ã½ã¼ã·ã£ã«æ©è½ã®å®è£ ãªã©å¤é¨ãµã¼ãã¹ã®APIã使ã£ãã¢ããªã±ã¼ã·ã§ã³ãå¢ããä¸ããâ 使ãã¥ããè¨è¨ã®APIãã¯ãéçºè ã«ã¨ã£ã¦ã¯é ã®çãåé¡ã§ã¯ãªãã§ããããï¼ Programable Web注1ä¸ã«æ稿ãããAPIã®ã¯ã¼ã¹ããã©ã¯ãã£ã¹ã«é¢ããè¨äºãå½å å¤ã®éçºè ã®ç®ã«æ¢ã¾ã話é¡ã«ãªã£ã¦ãã¾ãããã®è¨äºã«ããã¨æªãAPIã«è¦ããããã©ã¯ãã£ã¹ã¯æ¬¡ã®ãããªãã®ã ããã§ãã 貧弱ãªã¨ã©ã¼ãã³ããªã³ã° HTTPã®ã«ã¼ã«ãç¡è¦ããREST API è£ã«æ½ãã çã®ãã¼ã¿ã¢ãã«ã®é²åº ã»ãã¥ãªãã£ã®è¤éã ããã¥ã¡ã³ãåããã¦ããªãäºæãã¬ãªãªã¼ã¹ 貧弱ãªãããããã¨ã¯ã¹ããªã¨ã³ã¹ MVCï¼Model-View-Controllerï¼ãã¬ã¼ã ã¯ã¼ã¯ãè¯ãAPIã«ãã¦ãããã¨ããæã込㿠éçºããã°ä½¿ã£ã¦ããããã¨ã¿ãªãã㨠ä¸ååãªãµãã¼ã 貧弱ãªããã¥ã¡ã³ã èªåèªèº«ã®ãµã¼ãã¹ãAPIãå ¬éããå ´
æè¿ã®ã¢ãã³ãªWebãã©ã¦ã¶ããµãã¼ããã¦ãããã»ãã¥ãªãã£ã«é¢é£ããã㪠X- ãªHTTPã¬ã¹ãã³ã¹ããããã¾ã¨ãã¦ã¿ã¾ããããã以å¤ã«ããã£ããæãã¦ãã ããã X-XSS-Protection 0:XSSãã£ã«ã¿ãç¡å¹ã«ããã 1:XSSãã£ã«ã¿ãæå¹ã«ããã XSSãã£ã«ã¿ãæå¹ã«ãããã¨ã§ã¨ã³ãã¦ã¼ã¶ãXSSã®è¢«å®³ã«ããå¯è½æ§ãä½æ¸ããããã¾ãã«èª¤æ¤ç¥ãããã¨ã§ç»é¢ã®è¡¨ç¤ºãä¹±ãããã¨ããããIE8+ãSafariãChrome(å¤å) ã§æå¹ãIEã§ã¯ãX-XSS-Protection: 1; mode=blockãã¨ããæå®ãå¯è½ã 2008/7/2 - IE8 Security Part IV: The XSS FilterBug 27312 â [XSSAuditor] Add support for header X-XSS-Protection X-Content-Ty
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}