Toggle navigation
Toggle navigation
This project
Loading...
Sign in
fe
/
yoho-blk
·
Commits
Go to a project
GitLab
Go to group
Project
Activity
Files
Commits
Pipelines
0
Builds
0
Graphs
Milestones
Issues
0
Merge Requests
1
Members
Labels
Wiki
Forks
Network
Create a new issue
Download as
Email Patches
Plain Diff
Browse Files
Authored by
姜枫
9 years ago
Commit
52490a413984c1457340416c5356dcc1f69617c5
1 parent
799e1fce
fix 订单修改orderCode漏洞问题
Hide whitespace changes
Inline
Side-by-side
Showing
3 changed files
with
3 additions
and
2 deletions
apps/me/controllers/order.js
apps/me/views/partial/order/detail/order-status.hbs
public/js/me/order-detail.page.js
apps/me/controllers/order.js
View file @
52490a4
...
...
@@ -129,6 +129,7 @@ const editOrder = (req, res, next) => {
const
query
=
req
.
query
;
query
.
uid
=
uid
;
query
.
orderCode
=
crypto
.
decrypt
(
config
.
crypto
.
common
,
query
.
orderCode
);
orderModel
.
editOrder
(
query
).
then
(
result
=>
{
res
.
json
(
result
);
...
...
apps/me/views/partial/order/detail/order-status.hbs
View file @
52490a4
<div
class=
"order-status order"
data-code=
"
{{
orderCode
}}
"
>
<div
class=
"order-status order"
data-code=
"
{{
orderCode
}}
"
data-codem=
"
{{
orderCodeM
}}
"
>
<div
class=
"basic"
>
<p>
订单号:
{{
orderCode
}}
</p>
<p>
订单状态:
{{
statusStr
}}
</p>
...
...
public/js/me/order-detail.page.js
View file @
52490a4
...
...
@@ -26,7 +26,7 @@ $('.order .cancel-btn').on('click', function() {
$
(
'.order .edit-btn'
).
on
(
'click'
,
function
()
{
var
$this
=
$
(
this
);
var
$userInfo
=
$
(
'.user-info.info-box'
);
var
code
=
$this
.
closest
(
'.order'
).
data
(
'code'
);
var
code
=
$this
.
closest
(
'.order'
).
data
(
'code
m
'
);
var
areaCode
=
$userInfo
.
data
(
'area'
);
var
userName
=
$userInfo
.
find
(
'.user-name-sel'
).
data
(
'name'
);
...
...
Please
register
or
login
to post a comment