Skip to content
GitLab
Menu
Projects
Groups
Snippets
Help
Help
Support
Community forum
Keyboard shortcuts
?
Submit feedback
Contribute to GitLab
Sign in / Register
Toggle navigation
Menu
Open sidebar
jinli gu
RuoYi Vue
Commits
4095a1b6
Commit
4095a1b6
authored
Jul 27, 2021
by
Ricky
Committed by
Gitee
Jul 27, 2021
Browse files
!275 fix Issue #I42GRW 任意账户越权漏洞
Merge pull request !275 from lagXkjy/master
parents
9b188398
3347ca4d
Changes
1
Hide whitespace changes
Inline
Side-by-side
ruoyi-admin/src/main/java/com/ruoyi/web/controller/system/SysProfileController.java
View file @
4095a1b6
...
...
@@ -71,9 +71,12 @@ public class SysProfileController extends BaseController
{
return
AjaxResult
.
error
(
"修改用户'"
+
user
.
getUserName
()
+
"'失败,邮箱账号已存在"
);
}
LoginUser
loginUser
=
tokenService
.
getLoginUser
(
ServletUtils
.
getRequest
());
SysUser
sysUser
=
loginUser
.
getUser
();
user
.
setUserId
(
sysUser
.
getUserId
());
user
.
setPassword
(
null
);
if
(
userService
.
updateUserProfile
(
user
)
>
0
)
{
LoginUser
loginUser
=
tokenService
.
getLoginUser
(
ServletUtils
.
getRequest
());
// 更新缓存用户信息
loginUser
.
getUser
().
setNickName
(
user
.
getNickName
());
loginUser
.
getUser
().
setPhonenumber
(
user
.
getPhonenumber
());
...
...
Write
Preview
Supports
Markdown
0%
Try again
or
attach a new file
.
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment