【问题标题】:httpsession verification if existshttpsession验证是否存在
【发布时间】:2012-12-13 19:38:17
【问题描述】:

strong text我是新手,需要正确的验证方式。我关注了

5 行代码。它没有 httpsession 但仍会去约会.jsp。为什么这样? 我关注了How to check if session exists or not?

它正在给一个会话。 org.apache.catalina.session.StandardSessionFacade@3b59e880 但用户没有登录...

确实如此。但我不知道为什么以及如何得到一个?

if (request.getSession(false) == null) {
    request.getServletContext().getRequestDispatcher("/login.jsp").forward(request, response);
} else if (request.getSession(false) != null) {
    request.getServletContext().getRequestDispatcher("/appointment.jsp").forward(request, response);
}

【问题讨论】:

    标签: java jsp servlets


    【解决方案1】:

    用户登录后不会创建会话,它是在浏览器对容器的第一次请求时创建的。这使容器能够跟踪来自同一浏览器的后续请求。这通常使用具有唯一 ID(会话 ID)的 cookie 来实现。

    所以即使它取决于用户注销时发生的情况?你在调用 session.invalidate() 吗? 我们不能仅仅因为会话对象不为空就说用户已通过身份验证。

    【讨论】:

    • 为什么。如果 create 为 false 并且请求没有有效的 HttpSession,则此方法返回 null。 (这不是正确的方法吗?)
    • HttpSession getSession() 返回与此请求关联的当前会话,或者如果请求没有会话,则创建一个。
    • 是的,如果您的身份验证是使用自定义逻辑(比如过滤器)完成的,请告诉我?
    • 您的意思是,即使我进行会话与否。当用户打开页面时,浏览器会进行隐式会话吗?最好制作一个像“会话存在”“是”/“否”这样的会话属性
    • 是的,最好在会话属性中设置一个“IS_AUTHENTICATED”布尔标志。这样在登录时将其设置为 true,如果未设置或 false 则表示登录页面。另一种最佳方法是在过滤器中跟踪会话,使用自定义逻辑为您提供灵活性,例如跟踪数据库中的每个会话或强制注销用户会话等
    【解决方案2】:

    总会有一个 HttpSession 对象(好吧,并非总是如此,但大多数时候)——这不是一个经过身份验证的用户的指标。

    您需要设置会话属性,例如。 "authenticated" 将此会话标记为已验证或未验证。

    您可以通过调用 request.getSession().setAttribute(...) 来添加它

    【讨论】:

    • if ((Boolean)request.getSession(false).getAttribute("userLoggedIn")){ 没问题?
    • 是的,除了潜在的 NPE。 (getSesstion可以返回null,getAttribute也可以返回null aa,request也可以为null)
    • 这样可以吗? if ((Boolean)request.getSession(false).getAttribute("userLoggedIn")){ out.println("有会话"); out.print(request.getSession(false)); }else if (!(Boolean)request.getSession(false).getAttribute("userLoggedIn") || (Boolean)request.getSession(false).getAttribute("userLoggedIn") == null){ out.println("there没有会话"); out.print(request.getSession(false));
    • 嗯,风格不行。但我认为你会实现你的计划,有了它。
    • (Boolean)request.getSession(false).getAttribute("userLoggedIn") 可以为空。 Boolean loggedIn = (Boolean)request.getSession(false).getAttribute("userLoggedIn");然后检查loggedIn是否为null。
    【解决方案3】:

    默认情况下,JSP 将创建一个会话。您可能不希望您的登录页面出现这种行为,因此请使用 login.jsp 中的 page 指令:

    <%@ page session="false" %>
    

    您还需要确保在成功登录之前访问的任何其他 JSP 都不会创建会话。

    【讨论】:

    • 谢谢。现在我有所有适合答案的问题,但我必须选择一个。
    • 我已经做了 session = "false" 但我仍然得到一个隐式会话
    • 确保在成功登录之前您的其他页面都没有创建会话,并且如其他答案之一所述,确保在用户注销时使当前会话无效。
    • 非常感谢。加一个非常感谢。加一。但是仍然没有可行的代码来避免浏览器隐式会话出现空指针异常的问题
    • 这行得通。 if (request.getSession(false).getAttribute("userLoggedIn") != null ){ if((Boolean)request.getSession(false).getAttribute("userLoggedIn") ){ request.getServletContext().getRequestDispatcher("/约会.jsp").forward(请求,响应); } }else { request.getServletContext().getRequestDispatcher("/login.jsp").forward(request, response); }
    【解决方案4】:
    if (request.getSession(false).getAttribute("userLoggedIn") != null ) {
        if((Boolean)request.getSession(false).getAttribute("userLoggedIn") ) {
            request.getServletContext().getRequestDispatcher("/appointment.jsp").forward(request, response);
        }
    } else {
        request.getServletContext().getRequestDispatcher("/login.jsp").forward(request, response);
    }
    

    【讨论】:

    • 请注意,您可以通过以下方式向NullPointerException 敞开大门:request.getSession(false).getAttribute("userLoggedIn"),因为getSession(false) 可以返回null。
    • @kschneid 那么应该怎么做呢?包装另一个 if() 来检查会话是否为空?你能告诉我怎么做吗? .好吧,如果会话不存在,那么 userLoggedIn 将为空。然后代码进入 else{} 块。所以没有问题吗?
    猜你喜欢
    • 1970-01-01
    • 1970-01-01
    • 2018-05-06
    • 2021-05-28
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 2012-08-14
    • 2020-11-20
    相关资源
    最近更新 更多