Skip to content
GitLab
Menu
Projects
Groups
Snippets
Help
Help
Support
Community forum
Keyboard shortcuts
?
Submit feedback
Contribute to GitLab
Sign in / Register
Toggle navigation
Menu
Open sidebar
jinli gu
RuoYi Vue
Commits
6fa3bfe0
"eladmin-tools/src/main/vscode:/vscode.git/clone" did not exist on "5ab7fb5b73427700655997a144ec9ee6db334e63"
Commit
6fa3bfe0
authored
May 27, 2021
by
RuoYi
Browse files
修复两处存在SQL注入漏洞问题
parent
5e64a93d
Changes
2
Hide whitespace changes
Inline
Side-by-side
ruoyi-framework/src/main/java/com/ruoyi/framework/aspectj/DataScopeAspect.java
View file @
6fa3bfe0
...
@@ -66,6 +66,7 @@ public class DataScopeAspect
...
@@ -66,6 +66,7 @@ public class DataScopeAspect
@Before
(
"dataScopePointCut()"
)
@Before
(
"dataScopePointCut()"
)
public
void
doBefore
(
JoinPoint
point
)
throws
Throwable
public
void
doBefore
(
JoinPoint
point
)
throws
Throwable
{
{
clearDataScope
(
point
);
handleDataScope
(
point
);
handleDataScope
(
point
);
}
}
...
@@ -166,4 +167,17 @@ public class DataScopeAspect
...
@@ -166,4 +167,17 @@ public class DataScopeAspect
}
}
return
null
;
return
null
;
}
}
/**
* 拼接权限sql前先清空params.dataScope参数防止注入
*/
private
void
clearDataScope
(
final
JoinPoint
joinPoint
)
{
Object
params
=
joinPoint
.
getArgs
()[
0
];
if
(
StringUtils
.
isNotNull
(
params
)
&&
params
instanceof
BaseEntity
)
{
BaseEntity
baseEntity
=
(
BaseEntity
)
params
;
baseEntity
.
getParams
().
put
(
DATA_SCOPE
,
""
);
}
}
}
}
ruoyi-system/src/main/resources/mapper/system/SysDeptMapper.xml
View file @
6fa3bfe0
...
@@ -147,7 +147,7 @@ PUBLIC "-//mybatis.org//DTD Mapper 3.0//EN"
...
@@ -147,7 +147,7 @@ PUBLIC "-//mybatis.org//DTD Mapper 3.0//EN"
<if
test=
"updateBy != null and updateBy != ''"
>
update_by = #{updateBy},
</if>
<if
test=
"updateBy != null and updateBy != ''"
>
update_by = #{updateBy},
</if>
update_time = sysdate()
update_time = sysdate()
</set>
</set>
where
dept_id in (${
ancestors
}
)
where
find_in_set(#{deptId},
ancestors)
</update>
</update>
<delete
id=
"deleteDeptById"
parameterType=
"Long"
>
<delete
id=
"deleteDeptById"
parameterType=
"Long"
>
...
...
Write
Preview
Supports
Markdown
0%
Try again
or
attach a new file
.
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment