From 1a079532e823e78ce35f8fe7f312e37e8cd0f902 Mon Sep 17 00:00:00 2001
From: RuoYi <yzz_ivy@163.com>
Date: Wed, 29 Apr 2020 21:14:12 +0800
Subject: [PATCH] 只对json类型请求构建可重复读取inputStream的request
---
ruoyi/src/main/java/com/ruoyi/common/utils/html/EscapeUtil.java | 4 ++--
1 files changed, 2 insertions(+), 2 deletions(-)
diff --git a/ruoyi/src/main/java/com/ruoyi/common/utils/html/EscapeUtil.java b/ruoyi/src/main/java/com/ruoyi/common/utils/html/EscapeUtil.java
index f6754c4..8989ca1 100644
--- a/ruoyi/src/main/java/com/ruoyi/common/utils/html/EscapeUtil.java
+++ b/ruoyi/src/main/java/com/ruoyi/common/utils/html/EscapeUtil.java
@@ -58,7 +58,7 @@
*/
public static String clean(String content)
{
- return content.replaceAll(RE_HTML_MARK, "");
+ return new HTMLFilter().filter(content);
}
/**
@@ -144,7 +144,7 @@
public static void main(String[] args)
{
- String html = "<script>alert(1);</script>";
+ String html = "alert('11111');";
System.out.println(EscapeUtil.clean(html));
System.out.println(EscapeUtil.escape(html));
System.out.println(EscapeUtil.unescape(html));
--
Gitblit v1.9.2