Application Security
Het draaien van je app in Java op de server (zie Client en server) bevat hele klassen van webaanvallen voordat je een regel code schrijft. Het haalt echter je verantwoordelijkheden niet weg. Deze pagina's leggen uit waar de grens ligt, wat webforJ voor je afhandelt, waar je verantwoordelijk blijft en hoe je een productie-implementatie veilig houdt.
Voor het beheersen van wie elke weergave kan bereiken, zie de rest van de Beveiliging sectie over authenticatie en autorisatie op routeniveau.
Onderwerpen
Common Threats
How common web threats such as cross-site scripting (XSS), cross-site request forgery (CSRF), and SQL injection apply to a webforJ app, what the framework handles, and where you stay responsible.
Production Hardening
Practical steps for running a webforJ app safely in production, from transport encryption and dependency upkeep to server-side checks and disclosure.
Managing Secrets
Keep database passwords, API keys, and other secrets out of your webforJ source tree and configuration files by resolving them at runtime.