【发布时间】:2019-02-07 21:22:12
【问题描述】:
如何在嵌入式 tomcat 中禁用 http://localhost:9092 级别的 OPTIONS 和 TRACE http 方法? 我使用 ZAP 安全工具进行测试,我的请求是--
OPTIONS http://localhost:9092 HTTP/1.1
Proxy-Connection: keep-alive
Upgrade-Insecure-Requests: 1
User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,image/apng,*/*;q=0.8
Accept-Language: en-gb
Content-Length: 0
Host: localhost:9092
我收到回复了-
HTTP/1.1 404
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Pragma: no-cache
Expires: 0
X-XSS-Protection: 1; mode=block
X-Frame-Options: SAMEORIGIN
X-Content-Type-Options: nosniff
Allow: GET, HEAD, POST, PUT, DELETE, TRACE, OPTIONS, PATCH
我想禁用响应中的允许行
提前致谢
【问题讨论】:
标签: java spring-boot spring-security tomcat8 http-method