2

从早上开始,我一直在尝试解决这个问题。我有客户端和服务器应用程序,客户端发送用户名和密码,服务器接收它,检查数据库,向正确的用户发送成功消息。
但是,我无法从客户端处理此请求。
有什么问题,它在哪里撒谎?等待专家解决方案...

这是服务器:

import java.io.*;
import java.net.*;
import java.io.FileOutputStream;
import java.io.ObjectInputStream;
import java.io.ObjectOutputStream;
import java.net.ServerSocket;
import java.net.Socket;
import java.io.File;
import java.sql.*;

class TCPServer
{
    public static void main(String argv[]) throws Exception
       {
          String clientSentence,clientpassword;
          String capitalizedSentence;
          ServerSocket welcomeSocket = new ServerSocket(4003);
          Connection con = null;
          String url = "jdbc:mysql://localhost:3306/";
          String db = "database";
          String driver = "com.mysql.jdbc.Driver";
          String user = "root";
          String pass = "root";

          while(true)
          {
             Socket connectionSocket = welcomeSocket.accept();
             BufferedReader inFromClient =
             new BufferedReader(new InputStreamReader(connectionSocket.getInputStream()));
             BufferedReader inFromClient1 =
             new BufferedReader(new InputStreamReader(connectionSocket.getInputStream()));
             DataOutputStream outToClient = new DataOutputStream(connectionSocket.getOutputStream());
             clientSentence = inFromClient.readLine(); 
             clientpassword = inFromClient.readLine();
             System.out.println("Received User Name: " + clientSentence);
             System.out.println("Received Password: " + clientpassword);
             Class.forName(driver).newInstance();
             con = DriverManager.getConnection(url+db, user, pass);
             Statement st = con.createStatement();
             ResultSet res = st.executeQuery("SELECT * FROM  table WHERE user='clientSentence' AND password='clientpassword'");
             while (res.next()) { 
             String u = res.getString("user");
             String p = res.getString("password");
             if (clientSentence.equals(u) && clientpassword.equals(p)){
             capitalizedSentence = "Welcome "+clientSentence+" \n";
             outToClient.writeBytes(capitalizedSentence); 
            }else{  
             capitalizedSentence = "Sorry, not authorized \n";
             outToClient.writeBytes(capitalizedSentence); 
            }    
          }
        }con.close();
       }
}

和客户:

import java.io.*;
import java.net.*;
import java.io.File;
import java.io.FileInputStream;
import java.io.ObjectInputStream;
import java.io.ObjectOutputStream;
import java.net.Socket;
import java.util.Arrays;
import java.lang.*;
import java.util.Scanner;

class TCPClient
{
  public static void main(String argv[]) throws Exception
  {
   String sentence,sentence1;
   String modifiedSentence;
   BufferedReader inFromUser = new BufferedReader( new InputStreamReader(System.in));
   BufferedReader inFromUser1 = new BufferedReader( new InputStreamReader(System.in));
   Socket clientSocket = new Socket("localhost", 4003);
   DataOutputStream outToServer = new DataOutputStream(clientSocket.getOutputStream());
   DataOutputStream outToServer1 = new DataOutputStream(clientSocket.getOutputStream());
   BufferedReader inFromServer = new BufferedReader(new InputStreamReader(clientSocket.getInputStream()));
   Console console = System.console();
   String username = console.readLine("Enter your Username :");
   char pswd[] = console.readPassword("Enter your Password :");
   String upwd=new String(pswd);
   outToServer.writeBytes(username + '\n');
   outToServer1.writeBytes(upwd + '\n');
   modifiedSentence = inFromServer.readLine();
   System.out.println("FROM SERVER: " + modifiedSentence);
}
   clientSocket.close();
  }
}
4

2 回答 2

2

如果您在同一台机器上运行客户端和服务器,则不应为客户端和服务器套接字使用相同的端口..使用不同的端口..

于 2012-09-07T09:11:51.163 回答
2

如果您的 JVM 没有关联,您的代码会导致 in NullPointerExceptionTCPClientConsole


ResultSet res = st.executeQuery("SELECT * FROM table WHERE user='clientSentence' AND password='clientpassword'");

除非您真的想始终使用用户名“clientSentence”和密码“clientpassword”,否则这绝对行不通。

您应该传递您在该行上方设置的相应 java 变量的实际值。此外,正确的方法是使用 aPreparedStatement并将用户输入作为参数传递,以便驱动程序负责清理输入以避免 SQL 注入或类似ImbecilUserException. :)

于 2012-09-07T09:17:23.903 回答