瀏覽代碼

会员升级

Kirin 1 年之前
父節點
當前提交
ecf2c8334a
共有 1 個文件被更改,包括 4 次插入0 次删除
  1. 4 0
      app/controller/api/v1/user/UserController.php

+ 4 - 0
app/controller/api/v1/user/UserController.php

@@ -294,6 +294,10 @@ class UserController
     public function extractIntegral(Request $request, UserAwardIntegralServices $services, $id)
     {
         $info = $services->getIntegral($id);
+        $password = $request->post('password', '');
+        $user = $this->services->get($request->uid());
+        if ($user->pwd !== md5((string)$password))
+            return app('json')->success('密码错误');
         if (!$info || $info['uid'] != $request->uid()) {
             return app('json')->fail('记录不存在');
         }