Interface HttpServletRequest
- 
- All Superinterfaces:
- ServletRequest
 - All Known Implementing Classes:
- HttpServletRequestWrapper
 
 public interface HttpServletRequest extends ServletRequest Extends theServletRequestinterface to provide request information for HTTP servlets.The servlet container creates an HttpServletRequestobject and passes it as an argument to the servlet's service methods (doGet,doPost, etc).- Author:
- Various
 
- 
- 
Field SummaryFields Modifier and Type Field Description static StringBASIC_AUTHString identifier for Basic authentication.static StringCLIENT_CERT_AUTHString identifier for Client Certificate authentication.static StringDIGEST_AUTHString identifier for Digest authentication.static StringFORM_AUTHString identifier for Form authentication.
 - 
Method SummaryAll Methods Instance Methods Abstract Methods Default Methods Modifier and Type Method Description booleanauthenticate(HttpServletResponse response)Use the container login mechanism configured for theServletContextto authenticate the user making this request.StringchangeSessionId()Change the session id of the current session associated with this request and return the new session id.StringgetAuthType()Returns the name of the authentication scheme used to protect the servlet.StringgetContextPath()Returns the portion of the request URI that indicates the context of the request.Cookie[]getCookies()Returns an array containing all of theCookieobjects the client sent with this request.longgetDateHeader(String name)Returns the value of the specified request header as alongvalue that represents aDateobject.StringgetHeader(String name)Returns the value of the specified request header as aString.Enumeration<String>getHeaderNames()Returns an enumeration of all the header names this request contains.Enumeration<String>getHeaders(String name)Returns all the values of the specified request header as anEnumerationofStringobjects.default HttpServletMappinggetHttpServletMapping()Return the HttpServletMapping of the request.intgetIntHeader(String name)Returns the value of the specified request header as anint.StringgetMethod()Returns the name of the HTTP method with which this request was made, for example, GET, POST, or PUT.PartgetPart(String name)Gets thePartwith the given name.Collection<Part>getParts()Gets all thePartcomponents of this request, provided that it is of typemultipart/form-data.StringgetPathInfo()Returns any extra path information associated with the URL the client sent when it made this request.StringgetPathTranslated()Returns any extra path information after the servlet name but before the query string, and translates it to a real path.StringgetQueryString()Returns the query string that is contained in the request URL after the path.StringgetRemoteUser()Returns the login of the user making this request, if the user has been authenticated, ornullif the user has not been authenticated.StringgetRequestedSessionId()Returns the session ID specified by the client.StringgetRequestURI()Returns the part of this request's URL from the protocol name up to the query string in the first line of the HTTP request.StringBuffergetRequestURL()Reconstructs the URL the client used to make the request.StringgetServletPath()Returns the part of this request's URL that calls the servlet.HttpSessiongetSession()Returns the current session associated with this request, or if the request does not have a session, creates one.HttpSessiongetSession(boolean create)Returns the currentHttpSessionassociated with this request or, if there is no current session andcreateis true, returns a new session.default Map<String,String>getTrailerFields()Get the request trailer fields.PrincipalgetUserPrincipal()Returns ajava.security.Principalobject containing the name of the current authenticated user.booleanisRequestedSessionIdFromCookie()Checks whether the requested session ID was conveyed to the server as an HTTP cookie.booleanisRequestedSessionIdFromURL()Checks whether the requested session ID was conveyed to the server as part of the request URL.booleanisRequestedSessionIdValid()Checks whether the requested session ID is still valid.default booleanisTrailerFieldsReady()Return a boolean indicating whether trailer fields are ready to read usinggetTrailerFields().booleanisUserInRole(String role)Returns a boolean indicating whether the authenticated user is included in the specified logical "role".voidlogin(String username, String password)Validate the provided username and password in the password validation realm used by the web container login mechanism configured for theServletContext.voidlogout()Establishnullas the value returned whengetUserPrincipal,getRemoteUser, andgetAuthTypeis called on the request.default PushBuildernewPushBuilder()Instantiates a new instance ofPushBuilderfor issuing server push responses from the current request.<T extends HttpUpgradeHandler>
 Tupgrade(Class<T> handlerClass)Creates an instance ofHttpUpgradeHandlerfor a given class and uses it for the http protocol upgrade processing.- 
Methods inherited from interface jakarta.servlet.ServletRequestgetAsyncContext, getAttribute, getAttributeNames, getCharacterEncoding, getContentLength, getContentLengthLong, getContentType, getDispatcherType, getInputStream, getLocalAddr, getLocale, getLocales, getLocalName, getLocalPort, getParameter, getParameterMap, getParameterNames, getParameterValues, getProtocol, getProtocolRequestId, getReader, getRemoteAddr, getRemoteHost, getRemotePort, getRequestDispatcher, getRequestId, getScheme, getServerName, getServerPort, getServletConnection, getServletContext, isAsyncStarted, isAsyncSupported, isSecure, removeAttribute, setAttribute, setCharacterEncoding, startAsync, startAsync
 
- 
 
- 
- 
- 
Field Detail- 
BASIC_AUTHstatic final String BASIC_AUTH String identifier for Basic authentication. Value "BASIC"- See Also:
- Constant Field Values
 
 - 
FORM_AUTHstatic final String FORM_AUTH String identifier for Form authentication. Value "FORM"- See Also:
- Constant Field Values
 
 - 
CLIENT_CERT_AUTHstatic final String CLIENT_CERT_AUTH String identifier for Client Certificate authentication. Value "CLIENT_CERT"- See Also:
- Constant Field Values
 
 - 
DIGEST_AUTHstatic final String DIGEST_AUTH String identifier for Digest authentication. Value "DIGEST"- See Also:
- Constant Field Values
 
 
- 
 - 
Method Detail- 
getAuthTypeString getAuthType() Returns the name of the authentication scheme used to protect the servlet. All servlet containers support basic, form and client certificate authentication, and may additionally support digest authentication. If the servlet is not authenticatednullis returned.- Returns:
- one of the static members BASIC_AUTH, FORM_AUTH, CLIENT_CERT_AUTH, DIGEST_AUTH (suitable for == comparison)
 or the container-specific string indicating the authentication scheme, or nullif the request was not authenticated.
 
 - 
getCookiesCookie[] getCookies() Returns an array containing all of theCookieobjects the client sent with this request. This method returnsnullif no cookies were sent.- Returns:
- an array of all the Cookiesincluded with this request, ornullif the request has no cookies
 
 - 
getDateHeaderlong getDateHeader(String name) Returns the value of the specified request header as alongvalue that represents aDateobject. Use this method with headers that contain dates, such asIf-Modified-Since.The date is returned as the number of milliseconds since January 1, 1970 GMT. The header name is case insensitive. If the request did not have a header of the specified name, this method returns -1. If the header can't be converted to a date, the method throws an IllegalArgumentException.- Parameters:
- name- a- Stringspecifying the name of the header
- Returns:
- a longvalue representing the date specified in the header expressed as the number of milliseconds since January 1, 1970 GMT, or -1 if the named header was not included with the request
- Throws:
- IllegalArgumentException- If the header value can't be converted to a date
 
 - 
getHeaderString getHeader(String name) Returns the value of the specified request header as aString. If the request did not include a header of the specified name, this method returnsnull. If there are multiple headers with the same name, this method returns the first head in the request. The header name is case insensitive. You can use this method with any request header.- Parameters:
- name- a- Stringspecifying the header name
- Returns:
- a Stringcontaining the value of the requested header, ornullif the request does not have a header of that name
 
 - 
getHeadersEnumeration<String> getHeaders(String name) Returns all the values of the specified request header as anEnumerationofStringobjects.Some headers, such as Accept-Languagecan be sent by clients as several headers each with a different value rather than sending the header as a comma separated list.If the request did not include any headers of the specified name, this method returns an empty Enumeration. The header name is case insensitive. You can use this method with any request header.- Parameters:
- name- a- Stringspecifying the header name
- Returns:
- an Enumerationcontaining the values of the requested header. If the request does not have any headers of that name return an empty enumeration. If the container does not allow access to header information, return null
 
 - 
getHeaderNamesEnumeration<String> getHeaderNames() Returns an enumeration of all the header names this request contains. If the request has no headers, this method returns an empty enumeration.Some servlet containers do not allow servlets to access headers using this method, in which case this method returns null- Returns:
- an enumeration of all the header names sent with this request; if the request has no headers, an empty
 enumeration; if the servlet container does not allow servlets to use this method, null
 
 - 
getIntHeaderint getIntHeader(String name) Returns the value of the specified request header as anint. If the request does not have a header of the specified name, this method returns -1. If the header cannot be converted to an integer, this method throws aNumberFormatException.The header name is case insensitive. - Parameters:
- name- a- Stringspecifying the name of a request header
- Returns:
- an integer expressing the value of the request header or -1 if the request doesn't have a header of this name
- Throws:
- NumberFormatException- If the header value can't be converted to an- int
 
 - 
getHttpServletMappingdefault HttpServletMapping getHttpServletMapping() Return the HttpServletMapping of the request.The mapping returned depends on the current DispatcherTypeas obtained fromServletRequest.getDispatcherType():- DispatcherType.REQUEST,- DispatcherType.ASYNC,- DispatcherType.ERROR
- Return the mapping for the target of the dispatch i.e. the mapping for the current
 Servlet.
- DispatcherType.INCLUDE
- Return the mapping as prior to the current dispatch. i.e the mapping returned is unchanged by a call to
- DispatcherType.FORWARD
- Return the mapping for the target of the dispatch i.e. the mapping for the current
 Servlet, unless theRequestDispatcherwas obtained viaServletContext.getNamedDispatcher(String), in which case return the mapping as prior to the current dispatch. i.e the mapping returned is changed during a call toRequestDispatcher.forward(ServletRequest, jakarta.servlet.ServletResponse)only if the dispatcher is not a named dispatcher.
 RequestDispatcher.include(ServletRequest, jakarta.servlet.ServletResponse).For example: - For a sequence Servlet1 --include--> Servlet2 --include--> Servlet3, a call to this method in Servlet3 will return the mapping for Servlet1.
- For a sequence Servlet1 --async--> Servlet2 --named-forward--> Servlet3, a call to this method in Servlet3 will return the mapping for Servlet2.
 The returned object is immutable. Servlet 4.0 compliant implementations must override this method. - Returns:
- An instance of HttpServletMappingdescribing the manner in which the current request was invoked.
- Since:
- Servlet 4.0
 
 - 
getMethodString getMethod() Returns the name of the HTTP method with which this request was made, for example, GET, POST, or PUT.- Returns:
- a Stringspecifying the name of the method with which this request was made
 
 - 
getPathInfoString getPathInfo() Returns any extra path information associated with the URL the client sent when it made this request. The extra path information follows the servlet path but precedes the query string and will start with a "/" character.This method returns nullif there was no extra path information.- Returns:
- a Stringspecifying extra path information that comes after the servlet path but before the query string in the request URL; ornullif the URL does not have any extra path information. The path will be canonicalized as per section 3.5 of the specification. This method will not return any encoded characters unless the container is configured specifically to allow them.
- Throws:
- IllegalArgumentException- In standard configuration, this method will never throw. However, a container may be configured to not reject some suspicious sequences identified by 3.5.2, furthermore the container may be configured to allow such paths to only be accessed via safer methods like- getRequestURI()and to throw IllegalArgumentException if this method is called for such suspicious paths.
 
 - 
getPathTranslatedString getPathTranslated() Returns any extra path information after the servlet name but before the query string, and translates it to a real path.If the URL does not have any extra path information, this method returns nullor the servlet container cannot translate the virtual path to a real path for any reason (such as when the web application is executed from an archive). The web container does not decode this string.- Returns:
- a Stringspecifying the real path, ornullif the URL does not have any extra path information
 
 - 
newPushBuilderdefault PushBuilder newPushBuilder() Instantiates a new instance ofPushBuilderfor issuing server push responses from the current request. This method returns null if the current connection does not support server push, or server push has been disabled by the client via aSETTINGS_ENABLE_PUSHsettings frame value of0(zero).- Returns:
- a PushBuilderfor issuing server push responses from the current request, or null if push is not supported
- Since:
- Servlet 4.0
 
 - 
getContextPathString getContextPath() Returns the portion of the request URI that indicates the context of the request. The context path always comes first in a request URI. The path starts with a "/" character but does not end with a "/" character. For servlets in the default (root) context, this method returns "". The container does not decode this string.It is possible that a servlet container may match a context by more than one context path. In such cases this method will return the actual context path used by the request and it may differ from the path returned by the ServletContext.getContextPath()method. The context path returned byServletContext.getContextPath()should be considered as the prime or preferred context path of the application.- Returns:
- a Stringspecifying the portion of the request URI that indicates the context of the request. The path will be canonicalized as per section 3.5 of the specification. This method will not return any encoded characters unless the container is configured specifically to allow them.
- Throws:
- IllegalArgumentException- In standard configuration, this method will never throw. However, a container may be configured to not reject some suspicious sequences identified by 3.5.2, furthermore the container may be configured to allow such paths to only be accessed via safer methods like- getRequestURI()and to throw IllegalArgumentException if this method is called for such suspicious paths.
- See Also:
- ServletContext.getContextPath()
 
 - 
getQueryStringString getQueryString() Returns the query string that is contained in the request URL after the path. This method returnsnullif the URL does not have a query string.- Returns:
- a Stringcontaining the query string ornullif the URL contains no query string. The value is not decoded by the container.
 
 - 
getRemoteUserString getRemoteUser() Returns the login of the user making this request, if the user has been authenticated, ornullif the user has not been authenticated. Whether the user name is sent with each subsequent request depends on the browser and type of authentication.- Returns:
- a Stringspecifying the login of the user making this request, ornullif the user login is not known
 
 - 
isUserInRoleboolean isUserInRole(String role) Returns a boolean indicating whether the authenticated user is included in the specified logical "role". Roles and role membership can be defined using deployment descriptors. If the user has not been authenticated, the method returnsfalse.The role name "*" should never be used as an argument in calling isUserInRole. Any call toisUserInRolewith "*" must return false. If the role-name of the security-role to be tested is "**", and the application has NOT declared an application security-role with role-name "**",isUserInRolemust only return true if the user has been authenticated; that is, only whengetRemoteUser()andgetUserPrincipal()would both return a non-null value. Otherwise, the container must check the user for membership in the application role.- Parameters:
- role- a- Stringspecifying the name of the role
- Returns:
- a booleanindicating whether the user making this request belongs to a given role;falseif the user has not been authenticated
 
 - 
getUserPrincipalPrincipal getUserPrincipal() Returns ajava.security.Principalobject containing the name of the current authenticated user. If the user has not been authenticated, the method returnsnull.- Returns:
- a java.security.Principalcontaining the name of the user making this request;nullif the user has not been authenticated
 
 - 
getRequestedSessionIdString getRequestedSessionId() Returns the session ID specified by the client. This may not be the same as the ID of the current valid session for this request. If the client did not specify a session ID, this method returnsnull.- Returns:
- a Stringspecifying the session ID, ornullif the request did not specify a session ID
- See Also:
- isRequestedSessionIdValid()
 
 - 
getRequestURIString getRequestURI() Returns the part of this request's URL from the protocol name up to the query string in the first line of the HTTP request. The web container does not decode this String. For example:First line of HTTP request Returned Value POST /some/path.html HTTP/1.1 /some/path.html GET http://foo.bar/a.html HTTP/1.0 /a.html HEAD /xyz?a=b HTTP/1.1 /xyz - Returns:
- a Stringcontaining the part of the URL from the protocol name up to the query string
 
 - 
getRequestURLStringBuffer getRequestURL() Reconstructs the URL the client used to make the request. The returned URL contains a protocol, server name, port number, and server path, but it does not include query string parameters.If this request has been forwarded using RequestDispatcher.forward(jakarta.servlet.ServletRequest, jakarta.servlet.ServletResponse), the server path in the reconstructed URL must reflect the path used to obtain the RequestDispatcher, and not the server path specified by the client.Because this method returns a StringBuffer, not a string, you can modify the URL easily, for example, to append query parameters.This method is useful for creating redirect messages and for reporting errors. - Returns:
- a StringBufferobject containing the reconstructed URL
 
 - 
getServletPathString getServletPath() Returns the part of this request's URL that calls the servlet. This path starts with a "/" character and includes the path to the servlet, but does not include any extra path information or a query string.This method will return an empty string ("") if the servlet used to process this request was matched using the "/*" pattern. - Returns:
- a Stringcontaining the path of the servlet being called, as specified in the request URL, or an empty string if the servlet used to process the request is matched using the "/*" pattern. The path will be canonicalized as per section 3.5 of the specification. This method will not return any encoded characters unless the container is configured specifically to allow them.
- Throws:
- IllegalArgumentException- In standard configuration, this method will never throw. However, a container may be configured to not reject some suspicious sequences identified by 3.5.2, furthermore the container may be configured to allow such paths to only be accessed via safer methods like- getRequestURI()and to throw IllegalArgumentException if this method is called for such suspicious paths.
 
 - 
getSessionHttpSession getSession(boolean create) Returns the currentHttpSessionassociated with this request or, if there is no current session andcreateis true, returns a new session.If createisfalseand the request has no validHttpSession, this method returnsnull.To make sure the session is properly maintained, you must call this method before the response is committed. If the container is using cookies to maintain session integrity and is asked to create a new session when the response is committed, an IllegalStateException is thrown. - Parameters:
- create-- trueto create a new session for this request if necessary;- falseto return- nullif there's no current session
- Returns:
- the HttpSessionassociated with this request ornullifcreateisfalseand the request has no valid session
- See Also:
- getSession()
 
 - 
getSessionHttpSession getSession() Returns the current session associated with this request, or if the request does not have a session, creates one.- Returns:
- the HttpSessionassociated with this request
- See Also:
- getSession(boolean)
 
 - 
changeSessionIdString changeSessionId() Change the session id of the current session associated with this request and return the new session id.- Returns:
- the new session id
- Throws:
- IllegalStateException- if there is no session associated with the request
- Since:
- Servlet 3.1
 
 - 
isRequestedSessionIdValidboolean isRequestedSessionIdValid() Checks whether the requested session ID is still valid.If the client did not specify any session ID, this method returns false.- Returns:
- trueif this request has an id for a valid session in the current session context;- falseotherwise
- See Also:
- getRequestedSessionId(),- getSession(boolean)
 
 - 
isRequestedSessionIdFromCookieboolean isRequestedSessionIdFromCookie() Checks whether the requested session ID was conveyed to the server as an HTTP cookie. - Returns:
- trueif the session ID was conveyed to the server an an HTTP cookie; otherwise,- false
- See Also:
- getSession(boolean)
 
 - 
isRequestedSessionIdFromURLboolean isRequestedSessionIdFromURL() Checks whether the requested session ID was conveyed to the server as part of the request URL. - Returns:
- trueif the session ID was conveyed to the server as part of a URL; otherwise,- false
- See Also:
- getSession(boolean)
 
 - 
authenticateboolean authenticate(HttpServletResponse response) throws IOException, ServletException Use the container login mechanism configured for theServletContextto authenticate the user making this request.This method may modify and commit the argument HttpServletResponse.- Parameters:
- response- The- HttpServletResponseassociated with this- HttpServletRequest
- Returns:
- truewhen non-null values were or have been established as the values returned by- getUserPrincipal,- getRemoteUser, and- getAuthType. Return- falseif authentication is incomplete and the underlying login mechanism has committed, in the response, the message (e.g., challenge) and HTTP status code to be returned to the user.
- Throws:
- IOException- if an input or output error occurred while reading from this request or writing to the given response
- IllegalStateException- if the login mechanism attempted to modify the response and it was already committed
- ServletException- if the authentication failed and the caller is responsible for handling the error (i.e., the underlying login mechanism did NOT establish the message and HTTP status code to be returned to the user)
- Since:
- Servlet 3.0
 
 - 
loginvoid login(String username, String password) throws ServletException Validate the provided username and password in the password validation realm used by the web container login mechanism configured for theServletContext.This method returns without throwing a ServletExceptionwhen the login mechanism configured for theServletContextsupports username password validation, and when, at the time of the call to login, the identity of the caller of the request had not been established (i.e, all ofgetUserPrincipal,getRemoteUser, andgetAuthTypereturn null), and when validation of the provided credentials is successful. Otherwise, this method throws aServletExceptionas described below.When this method returns without throwing an exception, it must have established non-null values as the values returned by getUserPrincipal,getRemoteUser, andgetAuthType.- Parameters:
- username- The- Stringvalue corresponding to the login identifier of the user.
- password- The password- Stringcorresponding to the identified user.
- Throws:
- ServletException- if the configured login mechanism does not support username password authentication, or if a non-null caller identity had already been established (prior to the call to login), or if validation of the provided username and password fails.
- Since:
- Servlet 3.0
 
 - 
logoutvoid logout() throws ServletExceptionEstablishnullas the value returned whengetUserPrincipal,getRemoteUser, andgetAuthTypeis called on the request.- Throws:
- ServletException- if logout fails
- Since:
- Servlet 3.0
 
 - 
getPartsCollection<Part> getParts() throws IOException, ServletException Gets all thePartcomponents of this request, provided that it is of typemultipart/form-data.If this request is of type multipart/form-data, but does not contain anyPartcomponents, the returnedCollectionwill be empty.Any changes to the returned Collectionmust not affect thisHttpServletRequest.- Returns:
- a (possibly empty) Collectionof thePartcomponents of this request
- Throws:
- IOException- if an I/O error occurred during the retrieval of the- Partcomponents of this request
- ServletException- if this request is not of type- multipart/form-data
- IllegalStateException- if the request body is larger than- maxRequestSize, or any- Partin the request is larger than- maxFileSize, or there is no- @MultipartConfigor- multipart-configin deployment descriptors
- Since:
- Servlet 3.0
- See Also:
- MultipartConfig.maxFileSize(),- MultipartConfig.maxRequestSize()
 
 - 
getPartPart getPart(String name) throws IOException, ServletException Gets thePartwith the given name.- Parameters:
- name- the name of the requested- Part
- Returns:
- The Partwith the given name, ornullif this request is of typemultipart/form-data, but does not contain the requestedPart
- Throws:
- IOException- if an I/O error occurred during the retrieval of the requested- Part
- ServletException- if this request is not of type- multipart/form-data
- IllegalStateException- if the request body is larger than- maxRequestSize, or any- Partin the request is larger than- maxFileSize, or there is no- @MultipartConfigor- multipart-configin deployment descriptors
- Since:
- Servlet 3.0
- See Also:
- MultipartConfig.maxFileSize(),- MultipartConfig.maxRequestSize()
 
 - 
upgrade<T extends HttpUpgradeHandler> T upgrade(Class<T> handlerClass) throws IOException, ServletException Creates an instance ofHttpUpgradeHandlerfor a given class and uses it for the http protocol upgrade processing.- Type Parameters:
- T- The- Class, which extends- HttpUpgradeHandler, of the- handlerClass.
- Parameters:
- handlerClass- The- HttpUpgradeHandlerclass used for the upgrade.
- Returns:
- an instance of the HttpUpgradeHandler
- Throws:
- IOException- if an I/O error occurred during the upgrade
- ServletException- if the given- handlerClassfails to be instantiated
- Since:
- Servlet 3.1
- See Also:
- HttpUpgradeHandler,- WebConnection
 
 - 
getTrailerFieldsdefault Map<String,String> getTrailerFields() Get the request trailer fields.The returned map is not backed by the HttpServletRequestobject, so changes in the returned map are not reflected in theHttpServletRequestobject, and vice-versa.isTrailerFieldsReady()should be called first to determine if it is safe to call this method without causing an exception.- Returns:
- A map of trailer fields in which all the keys are in lowercase, regardless of the case they had at the
 protocol level. If there are no trailer fields, yet isTrailerFieldsReady()is returning true, the empty map is returned.
- Throws:
- IllegalStateException- if- isTrailerFieldsReady()is false
- Since:
- Servlet 4.0
 
 - 
isTrailerFieldsReadydefault boolean isTrailerFieldsReady() Return a boolean indicating whether trailer fields are ready to read usinggetTrailerFields(). This methods returns true immediately if it is known that there is no trailer in the request, for instance, the underlying protocol (such as HTTP 1.0) does not supports the trailer fields, or the request is not in chunked encoding in HTTP 1.1. And the method also returns true if both of the following conditions are satisfied:- the application has read all the request data and an EOF indication has been returned from the ServletRequest.getReader()orServletRequest.getInputStream().
- all the trailer fields sent by the client have been received. Note that it is possible that the client has sent no trailer fields.
 - Returns:
- a boolean whether trailer fields are ready to read
- Since:
- Servlet 4.0
 
- the application has read all the request data and an EOF indication has been returned from the 
 
- 
 
-