修复sql的XSS
This commit is contained in:
parent
b64f34a14c
commit
63ce165a74
|
|
@ -139,6 +139,10 @@ public class SalaryFormulaServiceImpl extends Service implements SalaryFormulaSe
|
|||
|
||||
//将select因XSS过滤造成的异常字符转换回来
|
||||
param.setFormula(param.getFormula().replaceAll("select", "select"));
|
||||
param.setFormula(param.getFormula().replaceAll("and", "and"));
|
||||
param.setFormula(param.getFormula().replaceAll("or", "or"));
|
||||
param.setFormula(param.getFormula().replaceAll("in", "in"));
|
||||
param.setFormula(param.getFormula().replaceAll("like", "like"));
|
||||
}
|
||||
|
||||
//试运行公式
|
||||
|
|
|
|||
Loading…
Reference in New Issue