From 9bfd1375e196842313c5b1072975a4680f582d76 Mon Sep 17 00:00:00 2001 From: RuoYi <yzz_ivy@163.com> Date: 星期五, 17 三月 2023 14:16:21 +0800 Subject: [PATCH] 修复用户多角色数据权限可能出现权限抬升的情况 --- src/main/java/com/ruoyi/framework/security/service/PermissionService.java | 1 + 1 files changed, 1 insertions(+), 0 deletions(-) diff --git a/src/main/java/com/ruoyi/framework/security/service/PermissionService.java b/src/main/java/com/ruoyi/framework/security/service/PermissionService.java index a27b798..a9f3c30 100644 --- a/src/main/java/com/ruoyi/framework/security/service/PermissionService.java +++ b/src/main/java/com/ruoyi/framework/security/service/PermissionService.java @@ -76,6 +76,7 @@ { return false; } + PermissionContextHolder.setContext(permissions); Set<String> authorities = loginUser.getPermissions(); for (String permission : permissions.split(PERMISSION_DELIMETER)) { -- Gitblit v1.9.3