1. regist.jsp中提交的有验证码信息
2. RegistServlet中,验证用户提交的信息和验证码生成时的信息是否一致,并进行相应的处理
EasyMall代码改造
ValiImageServlet【把验证码的数据存储到session中】
package com.easymall.ser;
import java.awt.Color;
import java.awt.Font;
import java.awt.Graphics2D;
import java.awt.image.BufferedImage;
import java.io.IOException;
import java.util.Random;
import javax.imageio.ImageIO;
import javax.servlet.ServletException;
import javax.servlet.http.HttpServlet;
import javax.servlet.http.HttpServletRequest;
import javax.servlet.http.HttpServletResponse;
@SuppressWarnings("serial")
public class ValiImageServlet extends HttpServlet {
// 背景参数
private int base = 30;
private int height = base;
private int width = base * 4;
@Override
protected void doGet(HttpServletRequest req, HttpServletResponse resp)
throws ServletException, IOException {
// 禁止浏览器缓存图片
resp.setHeader("Cache-Control", "no-cache");
resp.setHeader("Progma", "no-cache");
resp.setDateHeader("Expires", 0);
// 创建内存中的图片
BufferedImage di = new BufferedImage(width, height,
BufferedImage.TYPE_INT_RGB);
// 获取画布画背景
Graphics2D g2 = (Graphics2D) di.getGraphics();
// 填充矩形
g2.setColor(Color.white);
g2.fillRect(0, 0, width, height);
// 绘制边框
g2.setColor(Color.red);
g2.drawRect(0, 0, width - 1, height - 1);
// 写字并保存到session
String valistr2 = "";
g2.setFont(new Font("微软雅黑", Font.BOLD, 25));
for (int i = 0; i < 4; i++) {
String s = Integer.toString(getRandom(0, 10));
valistr2 += s;
g2.setColor(new Color(getRandom(0, 255), getRandom(0, 255),
getRandom(0, 255)));
int temp = getRandom(-45, 45);
g2.rotate(temp / 180.0 * Math.PI, 10 + 30 * i, 20);
g2.drawString(s, 10 + 30 * i, 20);
g2.rotate(-temp / 180.0 * Math.PI, 10 + 30 * i, 20);
}
System.out.println("当前验证码:" + valistr2);
req.getSession().setAttribute("valistr2", valistr2);
// 画干扰线
for (int i = 0; i < 3; i++) {
g2.setColor(new Color(getRandom(0, 255), getRandom(0, 255),
getRandom(0, 255)));
g2.drawLine(getRandom(0, width), getRandom(0, height),
getRandom(0, width), getRandom(0, height));
}
// 画干扰点
for (int i = 0; i < 5; i++) {
g2.setColor(new Color(getRandom(0, 255), getRandom(0, 255),
getRandom(0, 255)));
g2.drawOval(getRandom(0, width), getRandom(0, height), 5, 5);
}
// 画出图片
ImageIO.write(di, "JPG", resp.getOutputStream());
// 关闭画布
g2.dispose();
}
@Override
protected void doPost(HttpServletRequest req, HttpServletResponse resp)
throws ServletException, IOException {
this.doGet(req, resp);
}
// 获取随机数
private int getRandom(int start, int end) {
Random random = new Random();
return start + random.nextInt(end - start);
}
}
RegistServlet【注册逻辑中添加两个验证码数据的校验过程】
package com.easymall.ser;
import java.io.IOException;
import java.sql.Connection;
import java.sql.PreparedStatement;
import java.sql.ResultSet;
import javax.servlet.ServletContext;
import javax.servlet.ServletException;
import javax.servlet.http.HttpServlet;
import javax.servlet.http.HttpServletRequest;
import javax.servlet.http.HttpServletResponse;
import com.easymall.exception.MsgException;
import com.easymall.utils.MySqlUtils;
@SuppressWarnings("serial")
public class RegisteSer extends HttpServlet {
private Connection conn = null;
private PreparedStatement stat = null;
private ResultSet rs = null;
public void doGet(HttpServletRequest request, HttpServletResponse response)
throws ServletException, IOException {
// 全局变量
try {
// 0.获取应用参数
ServletContext sc = this.getServletContext();
String encode = sc.getInitParameter("encode");
// 1.解决requestpost请求乱码 解决response输出数据乱码
request.setCharacterEncoding(encode);
response.setCharacterEncoding(encode);
response.setContentType("text/html;charset=" + encode);
// 2.获取请求参数
String username = request.getParameter("username");
String password = request.getParameter("password");
String password2 = request.getParameter("password2");
String nickname = request.getParameter("nickname");
String email = request.getParameter("email");
String valistr = request.getParameter("valistr");
// 验证码校验--获取请求参数的验证码,获取session中的验证码,对比并进行相应的操作
String valistr2 = (String) request.getSession().getAttribute(
"valistr2");
if (valistr == null || valistr2 == null
|| !valistr.equals(valistr2)) {
request.setAttribute("msg", "验证码不正确!");
request.getRequestDispatcher(
request.getContextPath() + "/regist.jsp").forward(
request, response);
return;
}
// 3.检查数据有效性 如果有问题 向浏览器报错
if (username == null || "".equals(username)) {
throw new MsgException("用户名不能为空!");
}
if (password == null || "".equals(password)) {
throw new MsgException("密码不能为空!");
}
if (password2 == null || "".equals(password2)) {
throw new MsgException("确认密码不能为空!");
}
if (!password.equals(password2)) {
throw new MsgException("两次密码不一致!");
}
if (nickname == null || "".equals(nickname)) {
throw new MsgException("昵称不能为空!");
}
if (email == null || "".equals(email)) {
throw new MsgException("邮箱不能为空!");
}
if (!email.matches("^\\w+@\\w+(\\.\\w+)+$")) {
throw new MsgException("邮箱格式不正确!");
}
if (valistr == null || "".equals(valistr)) {
throw new MsgException("验证码不能为空!");
}
// 4.存入数据库
// 判断账号是否重复
conn = MySqlUtils.getConn();
stat = conn.prepareStatement("select * from user where username=?");
stat.setString(1, username);
rs = stat.executeQuery();
if (rs.next()) {// 账号重复
throw new MsgException("账号重复");
} else {// 账号不重复
stat = conn
.prepareStatement("insert into user values(?,?,?,?)");// 账号,密码,昵称,邮箱
stat.setString(1, username);
stat.setString(2, password);
stat.setString(3, nickname);
stat.setString(4, email);
stat.executeUpdate();
}
// 5.向浏览器报告成功 回到主页
response.getWriter().write("注册成功!正在前往主页------>>>");
response.setHeader("refresh", "1;url=" + request.getContextPath()
+ "/index.jsp");
} catch (MsgException e) {
String msg = e.getMessage();
response.getWriter().write(msg);
response.setHeader("refresh", "1;url=/regist.jsp");
} catch (Exception e) {
e.printStackTrace();
throw new RuntimeException(e);
} finally {
// 关闭数据库
MySqlUtils.close(conn, stat, rs);
}
}
public void doPost(HttpServletRequest request, HttpServletResponse response)
throws ServletException, IOException {
doGet(request, response);
}
}
代码改造
<%@ page language="java" import="java.util.*" pageEncoding="UTF-8"%>
欢迎注册EasyMall
欢迎注册EasyMall
Cookie | Session | |
---|---|---|
保存时间: | 自行设置 | 默认30分钟 |
位置: | 客户端保存数据 | 服务端保存数据 |
影响: | 有可能随着用户的操作被删除 | 只要不刻意删除对应的数据,在存活期间可以可靠的访问 |
安全性: | 不安全,可以翻看记录来获得相关的信息 | 安全,数据保存在服务器端 |
用途: | 记住用户名 | 一次会话的信息:验证码 |
...
...
...
...
1. 代表当前jsp页面
2. 作为入口参数获取其他八大隐式对象
3. 是一个域对象【request,ServletContext,session,pageContext】
1. 生命周期:访问jsp开始,访问完后销毁
2. 作用范围:当前jsp页面
3. 主要功能:
1. 在当前jsp中共享数据
1. setAttribute(String,Objejct)
2. getAttribute(String)
3. removeAttribute(String)
2. 作为入口对象操作四大作用域对象
1. setAttribute(String name,Objejct obj,int scope)
2. getAttribute(String,int scope)
3. removeAttribute(String,int scope)
4. 对应的域
1. PageContext.APPLICATION_SCOPE
2. PageContext.SESSION_SCOPE
3. PageContext.REQUEST_SCOPE
4. PageContext.PAGE_SCOPE
3. findAttribute(String)
1. 寻找指定的对象
2. 搜寻的顺序【由小到大:pageContext、Request、session、application】
3. 找到返回,找不到返回null
4. 转发pageContext.forward("路径");
5. 包含pageContext.include("路径");