Filter是javaweb的三大组件之一
Filter是一个定义的接口需要你自己去写实现类:
直接上代码:
package cout.pring;
import java.io.BufferedReader;
import java.io.FileReader;
import java.io.IOException;
import java.lang.reflect.InvocationHandler;
import java.lang.reflect.Method;
import java.lang.reflect.Proxy;
import java.util.ArrayList;
import java.util.List;
import javax.servlet.Filter;
import javax.servlet.FilterChain;
import javax.servlet.FilterConfig;
import javax.servlet.ServletContext;
import javax.servlet.ServletException;
import javax.servlet.ServletRequest;
import javax.servlet.ServletResponse;
import javax.servlet.annotation.WebFilter;
/**
* 敏感词汇过滤器
*/
@WebFilter("/*")//拦截所有
public class SensitiveWord implements Filter {
private List<String> list=new ArrayList<String>();//用来存入敏感词汇
public SensitiveWord() {
// TODO Auto-generated constructor stub
}
public void destroy() {//服务器正常关闭执行的
// TODO Auto-generated method stub
}
//主要拦截函数
public void doFilter(ServletRequest request, ServletResponse response, FilterChain chain) throws IOException, ServletException {
System.out.println("被敏感词汇拦截了");
//1.创建代理对象,增强getparameter方法
ServletRequest proxy_request=(ServletRequest) Proxy.newProxyInstance(request.getClass().getClassLoader(), request.getClass().getInterfaces(),new InvocationHandler()
{
// 增强方式:1. 增强参数列表2. 增强返回值类型3. 增强方法体执行逻辑
@Override
//参数:1.proxy:代理对象 2.method代理对象调用的方法,被封装为的对象 3.arrgs:代理对象调用的方法时,传递的实际参数
public Object invoke(Object proxy, Method method, Object[] args) throws Throwable
{
if(method.getName().equals("getParameter"))
{
String value = (String)method.invoke(request, args);//获取request里的数据
if(value!=null)
{
for (String i : list) {
if(value.contains(i))//如果有敏感词汇进行替换
{
value = value.replaceAll(i, "***");
}
}
}
return value;
}
// TODO Auto-generated method stub
return method.invoke(request, args);
}
});
System.out.println("敏感词汇放你走");
chain.doFilter(proxy_request, response);
}
/**
* @see Filter#init(FilterConfig)
*/
public void init(FilterConfig fConfig) throws ServletException {//服务器启动执行,把敏感词汇加载进list;
try {
//1.获取文件真实路径
ServletContext servletContext = fConfig.getServletContext();
String realPath = servletContext.getRealPath("/WEB-INF/classes/SensitiveWord.txt");
BufferedReader br = new BufferedReader(new FileReader(realPath));
String line=null;
while ((line=br.readLine())!=null)
{
list.add(line);
}
br.close();
} catch (Exception e) {
// TODO: handle exception
e.printStackTrace();
}
// TODO Auto-generated method stub
}
}