perf: 增强url特殊字符攻击检测

This commit is contained in:
fit2cloud-chenyw 2025-01-22 11:25:45 +08:00 committed by fit2cloud-chenyw
parent 69da2f1cd2
commit e13a594d45

View File

@ -103,7 +103,7 @@ public class WhitelistUtils {
}
private static void invalidUrl(String requestURI) {
if (requestURI.contains("./") || (requestURI.contains(";") && !requestURI.contains("?"))) {
if (requestURI.contains("./") || requestURI.contains(".%") || (requestURI.contains(";") && !requestURI.contains("?"))) {
DEException.throwException(INTERFACE_ADDRESS_INVALID.code(), String.format("%s [%s]", INTERFACE_ADDRESS_INVALID.message(), requestURI));
}
}