【问题标题】:Dropwizard validate a field only on @POSTDropwizard 仅在 @POST 上验证字段
【发布时间】:2016-05-26 14:21:20
【问题描述】:

我有这些需要安全的只读字段,例如密码。假设我们有一个用户对象:

public class User {
  @NotEmpty
  @Size(max = 100)
  private String name;
  @NotEmpty
  private String username;
  @NotEmpty
  @Email
  private String email;
  private String password;

  @JsonIgnore
  public String getPassword() {
    return password;
  }

  @JsonProperty
  public void setPassword(String password) {
    this.password = password;
  }
}

所以,这很好用;因为我可以获取/发布/放置我想要的任何东西,但我永远不会收到密码。但我也想确保第一次发布时,密码不应该为空。如果我这样做了

@NotEmpty
private string password;

如果我不想更改此用户的密码,我的 PUT(编辑)请求将失败并出现验证错误。

我能想到两种解决方案:

1-继承User类,只为POST创建一个特殊类,可以在getter上加上@NotEmpty注解。

public static class Create extends User {
  @NotEmpty
  @Override
  public String getPassword() {
    return password;
  }
}

这应该可以正常工作,但不适用于我的代码库,因为它已经在 CRUD 资源上大量使用了继承。对于这种方法,我需要打破和复制很多东西。

2- 处理资源类的验证:

public class UserResource {

  @POST
  public User createUser(User user) {
    if(user.getPassword().isEmpty()) {
      throw new ConstraintValidation....();
    }
  }
}

做得很好,但不是那么漂亮。特别是因为我有 5-10 个。

还有其他选择吗?

【问题讨论】:

  • 您能否制作自己的验证器实现而不是使用默认的验证器,然后进行更复杂的检查?例如,您可以有一个验证器来检查用户是否存在(如果不是您正在创建),然后根据它验证密码。我认为您无法访问验证器中的资源类型,除非您实现一个球衣过滤器,将您的方法类型存储在 threadLocal 或类似的愚蠢的东西中。
  • 实际上,读取球衣信息,您可以将 UriInfo 注入您的验证器中。然后,根据调用的资源方法进行验证不会有任何问题。见:jersey.java.net/documentation/latest/bean-validation.html
  • 啊哈,我实际上已经考虑过这一点,并检查了 ConstraintValidatorContext 的字段,看看我是否能找到相关的东西。没想到球衣注射。我想这也适用于hibernate-validator,对吧?如果是这样,您可以创建一个答案,我可以标记它。谢谢!
  • 找到了一个我认为更好的方法 :) 希望它有所帮助

标签: java jersey-2.0 dropwizard hibernate-validator


【解决方案1】:

除了球衣注入和自定义验证器之外,我发现了一个更酷、更简单、更流畅的解决方案,我认为你可能会感兴趣,Natan:

DW 支持验证组。有了这些,您可以根据您的方法决定要注释的内容,而无需验证知道该方法。您可以在此处阅读更多相关信息:

http://www.dropwizard.io/0.9.0/docs/manual/validation.html

(我在示例中使用的是 RC 版本)。

让我们开始吧:

@Path("/hello/world")
@Produces(MediaType.APPLICATION_JSON)
public class HelloWorldResource {

    @POST
    @Path("/v1")
    @Consumes(MediaType.APPLICATION_JSON)
    @Produces(MediaType.APPLICATION_JSON)
    public Response test(@Valid @Validated(V1Check.class) User user) {
        // checks only username
        System.out.println(user.getName());
        System.out.println(user.getPassword());

        return Response.ok().build();
    }


    @POST
    @Path("/v2")
    @Consumes(MediaType.APPLICATION_JSON)
    @Produces(MediaType.APPLICATION_JSON)
    public Response test2(@Valid @Validated(V2Check.class) User user) {
        // checks both
        System.out.println(user.getName());
        System.out.println(user.getPassword());

        return Response.ok().build();
    }
}

这是资源类。看看我是如何用@Validated 注释这两种方法的。这告诉 DW 要准确验证什么。

这是我的用户类:

public class User {

    @JsonProperty("name")
    private String name;

    @JsonProperty("password")
    private String password;

    @NotEmpty(message="other message", groups= {V2Check.class} )
    public String getPassword() {
        return password;
    }

    public void setPassword(String password) {
        this.password = password;
    }

    @NotEmpty(message="asd asd asd", groups= {V1Check.class, V2Check.class } )
    public String getName() {
        return name;
    }

    public void setName(String name) {
        this.name = name;
    }

    public interface V1Check {};
    public interface V2Check {};
}

我也在那个类中嵌入了接口。密码现在只检查了 V2。因此,对于您的 POST 方法,您需要将其添加到 Validated 注释中,而您的 get 方法可以保持 V1 检查并忽略密码。

为了更好的衡量,我的测试的首发:

public class Starter extends Application<Configuration> {

    @Override
    public void run(Configuration configuration, Environment environment) throws Exception {
        environment.jersey().register(HelloWorldResource.class);
    }

    public static void main(String[] args) throws Exception {
        new Starter().run("server", "/Users/artur/dev/repo/dw-test/src/main/resources/configuration.yaml");
    }

}

这是执行此操作的 DW 方法,但是您也应该能够将球衣注入添加到您的自定义验证器中。似乎没有必要编写自定义验证器,因为您不需要检查密码。

这是我的卷发。 user_json2:

{
    "name" : "artur"
}

V1,不检查密码:

arturk:tmp artur$ curl -XPOST "localhost:9085/hello/world/v1/" --header "Content-Type: application/json" -d @user_json2 -v
    *   Trying ::1...
    * Connected to localhost (::1) port 9085 (#0)
    > POST /hello/world/v1/ HTTP/1.1
    > Host: localhost:9085
    > User-Agent: curl/7.43.0
    > Accept: */*
    > Content-Type: application/json
    > Content-Length: 19
    >
    * upload completely sent off: 19 out of 19 bytes
    < HTTP/1.1 200 OK
    < Date: Fri, 27 May 2016 09:59:22 GMT
    < Content-Length: 0
    <
    * Connection #0 to host localhost left intact

V2,检查密码:

arturk:tmp artur$ curl -XPOST "localhost:9085/hello/world/v2/" --header "Content-Type: application/json" -d @user_json2 -v
*   Trying ::1...
* Connected to localhost (::1) port 9085 (#0)
> POST /hello/world/v2/ HTTP/1.1
> Host: localhost:9085
> User-Agent: curl/7.43.0
> Accept: */*
> Content-Type: application/json
> Content-Length: 19
>
* upload completely sent off: 19 out of 19 bytes
< HTTP/1.1 400 Bad Request
< Date: Fri, 27 May 2016 10:07:41 GMT
< Content-Type: text/html;charset=iso-8859-1
< Cache-Control: must-revalidate,no-cache,no-store
< Content-Length: 251
<
<html>
<head>
<meta http-equiv="Content-Type" content="text/html;charset=utf-8"/>
<title>Error 400 Bad Request</title>
</head>
<body><h2>HTTP ERROR 400</h2>
<p>Problem accessing /hello/world/v2/. Reason:
<pre>    Bad Request</pre></p>
</body>
</html>
* Connection #0 to host localhost left intact

希望对您有所帮助!

干杯,

阿图尔

【讨论】:

  • 是的!这是一个更好的方法。我知道球衣中有实体过滤,但不知道验证分组。我想我已经在发行说明中看到了它,但我完全忘记了它。谢谢!
猜你喜欢
  • 1970-01-01
  • 1970-01-01
  • 1970-01-01
  • 1970-01-01
  • 1970-01-01
  • 2013-04-25
  • 2013-01-12
  • 1970-01-01
  • 1970-01-01
相关资源
最近更新 更多