You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

RequestDispatcher include未执行JSP文件,仅显示源码的解决方法

问题:输入未注册邮箱时,调用include引入的JSP未执行,仅显示源码

核心Servlet代码

Class.forName("com.mysql.jdbc.Driver");
Connection con = DriverManager.getConnection("jdbc:mysql://localhost:3306/mysql", "root", "12345");
Statement st = con.createStatement();
String mi = "select * from empinfo where EEmailID = '" + email + "'";

ResultSet rs = st.executeQuery(mi);
if (rs.next()) {
    if (email.equals(rs.getString("EEMailID"))) { 
        // Generate a random OTP
        Random random = new Random();
        int otp = 100000 + random.nextInt(900000);

        // Send OTP through email Calling Function
        sendEmail(otp, email);

        // Store OTP in the session for Verification
        HttpSession session = request.getSession();
        session.setAttribute("OTP", Integer.toString(otp));
        session.setAttribute("eemail", email);

        // Redirect the user to the OTP verification page
        response.sendRedirect("otp.jsp");
    }
} else {
    out.println("Enter Registered Email Id only");
    RequestDispatcher dis = getServletContext().getRequestDispatcher("/forgotpassword.jsp");
    dis.include(request, response);
}

当前输出

<p>Enter Registered Email Id only</p>
<!DOCTYPE html>
<html>
    <head>
        <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
        <link href="bootstrap-4.0.0-dist/css/bootstrap.css" rel="stylesheet" type="text/css"/>
        <link href="bootstrap-4.0.0-dist/css/bootstrap.min.css" rel="stylesheet" type="text/css"/>
        <title>JSP Page</title>
    </head>
    <body>
       
        <center>
        <form action="OTPLoginServlet" method="post">
            <label for="email">Email:</label>
            <input type="email" id="email" name="email"><br><br>
            <input type="submit" value="Submit">
        </form>
    </center>
    </body>
</html>

解决方法

1. 修正响应内容类型

在调用out.println()或include之前,设置正确的响应Content-Type,告诉浏览器这是HTML内容:

response.setContentType("text/html;charset=UTF-8");

如果不设置,Servlet默认响应类型可能为text/plain,导致JSP的HTML源码被当作纯文本输出。

2. 避免直接用out.println()输出后再include

直接输出文本会打乱响应流逻辑,建议把错误提示存入request属性,让JSP负责渲染:

else {
    // 设置错误提示到request属性
    request.setAttribute("errorMsg", "请输入已注册的邮箱");
    RequestDispatcher dis = getServletContext().getRequestDispatcher("/forgotpassword.jsp");
    dis.forward(request, response); // 用forward更适合错误场景,替代include
}

然后在forgotpassword.jsp中添加代码显示错误:

<% 
String errorMsg = (String) request.getAttribute("errorMsg");
if (errorMsg != null) {
%>
    <p style="color:red;"><%= errorMsg %></p>
<% 
}
%>

3. 检查JSP路径是否正确

确保/forgotpassword.jsp位于Web应用根目录下,如果JSP放在WEB-INF文件夹内,路径需要改为/WEB-INF/forgotpassword.jsp。

4. 修复SQL注入漏洞(附带优化)

当前代码用字符串拼接生成SQL,存在严重注入风险,必须改用PreparedStatement:

String sql = "SELECT * FROM empinfo WHERE EEmailID = ?";
PreparedStatement pst = con.prepareStatement(sql);
pst.setString(1, email); // 安全绑定参数
ResultSet rs = pst.executeQuery();

内容的提问来源于stack exchange,提问作者Diana

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.27 03:32:45