2
我已發現此解決方案上索夫link 但我不得不它有兩個原因改變:如何在Tomcat 6設置的HttpOnly標誌在JSF 2.0應用
- 沒有.getFacesContext() 函數
- 我沒有特定的Cookie文件 (見行 ourcookiename = yourcookievalue)
我的代碼看起來是這樣的:
FacesContext facesContext = FacesContext.getCurrentInstance();
HttpServletResponse response = (HttpServletResponse) facesContext.getExternalContext().getResponse();
response.addHeader("Set-Cookie", "; HTTPOnly");
原代碼
FacesContext facesContext = FacesContext.getCurrentInstance().getFacesContext();
HttpServletResponse response = (HttpServletResponse) facesContext.getExternalContext().getResponse();
response.addHeader("Set-Cookie", "yourcookiename=yourcookievalue; HTTPOnly");
請糾正我,如果我錯了。謝謝你在前進
謝謝。我希望這將有助於防止XSS攻擊 – Szajba