预防xss

普通application/x-www-form-urlencoded请求xss

filter 配合 XssHttpServletRequestWrapper

  1. response head
  2. 标签

image.png
image.png