完善配置

This commit is contained in:
2023-09-10 20:24:21 +08:00
parent 94669d6e60
commit 3aa306c72f
2 changed files with 5 additions and 1 deletions

View File

@@ -14,6 +14,7 @@ import jakarta.servlet.ServletException;
import jakarta.servlet.http.HttpServletRequest; import jakarta.servlet.http.HttpServletRequest;
import jakarta.servlet.http.HttpServletResponse; import jakarta.servlet.http.HttpServletResponse;
import lombok.SneakyThrows; import lombok.SneakyThrows;
import org.apache.commons.lang3.BooleanUtils;
import org.apache.commons.lang3.StringUtils; import org.apache.commons.lang3.StringUtils;
import org.apache.http.entity.ContentType; import org.apache.http.entity.ContentType;
import org.slf4j.MDC; import org.slf4j.MDC;
@@ -132,7 +133,8 @@ public class AuthFilter extends OncePerRequestFilter {
.filter(x -> StringUtils.equals(x.getId(), resource.get().getId())).findAny(); .filter(x -> StringUtils.equals(x.getId(), resource.get().getId())).findAny();
if (userResource.isEmpty() && !user.getSysAdmin()) { if (userResource.isEmpty() && BooleanUtils.isFalse(user.getSysAdmin())) {
writeResponse(new BizException("invalidAccess", "当前资源未授权,请联系机构管理员处理。"), response); writeResponse(new BizException("invalidAccess", "当前资源未授权,请联系机构管理员处理。"), response);
} else { } else {

View File

@@ -27,6 +27,8 @@ public class SecurityConfig {
}) })
.csrf(AbstractHttpConfigurer::disable) .csrf(AbstractHttpConfigurer::disable)
.logout(AbstractHttpConfigurer::disable)
.formLogin(AbstractHttpConfigurer::disable)
.build(); .build();