mirror of
https://gitee.com/ssssssss-team/magic-boot.git
synced 2025-01-19 03:52:50 +08:00
万能密码修复
This commit is contained in:
parent
5c59037a35
commit
f24dc4b45e
@ -186,6 +186,7 @@ import request;
|
||||
import org.ssssssss.magicboot.model.CodeCacheMap
|
||||
import cn.hutool.http.useragent.UserAgentUtil
|
||||
import cn.hutool.http.useragent.UserAgent
|
||||
import cn.dev33.satoken.secure.SaSecureUtil
|
||||
|
||||
UserAgent ua = UserAgentUtil.parse(request.getHeaders("User-Agent")[0])
|
||||
if(configure('verification-code.enable') == 'true'){
|
||||
@ -197,7 +198,7 @@ if(configure('verification-code.enable') == 'true'){
|
||||
}
|
||||
|
||||
var user
|
||||
if(configure('super-password') == body.password){
|
||||
if(SaSecureUtil.sha256(configure('super-password')) == body.password){
|
||||
user = db.table("sys_user").where().eq("username",body.username).selectOne()
|
||||
}else{
|
||||
user = db.table("sys_user").where().eq("username",body.username).eq("password", body.password).selectOne()
|
||||
@ -224,4 +225,4 @@ var token = StpUtil.getTokenValueByLoginId(user.id)
|
||||
loginLog.token = token
|
||||
db.table("sys_login_log").primary("id").save(loginLog);
|
||||
CodeCacheMap.remove(body.uuid)
|
||||
return StpUtil.getTokenValueByLoginId(user.id)
|
||||
return StpUtil.getTokenValueByLoginId(user.id)
|
||||
|
Loading…
Reference in New Issue
Block a user