JSF 2.0; escape=“false” alternative to prevent XSS?

前端 未结 2 1103
南方客
南方客 2020-12-18 12:35

In my jsf webapplication i\'m using a messages.properties to output some text. This text could have html line breaks so format the outputtext.

That all works fine, i

2条回答
  •  误落风尘
    2020-12-18 13:03

    XSS can't happen if you're outputting some HTML from a safe source which is not input or editable by the user. You can safely use escape="false" in this case.

提交回复
热议问题