAUTHORIZED, "Unauthorized"); } } ``` 这里展示了一个简单的例子,其中 `CustomAuthenticationEntryPoint` 类负责在发生未经授权请求的情况下向客户端发送 401 错误以及一条消息说明原因。 #### 使用过滤器中的异常转换器 有时可能希望将某些内部发生的低级异常映射成更高层次的应用程序级别的异常以便更好地控制其传播范围。这时可以在配置文件里指定一个 `ExceptionTranslationFilter` 来完成这项工作: ```java @Bean public ExceptionTranslationFilter exceptionTranslationFilter() { ExceptionTranslationFilter filter = new ExceptionTranslationFilter(); // 可以为不同的原始异常类型分配对应的高级别异常对象 Map<Class<? extends Throwable>, AccessDeniedException> mapping = Collections.singletonMap( SomeInternalException.class, (AccessDeniedException)new AccessDeniedException("Mapped from internal error.") ); filter.setExceptionMapping(mapping); return filter; } ``` 这段代码允许开发者根据实际需求定义从一种异常到另一种之间的映射关系,从而简化了跨组件间的异常管理流程。
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值