|
|
@@ -867,7 +867,16 @@ router.route("/getUser").all((req, res, next) => {
|
|
|
// .hk和.com域名直接查询,不判断session
|
|
|
getmysql(req, res, "selectUserDeail", json["uid"]);
|
|
|
} else {
|
|
|
- res.end(JSON.stringify([]));
|
|
|
+ if (req.session && req.session.userId) {
|
|
|
+ if (req.session.userId == json["userid"]) {
|
|
|
+ getmysql(req, res, "selectUser", json["userid"]);
|
|
|
+ } else {
|
|
|
+ // 不匹配则返回空数组
|
|
|
+ res.end(JSON.stringify([]));
|
|
|
+ }
|
|
|
+ } else {
|
|
|
+ res.end(JSON.stringify([]));
|
|
|
+ }
|
|
|
}
|
|
|
});
|
|
|
|
|
|
@@ -4616,7 +4625,16 @@ router.route("/selectUser").all((req, res, next) => {
|
|
|
// .hk和.com域名直接查询,不判断session
|
|
|
getmysql(req, res, "selectUser", json["userid"]);
|
|
|
} else {
|
|
|
- res.end(JSON.stringify([]));
|
|
|
+ if (req.session && req.session.userId) {
|
|
|
+ if (req.session.userId == json["userid"]) {
|
|
|
+ getmysql(req, res, "selectUser", json["userid"]);
|
|
|
+ } else {
|
|
|
+ // 不匹配则返回空数组
|
|
|
+ res.end(JSON.stringify([]));
|
|
|
+ }
|
|
|
+ } else {
|
|
|
+ res.end(JSON.stringify([]));
|
|
|
+ }
|
|
|
}
|
|
|
});
|
|
|
|