Commit 16dc507d by 伍思炜

修复渗透漏洞

parent da8c0894
......@@ -59,7 +59,7 @@ public class codeManagerController extends BaseController {
@Autowired
private AuthCodeMapper authCodeMapper;
@Autowired
@Qualifier("redisStringTemplate")
// @Qualifier("redisStringTemplate")
private RedisTemplate redisTemplate;
@Autowired
private ProductMapper productMapper;
......@@ -75,6 +75,7 @@ public class codeManagerController extends BaseController {
@Autowired
private SaveAuthCodeUtil saveAuthCodeUtil;
private static String PATH1 = "StudentCard1";
private static String PATH2 = "StudentCard2";
private static String PATH3 = "StudentCard3";
......@@ -120,6 +121,7 @@ public class codeManagerController extends BaseController {
wrapper2.eq("order_status", "已完成");
wrapper2.eq("business_number", phone);
List<Order> list1 = orderMapper.selectList(wrapper2);
if (redisTemplate.hasKey(phone + ":num")) {
redisTemplate.opsForValue().increment(phone + ":num", 1L);
} else {
......
......@@ -276,7 +276,7 @@ public class PersonalCenterController extends BaseController {
@Permission(menuname = "个人中心用户详情", value = "partnerInfo", method = RequestMethod.POST)
public ResponseData<Map<String, Object>> selectPartnerInfo(String partner) {
ShiroUser shiroUser = getShiroUser();
if (partner.equals(shiroUser.getId().toString())){
if (!partner.equals(shiroUser.getId().toString())){
return ResponseData.error("权限不一致");
}
SysUser sysUser = sysUserMapper.selectById(partner);
......
......@@ -59,7 +59,7 @@ public class hhrUserController extends BaseController {
@Permission(menuname = "督导查询", value = "getOrderList", method = RequestMethod.POST)
public ResponseData<Map<String, Object>> getOrderList(String userId, Integer pageNo, Integer pageSize, String customer, String orderStatus, String userType, Integer selectFlag) {
ShiroUser shiroUser = getShiroUser();
if (shiroUser.getId().toString().equals(userId)){
if (!shiroUser.getId().toString().equals(userId)){
return ResponseData.error("权限不一致");
}
if (StringUtils.isBlank(userId)) {
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment