Browse Source

IpUtils工具,清除Xss特殊字符,防止Xff注入攻击

Live 4 years ago
parent
commit
19b8688759
1 changed files with 1 additions and 1 deletions
  1. 1 1
      ruoyi/src/main/java/com/ruoyi/common/utils/ip/IpUtils.java

+ 1 - 1
ruoyi/src/main/java/com/ruoyi/common/utils/ip/IpUtils.java

@@ -40,7 +40,7 @@ public class IpUtils
         {
             ip = request.getRemoteAddr();
         }
-
+        ip = EscapeUtil.clean(ip);//清除Xss特殊字符
         return "0:0:0:0:0:0:0:1".equals(ip) ? "127.0.0.1" : ip;
     }