English 中文(简体)
如果某些属性含有这些价值,如何在春季会堂中恢复请求机构
原标题:How to sanitise request body in spring boot if some attributes contain these values

是否有任何图书馆可将这些图书馆编成法典,如果这些图书馆作为价值观,那么这些图书馆可以是:html的属性、js事件、文字、真实的表述? 虽然它应当避免像“和”、50000”或“<232”这样的价值,即任何具有数字价值的“</>”; 或者如何根据白人名单制定这些规范?

<script>alert(1709881302027)</scipt>;
<script /**/>/**/alert(1709881242160)/**/</script /**/
<IMG onmouseover="alert( xxs )">
&gt;&lt;script&gt;alert(1709881242161)&lt;/script&gt;
%3Cscript%3Ealert%281%29%3C%2Fscript%3E1709881242161
javascript:alert(1709881302029)
1 OR 1=1 ; -- OR 1 OR 1=1 ;
  OR  1 = 1
1 OR 1=1;

如果是图书馆,它也会把所有存在与技术挂钩,即使它们不是属性或玩笑活动。

问题回答

我假定你指的是特别安全局问题?

但是,没有特别安全局的抗辩是完美的。 或许你可以尝试:

OWASP Java HTML Sanitizer




相关问题
Spring Properties File

Hi have this j2ee web application developed using spring framework. I have a problem with rendering mnessages in nihongo characters from the properties file. I tried converting the file to ascii using ...

Logging a global ID in multiple components

I have a system which contains multiple applications connected together using JMS and Spring Integration. Messages get sent along a chain of applications. [App A] -> [App B] -> [App C] We set a ...

Java Library Size

If I m given two Java Libraries in Jar format, 1 having no bells and whistles, and the other having lots of them that will mostly go unused.... my question is: How will the larger, mostly unused ...

How to get the Array Class for a given Class in Java?

I have a Class variable that holds a certain type and I need to get a variable that holds the corresponding array class. The best I could come up with is this: Class arrayOfFooClass = java.lang....

SQLite , Derby vs file system

I m working on a Java desktop application that reads and writes from/to different files. I think a better solution would be to replace the file system by a SQLite database. How hard is it to migrate ...

热门标签