public class ScsBIZBaseController {
protected HttpServletRequest request;
protected Map<String, Object> data;
@SuppressWarnings("unchecked")
@ModelAttribute
public void init(HttpServletRequest request) throws UnsupportedEncodingException {
this.request = request;
String paramData= request.getParameter("param111");
this.data = paramData;
}
//... 下面省略
看到了同事的这个写法,我觉得是不安全的,就去百度查了查,果然找到了。
https://www.jianshu.com/p/b79b144d4b95
你觉得这种写法安全吗? 说出你的看法。 谢谢各位大佬