微信支付签名被xss过滤问题处理忽略
This commit is contained in:
parent
59461175d9
commit
dbd35c18b5
@ -35,7 +35,20 @@ public class XssHttpServletRequestWrapper extends HttpServletRequestWrapper {
|
|||||||
*
|
*
|
||||||
* @todo 这里的参数应该更智能些,例如iv,前端的参数包含这两个字母就会放过,这是有问题的
|
* @todo 这里的参数应该更智能些,例如iv,前端的参数包含这两个字母就会放过,这是有问题的
|
||||||
*/
|
*/
|
||||||
private static final String[] IGNORE_FIELD = {"logo", "url", "photo", "intro", "content", "name", "image", "encrypted", "iv", "mail", "privateKey"};
|
private static final String[] IGNORE_FIELD = {
|
||||||
|
"logo",
|
||||||
|
"url",
|
||||||
|
"photo",
|
||||||
|
"intro",
|
||||||
|
"content",
|
||||||
|
"name",
|
||||||
|
"image",
|
||||||
|
"encrypted",
|
||||||
|
"iv",
|
||||||
|
"mail",
|
||||||
|
"privateKey",
|
||||||
|
"Wechatpay",
|
||||||
|
};
|
||||||
|
|
||||||
public XssHttpServletRequestWrapper(HttpServletRequest request) {
|
public XssHttpServletRequestWrapper(HttpServletRequest request) {
|
||||||
super(request);
|
super(request);
|
||||||
|
@ -1,4 +1,4 @@
|
|||||||
package cn.lili.controller.setting;
|
package cn.lili.controller.goods;
|
||||||
|
|
||||||
import cn.lili.common.enums.ResultUtil;
|
import cn.lili.common.enums.ResultUtil;
|
||||||
import cn.lili.common.vo.ResultMessage;
|
import cn.lili.common.vo.ResultMessage;
|
@ -1,4 +1,4 @@
|
|||||||
package cn.lili.controller.setting;
|
package cn.lili.controller.member;
|
||||||
|
|
||||||
import cn.lili.common.enums.ResultUtil;
|
import cn.lili.common.enums.ResultUtil;
|
||||||
import cn.lili.common.security.context.UserContext;
|
import cn.lili.common.security.context.UserContext;
|
Loading…
x
Reference in New Issue
Block a user