小编kev*_*val的帖子

在 Java Web 应用程序中为设置的 cookie 添加 httponly 和安全标志

我想为 Cookie添加httponlysecure标志。为了实现它,我正在使用Filtersweb.xml.

添加标志的代码如下:

package com.crisil.dbconn;

import java.io.IOException;

import javax.servlet.Filter;
import javax.servlet.FilterChain;
import javax.servlet.FilterConfig;
import javax.servlet.ServletException;
import javax.servlet.ServletRequest;
import javax.servlet.ServletResponse;
import javax.servlet.http.Cookie;
import javax.servlet.http.HttpServletRequest;
import javax.servlet.http.HttpServletResponse;

import org.apache.struts2.ServletActionContext;
import org.owasp.esapi.ESAPI;
import org.owasp.esapi.filters.SecurityWrapperResponse;

public class ClickjackFilter implements Filter 
{

    private String mode = "DENY";

    /**
     * Add X-FRAME-OPTIONS response header to tell IE8 (and any other browsers who
     * decide to implement) not to display this content in a frame. For details, please
     * …
Run Code Online (Sandbox Code Playgroud)

java security web.xml struts2 filter

2
推荐指数
1
解决办法
4万
查看次数

标签 统计

filter ×1

java ×1

security ×1

struts2 ×1

web.xml ×1