mirror of
https://gitee.com/zoujingli/ThinkAdmin.git
synced 2025-08-07 14:19:46 +08:00
修复session变量xss问题
This commit is contained in:
parent
4cc07b238a
commit
5e7c232500
@ -54,8 +54,8 @@
|
|||||||
<dd lay-unselect><a data-load="{:url('admin/login/out')}" data-confirm="确定要退出登录吗?"><i class="layui-icon layui-icon-release"></i> 退出登录</a></dd>
|
<dd lay-unselect><a data-load="{:url('admin/login/out')}" data-confirm="确定要退出登录吗?"><i class="layui-icon layui-icon-release"></i> 退出登录</a></dd>
|
||||||
</dl>
|
</dl>
|
||||||
<a class="layui-elip">
|
<a class="layui-elip">
|
||||||
<img alt="headimg" src="{:session('user.headimg')?:'__ROOT__/static/theme/img/headimg.png'}">
|
<img alt="headimg" src="{:htmlentities(session('user.headimg')?:'__ROOT__/static/theme/img/headimg.png')}">
|
||||||
<span>{:session('user.nickname')?:session('user.username')}</span>
|
<span>{:htmlentities(session('user.nickname')?:session('user.username'))}</span>
|
||||||
</a>
|
</a>
|
||||||
</li>
|
</li>
|
||||||
{else}
|
{else}
|
||||||
|
Loading…
x
Reference in New Issue
Block a user