fix 78578 【水平越权】动态消息--部分接口没处理水平越权
This commit is contained in:
+43
-12
@@ -143,11 +143,7 @@ public class LawsNewsFeedServiceImpl extends ServiceImpl<LawsNewsFeedMapper, Law
|
|||||||
}
|
}
|
||||||
// 判断是否拥有操作权限(管理员和编辑人拥有权限)
|
// 判断是否拥有操作权限(管理员和编辑人拥有权限)
|
||||||
LoginUser loginUser = (LoginUser) SecurityUtils.getSubject().getPrincipal();
|
LoginUser loginUser = (LoginUser) SecurityUtils.getSubject().getPrincipal();
|
||||||
if (StringUtils.isNotBlank(lawsNewsFeed.getWriter())
|
isHaveOperateAuth(lawsNewsFeed);
|
||||||
&& !lawsNewsFeed.getWriter().equals(loginUser.getId())
|
|
||||||
&& !loginUser.getRoleIds().contains(FieldCommon.ROLE_ADMIN)) {
|
|
||||||
throw new JeroBootException(ResultCommon.NO_PERMISSION);
|
|
||||||
}
|
|
||||||
lawsNewsFeed.setWriter(loginUser.getId());
|
lawsNewsFeed.setWriter(loginUser.getId());
|
||||||
saveOrUpdate(lawsNewsFeed);
|
saveOrUpdate(lawsNewsFeed);
|
||||||
|
|
||||||
@@ -175,6 +171,46 @@ public class LawsNewsFeedServiceImpl extends ServiceImpl<LawsNewsFeedMapper, Law
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @Author: liao
|
||||||
|
* @Date: 2023/11/27 9:29
|
||||||
|
* @Description: 是否拥有操作权限
|
||||||
|
**/
|
||||||
|
private void isHaveOperateAuth(LawsNewsFeed lawsNewsFeed) {
|
||||||
|
LoginUser loginUser = (LoginUser) SecurityUtils.getSubject().getPrincipal();
|
||||||
|
if (StringUtils.isNotBlank(lawsNewsFeed.getWriter())
|
||||||
|
&& !lawsNewsFeed.getWriter().equals(loginUser.getId())
|
||||||
|
&& !loginUser.getRoleIds().contains(FieldCommon.ROLE_ADMIN)) {
|
||||||
|
throw new JeroBootException(ResultCommon.NO_PERMISSION);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @Author: liao
|
||||||
|
* @Date: 2023/11/27 9:34
|
||||||
|
* @Description: 是否拥有查看权限
|
||||||
|
**/
|
||||||
|
private void isHaveQueryAuth(LawsNewsFeed lawsNewsFeed) {
|
||||||
|
String userId = CurrentUserUtil.getId();
|
||||||
|
String roles = CurrentUserUtil.getRoles();
|
||||||
|
// 如果是编辑者,直接返回
|
||||||
|
if (userId.equals(lawsNewsFeed.getWriter())) return;
|
||||||
|
// 如果发布状态为未发布,直接报错
|
||||||
|
if (0 == lawsNewsFeed.getReleaseStatus()) {
|
||||||
|
throw new JeroBootException(ResultCommon.HORIZONTAL_TRANSGRESSION);
|
||||||
|
}
|
||||||
|
// 管理员角色或者推送范围为全体用户,直接返回
|
||||||
|
if (roles.contains(FieldCommon.ROLE_ADMIN) || 2 == lawsNewsFeed.getPushRangeFlag()) return;
|
||||||
|
// 普通用户,且有推送范围
|
||||||
|
LambdaQueryWrapper<LawsPushRange> queryWrapper = new LambdaQueryWrapper<>();
|
||||||
|
queryWrapper.eq(LawsPushRange::getUniqueRelationFlag, lawsNewsFeed.getId());
|
||||||
|
queryWrapper.eq(LawsPushRange::getUserId, userId);
|
||||||
|
LawsPushRange lawsPushRange = lawsPushRangeService.getOne(queryWrapper, false);
|
||||||
|
if (lawsPushRange == null) {
|
||||||
|
throw new JeroBootException(ResultCommon.HORIZONTAL_TRANSGRESSION);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* @Author: liao
|
* @Author: liao
|
||||||
* @Date: 2023/11/10 15:20
|
* @Date: 2023/11/10 15:20
|
||||||
@@ -223,14 +259,8 @@ public class LawsNewsFeedServiceImpl extends ServiceImpl<LawsNewsFeedMapper, Law
|
|||||||
*/
|
*/
|
||||||
@Override
|
@Override
|
||||||
public void deleteByIds(List<String> ids) {
|
public void deleteByIds(List<String> ids) {
|
||||||
LoginUser loginUser = (LoginUser) SecurityUtils.getSubject().getPrincipal();
|
|
||||||
List<LawsNewsFeed> newsFeedList = listByIds(ids);
|
List<LawsNewsFeed> newsFeedList = listByIds(ids);
|
||||||
List<String> writerList = newsFeedList.stream().map(LawsNewsFeed::getWriter)
|
newsFeedList.forEach(lawsNewsFeed -> isHaveOperateAuth(lawsNewsFeed));
|
||||||
.distinct().collect(Collectors.toList());
|
|
||||||
if ((writerList.size() > 1 || !loginUser.getId().equals(writerList.get(0)))
|
|
||||||
&& !loginUser.getRoleIds().contains(FieldCommon.ROLE_ADMIN)) {
|
|
||||||
throw new JeroBootException(ResultCommon.NO_PERMISSION);
|
|
||||||
}
|
|
||||||
removeByIds(ids);
|
removeByIds(ids);
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -246,6 +276,7 @@ public class LawsNewsFeedServiceImpl extends ServiceImpl<LawsNewsFeedMapper, Law
|
|||||||
if (Objects.isNull(lawsNewsFeed)) {
|
if (Objects.isNull(lawsNewsFeed)) {
|
||||||
throw new JeroBootException(ResultCommon.NO_CORRESPONDING_DATA_FOUND);
|
throw new JeroBootException(ResultCommon.NO_CORRESPONDING_DATA_FOUND);
|
||||||
}
|
}
|
||||||
|
isHaveQueryAuth(lawsNewsFeed);
|
||||||
// 阅读次数加1
|
// 阅读次数加1
|
||||||
if ("query".equals(type)) {
|
if ("query".equals(type)) {
|
||||||
lawsNewsFeed.setReadCount(lawsNewsFeed.getReadCount() + 1);
|
lawsNewsFeed.setReadCount(lawsNewsFeed.getReadCount() + 1);
|
||||||
|
|||||||
+4
-1
@@ -258,12 +258,15 @@ public class LawsStandardSharingController extends JeroController<LawsStandardSh
|
|||||||
SysUser user = sysUserService.getById(sysUser.getId());
|
SysUser user = sysUserService.getById(sysUser.getId());
|
||||||
String recipientId = lawsStandardSharing.getRecipientId();
|
String recipientId = lawsStandardSharing.getRecipientId();
|
||||||
Date date = new Date();
|
Date date = new Date();
|
||||||
|
LawsNewsFeed lawsNewsFeed = lawsNewsFeedService.getById(lawsStandardSharing.getStandardId());
|
||||||
|
if (0 == lawsNewsFeed.getReleaseStatus()) {
|
||||||
|
throw new JeroBootException("未发布的消息不能进行分享");
|
||||||
|
}
|
||||||
List<LawsStandardSharing> sharings = new ArrayList<>();
|
List<LawsStandardSharing> sharings = new ArrayList<>();
|
||||||
List<String> recipientIdList = Arrays.asList(recipientId.split(","));
|
List<String> recipientIdList = Arrays.asList(recipientId.split(","));
|
||||||
for (int i = 0; i < recipientIdList.size(); i++) {
|
for (int i = 0; i < recipientIdList.size(); i++) {
|
||||||
LawsStandardSharing sharing = new LawsStandardSharing();
|
LawsStandardSharing sharing = new LawsStandardSharing();
|
||||||
sharing.setStandardId(lawsStandardSharing.getStandardId());
|
sharing.setStandardId(lawsStandardSharing.getStandardId());
|
||||||
LawsNewsFeed lawsNewsFeed = lawsNewsFeedService.getById(lawsStandardSharing.getStandardId());
|
|
||||||
sharing.setRubric(lawsNewsFeed.getDynamicHeading());
|
sharing.setRubric(lawsNewsFeed.getDynamicHeading());
|
||||||
sharing.setSource(CommonConstant.STANDARD_SOURCE_4);
|
sharing.setSource(CommonConstant.STANDARD_SOURCE_4);
|
||||||
sharing.setSharerId(sysUser.getId());
|
sharing.setSharerId(sysUser.getId());
|
||||||
|
|||||||
Reference in New Issue
Block a user