http://blog.livedoor.jp/dankogai/archives/51512419.html JavaScript ã§å¼ã³åºãã® () ãç ©ããããªãã以ä¸ã®ããã«æ¸ããã®ã§ã¯ãªããã #!/usr/bin/js var fl = { p : 0, valueOf : function(){ return this.p = !this.p; }, toString : valueOf }; print(fl); print(fl); print(fl); print(fl);
TL;DR X-Content-Type-Options X-Frame-Options(XFO) X-XSS-Protection Content-Security-Policy (CSP) Upgrade-Insecure-Requests Strict-Transport-Security (HSTS) Public-Key-Pins (HPKP) è¨å® TL;DR X-Content-Type-Options MIME ã¹ãããã£ã³ã°ã®ç¡å¹å X-Frame-Options(XFO) ãã¬ã¼ã 表示ãå¶éãã¯ãªãã¯ã¸ã£ããã³ã°ãäºé² X-XSS-Protection XSSãã£ã«ã¿ã®æå¹/ç¡å¹ Content-Security-Policy (CSP) XSSãªã©ã®æ»æã軽æ¸ããã»ãã¥ãªãã£ã¬ã¤ã¤ã¼ Strict-Transport-Security (HSTS) HTTP ã®ä»£ãã
ãç¥ãã
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}