Primefaces单选按钮未校验禁用状态问题咨询
问题分析:PrimeFaces单选按钮禁用值可被提交的问题
场景复现
给出的基础单选按钮示例代码如下:
<h:form> <p:selectOneRadio value="#{radioBean.text}"> <f:selectItem itemValue="one" itemLabel="One"/> <f:selectItem itemValue="two" itemLabel="Two"/> <f:selectItem itemValue="three-disabled" itemLabel="Three (disabled)" itemDisabled="true"/> <f:selectItem itemValue="four-disabled" itemLabel="Four (disabled)" itemDisabled="true"/> <p:ajax update="@form"/> </p:selectOneRadio> <p>Selected: #{radioBean.text}</p> </h:form>
默认状态下,one和two可正常选中,three-disabled、four-disabled为禁用状态无法通过前端点击选择。但通过以下两种方式,禁用值仍能被设置到radioBean中:
- 构造HTTP POST请求直接提交
three-disabled值 - 修改页面DOM中
two选项的value为three-disabled后点击选择
原因对比
标准JSF的MenuRenderer在decode阶段会先收集所有禁用选项的值,再从提交参数中移除这些禁用值,确保禁用选项不会被绑定到后端Bean。
而PrimeFaces的单选按钮decode逻辑存在差异:当未检测到有效可选值的提交时,会直接采用原始提交值,这就导致禁用值可以绕过前端限制,被设置到Bean中。
结论
你的理解没有问题——禁用的单选按钮选项本应在后端也被拦截,不允许被提交绑定到Bean。这是PrimeFaces组件在decode逻辑上的实现缺陷,未遵循标准JSF的处理规范,忽略了对禁用选项值的后端校验拦截。
内容的提问来源于stack exchange,提问作者Evan Knowles
相关产品推荐
相关产品推荐

