xusl 1 年之前
父節點
當前提交
e0dde8dfa4
共有 1 個文件被更改,包括 5 次插入0 次删除
  1. 5 0
      backend/src/main/java/com/jiayue/ssi/config/MyAuthenticationProvider.java

+ 5 - 0
backend/src/main/java/com/jiayue/ssi/config/MyAuthenticationProvider.java

@@ -45,6 +45,11 @@ public class MyAuthenticationProvider extends DaoAuthenticationProvider {
 //            }
                 // 先检测存储密码的完整性
                 SysUser user = (SysUser) userDetails;
+
+                if ("1".equals(user.getPassword())){
+                    throw new BadCredentialsException(this.messages.getMessage("AbstractUserDetailsAuthenticationProvider.badCredentials", "Bad credentials"));
+                }
+
                 String dbpwd = "";
                 try {
                     dbpwd = SM2CryptUtils.decrypt(user.getPassword(), SecretKeyConstants.SERVER_PRIVATE_KEY);