2022-05-20 15:31:42 +02:00
|
|
|
include::../summary.adoc[]
|
2020-06-30 12:50:28 +02:00
|
|
|
|
2022-05-20 15:31:42 +02:00
|
|
|
== Why is this an issue?
|
2020-06-30 12:50:28 +02:00
|
|
|
|
2022-05-20 15:31:42 +02:00
|
|
|
include::../rationale.adoc[]
|
|
|
|
|
|
|
|
include::../impact.adoc[]
|
|
|
|
|
2023-03-07 17:16:47 +01:00
|
|
|
// How to fix it section
|
2022-05-20 15:31:42 +02:00
|
|
|
|
2022-07-04 10:29:30 +02:00
|
|
|
include::how-to-fix-it/jsp.adoc[]
|
|
|
|
|
|
|
|
include::how-to-fix-it/servlet.adoc[]
|
|
|
|
|
|
|
|
include::how-to-fix-it/spring.adoc[]
|
|
|
|
|
|
|
|
include::how-to-fix-it/thymeleaf.adoc[]
|
2022-05-20 15:31:42 +02:00
|
|
|
|
|
|
|
== Resources
|
|
|
|
|
2022-07-04 14:51:49 +02:00
|
|
|
include::../common/resources/docs.adoc[]
|
2023-06-22 10:38:01 +02:00
|
|
|
|
2022-07-04 14:51:49 +02:00
|
|
|
* https://javadoc.io/doc/org.owasp.encoder/encoder/latest/index.html[OWASP Encoder]
|
2022-05-20 15:31:42 +02:00
|
|
|
* https://spring.io/guides/gs/securing-web/[Spring.io, Securing a Web Application]
|
2022-07-04 14:51:49 +02:00
|
|
|
* https://www.thymeleaf.org/doc/tutorials/2.1/usingthymeleaf.html[Thymeleaf.org, Tutorial: Using Thymeleaf]
|
2022-05-20 15:31:42 +02:00
|
|
|
|
|
|
|
include::../common/resources/articles.adoc[]
|
|
|
|
|
|
|
|
include::../common/resources/presentations.adoc[]
|
|
|
|
|
|
|
|
include::../common/resources/standards.adoc[]
|
2020-06-30 12:50:28 +02:00
|
|
|
|
2021-06-02 20:44:38 +02:00
|
|
|
|
2021-06-03 09:05:38 +02:00
|
|
|
ifdef::env-github,rspecator-view[]
|
2021-09-20 15:38:42 +02:00
|
|
|
|
|
|
|
'''
|
|
|
|
== Implementation Specification
|
|
|
|
(visible only on this page)
|
|
|
|
|
|
|
|
include::../message.adoc[]
|
|
|
|
|
|
|
|
include::../highlighting.adoc[]
|
|
|
|
|
2021-06-08 15:52:13 +02:00
|
|
|
'''
|
2021-06-02 20:44:38 +02:00
|
|
|
== Comments And Links
|
|
|
|
(visible only on this page)
|
|
|
|
|
|
|
|
include::../comments-and-links.adoc[]
|
2023-06-22 10:38:01 +02:00
|
|
|
|
2021-06-03 09:05:38 +02:00
|
|
|
endif::env-github,rspecator-view[]
|