2012-06-12 137 views
1

我使用SessionFilter servlet來驗證用戶,然後授予系統訪問權限。我的受限文件位於名爲「com.shadibandhan.Restricted」的文件夾中。 會話過濾器工作正常。JSF請求範圍的託管bean http-session導致實例化

這裏的sessionfilter的servlet

@Override 
public void doFilter(ServletRequest req, ServletResponse res, 
     FilterChain chain) throws IOException, ServletException { 

    HttpServletRequest request = (HttpServletRequest) req; 
    HttpServletResponse response = (HttpServletResponse) res; 
    String servletPath = request.getServletPath(); 
    String contextPath = request.getContextPath(); 
    String remoteHost = request.getRemoteHost(); 
    String url = contextPath + servletPath; 
    boolean allowedRequest = false; 

    if (urlList.contains(servletPath)) { 
     allowedRequest = true; 
    } 

    if (!allowedRequest) { 
     HttpSession session = request.getSession(false); 
     if (null == session) { 

      System.out.println("Session is not present"); 
      response.sendRedirect(contextPath); 
      return; 

     } if (null != session) { 
      //String loggedIn = (String) session.getAttribute("sb_logged_in"); 
      System.out.println("Session is present"); 
      System.out.println("\nSession no. is = " + session.getId()); 

      if (session.getAttribute("logged-in") == "true") { 
       System.out.println("Session logged-in attribute is true, " + session.getAttribute("sessionUsername") + " is logged in."); 

       //ServletContext context = request.getServletContext(); 
       RequestDispatcher dispatcher = request.getRequestDispatcher(servletPath); 
       dispatcher.forward(request, response); 
      } else { 
       System.out.println("Session logged-in attribute is not true"); 
       response.sendRedirect(contextPath); 
      } 
     } 
    } 

    chain.doFilter(req, res); 
} 

現在的相關代碼,當用戶登錄時,我把自己的用戶名和配置文件ID在HttpSession中,這裏的是綁定登錄頁面豆。

@ManagedBean 
@SessionScoped 
public class UserLoginManagedBean { 

    private User user = null; 
    private String username = null; 
    private String password = null; 
    private ServiceProvider server = null; 
    HttpServletRequest request = null; 
    HttpServletResponse response = null; 
    HttpSession session = null; 
    private Date date; 
    private int profileActiveness=0; 
    private int profileActivenessPercentage=0; 

    public UserLoginManagedBean() { 
     this.user = new User(); 
     this.server = ServiceProvider.getInstance(); 
    } 

    public String validateLogin() { 

     System.out.println("Inside validate login"); 
     boolean isUserValid = false; 

     System.out.println(this.username + " " + this.password); 

     isUserValid = this.authenticate(username, password); 

     if (isUserValid) { 
      //this.user = found; 
      System.out.println("User is valid---Redirecting to messages.xhtml"); 
      return "com.shadibandhan.Restricted/profile.xhtml?faces-redirect=true"; 

     } else { 
      //addGlobalErrorMessage("Unknown login, please try again"); 
      return null; 
     } 
    } 

    public boolean authenticate(String username, String password) { 
     boolean isUserValid = false; 
     String status = null; 

     //isUserValid = this.server.authenticateUser(this.username, this.password); 

     this.user = (User) this.server.getRecordByTwoColumns(User.class, "username" , this.username, "password", this.password); 

     if(null != this.user){ 
      isUserValid = true; 
     }else{ 
      isUserValid = false; 
     } 

     if (isUserValid) { 

      FacesContext context = FacesContext.getCurrentInstance(); 
      this.request = (HttpServletRequest) context.getExternalContext().getRequest(); 
      this.response = (HttpServletResponse) context.getExternalContext().getResponse(); 
      this.session = request.getSession(true); 
//     if there's no session, it'll creat a new one due to the true flag 


      status = this.updateUserRecord(); 


      if (status.equals("success")) { 
       if (null != this.session) { 

        session.setAttribute("sessionUsername", this.user.getUsername()); 
        session.setAttribute("sessionProfileId", this.user.getProfile().getProfileId()); 
        session.setAttribute("logged-in", "true"); 

        System.out.println("Session username is --->" + session.getAttribute("sessionUsername")); 
       } 

      } else { 
       isUserValid = false; 
       FacesMessage msg = new FacesMessage("Something went wrong"); 
       FacesContext.getCurrentInstance().addMessage(null, msg); 
      } 
     } 

     return isUserValid; 
    } 

    public String logOut() { 
     FacesContext context = FacesContext.getCurrentInstance(); 
     System.out.println("inside logout method"); 
     this.request = (HttpServletRequest) context.getExternalContext().getRequest(); 

     if (null != this.request) { 

      this.session = request.getSession(false); 
      session.invalidate(); 
      System.out.println("Session is now invalidated"); 
      return "../index.xhtml?faces-redirect=true"; 
     } else { 
      System.out.println("You're already signed out"); 
      return null; 
     } 
    } 

    private String updateUserRecord() { 
     String status = null; 

     Date lastLoginDate=this.user.getLastLogin(); 
     Date currentDate= new Date(); 
     this.profileActiveness=this.user.getProfileActiveness(); 


       SimpleDateFormat format = new SimpleDateFormat("yy-MM-dd HH:mm:ss"); 

     try { 
      lastLoginDate = format.parse(lastLoginDate.toString()); 
      currentDate = format.parse(currentDate.toString()); 
     } catch (ParseException e) { 
      e.printStackTrace(); 
     }  

     // Get msec from each, and subtract. 
     long diff = currentDate.getTime() - lastLoginDate.getTime(); 
     long diffSeconds = diff/1000;   
     long diffMinutes = diff/(60 * 1000);   
     long diffHours = diff/(60 * 60 * 1000);      
     System.out.println("Time: " + diff + " ."); 
     System.out.println("Time in seconds: " + diffSeconds + " seconds.");   
     System.out.println("Time in minutes: " + diffMinutes + " minutes.");   
     System.out.println("Time in hours: " + diffHours + " hours."); 
     if(diffHours<12) 
     { 
      if(profileActiveness<8){ 
      profileActiveness++; 
      profileActivenessPercentage=(int) (profileActiveness*12.5); 
      this.user.setProfileActiveness(this.profileActiveness); 
      } 
      } 
     if(diffHours>71) 
     { 
      if(profileActiveness>2){ 
      profileActiveness-=2; 
      profileActivenessPercentage=(int) (profileActiveness*12.5); 
      this.user.setProfileActiveness(this.profileActiveness); 
      } 
      else{ 
      profileActiveness=0; 
      } 
     } 



     this.user.setLastLogin(this.getCurrentDate()); 
     this.user.setLoginStatus(true); 

     status = this.server.updateObject(this.user); 

     return status; 
    } 

    // ... 
} 

而且,在另一個叫管理,MessagesManagedBean豆(請求範圍的),當我嘗試獲取配置文件ID的用戶登錄後,它就像一個魅力。現在

,我有兩個問題在這裏:

  1. 每當我嘗試從具有 具有相關的HTTP會話 在這樣的代碼就勢必豆受限制的文件夾訪問一個頁面情況下MessagesManagedBean,它給了我一個不能 實例化bean異常,因爲我得到 構造函數中的屬性,爲什麼?
  2. 即使我沒有登錄,它也會調用bean的構造函數,只要我嘗試訪問與之綁定的頁面。

回答

3

您在致電response.sendRedirect()後繼續chain.doFilter()的要求。 sendRedirect()僅僅會設置一個Location響應標題,然後瀏覽器將處理新的URL。但是如果你繼續請求chain.doFilter(),那麼整個JSF進程仍然會被執行。

您需要在sendRedirect()調用後添加return;語句以退出過濾器。

} else { 
    System.out.println("Session logged-in attribute is not true"); 
    response.sendRedirect(contextPath); 
    return; 
} 

無關的具體問題,您已在會議的一大設計錯誤作用域bean。您不應將HTTP請求,響應和會話分配爲bean的實例變量。這使得你的會話作用域bean不安全。 刪除所有這些屬性並僅在同一個方法塊內聲明它們爲threadlocal。

+0

它的工作。感謝並感謝其他有用的建議以及:) –

+0

不客氣。 – BalusC

+0

我的問題2呢? 每當我嘗試訪問頁面,即使沒有登錄,它調用bean的構造函數...? –