mirror of
https://github.com/mfish-qf/mfish-nocode.git
synced 2026-09-24 15:45:53 +08:00
feat: 组织角色逻辑完善
This commit is contained in:
@@ -20,4 +20,6 @@ public class UserRole {
|
||||
private String roleName;
|
||||
@ApiModelProperty(value = "角色编码")
|
||||
private String roleCode;
|
||||
@ApiModelProperty(value = "角色来源 0用户 1组织")
|
||||
private int source;
|
||||
}
|
||||
|
||||
@@ -99,10 +99,7 @@ public class SsoOrgController {
|
||||
@DeleteMapping("/{id}")
|
||||
@RequiresPermissions("sys:org:delete")
|
||||
public Result<Boolean> delete(@ApiParam(name = "id", value = "唯一性ID") @PathVariable String id) {
|
||||
if (ssoOrgService.removeOrg(id)) {
|
||||
return Result.ok("组织结构表-删除成功!");
|
||||
}
|
||||
return Result.fail("错误:组织结构表-删除失败!");
|
||||
return ssoOrgService.removeOrg(id);
|
||||
}
|
||||
|
||||
/**
|
||||
|
||||
@@ -17,9 +17,9 @@ import java.util.List;
|
||||
public interface SsoMenuMapper extends BaseMapper<SsoMenu> {
|
||||
int insertMenu(SsoMenu ssoMenu);
|
||||
|
||||
Integer queryMaxMenuLevel(@Param("reqSsoMenu") ReqSsoMenu reqSsoMenu, @Param("userId") String userId);
|
||||
Integer queryMaxMenuLevel(@Param("reqSsoMenu") ReqSsoMenu reqSsoMenu, @Param("roleIds") List<String> roleIds);
|
||||
|
||||
List<SsoMenu> queryMenu(@Param("reqSsoMenu") ReqSsoMenu reqSsoMenu, @Param("levels") List<Integer> levels, @Param("userId") String userId);
|
||||
List<SsoMenu> queryMenu(@Param("reqSsoMenu") ReqSsoMenu reqSsoMenu, @Param("levels") List<Integer> levels, @Param("roleIds") List<String> roleIds);
|
||||
|
||||
/**
|
||||
* 获取按钮权限用户
|
||||
|
||||
@@ -5,6 +5,7 @@ import cn.com.mfish.oauth.req.ReqSsoOrg;
|
||||
import com.baomidou.mybatisplus.core.mapper.BaseMapper;
|
||||
import org.apache.ibatis.annotations.Delete;
|
||||
import org.apache.ibatis.annotations.Param;
|
||||
import org.apache.ibatis.annotations.Select;
|
||||
|
||||
import java.util.List;
|
||||
|
||||
@@ -27,4 +28,9 @@ public interface SsoOrgMapper extends BaseMapper<SsoOrg> {
|
||||
|
||||
@Delete("delete from sso_org_role where org_id = #{orgId}")
|
||||
int deleteOrgRole(String orgId);
|
||||
|
||||
@Select("select count(0) from sso_org_user where org_id = #{orgId}")
|
||||
int queryUserCount(String orgId);
|
||||
@Select("select user_id from sso_org_user where org_id = #{orgId}")
|
||||
List<String> getOrgUserId(String orgId);
|
||||
}
|
||||
|
||||
@@ -28,7 +28,6 @@ public interface SsoRoleMapper extends BaseMapper<SsoRole> {
|
||||
* @param roleId
|
||||
* @return
|
||||
*/
|
||||
@Select("select user_id from sso_user_role where role_id=#{roleId}")
|
||||
List<String> getRoleUser(String roleId);
|
||||
|
||||
@Select("select menu_id from sso_role_menu where role_id=#{roleId}")
|
||||
|
||||
@@ -56,10 +56,13 @@
|
||||
</where>
|
||||
</select>
|
||||
<sql id="menuJoin">
|
||||
<if test="userId != null and userId != ''">
|
||||
<if test="roleIds != null and roleIds.size() > 0">
|
||||
inner join sso_role_menu rm on m.id = rm.menu_id
|
||||
inner join sso_user_role ur on ur.role_id = rm.role_id and ur.user_id = #{userId}
|
||||
inner join sso_role r on r.id = ur.role_id and r.status = 0
|
||||
and rm.role_id in (
|
||||
<foreach collection="roleIds" item="roleId" separator=",">
|
||||
#{roleId}
|
||||
</foreach>
|
||||
)
|
||||
</if>
|
||||
</sql>
|
||||
<!-- 找到当前菜单及所有他的父菜单 -->
|
||||
|
||||
@@ -19,4 +19,13 @@
|
||||
<resultMap id="roleMap" type="cn.com.mfish.oauth.entity.SsoRole">
|
||||
<result property="menus" column="menus" typeHandler="cn.com.mfish.oauth.handler.StrToListTypeHandler"></result>
|
||||
</resultMap>
|
||||
<select id="getRoleUser" resultType="string">
|
||||
select ur.user_id
|
||||
from sso_user_role ur
|
||||
where ur.role_id = #{roleId}
|
||||
union
|
||||
select ou.user_id
|
||||
from sso_org_user ou
|
||||
inner join sso_org_role sor on sor.role_id = #{roleId}
|
||||
</select>
|
||||
</mapper>
|
||||
|
||||
@@ -18,8 +18,9 @@
|
||||
</where>
|
||||
</select>
|
||||
<select id="getUserRoles" resultType="cn.com.mfish.common.oauth.api.entity.UserRole">
|
||||
select r.id, r.role_name, r.role_code
|
||||
select r.id, r.role_name, r.role_code, 0 source
|
||||
from sso_user u
|
||||
inner join sso_client_user cu on cu.user_id = u.id
|
||||
inner join sso_user_role ur on ur.user_id = u.id
|
||||
inner join sso_role r on r.id = ur.role_id
|
||||
<where>
|
||||
@@ -28,10 +29,25 @@
|
||||
and r.client_id = #{clientId}
|
||||
</if>
|
||||
</where>
|
||||
union
|
||||
select r.id, r.role_name, r.role_code,1 source
|
||||
from sso_user u
|
||||
inner join sso_client_user cu on cu.user_id = u.id
|
||||
inner join sso_org_user ou on u.id = ou.user_id
|
||||
inner join sso_org_role sor on ou.org_id = sor.org_id
|
||||
INNER JOIN sso_role r on r.id = sor.role_id
|
||||
<where>
|
||||
r.status = 0 and r.del_flag = 0 and u.id = #{userId}
|
||||
<if test="clientId!= null and clientId != ''">
|
||||
and r.client_id = #{clientId}
|
||||
</if>
|
||||
</where>
|
||||
</select>
|
||||
<select id="getUserPermissions" resultType="java.lang.String">
|
||||
select GROUP_CONCAT(m.permissions) permissions
|
||||
select GROUP_CONCAT(u.permissions) permissions from (
|
||||
select u.id,m.permissions
|
||||
from sso_user u
|
||||
inner join sso_client_user cu on cu.user_id = u.id
|
||||
inner join sso_user_role ur on ur.user_id = u.id
|
||||
inner join sso_role r on r.id = ur.role_id
|
||||
inner join sso_role_menu rm on rm.role_id = ur.role_id
|
||||
@@ -41,10 +57,27 @@
|
||||
and m.permissions is not null
|
||||
and m.permissions != ''
|
||||
<if test="clientId!= null and clientId != ''">
|
||||
and r.client_id = #{clientId}
|
||||
and cu.client_id = #{clientId}
|
||||
</if>
|
||||
</where>
|
||||
order by permissions
|
||||
union
|
||||
select u.id,m.permissions
|
||||
from sso_user u
|
||||
inner join sso_client_user cu on cu.user_id = u.id
|
||||
inner join sso_org_user ou on u.id = ou.user_id
|
||||
inner join sso_org_role sor on ou.org_id = sor.org_id
|
||||
inner join sso_role_menu rm on rm.role_id = sor.role_id
|
||||
inner join sso_menu m on rm.menu_id = m.id
|
||||
<where>
|
||||
u.id = #{userId}
|
||||
and m.permissions is not null
|
||||
and m.permissions != ''
|
||||
<if test="clientId!= null and clientId != ''">
|
||||
and cu.client_id = #{clientId}
|
||||
</if>
|
||||
</where> ) u
|
||||
group by u.id
|
||||
order by u.permissions
|
||||
</select>
|
||||
<select id="isAccountExist" resultType="java.lang.Integer">
|
||||
select count(0) from sso_user
|
||||
@@ -64,12 +97,20 @@
|
||||
typeHandler="cn.com.mfish.oauth.handler.StrToListTypeHandler"></result>
|
||||
</resultMap>
|
||||
<sql id="selectUser">
|
||||
select u.*, o.org_name, ou.org_id, GROUP_CONCAT(ur.role_id) roleIds
|
||||
from sso_user u
|
||||
inner join sso_client_user cu on cu.user_id = u.id
|
||||
left join sso_org_user ou on ou.user_id = u.id
|
||||
left join sso_org o on o.id = ou.org_id
|
||||
left join sso_user_role ur on u.id = ur.user_id
|
||||
select u.*,GROUP_CONCAT(role_id) roleIds from (
|
||||
select u.*, o.org_name, ou.org_id, ur.role_id
|
||||
from sso_user u
|
||||
inner join sso_client_user cu on cu.user_id = u.id
|
||||
left join sso_org_user ou on ou.user_id = u.id
|
||||
left join sso_org o on o.id = ou.org_id
|
||||
left join sso_user_role ur on u.id = ur.user_id
|
||||
union
|
||||
select u.*, o.org_name, ou.org_id, sor.role_id
|
||||
from sso_user u
|
||||
inner join sso_client_user cu on cu.user_id = u.id
|
||||
left join sso_org_user ou on ou.user_id = u.id
|
||||
left join sso_org o on o.id = ou.org_id
|
||||
left join sso_org_role sor on sor.org_id = o.id) u
|
||||
</sql>
|
||||
<select id="getUserById" resultMap="ssoUserMap">
|
||||
<include refid="selectUser"/>
|
||||
@@ -83,7 +124,7 @@
|
||||
<where>
|
||||
u.del_flag = 0
|
||||
<if test="orgId != null and orgId != ''">
|
||||
and o.id = #{orgId}
|
||||
and u.org_id = #{orgId}
|
||||
</if>
|
||||
<if test="phone != null and phone != ''">
|
||||
and u.phone like concat('%',#{phone},'%')
|
||||
@@ -98,7 +139,7 @@
|
||||
and u.status = #{status}
|
||||
</if>
|
||||
<if test="clientId != null and clientId !=''">
|
||||
and cu.client_id = #{clientId}
|
||||
and u.client_id = #{clientId}
|
||||
</if>
|
||||
</where>
|
||||
group by u.id
|
||||
|
||||
@@ -21,7 +21,7 @@ public interface SsoOrgService extends IService<SsoOrg> {
|
||||
|
||||
List<SsoOrg> queryOrg(ReqSsoOrg reqSsoOrg);
|
||||
|
||||
boolean removeOrg(String id);
|
||||
Result<Boolean> removeOrg(String id);
|
||||
|
||||
int insertOrgRole(String orgId, List<String> roles);
|
||||
|
||||
|
||||
@@ -22,4 +22,6 @@ public interface SsoRoleService extends IService<SsoRole> {
|
||||
boolean roleCodeExist(String clientId, String roleId, String roleCode);
|
||||
|
||||
List<String> getRoleMenus(String roleId);
|
||||
|
||||
void removeUserCache(List<String> userIds, String clientId);
|
||||
}
|
||||
|
||||
@@ -4,6 +4,7 @@ import cn.com.mfish.common.core.exception.MyRuntimeException;
|
||||
import cn.com.mfish.common.core.utils.AuthInfoUtils;
|
||||
import cn.com.mfish.common.core.utils.StringUtils;
|
||||
import cn.com.mfish.common.core.web.Result;
|
||||
import cn.com.mfish.common.oauth.common.OauthUtils;
|
||||
import cn.com.mfish.common.redis.common.RedisPrefix;
|
||||
import cn.com.mfish.oauth.cache.temp.UserPermissionTempCache;
|
||||
import cn.com.mfish.oauth.entity.SsoMenu;
|
||||
@@ -47,18 +48,19 @@ public class SsoMenuServiceImpl extends ServiceImpl<SsoMenuMapper, SsoMenu> impl
|
||||
|
||||
@Override
|
||||
public List<SsoMenu> queryMenu(ReqSsoMenu reqSsoMenu, String userId) {
|
||||
List<String> roleIds = new ArrayList<>();
|
||||
//如果是超户获取所有菜单
|
||||
if (AuthInfoUtils.isSuper(userId)) {
|
||||
userId = null;
|
||||
if (!AuthInfoUtils.isSuper(userId)) {
|
||||
roleIds = OauthUtils.getRoles().stream().map((role)->role.getId()).collect(Collectors.toList());
|
||||
}
|
||||
Integer level = baseMapper.queryMaxMenuLevel(reqSsoMenu, userId);
|
||||
Integer level = baseMapper.queryMaxMenuLevel(reqSsoMenu, roleIds);
|
||||
List<Integer> list = new ArrayList<>();
|
||||
if (level != null) {
|
||||
for (int i = 1; i < level; i++) {
|
||||
list.add(i);
|
||||
}
|
||||
}
|
||||
List<SsoMenu> menus = baseMapper.queryMenu(reqSsoMenu, list, userId);
|
||||
List<SsoMenu> menus = baseMapper.queryMenu(reqSsoMenu, list, roleIds);
|
||||
//菜单节点是从底部往上寻找,如果权限只设置了子节点,父节点并未存储
|
||||
//所以根据菜单类型展示时,先全部查出后再过滤不需要的类型
|
||||
if (reqSsoMenu.getMenuType() != null) {
|
||||
|
||||
@@ -10,12 +10,14 @@ import cn.com.mfish.common.oauth.api.entity.SsoOrg;
|
||||
import cn.com.mfish.oauth.mapper.SsoOrgMapper;
|
||||
import cn.com.mfish.oauth.req.ReqSsoOrg;
|
||||
import cn.com.mfish.oauth.service.SsoOrgService;
|
||||
import cn.com.mfish.oauth.service.SsoRoleService;
|
||||
import com.baomidou.mybatisplus.core.conditions.query.LambdaQueryWrapper;
|
||||
import com.baomidou.mybatisplus.extension.service.impl.ServiceImpl;
|
||||
import lombok.extern.slf4j.Slf4j;
|
||||
import org.springframework.stereotype.Service;
|
||||
import org.springframework.transaction.annotation.Transactional;
|
||||
|
||||
import javax.annotation.Resource;
|
||||
import java.text.MessageFormat;
|
||||
import java.util.ArrayList;
|
||||
import java.util.List;
|
||||
@@ -30,6 +32,8 @@ import java.util.stream.Collectors;
|
||||
@Service
|
||||
@Slf4j
|
||||
public class SsoOrgServiceImpl extends ServiceImpl<SsoOrgMapper, SsoOrg> implements SsoOrgService {
|
||||
@Resource
|
||||
SsoRoleService ssoRoleService;
|
||||
|
||||
@Override
|
||||
@Transactional
|
||||
@@ -80,10 +84,12 @@ public class SsoOrgServiceImpl extends ServiceImpl<SsoOrgMapper, SsoOrg> impleme
|
||||
success = true;
|
||||
}
|
||||
if (success) {
|
||||
if (null != ssoOrg.getRoleIds()) {
|
||||
baseMapper.deleteOrgRole(ssoOrg.getId());
|
||||
log.info(MessageFormat.format("删除组织角色数量:{0}条", baseMapper.deleteOrgRole(ssoOrg.getId())));
|
||||
if (null != ssoOrg.getRoleIds() && !ssoOrg.getRoleIds().isEmpty()) {
|
||||
insertOrgRole(ssoOrg.getId(), ssoOrg.getRoleIds());
|
||||
}
|
||||
List<String> userIds = baseMapper.getOrgUserId(ssoOrg.getId());
|
||||
ssoRoleService.removeUserCache(userIds, ssoOrg.getClientId());
|
||||
return Result.ok(ssoOrg, "组织编辑成功!");
|
||||
}
|
||||
throw new MyRuntimeException("错误:更新组织失败");
|
||||
@@ -136,13 +142,20 @@ public class SsoOrgServiceImpl extends ServiceImpl<SsoOrgMapper, SsoOrg> impleme
|
||||
}
|
||||
|
||||
@Override
|
||||
public boolean removeOrg(String id) {
|
||||
public Result<Boolean> removeOrg(String id) {
|
||||
if (StringUtils.isEmpty(id)) {
|
||||
return Result.fail(false, "错误:组织ID不允许为空");
|
||||
}
|
||||
int count = baseMapper.queryUserCount(id);
|
||||
if (count > 0) {
|
||||
return Result.fail(false, "错误:组织下存在用户,请先移出用户");
|
||||
}
|
||||
if (baseMapper.updateById(new SsoOrg().setId(id).setDelFlag(1)) == 1) {
|
||||
log.info(MessageFormat.format("删除组织成功,组织ID:{0}", id));
|
||||
return true;
|
||||
return Result.ok("删除组织成功");
|
||||
}
|
||||
log.error(MessageFormat.format("删除组织失败,组织ID:{0}", id));
|
||||
return false;
|
||||
return Result.fail("错误:删除组织失败");
|
||||
}
|
||||
|
||||
@Override
|
||||
|
||||
@@ -112,9 +112,17 @@ public class SsoRoleServiceImpl extends ServiceImpl<SsoRoleMapper, SsoRole> impl
|
||||
private void removeRoleCache(String roleId, String clientId) {
|
||||
//查询角色对应的用户并删除角色权限缓存
|
||||
List<String> list = baseMapper.getRoleUser(roleId);
|
||||
removeUserCache(list, clientId);
|
||||
}
|
||||
|
||||
@Override
|
||||
public void removeUserCache(List<String> userIds, String clientId) {
|
||||
if (userIds == null || userIds.isEmpty()) {
|
||||
return;
|
||||
}
|
||||
List<String> roleKeys = new ArrayList<>();
|
||||
List<String> permissionKeys = new ArrayList<>();
|
||||
for (String userId : list) {
|
||||
for (String userId : userIds) {
|
||||
roleKeys.add(RedisPrefix.buildUser2RolesKey(userId, clientId));
|
||||
permissionKeys.add(RedisPrefix.buildUser2PermissionsKey(userId, clientId));
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user