mirror of
https://github.com/chatopera/cosin.git
synced 2025-06-16 18:30:03 +08:00
fix 任意文件读取
Signed-off-by: fntr <2292534337@qq.com>
This commit is contained in:
parent
5a92f2776f
commit
db8f2c1d35
@ -166,7 +166,7 @@ public class MediaController extends Handler {
|
||||
@RequestMapping("/template")
|
||||
@Menu(type = "resouce", subtype = "template")
|
||||
public void template(HttpServletResponse response, HttpServletRequest request, @Valid String filename) throws IOException {
|
||||
if (StringUtils.isNotBlank(filename)) {
|
||||
if (StringUtils.isNotBlank(filename) && !(filename.contains("../") || filename.contains("..\\"))) {
|
||||
InputStream is = MediaController.class.getClassLoader().getResourceAsStream(TEMPLATE_DATA_PATH + filename);
|
||||
if (is != null) {
|
||||
response.setContentType("text/plain");
|
||||
|
Loading…
x
Reference in New Issue
Block a user