fix(aihr): close assignment identity bypass

This commit is contained in:
2026-07-14 13:12:00 +08:00
parent ebd7236388
commit f8a132bddc
3 changed files with 2 additions and 3 deletions
@@ -227,9 +227,6 @@ public class AihrMobileController {
}
private static String scopedAssignmentExtPartyId(String requested) {
if (requested == null || requested.isBlank()) {
return requested;
}
return ownMobileExtPartyId(requested);
}
@@ -475,6 +475,7 @@ public class AihrPracticeSeedServiceTest {
assertTrue(controllerSource.contains("无权访问员工个人数据"));
assertTrue(controllerSource.contains("UserType.SYS_USER.getUserType().equals(loginUser.getUserType())"));
assertTrue(controllerSource.contains("StpUtil.hasRoleOr(TenantConstants.SUPER_ADMIN_ROLE_KEY, \"hr_operator\")"));
assertTrue(controllerSource.contains("return ownMobileExtPartyId(requested);"));
assertTrue(controllerSource.contains("@SaCheckLogin\npublic class AihrMobileController"));
assertTrue(controllerSource.contains("@SaIgnore\n @GetMapping(\"/home/{role}\")"));
assertTrue(controllerSource.contains("if (!LoginHelper.isLogin())"));