RequestDispatcher include未执行JSP文件,仅显示源码的解决方法
问题:输入未注册邮箱时,调用include引入的JSP未执行,仅显示源码
核心Servlet代码
Class.forName("com.mysql.jdbc.Driver"); Connection con = DriverManager.getConnection("jdbc:mysql://localhost:3306/mysql", "root", "12345"); Statement st = con.createStatement(); String mi = "select * from empinfo where EEmailID = '" + email + "'"; ResultSet rs = st.executeQuery(mi); if (rs.next()) { if (email.equals(rs.getString("EEMailID"))) { // Generate a random OTP Random random = new Random(); int otp = 100000 + random.nextInt(900000); // Send OTP through email Calling Function sendEmail(otp, email); // Store OTP in the session for Verification HttpSession session = request.getSession(); session.setAttribute("OTP", Integer.toString(otp)); session.setAttribute("eemail", email); // Redirect the user to the OTP verification page response.sendRedirect("otp.jsp"); } } else { out.println("Enter Registered Email Id only"); RequestDispatcher dis = getServletContext().getRequestDispatcher("/forgotpassword.jsp"); dis.include(request, response); }
当前输出
<p>Enter Registered Email Id only</p> <!DOCTYPE html> <html> <head> <meta http-equiv="Content-Type" content="text/html; charset=UTF-8"> <link href="bootstrap-4.0.0-dist/css/bootstrap.css" rel="stylesheet" type="text/css"/> <link href="bootstrap-4.0.0-dist/css/bootstrap.min.css" rel="stylesheet" type="text/css"/> <title>JSP Page</title> </head> <body> <center> <form action="OTPLoginServlet" method="post"> <label for="email">Email:</label> <input type="email" id="email" name="email"><br><br> <input type="submit" value="Submit"> </form> </center> </body> </html>
解决方法
1. 修正响应内容类型
在调用out.println()或include之前,设置正确的响应Content-Type,告诉浏览器这是HTML内容:
response.setContentType("text/html;charset=UTF-8");
如果不设置,Servlet默认响应类型可能为text/plain,导致JSP的HTML源码被当作纯文本输出。
2. 避免直接用out.println()输出后再include
直接输出文本会打乱响应流逻辑,建议把错误提示存入request属性,让JSP负责渲染:
else { // 设置错误提示到request属性 request.setAttribute("errorMsg", "请输入已注册的邮箱"); RequestDispatcher dis = getServletContext().getRequestDispatcher("/forgotpassword.jsp"); dis.forward(request, response); // 用forward更适合错误场景,替代include }
然后在forgotpassword.jsp中添加代码显示错误:
<% String errorMsg = (String) request.getAttribute("errorMsg"); if (errorMsg != null) { %> <p style="color:red;"><%= errorMsg %></p> <% } %>
3. 检查JSP路径是否正确
确保/forgotpassword.jsp位于Web应用根目录下,如果JSP放在WEB-INF文件夹内,路径需要改为/WEB-INF/forgotpassword.jsp。
4. 修复SQL注入漏洞(附带优化)
当前代码用字符串拼接生成SQL,存在严重注入风险,必须改用PreparedStatement:
String sql = "SELECT * FROM empinfo WHERE EEmailID = ?"; PreparedStatement pst = con.prepareStatement(sql); pst.setString(1, email); // 安全绑定参数 ResultSet rs = pst.executeQuery();
内容的提问来源于stack exchange,提问作者Diana
相关产品推荐
相关产品推荐

