lyhzzz 3 роки тому
батько
коміт
e26d0c2044

+ 7 - 1
platform-common/src/main/java/com/platform/xss/SQLFilter.java

@@ -28,7 +28,7 @@ public class SQLFilter {
         str = StringUtils.replace(str, "\\", "");
         str = StringUtils.replace(str, "\\", "");
 
 
         //转换成小写
         //转换成小写
-        str = str.toLowerCase();
+        str = humpToLine(str);
 
 
         //非法字符
         //非法字符
         String[] keywords = {"master", "truncate", "insert", "select", "delete", "update", "declare", "alert", "drop"};
         String[] keywords = {"master", "truncate", "insert", "select", "delete", "update", "declare", "alert", "drop"};
@@ -42,4 +42,10 @@ public class SQLFilter {
 
 
         return str;
         return str;
     }
     }
+
+    //驼峰转下划线
+    public static String humpToLine(String str) {
+        return str.replaceAll("[A-Z]", "_$0").toLowerCase();
+    }
+
 }
 }

+ 1 - 1
platform-shop/src/main/java/com/platform/controller/SpecificationController.java

@@ -26,7 +26,7 @@ import java.util.Map;
  * @date 2017-08-13 10:41:10
  * @date 2017-08-13 10:41:10
  */
  */
 @RestController
 @RestController
-@RequestMapping("specification")
+@RequestMapping("/specification")
 public class SpecificationController {
 public class SpecificationController {
     @Autowired
     @Autowired
     private SpecificationService specificationService;
     private SpecificationService specificationService;