漏洞修复

This commit is contained in:
lizhenhua 2024-08-09 17:29:43 +08:00
parent aae65458d7
commit 61f8f72ebd
2 changed files with 22 additions and 22 deletions

View File

@ -43,7 +43,7 @@ PUBLIC "-//mybatis.org//DTD Mapper 3.0//EN"
AND status = #{status} AND status = #{status}
</if> </if>
<!-- 数据范围过滤 --> <!-- 数据范围过滤 -->
${params.dataScope} <include refid="com.bonus.system.mapper.DataScopeMapper.dataScopeFilter"/>
order by d.parent_id, d.order_num order by d.parent_id, d.order_num
</select> </select>

View File

@ -116,8 +116,8 @@
AND (u.dept_id = #{deptId} OR u.dept_id IN ( SELECT t.dept_id FROM sys_dept t WHERE find_in_set(#{deptId}, AND (u.dept_id = #{deptId} OR u.dept_id IN ( SELECT t.dept_id FROM sys_dept t WHERE find_in_set(#{deptId},
ancestors) )) ancestors) ))
</if> </if>
<!-- 数据范围过滤 --> <include refid="com.bonus.system.mapper.DataScopeMapper.dataScopeFilter"/>
${params.dataScope}
</select> </select>
<select id="selectAllocatedList" parameterType="SysUser" resultMap="SysUserResult"> <select id="selectAllocatedList" parameterType="SysUser" resultMap="SysUserResult">
@ -134,7 +134,7 @@
AND u.phonenumber like concat('%', #{phonenumber}, '%') AND u.phonenumber like concat('%', #{phonenumber}, '%')
</if> </if>
<!-- 数据范围过滤 --> <!-- 数据范围过滤 -->
${params.dataScope} <include refid="com.bonus.system.mapper.DataScopeMapper.dataScopeFilter"/>
</select> </select>
<select id="selectUnallocatedList" parameterType="SysUser" resultMap="SysUserResult"> <select id="selectUnallocatedList" parameterType="SysUser" resultMap="SysUserResult">
@ -153,7 +153,7 @@
AND u.phonenumber like concat('%', #{phonenumber}, '%') AND u.phonenumber like concat('%', #{phonenumber}, '%')
</if> </if>
<!-- 数据范围过滤 --> <!-- 数据范围过滤 -->
${params.dataScope} <include refid="com.bonus.system.mapper.DataScopeMapper.dataScopeFilter"/>
</select> </select>
<select id="selectUserByUserName" parameterType="String" resultMap="SysUserResult"> <select id="selectUserByUserName" parameterType="String" resultMap="SysUserResult">