From a2a1f2a22db7c2e53275359fb5f8d6c0dd15d8d6 Mon Sep 17 00:00:00 2001 From: kongzy <kongzy> Date: 星期五, 09 八月 2024 16:25:58 +0800 Subject: [PATCH] update --- assess-admin/src/main/resources/application.yml | 30 ++++++++++++++---------------- 1 files changed, 14 insertions(+), 16 deletions(-) diff --git a/assess-admin/src/main/resources/application.yml b/assess-admin/src/main/resources/application.yml index 9ae7cd4..64b5108 100644 --- a/assess-admin/src/main/resources/application.yml +++ b/assess-admin/src/main/resources/application.yml @@ -2,14 +2,14 @@ application: name: assess_admin profiles: - active: dev + active: pro servlet: multipart: enabled: true # 单个文件大小 - max-file-size: 10MB + max-file-size: 50MB # 设置总上传的文件大小 - max-request-size: 20MB + max-request-size: 100MB mvc: pathmatch: matching-strategy: ant_path_matcher @@ -19,16 +19,6 @@ servlet: context-path: /api -#shiro配置 -#shiro: -# sessionManager: -# sessionIdCookieEnabled: true -# sessionIdUrlRewritingEnabled: true -# unauthorizedUrl: /unauthorizedurl -# web: -# enabled: true -# successUrl: /index -# loginUrl: /account/login # 用户配置 user: @@ -38,6 +28,14 @@ image: - root_path: upload - upload_image: upload/images - upload_file: upload/documents + upload_path: upload + + +# 防止XSS攻击 +xss: + # 过滤开关 + enabled: true + # 排除链接(多个用逗号分隔) + excludes: + # 匹配链接 + urlPatterns: /system/*,/manage/* -- Gitblit v1.9.2