一、会话技术
会话:是一个过程,用户打开浏览器浏览网页(多次请求–响应),关闭浏览器,这个过程称为会话。
- 一次会话:浏览器第一次给服务器资源发送请求,会话建立,直到有一方断开为止。(一次会话中包含多次请求和响应)
-
功能:
- 在一次会话的范围内的多次请求间,共享数据
- 每个用户与服务器交互,会产生一些数据,程序希望保存这些数据,就可以保存在会话对象中。
-
方式:
- 客户端会话技术:
Cookie - 服务器端会话技术:
Session
二、Cookie
2.1 概念
Cookie:是客户端的会话技术,默认Cookie是保存在用户的浏览器上。
- 程序把用户的数据以Cookie的形式写回到用户的浏览器上(响应头:set-cookie)
- 当用户使用浏览器访问程序的时候,携带自己浏览器上的Cookie(请求头:cookie)
2.2 快速入门
2.2.1 Cookie对象的方法
方法名 | 功能 | 备注 |
---|
Cookie(String name, String value) | 构造方法,是key-value形式。 | Cookie不支持中文。如果出现中文乱码,可以通过URL编码存储和解码解析来存储与获取数据URLDecoder.decode(value,"utf-8"); | String getValue() | 获取Cookie的值 | | String getName() | 获取Cookie的名称 | | setValue() | 设置Cookie的值 | | void setMaxAge(int expiry) | 设置Cookie有效时间;单位 :秒 | 如果浏览器关闭了,Cookie默认就被清除了,Cookie默认的情况下是保存在浏览器的缓存中。设置有效的时间,Cookie就变成了持久的Cookie。默认的情况下,把Cookie保存到本地的文件中。 | void setPath(String uri) | 设置Cookie的有效路径 | 默认有效路径与创建Cookie的jsp和servlet程序的访问路径有关 。只有请求当前服务器并且访问路径为指定路径时才携带Cookie |
2.2.2 操作Cookie的方法
方法名 | 功能 | 备注 |
---|
Cookie[] getCookies() | 获取请求发送的Cookie数组 | HttpServletRequest接口中的方法 | void addCookie(Cookie cookie) | 向浏览器回写Cookie | HttpServletResponse接口中的方法 |
2.2.3 使用步骤
1、创建Cookie对象,绑定数据
new Cookie(String name, String value)
2、发送Cookie对象
response.addCookie(Cookie cookie)
3、获取Cookie,拿到数据
Cookie[] request.getCookies()
import javax.servlet.ServletException;
import javax.servlet.annotation.WebServlet;
import javax.servlet.http.Cookie;
import javax.servlet.http.HttpServlet;
import javax.servlet.http.HttpServletRequest;
import javax.servlet.http.HttpServletResponse;
import java.io.IOException;
@WebServlet("/CookieDemo1")
public class CookieDemo1 extends HttpServlet {
protected void doPost(HttpServletRequest request, HttpServletResponse response) throws ServletException, IOException {
Cookie c = new Cookie("msg", "hello");
response.addCookie(c);
}
protected void doGet(HttpServletRequest request, HttpServletResponse response) throws ServletException, IOException {
this.doPost(request, response);
}
}
import javax.servlet.ServletException;
import javax.servlet.annotation.WebServlet;
import javax.servlet.http.Cookie;
import javax.servlet.http.HttpServlet;
import javax.servlet.http.HttpServletRequest;
import javax.servlet.http.HttpServletResponse;
import java.io.IOException;
@WebServlet("/CookieDemo2")
public class CookieDemo2 extends HttpServlet {
protected void doPost(HttpServletRequest request, HttpServletResponse response) throws ServletException, IOException {
Cookie[] cookies = request.getCookies();
if(cookies != null){
for (Cookie c: cookies) {
String name = c.getName();
String value = c.getValue();
System.out.println(name + ":" + value);
}
}
}
protected void doGet(HttpServletRequest request, HttpServletResponse response) throws ServletException, IOException {
this.doPost(request, response);
}
}
2.3 实现原理
- 基于响应头set-cookie和请求头cookie实现
- Cookie是服务器端创建,客户端保存(默认浏览器的缓存中)
- Cookie是基于HTTP协议的
- Cookie可以在客户端与服务器端传递数据
 
2.4 Cookie的细节
-
1、一次可不可以发送多个Cookie?
可以
- 可以创建多个Cookie对象,使用response调用多次addCookie方法发送Cookie即可(
Set-Cookie msg=hello;Set-Cookie username=cookieName;Set-Cookie password=123456 )。 - 使用request获取Cookie时,接收到多个Cookie对象(
Cookie msg=hello; username=cookieName; password=123456 )。
-
2、Cookie在浏览器中保存多长时间?
Cookie由服务器创建,存储在客户端浏览器中,所以不能通过方法直接删除,可以通过配置Cookie的存活时间进行删除,也可以将Cookie的value设置为空字符串。 1、默认情况下,当浏览器关闭后,Cookie数据被销毁。 2、设置Cookie生命周期,让Cookie数据持久化存储:
setMaxAge(int seconds)
- 正数:将Cookie数据写到硬盘的文件中,实现Cookie数据的持久化存储。并指定Cookie存活时间,时间到后,Cookie文件自动失效。
- 负数:默认值。
- 零:删除Cookie信息。
Cookie c = new Cookie("msg", "serMaxAge");
c.setMaxAge(0);
response.addCookie(c);
-
3、Cookie能不能存中文?
1、在Tomcat 8 之前 Cookie中不能直接存储中文数据。
- 需要将中文数据转码——一般采用URL编码(%E3)
2、在Tomcat 8 之后,Cookie支持中文数据。特殊字符还是不支持,建议使用URL编码存储,URL解码解析。 URLDecoder.decode(value,"utf-8");
-
4、Cookie共享问题?
2.5 Cookie的特点和作用
- 特点:
1、Cookie存储数据在客户端浏览器。 2、浏览器对于单个Cookie 的大小有限制(4kb) 以及 对同一个域名下的总Cookie数量也有限制(20个)。
- 作用:
1、Cookie一般用于存出少量的不太敏感的数据。 2、在不登录的情况下,完成服务器对客户端的身份识别。
2.6 案例
2.6.1 记住上一次访问时间
-
需求:
1、访问一个Servlet,如果是第一次访问,则提示:您好,欢迎您首次访问。 2、如果不是第一次访问,则提示:欢迎回来,您上次访问时间为:显示时间字符串。
-
分析:
1、可以采用Cookie来完成 2、在服务器中的Servlet判断是否有一个名为lastTime的Cookie:
- 1、有:不是第一次访问
- 1、响应数据:欢迎回来,您上次访问时间为:2018年6月10日11:50:20
- 2、写回Cookie:lastTime=2018年6月10日11:50:01
- 2、没有:是第一次访问
- 1、响应数据:您好,欢迎您首次访问
- 2、写回Cookie:lastTime=2018年6月10日11:50:01
-
代码实现:
import javax.servlet.ServletException;
import javax.servlet.annotation.WebServlet;
import javax.servlet.http.Cookie;
import javax.servlet.http.HttpServlet;
import javax.servlet.http.HttpServletRequest;
import javax.servlet.http.HttpServletResponse;
import java.io.IOException;
import java.net.URLDecoder;
import java.net.URLEncoder;
import java.text.SimpleDateFormat;
import java.util.Date;
@WebServlet("/cookieTest")
public class CookieTest extends HttpServlet {
protected void doPost(HttpServletRequest request, HttpServletResponse response) throws ServletException, IOException {
response.setContentType("text/html;charset=utf-8");
Cookie[] cookies = request.getCookies();
boolean flag = false;
if (cookies != null && cookies.length > 0){
for (Cookie cookie : cookies) {
String name = cookie.getName();
if("lastTime".equals(name)){
flag = true;
Date date = new Date();
SimpleDateFormat sdf = new SimpleDateFormat("yyyy年MM月dd日 HH:mm:ss");
String str_date = sdf.format(date);
System.out.println("编码前:"+str_date);
str_date = URLEncoder.encode(str_date,"utf-8");
System.out.println("编码后:"+str_date);
cookie.setValue(str_date);
cookie.setMaxAge(60 * 60 * 24 * 30);
response.addCookie(cookie);
String value = cookie.getValue();
System.out.println("解码前:"+value);
value = URLDecoder.decode(value,"utf-8");
System.out.println("解码后:"+value);
response.getWriter().write("<h1>欢迎回来,您上次访问时间为:"+value+"</h1>");
break;
}
}
}
if (cookies == null || cookies.length == 0 || flag == false){
Date date = new Date();
SimpleDateFormat sdf = new SimpleDateFormat("yyyy年MM月dd日 HH:mm:ss");
String str_date = sdf.format(date);
System.out.println("编码前:"+str_date);
str_date = URLEncoder.encode(str_date,"utf-8");
System.out.println("编码后:"+str_date);
Cookie cookie = new Cookie("lastTime",str_date);
cookie.setMaxAge(60 * 60 * 24 * 30);
response.addCookie(cookie);
response.getWriter().write("<h1>您好,欢迎您首次访问</h1>");
}
}
protected void doGet(HttpServletRequest request, HttpServletResponse response) throws ServletException, IOException {
this.doPost(request, response);
}
}
2.6.2 显示用户浏览历史记录
import javax.servlet.ServletException;
import javax.servlet.annotation.WebServlet;
import javax.servlet.http.Cookie;
import javax.servlet.http.HttpServlet;
import javax.servlet.http.HttpServletRequest;
import javax.servlet.http.HttpServletResponse;
import java.io.IOException;
@WebServlet("/historyServlet")
public class HistoryServlet extends HttpServlet {
protected void doPost(HttpServletRequest request, HttpServletResponse response) throws ServletException, IOException {
String pid = request.getParameter("pid");
Cookie[] cks = request.getCookies();
Cookie cookie = null;
if(cks != null){
for (Cookie c : cks) {
if(c.getName().equals("history")){
cookie = c;
}
}
}
if(cookie == null){
cookie = new Cookie("history", pid+"-");
}else{
String lishi = cookie.getValue();
StringBuilder sb = new StringBuilder(lishi);
if(sb.indexOf(pid) != -1){
}else{
sb.insert(0, pid+"-");
}
lishi = sb.toString();
cookie.setValue(lishi);
}
response.addCookie(cookie);
response.sendRedirect("/day0813_cookie/index.jsp");
}
protected void doGet(HttpServletRequest request, HttpServletResponse response) throws ServletException, IOException {
this.doPost(request, response);
}
}
<%@ page contentType="text/html;charset=UTF-8" language="java" %>
<html>
<head>
<title>index</title>
<style type="text/css">
img{
width:400px;
}
</style>
</head>
<body>
<h2>商品列表</h2>
<div>
<a href="/day0813_cookie/historyServlet?pid=1"><img alt="" src="./image/1.jpg"></a>
</div>
<div>
<a href="/day0813_cookie/historyServlet?pid=2"><img alt="" src="./image/2.jpg"></a>
</div>
<div>
<a href="/day0813_cookie/historyServlet?pid=3"><img alt="" src="./image/3.jpg"></a>
</div>
<div>
<a href="/day0813_cookie/historyServlet?pid=4"><img alt="" src="./image/4.jpg"></a>
</div>
<h2>历史浏览记录</h2>
<%
Cookie [] ck = request.getCookies();
if(ck != null){
for(Cookie cookie : ck){
if(cookie.getName().equals("history")){
String lishi = cookie.getValue();
String [] goodsId = lishi.split("-");
for(int i = 0;i<goodsId.length;i++){
%>
<img alt="" src="./image/<%=goodsId[i] %>.jpg">
<%
}
}
}
}
%>
</body>
</html>
三、Session
3.1 概念
Session:服务器端会话技术,在一次会话的多次请求间共享数据,将数据保存在服务器端的对象中。HttpSession
- 服务器在运行时为每一个用户创建一个独享的session对象
- 每个用户在访问服务器过程中,产生的数据可以放在Session对象中
- 每个用户需要保存个人的,每次访问服务器的时候,都携带个人的sessionid
- Session技术基于Cookie,使用Cookie传递sessionid。
3.2 快速入门
3.2.1 Session有关的API
方法名 | 功能 |
---|
void setAttribute(String name, Object value) | 向域对象存入值 | Object getAttribute(String name) | 域对象取值 | void removeAttribute(String name) | 域对象删除值 | String getId() | session的空间有唯一的id值,获取该id值的。 | void invalidate() | 销毁session对象 | ServletContext getServletContext() | 获取ServletContext域对象 |
3.2.2 使用步骤
1、获取HttpSession对象:
HttpSession session = request.getSession();
2、使用HttpSession对象:
Object getAttribute(String name) :获取域对象的值void setAttribute(String name, Object value) :设置域对象的值void removeAttribute(String name) :移除域对象的值
import javax.servlet.ServletException;
import javax.servlet.annotation.WebServlet;
import javax.servlet.http.HttpServlet;
import javax.servlet.http.HttpServletRequest;
import javax.servlet.http.HttpServletResponse;
import javax.servlet.http.HttpSession;
import java.io.IOException;
@WebServlet("/sessionDemo1")
public class SessionDemo1 extends HttpServlet {
protected void doPost(HttpServletRequest request, HttpServletResponse response) throws ServletException, IOException {
HttpSession session = request.getSession();
session.setAttribute("msg","hello,Session");
}
protected void doGet(HttpServletRequest request, HttpServletResponse response) throws ServletException, IOException {
this.doPost(request, response);
}
}
import javax.servlet.ServletException;
import javax.servlet.annotation.WebServlet;
import javax.servlet.http.HttpServlet;
import javax.servlet.http.HttpServletRequest;
import javax.servlet.http.HttpServletResponse;
import javax.servlet.http.HttpSession;
import java.io.IOException;
@WebServlet("/sessionDemo2")
public class SessionDemo2 extends HttpServlet {
protected void doPost(HttpServletRequest request, HttpServletResponse response) throws ServletException, IOException {
HttpSession session = request.getSession();
Object msg = session.getAttribute("msg");
System.out.println(msg);
}
protected void doGet(HttpServletRequest request, HttpServletResponse response) throws ServletException, IOException {
this.doPost(request, response);
}
}
3.3 实现原理
 
3.4 Session的细节
- 1、当客户端关闭后,服务器不关闭,两次获取Session是否为同一个?
1、默认情况下,服务器不关闭,客户端关闭前后两次获取的Session不是同一个。 2、如果需要相同,则可以创建Cookie,键为JSESSIONID,设置最大存活时间,让Cookie持久化保存。 Cookie c = new Cookie("JSESSIONID",session.getId()); c.setMaxAge(60*60); response.addCookie(c);
import javax.servlet.ServletException;
import javax.servlet.annotation.WebServlet;
import javax.servlet.http.*;
import java.io.IOException;
@WebServlet("/sessionDemo3")
public class SessionDemo3 extends HttpServlet {
protected void doPost(HttpServletRequest request, HttpServletResponse response) throws ServletException, IOException {
HttpSession session = request.getSession();
System.out.println(session);
Cookie c = new Cookie("JSESSIONID", session.getId());
c.setMaxAge(60 * 60);
response.addCookie(c);
}
protected void doGet(HttpServletRequest request, HttpServletResponse response) throws ServletException, IOException {
this.doPost(request, response);
}
}
//选择性配置修改
<session-config>
<session-timeout>30</session-timeout>
</session-config>
3.5 Session的特点
1、Session用于存储一次会话中多次请求的数据,存在服务器端。 2、Session可以存储任意类型,任意大小的数据。
- Session与Cookie的区别:
1、Session存储数据在服务器端,Cookie在客户端 2、Session没有数据大小限制,Cookie有 3、Session数据安全,Cookie相对于不安全
3.6 案例
3.6.1 验证码
- 案例需求:
1、访问带有验证码的登录页面login.jsp 2、用户输入用户名,密码以及验证码。
- 如果用户名和密码输入有误,跳转登录页面,提示:用户名或密码错误
- 如果验证码输入有误,跳转登录页面,提示:验证码错误
- 如果全部输入正确,则跳转到主页success.jsp,显示:用户名,欢迎您
equalsIgnoreCase() :忽略大小写进行字符串比较。
- 分析:
 - 代码实现:
<%@ page contentType="text/html;charset=UTF-8" language="java" %>
<html>
<head>
<title>success</title>
</head>
<body>
<h1><%=request.getSession().getAttribute("user")%>,欢迎您</h1>
</body>
</html>
<%@ page contentType="text/html;charset=UTF-8" language="java" %>
<html>
<head>
<title>login</title>
<script>
window.onload = function () {
document.getElementById("img").onclick = function () {
this.src = "/day0813_sessionLoginTest/checkCodeServlet?time=" + new Date().getTime();
}
}
</script>
<style>
div {
color: red;
}
</style>
</head>
<body>
<form action="/day0813_sessionLoginTest/loginServlet" method="post">
<table>
<tr>
<td>用户名</td>
<td><input type="text" name="username"></td>
</tr>
<tr>
<td>密码</td>
<td><input type="password" name="password"></td>
</tr>
<tr>
<td>验证码</td>
<td><input type="text" name="checkCode"></td>
</tr>
<tr>
<td colspan="2"><img id="img" src="/day0813_sessionLoginTest/checkCodeServlet"></td>
</tr>
<tr>
<td colspan="2"><input type="submit" value="登录"></td>
</tr>
</table>
</form>
<div><%=request.getAttribute("cc_error") == null ? "" : request.getAttribute("cc_error")%>
</div>
<div><%=request.getAttribute("login_error") == null ? "" : request.getAttribute("login_error") %>
</div>
</body>
</html>
import javax.servlet.ServletException;
import javax.servlet.annotation.WebServlet;
import javax.servlet.http.HttpServlet;
import javax.servlet.http.HttpServletRequest;
import javax.servlet.http.HttpServletResponse;
import javax.servlet.http.HttpSession;
import java.io.IOException;
@WebServlet("/loginServlet")
public class LoginServlet extends HttpServlet {
protected void doPost(HttpServletRequest request, HttpServletResponse response) throws ServletException, IOException {
request.setCharacterEncoding("utf-8");
String username = request.getParameter("username");
String password = request.getParameter("password");
String checkCode = request.getParameter("checkCode");
HttpSession session = request.getSession();
String checkCode_session = (String) session.getAttribute("checkCode_session");
session.removeAttribute("checkCode_session");
if(checkCode_session!= null && checkCode_session.equalsIgnoreCase(checkCode)){
if("zhangsan".equals(username) && "123".equals(password)){
session.setAttribute("user",username);
response.sendRedirect(request.getContextPath()+"/success.jsp");
}else{
request.setAttribute("login_error","用户名或密码错误");
request.getRequestDispatcher("/login.jsp").forward(request,response);
}
}else{
request.setAttribute("cc_error","验证码错误");
request.getRequestDispatcher("/login.jsp").forward(request,response);
}
}
protected void doGet(HttpServletRequest request, HttpServletResponse response) throws ServletException, IOException {
this.doPost(request, response);
}
}
import javax.imageio.ImageIO;
import javax.servlet.ServletException;
import javax.servlet.annotation.WebServlet;
import javax.servlet.http.HttpServlet;
import javax.servlet.http.HttpServletRequest;
import javax.servlet.http.HttpServletResponse;
import java.awt.*;
import java.awt.image.BufferedImage;
import java.io.IOException;
import java.util.Random;
@WebServlet("/checkCodeServlet")
public class CheckCodeServlet extends HttpServlet {
protected void doPost(HttpServletRequest request, HttpServletResponse response) throws ServletException, IOException {
int width = 100;
int height = 50;
BufferedImage image = new BufferedImage(width,height,BufferedImage.TYPE_INT_RGB);
Graphics g = image.getGraphics();
g.setColor(Color.PINK);
g.fillRect(0,0,width,height);
g.setColor(Color.BLUE);
g.drawRect(0,0,width - 1,height - 1);
String str = "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghigklmnopqrstuvwxyz0123456789";
Random ran = new Random();
StringBuilder sb = new StringBuilder();
for (int i = 1; i <= 4; i++) {
int index = ran.nextInt(str.length());
char ch = str.charAt(index);
sb.append(ch);
g.drawString(ch+"",width/5*i,height/2);
}
String checkCode_session = sb.toString();
request.getSession().setAttribute("checkCode_session",checkCode_session);
g.setColor(Color.GREEN);
for (int i = 0; i < 10; i++) {
int x1 = ran.nextInt(width);
int x2 = ran.nextInt(width);
int y1 = ran.nextInt(height);
int y2 = ran.nextInt(height);
g.drawLine(x1,y1,x2,y2);
}
ImageIO.write(image,"jpg",response.getOutputStream());
}
protected void doGet(HttpServletRequest request, HttpServletResponse response) throws ServletException, IOException {
this.doPost(request, response);
}
}
3.6.2 购物车
<%@ page contentType="text/html;charset=UTF-8" language="java" %>
<html>
<head>
<title>$Title$</title>
<style type="text/css">
img{
width:200px;
}
</style>
</head>
<body>
<h2>商品列表</h2>
<div>
<img alt="" src="./image/1.jpg">
<a href="/day0813_sessionTest/addCartServlet?pid=1">添加到购物车</a>
</div>
<div>
<img alt="" src="./image/2.jpg">
<a href="/day0813_sessionTest/addCartServlet?pid=2">添加到购物车</a>
</div>
<div>
<img alt="" src="./image/3.jpg">
<a href="/day0813_sessionTest/addCartServlet?pid=3">添加到购物车</a>
</div>
<div>
<img alt="" src="./image/4.jpg">
<a href="/day0813_sessionTest/addCartServlet?pid=4">添加到购物车</a>
</div>
</body>
</html>
<%@ page contentType="text/html;charset=UTF-8" language="java" %>
<html>
<head>
<title>addCartSucc</title>
</head>
<body>
<h2>添加成功页面</h2>
<a href="./index.jsp">继续剁手</a>
<a href="./cart.jsp">结算</a>
</body>
</html>
<%@page import="org.apache.jasper.tagplugins.jstl.core.ForTokens"%>
<%@page import="java.util.HashMap"%>
<%@page import="java.util.Map"%>
<%@page import="java.util.Set"%>
<%@ taglib prefix="c" uri="http://java.sun.com/jsp/jstl/core" %>
<%@ page contentType="text/html;charset=UTF-8" language="java" %>
<html>
<head>
<title>cart</title>
</head>
<body>
<h2>购物车页面</h2>
<c:choose>
<c:when test="${empty sessionScope.cart }">
没有数据
</c:when>
<c:otherwise>
<c:forEach var ="good" items="${sessionScope.cart }">
${good }
</c:forEach>
</c:otherwise>
</c:choose>
</body>
</html>
import javax.servlet.ServletException;
import javax.servlet.annotation.WebServlet;
import javax.servlet.http.HttpServlet;
import javax.servlet.http.HttpServletRequest;
import javax.servlet.http.HttpServletResponse;
import javax.servlet.http.HttpSession;
import java.io.IOException;
import java.util.HashMap;
@WebServlet("/addCartServlet")
public class AddCartServlet extends HttpServlet {
protected void doPost(HttpServletRequest request, HttpServletResponse response) throws ServletException, IOException {
String pid = request.getParameter("pid");
HttpSession session = request.getSession();
Object o = session.getAttribute("cart");
if(o == null){
HashMap<String, Integer> map = new HashMap<String, Integer>();
map.put(pid, 1);
session.setAttribute("cart", map);
}else{
HashMap<String, Integer> map = (HashMap<String,Integer>)o;
if(map.containsKey(pid)){
Integer count = map.get(pid);
count++;
map.put(pid, count);
}else{
map.put(pid, 1);
}
System.out.println(map);
}
response.sendRedirect("/day0813_sessionTest/addCartSucc.jsp");
}
protected void doGet(HttpServletRequest request, HttpServletResponse response) throws ServletException, IOException {
this.doPost(request, response);
}
}
每日一点点进步 不进则退
|