From 1a079532e823e78ce35f8fe7f312e37e8cd0f902 Mon Sep 17 00:00:00 2001 From: RuoYi <yzz_ivy@163.com> Date: 星期三, 29 四月 2020 21:14:12 +0800 Subject: [PATCH] 只对json类型请求构建可重复读取inputStream的request --- ruoyi/src/main/java/com/ruoyi/common/utils/html/EscapeUtil.java | 4 ++-- 1 files changed, 2 insertions(+), 2 deletions(-) diff --git a/ruoyi/src/main/java/com/ruoyi/common/utils/html/EscapeUtil.java b/ruoyi/src/main/java/com/ruoyi/common/utils/html/EscapeUtil.java index f6754c4..8989ca1 100644 --- a/ruoyi/src/main/java/com/ruoyi/common/utils/html/EscapeUtil.java +++ b/ruoyi/src/main/java/com/ruoyi/common/utils/html/EscapeUtil.java @@ -58,7 +58,7 @@ */ public static String clean(String content) { - return content.replaceAll(RE_HTML_MARK, ""); + return new HTMLFilter().filter(content); } /** @@ -144,7 +144,7 @@ public static void main(String[] args) { - String html = "<script>alert(1);</script>"; + String html = "alert('11111');"; System.out.println(EscapeUtil.clean(html)); System.out.println(EscapeUtil.escape(html)); System.out.println(EscapeUtil.unescape(html)); -- Gitblit v1.9.2