Pārlūkot izejas kodu

修改xss逻辑

tianboguang 3 gadi atpakaļ
vecāks
revīzija
26a425377e

+ 2 - 1
platform-common/src/main/java/com/platform/xss/XssHttpServletRequestWrapper.java

@@ -35,7 +35,8 @@ public class XssHttpServletRequestWrapper extends HttpServletRequestWrapper {
     @Override
     public ServletInputStream getInputStream() throws IOException {
         //非json类型,直接返回
-        if (!super.getHeader(HttpHeaders.CONTENT_TYPE).equalsIgnoreCase(MediaType.APPLICATION_JSON_VALUE)) {
+        if (StringUtils.isBlank(super.getHeader(HttpHeaders.CONTENT_TYPE)) ||
+                !super.getHeader(HttpHeaders.CONTENT_TYPE).equalsIgnoreCase(MediaType.APPLICATION_JSON_VALUE)) {
             return super.getInputStream();
         }