Skip to content
Projects
Groups
Snippets
Help
Loading...
Help
Support
Keyboard shortcuts
?
Submit feedback
Contribute to GitLab
Sign in
Toggle navigation
F
finance-manage
Project overview
Project overview
Details
Activity
Releases
Repository
Repository
Files
Commits
Branches
Tags
Contributors
Graph
Compare
Issues
0
Issues
0
List
Boards
Labels
Milestones
Merge Requests
0
Merge Requests
0
CI / CD
CI / CD
Pipelines
Jobs
Schedules
Analytics
Analytics
CI / CD
Repository
Value Stream
Wiki
Wiki
Snippets
Snippets
Members
Members
Collapse sidebar
Close sidebar
Activity
Graph
Create a new issue
Jobs
Commits
Issue Boards
Open sidebar
finance-oa
finance-manage
Commits
8007b22b
Commit
8007b22b
authored
Jan 27, 2022
by
RuoYi
Browse files
Options
Browse Files
Download
Email Patches
Plain Diff
导出Excel时屏蔽公式,防止CSV注入风险
parent
35664d81
Changes
1
Show whitespace changes
Inline
Side-by-side
Showing
1 changed file
with
10 additions
and
1 deletion
+10
-1
ruoyi-common/src/main/java/com/ruoyi/common/utils/poi/ExcelUtil.java
...n/src/main/java/com/ruoyi/common/utils/poi/ExcelUtil.java
+10
-1
No files found.
ruoyi-common/src/main/java/com/ruoyi/common/utils/poi/ExcelUtil.java
View file @
8007b22b
...
@@ -86,6 +86,9 @@ public class ExcelUtil<T>
...
@@ -86,6 +86,9 @@ public class ExcelUtil<T>
{
{
private
static
final
Logger
log
=
LoggerFactory
.
getLogger
(
ExcelUtil
.
class
);
private
static
final
Logger
log
=
LoggerFactory
.
getLogger
(
ExcelUtil
.
class
);
public
static
final
String
[]
FORMULA_STR
=
{
"="
,
"-"
,
"+"
,
"@"
};
/**
/**
* Excel sheet最大行数,默认65536
* Excel sheet最大行数,默认65536
*/
*/
...
@@ -710,7 +713,13 @@ public class ExcelUtil<T>
...
@@ -710,7 +713,13 @@ public class ExcelUtil<T>
{
{
if
(
ColumnType
.
STRING
==
attr
.
cellType
())
if
(
ColumnType
.
STRING
==
attr
.
cellType
())
{
{
cell
.
setCellValue
(
StringUtils
.
isNull
(
value
)
?
attr
.
defaultValue
()
:
value
+
attr
.
suffix
());
String
cellValue
=
Convert
.
toStr
(
value
);
// 对于任何以表达式触发字符 =-+@开头的单元格,直接使用tab字符作为前缀,防止CSV注入。
if
(
StringUtils
.
containsAny
(
cellValue
,
FORMULA_STR
))
{
cellValue
=
StringUtils
.
replaceEach
(
cellValue
,
FORMULA_STR
,
new
String
[]
{
"\t="
,
"\t-"
,
"\t+"
,
"\t@"
});
}
cell
.
setCellValue
(
StringUtils
.
isNull
(
cellValue
)
?
attr
.
defaultValue
()
:
cellValue
+
attr
.
suffix
());
}
}
else
if
(
ColumnType
.
NUMERIC
==
attr
.
cellType
())
else
if
(
ColumnType
.
NUMERIC
==
attr
.
cellType
())
{
{
...
...
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment