防止盗链

1.创建类

package com.hbxy.web.c02.request;


import javax.servlet.RequestDispatcher;
import javax.servlet.ServletException;
import javax.servlet.http.HttpServlet;
import javax.servlet.http.HttpServletRequest;
import javax.servlet.http.HttpServletResponse;
import java.io.IOException;
import java.io.PrintWriter;

public class DownManagerServlet extends HttpServlet {
    public void doGet(HttpServletRequest request,
                      HttpServletResponse response) throws ServletException, IOException {
        response.setContentType("text/html;charset=utf-8");
        PrintWriter out = response.getWriter();
// ??获取referer头的值???
        String referer = request.getHeader("referer");
// ??????获取访问地址
        String sitePart = "http://" + request.getServerName();
// ??判断refer头是否为空,这个投的首地址是否是已???????????????sitePart???开始
        if (referer != null && referer.startsWith(sitePart)) {
// ?????????处理正在下载的请求
            out.println("dealing download ...");
        } else {
// ?????????非法请求跳转到download.html??页面
            RequestDispatcher rd = request.getRequestDispatcher("/myweb/download.html");
            rd.forward(request, response);
        }
    }

    public void doPost(HttpServletRequest request,
                       HttpServletResponse response) throws ServletException, IOException {
        doGet(request, response);
    }
}

2.创建download.html

<!DOCTYPE html>
<html lang="en">
<head>
    <meta charset="UTF-8">
    <title>??下载</title>
</head>
<body>
<a href="/DownManagerServlet">??下载</a>
</body>
</html>

3.配置web.xml

<?xml version="1.0" encoding="UTF-8"?>
<web-app xmlns="http://xmlns.jcp.org/xml/ns/javaee"
         xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://xmlns.jcp.org/xml/ns/javaee http://xmlns.jcp.org/xml/ns/javaee/web-app_3_1.xsd" version="3.1">



  <servlet>
    <servlet-name>DownManagerServlet</servlet-name>
    <servlet-class>com.hbxy.web.c02.request.DownManagerServlet</servlet-class>
  </servlet>
  <servlet-mapping>
    <servlet-name>DownManagerServlet</servlet-name>
    <url-pattern>/DownManagerServlet</url-pattern>
  </servlet-mapping>

</web-app>

测试

????只通过download.html才能下载;如果直接访问 ?????????? ?DownManagerServlet 将跳转到 ???????download.html?

 

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值