mirror of
https://github.com/dataease/dataease.git
synced 2025-02-23 11:03:04 +08:00
perf: 增强url特殊字符攻击检测
This commit is contained in:
parent
69da2f1cd2
commit
e13a594d45
@ -103,7 +103,7 @@ public class WhitelistUtils {
|
||||
}
|
||||
|
||||
private static void invalidUrl(String requestURI) {
|
||||
if (requestURI.contains("./") || (requestURI.contains(";") && !requestURI.contains("?"))) {
|
||||
if (requestURI.contains("./") || requestURI.contains(".%") || (requestURI.contains(";") && !requestURI.contains("?"))) {
|
||||
DEException.throwException(INTERFACE_ADDRESS_INVALID.code(), String.format("%s [%s]", INTERFACE_ADDRESS_INVALID.message(), requestURI));
|
||||
}
|
||||
}
|
||||
|
Loading…
Reference in New Issue
Block a user