Cookie Session - accidentlywoo/secsec GitHub Wiki

Cookie์™€ Session

Cookie

Cookie ํด๋ž˜์Šค๋Š” javax.servlet.http ํŒจํ‚ค์ง€์— ์†ํ•˜๋ฉฐ, ์ด ํด๋ž˜์Šค์˜ ๊ฐ์ฒด๋ฅผ ๋งŒ๋“ค ๋•Œ๋Š” ์ฟ ํ‚ค์˜ ์ด๋ฆ„๊ณผ ๊ฐ’์„ ํŒŒ๋ผ๋ฏธํ„ฐ๋กœ ๋„˜๊ฒจ์ค˜์•ผ ํ•œ๋‹ค.

์›น ๋ธŒ๋ผ์šฐ์ €๋Š” ์›น ์„œ๋ฒ„๊ฐ€ ์•„๋ฌด๋Ÿฐ ์š”์ฒญ์„ ํ•˜์ง€ ์•Š์•„๋„ ์›น ์„œ๋ฒ„๋กœ URL์„ ๋ณด๋‚ผ ๋•Œ ๋งˆ๋‹ค ๊ทธ URL์— ํฌํ•จ๋œ ์›น ์„œ๋ฒ„์˜ ์ฃผ์†Œ์— ํ•ด๋‹นํ•˜๋Š” ๋ชจ๋“  ์ฟ ํ‚ค๋ฅผ ์ฐพ์•„์„œ ์›น ์„œ๋ฒ„๋กœ ํ•จ๊ป˜ ๋ณด๋‚ธ๋‹ค.

Cookie์ด์šฉํ•˜๋Š” ๋ฐฉ๋ฒ•

  1. HTML์œ ์ง€ํ•˜๋Š” ๋ฐฉ๋ฒ• -> JavaScript Cookie(BOM)
  2. JavaScript Library
  3. Servlet

์ฟ ํ‚ค๋Š” ๋ฌธ์ž์—ด๋งŒ ์ €์žฅ๊ฐ€๋Šฅ

์„ธ์…˜์€ ๋ชจ๋“  ๋ฐ์ดํ„ฐํƒ€์ž… ์ €์žฅ๊ฐ€๋Šฅ

Session

HttpSession session = request.getSession();

session.setInactiveInterval(10);

session.invalidate();

session.removeAttribute("loginInfo");

Servlet Life Cycle

JSP Life Cycle

  1. a.jsp ์š”์ฒญ [ํด๋ผ์ด์–ธํŠธ]
  2. a_jsp.java ํŒŒ์ผ ์ฐพ๊ธฐ [WAS]
    1. No)
  1. a_jsp.javaํŒŒ์ผ Generated
  2. Compile --> a_jsp.class
  3. ๊ฐ์ฑ„ ์ƒ์„ฑ
  4. ์ƒ์„ฑ์ž ํ˜ธ์ถœ
  5. jspInit() ์ž๋™ ํ˜ธ์ถœ [WAS๊ฐ€ ํ˜ธ์ถœ Inversion of Controll : servlet์—์„œ๋Š” init()]
  6. _jspService() ์ž๋™ํ˜ธ์ถœ