Skip to content

Commit

Permalink
fix: 限制 mysql 非法参数
Browse files Browse the repository at this point in the history
  • Loading branch information
jinlong-T committed Jan 18, 2024
1 parent 4890307 commit 4128adf
Showing 1 changed file with 2 additions and 1 deletion.
Expand Up @@ -6,6 +6,7 @@
import org.apache.commons.lang3.StringUtils;
import org.springframework.stereotype.Component;

import java.net.URLDecoder;
import java.util.Arrays;
import java.util.List;

Expand All @@ -25,7 +26,7 @@ public String getJdbc() {
.replace("DATABASE", getDataBase().trim());
} else {
for (String illegalParameter : illegalParameters) {
if (getExtraParams().toLowerCase().contains(illegalParameter.toLowerCase())) {
if (getExtraParams().toLowerCase().contains(illegalParameter.toLowerCase()) || URLDecoder.decode(getExtraParams()).contains(illegalParameter.toLowerCase())) {
DEException.throwException("Illegal parameter: " + illegalParameter);
}
}
Expand Down

0 comments on commit 4128adf

Please sign in to comment.