更新代码
This commit is contained in:
@@ -145,21 +145,20 @@ func (c *BackendRoleController) currentTenantID() (uint64, bool) {
|
||||
return uint64(claims.TenantId), true
|
||||
}
|
||||
|
||||
// GetAllRoles 获取当前租户的角色列表
|
||||
// GetAllRoles 获取当前租户可见的角色列表
|
||||
// GET /backend/allRoles
|
||||
// 返回「全局角色(cid=2, tenant_id=0,所有租户共用)」+「本租户自建角色」;
|
||||
// 全局角色由平台端统一维护,租户端只读。
|
||||
func (c *BackendRoleController) GetAllRoles() {
|
||||
tid, ok := c.currentTenantID()
|
||||
if !ok {
|
||||
return
|
||||
}
|
||||
// 懒加载补齐当前租户的默认角色(租户管理员/部门负责人/员工)
|
||||
models.EnsureDefaultTenantRoles(tid)
|
||||
|
||||
var rows []models.AdminRole
|
||||
_, err := models.Orm.QueryTable(new(models.AdminRole)).
|
||||
Filter("cid", 2).
|
||||
Filter("tenant_id", tid).
|
||||
OrderBy("-id").
|
||||
Filter("tenant_id__in", []uint64{0, tid}).
|
||||
OrderBy("tenant_id", "is_custom", "id").
|
||||
All(&rows)
|
||||
if err != nil {
|
||||
c.Data["json"] = map[string]interface{}{"code": 500, "msg": "查询失败"}
|
||||
@@ -188,7 +187,7 @@ func (c *BackendRoleController) GetRoleByID() {
|
||||
if err := models.Orm.QueryTable(new(models.AdminRole)).
|
||||
Filter("id", id).
|
||||
Filter("cid", 2).
|
||||
Filter("tenant_id", tid).
|
||||
Filter("tenant_id__in", []uint64{0, tid}).
|
||||
One(&role); err != nil {
|
||||
c.Data["json"] = map[string]interface{}{"code": 404, "msg": "角色不存在"}
|
||||
_ = c.ServeJSON()
|
||||
@@ -218,6 +217,22 @@ func (c *BackendRoleController) CreateRole() {
|
||||
_ = c.ServeJSON()
|
||||
return
|
||||
}
|
||||
// 不能与本租户可见的角色重名(含平台默认的全局角色),避免混淆
|
||||
dup, derr := models.Orm.QueryTable(new(models.AdminRole)).
|
||||
Filter("cid", 2).
|
||||
Filter("tenant_id__in", []uint64{0, tid}).
|
||||
Filter("name", p.Name).
|
||||
Count()
|
||||
if derr != nil {
|
||||
c.Data["json"] = map[string]interface{}{"code": 500, "msg": "创建失败"}
|
||||
_ = c.ServeJSON()
|
||||
return
|
||||
}
|
||||
if dup > 0 {
|
||||
c.Data["json"] = map[string]interface{}{"code": 400, "msg": "已存在同名角色(含平台默认角色),请更换名称"}
|
||||
_ = c.ServeJSON()
|
||||
return
|
||||
}
|
||||
|
||||
status := uint8(1)
|
||||
if p.Status != nil {
|
||||
@@ -282,6 +297,37 @@ func (c *BackendRoleController) UpdateRole() {
|
||||
return
|
||||
}
|
||||
|
||||
// 全局角色(tenant_id=0)由平台端统一维护,租户端只读
|
||||
var target models.AdminRole
|
||||
if e := models.Orm.QueryTable(new(models.AdminRole)).
|
||||
Filter("id", id).
|
||||
Filter("cid", 2).
|
||||
One(&target); e == nil && target.TenantID == 0 {
|
||||
c.Data["json"] = map[string]interface{}{"code": 403, "msg": "全局角色由平台端统一维护,租户端不能修改"}
|
||||
_ = c.ServeJSON()
|
||||
return
|
||||
}
|
||||
|
||||
// 改名时不能与可见角色重名(含平台默认的全局角色,排除自身)
|
||||
if newName, ok := update["name"]; ok {
|
||||
dup, derr := models.Orm.QueryTable(new(models.AdminRole)).
|
||||
Filter("cid", 2).
|
||||
Filter("tenant_id__in", []uint64{0, tid}).
|
||||
Filter("name", newName).
|
||||
Exclude("id", id).
|
||||
Count()
|
||||
if derr != nil {
|
||||
c.Data["json"] = map[string]interface{}{"code": 500, "msg": "更新失败"}
|
||||
_ = c.ServeJSON()
|
||||
return
|
||||
}
|
||||
if dup > 0 {
|
||||
c.Data["json"] = map[string]interface{}{"code": 400, "msg": "已存在同名角色(含平台默认角色),请更换名称"}
|
||||
_ = c.ServeJSON()
|
||||
return
|
||||
}
|
||||
}
|
||||
|
||||
// 仅允许更新本租户名下的角色,防止越权改到其他租户
|
||||
cnt, err := models.Orm.QueryTable(new(models.AdminRole)).
|
||||
Filter("id", id).
|
||||
@@ -316,6 +362,17 @@ func (c *BackendRoleController) DeleteRole() {
|
||||
_ = c.ServeJSON()
|
||||
return
|
||||
}
|
||||
// 全局角色(tenant_id=0)由平台端统一维护,租户端不能删除
|
||||
var target models.AdminRole
|
||||
if e := models.Orm.QueryTable(new(models.AdminRole)).
|
||||
Filter("id", id).
|
||||
Filter("cid", 2).
|
||||
One(&target); e == nil && target.TenantID == 0 {
|
||||
c.Data["json"] = map[string]interface{}{"code": 403, "msg": "全局角色由平台端统一维护,租户端不能删除"}
|
||||
_ = c.ServeJSON()
|
||||
return
|
||||
}
|
||||
|
||||
// 仅允许删除本租户名下的角色
|
||||
cnt, err := models.Orm.QueryTable(new(models.AdminRole)).
|
||||
Filter("id", id).
|
||||
|
||||
Reference in New Issue
Block a user