Browse Source

根据文件名后缀判断是否安全文件

sdxiaomu 2 years ago
parent
commit
577ccd4632
1 changed files with 1 additions and 0 deletions
  1. 1 0
      src/main/java/com/jfinal/upload/ProgressUploadFileKit.java

+ 1 - 0
src/main/java/com/jfinal/upload/ProgressUploadFileKit.java

@@ -77,6 +77,7 @@ public class ProgressUploadFileKit {
      * @return
      */
     private static boolean isSafeFile(String fileName) {
+        fileName = fileName.trim().toLowerCase();
         return !fileName.endsWith(".jsp") && !fileName.endsWith(".jspx");
     }