diff --git a/framework/src/main/java/cn/lili/common/security/filter/XssHttpServletRequestWrapper.java b/framework/src/main/java/cn/lili/common/security/filter/XssHttpServletRequestWrapper.java index 013ebba1..a95b9eb4 100644 --- a/framework/src/main/java/cn/lili/common/security/filter/XssHttpServletRequestWrapper.java +++ b/framework/src/main/java/cn/lili/common/security/filter/XssHttpServletRequestWrapper.java @@ -29,7 +29,7 @@ import java.util.Map; */ public class XssHttpServletRequestWrapper extends HttpServletRequestWrapper { - private static final String[] ignoreField = {"logo", "url", "photo", "intro", "content", "name"}; + private static final String[] ignoreField = {"logo", "url", "photo", "intro", "content", "name", "encrypted"}; public XssHttpServletRequestWrapper(HttpServletRequest request) { super(request); diff --git a/framework/src/main/java/cn/lili/modules/connect/serviceimpl/ConnectServiceImpl.java b/framework/src/main/java/cn/lili/modules/connect/serviceimpl/ConnectServiceImpl.java index 8055ddc0..b2c5003c 100644 --- a/framework/src/main/java/cn/lili/modules/connect/serviceimpl/ConnectServiceImpl.java +++ b/framework/src/main/java/cn/lili/modules/connect/serviceimpl/ConnectServiceImpl.java @@ -309,8 +309,10 @@ public class ConnectServiceImpl extends ServiceImpl impl * @return 用户信息 */ public JSONObject getUserInfo(String encryptedData, String sessionKey, String iv) { + + log.info("encryptedData:{},sessionKey:{},iv:{}", encryptedData, sessionKey, iv); //被加密的数据 - byte[] dataByte = Base64.getDecoder().decode(encryptedData.replace("\r\n", "")); + byte[] dataByte = Base64.getDecoder().decode(encryptedData); //加密秘钥 byte[] keyByte = Base64.getDecoder().decode(sessionKey); //偏移量