java - 连续的服务器请求导致 hibernate 异常问题, session 的不安全使用

标签 java mysql hibernate spring-mvc spring-aop

我使用 Spring 4.3、hibernate 5 和 MySQL 5.6 创建了 Web 应用程序。

从 Spring 我正在使用 - 1.Spring处理程序拦截器-用于过滤每个请求。

2.Spring MVC - 管理 REST Web 资源。

3.Spring AOP - 作为声明式方法的事务管理器(@Transactional)

4.Hibernate - ORM 和 session 连接管理。

应用程序已成功部署在服务器上,我可以登录。

现在让我们谈谈我的问题:- 我登录到应用程序并连续点击请求(使用 f5)一段时间后从 hibernate DAO 层抛出异常。

每次都会遇到不同的异常,例如:-

  1. org.springframework.orm.hibernate5.HibernateSystemException:HHH000479:集合[dao.domain.WebService.webServicePermissionMaps]未由flush()处理。这可能是由于 session 的不安全使用(例如,同时在多个线程中使用、在实体生命周期 Hook 期间更新)。

  2. 内部服务器错误发现同一集合的两种表示形式: dao.domain.WebService.webServicePermissionMaps;

3.${PATTERN}${PATTERN} java.lang.NullPointerException: null 在 org.hibernate.event.internal.AbstractFlushingEventListener.prepareCollectionFlushes(AbstractFlushingEventListener.java:178) ~[hibernate-core-5.2.7.Final.jar:5.2.7.Final]

4.${PATTERN}${PATTERN} org.springframework.orm.hibernate5.HibernateSystemException:找到对集合的共享引用:dao.domain.WebService.webServicePermissionMaps;嵌套异常是 org.hibernate.HibernateException:找到对集合的共享引用:dao.domain.WebService.webServicePermissionMaps。

5.引起:java.sql.SQLException:语句关闭后不允许执行任何操作。 在 com.mysql.jdbc.SQLError.createSQLException(SQLError.java:998) ~[mysql-connector-java-5.1.36.jar:5.1.36]

以下是我的代码:-

Spring 配置-

@Configuration
@EnableWebMvc
@Import({DbConfiguration.class})
@ComponentScan(basePackages = "com")
@PropertySource("classpath:application.properties")
public class RestConfig extends WebMvcConfigurerAdapter {
    @Override
    public void addInterceptors(InterceptorRegistry registry) {
        registry.addInterceptor(authenticationInterceptor()).excludePathPatterns("/security/authenticate").excludePathPatterns("/security/ssoAuthenticate");
        registry.addInterceptor(authorizationInterceptor()).excludePathPatterns("/security/authenticate").excludePathPatterns("/security/ssoAuthenticate");
    }

    @Bean
    public AuthorizationInterceptor authorizationInterceptor() {
        return new AuthorizationInterceptor();
    }
}

数据库配置类-

@Configuration

    @EnableTransactionManagement

    public class DbConfiguration {

    @Bean
    public DataSource dataSource() throws NamingException { 
            return (DataSource) new JndiTemplate().lookup(env.getRequiredProperty("jdbc.url"));
        }

@Bean
@Autowired
public LocalSessionFactoryBean sessionFactory() throws NamingException {
    LocalSessionFactoryBean sessionFactory = new LocalSessionFactoryBean();
    sessionFactory.setDataSource(dataSource());
    sessionFactory.setPackagesToScan(new String[]{"com.dao"});
    sessionFactory.setHibernateProperties(hibProperties());
    return sessionFactory;
}

@Bean
@Autowired
public HibernateTransactionManager transactionManager(SessionFactory sessionFactory) {
    HibernateTransactionManager tm = new HibernateTransactionManager();
    tm.setSessionFactory(sessionFactory);
    return tm;
}

private Properties hibProperties() {
    Properties properties = new Properties();
    properties.put(PROPERTY_NAME_HIBERNATE_DIALECT, env.getRequiredProperty(PROPERTY_NAME_HIBERNATE_DIALECT));
    properties.put(PROPERTY_NAME_HIBERNATE_SHOW_SQL, "false");
    return properties;
}

}

Spring 拦截器-

public class AuthorizationInterceptor extends HandlerInterceptorAdapter {

private static Logger log = LoggerFactory.getLogger(AuthenticationInterceptor.class);

@Autowired
private ApplicationContext appContext;

@Override
public boolean preHandle(HttpServletRequest request, HttpServletResponse response, Object handler)
        throws Exception {

    //variables declaration
    try {
        servicePath = (String ) request.getAttribute(HandlerMapping.BEST_MATCHING_PATTERN_ATTRIBUTE);

        WebServiceUtil webServiceUtil = (WebServiceUtil)appContext.getBean("webServiceUtil");

        //This method causing hibernate erroe
        boolean isAccessible = webServiceUtil.isWebServiceAccessbile(roles, servicePath, request.getMethod());

    }catch (Exception e) {
        log.error("Error occured in AuthorizationInterceptor.preHandle method role  are : "+roles, e);
        response.setStatus(HttpStatus.INTERNAL_SERVER_ERROR.value());
        response.getWriter().write(e.getMessage());
        return false;
    }
    return true;
}

}

-Util Class(希望此类bean进入请求范围。此类没有@Transactional)

@Service("webServiceUtil")
@Scope(proxyMode = ScopedProxyMode.TARGET_CLASS, value = "request")
public class WebServiceUtil {

@Autowired
private AuthorizationService authorizationService;

public boolean isWebServiceAccessbile(Set<String> roles, String basePath, String methodType)
            throws SysException {

        try {
            List<WebService> webservices = authorizationService.getWebService(roles, methodType);

            List<String> webserviceUrl = new ArrayList<String>();
            for (WebService webService : webservices) {
                webserviceUrl.add(webService.getUrl());
            }

            return webserviceUrl.contains(basePath);
        } catch (SysException e) {
            throw e;
        }
    }
}

-服务等级

@Service("authorizationService")
public class AuthorizationServiceImpl implements AuthorizationService {

@Autowired
private WebServiceDAO webServiceDAO;

@Override
    @Transactional
    public List<WebService> getWebService(Set<String> roles, String method) throws DataAccessException {
            return webServiceDAO.getWebServices(roles, method);
    }

}

@存储库 公共(public)类 WebServiceDAOImpl 扩展 BaseDAOImpl 实现 WebServiceDAO {

private static Logger log = LoggerFactory.getLogger(WebServiceDAOImpl.class);

@Override
public List<WebService> getWebServices(Set<String> roles, String methodType) throws DataAccessException {

    TypedQuery<WebService> query = null;
    try {
        Session session = getSessionFromSessionFactory(getSessionFactory());

        StringBuilder sqlString = new StringBuilder("select ws.* from WEB_SERVICE_PERMISSION_MAP wpm "+ 
                 "join WEB_SERVICE ws on ws.ID = wpm.WEB_SERVICE_ID "+
                 "join WEB_SERVICE_METHOD wsm on wsm.ID = wpm.WEB_SERVICE_METHOD_ID "+
                 "where wpm.PERMISSION_ID in "+
                 "(select pe.id from ROLE_PERMISSION rope "+
                 "inner join Permission pe on rope.PERMISSIONID = pe.id "+
                 "inner join Role ro on rope.ROLEID = ro.ID "+
                 "where ro.name in (:roles)) and "+
                 "wsm.NAME in (:method)");

        query = session.createNativeQuery(sqlString.toString(), WebService.class);
        query.setParameter("roles", roles);
        query.setParameter("method", methodType);

    } catch (Exception e) {
        log.error("Error occured in WebServiceDAOImpl.getWebServices method while getting web services for roles : "+roles+" and request method type : "+methodType, e);
        throw new DataAccessException("Error occured in WebServiceDAOImpl.getWebServices method while getting web services for roles : "+roles+" and request method type : "+methodType, e);
    }
    return query.getResultList();
}

}

-Base DAO

public class BaseDAOImpl<T> implements BaseDAO<T> {

    @Autowired
    private SessionFactory sessionFactory;
    private Session session;
    private Class<T> domainClass;

    public Session getSessionFromSessionFactory(SessionFactory sessionFactory) {
        try {
            session = sessionFactory.getCurrentSession();
        } catch (HibernateException he) {
            log.error("Error in getSessionFromSessionFactory :" + he.getStackTrace());
        }
        return session;

    }

    public SessionFactory getSessionFactory() {
        return sessionFactory;
    }

    public void setSessionFactory(SessionFactory sessionFactory) {
        this.sessionFactory = sessionFactory;
    }

    public Session getSession() {
        return session;
    }

    public void setSession(Session session) {
        this.session = session;
    }

} 

最佳答案

问题已解决。这是我的错,因为我在类级别创建了 session 对象。并且 session 对象在线程之间共享。

关于java - 连续的服务器请求导致 hibernate 异常问题, session 的不安全使用,我们在Stack Overflow上找到一个类似的问题: https://stackoverflow.com/questions/47305687/

相关文章:

mysql - SQL中如何将每个组的结果与总体跨组指标进行比较

java - 如何使用JPA、Hibernate、Spring Boot实现复合主键和复合外键

java - 具有多个关联的 Hibernate 提取

java - getSharedPrefernces 仅在一个 Activity 中返回 null,而该 Activity 在另一个 Activity 中运行良好

java - 如何更改 JFrame 标题的字体?

mysql - SELECT * 和 SELECT ALL 之间有区别吗?

mysql - 在 MySQL 中存储货币值的最佳数据类型

java - JPA EntityManager.merge() 尝试将更新级联到已删除的实体

java - KeyListener 在 JFrame 中随机工作

java - 如何在 Java 中创建内存泄漏?