deleteRoleLogic.go 2.0 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465
  1. package role
  2. import (
  3. "context"
  4. "perms-system-server/internal/loaders"
  5. authHelper "perms-system-server/internal/logic/auth"
  6. "perms-system-server/internal/response"
  7. "perms-system-server/internal/svc"
  8. "perms-system-server/internal/types"
  9. "github.com/zeromicro/go-zero/core/logx"
  10. "github.com/zeromicro/go-zero/core/stores/sqlx"
  11. )
  12. type DeleteRoleLogic struct {
  13. logx.Logger
  14. ctx context.Context
  15. svcCtx *svc.ServiceContext
  16. }
  17. func NewDeleteRoleLogic(ctx context.Context, svcCtx *svc.ServiceContext) *DeleteRoleLogic {
  18. return &DeleteRoleLogic{
  19. Logger: logx.WithContext(ctx),
  20. ctx: ctx,
  21. svcCtx: svcCtx,
  22. }
  23. }
  24. // DeleteRole 删除角色。在事务内同时清理角色-权限和用户-角色绑定关系后删除角色,并批量清理受影响用户的权限缓存。
  25. func (l *DeleteRoleLogic) DeleteRole(req *types.DeleteRoleReq) error {
  26. role, err := l.svcCtx.SysRoleModel.FindOne(l.ctx, req.Id)
  27. if err != nil {
  28. return response.ErrNotFound("角色不存在")
  29. }
  30. if err := authHelper.RequireProductAdminFor(l.ctx, role.ProductCode); err != nil {
  31. return err
  32. }
  33. var affectedUserIds []int64
  34. if err := l.svcCtx.SysRoleModel.TransactCtx(l.ctx, func(ctx context.Context, session sqlx.Session) error {
  35. var err error
  36. affectedUserIds, err = l.svcCtx.SysUserRoleModel.FindUserIdsByRoleIdForUpdateTx(ctx, session, req.Id)
  37. if err != nil {
  38. return err
  39. }
  40. if err := l.svcCtx.SysRolePermModel.DeleteByRoleIdTx(ctx, session, req.Id); err != nil {
  41. return err
  42. }
  43. if err := l.svcCtx.SysUserRoleModel.DeleteByRoleIdTx(ctx, session, req.Id); err != nil {
  44. return err
  45. }
  46. return l.svcCtx.SysRoleModel.DeleteWithTx(ctx, session, req.Id)
  47. }); err != nil {
  48. return err
  49. }
  50. // 审计 L-R13-5 方案 A:角色被删除后所有持有者的 loadRoles / loadPerms 结果都要刷新,
  51. // detached ctx 防止请求 ctx 取消把 BatchDel 打断导致旧权限滞留 TTL 窗口。
  52. cleanCtx, cancel := loaders.DetachCacheCleanCtx(l.ctx)
  53. defer cancel()
  54. l.svcCtx.UserDetailsLoader.BatchDel(cleanCtx, affectedUserIds, role.ProductCode)
  55. return nil
  56. }