在Spring WebFlow中优雅地处理过期的HttpSession

dbr*_*aux 6 spring-webflow

(来自SpringSource论坛.)

当HttpSession已经过期并且用户在流程中重新提交页面时,他/她被发送回流程的开头.我想要添加到此行为的所有内容都是一条消息,解释了它发生的原因."你没有活动,所以你已经重新启动......"

最简单/最佳实践方法是什么?

dbr*_*aux 5

FlowHandlerAdapter.defaultHandleException() 中的默认行为“尝试开始新的已结束或过期流的执行”。

它看起来像一个Webflow的方式来处理,这将是提供FlowHandler一个handleException()方法,对于一个检查instanceof NoSuchFlowExecutionException,然后像做结构上的会话范围重定向URL或地方的东西,一旦使用以后可以去除。

由于 WebFlow 使用重定向的方式,我认为任何其他范围都不允许在新流的视图呈现时稍后使用此类标志或消息。

然而,简单地检测一个Interceptor或什Filter至a 中的新会话似乎同样有效。正如引用的论坛帖子中所记录的那样,这就是我在之前对此进行的调查中最终做的事情。我只是希望有更漂亮的东西。

此外,在新流开始时,已经创建了一个新的会话 ID,因此无法从 flow.xml 中最初检测到这种情况。

示例过滤器逻辑:

if (request.getRequestedSessionId() != null && !request.isRequestedSessionIdValid()) {
    log.info("Expired Session ID: " + request.getRequestedSessionId());
    response.sendRedirect("sessionExpired");
}
else {
    chain.doFilter(request, response);
}
Run Code Online (Sandbox Code Playgroud)

示例拦截器:

public class SessionExpiredInterceptor extends HandlerInterceptorAdapter
{
    private String redirectLocation = "sessionExpired";

    @Override
    public boolean preHandle(HttpServletRequest request, HttpServletResponse response,
        Object handler) throws Exception
    {
        if (request.getRequestedSessionId() != null && !request.isRequestedSessionIdValid())
        {
            response.sendRedirect(redirectLocation);
            return false;
        }

        return true;
    }

    public String getRedirectLocation() {
        return redirectLocation;
    }

    public void setRedirectLocation(String redirectLocation) {
        this.redirectLocation = redirectLocation;
    }
}
Run Code Online (Sandbox Code Playgroud)