点击劫持漏洞修复(前端、后端)

时间:2025-05-15 12:15:26
@Component public class AddResponseHeaderFilter extends OncePerRequestFilter { @Override protected void doFilterInternal(HttpServletRequest httpServletRequest, HttpServletResponse httpServletResponse, FilterChain filterChain) throws ServletException, IOException { System.out.println("=====X-Frame-Options, SAMEORIGIN====="); String requestUrI = httpServletRequest.getRequestURI().toString(); //("x-frame-options","DENY"); // 拒绝任何域加载 httpServletResponse.addHeader("X-Frame-Options", "SAMEORIGIN"); filterChain.doFilter(httpServletRequest, httpServletResponse); } }