国家信息安全漏洞(请务必保持cipherKey密钥唯一性)

This commit is contained in:
RuoYi
2020-07-04 20:52:27 +08:00
parent 7728ad9eb4
commit 91986f13f8
2 changed files with 7 additions and 1 deletions

View File

@ -85,6 +85,10 @@ public class ShiroConfig
@Value("${shiro.cookie.maxAge}")
private int maxAge;
// 设置cipherKey密钥
@Value("${shiro.cookie.cipherKey}")
private String cipherKey;
// 登录地址
@Value("${shiro.user.loginUrl}")
private String loginUrl;
@ -328,7 +332,7 @@ public class ShiroConfig
{
CookieRememberMeManager cookieRememberMeManager = new CookieRememberMeManager();
cookieRememberMeManager.setCookie(rememberMeCookie());
cookieRememberMeManager.setCipherKey(Base64.decode("fCq+/xW488hMTCD+cmJ3aQ=="));
cookieRememberMeManager.setCipherKey(Base64.decode(cipherKey));
return cookieRememberMeManager;
}