A base class which can be subclassed to create a HTTP filter component for a Web site.
More...
A base class which can be subclassed to create a HTTP filter component for a Web site.
- Note
- Threading: as with TdjWebComponent, the framework creates exactly one instance of each registered filter, and every concurrent request runs through that same instance's DoFilter method on its own thread. Do not keep per-request state in instance fields — two requests handled at the same time will read and write the same field, corrupting each other's data. Use local variables for anything request-specific, and if state truly must be shared across requests, synchronize access to it explicitly (e.g. with a critical section).
-
URL patterns are not authorization. A filter mapped to a prefix or suffix pattern (e.g. everything under '/admin/') is a routing rule, matched after the framework normalizes the request path (collapsing '.', '..' and repeated '/', and stripping ';'-parameters) – but it says nothing about who the caller is. An authentication/authorization filter must still check the caller's identity itself (e.g. the session) before allowing a request through, rather than relying on the URL pattern alone to gate access.