mirror of
https://gitee.com/zoujingli/ThinkAdmin.git
synced 2025-05-21 22:39:16 +08:00
修改微信关键词xss过滤,只允许a标签
This commit is contained in:
parent
416b2af237
commit
d7a9fc09a7
@ -169,6 +169,7 @@ class Keys extends Controller
|
|||||||
if (WechatKeys::mk()->where($map)->count() > 0) {
|
if (WechatKeys::mk()->where($map)->count() > 0) {
|
||||||
$this->error('该关键字已经存在!');
|
$this->error('该关键字已经存在!');
|
||||||
}
|
}
|
||||||
|
$data['content'] = strip_tags($data['content'], '<a>');
|
||||||
} elseif ($this->request->isGet()) {
|
} elseif ($this->request->isGet()) {
|
||||||
$public = dirname($this->request->basefile(true));
|
$public = dirname($this->request->basefile(true));
|
||||||
$this->defaultImage = "{$public}/static/theme/img/image.png";
|
$this->defaultImage = "{$public}/static/theme/img/image.png";
|
||||||
|
@ -4,6 +4,6 @@
|
|||||||
<div class="header"><span>{:date('H:i')}</span></div>
|
<div class="header"><span>{:date('H:i')}</span></div>
|
||||||
<div class="container">
|
<div class="container">
|
||||||
<div class="logo">Ta</div>
|
<div class="logo">Ta</div>
|
||||||
<div class="content arrow">{$content|default=''}</div>
|
<div class="content arrow">{$content|raw|default=''}</div>
|
||||||
</div>
|
</div>
|
||||||
{/block}
|
{/block}
|
Loading…
x
Reference in New Issue
Block a user