Parcourir la source

xssFilter增加白名单配置

zhouchenglin il y a 6 ans
Parent
commit
fdb9d8584c
1 fichiers modifiés avec 1 ajouts et 1 suppressions
  1. 1 1
      src/main/java/net/chenlin/dp/common/xss/XssFilter.java

+ 1 - 1
src/main/java/net/chenlin/dp/common/xss/XssFilter.java

@@ -25,7 +25,7 @@ public class XssFilter implements Filter {
 		HttpServletRequest httpServletRequest = (HttpServletRequest) request;
 		String servletPath = httpServletRequest.getServletPath();
 		httpServletRequest.getParameterMap();
-		if (!urlExclusion.isEmpty() && urlExclusion.contains(servletPath)) {
+		if (urlExclusion != null && urlExclusion.contains(servletPath)) {
 			chain.doFilter(request, response);
 		} else {
 			chain.doFilter(new XssHttpServletRequestWrapper(httpServletRequest), response);