bindRolesLogic.go 3.8 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143
  1. package user
  2. import (
  3. "context"
  4. "fmt"
  5. "time"
  6. "perms-system-server/internal/consts"
  7. authHelper "perms-system-server/internal/logic/auth"
  8. "perms-system-server/internal/middleware"
  9. "perms-system-server/internal/model/userrole"
  10. "perms-system-server/internal/response"
  11. "perms-system-server/internal/svc"
  12. "perms-system-server/internal/types"
  13. "github.com/zeromicro/go-zero/core/logx"
  14. "github.com/zeromicro/go-zero/core/stores/sqlx"
  15. )
  16. type BindRolesLogic struct {
  17. logx.Logger
  18. ctx context.Context
  19. svcCtx *svc.ServiceContext
  20. }
  21. func NewBindRolesLogic(ctx context.Context, svcCtx *svc.ServiceContext) *BindRolesLogic {
  22. return &BindRolesLogic{
  23. Logger: logx.WithContext(ctx),
  24. ctx: ctx,
  25. svcCtx: svcCtx,
  26. }
  27. }
  28. func (l *BindRolesLogic) BindRoles(req *types.BindRolesReq) error {
  29. if _, err := l.svcCtx.SysUserModel.FindOne(l.ctx, req.UserId); err != nil {
  30. return response.ErrNotFound("用户不存在")
  31. }
  32. productCode := middleware.GetProductCode(l.ctx)
  33. if err := authHelper.CheckManageAccess(l.ctx, l.svcCtx, req.UserId, productCode); err != nil {
  34. return err
  35. }
  36. if _, err := l.svcCtx.SysProductMemberModel.FindOneByProductCodeUserId(l.ctx, productCode, req.UserId); err != nil {
  37. return response.ErrBadRequest("目标用户不是当前产品的成员")
  38. }
  39. if len(req.RoleIds) > 0 {
  40. seen := make(map[int64]bool, len(req.RoleIds))
  41. uniqueIds := make([]int64, 0, len(req.RoleIds))
  42. for _, id := range req.RoleIds {
  43. if !seen[id] {
  44. seen[id] = true
  45. uniqueIds = append(uniqueIds, id)
  46. }
  47. }
  48. req.RoleIds = uniqueIds
  49. }
  50. caller := middleware.GetUserDetails(l.ctx)
  51. if len(req.RoleIds) > 0 {
  52. roles, err := l.svcCtx.SysRoleModel.FindByIds(l.ctx, req.RoleIds)
  53. if err != nil {
  54. return err
  55. }
  56. if int64(len(roles)) != int64(len(req.RoleIds)) {
  57. return response.ErrBadRequest("包含无效的角色ID")
  58. }
  59. for _, r := range roles {
  60. if r.ProductCode != productCode {
  61. return response.ErrBadRequest("不能绑定其他产品的角色")
  62. }
  63. if r.Status != consts.StatusEnabled {
  64. return response.ErrBadRequest("不能绑定已禁用的角色")
  65. }
  66. if caller != nil && !caller.IsSuperAdmin {
  67. if caller.MinPermsLevel == 0 || r.PermsLevel < caller.MinPermsLevel {
  68. return response.ErrForbidden("不能分配权限级别高于自身的角色")
  69. }
  70. }
  71. }
  72. }
  73. existingRoleIds, err := l.svcCtx.SysUserRoleModel.FindRoleIdsByUserIdForProduct(l.ctx, req.UserId, productCode)
  74. if err != nil {
  75. return err
  76. }
  77. existingSet := make(map[int64]bool, len(existingRoleIds))
  78. for _, id := range existingRoleIds {
  79. existingSet[id] = true
  80. }
  81. newSet := make(map[int64]bool, len(req.RoleIds))
  82. for _, id := range req.RoleIds {
  83. newSet[id] = true
  84. }
  85. var toAdd []int64
  86. for _, id := range req.RoleIds {
  87. if !existingSet[id] {
  88. toAdd = append(toAdd, id)
  89. }
  90. }
  91. var toRemove []int64
  92. for _, id := range existingRoleIds {
  93. if !newSet[id] {
  94. toRemove = append(toRemove, id)
  95. }
  96. }
  97. if len(toAdd) == 0 && len(toRemove) == 0 {
  98. return nil
  99. }
  100. if err := l.svcCtx.SysUserRoleModel.TransactCtx(l.ctx, func(ctx context.Context, session sqlx.Session) error {
  101. for _, roleId := range toRemove {
  102. query := fmt.Sprintf("DELETE FROM %s WHERE `userId` = ? AND `roleId` = ?", l.svcCtx.SysUserRoleModel.TableName())
  103. if _, err := session.ExecCtx(ctx, query, req.UserId, roleId); err != nil {
  104. return err
  105. }
  106. }
  107. if len(toAdd) > 0 {
  108. now := time.Now().Unix()
  109. data := make([]*userrole.SysUserRole, 0, len(toAdd))
  110. for _, roleId := range toAdd {
  111. data = append(data, &userrole.SysUserRole{
  112. UserId: req.UserId,
  113. RoleId: roleId,
  114. CreateTime: now,
  115. UpdateTime: now,
  116. })
  117. }
  118. return l.svcCtx.SysUserRoleModel.BatchInsertWithTx(ctx, session, data)
  119. }
  120. return nil
  121. }); err != nil {
  122. return err
  123. }
  124. l.svcCtx.UserDetailsLoader.Clean(l.ctx, req.UserId)
  125. return nil
  126. }