bindRolesLogic.go 6.1 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178
  1. package user
  2. import (
  3. "context"
  4. "errors"
  5. "time"
  6. "perms-system-server/internal/consts"
  7. authHelper "perms-system-server/internal/logic/auth"
  8. "perms-system-server/internal/middleware"
  9. "perms-system-server/internal/model/userrole"
  10. "perms-system-server/internal/response"
  11. "perms-system-server/internal/svc"
  12. "perms-system-server/internal/types"
  13. "github.com/zeromicro/go-zero/core/logx"
  14. "github.com/zeromicro/go-zero/core/stores/sqlx"
  15. )
  16. type BindRolesLogic struct {
  17. logx.Logger
  18. ctx context.Context
  19. svcCtx *svc.ServiceContext
  20. }
  21. func NewBindRolesLogic(ctx context.Context, svcCtx *svc.ServiceContext) *BindRolesLogic {
  22. return &BindRolesLogic{
  23. Logger: logx.WithContext(ctx),
  24. ctx: ctx,
  25. svcCtx: svcCtx,
  26. }
  27. }
  28. // BindRoles 绑定用户角色。对指定用户在当前产品下做角色全量覆盖(diff 后批量新增/删除),支持权限级别校验防止越权分配。
  29. func (l *BindRolesLogic) BindRoles(req *types.BindRolesReq) error {
  30. caller := middleware.GetUserDetails(l.ctx)
  31. if caller == nil {
  32. return response.ErrUnauthorized("未登录")
  33. }
  34. targetUser, err := l.svcCtx.SysUserModel.FindOne(l.ctx, req.UserId)
  35. if err != nil {
  36. return response.ErrNotFound("用户不存在")
  37. }
  38. productCode := middleware.GetProductCode(l.ctx)
  39. if err := authHelper.CheckManageAccess(l.ctx, l.svcCtx, req.UserId, productCode, authHelper.WithPrefetchedTarget(targetUser)); err != nil {
  40. return err
  41. }
  42. member, err := l.svcCtx.SysProductMemberModel.FindOneByProductCodeUserId(l.ctx, productCode, req.UserId)
  43. if err != nil {
  44. return response.ErrBadRequest("目标用户不是当前产品的成员")
  45. }
  46. if member.Status != consts.StatusEnabled {
  47. return response.ErrBadRequest("目标用户的成员资格已被禁用")
  48. }
  49. roleIds := req.RoleIds
  50. if len(roleIds) > 0 {
  51. seen := make(map[int64]bool, len(roleIds))
  52. uniqueIds := make([]int64, 0, len(roleIds))
  53. for _, id := range roleIds {
  54. if !seen[id] {
  55. seen[id] = true
  56. uniqueIds = append(uniqueIds, id)
  57. }
  58. }
  59. roleIds = uniqueIds
  60. }
  61. if len(roleIds) > 0 {
  62. roles, err := l.svcCtx.SysRoleModel.FindByIds(l.ctx, roleIds)
  63. if err != nil {
  64. return err
  65. }
  66. if int64(len(roles)) != int64(len(roleIds)) {
  67. return response.ErrBadRequest("包含无效的角色ID")
  68. }
  69. // 审计 M-R10-3:caller 在一次请求内不变,loadFreshMinPermsLevel 的结果也不变;改由
  70. // LoadCallerAssignableLevel 打一次 DB 取 snapshot,循环内对每个角色走 CheckRoleLevelAgainst
  71. // 做常数时间比较,把"批量绑 N 个 role → N 次 DB" 降到 1 次,同时缩小 caller 降权期间
  72. // 的 TOCTOU 窗口(原实现每次循环都重新读,反而给"超管在 loop 中途降级 caller"N 个窗口)。
  73. assignable, err := authHelper.LoadCallerAssignableLevel(l.ctx, l.svcCtx, caller)
  74. if err != nil {
  75. return err
  76. }
  77. for _, r := range roles {
  78. if r.ProductCode != productCode {
  79. return response.ErrBadRequest("不能绑定其他产品的角色")
  80. }
  81. if r.Status != consts.StatusEnabled {
  82. return response.ErrBadRequest("不能绑定已禁用的角色")
  83. }
  84. if err := authHelper.CheckRoleLevelAgainst(assignable, r.PermsLevel); err != nil {
  85. return err
  86. }
  87. }
  88. }
  89. newSet := make(map[int64]bool, len(roleIds))
  90. for _, id := range roleIds {
  91. newSet[id] = true
  92. }
  93. // 审计 M-R10-2:把"existing 读 + diff + delete/insert"整段收敛进事务,事务第一步以
  94. // FindOneForUpdateTx(member.Id) 锁住 sys_product_member 行,相当于把同一 (userId,
  95. // productCode) 下的并发 BindRoles 串行化;"A 完整覆盖 → B 基于 A 的最终态覆盖" 是唯一
  96. // 可能的交错,消除 RMW 第三态。member 行 lock 也保证了进入事务期间 member 不会被并发
  97. // RemoveMember 清零(那条路径本身也持该行 FOR UPDATE)。
  98. if err := l.svcCtx.SysUserRoleModel.TransactCtx(l.ctx, func(ctx context.Context, session sqlx.Session) error {
  99. if _, err := l.svcCtx.SysProductMemberModel.FindOneForUpdateTx(ctx, session, member.Id); err != nil {
  100. return err
  101. }
  102. // 审计 M-R12-1:对本次将要出现在 sys_user_role 里的 roleIds(事务外校验通过的入参集合)
  103. // 加 S 锁,闭合与 DeleteRole 的写偏斜。DeleteRole 末尾对 sys_role[R] 的 X 锁会被本 S 锁
  104. // 阻塞;等 BindRoles 提交后,DeleteRole 会在 FindUserIdsByRoleIdForUpdateTx 里看到新插入
  105. // 的绑定行,下游 BatchDel 能覆盖到这批用户缓存,不再留下孤儿 sys_user_role。
  106. // 注:只锁"本次请求携带的 roleIds"——已有但未出现在本次请求里的 existing 角色会被 diff
  107. // 到 toRemove,DELETE 自身就会对 sys_user_role 行取 X 锁,不依赖 sys_role 的 S 锁。
  108. if len(roleIds) > 0 {
  109. if err := l.svcCtx.SysRoleModel.LockRolesForShareTx(ctx, session, roleIds); err != nil {
  110. if errors.Is(err, sqlx.ErrNotFound) {
  111. return response.ErrBadRequest("包含已被删除或已禁用的角色ID")
  112. }
  113. return err
  114. }
  115. }
  116. existingRoleIds, err := l.svcCtx.SysUserRoleModel.FindRoleIdsByUserIdForProductTx(ctx, session, req.UserId, productCode)
  117. if err != nil {
  118. return err
  119. }
  120. existingSet := make(map[int64]bool, len(existingRoleIds))
  121. for _, id := range existingRoleIds {
  122. existingSet[id] = true
  123. }
  124. var toAdd []int64
  125. for _, id := range roleIds {
  126. if !existingSet[id] {
  127. toAdd = append(toAdd, id)
  128. }
  129. }
  130. var toRemove []int64
  131. for _, id := range existingRoleIds {
  132. if !newSet[id] {
  133. toRemove = append(toRemove, id)
  134. }
  135. }
  136. if len(toAdd) == 0 && len(toRemove) == 0 {
  137. return nil
  138. }
  139. if err := l.svcCtx.SysUserRoleModel.DeleteByUserIdAndRoleIdsTx(ctx, session, req.UserId, toRemove); err != nil {
  140. return err
  141. }
  142. if len(toAdd) > 0 {
  143. now := time.Now().Unix()
  144. data := make([]*userrole.SysUserRole, 0, len(toAdd))
  145. for _, roleId := range toAdd {
  146. data = append(data, &userrole.SysUserRole{
  147. UserId: req.UserId,
  148. RoleId: roleId,
  149. CreateTime: now,
  150. UpdateTime: now,
  151. })
  152. }
  153. return l.svcCtx.SysUserRoleModel.BatchInsertWithTx(ctx, session, data)
  154. }
  155. return nil
  156. }); err != nil {
  157. return err
  158. }
  159. l.svcCtx.UserDetailsLoader.Clean(l.ctx, req.UserId)
  160. return nil
  161. }