JavaWeb_session_防表单重复提交

FormServlet

package cn.itcast;

import java.io.IOException;
import java.security.MessageDigest;
import java.security.NoSuchAlgorithmException;
import java.util.Random;

import javax.servlet.ServletException;
import javax.servlet.http.HttpServlet;
import javax.servlet.http.HttpServletRequest;
import javax.servlet.http.HttpServletResponse;

import sun.misc.BASE64Encoder;

public class FormServlet extends HttpServlet {
   public void doGet(HttpServletRequest request, HttpServletResponse response)
         throws ServletException, IOException {
      /*
       * 产生随机数,用Session带给form.jsp产生表单
       * form.jsp表单 提交给DoFormServlet验证处理,防止重复提交
       */
      TokenProcessor tp=TokenProcessor.getInstance();
      String token=tp.generateToken();
      //用Session带token给form.jsp的hidden,并产生表单
      request.getSession().setAttribute("token", token);
      request.getRequestDispatcher("/form.jsp").forward(request, response);
   }
   public void doPost(HttpServletRequest request, HttpServletResponse response)
         throws ServletException, IOException {
      doGet(request, response);
   }
}
class TokenProcessor{
   /*
    * 单例3步走:构造私有,自已new个,提供公开方法
    */
   private TokenProcessor(){}
   private static final TokenProcessor instance=new TokenProcessor();
   public static TokenProcessor getInstance(){
      return instance;
   }
   public String generateToken(){
      /*
       * 重点:核心先取得token的md5摘要算法的数据指纹,
       * 即摘要计算后的字节数组
       * 然后将字节数组经base64编码成明文字符串返回
       */
      String token=System.currentTimeMillis()+new Random().nextInt()+"";
      /*
       * 如果没有 Provider 支持指定算法的 MessageDigestSpi 实现
       * 会报NoSuchAlgorithmException异常 
       */ 
      try {
         MessageDigest md=MessageDigest.getInstance("md5");
         byte[] md5=md.digest(token.getBytes());
         BASE64Encoder encoder=new BASE64Encoder();
         token=encoder.encode(md5);
         return token;
      } catch (NoSuchAlgorithmException e) {
         throw new RuntimeException();
      }
   }
}


form.jsp

<%@ page language="java" import="java.util.*" pageEncoding="UTF-8"%>

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
  <head>
    <title>My JSP 'form.jsp' starting page</title>
   <meta http-equiv="pragma" content="no-cache">
   <meta http-equiv="cache-control" content="no-cache">
   <meta http-equiv="expires" content="0">    
  </head>
  <body>
  由FormServlet产生token,跳本form.jsp页面显示,提交DoformServlet处理
  <script type="text/javascript">
     var flag=false;
     function Check(){
        if(!flag){
           flag=true;
           return true;
        }else{
           return false;
        }
     }
  </script>
  <form action="/day04/servlet/DoformServlet" method="post" onsubmit="return Check()">
        用户名:<input type="text" name="username"/>
        密  码:<input type="password" name="password"/>
        <input type="hidden" name="token" value="${token }"/>
        <input type="submit" value="注册"/>
    </form>
  </body>
</html>


DoformServlet


package cn.itcast;

import java.io.IOException;
import java.io.PrintWriter;

import javax.servlet.ServletException;
import javax.servlet.http.HttpServlet;
import javax.servlet.http.HttpServletRequest;
import javax.servlet.http.HttpServletResponse;

public class DoformServlet extends HttpServlet {
   public void doGet(HttpServletRequest request, HttpServletResponse response)
         throws ServletException, IOException {
      /*
       * 完成校验表单是否重复提交
       */
      //前三句防乱码+获取流
       response.setCharacterEncoding("UTF-8");
       response.setContentType("text/html;charset=UTF-8");
       PrintWriter out=response.getWriter();
       
      boolean b=isTokenValid(request);
      if (!b) {
         out.println("请不要重复提交!");
         return;
      }
      //是正常提交就处理,处理之前先清除token号
      request.getSession().removeAttribute("token");
      out.println("向数据库中注册用户");
   }
   private boolean isTokenValid(HttpServletRequest request) {
      /*方法说明:
      *专门写个方法校验表单是否重复提交
      *1,客户端token为空(防坏人自定义表单)
      *2,服务器token为空(提交过了,已经清除了)
      *3,两者是否相等
      */
      String c_token=request.getParameter("token");
      if (c_token==null) {
         return false;
      }
      String s_token=(String) request.getSession().getAttribute("token");
      if (s_token==null) {
         return false;
      }
      if (!c_token.equals(s_token)) {
         return false;
      }
      //代码同struts一样,闯过前三关才为true
      return true;
   }
   public void doPost(HttpServletRequest request, HttpServletResponse response)
         throws ServletException, IOException {
      doGet(request, response);
   }

}


你可能感兴趣的:(session,javaweb,重复提交)