Tomcat安全配置

    1. 编辑 conf目录下的server.xml文件
    1. # 查找httpHeaderSecurity,启用如下配置
    2. <filter>
    3. <filter-name>httpHeaderSecurity</filter-name>
    4. <filter-class>org.apache.catalina.filters.HttpHeaderSecurityFilter</filter-class>
    5. <init-param>
    6. <param-name>antiClickJackingEnabled</param-name>
    7. <param-value>true</param-value>
    8. </init-param>
    9. <init-param>
    10. <param-name>antiClickJackingOption</param-name>
    11. <param-value>SAMEORIGIN</param-value>
    12. </init-param>
    13. <async-supported>true</async-supported>
    14. </filter>
    15. <filter-mapping>
    16. <filter-name>httpHeaderSecurity</filter-name>
    17. <url-pattern>/*</url-pattern>
    18. </filter-mapping>
    1. 隐藏默认启动页

    修改webapps目录下的ROOT名称