2011-07-05 94 views
1

我正在嘗試從服務器獲取迴應。因此,我所做的是,我在驗證代碼中傳遞了我的用戶名和密碼,因爲該服務器需要身份驗證,然後從服務器獲得迴應......那麼是否有任何方法可以設置SMSESSION的cookie該用戶而不是在代碼中傳遞用戶名和密碼。假設用戶已經使用他/她的用戶名和密碼登錄到該瀏覽器。這是我的下面的代碼..當我註釋了傳遞的用戶名和密碼的一部分..這一個工作正常..但不是傳遞用戶名和密碼,我想設置該用戶已經登錄的SMSESSION cookie成瀏覽器..所以我加設置cookie的代碼,但它不工作,我得到設置SMSESSION cookie以獲取迴應

Access Denied Error 




<%@ page language="java" import=" 
org.apache.http.HttpEntity, 
org.apache.http.HttpResponse, 
org.apache.http.auth.AuthScope, 
org.apache.http.auth.UsernamePasswordCredentials, 
org.apache.http.client.methods.HttpPost, 
org.apache.http.client.methods.HttpGet, 
org.apache.http.impl.client.DefaultHttpClient, 
org.apache.http.util.EntityUtils, 
java.io.InputStream, 
java.io.InputStreamReader, 
java.io.BufferedReader, 
java.security.KeyStore, 
java.io.FileInputStream, 
java.io.File, 
org.apache.http.conn.ssl.SSLSocketFactory, 
org.apache.http.conn.scheme.Scheme, 
javax.net.ssl.HostnameVerifier, 
org.apache.http.impl.conn.SingleClientConnManager, 
javax.net.ssl.HttpsURLConnection, 
org.apache.http.conn.scheme.SchemeRegistry, 
javax.net.ssl.SSLContext, 
java.security.cert.X509Certificate, 
javax.net.ssl.X509TrustManager, 
javax.net.ssl.TrustManager, 
org.apache.http.conn.ClientConnectionManager, 
java.security.cert.CertificateException, 
org.apache.http.conn.scheme.Scheme" 
contentType="text/html; charset=ISO-8859-1" 
pageEncoding="ISO-8859-1"%> 

<% 
String a_Url = request.getParameter("url") ; 

DefaultHttpClient httpclient = new DefaultHttpClient(); 


/* 
    httpclient.getCredentialsProvider().setCredentials(
      new AuthScope(AuthScope.ANY_HOST, AuthScope.ANY_PORT, null), 
      new UsernamePasswordCredentials("test", "pass")); 
*/ 



    Cookie[] cookies = request.getCookies(); 
    boolean foundCookie = false; 
    // System.out.println(" hello " +cookies); 
    for(int i = 0; i < cookies.length; i++) { 
     Cookie c = cookies[i]; 
     //System.out.println(" " +c); 
     if (c.getName().equals("SMSESSION")) { 
      System.out.println("sm = " + c.getValue()); 
      foundCookie = true; 
     } 
    } 

    if (foundCookie) { 
     //System.out.println(foundCookie); 
     Cookie c = new Cookie("SMSESSION", "3jHUz3BcnWfVfgWH806Sro9Qs9obgTS6gp+b71d86HcPpupyZ8kcSI48KBpxcLT0DlTxnaKjP4Mgdn8iQFRkyJ1Uyji83qupvMy8zaD0b83h+5edOqF4GrDiXUDqzRBhwJ9wHMmswbf4As6gcu6aJDOoppI1pCoeA+yoLHpxMYi+B3VM1IZhOKiVkKb2+IrQwhvLCxMKy3oF/ew2gctmJ6AVfe/cA053niXPERjWW111cJhJMViFd/fP7YuxLuLZNzqBEBAdSBoK8YorzGwUTX0DDUTI7QJF9OGdeGETpmddHzE4u3hdqMZxrIdAYQc6zDLOf5I5MoMie7WnQVIu5gH8xa3b37BDk3rVuf4orOcaahv/UlrHPRRjIUtaWal1sAZXBHpYgQKH4wd3nNtPthW0hBAlxXQnGgHqZvJvQH4jLWlTV9uwC2q1hbMHrmo9zXCNO7uIxK6o0PyTYW6UhdVmcYtoHn/+mAX3dW3PRYAUM7ItAdIfsPV6LAs+bLiVexDf2P9E2ub4zF+ZSN+3AUSssMLiGKCOnWQ/IQyB8WOngkMa9Qc58pZv8g8E5Lxm5g/udiGbhqK24kYauJ8cUI4JtTW+JJKqwoqTbnwwdbTqdSenyNnrEnbH13CDowNxbSgJZeSUw2Z51ELARrXp+N5kGokLr+YXxwsgmvoXQxxo/5y9Lgn1RKtc4QAJiWjQNzDOFX2HoiFw+oWUXgrET8qTHHVOj+v9auqyxS0cPgcXj8wQmjJrUH+tYGlQmCdF2CCt5Ywf12Jaev+wfNcVb447fAmTR7LJTgtb/D5U15YqAMYZg36tVrPkx1MhP37XbEYLsCcpfdDO4FUVKb5t7zl0rTAhUvbCF3/Wn6V/0LjJ58UGl4GEhIF2y4K+vFJSkL7qJ+2ufVi9hfXu5362QKCtqqXt0LihgjmH9z0Mgg1Brfgl0jVPuO44os0KBKzfCuhFMzEK9oorNVpgWrVWED+yiBNO0B2JA4lurdsFFAwOcx3ZFyhJ1TC2jUYJpIBW "); 
     c.setMaxAge(24*60*60); 
     response.addCookie(c); 
    }  


    HttpGet httpget = new HttpGet(a_Url); 



    System.out.println("executing request" + httpget.getRequestLine()); 
    HttpResponse res = httpclient.execute(httpget); 

    HttpEntity entity = res.getEntity(); 

    System.out.println("----------------------------------------"); 
    System.out.println(res.getStatusLine()); 
    if (entity != null) { 

     System.out.println("Response content length: " + entity.getContentLength()); 
     InputStream input = entity.getContent(); 
     BufferedReader reader = new BufferedReader(new InputStreamReader(input)); 
     String ln = ""; 
     while((ln = reader.readLine()) != null) { 
      out.println("" + ln); 
     } 
     entity.consumeContent(); 
    } 
    EntityUtils.consume(entity); 

%> 

而且在響應頭我得到這個: -

Response Headers 
Content-Type text/html; charset=iso-8859-1 
Expires Thu, 01 Jan 1970 00:00:00 GMT 
Set-Cookie SMSESSION="3jHUz3BcnWfVfgWH806Sro9Qs9obgTS6gp+b71d86HcPpupyZ8kcSI48KBpxcLT0DlTxnaKjP4Mgdn8iQFRkyJ1Uyji83qupvMy8zaD0b83h+5edOqF4GrDiXUDqzRBhwJ9wHMmswbf4As6gcu6aJDOoppI1pCoeA+yoLHpxMYi+B3VM1IZhOKiVkKb2+IrQwhvLCxMKy3oF/ew2gctmJ6AVfe/cA053niXPERjWW111cJhJMViFd/fP7YuxLuLZNzqBEBAdSBoK8YorzGwUTX0DDUTI7QJF9OGdeGETpmddHzE4u3hdqMZxrIdAYQc6zDLOf5I5MoMie7WnQVIu5gH8xa3b37BDk3rVuf4orOcaahv/UlrHPRRjIUtaWal1sAZXBHpYgQKH4wd3nNtPthW0hBAlxXQnGgHqZvJvQH4jLWlTV9uwC2q1hbMHrmo9zXCNO7uIxK6o0PyTYW6UhdVmcYtoHn/+mAX3dW3PRYAUM7ItAdIfsPV6LAs+bLiVexDf2P9E2ub4zF+ZSN+3AUSssMLiGKCOnWQ/IQyB8WOngkMa9Qc58pZv8g8E5Lxm5g/udiGbhqK24kYauJ8cUI4JtTW+JJKqwoqTbnwwdbTqdSenyNnrEnbH13CDowNxbSgJZeSUw2Z51ELARrXp+N5kGokLr+YXxwsgmvoXQxxo/5y9Lgn1RKtc4QAJiWjQNzDOFX2HoiFw+oWUXgrET8qTHHVOj+v9auqyxS0cPgcXj8wQmjJrUH+tYGlQmCdF2CCt5Ywf12Jaev+wfNcVb447fAmTR7LJTgtb/D5U15YqAMYZg36tVrPkx1MhP37XbEYLsCcpfdDO4FUVKb5t7zl0rTAhUvbCF3/Wn6V/0LjJ58UGl4GEhIF2y4K+vFJSkL7qJ+2ufVi9hfXu5362QKCtqqXt0LihgjmH9z0Mgg1Brfgl0jVPuO44os0KBKzfCuhFMzEK9oorNVpgWrVWED+yiBNO0B2JA4lurdsFFAwOcx3ZFyhJ1TC2jUYJpIBW";Expires=Wed, 06-Jul-11 16:57:11 GMT 
Content-Length 2786 
Server Jetty(6.1.21) 

任何建議將不勝感激...

回答

1

SMSESSION是一個系統cookie使用由Siteminder。你不應該/一定不要惹它。

如果您的應用程序啓用了Siteminder,Siteminder將負責用戶的身份驗證過程。
用戶通過Siteminder進行身份驗證後,應用程序上的Siteminder代理將添加特定的HTTP標頭(特別是SM_USER),該標頭將包含有關用戶的信息。
您只需從請求中獲取這些信息。

1

SMSESSION cookie會定期更改,因此您無法像上面代碼中那樣靜態設置它。由於您使用的是Java,因此您可能需要查看SiteMinder的Java SDK