Java應用程式由Fortify靜態程式碼分析(SCA)工具進行弱點掃描時,出現[System Information Leak: Internal]漏洞的解法。
2025/3/19
2024/5/1
2023/6/6
2022/3/26
2021/9/8
Golang JSON Injection 安全漏洞 json.Unmarshal to map[string]interface{}
最近碰到Go原始碼在靜態程式碼掃描時警告有JSON Injection漏洞(vulnerabilities),本篇紀錄解決方式。
2021/2/2
Spring Boot 使用Google身分驗證器做TOTP驗證 Google Authenticator TOTP auth
Google Authenticator身分驗證器在Spring Boot中進行TOTP驗證。
2021/1/27
2020/4/10
2019/11/20
Spring Security CSRF預設保護的HTTP請求方法 CSRF default protect HTTP methods
Spring Security 啟用CSRF防護時,預設只保護會異動資料狀態的HTTP請求方法,
2018/3/13
Spring Security 什麼是Credential
根據Authentication.getCredentials()的說明,Credential(憑證)是指用來證明Principal身分的東西,通常是密碼(password)。
驗證(Authentication)與授權(Authorization)的區別
Authentication vs Authorization
Authentication和Authorization的區別如下。
Spring Security 什麼是Principal
Spring Security中常看到Principal這個字。Principle是指一個存取系統資源的實體(Entity),簡單來說就是登入的使用者。
2018/3/7
HTTP Basic 與 HTTP Digest 驗證的差別
HTTP Basic與HTTP Digest的差異在於,HTTP Basic在傳送憑證(credential)時僅是用Base64編碼(Base64 encoding)來傳送,而HTTP Digest是用MD5加密。
2018/2/22
2018/2/13
2018/2/12
2018/2/8
2018/1/14
訂閱:
文章 (Atom)