!669 用户多角色,数据权限切面处理时可能出现权限抬升的情况。
Merge pull request !669 from 0慕容雪0/master
This commit is contained in:
		
						commit
						4cbd56cbd7
					
				@ -108,6 +108,7 @@ public class DataScopeAspect
 | 
			
		||||
            if (DATA_SCOPE_ALL.equals(dataScope))
 | 
			
		||||
            {                                
 | 
			
		||||
                sqlString = new StringBuilder();
 | 
			
		||||
                conditions.add(dataScope);
 | 
			
		||||
                break;
 | 
			
		||||
            }
 | 
			
		||||
            else if (DATA_SCOPE_CUSTOM.equals(dataScope))
 | 
			
		||||
@ -141,6 +142,12 @@ public class DataScopeAspect
 | 
			
		||||
            conditions.add(dataScope);
 | 
			
		||||
        }
 | 
			
		||||
 | 
			
		||||
        // 多角色情况下,所有角色都不包含传递过来的权限字符,这个时候sqlString也会为空,所以要限制一下,不查询任何数据
 | 
			
		||||
        if (StringUtils.isEmpty(conditions))
 | 
			
		||||
        {
 | 
			
		||||
            sqlString.append(StringUtils.format(" OR {}.dept_id = 0 ", deptAlias));
 | 
			
		||||
        }
 | 
			
		||||
 | 
			
		||||
        if (StringUtils.isNotBlank(sqlString.toString()))
 | 
			
		||||
        {
 | 
			
		||||
            Object params = joinPoint.getArgs()[0];
 | 
			
		||||
 | 
			
		||||
		Loading…
	
		Reference in New Issue
	
	Block a user