Browse Source

修复深圳三院渗透扫描发现的问题。

Li Yuan 1 year ago
parent
commit
cef46784b8

+ 1 - 1
ibps-api-root/modules/api-base/src/main/java/com/lc/ibps/api/base/constants/StateEnum.java

@@ -81,7 +81,7 @@ public enum StateEnum /*implements BaseEnum*/ {
 	, ILLEGAL_ACCOUNT_EXPIRED_CREDENTIALS(6020109, "密码过期")
 	, ILLEGAL_ACCOUNT_DISABLED(6020110, "用户被禁用")
 	, ILLEGAL_ACCOUNT_LOCKED(6020111, "用户被锁定")
-	, ILLEGAL_ACCOUNT_UNKOWN(6020112, "未知账号")
+	, ILLEGAL_ACCOUNT_UNKOWN(6020112, "用户名或密码错误")
 	, ILLEGAL_ORG_UNKOWN(6020113, "未知部门")
 	, ILLEGAL_POSITION_UNKOWN(6020114, "未知岗位")
 	, ILLEGAL_ACCOUNT_PASSWORD_REQUEST_VALIDCODE(6020115, "用户名或密码错误多次需要输入验证码")

+ 1 - 1
ibps-oauth-root/modules/oauth-server2-default/src/main/java/com/lc/ibps/cloud/oauth/server/provider/BaseProvider.java

@@ -346,7 +346,7 @@ public class BaseProvider extends GenericProvider {
 
 	private PartyUserPo login(String password, PartyUserPo user) {
 		if(BeanUtils.isEmpty(user)){
-			throw new UnknownAccountException("未知账号");
+			throw new UnknownAccountException("用户名或密码错误");
 		}
 		
 		String account = user.getAccount();

+ 4 - 0
ibps-provider-root/modules/provider-platform-default/src/main/java/com/lc/ibps/org/provider/PartyEmployeeProvider.java

@@ -398,6 +398,10 @@ public class PartyEmployeeProvider extends GenericProvider implements IPartyEmpl
 					partyLevel = partyLevelRepository.get(partyOrg.getLevelID());
 				}
 			}
+
+			if(partyUser != null){
+				partyUser.setPassword(null);
+			}
 			
 			UserSecurityPo userSecurity = userSecurityRepository.getDefaultUserSecurity();
 			List<PartyAttrPo> partyAttrs = partyAttrRepository.findByPartyTypeUserId4Edit(PartyType.EMPLOYEE.getValue(), employeeId);