RequestDispatcher forward方法不生效:JEE应用权限验证后无法跳转至未授权页面
Alright, let's tackle why your Authenticate validation logic isn't redirecting to the Unauthorized page when it should, and instead seems to let the user pass through to the original JSP. The issue is almost certainly tied to how you're using synchronous AJAX here.
Why the Current Setup Fails
Your synchronous AJAX call (async: "false") is causing the browser to handle the server's redirect response incorrectly:
- When your
Authenticateendpoint returns a 302 redirect to the Unauthorized page, the AJAX request automatically follows that redirect behind the scenes. - Instead of navigating the user's browser to the Unauthorized page, it just fetches the HTML content of that page as the AJAX response.
- Since you're not doing anything with that response, the original JSP stays visible, making it look like the user passed validation.
Step-by-Step Fixes
1. Ditch Synchronous AJAX (Critical!)
Synchronous AJAX is deprecated in modern browsers and causes poor user experience (blocks the browser until the request finishes). Switch to asynchronous requests instead, and handle the response explicitly.
2. Adjust Server-Side Logic
Instead of returning a 302 redirect for unauthorized users, have your Authenticate endpoint return a 401 Unauthorized status code, or a JSON response with a clear authorization status (e.g., {"authorized": false}). This lets your frontend code know exactly how to react.
3. Update the AJAX Code to Handle Validation
Modify your script to check the response from the server and trigger the redirect manually when needed:
<script type="text/javascript"> $.ajax({ url: "${pageContext.request.contextPath}/Authenticate", type: "get", async: true, // Use asynchronous request cache: false, dataType: "json", // Adjust if your server returns plain text/HTML instead success: function(response) { // If server returns JSON with authorization status if (!response.authorized) { window.location.href = "${pageContext.request.contextPath}/Unauthorized"; } // Proceed with your app logic if user is authorized }, error: function(xhr) { // Catch 401 status code from server if (xhr.status === 401) { window.location.href = "${pageContext.request.contextPath}/Unauthorized"; } } }); </script>
Alternative: Handle Redirect in AJAX (Less Preferred)
If you can't adjust the server-side redirect logic, you can check if the AJAX response came from the Unauthorized page and trigger a redirect:
<script type="text/javascript"> $.ajax({ url: "${pageContext.request.contextPath}/Authenticate", type: "get", async: true, cache: false, success: function(response) { // Check for unique content from your Unauthorized page if (response.includes("Unauthorized Access")) { // Replace with your page's unique text window.location.href = "${pageContext.request.contextPath}/Unauthorized"; } } }); </script>
Key Takeaways
- Synchronous AJAX doesn't play nice with server-side redirects because it handles them in the background, not at the page level.
- Always use asynchronous requests and explicitly handle authorization statuses in your frontend code.
- Matching server-side status codes (like 401) with frontend redirect logic is the most reliable and maintainable approach.
内容的提问来源于stack exchange,提问作者Ainsworth

