diff --git a/bonus-common/pom.xml b/bonus-common/pom.xml index 9e51a60..8ea648a 100644 --- a/bonus-common/pom.xml +++ b/bonus-common/pom.xml @@ -153,6 +153,12 @@ 20231013 + + com.google.guava + guava + 32.1.3-jre + + \ No newline at end of file diff --git a/bonus-framework/src/main/java/com/bonus/framework/interceptor/XssRequestWrapper.java b/bonus-framework/src/main/java/com/bonus/framework/interceptor/XssRequestWrapper.java index 9da844f..2eb3934 100644 --- a/bonus-framework/src/main/java/com/bonus/framework/interceptor/XssRequestWrapper.java +++ b/bonus-framework/src/main/java/com/bonus/framework/interceptor/XssRequestWrapper.java @@ -167,7 +167,7 @@ public class XssRequestWrapper extends HttpServletRequestWrapper { private static final String regex10 = "onload(.*?)="; // 添加安全脚本模式 - public static final String SAFE_SCRIPT_PATTERN = "(\\||;|\\$|'|\\'|0x0d|0x0a|\\%27|\\%3B|<>|\\[\\]|\\(\\)|/|\"|script|alert|svg|confirm|prompt|onload|%3c|%3e|%2b|@|!|img|src)"; + public static final String SAFE_SCRIPT_PATTERN = "(\\||;|\\$|'|\\'|0x0d|0x0a|\\%27|\\%3B|<>|\\[\\]|\\(\\)|\"|script|alert|svg|confirm|prompt|onload|%3c|%3e|%2b|@|!|img|src)"; private String xssClean(String value) { if (value == null) {