http://www.oschina.net/code/snippet_100825_21906 springmvc中自己实现的token防表单重复提交,防止二次提交
http://www.cnblogs.com/Mainz/archive/2012/11/01/2749874.html Spring MVC防御CSRF、XSS和SQL注入攻击
http://blog.youkuaiyun.com/ljwhx2002/article/details/8233971 利用spring aop实现token 防止表单重复提交
http://explodingjava.blogspot.tw/2009/03/spring-mvc-synchronizer-token.html Simple Synchronizer Token with Spring MVC