SpringBoot监控请求响应日志,可以借此分析了解项目中的相关性能,安全方面的问题,开发人员也可以方便的拿取日志进行排错检查问题等一系列操作。
1.思考--request请求和rsponse请求都只能拿一次body体里面的参数,怎么办?
2.记录哪些数据?
3.拿到的日志数据如何存储?
4.实现方式?
5.是否有实现漏洞?
1.思考--request请求和rsponse请求都只能拿一次body体里面的参数,怎么办?
由于body体的特性导致数据拿取一次后就无法再次执行,我们可以实现相应的请求响应包装类,拿取数据后进行回填(内部再次请求),从而获取相应请求响应参数后,可以正确执行业务方法
RequestWrapper------Request包装类
package com.youfuli.task.interceptor;
import javax.servlet.ReadListener;
import javax.servlet.ServletInputStream;
import javax.servlet.http.HttpServletRequest;
import javax.servlet.http.HttpServletRequestWrapper;
import java.io.*;
import java.nio.charset.Charset;
public class RequestWrapper extends HttpServletRequestWrapper {
private final String body;
public RequestWrapper(HttpServletRequest request) throws IOException {
super(request);
StringBuilder stringBuilder = new StringBuilder();
BufferedReader bufferedReader = null;
try {
InputStream inputStream = request.getInputStream();
if (inputStream != null) {
bufferedReader = new BufferedReader(new InputStreamReader(inputStream));
char[] charBuffer = new char[128];
int bytesRead = -1;
while ((bytesRead = bufferedReader.read(charBuffer)) > 0) {
stringBuilder.append(charBuffer, 0, bytesRead);
}
} else {
stringBuilder.append("");
}
} catch (IOException ex) {
throw ex;
} finally {
if (bufferedReader != null) {
try {
bufferedReader.close();
} catch (IOException ex) {
throw ex;
}
}
}
body = stringBuilder.toString();
}
@Override
public ServletInputStream getInputStream() throws IOException {
final ByteArrayInputStream byteArrayInputStream = new ByteArrayInputStream(body.getBytes());
ServletInputStream servletInputStream = new ServletInputStream() {
@Override
public boolean isFinished() {
return false;
}
@Override
public boolean isReady() {
return false;
}
@Override
public void setReadListener(ReadListener readListener) {}
@Override
public int read() throws IOException {
return byteArrayInputStream.read();
}
};
return servletInputStream;
}
@Override
public BufferedReader getReader() throws IOException {
return new BufferedReader(new InputStreamReader(this.getInputStream()));
}
public String getBody() {
return this.body;
}
}
ResponseWrapper------Response包装类
package com.youfuli.task.interceptor;
import javax.servlet.ServletOutputStream;
import javax.servlet.WriteListener;
import javax.servlet.http.HttpServletResponse;
import javax.servlet.http.HttpServletResponseWrapper;
import java.io.ByteArrayOutputStream;
import java.io.IOException;
/**
* @author lxt
*/
public class ResponseWrapper extends HttpServletResponseWrapper {
private ByteArrayOutputStream buffer;
private ServletOutputStream out;
public ResponseWrapper(HttpServletResponse httpServletResponse)
{
super(httpServletResponse);
buffer = new ByteArrayOutputStream();
out = new WrapperOutputStream(buffer);
}
@Override
public ServletOutputStream getOutputStream()
throws IOException
{
return out;
}
@Override
public void flushBuffer()
throws IOException
{
if (out != null)
{
out.flush();
}
}
public byte[] getContent()
throws IOException
{
flushBuffer();
return buffer.toByteArray();
}
class WrapperOutputStream extends ServletOutputStream
{
private ByteArrayOutputStream bos;
public WrapperOutputStream(ByteArrayOutputStream bos)
{
this.bos = bos;
}
@Override
public void write(int b)
throws IOException
{
bos.write(b);
}
@Override
public boolean isReady()
{
// TODO Auto-generated method stub
return false;
}
@Override
public void setWriteListener(WriteListener arg0)
{
// TODO Auto-generated method stub
}
}
}
通过相应的包装类,我们可以在请求body体内进行参数的拿取和替换,从而达到记录参数日志的目的
2.记录哪些数据?
如图,这是我记录日志的数据库表结构,分为四类:请求基本信息,参数信息(分位query和body),响应信息,业务信息(用户之类的信息),后续可以根据相应业务流程进行配置
3.拿到的日志数据如何存储?4.实现方式?
存储方式采用本地集合+redis缓存(monogoDB后续需要查询再更换)配合使用,本地开启定时任务定时读取redis数据进行读取,然后批量插入数据库
实现方式:拦截器+过滤器,前者拦截相应请求信息,后者过滤请求信息和拿到响应信息(特殊接口可直接过滤,响应则只能再过滤器中拿到)
过滤器代码如下:
package com.youfuli.task.interceptor;
import com.alibaba.fastjson.JSONArray;
import com.alibaba.fastjson.JSONObject;
import com.youfuli.task.service.RedisService;
import com.youfuli.task.utils.LogProcess;
import lombok.extern.slf4j.Slf4j;
import org.springframework.beans.factory.annotation.Autowired;
import org.springframework.beans.factory.annotation.Value;
import javax.servlet.*;
import javax.servlet.http.HttpServletRequest;
import javax.servlet.http.HttpServletResponse;
import java.io.IOException;
import java.util.Enumeration;
import java.util.Map;
/**
* @author lxt
*/
@Slf4j
public class HttpServletFilter implements Filter {
@Autowired
LogProcess logProcess;
private static final String DOWMLOAD_FILE = "/base/downloadFile";
private static final String URI ="uri";
@Autowired
RedisService redisService;
/**
* 超时时间
*/
@Value("${authorization.timeout}")
long timeout;
@Override
public void init(FilterConfig filterConfig) throws ServletException {
}
@Override
public void doFilter(ServletRequest request, ServletResponse response, FilterChain chain) throws IOException, ServletException {
ServletRequest requestWrapper = null;
log.info("当前过滤器线程名称为{}",Thread.currentThread().getName());
ResponseWrapper responseWrapper = new ResponseWrapper((HttpServletResponse)response);
Enumeration<String> names = request.getParameterNames();
JSONObject endJson = new JSONObject();
endJson.put(URI,((HttpServletRequest) request).getRequestURI());
if(names.hasMoreElements()){
redisService.put(Thread.currentThread().getName(),endJson,timeout);
chain.doFilter(request, responseWrapper);
} else {
if(request instanceof HttpServletRequest) {
requestWrapper = new RequestWrapper((HttpServletRequest) request);
RequestWrapper myRequestWrapper =(RequestWrapper)requestWrapper;
String body = myRequestWrapper.getBody();
JSONArray bodyArray = new JSONArray();
JSONObject bodyJson = new JSONObject();
bodyJson.put("body",body);
bodyArray.add(bodyJson);
endJson.put("bodyParams",bodyArray.toJSONString());
endJson.put("queryParams","");
redisService.put(Thread.currentThread().getName(),endJson,timeout);
}
chain.doFilter(requestWrapper, responseWrapper);
}
//获取返回值
byte[] content = responseWrapper.getContent();
//判断是否有值
if (content.length > 0) {
String str = new String(content, "UTF-8");
ServletOutputStream out = response.getOutputStream();
out.write(content);
out.flush();
JSONObject endJson2 = (JSONObject) redisService.get(Thread.currentThread().getName());
if(!endJson2.getString(URI).contains(DOWMLOAD_FILE)){
endJson2.put("response",str);
redisService.put(Thread.currentThread().getName(),endJson2,timeout);
JSONObject endJsons = (JSONObject) redisService.get(Thread.currentThread().getName());
logProcess.addData(endJsons);
//删除当前缓存数据
redisService.deleteString(Thread.currentThread().getName());
}
}
}
@Override
public void destroy() {
}
}
此处我注释掉了@WebFilter注解,后续会解释其作用.
拦截器代码:
package com.youfuli.task.interceptor;
import com.alibaba.fastjson.JSONArray;
import com.alibaba.fastjson.JSONObject;
import com.youfuli.task.service.RedisService;
import com.youfuli.task.utils.CurrentUserHolder;
import lombok.extern.slf4j.Slf4j;
import org.springframework.beans.factory.annotation.Autowired;
import org.springframework.beans.factory.annotation.Value;
import org.springframework.stereotype.Component;
import org.springframework.web.servlet.ModelAndView;
import org.springframework.web.servlet.handler.HandlerInterceptorAdapter;
import javax.servlet.http.HttpServletRequest;
import javax.servlet.http.HttpServletResponse;
import java.text.SimpleDateFormat;
import java.util.*;
/**
* @author lxt
*/
@Component
@Slf4j
public class CommonInterceptor extends HandlerInterceptorAdapter{
/**格式化时间*/
private static final SimpleDateFormat DATE_FOMAT = new SimpleDateFormat("yyyy-MM-dd HH:mm:ss");
@Autowired
RedisService redisService;
/**
* 超时时间
*/
@Value("${authorization.timeout}")
long timeout;
public CommonInterceptor() {
}
@Override
public boolean preHandle(HttpServletRequest request, HttpServletResponse response, Object handler) throws Exception {
Enumeration<String> names = request.getParameterNames();
log.info("当前拦截器线程名称为{}",Thread.currentThread().getName());
JSONObject endJson = (JSONObject) redisService.get(Thread.currentThread().getName());
//获取请求的基本信息
endJson.put("method",request.getMethod());
endJson.put("contextPath",request.getContextPath());
endJson.put("contextType",request.getContentType());
endJson.put("clientIp",request.getRemoteAddr());
endJson.put("token",request.getHeader("authorization"));
endJson.put("referer",request.getHeader("referer"));
endJson.put("userAgent",request.getHeader("user-agent"));
//获取请求参数信息
if(names.hasMoreElements()){
JSONArray queryArray = new JSONArray();
JSONObject queryJson = new JSONObject();
while(names.hasMoreElements()){
String name = names.nextElement();
queryJson.put(name,request.getParameterValues(name));
}
queryArray.add(queryJson);
endJson.put("queryParams",queryArray.toJSONString());
endJson.put("bodyParams",null);
}
//获取用户信息
endJson.put("userName",CurrentUserHolder.getUser().getUserName());
endJson.put("startTime",DATE_FOMAT.format(new Date()));
endJson.put("latencyTime",System.currentTimeMillis());
redisService.put(Thread.currentThread().getName(),endJson,timeout);
return true;
}
@Override
public void postHandle(HttpServletRequest request, HttpServletResponse response, Object handler, ModelAndView modelAndView) throws Exception {
System.out.println(Thread.currentThread().getName());
JSONObject endJson = (JSONObject) redisService.get(Thread.currentThread().getName());
endJson.put("latencyTime",System.currentTimeMillis()-endJson.getLong("latencyTime"));
endJson.put("endTime",DATE_FOMAT.format(new Date()));
redisService.put(Thread.currentThread().getName(),endJson,timeout);
System.out.println(Thread.currentThread().getName());
super.postHandle(request, response, handler, modelAndView);
}
@Override
public void afterCompletion(HttpServletRequest request, HttpServletResponse response, Object handler, Exception ex) throws Exception {
super.afterCompletion(request, response, handler, ex);
}
@Override
public void afterConcurrentHandlingStarted(HttpServletRequest request, HttpServletResponse response, Object handler) throws Exception {
super.afterConcurrentHandlingStarted(request, response, handler);
}
}
此处通过json进行数据的装载,后期配合数据库进行批量插入
其实最后的插入方法在过滤器这边
logProcess.addData(CommonInterceptor.endJson);
package com.youfuli.task.utils;
import com.alibaba.fastjson.JSONObject;
import com.youfuli.task.service.RedisService;
import lombok.extern.slf4j.Slf4j;
import org.apache.poi.ss.formula.functions.T;
import org.springframework.beans.factory.annotation.Autowired;
import org.springframework.beans.factory.annotation.Value;
import org.springframework.stereotype.Component;
import java.util.*;
/**
* @author lxt
* 日志处理
*/
@Component
@Slf4j
public class LogProcess {
@Autowired
RedisService redisService;
public static final List<JSONObject> LIST = new ArrayList<>();
private static final Integer LISTSIZE = 100;
private static final String LISTNAME = "logList";
/**
* 超时时间
*/
@Value("${authorization.timeout}")
long timeout;
/**
* 添加缓存数据
* @param datas 日志数据
*/
public void addData(JSONObject datas){
if(LISTSIZE.equals(LIST.size())){
log.info("集合数据到达上限,准备存入缓存");
Map<String, Object> o = (Map<String, Object>)redisService.getAlls(LISTNAME);
Integer indexNo = Integer.valueOf(String.valueOf(getMaxKey(o)));
log.info("当前缓存列表共{}组",indexNo);
redisService.put(LISTNAME,String.valueOf(indexNo+1),LIST,timeout);
LIST.clear();
}
LIST.add(datas);
log.info("集合数据已有{}条",LIST.size());
}
public static Object getMaxKey(Map<String, Object> map) {
if (map.size()==0){
return 0;
}
Set<String> set = map.keySet();
Object[] obj = set.toArray();
Arrays.sort(obj);
return obj[obj.length-1];
}
}
LogProcess类中定义了一些静态参数,由于是测试类,没有定义到配置中,这个类中的addData方法,目的在于将静态集合中的数据缓存到redis中,此处缓存的数据格式位key-key-value的格式,所以定义了map进行存储,便于区分每个集合批次
此处使用的Redis相应方法如下
Map getAlls(String cacheName);
@Override
public Map getAlls(String cacheName) {
return hashOperations.entries(cacheName);
}
void put(String cacheName, String key, T value, long expire);
/**
* 添加
*
* @param key key
* @param value 对象
* @param expire 过期时间(单位:秒),传入 -1 时表示不设置过期时间
*/
@Override
public void put(String cacheName, String key, T value, long expire) {
hashOperations.put(cacheName, key, value);
if (expire != -1) {
redisTemplate.expire(cacheName, expire, TimeUnit.SECONDS);
}
}
最后就是定时任务了:
package com.youfuli.task.job;
import com.alibaba.fastjson.JSONObject;
import com.youfuli.task.mapper.log.TmpLogMapper;
import com.youfuli.task.service.RedisService;
import lombok.extern.slf4j.Slf4j;
import org.springframework.beans.factory.annotation.Autowired;
import org.springframework.scheduling.annotation.Scheduled;
import org.springframework.stereotype.Component;
import java.util.List;
import java.util.Map;
/**
* @author lxt
*/
@Slf4j
@Component
public class SynLog {
@Autowired
private RedisService redisService;
@Autowired
private TmpLogMapper tmpLogMapper;
//@Scheduled(cron="20 44 11 * * ?")
@Scheduled(cron="0 0/2 * * * ?")
public void saveLog(){
Map<String, Object> maps = (Map<String, Object>)redisService.getAlls("logList");
log.info("缓存待存入数据共{}组",maps.size());
if(maps.size()>0){
for(String keys:maps.keySet()){
List<JSONObject> list =(List<JSONObject>)maps.get(keys);
int counts = tmpLogMapper.insertForeach(list);
log.info("插入数据库数据{}条",counts);
redisService.remove("logList",keys);
log.info("logList集合编号第{}的数据已删除",keys);
}
}
}
}
mapper.xml
/**
* 批量插入log日志
* @param list list集合log
* @return int
*/
int insertForeach(List<JSONObject> list);
<!--批量插入log日志-->
<insert id="insertForeach" parameterType="java.util.List" useGeneratedKeys="false">
insert into tmp_log (client_ip, method,
context_path, context_type, uri,
token, referer, userAgent,
query_params, user_name, start_time,
end_time, latency_time, body_params,
response)
values
<foreach collection="list" item="item" index="index" separator=",">
(#{item.clientIp},
#{item.method},
#{item.contextPath},
#{item.contextType},
#{item.uri},
#{item.token},
#{item.referer},
#{item.userAgent},
#{item.queryParams},
#{item.userName},
#{item.startTime},
#{item.endTime},
#{item.latencyTime},
#{item.bodyParams},
#{item.response}
)
</foreach>
</insert>
其实,将思路给规划清楚,剩下就是怎么去实现的问题。
5.是否有实现漏洞?
此刻我的代码还跑不起来,为何?因为有如下漏洞
1.前文提到,我在过滤器中注释掉了@WebFilter注解,为什么?
大家将项目打成war包后你会发现,在没有去掉该注解的情况下,在filter类中关于@Autowried的依赖是没有注入的,原因很简单,springboot的加载顺序为listener-filter-servlet,所以在加载filter的时候还没有相关的依赖进入,自然获取不到相关的依赖了。解决办法分两步,第一删除掉@WebFilter注解,第二步在springboot中声明一个filter注册器即可
@Bean
public Filter generalFilter() {
return new HttpServletFilter();
}
@Bean
public FilterRegistrationBean uploadFilterRegistration() {
FilterRegistrationBean registration = new FilterRegistrationBean();
registration.setFilter(new DelegatingFilterProxy("generalFilter"));
registration.addUrlPatterns("/*");
registration.setName("generalFilter");
registration.setOrder(1);
return registration;
}
2.由于我采用的是先插入静态集合后缓存到redis,所以在没有处理的情况下,未插入到缓存中的日志会出现丢失的情况,这个时候我们要进行相应的事件监听,在整个服务停止的时候,将静态集合日志直接记录到数据库。
监听器代码如下:
package com.youfuli.task.listen;
import com.youfuli.task.mapper.log.TmpLogMapper;
import com.youfuli.task.utils.LogProcess;
import lombok.extern.slf4j.Slf4j;
import org.springframework.beans.factory.annotation.Autowired;
import org.springframework.context.ApplicationEvent;
import org.springframework.context.ApplicationListener;
import org.springframework.context.event.ContextClosedEvent;
import org.springframework.context.event.ContextStoppedEvent;
import org.springframework.stereotype.Component;
import javax.servlet.ServletContextEvent;
import javax.servlet.ServletContextListener;
/**
* @author lxt
*/
@Component
@Slf4j
public class CloseListener implements ApplicationListener<ContextClosedEvent> {
@Autowired
private TmpLogMapper tmpLogMapper;
/**
* 监听tomcat服务关闭
* @param event servletContextEvent
*/
@Override
public void onApplicationEvent(ContextClosedEvent event) {
if(event.getApplicationContext().getParent() == null){
log.info("程序停止");
log.info("tomcat服务器关闭");
int size = LogProcess.LIST.size();
log.info("当前日志集合数量为{}",size);
if(size>0){
int count = tmpLogMapper.insertForeach(LogProcess.LIST);
log.info("数据缓存完成,共缓存数据{}条",count);
}
}
}
}
然后在主启动类中进行注册
SpringApplication.run(TaskApplication.class, args).addApplicationListener(new CloseListener());
哦最后忘了,过滤器需要在主启动类上标注@ServletComponentScan注解
最终通过几个线程进行测试,暂时是没有发现什么问题哈哈