mirror of
https://github.com/dataease/dataease.git
synced 2026-05-15 05:22:13 +08:00
perf(X-Pack): 定时报告下载附件错误
This commit is contained in:
committed by
xuwei-fit2cloud
parent
738c169609
commit
1f29ce93b6
@@ -103,7 +103,7 @@ public class WhitelistUtils {
|
||||
}
|
||||
|
||||
private static void invalidUrl(String requestURI) {
|
||||
if (requestURI.contains("./") || requestURI.contains("%") || (requestURI.contains(";") && !requestURI.contains("?"))) {
|
||||
if (requestURI.contains("./") || requestURI.contains(".%") || requestURI.toLowerCase().contains("%2e") || (requestURI.contains(";") && !requestURI.contains("?"))) {
|
||||
DEException.throwException(INTERFACE_ADDRESS_INVALID.code(), String.format("%s [%s]", INTERFACE_ADDRESS_INVALID.message(), requestURI));
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user