mirror of
https://github.com/201206030/novel.git
synced 2025-06-23 23:58:30 +00:00
update books.sql and fix xss
This commit is contained in:
@ -321,7 +321,7 @@ public class BookController {
|
||||
@ResponseBody
|
||||
public Map<String, Object> sendBullet(@RequestParam("contentId") Long contentId, @RequestParam("bullet") String bullet) {
|
||||
Map<String, Object> result = new HashMap<>(2);
|
||||
bookService.sendBullet(contentId, bullet);
|
||||
bookService.sendBullet(contentId, bullet.replaceAll("<", "<").replaceAll(">", ">"));
|
||||
result.put("code", 1);
|
||||
result.put("desc", "ok");
|
||||
return result;
|
||||
|
@ -195,7 +195,7 @@
|
||||
}
|
||||
//发送弹幕
|
||||
function sendBullet(){
|
||||
var bullet = $("#screenBulletText").val();
|
||||
var bullet = $("#screenBulletText").val().replace(/</g, "<").replace(/>/g, ">");
|
||||
var contentId = $("#contentIdHidden").val();
|
||||
if (bullet && contentId) {
|
||||
if(bullet.length > 100){
|
||||
|
Reference in New Issue
Block a user