更新代码

This commit is contained in:
2026-09-15 10:44:31 +08:00
parent 9875832019
commit 943c3708b0
125 changed files with 2009 additions and 1728 deletions
+64 -7
View File
@@ -145,21 +145,20 @@ func (c *BackendRoleController) currentTenantID() (uint64, bool) {
return uint64(claims.TenantId), true
}
// GetAllRoles 获取当前租户的角色列表
// GetAllRoles 获取当前租户可见的角色列表
// GET /backend/allRoles
// 返回「全局角色(cid=2, tenant_id=0,所有租户共用)」+「本租户自建角色」;
// 全局角色由平台端统一维护,租户端只读。
func (c *BackendRoleController) GetAllRoles() {
tid, ok := c.currentTenantID()
if !ok {
return
}
// 懒加载补齐当前租户的默认角色(租户管理员/部门负责人/员工)
models.EnsureDefaultTenantRoles(tid)
var rows []models.AdminRole
_, err := models.Orm.QueryTable(new(models.AdminRole)).
Filter("cid", 2).
Filter("tenant_id", tid).
OrderBy("-id").
Filter("tenant_id__in", []uint64{0, tid}).
OrderBy("tenant_id", "is_custom", "id").
All(&rows)
if err != nil {
c.Data["json"] = map[string]interface{}{"code": 500, "msg": "查询失败"}
@@ -188,7 +187,7 @@ func (c *BackendRoleController) GetRoleByID() {
if err := models.Orm.QueryTable(new(models.AdminRole)).
Filter("id", id).
Filter("cid", 2).
Filter("tenant_id", tid).
Filter("tenant_id__in", []uint64{0, tid}).
One(&role); err != nil {
c.Data["json"] = map[string]interface{}{"code": 404, "msg": "角色不存在"}
_ = c.ServeJSON()
@@ -218,6 +217,22 @@ func (c *BackendRoleController) CreateRole() {
_ = c.ServeJSON()
return
}
// 不能与本租户可见的角色重名(含平台默认的全局角色),避免混淆
dup, derr := models.Orm.QueryTable(new(models.AdminRole)).
Filter("cid", 2).
Filter("tenant_id__in", []uint64{0, tid}).
Filter("name", p.Name).
Count()
if derr != nil {
c.Data["json"] = map[string]interface{}{"code": 500, "msg": "创建失败"}
_ = c.ServeJSON()
return
}
if dup > 0 {
c.Data["json"] = map[string]interface{}{"code": 400, "msg": "已存在同名角色(含平台默认角色),请更换名称"}
_ = c.ServeJSON()
return
}
status := uint8(1)
if p.Status != nil {
@@ -282,6 +297,37 @@ func (c *BackendRoleController) UpdateRole() {
return
}
// 全局角色(tenant_id=0)由平台端统一维护,租户端只读
var target models.AdminRole
if e := models.Orm.QueryTable(new(models.AdminRole)).
Filter("id", id).
Filter("cid", 2).
One(&target); e == nil && target.TenantID == 0 {
c.Data["json"] = map[string]interface{}{"code": 403, "msg": "全局角色由平台端统一维护,租户端不能修改"}
_ = c.ServeJSON()
return
}
// 改名时不能与可见角色重名(含平台默认的全局角色,排除自身)
if newName, ok := update["name"]; ok {
dup, derr := models.Orm.QueryTable(new(models.AdminRole)).
Filter("cid", 2).
Filter("tenant_id__in", []uint64{0, tid}).
Filter("name", newName).
Exclude("id", id).
Count()
if derr != nil {
c.Data["json"] = map[string]interface{}{"code": 500, "msg": "更新失败"}
_ = c.ServeJSON()
return
}
if dup > 0 {
c.Data["json"] = map[string]interface{}{"code": 400, "msg": "已存在同名角色(含平台默认角色),请更换名称"}
_ = c.ServeJSON()
return
}
}
// 仅允许更新本租户名下的角色,防止越权改到其他租户
cnt, err := models.Orm.QueryTable(new(models.AdminRole)).
Filter("id", id).
@@ -316,6 +362,17 @@ func (c *BackendRoleController) DeleteRole() {
_ = c.ServeJSON()
return
}
// 全局角色(tenant_id=0)由平台端统一维护,租户端不能删除
var target models.AdminRole
if e := models.Orm.QueryTable(new(models.AdminRole)).
Filter("id", id).
Filter("cid", 2).
One(&target); e == nil && target.TenantID == 0 {
c.Data["json"] = map[string]interface{}{"code": 403, "msg": "全局角色由平台端统一维护,租户端不能删除"}
_ = c.ServeJSON()
return
}
// 仅允许删除本租户名下的角色
cnt, err := models.Orm.QueryTable(new(models.AdminRole)).
Filter("id", id).