sysRoleModel.go 7.1 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174
  1. package role
  2. import (
  3. "context"
  4. "database/sql"
  5. "errors"
  6. "fmt"
  7. "sort"
  8. "strings"
  9. "perms-system-server/internal/consts"
  10. "github.com/zeromicro/go-zero/core/stores/cache"
  11. "github.com/zeromicro/go-zero/core/stores/sqlx"
  12. )
  13. var ErrUpdateConflict = errors.New("update conflict: data has been modified by another operation")
  14. var _ SysRoleModel = (*customSysRoleModel)(nil)
  15. type (
  16. SysRoleModel interface {
  17. sysRoleModel
  18. FindListByProductCode(ctx context.Context, productCode string, page, pageSize int64) ([]*SysRole, int64, error)
  19. FindByIds(ctx context.Context, ids []int64) ([]*SysRole, error)
  20. FindMinPermsLevelByUserIdAndProductCode(ctx context.Context, userId int64, productCode string) (int64, error)
  21. UpdateWithOptLock(ctx context.Context, data *SysRole, expectedUpdateTime int64) error
  22. // LockByIdTx 在当前事务里锁住 sys_role 行(SELECT ... FOR UPDATE),用于把"同一 role 的
  23. // BindRolePerms 并发覆盖"串行化,消除"existing 在事务外读 + 事务内 delete/insert"
  24. // 造成的第三态合并问题(见审计 M-R10-2)。
  25. LockByIdTx(ctx context.Context, session sqlx.Session, id int64) (*SysRole, error)
  26. // LockRolesForShareTx 在当前事务里对一批 sys_role 行取 S 锁(SELECT ... LOCK IN SHARE MODE),
  27. // 用于闭合 BindRoles × DeleteRole 的写偏斜(审计 M-R12-1):
  28. // DeleteRole 在事务末尾对 sys_role[R] 取 X 锁,会被本 S 锁阻塞;等 BindRoles 提交后
  29. // DeleteRole 再去 FindUserIdsByRoleIdForUpdateTx 时即能看到新插入的 sys_user_role 行,
  30. // 可选择抛错阻断删除或一并清理,不再留下 roleId 指向已删 sys_role 的孤儿。
  31. // 若命中行数 != len(ids) 或有行 status != Enabled,返回 sqlx.ErrNotFound 让调用方
  32. // 转成 400 "包含无效的角色ID"——因为 DeleteRole 的删除发生在 sys_role 行被移走、
  33. // 或者 UpdateRole 把角色 status 改为 Disabled,业务上都不应再绑定。
  34. // 本方法不走缓存,必须在 TransactCtx / Session 下调用;入参 ids 会在内部按升序排序
  35. // 取锁以避免死锁。
  36. LockRolesForShareTx(ctx context.Context, session sqlx.Session, ids []int64) error
  37. }
  38. customSysRoleModel struct {
  39. *defaultSysRoleModel
  40. }
  41. )
  42. func NewSysRoleModel(conn sqlx.SqlConn, c cache.CacheConf, cachePrefix string, opts ...cache.Option) SysRoleModel {
  43. return &customSysRoleModel{
  44. defaultSysRoleModel: newSysRoleModel(conn, c, cachePrefix, opts...),
  45. }
  46. }
  47. func (m *customSysRoleModel) FindListByProductCode(ctx context.Context, productCode string, page, pageSize int64) ([]*SysRole, int64, error) {
  48. var total int64
  49. countQuery := fmt.Sprintf("SELECT COUNT(*) FROM %s WHERE `productCode` = ?", m.table)
  50. if err := m.QueryRowNoCacheCtx(ctx, &total, countQuery, productCode); err != nil {
  51. return nil, 0, err
  52. }
  53. var list []*SysRole
  54. query := fmt.Sprintf("SELECT %s FROM %s WHERE `productCode` = ? ORDER BY `permsLevel` ASC, id DESC LIMIT ?,?", sysRoleRows, m.table)
  55. if err := m.QueryRowsNoCacheCtx(ctx, &list, query, productCode, (page-1)*pageSize, pageSize); err != nil {
  56. return nil, 0, err
  57. }
  58. return list, total, nil
  59. }
  60. func (m *customSysRoleModel) FindByIds(ctx context.Context, ids []int64) ([]*SysRole, error) {
  61. if len(ids) == 0 {
  62. return nil, nil
  63. }
  64. args := make([]interface{}, len(ids))
  65. marks := make([]string, len(ids))
  66. for i, id := range ids {
  67. args[i] = id
  68. marks[i] = "?"
  69. }
  70. var list []*SysRole
  71. query := fmt.Sprintf("SELECT %s FROM %s WHERE `id` IN (%s)", sysRoleRows, m.table, strings.Join(marks, ","))
  72. if err := m.QueryRowsNoCacheCtx(ctx, &list, query, args...); err != nil {
  73. return nil, err
  74. }
  75. return list, nil
  76. }
  77. func (m *customSysRoleModel) UpdateWithOptLock(ctx context.Context, data *SysRole, expectedUpdateTime int64) error {
  78. sysRoleIdKey := fmt.Sprintf("%s%v", cacheSysRoleIdPrefix, data.Id)
  79. sysRoleProductCodeNameKey := fmt.Sprintf("%s%v:%v", cacheSysRoleProductCodeNamePrefix, data.ProductCode, data.Name)
  80. res, err := m.ExecCtx(ctx, func(ctx context.Context, conn sqlx.SqlConn) (sql.Result, error) {
  81. query := fmt.Sprintf("UPDATE %s SET `name`=?, `remark`=?, `status`=?, `permsLevel`=?, `updateTime`=? WHERE `id`=? AND `updateTime`=?", m.table)
  82. return conn.ExecCtx(ctx, query, data.Name, data.Remark, data.Status, data.PermsLevel, data.UpdateTime, data.Id, expectedUpdateTime)
  83. }, sysRoleIdKey, sysRoleProductCodeNameKey)
  84. if err != nil {
  85. return err
  86. }
  87. affected, _ := res.RowsAffected()
  88. if affected == 0 {
  89. return ErrUpdateConflict
  90. }
  91. return nil
  92. }
  93. // LockRolesForShareTx 见接口注释(审计 M-R12-1)。
  94. func (m *customSysRoleModel) LockRolesForShareTx(ctx context.Context, session sqlx.Session, ids []int64) error {
  95. if len(ids) == 0 {
  96. return nil
  97. }
  98. // 去重 + 升序,避免同一事务重复 SELECT 相同 id 造成的等待链加长,并保证多条 BindRoles
  99. // 并发时按统一顺序取锁(避免 A 锁 1→2、B 锁 2→1 的死锁)。
  100. seen := make(map[int64]struct{}, len(ids))
  101. sorted := make([]int64, 0, len(ids))
  102. for _, id := range ids {
  103. if _, ok := seen[id]; ok {
  104. continue
  105. }
  106. seen[id] = struct{}{}
  107. sorted = append(sorted, id)
  108. }
  109. sort.Slice(sorted, func(i, j int) bool { return sorted[i] < sorted[j] })
  110. placeholders := make([]string, len(sorted))
  111. args := make([]interface{}, 0, len(sorted)+1)
  112. for i, id := range sorted {
  113. placeholders[i] = "?"
  114. args = append(args, id)
  115. }
  116. args = append(args, consts.StatusEnabled)
  117. var lockedIds []int64
  118. query := fmt.Sprintf(
  119. "SELECT `id` FROM %s WHERE `id` IN (%s) AND `status` = ? ORDER BY `id` LOCK IN SHARE MODE",
  120. m.table, strings.Join(placeholders, ","),
  121. )
  122. if err := session.QueryRowsCtx(ctx, &lockedIds, query, args...); err != nil {
  123. return err
  124. }
  125. // 任一 id 对不上(已被 DeleteRole 删掉、或 UpdateRole 改为 Disabled)都一刀切回 ErrNotFound,
  126. // 让调用方 BindRoles 立即终止事务并返回 400;不在本函数里做"部分成功 + 分辨哪些失败"的返回值
  127. // 语义(DeleteRole 对 sys_role 的 X 锁在本事务提交前不会释放,所以本 S 锁"全捕获"才是正确信号)。
  128. if len(lockedIds) != len(sorted) {
  129. return sqlx.ErrNotFound
  130. }
  131. return nil
  132. }
  133. // LockByIdTx 见接口注释。注意:本函数不走缓存层,必须在 TransactCtx / Session 下调用;
  134. // SELECT ... FOR UPDATE 的行锁由 InnoDB 持有到事务结束。
  135. func (m *customSysRoleModel) LockByIdTx(ctx context.Context, session sqlx.Session, id int64) (*SysRole, error) {
  136. var data SysRole
  137. query := fmt.Sprintf("SELECT %s FROM %s WHERE `id` = ? LIMIT 1 FOR UPDATE", sysRoleRows, m.table)
  138. if err := session.QueryRowCtx(ctx, &data, query, id); err != nil {
  139. return nil, err
  140. }
  141. return &data, nil
  142. }
  143. func (m *customSysRoleModel) FindMinPermsLevelByUserIdAndProductCode(ctx context.Context, userId int64, productCode string) (int64, error) {
  144. var level int64
  145. query := fmt.Sprintf(
  146. "SELECT IFNULL(MIN(r.`permsLevel`), -1) FROM %s r INNER JOIN `sys_user_role` ur ON r.`id` = ur.`roleId` WHERE ur.`userId` = ? AND r.`productCode` = ? AND r.`status` = ?",
  147. m.table,
  148. )
  149. if err := m.QueryRowNoCacheCtx(ctx, &level, query, userId, productCode, consts.StatusEnabled); err != nil {
  150. return 0, err
  151. }
  152. if level < 0 {
  153. return 0, ErrNotFound
  154. }
  155. return level, nil
  156. }