授权登录(Filter)

加入两个jar包:

jstl.jar

standard.jar

logout.jsp
<%@ page language="java" contentType="text/html; charset=UTF-8"
    pageEncoding="UTF-8"%>
<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
<title>Insert title here</title>
</head>
<body>
	
	Bye!
	
	<br><br>
	<a href="login.jsp">Login</a>
	
	<% 
		session.invalidate();
	%>
	
</body>
</html>
login.jsp
<?xml version="1.0" encoding="UTF-8" ?>
<%@ page language="java" contentType="text/html; charset=UTF-8"
    pageEncoding="UTF-8"%>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />
<title>Insert title here</title>
</head>
<body>
	
	<form action="LoginServlet?method=login" method="post">
		name: <input type="text" name="name" />
		<input type="submit" value="Submit" />
	</form>
	
</body>
</html>
authority-manager.jsp
<%@ page language="java" contentType="text/html; charset=UTF-8"
    pageEncoding="UTF-8"%>
<%@ taglib prefix="c" uri="http://java.sun.com/jsp/jstl/core" %>

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
<title>Insert title here</title>
</head>
<body>	
	<center>
		<br><br>
		<form action="AuthorityServlet?method=getAuthorities" method="post">
			name: <input type="text" name="username"/>
			<input type="submit" value="Submit"/>
		</form>
	     
		<c:if test="${requestScope.user != null }">
			<br><br>

			${requestScope.user.username } 的权限是: 
			<br><br>
			<!--  -->
			<form action="AuthorityServlet?method=updateAuthority" method="post">
			    <!-- 知道改的是谁    隐藏信息 -->
				<input type="hidden" name="username" value="${requestScope.user.username }"/> 
				<!-- 通过两层循环的防止筛选权限   获取权限 -->
				<c:forEach items="${authorities }" var="auth">
				    <!--最开始的值  false  -->
					<c:set var="flag" value="false"></c:set>
					  <!--用户的quanxian 被选中  √-->
					<c:forEach items="${user.authorities }" var="ua">
						
						<c:if test="${ua.url == auth.url }">
							<c:set var="flag" value="true"></c:set>
						</c:if>
						
					</c:forEach>
					
					<c:if test="${flag == true }">
						<input type="checkbox" name="authority" 
							value="${auth.url }" checked="checked"/>${auth.displayName }
					</c:if>
					<c:if test="${flag == false }">
						<input type="checkbox" name="authority" 
							value="${auth.url }" />${auth.displayName }
					</c:if>
					
					<br><br>
					
				</c:forEach>
				
				<input type="submit" value="Update"/>
				
			</form>
						
		</c:if>
	
	</center>

</body>
</html>
articles.jsp
<?xml version="1.0" encoding="UTF-8" ?>
<%@ page language="java" contentType="text/html; charset=UTF-8"
    pageEncoding="UTF-8"%>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />
<title>Insert title here</title>
</head>
<body>
	
	<a href="article-1.jsp">Article111 Page</a>
	<br /><br />
	
	<a href="article-2.jsp">Article222 Page</a>
	<br /><br />
	
	<a href="article-3.jsp">Article333 Page</a>
	<br /><br />
	
	<a href="article-4.jsp">Article444 Page</a>
	<br /><br />
	
	<a href="LoginServlet?method=logout">Logout...</a>
	
</body>
</html>
article-1.jsp
<?xml version="1.0" encoding="UTF-8" ?>
<%@ page language="java" contentType="text/html; charset=UTF-8"
    pageEncoding="UTF-8"%>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />
<title>Insert title here</title>
</head>
<body>
	
	
	Article 111

</body>
</html>
403.jsp
<?xml version="1.0" encoding="UTF-8" ?>
<%@ page language="java" contentType="text/html; charset=UTF-8"
    pageEncoding="UTF-8"%>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />
<title>Insert title here</title>
</head>
<body>
	<h4>
		没有对应的权限, 
		请 <a href="${pageContext.request.contextPath }/articles.jsp">返回</a>
	</h4>
</body>
</html>
package com.atguigu.javaweb;

import java.io.IOException;
import java.lang.reflect.Method;
import java.util.List;

import javax.servlet.ServletException;
import javax.servlet.annotation.WebServlet;
import javax.servlet.http.HttpServlet;
import javax.servlet.http.HttpServletRequest;
import javax.servlet.http.HttpServletResponse;

/**
 * Servlet implementation class AuthorityServlet
 */
@WebServlet("/AuthorityServlet")


public class AuthorityServlet extends HttpServlet {
    
	private static final long serialVersionUID = 1L;

	public void doPost(HttpServletRequest request,
			HttpServletResponse response) throws ServletException, IOException {
		String methodName = request.getParameter("method");
		//根据参数调取方法  
		try {
			Method method = getClass().getMethod(methodName, 
					HttpServletRequest.class, HttpServletResponse.class);
			method.invoke(this, request, response);
		} catch (Exception e) {
			e.printStackTrace();
		}
	}
	private UserDao userDao = new UserDao();
	             //查询权限
	public void getAuthorities(HttpServletRequest request,
			HttpServletResponse response) throws ServletException, IOException {
		//获取用户名 
		String username = request.getParameter("username");
		//根据name获取用户信息 
		User user = userDao.get(username);
		//向authority-manager.jsp 页面传参数   名字和权限 
		request.setAttribute("user", user);
		request.setAttribute("authorities", userDao.getAuthorities());
		
		request.getRequestDispatcher("/authority-manager.jsp").forward(request, response);
	}
	
	public void updateAuthority(HttpServletRequest request,
			HttpServletResponse response) throws ServletException, IOException {
		//获取用户名     
		String username = request.getParameter("username");
		//获取修改的权限      值是用户的权限    对数组循环  
		String [] authorities = request.getParameterValues("authority");
		List<Authority> authorityList = userDao.getAuthorities(authorities);
		 //新修改的传入到List中    update是一个List  所以要构建一个List  
		userDao.update(username, authorityList);
		response.sendRedirect(request.getContextPath() + "/authority-manager.jsp");
	}
}
package com.atguigu.javaweb;

import java.util.ArrayList;
import java.util.HashMap;
import java.util.List;
import java.util.Map;

public class UserDao {
      //用户信息
	private static Map<String, User> users;
	//有那些权限
	private static List<Authority> authorities = null;
	    
	static{
		
		authorities = new ArrayList<>();
		authorities.add(new Authority("Article-1", "/article-1.jsp"));
		authorities.add(new Authority("Article-2", "/article-2.jsp"));
		authorities.add(new Authority("Article-3", "/article-3.jsp"));
		authorities.add(new Authority("Article-4", "/article-4.jsp"));
		
		users = new HashMap<String, User>();
		
		User user1 = new User("AAA", authorities.subList(0, 2));
		users.put("AAA", user1);
		
		user1 = new User("BBB", authorities.subList(2, 4));
		users.put("BBB", user1);
		
	}
	
	
	
	User get(String username){
		return users.get(username); 
	}
	//先 从user中获取信息   
	void update(String username, List<Authority> authorities){
		users.get(username).setAuthorities(authorities);
	}
	
	public List<Authority> getAuthorities() {
		return authorities;
	}
	//获取所有的authorities 遍历数组获取的url 
	public List<Authority> getAuthorities(String[] urls) {
		List<Authority> authorities2 = new ArrayList<>();
		//当前所有的authorities
		for(Authority authority: authorities){
			
			if(urls != null){
				for(String url: urls){
					//等的话抽出来  
					if(url.equals(authority.getUrl())){
						authorities2.add(authority);
					}
				}
			}			
		}
		
		return authorities2;
	}
}
package com.atguigu.javaweb;

import java.io.IOException;
import java.lang.reflect.Method;

import javax.servlet.ServletException;
import javax.servlet.annotation.WebServlet;
import javax.servlet.http.HttpServlet;
import javax.servlet.http.HttpServletRequest;
import javax.servlet.http.HttpServletResponse;

/**
 * Servlet implementation class LoginServlet
 */
@WebServlet("/LoginServlet")


/**
 * Servlet implementation class LoginServlet
 */
public class LoginServlet extends HttpServlet {
	
	private static final long serialVersionUID = 1L;

	protected void doGet(HttpServletRequest request, HttpServletResponse response) throws ServletException, IOException {
		doPost(request, response);
	}

	protected void doPost(HttpServletRequest request, HttpServletResponse response) throws ServletException, IOException {
		String methodName = request.getParameter("method");
		
		try {
			Method method = getClass().getMethod(methodName, 
					HttpServletRequest.class, HttpServletResponse.class);
			method.invoke(this, request, response);
		} catch (Exception e) {
			e.printStackTrace();
		}
	}
	
	private UserDao userDao = new UserDao();
	
	public void login(HttpServletRequest request, HttpServletResponse response) throws ServletException, IOException {
		
		String name = request.getParameter("name");
		
		
		User user = userDao.get(name);
		request.getSession().setAttribute("user", user);
		
		
		response.sendRedirect(request.getContextPath() + "/articles.jsp");
	}
	
	public void logout(HttpServletRequest request, HttpServletResponse response) throws ServletException, IOException {
		
		
		
		request.getSession().invalidate();
		
		
		response.sendRedirect(request.getContextPath() + "/login.jsp");
	}
	

}



package com.atguigu.javaweb;

import java.io.IOException;
import java.util.Arrays;
import java.util.List;

import javax.servlet.Filter;
import javax.servlet.FilterChain;
import javax.servlet.FilterConfig;
import javax.servlet.ServletException;
import javax.servlet.ServletRequest;
import javax.servlet.ServletResponse;
import javax.servlet.annotation.WebFilter;
import javax.servlet.http.HttpServletRequest;
import javax.servlet.http.HttpServletResponse;

/**
 * Servlet Filter implementation class AuthorityFilter
 */
@WebFilter("*.jsp")



public class AuthorityFilter extends HttpFilter {

	@Override
	public void doFilter(HttpServletRequest request,
			HttpServletResponse response, FilterChain filterChain)
			throws IOException, ServletException {
        //获取映射路径
		String servletPath = request.getServletPath();
		//不需要过滤的jsp
		List<String> uncheckedUrls = Arrays.asList("/403.jsp", "/articles.jsp", 
				"/authority-manager.jsp", "/login.jsp", "/logout.jsp");
		//放行
		if(uncheckedUrls.contains(servletPath)){
			filterChain.doFilter(request, response);
			return;
		}
		//获取用户名字 
		User user = (User)request.getSession().getAttribute("user");
		if(user == null){
			response.sendRedirect(request.getContextPath() + "/login.jsp");
			return;
		}
		//检验用户是否有权限  
		List<Authority> authorities = user.getAuthorities();
		
		Authority authority = new Authority(null, servletPath);
		//有权限则直接响应 没有 转到 请返回页面
		if (authorities.contains(authority)) {
			filterChain.doFilter(request, response);
			return;
		}
		

		response.sendRedirect(request.getContextPath()+"/403.jsp");
		return;
	}

}

 

package com.atguigu.javaweb;

public class Authority {
	//显示到页面上的权限的名字
	private String displayName;
	//权限对应的 URL 地址: 一个权限对应着一个 URL, 例如 Article-1 -> /article-1.jsp

	private String url;

	public String getDisplayName() {
		return displayName;
	}

	public void setDisplayName(String displayName) {
		this.displayName = displayName;
	}

	public String getUrl() {
		return url;
	}

	public void setUrl(String url) {
		this.url = url;
	}

	public Authority(String displayName, String url) {
		super();
		this.displayName = displayName;
		this.url = url;
	}

	public Authority() {
		// TODO Auto-generated constructor stub
	}

	@Override
	public int hashCode() {
		final int prime = 31;
		int result = 1;
		result = prime * result + ((url == null) ? 0 : url.hashCode());
		return result;
	}

	@Override
	public boolean equals(Object obj) {
		if (this == obj)
			return true;
		if (obj == null)
			return false;
		if (getClass() != obj.getClass())
			return false;
		Authority other = (Authority) obj;
		if (url == null) {
			if (other.url != null)
				return false;
		} else if (!url.equals(other.url))
			return false;
		return true;
	}
	
	
}

 

package com.atguigu.javaweb;

import java.util.List;

public class User {
	private String username;
	private List<Authority> authorities;

	public String getUsername() {
		return username;
	}

	public void setUsername(String username) {
		this.username = username;
	}

	public List<Authority> getAuthorities() {
		return authorities;
	}

	public void setAuthorities(List<Authority> authorities) {
		this.authorities = authorities;
	}

	public User(String username, List<Authority> authorities) {
		super();
		this.username = username;
		this.authorities = authorities;
	}

	public User() {
		// TODO Auto-generated constructor stub
	}
}

 

  • 0
    点赞
  • 1
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值