Browse Source

修改权限控制的问题

宋悦 8 years ago
parent
commit
b23212e918

+ 6 - 0
core-api/src/main/java/cn/com/qmth/examcloud/service/core/api/CourseApi.java

@@ -62,6 +62,8 @@ public class CourseApi {
         AccessUser accessUser = (AccessUser) request.getAttribute("accessUser");
         if(accessUser != null){
             course.setOrgId(accessUser.getRootOrgId());
+        }else{
+            return new ResponseEntity(HttpStatus.NOT_FOUND);
         }
     	return new ResponseEntity(courseService.findAll(course,new PageRequest(curPage - 1,pageSize)), HttpStatus.OK);
     }
@@ -95,6 +97,8 @@ public class CourseApi {
         AccessUser accessUser = (AccessUser) request.getAttribute("accessUser");
         if(accessUser != null){
             course.setOrgId(accessUser.getRootOrgId());
+        }else{
+            return new ResponseEntity(HttpStatus.NOT_FOUND);
         }
         try {
 			return new ResponseEntity(courseService.save(course),HttpStatus.CREATED);
@@ -110,6 +114,8 @@ public class CourseApi {
         AccessUser accessUser = (AccessUser) request.getAttribute("accessUser");
         if(accessUser != null){
             course.setOrgId(accessUser.getRootOrgId());
+        }else{
+            return new ResponseEntity(HttpStatus.NOT_FOUND);
         }
         try {
 			return new ResponseEntity(courseService.update(course.getId(),course), HttpStatus.OK);

+ 4 - 0
core-api/src/main/java/cn/com/qmth/examcloud/service/core/api/UserApi.java

@@ -67,6 +67,8 @@ public class UserApi {
             }else{
                 userCriteria.setRootOrgId(accessUser.getRootOrgId());
             }
+        }else{
+            return new ResponseEntity(HttpStatus.NOT_FOUND);
         }
         return new ResponseEntity(userService.findAll(userCriteria,
                 new PageRequest(curPage - 1,pageSize)), HttpStatus.OK);
@@ -102,6 +104,8 @@ public class UserApi {
             }else{
                 user.setRootOrgId(user.getOrgId());
             }
+        }else{
+            return new ResponseEntity(HttpStatus.NOT_FOUND);
         }
         try {
 			return new ResponseEntity(userService.save(user), HttpStatus.CREATED);