diff --git a/manager-api/src/main/java/cn/lili/security/ManagerAuthenticationFilter.java b/manager-api/src/main/java/cn/lili/security/ManagerAuthenticationFilter.java index 0d3654e5..a6e37cbf 100755 --- a/manager-api/src/main/java/cn/lili/security/ManagerAuthenticationFilter.java +++ b/manager-api/src/main/java/cn/lili/security/ManagerAuthenticationFilter.java @@ -117,7 +117,7 @@ public class ManagerAuthenticationFilter extends BasicAuthenticationFilter { * @return 是否拥有权限 */ boolean match(List permissions, String url) { - if (permissions.isEmpty()) { + if (permissions == null || permissions.isEmpty()) { return false; } return PatternMatchUtils.simpleMatch(permissions.toArray(new String[0]), url);