Spring Web请求处理流程及Filter源码分析

一次Web HTTP请求后端执行的完整流程,

原始数据 如下(Spring v5.2.6):

at io.fbank.hilo.app.component.ControllerRequestLogInterceptor.preHandle(ControllerRequestLogInterceptor.java:52)
at org.springframework.web.servlet.HandlerExecutionChain.applyPreHandle(HandlerExecutionChain.java:141)
at org.springframework.web.servlet.DispatcherServlet.doDispatch(DispatcherServlet.java:1035)
at org.springframework.web.servlet.DispatcherServlet.doService(DispatcherServlet.java:943)
at org.springframework.web.servlet.FrameworkServlet.processRequest(FrameworkServlet.java:1006)
at org.springframework.web.servlet.FrameworkServlet.doPost(FrameworkServlet.java:909)
at javax.servlet.http.HttpServlet.service(HttpServlet.java:660)
at org.springframework.web.servlet.FrameworkServlet.service(FrameworkServlet.java:883)
at javax.servlet.http.HttpServlet.service(HttpServlet.java:741)
at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:231)
at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:166)
at org.apache.shiro.web.servlet.OncePerRequestFilter.doFilter(OncePerRequestFilter.java:112)
at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:193)
at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:166)
at com.alibaba.druid.support.http.WebStatFilter.doFilter(WebStatFilter.java:124)
at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:193)
at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:166)
at io.fbank.hilo.core.xss.XssFilter.doFilter(XssFilter.java:24)
at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:193)
at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:166)
at org.apache.shiro.web.servlet.ProxiedFilterChain.doFilter(ProxiedFilterChain.java:61)
at org.apache.shiro.web.servlet.AdviceFilter.executeChain(AdviceFilter.java:108)
at org.apache.shiro.web.servlet.AdviceFilter.doFilterInternal(AdviceFilter.java:137)
at org.apache.shiro.web.servlet.OncePerRequestFilter.doFilter(OncePerRequestFilter.java:125)
at org.apache.shiro.web.servlet.ProxiedFilterChain.doFilter(ProxiedFilterChain.java:66)
at org.apache.shiro.web.servlet.AbstractShiroFilter.executeChain(AbstractShiroFilter.java:449)
at org.apache.shiro.web.servlet.AbstractShiroFilter$1.call(AbstractShiroFilter.java:365)
at org.apache.shiro.subject.support.SubjectCallable.doCall(SubjectCallable.java:90)
at org.apache.shiro.subject.support.SubjectCallable.call(SubjectCallable.java:83)
at org.apache.shiro.subject.support.DelegatingSubject.execute(DelegatingSubject.java:383)
at org.apache.shiro.web.servlet.AbstractShiroFilter.doFilterInternal(AbstractShiroFilter.java:362)
at org.apache.shiro.web.servlet.OncePerRequestFilter.doFilter(OncePerRequestFilter.java:125)
at org.springframework.web.filter.DelegatingFilterProxy.invokeDelegate(DelegatingFilterProxy.java:358)
at org.springframework.web.filter.DelegatingFilterProxy.doFilter(DelegatingFilterProxy.java:271)
at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:193)
at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:166)
at org.springframework.web.filter.RequestContextFilter.doFilterInternal(RequestContextFilter.java:100)
at org.springframework.web.filter.OncePerRequestFilter.doFilter(OncePerRequestFilter.java:119)
at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:193)
at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:166)
at org.springframework.web.filter.FormContentFilter.doFilterInternal(FormContentFilter.java:93)
at org.springframework.web.filter.OncePerRequestFilter.doFilter(OncePerRequestFilter.java:119)
at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:193)
at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:166)
at org.springframework.boot.actuate.metrics.web.servlet.WebMvcMetricsFilter.doFilterInternal(WebMvcMetricsFilter.java:93)
at org.springframework.web.filter.OncePerRequestFilter.doFilter(OncePerRequestFilter.java:119)
at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:193)
at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:166)
at org.springframework.web.filter.CharacterEncodingFilter.doFilterInternal(CharacterEncodingFilter.java:201)
at org.springframework.web.filter.OncePerRequestFilter.doFilter(OncePerRequestFilter.java:119)
at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:193)
at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:166)
at org.springframework.web.filter.CorsFilter.doFilterInternal(CorsFilter.java:92)
at org.springframework.web.filter.OncePerRequestFilter.doFilter(OncePerRequestFilter.java:119)
at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:193)
at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:166)
at org.apache.catalina.core.StandardWrapperValve.invoke(StandardWrapperValve.java:202)
at org.apache.catalina.core.StandardContextValve.invoke(StandardContextValve.java:96)
at org.apache.catalina.authenticator.AuthenticatorBase.invoke(AuthenticatorBase.java:541)
at org.apache.catalina.core.StandardHostValve.invoke(StandardHostValve.java:139)
at org.apache.catalina.valves.ErrorReportValve.invoke(ErrorReportValve.java:92)
at org.apache.catalina.core.StandardEngineValve.invoke(StandardEngineValve.java:74)
at org.apache.catalina.connector.CoyoteAdapter.service(CoyoteAdapter.java:343)
at org.apache.coyote.http11.Http11Processor.service(Http11Processor.java:373)
at org.apache.coyote.AbstractProcessorLight.process(AbstractProcessorLight.java:65)
at org.apache.coyote.AbstractProtocol$ConnectionHandler.process(AbstractProtocol.java:868)
at org.apache.tomcat.util.net.NioEndpoint$SocketProcessor.doRun(NioEndpoint.java:1590)
at org.apache.tomcat.util.net.SocketProcessorBase.run(SocketProcessorBase.java:49)
at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1149)
at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:624)
at org.apache.tomcat.util.threads.TaskThread$WrappingRunnable.run(TaskThread.java:61)
at java.lang.Thread.run(Thread.java:748)

简单总结一下,HTTP请求的关键流程如下

Tomcat: TaskThread(ThreadPoolExecutor)、SocketProcessor

Coyote (tomcat Connector):AbstractProtocol + Http11Processor

Catalina(tomcat Servlet):StandardEngine、Authenticator、StandardContext、ApplicationFilter

App Filter(Spring Filter):CorsFilter、CharacterEncodingFilter、WebMvcMetricsFilter、FormContentFilter、RequestContextFilter、DelegatingFilterProxy

tomcat.websocket.server.WsFilter (在App Filter之后,tomcat有个处理websocket的WsFilter)

  App Servlet(Spring Servlet):FrameworkServlet、DispatcherServlet

    Spring Extension:HandlerExecutionChain……


接下来,从Spring的源头看起:第一个出现的是CorsFilter(继承自org.springframework.web.filter.OncePerRequestFilter)。


实际上,Spring的Filter是自己注册到Web Servlet容器上的,它优先级是可以自由调整的,如下所示。

@Bean
public FilterRegistrationBean<CorsFilter> corsFilterRegistration() {

    FilterRegistrationBean<CorsFilter> bean = new FilterRegistrationBean<>(new CorsFilter(source));
    bean.setOrder(Ordered.HIGHEST_PRECEDENCE);
    return bean;
}

之所以CorsFilter排在第一位,是因为我们配置了Ordered.HIGHEST_PRECEDENCE(=Integer.MIN_VALUE),值越大优先级越低。

那么上面的 CharacterEncodingFilter 、FormContentFilter 和 RequestContextFilter 又是在哪里配置Order的呢?


这是SpringBoot在自动装配时,

在WebMvcAutoConfiguration中,配置了OrderedFormContentFilter(默认是启用):

@Bean
@ConditionalOnMissingBean(FormContentFilter.class)
@ConditionalOnProperty(prefix = "spring.mvc.formcontent.filter", name = "enabled", matchIfMissing = true)
public OrderedFormContentFilter formContentFilter() {
    return new OrderedFormContentFilter();
}

这个filter的优先级为:

OrderedFilter.REQUEST_WRAPPER_FILTER_MAX_ORDER - 9900

即:-9900(优先级非常低)


在WebMvcAutoConfiguration.WebMvcAutoConfigurationAdapter类中,配置了 RequestContextFilter,

其优先级为:

OrderedFilter.REQUEST_WRAPPER_FILTER_MAX_ORDER - 105

即:-105,值更大,所以比 FormContentFilter 优先级低。


在HttpEncodingAutoConfiguration配置类里配置了CharacterEncodingFilter(优先级为Ordered.HIGHEST_PRECEDENCE),同时支持以下配置(server.servlet.encoding开头):

# 是否启用CharacterEncodingFilter,如果不配置也代表true
server.servlet.encoding=enabled

# 设置的编码,默认为:UTF-8
server.servlet.encoding.charset=UTF-8

# 是否强制设置请求和响应的编码格式为设置的编码格式
server.servlet.encoding.force=

# 是否强制设置请求的编码格式为设置的编码格式
server.servlet.encoding.force-request=

# 是否强制设置响应的编码格式为设置的编码格式
server.servlet.encoding.force-response=

默认force与否的逻辑为:

    如果 forceEncoding=true或者request.getCharacterEncoding()为空,则设置其值为 encoding(默认值为UTF-8)

    反之,如果没有设置forceEncoding,且request.getCharacterEncoding()不为空,则不管。

注意这个类的注解有点意思:

@Configuration(proxyBeanMethods = false)
@EnableConfigurationProperties(ServerProperties.class)
@ConditionalOnWebApplication(type = ConditionalOnWebApplication.Type.SERVLET)
@ConditionalOnClass(CharacterEncodingFilter.class)
@ConditionalOnProperty(prefix = "server.servlet.encoding", value = "enabled", matchIfMissing = true)
public class HttpEncodingAutoConfiguration {

}


什么是 Spring DelegatingFilterProxy呢?

直接参见这篇文章吧:https://blog.csdn.net/fly910905/article/details/95062258


额外收获

有点想说的是,SpringMVC框架太重了!!

SpringBoot利用了SpringMVC,但是隐藏了太多的细节,默认配置了很多东西(虽然有些有开关可以控制,但是大家根本没精力去关注这么多)。

所以说Spring项目可以优化的地方太多太多了,大部分人其实根本没能掌握好其中的细节。

我曾经还遇到一个Spring的怪异问题,给Spring官方提过issues、写过建议,后来查到原因,因为Spring默认配置问题导致的,但是有开关可以更改,细节太多,坑太多,看似一个简单的HTTP调用,SpringMVC在后台走了很长的流程、做了很多的工作,而我认为很多是不必要的,很多场景一个裸servlet就足够了。

这也是我自己使用ZolltyMVC而非SpringMVC的原因,ZolltyMVC一个jar包只有100多kb,但是具备SpringMVC的所有核心功能(DI / IoC、Model Driven、URI Pattern、AOP等),而且自己设计的注解API,用着超顺手。


© 2009-2020 Zollty.com 版权所有。渝ICP备20008982号