RoleController.cs 11 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321
  1. using Hotline.Caches;
  2. using Hotline.Identity.Roles;
  3. using Hotline.Permissions;
  4. using Hotline.Repository.SqlSugar;
  5. using Hotline.Repository.SqlSugar.Extensions;
  6. using Hotline.Settings;
  7. using Hotline.Share.Dtos;
  8. using Hotline.Share.Dtos.Roles;
  9. using MapsterMapper;
  10. using Microsoft.AspNetCore.Mvc;
  11. using Microsoft.Extensions.Options;
  12. using SqlSugar;
  13. using XF.Domain.Exceptions;
  14. using XF.Domain.Options;
  15. using XF.Utility.UnifyResponse;
  16. namespace Hotline.Api.Controllers;
  17. /// <summary>
  18. /// 角色权限管理相关接口
  19. /// </summary>
  20. public class RoleController : BaseController
  21. {
  22. private readonly IRoleRepository _roleRepository;
  23. private readonly ISystemAuthorityRepository _systemAuthorityRepository;
  24. private readonly ISystemDataAuthorityRepository _systemDataAuthorityRepository;
  25. private readonly ITableAccessLevelRepository _tableAccessLevelRepository;
  26. private readonly IMapper _mapper;
  27. private readonly ITableAccessLevelCacheManager _tableAccessLevelCacheManager;
  28. private readonly IRolePermissionsCacheManager _rolePermissionsCacheManager;
  29. private readonly IOptions<IdentityConfiguration> _identityConfigurationAccessor;
  30. private readonly ISystemDataTableRepository _systemDataTableRepository;
  31. public RoleController(
  32. IRoleRepository roleRepository,
  33. ISystemAuthorityRepository systemAuthorityRepository,
  34. ISystemDataAuthorityRepository systemDataAuthorityRepository,
  35. ITableAccessLevelRepository tableAccessLevelRepository,
  36. ITableAccessLevelCacheManager tableAccessLevelCacheManager,
  37. IRolePermissionsCacheManager rolePermissionsCacheManager,
  38. IMapper mapper,
  39. IOptions<IdentityConfiguration> identityConfigurationAccessor,
  40. ISystemDataTableRepository systemDataTableRepository)
  41. {
  42. _roleRepository = roleRepository;
  43. _systemAuthorityRepository = systemAuthorityRepository;
  44. _systemDataAuthorityRepository = systemDataAuthorityRepository;
  45. _tableAccessLevelRepository = tableAccessLevelRepository;
  46. _tableAccessLevelCacheManager = tableAccessLevelCacheManager;
  47. _rolePermissionsCacheManager = rolePermissionsCacheManager;
  48. _mapper = mapper;
  49. _identityConfigurationAccessor = identityConfigurationAccessor;
  50. _systemDataTableRepository = systemDataTableRepository;
  51. }
  52. /// <summary>
  53. /// 分页查询角色
  54. /// </summary>
  55. /// <param name="dto"></param>
  56. /// <returns></returns>
  57. [HttpGet("paged")]
  58. [Permission(EPermission.QueryPagedRole)]
  59. public async Task<PagedDto<RoleDto>> QueryPaged([FromQuery] QueryRolesPagedDto dto)
  60. {
  61. var (total, items) = await _roleRepository.Queryable(includeDeleted: dto.IncludeDeleted)
  62. .Includes(d => d.Accounts)
  63. .WhereIF(!string.IsNullOrEmpty(dto.Keyword), d => d.Name.Contains(dto.Keyword!) || d.DisplayName.Contains(dto.Keyword!))
  64. .OrderByDescending(d => d.CreationTime)
  65. .ToPagedListAsync(dto.PageIndex, dto.PageSize, HttpContext.RequestAborted);
  66. return new PagedDto<RoleDto>(total, _mapper.Map<IReadOnlyList<RoleDto>>(items));
  67. }
  68. /// <summary>
  69. /// 新增角色
  70. /// </summary>
  71. /// <param name="dto"></param>
  72. /// <returns></returns>
  73. [Permission(EPermission.AddRole)]
  74. [HttpPost]
  75. public async Task<string> Add([FromBody] AddRoleDto dto)
  76. {
  77. var jwtOption = _identityConfigurationAccessor.Value.Jwt;
  78. var clientId = jwtOption.Issuer;
  79. if (string.IsNullOrEmpty(clientId))
  80. throw new UserFriendlyException("jwt.Issuer未配置");
  81. var exists = await _roleRepository.Queryable(includeDeleted: true)
  82. .AnyAsync(d => d.ClientId == clientId && d.Name == dto.Name);
  83. if (exists)
  84. throw UserFriendlyException.SameMessage("角色编码重复");
  85. var role = _mapper.Map<Role>(dto);
  86. role.ClientId = clientId;
  87. return await _roleRepository.AddAsync(role, HttpContext.RequestAborted);
  88. }
  89. /// <summary>
  90. /// 删除角色
  91. /// </summary>
  92. /// <param name="id"></param>
  93. /// <returns></returns>
  94. [Permission(EPermission.RemoveRole)]
  95. [HttpDelete("{id}")]
  96. public async Task Remove(string id)
  97. {
  98. var role = await _roleRepository.Queryable()
  99. .Includes(d => d.Accounts)
  100. .FirstAsync(d => d.Id == id);
  101. role.Accounts.Clear();
  102. await _roleRepository.UpdateNav(role)
  103. .Include(d => d.Accounts)
  104. .ExecuteCommandAsync();
  105. await _systemAuthorityRepository.RemoveAsync(id);
  106. await _systemDataAuthorityRepository.RemoveAsync(x => x.RoleId == id);
  107. await _roleRepository.RemoveAsync(id, true, HttpContext.RequestAborted);
  108. }
  109. /// <summary>
  110. /// 更新角色
  111. /// </summary>
  112. /// <param name="dto"></param>
  113. /// <returns></returns>
  114. [Permission(EPermission.UpdateRole)]
  115. [HttpPut]
  116. public async Task Update([FromBody] UpdateRoleDto dto)
  117. {
  118. await _roleRepository.UpdateAsync(_mapper.Map<Role>(dto), HttpContext.RequestAborted);
  119. }
  120. #region 应用权限管理
  121. /// <summary>
  122. /// 分配权限
  123. /// </summary>
  124. /// <param name="dto"></param>
  125. /// <returns></returns>
  126. [Permission(EPermission.AllocationAuthority)]
  127. [HttpPost("allocationauthority")]
  128. public async Task AllocationAuthority(RoleAuthorityDto dto)
  129. {
  130. //判断是否存在,如果存在就做更新
  131. var model = await _systemAuthorityRepository.GetAsync(x => x.RoleId == dto.RoleId);
  132. if (model is null)
  133. {
  134. model = _mapper.Map<SystemAuthority>(dto);
  135. await _systemAuthorityRepository.AddAsync(model);
  136. }
  137. else
  138. {
  139. _mapper.Map(dto, model);
  140. await _systemAuthorityRepository.UpdateAsync(model);
  141. }
  142. _rolePermissionsCacheManager.RemovePermissions(dto.RoleCode);
  143. }
  144. /// <summary>
  145. /// 获取角色权限
  146. /// </summary>
  147. /// <param name="roleid"></param>
  148. /// <returns></returns>
  149. [Permission(EPermission.GetAuthority)]
  150. [HttpGet("getauthority")]
  151. public async Task<SystemAuthority?> GetAuthority(string roleid)
  152. {
  153. return await _systemAuthorityRepository.GetAsync(x => x.RoleId == roleid, HttpContext.RequestAborted);
  154. }
  155. #endregion
  156. #region 数据权限管理
  157. /// <summary>
  158. /// 获取数据表
  159. /// </summary>
  160. /// <returns></returns>
  161. [HttpGet("datatable-list")]
  162. [Obsolete]
  163. public async Task<IReadOnlyList<SystemDataTable>> GetDataTable()
  164. {
  165. return await _systemDataTableRepository.Queryable().ToListAsync();
  166. }
  167. /// <summary>
  168. /// 获取数据表
  169. /// </summary>
  170. [HttpGet("tables")]
  171. public IReadOnlyList<KeyValuePair<string, string>> GetTables([FromServices] ISugarUnitOfWork<HotlineDbContext> uow)
  172. {
  173. var tables = uow.Db.DbMaintenance.GetTableInfoList(false)
  174. .Where(d => !string.IsNullOrEmpty(d.Description))
  175. .Select(d => new KeyValuePair<string, string>(d.Name, d.Description))
  176. .ToList();
  177. return tables;
  178. }
  179. /// <summary>
  180. /// 新增数据权限
  181. /// </summary>
  182. /// <param name="dto"></param>
  183. /// <returns></returns>
  184. [Permission(EPermission.AddDataAuthority)]
  185. [HttpPost("add-data-authority")]
  186. [Obsolete]
  187. public async Task AddDataAuthority([FromBody] AddAccessLevelDto dto)
  188. {
  189. var dataAuthority = _mapper.Map<SystemDataAuthority>(dto);
  190. await _systemDataAuthorityRepository.AddAsync(dataAuthority);
  191. }
  192. /// <summary>
  193. /// 新增数据权限
  194. /// </summary>
  195. [HttpPost("accesslevel")]
  196. public async Task<string> AddAccessLevel([FromBody] AddAccessLevelDto dto)
  197. {
  198. var access = _mapper.Map<TableAccessLevel>(dto);
  199. await _tableAccessLevelRepository.AddAsync(access, HttpContext.RequestAborted);
  200. _tableAccessLevelCacheManager.Reload();
  201. return access.Id;
  202. }
  203. /// <summary>
  204. /// 修改数据权限
  205. /// </summary>
  206. /// <param name="dto"></param>
  207. /// <returns></returns>
  208. [Permission(EPermission.UpdateDataAuthority)]
  209. [HttpPost("update-data-authority")]
  210. [Obsolete]
  211. public async Task UpdateDataAuthority([FromBody] UpdateDataAuthorityDto dto)
  212. {
  213. var entity = await _systemDataAuthorityRepository.GetAsync(x => x.Id == dto.Id, HttpContext.RequestAborted);
  214. if (entity is null)
  215. throw UserFriendlyException.SameMessage("无效数据");
  216. _mapper.Map(dto, entity);
  217. await _systemDataAuthorityRepository.UpdateAsync(entity, HttpContext.RequestAborted);
  218. }
  219. /// <summary>
  220. /// 修改数据权限
  221. /// </summary>
  222. [HttpPut("accesslevel")]
  223. public async Task UpdateAccessLevel([FromBody] UpdateDataAuthorityDto dto)
  224. {
  225. var access = await _tableAccessLevelRepository.GetAsync(dto.Id, HttpContext.RequestAborted);
  226. if (access is null)
  227. throw UserFriendlyException.SameMessage("无效accesslevel编号");
  228. _mapper.Map(dto, access);
  229. await _tableAccessLevelRepository.UpdateAsync(access, HttpContext.RequestAborted);
  230. _tableAccessLevelCacheManager.Reload();
  231. }
  232. /// <summary>
  233. /// 删除数据权限
  234. /// </summary>
  235. /// <param name="id"></param>
  236. /// <returns></returns>
  237. [Permission(EPermission.RemoveDataAuthority)]
  238. [HttpDelete("remove-data-authority/{id}")]
  239. [Obsolete]
  240. public async Task RemoveDataAuthority(string id)
  241. {
  242. var entity = await _systemDataAuthorityRepository.GetAsync(id, HttpContext.RequestAborted);
  243. if (entity is null)
  244. throw UserFriendlyException.SameMessage("无效数据");
  245. await _systemDataAuthorityRepository.RemoveAsync(id);
  246. }
  247. /// <summary>
  248. /// 删除数据权限
  249. /// </summary>
  250. [HttpDelete("accesslevel/{id}")]
  251. public async Task RemoveAccessLevel(string id)
  252. {
  253. await _tableAccessLevelRepository.RemoveAsync(id, cancellationToken: HttpContext.RequestAborted);
  254. _tableAccessLevelCacheManager.Reload();
  255. }
  256. /// <summary>
  257. /// 获取角色所有数据权限设置
  258. /// </summary>
  259. /// <param name="roleid"></param>
  260. /// <returns></returns>
  261. [Permission(EPermission.GetDataAuthorityByRole)]
  262. [HttpGet("getdataauthoritybyrole")]
  263. [Obsolete]
  264. public async Task<IReadOnlyList<SystemDataAuthority>> GetDataAuthorityByRole(string roleid)
  265. {
  266. return await _systemDataAuthorityRepository.Queryable().Where(x => x.RoleId == roleid).Includes(x => x.Table).Includes(x => x.Role).ToListAsync();
  267. }
  268. /// <summary>
  269. /// 获取角色所有数据权限设置
  270. /// </summary>
  271. [HttpGet("{roleId}/accesslevels")]
  272. public async Task<IReadOnlyList<TableAccessLevel>> GetAccessLevels(string roleId)
  273. {
  274. return await _tableAccessLevelRepository.Queryable()
  275. .Where(d => d.RoleId == roleId)
  276. .ToListAsync();
  277. }
  278. #endregion
  279. #region private
  280. private void CheckHttpRequestSuccess(ApiResponse response, string msg)
  281. {
  282. if (response == null || !response.IsSuccess)
  283. throw new UserFriendlyException($"identity service request failed: {msg}");
  284. }
  285. #endregion
  286. }