We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
任意用户登录成功后,都可以通过修改请求参数访问其他用户创建的实体。比如用户3登录后,通过http://localhost:8080/kjb/entity/show?userId=1,可以得到用户1创建的实体,得到实体id后可以修改删除
The text was updated successfully, but these errors were encountered:
应该在controller中由当前登录的用户id检查请求的合法性
Sorry, something went wrong.
No branches or pull requests
任意用户登录成功后,都可以通过修改请求参数访问其他用户创建的实体。比如用户3登录后,通过http://localhost:8080/kjb/entity/show?userId=1,可以得到用户1创建的实体,得到实体id后可以修改删除
The text was updated successfully, but these errors were encountered: