修补会员退货接口中未校验用户ID的安全漏洞

Signed-off-by: 杨宇庆 <hiyyq@qq.com>
This commit is contained in:
杨宇庆 2024-02-28 18:23:54 +00:00 committed by Gitee
parent c3717b68c8
commit 9c4d373f81
No known key found for this signature in database
GPG Key ID: 173E9B9CA92EEF8F
1 changed files with 1 additions and 1 deletions

View File

@ -245,7 +245,7 @@ public class AfterSaleServiceImpl implements AfterSaleService {
@AfterSaleLog(operateType = AfterSaleOperateTypeEnum.MEMBER_DELIVERY)
public void deliveryAfterSale(Long userId, AppAfterSaleDeliveryReqVO deliveryReqVO) {
// 校验售后单存在并状态未退货
AfterSaleDO afterSale = tradeAfterSaleMapper.selectById(deliveryReqVO.getId());
AfterSaleDO afterSale = tradeAfterSaleMapper.selectByIdAndUserId(deliveryReqVO.getId(), userId);
if (afterSale == null) {
throw exception(AFTER_SALE_NOT_FOUND);
}