DWN-31929 : move whitelist to class level
parent
dd92d8473e
commit
acaa64b4d5
|
@ -54,6 +54,10 @@ import com.google.gson.JsonSerializer;
|
||||||
*/
|
*/
|
||||||
public class UserInfoInterceptor extends HandlerInterceptorAdapter {
|
public class UserInfoInterceptor extends HandlerInterceptorAdapter {
|
||||||
|
|
||||||
|
private final Whitelist whitelist = Whitelist.relaxed()
|
||||||
|
.removeTags("a")
|
||||||
|
.removeProtocols("img", "src", "http", "https");
|
||||||
|
|
||||||
private Gson gson = new GsonBuilder()
|
private Gson gson = new GsonBuilder()
|
||||||
.registerTypeHierarchyAdapter(GrantedAuthority.class, new JsonSerializer<GrantedAuthority>() {
|
.registerTypeHierarchyAdapter(GrantedAuthority.class, new JsonSerializer<GrantedAuthority>() {
|
||||||
@Override
|
@Override
|
||||||
|
@ -142,10 +146,6 @@ public class UserInfoInterceptor extends HandlerInterceptorAdapter {
|
||||||
}
|
}
|
||||||
|
|
||||||
private String sanitise(String elementToClean) {
|
private String sanitise(String elementToClean) {
|
||||||
final Whitelist whitelist = Whitelist.relaxed()
|
|
||||||
.removeTags("a")
|
|
||||||
.removeProtocols("img", "src", "http", "https");
|
|
||||||
|
|
||||||
if (elementToClean != null) {
|
if (elementToClean != null) {
|
||||||
return Jsoup.clean(elementToClean, whitelist);
|
return Jsoup.clean(elementToClean, whitelist);
|
||||||
}
|
}
|
||||||
|
|
Loading…
Reference in New Issue