From 9bfd1375e196842313c5b1072975a4680f582d76 Mon Sep 17 00:00:00 2001
From: RuoYi <yzz_ivy@163.com>
Date: 星期五, 17 三月 2023 14:16:21 +0800
Subject: [PATCH] 修复用户多角色数据权限可能出现权限抬升的情况
---
src/main/java/com/ruoyi/framework/config/SecurityConfig.java | 2 +-
1 files changed, 1 insertions(+), 1 deletions(-)
diff --git a/src/main/java/com/ruoyi/framework/config/SecurityConfig.java b/src/main/java/com/ruoyi/framework/config/SecurityConfig.java
index f0244e2..bdb7199 100644
--- a/src/main/java/com/ruoyi/framework/config/SecurityConfig.java
+++ b/src/main/java/com/ruoyi/framework/config/SecurityConfig.java
@@ -98,7 +98,7 @@
// 娉ㄨВ鏍囪鍏佽鍖垮悕璁块棶鐨剈rl
ExpressionUrlAuthorizationConfigurer<HttpSecurity>.ExpressionInterceptUrlRegistry registry = httpSecurity.authorizeRequests();
permitAllUrl.getUrls().forEach(url -> registry.antMatchers(url).permitAll());
-
+
httpSecurity
// CSRF绂佺敤锛屽洜涓轰笉浣跨敤session
.csrf().disable()
--
Gitblit v1.9.3