From 7161b213a560237be29c687a2feec0311807f8c5 Mon Sep 17 00:00:00 2001 From: sgjj <995959152@qq.com> Date: Thu, 10 Oct 2019 10:42:13 +0800 Subject: [PATCH] xss --- src/main/java/net/mingsoft/config/WebConfig.java | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/src/main/java/net/mingsoft/config/WebConfig.java b/src/main/java/net/mingsoft/config/WebConfig.java index e78a70ac..53da20d9 100644 --- a/src/main/java/net/mingsoft/config/WebConfig.java +++ b/src/main/java/net/mingsoft/config/WebConfig.java @@ -150,7 +150,8 @@ public class WebConfig implements WebMvcConfigurer { FilterRegistrationBean registration = new FilterRegistrationBean(xssFilter); xssFilter.excludes.add(".*file/upload.do"); xssFilter.excludes.add(".*/jsp/editor.do"); - registration.addUrlPatterns("/**"); + xssFilter.excludes.add("/"); + registration.addUrlPatterns("/*"); return registration; }