安全测评测出一下问题:
以下是我的代码解决方案:
1、写好一个类,给它命名为CSRFilter.java
package com.xr.modules.sys.utils;
import java.io.IOException;
import javax.servlet.Filter;
import javax.servlet.FilterChain;
import javax.servlet.FilterConfig;
import javax.servlet.ServletException;
import javax.servlet.ServletRequest;
import javax.servlet.ServletResponse;
import javax.servlet.http.HttpServletRequest;
/**
* 跨站点请求伪造 CSRF攻击
* @author ChenJZ
*
*/
public class CSRFilter implements Filter {
private String[] verifyReferer = null;
@Override
public void destroy() {
&nb