修改微信关键词xss过滤,只允许a标签

This commit is contained in:
邹景立 2021-09-17 14:48:35 +08:00
parent 416b2af237
commit d7a9fc09a7
2 changed files with 2 additions and 1 deletions

View File

@ -169,6 +169,7 @@ class Keys extends Controller
if (WechatKeys::mk()->where($map)->count() > 0) {
$this->error('该关键字已经存在!');
}
$data['content'] = strip_tags($data['content'], '<a>');
} elseif ($this->request->isGet()) {
$public = dirname($this->request->basefile(true));
$this->defaultImage = "{$public}/static/theme/img/image.png";

View File

@ -4,6 +4,6 @@
<div class="header"><span>{:date('H:i')}</span></div>
<div class="container">
<div class="logo">Ta</div>
<div class="content arrow">{$content|default=''}</div>
<div class="content arrow">{$content|raw|default=''}</div>
</div>
{/block}