Skip to content
GitLab
Menu
Projects
Groups
Snippets
Help
Help
Support
Community forum
Keyboard shortcuts
?
Submit feedback
Contribute to GitLab
Sign in / Register
Toggle navigation
Menu
Open sidebar
jinli gu
RuoYi Vue
Commits
3347ca4d
Commit
3347ca4d
authored
Jul 27, 2021
by
江强
Browse files
fix:Issue #I42GRW 修复任意账户越权漏洞
parent
9b188398
Changes
1
Hide whitespace changes
Inline
Side-by-side
ruoyi-admin/src/main/java/com/ruoyi/web/controller/system/SysProfileController.java
View file @
3347ca4d
...
...
@@ -71,9 +71,12 @@ public class SysProfileController extends BaseController
{
return
AjaxResult
.
error
(
"修改用户'"
+
user
.
getUserName
()
+
"'失败,邮箱账号已存在"
);
}
LoginUser
loginUser
=
tokenService
.
getLoginUser
(
ServletUtils
.
getRequest
());
SysUser
sysUser
=
loginUser
.
getUser
();
user
.
setUserId
(
sysUser
.
getUserId
());
user
.
setPassword
(
null
);
if
(
userService
.
updateUserProfile
(
user
)
>
0
)
{
LoginUser
loginUser
=
tokenService
.
getLoginUser
(
ServletUtils
.
getRequest
());
// 更新缓存用户信息
loginUser
.
getUser
().
setNickName
(
user
.
getNickName
());
loginUser
.
getUser
().
setPhonenumber
(
user
.
getPhonenumber
());
...
...
Write
Preview
Supports
Markdown
0%
Try again
or
attach a new file
.
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment