whyclxw
2024-12-03 2c62e9ed95a65410d3a34492ce2e04fb2c25f859
跨域
1个文件已修改
4 ■■■■ 已修改文件
src/main/java/com/whyc/filter/CrossDomainFilter.java 4 ●●●● 补丁 | 查看 | 原始文档 | blame | 历史
src/main/java/com/whyc/filter/CrossDomainFilter.java
@@ -52,14 +52,14 @@
        resp.setHeader("Access-Control-Allow-Methods", "GET, POST");
        resp.setHeader("Access-Control-Allow-Credentials", "true");
        //只准使用GET,POST
        String method = req.getMethod().toUpperCase();
        /*String method = req.getMethod().toUpperCase();
        String profileType = YamlProperties.profileType;
        if(!profileType.contains("dev") && !(method.equals("GET")||method.equals("POST"))){
            resp.setStatus(HttpServletResponse.SC_METHOD_NOT_ALLOWED);
            response.setContentType("text/html;charset=utf-8");
            response.getWriter().write("不安全的请求");
            return;
        }
        }*/
        //处理响应头缺失,信息漏洞
        /*resp.addHeader("X-Frame-Options","SAMEORIGIN");
        resp.addHeader("Referrer-Policy","origin");