增加说明
This commit is contained in:
parent
078af06b63
commit
1d317998af
@ -29,7 +29,12 @@ import java.util.Map;
|
|||||||
*/
|
*/
|
||||||
public class XssHttpServletRequestWrapper extends HttpServletRequestWrapper {
|
public class XssHttpServletRequestWrapper extends HttpServletRequestWrapper {
|
||||||
|
|
||||||
private static final String[] ignoreField = {"logo", "url", "photo", "intro", "content", "name", "encrypted", "iv"};
|
|
||||||
|
/**
|
||||||
|
* xss过滤参数
|
||||||
|
* @todo 这里的参数应该更智能些,例如iv,前端的参数包含这两个字母就会放过,这是有问题的
|
||||||
|
*/
|
||||||
|
private static final String[] IGNORE_FIELD = {"logo", "url", "photo", "intro", "content", "name", "encrypted", "iv"};
|
||||||
|
|
||||||
public XssHttpServletRequestWrapper(HttpServletRequest request) {
|
public XssHttpServletRequestWrapper(HttpServletRequest request) {
|
||||||
super(request);
|
super(request);
|
||||||
|
Loading…
x
Reference in New Issue
Block a user