/**
* 过滤样式文件,防止被非法下载
* (通过抓包工具(如:HttpWatch)可以破解该方法)
* @author RuiLin.Xie - xKF24276
*
*/
public class StyleFilter implements Filter
{
public void destroy()
{
}
/**
* 过滤样式文件,防止被非法下载
* (通过抓包工具(如:HttpWatch)可以破解该方法)
*/
public void doFilter(ServletRequest arg0, ServletResponse arg1,
FilterChain arg2) throws IOException, ServletException
{
HttpServletRequest request = (HttpServletRequest)arg0;
//获得上一访问的地址
String referer = request.getHeader("referer");
/** Cookie验证 **/
Cookie[] cookies = request.getCookies();
String v = null;
for(int i = 0; cookies != null && i < cookies.length; i++)
{
String n = cookies[i].getName();
if(n.equals("FURL"))
{
//读出URL并解密
v = cookies[i].getValue();
}
else
continue;
}
Object oFurl = request.getSession().getAttribute("FURL");
//如果值不一致,说明错误,直接返回空
if(v == null || oFurl == null || !v.equals(oFurl.toString()))
{
System.out.println("非法下载,已被拦截");
return;
}
/** Cookie验证结束 **/
//如果是从本站访问,那么可以下载,否则不可下载
if(referer != null && referer.startsWith("http://localhost:8080/"))
{
//禁止IE缓存,否则还是可以下载
HttpServletResponse response = (HttpServletResponse)arg1;
response.setHeader("Cache-Control","no-cache"); //HTTP 1.1
response.setHeader("Pragma","no-cache"); //HTTP 1.0
response.setDateHeader ("Expires", 0); //prevents caching at the proxy server
arg2.doFilter(arg0, arg1);
}
else
{
System.out.println("非法下载,已被拦截");
}
}
public void init(FilterConfig arg0) throws ServletException
{
}
}