Browse Source

注释权限拦截

zhaohongpeng 8 years ago
parent
commit
dd70493c72

+ 1 - 7
src/main/java/com/uas/platform/b2c/common/account/controller/AuthenticationController.java

@@ -4,16 +4,9 @@ import com.uas.platform.b2c.common.account.dao.UserLoginTimeDao;
 import com.uas.platform.b2c.common.account.model.User;
 import com.uas.platform.b2c.common.account.model.UserInfo;
 import com.uas.platform.b2c.common.account.model.UserLoginTime;
-import com.uas.platform.b2c.common.account.model.UserQuestion;
-import com.uas.platform.b2c.common.account.service.UserQuestionService;
-import com.uas.platform.b2c.common.account.model.UserQuestion;
 import com.uas.platform.b2c.common.account.service.UserQuestionService;
 import com.uas.platform.b2c.common.account.service.UserService;
 import com.uas.platform.b2c.core.support.SystemSession;
-
-import java.util.Collection;
-import java.util.List;
-
 import com.uas.platform.core.model.Constant;
 import net.sf.ehcache.CacheManager;
 import org.springframework.beans.factory.annotation.Autowired;
@@ -22,6 +15,7 @@ import org.springframework.util.CollectionUtils;
 import org.springframework.web.bind.annotation.*;
 
 import javax.servlet.http.HttpServletRequest;
+import java.util.List;
 
 /**
  *

+ 3 - 2
src/main/java/com/uas/platform/b2c/core/filter/SSOInterceptor.java

@@ -208,7 +208,8 @@ public class SSOInterceptor extends AbstractSSOInterceptor {
         // 暂时在正式 过滤admin访问权限
         if (needPermission != null) {
             if ("prod".equals(profile)) {
-                if (!user.getEnterprise().getUu().toString().equals(enUU)) {
+                //暂时放行所有权限,发布权限时打开注释;
+              /*  if (!user.getEnterprise().getUu().toString().equals(enUU)) {
                     throw new AccessDeniedException("无法访问,没有 " + needPermission + " 权限!");
                 } else {
                     if (user.getEnterprise().getUu().toString().equals(enUU)) {
@@ -216,7 +217,7 @@ public class SSOInterceptor extends AbstractSSOInterceptor {
                             throw new AccessDeniedException("无法访问,没有 " + needPermission + " 权限!");
                         }
                     }
-                }
+                }*/
             } else {
                 throw new AccessDeniedException("无法访问,没有 " + needPermission + " 权限!");
             }