Beetl解決XSS問題

來源:互聯網
上載者:User

標籤:http   java   使用   os   資料   for   2014   ar   

很多時候,我們為了安全,會對儲存的資訊,進行轉義,過濾等處理,這樣帶來的壞處是,破壞原始的資料,而且轉義會佔用多餘的空間.

本人使用JFinal架構,開始考慮過全域設定過濾器,有的不需要的也會轉義,不是很友好~

後來發現這邊文章http://www.iteye.com/topic/1123423 ,通過Beetl來處理XSS這一類的問題

首先,自訂一個格式化類XSSDefenseFormat.java

import org.apache.commons.lang.StringEscapeUtils;import org.beetl.core.Format;public class XSSDefenseFormat implements Format {    @Override    public Object format(Object data, String pattern) {        if (null == data) {            return null;        } else {            return StringEscapeUtils.escapeHtml((String) data);        }    }}



然後註冊該格式化
groupTemplate.registerFormat("xss", new XSSDefenseFormat());



最後針對需要的地方,進行xss處理
${a.name, xss}



使用結果不再彈出alert提示

可以根據自己實際需求,自訂一些其他方法.

聯繫我們

該頁面正文內容均來源於網絡整理,並不代表阿里雲官方的觀點,該頁面所提到的產品和服務也與阿里云無關,如果該頁面內容對您造成了困擾,歡迎寫郵件給我們,收到郵件我們將在5個工作日內處理。

如果您發現本社區中有涉嫌抄襲的內容,歡迎發送郵件至: info-contact@alibabacloud.com 進行舉報並提供相關證據,工作人員會在 5 個工作天內聯絡您,一經查實,本站將立刻刪除涉嫌侵權內容。

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.