使用Spring MVC框架,Session和Cookie自己管理
Cookie管理的代码
public class CookieUtil {
public static int COOKIE_MAX_AGE = 60 * 60;//3600s
public static void addCookie(HttpServletResponse response, Cookie cookie) {
if (cookie != null)
response.addCookie(cookie);
}
public static void addCookie(HttpServletResponse response, String cookieName, String cookieValue, String domain, boolean httpOnly, int maxAge, String path, boolean secure) {
if (cookieName != null && !cookieName.equals("")) {
if (cookieValue == null) {
cookieValue = "";
}
Cookie newCookie = new Cookie(cookieName, cookieValue);
if (domain != null) {
newCookie.setDomain(domain);
}
newCookie.setHttpOnly(httpOnly);
if (maxAge > 0) {
newCookie.setMaxAge(maxAge);
}
if (path == null) {
newCookie.setPath("/");
} else {
newCookie.setPath(path);
}
newCookie.setSecure(secure);
addCookie(response, newCookie);
}
}
public static void addCookie(HttpServletResponse response, String cookieName, String cookieValue, String domain) {
addCookie(response, cookieName, cookieValue, domain, true, COOKIE_MAX_AGE, "/", false);
}
public static Cookie getCookie(HttpServletRequest request, String cookieName) {
Cookie[] cookies = request.getCookies();
if (cookies == null || cookieName == null || cookieName.equals("")) {
return null;
}
for (Cookie c : cookies) {
if (c.getName().equals(cookieName))
return c;
}
return null;
}
public static String getCookieValue(HttpServletRequest request, String cookieName) {
Cookie cookie = getCookie(request, cookieName);
if (cookie == null) {
return null;
} else {
return cookie.getValue();
}
}
public static void deleteCookie(HttpServletResponse response, Cookie cookie) {
if (cookie != null) {
cookie.setPath("/");
cookie.setMaxAge(0);
cookie.setValue(null);
response.addCookie(cookie);
}
}
public static void delCookie(HttpServletRequest request, HttpServletResponse response, String cookieName) {
Cookie c = getCookie(request, cookieName);
if (c != null && c.getName().equals(cookieName)) {
deleteCookie(response, c);
}
}
public static void editCookie(HttpServletRequest request, HttpServletResponse response, String cookieName, String cookieValue, String domain) {
Cookie c = getCookie(request, cookieName);
if (c != null && cookieName != null && !cookieName.equals("") && c.getName().equals(cookieName)) {
addCookie(response, cookieName, cookieValue, domain);
}
}
}
复制代码
Session的管理代码
public class SessionUtil {
private static HashMap<String, HttpSession> sessionMap = new HashMap<String, HttpSession>();
public static synchronized void addSession(HttpSession session) {
if (session != null) {
sessionMap.put(session.getId(), session);
}
}
public static synchronized void deleteSession(HttpSession session) {
if (session != null) {
sessionMap.remove(session.getId());
}
}
public static HttpSession getSession(String sessionID) {
if (sessionID == null) {
return null;
}
return sessionMap.get(sessionID);
}
public static HashMap<String, HttpSession> getSessionMap() {
return sessionMap;
}
}
复制代码
开始模拟自动登录
- 首先要监听Session的创建和摧毁
public class SessionListener implements HttpSessionListener {
public void sessionCreated(HttpSessionEvent se) {
System.out.println("创建session......"+se.getSession());
SessionUtil.addSession(se.getSession());
}
public void sessionDestroyed(HttpSessionEvent se) {
System.out.println("摧毁session......"+se.getSession());
SessionUtil.deleteSession(se.getSession());
}
}
复制代码
然后在web.xml中注册listener
<listener>
<listener-class>com.reet.listener.SessionListener</listener-class>
</listener>
复制代码
- 模拟手动登录 这里设置Cookie存在的时常为60s
@RequestMapping("/manual_login")
public String cookie(HttpServletRequest request,HttpServletResponse response) {
HttpSession session = request.getSession(true);
CookieUtil.addCookie(response,"JSESSIONID",session.getId(),"localhost", true, 60, "/", false);
return "forward:/index.html";
}
复制代码
- 模拟自动登录
@RequestMapping("/auto_login")
public String autoLogin(HttpServletRequest request, HttpServletResponse response) {
String sessionID = CookieUtil.getCookieValue(request,"JSESSIONID");
if(sessionID==null||sessionID.equals("")){
return "forward:/login";
}
HttpSession session = SessionUtil.getSession(sessionID);
if(session==null){
return "forward:/login";
}
return "welcome";
}
复制代码
- 这里就是如果一开始没有调用/manual_login,那么cookie为空,sessionID就一定为空,自动forward到输入账号密码的界面
- 当调用了/manual_login,这时在刷新/auto_login,就会自动跳转到welcome界面
- 这时等待60s,再次刷新界面,由于cookie已经失效,这时也就会再次forward到输入账号密码的界面了