• 博客园logo
  • 会员
  • 周边
  • 新闻
  • 博问
  • 闪存
  • 赞助商
  • YouClaw
    • 搜索
      所有博客
    • 搜索
      当前博客
  • 写随笔 我的博客 短消息 简洁模式
    用户头像
    我的博客 我的园子 账号设置 会员中心 简洁模式 ... 退出登录
    注册 登录
helong
博客园    首页    新随笔    联系   管理    订阅  订阅

Java 使用过滤器过滤非法字符

package com.iapppay.wap.common;

import java.io.IOException;
import java.io.PrintWriter;

import javax.servlet.Filter;
import javax.servlet.FilterChain;
import javax.servlet.FilterConfig;
import javax.servlet.ServletException;
import javax.servlet.ServletRequest;
import javax.servlet.ServletResponse;
import javax.servlet.annotation.WebFilter;
import javax.servlet.http.HttpServletRequest;
import javax.servlet.http.HttpServletResponse;

import org.slf4j.Logger;
import org.slf4j.LoggerFactory;

import com.iapppay.wap.control.LoginControl;

/**
* Servlet Filter implementation class CharFilter
*/
@WebFilter(
"/CharFilter")
public class CharFilter implements Filter {

private String[] characterParams = null;
private boolean OK = true;
private static Logger logger = LoggerFactory.getLogger(LoginControl.class);
/**
* Default constructor.
*/
public CharFilter() {
// TODO Auto-generated constructor stub
}

/**
*
@see Filter#destroy()
*/
public void destroy() {
// TODO Auto-generated method stub
}

/**
*
@see Filter#doFilter(ServletRequest, ServletResponse, FilterChain)
*/
public void doFilter(ServletRequest request, ServletResponse response, FilterChain chain)
throws IOException, ServletException {
HttpServletRequest servletrequest
= (HttpServletRequest) request;
HttpServletResponse servletresponse
= (HttpServletResponse) response;
boolean status = false;
java.util.Enumeration params
= request.getParameterNames();
String param
= "";
String paramValue
= "";
servletresponse.setContentType(
"text/html");
servletresponse.setCharacterEncoding(
"utf-8");
while (params.hasMoreElements()) {
param
= (String) params.nextElement();
String[] values
= request.getParameterValues(param);
paramValue
= "";
if (OK) {// 过滤字符串为0个时 不对字符过滤
for (int i = 0; i < values.length; i++)
paramValue
= paramValue + values[i];
for (int i = 0; i < characterParams.length; i++)
if (paramValue.indexOf(characterParams[i]) >= 0) {
status
= true;
break;
}
if (status)
break;
}
}
// System.out.println(param+"="+paramValue+";");

if (status) {
logger.warn(
"输入的值不合法:"+paramValue);
StringBuffer url
= servletrequest.getRequestURL();
servletresponse.sendRedirect(servletrequest.getContextPath()
+"/v/login/illegalchar?url="+url.toString());
}
else
chain.doFilter(request, response);

}

/**
*
@see Filter#init(FilterConfig)
*/
public void init(FilterConfig fConfig) throws ServletException {
String str
=fConfig.getInitParameter("characterParams");
if(str==null||"".equals(str)){
OK
= false;
}
else{
this.characterParams = fConfig.getInitParameter("characterParams").split(",");
}

}

}

WEB.XML

<filter>
<filter-name>charFilter</filter-name>
<filter-class>com.iapppay.wap.common.CharFilter</filter-class>
<init-param>
<param-name>characterParams</param-name>
<param-value>|,&amp;,;,$,%,',&quot;,\',\&quot;,\,&lt;,&gt;,(,),+,CR,LF,BS</param-value>
</init-param>
</filter>
<filter-mapping>
<filter-name>charFilter</filter-name>
<url-pattern>/v/*</url-pattern>
</filter-mapping>

posted @ 2011-09-17 15:25  helong  阅读(2224)  评论(0)    收藏  举报
刷新页面返回顶部
博客园  ©  2004-2026
浙公网安备 33010602011771号 浙ICP备2021040463号-3