You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Struts1.1+Weblogic12C项目中X-Frame-Options:sameorigin配置位置咨询

Great question! Let's break down how to add the X-Frame-Options: sameorigin header to your Struts 1.1 + WebLogic 12c application across the three locations you mentioned. I'll start with the most scalable approaches first:

This is the best approach because it applies the header to all requests in your app, no need to modify individual pages or actions. You have two options here:

Option A: WebLogic-Specific Container Descriptor

WebLogic 12c lets you define response headers directly in web.xml without writing custom code. Add this inside your <web-app> tag:

<container-descriptor>
    <response-header>
        <name>X-Frame-Options</name>
        <value>sameorigin</value>
    </response-header>
</container-descriptor>

Option B: Custom Servlet Filter

If you need more flexibility (or want a container-agnostic solution), create a filter:
First, write the filter class:

import javax.servlet.*;
import javax.servlet.http.HttpServletResponse;
import java.io.IOException;

public class XFrameOptionsFilter implements Filter {
    @Override
    public void init(FilterConfig filterConfig) throws ServletException {}

    @Override
    public void doFilter(ServletRequest request, ServletResponse response, FilterChain chain) throws IOException, ServletException {
        HttpServletResponse httpResponse = (HttpServletResponse) response;
        httpResponse.setHeader("X-Frame-Options", "sameorigin");
        chain.doFilter(request, response);
    }

    @Override
    public void destroy() {}
}

Then register it in web.xml:

<filter>
    <filter-name>XFrameOptionsFilter</filter-name>
    <filter-class>com.your.package.XFrameOptionsFilter</filter-class>
</filter>
<filter-mapping>
    <filter-name>XFrameOptionsFilter</filter-name>
    <url-pattern>/*</url-pattern> <!-- Applies to all requests -->
</filter-mapping>
2. Adding in Java Code (Struts Actions)

If you need to apply the header only to specific actions, or want to add it globally via a base action:

Global Base Action

If all your Struts actions extend a custom base class, add the header there:

import org.apache.struts.action.Action;
import org.apache.struts.action.ActionForm;
import org.apache.struts.action.ActionForward;
import org.apache.struts.action.ActionMapping;
import javax.servlet.http.HttpServletRequest;
import javax.servlet.http.HttpServletResponse;

public class BaseAction extends Action {
    @Override
    public ActionForward execute(ActionMapping mapping, ActionForm form,
                                 HttpServletRequest request, HttpServletResponse response)
            throws Exception {
        response.setHeader("X-Frame-Options", "sameorigin");
        return super.execute(mapping, form, request, response);
    }
}

Individual Actions

For specific actions, add the header directly in their execute method:

public class YourSpecificAction extends Action {
    @Override
    public ActionForward execute(ActionMapping mapping, ActionForm form,
                                 HttpServletRequest request, HttpServletResponse response)
            throws Exception {
        // Add the header here
        response.setHeader("X-Frame-Options", "sameorigin");
        
        // Your existing action logic
        return mapping.findForward("success");
    }
}
3. Adding in JSP Pages (Per-Page Basis)

If you only need the header on specific JSPs, add this scriptlet at the top of the JSP (right after the page directive):

<%@ page language="java" contentType="text/html; charset=UTF-8" pageEncoding="UTF-8"%>
<%
    // Add X-Frame-Options header
    response.setHeader("X-Frame-Options", "sameorigin");
%>
<!-- Rest of your JSP content -->

Quick Recommendation

Stick with the web.xml container descriptor (Option A) if you're using WebLogic exclusively—it's the simplest and most maintainable. The filter approach works if you need to run on other containers later.

内容的提问来源于stack exchange,提问作者user7491136

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 08:07:02