diff --git a/bonus-common/bonus-common-security/src/main/java/com/bonus/common/security/interceptor/ParamSecureHandler.java b/bonus-common/bonus-common-security/src/main/java/com/bonus/common/security/interceptor/ParamSecureHandler.java index 892f701..11e2fe2 100644 --- a/bonus-common/bonus-common-security/src/main/java/com/bonus/common/security/interceptor/ParamSecureHandler.java +++ b/bonus-common/bonus-common-security/src/main/java/com/bonus/common/security/interceptor/ParamSecureHandler.java @@ -52,8 +52,10 @@ public class ParamSecureHandler implements AsyncHandlerInterceptor { } XssRequestWrapper requestWrapper = new XssRequestWrapper(request); String requestUrl = requestWrapper.getRequestURI(); - if("/operlog/addLogs".equals(requestUrl) || "/autoPractice/submitAnswe".equals(requestUrl) - || "/learningTask/updateQuestionAnswer".equals(requestUrl) || "/learningTask/updateAnswer".equals(requestUrl) ){ + if("/operlog/addLogs".equals(requestUrl) || "/autoPractice/submitAnswer".equals(requestUrl) + || "/learningTask/updateQuestionAnswer".equals(requestUrl) || "/learningTask/updateAnswer".equals(requestUrl) + || "/webAutoPractice/webSubmitAnswer".equals(requestUrl) || "/learningTask/updateQuestionAnswe".equals(requestUrl) + ){ return true; } /**