参考https://www.jianshu.com/p/251704d8ff18 实际解决: 加一行,response.addHeader("X-Frame-Options","SAMEORIGIN");