Authored by 张帅

xss转义

@@ -7,6 +7,7 @@ import com.yohobuy.platform.dal.grass.IGrassTopicDAO; @@ -7,6 +7,7 @@ import com.yohobuy.platform.dal.grass.IGrassTopicDAO;
7 import com.yohobuy.platform.dal.grass.IGrassTopicGroupDAO; 7 import com.yohobuy.platform.dal.grass.IGrassTopicGroupDAO;
8 import com.yohobuy.platform.dal.grass.model.TopicGroup; 8 import com.yohobuy.platform.dal.grass.model.TopicGroup;
9 import com.yohobuy.platform.grass.service.ITopicGroupService; 9 import com.yohobuy.platform.grass.service.ITopicGroupService;
  10 +import com.yohobuy.platform.grass.util.HtmlUtils;
10 import com.yohobuy.platform.model.common.ApiResponse; 11 import com.yohobuy.platform.model.common.ApiResponse;
11 import com.yohobuy.platform.model.common.PageResponseVO; 12 import com.yohobuy.platform.model.common.PageResponseVO;
12 import com.yohobuy.platform.model.grass.request.TopicGroupReq; 13 import com.yohobuy.platform.model.grass.request.TopicGroupReq;
@@ -59,7 +60,7 @@ public class TopicGroupServiceImpl implements ITopicGroupService { @@ -59,7 +60,7 @@ public class TopicGroupServiceImpl implements ITopicGroupService {
59 Integer id = req.getId(); 60 Integer id = req.getId();
60 TopicGroup record = new TopicGroup(); 61 TopicGroup record = new TopicGroup();
61 record.setId(id); 62 record.setId(id);
62 - record.setGroupName(req.getGroupName()); 63 + record.setGroupName(HtmlUtils.translate(req.getGroupName()));
63 record.setStatus(req.getStatus()); 64 record.setStatus(req.getStatus());
64 record.setImageUrl(req.getImageUrl() == null ? "" : req.getImageUrl()); 65 record.setImageUrl(req.getImageUrl() == null ? "" : req.getImageUrl());
65 if(id != null && id > 0 ){//修改 66 if(id != null && id > 0 ){//修改