1. 程式人生 > >Cookie 缺少 HttpOnly屬性和x-frame-options 缺失問題

Cookie 缺少 HttpOnly屬性和x-frame-options 缺失問題

過濾器dofileter 方法中 新增 HttpServletRequest req = (HttpServletRequest) request;
HttpServletResponse res = (HttpServletResponse) response;
res.addHeader("Set-Cookie", " Path=/;  HttpOnly");  //Cookie 缺少 HttpOnly屬性
res.addHeader("X-Frame-Options","SAMEORIGIN");  //防止 x-frame-options 缺失