FormServlet
package cn.itcast; import java.io.IOException; import java.security.MessageDigest; import java.security.NoSuchAlgorithmException; import java.util.Random; import javax.servlet.ServletException; import javax.servlet.http.HttpServlet; import javax.servlet.http.HttpServletRequest; import javax.servlet.http.HttpServletResponse; import sun.misc.BASE64Encoder; public class FormServlet extends HttpServlet { public void doGet(HttpServletRequest request, HttpServletResponse response) throws ServletException, IOException { /* * 产生随机数,用Session带给form.jsp产生表单 * form.jsp表单 提交给DoFormServlet验证处理,防止重复提交 */ TokenProcessor tp=TokenProcessor.getInstance(); String token=tp.generateToken(); //用Session带token给form.jsp的hidden,并产生表单 request.getSession().setAttribute("token", token); request.getRequestDispatcher("/form.jsp").forward(request, response); } public void doPost(HttpServletRequest request, HttpServletResponse response) throws ServletException, IOException { doGet(request, response); } } class TokenProcessor{ /* * 单例3步走:构造私有,自已new个,提供公开方法 */ private TokenProcessor(){} private static final TokenProcessor instance=new TokenProcessor(); public static TokenProcessor getInstance(){ return instance; } public String generateToken(){ /* * 重点:核心先取得token的md5摘要算法的数据指纹, * 即摘要计算后的字节数组 * 然后将字节数组经base64编码成明文字符串返回 */ String token=System.currentTimeMillis()+new Random().nextInt()+""; /* * 如果没有 Provider 支持指定算法的 MessageDigestSpi 实现 * 会报NoSuchAlgorithmException异常 */ try { MessageDigest md=MessageDigest.getInstance("md5"); byte[] md5=md.digest(token.getBytes()); BASE64Encoder encoder=new BASE64Encoder(); token=encoder.encode(md5); return token; } catch (NoSuchAlgorithmException e) { throw new RuntimeException(); } } }
form.jsp
<%@ page language="java" import="java.util.*" pageEncoding="UTF-8"%> <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <html> <head> <title>My JSP 'form.jsp' starting page</title> <meta http-equiv="pragma" content="no-cache"> <meta http-equiv="cache-control" content="no-cache"> <meta http-equiv="expires" content="0"> </head> <body> 由FormServlet产生token,跳本form.jsp页面显示,提交DoformServlet处理 <script type="text/javascript"> var flag=false; function Check(){ if(!flag){ flag=true; return true; }else{ return false; } } </script> <form action="/day04/servlet/DoformServlet" method="post" onsubmit="return Check()"> 用户名:<input type="text" name="username"/> 密 码:<input type="password" name="password"/> <input type="hidden" name="token" value="${token }"/> <input type="submit" value="注册"/> </form> </body> </html>
DoformServlet
package cn.itcast; import java.io.IOException; import java.io.PrintWriter; import javax.servlet.ServletException; import javax.servlet.http.HttpServlet; import javax.servlet.http.HttpServletRequest; import javax.servlet.http.HttpServletResponse; public class DoformServlet extends HttpServlet { public void doGet(HttpServletRequest request, HttpServletResponse response) throws ServletException, IOException { /* * 完成校验表单是否重复提交 */ //前三句防乱码+获取流 response.setCharacterEncoding("UTF-8"); response.setContentType("text/html;charset=UTF-8"); PrintWriter out=response.getWriter(); boolean b=isTokenValid(request); if (!b) { out.println("请不要重复提交!"); return; } //是正常提交就处理,处理之前先清除token号 request.getSession().removeAttribute("token"); out.println("向数据库中注册用户"); } private boolean isTokenValid(HttpServletRequest request) { /*方法说明: *专门写个方法校验表单是否重复提交 *1,客户端token为空(防坏人自定义表单) *2,服务器token为空(提交过了,已经清除了) *3,两者是否相等 */ String c_token=request.getParameter("token"); if (c_token==null) { return false; } String s_token=(String) request.getSession().getAttribute("token"); if (s_token==null) { return false; } if (!c_token.equals(s_token)) { return false; } //代码同struts一样,闯过前三关才为true return true; } public void doPost(HttpServletRequest request, HttpServletResponse response) throws ServletException, IOException { doGet(request, response); } }