update backend/dvadmin/system/views/user.py.
修改URL样式,,,另外此处密码修改和密码重置使用id进行判断用户可能存在越权?作者确认下pull/61/head
parent
b7114880ff
commit
5454e1e823
|
@ -229,7 +229,7 @@ class UserViewSet(CustomModelViewSet):
|
|||
"role": "角色ID",
|
||||
}
|
||||
|
||||
@action(methods=["GET"], detail=True, permission_classes=[IsAuthenticated])
|
||||
@action(methods=["GET"], detail=False, permission_classes=[IsAuthenticated])
|
||||
def user_info(self, request):
|
||||
"""获取当前用户信息"""
|
||||
user = request.user
|
||||
|
@ -242,7 +242,7 @@ class UserViewSet(CustomModelViewSet):
|
|||
}
|
||||
return DetailResponse(data=result, msg="获取成功")
|
||||
|
||||
@action(methods=["PUT"], detail=True, permission_classes=[IsAuthenticated])
|
||||
@action(methods=["PUT"], detail=False, permission_classes=[IsAuthenticated])
|
||||
def update_user_info(self, request):
|
||||
"""修改当前用户信息"""
|
||||
user = request.user
|
||||
|
|
Loading…
Reference in New Issue