gpt4 book ai didi

Wicket 口中的javascript注入(inject)

转载 作者:搜寻专家 更新时间:2023-11-01 02:18:33 25 4
gpt4 key购买 nike

我有一个使用 wicket 框架的 J2EE 项目。我想知道如何防止在 wicket 中注入(inject) javascript?

最佳答案

尽管我认为您提出问题的方式不值得(没有详细信息、没有背景、没有示例问题陈述、隐含的注入(inject)敏感性等),但我还是从 Excellent Wicket in Action 中挖掘了一些细节。 :

Wicket 默认是安全的

You never need to worry about pimple-faced 14-year-olds trying to hack your web application. To do so, they would have to hijack the session and then guess the right page identifiers and version numbers, which would be relative to the session and the relevant component paths. You’d have to be a persistent hacker to pull that off. You can make your Wicket application even more secure from the default by encrypting requests with, for instance, CryptedUrlWebRequestCodingStrategy.

关于 Wicket 口中的javascript注入(inject),我们在Stack Overflow上找到一个类似的问题: https://stackoverflow.com/questions/1216213/

25 4 0
Copyright 2021 - 2024 cfsdn All Rights Reserved 蜀ICP备2022000587号
广告合作:1813099741@qq.com 6ren.com