在tomcat下web.xml中添加过滤器:
<filter>
<filter-name>httpHeaderSecurity</filter-name>
<filter-class>org.apache.catalina.filters.HttpHeaderSecurityFilter</filter-class>
<init-param>
<param-name>antiClickJackingOption</param-name>
<param-value>DENY</param-value>
</init-param>
<async-supported>true</async-supported>
</filter>
<filter-mapping>
<filter-name>httpHeaderSecurity</filter-name>
<url-pattern>/*</url-pattern>
<dispatcher>REQUEST</dispatcher>
</filter-mapping>
本文介绍如何在Tomcat服务器的web.xml文件中配置HttpHeaderSecurityFilter过滤器来防止点击劫持攻击,通过设置DENY策略增强网站安全性。
3867

被折叠的 条评论
为什么被折叠?



