fix 修复用户相关更新操作会越权的问题

This commit is contained in:
jenn
2023-03-10 21:15:54 +08:00
parent f8c98a1f48
commit cdb509a4fa
5 changed files with 84 additions and 43 deletions
@@ -83,7 +83,6 @@ public class SysProfileController extends BaseController {
@PutMapping("/updatePwd")
public R<Void> updatePwd(String oldPassword, String newPassword) {
SysUserVo user = userService.selectUserById(LoginHelper.getUserId());
String userName = user.getUserName();
String password = user.getPassword();
if (!BCrypt.checkpw(oldPassword, password)) {
return R.fail("修改密码失败,旧密码错误");
@@ -92,7 +91,7 @@ public class SysProfileController extends BaseController {
return R.fail("新密码不能与旧密码相同");
}
if (userService.resetUserPwd(userName, BCrypt.hashpw(newPassword)) > 0) {
if (userService.resetUserPwd(user.getUserId(), BCrypt.hashpw(newPassword)) > 0) {
return R.ok();
}
return R.fail("修改密码异常,请联系管理员");
@@ -113,7 +112,7 @@ public class SysProfileController extends BaseController {
}
SysOssVo oss = sysOssService.upload(avatarfile);
String avatar = oss.getUrl();
if (userService.updateUserAvatar(LoginHelper.getUsername(), oss.getOssId())) {
if (userService.updateUserAvatar(LoginHelper.getUserId(), oss.getOssId())) {
AvatarVo avatarVo = new AvatarVo();
avatarVo.setImgUrl(avatar);
return R.ok(avatarVo);
@@ -182,7 +182,7 @@ public class SysUserController extends BaseController {
userService.checkUserAllowed(user);
userService.checkUserDataScope(user.getUserId());
user.setPassword(BCrypt.hashpw(user.getPassword()));
return toAjax(userService.resetPwd(user));
return toAjax(userService.resetUserPwd(user.getUserId(),user.getPassword()));
}
/**