sysRoleModel.go 9.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223
  1. package role
  2. import (
  3. "context"
  4. "database/sql"
  5. "errors"
  6. "fmt"
  7. "sort"
  8. "strings"
  9. "perms-system-server/internal/consts"
  10. "github.com/zeromicro/go-zero/core/logx"
  11. "github.com/zeromicro/go-zero/core/stores/cache"
  12. "github.com/zeromicro/go-zero/core/stores/sqlx"
  13. )
  14. var ErrUpdateConflict = errors.New("update conflict: data has been modified by another operation")
  15. var _ SysRoleModel = (*customSysRoleModel)(nil)
  16. type (
  17. SysRoleModel interface {
  18. sysRoleModel
  19. FindListByProductCode(ctx context.Context, productCode string, page, pageSize int64) ([]*SysRole, int64, error)
  20. FindListByPage(ctx context.Context, page, pageSize int64) ([]*SysRole, int64, error)
  21. FindByIds(ctx context.Context, ids []int64) ([]*SysRole, error)
  22. FindMinPermsLevelByUserIdAndProductCode(ctx context.Context, userId int64, productCode string) (int64, error)
  23. UpdateWithOptLock(ctx context.Context, data *SysRole, expectedUpdateTime int64) error
  24. // LockByIdTx 在当前事务里锁住 sys_role 行(SELECT ... FOR UPDATE),用于把"同一 role 的
  25. // BindRolePerms 并发覆盖"串行化,消除"existing 在事务外读 + 事务内 delete/insert"
  26. // 造成的第三态合并问题(见审计 M-R10-2)。
  27. LockByIdTx(ctx context.Context, session sqlx.Session, id int64) (*SysRole, error)
  28. // LockRolesForShareTx 在当前事务里对一批 sys_role 行取 S 锁(SELECT ... LOCK IN SHARE MODE),
  29. // 用于闭合 BindRoles × DeleteRole 的写偏斜(审计 M-R12-1):
  30. // DeleteRole 在事务末尾对 sys_role[R] 取 X 锁,会被本 S 锁阻塞;等 BindRoles 提交后
  31. // DeleteRole 再去 FindUserIdsByRoleIdForUpdateTx 时即能看到新插入的 sys_user_role 行,
  32. // 可选择抛错阻断删除或一并清理,不再留下 roleId 指向已删 sys_role 的孤儿。
  33. // 若命中行数 != len(ids) 或有行 status != Enabled,返回 sqlx.ErrNotFound 让调用方
  34. // 转成 400 "包含无效的角色ID"——因为 DeleteRole 的删除发生在 sys_role 行被移走、
  35. // 或者 UpdateRole 把角色 status 改为 Disabled,业务上都不应再绑定。
  36. // 本方法不走缓存,必须在 TransactCtx / Session 下调用;入参 ids 会在内部按升序排序
  37. // 取锁以避免死锁。
  38. LockRolesForShareTx(ctx context.Context, session sqlx.Session, ids []int64) error
  39. // InvalidateRoleCache 失效 sysRole 的 id / (productCode, name) 两把低层缓存键。对齐
  40. // sysDeptModel.InvalidateDeptCache 与 sysUserModel.InvalidateProfileCache 的 L-R12-1
  41. // 契约(审计 H-R17-2):仅应在事务 commit 成功后调用,兜底 `*WithTx` 路径里 sqlc
  42. // `ExecCtx` "exec → DelCache" 钩子过早清缓存之后、commit 之前被并发 `FindOne` 把旧行
  43. // 回填进 Redis 的幽灵快照。best-effort:失败只记日志,TTL 兜底。
  44. //
  45. // 调用方必须传入删除/更新前真实的 (productCode, name)——因为 name 键由这两个字段拼接,
  46. // 如果更新修改了 name,post-commit 失效时要同时清老 name 和新 name 两个键(可由调用方
  47. // 分别调两次本方法,或在调用方自行按需去重)。
  48. InvalidateRoleCache(ctx context.Context, id int64, productCode, name string)
  49. }
  50. customSysRoleModel struct {
  51. *defaultSysRoleModel
  52. }
  53. )
  54. func NewSysRoleModel(conn sqlx.SqlConn, c cache.CacheConf, cachePrefix string, opts ...cache.Option) SysRoleModel {
  55. return &customSysRoleModel{
  56. defaultSysRoleModel: newSysRoleModel(conn, c, cachePrefix, opts...),
  57. }
  58. }
  59. func (m *customSysRoleModel) FindListByProductCode(ctx context.Context, productCode string, page, pageSize int64) ([]*SysRole, int64, error) {
  60. var total int64
  61. countQuery := fmt.Sprintf("SELECT COUNT(*) FROM %s WHERE `productCode` = ?", m.table)
  62. if err := m.QueryRowNoCacheCtx(ctx, &total, countQuery, productCode); err != nil {
  63. return nil, 0, err
  64. }
  65. var list []*SysRole
  66. query := fmt.Sprintf("SELECT %s FROM %s WHERE `productCode` = ? ORDER BY `permsLevel` ASC, id DESC LIMIT ?,?", sysRoleRows, m.table)
  67. if err := m.QueryRowsNoCacheCtx(ctx, &list, query, productCode, (page-1)*pageSize, pageSize); err != nil {
  68. return nil, 0, err
  69. }
  70. return list, total, nil
  71. }
  72. func (m *customSysRoleModel) FindByIds(ctx context.Context, ids []int64) ([]*SysRole, error) {
  73. if len(ids) == 0 {
  74. return nil, nil
  75. }
  76. args := make([]interface{}, len(ids))
  77. marks := make([]string, len(ids))
  78. for i, id := range ids {
  79. args[i] = id
  80. marks[i] = "?"
  81. }
  82. var list []*SysRole
  83. query := fmt.Sprintf("SELECT %s FROM %s WHERE `id` IN (%s)", sysRoleRows, m.table, strings.Join(marks, ","))
  84. if err := m.QueryRowsNoCacheCtx(ctx, &list, query, args...); err != nil {
  85. return nil, err
  86. }
  87. return list, nil
  88. }
  89. func (m *customSysRoleModel) FindListByPage(ctx context.Context, page, pageSize int64) ([]*SysRole, int64, error) {
  90. var total int64
  91. countQuery := fmt.Sprintf("SELECT COUNT(*) FROM %s", m.table)
  92. if err := m.QueryRowNoCacheCtx(ctx, &total, countQuery); err != nil {
  93. return nil, 0, err
  94. }
  95. var list []*SysRole
  96. query := fmt.Sprintf("SELECT %s FROM %s ORDER BY `permsLevel` ASC, id DESC LIMIT ?,?", sysRoleRows, m.table)
  97. if err := m.QueryRowsNoCacheCtx(ctx, &list, query, (page-1)*pageSize, pageSize); err != nil {
  98. return nil, 0, err
  99. }
  100. return list, total, nil
  101. }
  102. func (m *customSysRoleModel) UpdateWithOptLock(ctx context.Context, data *SysRole, expectedUpdateTime int64) error {
  103. sysRoleIdKey := fmt.Sprintf("%s%v", cacheSysRoleIdPrefix, data.Id)
  104. sysRoleProductCodeNameKey := fmt.Sprintf("%s%v:%v", cacheSysRoleProductCodeNamePrefix, data.ProductCode, data.Name)
  105. res, err := m.ExecCtx(ctx, func(ctx context.Context, conn sqlx.SqlConn) (sql.Result, error) {
  106. query := fmt.Sprintf("UPDATE %s SET `name`=?, `remark`=?, `status`=?, `permsLevel`=?, `updateTime`=? WHERE `id`=? AND `updateTime`=?", m.table)
  107. return conn.ExecCtx(ctx, query, data.Name, data.Remark, data.Status, data.PermsLevel, data.UpdateTime, data.Id, expectedUpdateTime)
  108. }, sysRoleIdKey, sysRoleProductCodeNameKey)
  109. if err != nil {
  110. return err
  111. }
  112. affected, _ := res.RowsAffected()
  113. if affected == 0 {
  114. return ErrUpdateConflict
  115. }
  116. return nil
  117. }
  118. // LockRolesForShareTx 见接口注释(审计 M-R12-1)。
  119. func (m *customSysRoleModel) LockRolesForShareTx(ctx context.Context, session sqlx.Session, ids []int64) error {
  120. if len(ids) == 0 {
  121. return nil
  122. }
  123. // 去重 + 升序,避免同一事务重复 SELECT 相同 id 造成的等待链加长,并保证多条 BindRoles
  124. // 并发时按统一顺序取锁(避免 A 锁 1→2、B 锁 2→1 的死锁)。
  125. seen := make(map[int64]struct{}, len(ids))
  126. sorted := make([]int64, 0, len(ids))
  127. for _, id := range ids {
  128. if _, ok := seen[id]; ok {
  129. continue
  130. }
  131. seen[id] = struct{}{}
  132. sorted = append(sorted, id)
  133. }
  134. sort.Slice(sorted, func(i, j int) bool { return sorted[i] < sorted[j] })
  135. placeholders := make([]string, len(sorted))
  136. args := make([]interface{}, 0, len(sorted)+1)
  137. for i, id := range sorted {
  138. placeholders[i] = "?"
  139. args = append(args, id)
  140. }
  141. args = append(args, consts.StatusEnabled)
  142. var lockedIds []int64
  143. query := fmt.Sprintf(
  144. "SELECT `id` FROM %s WHERE `id` IN (%s) AND `status` = ? ORDER BY `id` LOCK IN SHARE MODE",
  145. m.table, strings.Join(placeholders, ","),
  146. )
  147. if err := session.QueryRowsCtx(ctx, &lockedIds, query, args...); err != nil {
  148. return err
  149. }
  150. // 任一 id 对不上(已被 DeleteRole 删掉、或 UpdateRole 改为 Disabled)都一刀切回 ErrNotFound,
  151. // 让调用方 BindRoles 立即终止事务并返回 400;不在本函数里做"部分成功 + 分辨哪些失败"的返回值
  152. // 语义(DeleteRole 对 sys_role 的 X 锁在本事务提交前不会释放,所以本 S 锁"全捕获"才是正确信号)。
  153. if len(lockedIds) != len(sorted) {
  154. return sqlx.ErrNotFound
  155. }
  156. return nil
  157. }
  158. // InvalidateRoleCache 见接口注释(审计 H-R17-2)。与 sysDeptModel.InvalidateDeptCache 同型:
  159. // post-commit best-effort 失效,ctx 取消与其它错误分档日志,方便 Redis 抖动与主动取消区分告警。
  160. func (m *customSysRoleModel) InvalidateRoleCache(ctx context.Context, id int64, productCode, name string) {
  161. keys := []string{fmt.Sprintf("%s%v", cacheSysRoleIdPrefix, id)}
  162. if productCode != "" && name != "" {
  163. keys = append(keys, fmt.Sprintf("%s%v:%v", cacheSysRoleProductCodeNamePrefix, productCode, name))
  164. }
  165. if err := m.DelCacheCtx(ctx, keys...); err != nil {
  166. if errors.Is(err, context.Canceled) || errors.Is(err, context.DeadlineExceeded) {
  167. logx.WithContext(ctx).Errorw("cache invalidation skipped: ctx canceled",
  168. logx.Field("audit", "cache_invalidation_skipped_due_to_ctx_cancel"),
  169. logx.Field("scope", "sysRoleModel.InvalidateRoleCache"),
  170. logx.Field("id", id),
  171. logx.Field("err", err.Error()),
  172. )
  173. } else {
  174. logx.WithContext(ctx).Errorf("sysRoleModel.InvalidateRoleCache failed: id=%d err=%v", id, err)
  175. }
  176. }
  177. }
  178. // LockByIdTx 见接口注释。注意:本函数不走缓存层,必须在 TransactCtx / Session 下调用;
  179. // SELECT ... FOR UPDATE 的行锁由 InnoDB 持有到事务结束。
  180. func (m *customSysRoleModel) LockByIdTx(ctx context.Context, session sqlx.Session, id int64) (*SysRole, error) {
  181. var data SysRole
  182. query := fmt.Sprintf("SELECT %s FROM %s WHERE `id` = ? LIMIT 1 FOR UPDATE", sysRoleRows, m.table)
  183. if err := session.QueryRowCtx(ctx, &data, query, id); err != nil {
  184. return nil, err
  185. }
  186. return &data, nil
  187. }
  188. func (m *customSysRoleModel) FindMinPermsLevelByUserIdAndProductCode(ctx context.Context, userId int64, productCode string) (int64, error) {
  189. var level int64
  190. query := fmt.Sprintf(
  191. "SELECT IFNULL(MIN(r.`permsLevel`), -1) FROM %s r INNER JOIN `sys_user_role` ur ON r.`id` = ur.`roleId` WHERE ur.`userId` = ? AND r.`productCode` = ? AND r.`status` = ?",
  192. m.table,
  193. )
  194. if err := m.QueryRowNoCacheCtx(ctx, &level, query, userId, productCode, consts.StatusEnabled); err != nil {
  195. return 0, err
  196. }
  197. if level < 0 {
  198. return 0, ErrNotFound
  199. }
  200. return level, nil
  201. }