JavaWeb同步学习笔记之八十、JavaWeb_权限过滤代码实现

JavaWeb_权限过滤代码实现

权限过滤代码实现

  • 1.login.jsp
<%@ page language="java" contentType="text/html; charset=UTF-8"
    pageEncoding="UTF-8"%>
<!DOCTYPE html>
<html>
<head>
<meta charset="UTF-8">
<title>Insert title here</title>
</head>
<body>

	<form action="/Filter_1/loginServlet?method=login" method="post">
		
		uername:<input type="text" name="userName">
		<input type="submit" value="Submit" />
		
	</form>

</body>
</html>
  • 2.article-1.jsp
<%@ page language="java" contentType="text/html; charset=UTF-8"
    pageEncoding="UTF-8"%>
<!DOCTYPE html>
<html>
<head>
<meta charset="UTF-8">
<title>Insert title here</title>
</head>
<body>

	Article 111

</body>
</html>
  • 3.article-2.jsp
<%@ page language="java" contentType="text/html; charset=UTF-8"
    pageEncoding="UTF-8"%>
<!DOCTYPE html>
<html>
<head>
<meta charset="UTF-8">
<title>Insert title here</title>
</head>
<body>

	Article 222

</body>
</html>
  • 4.article-3.jsp
<%@ page language="java" contentType="text/html; charset=UTF-8"
    pageEncoding="UTF-8"%>
<!DOCTYPE html>
<html>
<head>
<meta charset="UTF-8">
<title>Insert title here</title>
</head>
<body>

	Article 333

</body>
</html>
  • 5.article-4.jsp
<%@ page language="java" contentType="text/html; charset=UTF-8"
    pageEncoding="UTF-8"%>
<!DOCTYPE html>
<html>
<head>
<meta charset="UTF-8">
<title>Insert title here</title>
</head>
<body>

	Article 444

</body>
</html>
  • 6.articles.jsp
<%@ page language="java" contentType="text/html; charset=UTF-8"
    pageEncoding="UTF-8"%>
<!DOCTYPE html>
<html>
<head>
<meta charset="UTF-8">
<title>Insert title here</title>
</head>
<body>

	<a href="article-1.jsp">Article111 Page</a>
	<br/><br/>
	
	<a href="article-2.jsp">Article222 Page</a>
	<br/><br/>
	
	<a href="article-3.jsp">Article333 Page</a>
	<br/><br/>
	
	<a href="article-4.jsp">Article444 Page</a>
	<br/><br/>
	
	<a href="/Filter_1/loginServlet?method=logout">Logout...</a>

</body>
</html>
  • 7.authority-manager.jsp
<%@ page language="java" contentType="text/html; charset=UTF-8"
    pageEncoding="UTF-8"%>
<%@ taglib prefix="c" uri="http://java.sun.com/jsp/jstl/core" %>
<!DOCTYPE html>
<html>
<head>
<meta charset="UTF-8">
<title>Insert title here</title>
</head>
<body>

	<center>
		
		<br><br>
		<form action="/Filter_1/authorityServlet?method=getAuthority" method="post">
			username:<input type="text" name="userName"/>
			<input type="submit" value="Submit">
		</form>
		
		<c:if test="${requestScope.user != null }">
			<br><br>
			
			${requestScope.user.userName }的权限是:
			<br><br>
			
			<form action="/Filter_1/authorityServlet?method=updateAuthority" method="post">
				
				<input type="hidden" name="userName" value="${requestScope.user.userName }"/>
				
				<c:forEach items="${authorities }" var="auth">
				<c:set var="flag" value="false"></c:set>
					
					<c:forEach items="${user.authorities }" var="ua">
						<c:if test="${ua.url == auth.url }">
							<c:set var="flag" value="true"></c:set>
						</c:if>
					</c:forEach>
					<c:if test="${flag == true }">
						<input type="checkbox" name="authority" value="${auth.url }" checked="checked" />${auth.displayName }
					</c:if>
					<c:if test="${flag == false }">
						<input type="checkbox" name="authority" value="${auth.url }" />${auth.displayName }
					</c:if>
					<br><br>
					
				</c:forEach>
				
				<input type="submit" value="Update">
				
			</form>
			
			<br><br>
		</c:if>
		
	</center>
		

</body>
</html>
  • 8.403.jsp
<%@ page language="java" contentType="text/html; charset=UTF-8"
	pageEncoding="UTF-8"%>
<!DOCTYPE html>
<html>
<head>
<meta charset="UTF-8">
<title>Insert title here</title>
</head>
<body>

	<h4>
		没有对应的权限, 请 <a href="${pageContext.request.contextPath }/app/articles.jsp">返回</a>
	</h4>

</body>
</html>
  • 9.Authority.java
/**  
 * All rights Reserved,Designed By XS
 * @Title: Authority.java
 * @Package com.xs.javaweb
 * @Description: TODO
 * @author: XS
 * @date: 2019年3月18日 上午10:43:22
 * @version V1.0
 */
package com.xs.javaweb;

/**   
 * @ClassName: Authority
 * @Description: TODO
 * @author: XS
 * @date: 2019年3月18日 上午10:43:22
 * @version V1.0
 */
public class Authority {
	
	private String displayName;
	
	private String url;

	/**   
	 * <p>Title: hashCode</p>
	 * <p>Description: </p>
	 * @see java.lang.Object#hashCode()
	 * @return
	 */
	@Override
	public int hashCode() {
		final int prime = 31;
		int result = 1;
		result = prime * result + ((url == null) ? 0 : url.hashCode());
		return result;
	}

	/**   
	 * <p>Title: equals</p>
	 * <p>Description: </p>
	 * @see java.lang.Object#equals(java.lang.Object)
	 * @param obj
	 * @return
	 */
	@Override
	public boolean equals(Object obj) {
		if (this == obj)
			return true;
		if (obj == null)
			return false;
		if (getClass() != obj.getClass())
			return false;
		Authority other = (Authority) obj;
		if (url == null) {
			if (other.url != null)
				return false;
		} else if (!url.equals(other.url))
			return false;
		return true;
	}

	/**  
	 * @return the displayName
	 */
	public String getDisplayName() {
		return displayName;
	}

	/**  
	 * @param displayName: the displayName to set
	 */
	public void setDisplayName(String displayName) {
		this.displayName = displayName;
	}

	/**  
	 * @return the url
	 */
	public String getUrl() {
		return url;
	}

	/**  
	 * @param url: the url to set
	 */
	public void setUrl(String url) {
		this.url = url;
	}

	/**   
	 * @Title: Authority
	 * @Description: TODO
	 * @param displayName
	 * @param url
	 */
	public Authority(String displayName, String url) {
		super();
		this.displayName = displayName;
		this.url = url;
	}

	/**   
	 * @Title: Authority
	 * @Description: TODO
	 */
	public Authority() {
		super();
	}

	/**   
	 * <p>Title: toString</p>
	 * <p>Description: </p>
	 * @see java.lang.Object#toString()
	 * @return
	 */
	@Override
	public String toString() {
		return "Authority [displayName=" + displayName + ", url=" + url + "]";
	}
	
	

}
  • 10.AuthotityServlet.java
package com.xs.javaweb;

import java.io.IOException;
import java.lang.reflect.Method;
import java.util.List;

import javax.servlet.ServletException;
import javax.servlet.annotation.WebServlet;
import javax.servlet.http.HttpServlet;
import javax.servlet.http.HttpServletRequest;
import javax.servlet.http.HttpServletResponse;

@WebServlet("/authorityServlet")
public class AuthorityServlet extends HttpServlet {

	private static final long serialVersionUID = 1L;

	/**
	 * <p>
	 * Title: doGet
	 * </p>
	 * <p>
	 * Description:
	 * </p>
	 * 
	 * @see javax.servlet.http.HttpServlet#doGet(javax.servlet.http.HttpServletRequest,
	 *      javax.servlet.http.HttpServletResponse)
	 * @param req
	 * @param resp
	 * @throws ServletException
	 * @throws IOException
	 */
	@Override
	protected void doGet(HttpServletRequest req, HttpServletResponse resp) throws ServletException, IOException {
		doPost(req, resp);
	}

	/**
	 * <p>
	 * Title: doPost
	 * </p>
	 * <p>
	 * Description:
	 * </p>
	 * 
	 * @see javax.servlet.http.HttpServlet#doPost(javax.servlet.http.HttpServletRequest,
	 *      javax.servlet.http.HttpServletResponse)
	 * @param request
	 * @param response
	 * @throws ServletException
	 * @throws IOException
	 */
	protected void doPost(HttpServletRequest request, HttpServletResponse response)
			throws ServletException, IOException {

		String methodName = request.getParameter("method");
		
		
		try {
			Method method = getClass().getMethod(methodName, HttpServletRequest.class, HttpServletResponse.class);
			method.invoke(this, request, response);
		} catch (Exception e) {
			e.printStackTrace();
		}

	}

	private UserDAO userDAO = new UserDAO();

	/**
	 * @Title: getAuthority
	 * @Description: TODO
	 * @param request
	 * @param response
	 * @throws ServletException
	 * @throws IOException
	 * @return void
	 */
	public void getAuthority(HttpServletRequest request, HttpServletResponse response)
			throws ServletException, IOException {

		String userName = request.getParameter("userName");
		User user = userDAO.get(userName);

		request.setAttribute("user", user);
		request.setAttribute("authorities", userDAO.getAuthorities());
		request.getRequestDispatcher("/app/authority-manager.jsp").forward(request, response);

	}

	public void updateAuthority(HttpServletRequest request, HttpServletResponse response)
			throws ServletException, IOException {
		
		String userName = request.getParameter("userName");
		
		String [] authorities = request.getParameterValues("authority");
		
		List<Authority> authorityList = userDAO.getAuthorities(authorities);
		
		
		
		userDAO.update(userName, authorityList);
		
		response.sendRedirect(request.getContextPath() + "/app/authority-manager.jsp");
		
		
	}

}

  • 11.User.java
/**  
 * All rights Reserved,Designed By XS
 * @Title: User.java
 * @Package com.xs.javaweb
 * @Description: TODO
 * @author: XS
 * @date: 2019年3月18日 上午10:43:33
 * @version V1.0
 */
package com.xs.javaweb;

import java.util.List;

/**   
 * @ClassName: User
 * @Description: TODO
 * @author: XS
 * @date: 2019年3月18日 上午10:43:33
 * @version V1.0
 */
public class User {
	
	/**   
	 * <p>Title: toString</p>
	 * <p>Description: </p>
	 * @see java.lang.Object#toString()
	 * @return
	 */
	@Override
	public String toString() {
		return "User [userName=" + userName + ", authorities=" + authorities + "]";
	}

	private String userName;
	
	private List<Authority> authorities;

	/**  
	 * @return the userName
	 */
	public String getUserName() {
		return userName;
	}

	/**  
	 * @param userName: the userName to set
	 */
	public void setUserName(String userName) {
		this.userName = userName;
	}

	/**  
	 * @return the authorities
	 */
	public List<Authority> getAuthorities() {
		return authorities;
	}

	/**  
	 * @param authorities: the authorities to set
	 */
	public void setAuthorities(List<Authority> authorities) {
		this.authorities = authorities;
	}

	/**   
	 * @Title: User
	 * @Description: TODO
	 * @param userName
	 * @param authorities
	 */
	public User(String userName, List<Authority> authorities) {
		super();
		this.userName = userName;
		this.authorities = authorities;
	}

	/**   
	 * @Title: User
	 * @Description: TODO
	 */
	public User() {
		super();
	}
	
}
  • 12.UserDAO.java
/**  
 * All rights Reserved,Designed By XS
 * @Title: UserDAO.java
 * @Package com.xs.javaweb
 * @Description: TODO
 * @author: XS
 * @date: 2019年3月18日 上午10:46:28
 * @version V1.0
 */
package com.xs.javaweb;

import java.util.ArrayList;
import java.util.HashMap;
import java.util.List;
import java.util.Map;

/**
 * @ClassName: UserDAO
 * @Description: TODO
 * @author: XS
 * @date: 2019年3月18日 上午10:46:28
 * @version V1.0
 */
public class UserDAO {

	private static Map<String, User> users;

	private static List<Authority> authorities = null;

	static {

		authorities = new ArrayList<>();

		authorities.add(new Authority("Article-1", "/app/article-1.jsp"));
		authorities.add(new Authority("Article-2", "/app/article-2.jsp"));
		authorities.add(new Authority("Article-3", "/app/article-3.jsp"));
		authorities.add(new Authority("Article-4", "/app/article-4.jsp"));

		users = new HashMap<String, User>();

		User user1 = new User("AAA", authorities.subList(0, 2));
		users.put("AAA", user1);

		User user2 = new User("BBB", authorities.subList(2, 4));
		users.put("BBB", user2);

	}

	public User get(String userName) {
		return users.get(userName);
	}

	public void update(String userName, List<Authority> authorities) {
		users.get(userName).setAuthorities(authorities);

	}
	
	public List<Authority> getAuthorities() {
		return authorities;
	}

	/**   
	 * @Title: getAuthorities
	 * @Description: TODO
	 * @param authorities2
	 * @return 
	 * @return List<Authority>
	 */
	public List<Authority> getAuthorities(String[] urls) {
		List<Authority> authorities2 = new ArrayList<>();
		
		for (Authority authority: authorities) {
			if (urls != null) {
				for (String url: urls) {
					if (url.equals(authority.getUrl())) {
						authorities2.add(authority);
					}
					
				}
			}
			
		}
		
		return authorities2;
	}

}
  • 13.HttpFilter.java
/**  
 * All rights Reserved,Designed By XS
 * @Title: HttpFilter.java
 * @Package com.xs.javaweb
 * @Description: TODO
 * @author: XS
 * @date: 2019年3月17日 上午10:05:01
 * @version V1.0
 */
package com.xs.javaweb;

import java.io.IOException;

import javax.servlet.Filter;
import javax.servlet.FilterChain;
import javax.servlet.FilterConfig;
import javax.servlet.ServletException;
import javax.servlet.ServletRequest;
import javax.servlet.ServletResponse;
import javax.servlet.http.HttpServletRequest;
import javax.servlet.http.HttpServletResponse;

/**
 * @ClassName: HttpFilter
 * @Description: TODO 自定义的HttpFilter,实现 Filter 接口
 * @author: XS
 * @date: 2019年3月17日 上午10:05:01
 * @version V1.0
 */
public abstract class HttpFilter implements Filter {

	// 用于保存FilterConfig对象
	private FilterConfig FilterConfig;

	/**
	 * <p>
	 * Title: init
	 * </p>
	 * <p>
	 * Description: 不建议子类直接覆盖,若直接覆盖,将可能会导致filterConfig成员变量初始化失败。
	 * </p>
	 * 
	 * @see javax.servlet.Filter#init(javax.servlet.FilterConfig)
	 * @param filterConfig
	 * @throws ServletException
	 */
	@Override
	public void init(FilterConfig filterConfig) throws ServletException {

		this.FilterConfig = filterConfig;
		init();

	}

	/**
	 * @Title: init
	 * @Description: TODO 供子类继承的初始化方法。可以通过getFilterConfig() 获取FilterConfig对象。
	 * @return void
	 */
	protected void init() {
	}

	/**
	 * @Title: getFilterConfig
	 * @Description: TODO 直接返回init(ServletConfig)的FilterConfig对象
	 * @return
	 * @return FilterConfig
	 */
	public FilterConfig getFilterConfig() {
		return FilterConfig;
	}

	/**
	 * <p>
	 * Title: destroy
	 * </p>
	 * <p>
	 * Description: 空地destroy方法。
	 * </p>
	 * 
	 * @see javax.servlet.Filter#destroy()
	 */
	@Override
	public void destroy() {

	}

	/**
	 * <p>
	 * Title: doFilter
	 * </p>
	 * <p>
	 * Description: 原生的doFilter方法,在方法内部把ServletRequest和ServletResponse
	 * 转为了HttpServletRequest和HttpServletResponse,并调用了 doFilter(HttpServletRequest
	 * request, HttpServletResponse response, FilterChain chain)
	 * 
	 * 若编写Filter的过滤方法不建议直接继承该方法,而建议继承 doFilter(HttpServletRequest request,
	 * HttpServletResponse response, FilterChain chain) 方法
	 * </p>
	 * 
	 * @see javax.servlet.Filter#doFilter(javax.servlet.ServletRequest,
	 *      javax.servlet.ServletResponse, javax.servlet.FilterChain)
	 * @param request
	 * @param response
	 * @param chain
	 * @throws IOException
	 * @throws ServletException
	 */
	@Override
	public void doFilter(ServletRequest req, ServletResponse resp, FilterChain chain)
			throws IOException, ServletException {

		HttpServletRequest request = (HttpServletRequest) req;
		HttpServletResponse response = (HttpServletResponse) resp;

		doFilter(request, response, chain);

	}

	/**
	 * @Title: doFilter
	 * @Description: TODO 抽象方法,为Http请求定制,必须实现的方法。
	 * @param request
	 * @param response
	 * @param chain
	 * @throws IOException
	 * @throws ServletException
	 * @return void
	 */
	public abstract void doFilter(HttpServletRequest request, HttpServletResponse response, FilterChain chain)
			throws IOException, ServletException;

}

  • 14.AuthorityFilter.java
package com.xs.javaweb;

import java.io.IOException;
import java.util.Arrays;
import java.util.List;

import javax.servlet.FilterChain;
import javax.servlet.ServletException;
import javax.servlet.annotation.WebFilter;
import javax.servlet.http.HttpServletRequest;
import javax.servlet.http.HttpServletResponse;

/**
 * Servlet Filter implementation class AuthorityFilter
 */
@WebFilter("*.jsp")
public class AuthorityFilter extends HttpFilter {

	/**   
	 * <p>Title: doFilter</p>
	 * <p>Description: </p>
	 * @see com.xs.javaweb.HttpFilter#doFilter(javax.servlet.http.HttpServletRequest, javax.servlet.http.HttpServletResponse, javax.servlet.FilterChain)
	 * @param request
	 * @param response
	 * @param chain
	 * @throws IOException
	 * @throws ServletException
	 */
	@Override
	public void doFilter(HttpServletRequest request, HttpServletResponse response, FilterChain chain)
			throws IOException, ServletException {

		String servletPath = request.getServletPath();
		
		List<String> uncheckedUrls = Arrays.asList("/app/403.jsp", "/app/articles.jsp", "/app/authority-manager.jsp", "/app/login.jsp", "/app/logout.jsp");
		
		if (uncheckedUrls.contains(servletPath)) {
			
			chain.doFilter(request, response);
			return;
			
		}
		
		User user = (User)request.getSession().getAttribute("user");
		if (user == null) {
			
			response.sendRedirect(request.getContextPath() + "/app/login.jsp");
			return;
			
		}
		
		List<Authority> authorities = user.getAuthorities();
		
		Authority authority = new Authority(null, servletPath);
		
		
		if (authorities.contains(authority)) {
			
			chain.doFilter(request, response);
			return;
			
		}
		
		response.sendRedirect(request.getContextPath() + "/app/403.jsp");
		return;
		
	}

}

  • 15.LoginServlet.java
package com.xs.javaweb;

import java.io.IOException;
import java.lang.reflect.Method;

import javax.servlet.ServletException;
import javax.servlet.annotation.WebServlet;
import javax.servlet.http.HttpServlet;
import javax.servlet.http.HttpServletRequest;
import javax.servlet.http.HttpServletResponse;

/**
 * Servlet implementation class LoginServlet
 */
@WebServlet("/loginServlet")
public class LoginServlet extends HttpServlet {
	
	private static final long serialVersionUID = 1L;

	private UserDAO userDAO = new UserDAO();
	
	/**
	 * @see HttpServlet#doGet(HttpServletRequest request, HttpServletResponse
	 *      response)
	 */
	protected void doGet(HttpServletRequest request, HttpServletResponse response)
			throws ServletException, IOException {

		doPost(request, response);
	}

	/**
	 * @see HttpServlet#doPost(HttpServletRequest request, HttpServletResponse
	 *      response)
	 */
	protected void doPost(HttpServletRequest request, HttpServletResponse response)
			throws ServletException, IOException {

		String methodName = request.getParameter("method");

		try {
			Method method = getClass().getMethod(methodName, HttpServletRequest.class, HttpServletResponse.class);
			method.invoke(this, request, response);
		} catch (Exception e) {
			e.printStackTrace();
		}

	}

	public void login(HttpServletRequest request, HttpServletResponse response)
			throws ServletException, IOException {
		
		String userName = request.getParameter("userName");
		
		User user = userDAO.get(userName);
		request.getSession().setAttribute("user", user);
		
		response.sendRedirect(request.getContextPath() + "/app/articles.jsp");
		

	}

	public void logout(HttpServletRequest request, HttpServletResponse response)
			throws ServletException, IOException {
		
		request.getSession().invalidate();
		
		response.sendRedirect(request.getContextPath() + "/app/login.jsp");

	}

}

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值