Browse Source

2026-03-24

接口优化,不校验xss
master
fengyuan_yang 3 months ago
parent
commit
e5448c0fcb
  1. 6
      src/main/java/com/gaotao/common/xss/XssHttpServletRequestWrapper.java
  2. 1
      src/main/java/com/gaotao/modules/pms/data/QcFAIRecordData.java
  3. 1
      src/main/resources/mapper/pms/QcMapper.xml

6
src/main/java/com/gaotao/common/xss/XssHttpServletRequestWrapper.java

@ -35,8 +35,10 @@ public class XssHttpServletRequestWrapper extends HttpServletRequestWrapper {
@Override @Override
public ServletInputStream getInputStream() throws IOException { public ServletInputStream getInputStream() throws IOException {
//非json类型直接返回
if(!MediaType.APPLICATION_JSON_VALUE.equalsIgnoreCase(super.getHeader(HttpHeaders.CONTENT_TYPE))){
// 对于 application/json 类型的请求直接返回原始流不做全局的正则 XSS 过滤
// 因为直接对整个 JSON 字符串做正则替换会破坏 JSON 结构误删双引号大括号等
String contentType = super.getHeader(HttpHeaders.CONTENT_TYPE);
if (StringUtils.isNotBlank(contentType) && contentType.toLowerCase().contains(MediaType.APPLICATION_JSON_VALUE.toLowerCase())) {
return super.getInputStream(); return super.getInputStream();
} }

1
src/main/java/com/gaotao/modules/pms/data/QcFAIRecordData.java

@ -295,4 +295,5 @@ public class QcFAIRecordData extends QueryPage {
private String customerNo; private String customerNo;
private String customerName; private String customerName;
private Integer detailImageNum; private Integer detailImageNum;
private BigDecimal dhjs;
} }

1
src/main/resources/mapper/pms/QcMapper.xml

@ -970,6 +970,7 @@
a.po_orderNo, a.po_orderNo,
a.po_itemNo, a.po_itemNo,
a.roll_count, a.roll_count,
a.roll_count as dhjs,
dbo.qc_get_order_type(a.site, a.po_orderNo, a.po_itemNo) as orderType, dbo.qc_get_order_type(a.site, a.po_orderNo, a.po_itemNo) as orderType,
a.action_date, a.action_date,
a.action_by, a.action_by,

Loading…
Cancel
Save