Struts1.1+Weblogic12C项目中X-Frame-Options:sameorigin配置位置咨询
Great question! Let's break down how to add the X-Frame-Options: sameorigin header to your Struts 1.1 + WebLogic 12c application across the three locations you mentioned. I'll start with the most scalable approaches first:
web.xml (Recommended) This is the best approach because it applies the header to all requests in your app, no need to modify individual pages or actions. You have two options here:
Option A: WebLogic-Specific Container Descriptor
WebLogic 12c lets you define response headers directly in web.xml without writing custom code. Add this inside your <web-app> tag:
<container-descriptor> <response-header> <name>X-Frame-Options</name> <value>sameorigin</value> </response-header> </container-descriptor>
Option B: Custom Servlet Filter
If you need more flexibility (or want a container-agnostic solution), create a filter:
First, write the filter class:
import javax.servlet.*; import javax.servlet.http.HttpServletResponse; import java.io.IOException; public class XFrameOptionsFilter implements Filter { @Override public void init(FilterConfig filterConfig) throws ServletException {} @Override public void doFilter(ServletRequest request, ServletResponse response, FilterChain chain) throws IOException, ServletException { HttpServletResponse httpResponse = (HttpServletResponse) response; httpResponse.setHeader("X-Frame-Options", "sameorigin"); chain.doFilter(request, response); } @Override public void destroy() {} }
Then register it in web.xml:
<filter> <filter-name>XFrameOptionsFilter</filter-name> <filter-class>com.your.package.XFrameOptionsFilter</filter-class> </filter> <filter-mapping> <filter-name>XFrameOptionsFilter</filter-name> <url-pattern>/*</url-pattern> <!-- Applies to all requests --> </filter-mapping>
If you need to apply the header only to specific actions, or want to add it globally via a base action:
Global Base Action
If all your Struts actions extend a custom base class, add the header there:
import org.apache.struts.action.Action; import org.apache.struts.action.ActionForm; import org.apache.struts.action.ActionForward; import org.apache.struts.action.ActionMapping; import javax.servlet.http.HttpServletRequest; import javax.servlet.http.HttpServletResponse; public class BaseAction extends Action { @Override public ActionForward execute(ActionMapping mapping, ActionForm form, HttpServletRequest request, HttpServletResponse response) throws Exception { response.setHeader("X-Frame-Options", "sameorigin"); return super.execute(mapping, form, request, response); } }
Individual Actions
For specific actions, add the header directly in their execute method:
public class YourSpecificAction extends Action { @Override public ActionForward execute(ActionMapping mapping, ActionForm form, HttpServletRequest request, HttpServletResponse response) throws Exception { // Add the header here response.setHeader("X-Frame-Options", "sameorigin"); // Your existing action logic return mapping.findForward("success"); } }
If you only need the header on specific JSPs, add this scriptlet at the top of the JSP (right after the page directive):
<%@ page language="java" contentType="text/html; charset=UTF-8" pageEncoding="UTF-8"%> <% // Add X-Frame-Options header response.setHeader("X-Frame-Options", "sameorigin"); %> <!-- Rest of your JSP content -->
Quick Recommendation
Stick with the web.xml container descriptor (Option A) if you're using WebLogic exclusively—it's the simplest and most maintainable. The filter approach works if you need to run on other containers later.
内容的提问来源于stack exchange,提问作者user7491136

