cors:
服务器端对于CORS的支持,主要就是通过设置Access-Control-Allow-Origin来进行的。不能设置成*,要设置成信任名单,并且可配置
https://blog.csdn.net/saytime/article/details/51549888
xss和csrf:
http://www.freebuf.com/articles/web/39234.html
架构师:
https://blog.csdn.net/youanyyou/article/details/78990233
md5加密+加盐
https://www.cnblogs.com/peaceliu/p/7825706.html