diff --git a/bonus-common/pom.xml b/bonus-common/pom.xml index 9e51a60..8ea648a 100644 --- a/bonus-common/pom.xml +++ b/bonus-common/pom.xml @@ -153,6 +153,12 @@ 20231013 + + com.google.guava + guava + 32.1.3-jre + + \ No newline at end of file diff --git a/bonus-framework/src/main/java/com/bonus/framework/interceptor/ParamSecureHandler.java b/bonus-framework/src/main/java/com/bonus/framework/interceptor/ParamSecureHandler.java index e59688a..592c384 100644 --- a/bonus-framework/src/main/java/com/bonus/framework/interceptor/ParamSecureHandler.java +++ b/bonus-framework/src/main/java/com/bonus/framework/interceptor/ParamSecureHandler.java @@ -70,13 +70,13 @@ public class ParamSecureHandler implements AsyncHandlerInterceptor { /** * 校验参数是否合法 */ - /*if (!requestWrapper.isChecked()) { + if (!requestWrapper.isChecked()) { log.error("输入值非法: queryString={}, body={}", StringUtils.defaultString(requestWrapper.getQueryString(), "null"), StringUtils.defaultString(requestWrapper.getReaderParam(), "null")); returnJson(response, "输入值非法", 500); return false; - }*/ + } // System.err.println(JSON.toJSONString(request.getParameterMap())); /** diff --git a/bonus-framework/src/main/java/com/bonus/framework/interceptor/XssRequestWrapper.java b/bonus-framework/src/main/java/com/bonus/framework/interceptor/XssRequestWrapper.java index 9da844f..2eb3934 100644 --- a/bonus-framework/src/main/java/com/bonus/framework/interceptor/XssRequestWrapper.java +++ b/bonus-framework/src/main/java/com/bonus/framework/interceptor/XssRequestWrapper.java @@ -167,7 +167,7 @@ public class XssRequestWrapper extends HttpServletRequestWrapper { private static final String regex10 = "onload(.*?)="; // 添加安全脚本模式 - public static final String SAFE_SCRIPT_PATTERN = "(\\||;|\\$|'|\\'|0x0d|0x0a|\\%27|\\%3B|<>|\\[\\]|\\(\\)|/|\"|script|alert|svg|confirm|prompt|onload|%3c|%3e|%2b|@|!|img|src)"; + public static final String SAFE_SCRIPT_PATTERN = "(\\||;|\\$|'|\\'|0x0d|0x0a|\\%27|\\%3B|<>|\\[\\]|\\(\\)|\"|script|alert|svg|confirm|prompt|onload|%3c|%3e|%2b|@|!|img|src)"; private String xssClean(String value) { if (value == null) {