@@ -0,0 +1,150 @@
+# 是否要打印配置属性,默认为true
+# ESAPI Encoder
+# ESAPI 加密模块
+# ESAPI Http工具
+# Force flags on cookies, if you use HttpUtilities to set cookies
+# Maximum size of HTTP headers
+# File upload configuration
+# Using UTF-8 throughout your stack is highly recommended. That includes your database driver,
+# container, and any other technologies you may be using. Failure to do this may expose you
+# to Unicode transcoding injection attacks. Use of UTF-8 does not hinder internationalization.
+HttpUtilities.ResponseContentType=text/html; charset=UTF-8
+# This is the name of the cookie used to represent the HTTP session
+# Typically this will be the default "JSESSIONID"
+# ESAPI Executor
+# ESAPI Logging
+# Set the application name if these logs are combined with other applications
+# If you use an HTML log viewer that does not properly HTML escape log data, you can set LogEncodingRequired to true
+# Determines whether ESAPI should log the application name. This might be clutter in some single-server/single-app environments.
+# Determines whether ESAPI should log the server IP and port. This might be clutter in some single-server environments.
+# LogFileName, the name of the logging file. Provide a full directory path (e.g., C:\\ESAPI\\ESAPI_logging_file) if you
+# want to place it in a specific directory.
+# MaxLogFileSize, the max size (in bytes) of a single log file before it cuts over to a new one (default is 10,000,000)
+# ESAPI Intrusion Detection
+# ESAPI 校验器
+# Validators used by ESAPI
+#the word TEST below should be changed to your application
+#name - only relative URL's are supported
+# Global HTTP Validation Rules
+# Values with Base64 encoded data (e.g. encrypted state) will need at least [a-zA-Z0-9\/+=]
+Validator.HTTPParameterValue=^[a-zA-Z0-9.\\-\\/+=@_ ]*$
+Validator.HTTPCookieValue=^[a-zA-Z0-9\\-\\/+=_ ]*$
+# Note that max header name capped at 150 in SecurityRequestWrapper!
+Validator.HTTPHeaderValue=^[a-zA-Z0-9()\\-=\\*\\.\\?;,+\\/:&_ ]*$
+Validator.HTTPQueryString=^[a-zA-Z0-9()\\-=\\*\\.\\?;,+\\/:&_ %]*$
+Validator.HTTPURI=^[a-zA-Z0-9()\\-=\\*\\.\\?;,+\\/:&_ ]*$
+# Validation of file related input
+Validator.FileName=^[a-zA-Z0-9!@#$%^&{}\\[\\]()_+\\-=,.~'` ]{1,255}$
+Validator.DirectoryName=^[a-zA-Z0-9:/\\\\!@#$%^&{}\\[\\]()_+\\-=,.~'` ]{1,255}$
+# Validation of dates. Controls whether or not 'lenient' dates are accepted.
+# See DataFormat.setLenient(boolean flag) for further details.