Introduction - If you have any usage issues, please Google them yourself
The backstage management authority the original validate permissions control mechanism, not like the traditional program using a username as the authority to determine the standard, but the use of a random string as the criteria, the intruders even tampered with the session or cookie value also is unable to obtain the permission.
4. In the background the content of all HTML characters are escaped, and in some places (such as information release system) support for HTML, prevent submit embedded web framework and VBScript, JavaScript, ASP, PHP and other scripts.