LoginSignup
0
0

More than 5 years have passed since last update.

token interceptor

Posted at

package com.smartt.api.interceptor;

import java.lang.annotation.*;

@Target(ElementType.METHOD)

@Retention (RetentionPolicy.RUNTIME)

@Documented

public @interface Token {

boolean save() default false;

boolean remove() default false;

}

package com.smartt.api.interceptor;

import java.lang.reflect.Method;

import java.util.UUID;

import javax.servlet.http.HttpServletRequest;

import javax.servlet.http.HttpServletResponse;

import org.springframework.web.method.HandlerMethod;

import org.springframework.web.servlet.handler.HandlerInterceptorAdapter;

public class TokenInterceptor extends HandlerInterceptorAdapter {

@Override  
public boolean preHandle(HttpServletRequest request, HttpServletResponse response, Object handler) throws Exception {  
    if (handler instanceof HandlerMethod) {  
        HandlerMethod handlerMethod = (HandlerMethod) handler;  
        Method method = handlerMethod.getMethod();  
        Token annotation = method.getAnnotation(Token.class);  
        if (annotation != null) {  
            boolean needSaveSession = annotation.save();  
            if (needSaveSession) {  
                request.getSession(false).setAttribute("token", UUID.randomUUID().toString());  
            }  
            boolean needRemoveSession = annotation.remove();  
            if (needRemoveSession) {  
                if (isRepeatSubmit(request)) {  
                    return false;  
                }  
                request.getSession(false).removeAttribute("token");  
            }  
        }  
        return true;  
    } else {  
        return super.preHandle(request, response, handler);  
    }  
}  

private boolean isRepeatSubmit(HttpServletRequest request) {  
    String serverToken = (String) request.getSession(false).getAttribute("token");  
    if (serverToken == null) {  
        return true;  
    }  
    String clinetToken = request.getParameter("token");  
    if (clinetToken == null) {  
        return true;  
    }  
    if (!serverToken.equals(clinetToken)) {  
        return true;  
    }  
    return false;  
}  

}

0
0
0

Register as a new user and use Qiita more conveniently

  1. You get articles that match your needs
  2. You can efficiently read back useful information
  3. You can use dark theme
What you can do with signing up
0
0