Browse Source

Fix a authorization bug of OrderAppService

pull/103/head 0.14.1
gdlcf88 6 years ago
parent
commit
0c35001085
  1. 2
      common.props
  2. 7
      modules/EasyAbp.EShop.Orders/src/EasyAbp.EShop.Orders.Application/EasyAbp/EShop/Orders/Orders/OrderAppService.cs

2
common.props

@ -1,7 +1,7 @@
<Project> <Project>
<PropertyGroup> <PropertyGroup>
<LangVersion>latest</LangVersion> <LangVersion>latest</LangVersion>
<Version>0.14.0</Version> <Version>0.14.1</Version>
<NoWarn>$(NoWarn);CS1591</NoWarn> <NoWarn>$(NoWarn);CS1591</NoWarn>
<GeneratePackageOnBuild>true</GeneratePackageOnBuild> <GeneratePackageOnBuild>true</GeneratePackageOnBuild>
<Authors>EasyAbp Team</Authors> <Authors>EasyAbp Team</Authors>

7
modules/EasyAbp.EShop.Orders/src/EasyAbp.EShop.Orders.Application/EasyAbp/EShop/Orders/Orders/OrderAppService.cs

@ -6,13 +6,10 @@ using EasyAbp.EShop.Orders.Authorization;
using EasyAbp.EShop.Orders.Orders.Dtos; using EasyAbp.EShop.Orders.Orders.Dtos;
using EasyAbp.EShop.Products.Products; using EasyAbp.EShop.Products.Products;
using EasyAbp.EShop.Products.Products.Dtos; using EasyAbp.EShop.Products.Products.Dtos;
using EasyAbp.EShop.Stores.Authorization;
using EasyAbp.EShop.Stores.Stores; using EasyAbp.EShop.Stores.Stores;
using Microsoft.AspNetCore.Authorization; using Microsoft.AspNetCore.Authorization;
using Volo.Abp; using Volo.Abp;
using Volo.Abp.Application.Dtos; using Volo.Abp.Application.Dtos;
using Volo.Abp.Application.Services;
using Volo.Abp.Authorization;
using Volo.Abp.Users; using Volo.Abp.Users;
namespace EasyAbp.EShop.Orders.Orders namespace EasyAbp.EShop.Orders.Orders
@ -87,7 +84,7 @@ namespace EasyAbp.EShop.Orders.Orders
public override async Task<OrderDto> CreateAsync(CreateOrderDto input) public override async Task<OrderDto> CreateAsync(CreateOrderDto input)
{ {
await CheckMultiStorePolicyAsync(input.StoreId, CreatePolicyName); await CheckCreatePolicyAsync();
// Todo: Check if the store is open. // Todo: Check if the store is open.
@ -134,6 +131,8 @@ namespace EasyAbp.EShop.Orders.Orders
public virtual async Task<OrderDto> GetByOrderNumberAsync(string orderNumber) public virtual async Task<OrderDto> GetByOrderNumberAsync(string orderNumber)
{ {
await CheckGetPolicyAsync();
var order = await _repository.GetAsync(x => x.OrderNumber == orderNumber); var order = await _repository.GetAsync(x => x.OrderNumber == orderNumber);
if (order.CustomerUserId != CurrentUser.GetId()) if (order.CustomerUserId != CurrentUser.GetId())

Loading…
Cancel
Save