Interface HttpServletRequest
- All Superinterfaces:
ServletRequest
- All Known Implementing Classes:
HttpServletRequestWrapper
ServletRequest interface to provide request information for HTTP servlets.
The servlet container creates an HttpServletRequest object and passes it as an argument to the servlet's
service methods (doGet, doPost, etc).
-
Field Summary
FieldsModifier and TypeFieldDescriptionstatic final StringString identifier for Basic authentication.static final StringString identifier for Client Certificate authentication.static final StringString identifier for Digest authentication.static final StringString identifier for Form authentication. -
Method Summary
Modifier and TypeMethodDescriptionbooleanauthenticate(HttpServletResponse response) Triggers the same authentication process as would be triggered if the request is for a resource that is protected by a security constraint.Changes the session ID of the session associated with this request.Returns the name of the authentication scheme used to protect the servlet.Returns the portion of the request URI that indicates the context of the request.Cookie[]Returns an array containing all of theCookieobjects the client sent with this request.longgetDateHeader(String name) Returns the value of the specified request header as alongvalue that represents aDateobject.Returns the value of the specified request header as aString.Returns an enumeration of all the header names this request contains.getHeaders(String name) Returns all the values of the specified request header as anEnumerationofStringobjects.default HttpServletMappingObtain the mapping information for this request.intgetIntHeader(String name) Returns the value of the specified request header as anint.Returns the name of the HTTP method with which this request was made, for example, GET, POST, or PUT.Gets the named Part or null if the Part does not exist.getParts()Return a collection of all uploaded Parts.Returns any extra path information associated with the URL the client sent when it made this request.Returns any extra path information after the servlet name but before the query string, and translates it to a real path.Returns the query string that is contained in the request URL after the path.Returns the login of the user making this request, if the user has been authenticated, ornullif the user has not been authenticated.Returns the session ID specified by the client.Returns the part of this request's URL from the protocol name up to the query string in the first line of the HTTP request.Reconstructs the URL the client used to make the request.Returns the part of this request's URL that calls the servlet.Returns the current session associated with this request, or if the request does not have a session, creates one.getSession(boolean create) Returns the currentHttpSessionassociated with this request or, if there is no current session andcreateis true, returns a new session.Obtain a Map of the trailer fields that is not backed by the request object.Returns ajava.security.Principalobject containing the name of the current authenticated user.booleanChecks whether the requested session ID came in as a cookie.booleanDeprecated.booleanChecks whether the requested session ID came in as part of the request URL.booleanChecks whether the requested session ID is still valid.default booleanAre trailer fields ready to be read (there may still be no trailers to read).booleanisUserInRole(String role) Returns a boolean indicating whether the authenticated user is included in the specified logical "role".voidAuthenticate the provided user name and password and then associated the authenticated user with the request.voidlogout()Removes any authenticated user from the request.default PushBuilderObtain a builder for generating push requests.<T extends HttpUpgradeHandler>
TStart the HTTP upgrade process and create and instance of the provided protocol handler class.Methods inherited from interface javax.servlet.ServletRequest
getAsyncContext, getAttribute, getAttributeNames, getCharacterEncoding, getContentLength, getContentLengthLong, getContentType, getDispatcherType, getInputStream, getLocalAddr, getLocale, getLocales, getLocalName, getLocalPort, getParameter, getParameterMap, getParameterNames, getParameterValues, getProtocol, getReader, getRealPath, getRemoteAddr, getRemoteHost, getRemotePort, getRequestDispatcher, getScheme, getServerName, getServerPort, getServletContext, isAsyncStarted, isAsyncSupported, isSecure, removeAttribute, setAttribute, setCharacterEncoding, startAsync, startAsync
-
Field Details
-
BASIC_AUTH
-
FORM_AUTH
-
CLIENT_CERT_AUTH
String identifier for Client Certificate authentication. Value "CLIENT_CERT"- See Also:
-
DIGEST_AUTH
String identifier for Digest authentication. Value "DIGEST"- See Also:
-
-
Method Details
-
getAuthType
String getAuthType()Returns the name of the authentication scheme used to protect the servlet. All servlet containers support basic, form and client certificate authentication, and may additionally support digest authentication. If the servlet is not authenticatednullis returned.Same as the value of the CGI variable AUTH_TYPE.
- Returns:
- one of the static members BASIC_AUTH, FORM_AUTH, CLIENT_CERT_AUTH, DIGEST_AUTH (suitable for ==
comparison) or the container-specific string indicating the authentication scheme, or
nullif the request was not authenticated.
-
getCookies
Cookie[] getCookies()Returns an array containing all of theCookieobjects the client sent with this request. This method returnsnullif no cookies were sent.- Returns:
- an array of all the
Cookiesincluded with this request, ornullif the request has no cookies
-
getDateHeader
Returns the value of the specified request header as alongvalue that represents aDateobject. Use this method with headers that contain dates, such asIf-Modified-Since.The date is returned as the number of milliseconds since January 1, 1970 GMT. The header name is case insensitive.
If the request did not have a header of the specified name, this method returns -1. If the header can't be converted to a date, the method throws an
IllegalArgumentException.- Parameters:
name- aStringspecifying the name of the header- Returns:
- a
longvalue representing the date specified in the header expressed as the number of milliseconds since January 1, 1970 GMT, or -1 if the named header was not included with the request - Throws:
IllegalArgumentException- If the header value can't be converted to a date
-
getHeader
Returns the value of the specified request header as aString. If the request did not include a header of the specified name, this method returnsnull. If there are multiple headers with the same name, this method returns the first head in the request. The header name is case insensitive. You can use this method with any request header.- Parameters:
name- aStringspecifying the header name- Returns:
- a
Stringcontaining the value of the requested header, ornullif the request does not have a header of that name
-
getHeaders
Returns all the values of the specified request header as anEnumerationofStringobjects.Some headers, such as
Accept-Languagecan be sent by clients as several headers each with a different value rather than sending the header as a comma separated list.If the request did not include any headers of the specified name, this method returns an empty
Enumeration. The header name is case insensitive. You can use this method with any request header.- Parameters:
name- aStringspecifying the header name- Returns:
- an
Enumerationcontaining the values of the requested header. If the request does not have any headers of that name return an empty enumeration. If the container does not allow access to header information, return null
-
getHeaderNames
Enumeration<String> getHeaderNames()Returns an enumeration of all the header names this request contains. If the request has no headers, this method returns an empty enumeration.Some servlet containers do not allow servlets to access headers using this method, in which case this method returns
null- Returns:
- an enumeration of all the header names sent with this request; if the request has no headers, an empty
enumeration; if the servlet container does not allow servlets to use this method,
null
-
getIntHeader
Returns the value of the specified request header as anint. If the request does not have a header of the specified name, this method returns -1. If the header cannot be converted to an integer, this method throws aNumberFormatException.The header name is case insensitive.
- Parameters:
name- aStringspecifying the name of a request header- Returns:
- an integer expressing the value of the request header or -1 if the request doesn't have a header of this name
- Throws:
NumberFormatException- If the header value can't be converted to anint
-
getHttpServletMapping
Obtain the mapping information for this request.- Returns:
- the mapping information for this request
-
getMethod
String getMethod()Returns the name of the HTTP method with which this request was made, for example, GET, POST, or PUT. Same as the value of the CGI variable REQUEST_METHOD.- Returns:
- a
Stringspecifying the name of the method with which this request was made
-
getPathInfo
String getPathInfo()Returns any extra path information associated with the URL the client sent when it made this request. The extra path information follows the servlet path but precedes the query string and will start with a "/" character.This method returns
nullif there was no extra path information.Same as the value of the CGI variable PATH_INFO.
- Returns:
- a
String, decoded by the web container, specifying extra path information that comes after the servlet path but before the query string in the request URL; ornullif the URL does not have any extra path information
-
getPathTranslated
String getPathTranslated()Returns any extra path information after the servlet name but before the query string, and translates it to a real path. Same as the value of the CGI variable PATH_TRANSLATED.If the URL does not have any extra path information, this method returns
nullor the servlet container cannot translate the virtual path to a real path for any reason (such as when the web application is executed from an archive). The web container does not decode this string.- Returns:
- a
Stringspecifying the real path, ornullif the URL does not have any extra path information
-
newPushBuilder
Obtain a builder for generating push requests.PushBuilderdocuments how this request will be used as the basis for a push request. Each call to this method will return a new instance, independent of any previous instance obtained.- Returns:
- A builder that can be used to generate push requests based on this request or
nullif push is not supported. Note that even if a PushBuilder instance is returned, by the time thatPushBuilder.push()is called, it may no longer be valid to push a request and the push request will be ignored. - Since:
- Servlet 4.0
-
getContextPath
String getContextPath()Returns the portion of the request URI that indicates the context of the request. The context path always comes first in a request URI. The path starts with a "/" character but does not end with a "/" character. For servlets in the default (root) context, this method returns "". The container does not decode this string.- Returns:
- a
Stringspecifying the portion of the request URI that indicates the context of the request
-
getQueryString
String getQueryString()Returns the query string that is contained in the request URL after the path. This method returnsnullif the URL does not have a query string. Same as the value of the CGI variable QUERY_STRING.- Returns:
- a
Stringcontaining the query string ornullif the URL contains no query string. The value is not decoded by the container.
-
getRemoteUser
String getRemoteUser()Returns the login of the user making this request, if the user has been authenticated, ornullif the user has not been authenticated. Whether the user name is sent with each subsequent request depends on the browser and type of authentication. Same as the value of the CGI variable REMOTE_USER.- Returns:
- a
Stringspecifying the login of the user making this request, ornullif the user login is not known
-
isUserInRole
Returns a boolean indicating whether the authenticated user is included in the specified logical "role". Roles and role membership can be defined using deployment descriptors. If the user has not been authenticated, the method returnsfalse.- Parameters:
role- aStringspecifying the name of the role- Returns:
- a
booleanindicating whether the user making this request belongs to a given role;falseif the user has not been authenticated
-
getUserPrincipal
Principal getUserPrincipal()Returns ajava.security.Principalobject containing the name of the current authenticated user. If the user has not been authenticated, the method returnsnull.- Returns:
- a
java.security.Principalcontaining the name of the user making this request;nullif the user has not been authenticated
-
getRequestedSessionId
String getRequestedSessionId()Returns the session ID specified by the client. This may not be the same as the ID of the current valid session for this request. If the client did not specify a session ID, this method returnsnull.- Returns:
- a
Stringspecifying the session ID, ornullif the request did not specify a session ID - See Also:
-
getRequestURI
String getRequestURI()Returns the part of this request's URL from the protocol name up to the query string in the first line of the HTTP request. The web container does not decode this String. For example:Examples of Returned Values First line of HTTP request Returned Value POST /some/path.html HTTP/1.1 /some/path.html GET http://foo.bar/a.html HTTP/1.0 /a.html HEAD /xyz?a=b HTTP/1.1 /xyz To reconstruct a URL with a scheme and host, use
getRequestURL().- Returns:
- a
Stringcontaining the part of the URL from the protocol name up to the query string - See Also:
-
getRequestURL
StringBuffer getRequestURL()Reconstructs the URL the client used to make the request. The returned URL contains a protocol, server name, port number, and server path, but it does not include query string parameters.Because this method returns a
StringBuffer, not a string, you can modify the URL easily, for example, to append query parameters.This method is useful for creating redirect messages and for reporting errors.
- Returns:
- a
StringBufferobject containing the reconstructed URL
-
getServletPath
String getServletPath()Returns the part of this request's URL that calls the servlet. This path starts with a "/" character and includes either the servlet name or a path to the servlet, but does not include any extra path information or a query string. Same as the value of the CGI variable SCRIPT_NAME.This method will return an empty string ("") if the servlet used to process this request was matched using the "/*" pattern.
- Returns:
- a
Stringcontaining the name or path of the servlet being called, as specified in the request URL, decoded, or an empty string if the servlet used to process the request is matched using the "/*" pattern.
-
getSession
Returns the currentHttpSessionassociated with this request or, if there is no current session andcreateis true, returns a new session.If
createisfalseand the request has no validHttpSession, this method returnsnull.To make sure the session is properly maintained, you must call this method before the response is committed. If the container is using cookies to maintain session integrity and is asked to create a new session when the response is committed, an IllegalStateException is thrown.
- Parameters:
create-trueto create a new session for this request if necessary;falseto returnnullif there's no current session- Returns:
- the
HttpSessionassociated with this request ornullifcreateisfalseand the request has no valid session - See Also:
-
getSession
HttpSession getSession()Returns the current session associated with this request, or if the request does not have a session, creates one.- Returns:
- the
HttpSessionassociated with this request - See Also:
-
changeSessionId
String changeSessionId()Changes the session ID of the session associated with this request. This method does not create a new session object it only changes the ID of the current session.- Returns:
- the new session ID allocated to the session
- Since:
- Servlet 3.1
- See Also:
-
isRequestedSessionIdValid
boolean isRequestedSessionIdValid()Checks whether the requested session ID is still valid.- Returns:
trueif this request has an id for a valid session in the current session context;falseotherwise- See Also:
-
isRequestedSessionIdFromCookie
boolean isRequestedSessionIdFromCookie()Checks whether the requested session ID came in as a cookie.- Returns:
trueif the session ID came in as a cookie; otherwise,false- See Also:
-
isRequestedSessionIdFromURL
boolean isRequestedSessionIdFromURL()Checks whether the requested session ID came in as part of the request URL.- Returns:
trueif the session ID came in as part of a URL; otherwise,false- See Also:
-
isRequestedSessionIdFromUrl
Deprecated.As of Version 2.1 of the Java Servlet API, useisRequestedSessionIdFromURL()instead.- Returns:
isRequestedSessionIdFromURL()
-
authenticate
Triggers the same authentication process as would be triggered if the request is for a resource that is protected by a security constraint.- Parameters:
response- The response to use to return any authentication challenge- Returns:
trueif the user is successfully authenticated andfalseif not- Throws:
IOException- if the authentication process attempted to read from the request or write to the response and an I/O error occurredIllegalStateException- if the authentication process attempted to write to the response after it had been committedServletException- if the authentication failed and the caller is expected to handle the failure- Since:
- Servlet 3.0
-
login
Authenticate the provided user name and password and then associated the authenticated user with the request.- Parameters:
username- The user name to authenticatepassword- The password to use to authenticate the user- Throws:
ServletException- If any ofgetRemoteUser(),getUserPrincipal()orgetAuthType()are non-null, if the configured authenticator does not support user name and password authentication or if the authentication fails- Since:
- Servlet 3.0
-
logout
Removes any authenticated user from the request.- Throws:
ServletException- If the logout fails- Since:
- Servlet 3.0
-
getParts
Return a collection of all uploaded Parts.- Returns:
- A collection of all uploaded Parts.
- Throws:
IOException- if an I/O error occursIllegalStateException- if size limits are exceeded or no multipart configuration is providedServletException- if the request is not multipart/form-data- Since:
- Servlet 3.0
-
getPart
Gets the named Part or null if the Part does not exist. Triggers upload of all Parts.- Parameters:
name- The name of the Part to obtain- Returns:
- The named Part or null if the Part does not exist
- Throws:
IOException- if an I/O error occursIllegalStateException- if size limits are exceededServletException- if the request is not multipart/form-data- Since:
- Servlet 3.0
-
upgrade
<T extends HttpUpgradeHandler> T upgrade(Class<T> httpUpgradeHandlerClass) throws IOException, ServletException Start the HTTP upgrade process and create and instance of the provided protocol handler class. The connection will be passed this instance once the current request/response pair has completed processing. Calling this method sets the response status toHttpServletResponse.SC_SWITCHING_PROTOCOLS.- Type Parameters:
T- The type of the upgrade handler- Parameters:
httpUpgradeHandlerClass- The class that implements the upgrade handler- Returns:
- A newly created instance of the specified upgrade handler type
- Throws:
IOException- if an I/O error occurred during the upgradeServletException- if the given httpUpgradeHandlerClass fails to be instantiated- Since:
- Servlet 3.1
-
getTrailerFields
-
isTrailerFieldsReady
default boolean isTrailerFieldsReady()Are trailer fields ready to be read (there may still be no trailers to read). This method always returnstrueif the underlying protocol does not support trailer fields. Otherwise,trueis returned once all of the following are true:- The application has ready all the request data and an EOF has been received or the content-length is zero
- All trailer fields, if any, have been received
- Returns:
trueif trailers are ready to be read- Since:
- Servlet 4.0
-
isRequestedSessionIdFromURL()instead.