前言:上产环境中推荐解决方案:前端提交防重 + 后端自定义重复提交过滤器
防止表单重复提交常见做法
(1)前端提交按钮防重:点击提交后,按钮置灰不可用
(2)数据库唯一键:使用唯一主键/索引插入数据库报错
(3)使用session:从后端生成session[可以在获取表单内容时生成返回],提交表单时设置在header中,后端校验session是否有效
(4)后端自定义重复提交过滤器&拦截器
实现思路【Redis保存请求历史,key粒度: url + 操作人ID,缓存存在则比较时间间隔】
- 自定义方法注解 @RepeatSubmit
- 为了使request的流可以重复读取【HttpServletRequest 的流只能读取一次,拦截器读取后,实际的接口就读取不到body,需要包装类,放到包装类缓存中】,自定义过滤器:RepeatableFilter,HttpServletRequest包装类:RepeatedlyRequestWrapper
- 自定义拦截器:RepeatSubmitInterceptor、SameUrlDataInterceptor,实现核心的重复校验逻辑
- 过滤器配置,把过滤器加入到过滤链中
核心代码:
/**
* @author liangjinjie
* @description 自定义注解:防止表单重复提交
*/
@Inherited
@Target(ElementType.METHOD)
@Retention(RetentionPolicy.RUNTIME)
@Documented
public @interface RepeatSubmit {
/**
* 间隔时间(ms),小于此时间视为重复提交
*/
int interval() default 5000;
/**
* 提示消息
*/
String message() default "不允许重复提交,请稍候再试";
}
/**
* @author liangjinjie
* @description 防止重复提交拦截器
*/
public abstract class RepeatSubmitInterceptor implements HandlerInterceptor {
@Override
public boolean preHandle(HttpServletRequest request, HttpServletResponse response, Object handler) throws Exception {
if (handler instanceof HandlerMethod) {
HandlerMethod handlerMethod = (HandlerMethod) handler;
Method method = handlerMethod.getMethod();
RepeatSubmit annotation = method.getAnnotation(RepeatSubmit.class);
if (Objects.nonNull(annotation)) {
if (this.isRepeatSubmit(request, annotation)) {
HttpHelper.renderString(response, JSON.toJSONString(ResultDTO.error(annotation.message())));
return false;
}
}
return true;
}
return true;
}
/**
* 验证是否重复提交由子类实现具体的防重复提交的规则
*
* @param request
* @param annotation
* @return
*/
public abstract boolean isRepeatSubmit(HttpServletRequest request, RepeatSubmit annotation);
}
/**
* @author liangjinjie
* @description 判断是否重复提交实现(url+data),一定时间内提交的接口数据相同,则拦截
* 实现思路:redis记录请求的历史,key = uri + [operator] , value = <data & time>
*/
@Component
public class SameUrlDataInterceptor extends RepeatSubmitInterceptor {
@Autowired
private RedisTemplate<String, Object> redisTemplate;
/**
* 防重提交 redis key
*/
public static final String REPEAT_SUBMIT_KEY = "repeatSubmit:";
public final String REPEAT_PARAMS = "repeatParams";
public final String REPEAT_TIME = "repeatTime";
/**
* 核心逻辑
*
* @param request 请求request
* @param annotation 注解
* @return
*/
@Override
public boolean isRepeatSubmit(HttpServletRequest request, RepeatSubmit annotation) {
// 获取body字符串, request已经被RepeatableFilter过滤器处理成包装类RepeatedlyRequestWrapper,可以重复读取
String curParams = "";
if (request instanceof RepeatedlyRequestWrapper) {
RepeatedlyRequestWrapper repeatedlyRequest = (RepeatedlyRequestWrapper) request;
curParams = HttpHelper.getBodyString(repeatedlyRequest);
}
// body为空,获取parameter参数
if (StringUtils.isBlank(curParams)) {
curParams = JSON.toJSONString(request.getParameterMap());
}
Map<String, String> nowMap = new HashMap<>();
nowMap.put(REPEAT_PARAMS, curParams);
nowMap.put(REPEAT_TIME, String.valueOf(System.currentTimeMillis()));
String uri = request.getRequestURI();
String cacheRepeatKey = REPEAT_SUBMIT_KEY + uri;
String operator = request.getHeader("operator");
if (StringUtils.isNotBlank(operator)) {
cacheRepeatKey += operator;
}
Object cacheObject = redisTemplate.opsForValue().get(cacheRepeatKey);
if (Objects.nonNull(cacheObject)) {
Map<String, String> preMap = (Map<String, String>) cacheObject;
if (compareParams(nowMap, preMap) && compareTime(nowMap, preMap, annotation.interval())) {
return true;
}
}
redisTemplate.opsForValue().set(cacheRepeatKey, nowMap, annotation.interval(), TimeUnit.MILLISECONDS);
return false;
}
/**
* 判断参数是否相同
*/
private boolean compareParams(Map<String, String> nowMap, Map<String, String> preMap) {
String nowParams = nowMap.get(REPEAT_PARAMS);
String preParams = preMap.get(REPEAT_PARAMS);
return nowParams.equals(preParams);
}
/**
* 判断两次间隔时间是否小于注解间隔
*/
private boolean compareTime(Map<String, String> nowMap, Map<String, String> preMap, int interval) {
long nowTime = NumberUtils.toLong(nowMap.get(REPEAT_TIME));
long preTime = NumberUtils.toLong(preMap.get(REPEAT_TIME));
if ((nowTime - preTime) < interval) {
return true;
}
return false;
}
}
/**
* 过滤器配置
**/
@Configuration
public class FilterConfig implements WebMvcConfigurer {
@Autowired
private SameUrlDataInterceptor sameUrlDataInterceptor;
@Override
public void addInterceptors(InterceptorRegistry registry) {
// 加入框架的拦截器,用于处理header中的公共参数
registry.addInterceptor(sameUrlDataInterceptor).addPathPatterns("/**");
}
@Bean
public FilterRegistrationBean someFilterRegistration() {
FilterRegistrationBean registration = new FilterRegistrationBean();
registration.setFilter(new RepeatableFilter());
registration.addUrlPatterns("/*");
registration.setName("repeatableFilter");
registration.setOrder(FilterRegistrationBean.LOWEST_PRECEDENCE);
return registration;
}
让HttpServerletRequest能重复读取
/**
* @author liangjinjie
* @description Repeatable 过滤器
*/
public class RepeatableFilter implements Filter {
@Override
public void init(FilterConfig filterConfig) throws ServletException {
}
@Override
public void doFilter(ServletRequest request, ServletResponse response, FilterChain chain)
throws IOException, ServletException {
ServletRequest requestWrapper = null;
if (request instanceof HttpServletRequest
&& StringUtils.startsWithIgnoreCase(request.getContentType(), MediaType.APPLICATION_JSON_VALUE)) {
requestWrapper = new RepeatedlyRequestWrapper((HttpServletRequest) request);
}
if (null == requestWrapper) {
chain.doFilter(request, response);
} else {
chain.doFilter(requestWrapper, response);
}
}
@Override
public void destroy() {
}
}
/**
* @author liangjinjie
* @description requst包装类,构建可重复读取inputStream的request
*/
public class RepeatedlyRequestWrapper extends HttpServletRequestWrapper {
private final byte[] body;
public RepeatedlyRequestWrapper(HttpServletRequest request) throws IOException {
super(request);
body = HttpHelper.getBodyString(request).getBytes("UTF-8");
}
@Override
public BufferedReader getReader() throws IOException {
return new BufferedReader(new InputStreamReader(getInputStream()));
}
@Override
public ServletInputStream getInputStream() throws IOException {
final ByteArrayInputStream bais = new ByteArrayInputStream(body);
return new ServletInputStream() {
@Override
public int read() throws IOException {
return bais.read();
}
@Override
public int available() throws IOException {
return body.length;
}
@Override
public boolean isFinished() {
return false;
}
@Override
public boolean isReady() {
return false;
}
@Override
public void setReadListener(ReadListener readListener) {
}
};
}
}
使用到的工具类代码
/**
* @author liangjinjie
* @description Http工具类
*/
@Slf4j
public class HttpHelper {
/**
* 将字符串渲染到response返回给前端
*
* @param response 渲染对象
* @param string 待渲染的字符串
*/
public static void renderString(HttpServletResponse response, String string) {
try {
response.setStatus(200);
response.setContentType("application/json");
response.setCharacterEncoding("utf-8");
response.getWriter().print(string);
} catch (IOException e) {
log.warn("输出response返回异常", e);
}
}
/**
* 读取Body内容
*
* @param request 请求request
* @return
*/
public static String getBodyString(ServletRequest request) {
StringBuilder sb = new StringBuilder();
BufferedReader reader = null;
try (InputStream inputStream = request.getInputStream()) {
reader = new BufferedReader(new InputStreamReader(inputStream, StandardCharsets.UTF_8));
String line = "";
while ((line = reader.readLine()) != null) {
sb.append(line);
}
} catch (IOException e) {
log.warn("getBodyString出现问题!");
} finally {
if (reader != null) {
try {
reader.close();
} catch (IOException e) {
log.error(ExceptionUtils.getMessage(e));
}
}
}
return sb.toString();
}
}