import javax.servlet.http.*
import java.io.*
import java.util.*
import java.util.regex.*
import org.apache.commons.fileupload.*
public class upload extends HttpServlet {
private static final String CONTENT_TYPE = "text/htmlcharset=GB2312"
//Process the HTTP Post request
public void doPost(HttpServletRequest request, HttpServletResponse response) throws ServletException, IOException {
response.setContentType(CONTENT_TYPE)
PrintWriter out=response.getWriter()
try {
DiskFileUpload fu = new DiskFileUpload()
// 设置允许用户上传文件大小,单位:字节,这里设为2m
fu.setSizeMax(2*1024*1024)
// 设置最多只允许在内存中存储的数据,单位:字节
fu.setSizeThreshold(4096)
// 设置一旦文件大小超过getSizeThreshold()的值时数据存放在硬盘的目录
fu.setRepositoryPath("c:\\windows\\temp")
//开始读取上传信息
List fileItems = fu.parseRequest(request)
// 依次处理每个上传的文件
Iterator iter = fileItems.iterator()//正则匹配,过滤路径取文件名
String regExp=".+\\\\(.+)$"//过滤掉的文件类型
String[] errorType={".exe",".com",".cgi",".asp"}
Pattern p = Pattern.compile(regExp)
while (iter.hasNext()) {
FileItem item = (FileItem)iter.next()
//忽略其他不是文件域的所有表单信息
if (!item.isFormField()) {
String name = item.getName()
long size = item.getSize()
if((name==null||name.equals("")) &&size==0)
continue
Matcher m = p.matcher(name)
boolean result = m.find()
if (result){
for (int temp=0temp if (m.group(1).endsWith(errorType[temp])){
throw new IOException(name+": wrong type")
}
}
try{//保存上传的文件到指定的目录//在下文中上传文件至数据库时,将对这里改写
item.write(new File("d:\\" + m.group(1))) out.print(name+" "+size+"
")
}
catch(Exception e){
out.println(e)
}}
else
{
throw new IOException("fail to upload")
}
}
}
}
catch (IOException e){
out.println(e)
}
catch (FileUploadException e){
out.println(e)
}
}
}
欢迎分享,转载请注明来源:内存溢出
评论列表(0条)