Browse Source

漏洞修复

zjs 1 month ago
parent
commit
2a8ccd0a4c

+ 1 - 3
ruoyi-common/src/main/java/com/ruoyi/common/filter/RestCorsFilter.java

@@ -24,13 +24,11 @@ public class RestCorsFilter implements Filter {
24
         HttpServletResponse response = (HttpServletResponse) res;
24
         HttpServletResponse response = (HttpServletResponse) res;
25
         HttpServletRequest request = (HttpServletRequest) req;
25
         HttpServletRequest request = (HttpServletRequest) req;
26
 
26
 
27
-        String[] allowDomain={"http://10.152.72.7","http://10.152.70.21","http://10.152.72.5"};
27
+        String[] allowDomain={"http://10.152.72.*","http://10.152.70.*"};
28
         Set<String> allowedOrigins=new HashSet<>(Arrays.asList(allowDomain));
28
         Set<String> allowedOrigins=new HashSet<>(Arrays.asList(allowDomain));
29
         String originHeader=request.getHeader("Origin");
29
         String originHeader=request.getHeader("Origin");
30
         if(allowedOrigins.contains(originHeader)){
30
         if(allowedOrigins.contains(originHeader)){
31
             response.setHeader("Access-Control-Allow-Origin",originHeader);
31
             response.setHeader("Access-Control-Allow-Origin",originHeader);
32
-        }else{
33
-            response.setHeader("Access-Control-Allow-Origin","http://10.152.72.7");
34
         }
32
         }
35
         response.setHeader("Access-Control-Allow-Credentials","true");
33
         response.setHeader("Access-Control-Allow-Credentials","true");
36
         response.setHeader("Access-Control-Allow-Methods", "POST, GET,DELETE,PUT");
34
         response.setHeader("Access-Control-Allow-Methods", "POST, GET,DELETE,PUT");