CRSF token and spring

http://seamframework.org/Documentation/CrossSiteScripting

<h:outputText value="#{param.name}" escape="false"/>  <!-- DON'T DO THIS! XSS SECURITY HOLE! -->

but do this:

<h:outputText value="#{myBean.myTextContent}" escape="false"/>  <!-- Content contains &entity; and is already safe! -->

Advertisement

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Connecting to %s

Follow

Get every new post delivered to your Inbox.