Class StandardSession
- All Implemented Interfaces:
Serializable,HttpSession,Session
- Direct Known Subclasses:
DeltaSession
IMPLEMENTATION NOTE: An instance of this class represents both the internal (Session) and application level
(HttpSession) view of the session. However, because the class itself is not declared public, Java logic outside of
the org.apache.catalina.session package cannot cast an HttpSession view of this instance back to a
Session view.
IMPLEMENTATION NOTE: If you add fields to this class, you must make sure that you carry them over in the read/writeObject methods so that this class is properly serialized.
- Author:
- Craig R. McClanahan, Sean Legassick, Jon S. Stevens
- See Also:
-
Field Summary
FieldsModifier and TypeFieldDescriptionprotected AtomicIntegerThe access count for this session.protected static final booleanprotected ConcurrentMap<String,Object> The collection of user data attributes associated with this Session.protected StringThe authentication type used to authenticate our cached Principal, if any.protected longThe time this session was created, in milliseconds since midnight, January 1, 1970 GMT.protected static final String[]Type array.protected booleanWe are currently processing a session expiration, so bypass certain IllegalStateException tests.protected StandardSessionFacadeThe facade associated with this session.protected StringThe session identifier of this Session.protected booleanFlag indicating whether this session is new or not.protected booleanFlag indicating whether this session is valid or not.protected static final booleanprotected longThe last accessed time for this Session.protected ArrayList<SessionListener>The session event listeners for this Session.protected ManagerThe Manager with which this Session is associated.protected intThe maximum time interval, in seconds, between client requests before the servlet container may invalidate this session.Internal notes associated with this session by Catalina components and event listeners.protected PrincipalThe authenticated Principal associated with this session, if any.protected static HttpSessionContextDeprecated.protected static final StringManagerThe string manager for this package.protected static final booleanprotected final PropertyChangeSupportThe property change support for this component.protected longThe current accessed time for this session.Fields inherited from interface org.apache.catalina.Session
SESSION_ACTIVATED_EVENT, SESSION_CREATED_EVENT, SESSION_DESTROYED_EVENT, SESSION_PASSIVATED_EVENT -
Constructor Summary
ConstructorsConstructorDescriptionStandardSession(Manager manager) Construct a new Session associated with the specified Manager. -
Method Summary
Modifier and TypeMethodDescriptionvoidaccess()Update the accessed time information for this session.voidactivate()Perform internal processing required to activate this session.voidaddSessionListener(SessionListener listener) Add a session event listener to this component.protected voiddoReadObject(ObjectInputStream stream) Read a serialized version of this session object from the specified object input stream.protected voiddoWriteObject(ObjectOutputStream stream) Write a serialized version of this session object to the specified object output stream.voidEnd access to the session.protected booleanShould the given session attribute be excluded?voidexpire()Perform the internal processing required to invalidate this session, without triggering an exception if the session has already expired.voidexpire(boolean notify) Perform the internal processing required to invalidate this session, without triggering an exception if the session has already expired.voidfireSessionEvent(String type, Object data) Notify all session event listeners that a particular event has occurred for this Session.getAttribute(String name) Returns the object bound with the specified name in this session, ornullif no object is bound under the name.Returns anEnumerationofStringobjects containing the names of all the objects bound to this session.longReturns the time when this session was created, measured in milliseconds since midnight January 1, 1970 GMT.longgetId()Returns a string containing the unique identifier assigned to this session.longlonglongReturns the last time the client sent a request associated with this session, as the number of milliseconds since midnight January 1, 1970 GMT, and marked by the time the container received the request.longintReturns the maximum time interval, in seconds, that the servlet container will keep this session open between client accesses.Returns the ServletContext to which this session belongs.Deprecated.As of Version 2.1, this method is deprecated and has no replacement.longlongDeprecated.String[]Deprecated.voidInvalidates this session then unbinds any objects bound to it.booleanisAttributeDistributable(String name, Object value) Does the session implementation support the distributing of the given attribute?booleanisNew()Returnstrueif the client does not yet know about the session or if the client chooses not to join the session.booleanisValid()protected booleanprotected String[]keys()voidPerform the internal processing required to passivate this session.voidDeprecated.voidreadObjectData(ObjectInputStream stream) Read a serialized version of the contents of this session object from the specified object input stream, without requiring that the StandardSession itself have been serialized.voidrecycle()Release all object references, and initialize instance variables, in preparation for reuse of this object.voidremoveAttribute(String name) Removes the object bound with the specified name from this session.voidremoveAttribute(String name, boolean notify) Remove the object bound with the specified name from this session.protected voidremoveAttributeInternal(String name, boolean notify) Remove the object bound with the specified name from this session.voidremoveNote(String name) Remove any object bound to the specified name in the internal notes for this session.voidremoveSessionListener(SessionListener listener) Remove a session event listener from this component.voidremoveValue(String name) Deprecated.voidsetAttribute(String name, Object value) Binds an object to this session, using the name specified.voidsetAttribute(String name, Object value, boolean notify) Bind an object to this session, using the specified name.voidsetAuthType(String authType) Set the authentication type used to authenticate our cached Principal, if any.voidsetCreationTime(long time) Set the creation time for this session.voidSet the session identifier for this session and notifies any associated listeners that a new session has been created.voidSet the session identifier for this session and optionally notifies any associated listeners that a new session has been created.voidsetManager(Manager manager) Set the Manager within which this Session is valid.voidsetMaxInactiveInterval(int interval) Specifies the time, in seconds, between client requests before the servlet container will invalidate this session.voidsetNew(boolean isNew) Set theisNewflag for this session.voidBind an object to a specified name in the internal notes associated with this session, replacing any existing binding for this name.voidsetPrincipal(Principal principal) Set the authenticated Principal that is associated with this Session.voidsetValid(boolean isValid) Set theisValidflag for this session.voidtellChangedSessionId(String newId, String oldId, boolean notifySessionListeners, boolean notifyContainerListeners) Inform the listeners about the change session ID.voidtellNew()Inform the listeners about the new session.toString()voidwriteObjectData(ObjectOutputStream stream) Write a serialized version of the contents of this session object to the specified object output stream, without requiring that the StandardSession itself have been serialized.
-
Field Details
-
STRICT_SERVLET_COMPLIANCE
protected static final boolean STRICT_SERVLET_COMPLIANCE -
ACTIVITY_CHECK
protected static final boolean ACTIVITY_CHECK -
LAST_ACCESS_AT_START
protected static final boolean LAST_ACCESS_AT_START -
EMPTY_ARRAY
Type array. -
attributes
The collection of user data attributes associated with this Session. -
authType
The authentication type used to authenticate our cached Principal, if any. NOTE: This value is not included in the serialized version of this object. -
creationTime
protected long creationTimeThe time this session was created, in milliseconds since midnight, January 1, 1970 GMT. -
expiring
protected transient volatile boolean expiringWe are currently processing a session expiration, so bypass certain IllegalStateException tests. NOTE: This value is not included in the serialized version of this object. -
facade
The facade associated with this session. NOTE: This value is not included in the serialized version of this object. -
id
The session identifier of this Session. -
lastAccessedTime
protected volatile long lastAccessedTimeThe last accessed time for this Session. -
listeners
The session event listeners for this Session. -
manager
The Manager with which this Session is associated. -
maxInactiveInterval
protected volatile int maxInactiveIntervalThe maximum time interval, in seconds, between client requests before the servlet container may invalidate this session. A negative time indicates that the session should never time out. -
isNew
protected volatile boolean isNewFlag indicating whether this session is new or not. -
isValid
protected volatile boolean isValidFlag indicating whether this session is valid or not. -
notes
Internal notes associated with this session by Catalina components and event listeners. IMPLEMENTATION NOTE: This object is not saved and restored across session serializations! -
principal
The authenticated Principal associated with this session, if any. IMPLEMENTATION NOTE: This object is not saved and restored across session serializations! -
sm
The string manager for this package. -
sessionContext
Deprecated.The HTTP session context associated with this session. -
support
The property change support for this component. NOTE: This value is not included in the serialized version of this object. -
thisAccessedTime
protected volatile long thisAccessedTimeThe current accessed time for this session. -
accessCount
The access count for this session.
-
-
Constructor Details
-
StandardSession
Construct a new Session associated with the specified Manager.- Parameters:
manager- The manager with which this Session is associated
-
-
Method Details
-
getAuthType
- Specified by:
getAuthTypein interfaceSession- Returns:
- the authentication type used to authenticate our cached Principal, if any.
-
setAuthType
Description copied from interface:SessionSet the authentication type used to authenticate our cached Principal, if any.- Specified by:
setAuthTypein interfaceSession- Parameters:
authType- The new cached authentication type
-
setCreationTime
public void setCreationTime(long time) Description copied from interface:SessionSet the creation time for this session. This method is called by the Manager when an existing Session instance is reused.- Specified by:
setCreationTimein interfaceSession- Parameters:
time- The new creation time
-
getId
Description copied from interface:javax.servlet.http.HttpSessionReturns a string containing the unique identifier assigned to this session. The identifier is assigned by the servlet container and is implementation dependent.- Specified by:
getIdin interfaceHttpSession- Specified by:
getIdin interfaceSession- Returns:
- a string specifying the identifier assigned to this session
-
getIdInternal
- Specified by:
getIdInternalin interfaceSession- Returns:
- the session identifier for this session.
-
setId
Description copied from interface:SessionSet the session identifier for this session and notifies any associated listeners that a new session has been created. -
setId
Description copied from interface:SessionSet the session identifier for this session and optionally notifies any associated listeners that a new session has been created. -
tellNew
public void tellNew()Inform the listeners about the new session. -
tellChangedSessionId
public void tellChangedSessionId(String newId, String oldId, boolean notifySessionListeners, boolean notifyContainerListeners) Description copied from interface:SessionInform the listeners about the change session ID.- Specified by:
tellChangedSessionIdin interfaceSession- Parameters:
newId- new session IDoldId- old session IDnotifySessionListeners- Should any associated sessionListeners be notified that session ID has been changed?notifyContainerListeners- Should any associated ContainerListeners be notified that session ID has been changed?
-
getThisAccessedTime
public long getThisAccessedTime()- Specified by:
getThisAccessedTimein interfaceSession- Returns:
- the last time the client sent a request associated with this session, as the number of milliseconds since midnight, January 1, 1970 GMT. Actions that your application takes, such as getting or setting a value associated with the session, do not affect the access time. This one gets updated whenever a request starts.
-
getThisAccessedTimeInternal
public long getThisAccessedTimeInternal()- Specified by:
getThisAccessedTimeInternalin interfaceSession- Returns:
- the last client access time without invalidation check
- See Also:
-
getLastAccessedTime
public long getLastAccessedTime()Description copied from interface:javax.servlet.http.HttpSessionReturns the last time the client sent a request associated with this session, as the number of milliseconds since midnight January 1, 1970 GMT, and marked by the time the container received the request.Actions that your application takes, such as getting or setting a value associated with the session, do not affect the access time.
- Specified by:
getLastAccessedTimein interfaceHttpSession- Specified by:
getLastAccessedTimein interfaceSession- Returns:
- a
longrepresenting the last time the client sent a request associated with this session, expressed in milliseconds since 1/1/1970 GMT
-
getLastAccessedTimeInternal
public long getLastAccessedTimeInternal()- Specified by:
getLastAccessedTimeInternalin interfaceSession- Returns:
- the last client access time without invalidation check
- See Also:
-
getIdleTime
public long getIdleTime()- Specified by:
getIdleTimein interfaceSession- Returns:
- the idle time (in milliseconds) from last client access time.
-
getIdleTimeInternal
public long getIdleTimeInternal()- Specified by:
getIdleTimeInternalin interfaceSession- Returns:
- the idle time from last client access time without invalidation check
- See Also:
-
getManager
- Specified by:
getManagerin interfaceSession- Returns:
- the Manager within which this Session is valid.
-
setManager
Description copied from interface:SessionSet the Manager within which this Session is valid.- Specified by:
setManagerin interfaceSession- Parameters:
manager- The new Manager
-
getMaxInactiveInterval
public int getMaxInactiveInterval()Description copied from interface:javax.servlet.http.HttpSessionReturns the maximum time interval, in seconds, that the servlet container will keep this session open between client accesses. After this interval, the servlet container will invalidate the session. The maximum time interval can be set with thesetMaxInactiveIntervalmethod. A zero or negative time indicates that the session should never timeout.- Specified by:
getMaxInactiveIntervalin interfaceHttpSession- Specified by:
getMaxInactiveIntervalin interfaceSession- Returns:
- an integer specifying the number of seconds this session remains open between client requests
- See Also:
-
setMaxInactiveInterval
public void setMaxInactiveInterval(int interval) Description copied from interface:javax.servlet.http.HttpSessionSpecifies the time, in seconds, between client requests before the servlet container will invalidate this session. A zero or negative time indicates that the session should never timeout.- Specified by:
setMaxInactiveIntervalin interfaceHttpSession- Specified by:
setMaxInactiveIntervalin interfaceSession- Parameters:
interval- An integer specifying the number of seconds
-
setNew
public void setNew(boolean isNew) Description copied from interface:SessionSet theisNewflag for this session. -
getPrincipal
- Specified by:
getPrincipalin interfaceSession- Returns:
- the authenticated Principal that is associated with this Session.
This provides an
Authenticatorwith a means to cache a previously authenticated Principal, and avoid potentially expensiveRealm.authenticate()calls on every request. If there is no current associated Principal, returnnull.
-
setPrincipal
Description copied from interface:SessionSet the authenticated Principal that is associated with this Session. This provides anAuthenticatorwith a means to cache a previously authenticated Principal, and avoid potentially expensiveRealm.authenticate()calls on every request.- Specified by:
setPrincipalin interfaceSession- Parameters:
principal- The new Principal, ornullif none
-
getSession
- Specified by:
getSessionin interfaceSession- Returns:
- the
HttpSessionfor which this object is the facade.
-
isValid
public boolean isValid() -
setValid
public void setValid(boolean isValid) Description copied from interface:SessionSet theisValidflag for this session. -
access
public void access()Description copied from interface:SessionUpdate the accessed time information for this session. This method should be called by the context when a request comes in for a particular session, even if the application does not reference it. -
endAccess
public void endAccess()Description copied from interface:SessionEnd access to the session. -
addSessionListener
Description copied from interface:SessionAdd a session event listener to this component.- Specified by:
addSessionListenerin interfaceSession- Parameters:
listener- the SessionListener instance that should be notified for session events
-
expire
public void expire()Description copied from interface:SessionPerform the internal processing required to invalidate this session, without triggering an exception if the session has already expired. -
expire
public void expire(boolean notify) Perform the internal processing required to invalidate this session, without triggering an exception if the session has already expired.- Parameters:
notify- Should we notify listeners about the demise of this session?
-
passivate
public void passivate()Perform the internal processing required to passivate this session. -
activate
public void activate()Perform internal processing required to activate this session. -
getNote
-
getNoteNames
- Specified by:
getNoteNamesin interfaceSession- Returns:
- an Iterator containing the String names of all notes bindings that exist for this session.
-
recycle
public void recycle()Description copied from interface:SessionRelease all object references, and initialize instance variables, in preparation for reuse of this object. -
removeNote
Description copied from interface:SessionRemove any object bound to the specified name in the internal notes for this session.- Specified by:
removeNotein interfaceSession- Parameters:
name- Name of the note to be removed
-
removeSessionListener
Description copied from interface:SessionRemove a session event listener from this component.- Specified by:
removeSessionListenerin interfaceSession- Parameters:
listener- remove the session listener, which will no longer be notified
-
setNote
Description copied from interface:SessionBind an object to a specified name in the internal notes associated with this session, replacing any existing binding for this name. -
toString
-
readObjectData
Read a serialized version of the contents of this session object from the specified object input stream, without requiring that the StandardSession itself have been serialized.- Parameters:
stream- The object input stream to read from- Throws:
ClassNotFoundException- if an unknown class is specifiedIOException- if an input/output error occurs
-
writeObjectData
Write a serialized version of the contents of this session object to the specified object output stream, without requiring that the StandardSession itself have been serialized.- Parameters:
stream- The object output stream to write to- Throws:
IOException- if an input/output error occurs
-
getCreationTime
public long getCreationTime()Description copied from interface:javax.servlet.http.HttpSessionReturns the time when this session was created, measured in milliseconds since midnight January 1, 1970 GMT.- Specified by:
getCreationTimein interfaceHttpSession- Specified by:
getCreationTimein interfaceSession- Returns:
- a
longspecifying when this session was created, expressed in milliseconds since 1/1/1970 GMT
-
getCreationTimeInternal
public long getCreationTimeInternal()- Specified by:
getCreationTimeInternalin interfaceSession- Returns:
- the creation time for this session, bypassing the session validity checks.
-
getServletContext
Description copied from interface:javax.servlet.http.HttpSessionReturns the ServletContext to which this session belongs.- Specified by:
getServletContextin interfaceHttpSession- Returns:
- The ServletContext object for the web application
-
getSessionContext
Deprecated.As of Version 2.1, this method is deprecated and has no replacement. It will be removed in a future version of the Java Servlet API.Return the session context with which this session is associated.- Specified by:
getSessionContextin interfaceHttpSession- Returns:
- A dummy implementation of HttpSessionContext
-
getAttribute
Description copied from interface:javax.servlet.http.HttpSessionReturns the object bound with the specified name in this session, ornullif no object is bound under the name.- Specified by:
getAttributein interfaceHttpSession- Parameters:
name- a string specifying the name of the object- Returns:
- the object with the specified name
-
getAttributeNames
Description copied from interface:javax.servlet.http.HttpSessionReturns anEnumerationofStringobjects containing the names of all the objects bound to this session.- Specified by:
getAttributeNamesin interfaceHttpSession- Returns:
- an
EnumerationofStringobjects specifying the names of all the objects bound to this session
-
getValue
Deprecated.- Specified by:
getValuein interfaceHttpSession- Parameters:
name- a string specifying the name of the object- Returns:
- the object with the specified name
-
getValueNames
Deprecated.- Specified by:
getValueNamesin interfaceHttpSession- Returns:
- an array of
Stringobjects specifying the names of all the objects bound to this session
-
invalidate
public void invalidate()Description copied from interface:javax.servlet.http.HttpSessionInvalidates this session then unbinds any objects bound to it.- Specified by:
invalidatein interfaceHttpSession
-
isNew
public boolean isNew()Description copied from interface:javax.servlet.http.HttpSessionReturnstrueif the client does not yet know about the session or if the client chooses not to join the session. For example, if the server used only cookie-based sessions, and the client had disabled the use of cookies, then a session would be new on each request.- Specified by:
isNewin interfaceHttpSession- Returns:
trueif the server has created a session, but the client has not yet joined
-
putValue
Deprecated.- Specified by:
putValuein interfaceHttpSession- Parameters:
name- the name to which the object is bound; cannot be nullvalue- the object to be bound; cannot be null
-
removeAttribute
Description copied from interface:javax.servlet.http.HttpSessionRemoves the object bound with the specified name from this session. If the session does not have an object bound with the specified name, this method does nothing.After this method executes, and if the object implements
HttpSessionBindingListener, the container callsHttpSessionBindingListener.valueUnbound. The container then notifies anyHttpSessionAttributeListeners in the web application.- Specified by:
removeAttributein interfaceHttpSession- Parameters:
name- the name of the object to remove from this session
-
removeAttribute
Remove the object bound with the specified name from this session. If the session does not have an object bound with this name, this method does nothing.After this method executes, and if the object implements
HttpSessionBindingListener, the container callsvalueUnbound()on the object.- Parameters:
name- Name of the object to remove from this session.notify- Should we notify interested listeners that this attribute is being removed?- Throws:
IllegalStateException- if this method is called on an invalidated session
-
removeValue
Deprecated.- Specified by:
removeValuein interfaceHttpSession- Parameters:
name- the name of the object to remove from this session
-
setAttribute
Description copied from interface:javax.servlet.http.HttpSessionBinds an object to this session, using the name specified. If an object of the same name is already bound to the session, the object is replaced.After this method executes, and if the new object implements
HttpSessionBindingListener, the container callsHttpSessionBindingListener.valueBound. The container then notifies anyHttpSessionAttributeListeners in the web application.If an object was already bound to this session of this name that implements
HttpSessionBindingListener, itsHttpSessionBindingListener.valueUnboundmethod is called.If the value passed in is null, this has the same effect as calling
removeAttribute().- Specified by:
setAttributein interfaceHttpSession- Parameters:
name- the name to which the object is bound; cannot be nullvalue- the object to be bound
-
setAttribute
Bind an object to this session, using the specified name. If an object of the same name is already bound to this session, the object is replaced.After this method executes, and if the object implements
HttpSessionBindingListener, the container callsvalueBound()on the object.- Parameters:
name- Name to which the object is bound, cannot be nullvalue- Object to be bound, cannot be nullnotify- whether to notify session listeners- Throws:
IllegalArgumentException- if an attempt is made to add a non-serializable object in an environment marked distributable.IllegalStateException- if this method is called on an invalidated session
-
isValidInternal
protected boolean isValidInternal()- Returns:
- the
isValidflag for this session without any expiration check.
-
isAttributeDistributable
Does the session implementation support the distributing of the given attribute? If the Manager is marked as distributable, then this method must be used to check attributes before adding them to a session and anIllegalArgumentExceptionthrown if the proposed attribute is not distributable.Note that the
Managerimplementation may further restrict which attributes are distributed but aManagerlevel restriction should not trigger anIllegalArgumentExceptioninHttpSession.setAttribute(String, Object)This implementation simply checks the value for serializability. Sub-classes might use other distribution technology not based on serialization and can override this check.
- Specified by:
isAttributeDistributablein interfaceSession- Parameters:
name- The attribute namevalue- The attribute value- Returns:
trueif distribution is supported, otherwisefalse
-
doReadObject
Read a serialized version of this session object from the specified object input stream.IMPLEMENTATION NOTE: The reference to the owning Manager is not restored by this method, and must be set explicitly.
- Parameters:
stream- The input stream to read from- Throws:
ClassNotFoundException- if an unknown class is specifiedIOException- if an input/output error occurs
-
doWriteObject
Write a serialized version of this session object to the specified object output stream.IMPLEMENTATION NOTE: The owning Manager will not be stored in the serialized representation of this Session. After calling
readObject(), you must set the associated Manager explicitly.IMPLEMENTATION NOTE: Any attribute that is not Serializable will be unbound from the session, with appropriate actions if it implements HttpSessionBindingListener. If you do not want any such attributes, be sure the
distributableproperty of the associated Manager is set totrue.- Parameters:
stream- The output stream to write to- Throws:
IOException- if an input/output error occurs
-
exclude
Should the given session attribute be excluded? This implementation checks: Note: This method deliberately does not checkisAttributeDistributable(String, Object)which is kept separate to support the checks required insetAttribute(String, Object, boolean)- Parameters:
name- The attribute namevalue- The attribute value- Returns:
trueif the attribute should be excluded from distribution, otherwisefalse
-
fireSessionEvent
Notify all session event listeners that a particular event has occurred for this Session. The default implementation performs this notification synchronously using the calling thread.- Parameters:
type- Event typedata- Event data
-
keys
- Returns:
- the names of all currently defined session attributes as an array of Strings. If there are no defined attributes, a zero-length array is returned.
-
removeAttributeInternal
Remove the object bound with the specified name from this session. If the session does not have an object bound with this name, this method does nothing.After this method executes, and if the object implements
HttpSessionBindingListener, the container callsvalueUnbound()on the object.- Parameters:
name- Name of the object to remove from this session.notify- Should we notify interested listeners that this attribute is being removed?
-