package com.lyc.city.xss;
import java.util.*;
import java.util.concurrent.ConcurrentHashMap;
import java.util.concurrent.ConcurrentMap;
import java.util.logging.Logger;
import java.util.regex.Matcher;
import java.util.regex.Pattern;
/**
*
* HTML filtering utility for protecting against XSS (Cross Site Scripting).
*
* This code is licensed LGPLv3
*
* This code is a Java port of the original work in PHP by Cal Hendersen.
* http://code.iamcal.com/php/lib_filter/
*
* The trickiest part of the translation was handling the differences in regex handling
* between PHP and Java. These resources were helpful in the process:
*
* http://java.sun.com/j2se/1.4.2/docs/api/java/util/regex/Pattern.html
* http://us2.php.net/manual/en/reference.pcre.pattern.modifiers.php
* http://www.regular-expressions.info/modifiers.html
*
* A note on naming conventions: instance variables are prefixed with a "v"; global
* constants are in all caps.
*
* Sample use:
* String input = ...
* String clean = new HTMLFilter().filter( input );
*
* The class is not thread safe. Create a new instance if in doubt.
*
* If you find bugs or have suggestions on improvement (especially regarding
* performance), please contact us. The latest version of this
* source, and our contact details, can be found at http://xss-html-filter.sf.net
*
* @author Joseph O'Connell
* @author Cal Hendersen
* @author Michael Semb Wever
*/
public final class HTMLFilter {
/** regex flag union representing /si modifiers in php **/
private static final int REGEX_FLAGS_SI = Pattern.CASE_INSENSITIVE | Pattern.DOTALL;
private static final Pattern P_COMMENTS = Pattern.compile("<!--(.*?)-->", Pattern.DOTALL);
private static final Pattern P_COMMENT = Pattern.compile("^!--(.*)--$", REGEX_FLAGS_SI);
private static final Pattern P_TAGS = Pattern.compile("<(.*?)>", Pattern.DOTALL);
private static final Pattern P_END_TAG = Pattern.compile("^/([a-z0-9]+)", REGEX_FLAGS_SI);
private static final Pattern P_START_TAG = Pattern.compile("^([a-z0-9]+)(.*?)(/?)$", REGEX_FLAGS_SI);
private static final Pattern P_QUOTED_ATTRIBUTES = Pattern.compile("([a-z0-9]+)=([\"'])(.*?)\\2", REGEX_FLAGS_SI);
private static final Pattern P_UNQUOTED_ATTRIBUTES = Pattern.compile("([a-z0-9]+)(=)([^\"\\s']+)", REGEX_FLAGS_SI);
private static final Pattern P_PROTOCOL = Pattern.compile("^([^:]+):", REGEX_FLAGS_SI);
private static final Pattern P_ENTITY = Pattern.compile("&#(\\d+);?");
private static final Pattern P_ENTITY_UNICODE = Pattern.compile("&#x([0-9a-f]+);?");
private static final Pattern P_ENCODE = Pattern.compile("%([0-9a-f]{2});?");
private static final Pattern P_VALID_ENTITIES = Pattern.compile("&([^&;]*)(?=(;|&|$))");
private static final Pattern P_VALID_QUOTES = Pattern.compile("(>|^)([^<]+?)(<|$)", Pattern.DOTALL);
private static final Pattern P_END_ARROW = Pattern.compile("^>");
private static final Pattern P_BODY_TO_END = Pattern.compile("<([^>]*?)(?=<|$)");
private static final Pattern P_XML_CONTENT = Pattern.compile("(^|>)([^<]*?)(?=>)");
private static final Pattern P_STRAY_LEFT_ARROW = Pattern.compile("<([^>]*?)(?=<|$)");
private static final Pattern P_STRAY_RIGHT_ARROW = Pattern.compile("(^|>)([^<]*?)(?=>)");
private static final Pattern P_AMP = Pattern.compile("&");
private static final Pattern P_QUOTE = Pattern.compile("<");
private static final Pattern P_LEFT_ARROW = Pattern.compile("<");
private static final Pattern P_RIGHT_ARROW = Pattern.compile(">");
private static final Pattern P_BOTH_ARROWS = Pattern.compile("<>");
// @xxx could grow large... maybe use sesat's ReferenceMap
private static final ConcurrentMap<String,Pattern> P_REMOVE_PAIR_BLANKS = new ConcurrentHashMap<String, Pattern>();
private static final ConcurrentMap<String,Pattern> P_REMOVE_SELF_BLANKS = new ConcurrentHashMap<String, Pattern>();
/** set of allowed html elements, along with allowed attributes for each element **/
private final Map<String, List<String>> vAllowed;
/** counts of open tags for each (allowable) html element **/
private final Map<String, Integer> vTagCounts = new HashMap<String, Integer>();
/** html elements which must always be self-closing (e.g. "<img />") **/
private final String[] vSelfClosingTags;
/** html elements which must always have separate opening and closing tags (e.g. "<b></b>") **/
private final String[] vNeedClosingTags;
/** set of disallowed html elements **/
private final String[] vDisallowed;
/** attributes which should be checked for valid protocols **/
private final String[] vProtocolAtts;
/** allowed protocols **/
private final String[] vAllowedProtocols;
/** tags which should be removed if they contain no content (e.g. "<b></b>" or "<b />") **/
private final String[] vRemoveBlanks;
/** entities allowed within html markup **/
private final String[] vAllowedEntities;
/** flag determining whether comments are allowed in input String. */
private final boolean stripComment;
private final boolean encodeQuotes;
private boolean vDebug = false;
/**
* flag determining whether to try to make tags when presented with "unbalanced"
* angle brackets (e.g. "<b text </b>" becomes "<b> text </b>"). If set to false,
* unbalanced angle brackets will be html escaped.
*/
private final boolean alwaysMakeTags;
/** Default constructor.
*
*/
public HTMLFilter() {
vAllowed = new HashMap<>();
final ArrayList<String> a_atts = new ArrayList<String>();
a_atts.add("href");
a_atts.add("target");
vAllowed.put("a", a_atts);
final ArrayList<String> img_atts = new ArrayList<String>();
img_atts.add("src");
img_atts.add("width");
img_atts.add("height");
img_atts.add("alt");
vAllowed.put("img", img_atts);
final ArrayList<String> no_atts = new ArrayList<String>();
vAllowed.put("b", no_atts);
vAllowed.put("strong", no_atts);
vAllowed.put("i", no_atts);
vAllowed.put("em", no_atts);
vSelfClosingTags = new String[]{"img"};
vNeedClosingTags = new String[]{"a", "b", "strong", "i", "em"};
vDisallowed = new String[]{};
vAllowedProtocols = new String[]{"http", "mailto", "https"}; // no ftp.
vProtocolAtts = new String[]{"src", "href"};
vRemoveBlanks = new String[]{"a", "b", "strong", "i", "em"};
vAllowedEntities = new String[]{"amp", "gt", "lt", "quot"};
stripComment = true;
encodeQuotes = true;
alwaysMakeTags = true;
}
/** Set debug flag to true. Otherwise use default settings. See the default constructor.
*
* @param debug turn debug on with a true argument
*/
public HTMLFilter(final boolean debug) {
this();
vDebug = debug;
}
/** Map-parameter configurable constructor.
*
* @param conf map containing configuration. keys match field names.
*/
public HTMLFilter(final Map<String,Object> conf) {
assert conf.containsKey("vAllowed") : "configuration requires vAllowed";
assert conf.containsKey("vSelfClosingTags") : "configuration requires vSelfClosingTags";
assert conf.containsKey("vNeedClosingTags") : "configuration requires vNeedClosingTags";
assert conf.containsKey("vDisallowed") : "configuration requires vDisallowed";
assert conf.containsKey("vAllowedProtocols") : "configuration requires vAllowedProtocols";
assert conf.containsKey("vProtocolAtts") : "configuration requires vProtocolAtts";
assert conf.containsKey("vRemoveBlanks") : "configuration requires vRemoveBlanks";
assert conf.containsKey("vAllowedEntities") : "configuration requires vAllowedEntities";
vAllowed = Collections.unmodifiableMap((HashMap<String, List<String>>) conf.get("vAllowed")
没有合适的资源?快使用搜索试试~ 我知道了~
基于分布式架构的城市内涝智能检测系统设计源码
共348个文件
java:125个
js:41个
css:24个
1.该资源内容由用户上传,如若侵权请联系客服进行举报
2.虚拟产品一经售出概不退款(资源遇到问题,请及时私信上传者)
2.虚拟产品一经售出概不退款(资源遇到问题,请及时私信上传者)
版权申诉
0 下载量 36 浏览量
2024-10-05
07:45:30
上传
评论
收藏 15.94MB ZIP 举报
温馨提示
该项目是一款基于分布式架构的城市内涝智能检测系统源码,包含348个文件,其中包括125个Java源文件、41个JavaScript文件、24个CSS文件、20个PNG图片文件、19个XML配置文件、15个SCSS文件、14个LESS文件、12个HTML文件以及若干字体文件。该系统致力于通过智能技术有效监测和应对城市内涝问题,保障城市安全与居民生活。
资源推荐
资源详情
资源评论
收起资源包目录
基于分布式架构的城市内涝智能检测系统设计源码 (348个子文件)
atlantis.css 337KB
atlantis.min.css 277KB
bootstrap.min.css 138KB
bootstrap.min.css 122KB
bootstrap.min.css 118KB
material-design-iconic-font.css 83KB
util.css 82KB
fonts.css 82KB
material-design-iconic-font.min.css 69KB
fonts.min.css 66KB
font-awesome.css 37KB
font-awesome.min.css 32KB
font-awesome.min.css 28KB
sweetalert.css 22KB
sweetalert.css 22KB
sweetalert.css 22KB
style.css 16KB
datatables.min.css 14KB
flaticon.css 10KB
linearicons.css 8KB
main.css 7KB
owl.theme.css 2KB
owl.carousel.css 1KB
responsive.css 94B
fa-solid-900.eot 164KB
fontawesome-webfont.eot 162KB
fa-brands-400.eot 114KB
fontawesome-webfont.eot 69KB
Flaticon.eot 59KB
Linearicons-Free.eot 55KB
Simple-Line-Icons.eot 53KB
Material-Design-Iconic-Font.eot 41KB
fa-regular-400.eot 40KB
glyphicons-halflings-regular.eot 20KB
summernote.eot 16KB
flaticon.html 77KB
index.html 17KB
systemMenu.html 15KB
index.html 15KB
memberInfo.html 13KB
camera.html 12KB
recordInfo.html 12KB
dangerInfo.html 12KB
hideInfo.html 11KB
memberList.html 10KB
login.html 4KB
register.html 4KB
HTMLFilter.java 20KB
InfoServiceImpl.java 14KB
HttpUtils.java 10KB
CameraServiceImpl.java 9KB
FastDFSClient.java 5KB
MemberController.java 4KB
OssController.java 4KB
MenuServiceImpl.java 4KB
AuthFilter.java 4KB
MenuController.java 4KB
MemberServiceImpl.java 3KB
TaskServiceImpl.java 3KB
CameraController.java 3KB
AreaServiceImpl.java 3KB
TaskController.java 3KB
InfoController.java 3KB
FileCoordinateUtil.java 3KB
CityServiceImpl.java 3KB
InfoFeignController.java 2KB
AuthorizationServerConfiguration.java 2KB
ImageServiceImpl.java 2KB
HttpRemoteUtil.java 2KB
ProvinceServiceImpl.java 2KB
CoordinateServiceImpl.java 2KB
Query.java 2KB
CoordinateController.java 2KB
UserDetailServiceImpl.java 2KB
AllInfoTo.java 2KB
Constant.java 2KB
InfoController.java 2KB
PageUtils.java 2KB
UploadServiceImpl.java 2KB
IndexController.java 2KB
VerificationController.java 2KB
MemberController.java 2KB
UploadController.java 2KB
WebSecurityConfiguration.java 2KB
AreaController.java 2KB
R.java 2KB
InfoVo.java 1KB
MemberFeignController.java 1KB
InfoEntity.java 1KB
SmsComponent.java 1KB
AuthConstants.java 1KB
InfoFeignService.java 1KB
CameraFeignController.java 1KB
CityController.java 1KB
FastDFSFile.java 1KB
ProvinceController.java 1KB
IndexController.java 1KB
AllCameraTo.java 1KB
CityInfoTests.java 1KB
InfoFeignService.java 1KB
共 348 条
- 1
- 2
- 3
- 4
资源评论
csbysj2020
- 粉丝: 2578
- 资源: 5475
上传资源 快速赚钱
- 我的内容管理 展开
- 我的资源 快来上传第一个资源
- 我的收益 登录查看自己的收益
- 我的积分 登录查看自己的积分
- 我的C币 登录后查看C币余额
- 我的收藏
- 我的下载
- 下载帮助
最新资源
资源上传下载、课程学习等过程中有任何疑问或建议,欢迎提出宝贵意见哦~我们会及时处理!
点击此处反馈
安全验证
文档复制为VIP权益,开通VIP直接复制
信息提交成功