xusl 1 ano atrás
pai
commit
e0dde8dfa4

+ 5 - 0
backend/src/main/java/com/jiayue/ssi/config/MyAuthenticationProvider.java

@@ -45,6 +45,11 @@ public class MyAuthenticationProvider extends DaoAuthenticationProvider {
 //            }
                 // 先检测存储密码的完整性
                 SysUser user = (SysUser) userDetails;
+
+                if ("1".equals(user.getPassword())){
+                    throw new BadCredentialsException(this.messages.getMessage("AbstractUserDetailsAuthenticationProvider.badCredentials", "Bad credentials"));
+                }
+
                 String dbpwd = "";
                 try {
                     dbpwd = SM2CryptUtils.decrypt(user.getPassword(), SecretKeyConstants.SERVER_PRIVATE_KEY);