bindRolesLogic.go 3.9 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147
  1. package user
  2. import (
  3. "context"
  4. "time"
  5. "perms-system-server/internal/consts"
  6. authHelper "perms-system-server/internal/logic/auth"
  7. "perms-system-server/internal/middleware"
  8. "perms-system-server/internal/model/userrole"
  9. "perms-system-server/internal/response"
  10. "perms-system-server/internal/svc"
  11. "perms-system-server/internal/types"
  12. "github.com/zeromicro/go-zero/core/logx"
  13. "github.com/zeromicro/go-zero/core/stores/sqlx"
  14. )
  15. type BindRolesLogic struct {
  16. logx.Logger
  17. ctx context.Context
  18. svcCtx *svc.ServiceContext
  19. }
  20. func NewBindRolesLogic(ctx context.Context, svcCtx *svc.ServiceContext) *BindRolesLogic {
  21. return &BindRolesLogic{
  22. Logger: logx.WithContext(ctx),
  23. ctx: ctx,
  24. svcCtx: svcCtx,
  25. }
  26. }
  27. // BindRoles 绑定用户角色。对指定用户在当前产品下做角色全量覆盖(diff 后批量新增/删除),支持权限级别校验防止越权分配。
  28. func (l *BindRolesLogic) BindRoles(req *types.BindRolesReq) error {
  29. caller := middleware.GetUserDetails(l.ctx)
  30. if caller == nil {
  31. return response.ErrUnauthorized("未登录")
  32. }
  33. if _, err := l.svcCtx.SysUserModel.FindOne(l.ctx, req.UserId); err != nil {
  34. return response.ErrNotFound("用户不存在")
  35. }
  36. productCode := middleware.GetProductCode(l.ctx)
  37. if err := authHelper.CheckManageAccess(l.ctx, l.svcCtx, req.UserId, productCode); err != nil {
  38. return err
  39. }
  40. member, err := l.svcCtx.SysProductMemberModel.FindOneByProductCodeUserId(l.ctx, productCode, req.UserId)
  41. if err != nil {
  42. return response.ErrBadRequest("目标用户不是当前产品的成员")
  43. }
  44. if member.Status != consts.StatusEnabled {
  45. return response.ErrBadRequest("目标用户的成员资格已被禁用")
  46. }
  47. roleIds := req.RoleIds
  48. if len(roleIds) > 0 {
  49. seen := make(map[int64]bool, len(roleIds))
  50. uniqueIds := make([]int64, 0, len(roleIds))
  51. for _, id := range roleIds {
  52. if !seen[id] {
  53. seen[id] = true
  54. uniqueIds = append(uniqueIds, id)
  55. }
  56. }
  57. roleIds = uniqueIds
  58. }
  59. if len(roleIds) > 0 {
  60. roles, err := l.svcCtx.SysRoleModel.FindByIds(l.ctx, roleIds)
  61. if err != nil {
  62. return err
  63. }
  64. if int64(len(roles)) != int64(len(roleIds)) {
  65. return response.ErrBadRequest("包含无效的角色ID")
  66. }
  67. for _, r := range roles {
  68. if r.ProductCode != productCode {
  69. return response.ErrBadRequest("不能绑定其他产品的角色")
  70. }
  71. if r.Status != consts.StatusEnabled {
  72. return response.ErrBadRequest("不能绑定已禁用的角色")
  73. }
  74. if err := authHelper.GuardRoleLevelAssignable(caller, r.PermsLevel); err != nil {
  75. return err
  76. }
  77. }
  78. }
  79. existingRoleIds, err := l.svcCtx.SysUserRoleModel.FindRoleIdsByUserIdForProduct(l.ctx, req.UserId, productCode)
  80. if err != nil {
  81. return err
  82. }
  83. existingSet := make(map[int64]bool, len(existingRoleIds))
  84. for _, id := range existingRoleIds {
  85. existingSet[id] = true
  86. }
  87. newSet := make(map[int64]bool, len(roleIds))
  88. for _, id := range roleIds {
  89. newSet[id] = true
  90. }
  91. var toAdd []int64
  92. for _, id := range roleIds {
  93. if !existingSet[id] {
  94. toAdd = append(toAdd, id)
  95. }
  96. }
  97. var toRemove []int64
  98. for _, id := range existingRoleIds {
  99. if !newSet[id] {
  100. toRemove = append(toRemove, id)
  101. }
  102. }
  103. if len(toAdd) == 0 && len(toRemove) == 0 {
  104. l.svcCtx.UserDetailsLoader.Clean(l.ctx, req.UserId)
  105. return nil
  106. }
  107. if err := l.svcCtx.SysUserRoleModel.TransactCtx(l.ctx, func(ctx context.Context, session sqlx.Session) error {
  108. if err := l.svcCtx.SysUserRoleModel.DeleteByUserIdAndRoleIdsTx(ctx, session, req.UserId, toRemove); err != nil {
  109. return err
  110. }
  111. if len(toAdd) > 0 {
  112. now := time.Now().Unix()
  113. data := make([]*userrole.SysUserRole, 0, len(toAdd))
  114. for _, roleId := range toAdd {
  115. data = append(data, &userrole.SysUserRole{
  116. UserId: req.UserId,
  117. RoleId: roleId,
  118. CreateTime: now,
  119. UpdateTime: now,
  120. })
  121. }
  122. return l.svcCtx.SysUserRoleModel.BatchInsertWithTx(ctx, session, data)
  123. }
  124. return nil
  125. }); err != nil {
  126. return err
  127. }
  128. l.svcCtx.UserDetailsLoader.Clean(l.ctx, req.UserId)
  129. return nil
  130. }