19.spring拦截器:用户登录权限控制

 login.jsp

			<form action="${pageContext.request.contextPath}/user/login"
				method="post">
				<div class="form-group has-feedback">
					<input type="text" name="username" class="form-control"
						placeholder="用户名"> <span
						class="glyphicon glyphicon-envelope form-control-feedback"></span>
				</div>
				<div class="form-group has-feedback">
					<input type="password" name="password" class="form-control"
						placeholder="密码"> <span
						class="glyphicon glyphicon-lock form-control-feedback"></span>
				</div>
				<div class="row">
					<div class="col-xs-8">
						<div class="checkbox icheck">
							<label><input type="checkbox"> 记住 下次自动登录</label>
						</div>
					</div>
					<!-- /.col -->
					<div class="col-xs-4">
						<button type="submit" class="btn btn-primary btn-block btn-flat">登录</button>
					</div>
					<!-- /.col -->
				</div>
			</form>

 需要用拦截器对其他方法进行拦截,不然直接输入地址栏就可以访问其他资源,无需登录

package com.itheima.interceptor;

import com.itheima.domain.User;
import org.springframework.web.servlet.HandlerInterceptor;

import javax.servlet.http.HttpServletRequest;
import javax.servlet.http.HttpServletResponse;
import javax.servlet.http.HttpSession;

public class PrivilegeInterceptor implements HandlerInterceptor
{
    public boolean preHandle(HttpServletRequest request, HttpServletResponse response, Object handler) throws Exception
    {
        //判断用户是否登录 判断session中有没有user
        HttpSession session = request.getSession();
        User user = (User) session.getAttribute("user");
        if(user==null)
        {
            //没有登录
            response.sendRedirect("/login.jsp");
            return false;
        }else
        {
            return true;
        }

    }
}

注册拦截器的映射地址

    <mvc:interceptors><!--拦截器只拦截controller中的方法资源路径-->
        <mvc:interceptor>
            <mvc:mapping path="/**"/> <!--对所有方法进行拦截-->
            <mvc:exclude-mapping path="/user/login"/> <!--排除登录方法的拦截-->
            <bean class="com.itheima.interceptor.PrivilegeInterceptor"></bean>
        </mvc:interceptor>
    </mvc:interceptors>

表单提交,执行controller层的方法

@Controller
@RequestMapping("/user")
public class UserController {

    @Autowired
    private UserService userService;

    @Autowired
    private RoleService roleService;

    @RequestMapping("/login")
    public String login(String username, String password, HttpSession session)
    {
        User user = userService.login(username,password);
        if(user!=null)
        {
            session.setAttribute("user",user);
            return "redirect:/pages/main.jsp";
        }else
        {
            return "redirect:/login.jsp";
        }
    }
}

service:

    public User login(String username, String password)
    {
        User user = null;
        try {
            user = userDao.findUserNameAndPassword(username,password);
            return user;
        } catch (EmptyResultDataAccessException e) {
            return null;
        }
    }

Dao:(该方法没查询到,jdbcTemplate抛出EmptyResultDataAccessException,因此需要在service层catch这个方法的异常,把user置为null)

    public User findUserNameAndPassword(String username, String password) throws EmptyResultDataAccessException
    {
        User user = (User) jdbcTemplate.queryForObject("select * from sys_user where username=? and password=?",new BeanPropertyRowMapper(User.class),username,password);
        return user;
    }

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值