Java 拦截器 + AOP

这两篇文章详细介绍了如何在Spring环境中使用Filter进行请求头的TOKEN校验,以及通过AspectJ实现AOP切面,对Controller层的方法调用进行拦截并执行TOKEN验证,确保请求的安全性。同时,展示了如何使用DigestUtils进行MD5哈希计算,提高代码的可读性和复用性。

摘要生成于 C知道 ,由 DeepSeek-R1 满血版支持, 前往体验 >

附带两篇对应文章
https://blog.youkuaiyun.com/qq_41974570/article/details/115936788
https://www.jianshu.com/p/1538b1872c6a

import org.apache.commons.codec.digest.DigestUtils;
import org.apache.commons.lang3.StringUtils;
import org.springframework.stereotype.Component;
import javax.servlet.*;
import javax.servlet.http.HttpServletRequest;
import javax.servlet.http.HttpServletResponse;
import java.io.IOException;

@Component
public class FilterUtil implements Filter {
private final static Integer ERROR_CODE = 500;
@Override
public void doFilter(ServletRequest servletRequest, ServletResponse servletResponse, FilterChain filterChain) throws IOException, ServletException {
HttpServletResponse response = (HttpServletResponse) servletResponse;
HttpServletRequest request = (HttpServletRequest) servletRequest;
String TOKEN = request.getHeader(“TOKEN”);
if (StringUtils.isBlank(TOKEN)){
response.sendError(ERROR_CODE);
return;
}
long start = System.currentTimeMillis();
String token = DigestUtils.md5Hex(String.valueOf(start).substring(0,8) + “TOKEN”);
if (!TOKEN.equalsIgnoreCase(token)){
response.sendError(ERROR_CODE);
return;
}
filterChain.doFilter(servletRequest, servletResponse);
}
}

import org.apache.commons.codec.digest.DigestUtils;
import org.aspectj.lang.ProceedingJoinPoint;
import org.aspectj.lang.annotation.Around;
import org.aspectj.lang.annotation.Aspect;
import org.aspectj.lang.annotation.Pointcut;
import org.slf4j.Logger;
import org.slf4j.LoggerFactory;
import org.springframework.core.annotation.Order;
import org.springframework.stereotype.Component;
import org.springframework.web.context.request.RequestContextHolder;
import org.springframework.web.context.request.ServletRequestAttributes;

import javax.servlet.http.HttpServletRequest;

@Component
@Order(1)
class AspectService {
private static Logger logger = LoggerFactory.getLogger(AspectService.class);

// @Pointcut(“@annotation(org.springframework.web.bind.annotation.GetMapping)”)
@Pointcut(“execution(* com.aliyun.pcc.controller….(…)))”)
public void aop(){
}

@Around("aop()")
public Object around(ProceedingJoinPoint pjp) throws Throwable {
    String name = pjp.getSignature().getName();
    ServletRequestAttributes attributes = (ServletRequestAttributes) RequestContextHolder.getRequestAttributes();
    HttpServletRequest request = attributes.getRequest();
    String uStamp = request.getHeader("TOKEN");
    long start = System.currentTimeMillis();
    String token = DigestUtils.md5Hex(String.valueOf(start).substring(0,8) + "TOKEN");

    if (! uStamp.equals(token)) {
        return CallResult.error(StatusCode.FAIL, "sssss",null);
    }
    Object result = pjp.proceed();
    long end = System.currentTimeMillis();
    logger.info(name + "方法执行时间为:" + (end - start) + " ms");
    return result;
}

}

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值