diff --git a/server/home/home-web/src/main/java/io/holoinsight/server/home/web/security/custom/AbstractResourceChecker.java b/server/home/home-web/src/main/java/io/holoinsight/server/home/web/security/custom/AbstractResourceChecker.java index 3d91748cd..39e08c0c7 100644 --- a/server/home/home-web/src/main/java/io/holoinsight/server/home/web/security/custom/AbstractResourceChecker.java +++ b/server/home/home-web/src/main/java/io/holoinsight/server/home/web/security/custom/AbstractResourceChecker.java @@ -3,9 +3,7 @@ */ package io.holoinsight.server.home.web.security.custom; -import io.holoinsight.server.home.web.security.LevelAuthorizationCheck; import io.holoinsight.server.home.web.security.LevelAuthorizationCheckResult; -import lombok.extern.slf4j.Slf4j; import org.apache.commons.lang3.StringUtils; import org.springframework.util.CollectionUtils; @@ -21,8 +19,12 @@ public interface AbstractResourceChecker { default LevelAuthorizationCheckResult checkIdNotNull(List parameters) { - if (CollectionUtils.isEmpty(parameters) || !StringUtils.isNumeric(parameters.get(0))) { - return failCheckResult("parameters %s is empty or is not numeric.", parameters); + if (CollectionUtils.isEmpty(parameters)) { + return failCheckResult("parameters %s is empty.", parameters); + } + + if (!StringUtils.isNumeric(parameters.get(0))) { + return failCheckResult("parameters %s is not numeric.", parameters.get(0)); } return successCheckResult(); } diff --git a/server/home/home-web/src/main/java/io/holoinsight/server/home/web/security/custom/AlarmRuleLevelAuthorizationChecker.java b/server/home/home-web/src/main/java/io/holoinsight/server/home/web/security/custom/AlarmRuleLevelAuthorizationChecker.java index f1ace1553..bfcf23bee 100644 --- a/server/home/home-web/src/main/java/io/holoinsight/server/home/web/security/custom/AlarmRuleLevelAuthorizationChecker.java +++ b/server/home/home-web/src/main/java/io/holoinsight/server/home/web/security/custom/AlarmRuleLevelAuthorizationChecker.java @@ -164,7 +164,8 @@ private LevelAuthorizationCheckResult checkSelfBool(String methodName, List parameters, String tenant, String workspace) { - String[] idArray = StringUtils.split(parameters.get(0), ","); + String st = parameters.get(0); + String[] idArray = StringUtils.split(st.substring(1, st.length() - 1), ","); for (String id : idArray) { LevelAuthorizationCheckResult checkResult = checkIdExists(Collections.singletonList(id), tenant, workspace);