From 46e1f99727433d024057e465164e3bbda2115536 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=E6=BD=87=E6=B9=98=E6=8C=AF=E5=AE=87?= Date: Tue, 4 Oct 2022 22:13:56 +0800 Subject: [PATCH] =?UTF-8?q?feat:=20=E5=AE=9A=E6=97=B6=E4=BB=BB=E5=8A=A1?= =?UTF-8?q?=E6=B7=BB=E5=8A=A0=E6=89=A9=E5=B1=95=E7=9A=84=E7=99=BD=E5=90=8D?= =?UTF-8?q?=E5=8D=95=E9=85=8D=E7=BD=AE=EF=BC=88=E9=99=8D=E4=BD=8E=E5=AF=B9?= =?UTF-8?q?=E8=8B=A5=E4=BE=9D=E6=A1=86=E6=9E=B6=E4=BB=A3=E7=A0=81=E7=9A=84?= =?UTF-8?q?=E4=BF=AE=E6=94=B9=EF=BC=89?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- .../ruoyi/quartz/controller/SysJobController.java | 8 ++++++-- .../java/com/ruoyi/quartz/util/ScheduleUtils.java | 15 ++++++++++----- 2 files changed, 16 insertions(+), 7 deletions(-) diff --git a/ruoyi-quartz/src/main/java/com/ruoyi/quartz/controller/SysJobController.java b/ruoyi-quartz/src/main/java/com/ruoyi/quartz/controller/SysJobController.java index 6cbe3114b..a9a6b5577 100644 --- a/ruoyi-quartz/src/main/java/com/ruoyi/quartz/controller/SysJobController.java +++ b/ruoyi-quartz/src/main/java/com/ruoyi/quartz/controller/SysJobController.java @@ -4,6 +4,7 @@ import java.util.List; import org.apache.shiro.authz.annotation.RequiresPermissions; import org.quartz.SchedulerException; import org.springframework.beans.factory.annotation.Autowired; +import org.springframework.beans.factory.annotation.Value; import org.springframework.stereotype.Controller; import org.springframework.ui.ModelMap; import org.springframework.validation.annotation.Validated; @@ -37,6 +38,9 @@ import com.ruoyi.quartz.util.ScheduleUtils; public class SysJobController extends BaseController { private String prefix = "monitor/job"; + + @Value("${job.whiteList:}") + private List whiteList; @Autowired private ISysJobService jobService; @@ -153,7 +157,7 @@ public class SysJobController extends BaseController { return error("新增任务'" + job.getJobName() + "'失败,目标字符串存在违规"); } - else if (!ScheduleUtils.whiteList(job.getInvokeTarget())) + else if (!ScheduleUtils.whiteList(job.getInvokeTarget(), whiteList.toArray(new String[whiteList.size()]))) { return error("新增任务'" + job.getJobName() + "'失败,目标字符串不在白名单内"); } @@ -201,7 +205,7 @@ public class SysJobController extends BaseController { return error("修改任务'" + job.getJobName() + "'失败,目标字符串存在违规"); } - else if (!ScheduleUtils.whiteList(job.getInvokeTarget())) + else if (!ScheduleUtils.whiteList(job.getInvokeTarget(), whiteList.toArray(new String[whiteList.size()]))) { return error("修改任务'" + job.getJobName() + "'失败,目标字符串不在白名单内"); } diff --git a/ruoyi-quartz/src/main/java/com/ruoyi/quartz/util/ScheduleUtils.java b/ruoyi-quartz/src/main/java/com/ruoyi/quartz/util/ScheduleUtils.java index 100e22adb..111b31152 100644 --- a/ruoyi-quartz/src/main/java/com/ruoyi/quartz/util/ScheduleUtils.java +++ b/ruoyi-quartz/src/main/java/com/ruoyi/quartz/util/ScheduleUtils.java @@ -1,5 +1,6 @@ package com.ruoyi.quartz.util; +import org.apache.commons.lang3.ArrayUtils; import org.quartz.CronScheduleBuilder; import org.quartz.CronTrigger; import org.quartz.Job; @@ -123,17 +124,21 @@ public class ScheduleUtils * 检查包名是否为白名单配置 * * @param invokeTarget 目标字符串 + * @param extendedWhiteList 扩展的名单单 * @return 结果 */ - public static boolean whiteList(String invokeTarget) - { + public static boolean whiteList(String invokeTarget, String... extendedWhiteList) + { + String[] whiteList = StringUtils.isEmpty(extendedWhiteList) ? Constants.JOB_WHITELIST_STR + : ArrayUtils.addAll(extendedWhiteList, Constants.JOB_WHITELIST_STR); String packageName = StringUtils.substringBefore(invokeTarget, "("); int count = StringUtils.countMatches(packageName, "."); if (count > 1) { - return StringUtils.containsAnyIgnoreCase(invokeTarget, Constants.JOB_WHITELIST_STR); + return StringUtils.containsAnyIgnoreCase(invokeTarget, whiteList); } Object obj = SpringUtils.getBean(StringUtils.split(invokeTarget, ".")[0]); - return StringUtils.containsAnyIgnoreCase(obj.getClass().getPackage().getName(), Constants.JOB_WHITELIST_STR); - } + return StringUtils.containsAnyIgnoreCase(obj.getClass().getPackage().getName(), whiteList); + } + } \ No newline at end of file