update books.sql and fix xss

This commit is contained in:
xiongxiaoyang
2020-04-23 09:00:05 +08:00
parent 8aa724bd69
commit 9c1d954bfd
3 changed files with 5 additions and 21 deletions

View File

@ -321,7 +321,7 @@ public class BookController {
@ResponseBody
public Map<String, Object> sendBullet(@RequestParam("contentId") Long contentId, @RequestParam("bullet") String bullet) {
Map<String, Object> result = new HashMap<>(2);
bookService.sendBullet(contentId, bullet);
bookService.sendBullet(contentId, bullet.replaceAll("<", "&lt;").replaceAll(">", "&gt;"));
result.put("code", 1);
result.put("desc", "ok");
return result;

View File

@ -195,7 +195,7 @@
}
//发送弹幕
function sendBullet(){
var bullet = $("#screenBulletText").val();
var bullet = $("#screenBulletText").val().replace(/</g, "&lt;").replace(/>/g, "&gt;");
var contentId = $("#contentIdHidden").val();
if (bullet && contentId) {
if(bullet.length > 100){