Tomcat解决Web漏洞Clickjacking: X-Frame-Options header missing

Tomcat解决Web漏洞Clickjacking: X-Frame-Options header missing在tomcat的conf目录下的web.xml配置中增加以下配置<filter><filter-name&g

Tomcat解决Web漏洞Clickjacking: X-Frame-Options header missing

在tomcat的conf目录下的web.xml配置中增加以下配置

	<filter>
		<filter-name>httpHeaderSecurity</filter-name>
		<filter-class>org.apache.catalina.filters.HttpHeaderSecurityFilter</filter-class>
		<init-param>
			<param-name>antiClickJackingEnabled</param-name>
			<param-value>true</param-value>
		</init-param>
		<init-param>
			<param-name>antiClickJackingOption</param-name>
			<param-value>SAMEORIGIN</param-value>
		</init-param>
		<async-supported>true</async-supported>
	</filter>
	<filter-mapping>
		<filter-name>httpHeaderSecurity</filter-name>
		<url-pattern>/*</url-pattern>
	</filter-mapping>

 

发布者:admin,转转请注明出处:http://www.yc00.com/web/1754943531a5218534.html

相关推荐

发表回复

评论列表(0条)

  • 暂无评论

联系我们

400-800-8888

在线咨询: QQ交谈

邮件:admin@example.com

工作时间:周一至周五,9:30-18:30,节假日休息

关注微信