mirror of
https://github.com/jeecgboot/JeecgBoot.git
synced 2026-08-25 14:19:04 +00:00
BUG JeecgBoot权限绕过与SQL注入组合漏洞(LDYVUL- 2026-00170236) #9840
This commit is contained in:
parent
6589fae6ae
commit
72ce07576c
@ -45,6 +45,25 @@ import java.util.*;
|
|||||||
@Slf4j
|
@Slf4j
|
||||||
@Configuration
|
@Configuration
|
||||||
public class ShiroConfig {
|
public class ShiroConfig {
|
||||||
|
//update-begin---author:scott ---date:2026-08-24 for:【issues/9840】静态资源按目录放行,避免业务接口通过伪造文件后缀绕过JWT-----------
|
||||||
|
private static final String[] ANONYMOUS_STATIC_RESOURCE_PATHS = {
|
||||||
|
// 基础入口
|
||||||
|
"/", "/index.html", "/doc.html", "/favicon.ico", "/logo.png", "/pca.json", "/demo1.html",
|
||||||
|
// Vue3前端构建资源
|
||||||
|
"/manifest.webmanifest", "/sw.js", "/workbox-*.js", "/assets/**", "/resource/**",
|
||||||
|
"/static/**", "/css/**", "/js/**", "/img/**", "/fonts/**",
|
||||||
|
// 系统内置静态页面
|
||||||
|
"/generic/**", "/view/userlist.html",
|
||||||
|
// 开源Demo大屏模板
|
||||||
|
"/bigscreen/template1/**", "/bigscreen/template2/**",
|
||||||
|
// 积木报表
|
||||||
|
"/jmreport/desreport_/**",
|
||||||
|
// 积木BI仪表盘、大屏
|
||||||
|
"/drag/favicon.ico", "/drag/lib/**", "/drag/list/**",
|
||||||
|
// Chat2BI
|
||||||
|
"/chat2bi/**", "/jimu/chat2bi/css/**", "/jimu/chat2bi/js/**","/jimu/chat2bi/libs/**", "/jimu/chat2bi/logo.png"
|
||||||
|
};
|
||||||
|
//update-end---author:scott ---date:2026-08-24 for:【issues/9840】静态资源按目录放行,避免业务接口通过伪造文件后缀绕过JWT-----------
|
||||||
|
|
||||||
@Resource
|
@Resource
|
||||||
private LettuceConnectionFactory lettuceConnectionFactory;
|
private LettuceConnectionFactory lettuceConnectionFactory;
|
||||||
@ -104,31 +123,14 @@ public class ShiroConfig {
|
|||||||
|
|
||||||
//filterChainDefinitionMap.put("/sys/common/view/**", "anon");//图片预览不限制token
|
//filterChainDefinitionMap.put("/sys/common/view/**", "anon");//图片预览不限制token
|
||||||
//filterChainDefinitionMap.put("/sys/common/download/**", "anon");//文件下载不限制token
|
//filterChainDefinitionMap.put("/sys/common/download/**", "anon");//文件下载不限制token
|
||||||
filterChainDefinitionMap.put("/generic/**", "anon");//pdf预览需要文件
|
|
||||||
|
|
||||||
filterChainDefinitionMap.put("/sys/getLoginQrcode/**", "anon"); //登录二维码
|
filterChainDefinitionMap.put("/sys/getLoginQrcode/**", "anon"); //登录二维码
|
||||||
filterChainDefinitionMap.put("/sys/getQrcodeToken/**", "anon"); //监听扫码
|
filterChainDefinitionMap.put("/sys/getQrcodeToken/**", "anon"); //监听扫码
|
||||||
filterChainDefinitionMap.put("/sys/checkAuth", "anon"); //授权接口排除
|
filterChainDefinitionMap.put("/sys/checkAuth", "anon"); //授权接口排除
|
||||||
filterChainDefinitionMap.put("/openapi/call/**", "anon"); // 开放平台接口排除
|
filterChainDefinitionMap.put("/openapi/call/**", "anon"); // 开放平台接口排除
|
||||||
|
|
||||||
// 代码逻辑说明: 排除静态资源后缀
|
//update-begin---author:scott ---date:2026-08-24 for:【issues/9840】禁止按URL后缀全局放行静态资源-----------
|
||||||
filterChainDefinitionMap.put("/", "anon");
|
addAnonymousStaticResourcePaths(filterChainDefinitionMap);
|
||||||
filterChainDefinitionMap.put("/doc.html", "anon");
|
//update-end---author:scott ---date:2026-08-24 for:【issues/9840】禁止按URL后缀全局放行静态资源-----------
|
||||||
filterChainDefinitionMap.put("/**/*.js", "anon");
|
|
||||||
filterChainDefinitionMap.put("/**/*.css", "anon");
|
|
||||||
filterChainDefinitionMap.put("/**/*.html", "anon");
|
|
||||||
filterChainDefinitionMap.put("/**/*.svg", "anon");
|
|
||||||
filterChainDefinitionMap.put("/**/*.pdf", "anon");
|
|
||||||
filterChainDefinitionMap.put("/**/*.jpg", "anon");
|
|
||||||
filterChainDefinitionMap.put("/**/*.png", "anon");
|
|
||||||
filterChainDefinitionMap.put("/**/*.gif", "anon");
|
|
||||||
filterChainDefinitionMap.put("/**/*.ico", "anon");
|
|
||||||
filterChainDefinitionMap.put("/**/*.ttf", "anon");
|
|
||||||
filterChainDefinitionMap.put("/**/*.woff", "anon");
|
|
||||||
filterChainDefinitionMap.put("/**/*.woff2", "anon");
|
|
||||||
|
|
||||||
filterChainDefinitionMap.put("/**/*.glb", "anon");
|
|
||||||
filterChainDefinitionMap.put("/**/*.wasm", "anon");
|
|
||||||
|
|
||||||
filterChainDefinitionMap.put("/druid/**", "anon");
|
filterChainDefinitionMap.put("/druid/**", "anon");
|
||||||
filterChainDefinitionMap.put("/swagger-ui.html", "anon");
|
filterChainDefinitionMap.put("/swagger-ui.html", "anon");
|
||||||
@ -143,8 +145,6 @@ public class ShiroConfig {
|
|||||||
|
|
||||||
//积木报表排除
|
//积木报表排除
|
||||||
filterChainDefinitionMap.put("/jmreport/**", "anon");
|
filterChainDefinitionMap.put("/jmreport/**", "anon");
|
||||||
filterChainDefinitionMap.put("/**/*.js.map", "anon");
|
|
||||||
filterChainDefinitionMap.put("/**/*.css.map", "anon");
|
|
||||||
|
|
||||||
//积木BI大屏和仪表盘排除
|
//积木BI大屏和仪表盘排除
|
||||||
filterChainDefinitionMap.put("/drag/view", "anon");
|
filterChainDefinitionMap.put("/drag/view", "anon");
|
||||||
@ -164,8 +164,6 @@ public class ShiroConfig {
|
|||||||
|
|
||||||
//大屏模板例子
|
//大屏模板例子
|
||||||
filterChainDefinitionMap.put("/test/bigScreen/**", "anon");
|
filterChainDefinitionMap.put("/test/bigScreen/**", "anon");
|
||||||
filterChainDefinitionMap.put("/bigscreen/template1/**", "anon");
|
|
||||||
filterChainDefinitionMap.put("/bigscreen/template2/**", "anon");
|
|
||||||
//filterChainDefinitionMap.put("/test/jeecgDemo/rabbitMqClientTest/**", "anon"); //MQ测试
|
//filterChainDefinitionMap.put("/test/jeecgDemo/rabbitMqClientTest/**", "anon"); //MQ测试
|
||||||
//filterChainDefinitionMap.put("/test/jeecgDemo/html", "anon"); //模板页面
|
//filterChainDefinitionMap.put("/test/jeecgDemo/html", "anon"); //模板页面
|
||||||
//filterChainDefinitionMap.put("/test/jeecgDemo/redis/**", "anon"); //redis测试
|
//filterChainDefinitionMap.put("/test/jeecgDemo/redis/**", "anon"); //redis测试
|
||||||
@ -209,6 +207,13 @@ public class ShiroConfig {
|
|||||||
return shiroFilterFactoryBean;
|
return shiroFilterFactoryBean;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
//update-begin---author:scott ---date:2026-08-24 for:【issues/9840】集中维护允许匿名访问的静态资源路径-----------
|
||||||
|
static void addAnonymousStaticResourcePaths(Map<String, String> filterChainDefinitionMap) {
|
||||||
|
for (String path : ANONYMOUS_STATIC_RESOURCE_PATHS) {
|
||||||
|
filterChainDefinitionMap.put(path, "anon");
|
||||||
|
}
|
||||||
|
}
|
||||||
|
//update-end---author:scott ---date:2026-08-24 for:【issues/9840】集中维护允许匿名访问的静态资源路径-----------
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* spring过滤装饰器 <br/>
|
* spring过滤装饰器 <br/>
|
||||||
|
|||||||
Loading…
x
Reference in New Issue
Block a user