From bc6eaea2b4b2ca14edcc6472f68f6bdd5a82e38b Mon Sep 17 00:00:00 2001 From: zhangxingjia Date: Fri, 7 Apr 2023 19:07:33 +0800 Subject: [PATCH] =?UTF-8?q?fix=20xss=E8=AF=B7=E6=B1=82Wrapper=20getAttribu?= =?UTF-8?q?te=E6=96=B9=E6=B3=95=20=E9=97=AE=E9=A2=98=E4=BF=AE=E5=A4=8D?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- .../yudao/framework/xss/core/filter/XssRequestWrapper.java | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/yudao-framework/yudao-spring-boot-starter-web/src/main/java/cn/iocoder/yudao/framework/xss/core/filter/XssRequestWrapper.java b/yudao-framework/yudao-spring-boot-starter-web/src/main/java/cn/iocoder/yudao/framework/xss/core/filter/XssRequestWrapper.java index 35819f4435..1466a97cc1 100644 --- a/yudao-framework/yudao-spring-boot-starter-web/src/main/java/cn/iocoder/yudao/framework/xss/core/filter/XssRequestWrapper.java +++ b/yudao-framework/yudao-spring-boot-starter-web/src/main/java/cn/iocoder/yudao/framework/xss/core/filter/XssRequestWrapper.java @@ -64,7 +64,7 @@ public class XssRequestWrapper extends HttpServletRequestWrapper { public Object getAttribute(String name) { Object value = super.getAttribute(name); if (value instanceof String) { - xssCleaner.clean((String) value); + return xssCleaner.clean((String) value); } return value; }