浏览代码

修复xss

laowo 4 年之前
父节点
当前提交
bc1ff01d43

+ 1 - 1
WebRoot/view/maintenanceplan/scripts/maintenanceplan.js

@@ -899,7 +899,7 @@ Ext.onReady(function(){
 	 
 	 var piedarHtml_fun = function(){
 		   var query = new Object();
-		   // query.V_LOGINNAME = $("#V_LOGINNAME").val();
+		    query.V_LOGINNAME = $("#V_LOGINNAME").val();
 		   $.ajax({
 		          type:'POST',
 		          url: baseUrl+"iot/planteam/getzrrList",

+ 1 - 1
WebRoot/view/patrolplan/scripts/patrolplan.js

@@ -952,7 +952,7 @@ Ext.onReady(function(){
 	 
 	 var piedarHtml_fun = function(){
 		   var query = new Object();
-		   // query.V_LOGINNAME = $("#V_LOGINNAME").val();
+		    query.V_LOGINNAME = $("#V_LOGINNAME").val();
 		   $.ajax({
 		          type:'POST',
 		          url: baseUrl+"iot/planteam/getzrrList1",

+ 41 - 39
WebRoot/view/springhandle/index.jsp

@@ -1,54 +1,56 @@
 <%@ page language="java" contentType="text/html; charset=UTF-8"
-    pageEncoding="UTF-8"%>
+         pageEncoding="UTF-8" %>
 <%@ page session="true" %>
 <%
     String path = request.getContextPath();
-    String basePath = request.getScheme()+"://"+request.getServerName()+":"+request.getServerPort()+path+"/";
-    String baseUrl = request.getScheme()+"://"+request.getServerName()+":"+request.getServerPort()+"/";
+    String basePath = request.getScheme() + "://" + request.getServerName() + ":" + request.getServerPort() + path + "/";
+    String baseUrl = request.getScheme() + "://" + request.getServerName() + ":" + request.getServerPort() + "/";
     String t = String.valueOf(System.currentTimeMillis());
     String theme = request.getParameter("theme");
     String css_name = "ext-all-access.css";
-    if(theme!=null){
-    	if(theme.equals("gray"))
-    		css_name = "ext-all-gray.css";
-    	else if(theme.equals("access"))
-    		css_name = "ext-all-access.css";
-    	else if(theme.equals("neptune"))
-    		css_name = "ext-neptune.css";
-    	else if(theme.equals("default"))
-    		css_name = "ext-all.css";
-    	else if(theme.equals("scoped"))
-    		css_name = "ext-all-scoped";
-    	else if(theme.equals("ie"))
-    		css_name = "ext-ie.css";
-    	else if(theme.equals("sandbox"))
-    		css_name = "ext-sandbox.css";
-    	else if(theme.equals("standard"))
-    		css_name = "ext-standard.css";
-    	else {
-    		theme="";
-		}
+    if (theme != null) {
+        if (theme.equals("gray"))
+            css_name = "ext-all-gray.css";
+        else if (theme.equals("access"))
+            css_name = "ext-all-access.css";
+        else if (theme.equals("neptune"))
+            css_name = "ext-neptune.css";
+        else if (theme.equals("default"))
+            css_name = "ext-all.css";
+        else if (theme.equals("scoped"))
+            css_name = "ext-all-scoped";
+        else if (theme.equals("ie"))
+            css_name = "ext-ie.css";
+        else if (theme.equals("sandbox"))
+            css_name = "ext-sandbox.css";
+        else if (theme.equals("standard"))
+            css_name = "ext-standard.css";
+        else {
+            theme = "";
+        }
+    } else {
+        theme = "";
     }
 %>
 <!DOCTYPE html>
 <html>
 <head>
-<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
-<link type="text/css" rel="stylesheet" href="<%=basePath+"res/extjs/resources/css/"+css_name %>"/>
-<link type="text/css" rel="stylesheet" href="<%=basePath+"res/img/myImages.css?" %>"/>
-<link type="text/css" rel="stylesheet" href="<%=basePath+"res/img/myImages.css?" %>"/>
-<script type="text/javascript" src="<%=basePath+"res/jquery/jquery-3.3.1.min.js" %>"></script>
-<script type="text/javascript" src="<%=basePath+"res/jquery/laydate.js" %>"></script>
-<script type="text/javascript" src ="<%=basePath+"res/extjs/ext-all.js" %>"></script>
-<script type="text/javascript" src ="<%=basePath+"res/extjs/locale/ext-lang-zh_CN.js" %>"></script>
-<script type="text/javascript" src="<%=basePath+"res/jquery/html2canvas.min.js" %>"></script>
-<script type="text/javascript" src="<%=basePath+"res/jquery/canvas2image.js" %>"></script>
-<script type="text/javascript" src="<%=basePath+"res/jquery/base64.js" %>"></script>
-<script type="text/javascript" src="<%=basePath+"res/jquery/echarts.simple.min.js" %>"></script>
-<script type="text/javascript" src="<%=basePath+"res/jquery/highcharts.js"%>"></script>
-<script type="text/javascript" src="<%=basePath+"res/jquery/exporting.js" %>"></script>
-<script type="text/javascript" src ="<%=basePath+"view/springhandle/scripts/springHandle.js?" %>"></script>
-<title>事件处理管理</title>
+    <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
+    <link type="text/css" rel="stylesheet" href="<%=basePath+"res/extjs/resources/css/"+css_name %>"/>
+    <link type="text/css" rel="stylesheet" href="<%=basePath+"res/img/myImages.css?" %>"/>
+    <link type="text/css" rel="stylesheet" href="<%=basePath+"res/img/myImages.css?" %>"/>
+    <script type="text/javascript" src="<%=basePath+"res/jquery/jquery-3.3.1.min.js" %>"></script>
+    <script type="text/javascript" src="<%=basePath+"res/jquery/laydate.js" %>"></script>
+    <script type="text/javascript" src="<%=basePath+"res/extjs/ext-all.js" %>"></script>
+    <script type="text/javascript" src="<%=basePath+"res/extjs/locale/ext-lang-zh_CN.js" %>"></script>
+    <script type="text/javascript" src="<%=basePath+"res/jquery/html2canvas.min.js" %>"></script>
+    <script type="text/javascript" src="<%=basePath+"res/jquery/canvas2image.js" %>"></script>
+    <script type="text/javascript" src="<%=basePath+"res/jquery/base64.js" %>"></script>
+    <script type="text/javascript" src="<%=basePath+"res/jquery/echarts.simple.min.js" %>"></script>
+    <script type="text/javascript" src="<%=basePath+"res/jquery/highcharts.js"%>"></script>
+    <script type="text/javascript" src="<%=basePath+"res/jquery/exporting.js" %>"></script>
+    <script type="text/javascript" src="<%=basePath+"view/springhandle/scripts/springHandle.js?" %>"></script>
+    <title>事件处理管理</title>
 </head>
 <body>
 <input type="hidden" id="theme" name="theme" value="<%=theme %>"/>