拦截器实现用户权限验证

一 领域模型

User

package org.fkit.domain;
import java.io.Serializable;
public class User implements Serializable{
     private static final long serialVersionUID = 1L;
     
     private Integer id;             // id
     private String loginname;  // 登录名
     private String password;   // 密码
     private String username;   // 用户名
     
     public User() {
           super();
           // TODO Auto-generated constructor stub
     }
     public Integer getId() {
           return id;
     }
     public void setId(Integer id) {
           this.id = id;
     }
     public String getLoginname() {
           return loginname;
     }
     public void setLoginname(String loginname) {
           this.loginname = loginname;
     }
     public String getPassword() {
           return password;
     }
     public void setPassword(String password) {
           this.password = password;
     }
     public String getUsername() {
           return username;
     }
     public void setUsername(String username) {
           this.username = username;
     }
     
     @Override
     public String toString() {
           return "User [id=" + id + ", loginname=" + loginname  + ", password="
                     + password + ", username=" + username +  "]";
     }
     
     
}

2 Book

package org.fkit.domain;
import java.io.Serializable;
public class Book implements Serializable{
     
     private static final long serialVersionUID = 1L;
     
     private Integer id;                  // id
     private String name;            // 书名
     private String author;               // 作者
     private Double price;           // 价格
     private String image;           // 封面图片
     
     public Book() {
           super();
           // TODO Auto-generated constructor stub
     }
     public Book( String image,String name, String author,  Double price) {
           super();
           this.image = image;
           this.name = name;
           this.author = author;
           this.price = price;
     }
     public Integer getId() {
           return id;
     }
     public void setId(Integer id) {
           this.id = id;
     }
     public String getName() {
           return name;
     }
     public void setName(String name) {
           this.name = name;
     }
     public String getAuthor() {
           return author;
     }
     public void setAuthor(String author) {
           this.author = author;
     }
     
     public Double getPrice() {
           return price;
     }
     public void setPrice(Double price) {
           this.price = price;
     }
     public String getImage() {
           return image;
     }
     public void setImage(String image) {
           this.image = image;
     }
     @Override
     public String toString() {
           return "Book [id=" + id + ", name=" + name + ",  author=" + author
                     + ", price=" + price + ", image=" + image  + "]";
     }
     
}

二 控制器

BookController

package org.fkit.controller;

import java.util.ArrayList;
import java.util.List;
import org.fkit.domain.Book;
import org.springframework.stereotype.Controller;
import org.springframework.ui.Model;
import org.springframework.web.bind.annotation.RequestMapping;

/**
* 处理图书请求控制器
* */
@Controller
public class BookController {


    /**
     * 处理/main请求
     * */
    @RequestMapping(value="/main")
     public String main(Model model){
        // 模拟数据库获得所有图书集合
        List<Book> book_list = new ArrayList<Book>();
        book_list.add(new Book("java.jpg","疯狂Java讲义(附光盘)","李刚 编著",74.2));
        book_list.add(new Book("ee.jpg","轻量级Java EE企业应用实战","李刚 编著",59.2));
        book_list.add(new Book("android.jpg","疯狂Android讲义(附光盘)","李刚 编著",60.6));
        book_list.add(new Book("ajax.jpg","疯狂Ajax讲义(附光盘)","李刚 编著",66.6));
        // 将图书集合添加到model当中
        model.addAttribute("book_list", book_list);
        // 跳转到main页面
        return "main";
    }
    
}

FormController

package org.fkit.controller;

import org.springframework.stereotype.Controller;
import org.springframework.web.bind.annotation.GetMapping;


/**
* 动态页面跳转控制器
* */
@Controller
public class FormController{

    @GetMapping(value="/loginForm")
     public String loginForm(){
        // 跳转到登录页面
        return "loginForm";
    }

}

UserController

package org.fkit.controller;

import javax.servlet.http.HttpSession;

import org.fkit.domain.User;
import org.springframework.stereotype.Controller;
import org.springframework.web.bind.annotation.PostMapping;
import org.springframework.web.servlet.ModelAndView;

/**
* 处理用户请求控制器
* */
@Controller
public class UserController {

    /**
     * 处理/login请求
     * */
    @PostMapping(value="/login")
     public ModelAndView login(
             String loginname,String password,
             ModelAndView mv,
             HttpSession session){
        // 模拟数据库根据登录名和密码查找用户,判断用户登录
        if(loginname != null && loginname.equals("fkit")
                && password!= null && password.equals("123456")){
            // 模拟创建用户
            User user = new User();
            user.setLoginname(loginname);
            user.setPassword(password);
            user.setUsername("管理员");
            // 登录成功,将user对象设置到HttpSession作用范围域
            session.setAttribute("user", user);
            // 转发到main请求
            mv.setViewName("redirect:main");
        }else{
            // 登录失败,设置失败提示信息,并跳转到登录页面
            mv.addObject("message", "登录名或密码错误,请重新输入!");
            mv.setViewName("loginForm");
        }
        return mv;
    }
    
    
}

三 拦截器

package org.fkit.interceptor;

import javax.servlet.http.HttpServletRequest;
import javax.servlet.http.HttpServletResponse;
import org.fkit.domain.User;
import org.springframework.web.servlet.HandlerInterceptor;
import org.springframework.web.servlet.ModelAndView;

/**
* 拦截器必须实现HandlerInterceptor接口
* */
public class AuthorizationInterceptor  implements HandlerInterceptor {

    // 不拦截"/loginForm"和"/login"请求
    private static final String[] IGNORE_URI = {"/loginForm", "/login"};
    
     /**
     * 该方法将在整个请求完成之后执行, 主要作用是用于清理资源的,
     * 该方法也只能在当前Interceptor的preHandle方法的返回值为true时才会执行。
     */  
    @Override
    public void afterCompletion(HttpServletRequest request,
            HttpServletResponse response, Object handler, Exception exception)
            throws Exception {
        System.out.println("AuthorizationInterceptor afterCompletion --> ");
        
    }
    /**
     * 该方法将在Controller的方法调用之后执行, 方法中可以对ModelAndView进行操作 ,
     * 该方法也只能在当前Interceptor的preHandle方法的返回值为true时才会执行。
     */
    @Override
    public void postHandle(HttpServletRequest request, HttpServletResponse response,
            Object handler, ModelAndView mv) throws Exception {
        System.out.println("AuthorizationInterceptor postHandle --> ");
        
    }

     /**
     * preHandle方法是进行处理器拦截用的,该方法将在Controller处理之前进行调用,
     * 该方法的返回值为true拦截器才会继续往下执行,该方法的返回值为false的时候整个请求就结束了。
     */  
    @Override
    public boolean preHandle(HttpServletRequest request, HttpServletResponse response,
            Object handler) throws Exception {
        System.out.println("AuthorizationInterceptor preHandle --> ");
        // flag变量用于判断用户是否登录,默认为false
        boolean flag = false;
        //获取请求的路径进行判断
        String servletPath = request.getServletPath();
        // 判断请求是否需要拦截
        for (String s : IGNORE_URI) {
            if (servletPath.contains(s)) {
                flag = true;
                break;
            }
        }
        // 拦截请求
        if (!flag){
            // 1.获取session中的用户
            User user = (User) request.getSession().getAttribute("user");
            // 2.判断用户是否已经登录
            if(user == null){
                // 如果用户没有登录,则设置提示信息,跳转到登录页面
                 System.out.println("AuthorizationInterceptor拦截请求:");
                 request.setAttribute("message", "请先登录再访问网站");
                 request.getRequestDispatcher("loginForm").forward(request, response);
            }else{
                // 如果用户已经登录,则验证通过,放行
                 System.out.println("AuthorizationInterceptor放行请求:");
                 flag = true;
            }
        }
        return flag;
        
    }

}

四 配置文件

<?xml version="1.0" encoding="UTF-8"?>
<beans xmlns="http://www.springframework.org/schema/beans"
    xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
    xmlns:p="http://www.springframework.org/schema/p"
    xmlns:c="http://www.springframework.org/schema/c"
    xmlns:mvc="http://www.springframework.org/schema/mvc"
     xmlns:context="http://www.springframework.org/schema/context"
    xsi:schemaLocation="
        http://www.springframework.org/schema/beans
         http://www.springframework.org/schema/beans/spring-beans.xsd
        http://www.springframework.org/schema/mvc
        http://www.springframework.org/schema/mvc/spring-mvc.xsd     
        http://www.springframework.org/schema/context
         http://www.springframework.org/schema/context/spring-context.xsd">
        
    <!-- spring可以自动去扫描base-pack下面的包或者子包下面的java文件,
      如果扫描到有Spring的相关注解的类,则把这些类注册为Spring的bean  -->
    <context:component-scan base-package="org.fkit.controller"/>
    <!-- 默认装配方案 -->
    <mvc:annotation-driven/>
     <!-- 静态资源处理 -->
    <mvc:default-servlet-handler/>
        
    <!-- 视图解析器  p:prefix属性表示前缀  p:suffix 表示后缀  -->
     <bean id="viewResolver"
           class="org.springframework.web.servlet.view.InternalResourceViewResolver"
          p:prefix="/WEB-INF/content/" p:suffix=".jsp"/>
    
    <mvc:interceptors>
      <mvc:interceptor>
           <mvc:mapping path="/*"/>
           <!-- 使用bean定义一个Interceptor,直接定义在mvc:interceptors下面的Interceptor将拦截所有的请求 -->  
           <bean  class="org.fkit.interceptor.AuthorizationInterceptor"/>
      </mvc:interceptor>
    </mvc:interceptors>
    
</beans>

五 视图

1 loginForm.jsp

<%@ page language="java" contentType="text/html; charset=UTF-8"
    pageEncoding="UTF-8"%>
<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"  "http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<meta http-equiv="Content-Type" content="text/html;  charset=UTF-8">
<title>登录页面</title>
</head>
<body>
<h3>登录页面</h3>
<form action="login" method="post">
     <!-- 提示信息 -->
     <font color="red">${requestScope.message }</font>
     <table>
         <tr>
            <td><label>登录名: </label></td>
             <td><input type="text" id="loginname"  name="loginname" ></td>
         </tr>
         <tr>
            <td><label>密码: </label></td>
             <td><input type="password" id="password"  name="password" ></td>
         </tr>
         <tr>
             <td><input type="submit" value="登录"></td>
         </tr>
     </table>
</form>
</body>
</html>

2 main.jsp

<%@ page language="java" contentType="text/html; charset=UTF-8"
    pageEncoding="UTF-8"%>
<%@ taglib uri="http://java.sun.com/jsp/jstl/core" prefix="c" %>
<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"  "http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<meta http-equiv="Content-Type" content="text/html;  charset=UTF-8">
<title>首页</title>
<style type="text/css">
     table{border-collapse:collapse;border-spacing:0;border-left:1px  solid #888;border-top:1px solid #888;background:#efefef;}
     th,td{border-right:1px solid #888;border-bottom:1px solid  #888;padding:5px 15px;}
     th{font-weight:bold;background:#ccc;}
</style>
</head>
<body>
<h3>欢迎[${sessionScope.user.username }]访问</h3>

<table border="1">
     <tr>
           <th>封面</th><th>书名</th><th>作者</th><th>价格</th>
     </tr>
     <c:forEach items="${requestScope.book_list }" var="book">
           <tr>
                <td><img src="images/${book.image }"  height="60"></td>
                <td>${book.name }</td>
                <td>${book.author }</td>
                <td>${book.price }</td>
           </tr>
     </c:forEach>
</table>
</body>
</html>

六 测试

 

  • 2
    点赞
  • 4
    收藏
    觉得还不错? 一键收藏
  • 0
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值