From fa38561b19ed2474c39cf1654141f1f9f6b389a2 Mon Sep 17 00:00:00 2001 From: mao Date: Tue, 6 May 2025 14:25:37 +0800 Subject: [PATCH] =?UTF-8?q?fix(app/controller):=20=E4=BF=AE=E5=A4=8D?= =?UTF-8?q?=E7=9F=AD=E4=BF=A1=E5=86=85=E5=AE=B9=E6=9F=A5=E8=AF=A2=E6=9C=AA?= =?UTF-8?q?=E6=B7=BB=E5=8A=A0=E7=94=A8=E6=88=B7=E6=9D=83=E9=99=90=E9=AA=8C?= =?UTF-8?q?=E8=AF=81?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit - 在 SmsController 中查询短信内容时,添加了用户 ID 的条件限制 - 这个修改确保了用户只能查询自己的短信内容,增强了系统安全性 --- app/controller/SmsController.php | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/app/controller/SmsController.php b/app/controller/SmsController.php index f325678..a46b868 100644 --- a/app/controller/SmsController.php +++ b/app/controller/SmsController.php @@ -23,7 +23,7 @@ class SmsController $sms_app = SmsApp::where('user_id', session('user_id'))->get(); // 获取短信内容 - $smsContent = SmsContent::select(); + $smsContent = SmsContent::select()->where('user_id', session('user_id')); // 根据应用名称获取短信内容 if (!empty($request->get('app_name'))) {