通过拦截器和过滤器实现,话不多说上代码。
1、重写HttpServletRequestWrapper读取body里面的内容。
public class RequestWrapper extends HttpServletRequestWrapper { private final String body; public RequestWrapper(HttpServletRequest request) { super(request); StringBuilder stringBuilder = new StringBuilder(); BufferedReader bufferedReader = null; InputStream inputStream = null; try { inputStream = request.getInputStream(); if (inputStream != null) { bufferedReader = new BufferedReader(new InputStreamReader(inputStream)); char[] charBuffer = new char[128]; int bytesRead = -1; while ((bytesRead = bufferedReader.read(charBuffer)) > 0) { stringBuilder.append(charBuffer, 0, bytesRead); } } else { stringBuilder.append(""); } } catch (IOException ex) { } finally { if (inputStream != null) { try { inputStream.close(); } catch (IOException e) { e.printStackTrace(); } } if (bufferedReader != null) { try { bufferedReader.close(); } catch (IOException e) { e.printStackTrace(); } } } body = stringBuilder.toString(); } @Override public ServletInputStream getInputStream() throws IOException { final ByteArrayInputStream byteArrayInputStream = new ByteArrayInputStream(body.getBytes()); ServletInputStream servletInputStream = new ServletInputStream() { @Override public boolean isFinished() { return false; } @Override public boolean isReady() { return false; } @Override public void setReadListener(ReadListener readListener) { } @Override public int read() throws IOException { return byteArrayInputStream.read(); } }; return servletInputStream; } @Override public BufferedReader getReader() throws IOException { return new BufferedReader(new InputStreamReader(this.getInputStream())); } public String getBody() { return this.body; } }HttpServletRequestWrapper
2、因为reque里面的内容只能读取一次,需要重写回去。增加ChannelFilter
import org.springframework.stereotype.Component; import javax.servlet.*; import javax.servlet.annotation.WebFilter; import javax.servlet.http.HttpServletRequest; import java.io.IOException; @Component @WebFilter(urlPatterns = "/*",filterName = "channelFilter") public class ChannelFilter implements Filter { @Override public void init(FilterConfig filterConfig) throws ServletException { } @Override public void doFilter(ServletRequest servletRequest, ServletResponse servletResponse, FilterChain filterChain) throws IOException, ServletException { ServletRequest requestWrapper = null; if(servletRequest instanceof HttpServletRequest) { requestWrapper = new RequestWrapper((HttpServletRequest) servletRequest); } if(requestWrapper == null) { filterChain.doFilter(servletRequest, servletResponse); } else { filterChain.doFilter(requestWrapper, servletResponse); } } @Override public void destroy() { } }ChannelFilter
3、增加拦截器,获取请求的body
@Component public class ParamInterceptor implements HandlerInterceptor { @Override public boolean preHandle(HttpServletRequest request, HttpServletResponse response, Object handler) throws Exception { String method = request.getMethod(); String contentType = request.getContentType() == null ? "" : request.getContentType(); if (HttpMethod.POST.name().equals(method) && !contentType.equals(MediaType.MULTIPART_FORM_DATA_VALUE)) { RequestWrapper requestWrapper = new RequestWrapper(request); String body = requestWrapper.getBody(); testParam(body); } return true; } private void testParam(String param){ try { param = param.replace(" ", ""); param = param.replace("&", ""); param = param.replace("#", ""); param = param.replace(" ", ""); param = param.replace("\"\"", ""); if (param.toLowerCase().contains("<script") || param.contains("<") || param.contains(">") || param.toLowerCase().contains("<html") || param.toLowerCase().contains("<header") || param.toLowerCase().contains("alert") || param.toLowerCase().contains("console") ) { throw new BusinessException("500", "非法参数!"); } } catch (Exception ex) { if (ex instanceof BusinessException) { throw new BusinessException("500", ((BusinessException) ex).getMsg()); } } } }ParamInterceptor
4、拦截器配置(略)
5、过滤器配置,在启动类上增加@ServletComponentScan注解
标签:body,请求,非法,param,IOException,Override,new,public,springboot From: https://www.cnblogs.com/rolayblog/p/18037400