xss修改
This commit is contained in:
@@ -109,6 +109,7 @@ public class XssRequestWrapper extends HttpServletRequestWrapper {
|
||||
String str = StringEscapeUtils.escapeHtml(cr.getCleanHTML());
|
||||
str = str.replaceAll((antiSamy.scan(" ", policy)).getCleanHTML(), "");
|
||||
str = StringEscapeUtils.unescapeHtml(str);
|
||||
str = str.replaceAll(""", "\"");
|
||||
log.info("xssfilter value after xssClean:" + str);
|
||||
return str;
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user