From 0673cc5a24b3cd5b027fdd5707c55e701a72bb1b Mon Sep 17 00:00:00 2001 From: gong <1157756119@qq.com> Date: Mon, 8 Dec 2025 15:42:46 +0800 Subject: [PATCH] =?UTF-8?q?=E5=8E=BB=E9=99=A4=E7=BA=BF=E4=B8=8A=E4=B8=87?= =?UTF-8?q?=E8=83=BD=E9=AA=8C=E8=AF=81=E7=A0=81=E5=8A=9F=E8=83=BD?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- .../impl/AuthorizationServiceImpl.java | 20 ++++++++++++++++++- 1 file changed, 19 insertions(+), 1 deletion(-) diff --git a/cash-service/account-service/src/main/java/com/czg/service/account/service/impl/AuthorizationServiceImpl.java b/cash-service/account-service/src/main/java/com/czg/service/account/service/impl/AuthorizationServiceImpl.java index df4a37d79..db2a20a21 100644 --- a/cash-service/account-service/src/main/java/com/czg/service/account/service/impl/AuthorizationServiceImpl.java +++ b/cash-service/account-service/src/main/java/com/czg/service/account/service/impl/AuthorizationServiceImpl.java @@ -22,6 +22,7 @@ import com.czg.service.account.mapper.SysMenuMapper; import com.wf.captcha.SpecCaptcha; import jakarta.annotation.Resource; import org.jetbrains.annotations.NotNull; +import org.springframework.beans.factory.annotation.Value; import org.springframework.stereotype.Service; import java.util.ArrayList; @@ -55,6 +56,9 @@ public class AuthorizationServiceImpl implements AuthorizationService { private HandoverRecordService handoverRecordService; + @Value("${spring.profiles.active}") + private String activeProfile; + @Override public Object getCaptcha() { // 生成验证码(130x48,4位字符) @@ -79,7 +83,21 @@ public class AuthorizationServiceImpl implements AuthorizationService { @Override public LoginVO login(SysLoginDTO loginDTO, String platType) { Object code = redisService.get(RedisCst.LOGIN_CODE + loginDTO.uuid()); - if (!"666666".equals(loginDTO.code()) && (code == null || !code.equals(loginDTO.code().toLowerCase()))) { + if (code == null) { + throw new CzgException("验证码已过期"); + } + + String userCode = loginDTO.code(); + boolean isDevEnv = "dev".equals(activeProfile); + + // 核心验证逻辑 + boolean isCodeValid = + // 开发环境万能码 + (isDevEnv && "666666".equals(userCode)) + // 正常验证码匹配 + || code.equals(userCode.toLowerCase()); + + if (!isCodeValid) { throw new CzgException("验证码错误"); }