日期:2014-05-16  浏览次数:20336 次

防止javascript 注入解決方法

??? ??? //防止javascript 注入:
??? ??? String strings = "<java>test</java>";
??? ??? System.out.println(strings.replace("<", "&lt;").replace(">", "&gt;"));

?

?

?

public class StringUtil {
??? public static String getClassShortNameByEntity(Object entity) {
??? ??? String classPackage = entity.getClass().toString();
??? ??? return classPackage.substring(classPackage.lastIndexOf(".") + 1);
??? }
??? public static String getHtmlIncodeByString(String str){
??? ??? if(null!=str && !"".equals(str)){
??? ??? ??? return str.trim().replace("<", "&lt;").replace(">", "&gt;");
??? ??? }
??? ??? return null;
??? }
}