• servlet Filter过滤javascript


    新建HttpServletRequestWrapper子类XssHttpServletRequestWrapper

    import javax.servlet.http.HttpServletRequest;
    import javax.servlet.http.HttpServletRequestWrapper;
    
    public class XssHttpServletRequestWrapper extends HttpServletRequestWrapper {
    	public XssHttpServletRequestWrapper(HttpServletRequest request){
    		super(request);
    	}
    
    	public String[] getParameterValues(String parameter){
    		String[] values = super.getParameterValues(parameter);
    		if(values==null){
    			return null;
    		}
    		int count = values.length;
    		String[] encodedValues = new String[count];
    		for (int i = 0;i<count;i++){
    			encodedValues[i] = this.cleanXss(values[i]);
    		}
    		return encodedValues;
    	}
    
    	public String getParameter(String parameter){
    		String value = super.getParamerter(parameter);
    		if(valuee == null){
    			return null;
    		}
    		return cleanXss(value);
    	}
    
    	private String cleanXss(String value){
    		value = value.replaceAll("<","&lt").replaceAll(">","&gt");
    		value = value.replaceAll("script","");
    		return value;
    	}
    }
    

     在Fileter中调用

    import javax.servlet.Filter;
    import javax.servlet.FilterChain;
    import javax.servlet.http.HttpServletRequest;
    import javax.servlet.http.HttpServletResponse;
    
    public class HttpMethodFilter implements Filter {
        public void doFilter(ServletRequest request,ServletResponse response,FilterChain chain) throws IOException,ServletException {
            HttpServletRequest hsreq = (HttpServletResponse) request;
            HttpServletResponse hsrep = (HttpServletResponse) response;
            chain.doFilter(new XssHttpServletRequestWrapper((HttpServletRequest) request),response);
        }
    }
  • 相关阅读:
    P1364 医院设置
    Can you solve this equation?
    HDU 3732 Ahui Writes Word
    2016-2017 ACM-ICPC, NEERC, Southern Subregional Contest H. Delete Them
    2016-2017 ACM-ICPC, NEERC, Southern Subregional Contest J. Bottles
    数据结构--KMP算法总结
    Power Strings(KMP)
    KMP (next数组的性质及证明)
    KMP模板
    poj 3461 Oulipo(KMP模板题)
  • 原文地址:https://www.cnblogs.com/live365wang/p/5893597.html
Copyright © 2020-2023  润新知