package com.xxx.servlet;
import java.io.IOException;
import javax.servlet.ServletException;
import javax.servlet.annotation.WebServlet;
import javax.servlet.http.HttpServlet;
import javax.servlet.http.HttpServletRequest;
import javax.servlet.http.HttpServletResponse;
import com.xxx.utils.Token;
@WebServlet(name="form",urlPatterns="/form")
public class FormServlet extends HttpServlet {
@Override
protected void doGet(HttpServletRequest request, HttpServletResponse response)
throws ServletException, IOException {
response.setCharacterEncoding("UTF-8");
response.setContentType("text/html;charset=UTF-8");
String token=null;
try{
token=Token.getInstance().makeToken();
}catch(Exception e){
e.printStackTrace();
}
request.getSession().setAttribute("token", token);
this.getServletContext().getRequestDispatcher("/form.jsp").forward(request, response);
}
}
<form action="${pageContext.request.contextPath}/doForm" method="post">
<input type="text" name="user" ><br>
<input type="hidden" name="token" value=${token}>
<input type="submit">
</form>
package com.xxx.servlet;
import java.io.IOException;
import javax.servlet.ServletException;
import javax.servlet.annotation.WebServlet;
import javax.servlet.http.HttpServlet;
import javax.servlet.http.HttpServletRequest;
import javax.servlet.http.HttpServletResponse;
@WebServlet(name="doForm",urlPatterns="/doForm")
public class DoFormServlet extends HttpServlet {
@Override
protected void doGet(HttpServletRequest request, HttpServletResponse response)
throws ServletException, IOException {
request.setCharacterEncoding("UTF-8");
String token=request.getParameter("token");
String sessToken=(String) request.getSession().getAttribute("token");
if(token==null || sessToken==null || !token.equals(sessToken)){
System.out.println("表单重复提交");
}else{
System.out.println("正常提交");
}
}
@Override
protected void doPost(HttpServletRequest req, HttpServletResponse resp)
throws ServletException, IOException {
this.doGet(req, resp);
}
}
package com.xxx.utils;
import java.security.MessageDigest;
import java.security.NoSuchAlgorithmException;
import java.util.Random;
import sun.misc.BASE64Encoder;
public class Token {
private static Token token=new Token();
private Token(){
}
public static Token getInstance(){
return token;
}
public static String makeToken() throws NoSuchAlgorithmException{
String token=(System.currentTimeMillis()+new Random().nextInt(999999))+"";
MessageDigest md=MessageDigest.getInstance("MD5");
byte[] md5=md.digest(token.getBytes());
BASE64Encoder base64=new BASE64Encoder();
return base64.encode(md5);
}
}