From a2793c4d5a50f4638a3243f7a94c5ed1c7998968 Mon Sep 17 00:00:00 2001 From: gaowdong Date: Fri, 7 Mar 2025 13:54:10 +0800 Subject: [PATCH] =?UTF-8?q?=E5=AE=89=E5=85=A8=E8=84=9A=E6=9C=AC=E6=A8=A1?= =?UTF-8?q?=E5=BC=8F=20=E5=8E=BB=E6=8E=89;?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- .../src/main/java/com/bonus/common/core/utils/SafeUtil.java | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/bonus-common/bonus-common-core/src/main/java/com/bonus/common/core/utils/SafeUtil.java b/bonus-common/bonus-common-core/src/main/java/com/bonus/common/core/utils/SafeUtil.java index 6a4d2a3..594537e 100644 --- a/bonus-common/bonus-common-core/src/main/java/com/bonus/common/core/utils/SafeUtil.java +++ b/bonus-common/bonus-common-core/src/main/java/com/bonus/common/core/utils/SafeUtil.java @@ -22,7 +22,10 @@ public class SafeUtil { * 安全脚本模式,用于检测脚本注入的正则表达式 * 由于平台中setfilter中使用多个参数时用到&符号,因此未包含&符号 */ - public final static String SAFE_SCRIPT_PATTERN = "(\\||;|\\$|'|\\'|0x0d|0x0a|\\%27|\\%3B)"; +// public final static String SAFE_SCRIPT_PATTERN = "(\\||;|\\$|'|\\'|0x0d|0x0a|\\%27|\\%3B)"; + + public final static String SAFE_SCRIPT_PATTERN = "(\\||\\$|'|\\'|0x0d|0x0a|\\%27|\\%3B)"; + /** * 检查特殊字符的正则表达式