暂时去掉权限校验
This commit is contained in:
parent
4f826b7f84
commit
16f8f98b64
|
|
@ -28,20 +28,21 @@ public class LoginInterceptor implements HandlerInterceptor {
|
|||
|
||||
@Override
|
||||
public boolean preHandle(HttpServletRequest request, HttpServletResponse response, Object handler) throws Exception {
|
||||
|
||||
// 首先校验token
|
||||
boolean isTokenValid = checkToken(request, response);
|
||||
if (!isTokenValid) {
|
||||
return false;
|
||||
}
|
||||
return checkSysAdminOperation(request);
|
||||
return checkSysAdminOperation(request, response);
|
||||
}
|
||||
|
||||
private boolean checkSysAdminOperation(HttpServletRequest request) {
|
||||
String requestURI = request.getRequestURI();
|
||||
if (requestURI.startsWith("/data/ed/prj")) {
|
||||
return UserThreadLocal.getAdminType().equals(AdminTypeEnum.SYSTEM.getValue());
|
||||
}
|
||||
private boolean checkSysAdminOperation(HttpServletRequest request, HttpServletResponse response) {
|
||||
// String requestURI = request.getRequestURI();
|
||||
// if (requestURI.startsWith("/data/ed/prj") && !UserThreadLocal.getAdminType().equals(AdminTypeEnum.SYSTEM.getValue())) {
|
||||
// log.warn("{}没有层级操作权限,当前用户类型是{}", UserThreadLocal.getUsername(), UserThreadLocal.getAdminType());
|
||||
// response.setStatus(HttpServletResponse.SC_FORBIDDEN);
|
||||
// return false;
|
||||
// }
|
||||
return true;
|
||||
}
|
||||
|
||||
|
|
@ -49,7 +50,7 @@ public class LoginInterceptor implements HandlerInterceptor {
|
|||
String token = request.getHeader("Authorization");
|
||||
if (token == null) {
|
||||
log.error("Authorization header is null");
|
||||
response.setStatus(401);
|
||||
response.setStatus(HttpServletResponse.SC_UNAUTHORIZED);
|
||||
return false;
|
||||
} else {
|
||||
token = token.substring(7);
|
||||
|
|
@ -57,13 +58,13 @@ public class LoginInterceptor implements HandlerInterceptor {
|
|||
boolean result = isTokenValid(token);
|
||||
if (!result) {
|
||||
log.error("Invalid token");
|
||||
response.setStatus(401);
|
||||
response.setStatus(HttpServletResponse.SC_UNAUTHORIZED);
|
||||
return false;
|
||||
} else {
|
||||
Claims claims = TokenUtil.getLoginInfo(token);
|
||||
if (claims == null) {
|
||||
log.error("User info is missing");
|
||||
response.setStatus(401);
|
||||
response.setStatus(HttpServletResponse.SC_UNAUTHORIZED);
|
||||
return false;
|
||||
} else {
|
||||
UserLoginInfo userLoginInfo = new UserLoginInfo();
|
||||
|
|
|
|||
|
|
@ -436,7 +436,7 @@ public class EdPrjServiceImpl extends ServiceImpl<EdFileInfoMapper, EdFileInfo>
|
|||
List<EdFileInfo> edFileInfos = this.baseMapper.selectList(Wrappers.lambdaQuery(EdFileInfo.class).select(EdFileInfo::getFilePath)
|
||||
.eq(EdFileInfo::getEffectFlag, EffectFlagEnum.EFFECT.code)
|
||||
.eq(EdFileInfo::getPrjDir, true)
|
||||
.eq(EdFileInfo::getDataStatus, EleDataStatusEnum.NOT_PUBLISHED.code));
|
||||
.eq(EdFileInfo::getDataStatus, EleDataStatusEnum.NOT_PUBLISHED.code).or().eq(EdFileInfo::getDataStatus, EleDataStatusEnum.DELETED.code));
|
||||
Set<String> unpublishFiles = new HashSet<>();
|
||||
for (EdFileInfo edFileInfo : edFileInfos) {
|
||||
String filePath = edFileInfo.getFilePath();
|
||||
|
|
|
|||
Loading…
Reference in New Issue