Compare commits

...

2 Commits

Author SHA1 Message Date
5747e255e9 改! 2024-07-06 07:19:31 +08:00
f51a66073b 完善tenant权限相关 2024-07-06 06:15:11 +08:00
4 changed files with 45 additions and 89 deletions

View File

@ -73,6 +73,11 @@ public class NewsService {
public void createNews(NewsRequest request) {
String username = JwtUtil.extractUsername(request.getToken());
UserHS user = userService.getUserByUsername(username);
if (!user.getSuperAdmin() && !user.getTenant().equals(request.getTenant())){
throw new IllegalArgumentException("只能在自己的租户的名下新增新闻!");
}
News news = new News();
news.setTitle(request.getTitle());
news.setSummary(request.getSummary());
@ -91,7 +96,9 @@ public class NewsService {
news.setContent(request.getContent());
news.setAuthor(request.getAuthor());
news.setImagePath(request.getImagePath());
if (userService.getUserByUsername(JwtUtil.extractUsername(request.getToken())).getSuperAdmin()) {
news.setTenant(request.getTenant());
}
newsRepository.save(news);
}
}
@ -114,26 +121,6 @@ public class NewsService {
return newsRepository.count();
}
// TODO:完善用户权限
// public List<News> searchNews(SearchNewsRequest request) {
// String username = JwtUtil.extractUsername(request.getToken());
// UserHS user = userService.getUserByUsername(username);
// if (user.getSuperAdmin()) {
// return newsRepository.findByTitleContainingOrSummaryContainingOrAuthorContainingOrImagePathContaining(
// request.getTitle(),
// request.getSummary(),
// request.getAuthor(),
// request.getImagePath()
// );
// }
// return newsRepository.findByTitleContainingOrSummaryContainingOrAuthorContainingOrImagePathContainingAndTenantEquals(
// request.getTitle(),
// request.getSummary(),
// request.getAuthor(),
// request.getImagePath(),
// user.getUsername()
// );
// }
public List<News> searchNews(SearchNewsRequest request) {
String username = JwtUtil.extractUsername(request.getToken());
UserHS user = userService.getUserByUsername(username);

View File

@ -9,6 +9,7 @@ import java.util.stream.Collectors;
public class UserHS2User {
public static User convert(UserHS userHS) {
User user = new User();
user.setId(userHS.getId());
user.setAccount(userHS.getUsername());
user.setPassword(userHS.getPassword());
user.setName(userHS.getNickname());

View File

@ -1,39 +0,0 @@
package org.cmh.backend.UserManagement.controller;
import org.cmh.backend.UserManagement.model.User;
import org.cmh.backend.UserManagement.service.UserServiceTemp;
import org.springframework.beans.factory.annotation.Autowired;
import org.springframework.http.ResponseEntity;
import org.springframework.web.bind.annotation.*;
import java.util.Map;
import static org.springframework.http.ResponseEntity.ok;
@RestController
public class UserController {
@Autowired
private UserServiceTemp userService;
@CrossOrigin(origins = "http://localhost:5173")
@PostMapping("/checkLogin")
public ResponseEntity<User> login(@RequestBody Map<String,String> credentials) {
String account = credentials.get("account");
String password = credentials.get("password");
User user = userService.getUserByAccountAndPassword(account, password);
return ok(user);
}
@CrossOrigin(origins = "http://localhost:5173")
@PostMapping("/checkRegister")
public String register(@RequestBody User user) {
if(userService.registerUser(user) != null){
return "注册成功";
}else
return "注册错误";
}
}

View File

@ -1,22 +1,22 @@
package org.cmh.backend.UserManagement.controller;
import io.jsonwebtoken.JwtParser;
import jakarta.transaction.Transactional;
import org.cmh.backend.OrganizationManagement.service.OrganizationService;
import org.cmh.backend.UserManagement.adpter.User2UserHS;
import org.cmh.backend.UserManagement.adpter.UserHS2User;
import org.cmh.backend.UserManagement.service.UserManagementService;
import org.cmh.backend.UserManagement.model.User;
import org.cmh.backend.UserManagement.service.UserManagementService;
import org.cmh.backend.Utils.JwtUtil;
import org.cmh.backend.Utils.JwtVerify;
import org.cmh.backend.authentication.dto.UserProfileResponse;
import org.cmh.backend.authentication.model.UserHS;
import org.cmh.backend.authentication.repository.UserRepository;
import org.cmh.backend.authentication.service.UserService;
import org.springframework.beans.factory.annotation.Autowired;
import org.springframework.http.HttpEntity;
import org.springframework.http.HttpStatus;
import org.springframework.http.ResponseEntity;
import org.springframework.web.bind.annotation.*;
import java.util.List;
@RestController
@ -28,6 +28,8 @@ public class UserManagementController {
private OrganizationService organizationService;
@Autowired
private UserService userService;
@Autowired
private UserRepository userRepository;
@PostMapping("/addUser")
public ResponseEntity<UserProfileResponse> addUser(@RequestBody User user) {
@ -56,42 +58,47 @@ public class UserManagementController {
public List<User> getAll(@RequestParam String token) {
String username = JwtUtil.extractUsername(token);
UserHS userHS = userService.getUserByUsername(username);
List<UserHS> userHSList = userService.getAllUsers();
//这里分权限进行不同请求
//超级管理员
if (userHS.getSuperAdmin()) {
return UserHS2User.convertList(userHSList);
return UserHS2User.convertList(userService.getAllUsers());
} else {
return null;
return UserHS2User.convertList(userService.getUsersByTenant(userHS.getTenant()));
}
}
@PostMapping("/update")
public ResponseEntity<UserProfileResponse> update(@RequestBody User user) {
UserHS newuser = User2UserHS.convert(user);
UserHS reqUser = User2UserHS.convert(user);
UserHS tarUser = userService.getUserByUsername(reqUser.getUsername());
if (tarUser != null) {
tarUser.setNickname(reqUser.getNickname());
tarUser.setGender(reqUser.getGender());
tarUser.setPhoneNumber(reqUser.getPhoneNumber());
tarUser.setEmail(reqUser.getEmail());
tarUser.setRole(reqUser.getRole());
UserProfileResponse response = new UserProfileResponse(
newuser.getUsername(),
newuser.getNickname(),
newuser.getGender(),
newuser.getPhoneNumber(),
newuser.getEmail(),
newuser.getDepartment(),
newuser.getRole(),
newuser.getCreatedAt()
reqUser.getUsername(),
reqUser.getNickname(),
reqUser.getGender(),
reqUser.getPhoneNumber(),
reqUser.getEmail(),
reqUser.getDepartment(),
reqUser.getRole(),
reqUser.getCreatedAt()
);
if(organizationService.getByName(newuser.getDepartment()) != null){
userService.addUser(newuser);
if (organizationService.getByName(reqUser.getDepartment()) != null) {
tarUser.setDepartment(reqUser.getDepartment());
}
userRepository.save(tarUser);
return new ResponseEntity<>(response, HttpStatus.OK);
} else {
return null;
return new ResponseEntity<>(null, HttpStatus.OK);
}
}
@PostMapping("/delete")
@Transactional
//不确定这里返回值应该是什么
public void delete(@RequestBody User user) {
UserHS userHS = userService.getUserByUsername(user.getName());
if (userHS != null) {