Browse Source

框架漏洞

master
467010279@qq.com 2 weeks ago
parent
commit
e59ec0aa29
  1. 14
      ruoyi-admin/src/main/java/com/ruoyi/web/controller/tool/SwaggerController.java
  2. 8
      ruoyi-framework/src/main/java/com/ruoyi/framework/config/ResourcesConfig.java

14
ruoyi-admin/src/main/java/com/ruoyi/web/controller/tool/SwaggerController.java

@ -8,17 +8,17 @@ import com.ruoyi.common.core.controller.BaseController;
/** /**
* swagger 接口 * swagger 接口
* *
* @author ruoyi * @author ruoyi
*/ */
@Controller @Controller
@RequestMapping("/tool/swagger") @RequestMapping("/tool/swagger")
public class SwaggerController extends BaseController public class SwaggerController extends BaseController
{ {
@PreAuthorize("@ss.hasPermi('tool:swagger:view')") // @PreAuthorize("@ss.hasPermi('tool:swagger:view')")
@GetMapping() // @GetMapping()
public String index() // public String index()
{ // {
return redirect("/swagger-ui.html"); // return redirect("/swagger-ui.html");
} // }
} }

8
ruoyi-framework/src/main/java/com/ruoyi/framework/config/ResourcesConfig.java

@ -15,7 +15,7 @@ import com.ruoyi.framework.interceptor.RepeatSubmitInterceptor;
/** /**
* 通用配置 * 通用配置
* *
* @author ruoyi * @author ruoyi
*/ */
@Configuration @Configuration
@ -32,8 +32,8 @@ public class ResourcesConfig implements WebMvcConfigurer
.addResourceLocations("file:" + RuoYiConfig.getProfile() + "/"); .addResourceLocations("file:" + RuoYiConfig.getProfile() + "/");
/** swagger配置 */ /** swagger配置 */
registry.addResourceHandler("/swagger-ui/**") // registry.addResourceHandler("/swagger-ui/**")
.addResourceLocations("classpath:/META-INF/resources/webjars/springfox-swagger-ui/"); // .addResourceLocations("classpath:/META-INF/resources/webjars/springfox-swagger-ui/");
} }
/** /**
@ -67,4 +67,4 @@ public class ResourcesConfig implements WebMvcConfigurer
// 返回新的CorsFilter // 返回新的CorsFilter
return new CorsFilter(source); return new CorsFilter(source);
} }
} }

Loading…
Cancel
Save