You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

迁移至Struts 6.3.0.2后window.opener元素innerHTML赋值失效问题

Struts 2 6.3.0.2迁移后子窗口操作父页面DOM失效解决方案

问题原因

Struts 2 6.3.0.2版本默认启用了更严格的跨窗口安全防护策略,限制子窗口通过window.opener直接操作父页面DOM元素,以此防范点击劫持等安全风险,导致原代码window.opener.document.getElementById(<%=param%>).innerHTML= myvalue失效。

解决方法

方法1:调整Struts2安全配置

在struts.xml中添加或修改以下配置,放宽窗口 opener的访问限制:

<constant name="struts.security.window.opener.restriction" value="none"/>

方法2:改用postMessage跨窗口通信(推荐)

现代浏览器对window.opener的访问限制日趋严格,使用postMessage是更安全且兼容的方案:

  • 子窗口按钮点击事件代码:
// 子窗口点击添加按钮时
const myvalue = "目标内容";
window.opener.postMessage({
  type: 'updateInnerHTML',
  elementId: <%=param%>,
  content: myvalue
}, window.opener.origin); // 建议替换为父页面的具体域名,进一步提升安全性
  • 父页面添加消息监听:
window.addEventListener('message', (event) => {
  // 验证消息来源,防止恶意攻击
  if (event.origin !== 'https://父页面域名.com') return;
  if (event.data.type === 'updateInnerHTML') {
    const targetEl = document.getElementById(event.data.elementId);
    if (targetEl) {
      targetEl.innerHTML = event.data.content;
    }
  }
});

方法3:排查XSS防护拦截

若innerHTML内容包含特殊字符,可能被Struts2的XSS防护过滤:

  • 临时关闭XSS防护测试(不建议生产环境使用):
<constant name="struts.xss.protection.enabled" value="false"/>
  • 生产环境建议对myvalue进行安全转义后再插入DOM,避免XSS风险。

内容的提问来源于stack exchange,提问作者Akash

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.26 10:01:01