From 2fecc6273b38776b778debca614d3381c50950db Mon Sep 17 00:00:00 2001
From: 若依 <yzz_ivy@163.com>
Date: Tue, 15 Aug 2023 12:17:49 +0800
Subject: [PATCH] !340 修改个人信息:防止用户有目的性的修改其他属性 Merge pull request !340 from 码上秃Hello/N/A
---
ruoyi-modules/ruoyi-system/src/main/java/com/ruoyi/system/controller/SysRoleController.java | 45 +++++++++++++++++++++++++++++++++------------
1 files changed, 33 insertions(+), 12 deletions(-)
diff --git a/ruoyi-modules/ruoyi-system/src/main/java/com/ruoyi/system/controller/SysRoleController.java b/ruoyi-modules/ruoyi-system/src/main/java/com/ruoyi/system/controller/SysRoleController.java
index 52023fb..440f5a1 100644
--- a/ruoyi-modules/ruoyi-system/src/main/java/com/ruoyi/system/controller/SysRoleController.java
+++ b/ruoyi-modules/ruoyi-system/src/main/java/com/ruoyi/system/controller/SysRoleController.java
@@ -12,7 +12,6 @@
import org.springframework.web.bind.annotation.RequestBody;
import org.springframework.web.bind.annotation.RequestMapping;
import org.springframework.web.bind.annotation.RestController;
-import com.ruoyi.common.core.constant.UserConstants;
import com.ruoyi.common.core.utils.poi.ExcelUtil;
import com.ruoyi.common.core.web.controller.BaseController;
import com.ruoyi.common.core.web.domain.AjaxResult;
@@ -21,9 +20,11 @@
import com.ruoyi.common.log.enums.BusinessType;
import com.ruoyi.common.security.annotation.RequiresPermissions;
import com.ruoyi.common.security.utils.SecurityUtils;
+import com.ruoyi.system.api.domain.SysDept;
import com.ruoyi.system.api.domain.SysRole;
import com.ruoyi.system.api.domain.SysUser;
import com.ruoyi.system.domain.SysUserRole;
+import com.ruoyi.system.service.ISysDeptService;
import com.ruoyi.system.service.ISysRoleService;
import com.ruoyi.system.service.ISysUserService;
@@ -41,6 +42,9 @@
@Autowired
private ISysUserService userService;
+
+ @Autowired
+ private ISysDeptService deptService;
@RequiresPermissions("system:role:list")
@GetMapping("/list")
@@ -69,7 +73,7 @@
public AjaxResult getInfo(@PathVariable Long roleId)
{
roleService.checkRoleDataScope(roleId);
- return AjaxResult.success(roleService.selectRoleById(roleId));
+ return success(roleService.selectRoleById(roleId));
}
/**
@@ -80,13 +84,13 @@
@PostMapping
public AjaxResult add(@Validated @RequestBody SysRole role)
{
- if (UserConstants.NOT_UNIQUE.equals(roleService.checkRoleNameUnique(role)))
+ if (!roleService.checkRoleNameUnique(role))
{
- return AjaxResult.error("新增角色'" + role.getRoleName() + "'失败,角色名称已存在");
+ return error("新增角色'" + role.getRoleName() + "'失败,角色名称已存在");
}
- else if (UserConstants.NOT_UNIQUE.equals(roleService.checkRoleKeyUnique(role)))
+ else if (!roleService.checkRoleKeyUnique(role))
{
- return AjaxResult.error("新增角色'" + role.getRoleName() + "'失败,角色权限已存在");
+ return error("新增角色'" + role.getRoleName() + "'失败,角色权限已存在");
}
role.setCreateBy(SecurityUtils.getUsername());
return toAjax(roleService.insertRole(role));
@@ -102,13 +106,14 @@
public AjaxResult edit(@Validated @RequestBody SysRole role)
{
roleService.checkRoleAllowed(role);
- if (UserConstants.NOT_UNIQUE.equals(roleService.checkRoleNameUnique(role)))
+ roleService.checkRoleDataScope(role.getRoleId());
+ if (!roleService.checkRoleNameUnique(role))
{
- return AjaxResult.error("修改角色'" + role.getRoleName() + "'失败,角色名称已存在");
+ return error("修改角色'" + role.getRoleName() + "'失败,角色名称已存在");
}
- else if (UserConstants.NOT_UNIQUE.equals(roleService.checkRoleKeyUnique(role)))
+ else if (!roleService.checkRoleKeyUnique(role))
{
- return AjaxResult.error("修改角色'" + role.getRoleName() + "'失败,角色权限已存在");
+ return error("修改角色'" + role.getRoleName() + "'失败,角色权限已存在");
}
role.setUpdateBy(SecurityUtils.getUsername());
return toAjax(roleService.updateRole(role));
@@ -123,6 +128,7 @@
public AjaxResult dataScope(@RequestBody SysRole role)
{
roleService.checkRoleAllowed(role);
+ roleService.checkRoleDataScope(role.getRoleId());
return toAjax(roleService.authDataScope(role));
}
@@ -135,6 +141,7 @@
public AjaxResult changeStatus(@RequestBody SysRole role)
{
roleService.checkRoleAllowed(role);
+ roleService.checkRoleDataScope(role.getRoleId());
role.setUpdateBy(SecurityUtils.getUsername());
return toAjax(roleService.updateRoleStatus(role));
}
@@ -157,7 +164,7 @@
@GetMapping("/optionselect")
public AjaxResult optionselect()
{
- return AjaxResult.success(roleService.selectRoleAll());
+ return success(roleService.selectRoleAll());
}
/**
* 查询已分配用户角色列表
@@ -213,6 +220,20 @@
@PutMapping("/authUser/selectAll")
public AjaxResult selectAuthUserAll(Long roleId, Long[] userIds)
{
+ roleService.checkRoleDataScope(roleId);
return toAjax(roleService.insertAuthUsers(roleId, userIds));
}
-}
\ No newline at end of file
+
+ /**
+ * 获取对应角色部门树列表
+ */
+ @RequiresPermissions("system:role:query")
+ @GetMapping(value = "/deptTree/{roleId}")
+ public AjaxResult deptTree(@PathVariable("roleId") Long roleId)
+ {
+ AjaxResult ajax = AjaxResult.success();
+ ajax.put("checkedKeys", deptService.selectDeptListByRoleId(roleId));
+ ajax.put("depts", deptService.selectDeptTreeList(new SysDept()));
+ return ajax;
+ }
+}
--
Gitblit v1.9.3