cookie
当客户端向服务器发出请求时,服务器会向客户端响应若干个cookie信息,包括一些客户端访问的信息
简单示例
import javax.servlet.ServletException;
import javax.servlet.http.Cookie;
import javax.servlet.http.HttpServlet;
import javax.servlet.http.HttpServletRequest;
import javax.servlet.http.HttpServletResponse;
import java.io.IOException;
import java.io.PrintWriter;
import java.util.Date;
public class CookieDemo01 extends HttpServlet {
@Override
protected void doGet(HttpServletRequest req, HttpServletResponse resp) throws ServletException, IOException {
req.setCharacterEncoding("utf-8");
resp.setCharacterEncoding("utf-8");
resp.setContentType("text/html");//设置编码和文本类型
PrintWriter out = resp.getWriter(); //获取响应输出对象
Cookie[] cookies = req.getCookies(); //通过请求获得cookie数组
//cookie.getName() 获得cookie键
//cookie.getValue() 获得cookie值
if (cookies.length==3){ //判断cookie数组长度判断是否为第一次访问页面
for (int i = 0; i < cookies.length; i++) {
if (cookies[i].getName().equals("lastLoginTime")){ //在cookie数组找到lastLoginTime cookie
out.print(new Date(Long.parseLong(cookies[i].getValue())).toLocaleString()); //打印上次访问信息
}
}
}else{
out.print("这是第一次访问页面");
}
resp.addCookie(new Cookie("lastLoginTime",System.currentTimeMillis()+"")); //给客户端响应一个cookie
}
@Override
protected void doPost(HttpServletRequest req, HttpServletResponse resp) throws ServletException, IOException {
doGet(req, resp);
}
}
第一次访问
第二次访问
当关闭浏览器后,默认cookie信息被清除
可以设置cookie生命期保存cookie信息
cookie.setMaxAge(24*60*60); //设置cookie生命期
Session
会话对象,用户一旦访问浏览器,服务器就会为用户创建一个唯一ID的Session对象,默认直到用户关闭浏览器,Session失效
示例
import javax.servlet.ServletException;
import javax.servlet.http.HttpServlet;
import javax.servlet.http.HttpServletRequest;
import javax.servlet.http.HttpServletResponse;
import javax.servlet.http.HttpSession;
import java.io.IOException;
public class SessionDemo02 extends HttpServlet {
@Override
protected void doGet(HttpServletRequest req, HttpServletResponse resp) throws ServletException, IOException {
req.setCharacterEncoding("utf-8");
resp.setCharacterEncoding("utf-8");
resp.setContentType("text/html;charSet=utf-8");
HttpSession session = req.getSession();
session.setAttribute("username","khp"); //存放一个数据
}
@Override
protected void doPost(HttpServletRequest req, HttpServletResponse resp) throws ServletException, IOException {
doGet(req, resp);
}
}
public class SessionDemo01 extends HttpServlet {
@Override
protected void doGet(HttpServletRequest req, HttpServletResponse resp) throws ServletException, IOException {
req.setCharacterEncoding("utf-8");
resp.setCharacterEncoding("utf-8");
resp.setContentType("text/html;charSet=utf-8");
PrintWriter out = resp.getWriter();
//获取session对象
HttpSession session = req.getSession();
//通过请求获取ID及创建时间
out.print(session.getAttribute("username")+" id为:"+session.getId()+"的创建时间为:"+new Date(session.getCreationTime()).toLocaleString());
}
@Override
protected void doPost(HttpServletRequest req, HttpServletResponse resp) throws ServletException, IOException {
doGet(req, resp);
}
}
可以看到除了ServletContext对象,Session对象也可以实现存取数据,对于一个会话,有且仅有一个SessionId
设置Session对象生命期
一般来说,Cookie对象在关闭浏览器后就会消失,当然我们也可以通过一些设置来控制在未关闭浏览器时让Session对象消失
- 在web.xml文件中修改Session有效期
<!-- 设置session有效期为1分钟-->
<session-config>
<session-timeout>1</session-timeout>
</session-config>
- 利用Session对象中的invalidate()销毁Session
session.invalidate();
Session与Cookie的联系与区别
- 联系
我们可以通过cookie信息中找到SessionId,也就是说cookie信息中也会包括SessionId
若显式在cookie信息中添加SessionId等同于
resp.addCookie( new Cookie("JSESSIONID","session.getId()"));
- 区别
- Cookie在浏览器中保存,而Session在服务器端保存
- 用户访问服务器时Cokkie往往有多个,而Session往往很少
- Cookie只能保存String类型数据,而Session可以保存Object类型数据