zoukankan      html  css  js  c++  java
  • servlet Filter过滤javascript

    新建HttpServletRequestWrapper子类XssHttpServletRequestWrapper

    import javax.servlet.http.HttpServletRequest;
    import javax.servlet.http.HttpServletRequestWrapper;
    
    public class XssHttpServletRequestWrapper extends HttpServletRequestWrapper {
    	public XssHttpServletRequestWrapper(HttpServletRequest request){
    		super(request);
    	}
    
    	public String[] getParameterValues(String parameter){
    		String[] values = super.getParameterValues(parameter);
    		if(values==null){
    			return null;
    		}
    		int count = values.length;
    		String[] encodedValues = new String[count];
    		for (int i = 0;i<count;i++){
    			encodedValues[i] = this.cleanXss(values[i]);
    		}
    		return encodedValues;
    	}
    
    	public String getParameter(String parameter){
    		String value = super.getParamerter(parameter);
    		if(valuee == null){
    			return null;
    		}
    		return cleanXss(value);
    	}
    
    	private String cleanXss(String value){
    		value = value.replaceAll("<","&lt").replaceAll(">","&gt");
    		value = value.replaceAll("script","");
    		return value;
    	}
    }
    

     在Fileter中调用

    import javax.servlet.Filter;
    import javax.servlet.FilterChain;
    import javax.servlet.http.HttpServletRequest;
    import javax.servlet.http.HttpServletResponse;
    
    public class HttpMethodFilter implements Filter {
        public void doFilter(ServletRequest request,ServletResponse response,FilterChain chain) throws IOException,ServletException {
            HttpServletRequest hsreq = (HttpServletResponse) request;
            HttpServletResponse hsrep = (HttpServletResponse) response;
            chain.doFilter(new XssHttpServletRequestWrapper((HttpServletRequest) request),response);
        }
    }
  • 相关阅读:
    windows10上安装 .NET Framework 3.5
    Mac上安装Tomcat服务器
    实验室中搭建Spark集群和PyCUDA开发环境
    训练实录
    Hello World
    存储管理
    java脚本实现selenium架构下的复选框、上传文件的操作
    java脚本,selenium工具,自动发QQ邮件
    用java脚本,selenium2.0工具,切换窗口经验总结
    六、排队论模型
  • 原文地址:https://www.cnblogs.com/live365wang/p/5893597.html
Copyright © 2011-2022 走看看