From aa2d8ac17c1fcd41ca155e7d0e2d8134de949482 Mon Sep 17 00:00:00 2001 From: sgjj <995959152@qq.com> Date: Thu, 10 Oct 2019 10:31:37 +0800 Subject: [PATCH] xss --- .../java/net/mingsoft/config/WebConfig.java | 18 +++++++++--------- 1 file changed, 9 insertions(+), 9 deletions(-) diff --git a/src/main/java/net/mingsoft/config/WebConfig.java b/src/main/java/net/mingsoft/config/WebConfig.java index a2f6edb0..e78a70ac 100644 --- a/src/main/java/net/mingsoft/config/WebConfig.java +++ b/src/main/java/net/mingsoft/config/WebConfig.java @@ -144,15 +144,15 @@ public class WebConfig implements WebMvcConfigurer { return new DefaultPointcutAdvisor(druidStatPointcut(), druidStatInterceptor()); } -// @Bean -// public FilterRegistrationBean xssFilterRegistration() { -// XSSEscapeFilter xssFilter = new XSSEscapeFilter(); -// FilterRegistrationBean registration = new FilterRegistrationBean(xssFilter); -// xssFilter.excludes.add(".*file/upload.do"); -// xssFilter.excludes.add(".*/jsp/editor.do"); -// registration.addUrlPatterns("/**"); -// return registration; -// } + @Bean + public FilterRegistrationBean xssFilterRegistration() { + XSSEscapeFilter xssFilter = new XSSEscapeFilter(); + FilterRegistrationBean registration = new FilterRegistrationBean(xssFilter); + xssFilter.excludes.add(".*file/upload.do"); + xssFilter.excludes.add(".*/jsp/editor.do"); + registration.addUrlPatterns("/**"); + return registration; + } /** * RequestContextListener注册