后台用户修改
This commit is contained in:
@@ -196,10 +196,9 @@ class Admin extends adminApi
|
||||
return V(0,"失败", []);
|
||||
}
|
||||
|
||||
// 先移除所有权限
|
||||
model('admin/AuthGroupAccess')->where('uid', $params['id'])->delete();
|
||||
|
||||
if(!empty($group)){
|
||||
// 先移除所有权限
|
||||
model('admin/AuthGroupAccess')->where('uid', $params['id'])->delete();
|
||||
// 过滤不允许的组别,避免越权
|
||||
$group = array_intersect($this->childrenGroupIds, $group);
|
||||
if (!$group) {
|
||||
|
||||
Reference in New Issue
Block a user