admin用户不可以被禁用

This commit is contained in:
cl
2021-07-15 15:43:16 +08:00
parent 9fb646357c
commit 5d536f641f

View File

@@ -93,7 +93,7 @@ public class SysUserController {
public ResponseEntity<String> password(@RequestBody @Valid UpdatePasswordDto param){
Long userId = SecurityUtils.getSysUser().getUserId();
// 开源版代码禁止用户修改admin 的账号密码密码
// 开源版代码禁止用户修改admin 的账号密码
// 正式使用时,删除此部分代码即可
if (Objects.equals(1L,userId) && StrUtil.isNotBlank(param.getNewPassword())) {
throw new YamiShopBindException("禁止修改admin的账号密码");
@@ -153,7 +153,6 @@ public class SysUserController {
@PreAuthorize("@pms.hasPermission('sys:user:update')")
public ResponseEntity<String> update(@Valid @RequestBody SysUser user){
String password = user.getPassword();
SysUser dbUser = sysUserService.getSysUserById(user.getUserId());
if (!Objects.equals(dbUser.getShopId(), SecurityUtils.getSysUser().getShopId())) {
@@ -175,6 +174,10 @@ public class SysUserController {
if (is) {
throw new YamiShopBindException("禁止修改admin的账号密码");
}
if (Objects.equals(1L,user.getUserId()) && user.getStatus()==0) {
throw new YamiShopBindException("admin用户不可以被禁用");
}
sysUserService.updateUserAndUserRole(user);
return ResponseEntity.ok().build();
}