一次Web HTTP请求后端执行的完整流程,
原始数据 如下(Spring v5.2.6):
at io.fbank.hilo.app.component.ControllerRequestLogInterceptor.preHandle(ControllerRequestLogInterceptor.java:52) at org.springframework.web.servlet.HandlerExecutionChain.applyPreHandle(HandlerExecutionChain.java:141) at org.springframework.web.servlet.DispatcherServlet.doDispatch(DispatcherServlet.java:1035) at org.springframework.web.servlet.DispatcherServlet.doService(DispatcherServlet.java:943) at org.springframework.web.servlet.FrameworkServlet.processRequest(FrameworkServlet.java:1006) at org.springframework.web.servlet.FrameworkServlet.doPost(FrameworkServlet.java:909) at javax.servlet.http.HttpServlet.service(HttpServlet.java:660) at org.springframework.web.servlet.FrameworkServlet.service(FrameworkServlet.java:883) at javax.servlet.http.HttpServlet.service(HttpServlet.java:741) at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:231) at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:166) at org.apache.shiro.web.servlet.OncePerRequestFilter.doFilter(OncePerRequestFilter.java:112) at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:193) at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:166) at com.alibaba.druid.support.http.WebStatFilter.doFilter(WebStatFilter.java:124) at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:193) at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:166) at io.fbank.hilo.core.xss.XssFilter.doFilter(XssFilter.java:24) at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:193) at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:166) at org.apache.shiro.web.servlet.ProxiedFilterChain.doFilter(ProxiedFilterChain.java:61) at org.apache.shiro.web.servlet.AdviceFilter.executeChain(AdviceFilter.java:108) at org.apache.shiro.web.servlet.AdviceFilter.doFilterInternal(AdviceFilter.java:137) at org.apache.shiro.web.servlet.OncePerRequestFilter.doFilter(OncePerRequestFilter.java:125) at org.apache.shiro.web.servlet.ProxiedFilterChain.doFilter(ProxiedFilterChain.java:66) at org.apache.shiro.web.servlet.AbstractShiroFilter.executeChain(AbstractShiroFilter.java:449) at org.apache.shiro.web.servlet.AbstractShiroFilter$1.call(AbstractShiroFilter.java:365) at org.apache.shiro.subject.support.SubjectCallable.doCall(SubjectCallable.java:90) at org.apache.shiro.subject.support.SubjectCallable.call(SubjectCallable.java:83) at org.apache.shiro.subject.support.DelegatingSubject.execute(DelegatingSubject.java:383) at org.apache.shiro.web.servlet.AbstractShiroFilter.doFilterInternal(AbstractShiroFilter.java:362) at org.apache.shiro.web.servlet.OncePerRequestFilter.doFilter(OncePerRequestFilter.java:125) at org.springframework.web.filter.DelegatingFilterProxy.invokeDelegate(DelegatingFilterProxy.java:358) at org.springframework.web.filter.DelegatingFilterProxy.doFilter(DelegatingFilterProxy.java:271) at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:193) at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:166) at org.springframework.web.filter.RequestContextFilter.doFilterInternal(RequestContextFilter.java:100) at org.springframework.web.filter.OncePerRequestFilter.doFilter(OncePerRequestFilter.java:119) at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:193) at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:166) at org.springframework.web.filter.FormContentFilter.doFilterInternal(FormContentFilter.java:93) at org.springframework.web.filter.OncePerRequestFilter.doFilter(OncePerRequestFilter.java:119) at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:193) at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:166) at org.springframework.boot.actuate.metrics.web.servlet.WebMvcMetricsFilter.doFilterInternal(WebMvcMetricsFilter.java:93) at org.springframework.web.filter.OncePerRequestFilter.doFilter(OncePerRequestFilter.java:119) at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:193) at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:166) at org.springframework.web.filter.CharacterEncodingFilter.doFilterInternal(CharacterEncodingFilter.java:201) at org.springframework.web.filter.OncePerRequestFilter.doFilter(OncePerRequestFilter.java:119) at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:193) at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:166) at org.springframework.web.filter.CorsFilter.doFilterInternal(CorsFilter.java:92) at org.springframework.web.filter.OncePerRequestFilter.doFilter(OncePerRequestFilter.java:119) at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:193) at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:166) at org.apache.catalina.core.StandardWrapperValve.invoke(StandardWrapperValve.java:202) at org.apache.catalina.core.StandardContextValve.invoke(StandardContextValve.java:96) at org.apache.catalina.authenticator.AuthenticatorBase.invoke(AuthenticatorBase.java:541) at org.apache.catalina.core.StandardHostValve.invoke(StandardHostValve.java:139) at org.apache.catalina.valves.ErrorReportValve.invoke(ErrorReportValve.java:92) at org.apache.catalina.core.StandardEngineValve.invoke(StandardEngineValve.java:74) at org.apache.catalina.connector.CoyoteAdapter.service(CoyoteAdapter.java:343) at org.apache.coyote.http11.Http11Processor.service(Http11Processor.java:373) at org.apache.coyote.AbstractProcessorLight.process(AbstractProcessorLight.java:65) at org.apache.coyote.AbstractProtocol$ConnectionHandler.process(AbstractProtocol.java:868) at org.apache.tomcat.util.net.NioEndpoint$SocketProcessor.doRun(NioEndpoint.java:1590) at org.apache.tomcat.util.net.SocketProcessorBase.run(SocketProcessorBase.java:49) at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1149) at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:624) at org.apache.tomcat.util.threads.TaskThread$WrappingRunnable.run(TaskThread.java:61) at java.lang.Thread.run(Thread.java:748)
简单总结一下,HTTP请求的关键流程如下:
Tomcat: TaskThread(ThreadPoolExecutor)、SocketProcessor Coyote (tomcat Connector):AbstractProtocol + Http11Processor Catalina(tomcat Servlet):StandardEngine、Authenticator、StandardContext、ApplicationFilter App Filter(Spring Filter):CorsFilter、CharacterEncodingFilter、WebMvcMetricsFilter、FormContentFilter、RequestContextFilter、DelegatingFilterProxy tomcat.websocket.server.WsFilter (在App Filter之后,tomcat有个处理websocket的WsFilter) App Servlet(Spring Servlet):FrameworkServlet、DispatcherServlet Spring Extension:HandlerExecutionChain……
接下来,从Spring的源头看起:第一个出现的是CorsFilter(继承自org.springframework.web.filter.OncePerRequestFilter)。
实际上,Spring的Filter是自己注册到Web Servlet容器上的,它优先级是可以自由调整的,如下所示。
@Bean public FilterRegistrationBean<CorsFilter> corsFilterRegistration() { FilterRegistrationBean<CorsFilter> bean = new FilterRegistrationBean<>(new CorsFilter(source)); bean.setOrder(Ordered.HIGHEST_PRECEDENCE); return bean; }
之所以CorsFilter排在第一位,是因为我们配置了Ordered.HIGHEST_PRECEDENCE(=Integer.MIN_VALUE),值越大优先级越低。
那么上面的 CharacterEncodingFilter 、FormContentFilter 和 RequestContextFilter 又是在哪里配置Order的呢?
这是SpringBoot在自动装配时,
在WebMvcAutoConfiguration中,配置了OrderedFormContentFilter(默认是启用):
@Bean @ConditionalOnMissingBean(FormContentFilter.class) @ConditionalOnProperty(prefix = "spring.mvc.formcontent.filter", name = "enabled", matchIfMissing = true) public OrderedFormContentFilter formContentFilter() { return new OrderedFormContentFilter(); }
这个filter的优先级为:
OrderedFilter.REQUEST_WRAPPER_FILTER_MAX_ORDER - 9900
即:-9900(优先级非常低)
在WebMvcAutoConfiguration.WebMvcAutoConfigurationAdapter类中,配置了 RequestContextFilter,
其优先级为:
OrderedFilter.REQUEST_WRAPPER_FILTER_MAX_ORDER - 105
即:-105,值更大,所以比 FormContentFilter 优先级低。
在HttpEncodingAutoConfiguration配置类里配置了CharacterEncodingFilter(优先级为Ordered.HIGHEST_PRECEDENCE),同时支持以下配置(server.servlet.encoding开头):
# 是否启用CharacterEncodingFilter,如果不配置也代表true server.servlet.encoding=enabled # 设置的编码,默认为:UTF-8 server.servlet.encoding.charset=UTF-8 # 是否强制设置请求和响应的编码格式为设置的编码格式 server.servlet.encoding.force= # 是否强制设置请求的编码格式为设置的编码格式 server.servlet.encoding.force-request= # 是否强制设置响应的编码格式为设置的编码格式 server.servlet.encoding.force-response=
默认force与否的逻辑为:
如果 forceEncoding=true或者request.getCharacterEncoding()为空,则设置其值为 encoding(默认值为UTF-8)
反之,如果没有设置forceEncoding,且request.getCharacterEncoding()不为空,则不管。
注意这个类的注解有点意思:
@Configuration(proxyBeanMethods = false) @EnableConfigurationProperties(ServerProperties.class) @ConditionalOnWebApplication(type = ConditionalOnWebApplication.Type.SERVLET) @ConditionalOnClass(CharacterEncodingFilter.class) @ConditionalOnProperty(prefix = "server.servlet.encoding", value = "enabled", matchIfMissing = true) public class HttpEncodingAutoConfiguration { }
什么是 Spring DelegatingFilterProxy呢?
直接参见这篇文章吧:https://blog.csdn.net/fly910905/article/details/95062258
额外收获
有点想说的是,SpringMVC框架太重了!!
SpringBoot利用了SpringMVC,但是隐藏了太多的细节,默认配置了很多东西(虽然有些有开关可以控制,但是大家根本没精力去关注这么多)。
所以说Spring项目可以优化的地方太多太多了,大部分人其实根本没能掌握好其中的细节。
我曾经还遇到一个Spring的怪异问题,给Spring官方提过issues、写过建议,后来查到原因,因为Spring默认配置问题导致的,但是有开关可以更改,细节太多,坑太多,看似一个简单的HTTP调用,SpringMVC在后台走了很长的流程、做了很多的工作,而我认为很多是不必要的,很多场景一个裸servlet就足够了。
这也是我自己使用ZolltyMVC而非SpringMVC的原因,ZolltyMVC一个jar包只有100多kb,但是具备SpringMVC的所有核心功能(DI / IoC、Model Driven、URI Pattern、AOP等),而且自己设计的注解API,用着超顺手。