7a5e268a9c48f8cd621b5fafc6cedc02fa3d1c37.svn-base 6.2 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166
  1. package org.jeecg.common.util.filter;
  2. import org.apache.commons.lang3.StringUtils;
  3. import org.springframework.web.multipart.MultipartFile;
  4. import java.io.InputStream;
  5. import java.util.HashMap;
  6. import java.util.Iterator;
  7. import java.util.regex.Matcher;
  8. import java.util.regex.Pattern;
  9. /**
  10. * @Description: TODO
  11. * @author: lsq
  12. * @date: 2021年08月09日 15:29
  13. */
  14. public class FileTypeFilter {
  15. //文件后缀
  16. private static String[] forbidType = {"jsp","php"};
  17. // 初始化文件头类型,不够的自行补充
  18. final static HashMap<String, String> fileTypeMap = new HashMap<>();
  19. static {
  20. fileTypeMap.put("3c25402070616765206c", "jsp");
  21. fileTypeMap.put("3c3f7068700a0a2f2a2a0a202a205048", "php");
  22. /* fileTypeMap.put("ffd8ffe000104a464946", "jpg");
  23. fileTypeMap.put("89504e470d0a1a0a0000", "png");
  24. fileTypeMap.put("47494638396126026f01", "gif");
  25. fileTypeMap.put("49492a00227105008037", "tif");
  26. fileTypeMap.put("424d228c010000000000", "bmp");
  27. fileTypeMap.put("424d8240090000000000", "bmp");
  28. fileTypeMap.put("424d8e1b030000000000", "bmp");
  29. fileTypeMap.put("41433130313500000000", "dwg");
  30. fileTypeMap.put("3c21444f435459504520", "html");
  31. fileTypeMap.put("3c21646f637479706520", "htm");
  32. fileTypeMap.put("48544d4c207b0d0a0942", "css");
  33. fileTypeMap.put("696b2e71623d696b2e71", "js");
  34. fileTypeMap.put("7b5c727466315c616e73", "rtf");
  35. fileTypeMap.put("38425053000100000000", "psd");
  36. fileTypeMap.put("46726f6d3a203d3f6762", "eml");
  37. fileTypeMap.put("d0cf11e0a1b11ae10000", "doc");
  38. fileTypeMap.put("5374616E64617264204A", "mdb");
  39. fileTypeMap.put("252150532D41646F6265", "ps");
  40. fileTypeMap.put("255044462d312e350d0a", "pdf");
  41. fileTypeMap.put("2e524d46000000120001", "rmvb");
  42. fileTypeMap.put("464c5601050000000900", "flv");
  43. fileTypeMap.put("00000020667479706d70", "mp4");
  44. fileTypeMap.put("49443303000000002176", "mp3");
  45. fileTypeMap.put("000001ba210001000180", "mpg");
  46. fileTypeMap.put("3026b2758e66cf11a6d9", "wmv");
  47. fileTypeMap.put("52494646e27807005741", "wav");
  48. fileTypeMap.put("52494646d07d60074156", "avi");
  49. fileTypeMap.put("4d546864000000060001", "mid");
  50. fileTypeMap.put("504b0304140000000800", "zip");
  51. fileTypeMap.put("526172211a0700cf9073", "rar");
  52. fileTypeMap.put("235468697320636f6e66", "ini");
  53. fileTypeMap.put("504b03040a0000000000", "jar");
  54. fileTypeMap.put("4d5a9000030000000400", "exe");
  55. fileTypeMap.put("3c25402070616765206c", "jsp");
  56. fileTypeMap.put("4d616e69666573742d56", "mf");
  57. fileTypeMap.put("3c3f786d6c2076657273", "xml");
  58. fileTypeMap.put("494e5345525420494e54", "sql");
  59. fileTypeMap.put("7061636b616765207765", "java");
  60. fileTypeMap.put("406563686f206f66660d", "bat");
  61. fileTypeMap.put("1f8b0800000000000000", "gz");
  62. fileTypeMap.put("6c6f67346a2e726f6f74", "properties");
  63. fileTypeMap.put("cafebabe0000002e0041", "class");
  64. fileTypeMap.put("49545346030000006000", "chm");
  65. fileTypeMap.put("04000000010000001300", "mxp");
  66. fileTypeMap.put("504b0304140006000800", "docx");
  67. fileTypeMap.put("6431303a637265617465", "torrent");
  68. fileTypeMap.put("6D6F6F76", "mov");
  69. fileTypeMap.put("FF575043", "wpd");
  70. fileTypeMap.put("CFAD12FEC5FD746F", "dbx");
  71. fileTypeMap.put("2142444E", "pst");
  72. fileTypeMap.put("AC9EBD8F", "qdf");
  73. fileTypeMap.put("E3828596", "pwl");
  74. fileTypeMap.put("2E7261FD", "ram");*/
  75. }
  76. /**
  77. * @param fileName
  78. * @return String
  79. * @description 通过文件后缀名获取文件类型
  80. */
  81. private static String getFileTypeBySuffix(String fileName) {
  82. return fileName.substring(fileName.lastIndexOf(".") + 1, fileName.length());
  83. }
  84. /**
  85. * 文件类型过滤
  86. *
  87. * @param file
  88. */
  89. public static void fileTypeFilter(MultipartFile file) throws Exception {
  90. String suffix = getFileType(file);
  91. for (String type : forbidType) {
  92. if (type.contains(suffix)) {
  93. throw new Exception("上传失败,文件类型异常:" + suffix);
  94. }
  95. }
  96. }
  97. /**
  98. * 通过读取文件头部获得文件类型
  99. *
  100. * @param file
  101. * @return 文件类型
  102. * @throws Exception
  103. */
  104. private static String getFileType(MultipartFile file) throws Exception {
  105. String fileExtendName = null;
  106. InputStream is;
  107. try {
  108. //is = new FileInputStream(file);
  109. is = file.getInputStream();
  110. byte[] b = new byte[10];
  111. is.read(b, 0, b.length);
  112. String fileTypeHex = String.valueOf(bytesToHexString(b));
  113. Iterator<String> keyIter = fileTypeMap.keySet().iterator();
  114. while (keyIter.hasNext()) {
  115. String key = keyIter.next();
  116. // 验证前5个字符比较
  117. if (key.toLowerCase().startsWith(fileTypeHex.toLowerCase().substring(0, 5))
  118. || fileTypeHex.toLowerCase().substring(0, 5).startsWith(key.toLowerCase())) {
  119. fileExtendName = fileTypeMap.get(key);
  120. break;
  121. }
  122. }
  123. // 如果不是上述类型,则判断扩展名
  124. if (StringUtils.isBlank(fileExtendName)) {
  125. String fileName = file.getOriginalFilename();
  126. return getFileTypeBySuffix(fileName);
  127. }
  128. is.close();
  129. return fileExtendName;
  130. } catch (Exception exception) {
  131. throw new Exception(exception.getMessage(), exception);
  132. }
  133. }
  134. /**
  135. * 获得文件头部字符串
  136. *
  137. * @param src
  138. * @return
  139. */
  140. private static String bytesToHexString(byte[] src) {
  141. StringBuilder stringBuilder = new StringBuilder();
  142. if (src == null || src.length <= 0) {
  143. return null;
  144. }
  145. for (int i = 0; i < src.length; i++) {
  146. int v = src[i] & 0xFF;
  147. String hv = Integer.toHexString(v);
  148. if (hv.length() < 2) {
  149. stringBuilder.append(0);
  150. }
  151. stringBuilder.append(hv);
  152. }
  153. return stringBuilder.toString();
  154. }
  155. }