栏目分类:
子分类:
返回
名师互学网用户登录
快速导航关闭
当前搜索
当前分类
子分类
实用工具
热门搜索
名师互学网 > IT > 软件开发 > 后端开发 > Java

XSS防御

Java 更新时间: 发布时间: IT归档 最新发布 模块sitemap 名妆网 法律咨询 聚返吧 英语巴士网 伯小乐 网商动力

XSS防御

自定义json反序列化器
package cc.fedtech.filter;

import com.fasterxml.jackson.core.JsonParser;
import com.fasterxml.jackson.core.JsonProcessingException;
import com.fasterxml.jackson.databind.DeserializationContext;
import com.fasterxml.jackson.databind.JsonDeserializer;
import org.springframework.web.util.HtmlUtils;

import java.io.IOException;

public class XssJsonDeserializer extends JsonDeserializer {
 @Override
 public String deserialize(JsonParser jsonParser, DeserializationContext ctxt)
  throws IOException, JsonProcessingException {
     String value = jsonParser.getValueAsString();
     if (value != null) {
  //对于值进行HTML转义
  return HtmlUtils.htmlEscape(value);
     }
     return value;
 }

 @Override
 public Class handledType() {
     return String.class;
 }
    }
自定义json序列化器
package cc.fedtech.filter;

import com.fasterxml.jackson.core.JsonGenerator;
import com.fasterxml.jackson.databind.JsonSerializer;
import com.fasterxml.jackson.databind.SerializerProvider;
import org.springframework.web.util.HtmlUtils;

import java.io.IOException;

public class XssJsonSerializer extends JsonSerializer {
    @Override
    public Class handledType() { return String.class; }

    @Override
    public void serialize(String value, JsonGenerator jsonGenerator, SerializerProvider serializerProvider)
     throws IOException {
 if (value != null) {
     //对字符串进行HTML转义
     jsonGenerator.writeString(HtmlUtils.htmlEscape(value));
 }
    }
}
自定义拦截器
package com.fedtech.common.filter.xss;

import org.apache.commons.lang3.StringUtils;
import org.springframework.core.Ordered;
import org.springframework.core.annotation.Order;
import org.springframework.stereotype.Component;

import javax.servlet.*;
import javax.servlet.http.HttpServletRequest;
import java.io.IOException;


@Component
@Order(Ordered.HIGHEST_PRECEDENCE)
public class XssFilter implements Filter {
    @Override
    public void doFilter(ServletRequest request, ServletResponse response, FilterChain chain)
     throws IOException, ServletException {
 String path = ((HttpServletRequest) request).getServletPath();
 if (path.equals("/")) {
     chain.doFilter(request, response);
 }
 if (StringUtils.containsAny(path, "/assets", "/templates", "/mapper","/oauth")) {
     chain.doFilter(request, response);
 }

 chain.doFilter(new XssRequestWrapper((HttpServletRequest) request), response);
    }

    @Override
    public void init(FilterConfig filterConfig) throws ServletException {

    }

    @Override
    public void destroy() {

    }
}


请求参数处理
package cc.fedtech.filter;

import org.apache.commons.lang3.StringUtils;
import org.springframework.web.util.HtmlUtils;

import javax.servlet.http.HttpServletRequest;
import javax.servlet.http.HttpServletRequestWrapper;
import java.util.Arrays;

public class XssRequestWrapper extends HttpServletRequestWrapper {

    public XssRequestWrapper(HttpServletRequest request) {
 super(request);
    }

    @Override
    public String[] getParameterValues(String parameter) {
 //获取多个参数值的时候对所有参数值应用clean方法逐一清洁
 return Arrays.stream(super.getParameterValues(parameter)).map(this::clean).toArray(String[]::new);
    }

    @Override
    public String getHeader(String name) {
 //同样清洁请求头
 return clean(super.getHeader(name));
    }

    @Override
    public String getParameter(String parameter) {
 //获取参数单一值也要处理
 return clean(super.getParameter(parameter));
    }
    //clean方法就是对值进行HTML转义
    private String clean(String value) {
      return StringUtils.isEmpty(value)? "" : HtmlUtils.htmlEscape(value);
    }
}    
注册反序列化器
    //注册自定义的Jackson反序列器
    @Bean
    public Module xssModule() {
 SimpleModule module = new SimpleModule();
 module.addDeserializer(String.class, new XssJsonDeserializer());
 module.addSerializer(String.class, new XssJsonSerializer());
 return module;
    }
转载请注明:文章转载自 www.mshxw.com
我们一直用心在做
关于我们 文章归档 网站地图 联系我们

版权所有 (c)2021-2022 MSHXW.COM

ICP备案号:晋ICP备2021003244-6号