fix 恶意刷新查看量
全局搜索代替了原来长连接的方式,增加了很多隐藏的门路。
This commit is contained in:
@@ -36,7 +36,7 @@ public class AboutController extends BaseModelController {
|
||||
|
||||
|
||||
@GetMapping("/about")
|
||||
public String userIndexBlog(Model model){
|
||||
public String userIndexBlog(HttpServletRequest request,Model model){
|
||||
Page<About> pageParam = new Page<>(1, 20);
|
||||
aboutService.page(pageParam,new QueryWrapper<About>().orderByDesc("gmt_create"));
|
||||
// 结果
|
||||
@@ -50,7 +50,7 @@ public class AboutController extends BaseModelController {
|
||||
@PostMapping("/about")
|
||||
public String saveSay(HttpServletRequest request, About about){
|
||||
String loginUserId = getLoginUserId(request);
|
||||
User user = userService.getOne(new QueryWrapper<User>().eq("uid", ""));
|
||||
User user = userService.getOne(new QueryWrapper<User>().eq("uid", loginUserId));
|
||||
// 防止请求提交
|
||||
if (!RoleType.ADMIN.name().equals(user)){
|
||||
return "redirect:/about";
|
||||
|
||||
Reference in New Issue
Block a user