|
|
@ -2,15 +2,15 @@ package com.techsor.datacenter.business.configurator; |
|
|
|
|
|
|
|
|
import java.io.IOException; |
|
|
import java.io.IOException; |
|
|
|
|
|
|
|
|
import javax.servlet.Filter; |
|
|
import jakarta.servlet.Filter; |
|
|
import javax.servlet.FilterChain; |
|
|
import jakarta.servlet.FilterChain; |
|
|
import javax.servlet.FilterConfig; |
|
|
import jakarta.servlet.FilterConfig; |
|
|
import javax.servlet.ServletException; |
|
|
import jakarta.servlet.ServletException; |
|
|
import javax.servlet.ServletRequest; |
|
|
import jakarta.servlet.ServletRequest; |
|
|
import javax.servlet.ServletResponse; |
|
|
import jakarta.servlet.ServletResponse; |
|
|
import javax.servlet.annotation.WebFilter; |
|
|
import jakarta.servlet.annotation.WebFilter; |
|
|
import javax.servlet.http.HttpServletRequest; |
|
|
import jakarta.servlet.http.HttpServletRequest; |
|
|
import javax.servlet.http.HttpServletResponse; |
|
|
import jakarta.servlet.http.HttpServletResponse; |
|
|
|
|
|
|
|
|
import org.slf4j.Logger; |
|
|
import org.slf4j.Logger; |
|
|
import org.slf4j.LoggerFactory; |
|
|
import org.slf4j.LoggerFactory; |
|
|
@ -93,6 +93,9 @@ public class CrosXssFilter implements Filter { |
|
|
// 设置允许的域名
|
|
|
// 设置允许的域名
|
|
|
httpServletResponse.setHeader("Access-Control-Allow-Origin", accessControlAllowOrigin); |
|
|
httpServletResponse.setHeader("Access-Control-Allow-Origin", accessControlAllowOrigin); |
|
|
httpServletResponse.setHeader("Access-Control-Allow-Credentials", "true"); |
|
|
httpServletResponse.setHeader("Access-Control-Allow-Credentials", "true"); |
|
|
|
|
|
|
|
|
|
|
|
// 修复 X-XSS-Protection 问题
|
|
|
|
|
|
httpServletResponse.setHeader("X-XSS-Protection", "1; mode=block"); |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|