zoukankan      html  css  js  c++  java
  • servlet Filter过滤javascript

    新建HttpServletRequestWrapper子类XssHttpServletRequestWrapper

    import javax.servlet.http.HttpServletRequest;
    import javax.servlet.http.HttpServletRequestWrapper;
    
    public class XssHttpServletRequestWrapper extends HttpServletRequestWrapper {
    	public XssHttpServletRequestWrapper(HttpServletRequest request){
    		super(request);
    	}
    
    	public String[] getParameterValues(String parameter){
    		String[] values = super.getParameterValues(parameter);
    		if(values==null){
    			return null;
    		}
    		int count = values.length;
    		String[] encodedValues = new String[count];
    		for (int i = 0;i<count;i++){
    			encodedValues[i] = this.cleanXss(values[i]);
    		}
    		return encodedValues;
    	}
    
    	public String getParameter(String parameter){
    		String value = super.getParamerter(parameter);
    		if(valuee == null){
    			return null;
    		}
    		return cleanXss(value);
    	}
    
    	private String cleanXss(String value){
    		value = value.replaceAll("<","&lt").replaceAll(">","&gt");
    		value = value.replaceAll("script","");
    		return value;
    	}
    }
    

     在Fileter中调用

    import javax.servlet.Filter;
    import javax.servlet.FilterChain;
    import javax.servlet.http.HttpServletRequest;
    import javax.servlet.http.HttpServletResponse;
    
    public class HttpMethodFilter implements Filter {
        public void doFilter(ServletRequest request,ServletResponse response,FilterChain chain) throws IOException,ServletException {
            HttpServletRequest hsreq = (HttpServletResponse) request;
            HttpServletResponse hsrep = (HttpServletResponse) response;
            chain.doFilter(new XssHttpServletRequestWrapper((HttpServletRequest) request),response);
        }
    }
  • 相关阅读:
    《网络对抗技术》Exp6 MSF应用基础
    用Onenote写博客日志 
    C语言文法
    0909
    使用jQuery解决溢出文本省略
    几种流行的AJAX框架jQuery,Mootools,Dojo,Ext JS的对比
    jQuery实现动态加载大尺寸图片
    常用jQuery插件推荐
    使用不带单位的lineheight
    JavaScript懒加载技术 lazyload
  • 原文地址:https://www.cnblogs.com/live365wang/p/5893597.html
Copyright © 2011-2022 走看看