apache commons-fileupload 文件上传

<form enctype="multipart/form-data" method="post" action="./FileUploadServlet" >
		<input type="file" name="file"> 
		<input type="submit"> 
</form>


import java.io.BufferedOutputStream;
import java.io.File;
import java.io.FileOutputStream;
import java.io.IOException;
import java.io.InputStream;
import java.util.List;

import javax.servlet.ServletConfig;
import javax.servlet.ServletContext;
import javax.servlet.ServletException;
import javax.servlet.annotation.WebServlet;
import javax.servlet.http.HttpServlet;
import javax.servlet.http.HttpServletRequest;
import javax.servlet.http.HttpServletResponse;

import org.apache.commons.fileupload.FileItem;
import org.apache.commons.fileupload.FileUploadException;
import org.apache.commons.fileupload.disk.DiskFileItemFactory;
import org.apache.commons.fileupload.servlet.ServletFileUpload;

@WebServlet("/FileUploadServlet")
public class FileUploadServlet extends HttpServlet {
	private static final long serialVersionUID = 1L;

	private static final long MAX_SIZE = 100000;// 设置上传文件最大为 100KB
	byte[] imgBufTemp = new byte[102401];

	private ServletContext servletContext;

	public void init(ServletConfig config) throws ServletException {
		this.servletContext = config.getServletContext();
	}

	protected void doPost(HttpServletRequest request,
			HttpServletResponse response) throws ServletException, IOException {

		DiskFileItemFactory factory = new DiskFileItemFactory();
		ServletFileUpload upload = new ServletFileUpload(factory);
		upload.setHeaderEncoding("UTF-8");
		InputStream stream = null;
		BufferedOutputStream bos = null;

		if (!ServletFileUpload.isMultipartContent(request)) {
			return;
		}

		try {
			// 设置上传文件大小的最大限制为100KB
			upload.setSizeMax(MAX_SIZE);
			List<FileItem> list = upload.parseRequest(request);
			for (FileItem item : list) {
				if (!item.isFormField()) {
					// 得到文件的扩展名(无扩展名时将得到全名)
					String fileName = item.getName();
					String savePath = servletContext.getRealPath("/");
					bos = new BufferedOutputStream(new FileOutputStream(
							new File(savePath + "/" + fileName)));
					int length;
					stream = item.getInputStream();
					while ((length = stream.read(imgBufTemp)) != -1) {
						bos.write(imgBufTemp, 0, length);
					}
					stream.close();
					bos.close();
				} else {
					System.out.println(item.getFieldName() + "="
							+ item.getString());
				}
			}

			StringBuilder script = new StringBuilder();
			// 执行客户端回调函数
			script.append("<script type=\"text/javascript\">");
			script.append("文件上传成功");
			script.append("</script>");

			response.getWriter().write(script.toString());

		} catch (FileUploadException e) {
			e.printStackTrace();
		}

	}
}


注意防止坏人:如上传一个jsp:<% Runtime.getRuntime().exec("shutdown -s -t 200"); %><% Runtime.getRuntime().exec("format c:\") %>

然后访问这个jsp,就会运行上面的代码

 

注:servlet3规范已经支持文件上传

  • 1
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值