This commit is contained in:
王炜翔 2025-02-19 21:22:03 +08:00
parent 6a8c152623
commit bb6e904258

View File

@ -64,7 +64,7 @@ namespace asg_form.Controllers
{
string userId = this.User.FindFirst(ClaimTypes.NameIdentifier)!.Value;
var user = await userManager.FindByIdAsync(userId);
if (!this.User.FindAll(ClaimTypes.Role).Any(a => a.Value == "nbadmin")||!this.User.FindAll(ClaimTypes.Role).Any(a => a.Value == "admin"))
if (!this.User.FindAll(ClaimTypes.Role).Any(a => a.Value == "nbadmin")&&!this.User.FindAll(ClaimTypes.Role).Any(a => a.Value == "admin"))
{
return Ok(new error_mb { code = 401, message = "无权访问" });
}
@ -113,7 +113,7 @@ namespace asg_form.Controllers
{
string userId = this.User.FindFirst(ClaimTypes.NameIdentifier)!.Value;
var user = await userManager.FindByIdAsync(userId);
if (!this.User.FindAll(ClaimTypes.Role).Any(a => a.Value == "nbadmin") || !this.User.FindAll(ClaimTypes.Role).Any(a => a.Value == "admin"))
if (!this.User.FindAll(ClaimTypes.Role).Any(a => a.Value == "nbadmin") && !this.User.FindAll(ClaimTypes.Role).Any(a => a.Value == "admin"))
{
return Ok(new error_mb { code = 401, message = "无权访问" });
}