commit
eb25827937
@ -2,7 +2,6 @@ package cn.lili.common.security.filter;
|
|||||||
|
|
||||||
|
|
||||||
import cn.hutool.core.text.CharSequenceUtil;
|
import cn.hutool.core.text.CharSequenceUtil;
|
||||||
import cn.hutool.http.HtmlUtil;
|
|
||||||
import cn.hutool.json.JSONUtil;
|
import cn.hutool.json.JSONUtil;
|
||||||
import lombok.extern.slf4j.Slf4j;
|
import lombok.extern.slf4j.Slf4j;
|
||||||
import org.owasp.html.Sanitizers;
|
import org.owasp.html.Sanitizers;
|
||||||
@ -48,6 +47,7 @@ public class XssHttpServletRequestWrapper extends HttpServletRequestWrapper {
|
|||||||
"encrypted",
|
"encrypted",
|
||||||
"iv",
|
"iv",
|
||||||
"mail",
|
"mail",
|
||||||
|
"sell",
|
||||||
"privateKey",
|
"privateKey",
|
||||||
"wechatpay",
|
"wechatpay",
|
||||||
};
|
};
|
||||||
@ -267,7 +267,7 @@ public class XssHttpServletRequestWrapper extends HttpServletRequestWrapper {
|
|||||||
private String filterXss(String name, String value) {
|
private String filterXss(String name, String value) {
|
||||||
if (CharSequenceUtil.containsAny(name.toLowerCase(Locale.ROOT), IGNORE_FIELD)) {
|
if (CharSequenceUtil.containsAny(name.toLowerCase(Locale.ROOT), IGNORE_FIELD)) {
|
||||||
// 忽略的处理,(过滤敏感字符)
|
// 忽略的处理,(过滤敏感字符)
|
||||||
return HtmlUtil.unescape(HtmlUtil.filter(value));
|
return value;
|
||||||
} else {
|
} else {
|
||||||
return cleanXSS(value);
|
return cleanXSS(value);
|
||||||
}
|
}
|
||||||
|
@ -81,7 +81,7 @@ public class RefundSupport {
|
|||||||
**/
|
**/
|
||||||
private void updateReturnGoodsNumber(AfterSale afterSale) {
|
private void updateReturnGoodsNumber(AfterSale afterSale) {
|
||||||
//根据商品id及订单sn获取子订单
|
//根据商品id及订单sn获取子订单
|
||||||
OrderItem orderItem = orderItemService.getByOrderSnAndSkuId(afterSale.getOrderSn(), afterSale.getGoodsId());
|
OrderItem orderItem = orderItemService.getByOrderSnAndSkuId(afterSale.getOrderSn(), afterSale.getSkuId());
|
||||||
|
|
||||||
orderItem.setReturnGoodsNumber(afterSale.getNum() + orderItem.getReturnGoodsNumber());
|
orderItem.setReturnGoodsNumber(afterSale.getNum() + orderItem.getReturnGoodsNumber());
|
||||||
|
|
||||||
|
Loading…
x
Reference in New Issue
Block a user