栈初始化java_java - 使用application.properties中的值初始化过滤器 - 堆栈内存溢出

我想基于IP地址保护我的REST API(jersey2),但是没有Spring Security等的麻烦。 我只需要将一些被授予完全访问权限的IP列入白名单。

为了实现这一点,我想到了将IP放入application.properties并使用Filter强制执行限制。 在使用嵌入式Jetty服务器时,这工作得很好,但是在Tomcat上以战争方式部署应用程序时失败。

我试图读取Filter构造函数和init-method(仅下面片段中所示的构造函数示例)中的属性。 但是,访问存储IP的类字段(字符串ips)时,两者都导致NullPointerException。 另外,使用Enviroment变量似乎也无济于事。

任何帮助表示赞赏。 谢谢!

@Component("RestAuthFilter")

public class RestAuthFilter implements Filter {

private String ips;

public RestAuthFilter() {

try {

final Properties p;

final InputStream input = Thread.currentThread().getContextClassLoader().getResourceAsStream("application.properties");

p = new Properties();

p.load(input);

ips = p.getProperty("whitelist.rest.ips");

} catch(IOException e) {

ips = "127.0.0.1";

}

}

@Override

public void init(final FilterConfig config) throws ServletException {

}

@Override

public void doFilter(final ServletRequest req, final ServletResponse res,

final FilterChain chain) throws ServletException, IOException {

final List allowedIPs = Arrays.asList(ips.split("[,]"));

if(!allowedIPs.contains(req.getRemoteAddr())) {

((HttpServletResponse) res).setStatus(HttpServletResponse.SC_FORBIDDEN, "Not allowed to use REST API!");

} else {

chain.doFilter(req, res);

}

}

@Override

public void destroy() {

}

}

堆栈跟踪:

java.lang.NullPointerException: null

at com.example.RestAuthFilter.doFilter(RestAuthFilter.java:44)

at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:241)

at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:208)

at org.springframework.web.filter.CharacterEncodingFilter.doFilterInternal(CharacterEncodingFilter.java:85)

at org.springframework.web.filter.OncePerRequestFilter.doFilter(OncePerRequestFilter.java:107)

at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:241)

at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:208)

at org.springframework.boot.context.web.ErrorPageFilter.doFilter(ErrorPageFilter.java:113)

at org.springframework.boot.context.web.ErrorPageFilter.access$000(ErrorPageFilter.java:59)

at org.springframework.boot.context.web.ErrorPageFilter$1.doFilterInternal(ErrorPageFilter.java:88)

at org.springframework.web.filter.OncePerRequestFilter.doFilter(OncePerRequestFilter.java:107)

at org.springframework.boot.context.web.ErrorPageFilter.doFilter(ErrorPageFilter.java:106)

at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:241)

at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:208)

at org.apache.catalina.core.StandardWrapperValve.invoke(StandardWrapperValve.java:220)

at org.apache.catalina.core.StandardContextValve.invoke(StandardContextValve.java:122)

at org.apache.catalina.authenticator.AuthenticatorBase.invoke(AuthenticatorBase.java:501)

at org.apache.catalina.core.StandardHostValve.invoke(StandardHostValve.java:170)

at org.apache.catalina.valves.ErrorReportValve.invoke(ErrorReportValve.java:98)

at org.apache.catalina.valves.AccessLogValve.invoke(AccessLogValve.java:950)

at org.apache.catalina.core.StandardEngineValve.invoke(StandardEngineValve.java:116)

at org.apache.catalina.connector.CoyoteAdapter.service(CoyoteAdapter.java:408)

at org.apache.coyote.http11.AbstractHttp11Processor.process(AbstractHttp11Processor.java:1040)

at org.apache.coyote.AbstractProtocol$AbstractConnectionHandler.process(AbstractProtocol.java:607)

at org.apache.tomcat.util.net.JIoEndpoint$SocketProcessor.run(JIoEndpoint.java:313)

at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1145)

at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:615)

at java.lang.Thread.run(Thread.java:745)

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值