A request has been denied as a potential CSRF attack.”

来源:互联网 发布:蔡英文2017 知乎 编辑:程序博客网 时间:2024/06/05 18:39

A request has been denied as a potential CSRF attack.”

2014年01月07日 ⁄ 综合 ⁄ 共 600字 ⁄ 字号 小 中 大 ⁄ 评论关闭
<iframe id="iframeu1788635_0" src="http://pos.baidu.com/acom?rdid=1788635&amp;dc=2&amp;di=u1788635&amp;dri=0&amp;dis=0&amp;dai=2&amp;ps=236x804&amp;dcb=BAIDU_UNION_define&amp;dtm=BAIDU_DUP_SETJSONADSLOT&amp;dvi=0.0&amp;dci=-1&amp;dpt=none&amp;tsr=0&amp;tpr=1457320711432&amp;ti=A%20request%20has%20been%20denied%20as%20a%20potential%20CSRF%20attack.%E2%80%9D%20%7C%20%E5%AD%A6%E6%AD%A5%E5%9B%AD&amp;ari=1&amp;dbv=2&amp;drs=1&amp;pcs=1156x562&amp;pss=1156x256&amp;cfv=0&amp;cpl=4&amp;chi=1&amp;cce=true&amp;cec=UTF-8&amp;tlm=1457320711&amp;ltu=http%3A%2F%2Fwww.xuebuyuan.com%2F1843812.html&amp;ltr=https%3A%2F%2Fwww.baidu.com%2Flink%3Furl%3DejKJvmv5bzsZ6gzHraLt_-I2tGSW1VC3V4ffHQB_BM6HmLXdxlU5OInj5SiMvw9F%26wd%3D%26eqid%3Df288193600003d8e0000000556dcf2ac&amp;ecd=1&amp;psr=1366x768&amp;par=1366x728&amp;pis=-1x-1&amp;ccd=24&amp;cja=false&amp;cmi=6&amp;col=zh-CN&amp;cdo=-1&amp;tcn=1457320711&amp;qn=6a23d87926e9ca87&amp;tt=1457320711408.62.270.271" width="336" height="280" align="center,center" vspace="0" hspace="0" marginwidth="0" marginheight="0" scrolling="no" frameborder="0" allowtransparency="true" style="margin: 0px; padding: 0px; border-width: 0px; border-style: initial; font-size: 13px; vertical-align: bottom; background: transparent;"></iframe>

最近想学AJAX。   刚上来就碰到了这么个错误:“严重: A request has been denied as a potential CSRF attack.” 传递的值还是“session error”。

后来在网上发现了这个问题解决办法。

在web.xml配置文件中修改dwr的配置:

Xml代码

 

  1. <servlet>  
  2.  <servlet-name>dwr-invoker</servlet-name>  
  3.   <servlet-class>org.directwebremoting.servlet.DwrServlet</servlet-class>  
  4.   <init-param>  
  5.    <param-name>debug</param-name>  
  6.    <param-value>true</param-value>  
  7.   </init-param>  
  8.   <!-- 新加corssDomainSessionSecurity参数 -->  
  9.   <init-param>      
  10.             <param-name>crossDomainSessionSecurity</param-name>      
  11.             <param-value>false</param-value>      
  12.     </init-param>  
  13.  </servlet>  

 加入红色部分后。问题就消失了。


0 0