diff --git a/pig-common/pig-common-xss/src/main/java/com/pig4cloud/pig/common/xss/utils/XssUtil.java b/pig-common/pig-common-xss/src/main/java/com/pig4cloud/pig/common/xss/utils/XssUtil.java index ec8174c7cd083406bd9df941a4346f8e76bbce59..31e7cb46d7fee015cd24a73b176bc51678549d87 100644 --- a/pig-common/pig-common-xss/src/main/java/com/pig4cloud/pig/common/xss/utils/XssUtil.java +++ b/pig-common/pig-common-xss/src/main/java/com/pig4cloud/pig/common/xss/utils/XssUtil.java @@ -69,7 +69,7 @@ public class XssUtil { addTags("a", "b", "blockquote", "br", "caption", "cite", "code", "col", "colgroup", "dd", "div", "span", "embed", "object", "dl", "dt", "em", "h1", "h2", "h3", "h4", "h5", "h6", "i", "img", "li", "ol", "p", "pre", "q", "small", "strike", "strong", "sub", "sup", "table", "tbody", "td", "tfoot", "th", - "thead", "tr", "u", "ul"); + "thead", "tr", "u", "ul","source"); addAttributes("a", "href", "title", "target"); addAttributes("blockquote", "cite"); @@ -99,6 +99,10 @@ public class XssUtil { // 如果添加以下的协议,那么src必须是http 或者 https 开头,相对路径则被过滤掉了, // 所以必须注释掉,允许相对路径的图片资源 // addProtocols("img", "src", "http", "https"); + + //富文本编辑器视频 + addAttributes("div", "data-w-e-type","data-w-e-is-void"); + addAttributes("source", "src", "type"); } @Override