How do I disable resolving login parameters passed as url parameters / from the url

后端 未结 4 1079
攒了一身酷
攒了一身酷 2020-12-03 09:28

The application logs all requested urls. This means, that it\'s critical not to authenticate using url parameters, because it would cause the situation in which

4条回答
  •  暗喜
    暗喜 (楼主)
    2020-12-03 10:22

    To the best of my knowledge and intuition, like jhan had mentioned, the appropriate solution would be to use annotation @RequestMapping(value="/login", method="RequestMethod.POST"). Then, no matter what parameters the user may pass with the URL, both the URL and URI will always default to /login. And that is what the logger will document. Not the username and password pairs, but "http://localhost:8080/login", or whatever your port is.

提交回复
热议问题