fix(aihr): restrict mobile personal data reads
This commit is contained in:
+9
-1
@@ -215,7 +215,15 @@ public class AihrMobileController {
|
||||
|
||||
private static String ownMobileExtPartyId(String requested) {
|
||||
String username = currentAppUsername();
|
||||
return username.isBlank() ? requested : username;
|
||||
if (!username.isBlank()) {
|
||||
return username;
|
||||
}
|
||||
LoginUser loginUser = LoginHelper.getLoginUser();
|
||||
if (loginUser != null && UserType.SYS_USER.getUserType().equals(loginUser.getUserType())
|
||||
&& !StpUtil.hasRoleOr(TenantConstants.SUPER_ADMIN_ROLE_KEY, "hr_operator")) {
|
||||
throw new ServiceException("无权访问员工个人数据");
|
||||
}
|
||||
return requested;
|
||||
}
|
||||
|
||||
private static String scopedAssignmentExtPartyId(String requested) {
|
||||
|
||||
+3
@@ -472,6 +472,9 @@ public class AihrPracticeSeedServiceTest {
|
||||
assertTrue(controllerSource.contains("catch (RuntimeException ex)"));
|
||||
assertTrue(controllerSource.contains("private String supervisorScopeExtPartyId()"));
|
||||
assertTrue(controllerSource.contains("mobileSeedService.requireSupervisorIdentity(currentAppUsername())"));
|
||||
assertTrue(controllerSource.contains("无权访问员工个人数据"));
|
||||
assertTrue(controllerSource.contains("UserType.SYS_USER.getUserType().equals(loginUser.getUserType())"));
|
||||
assertTrue(controllerSource.contains("StpUtil.hasRoleOr(TenantConstants.SUPER_ADMIN_ROLE_KEY, \"hr_operator\")"));
|
||||
assertTrue(controllerSource.contains("@SaCheckLogin\npublic class AihrMobileController"));
|
||||
assertTrue(controllerSource.contains("@SaIgnore\n @GetMapping(\"/home/{role}\")"));
|
||||
assertTrue(controllerSource.contains("if (!LoginHelper.isLogin())"));
|
||||
|
||||
Reference in New Issue
Block a user