From f846c66a2a5b752270117d614053797706e81268 Mon Sep 17 00:00:00 2001 From: wangxiang <1827945911@qq.com> Date: Thu, 26 Oct 2023 16:21:59 +0800 Subject: [PATCH] chore: xss --- .../workflow/config/WebSecurityConfig.java | 30 +++++++++++++++++++ 1 file changed, 30 insertions(+) create mode 100644 kicc-platform/kicc-platform-biz/kicc-workflow-biz/src/main/java/com/cloud/kicc/workflow/config/WebSecurityConfig.java diff --git a/kicc-platform/kicc-platform-biz/kicc-workflow-biz/src/main/java/com/cloud/kicc/workflow/config/WebSecurityConfig.java b/kicc-platform/kicc-platform-biz/kicc-workflow-biz/src/main/java/com/cloud/kicc/workflow/config/WebSecurityConfig.java new file mode 100644 index 00000000..53e2dd63 --- /dev/null +++ b/kicc-platform/kicc-platform-biz/kicc-workflow-biz/src/main/java/com/cloud/kicc/workflow/config/WebSecurityConfig.java @@ -0,0 +1,30 @@ +package com.cloud.kicc.workflow.config; + +import lombok.RequiredArgsConstructor; +import org.springframework.context.annotation.Configuration; +import org.springframework.security.config.annotation.web.builders.WebSecurity; +import org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter; +import org.springframework.security.web.firewall.StrictHttpFirewall; + +/** + *

+ * 安全相关配置 + *

+ * + * @Author: wangxiang4 + * @Since: 2023/10/26 + */ +@Configuration +@RequiredArgsConstructor +public class WebSecurityConfig extends WebSecurityConfigurerAdapter { + + @Override + public void configure(WebSecurity web) throws Exception { + super.configure(web); + StrictHttpFirewall strictHttpFirewall = new StrictHttpFirewall(); + strictHttpFirewall.setAllowSemicolon(true); + web.httpFirewall(strictHttpFirewall); + } + + +}