更新操作日志和登录日志的数据隔离

This commit is contained in:
2026-09-04 23:57:08 +08:00
parent 20be7f4817
commit 3d53f03246
8 changed files with 1053 additions and 934 deletions
+54 -15
View File
@@ -2,11 +2,13 @@ package controllers
import (
"encoding/json"
"fmt"
"strconv"
"strings"
"time"
"server/models"
"server/pkg/jwtutil"
"github.com/beego/beego/v2/client/orm"
beego "github.com/beego/beego/v2/server/web"
@@ -17,6 +19,40 @@ type BackendErpContactController struct {
beego.Controller
}
// contactClaims 从请求头解析登录态 JWT,返回后端用户 Claims
func (c *BackendErpContactController) contactClaims() (*jwtutil.Claims, error) {
auth := c.Ctx.Request.Header.Get("Authorization")
if auth == "" {
return nil, fmt.Errorf("未登录")
}
parts := strings.SplitN(auth, " ", 2)
if len(parts) != 2 || !strings.EqualFold(parts[0], "Bearer") {
return nil, fmt.Errorf("认证信息格式错误")
}
claims, err := jwtutil.ParseToken(parts[1])
if err != nil {
return nil, fmt.Errorf("无效的token")
}
if claims.UserType != "backend" {
return nil, fmt.Errorf("无权访问")
}
return claims, nil
}
// contactTenantID 获取当前请求的租户ID:优先使用登录态 JWT 中的租户,
// 仅当显式传入 tid 参数时才以参数为准(兼容管理端等显式指定场景)。
func (c *BackendErpContactController) contactTenantID() (uint64, error) {
claims, err := c.contactClaims()
if err != nil {
return 0, err
}
tid := uint64(claims.TenantId)
if v, e := c.GetInt64("tid"); e == nil && v > 0 {
tid = uint64(v)
}
return tid, nil
}
type erpContactDTO struct {
ID uint64 `json:"id"`
Tid uint64 `json:"tid"`
@@ -46,7 +82,11 @@ type erpContactDTO struct {
// List 获取通讯录列表(支持分页、搜索、按组织筛选)
// GET /backend/erp/contact/list
func (c *BackendErpContactController) List() {
tid, _ := c.GetInt64("tid")
tid, err := c.contactTenantID()
if err != nil {
c.contactJsonError(401, "未登录或无权访问")
return
}
page, _ := c.GetInt("page", 1)
pageSize, _ := c.GetInt("page_size", 20)
keyword := strings.TrimSpace(c.GetString("keyword"))
@@ -62,10 +102,8 @@ func (c *BackendErpContactController) List() {
qs := models.Orm.QueryTable(new(models.BackendErpContact)).
Filter("delete_time__isnull", true).
Exclude("status", 0)
if tid > 0 {
qs = qs.Filter("tid", tid)
}
Exclude("status", 0).
Filter("tid", tid)
if orgID > 0 {
qs = qs.Filter("org_id", orgID)
}
@@ -398,17 +436,19 @@ func (c *BackendErpContactController) SyncAllContacts() {
// GetContactOrgTree 获取通讯录组织树(带各部门联系人数量)
// GET /backend/erp/contact/orgTree
func (c *BackendErpContactController) GetContactOrgTree() {
tid, _ := c.GetInt64("tid")
tid, err := c.contactTenantID()
if err != nil {
c.contactJsonError(401, "未登录或无权访问")
return
}
qs := models.Orm.QueryTable(new(models.BackendOrganization)).
Filter("delete_time__isnull", true).
Exclude("status", 0)
if tid > 0 {
qs = qs.Filter("tid", tid)
}
Exclude("status", 0).
Filter("tid", tid)
var orgs []models.BackendOrganization
_, err := qs.OrderBy("sort", "id").All(&orgs)
_, err = qs.OrderBy("sort", "id").All(&orgs)
if err != nil {
c.contactJsonError(500, "查询组织架构失败: "+err.Error())
return
@@ -418,10 +458,8 @@ func (c *BackendErpContactController) GetContactOrgTree() {
cqs := models.Orm.QueryTable(new(models.BackendErpContact)).
Filter("delete_time__isnull", true).
Exclude("status", 0).
Filter("contact_type", 1)
if tid > 0 {
cqs = cqs.Filter("tid", tid)
}
Filter("contact_type", 1).
Filter("tid", tid)
type orgCount struct {
OrgID uint64 `orm:"column(org_id)"`
@@ -437,6 +475,7 @@ func (c *BackendErpContactController) GetContactOrgTree() {
for _, org := range orgs {
cnt, _ := models.Orm.QueryTable(new(models.BackendErpContact)).
Filter("org_id", org.ID).
Filter("tid", tid).
Filter("delete_time__isnull", true).
Exclude("status", 0).
Filter("contact_type", 1).