mirror of
https://gitee.com/vben/vben-java.git
synced 2026-10-06 14:13:12 +08:00
优化代码,增加大量注释
This commit is contained in:
@@ -6,6 +6,7 @@ import vboot.core.common.entity.BaseCateEntity;
|
||||
|
||||
import javax.persistence.*;
|
||||
|
||||
//供应商分类
|
||||
@Entity
|
||||
@Getter
|
||||
@Setter
|
||||
|
||||
@@ -5,10 +5,10 @@ import org.springframework.web.bind.annotation.*;
|
||||
import vboot.core.common.api.R;
|
||||
import vboot.core.common.dao.Sqler;
|
||||
import vboot.core.common.pojo.Ztree;
|
||||
import vboot.core.module.mon.log.oper.Oplog;
|
||||
|
||||
import java.util.List;
|
||||
|
||||
//供应商分类接口
|
||||
@RestController
|
||||
@RequestMapping("de/supp/cate")
|
||||
public class DeSuppCateApi {
|
||||
@@ -17,19 +17,19 @@ public class DeSuppCateApi {
|
||||
|
||||
//获取除自身及子节点外的分类
|
||||
@GetMapping("treez")
|
||||
public R getTreez(String name,String id) {
|
||||
List<Ztree> list = service.tier2Choose(table,id,name);
|
||||
public R getTreez(String name, String id) {
|
||||
List<Ztree> list = service.tier2Choose(table, id, name);
|
||||
return R.ok(list);
|
||||
}
|
||||
|
||||
//获取所有分类
|
||||
//获取所有分类-用于分类选择下拉框
|
||||
@GetMapping("treea")
|
||||
public R getTreea(String name) {
|
||||
List<Ztree> list = service.findTreeList(table,name);
|
||||
List<Ztree> list = service.findTreeList(table, name);
|
||||
return R.ok(list);
|
||||
}
|
||||
|
||||
//
|
||||
//获取分类treeTable数据
|
||||
@GetMapping("tree")
|
||||
public R getTree(String name) {
|
||||
Sqler sqler = new Sqler(table);
|
||||
@@ -41,6 +41,7 @@ public class DeSuppCateApi {
|
||||
return R.ok(list);
|
||||
}
|
||||
|
||||
//获取分类分页数据
|
||||
@GetMapping
|
||||
public R get(String name) {
|
||||
Sqler sqler = new Sqler(table);
|
||||
@@ -49,19 +50,25 @@ public class DeSuppCateApi {
|
||||
return R.ok(service.findPageData(sqler));
|
||||
}
|
||||
|
||||
//获取单个分类详细信息
|
||||
@GetMapping("one/{id}")
|
||||
public R getOne(@PathVariable String id) {return R.ok(service.findOne(id)); }
|
||||
public R getOne(@PathVariable String id) {
|
||||
return R.ok(service.findOne(id));
|
||||
}
|
||||
|
||||
//新增供应商分类
|
||||
@PostMapping
|
||||
public R post(@RequestBody DeSuppCate main) {
|
||||
return R.ok(service.insert(main));
|
||||
}
|
||||
|
||||
//更新供应商分类
|
||||
@PutMapping
|
||||
public R put(@RequestBody DeSuppCate main) {
|
||||
return R.ok(service.update(main,table));
|
||||
return R.ok(service.update(main, table));
|
||||
}
|
||||
|
||||
//删除供应商分类
|
||||
@DeleteMapping("{ids}")
|
||||
public R delete(@PathVariable String[] ids) {
|
||||
return R.ok(service.delete(ids));
|
||||
|
||||
@@ -2,6 +2,7 @@ package vboot.app.module.de.supp.cate;
|
||||
|
||||
import org.springframework.data.jpa.repository.JpaRepository;
|
||||
|
||||
//供应商分类JPA仓储
|
||||
public interface DeSuppCateRepo extends JpaRepository<DeSuppCate,String> {
|
||||
|
||||
|
||||
|
||||
+4
-1
@@ -9,11 +9,14 @@ import vboot.core.common.service.BaseCateService;
|
||||
import javax.annotation.PostConstruct;
|
||||
import java.util.List;
|
||||
|
||||
//供应商分类服务
|
||||
@Service
|
||||
public class DeSuppCateService extends BaseCateService<DeSuppCate> {
|
||||
|
||||
//获取分类treeTable数据
|
||||
public List<DeSuppCate> findTree(Sqler sqler) {
|
||||
List<DeSuppCate> list = jdbcDao.getTp().query(sqler.getSql(), sqler.getParams(), new BeanPropertyRowMapper<>(DeSuppCate.class));
|
||||
List<DeSuppCate> list = jdbcDao.getTp().query(sqler.getSql(), sqler.getParams(),
|
||||
new BeanPropertyRowMapper<>(DeSuppCate.class));
|
||||
return buildByRecursive(list);
|
||||
}
|
||||
|
||||
|
||||
@@ -7,33 +7,34 @@ import javax.persistence.Entity;
|
||||
import javax.persistence.Id;
|
||||
import javax.persistence.Transient;
|
||||
|
||||
//供应商附件---主记录OneToMany
|
||||
@Entity
|
||||
@Data
|
||||
public class DeSuppAtt
|
||||
{
|
||||
@Id
|
||||
@Column(length = 32)
|
||||
private String id;
|
||||
private String id;//主键
|
||||
|
||||
@Column(length = 32)
|
||||
private String addre;
|
||||
private String addre;//存储地址
|
||||
|
||||
@Column(length = 128)
|
||||
private String pname;
|
||||
private String pname;//文件前缀名
|
||||
|
||||
@Column(length = 128)
|
||||
private String sname;
|
||||
private String sname;//文件后缀名
|
||||
|
||||
@Column(length = 16)
|
||||
private String zsize;
|
||||
private String zsize;//文件大小
|
||||
|
||||
@Transient
|
||||
private String zimg;
|
||||
private String zimg;//图片缩略图
|
||||
|
||||
@Column(length = 256)
|
||||
private String name;
|
||||
private String name;//文件全名
|
||||
|
||||
@Column(length = 256)
|
||||
private String link;
|
||||
private String link;//文件链接地址
|
||||
|
||||
}
|
||||
|
||||
@@ -6,6 +6,7 @@ import javax.persistence.Column;
|
||||
import javax.persistence.Entity;
|
||||
import javax.persistence.Id;
|
||||
|
||||
//供应商联系人---主记录OneToMany
|
||||
@Data
|
||||
@Entity
|
||||
public class DeSuppContact {
|
||||
|
||||
@@ -9,11 +9,53 @@ import javax.persistence.*;
|
||||
import java.util.ArrayList;
|
||||
import java.util.List;
|
||||
|
||||
//供应商主信息
|
||||
@Entity
|
||||
@Getter
|
||||
@Setter
|
||||
public class DeSuppMain extends BaseMainEntity {
|
||||
|
||||
//关联分类表示例
|
||||
@Column(length = 32)
|
||||
private String catid;//供应商分类
|
||||
|
||||
//流水号示例
|
||||
@Column(length = 32)
|
||||
private String senum;//流水号
|
||||
|
||||
//数据字典示例
|
||||
@Column(length = 32)
|
||||
private String level;//供应商资质
|
||||
|
||||
//ManyToOne示例
|
||||
@ManyToOne
|
||||
@JoinColumn(name = "opman")
|
||||
private SysOrg opman;//经办人
|
||||
|
||||
//ManyToMany示例
|
||||
@ManyToMany
|
||||
@JoinTable(name = "de_supp_viewer", joinColumns = {@JoinColumn(name = "mid")},
|
||||
inverseJoinColumns = {@JoinColumn(name = "oid")})
|
||||
private List<SysOrg> viewers;//可查看者
|
||||
|
||||
//ManyToMany示例
|
||||
@ManyToMany
|
||||
@JoinTable(name = "de_supp_editor", joinColumns = {@JoinColumn(name = "mid")},
|
||||
inverseJoinColumns = {@JoinColumn(name = "oid")})
|
||||
private List<SysOrg> editors;//可编辑者
|
||||
|
||||
//OneToMany示例
|
||||
@OneToMany(cascade = CascadeType.ALL, orphanRemoval = true)
|
||||
@JoinColumn(name = "maiid")
|
||||
@OrderBy("ornum ASC")
|
||||
private List<DeSuppContact> contacts = new ArrayList<>();//联系人
|
||||
|
||||
//附件示例
|
||||
@OneToMany(cascade = CascadeType.ALL, orphanRemoval = true)
|
||||
@JoinColumn(name = "maiid")
|
||||
private List<DeSuppAtt> atts = new ArrayList<>();//附件
|
||||
|
||||
//地址选择示例,可根据实际情况存想要的字段
|
||||
//--------地址相关信息------<<<
|
||||
private String addre;//完整地址
|
||||
|
||||
@@ -35,38 +77,4 @@ public class DeSuppMain extends BaseMainEntity {
|
||||
@Column(length = 32)
|
||||
private String addis;//区
|
||||
//--------地址相关信息------>>>
|
||||
|
||||
@Column(length = 32)
|
||||
private String catid;//供应商分类
|
||||
|
||||
@Column(length = 32)
|
||||
private String senum;//流水号
|
||||
|
||||
private String notes;//备注
|
||||
|
||||
@Column(length = 32)
|
||||
private String level;//供应商资质
|
||||
|
||||
@ManyToOne
|
||||
@JoinColumn(name = "opman")
|
||||
private SysOrg opman;//经办人
|
||||
|
||||
@ManyToMany
|
||||
@JoinTable(name = "de_supp_viewer", joinColumns = {@JoinColumn(name = "mid")},
|
||||
inverseJoinColumns = {@JoinColumn(name = "oid")})
|
||||
private List<SysOrg> viewers;//可查看者
|
||||
|
||||
@ManyToMany
|
||||
@JoinTable(name = "de_supp_editor", joinColumns = {@JoinColumn(name = "mid")},
|
||||
inverseJoinColumns = {@JoinColumn(name = "oid")})
|
||||
private List<SysOrg> editors;//可编辑者
|
||||
|
||||
@OneToMany(cascade = CascadeType.ALL, orphanRemoval = true)
|
||||
@JoinColumn(name = "maiid")
|
||||
@OrderBy("ornum ASC")
|
||||
private List<DeSuppContact> contacts = new ArrayList<>();//联系人
|
||||
|
||||
@OneToMany(cascade = CascadeType.ALL, orphanRemoval = true)
|
||||
@JoinColumn(name = "maiid")
|
||||
private List<DeSuppAtt> atts = new ArrayList<>();//附件
|
||||
}
|
||||
|
||||
@@ -7,11 +7,12 @@ import org.springframework.web.bind.annotation.*;
|
||||
import vboot.core.module.ass.num.main.AssNumMainService;
|
||||
import vboot.core.module.mon.log.oper.Oplog;
|
||||
|
||||
//供应商主信息接口
|
||||
@RestController
|
||||
@RequestMapping("de/supp/main")
|
||||
public class DeSuppMainApi {
|
||||
|
||||
@Oplog("查询供应商")
|
||||
@Oplog("查询供应商分页数据")
|
||||
@GetMapping
|
||||
public R get(String name) {
|
||||
Sqler sqler = new Sqler("de_supp_main");
|
||||
@@ -20,23 +21,27 @@ public class DeSuppMainApi {
|
||||
return R.ok(service.findPageData(sqler));
|
||||
}
|
||||
|
||||
@Oplog("查询供应商单个详情")
|
||||
@GetMapping("one/{id}")
|
||||
public R getOne(@PathVariable String id) {
|
||||
DeSuppMain main = service.findOne(id);
|
||||
return R.ok(main);
|
||||
}
|
||||
|
||||
@Oplog("新增供应商")
|
||||
@PostMapping
|
||||
public R post(@RequestBody DeSuppMain main) {
|
||||
main.setSenum(numService.getNum("SUPP"));
|
||||
main.setSenum(numService.getNum("SUPP"));//设置供应商流水号
|
||||
return R.ok(service.insert(main));
|
||||
}
|
||||
|
||||
@Oplog("更新供应商")
|
||||
@PutMapping
|
||||
public R put(@RequestBody DeSuppMain main) {
|
||||
return R.ok(service.update(main));
|
||||
}
|
||||
|
||||
@Oplog("删除供应商")
|
||||
@DeleteMapping("{ids}")
|
||||
public R delete(@PathVariable String[] ids) {
|
||||
return R.ok(service.delete(ids));
|
||||
|
||||
@@ -2,6 +2,7 @@ package vboot.app.module.de.supp.main;
|
||||
|
||||
import org.springframework.data.jpa.repository.JpaRepository;
|
||||
|
||||
//供应商JPA仓储
|
||||
public interface DeSuppMainRepo extends JpaRepository<DeSuppMain,String> {
|
||||
|
||||
|
||||
|
||||
@@ -6,6 +6,7 @@ import vboot.core.common.service.BaseMainService;
|
||||
|
||||
import javax.annotation.PostConstruct;
|
||||
|
||||
//供应商服务
|
||||
@Service
|
||||
public class DeSuppMainService extends BaseMainService<DeSuppMain> {
|
||||
|
||||
|
||||
@@ -7,6 +7,7 @@ import lombok.NoArgsConstructor;
|
||||
import java.util.List;
|
||||
import java.util.Map;
|
||||
|
||||
//分页数据返回用VO
|
||||
@Data
|
||||
@AllArgsConstructor
|
||||
@NoArgsConstructor
|
||||
|
||||
@@ -3,6 +3,7 @@ package vboot.core.common.api;
|
||||
import java.util.ArrayList;
|
||||
import java.util.HashMap;
|
||||
|
||||
//Rest Result结果返回
|
||||
public class R extends HashMap<String, Object> {
|
||||
private static final long serialVersionUID = 1L;
|
||||
|
||||
|
||||
@@ -2,11 +2,12 @@ package vboot.core.common.dao;
|
||||
|
||||
import java.sql.SQLException;
|
||||
|
||||
public abstract class BaseSqler {
|
||||
|
||||
//增删改SqlHelper的基类 为多个增删改时提供方便的统一处理
|
||||
public abstract class BaseSqler {
|
||||
|
||||
public abstract String getSql() throws SQLException;
|
||||
|
||||
|
||||
public abstract Object[] getParams();
|
||||
|
||||
}
|
||||
|
||||
@@ -7,6 +7,7 @@ import org.springframework.stereotype.Component;
|
||||
import java.util.Map;
|
||||
import java.util.concurrent.TimeUnit;
|
||||
|
||||
//缓存Dao
|
||||
@Component
|
||||
public class CacheDao<T> {
|
||||
|
||||
@@ -18,8 +19,6 @@ public class CacheDao<T> {
|
||||
}
|
||||
|
||||
|
||||
//============================String=============================
|
||||
|
||||
/**
|
||||
* 普通缓存获取
|
||||
*
|
||||
|
||||
@@ -4,6 +4,7 @@ import java.sql.SQLException;
|
||||
import java.util.ArrayList;
|
||||
import java.util.List;
|
||||
|
||||
//删除用的SqlHelper 配合JdbcTemplate使用
|
||||
public class Dsqler extends BaseSqler{
|
||||
private String deleteClause = "";
|
||||
private String whereClause = "";
|
||||
|
||||
@@ -3,6 +3,7 @@ package vboot.core.common.dao;
|
||||
import java.util.ArrayList;
|
||||
import java.util.List;
|
||||
|
||||
//插入用的SqlHelper 配合JdbcTemplate使用
|
||||
public class Isqler extends BaseSqler
|
||||
{
|
||||
private String insertClause = "";
|
||||
|
||||
@@ -75,7 +75,7 @@ public class JdbcDao {
|
||||
ztree.setPid(rs.getString("pid"));
|
||||
return ztree;
|
||||
});
|
||||
return XjsonUtil.buildByRecursive(list);
|
||||
return XjsonUtil.buildTreeByRecursive(list);
|
||||
}
|
||||
|
||||
|
||||
|
||||
@@ -7,6 +7,7 @@ import vboot.core.security.pojo.Zuser;
|
||||
import java.util.ArrayList;
|
||||
import java.util.List;
|
||||
|
||||
//查询用的SqlHelper 配合JdbcTemplate使用
|
||||
public class Sqler
|
||||
{
|
||||
private String fromClause = "";
|
||||
|
||||
@@ -4,6 +4,7 @@ import java.sql.SQLException;
|
||||
import java.util.ArrayList;
|
||||
import java.util.List;
|
||||
|
||||
//更新用的SqlHelper 配合JdbcTemplate使用
|
||||
public class Usqler extends BaseSqler
|
||||
{
|
||||
private String updateClause = "";
|
||||
|
||||
@@ -9,6 +9,7 @@ import java.util.ArrayList;
|
||||
import java.util.Date;
|
||||
import java.util.List;
|
||||
|
||||
//分类Entity基类,可实现无限多级的树结构
|
||||
@MappedSuperclass
|
||||
@Getter
|
||||
@Setter
|
||||
@@ -30,7 +31,7 @@ public class BaseCateEntity {
|
||||
|
||||
@Transient
|
||||
protected List<BaseCateEntity> children = new ArrayList<>(); //子元素
|
||||
//----------------------norm标准属性-----------------------
|
||||
//----------------------通用属性-----------------------
|
||||
@Column(length = 100)
|
||||
protected String name;//名称
|
||||
|
||||
|
||||
@@ -7,12 +7,12 @@ import javax.persistence.Column;
|
||||
import javax.persistence.Id;
|
||||
import javax.persistence.MappedSuperclass;
|
||||
|
||||
//简单Entity基类,仅提供id与name字段,如有租户需求,可加租户ID。
|
||||
@MappedSuperclass
|
||||
@Getter
|
||||
@Setter
|
||||
public class BaseEntity {
|
||||
|
||||
|
||||
@Id
|
||||
@Column(length = 32)
|
||||
protected String id;
|
||||
|
||||
@@ -8,6 +8,7 @@ import lombok.Setter;
|
||||
import javax.persistence.*;
|
||||
import java.util.Date;
|
||||
|
||||
//主数据Entity基类,提供通用的字段
|
||||
@MappedSuperclass
|
||||
@Getter
|
||||
@Setter
|
||||
@@ -50,4 +51,6 @@ public class BaseMainEntity {
|
||||
|
||||
protected Date uptim;//更新时间
|
||||
|
||||
protected String notes;//备注
|
||||
|
||||
}
|
||||
|
||||
@@ -16,6 +16,7 @@ import java.util.ArrayList;
|
||||
import java.util.Date;
|
||||
import java.util.List;
|
||||
|
||||
//辅助数据初始化
|
||||
@Component
|
||||
public class AssInit {
|
||||
|
||||
@@ -24,10 +25,9 @@ public class AssInit {
|
||||
initDict();
|
||||
}
|
||||
|
||||
//流水号初始化
|
||||
private void initNum() {
|
||||
List<AssNumMain> numList = new ArrayList<>();
|
||||
// SimpleDateFormat dateFormat = new SimpleDateFormat("yyyyMMdd");
|
||||
// String cudat=dateFormat.format(new Date());
|
||||
AssNumMain suppNum = new AssNumMain();
|
||||
suppNum.setId("SUPP");
|
||||
suppNum.setName("供应商流水号");
|
||||
@@ -67,6 +67,7 @@ public class AssInit {
|
||||
|
||||
}
|
||||
|
||||
//数据字典初始化
|
||||
private void initDict() {
|
||||
List<AssDictMain> dictList = new ArrayList<>();
|
||||
|
||||
|
||||
@@ -8,22 +8,21 @@ import org.springframework.context.ApplicationListener;
|
||||
import org.springframework.context.annotation.Configuration;
|
||||
import org.springframework.context.event.ContextRefreshedEvent;
|
||||
|
||||
//数据库初始化监听器
|
||||
@Configuration
|
||||
@Slf4j
|
||||
public class DbInitListener implements ApplicationListener<ContextRefreshedEvent> {
|
||||
|
||||
|
||||
@Value("${app.init.type}")
|
||||
private String INIT_TYPE;
|
||||
/**
|
||||
* 首次数据库生成后,初始化组织架构,菜单,权限角色,接口等信息
|
||||
*/
|
||||
|
||||
//首次数据库生成后,初始化组织架构,菜单,权限角色,接口等信息
|
||||
@Override
|
||||
public void onApplicationEvent(ContextRefreshedEvent event) {
|
||||
try {
|
||||
if (!userDao.existsById("sa")) {
|
||||
System.out.println("首次启动系统,正在进行数据库初始化,请耐心等待。");
|
||||
if("demo".equals(INIT_TYPE)){
|
||||
if ("demo".equals(INIT_TYPE)) {
|
||||
sysOrgInit.initCorp();
|
||||
System.out.println("1.1 初始化部门完毕");
|
||||
sysOrgInit.initUser();
|
||||
@@ -65,5 +64,4 @@ public class DbInitListener implements ApplicationListener<ContextRefreshedEvent
|
||||
@Autowired
|
||||
private SysPortalInit sysPortalInit;
|
||||
|
||||
|
||||
}
|
||||
@@ -1,22 +0,0 @@
|
||||
package vboot.core.common.init;
|
||||
|
||||
import java.util.ArrayList;
|
||||
import java.util.List;
|
||||
|
||||
public class SysApiCache {
|
||||
|
||||
public static List<Yapi> GET1_APIS=new ArrayList<>();
|
||||
|
||||
public static List<Yapi> GET2_APIS=new ArrayList<>();
|
||||
|
||||
public static List<Yapi> POST_APIS=new ArrayList<>();
|
||||
|
||||
public static List<Yapi> PUT_APIS=new ArrayList<>();
|
||||
|
||||
public static List<Yapi> DELETE_APIS=new ArrayList<>();
|
||||
|
||||
public static List<Yapi> PATCH_APIS=new ArrayList<>();
|
||||
|
||||
public static int AUTHPOS=0;
|
||||
|
||||
}
|
||||
@@ -5,15 +5,25 @@ import org.springframework.web.bind.annotation.*;
|
||||
import vboot.core.common.dao.JdbcDao;
|
||||
import org.springframework.beans.factory.annotation.Autowired;
|
||||
import org.springframework.stereotype.Component;
|
||||
import vboot.core.security.authz.AuthzApiData;
|
||||
import vboot.core.security.pojo.Yapi;
|
||||
import vboot.core.security.pojo.Yurl;
|
||||
|
||||
import java.lang.reflect.Method;
|
||||
import java.util.*;
|
||||
|
||||
/**
|
||||
* API接口初始化,每次修改代码重启后,都会从代码搜集比对需要认证的请求URL,生成唯一的权限码存入数据库
|
||||
* 并将最新的需要认证的Url根据Method分类放到公共内存,用于用户每次请求时获取权限码做权限认证
|
||||
*/
|
||||
@Component
|
||||
public class SysApiInit {
|
||||
|
||||
protected void initApi() {
|
||||
//扫描Controller中的所有Mapping方法,得到需要认证的URL集合
|
||||
List<Yurl> codeUrlList = getScanList();
|
||||
|
||||
//从数据库获取所有已存的URL集合
|
||||
List<String> dbUrlList = jdbcDao.findStringList("select id from sys_api_main");
|
||||
|
||||
//收集最大权限位及最大权限位的最大权限码
|
||||
@@ -25,7 +35,8 @@ public class SysApiInit {
|
||||
pos = Integer.parseInt(String.valueOf(maxMap.get("pos")));
|
||||
code = Long.parseLong(String.valueOf(maxMap.get("code")));
|
||||
}
|
||||
//比较两个list得到insertList
|
||||
|
||||
//比较两个集合,计算得到需要插入数据库的insertList与需要更新数据库的updateList
|
||||
List<Object[]> insertList = new ArrayList<Object[]>();
|
||||
List<Object[]> updateList = new ArrayList<Object[]>();
|
||||
for (Yurl yurl : codeUrlList) {
|
||||
@@ -36,8 +47,7 @@ public class SysApiInit {
|
||||
break;
|
||||
}
|
||||
}
|
||||
//插入
|
||||
if (!flag) {
|
||||
if (!flag) {//插入
|
||||
if (yurl.getType() == null) {
|
||||
Object[] objects = new Object[7];
|
||||
objects[0] = yurl.getId();
|
||||
@@ -83,42 +93,45 @@ public class SysApiInit {
|
||||
// objects[5] = 1;
|
||||
// }
|
||||
// }
|
||||
//更新数据库
|
||||
|
||||
//批量插入与更新数据库
|
||||
String initSql = "UPDATE sys_api_main SET avtag=0";
|
||||
String updateSql = "UPDATE sys_api_main SET pid=?,type=?,avtag=1 WHERE id=?";
|
||||
String insertSql = "INSERT INTO sys_api_main(id,pid,pos,code,url,type,crtim,avtag) VALUES(?,?,?,?,?,?,?,1)";
|
||||
jdbcDao.update(initSql);
|
||||
jdbcDao.batch(updateSql, updateList);
|
||||
jdbcDao.batch(insertSql, insertList);
|
||||
SysApiCache.AUTHPOS = pos;
|
||||
AuthzApiData.AUTHPOS = pos;
|
||||
|
||||
//初始化所有用户权限
|
||||
String updateUserSql = "update sys_org_user set retag=0";
|
||||
jdbcDao.update(updateUserSql);
|
||||
//将所有要求认证的权限放入application
|
||||
String g1permSql = "SELECT url,pos,code from sys_api_main where avtag=1 and type='get' and id not like '%}:get'";
|
||||
SysApiCache.GET1_APIS = getPerms(g1permSql);
|
||||
|
||||
String g2permSql = "SELECT url,pos,code from sys_api_main where avtag=1 and type='get' and id like '%}:get'";
|
||||
SysApiCache.GET2_APIS = getPerms(g2permSql);
|
||||
//将所有要求认证的Url分Method放入内存,用于每次请求时的权限校验
|
||||
String g1ApiSql = "SELECT url,pos,code from sys_api_main where avtag=1 and type='get' and id not like '%}:get'";
|
||||
AuthzApiData.GET1_APIS = findDbApis(g1ApiSql);
|
||||
|
||||
String postUrlSql = "SELECT url,pos,code from sys_api_main where avtag=1 and type='post'";
|
||||
SysApiCache.POST_APIS = getPerms(postUrlSql);
|
||||
String g2ApiSql = "SELECT url,pos,code from sys_api_main where avtag=1 and type='get' and id like '%}:get'";
|
||||
AuthzApiData.GET2_APIS = findDbApis(g2ApiSql);
|
||||
|
||||
String putUrlSql = "SELECT url,pos,code from sys_api_main where avtag=1 and type='put'";
|
||||
SysApiCache.PUT_APIS = getPerms(putUrlSql);
|
||||
String postApiSql = "SELECT url,pos,code from sys_api_main where avtag=1 and type='post'";
|
||||
AuthzApiData.POST_APIS = findDbApis(postApiSql);
|
||||
|
||||
String deleteUrlSql = "SELECT url,pos,code from sys_api_main where avtag= 1 and type='delete'";
|
||||
SysApiCache.DELETE_APIS = getPerms(deleteUrlSql);
|
||||
String putApiSql = "SELECT url,pos,code from sys_api_main where avtag=1 and type='put'";
|
||||
AuthzApiData.PUT_APIS = findDbApis(putApiSql);
|
||||
|
||||
String patchUrlSql = "SELECT url,pos,code from sys_api_main where avtag=1 and type='patch'";
|
||||
SysApiCache.PATCH_APIS = getPerms(patchUrlSql);
|
||||
String deleteApiSql = "SELECT url,pos,code from sys_api_main where avtag= 1 and type='delete'";
|
||||
AuthzApiData.DELETE_APIS = findDbApis(deleteApiSql);
|
||||
|
||||
String patchApiSql = "SELECT url,pos,code from sys_api_main where avtag=1 and type='patch'";
|
||||
AuthzApiData.PATCH_APIS = findDbApis(patchApiSql);
|
||||
|
||||
}
|
||||
|
||||
//扫描Controller中的所有Mapping方法,得到需要认证的URL集合
|
||||
private List<Yurl> getScanList() {
|
||||
List<Yurl> list = new ArrayList<>();
|
||||
Set<Class<?>> classes = ClassScanner.scanPackage("vboot");
|
||||
|
||||
for (Class<?> clazz : classes) {
|
||||
RequestMapping requestMapping = clazz.getAnnotation(RequestMapping.class);
|
||||
if (requestMapping != null) {
|
||||
@@ -131,7 +144,7 @@ public class SysApiInit {
|
||||
if (!classUrl.startsWith("/")) {
|
||||
classUrl = "/" + classUrl;
|
||||
}
|
||||
if(topUrl.getId().contains("-")){
|
||||
if (topUrl.getId().contains("-")) {
|
||||
topUrl.setPid(topUrl.getId().split("-")[0]);
|
||||
}
|
||||
topUrl.setUrl(classUrl);
|
||||
@@ -156,6 +169,7 @@ public class SysApiInit {
|
||||
list.add(yurl);
|
||||
continue;
|
||||
}
|
||||
|
||||
PostMapping postMapping = method.getAnnotation(PostMapping.class);
|
||||
if (postMapping != null) {
|
||||
Yurl yurl = new Yurl();
|
||||
@@ -174,6 +188,7 @@ public class SysApiInit {
|
||||
list.add(yurl);
|
||||
continue;
|
||||
}
|
||||
|
||||
PutMapping putMapping = method.getAnnotation(PutMapping.class);
|
||||
if (putMapping != null) {
|
||||
Yurl yurl = new Yurl();
|
||||
@@ -192,6 +207,7 @@ public class SysApiInit {
|
||||
list.add(yurl);
|
||||
continue;
|
||||
}
|
||||
|
||||
DeleteMapping deleteMapping = method.getAnnotation(DeleteMapping.class);
|
||||
if (deleteMapping != null) {
|
||||
Yurl yurl = new Yurl();
|
||||
@@ -211,7 +227,7 @@ public class SysApiInit {
|
||||
list.add(yurl);
|
||||
continue;
|
||||
}
|
||||
//
|
||||
|
||||
PatchMapping patchMapping = method.getAnnotation(PatchMapping.class);
|
||||
if (patchMapping != null) {
|
||||
Yurl yurl = new Yurl();
|
||||
@@ -235,22 +251,24 @@ public class SysApiInit {
|
||||
}
|
||||
}
|
||||
}
|
||||
Set<String> rootSet = new HashSet<>();
|
||||
|
||||
//设置请求URL的root根目录,方便后面API权限分配
|
||||
Set<String> rootSet = new HashSet<>();
|
||||
for (Yurl yurl : list) {
|
||||
if(yurl.getType()==null&&yurl.getPid()!=null){
|
||||
if (yurl.getType() == null && yurl.getPid() != null) {
|
||||
rootSet.add(yurl.getPid());
|
||||
}
|
||||
}
|
||||
for (String str : rootSet) {
|
||||
Yurl yurl=new Yurl();
|
||||
Yurl yurl = new Yurl();
|
||||
yurl.setId(str);
|
||||
list.add(yurl);
|
||||
}
|
||||
return list;
|
||||
}
|
||||
|
||||
private List<Yapi> getPerms(String sql) {
|
||||
//获取数据库请求的通用方法
|
||||
private List<Yapi> findDbApis(String sql) {
|
||||
return jdbcDao.getTp().query(sql, (rs, rowNum) -> {
|
||||
Yapi yperm = new Yapi();
|
||||
String url = rs.getString("url");
|
||||
|
||||
@@ -13,10 +13,10 @@ import org.springframework.stereotype.Component;
|
||||
import java.util.ArrayList;
|
||||
import java.util.List;
|
||||
|
||||
//组织架构初始化,可根据application.properties的app.init.type配置生成不同的基础数据
|
||||
@Component
|
||||
public class SysOrgInit {
|
||||
|
||||
|
||||
//公司及子公司初始化
|
||||
protected void initCorp() throws Exception {
|
||||
List<SysOrgDept> deptList = new ArrayList<>();
|
||||
@@ -159,6 +159,7 @@ public class SysOrgInit {
|
||||
|
||||
}
|
||||
|
||||
//用户初始化
|
||||
protected void initUser() {
|
||||
List<SysOrgUser> userList = new ArrayList<>();
|
||||
initUser(userList,"刘", "liu", "LIU");
|
||||
@@ -174,6 +175,7 @@ public class SysOrgInit {
|
||||
userService.insertAll(userList);
|
||||
}
|
||||
|
||||
//用户初始化具体实现
|
||||
private void initUser(List<SysOrgUser> userList,String name, String id, String pid) {
|
||||
SysOrgUser user0 = new SysOrgUser();
|
||||
user0.setId(id+"lao");
|
||||
@@ -212,7 +214,7 @@ public class SysOrgInit {
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
//多层级部门与用户初始化
|
||||
protected void initZsf() {
|
||||
|
||||
SysOrgDept dept1 = new SysOrgDept();
|
||||
@@ -249,6 +251,7 @@ public class SysOrgInit {
|
||||
userService.insert(user4);
|
||||
}
|
||||
|
||||
//管理员初始化,正式项目一般只初始化这个就够了,上面的都是演示数据
|
||||
protected void initSa() {
|
||||
SysOrgUser user = new SysOrgUser();
|
||||
user.setId("sa");
|
||||
|
||||
@@ -7,10 +7,11 @@ import vboot.core.module.sys.portal.main.SysPortalMainService;
|
||||
import vboot.core.module.sys.portal.menu.SysPortalMenu;
|
||||
import vboot.core.module.sys.portal.menu.SysPortalMenuService;
|
||||
|
||||
|
||||
//系统门户与菜单初始化
|
||||
@Component
|
||||
public class SysPortalInit {
|
||||
|
||||
//门户初始化
|
||||
protected void initPortal() {
|
||||
SysPortalMain sysPortalMain=new SysPortalMain();
|
||||
sysPortalMain.setId("sys");
|
||||
@@ -25,6 +26,7 @@ public class SysPortalInit {
|
||||
mainService.save(sysPortalMain2);
|
||||
}
|
||||
|
||||
//管理员门户的菜单初始化
|
||||
protected void initSysMenu() {
|
||||
SysPortalMenu home = new SysPortalMenu();
|
||||
home.setId("Home");
|
||||
@@ -40,6 +42,7 @@ public class SysPortalInit {
|
||||
home.setPorid("sys");
|
||||
menuService.insert(home);
|
||||
|
||||
//-----------------系统管理--------------------
|
||||
SysPortalMenu menu1 = new SysPortalMenu();
|
||||
menu1.setId("Sys");
|
||||
menu1.setName("系统管理");
|
||||
@@ -134,7 +137,7 @@ public class SysPortalInit {
|
||||
menu112a.setType("M");
|
||||
menu112a.setPorid("sys");
|
||||
menuService.insert(menu112a);
|
||||
//
|
||||
|
||||
SysPortalMenu menu113 = new SysPortalMenu();
|
||||
menu113.setId("SysOrgPost");
|
||||
menu113.setName("岗位管理");
|
||||
@@ -679,7 +682,7 @@ public class SysPortalInit {
|
||||
menu371.setPorid("sys");
|
||||
menuService.insert(menu371);
|
||||
|
||||
//-----------------OA办公--------------------
|
||||
//-----------------应用中心--------------------
|
||||
SysPortalMenu menu4 = new SysPortalMenu();
|
||||
menu4.setId("Oa");
|
||||
menu4.setName("应用中心");
|
||||
@@ -823,7 +826,7 @@ public class SysPortalInit {
|
||||
menu413b.setPorid("sys");
|
||||
menuService.insert(menu413b);
|
||||
|
||||
//DEMO
|
||||
//-----------------DEMO--------------------
|
||||
SysPortalMenu menu8 = new SysPortalMenu();
|
||||
menu8.setId("De");
|
||||
menu8.setName("Demo");
|
||||
@@ -889,6 +892,7 @@ public class SysPortalInit {
|
||||
|
||||
}
|
||||
|
||||
//营销门户的菜单初始化
|
||||
protected void initSaMenu() {
|
||||
SysPortalMenu home = new SysPortalMenu();
|
||||
home.setId("Sa-Home");
|
||||
@@ -934,8 +938,6 @@ public class SysPortalInit {
|
||||
menu11.setType("M");
|
||||
menu11.setPorid("sa");
|
||||
menuService.insert(menu11);
|
||||
|
||||
|
||||
}
|
||||
|
||||
@Autowired
|
||||
|
||||
@@ -1,11 +1,10 @@
|
||||
package vboot.core.common.pojo;
|
||||
|
||||
|
||||
|
||||
import lombok.AllArgsConstructor;
|
||||
import lombok.Data;
|
||||
import lombok.NoArgsConstructor;
|
||||
|
||||
//数据库连接Pojo
|
||||
@Data
|
||||
@AllArgsConstructor
|
||||
@NoArgsConstructor
|
||||
@@ -18,8 +17,6 @@ public class Zconn {
|
||||
|
||||
private String passcode;
|
||||
|
||||
|
||||
|
||||
public String getSid()
|
||||
{
|
||||
if(isMysql())
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
package vboot.core.common.pojo;
|
||||
|
||||
|
||||
//基础pojo,只有id与name属性
|
||||
public class ZidName
|
||||
{
|
||||
private String id;
|
||||
|
||||
@@ -2,6 +2,7 @@ package vboot.core.common.pojo;
|
||||
|
||||
import java.util.List;
|
||||
|
||||
//id,name,pid简单属性pojo,也可变化加入children组成树形pojo
|
||||
public class Zinp {
|
||||
private String id;
|
||||
private String name;
|
||||
|
||||
@@ -7,6 +7,7 @@ import lombok.Data;
|
||||
import java.util.List;
|
||||
import java.util.Map;
|
||||
|
||||
//树形pojo
|
||||
@Data
|
||||
public class Ztree {
|
||||
private String id;
|
||||
|
||||
@@ -19,6 +19,7 @@ import java.util.ArrayList;
|
||||
import java.util.Date;
|
||||
import java.util.List;
|
||||
|
||||
//分类Service基类,提供分类Entity增删改查的通用方法
|
||||
@Transactional(rollbackFor = Exception.class)
|
||||
public abstract class BaseCateService<T extends BaseCateEntity> {
|
||||
|
||||
|
||||
@@ -14,6 +14,7 @@ import java.util.Date;
|
||||
import java.util.List;
|
||||
import java.util.Map;
|
||||
|
||||
//主数据Service基类,提供主数据Entity增删改查的通用方法
|
||||
@Transactional(rollbackFor = Exception.class)
|
||||
public abstract class BaseMainService<T extends BaseMainEntity> {
|
||||
|
||||
|
||||
@@ -12,6 +12,7 @@ import org.springframework.transaction.annotation.Transactional;
|
||||
import java.util.List;
|
||||
import java.util.Map;
|
||||
|
||||
//简单表Service基类,提供简单Entity增删改查的通用方法
|
||||
@Transactional(rollbackFor = Exception.class)
|
||||
public abstract class BaseService<T extends BaseEntity> {
|
||||
|
||||
|
||||
@@ -13,8 +13,6 @@ import java.util.List;
|
||||
@Setter
|
||||
public class AssCogeForm extends BaseMainEntity {
|
||||
|
||||
private String notes;
|
||||
|
||||
@Lob
|
||||
private String vform;
|
||||
}
|
||||
|
||||
@@ -22,8 +22,6 @@ public class AssCogeTable extends BaseMainEntity {
|
||||
@Column(length = 64)
|
||||
private String remark;//表描述
|
||||
|
||||
private String notes;//备注
|
||||
|
||||
@Column(length = 64)
|
||||
private String mode;//生成模式
|
||||
|
||||
|
||||
@@ -13,8 +13,6 @@ import javax.persistence.Entity;
|
||||
@Setter
|
||||
public class AssDictData extends BaseMainEntity {
|
||||
|
||||
private String notes;//备注
|
||||
|
||||
@Column(length = 32)
|
||||
private String code;//编码
|
||||
|
||||
|
||||
@@ -12,7 +12,6 @@ import javax.persistence.Entity;
|
||||
@Setter
|
||||
public class AssDictMain extends BaseMainEntity {
|
||||
|
||||
private String notes;
|
||||
|
||||
private Integer ornum;
|
||||
|
||||
|
||||
@@ -1,56 +0,0 @@
|
||||
package vboot.core.module.sys.api.main;
|
||||
|
||||
import org.springframework.stereotype.Component;
|
||||
import vboot.core.common.init.SysApiCache;
|
||||
import vboot.core.security.pojo.Zuser;
|
||||
|
||||
@Component
|
||||
public class SysApiMainHand {
|
||||
|
||||
public boolean hasPerm(Zuser zuser, String method,String url){
|
||||
if(zuser.isAdmin()){
|
||||
return true;
|
||||
}
|
||||
boolean flag=false;
|
||||
if("GET".equals(method)){
|
||||
for (int i = 0; i < SysApiCache.GET1_APIS.size(); i++) {
|
||||
if(SysApiCache.GET1_APIS.get(i).getUrl().equals(url)){
|
||||
flag = zuser.hasPerm(SysApiCache.GET1_APIS.get(i).getPos(), SysApiCache.GET1_APIS.get(i).getCode());
|
||||
break;
|
||||
}
|
||||
}
|
||||
if(!flag){
|
||||
String frontUrl=url.substring(0,url.lastIndexOf("/"));
|
||||
for (int i = 0; i < SysApiCache.GET2_APIS.size(); i++) {
|
||||
if(SysApiCache.GET2_APIS.get(i).getUrl().equals(frontUrl)){
|
||||
flag = zuser.hasPerm(SysApiCache.GET2_APIS.get(i).getPos(), SysApiCache.GET2_APIS.get(i).getCode());
|
||||
break;
|
||||
}
|
||||
}
|
||||
}
|
||||
}else if("POST".equals(method)){
|
||||
for (int i = 0; i < SysApiCache.POST_APIS.size(); i++) {
|
||||
if(SysApiCache.POST_APIS.get(i).getUrl().equals(url)){
|
||||
flag = zuser.hasPerm(SysApiCache.POST_APIS.get(i).getPos(), SysApiCache.POST_APIS.get(i).getCode());
|
||||
break;
|
||||
}
|
||||
}
|
||||
}else if("PUT".equals(method)){
|
||||
for (int i = 0; i < SysApiCache.PUT_APIS.size(); i++) {
|
||||
if(SysApiCache.PUT_APIS.get(i).getUrl().equals(url)){
|
||||
flag = zuser.hasPerm(SysApiCache.PUT_APIS.get(i).getPos(), SysApiCache.PUT_APIS.get(i).getCode());
|
||||
break;
|
||||
}
|
||||
}
|
||||
}else if("DELETE".equals(method)){
|
||||
String frontUrl=url.substring(0,url.lastIndexOf("/"));
|
||||
for (int i = 0; i < SysApiCache.DELETE_APIS.size(); i++) {
|
||||
if(SysApiCache.DELETE_APIS.get(i).getUrl().equals(frontUrl)){
|
||||
flag = zuser.hasPerm(SysApiCache.DELETE_APIS.get(i).getPos(), SysApiCache.DELETE_APIS.get(i).getCode());
|
||||
break;
|
||||
}
|
||||
}
|
||||
}
|
||||
return flag;
|
||||
}
|
||||
}
|
||||
@@ -15,8 +15,6 @@ public class SysPortalMain extends BaseMainEntity {
|
||||
|
||||
private Integer ornum;
|
||||
|
||||
private String notes;
|
||||
|
||||
@ManyToMany
|
||||
@JoinTable(name = "sys_portal_main_viewer", joinColumns = {@JoinColumn(name = "mid")},
|
||||
inverseJoinColumns = {@JoinColumn(name = "oid")})
|
||||
|
||||
@@ -25,8 +25,6 @@ public class SysPortalRole extends BaseMainEntity
|
||||
@Column(length = 32)
|
||||
private String label;
|
||||
|
||||
private String notes;
|
||||
|
||||
//拥有的菜单
|
||||
@ManyToMany
|
||||
@JoinTable(name = "sys_portal_role_menu",
|
||||
|
||||
@@ -20,6 +20,7 @@ import org.springframework.web.cors.UrlBasedCorsConfigurationSource;
|
||||
import java.util.Arrays;
|
||||
import java.util.Collections;
|
||||
|
||||
//Spring Security的配置
|
||||
@Configuration
|
||||
@RequiredArgsConstructor
|
||||
public class SecurityConfig extends WebSecurityConfigurerAdapter {
|
||||
@@ -60,10 +61,11 @@ public class SecurityConfig extends WebSecurityConfigurerAdapter {
|
||||
@Bean
|
||||
CorsConfigurationSource corsConfigurationSource() {
|
||||
CorsConfiguration configuration = new CorsConfiguration();
|
||||
//可限制域名
|
||||
// if (environment.acceptsProfiles(Profiles.of("dev"))) {
|
||||
// configuration.setAllowedOrigins(Collections.singletonList("http://localhost:3100"));
|
||||
// } else {
|
||||
// configuration.setAllowedOrigins(Collections.singletonList("https://uaa.imooc.com"));
|
||||
// configuration.setAllowedOrigins(Collections.singletonList("http://zsvg.com"));
|
||||
// }
|
||||
// configuration.setAllowedOrigins(Collections.singletonList("http://localhost:3100"));
|
||||
configuration.setAllowedOrigins(Collections.singletonList("*"));
|
||||
|
||||
@@ -28,36 +28,21 @@ import java.io.IOException;
|
||||
import java.util.HashMap;
|
||||
import java.util.Map;
|
||||
|
||||
|
||||
//认证API:主要包含登录登出、token刷新、菜单获取、用户信息获取
|
||||
@RestController
|
||||
public class AuthcApi {
|
||||
|
||||
//登录
|
||||
@PostMapping("/login")
|
||||
public R login(@Valid @RequestBody LoginVo loginVo, HttpServletRequest request) throws IOException, ClassNotFoundException {
|
||||
// System.out.println("开始登录");
|
||||
public R login(@Valid @RequestBody LoginVo loginVo, HttpServletRequest request) {
|
||||
//1.登录验证
|
||||
UserDo userDo = null;
|
||||
try {
|
||||
userDo = jdbcDao.getTp().queryForObject("select id,name,pacod,retag from sys_org_user where usnam=? and avtag=1",
|
||||
new Object[]{loginVo.getUsername()}, new BeanPropertyRowMapper<>(UserDo.class));
|
||||
} catch (DataAccessException ignored) {
|
||||
|
||||
}
|
||||
|
||||
boolean passFlag = false;
|
||||
if (userDo != null) {
|
||||
String encodePassword = DigestUtils.md5DigestAsHex(("abc" + loginVo.getPassword() + "xyz").getBytes());//数据库密码验证
|
||||
if (encodePassword.equals(userDo.getPacod())) {
|
||||
passFlag = true;
|
||||
} else {
|
||||
//passFlag = ldapHandler.authenticate(loginVo.getUsername(), loginVo.getPassword());//AD域密码验证
|
||||
}
|
||||
}
|
||||
boolean passFlag = authcService.check(userDo, loginVo);
|
||||
if (!passFlag) {
|
||||
return R.build(402, "账号不存在或密码错误");
|
||||
}
|
||||
|
||||
//2.初始化用户信息,获取菜单与权限
|
||||
//2.创建accessToken与refreshToken
|
||||
String atokenUUID = IdUtil.simpleUUID();
|
||||
String atoken = jwtHandler.createTokenByUuid(atokenUUID);
|
||||
String rtoken = jwtHandler.createTokenByUuid(loginVo.getUsername());//需要加密下
|
||||
@@ -66,18 +51,18 @@ public class AuthcApi {
|
||||
backMap.put("token", atoken);
|
||||
backMap.put("rtoken", rtoken);
|
||||
|
||||
//3.初始化用户信息,获取门户,菜单与按钮
|
||||
Zuser zuser = new Zuser(userDo.getId(), userDo.getName(), loginVo.getUsername());
|
||||
authcService.initZuser(zuser, userDo, backMap);//初始化用户
|
||||
authcService.initZuser(zuser, userDo, backMap); //这个方法非常重要
|
||||
|
||||
redisHandler.set("online-key:" + atokenUUID, zuser, appConfig.getJwt().getAtime());//默认8小时过期
|
||||
|
||||
redisHandler.set("online-key:"+atokenUUID, zuser, appConfig.getJwt().getAtime());//默认8小时过期
|
||||
|
||||
//3.异步方式记录登录日志
|
||||
monLogLoginService.save("online-key:"+atokenUUID,zuser,request);
|
||||
//4.异步方式记录登录日志
|
||||
monLogLoginService.save("online-key:" + atokenUUID, zuser, request);
|
||||
return R.ok(backMap);
|
||||
|
||||
}
|
||||
|
||||
//token刷新
|
||||
@GetMapping("/rtoken")
|
||||
public R rtoken(@PathParam("token2") String token2) {
|
||||
System.out.println("token2=" + token2);
|
||||
@@ -92,40 +77,38 @@ public class AuthcApi {
|
||||
return R.ok(backMap);
|
||||
}
|
||||
|
||||
//登出
|
||||
@GetMapping("/logout")
|
||||
public R logout(Authentication auth) {
|
||||
return R.ok();
|
||||
}
|
||||
|
||||
//获取用户信息
|
||||
@GetMapping("/getUserInfo")
|
||||
public R getUserInfo(Authentication auth, HttpServletRequest request) {
|
||||
Zuser zuser = (Zuser) auth.getPrincipal();
|
||||
//monLogLoginService.save(zuser,request);
|
||||
return R.ok(zuser);
|
||||
}
|
||||
|
||||
//获取菜单树
|
||||
@GetMapping("/getMenuList")
|
||||
public R getMenuList(String porid, Authentication auth, HttpServletRequest request) {
|
||||
if(auth==null){
|
||||
//System.out.println("登录过期");
|
||||
return R.build(401,"登录过期");
|
||||
if (auth == null) {
|
||||
return R.build(401, "登录过期");
|
||||
}
|
||||
Map<String, Object> backMap = new HashMap<>();
|
||||
Zuser zuser = (Zuser) auth.getPrincipal();
|
||||
|
||||
UserDo userDo = jdbcDao.getTp().queryForObject("select id,name,pacod,retag from sys_org_user where id=? and avtag=1",
|
||||
new Object[]{zuser.getId()}, new BeanPropertyRowMapper<>(UserDo.class));
|
||||
if(XstrUtil.isBlank(porid)){
|
||||
UserDo userDo = jdbcDao.getTp().queryForObject("select id,name,pacod,retag from sys_org_user where id=? and avtag=1",
|
||||
new Object[]{zuser.getId()}, new BeanPropertyRowMapper<>(UserDo.class));
|
||||
if (XstrUtil.isBlank(porid)) {
|
||||
authcService.initZuser(zuser, userDo, backMap);
|
||||
}else{
|
||||
authcService.initZuser2(zuser, backMap,porid);
|
||||
} else {
|
||||
authcService.switchPortal(zuser, backMap, porid);
|
||||
}
|
||||
// monLogLoginService.save(zuser,request);
|
||||
|
||||
return R.ok(backMap);
|
||||
}
|
||||
|
||||
|
||||
@Autowired
|
||||
private AuthcService authcService;
|
||||
|
||||
@@ -138,17 +121,11 @@ public class AuthcApi {
|
||||
@Autowired
|
||||
private JwtHandler jwtHandler;
|
||||
|
||||
@Autowired
|
||||
private LdapHandler ldapHandler;
|
||||
|
||||
@Autowired
|
||||
private JdbcDao jdbcDao;
|
||||
|
||||
@Autowired
|
||||
private MonLogLoginService monLogLoginService;
|
||||
|
||||
@Autowired
|
||||
private SysOrgUserService userService;
|
||||
|
||||
|
||||
}
|
||||
|
||||
@@ -15,6 +15,7 @@ import java.util.HashMap;
|
||||
import java.util.Map;
|
||||
import java.util.Optional;
|
||||
|
||||
//认证失败后的处理
|
||||
@Component
|
||||
public class AuthcFailedHandler implements AuthenticationEntryPoint {
|
||||
|
||||
|
||||
@@ -0,0 +1,57 @@
|
||||
package vboot.core.security.authc;
|
||||
|
||||
import cn.hutool.core.util.StrUtil;
|
||||
import org.springframework.beans.factory.annotation.Autowired;
|
||||
import org.springframework.stereotype.Component;
|
||||
import vboot.core.common.dao.JdbcDao;
|
||||
import vboot.core.security.pojo.UserDo;
|
||||
|
||||
import java.util.List;
|
||||
|
||||
//服务于认证Service,提供组织架构相关逻辑处理
|
||||
@Component
|
||||
public class AuthcOrgHandler {
|
||||
|
||||
//获取组织架构可用集
|
||||
public String findConds(UserDo duser) {
|
||||
StringBuilder conds = new StringBuilder();
|
||||
//1. conds拼接父级id
|
||||
if (StrUtil.isNotBlank(duser.getTier())) {
|
||||
String[] pidArr = duser.getTier().split("x");
|
||||
for (int i = pidArr.length - 1; i >= 0; i--) {
|
||||
if (!"".equals(pidArr[i])) {
|
||||
conds.append("'").append(pidArr[i]).append("',");
|
||||
}
|
||||
}
|
||||
} else {
|
||||
conds = new StringBuilder("'" + duser.getId() + "',");
|
||||
}
|
||||
//2. conds拼接岗位id
|
||||
List<String> postList = findPostList(duser.getId());
|
||||
for (String str : postList) {
|
||||
conds.append("'").append(str).append("',");
|
||||
}
|
||||
conds = new StringBuilder(conds.substring(0, conds.length() - 1));//优化
|
||||
//3. conds拼接群组id
|
||||
List<String> groupList = findGroupList(conds.toString());
|
||||
for (String str : groupList) {
|
||||
conds.append(",'").append(str).append("'");
|
||||
}
|
||||
return conds.toString();
|
||||
}
|
||||
|
||||
//获取组织架构岗位id集合
|
||||
private List<String> findPostList(String uid) {
|
||||
String sql = "select pid as id from sys_org_post_org where oid=?";
|
||||
return jdbcDao.findStringList(sql, uid);
|
||||
}
|
||||
|
||||
//获取组织架构群组id集合
|
||||
private List<String> findGroupList(String conds) {
|
||||
String sql = "select DISTINCT gid as id from sys_org_group_org where oid in (" + conds + ")";
|
||||
return jdbcDao.findStringList(sql);
|
||||
}
|
||||
|
||||
@Autowired
|
||||
private JdbcDao jdbcDao;
|
||||
}
|
||||
@@ -0,0 +1,270 @@
|
||||
package vboot.core.security.authc;
|
||||
|
||||
import org.springframework.beans.factory.annotation.Autowired;
|
||||
import org.springframework.jdbc.core.BeanPropertyRowMapper;
|
||||
import org.springframework.stereotype.Component;
|
||||
import vboot.core.common.dao.JdbcDao;
|
||||
import vboot.core.security.pojo.Zmenu;
|
||||
import vboot.core.security.pojo.Zmeta;
|
||||
import vboot.core.security.pojo.Zportal;
|
||||
|
||||
import java.util.ArrayList;
|
||||
import java.util.List;
|
||||
|
||||
//服务于认证Service,提供门户及菜单相关逻辑处理
|
||||
@Component
|
||||
public class AuthcPortalHandler {
|
||||
|
||||
//获取门户集合
|
||||
public List<Zportal> findPortalList(String conds) {
|
||||
String sql = "select distinct m.name,m.id from sys_portal_main m inner join sys_portal_role r on r.porid=m.id" +
|
||||
" inner join sys_portal_role_org ro on ro.rid=r.id where m.avtag=1 and ro.oid in (" + conds + ") order by m.ornum";
|
||||
return jdbcDao.getTp().query(sql, new BeanPropertyRowMapper<>(Zportal.class));
|
||||
}
|
||||
|
||||
//获取菜单集合
|
||||
public List<Zmenu> findMenuList(String conds, List<Zportal> portalList, String porid) {
|
||||
String portals = "";
|
||||
for (Zportal zportal : portalList) {
|
||||
portals += "'" + zportal.getId() + "',";
|
||||
}
|
||||
portals = portals.substring(0, portals.length() - 1);
|
||||
|
||||
//1.获取目录集合
|
||||
String direSql = "select m.porid,m.shtag,m.name,m.code,m.path,m.icon,m.comp,m.ornum,m.id,m.pid,m.perm from sys_portal_menu m where m.type = 'D' and m.porid in (" + portals + ") and m.avtag=1 order by m.ornum";
|
||||
List<Zmenu> direList = jdbcDao.getTp().query(direSql, (rs, rowNum) -> {
|
||||
Zmenu zmenu = new Zmenu();
|
||||
zmenu.setType("D");
|
||||
zmenu.setId(rs.getString("id"));
|
||||
zmenu.setPorid(rs.getString("porid"));
|
||||
zmenu.setPid(rs.getString("pid"));
|
||||
zmenu.setPerm(rs.getString("perm"));
|
||||
zmenu.setName(rs.getString("code"));
|
||||
zmenu.setPath(rs.getString("path"));
|
||||
zmenu.setComponent(rs.getString("comp"));
|
||||
Zmeta zmeta = new Zmeta();
|
||||
zmeta.setTitle(rs.getString("name"));
|
||||
zmeta.setOrderNo(rs.getInt("ornum"));
|
||||
zmeta.setIsHide(!rs.getBoolean("shtag"));
|
||||
if (!porid.equals(rs.getString("porid"))) {
|
||||
zmeta.setIsHide(true);
|
||||
}
|
||||
zmeta.setIcon(rs.getString("icon"));
|
||||
zmenu.setMeta(zmeta);
|
||||
return zmenu;
|
||||
});
|
||||
|
||||
//2.获取菜单集合
|
||||
String sql = "select distinct m.porid,m.shtag,m.type,m.name,m.code,m.path,m.icon,m.comp,m.ornum,m.id,m.pid,m.perm from sys_portal_menu m inner join sys_portal_role_menu rm on rm.mid=m.id inner join sys_portal_role_org ru on ru.rid=rm.rid where m.type = 'M' and m.porid in (" + portals + ") and m.avtag=1 and ru.oid in (" + conds + ") order by m.ornum";
|
||||
List<Zmenu> list = jdbcDao.getTp().query(sql, (rs, rowNum) -> {
|
||||
Zmenu zmenu = new Zmenu();
|
||||
zmenu.setId(rs.getString("id"));
|
||||
zmenu.setType("M");
|
||||
zmenu.setPorid(rs.getString("porid"));
|
||||
zmenu.setPid(rs.getString("pid"));
|
||||
zmenu.setPerm(rs.getString("perm"));
|
||||
zmenu.setName(rs.getString("code"));
|
||||
zmenu.setPath(rs.getString("path"));
|
||||
zmenu.setComponent(rs.getString("comp"));
|
||||
Zmeta zmeta = new Zmeta();
|
||||
zmeta.setTitle(rs.getString("name"));
|
||||
zmeta.setIsHide(!rs.getBoolean("shtag"));
|
||||
if (!porid.equals(rs.getString("porid"))) {
|
||||
zmeta.setIsHide(true);
|
||||
}
|
||||
zmeta.setOrderNo(rs.getInt("ornum"));
|
||||
zmeta.setIcon(rs.getString("icon"));
|
||||
zmenu.setMeta(zmeta);
|
||||
return zmenu;
|
||||
});
|
||||
|
||||
//3.将菜单装载到目录
|
||||
List<Zmenu> shouldAddlist1 = new ArrayList<>();
|
||||
for (Zmenu zdire : direList) {
|
||||
for (Zmenu zmenu : list) {
|
||||
if (zdire.getId().equals(zmenu.getPid())) {
|
||||
shouldAddlist1.add(zdire);
|
||||
break;
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
List<Zmenu> shouldAddlist2 = new ArrayList<>();
|
||||
for (Zmenu zdire : direList) {
|
||||
for (Zmenu zshould : shouldAddlist1) {
|
||||
if (zshould.getPid() != null) {
|
||||
if (zdire.getId().equals(zshould.getPid())) {
|
||||
shouldAddlist2.add(zdire);
|
||||
break;
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
List<Zmenu> shouldAddlist3 = new ArrayList<>();
|
||||
for (Zmenu zdire : direList) {
|
||||
for (Zmenu zshould : shouldAddlist2) {
|
||||
if (zshould.getPid() != null) {
|
||||
if (zdire.getId().equals(zshould.getPid())) {
|
||||
shouldAddlist3.add(zdire);
|
||||
break;
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
list.addAll(shouldAddlist1);
|
||||
list.addAll(shouldAddlist2);
|
||||
list.addAll(shouldAddlist3);
|
||||
if (list.size() == 0) {
|
||||
return findNoPowerMenuList();
|
||||
}
|
||||
if (portalList.size() == 1) {
|
||||
return list;
|
||||
}
|
||||
|
||||
//4.如果存在多个门户,则要进一步处理。
|
||||
//去除其他门户相同name或path的菜单
|
||||
List<Zmenu> backList = new ArrayList<>();
|
||||
for (Zmenu zmenu : list) {
|
||||
if (porid.equals(zmenu.getPorid())) {
|
||||
backList.add(zmenu);
|
||||
}
|
||||
}
|
||||
for (Zmenu zmenu : list) {
|
||||
if (!porid.equals(zmenu.getPorid())) {
|
||||
boolean flag = false;
|
||||
for (Zmenu backMenu : backList) {
|
||||
if (backMenu.getName().equals(zmenu.getName()) || backMenu.getPath().equals(zmenu.getPath())) {
|
||||
flag = true;
|
||||
break;
|
||||
}
|
||||
}
|
||||
if (!flag) {
|
||||
backList.add(zmenu);
|
||||
}
|
||||
}
|
||||
}
|
||||
return backList;
|
||||
}
|
||||
|
||||
//获取所有门户列表,管理员用
|
||||
public List<Zportal> findAllPortalList() {
|
||||
String sql = "select id,name from sys_portal_main where avtag=1 order by ornum";
|
||||
return jdbcDao.getTp().query(sql, new BeanPropertyRowMapper<>(Zportal.class));
|
||||
}
|
||||
|
||||
//获取管理员门户的菜单,管理员用
|
||||
public List<Zmenu> findSysMenuList(String porid) {
|
||||
String sql = "select m.porid,m.shtag,m.type,m.name,m.code,m.path,m.icon,m.comp,m.ornum,m.id,m.pid,m.perm from sys_portal_menu m where m.avtag=1 order by m.ornum";
|
||||
List<Zmenu> list = jdbcDao.getTp().query(sql, (rs, rowNum) -> {
|
||||
Zmenu zmenu = new Zmenu();
|
||||
zmenu.setId(rs.getString("id"));
|
||||
zmenu.setPorid(rs.getString("porid"));
|
||||
zmenu.setPid(rs.getString("pid"));
|
||||
zmenu.setPerm(rs.getString("perm"));
|
||||
zmenu.setType(rs.getString("type"));
|
||||
zmenu.setName(rs.getString("code"));
|
||||
zmenu.setPath(rs.getString("path"));
|
||||
zmenu.setComponent(rs.getString("comp"));
|
||||
Zmeta zmeta = new Zmeta();
|
||||
zmeta.setIsHide(!rs.getBoolean("shtag"));
|
||||
if (!porid.equals(rs.getString("porid"))) {
|
||||
zmeta.setIsHide(true);
|
||||
}
|
||||
zmeta.setTitle(rs.getString("name"));
|
||||
zmeta.setOrderNo(rs.getInt("ornum"));
|
||||
zmeta.setIcon(rs.getString("icon"));
|
||||
zmenu.setMeta(zmeta);
|
||||
return zmenu;
|
||||
});
|
||||
//去除其他门户相同name或path的菜单
|
||||
List<Zmenu> backList = new ArrayList<>();
|
||||
for (Zmenu zmenu : list) {
|
||||
if (porid.equals(zmenu.getPorid())) {
|
||||
backList.add(zmenu);
|
||||
}
|
||||
}
|
||||
for (Zmenu zmenu : list) {
|
||||
if (!porid.equals(zmenu.getPorid())) {
|
||||
boolean flag = false;
|
||||
for (Zmenu backMenu : backList) {
|
||||
if (backMenu.getName().equals(zmenu.getName()) || backMenu.getPath().equals(zmenu.getPath())) {
|
||||
flag = true;
|
||||
break;
|
||||
}
|
||||
}
|
||||
if (!flag) {
|
||||
backList.add(zmenu);
|
||||
}
|
||||
}
|
||||
}
|
||||
return backList;
|
||||
}
|
||||
|
||||
//如果用户没有菜单授权,则返回一个未授权的菜单
|
||||
public List<Zmenu> findNoPowerMenuList() {
|
||||
List<Zmenu> list = new ArrayList<>();
|
||||
Zmenu zmenu = new Zmenu();
|
||||
zmenu.setType("M");
|
||||
zmenu.setId("Home");
|
||||
zmenu.setName("Home");
|
||||
zmenu.setPath("/home");
|
||||
zmenu.setComponent("/home/noPower");
|
||||
Zmeta zmeta = new Zmeta();
|
||||
zmeta.setTitle("未授权");
|
||||
zmeta.setOrderNo(0);
|
||||
zmeta.setIsHide(false);
|
||||
zmeta.setIcon("ele-Lock");
|
||||
zmenu.setMeta(zmeta);
|
||||
list.add(zmenu);
|
||||
return list;
|
||||
}
|
||||
|
||||
//使用递归方法建树
|
||||
public List<Zmenu> buildByRecursive(List<Zmenu> nodes)
|
||||
{
|
||||
List<Zmenu> list = new ArrayList<>();
|
||||
for (Zmenu node : nodes) {
|
||||
if (node.getPid() == null)
|
||||
{
|
||||
list.add(findChildrenByTier(node, nodes));
|
||||
}
|
||||
else
|
||||
{
|
||||
boolean flag = false;
|
||||
for (Zmenu node2 : nodes) {
|
||||
if (node.getPid().equals(node2.getId()))
|
||||
{
|
||||
flag = true;
|
||||
break;
|
||||
}
|
||||
}
|
||||
if (!flag)
|
||||
{
|
||||
list.add(findChildrenByTier(node, nodes));
|
||||
}
|
||||
}
|
||||
}
|
||||
return list;
|
||||
}
|
||||
|
||||
//递归查找子节点
|
||||
private Zmenu findChildrenByTier(Zmenu node, List<Zmenu> nodes)
|
||||
{
|
||||
for (Zmenu item : nodes) {
|
||||
if (node.getId().equals(item.getPid()))
|
||||
{
|
||||
if (node.getChildren() == null)
|
||||
{
|
||||
node.setChildren(new ArrayList<>());
|
||||
}
|
||||
node.getChildren().add(findChildrenByTier(item, nodes));
|
||||
}
|
||||
}
|
||||
return node;
|
||||
}
|
||||
|
||||
@Autowired
|
||||
private JdbcDao jdbcDao;
|
||||
|
||||
}
|
||||
@@ -1,11 +1,12 @@
|
||||
package vboot.core.security.authc;
|
||||
|
||||
import cn.hutool.core.util.StrUtil;
|
||||
import com.alibaba.fastjson.JSON;
|
||||
import org.springframework.dao.DataAccessException;
|
||||
import org.springframework.jdbc.core.BeanPropertyRowMapper;
|
||||
import org.springframework.util.DigestUtils;
|
||||
import vboot.core.common.dao.JdbcDao;
|
||||
import vboot.core.common.init.SysApiCache;
|
||||
import vboot.core.common.init.Yapi;
|
||||
import vboot.core.security.authz.AuthzApiData;
|
||||
import vboot.core.security.pojo.Yapi;
|
||||
import vboot.core.security.pojo.*;
|
||||
import org.springframework.beans.factory.annotation.Autowired;
|
||||
import org.springframework.stereotype.Service;
|
||||
@@ -15,47 +16,75 @@ import java.util.ArrayList;
|
||||
import java.util.List;
|
||||
import java.util.Map;
|
||||
|
||||
//认证Service
|
||||
@Service
|
||||
@Transactional(rollbackFor = Exception.class)
|
||||
public class AuthcService {
|
||||
|
||||
//校验密码是否正确
|
||||
public boolean check(UserDo userDo,LoginVo loginVo){
|
||||
try {
|
||||
userDo = jdbcDao.getTp().queryForObject(
|
||||
"select id,name,pacod,retag from sys_org_user where usnam=? and avtag=1",
|
||||
new Object[]{loginVo.getUsername()}, new BeanPropertyRowMapper<>(UserDo.class));
|
||||
} catch (DataAccessException ignored) {
|
||||
|
||||
}
|
||||
|
||||
boolean passFlag = false;
|
||||
if (userDo != null) {
|
||||
//前台传入的登录密码做加盐MD5加密
|
||||
String encodePassword = DigestUtils.md5DigestAsHex(("abc" + loginVo.getPassword() + "xyz").getBytes());
|
||||
//比较数据里的加盐密码是否相同
|
||||
if (encodePassword.equals(userDo.getPacod())) {
|
||||
passFlag = true;
|
||||
} else {
|
||||
//如数据库校验不通过,可尝试其他方式校验,比如下面的AD域密码验证校验
|
||||
//passFlag = ldapHandler.authenticate(loginVo.getUsername(), loginVo.getPassword());
|
||||
}
|
||||
}
|
||||
return passFlag;
|
||||
}
|
||||
|
||||
//初始化用户
|
||||
//查询用户组织架构可用集,门户列表,菜单树,API权限集
|
||||
//查询完后做缓存,下次查询直接通过缓存查询
|
||||
public void initZuser(Zuser zuser, UserDo userDo, Map<String, Object> backMap) {
|
||||
if (!userDo.getRetag()) {
|
||||
//判断是否已经初始化过了,如已初始化,则可走缓存路线
|
||||
if (!userDo.getRetag()) {//数据库按步骤路线
|
||||
//1.获取用户所有的组织架构集:conds
|
||||
String conds = findConds(userDo);
|
||||
String conds = orgHandler.findConds(userDo);
|
||||
zuser.setConds(conds);
|
||||
|
||||
//2.根据组织架构集conds查询前台菜单集:menus
|
||||
List<Zmenu> menuList;
|
||||
List<Zportal> portalList;
|
||||
if (zuser.isAdmin()) {
|
||||
portalList = findAllPortalList();
|
||||
menuList = findSysMenuList(portalList.get(0).getId());
|
||||
portalList = portalHandler.findAllPortalList();
|
||||
menuList = portalHandler.findSysMenuList(portalList.get(0).getId());
|
||||
} else {
|
||||
portalList = findPortalList(zuser.getConds());
|
||||
portalList = portalHandler.findPortalList(zuser.getConds());
|
||||
if (portalList != null && portalList.size() > 0) {
|
||||
menuList = findMenuList(zuser.getConds(), portalList, portalList.get(0).getId());
|
||||
menuList = portalHandler.findMenuList(zuser.getConds(), portalList, portalList.get(0).getId());
|
||||
} else {
|
||||
menuList = findNoPowerMenuList();
|
||||
menuList = portalHandler.findNoPowerMenuList();
|
||||
}
|
||||
}
|
||||
|
||||
//3.根据组织架构集conds查询前台按钮集:btns
|
||||
// 设置zuser的权限集(位与代码方式的权限集)
|
||||
List<String> btnList = findBtnList(zuser);
|
||||
List<String> btnList = findBtnList(zuser);//附加功能:设置zuser的权限集
|
||||
|
||||
//4.设置前台返回数据
|
||||
menuList = buildByRecursive(menuList);
|
||||
menuList = portalHandler.buildByRecursive(menuList);
|
||||
backMap.put("portals", portalList);
|
||||
backMap.put("menus", menuList);
|
||||
backMap.put("btns", btnList);
|
||||
backMap.put("zuser", zuser);
|
||||
|
||||
//5.更新用户,序列化保存数据,使下次这些数据可直接从数据库取
|
||||
updateUser(zuser, menuList, btnList, portalList);
|
||||
System.out.println("通过数据库");
|
||||
|
||||
} else {
|
||||
//5.更新用户,序列化保存数据,使下次这些数据可直接从缓存表读取
|
||||
updateUser(zuser, portalList, menuList, btnList);
|
||||
//System.out.println("通过数据库");
|
||||
} else {//缓存路线,可扩展成redis方式
|
||||
String sql = "select conds,menus,btns,perms,portals from sys_org_user_cache where id=?";
|
||||
Map<String, Object> map = jdbcDao.findMap(sql, zuser.getId());
|
||||
zuser.setConds((String) map.get("conds"));
|
||||
@@ -84,400 +113,54 @@ public class AuthcService {
|
||||
backMap.put("portals", portalList);
|
||||
backMap.put("btns", btnArr);
|
||||
backMap.put("zuser", zuser);
|
||||
System.out.println("通过缓存");
|
||||
//System.out.println("通过缓存");
|
||||
}
|
||||
|
||||
// //初始化数据库user
|
||||
// String perms = "";
|
||||
// for (int i = 0; i < permSum.length; i++) {
|
||||
// perms += permSum[i] + ";";
|
||||
// }
|
||||
// if (!perms.equals("")) {
|
||||
// perms = perms.substring(0, perms.length() - 1);
|
||||
// } else {
|
||||
// perms = "0";
|
||||
// }
|
||||
// updatePerson(perms, conds, id);
|
||||
// zuser = new Zuser(id, "" + orgInfo.get("name"), sysOrgUser.getUsnam(), permSum, conds);
|
||||
// zuser.setAdmin(XuserUtil.isAdmin(sysOrgUser.getUsnam()));
|
||||
// zuser.setWatag(sysOrgUser.getWatag());
|
||||
// } else {
|
||||
// String[] permArr = sysOrgUser.getPerms().split(";");
|
||||
// long[] permSum = new long[permArr.length];
|
||||
// for (int i = 0; i < permArr.length; i++) {
|
||||
// permSum[i] = Long.parseLong(permArr[i]);
|
||||
// }
|
||||
// zuser = new Zuser(id, "" + orgInfo.get("name"), "" + sysOrgUser.getUsnam(), permSum, sysOrgUser.getConds());
|
||||
// zuser.setAdmin(XuserUtil.isAdmin(sysOrgUser.getUsnam()));
|
||||
// zuser.setWatag(sysOrgUser.getWatag());
|
||||
// }
|
||||
// return zuser;
|
||||
|
||||
|
||||
}
|
||||
|
||||
public void initZuser2(Zuser zuser, Map<String, Object> backMap, String porid) {
|
||||
//2.根据组织架构集conds查询前台菜单集:menus
|
||||
//切换门户,根据门户id,设置菜单
|
||||
public void switchPortal(Zuser zuser, Map<String, Object> backMap, String porid) {
|
||||
//1.根据组织架构集conds查询前台菜单集:menus
|
||||
List<Zmenu> menuList;
|
||||
List<Zportal> portalList;
|
||||
if (zuser.isAdmin()) {
|
||||
portalList = findAllPortalList();
|
||||
menuList = findSysMenuList(porid);
|
||||
portalList = portalHandler.findAllPortalList();
|
||||
menuList = portalHandler.findSysMenuList(porid);
|
||||
} else {
|
||||
portalList = findPortalList(zuser.getConds());
|
||||
portalList = portalHandler.findPortalList(zuser.getConds());
|
||||
if (portalList != null && portalList.size() > 0) {
|
||||
menuList = findMenuList(zuser.getConds(), portalList, porid);
|
||||
menuList = portalHandler.findMenuList(zuser.getConds(), portalList, porid);
|
||||
} else {
|
||||
menuList = findNoPowerMenuList();
|
||||
menuList = portalHandler.findNoPowerMenuList();
|
||||
}
|
||||
}
|
||||
|
||||
//4.设置前台返回数据
|
||||
menuList = buildByRecursive(menuList);
|
||||
//2.设置前台返回数据
|
||||
menuList = portalHandler.buildByRecursive(menuList);
|
||||
backMap.put("portals", portalList);
|
||||
backMap.put("menus", menuList);
|
||||
}
|
||||
|
||||
// private void calcPerms(Zuser zuser,){
|
||||
// //查询权限集合
|
||||
// Integer posSum = SysPermApiService.AUTHPOS + 1;//取出最大权限位
|
||||
// long[] permSum = new long[posSum];
|
||||
////
|
||||
// List<Zperm> zpermList = getPermList(conds);
|
||||
// for (Zperm zperm : zpermList) {
|
||||
// for (int i = 0; i < posSum; i++) {
|
||||
// if (i == zperm.getPos()) {
|
||||
// permSum[i] = permSum[i] + zperm.getCode();
|
||||
// }
|
||||
// }
|
||||
// }
|
||||
// }
|
||||
|
||||
private void setPerms(Zuser zuser, List<Zmenu> zmenus) {
|
||||
|
||||
//获取用户信息
|
||||
@Transactional(readOnly = true)
|
||||
public Zuser getUser(String username) {
|
||||
Map<String, Object> map = jdbcDao.getTp().queryForMap("select u.id,u.name from sys_org_user u where u.usnam=? and u.avtag=1", username);
|
||||
Zuser user = new Zuser();
|
||||
user.setId((String) map.get("id"));
|
||||
user.setName((String) map.get("name"));
|
||||
return user;
|
||||
}
|
||||
|
||||
private String findConds(UserDo duser) {
|
||||
StringBuilder conds = new StringBuilder();
|
||||
//1. conds拼接父级id
|
||||
if (StrUtil.isNotBlank(duser.getTier())) {
|
||||
String[] pidArr = duser.getTier().split("x");
|
||||
for (int i = pidArr.length - 1; i >= 0; i--) {
|
||||
if (!"".equals(pidArr[i])) {
|
||||
conds.append("'").append(pidArr[i]).append("',");
|
||||
}
|
||||
}
|
||||
} else {
|
||||
conds = new StringBuilder("'" + duser.getId() + "',");
|
||||
}
|
||||
//2. conds拼接岗位id
|
||||
List<String> postList = findPostList(duser.getId());
|
||||
for (String str : postList) {
|
||||
conds.append("'").append(str).append("',");
|
||||
}
|
||||
conds = new StringBuilder(conds.substring(0, conds.length() - 1));//优化
|
||||
//3. conds拼接群组id
|
||||
List<String> groupList = findGroupList(conds.toString());
|
||||
for (String str : groupList) {
|
||||
conds.append(",'").append(str).append("'");
|
||||
}
|
||||
return conds.toString();
|
||||
}
|
||||
//获取前台按钮集合,设置用户API权限集
|
||||
private List<String> findBtnList(Zuser zuser) {
|
||||
List<String> btnList = new ArrayList<>();
|
||||
|
||||
|
||||
private List<String> findPostList(String uid) {
|
||||
String sql = "select pid as id from sys_org_post_org where oid=?";
|
||||
return jdbcDao.findStringList(sql, uid);
|
||||
}
|
||||
|
||||
private List<String> findGroupList(String conds) {
|
||||
String sql = "select DISTINCT gid as id from sys_org_group_org where oid in (" + conds + ")";
|
||||
return jdbcDao.findStringList(sql);
|
||||
}
|
||||
|
||||
public List<Zportal> findPortalList(String conds) {
|
||||
String sql = "select distinct m.name,m.id from sys_portal_main m inner join sys_portal_role r on r.porid=m.id" +
|
||||
" inner join sys_portal_role_org ro on ro.rid=r.id where m.avtag=1 and ro.oid in (" + conds + ") order by m.ornum";
|
||||
return jdbcDao.getTp().query(sql, new BeanPropertyRowMapper<>(Zportal.class));
|
||||
}
|
||||
|
||||
public List<Zmenu> findMenuList(String conds, List<Zportal> portalList, String porid) {
|
||||
String portals = "";
|
||||
for (Zportal zportal : portalList) {
|
||||
portals += "'" + zportal.getId() + "',";
|
||||
}
|
||||
portals = portals.substring(0, portals.length() - 1);
|
||||
|
||||
String direSql = "select m.porid,m.shtag,m.name,m.code,m.path,m.icon,m.comp,m.ornum,m.id,m.pid,m.perm from sys_portal_menu m where m.type = 'D' and m.porid in (" + portals + ") and m.avtag=1 order by m.ornum";
|
||||
List<Zmenu> direList = jdbcDao.getTp().query(direSql, (rs, rowNum) -> {
|
||||
Zmenu zmenu = new Zmenu();
|
||||
zmenu.setType("D");
|
||||
zmenu.setId(rs.getString("id"));
|
||||
zmenu.setPorid(rs.getString("porid"));
|
||||
zmenu.setPid(rs.getString("pid"));
|
||||
zmenu.setPerm(rs.getString("perm"));
|
||||
zmenu.setName(rs.getString("code"));
|
||||
zmenu.setPath(rs.getString("path"));
|
||||
zmenu.setComponent(rs.getString("comp"));
|
||||
Zmeta zmeta = new Zmeta();
|
||||
zmeta.setTitle(rs.getString("name"));
|
||||
zmeta.setOrderNo(rs.getInt("ornum"));
|
||||
zmeta.setIsHide(!rs.getBoolean("shtag"));
|
||||
if (!porid.equals(rs.getString("porid"))) {
|
||||
zmeta.setIsHide(true);
|
||||
}
|
||||
zmeta.setIcon(rs.getString("icon"));
|
||||
zmenu.setMeta(zmeta);
|
||||
return zmenu;
|
||||
});
|
||||
|
||||
String sql = "select distinct m.porid,m.shtag,m.type,m.name,m.code,m.path,m.icon,m.comp,m.ornum,m.id,m.pid,m.perm from sys_portal_menu m inner join sys_portal_role_menu rm on rm.mid=m.id inner join sys_portal_role_org ru on ru.rid=rm.rid where m.type = 'M' and m.porid in (" + portals + ") and m.avtag=1 and ru.oid in (" + conds + ") order by m.ornum";
|
||||
|
||||
List<Zmenu> list = jdbcDao.getTp().query(sql, (rs, rowNum) -> {
|
||||
Zmenu zmenu = new Zmenu();
|
||||
zmenu.setId(rs.getString("id"));
|
||||
zmenu.setType("M");
|
||||
zmenu.setPorid(rs.getString("porid"));
|
||||
zmenu.setPid(rs.getString("pid"));
|
||||
zmenu.setPerm(rs.getString("perm"));
|
||||
zmenu.setName(rs.getString("code"));
|
||||
zmenu.setPath(rs.getString("path"));
|
||||
zmenu.setComponent(rs.getString("comp"));
|
||||
Zmeta zmeta = new Zmeta();
|
||||
zmeta.setTitle(rs.getString("name"));
|
||||
zmeta.setIsHide(!rs.getBoolean("shtag"));
|
||||
if (!porid.equals(rs.getString("porid"))) {
|
||||
zmeta.setIsHide(true);
|
||||
}
|
||||
zmeta.setOrderNo(rs.getInt("ornum"));
|
||||
zmeta.setIcon(rs.getString("icon"));
|
||||
zmenu.setMeta(zmeta);
|
||||
return zmenu;
|
||||
});
|
||||
|
||||
List<Zmenu> shouldAddlist1 = new ArrayList<>();
|
||||
for (Zmenu zdire : direList) {
|
||||
for (Zmenu zmenu : list) {
|
||||
if (zdire.getId().equals(zmenu.getPid())) {
|
||||
shouldAddlist1.add(zdire);
|
||||
break;
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
List<Zmenu> shouldAddlist2 = new ArrayList<>();
|
||||
for (Zmenu zdire : direList) {
|
||||
for (Zmenu zshould : shouldAddlist1) {
|
||||
if (zshould.getPid() != null) {
|
||||
if (zdire.getId().equals(zshould.getPid())) {
|
||||
shouldAddlist2.add(zdire);
|
||||
break;
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
List<Zmenu> shouldAddlist3 = new ArrayList<>();
|
||||
for (Zmenu zdire : direList) {
|
||||
for (Zmenu zshould : shouldAddlist2) {
|
||||
if (zshould.getPid() != null) {
|
||||
if (zdire.getId().equals(zshould.getPid())) {
|
||||
shouldAddlist3.add(zdire);
|
||||
break;
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
list.addAll(shouldAddlist1);
|
||||
list.addAll(shouldAddlist2);
|
||||
list.addAll(shouldAddlist3);
|
||||
if (list.size() == 0) {
|
||||
return findNoPowerMenuList();
|
||||
}
|
||||
if (portalList.size() == 1) {
|
||||
return list;
|
||||
}
|
||||
//去除其他门户相同name或path的菜单
|
||||
List<Zmenu> backList = new ArrayList<>();
|
||||
for (Zmenu zmenu : list) {
|
||||
if (porid.equals(zmenu.getPorid())) {
|
||||
backList.add(zmenu);
|
||||
}
|
||||
}
|
||||
for (Zmenu zmenu : list) {
|
||||
if (!porid.equals(zmenu.getPorid())) {
|
||||
boolean flag = false;
|
||||
for (Zmenu backMenu : backList) {
|
||||
if (backMenu.getName().equals(zmenu.getName()) || backMenu.getPath().equals(zmenu.getPath())) {
|
||||
flag = true;
|
||||
break;
|
||||
}
|
||||
}
|
||||
if (!flag) {
|
||||
backList.add(zmenu);
|
||||
}
|
||||
}
|
||||
}
|
||||
return backList;
|
||||
}
|
||||
|
||||
public List<Zportal> findAllPortalList() {
|
||||
String sql = "select id,name from sys_portal_main where avtag=1 order by ornum";
|
||||
return jdbcDao.getTp().query(sql, new BeanPropertyRowMapper<>(Zportal.class));
|
||||
}
|
||||
|
||||
|
||||
public List<Zmenu> findSysMenuList(String porid) {
|
||||
// String sql = "select m.shtag,m.type,m.name,m.code,m.path,m.icon,m.comp,m.ornum,m.id,m.pid,m.perm from sys_portal_menu m where m.porid='sys' and m.avtag=1 order by m.ornum";
|
||||
String sql = "select m.porid,m.shtag,m.type,m.name,m.code,m.path,m.icon,m.comp,m.ornum,m.id,m.pid,m.perm from sys_portal_menu m where m.avtag=1 order by m.ornum";
|
||||
List<Zmenu> list = jdbcDao.getTp().query(sql, (rs, rowNum) -> {
|
||||
Zmenu zmenu = new Zmenu();
|
||||
zmenu.setId(rs.getString("id"));
|
||||
zmenu.setPorid(rs.getString("porid"));
|
||||
zmenu.setPid(rs.getString("pid"));
|
||||
zmenu.setPerm(rs.getString("perm"));
|
||||
zmenu.setType(rs.getString("type"));
|
||||
zmenu.setName(rs.getString("code"));
|
||||
zmenu.setPath(rs.getString("path"));
|
||||
zmenu.setComponent(rs.getString("comp"));
|
||||
Zmeta zmeta = new Zmeta();
|
||||
zmeta.setIsHide(!rs.getBoolean("shtag"));
|
||||
if (!porid.equals(rs.getString("porid"))) {
|
||||
zmeta.setIsHide(true);
|
||||
}
|
||||
zmeta.setTitle(rs.getString("name"));
|
||||
zmeta.setOrderNo(rs.getInt("ornum"));
|
||||
zmeta.setIcon(rs.getString("icon"));
|
||||
zmenu.setMeta(zmeta);
|
||||
return zmenu;
|
||||
});
|
||||
//去除其他门户相同name或path的菜单
|
||||
List<Zmenu> backList = new ArrayList<>();
|
||||
for (Zmenu zmenu : list) {
|
||||
if (porid.equals(zmenu.getPorid())) {
|
||||
backList.add(zmenu);
|
||||
}
|
||||
}
|
||||
for (Zmenu zmenu : list) {
|
||||
if (!porid.equals(zmenu.getPorid())) {
|
||||
boolean flag = false;
|
||||
for (Zmenu backMenu : backList) {
|
||||
if (backMenu.getName().equals(zmenu.getName()) || backMenu.getPath().equals(zmenu.getPath())) {
|
||||
flag = true;
|
||||
break;
|
||||
}
|
||||
}
|
||||
if (!flag) {
|
||||
backList.add(zmenu);
|
||||
}
|
||||
}
|
||||
}
|
||||
return backList;
|
||||
}
|
||||
|
||||
public List<Zmenu> findNoPowerMenuList() {
|
||||
List<Zmenu> list = new ArrayList<>();
|
||||
Zmenu zmenu = new Zmenu();
|
||||
zmenu.setType("M");
|
||||
zmenu.setId("Home");
|
||||
zmenu.setName("Home");
|
||||
zmenu.setPath("/home");
|
||||
zmenu.setComponent("/home/noPower");
|
||||
Zmeta zmeta = new Zmeta();
|
||||
zmeta.setTitle("未授权");
|
||||
zmeta.setOrderNo(0);
|
||||
zmeta.setIsHide(false);
|
||||
zmeta.setIcon("ele-Lock");
|
||||
zmenu.setMeta(zmeta);
|
||||
list.add(zmenu);
|
||||
return list;
|
||||
}
|
||||
|
||||
|
||||
// //使用递归方法建树
|
||||
// private List<Zmenu> buildTree(List<Zmenu> treeNodes) {
|
||||
// List<Zmenu> trees = new ArrayList<>();
|
||||
// for (Zmenu treeNode : treeNodes) {
|
||||
// if (treeNode.getPid() == null) {
|
||||
// trees.add(recTree(treeNode, treeNodes));
|
||||
// }
|
||||
// }
|
||||
// return trees;
|
||||
// }
|
||||
//
|
||||
//
|
||||
// //递归查找子节点
|
||||
// private Zmenu recTree(Zmenu treeNode, List<Zmenu> treeNodes) {
|
||||
// for (Zmenu it : treeNodes) {
|
||||
// if (treeNode.getId().equals(it.getPid())) {
|
||||
// if (treeNode.getChildren() == null) {
|
||||
// treeNode.setChildren(new ArrayList<>());
|
||||
// }
|
||||
// treeNode.getChildren().add(recTree(it, treeNodes));
|
||||
// }
|
||||
// }
|
||||
// return treeNode;
|
||||
// }
|
||||
|
||||
|
||||
//使用递归方法建树
|
||||
private List<Zmenu> buildByRecursive(List<Zmenu> nodes)
|
||||
{
|
||||
List<Zmenu> list = new ArrayList<>();
|
||||
for (Zmenu node : nodes) {
|
||||
if (node.getPid() == null)
|
||||
{
|
||||
list.add(findChildrenByTier(node, nodes));
|
||||
}
|
||||
else
|
||||
{
|
||||
boolean flag = false;
|
||||
for (Zmenu node2 : nodes) {
|
||||
if (node.getPid().equals(node2.getId()))
|
||||
{
|
||||
flag = true;
|
||||
break;
|
||||
}
|
||||
}
|
||||
if (!flag)
|
||||
{
|
||||
list.add(findChildrenByTier(node, nodes));
|
||||
}
|
||||
}
|
||||
}
|
||||
return list;
|
||||
}
|
||||
|
||||
//递归查找子节点
|
||||
private Zmenu findChildrenByTier(Zmenu node, List<Zmenu> nodes)
|
||||
{
|
||||
for (Zmenu item : nodes) {
|
||||
if (node.getId().equals(item.getPid()))
|
||||
{
|
||||
if (node.getChildren() == null)
|
||||
{
|
||||
node.setChildren(new ArrayList<>());
|
||||
}
|
||||
node.getChildren().add(findChildrenByTier(item, nodes));
|
||||
}
|
||||
}
|
||||
return node;
|
||||
}
|
||||
|
||||
|
||||
private List<Yapi> findYapiList(String conds) {
|
||||
String sql = "select distinct m.id url,m.pos,m.code from sys_api_main m " +
|
||||
"inner join sys_api_role_api rm on rm.mid=m.id " +
|
||||
"inner join sys_api_role_org ru on ru.rid=rm.rid " +
|
||||
"where m.avtag=1 and ru.oid in (" + conds + ") and code<>0";
|
||||
return jdbcDao.getTp().query(sql, new BeanPropertyRowMapper<>(Yapi.class));
|
||||
}
|
||||
"where m.avtag=1 and ru.oid in (" + zuser.getConds() + ") and code<>0";
|
||||
List<Yapi> apiList = jdbcDao.getTp().query(sql, new BeanPropertyRowMapper<>(Yapi.class));
|
||||
|
||||
|
||||
private List<String> findBtnList(Zuser zuser) {
|
||||
List<String> btnList = new ArrayList<>();
|
||||
List<Yapi> apiList = findYapiList(zuser.getConds());
|
||||
int posSum = SysApiCache.AUTHPOS + 1;
|
||||
int posSum = AuthzApiData.AUTHPOS + 1;
|
||||
long[] permArr = new long[posSum];
|
||||
for (Yapi api : apiList) {
|
||||
for (int i = 0; i < posSum; i++) {
|
||||
@@ -491,8 +174,8 @@ public class AuthcService {
|
||||
return btnList;
|
||||
}
|
||||
|
||||
|
||||
private void updateUser(Zuser zuser, List<Zmenu> menuList, List<String> btnList, List<Zportal> portalList) {
|
||||
//缓存用户门户、菜单、按钮到缓存表
|
||||
private void updateUser(Zuser zuser, List<Zportal> portalList, List<Zmenu> menuList, List<String> btnList) {
|
||||
|
||||
String menus = JSON.toJSONString(menuList);
|
||||
String portals = JSON.toJSONString(portalList);
|
||||
@@ -517,22 +200,17 @@ public class AuthcService {
|
||||
}
|
||||
String retagSql = "update sys_org_user set retag=1 where id=?";
|
||||
jdbcDao.update(retagSql, zuser.getId());
|
||||
|
||||
}
|
||||
|
||||
@Autowired
|
||||
private AuthcOrgHandler orgHandler;
|
||||
|
||||
@Transactional(readOnly = true)
|
||||
public Zuser getUser(String username) {
|
||||
Map<String, Object> map = jdbcDao.getTp().queryForMap("select u.id,u.name from sys_org_user u where u.usnam=? and u.avtag=1", username);
|
||||
Zuser user = new Zuser();
|
||||
user.setId((String) map.get("id"));
|
||||
user.setName((String) map.get("name"));
|
||||
return user;
|
||||
}
|
||||
|
||||
@Autowired
|
||||
private AuthcPortalHandler portalHandler;
|
||||
|
||||
@Autowired
|
||||
private JdbcDao jdbcDao;
|
||||
|
||||
|
||||
// @Autowired
|
||||
// private LdapHandler ldapHandler;
|
||||
}
|
||||
|
||||
@@ -0,0 +1,24 @@
|
||||
package vboot.core.security.authz;
|
||||
|
||||
import vboot.core.security.pojo.Yapi;
|
||||
|
||||
import java.util.ArrayList;
|
||||
import java.util.List;
|
||||
|
||||
//所有需要认证API(URL)的内存快照,根据请求method分类,用于快速找到请求URL的权限码
|
||||
public class AuthzApiData {
|
||||
|
||||
public static List<Yapi> GET1_APIS = new ArrayList<>();
|
||||
|
||||
public static List<Yapi> GET2_APIS = new ArrayList<>();
|
||||
|
||||
public static List<Yapi> POST_APIS = new ArrayList<>();
|
||||
|
||||
public static List<Yapi> PUT_APIS = new ArrayList<>();
|
||||
|
||||
public static List<Yapi> DELETE_APIS = new ArrayList<>();
|
||||
|
||||
public static List<Yapi> PATCH_APIS = new ArrayList<>();
|
||||
|
||||
public static int AUTHPOS = 0;
|
||||
}
|
||||
@@ -15,6 +15,7 @@ import java.util.HashMap;
|
||||
import java.util.Map;
|
||||
import java.util.Optional;
|
||||
|
||||
//授权拒绝时候的处理
|
||||
@Component
|
||||
public class AuthzDeniedHandler implements AccessDeniedHandler {
|
||||
|
||||
|
||||
@@ -15,6 +15,7 @@ import javax.servlet.http.HttpServletRequest;
|
||||
import javax.servlet.http.HttpServletResponse;
|
||||
import java.io.IOException;
|
||||
|
||||
//授权过滤器
|
||||
@Slf4j
|
||||
public class AuthzFilter extends OncePerRequestFilter {
|
||||
|
||||
|
||||
@@ -1,13 +1,12 @@
|
||||
package vboot.core.security.authz;
|
||||
|
||||
import org.springframework.beans.factory.annotation.Autowired;
|
||||
import vboot.core.module.sys.api.main.SysApiMainHand;
|
||||
import vboot.core.security.pojo.Zuser;
|
||||
import org.springframework.security.core.Authentication;
|
||||
import org.springframework.stereotype.Component;
|
||||
|
||||
import javax.servlet.http.HttpServletRequest;
|
||||
|
||||
//权限校验处理器
|
||||
@Component
|
||||
public class AuthzHandler {
|
||||
|
||||
@@ -24,11 +23,55 @@ public class AuthzHandler {
|
||||
if("/getMenuList".equals(uri)||"/getUserInfo".equals(uri)){
|
||||
return true;
|
||||
}
|
||||
return apiHand.hasPerm(zuser, method, uri);
|
||||
|
||||
return checkPerm(zuser, method, uri);
|
||||
}
|
||||
|
||||
@Autowired
|
||||
private SysApiMainHand apiHand;
|
||||
private boolean checkPerm(Zuser zuser, String method,String url){
|
||||
if(zuser.isAdmin()){
|
||||
return true;
|
||||
}
|
||||
boolean flag=false;
|
||||
//根据method分类快速定位到请求url的权限码,再通过二进制&计算快速校验用户是否有权限
|
||||
if("GET".equals(method)){
|
||||
for (int i = 0; i < AuthzApiData.GET1_APIS.size(); i++) {
|
||||
if(AuthzApiData.GET1_APIS.get(i).getUrl().equals(url)){
|
||||
flag = zuser.hasPerm(AuthzApiData.GET1_APIS.get(i).getPos(), AuthzApiData.GET1_APIS.get(i).getCode());
|
||||
break;
|
||||
}
|
||||
}
|
||||
if(!flag){
|
||||
String frontUrl=url.substring(0,url.lastIndexOf("/"));
|
||||
for (int i = 0; i < AuthzApiData.GET2_APIS.size(); i++) {
|
||||
if(AuthzApiData.GET2_APIS.get(i).getUrl().equals(frontUrl)){
|
||||
flag = zuser.hasPerm(AuthzApiData.GET2_APIS.get(i).getPos(), AuthzApiData.GET2_APIS.get(i).getCode());
|
||||
break;
|
||||
}
|
||||
}
|
||||
}
|
||||
}else if("POST".equals(method)){
|
||||
for (int i = 0; i < AuthzApiData.POST_APIS.size(); i++) {
|
||||
if(AuthzApiData.POST_APIS.get(i).getUrl().equals(url)){
|
||||
flag = zuser.hasPerm(AuthzApiData.POST_APIS.get(i).getPos(), AuthzApiData.POST_APIS.get(i).getCode());
|
||||
break;
|
||||
}
|
||||
}
|
||||
}else if("PUT".equals(method)){
|
||||
for (int i = 0; i < AuthzApiData.PUT_APIS.size(); i++) {
|
||||
if(AuthzApiData.PUT_APIS.get(i).getUrl().equals(url)){
|
||||
flag = zuser.hasPerm(AuthzApiData.PUT_APIS.get(i).getPos(), AuthzApiData.PUT_APIS.get(i).getCode());
|
||||
break;
|
||||
}
|
||||
}
|
||||
}else if("DELETE".equals(method)){
|
||||
String frontUrl=url.substring(0,url.lastIndexOf("/"));
|
||||
for (int i = 0; i < AuthzApiData.DELETE_APIS.size(); i++) {
|
||||
if(AuthzApiData.DELETE_APIS.get(i).getUrl().equals(frontUrl)){
|
||||
flag = zuser.hasPerm(AuthzApiData.DELETE_APIS.get(i).getPos(), AuthzApiData.DELETE_APIS.get(i).getCode());
|
||||
break;
|
||||
}
|
||||
}
|
||||
}
|
||||
return flag;
|
||||
}
|
||||
|
||||
}
|
||||
|
||||
@@ -7,15 +7,16 @@ import org.springframework.security.config.annotation.web.builders.HttpSecurity;
|
||||
import org.springframework.security.web.DefaultSecurityFilterChain;
|
||||
import org.springframework.security.web.authentication.UsernamePasswordAuthenticationFilter;
|
||||
|
||||
//授权过滤器适配器
|
||||
@RequiredArgsConstructor
|
||||
public class JwtFilterAdapter extends SecurityConfigurerAdapter<DefaultSecurityFilterChain, HttpSecurity> {
|
||||
|
||||
private final JwtHandler jwtHandler;
|
||||
|
||||
private final RedisHandler redisHandler;
|
||||
|
||||
|
||||
@Override
|
||||
public void configure(HttpSecurity http) throws Exception {
|
||||
public void configure(HttpSecurity http) {
|
||||
AuthzFilter jwtFilter = new AuthzFilter(jwtHandler, redisHandler);
|
||||
http.addFilterBefore(jwtFilter, UsernamePasswordAuthenticationFilter.class);
|
||||
}
|
||||
|
||||
@@ -16,6 +16,7 @@ import javax.servlet.http.HttpServletRequest;
|
||||
import java.security.Key;
|
||||
import java.util.ArrayList;
|
||||
|
||||
//Jwt处理器
|
||||
@Component
|
||||
public class JwtHandler implements InitializingBean {
|
||||
|
||||
@@ -50,12 +51,8 @@ public class JwtHandler implements InitializingBean {
|
||||
}
|
||||
|
||||
public String createTokenByUuid(String uuid) {
|
||||
// System.out.println("uuidz:" + uuid);
|
||||
return jwtBuilder
|
||||
.setId(uuid)
|
||||
.claim("username", uuid)
|
||||
.setSubject(uuid)
|
||||
.compact();
|
||||
return jwtBuilder.setId(uuid).claim("username", uuid)
|
||||
.setSubject(uuid).compact();
|
||||
}
|
||||
|
||||
|
||||
|
||||
@@ -7,6 +7,7 @@ import lombok.NoArgsConstructor;
|
||||
import javax.validation.constraints.NotNull;
|
||||
import java.io.Serializable;
|
||||
|
||||
//用户名与密码VO,登录时用到
|
||||
@Data
|
||||
@NoArgsConstructor
|
||||
@AllArgsConstructor
|
||||
|
||||
@@ -2,6 +2,7 @@ package vboot.core.security.pojo;
|
||||
|
||||
import lombok.Data;
|
||||
|
||||
//数据库用户信息,登录时用到
|
||||
@Data
|
||||
public class UserDo {
|
||||
|
||||
|
||||
+4
-4
@@ -1,15 +1,15 @@
|
||||
package vboot.core.common.init;
|
||||
package vboot.core.security.pojo;
|
||||
|
||||
import lombok.Data;
|
||||
|
||||
import java.io.Serializable;
|
||||
|
||||
//api pojo:存储URL,权限位与权限码
|
||||
@Data
|
||||
public class Yapi implements Serializable
|
||||
{
|
||||
public class Yapi implements Serializable {
|
||||
private static final long serialVersionUID = 7712491509249951764L;
|
||||
|
||||
private int pos;
|
||||
private int pos;
|
||||
|
||||
private long code;
|
||||
|
||||
+2
-1
@@ -1,7 +1,8 @@
|
||||
package vboot.core.common.init;
|
||||
package vboot.core.security.pojo;
|
||||
|
||||
import lombok.Data;
|
||||
|
||||
//url扫描收集时是用到的pojo
|
||||
@Data
|
||||
public class Yurl {
|
||||
private String id ;
|
||||
@@ -7,6 +7,7 @@ import lombok.Data;
|
||||
import java.io.Serializable;
|
||||
import java.util.List;
|
||||
|
||||
//前台返回菜单
|
||||
@Data
|
||||
public class Zmenu implements Serializable {
|
||||
private static final long serialVersionUID = 1L;
|
||||
|
||||
@@ -4,6 +4,7 @@ import lombok.Data;
|
||||
|
||||
import java.io.Serializable;
|
||||
|
||||
//前台返回菜单meta信息
|
||||
@Data
|
||||
public class Zmeta implements Serializable {
|
||||
private static final long serialVersionUID = 1L;
|
||||
|
||||
@@ -2,6 +2,7 @@ package vboot.core.security.pojo;
|
||||
|
||||
import lombok.Data;
|
||||
|
||||
//前台返回门户
|
||||
@Data
|
||||
public class Zportal {
|
||||
private String id;
|
||||
|
||||
@@ -9,6 +9,7 @@ import java.io.Serializable;
|
||||
import java.util.Collection;
|
||||
import java.util.List;
|
||||
|
||||
//用户pojo,前台与后台都会用到,前台用于获取用户信息,后台存在redis里,用于获取用户信息及权限校验
|
||||
@Data
|
||||
public class Zuser implements UserDetails, Serializable {
|
||||
|
||||
@@ -18,7 +19,7 @@ public class Zuser implements UserDetails, Serializable {
|
||||
|
||||
private String name;//用户姓名
|
||||
|
||||
private Boolean watag;
|
||||
private Boolean watag;//前台通知是否查看过的标记
|
||||
|
||||
private String usnam;//用户名
|
||||
|
||||
@@ -60,7 +61,7 @@ public class Zuser implements UserDetails, Serializable {
|
||||
isAdmin = admin;
|
||||
}
|
||||
|
||||
|
||||
//权限校验
|
||||
public boolean hasPerm(int pos, long code) {
|
||||
if (isAdmin()) {
|
||||
return true;
|
||||
|
||||
@@ -8,63 +8,129 @@ import java.util.List;
|
||||
|
||||
public class XjsonUtil {
|
||||
|
||||
|
||||
//使用递归方法建树
|
||||
public static List<Ztree> buildByRecursive(List<Ztree> treeNodes) {
|
||||
List<Ztree> trees = new ArrayList<>();
|
||||
for (Ztree treeNode : treeNodes) {
|
||||
if (treeNode.getPid()==null) {
|
||||
trees.add(findChildrenByTier(treeNode,treeNodes));
|
||||
public static List<Ztree> buildTreeByRecursive(List<Ztree> nodes) {
|
||||
List<Ztree> list = new ArrayList<>();
|
||||
for (Ztree node : nodes) {
|
||||
if (node.getPid() == null) {
|
||||
list.add(findTreeChildrenByTier(node, nodes));
|
||||
} else {
|
||||
boolean flag = false;
|
||||
for (Ztree node2 : nodes) {
|
||||
if (node.getPid().equals(node2.getId())) {
|
||||
flag = true;
|
||||
break;
|
||||
}
|
||||
}
|
||||
if (!flag) {
|
||||
list.add(findTreeChildrenByTier(node, nodes));
|
||||
}
|
||||
}
|
||||
}
|
||||
return trees;
|
||||
return list;
|
||||
}
|
||||
|
||||
|
||||
|
||||
|
||||
//递归查找子节点
|
||||
public static Ztree findChildrenByTier(Ztree treeNode, List<Ztree> treeNodes) {
|
||||
// treeNode.setChildren(new ArrayList<>());
|
||||
for (Ztree it : treeNodes) {
|
||||
if(treeNode.getId().equals(it.getPid())) {
|
||||
if (treeNode.getChildren() == null) {
|
||||
treeNode.setChildren(new ArrayList<>());
|
||||
private static Ztree findTreeChildrenByTier(Ztree node, List<Ztree> nodes) {
|
||||
for (Ztree item : nodes) {
|
||||
if (node.getId().equals(item.getPid())) {
|
||||
if (node.getChildren() == null) {
|
||||
node.setChildren(new ArrayList<>());
|
||||
}
|
||||
treeNode.getChildren().add(findChildrenByTier(it,treeNodes));
|
||||
node.getChildren().add(findTreeChildrenByTier(item, nodes));
|
||||
}
|
||||
}
|
||||
return treeNode;
|
||||
return node;
|
||||
}
|
||||
|
||||
|
||||
//
|
||||
public static List<Ztree> inpToTree(List<Zinp> inpList) {
|
||||
List<Ztree> trees = new ArrayList<>();
|
||||
for (Zinp zinp : inpList) {
|
||||
if (zinp.getPid()==null) {
|
||||
trees.add(findChildrenByTree(zinp,inpList));
|
||||
}
|
||||
}
|
||||
return trees;
|
||||
}
|
||||
|
||||
|
||||
public static Ztree findChildrenByTree(Zinp zinp, List<Zinp> zinpList) {
|
||||
// treeNode.setChildren(new ArrayList<>());
|
||||
Ztree ztree =new Ztree();
|
||||
ztree.setId(zinp.getId());
|
||||
ztree.setName(zinp.getName());
|
||||
for (Zinp it : zinpList) {
|
||||
if(zinp.getId().equals(it.getPid())) {
|
||||
if (ztree.getChildren() == null) {
|
||||
ztree.setChildren(new ArrayList<>());
|
||||
// //使用递归方法建树
|
||||
public static List<Zinp> buildInpByRecursive(List<Zinp> nodes) {
|
||||
List<Zinp> list = new ArrayList<>();
|
||||
for (Zinp node : nodes) {
|
||||
if (node.getPid() == null) {
|
||||
list.add(findInpChildrenByTier(node, nodes));
|
||||
} else {
|
||||
boolean flag = false;
|
||||
for (Zinp node2 : nodes) {
|
||||
if (node.getPid().equals(node2.getId())) {
|
||||
flag = true;
|
||||
break;
|
||||
}
|
||||
}
|
||||
if (!flag) {
|
||||
list.add(findInpChildrenByTier(node, nodes));
|
||||
}
|
||||
ztree.getChildren().add(findChildrenByTree(it,zinpList));
|
||||
}
|
||||
}
|
||||
return ztree;
|
||||
return list;
|
||||
}
|
||||
//
|
||||
//
|
||||
// //递归查找子节点
|
||||
private static Zinp findInpChildrenByTier(Zinp node, List<Zinp> nodes) {
|
||||
for (Zinp item : nodes) {
|
||||
if (node.getId().equals(item.getPid())) {
|
||||
if (node.getChildren() == null) {
|
||||
node.setChildren(new ArrayList<>());
|
||||
}
|
||||
node.getChildren().add(findInpChildrenByTier(item, nodes));
|
||||
}
|
||||
}
|
||||
return node;
|
||||
}
|
||||
|
||||
|
||||
// //使用递归方法建树
|
||||
// public static List<Ztree> buildByRecursive(List<Ztree> treeNodes) {
|
||||
// List<Ztree> trees = new ArrayList<>();
|
||||
// for (Ztree treeNode : treeNodes) {
|
||||
// if (treeNode.getPid()==null) {
|
||||
// trees.add(findChildrenByTier(treeNode,treeNodes));
|
||||
// }
|
||||
// }
|
||||
// return trees;
|
||||
// }
|
||||
//
|
||||
// //递归查找子节点
|
||||
// public static Ztree findChildrenByTier(Ztree treeNode, List<Ztree> treeNodes) {
|
||||
//// treeNode.setChildren(new ArrayList<>());
|
||||
// for (Ztree it : treeNodes) {
|
||||
// if(treeNode.getId().equals(it.getPid())) {
|
||||
// if (treeNode.getChildren() == null) {
|
||||
// treeNode.setChildren(new ArrayList<>());
|
||||
// }
|
||||
// treeNode.getChildren().add(findChildrenByTier(it,treeNodes));
|
||||
// }
|
||||
// }
|
||||
// return treeNode;
|
||||
// }
|
||||
|
||||
// public static List<Ztree> inpToTree(List<Zinp> inpList) {
|
||||
// List<Ztree> trees = new ArrayList<>();
|
||||
// for (Zinp zinp : inpList) {
|
||||
// if (zinp.getPid()==null) {
|
||||
// trees.add(findChildrenByTree(zinp,inpList));
|
||||
// }
|
||||
// }
|
||||
// return trees;
|
||||
// }
|
||||
//
|
||||
// private static Ztree findChildrenByTree(Zinp zinp, List<Zinp> zinpList) {
|
||||
//// treeNode.setChildren(new ArrayList<>());
|
||||
// Ztree ztree =new Ztree();
|
||||
// ztree.setId(zinp.getId());
|
||||
// ztree.setName(zinp.getName());
|
||||
// for (Zinp it : zinpList) {
|
||||
// if(zinp.getId().equals(it.getPid())) {
|
||||
// if (ztree.getChildren() == null) {
|
||||
// ztree.setChildren(new ArrayList<>());
|
||||
// }
|
||||
// ztree.getChildren().add(findChildrenByTree(it,zinpList));
|
||||
// }
|
||||
// }
|
||||
// return ztree;
|
||||
// }
|
||||
|
||||
|
||||
}
|
||||
|
||||
@@ -11,7 +11,5 @@ import javax.persistence.Entity;
|
||||
@Setter
|
||||
public class OaDocMain extends BaseMainEntity {
|
||||
|
||||
private String notes;
|
||||
|
||||
|
||||
}
|
||||
@@ -21,8 +21,6 @@ public class OaFlowMain extends BaseMainEntity {
|
||||
@Column(length = 32)
|
||||
private String protd;//全局流程模板ID
|
||||
|
||||
private String notes;
|
||||
|
||||
@Lob
|
||||
private String zform;
|
||||
|
||||
|
||||
@@ -14,7 +14,6 @@ public class OaFlowTemp extends BaseMainEntity {
|
||||
|
||||
private Integer ornum;
|
||||
|
||||
private String notes;
|
||||
|
||||
private String protd;//全局流程模板ID
|
||||
|
||||
|
||||
@@ -11,6 +11,4 @@ import javax.persistence.*;
|
||||
@Setter
|
||||
public class OaTestOne extends BaseMainEntity {
|
||||
|
||||
private String notes;//备注
|
||||
|
||||
}
|
||||
@@ -11,8 +11,5 @@ import javax.persistence.Entity;
|
||||
@Setter
|
||||
public class OaTestTwo extends BaseMainEntity {
|
||||
|
||||
//备注
|
||||
private String notes;
|
||||
|
||||
|
||||
}
|
||||
Reference in New Issue
Block a user