Parcourir la source

漏洞修复,禁用querySysUser

fenghaifu il y a 1 jour
Parent
commit
18a02c31d3

+ 1 - 1
jeecg-boot/jeecg-boot-module-system/src/main/java/org/jeecg/config/ShiroConfig.java

@@ -87,7 +87,7 @@ public class ShiroConfig {
 		filterChainDefinitionMap.put("/sys/phoneLogin", "anon");//手机登录		
 		filterChainDefinitionMap.put("/sys/user/checkOnlyUser", "anon");//校验用户是否存在
 		filterChainDefinitionMap.put("/sys/user/register", "anon");//用户注册
-		filterChainDefinitionMap.put("/sys/user/querySysUser", "anon");//根据手机号获取用户信息
+//		filterChainDefinitionMap.put("/sys/user/querySysUser", "anon");//根据手机号获取用户信息
 		filterChainDefinitionMap.put("/sys/user/phoneVerification", "anon");//用户忘记密码验证手机号
 		filterChainDefinitionMap.put("/sys/user/passwordChange", "anon");//用户更改密码
 		filterChainDefinitionMap.put("/sys/user/detail/**", "anon");//根据id查用户信息