Commit 99470398 by wyc

大小写比对

parent 0b5b8bf8
...@@ -105,7 +105,7 @@ public AntiSqlInjectFilter(IOptions<Application> options) ...@@ -105,7 +105,7 @@ public AntiSqlInjectFilter(IOptions<Application> options)
if (_application.OpenAntiSqlInject == true) if (_application.OpenAntiSqlInject == true)
{ {
var routePath = context.HttpContext.Request.Path.ToString(); var routePath = context.HttpContext.Request.Path.ToString();
if (_application.AntiSqlInjectRouteWhite?.Any(route => route.Equals(routePath)) != true) if (_application.AntiSqlInjectRouteWhite?.Any(route => route.Equals(routePath,StringComparison.OrdinalIgnoreCase)) != true)
{ {
foreach (var value in context.ActionArguments.Where(w => w.Value != null).Select(w => w.Value)) foreach (var value in context.ActionArguments.Where(w => w.Value != null).Select(w => w.Value))
{ {
......
...@@ -15,8 +15,8 @@ ...@@ -15,8 +15,8 @@
"OpenAntiSqlInject": true, "OpenAntiSqlInject": true,
// 开启反SQL注入白名单地址 // 开启反SQL注入白名单地址
"AntiSqlInjectRouteWhite": [ "AntiSqlInjectRouteWhite": [
"account/logins", "/api/account/login",
"account/quick/login" "/api/account/quick/login"
], ],
//登录过期时间 //登录过期时间
"ExpirationMinutes": "1200", "ExpirationMinutes": "1200",
......
...@@ -54,6 +54,11 @@ ...@@ -54,6 +54,11 @@
是否开启反SQL注入 默认关闭 true 开启 false 关闭 是否开启反SQL注入 默认关闭 true 开启 false 关闭
</summary> </summary>
</member> </member>
<member name="P:Performance.DtoModels.AppSettings.Application.AntiSqlInjectRouteWhite">
<summary>
开启反SQL注入白名单地址
</summary>
</member>
<member name="P:Performance.DtoModels.AppSettings.RateLimitingConfig.Endpoints"> <member name="P:Performance.DtoModels.AppSettings.RateLimitingConfig.Endpoints">
<summary> <summary>
路径 路径
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment