Alex Rivera | Logout

How do I prevent people from doing XSS in Spring MVC?

Asked 2010-01-27T15:10:56.210
64

What should I do to prevent XSS in Spring MVC? Right now I am just putting all places where I output user text into JSTL <c:out> tags or fn:escapeXml() functions, but this seems error prone as I might miss a place.

Is there an easy systematic way to prevent this? Maybe like a filter or something? I'm collecting input by specifying @RequestParam parameters on my controller methods.

Edit
Report

1 Answer

0

How are you collecting user input in the first place? This question / answer may assist if you're using a FormController:

Spring: escaping input when binding to command

answered 2010-01-27T15:15:24.207

Your Answer