|
@@ -83,7 +83,7 @@ public class AdminNewsHandler {
|
|
|
}
|
|
|
|
|
|
// 富文本XSS过滤
|
|
|
- news.setNewsContexts(StaticCacheMemory.XSS.antiXSS(news.getNewsContexts()));
|
|
|
+ //news.setNewsContexts(StaticCacheMemory.XSS.antiXSS(news.getNewsContexts()));
|
|
|
|
|
|
// 检查图片
|
|
|
if (!news.getNewsImage().startsWith("http")) {
|
|
@@ -104,12 +104,12 @@ public class AdminNewsHandler {
|
|
|
|
|
|
// XSS
|
|
|
News obj = newsService.getOne(id);
|
|
|
- obj.setNewsAuthor(XSSHandler.handle(obj.getNewsAuthor(), true, false, false));
|
|
|
- obj.setNewsDesc(XSSHandler.handle(obj.getNewsDesc(), true, false, false));
|
|
|
- obj.setNewsSource(XSSHandler.handle(obj.getNewsSource(), true, false, false));
|
|
|
- obj.setNewsSourceUrl(XSSHandler.handle(obj.getNewsSourceUrl(), true, false, false));
|
|
|
- obj.setNewsTitle(XSSHandler.handle(obj.getNewsTitle(), true, false, false));
|
|
|
- obj.setNewsImage(XSSHandler.handle(obj.getNewsImage(), true, false, false));
|
|
|
+ obj.setNewsAuthor(obj.getNewsAuthor());
|
|
|
+ obj.setNewsDesc(obj.getNewsDesc());
|
|
|
+ obj.setNewsSource(obj.getNewsSource());
|
|
|
+ obj.setNewsSourceUrl(obj.getNewsSourceUrl());
|
|
|
+ obj.setNewsTitle(obj.getNewsTitle());
|
|
|
+ obj.setNewsImage(obj.getNewsImage());
|
|
|
mv.addObject("obj", obj);
|
|
|
return mv;
|
|
|
}
|
|
@@ -133,7 +133,7 @@ public class AdminNewsHandler {
|
|
|
}
|
|
|
|
|
|
// 富文本XSS过滤
|
|
|
- news.setNewsContexts(StaticCacheMemory.XSS.antiXSS(news.getNewsContexts()));
|
|
|
+ //news.setNewsContexts(StaticCacheMemory.XSS.antiXSS(news.getNewsContexts()));
|
|
|
|
|
|
// 检查图片
|
|
|
if (!news.getNewsImage().startsWith("http")) {
|