This commit is contained in:
2023-05-22 17:32:08 +08:00
parent 3dc6fb7828
commit 3baba77120
25 changed files with 457 additions and 10 deletions

View File

@ -80,4 +80,5 @@ public interface SysRoleApiService {
* @return 结果
*/
int changeStatus(String roleId, String status);
}

View File

@ -0,0 +1,29 @@
package com.qiaoba.auth.annotation;
import java.lang.annotation.*;
/**
* 数据权限过滤注解
*
* @author ruoyi
*/
@Target(ElementType.METHOD)
@Retention(RetentionPolicy.RUNTIME)
@Documented
public @interface DataScope
{
/**
* 部门表的别名
*/
public String deptAlias() default "";
/**
* 用户表的别名
*/
public String userAlias() default "";
/**
* 权限字符(用于多个角色匹配符合要求的权限)默认根据权限注解@ss获取多个权限用逗号分隔开来
*/
public String permission() default "";
}

View File

@ -0,0 +1,110 @@
package com.qiaoba.auth.aspectj;
import cn.hutool.core.collection.CollUtil;
import cn.hutool.core.util.StrUtil;
import com.qiaoba.auth.annotation.DataScope;
import com.qiaoba.auth.entity.LoginUser;
import com.qiaoba.auth.entity.dto.RoleDto;
import org.aspectj.lang.JoinPoint;
import org.aspectj.lang.annotation.Aspect;
import org.aspectj.lang.annotation.Before;
import org.springframework.stereotype.Component;
import java.util.ArrayList;
import java.util.List;
/**
* 数据过滤处理
*
* @author ruoyi
*/
@Aspect
@Component
public class DataScopeAspect {
/**
* 全部数据权限
*/
public static final String DATA_SCOPE_ALL = "1";
/**
* 自定数据权限
*/
public static final String DATA_SCOPE_CUSTOM = "2";
/**
* 部门数据权限
*/
public static final String DATA_SCOPE_DEPT = "3";
/**
* 部门及以下数据权限
*/
public static final String DATA_SCOPE_DEPT_AND_CHILD = "4";
/**
* 仅本人数据权限
*/
public static final String DATA_SCOPE_SELF = "5";
/**
* 数据权限过滤关键字
*/
public static final String DATA_SCOPE = "dataScope";
@Before("@annotation(controllerDataScope)")
public void doBefore(JoinPoint point, DataScope controllerDataScope) throws Throwable {
}
/**
* 数据范围过滤
*
* @param joinPoint 切点
* @param user 用户
* @param deptAlias 部门别名
* @param userAlias 用户别名
*/
public static void dataScopeFilter(JoinPoint joinPoint, LoginUser user, String deptAlias, String userAlias) {
StringBuilder sqlString = new StringBuilder();
List<String> conditions = new ArrayList<String>();
for (RoleDto role : user.getRoles()) {
String dataScope = role.getDataScope();
if (!DATA_SCOPE_CUSTOM.equals(dataScope) && conditions.contains(dataScope)) {
continue;
}
if (DATA_SCOPE_ALL.equals(dataScope)) {
sqlString = new StringBuilder();
conditions.add(dataScope);
break;
} else if (DATA_SCOPE_CUSTOM.equals(dataScope)) {
sqlString.append(StrUtil.format(
" OR {}.dept_id IN ( SELECT dept_id FROM sys_role_dept WHERE role_id = {} ) ", deptAlias,
role.getRoleId()));
} else if (DATA_SCOPE_DEPT.equals(dataScope)) {
sqlString.append(StrUtil.format(" OR {}.dept_id = {} ", deptAlias, user.getDeptId()));
} else if (DATA_SCOPE_DEPT_AND_CHILD.equals(dataScope)) {
sqlString.append(StrUtil.format(
// todo
" OR {}.dept_id IN ( SELECT dept_id FROM sys_dept WHERE dept_id = {} or {} )",
deptAlias, user.getDeptId(), user.getDeptId()));
} else if (DATA_SCOPE_SELF.equals(dataScope)) {
if (StrUtil.isNotBlank(userAlias)) {
sqlString.append(StrUtil.format(" OR {}.user_id = {} ", userAlias, user.getUserId()));
} else {
// 数据权限为仅本人且没有userAlias别名不查询任何数据
sqlString.append(StrUtil.format(" OR {}.dept_id = 0 ", deptAlias));
}
}
conditions.add(dataScope);
}
// 多角色情况下所有角色都不包含传递过来的权限字符这个时候sqlString也会为空所以要限制一下,不查询任何数据
if (CollUtil.isEmpty(conditions)) {
sqlString.append(StrUtil.format(" OR {}.dept_id = 0 ", deptAlias));
}
//find_in_set( {} , ancestors )
}
}

View File

@ -0,0 +1,24 @@
package com.qiaoba.auth.context;
import cn.hutool.core.convert.Convert;
import org.springframework.web.context.request.RequestAttributes;
import org.springframework.web.context.request.RequestContextHolder;
/**
* 权限信息
*
* @author ruoyi
*/
public class PermissionContextHolder {
private static final String PERMISSION_CONTEXT_ATTRIBUTES = "PERMISSION_CONTEXT";
public static void setContext(String permission) {
RequestContextHolder.currentRequestAttributes().setAttribute(PERMISSION_CONTEXT_ATTRIBUTES, permission,
RequestAttributes.SCOPE_REQUEST);
}
public static String getContext() {
return Convert.toStr(RequestContextHolder.currentRequestAttributes().getAttribute(PERMISSION_CONTEXT_ATTRIBUTES,
RequestAttributes.SCOPE_REQUEST));
}
}

View File

@ -2,6 +2,7 @@ package com.qiaoba.auth.entity;
import cn.hutool.core.util.StrUtil;
import com.fasterxml.jackson.annotation.JsonIgnore;
import com.qiaoba.auth.entity.dto.RoleDto;
import org.springframework.security.core.GrantedAuthority;
import org.springframework.security.core.authority.SimpleGrantedAuthority;
import org.springframework.security.core.userdetails.UserDetails;
@ -54,6 +55,7 @@ public class LoginUser implements UserDetails {
*/
private Set<String> permissions;
private List<RoleDto> roles;
public LoginUser() {
}
@ -67,6 +69,14 @@ public class LoginUser implements UserDetails {
this.roleKeys = roleKeys;
}
public List<RoleDto> getRoles() {
return roles;
}
public void setRoles(List<RoleDto> roles) {
this.roles = roles;
}
public String getUserId() {
return userId;
}

View File

@ -0,0 +1,18 @@
package com.qiaoba.auth.entity.dto;
import lombok.Data;
/**
* 角色
*
* @author ailanyin
* @version 1.0
* @since 2023/5/22 17:08
*/
@Data
public class RoleDto {
private String roleId;
private String roleKey;
private String dataScope;
}

View File

@ -20,5 +20,9 @@
<groupId>org.springframework.boot</groupId>
<artifactId>spring-boot-starter-validation</artifactId>
</dependency>
<dependency>
<groupId>org.springframework.boot</groupId>
<artifactId>spring-boot-starter-aop</artifactId>
</dependency>
</dependencies>
</project>

View File

@ -19,6 +19,11 @@ public class BaseConstant {
*/
public static final String DEFAULT_SPLIT_STR = ",";
/**
* 竖线拼接符号: '|'(英文竖线)
*/
public static final String LINE_JOIN_STR = "|";
/**
* 树的key的命名
*/

View File

@ -0,0 +1,43 @@
package com.qiaoba.common.base.context;
import java.util.HashMap;
import java.util.Map;
/**
* 全局上下文对象
*
* @author ailanyin
* @version 1.0
* @since 2023/5/22 17:24
*/
public class BaseContext {
private static final String DATABASE_TYPE_MAP_KEY = "databaseType";
private static final ThreadLocal<Map<String, Object>> CONTEXT_HOLDER = new ThreadLocal<>();
/**
* 获取上下文中的数据源
*/
public String getDatabaseType() {
return CONTEXT_HOLDER.get().get(DATABASE_TYPE_MAP_KEY).toString();
}
/**
* 设置上下文中的数据源
*/
public void setDatabaseType(String type) {
Map<String, Object> map = new HashMap<>(1);
map.put(DATABASE_TYPE_MAP_KEY, type);
CONTEXT_HOLDER.set(map);
}
/**
* 清除上下文中的数据源
*/
public void clearDataSource() {
CONTEXT_HOLDER.remove();
}
}

View File

@ -0,0 +1,51 @@
package com.qiaoba.common.database.enums;
import cn.hutool.core.util.StrUtil;
import lombok.AllArgsConstructor;
import lombok.Getter;
/**
* 数据库类型
*
* @author ailanyin
* @version 1.0
* @since 2023/5/22 16:41
*/
@Getter
@AllArgsConstructor
public enum DataBaseTypeEnum {
/**
* MySQL
*/
MY_SQL("MySQL"),
/**
* Oracle
*/
ORACLE("Oracle"),
/**
* PostgreSQL
*/
POSTGRE_SQL("PostgreSQL"),
/**
* SQL Server
*/
SQL_SERVER("Microsoft SQL Server");
private final String type;
public static DataBaseTypeEnum find(String databaseProductName) {
if (StrUtil.isBlank(databaseProductName)) {
return null;
}
for (DataBaseTypeEnum type : values()) {
if (type.getType().equals(databaseProductName)) {
return type;
}
}
return null;
}
}

View File

@ -3,6 +3,7 @@ package com.qiaoba.common.database.filters;
import com.qiaoba.common.base.utils.TenantUtil;
import com.qiaoba.common.database.config.DynamicDataSourceContext;
import com.qiaoba.common.database.constants.DynamicDatasourceConstant;
import com.qiaoba.common.database.utils.DatabaseUtil;
import com.qiaoba.common.web.utils.ResponseUtil;
import org.springframework.core.annotation.Order;
import org.springframework.stereotype.Component;
@ -36,6 +37,7 @@ public class DynamicDataSourceFilter extends OncePerRequestFilter {
dynamicDataSourceContext.setDataSource(DynamicDatasourceConstant.DEFAULT_MASTER_DATASOURCE_KEY);
// todo
TenantUtil.setTenantId("1");
DatabaseUtil.handleFindInSet();
filterChain.doFilter(request, response);
dynamicDataSourceContext.clearDataSource();
TenantUtil.clearTenantId();

View File

@ -0,0 +1,55 @@
package com.qiaoba.common.database.utils;
import cn.hutool.core.convert.Convert;
import com.qiaoba.common.base.exceptions.ServiceException;
import com.qiaoba.common.database.config.DynamicDataSourceConfig;
import com.qiaoba.common.database.enums.DataBaseTypeEnum;
import lombok.extern.slf4j.Slf4j;
import javax.sql.DataSource;
import java.sql.Connection;
import java.sql.DatabaseMetaData;
import java.sql.SQLException;
/**
* 数据库工具类
*
* @author ailanyin
* @version 1.0
* @since 2023/5/22 16:41
*/
@Slf4j
public class DatabaseUtil {
/**
* 获取当前数据库类型
*/
public static DataBaseTypeEnum getDataBaseType() {
DataSource dataSource = (DataSource) DynamicDataSourceConfig.DATA_SOURCE_MAP.get("");
try (Connection conn = dataSource.getConnection()) {
DatabaseMetaData metaData = conn.getMetaData();
String databaseProductName = metaData.getDatabaseProductName();
return DataBaseTypeEnum.find(databaseProductName);
} catch (SQLException e) {
throw new ServiceException(e.getMessage());
}
}
public static String handleFindInSet(Object var1, String var2) {
DataBaseTypeEnum dataBaseType = getDataBaseType();
String var = Convert.toStr(var1);
if (dataBaseType == DataBaseTypeEnum.SQL_SERVER) {
// charindex(',100,' , ',0,100,101,') <> 0
return "charindex('," + var + ",' , ','+" + var2 + "+',') <> 0";
} else if (dataBaseType == DataBaseTypeEnum.POSTGRE_SQL) {
// (select position(',100,' in ',0,100,101,')) <> 0
return "(select position('," + var + ",' in ','||" + var2 + "||',')) <> 0";
} else if (dataBaseType == DataBaseTypeEnum.ORACLE) {
// instr(',0,100,101,' , ',100,') <> 0
return "instr(','||" + var2 + "||',' , '," + var + ",') <> 0";
}
// find_in_set(100 , '0,100,101')
return "find_in_set(" + var + " , " + var2 + ") <> 0";
}
}

View File

@ -50,9 +50,9 @@ public interface RedisService {
/**
* 批量删除
*
* @param collection keys
* @param keys keys
*/
void del(Collection<String> collection);
void del(Collection<String> keys);
/**

View File

@ -12,6 +12,7 @@ import java.util.List;
import java.util.Map;
import java.util.Set;
import java.util.concurrent.TimeUnit;
import java.util.stream.Collectors;
/**
* 自定义Redis接口实现类
@ -47,9 +48,9 @@ public class RedisServiceImpl implements RedisService {
}
@Override
public void del(Collection<String> collection) {
// todo
redisTemplate.delete(collection);
public void del(Collection<String> keys) {
List<String> list = keys.stream().map(key -> key = handleKey(key)).collect(Collectors.toList());
redisTemplate.delete(list);
}
@Override

View File

@ -4,6 +4,8 @@ import com.qiaoba.api.system.entity.dto.ResetUserBasicInfoDto;
import com.qiaoba.auth.utils.SecurityUtil;
import com.qiaoba.common.base.result.AjaxResult;
import com.qiaoba.module.system.service.SysProfileService;
import com.qiaoba.module.system.service.SysUserPostService;
import com.qiaoba.module.system.service.SysUserRoleService;
import com.qiaoba.module.system.service.SysUserService;
import io.swagger.v3.oas.annotations.Operation;
import io.swagger.v3.oas.annotations.tags.Tag;
@ -26,15 +28,16 @@ public class SysProfileController {
private final SysProfileService sysProfileService;
private final SysUserService sysUserService;
private final SysUserRoleService sysUserRoleService;
private final SysUserPostService sysUserPostService;
@GetMapping
@Operation(summary = "基本信息")
public AjaxResult profile() {
String username = SecurityUtil.getLoginUserId();
AjaxResult ajax = AjaxResult.success(sysUserService.selectById(username, false));
// todo
ajax.put("roleGroup", "超级管理员,普通角色");
ajax.put("postGroup", "董事长");
String userId = SecurityUtil.getLoginUserId();
AjaxResult ajax = AjaxResult.success(sysUserService.selectById(userId, false));
ajax.put("roleGroup", sysUserRoleService.selectRoleGroup(userId));
ajax.put("postGroup", sysUserPostService.selectPostGroup(userId));
return ajax;
}

View File

@ -39,4 +39,11 @@ public interface SysRoleMapper extends BaseMapper<SysRole> {
*/
String selectBindUserByRoleId(@Param("list") List<String> ids);
/**
* 查询用户拥有角色
*
* @param userId userId
* @return 角色名称
*/
List<String> selectRoleGroupByUserId(String userId);
}

View File

@ -22,6 +22,14 @@ public interface SysUserPostMapper extends BaseMapper<SysUserPost> {
*/
List<String> selectPostIdsByUserId(String userId);
/**
* 通过userId查询所绑定的岗位名称列表
*
* @param userId userId
* @return postNames
*/
List<String> selectPostNamesByUserId(String userId);
/**
* 查询正在被使用的岗位名称列表
*

View File

@ -33,6 +33,15 @@ public interface SysUserRoleMapper extends BaseMapper<SysUserRole> {
*/
List<String> selectRoleKeysByUserId(@Param("userId") String userId, @Param("status") String status);
/**
* 通过userId查询所绑定的角色Key列表
*
* @param userId userId
* @param status 状态
* @return roleIds
*/
List<String> selectRoleNamesByUserId(@Param("userId") String userId, @Param("status") String status);
/**
* 批量取消角色所绑定的用户
*

View File

@ -49,4 +49,12 @@ public interface SysUserPostService {
* @return postNames
*/
List<String> selectUsedPostNameByIds(List<String> postIds);
/**
* 查询用户拥有的岗位
*
* @param userId userId
* @return 岗位 逗号拼接
*/
String selectPostGroup(String userId);
}

View File

@ -60,6 +60,15 @@ public interface SysUserRoleService {
*/
List<String> selectRoleKeysByUserId(String userId, String status);
/**
* 通过userId查询所绑定的角色Key列表
*
* @param userId userId
* @param status 状态
* @return roleNames
*/
List<String> selectRoleNamesByUserId(String userId, String status);
/**
* 批量选择用户授权
*
@ -67,4 +76,12 @@ public interface SysUserRoleService {
* @param userIds userIds
*/
void insertAuthUsers(String roleId, List<String> userIds);
/**
* 查询用户拥有的角色
*
* @param userId userId
* @return 角色 逗号拼接
*/
String selectRoleGroup(String userId);
}

View File

@ -11,6 +11,7 @@ import com.qiaoba.api.system.entity.dto.DataScopeDto;
import com.qiaoba.api.system.entity.dto.SysRoleDto;
import com.qiaoba.api.system.entity.param.SysRoleParam;
import com.qiaoba.auth.utils.SecurityUtil;
import com.qiaoba.common.base.constants.BaseConstant;
import com.qiaoba.common.base.exceptions.ServiceException;
import com.qiaoba.common.database.entity.PageQuery;
import com.qiaoba.common.database.entity.TableDataInfo;

View File

@ -1,8 +1,11 @@
package com.qiaoba.module.system.service.impl;
import cn.hutool.core.collection.CollUtil;
import cn.hutool.core.util.StrUtil;
import com.baomidou.mybatisplus.core.conditions.query.QueryWrapper;
import com.baomidou.mybatisplus.extension.toolkit.Db;
import com.qiaoba.api.system.entity.SysUserPost;
import com.qiaoba.common.base.constants.BaseConstant;
import com.qiaoba.module.system.mapper.SysUserPostMapper;
import com.qiaoba.module.system.service.SysUserPostService;
import lombok.RequiredArgsConstructor;
@ -48,6 +51,12 @@ public class SysUserPostServiceImpl implements SysUserPostService {
return sysUserPostMapper.selectUsedPostNameByIds(postIds);
}
@Override
public String selectPostGroup(String userId) {
List<String> list = sysUserPostMapper.selectPostNamesByUserId(userId);
return CollUtil.isNotEmpty(list) ? StrUtil.join(BaseConstant.LINE_JOIN_STR, list) : StrUtil.EMPTY;
}
private QueryWrapper<SysUserPost> createWrapper(String userId) {
QueryWrapper<SysUserPost> wrapper = new QueryWrapper<>();
wrapper.lambda()

View File

@ -1,8 +1,12 @@
package com.qiaoba.module.system.service.impl;
import cn.hutool.core.collection.CollUtil;
import cn.hutool.core.util.StrUtil;
import com.baomidou.mybatisplus.core.conditions.query.QueryWrapper;
import com.baomidou.mybatisplus.extension.toolkit.Db;
import com.qiaoba.api.system.entity.SysUserRole;
import com.qiaoba.common.base.constants.BaseConstant;
import com.qiaoba.common.base.enums.BaseEnum;
import com.qiaoba.module.system.mapper.SysUserRoleMapper;
import com.qiaoba.module.system.service.SysUserRoleService;
import lombok.RequiredArgsConstructor;
@ -54,6 +58,11 @@ public class SysUserRoleServiceImpl implements SysUserRoleService {
return sysUserRoleMapper.selectRoleKeysByUserId(userId, status);
}
@Override
public List<String> selectRoleNamesByUserId(String userId, String status) {
return sysUserRoleMapper.selectRoleNamesByUserId(userId, status);
}
@Override
public void insertAuthUsers(String roleId, List<String> userIds) {
List<SysUserRole> list = new ArrayList<>();
@ -63,6 +72,12 @@ public class SysUserRoleServiceImpl implements SysUserRoleService {
Db.saveBatch(list);
}
@Override
public String selectRoleGroup(String userId) {
List<String> list = selectRoleNamesByUserId(userId, BaseEnum.NORMAL.getCode());
return CollUtil.isNotEmpty(list) ? StrUtil.join(BaseConstant.LINE_JOIN_STR, list) : StrUtil.EMPTY;
}
private QueryWrapper<SysUserRole> createWrapper(String userId) {
QueryWrapper<SysUserRole> wrapper = new QueryWrapper<>();
wrapper.lambda()

View File

@ -8,6 +8,14 @@
select post_id from sys_user_post where user_id = #{userId}
</select>
<select id="selectPostNamesByUserId" resultType="string">
select t2.post_name
from sys_user_post t1
left join sys_post t2 on t1.post_id = t2.post_id
where t1.user_id = #{userId}
order by t2.post_sort asc
</select>
<select id="selectUsedPostNameByIds" resultType="string">
select DISTINCT t1.post_name
from sys_post t1

View File

@ -22,6 +22,15 @@
</if>
</select>
<select id="selectRoleNamesByUserId" resultType="string">
select t2.role_name from sys_user_role t1
left join sys_role t2 on t2.role_id = t1.role_id
where t1.user_id = #{userId}
<if test="status != null and status != ''">
and t2.status = #{status}
</if>
</select>
<delete id="deleteByRoleIdAndUserIds">
delete from sys_user_role where role_id = #{roleId} and user_id in
<foreach collection="list" item="userId" open="(" separator="," close=")">