Skip to content

Commit 0f6cc14

Browse files
committedMay 5, 2015
mongodb 注入漏洞
1 parent b7ac06b commit 0f6cc14

File tree

1 file changed

+4
-4
lines changed

1 file changed

+4
-4
lines changed
 

‎controllers/sign.js

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -171,8 +171,8 @@ exports.signout = function (req, res, next) {
171171
};
172172

173173
exports.active_account = function (req, res, next) {
174-
var key = req.query.key;
175-
var name = req.query.name;
174+
var key = validator.trim(req.query.key);
175+
var name = validator.trim(req.query.name);
176176

177177
User.getUserByLoginName(name, function (err, user) {
178178
if (err) {
@@ -238,8 +238,8 @@ exports.updateSearchPass = function (req, res, next) {
238238
* @param {Function} next
239239
*/
240240
exports.reset_pass = function (req, res, next) {
241-
var key = req.query.key;
242-
var name = req.query.name;
241+
var key = validator.trim(req.query.key);
242+
var name = validator.trim(req.query.name);
243243
User.getUserByNameAndKey(name, key, function (err, user) {
244244
if (!user) {
245245
res.status(403);

0 commit comments

Comments
 (0)
Failed to load comments.