为我的web应用程序(JSF 2.0)编写一个授权过滤器



根据一些建议,我决定为我的web应用程序编写自己的授权过滤器(我不使用容器管理的安全性,所以我必须这样做)。

这是我的第一个过滤器,所以我有点困惑我应该如何实现它。以下是我目前所做的:

package filters;
import java.io.IOException;
import javax.servlet.Filter;
import javax.servlet.FilterChain;
import javax.servlet.FilterConfig;
import javax.servlet.ServletException;
import javax.servlet.ServletRequest;
import javax.servlet.ServletResponse;
import javax.servlet.http.HttpServletRequest;
import javax.servlet.http.HttpServletResponse;
import javax.servlet.http.HttpSession;
import entities.Role;
public class RestrictPageFilter implements Filter {
    FilterConfig fc;
    public void init(FilterConfig filterConfig) throws ServletException {
        // The easiest way to initialize the filter
        fc = filterConfig;
    }
    public void doFilter(ServletRequest request, ServletResponse response,
            FilterChain chain) throws IOException, ServletException {
        HttpServletRequest req = (HttpServletRequest) request;
        HttpServletResponse resp = (HttpServletResponse) response;
        HttpSession session = req.getSession(true);
        String pageRequested = req.getRequestURL().toString();
        Role currentUser = (Role) session.getAttribute("userRole");
        //Pages that are allowed with no need to login:
        //-faq.xhtml
        //-index.jsp
        //-login.xhtml
        //-main.xhtml
        //-registration.xhtml
        //NOW pages that are restricted depending on the type of user
        //buyoffer.xhtml(Only BUYER)
        //sellerpanel.xhtml(Only SELLER)
        //adminpanel.xhtml(Only ADMINISTRATOR)
        //HOW SHOULD I IMPLEMENT THAT??
        if(currentUser != null && currentUser.getType().equals("BUYER")) {          
        }
        if(currentUser != null && currentUser.getType().equals("SELLER")) {         
        }
        if(currentUser != null && currentUser.getType().equals("ADMINISTRATOR")) {          
        }

    }
    public void destroy() {
        // Not needed
    }
}

正如你所看到的,我在卡住的地方留下了评论。有人能给我一个手完成这个过滤器或给我一些伪代码提示我应该如何完成它?

我在网上看到了一些例子,但是它们都没有根据用户类型进行不同的过滤。

谢谢你的帮助

更新

我创建了一个xml文件来帮助我进行过滤(它位于WEB-INF/classes中)

<access>
    <buyer>
        <page>buyoffer.xhtml</page>
        <page>faq.xhtml</page>
        <page>index.jsp</page>
        <page>login.xhtml</page>
        <page>main.xhtml</page>
        <page>registrationSucceded.xhtml</page>     
    </buyer>
    <seller>
        <page>sellerpanel.xhtml</page>
        <page>faq.xhtml</page>
        <page>index.jsp</page>
        <page>login.xhtml</page>
        <page>main.xhtml</page>
        <page>registrationSucceded.xhtml</page>     
    </seller>
    <administrator>
        <page>sellerpanel.xhtml</page>
        <page>faq.xhtml</page>
        <page>index.jsp</page>
        <page>login.xhtml</page>
        <page>main.xhtml</page>
        <page>registrationSucceded.xhtml</page>     
    </administrator>
</access>
<!-- THE REGISTRATION PAGES SHOULD NOT BE ACCESSIBLE IF THE USER IS LOGGED IN -->

我从init()方法读取文件。()

public class RestrictPageFilter implements Filter {
    private FilterConfig fc;
private InputStream in;
    public void init(FilterConfig filterConfig) throws ServletException {
        // The easiest way to initialize the filter
        fc = filterConfig;
        //Get the file that contains the allowed pages
        in = this.getClass().getResourceAsStream("/allowedpages.xml");
    }
    public void doFilter(ServletRequest request, ServletResponse response,
            FilterChain chain) throws IOException, ServletException {
        HttpServletRequest req = (HttpServletRequest) request;
        HttpServletResponse resp = (HttpServletResponse) response;
        HttpSession session = req.getSession(true);
        String pageRequested = req.getRequestURL().toString();
        //Get the value of the current logged user 
        Role currentUser = (Role) session.getAttribute("userRole");
        if (currentUser != null) {
        }
    }
    public void destroy() {
        // Not needed
    }
}

如果需要允许访问,只需调用

// it will process request normally, means it will leave the control from Filter
chain.doFilter(request, response);

如果你想限制用户,那么调用

//take some action
response.sendRedirect("URL to some page");//it will simply make user redirected 

一些建议

  • 使其可配置使用某种XML属性文件,你的代码对我来说似乎很难,明天可能会有另一个页面添加,所以你需要重新编译你的过滤器。

  • 如果允许,那么简单地使用Spring Security,它有很好的功能。而且你也不会重新发明轮子

相关内容

  • 没有找到相关文章

最新更新