咨询JSP中session.getAttribute()的替代方案及Struts2下XSS防护方法
session.getAttribute() in JSP (Struts2 + XSS Prevention) Hey there! Great question—let's break down how you can avoid direct session.getAttribute() calls in your Struts2 app while also hardening against XSS attacks. The key here is to leverage Struts2's built-in features to keep session access centralized and output safe.
1. Use Struts2's SessionAware Interface & Action Layer
Struts2 encourages keeping session interactions in your Action classes rather than directly in JSPs. This not only cleans up your view layer but also gives you control over how session data is exposed, making it easier to enforce safety checks.
How to implement:
- Make your Action class implement
SessionAware, which injects the session map directly into your Action. - Extract the session data you need into Action properties, then access those properties in your JSP using Struts2 tags (which automatically handle HTML escaping by default).
Example Action code:
public class UserAction extends ActionSupport implements SessionAware { private Map<String, Object> session; private String userName; // Expose this property to JSP @Override public void setSession(Map<String, Object> session) { this.session = session; } public String execute() { // Fetch session data in the Action layer instead of JSP User loggedInUser = (User) session.get("loggedInUser"); this.userName = loggedInUser.getName(); return SUCCESS; } // Getter for the exposed property public String getUserName() { return userName; } }
Example JSP code:
<!-- Uses Struts2's property tag, which escapes HTML by default --> Welcome, <s:property value="userName" />!
2. Access Session via OGNL with Struts2 Tags
If you need to access session data directly in JSP, skip session.getAttribute() and use Struts2's OGNL expression language with <s:property> tags. This approach still ensures HTML escaping is applied automatically, eliminating raw output risks.
Example JSP code:
<!-- Safe alternative to session.getAttribute("userEmail") --> Your registered email: <s:property value="#session.userEmail" />
Unlike scriptlets (<%= session.getAttribute("userEmail") %>), which spit out raw data and leave you vulnerable to XSS, the <s:property> tag escapes special characters like <, >, and " to neutralize malicious scripts.
3. Wrap Session Data in a Custom Context Object
For better organization and reduced session clutter, wrap all your session-related data (like user info, app preferences) into a single custom object (e.g., UserSessionContext). Store this object in the session once, then access it through your Action layer.
Example:
// Custom context class to encapsulate session data public class UserSessionContext { private String userId; private String userName; // Add other session properties + getters/setters } // In your login Action: public String login() { UserSessionContext context = new UserSessionContext(); context.setUserId("user_123"); context.setUserName("JaneDoe"); session.put("userContext", context); return SUCCESS; } // In your profile Action: public String profile() { UserSessionContext context = (UserSessionContext) session.get("userContext"); this.userName = context.getUserName(); return SUCCESS; }
Then in JSP, access the exposed Action property as before with <s:property>. This reduces direct session access and makes your code more maintainable long-term.
Critical Note About XSS Prevention
Remember: session.getAttribute() itself isn't the root of XSS attacks—the risk comes from outputting unescaped data to the page. Even with these alternatives, never use scriptlets (<%= %>) to output dynamic content. Stick to Struts2 tags, or manually escape data if you must output it raw (use org.apache.struts2.util.TextUtils.escapeHtml() for this).
内容的提问来源于stack exchange,提问作者Sagar Borkhatariya

