Prevent malicious user from executing JavaScript

后端 未结 2 1950
深忆病人
深忆病人 2021-01-23 04:14

In my JSP I have a function like fnGetTicketDetails:

function fnGetTicketDetails(record){
    $(\"#TicketNumber\").val(record);
    $(\"#TicketDeta         


        
2条回答
  •  借酒劲吻你
    2021-01-23 05:00

    You can't. Any data stored on the client is going to be visible to the end user.

    The issue here is that your server is willing to show the details to anyone who asks for them. Don't even try to stop the user asking. Just do a check server side to make sure that that user is allowed to view those ticket details. If they're not, don't deliver them!

提交回复
热议问题