过滤器和拦截器
过滤器
场景搭建:通过用户输入的用户名和密码来登录页面
过滤器:
- 自定义过滤器(实现Filter接口),重写接口中的
doFilter
方法 - 配置过滤器:
- 在web.xml中进行配置
- 使用@WebFilter注解
MyFilter.java
package com.my.config;
import com.my.util.FilterUtil;
import lombok.extern.slf4j.Slf4j;
import javax.servlet.*;
import javax.servlet.annotation.WebFilter;
import javax.servlet.http.HttpServletRequest;
import javax.servlet.http.HttpServletResponse;
import java.io.IOException;
//@WebFilter(filterName = "loginFilter",urlPatterns = "/*")
public class MyFilter implements Filter {
@Override
public void doFilter(ServletRequest servletRequest, ServletResponse servletResponse, FilterChain filterChain) throws IOException, ServletException {
HttpServletRequest request = (HttpServletRequest) servletRequest;
HttpServletResponse response = (HttpServletResponse) servletResponse;
//获取每次请求的URL
String requestURI = request.getRequestURI();
System.out.println("===="+requestURI);
//定义不需要处理(拦截)的请求路径
//也可以转换思路:指定要需要拦截的路径
String[] urls = new String[]{
"/login",
"/",
"/goLogin",
"/goOut"
};
//判断本次请求是否需要处理
Boolean aBoolean = check(requestURI, urls);
//如果请求路径没有包含在需要过滤的路径中,则直接放行
if (aBoolean){
filterChain.doFilter(request,response);
return;
}
//员工:如果已经登录直接放行
if (request.getSession().getAttribute("userNameInFo")!=null){
System.out.println(request.getSession().getAttribute("userNameInFo"));
filterChain.doFilter(request,response);
return;
}
//用户:如果已经登录直接放行
//员工或用户未登录直接返回到登录页面
System.out.println("请求被拦截!");
// response.getWriter().write("请先登录!");
request.getRequestDispatcher("/WEB-INF/jsp/login.jsp").forward(request,response);
return;
}
/*自定义方法:
* 获取前端的请求路径和不需要处理的请求路径作比较
* 如果请求路径在字符串属组存在,则该请求不需要处理
* 如果不存在,进行处理
* */
public Boolean check(String requestURI,String[] urls){
for (String url : urls) {
if (url.equals(requestURI)){
return true;
}
}
return false;
}
}
web.xml
<!--配置过滤器-->
<filter>
<filter-name>loginFilter</filter-name>
<filter-class>com.my.config.MyFilter</filter-class>
</filter>
<filter-mapping>
<filter-name>loginFilter</filter-name>
<url-pattern>/*</url-pattern>
</filter-mapping>
注意这样写遇到个Bug:
SpringMVC配置过滤器@WebFilter注解有效,web.xml配置无效;且使用@WebFilter注解成功登录,重新访问首页再次获取Session中值为空(成功登录再次访问首页也能够进去,说明Session是有值的,但是取不到)
拦截器
场景搭建:通过用户输入的用户名和密码来登录页面
拦截器是SpringMVC独有的,在SpringMVC中使用拦截器:
- 自定义拦截器类(实现
HandlerInterceptor
接口) - .xml配置文件中配置拦截器
applicationContext.xml
<?xml version="1.0" encoding="UTF-8"?>
<beans xmlns="http://www.springframework.org/schema/beans"
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xmlns:context="http://www.springframework.org/schema/context"
xmlns:mvc="http://www.springframework.org/schema/mvc"
xsi:schemaLocation="http://www.springframework.org/schema/beans
http://www.springframework.org/schema/beans/spring-beans.xsd
http://www.springframework.org/schema/context
https://www.springframework.org/schema/context/spring-context.xsd
http://www.springframework.org/schema/mvc
https://www.springframework.org/schema/mvc/spring-mvc.xsd">
<!--自动扫描controller包-->
<context:component-scan base-package="com.my.controller"/>
<!--静态资源过滤-->
<mvc:default-servlet-handler/>
<!--开启注解驱动,以及防止json乱码-->
<mvc:annotation-driven>
<mvc:message-converters register-defaults="true">
<bean class="org.springframework.http.converter.StringHttpMessageConverter">
<constructor-arg value="UTF-8"/>
</bean>
<bean class="org.springframework.http.converter.json.MappingJackson2HttpMessageConverter">
<property name="objectMapper">
<bean class="org.springframework.http.converter.json.Jackson2ObjectMapperFactoryBean">
<property name="failOnEmptyBeans" value="false"/>
</bean>
</property>
</bean>
</mvc:message-converters>
</mvc:annotation-driven>
<!--视图解析器-->
<bean class="org.springframework.web.servlet.view.InternalResourceViewResolver" id="internalResourceViewResolver">
<property name="prefix" value="/WEB-INF/jsp/"/>
<property name="suffix" value=".jsp"/>
</bean>
<!--配置拦截器-->
<mvc:interceptors>
<!--path:
/admin/**:意思就是执行当前路径下,admin路径下,的所以请求
/**:意思就是执行当前路径下的所有请求
-->
<mvc:interceptor>
<mvc:mapping path="/**"/>
<bean class="com.my.config.LoginInterceptor"/>
</mvc:interceptor>
</mvc:interceptors>
</beans>
LoginController.java
@Controller
public class LoginController {
//前端登录页输入数据,点击提交执行下面方法
@RequestMapping("/login")
public String test01(String username, String password, HttpSession session, Model model){
//把用户信息放在session中
System.out.println("username===="+username);
session.setAttribute("userNameInFo",username);
model.addAttribute("username",username);
model.addAttribute("password",password);
return "main";
}
//进入网站首页
@RequestMapping("/main")
public String test02(){
return "main";
}
//去登录页
@RequestMapping("/goLogin")
public String test03(){
return "login";
}
//移除session退出登录,返回到登录页
@RequestMapping("/goOut")
public String test04(HttpSession session){
session.removeAttribute("userNameInFo");
return "login";
}
}
LoginInterceptor.java
public class LoginInterceptor implements HandlerInterceptor {
@Override
public boolean preHandle(HttpServletRequest request, HttpServletResponse response, Object handler) throws Exception {
//什么情况下,拦截器放行
HttpSession session = request.getSession();
//1、session不为空;第一次登录时,也没有session,为了保证第一次登录放行,需要添加“login”
if (session.getAttribute("userNameInFo")!=null){
return true;
}
//2、URL(获取请求路径,对应跳转到登录页的路径直接放行)
if (request.getRequestURI().contains("goLogin")){
System.out.println("===>"+request.getRequestURI());
return true;
}
if (request.getRequestURI().contains("login")){
System.out.println("===>"+request.getRequestURI());
return true;
}
//什么情况下,拦截器不放行;如果不放行要跳转到哪里?
System.out.println("请求被拦截了!");
request.getRequestDispatcher("/WEB-INF/jsp/login.jsp").forward(request, response);
return false;
}
}