Browse Source

自动识别json对象白名单配置范围缩小

master
RuoYi 7 months ago
parent
commit
191fd29301
  1. 2
      ruoyi-common/src/main/java/com/ruoyi/common/constant/Constants.java

2
ruoyi-common/src/main/java/com/ruoyi/common/constant/Constants.java

@ -158,7 +158,7 @@ public class Constants
/**
* 自动识别json对象白名单配置仅允许解析的包名范围越小越安全
*/
public static final String[] JSON_WHITELIST_STR = { "org.springframework", "com.ruoyi" };
public static final String[] JSON_WHITELIST_STR = { "com.ruoyi" };
/**
* 定时任务白名单配置仅允许访问的包名如其他需要可以自行添加

Loading…
Cancel
Save