{"id":16655,"date":"2024-11-21T14:21:53","date_gmt":"2024-11-21T06:21:53","guid":{"rendered":"https:\/\/92it.top\/?p=16655"},"modified":"2024-11-21T14:21:53","modified_gmt":"2024-11-21T06:21:53","slug":"content-security-policy%ef%bc%88csp%ef%bc%89%e8%af%a6%e8%a7%a3","status":"publish","type":"post","link":"https:\/\/92it.top\/?p=16655","title":{"rendered":"Content-Security-Policy\uff08CSP\uff09\u8be6\u89e3"},"content":{"rendered":"\n<p><strong>\u4e00\u3001\u524d\u8a00<\/strong><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p>\u4f5c\u4e3a\u524d\u7aef\u5de5\u7a0b\u5e08\u4f60\u771f\u7684\u4e86\u89e3 XSS \u5417\uff1f\u8d8a\u6765\u8d8a\u591a\u8d85\u7ea7\u5e94\u7528\u57fa\u4e8e Web \u6784\u5efa\uff0c\u5982\u4f55\u7cfb\u7edf\u6027\u653b\u9632 XSS \u5c24\u4e3a\u91cd\u8981\u3002\u5fae\u8f6f\u5b89\u5168\u5de5\u7a0b\u5e08 1999 \u5e74\u5e95\u62ab\u9732\u4e86 XSS\uff0c20\u591a \u5e74\u6765 XSS \u4e00\u76f4\u7a33\u5c45 OWASP\uff08\u5f00\u653e Web \u5e94\u7528\u7a0b\u5e8f\u5b89\u5168 \uff09 \u62a5\u544a\u524d TOP10\u3002<\/p>\n\n\n\n<p>\u8de8\u57df\u811a\u672c\u653b\u51fb\uff08XSS\uff1aCross-Site Scripting\uff09\u662f\u6700\u5e38\u89c1\u3001\u5371\u5bb3\u6700\u5927\u7684\u7f51\u9875\u5b89\u5168\u6f0f\u6d1e\u3002XSS \u653b\u51fb\u5229\u7528\u4e86\u6d4f\u89c8\u5668\u5bf9\u4e8e\u4ece\u670d\u52a1\u5668\u6240\u83b7\u53d6\u7684\u5185\u5bb9\u7684\u4fe1\u4efb\u3002\u6076\u610f\u811a\u672c\u5728\u53d7\u5bb3\u8005\u7684\u6d4f\u89c8\u5668\u4e2d\u5f97\u4ee5\u8fd0\u884c\uff0c\u56e0\u4e3a\u6d4f\u89c8\u5668\u4fe1\u4efb\u5176\u5185\u5bb9\u6765\u6e90\uff0c\u5373\u4f7f\u6709\u7684\u65f6\u5019\u8fd9\u4e9b\u811a\u672c\u5e76\u975e\u6765\u81ea\u4e8e\u5b83\u672c\u8be5\u6765\u7684\u5730\u65b9\u3002<\/p>\n\n\n\n<p>\u4e3a\u4e86\u9632\u6b62\u5b83\uff0c\u8981\u91c7\u53d6\u5f88\u591a\u7f16\u7a0b\u63aa\u65bd\uff08\u6bd4\u5982\u5927\u591a\u6570\u4eba\u90fd\u77e5\u9053\u7684\u8f6c\u4e49\u3001\u8fc7\u6ee4HTML\uff09\u3002\u5f88\u591a\u4eba\u63d0\u51fa\uff0c\u80fd\u4e0d\u80fd\u6839\u672c\u4e0a\u89e3\u51b3\u95ee\u9898\uff0c\u5373\u6d4f\u89c8\u5668\u81ea\u52a8\u7981\u6b62\u5916\u90e8\u6ce8\u5165\u6076\u610f\u811a\u672c\uff1f<\/p>\n\n\n\n<p>\u8fd9\u5c31\u662f&#8221;\u5185\u5bb9\u5b89\u5168\u7b56\u7565&#8221;\uff08Content Security Policy\uff0c\u7f29\u5199 CSP\uff09\u7684\u7531\u6765\u3002<\/p>\n\n\n\n<p>XSS\uff08Cross-Site Scripting\uff0c\u8de8\u7ad9\u811a\u672c\u653b\u51fb\uff0c\u7b80\u79f0XSS\uff09\u653b\u51fb\u662f\u4e00\u79cd\u5229\u7528\u7f51\u9875\u5e94\u7528\u7a0b\u5e8f\u7684\u5b89\u5168\u6f0f\u6d1e\u7684\u653b\u51fb\u65b9\u5f0f\uff0c\u653b\u51fb\u8005\u901a\u8fc7\u5728\u7f51\u9875\u4e2d\u6ce8\u5165\u6076\u610f\u811a\u672c\u4ee3\u7801\uff0c\u4f7f\u5176\u5728\u7528\u6237\u7684\u6d4f\u89c8\u5668\u4e2d\u6267\u884c\u3002\u8fd9\u4e9b\u6076\u610f\u811a\u672c\u53ef\u4ee5\u7528\u6765\u7a83\u53d6\u7528\u6237\u7684\u654f\u611f\u4fe1\u606f\u3001\u7be1\u6539\u7f51\u9875\u5185\u5bb9\u6216\u8fdb\u884c\u5176\u4ed6\u672a\u7ecf\u6388\u6743\u7684\u64cd\u4f5c\u3002<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"175\" src=\"https:\/\/92it.top\/wp-content\/uploads\/2024\/11\/image-145-1024x175.png\" alt=\"\" class=\"wp-image-16656\" style=\"width:518px;height:auto\" srcset=\"https:\/\/92it.top\/wp-content\/uploads\/2024\/11\/image-145-1024x175.png 1024w, https:\/\/92it.top\/wp-content\/uploads\/2024\/11\/image-145-300x51.png 300w, https:\/\/92it.top\/wp-content\/uploads\/2024\/11\/image-145-768x131.png 768w, https:\/\/92it.top\/wp-content\/uploads\/2024\/11\/image-145-830x142.png 830w, https:\/\/92it.top\/wp-content\/uploads\/2024\/11\/image-145-230x39.png 230w, https:\/\/92it.top\/wp-content\/uploads\/2024\/11\/image-145-350x60.png 350w, https:\/\/92it.top\/wp-content\/uploads\/2024\/11\/image-145-480x82.png 480w, https:\/\/92it.top\/wp-content\/uploads\/2024\/11\/image-145.png 1532w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure><\/div>\n\n\n<p>\u6709\u5c0f\u4f19\u4f34\u53ef\u80fd\u4f1a\u7591\u60d1\uff1a&#8221;\u653b\u51fb\u8005\u662f\u600e\u4e48\u5411\u7f51\u9875\u6ce8\u5165\u6076\u610f\u811a\u672c\u7684\uff1f&#8221;\uff0c\u6211\u4eec\u770b\u4e0b\u9762\u7684\u4f8b\u5b50\uff1a<\/p>\n\n\n\n<p>\u6709\u4e00\u4e2a\u535a\u5ba2\u7f51\u7ad9\u63d0\u4f9b\u4e86\u8bc4\u8bba\u529f\u80fd\uff0c\u7528\u6237\u8bc4\u8bba\u53ef\u4ee5\u5b9e\u65f6\u6e32\u67d3\u5230DOM\u4e2d\uff0c\u4f46\u7531\u4e8e\u8be5\u535a\u5ba2\u5e76\u672a\u505a\u7528\u6237\u8f93\u5165\u4ee5\u53ca\u6e32\u67d3\u5230DOM\u65f6\u7684\u6570\u636e\u6821\u9a8c\uff0c\u56e0\u6b64\u653b\u51fb\u8005\u5c31\u53ef\u4ee5\u8bc4\u8bba\u5982\u4e0b\u5185\u5bb9\uff1a<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"348\" src=\"https:\/\/92it.top\/wp-content\/uploads\/2024\/11\/image-146-1024x348.png\" alt=\"\" class=\"wp-image-16657\" style=\"width:512px;height:auto\" srcset=\"https:\/\/92it.top\/wp-content\/uploads\/2024\/11\/image-146-1024x348.png 1024w, https:\/\/92it.top\/wp-content\/uploads\/2024\/11\/image-146-300x102.png 300w, https:\/\/92it.top\/wp-content\/uploads\/2024\/11\/image-146-768x261.png 768w, https:\/\/92it.top\/wp-content\/uploads\/2024\/11\/image-146-830x282.png 830w, https:\/\/92it.top\/wp-content\/uploads\/2024\/11\/image-146-230x78.png 230w, https:\/\/92it.top\/wp-content\/uploads\/2024\/11\/image-146-350x119.png 350w, https:\/\/92it.top\/wp-content\/uploads\/2024\/11\/image-146-480x163.png 480w, https:\/\/92it.top\/wp-content\/uploads\/2024\/11\/image-146.png 1506w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure><\/div>\n\n\n<p>\u5f53\u5176\u4ed6\u7528\u6237\u6d4f\u89c8\u8bc4\u8bba\u65f6\uff0c\u6d4f\u89c8\u5668\u4f1a\u6267\u884c\u8bc4\u8bba\u4e2d\u7684JavaScript\u4ee3\u7801\u3002\u8fd9\u4e2a\u6076\u610f\u811a\u672c\u4f1a\u7a83\u53d6\u7528\u6237\u7684Cookie\u6570\u636e\uff0c\u5e76\u5c06\u5b83\u53d1\u9001\u5230\u653b\u51fb\u8005\u7684\u670d\u52a1\u5668\uff0c\u653b\u51fb\u8005\u53ef\u4ee5\u5728\u670d\u52a1\u5668\u4e0a\u5206\u6790\u8fd9\u4e9bCookie\u6570\u636e\uff0c\u53ef\u80fd\u7528\u4e8e\u8fdb\u4e00\u6b65\u7684\u653b\u51fb\uff0c\u5982\u8eab\u4efd\u76d7\u7a83\u6216\u4f1a\u8bdd\u52ab\u6301\u3002<\/p>\n\n\n\n<p>\u662f\u4e0d\u662f\u5f88\u6050\u6016\uff0c\u5f53\u7136\u806a\u660e\u7684\u670b\u53cb\u53ef\u80fd\u4f1a\u8bf4\uff1a&#8221;\u90a3\u6211\u505a\u597d\u7528\u6237\u8f93\u5165\u3001\u5ba2\u6237\u7aef\u6e32\u67d3\u7684\u6570\u636e\u6821\u9a8c\u4e0d\u5c31\u53ef\u4ee5\u4e86\u5417\uff1f&#8221;\u3002\u786e\u5b9e\uff0c<strong>\u505a\u597d\u7528\u6237\u8f93\u5165\u7684\u9a8c\u8bc1\u548c\u5ba2\u6237\u7aef\u6e32\u67d3\u6570\u636e\u7684\u6821\u9a8c\u662f\u9632\u6b62XSS\u653b\u51fb\u7684\u5173\u952e\u6b65\u9aa4\u4e4b\u4e00<\/strong>\uff0c\u4f46\u4e0d\u80fd\u5b8c\u5168\u4f9d\u8d56\u5b83\u6765\u786e\u4fdd\u5b89\u5168\uff0c\u56e0\u4e3aXSS\u653b\u51fb\u53ef\u4ee5\u975e\u5e38\u9690\u853d\u548c\u590d\u6742\uff0c\u6bd4\u5982\u4e0b\u9762\u8fd9\u4e2a\u4f8b\u5b50\uff1a<\/p>\n\n\n\n<p>\u6709\u4e00\u4e2a\u5728\u7ebf\u8bba\u575b\u7f51\u7ad9\u7528\u4e8e\u7528\u6237\u53d1\u8868\u548c\u6d4f\u89c8\u5e16\u5b50\u3002\u5b83\u4f7f\u7528\u4e86\u4e00\u4e2a\u5f00\u6e90\u7684Markdown\u6e32\u67d3\u5e93\uff0c\u8be5\u5e93\u7528\u4e8e\u5c06\u7528\u6237\u8f93\u5165\u7684Markdown\u6587\u672c\u8f6c\u6362\u4e3aHTML\u4ee5\u8fdb\u884c\u663e\u793a\u3002\u8be5\u7f51\u7ad9\u6267\u884c\u4e86\u4e25\u683c\u7684\u7528\u6237\u8f93\u5165\u3001\u6570\u636e\u6e32\u67d3\u9a8c\u8bc1\uff0c\u4ee5\u786e\u4fdd\u7528\u6237\u4e0d\u80fd\u76f4\u63a5\u63d2\u5165\u6076\u610f\u811a\u672c\u6216HTML\u6807\u7b7e\u3002\u4f46\u5176\u4f9d\u8d56\u7684Markdown\u6e32\u67d3\u5e93\u88ab\u6c61\u67d3\uff0c\u5728\u67d0\u4e2a\u65f6\u523b\u88ab\u653b\u51fb\u8005\u7be1\u6539\uff0c\u5305\u542b\u4e86\u4ee5\u4e0b\u4ee3\u7801\uff1a<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"316\" src=\"https:\/\/92it.top\/wp-content\/uploads\/2024\/11\/image-147-1024x316.png\" alt=\"\" class=\"wp-image-16658\" style=\"width:514px;height:auto\" srcset=\"https:\/\/92it.top\/wp-content\/uploads\/2024\/11\/image-147-1024x316.png 1024w, https:\/\/92it.top\/wp-content\/uploads\/2024\/11\/image-147-300x93.png 300w, https:\/\/92it.top\/wp-content\/uploads\/2024\/11\/image-147-768x237.png 768w, https:\/\/92it.top\/wp-content\/uploads\/2024\/11\/image-147-830x256.png 830w, https:\/\/92it.top\/wp-content\/uploads\/2024\/11\/image-147-230x71.png 230w, https:\/\/92it.top\/wp-content\/uploads\/2024\/11\/image-147-350x108.png 350w, https:\/\/92it.top\/wp-content\/uploads\/2024\/11\/image-147-480x148.png 480w, https:\/\/92it.top\/wp-content\/uploads\/2024\/11\/image-147.png 1498w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure><\/div>\n\n\n<p>\u5f53\u7528\u6237\u6d4f\u89c8Markdown\u65f6\uff0c\u6d4f\u89c8\u5668\u4f1a\u6267\u884c\u7b2c\u4e09\u65b9\u5e93\u6076\u610f\u4ee3\u7801\u3002\u8fd9\u4e2a\u6076\u610f\u811a\u672c\u4f1a\u7a83\u53d6\u7528\u6237\u7684Cookie\u6570\u636e\uff0c\u5e76\u5c06\u5b83\u53d1\u9001\u5230\u653b\u51fb\u8005\u7684\u670d\u52a1\u5668\uff0c\u653b\u51fb\u8005\u53ef\u4ee5\u5728\u670d\u52a1\u5668\u4e0a\u5206\u6790\u8fd9\u4e9bCookie\u6570\u636e\uff0c\u53ef\u80fd\u7528\u4e8e\u8fdb\u4e00\u6b65\u7684\u653b\u51fb\uff0c\u5982\u8eab\u4efd\u76d7\u7a83\u6216\u4f1a\u8bdd\u52ab\u6301\u3002<\/p>\n\n\n\n<p>\u4e0a\u8ff0\u4f8b\u5b50\u4e2d\u8be5\u7f51\u7ad9\u867d\u7136\u5bf9\u7528\u6237\u8f93\u5165\u3001\u6570\u636e\u6e32\u67d3\u8fdb\u884c\u4e86\u4e25\u683c\u7684\u9a8c\u8bc1\uff0c\u4f46\u7531\u4e8e\u7b2c\u4e09\u65b9\u5e93\u5b58\u5728\u6f0f\u6d1e\uff0c\u5bfc\u81f4\u6076\u610fJavaScript\u4ee3\u7801\u88ab\u6267\u884c\u3002\u5f53\u7136\uff0c\u8fd9\u53ef\u4ee5\u901a\u8fc7<strong>\u5c3d\u91cf\u9009\u62e9\u53d7\u4fe1\u4efb\u7684\u6e90\uff08\u5982\u5b98\u65b9\u4ed3\u5e93\u6216\u793e\u533a\u7ef4\u62a4\u7684\u5e93\uff09\u7684\u4f9d\u8d56\uff0c\u4ee5\u53ca\u5b9a\u671f\u5ba1\u67e5\u4f9d\u8d56\u7684\u5b89\u5168\u98ce\u9669\u6765\u964d\u4f4eXSS\u653b\u51fb\u7684\u98ce\u9669<\/strong>\u3002<\/p>\n\n\n\n<p>\u4ece\u4e0a\u8ff0\u4e24\u4e2a\u4f8b\u5b50\u6211\u4eec\u53ef\u4ee5\u770b\u5230\u60f3\u8981\u9632\u6b62XSS\u653b\u51fb\u662f\u6781\u5ea6\u590d\u6742\u4e14\u56f0\u96be\u7684\uff0c\u4e3a\u4e86\u63d0\u4f9b\u4e00\u79cd\u6709\u6548\u7684\u65b9\u5f0f\u6765\u964d\u4f4eXSS\u653b\u51fb\u98ce\u9669\uff0cW3C\u63a8\u51fa\u4e86\u4e00\u9879\u5b89\u5168\u63aa\u65bd\u2014\u2014\u5185\u5bb9\u5b89\u5168\u7b56\u7565<\/p>\n\n\n\n<p><strong>\u4e8c\u3001CSP\u4ecb\u7ecd<\/strong><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p>Content Security Policy (CSP) \u662f\u4e00\u79cd\u52a0\u56fa Web \u5e94\u7528\u7684\u5b89\u5168\u6027\u6280\u672f\uff0c\u901a\u8fc7\u5728\u7f51\u7ad9\u9875\u9762\u4e2d\u8bbe\u7f6e CSP Header \u6765\u9650\u5236\u9875\u9762\u4e2d\u80fd\u591f\u6267\u884c\u7684\u811a\u672c\u3001\u6837\u5f0f\u3001\u56fe\u7247\u7b49\u8d44\u6e90\u3002CSP \u5305\u62ec\u5f88\u591a\u4e0d\u540c\u7684\u7b56\u7565\uff0c\u56e0\u6b64\u5b89\u5168\u8bbe\u7f6e\u7684\u5177\u4f53\u503c\u53d6\u51b3\u76ee\u6807\u7f51\u7ad9\u7684\u9700\u6c42\u548c\u8d44\u6e90\u4f7f\u7528\u60c5\u51b5\u3002\u4e00\u822c\u800c\u8a00\uff0c\u5efa\u8bae\u8bbe\u7f6e\u8f83\u4e3a\u4e25\u683c\u7684 CSP\uff0c\u4ee5\u907f\u514d XSS\u3001CSRF \u7b49\u5b89\u5168\u95ee\u9898\u3002\u4f8b\u5982\uff0c\u53ef\u4ee5\u914d\u7f6e\u4ee5\u4e0b CSP\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">Content-Security-Policy: default-src 'self'; script-src 'self' https:\/\/example.com; img-src 'self' data:; style-src 'self' 'unsafe-inline'; font-src 'self' https:\/\/example.com;<\/pre>\n\n\n\n<p>\u4ee5\u4e0a\u8bbe\u7f6e\u7684 CSP \u89c4\u5219\u7981\u6b62\u6240\u6709\u6765\u81ea\u7b2c\u4e09\u65b9\u7f51\u7ad9\u7684\u8d44\u6e90\uff0c\u53ea\u5141\u8bb8\u672c\u7f51\u7ad9\u7684\u8d44\u6e90\u52a0\u8f7d\u3002\u5176\u4e2d script-src \u53ea\u5141\u8bb8\u672c\u7f51\u7ad9\u548c example.com \u7684\u811a\u672c\u52a0\u8f7d\uff0cimg-src \u53ea\u5141\u8bb8\u672c\u7f51\u7ad9\u548c data: URI \u7684\u56fe\u7247\u52a0\u8f7d\uff0cstyle-src \u53ea\u5141\u8bb8\u672c\u7f51\u7ad9\u548c\u5185\u8054\u6837\u5f0f\u52a0\u8f7d\uff0cfont-src \u53ea\u5141\u8bb8\u672c\u7f51\u7ad9\u548c example.com \u7684\u5b57\u4f53\u52a0\u8f7d\u3002\u8bf7\u6839\u636e\u5b9e\u9645\u60c5\u51b5\u8fdb\u884c\u8c03\u6574\u3002<\/p>\n\n\n\n<p>CSP \u7684\u5b9e\u8d28\u5c31\u662f\u767d\u540d\u5355\u5236\u5ea6\uff0c\u5f00\u53d1\u8005\u660e\u786e\u544a\u8bc9\u5ba2\u6237\u7aef\uff0c\u54ea\u4e9b\u5916\u90e8\u8d44\u6e90\u53ef\u4ee5\u52a0\u8f7d\u548c\u6267\u884c\uff0c\u7b49\u540c\u4e8e\u63d0\u4f9b\u767d\u540d\u5355\u3002\u5b83\u7684\u5b9e\u73b0\u548c\u6267\u884c\u5168\u90e8\u7531\u6d4f\u89c8\u5668\u5b8c\u6210\uff0c\u5f00\u53d1\u8005\u53ea\u9700\u63d0\u4f9b\u914d\u7f6e\u3002<\/p>\n\n\n\n<p>CSP \u5927\u5927\u589e\u5f3a\u4e86\u7f51\u9875\u7684\u5b89\u5168\u6027\u3002\u653b\u51fb\u8005\u5373\u4f7f\u53d1\u73b0\u4e86\u6f0f\u6d1e\uff0c\u4e5f\u6ca1\u6cd5\u6ce8\u5165\u811a\u672c\uff0c\u9664\u975e\u8fd8\u63a7\u5236\u4e86\u4e00\u53f0\u5217\u5165\u4e86\u767d\u540d\u5355\u7684\u53ef\u4fe1\u4e3b\u673a\u3002<\/p>\n\n\n\n<p>\u4e24\u79cd\u65b9\u6cd5\u53ef\u4ee5\u542f\u7528 CSP\uff1a<\/p>\n\n\n\n<ul>\n<li>\u8bbe\u7f6e HTTP \u7684 <code>Content-Security-Policy<\/code> \u5934\u90e8\u5b57\u6bb5\uff1b<\/li>\n\n\n\n<li>\u8bbe\u7f6e\u7f51\u9875\u7684<code>&lt;meta><\/code>\u6807\u7b7e\u3002<\/li>\n<\/ul>\n\n\n\n<p><strong>2.1 \u4f7f\u7528HTTP\u7684 Content-Security-Policy\u5934\u90e8<\/strong><\/p>\n\n\n\n<p>\u5728\u670d\u52a1\u5668\u7aef\u4f7f\u7528 HTTP\u7684 Content-Security-Policy\u54cd\u5e94\u5934\u90e8\u6765\u6307\u5b9a\u5b89\u5168\u7b56\u7565\u3002<\/p>\n\n\n\n<p>Content-Security-Policy: policy\uff1a policy\u53c2\u6570\u662f\u4e00\u4e2a\u5305\u542b\u4e86\u5404\u79cd\u63cf\u8ff0CSP\u7b56\u7565\u6307\u4ee4\u7684\u5b57\u7b26\u4e32\u3002<br><strong>\u793a\u4f8b1\uff1a<\/strong><\/p>\n\n\n\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\" data-enlighter-theme=\"\" data-enlighter-highlight=\"\" data-enlighter-linenumbers=\"\" data-enlighter-lineoffset=\"\" data-enlighter-title=\"\" data-enlighter-group=\"\">\/\/ index.js\nconst http = require('http');\nconst fs = require('fs');\nhttp.createServer((req, res) => {\n   const html = fs.readFileSync('index.html', 'utf8');\n   res.writeHead(200, {\n       'Content-Type': 'text-html',\n       'Content-Security-Policy': 'default-src http: https:' \n   });\n   res.end(html);\n}).listen(9000);\n\nconsole.log('server listening on 9000');\n<\/pre>\n\n\n\n<p>\u4ee5\u4e0a\u4ee3\u7801\u4f7f\u7528\u539f\u751fnodejs\u8d77\u4e86\u4e2a\u670d\u52a1\uff0c\u7136\u540e\u8bbe\u7f6e\u54cd\u5e94\u5934\u90e8<code>'Content-Security-Policy': 'default-src http: https:'<\/code>\u8868\u793a\u53ea\u80fd\u901a\u8fc7\u5916\u8054\u7684\u65b9\u5f0f\u6765\u5f15\u7528<code>js<\/code>\u548c<code>css<\/code>\uff0c\u5982\u679c\u4f7f\u7528\u5185\u8054\u7684\u5c06\u62a5\u9519\uff1a<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"1012\" height=\"122\" src=\"https:\/\/92it.top\/wp-content\/uploads\/2024\/11\/image-148.png\" alt=\"\" class=\"wp-image-16660\" style=\"width:460px;height:auto\" srcset=\"https:\/\/92it.top\/wp-content\/uploads\/2024\/11\/image-148.png 1012w, https:\/\/92it.top\/wp-content\/uploads\/2024\/11\/image-148-300x36.png 300w, https:\/\/92it.top\/wp-content\/uploads\/2024\/11\/image-148-768x93.png 768w, https:\/\/92it.top\/wp-content\/uploads\/2024\/11\/image-148-830x100.png 830w, https:\/\/92it.top\/wp-content\/uploads\/2024\/11\/image-148-230x28.png 230w, https:\/\/92it.top\/wp-content\/uploads\/2024\/11\/image-148-350x42.png 350w, https:\/\/92it.top\/wp-content\/uploads\/2024\/11\/image-148-480x58.png 480w\" sizes=\"(max-width: 1012px) 100vw, 1012px\" \/><\/figure><\/div>\n\n\n<p><strong>\u793a\u4f8b2<\/strong>\uff1a<\/p>\n\n\n\n<p>\u53ea\u80fd\u5728\u6307\u5b9a\u7684\u57df\u4e0b\u52a0\u8f7d\u6587\u4ef6\uff0c\u8fd9\u91cc\u8868\u793a\u53ea\u80fd\u4ece\u540c\u57df\u4e0b\u52a0\u8f7d\uff0c\u659c\u6760\u4e3a\u8f6c\u4e49\u7b26\uff1a<code>'Content-Security-Policy': 'default-src \\'self\\''<\/code><\/p>\n\n\n\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\" data-enlighter-theme=\"\" data-enlighter-highlight=\"\" data-enlighter-linenumbers=\"\" data-enlighter-lineoffset=\"\" data-enlighter-title=\"\" data-enlighter-group=\"\">&lt;script type=\"text\/javascript\" src=\"https:\/\/cdn.bootcss.com\/jquery\/3.3.1\/jquery.js\">&lt;\/script>\n<\/pre>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"1000\" height=\"118\" src=\"https:\/\/92it.top\/wp-content\/uploads\/2024\/11\/image-149.png\" alt=\"\" class=\"wp-image-16661\" style=\"width:512px;height:auto\" srcset=\"https:\/\/92it.top\/wp-content\/uploads\/2024\/11\/image-149.png 1000w, https:\/\/92it.top\/wp-content\/uploads\/2024\/11\/image-149-300x35.png 300w, https:\/\/92it.top\/wp-content\/uploads\/2024\/11\/image-149-768x91.png 768w, https:\/\/92it.top\/wp-content\/uploads\/2024\/11\/image-149-830x98.png 830w, https:\/\/92it.top\/wp-content\/uploads\/2024\/11\/image-149-230x27.png 230w, https:\/\/92it.top\/wp-content\/uploads\/2024\/11\/image-149-350x41.png 350w, https:\/\/92it.top\/wp-content\/uploads\/2024\/11\/image-149-480x57.png 480w\" sizes=\"(max-width: 1000px) 100vw, 1000px\" \/><\/figure><\/div>\n\n\n<p>\u6253\u5f00\u63a7\u5236\u53f0\u4e5f\u53ef\u4ee5\u770b\u5230\u8bf7\u6c42\u5728\u6d4f\u89c8\u5668\u5c31\u5df2\u7ecf\u88ab\u9650\u5236\u4e86\uff1a<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"690\" height=\"158\" src=\"https:\/\/92it.top\/wp-content\/uploads\/2024\/11\/image-150.png\" alt=\"\" class=\"wp-image-16662\" style=\"width:410px;height:auto\" srcset=\"https:\/\/92it.top\/wp-content\/uploads\/2024\/11\/image-150.png 690w, https:\/\/92it.top\/wp-content\/uploads\/2024\/11\/image-150-300x69.png 300w, https:\/\/92it.top\/wp-content\/uploads\/2024\/11\/image-150-230x53.png 230w, https:\/\/92it.top\/wp-content\/uploads\/2024\/11\/image-150-350x80.png 350w, https:\/\/92it.top\/wp-content\/uploads\/2024\/11\/image-150-480x110.png 480w\" sizes=\"(max-width: 690px) 100vw, 690px\" \/><\/figure><\/div>\n\n\n<p>\u5982\u679c\u8981\u5141\u8bb8\u8bf7\u6c42\u5230\u8fd9\u4e2a\u57df\uff0c\u6dfb\u52a0\u8fdb\u7b56\u7565\u5373\u53ef\uff1a<\/p>\n\n\n\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\" data-enlighter-theme=\"\" data-enlighter-highlight=\"\" data-enlighter-linenumbers=\"\" data-enlighter-lineoffset=\"\" data-enlighter-title=\"\" data-enlighter-group=\"\">'Content-Security-Policy': 'default-src \\'self\\' https:\/\/cdn.bootcss.com\/' <\/pre>\n\n\n\n<p><strong>\u793a\u4f8b3<\/strong>\uff1a<\/p>\n\n\n\n<p>\u4e0a\u9762\u7684\u7b56\u7565\u662f\u65e0\u6cd5\u9650\u5236form\u8868\u5355\u7684\u63d0\u4ea4\u7684\uff0c\u5982\u4e0b\u5217\u8868\u5355\uff0c\u70b9\u51fb\u540e\u76f4\u63a5\u8df3\u5230\u4e86\u767e\u5ea6\u9875\u9762\uff1a<\/p>\n\n\n\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\" data-enlighter-theme=\"\" data-enlighter-highlight=\"\" data-enlighter-linenumbers=\"\" data-enlighter-lineoffset=\"\" data-enlighter-title=\"\" data-enlighter-group=\"\"> &lt;form action=\"https:\/\/baidu.com\">\n        &lt;button>click me&lt;\/button>\n    &lt;\/form><\/pre>\n\n\n\n<p>\u8fd9\u65f6\u5019\u5c31\u8981\u8bbe\u7f6eform-action\u7b56\u7565\uff1a<\/p>\n\n\n\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\" data-enlighter-theme=\"\" data-enlighter-highlight=\"\" data-enlighter-linenumbers=\"\" data-enlighter-lineoffset=\"\" data-enlighter-title=\"\" data-enlighter-group=\"\">'Content-Security-Policy': 'default-src \\'self\\' https:\/\/cdn.bootcss.com\/; form-action \\'self\\''<\/pre>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"84\" src=\"https:\/\/92it.top\/wp-content\/uploads\/2024\/11\/image-151-1024x84.png\" alt=\"\" class=\"wp-image-16663\" style=\"width:639px;height:auto\" srcset=\"https:\/\/92it.top\/wp-content\/uploads\/2024\/11\/image-151-1024x84.png 1024w, https:\/\/92it.top\/wp-content\/uploads\/2024\/11\/image-151-300x25.png 300w, https:\/\/92it.top\/wp-content\/uploads\/2024\/11\/image-151-768x63.png 768w, https:\/\/92it.top\/wp-content\/uploads\/2024\/11\/image-151-830x68.png 830w, https:\/\/92it.top\/wp-content\/uploads\/2024\/11\/image-151-230x19.png 230w, https:\/\/92it.top\/wp-content\/uploads\/2024\/11\/image-151-350x29.png 350w, https:\/\/92it.top\/wp-content\/uploads\/2024\/11\/image-151-480x39.png 480w, https:\/\/92it.top\/wp-content\/uploads\/2024\/11\/image-151.png 1320w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure><\/div>\n\n\n<p>\u5176\u4e2d\uff0c<code>default-src<\/code>\u8bbe\u7f6e\u7684\u662f\u5168\u5c40\uff0c\u5982\u679c\u53ea\u60f3\u9650\u5236<code>js<\/code>\u7684\u8bf7\u6c42\uff0c\u53ef\u4ee5\u5c06<code>default-src<\/code>\u6539\u4e3a<code>script-src<\/code>\u3002<br>\u542f\u7528\u8fdd\u4f8b\u62a5\u544a<br>\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u8fdd\u89c4\u62a5\u544a\u5e76\u4e0d\u4f1a\u53d1\u9001\u3002\u4e3a\u542f\u7528\u53d1\u9001\u8fdd\u89c4\u62a5\u544a\uff0c\u9700\u8981\u6307\u5b9a <code>report-uri<\/code>\u7b56\u7565\u6307\u4ee4\uff0c\u5e76\u63d0\u4f9b\u81f3\u5c11\u4e00\u4e2aURI\u5730\u5740\u53bb\u9012\u4ea4\u62a5\u544a\uff1a<\/p>\n\n\n\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\" data-enlighter-theme=\"\" data-enlighter-highlight=\"\" data-enlighter-linenumbers=\"\" data-enlighter-lineoffset=\"\" data-enlighter-title=\"\" data-enlighter-group=\"\">'Content-Security-Policy': 'script-src \\'self\\'; report-uri \/report'<\/pre>\n\n\n\n<p>\u8fd9\u91cc\u7684\u62a5\u544a\u6211\u4eec\u53ef\u4ee5\u76f4\u63a5\u5728\u6d4f\u89c8\u5668\u770b\u5230\uff0c\u5b83\u4f1a\u81ea\u52a8\u53d1\u9001\u4e00\u4e2a\u8bf7\u6c42\u51fa\u53bb\uff1a<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"508\" src=\"https:\/\/92it.top\/wp-content\/uploads\/2024\/11\/image-152-1024x508.png\" alt=\"\" class=\"wp-image-16664\" style=\"width:518px;height:auto\" srcset=\"https:\/\/92it.top\/wp-content\/uploads\/2024\/11\/image-152-1024x508.png 1024w, https:\/\/92it.top\/wp-content\/uploads\/2024\/11\/image-152-300x149.png 300w, https:\/\/92it.top\/wp-content\/uploads\/2024\/11\/image-152-768x381.png 768w, https:\/\/92it.top\/wp-content\/uploads\/2024\/11\/image-152-830x411.png 830w, https:\/\/92it.top\/wp-content\/uploads\/2024\/11\/image-152-230x114.png 230w, https:\/\/92it.top\/wp-content\/uploads\/2024\/11\/image-152-350x174.png 350w, https:\/\/92it.top\/wp-content\/uploads\/2024\/11\/image-152-480x238.png 480w, https:\/\/92it.top\/wp-content\/uploads\/2024\/11\/image-152.png 1416w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure><\/div>\n\n\n<p>\u5982\u679c\u53ea\u60f3\u6536\u96c6\u62a5\u544a\uff0c\u4f46\u662f\u4e0d\u771f\u6b63\u7684\u53bb\u9650\u5236\u8bf7\u6c42\uff0c\u90a3\u600e\u4e48\u529e\uff1f\u9664\u4e86Content-Security-Policy\uff0c\u8fd8\u6709\u4e00\u4e2aContent-Security-Policy-Report-Only\u5b57\u6bb5\uff0c\u8868\u793a\u4e0d\u6267\u884c\u9650\u5236\u9009\u9879\uff0c\u53ea\u662f\u8bb0\u5f55\u8fdd\u53cd\u9650\u5236\u7684\u884c\u4e3a\u3002\u5c06\u5934\u90e8\u6539\u4e3a\u8fd9\u4e2a\u5373\u53ef\u3002<\/p>\n\n\n\n<p>\u5982\u679c Content-Security-Policy-Report-Only \u6807\u5934\u548c Content-Security-Policy \u540c\u65f6\u51fa\u73b0\u5728\u4e00\u4e2a\u54cd\u5e94\u4e2d\uff0c\u4e24\u4e2a\u7b56\u7565\u5747\u6709\u6548\u3002\u5728 Content-Security-Policy \u6807\u5934\u4e2d\u6307\u5b9a\u7684\u7b56\u7565\u6709\u5f3a\u5236\u6027\uff0c\u800c Content-Security-Policy-Report-Only \u4e2d\u7684\u7b56\u7565\u4ec5\u4ea7\u751f\u62a5\u544a\u800c\u4e0d\u5177\u6709\u5f3a\u5236\u6027\u3002<\/p>\n\n\n\n<p><strong>3.2 \u4f7f\u7528 meta \u6807\u7b7e<\/strong><\/p>\n\n\n\n<p>\u4ee5\u4e0a\u89c4\u5219\u53ef\u4ee5\u5728\u6d4f\u89c8\u5668\u7aef\u8bbe\u7f6e\uff0c\u5982\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">&lt;meta http-equiv=\"Content-Security-Policy\" content=\"form-action 'self';\"><\/pre>\n\n\n\n<p>\u4f46\u4e0e\u670d\u52a1\u5668\u7aef\u8bbe\u7f6e\u6709\u70b9\u4e0d\u540c\u7684\u662f\uff0c<code>meta<\/code>\u65e0\u6cd5\u4f7f\u7528<code>report<\/code>\uff0c\u53ea\u80fd\u5728\u670d\u52a1\u5668\u7aef\u8bbe\u7f6e\uff1a<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"35\" src=\"https:\/\/92it.top\/wp-content\/uploads\/2024\/11\/image-153-1024x35.png\" alt=\"\" class=\"wp-image-16665\" style=\"width:585px;height:auto\" srcset=\"https:\/\/92it.top\/wp-content\/uploads\/2024\/11\/image-153-1024x35.png 1024w, https:\/\/92it.top\/wp-content\/uploads\/2024\/11\/image-153-300x10.png 300w, https:\/\/92it.top\/wp-content\/uploads\/2024\/11\/image-153-768x26.png 768w, https:\/\/92it.top\/wp-content\/uploads\/2024\/11\/image-153-830x28.png 830w, https:\/\/92it.top\/wp-content\/uploads\/2024\/11\/image-153-230x8.png 230w, https:\/\/92it.top\/wp-content\/uploads\/2024\/11\/image-153-350x12.png 350w, https:\/\/92it.top\/wp-content\/uploads\/2024\/11\/image-153-480x16.png 480w, https:\/\/92it.top\/wp-content\/uploads\/2024\/11\/image-153.png 1174w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure><\/div>\n\n\n<p><strong>\u4e09\u3001CSP \u5b9e\u65bd\u7b56\u7565<\/strong><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p>\u9650\u5236\u65b9\u5f0f<\/p>\n\n\n\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\" data-enlighter-theme=\"\" data-enlighter-highlight=\"\" data-enlighter-linenumbers=\"\" data-enlighter-lineoffset=\"\" data-enlighter-title=\"\" data-enlighter-group=\"\">default-src\uff1a \u9650\u5236\u5168\u5c40\uff0c\u9ed8\u8ba4\u6240\u6709\u90fd\u4f1a\u4f7f\u7528\u8fd9\u79cd\u89c4\u5219\u3002\nscript-src\uff1a \u9650\u5236JavaScript\u7684\u6e90\u5730\u5740\u3002\nstyle-src\uff1a\u9650\u5236\u5c42\u53e0\u6837\u5f0f\u8868\u6587\u4ef6\u6e90\u3002\nimg-src\uff1a\u9650\u5236\u56fe\u7247\u548c\u56fe\u6807\u7684\u6e90\u5730\u5740\u3002\nfont-src\uff1a\u5b9a\u4e49\u4e86\u5b57\u4f53\u52a0\u8f7d\u7684\u6709\u6548\u6765\u6e90\u3002\nconnect-src\uff1a\u5b9a\u4e49\u4e86\u8bf7\u6c42\u3001XMLHttpRequest\u3001WebSocket \u548c EventSource \u7684\u8fde\u63a5\u6765\u6e90\nchild-src\uff1a \u6307\u5b9a\u5b9a\u4e49\u4e86 web workers \u4ee5\u53ca\u5d4c\u5957\u7684\u6d4f\u89c8\u4e0a\u4e0b\u6587\uff08\u5982&lt;frame>\u548c&lt;iframe>\uff09\u7684\u6e90\u3002\nmedia-src\uff1a\u9650\u5236\u901a\u8fc7 &lt;audio>\u3001&lt;video> \u6216 &lt;track> \u6807\u7b7e\u52a0\u8f7d\u7684\u5a92\u4f53\u6587\u4ef6\u7684\u6e90\u5730\u5740\u3002\nobject-src\uff1a\u9650\u5236 &lt;object> \u6216 &lt;embed> \u6807\u7b7e\u7684\u6e90\u5730\u5740\u3002\nmanifest-src\uff1a\u9650\u5236\u5e94\u7528\u58f0\u660e\u6587\u4ef6\u7684\u6e90\u5730\u5740\u3002\nprefetch-src\uff1a\u6307\u5b9a\u9884\u52a0\u8f7d\u6216\u9884\u6e32\u67d3\u7684\u5141\u8bb8\u6e90\u5730\u5740\u3002\nworker-src\uff1a\u9650\u5236 Worker\u3001SharedWorker \u6216 ServiceWorker \u811a\u672c\u6e90\u3002\nwebrtc-src\uff1a\u6307\u5b9aWebRTC\u8fde\u63a5\u7684\u5408\u6cd5\u6e90\u5730\u5740\u3002<\/pre>\n\n\n\n<p><strong>\u6ce8\u26a0\ufe0f\uff1a\u8bbe\u7f6e\u591a\u4e2a\u9650\u5236\u6761\u4ef6\uff0c\u540e\u9762\u7684\u4f1a\u8986\u76d6\u524d\u9762\u7684\uff01<\/strong><\/p>\n\n\n\n<p>\u4e00\u4e2aCSP\u5934\u7531\u591a\u7ec4CSP\u7b56\u7565\u7ec4\u6210\uff0c\u4e2d\u95f4\u7531\u5206\u53f7\u5206\u9694\u3002\u5176\u4e2d\u6bcf\u4e00\u7ec4\u7b56\u7565\u5305\u542b\u4e00\u4e2a\u7b56\u7565\u6307\u4ee4\u548c\u4e00\u4e2a\u5185\u5bb9\u6e90\u5217\u8868\u3002\u4f8b\u5982\uff1a<\/p>\n\n\n\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\" data-enlighter-theme=\"\" data-enlighter-highlight=\"\" data-enlighter-linenumbers=\"\" data-enlighter-lineoffset=\"\" data-enlighter-title=\"\" data-enlighter-group=\"\">Content-Security-Policy: default-src 'self' www.baidu.com; script-src 'unsafe-inline'<\/pre>\n\n\n\n<p><strong>\u4ec0\u4e48\u662f\u540c\u6e90\u7b56\u7565\uff1f<\/strong><\/p>\n\n\n\n<p>URL\u7531\u534f\u8bae\u3001\u57df\u540d\u3001\u7aef\u53e3\u548c\u8def\u5f84\u7ec4\u6210\uff0c\u5982\u679c\u4e24\u4e2aURL\u7684\u534f\u8bae\u3001\u57df\u540d\u548c\u7aef\u53e3\u76f8\u540c\uff0c\u5219\u8868\u793a\u4ed6\u4eec\u662f\u540c\u6e90\u7684\u3002\u540c\u6e90\u7b56\u7565\u662f\u6d4f\u89c8\u5668\u4e0a\u4e3a\u5b89\u5168\u6027\u8003\u8651\u5b9e\u65bd\u7684\u975e\u5e38\u91cd\u8981\u7684\u5b89\u5168\u7b56\u7565\u3002\u9650\u5236\u6765\u81ea\u4e0d\u540c\u6e90\u7684\u201ddocument\u201d\uff0c\u5bf9\u5f53\u524d\u201ddocument\u201d\u8bfb\u53d6\u6216\u8bbe\u7f6e\u67d0\u4e9b\u5c5e\u6027\u3002<\/p>\n\n\n\n<p>\u5728\u6d4f\u89c8\u5668\u4e2d\uff0c&lt;script&gt;\u3001&lt;img&gt;\u3001&lt;link&gt;\u3001&lt;frame&gt;\u7b49\u6807\u7b7e\u90fd\u53ef\u52a0\u8f7d\u8de8\u57df\u8d44\u6e90\uff0c\u800c\u4e0d\u53d7\u540c\u6e90\u7b56\u7565\u9650\u5236\uff0c\u8fd9\u5e26\u201dsrc\u201d\u5c5e\u6027\u7684\u6807\u7b7e\u52a0\u8f7d\u65f6\uff0c\u5b9e\u9645\u4e0a\u662f\u7531\u6d4f\u89c8\u5668\u53d1\u8d77\u4e00\u6b21GET\u8bf7\u6c42\uff0c\u4e0d\u540c\u4e8eXMLHttpRequest\uff0c\u4ed6\u4eec\u901a\u8fc7src\u5c5e\u6027\u52a0\u8f7d\u7684\u8d44\u6e90\u3002\u4f46\u6d4f\u89c8\u5668\u9650\u5236\u4e86JavaScript\u7684\u6743\u9650\uff0c\u4f7f\u5176\u4e0d\u80fd\u8bfb\u3001\u5199\u5176\u4e2d\u8fd4\u56de\u7684\u5185\u5bb9\u3002\u8de8\u57df\u8bf7\u6c42\u7684\u5b89\u5168\u57fa\u7840\u662fJavaScript\u65e0\u6cd5\u4fee\u6539\u8bf7\u6c42\u5bf9\u8c61\u7684http\u5934\u90e8\u3002\u5982\u679cXMLHttpRequest\u80fd\u591f\u8de8\u57df\u8bf7\u6c42\u8d44\u6e90\uff0c\u53ef\u80fd\u5bfc\u81f4\u654f\u611f\u4fe1\u606f\u6cc4\u9732\uff0c\u6bd4\u5982CSRF\u7684token\u4fe1\u606f\u3002<\/p>\n\n\n\n<p><strong>\u4e3a\u4ec0\u4e48\u4f7f\u7528\u540c\u6e90\u7b56\u7565\uff1f<\/strong><\/p>\n\n\n\n<p>\u4e00\u4e2a\u91cd\u8981\u539f\u56e0\u5c31\u662f\u5bf9cookie\u7684\u4fdd\u62a4\uff0ccookie \u4e2d\u5b58\u7740sessionID\u3002\u5982\u679c\u5df2\u7ecf\u767b\u5f55\u7f51\u7ad9\uff0c\u540c\u65f6\u53c8\u53bb\u4e86\u4efb\u610f\u5176\u4ed6\u7f51\u7ad9\uff0c\u8be5\u7f51\u7ad9\u6709\u6076\u610fJS\u4ee3\u7801\u3002\u5982\u679c\u6ca1\u6709\u540c\u6e90\u7b56\u7565\uff0c\u90a3\u4e48\u8fd9\u4e2a\u7f51\u7ad9\u5c31\u80fd\u901a\u8fc7js \u8bbf\u95eedocument.cookie \u5f97\u5230\u7528\u6237\u5173\u4e8e\u7684\u5404\u4e2a\u7f51\u7ad9\u7684sessionID\u3002\u5176\u4e2d\u53ef\u80fd\u6709\u94f6\u884c\u7f51\u7ad9\uff0c\u901a\u8fc7\u5df2\u7ecf\u5efa\u7acb\u597d\u7684session\u8fde\u63a5\u8fdb\u884c\u653b\u51fb\uff0c\u8fd9\u91cc\u6709\u4e00\u4e2a\u4e13\u6709\u540d\u8bcd\uff0cCSRF\uff0c\u8fd8\u6709\u9700\u8981\u6ce8\u610f\u7684\u662f\u540c\u6e90\u7b56\u7565\u65e0\u6cd5\u5b8c\u5168\u9632\u5fa1CSRF\uff0c\u8fd9\u91cc\u9700\u8981\u670d\u52a1\u7aef\u914d\u5408\u3002<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u4e00\u3001\u524d\u8a00 \u4f5c\u4e3a\u524d\u7aef\u5de5\u7a0b\u5e08\u4f60\u771f\u7684\u4e86\u89e3 XSS \u5417\uff1f\u8d8a\u6765\u8d8a\u591a\u8d85\u7ea7\u5e94\u7528\u57fa\u4e8e Web \u6784\u5efa\uff0c\u5982\u4f55\u7cfb\u7edf\u6027\u653b\u9632 XSS \u5c24 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[11],"tags":[],"_links":{"self":[{"href":"https:\/\/92it.top\/index.php?rest_route=\/wp\/v2\/posts\/16655"}],"collection":[{"href":"https:\/\/92it.top\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/92it.top\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/92it.top\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/92it.top\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=16655"}],"version-history":[{"count":2,"href":"https:\/\/92it.top\/index.php?rest_route=\/wp\/v2\/posts\/16655\/revisions"}],"predecessor-version":[{"id":16666,"href":"https:\/\/92it.top\/index.php?rest_route=\/wp\/v2\/posts\/16655\/revisions\/16666"}],"wp:attachment":[{"href":"https:\/\/92it.top\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=16655"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/92it.top\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=16655"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/92it.top\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=16655"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}