Web Application Security
Reference
XSS (Cross-site scripting)
防御XSS
- 字符转义
CSRF (Cross-site request forgery)
- https://en.wikipedia.org/wiki/Cross-site_request_forgery
- https://www.cnblogs.com/hyddd/archive/2009/04/09/1432744.html
- https://blog.csdn.net/qq_43437874/article/details/118676337
防御CSRF
- 验证 HTTP Referer 字段
- 随机Token
- 验证码