RError.com

RError.com Logo RError.com Logo

RError.com Navigation

  • 主页

Mobile menu

Close
  • 主页
  • 系统&网络
    • 热门问题
    • 最新问题
    • 标签
  • Ubuntu
    • 热门问题
    • 最新问题
    • 标签
  • 帮助
主页 / 问题 / 1480460
Accepted
ulxanxv
ulxanxv
Asked:2022-12-23 17:52:23 +0000 UTC2022-12-23 17:52:23 +0000 UTC 2022-12-23 17:52:23 +0000 UTC

成功生成响应后如何更改响应标头?

  • 772

大家好!许多人都熟悉 class javax.servlet.Filter,它允许您在请求生命周期中嵌入自己的逻辑,我对此有疑问:

public class CorsFilter implements Filter {

    private static final String ACCESS_CONTROL_ALLOW_ORIGIN = "Access-Control-Allow-Origin";
    private static final String ACCESS_CONTROL_ALLOW_HEADERS = "Access-Control-Allow-Headers";
    private static final String ACCESS_CONTROL_ALLOW_METHODS = "Access-Control-Allow-Methods";
    private static final String ALLOW = "Allow";

    @Override
    public void init(FilterConfig filterConfig) {
        // NO LOGIC
    }

    @Override
    public void doFilter(ServletRequest req, ServletResponse resp, FilterChain chain) throws IOException, ServletException {
        chain.doFilter(req, resp);

        final HttpServletResponse response = (HttpServletResponse) resp;
        
        final Collection<String> headers = response.getHeaderNames();
        if (notContainHeaderWithIgnoreCase(headers, ACCESS_CONTROL_ALLOW_ORIGIN)) {
            response.addHeader(ACCESS_CONTROL_ALLOW_ORIGIN, "*");
        }
        if (notContainHeaderWithIgnoreCase(headers, ACCESS_CONTROL_ALLOW_HEADERS)) {
            response.addHeader(ACCESS_CONTROL_ALLOW_HEADERS, "*");
        }
        if (notContainHeaderWithIgnoreCase(headers, ACCESS_CONTROL_ALLOW_METHODS)) {
            response.addHeader(ACCESS_CONTROL_ALLOW_METHODS, "GET, POST, PUT, DELETE, OPTIONS");
        }
        if (notContainHeaderWithIgnoreCase(headers, ALLOW)) {
            response.addHeader(ALLOW, "GET, POST, PUT, DELETE, OPTIONS");
        }
    }

    private boolean notContainHeaderWithIgnoreCase(Collection<String> headers, String name) {
        return headers.stream().noneMatch(header -> header.equalsIgnoreCase(name));
    }

    @Override
    public void destroy() {
        // NO LOGIC
    }
}

在这个过滤器中,在形成响应后,我尝试查看其中是否有CORS标题,如果没有,则将它们放下。我不能在生成响应之前执行此操作,因为该服务有时会代理请求并且第三方服务也会CORS放下,从而复制它。

此实现不起作用,因为生成响应后,它被标记为commited并且无法更改。怎样成为?

java
  • 1 1 个回答
  • 32 Views

1 个回答

  • Voted
  1. Best Answer
    ulxanxv
    2022-12-24T14:47:25Z2022-12-24T14:47:25Z

    我想通了问题,结果是这样的(也许有人会需要它):

    public class CorsFilter implements Filter {
    
        private static final String ACCESS_CONTROL_ALLOW_ORIGIN = "Access-Control-Allow-Origin";
        private static final String ACCESS_CONTROL_ALLOW_HEADERS = "Access-Control-Allow-Headers";
        private static final String ACCESS_CONTROL_ALLOW_METHODS = "Access-Control-Allow-Methods";
        private static final String ALLOW = "Allow";
    
        @Override
        public void doFilter(ServletRequest req, ServletResponse resp, FilterChain filterChain) throws IOException, ServletException {
            final ResponseWrapper wrapper = new ResponseWrapper(
                    (HttpServletResponse) resp);
    
            filterChain.doFilter(req, wrapper);
    
            setCorsHeaders((HttpServletResponse) resp);
            copyResponseToOriginalResponse(wrapper, resp);
        }
    
        private void setCorsHeaders(HttpServletResponse response) {
            final HeaderNames headerNames = new HeaderNames(response.getHeaderNames());
            if (headerNames.notContainsIgnoreCase(ACCESS_CONTROL_ALLOW_ORIGIN)) {
                response.addHeader(ACCESS_CONTROL_ALLOW_ORIGIN, "*");
            }
            if (headerNames.notContainsIgnoreCase(ACCESS_CONTROL_ALLOW_HEADERS)) {
                response.addHeader(ACCESS_CONTROL_ALLOW_HEADERS, "*");
            }
            if (headerNames.notContainsIgnoreCase(ACCESS_CONTROL_ALLOW_METHODS)) {
                response.addHeader(ACCESS_CONTROL_ALLOW_METHODS, "GET, POST, PUT, DELETE, OPTIONS");
            }
            if (headerNames.notContainsIgnoreCase(ALLOW)) {
                response.addHeader(ALLOW, "GET, POST, PUT, DELETE, OPTIONS");
            }
        }
    
        private void copyResponseToOriginalResponse(ResponseWrapper wrapper, ServletResponse response) throws IOException {
            final ServletOutputStream outputStream = response.getOutputStream();
            outputStream.write(wrapper.getCaptureAsBytes());
        }
    
        private static final class ResponseWrapper extends HttpServletResponseWrapper {
    
            private final ByteArrayOutputStream capture;
            private ServletOutputStream output;
            private PrintWriter writer;
    
            public ResponseWrapper(HttpServletResponse response) {
                super(response);
                capture = new ByteArrayOutputStream(response.getBufferSize());
            }
    
            @Override
            public ServletOutputStream getOutputStream() {
                if (writer != null) {
                    throw new IllegalStateException("getWriter() has already been called on this response.");
                }
    
                if (output == null) {
                    output = new ServletOutputStream() {
                        @Override
                        public void write(int b) throws IOException {
                            capture.write(b);
                        }
    
                        @Override
                        public void flush() throws IOException {
                            capture.flush();
                        }
    
                        @Override
                        public void close() throws IOException {
                            capture.close();
                        }
    
                        @Override
                        public boolean isReady() {
                            return false;
                        }
    
                        @Override
                        public void setWriteListener(WriteListener arg0) {
                        }
                    };
                }
    
                return output;
            }
    
            @Override
            public PrintWriter getWriter() throws IOException {
                if (output != null) {
                    throw new IllegalStateException("getOutputStream() has already been called on this response.");
                }
    
                if (writer == null) {
                    writer = new PrintWriter(new OutputStreamWriter(capture, getCharacterEncoding()));
                }
    
                return writer;
            }
    
            @Override
            public void flushBuffer() throws IOException {
                super.flushBuffer();
    
                if (writer != null) {
                    writer.flush();
                } else if (output != null) {
                    output.flush();
                }
            }
    
            public byte[] getCaptureAsBytes() throws IOException {
                if (writer != null) {
                    writer.close();
                } else if (output != null) {
                    output.close();
                }
    
                return capture.toByteArray();
            }
        }
    
        @Override
        public void init(FilterConfig filterConfig) {
            /* NO LOGIC */
        }
    
        @Override
        public void destroy() {
            /* NO LOGIC */
        }
    }
    
    • 0

相关问题

  • wpcap 找不到指定的模块

  • 如何以编程方式从桌面应用程序打开 HTML 页面?

  • Android Studio 中的 R.java 文件在哪里?

  • HashMap 初始化

  • 如何使用 lambda 表达式通过增加与原点的距离来对点进行排序?

  • 最大化窗口时如何调整元素大小?

Sidebar

Stats

  • 问题 10021
  • Answers 30001
  • 最佳答案 8000
  • 用户 6900
  • 常问
  • 回答
  • Marko Smith

    我看不懂措辞

    • 1 个回答
  • Marko Smith

    请求的模块“del”不提供名为“default”的导出

    • 3 个回答
  • Marko Smith

    "!+tab" 在 HTML 的 vs 代码中不起作用

    • 5 个回答
  • Marko Smith

    我正在尝试解决“猜词”的问题。Python

    • 2 个回答
  • Marko Smith

    可以使用哪些命令将当前指针移动到指定的提交而不更改工作目录中的文件?

    • 1 个回答
  • Marko Smith

    Python解析野莓

    • 1 个回答
  • Marko Smith

    问题:“警告:检查最新版本的 pip 时出错。”

    • 2 个回答
  • Marko Smith

    帮助编写一个用值填充变量的循环。解决这个问题

    • 2 个回答
  • Marko Smith

    尽管依赖数组为空,但在渲染上调用了 2 次 useEffect

    • 2 个回答
  • Marko Smith

    数据不通过 Telegram.WebApp.sendData 发送

    • 1 个回答
  • Martin Hope
    Alexandr_TT 2020年新年大赛! 2020-12-20 18:20:21 +0000 UTC
  • Martin Hope
    Alexandr_TT 圣诞树动画 2020-12-23 00:38:08 +0000 UTC
  • Martin Hope
    Air 究竟是什么标识了网站访问者? 2020-11-03 15:49:20 +0000 UTC
  • Martin Hope
    Qwertiy 号码显示 9223372036854775807 2020-07-11 18:16:49 +0000 UTC
  • Martin Hope
    user216109 如何为黑客设下陷阱,或充分击退攻击? 2020-05-10 02:22:52 +0000 UTC
  • Martin Hope
    Qwertiy 并变成3个无穷大 2020-11-06 07:15:57 +0000 UTC
  • Martin Hope
    koks_rs 什么是样板代码? 2020-10-27 15:43:19 +0000 UTC
  • Martin Hope
    Sirop4ik 向 git 提交发布的正确方法是什么? 2020-10-05 00:02:00 +0000 UTC
  • Martin Hope
    faoxis 为什么在这么多示例中函数都称为 foo? 2020-08-15 04:42:49 +0000 UTC
  • Martin Hope
    Pavel Mayorov 如何从事件或回调函数中返回值?或者至少等他们完成。 2020-08-11 16:49:28 +0000 UTC

热门标签

javascript python java php c# c++ html android jquery mysql

Explore

  • 主页
  • 问题
    • 热门问题
    • 最新问题
  • 标签
  • 帮助

Footer

RError.com

关于我们

  • 关于我们
  • 联系我们

Legal Stuff

  • Privacy Policy

帮助

© 2023 RError.com All Rights Reserve   沪ICP备12040472号-5