SessionSafeã¯ããã³ãã«ã°å¤§å¦ã®Martin Johnsãããæ¸ããWeb APã®æ¹å¼æ¡ã§ãã ããWeb APã«XSSèå¼±æ§ããã£ã¦ããããæ»æãããã¨ãã¦ãã ã»ãã·ã§ã³IDãçã¾ããªã å½è©²ãã¼ã¸ä»¥å¤ã®æ å ±ãçªåã»æ¹ç«ãããªã ãã¨ãç®æãã¦ãã¾ãã é¢ç½ããªã¼ã¨æã£ãã®ã§ãå 容ã«ã¤ãã¦å°ãæ¸ãã¾ãã ãªããå è¨äºãé«éæãèªã¿ããã®ã§ããã®æ¥è¨ã®å 容ã«ã¯ééããå«ã¾ãã¦ããããããã¾ãããèå³ã®ããæ¹ã¯åæ¬ãè¦ã¦ãã ããã ã»ãã·ã§ã³IDãçã¾ããªã 以ä¸ã®äºã¤ã®ãã¡ã¤ã³ãããã¨ãã¾ãã www.example.com secure.example.com ã»ãã·ã§ã³IDã®Cookieã¯ãsecureãµããã¡ã¤ã³ã«çºè¡ãã¾ãã Webãã¼ã¸ã表示ããéã¯www.example.comã®URLã«ã¢ã¯ã»ã¹ãã¾ããããã§è¿ãHTMLã«è²ã ã¨ä»æããæ½ãã¾ãã HTMLã®ä»æã
{{#tags}}- {{label}}
{{/tags}}