updateUserLogic.go 4.1 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149
  1. package user
  2. import (
  3. "context"
  4. "errors"
  5. "strings"
  6. "perms-system-server/internal/consts"
  7. authHelper "perms-system-server/internal/logic/auth"
  8. "perms-system-server/internal/middleware"
  9. userModel "perms-system-server/internal/model/user"
  10. "perms-system-server/internal/response"
  11. "perms-system-server/internal/svc"
  12. "perms-system-server/internal/types"
  13. "perms-system-server/internal/util"
  14. "github.com/zeromicro/go-zero/core/logx"
  15. )
  16. type UpdateUserLogic struct {
  17. logx.Logger
  18. ctx context.Context
  19. svcCtx *svc.ServiceContext
  20. }
  21. func NewUpdateUserLogic(ctx context.Context, svcCtx *svc.ServiceContext) *UpdateUserLogic {
  22. return &UpdateUserLogic{
  23. Logger: logx.WithContext(ctx),
  24. ctx: ctx,
  25. svcCtx: svcCtx,
  26. }
  27. }
  28. // UpdateUser 更新用户信息。修改用户昵称、邮箱、手机、备注、部门归属等。用户可修改自身非敏感字段,管理者可修改下属用户信息。
  29. func (l *UpdateUserLogic) UpdateUser(req *types.UpdateUserReq) error {
  30. caller := middleware.GetUserDetails(l.ctx)
  31. if caller == nil {
  32. return response.ErrUnauthorized("未登录")
  33. }
  34. if caller.UserId == req.Id {
  35. if req.DeptId != nil || req.Status != 0 {
  36. return response.ErrForbidden("不允许修改自己的部门和状态")
  37. }
  38. } else {
  39. productCode := middleware.GetProductCode(l.ctx)
  40. if err := authHelper.CheckManageAccess(l.ctx, l.svcCtx, req.Id, productCode); err != nil {
  41. return err
  42. }
  43. }
  44. if req.Status != 0 {
  45. if err := authHelper.ValidateStatusChange(l.ctx, l.svcCtx, caller.UserId, req.Id); err != nil {
  46. return err
  47. }
  48. }
  49. user, err := l.svcCtx.SysUserModel.FindOne(l.ctx, req.Id)
  50. if err != nil {
  51. return response.ErrNotFound("用户不存在")
  52. }
  53. if caller.UserId != req.Id && user.IsSuperAdmin == consts.IsSuperAdminYes {
  54. if req.DeptId != nil {
  55. return response.ErrForbidden("不能通过此接口修改其他超级管理员的部门")
  56. }
  57. }
  58. if req.Nickname != nil && len(*req.Nickname) > 64 {
  59. return response.ErrBadRequest("昵称长度不能超过64个字符")
  60. }
  61. if req.Email != nil && len(*req.Email) > 64 {
  62. return response.ErrBadRequest("邮箱长度不能超过64个字符")
  63. }
  64. if req.Phone != nil && len(*req.Phone) > 32 {
  65. return response.ErrBadRequest("手机号长度不能超过32个字符")
  66. }
  67. if req.Remark != nil && len(*req.Remark) > 255 {
  68. return response.ErrBadRequest("备注长度不能超过255个字符")
  69. }
  70. nickname := user.Nickname
  71. email := user.Email
  72. phone := user.Phone
  73. remark := user.Remark
  74. deptId := user.DeptId
  75. if req.Nickname != nil {
  76. nickname = *req.Nickname
  77. }
  78. if req.Email != nil {
  79. if *req.Email != "" && !util.IsValidEmail(*req.Email) {
  80. return response.ErrBadRequest("邮箱格式不正确")
  81. }
  82. email = *req.Email
  83. }
  84. if req.Phone != nil {
  85. if *req.Phone != "" && !util.IsValidPhone(*req.Phone) {
  86. return response.ErrBadRequest("手机号格式不正确")
  87. }
  88. phone = *req.Phone
  89. }
  90. if req.Remark != nil {
  91. remark = *req.Remark
  92. }
  93. if req.DeptId != nil {
  94. if *req.DeptId > 0 {
  95. newDept, err := l.svcCtx.SysDeptModel.FindOne(l.ctx, *req.DeptId)
  96. if err != nil {
  97. return response.ErrBadRequest("部门不存在")
  98. }
  99. if !caller.IsSuperAdmin &&
  100. caller.MemberType != consts.MemberTypeAdmin &&
  101. caller.DeptPath != "" &&
  102. !strings.HasPrefix(newDept.Path, caller.DeptPath) {
  103. return response.ErrForbidden("无权将用户调入非自己管辖的部门")
  104. }
  105. }
  106. deptId = *req.DeptId
  107. }
  108. statusChanged := false
  109. if req.Status != 0 {
  110. if req.Status != consts.StatusEnabled && req.Status != consts.StatusDisabled {
  111. return response.ErrBadRequest("状态值无效,仅支持 1(启用) 和 2(冻结)")
  112. }
  113. if user.Status != req.Status {
  114. statusChanged = true
  115. }
  116. }
  117. newStatus := user.Status
  118. if statusChanged {
  119. newStatus = req.Status
  120. }
  121. if err := l.svcCtx.SysUserModel.UpdateProfile(
  122. l.ctx, req.Id, user.Username,
  123. nickname, email, phone, remark, deptId,
  124. newStatus, statusChanged, user.UpdateTime,
  125. ); err != nil {
  126. if errors.Is(err, userModel.ErrUpdateConflict) {
  127. return response.ErrConflict("数据已被其他操作修改,请刷新后重试")
  128. }
  129. return err
  130. }
  131. l.svcCtx.UserDetailsLoader.Clean(l.ctx, req.Id)
  132. return nil
  133. }