1. UTF-8 设置
${tomcat.home}/conf/server.xml
2. 禁止目录浏览
${tomcat.home}/conf/web.xml
3. 增加 Admin 控制台用户
${tomcat.home}/conf/tomcat-users.xml
${tomcat.home}/conf/server.xml
<
Connector
port
="8080"
maxThreads ="150" minSpareThreads ="25" maxSpareThreads ="75"
enableLookups ="false" redirectPort ="8443" acceptCount ="100"
debug ="0" connectionTimeout ="20000"
disableUploadTimeout ="true"
URIEncoding ="UTF-8" />
maxThreads ="150" minSpareThreads ="25" maxSpareThreads ="75"
enableLookups ="false" redirectPort ="8443" acceptCount ="100"
debug ="0" connectionTimeout ="20000"
disableUploadTimeout ="true"
URIEncoding ="UTF-8" />
2. 禁止目录浏览
${tomcat.home}/conf/web.xml
<
servlet
>
< servlet-name > default </ servlet-name >
< servlet-class >
org.apache.catalina.servlets.DefaultServlet
</ servlet-class >
< init-param >
< param-name > debug </ param-name >
< param-value > 0 </ param-value >
</ init-param >
< init-param >
< param-name > listings </ param-name >
< param-value > false </ param-value >
</ init-param >
< load-on-startup > 1 </ load-on-startup >
</ servlet >
< servlet-name > default </ servlet-name >
< servlet-class >
org.apache.catalina.servlets.DefaultServlet
</ servlet-class >
< init-param >
< param-name > debug </ param-name >
< param-value > 0 </ param-value >
</ init-param >
< init-param >
< param-name > listings </ param-name >
< param-value > false </ param-value >
</ init-param >
< load-on-startup > 1 </ load-on-startup >
</ servlet >
3. 增加 Admin 控制台用户
${tomcat.home}/conf/tomcat-users.xml
<?
xml version='1.0' encoding='utf-8'
?>
< tomcat-users >
< role rolename ="tomcat" />
< role rolename ="role1" />
< role rolename ="manager"/>
< user username ="admin" password ="admin" roles ="manager"/>
< user username ="tomcat" password ="tomcat" roles ="tomcat" />
< user username ="both" password ="tomcat" roles ="tomcat,role1" />
< user username ="role1" password ="tomcat" roles ="role1" />
</ tomcat-users >
< tomcat-users >
< role rolename ="tomcat" />
< role rolename ="role1" />
< role rolename ="manager"/>
< user username ="admin" password ="admin" roles ="manager"/>
< user username ="tomcat" password ="tomcat" roles ="tomcat" />
< user username ="both" password ="tomcat" roles ="tomcat,role1" />
< user username ="role1" password ="tomcat" roles ="role1" />
</ tomcat-users >