lzq 2025-12-11 17:59:05 +08:00
parent b4b2cefe75
commit b9858c758e
43 changed files with 683 additions and 157 deletions

View File

@ -28,6 +28,7 @@
<dependency>
<groupId>com.njzscloud</groupId>
<artifactId>njzscloud-common-redis</artifactId>
<scope>provided</scope>
</dependency>
</dependencies>

View File

@ -2,6 +2,7 @@ package com.njzscloud.common.security.config;
import cn.hutool.core.collection.CollUtil;
import cn.hutool.core.util.ArrayUtil;
import com.njzscloud.common.security.controller.PermissionController;
import com.njzscloud.common.security.handler.AccessDeniedExceptionHandler;
import com.njzscloud.common.security.handler.AuthExceptionHandler;
import com.njzscloud.common.security.handler.LogoutPostHandler;
@ -11,10 +12,12 @@ import com.njzscloud.common.security.module.password.PasswordAuthenticationProvi
import com.njzscloud.common.security.module.password.PasswordLoginPreparer;
import com.njzscloud.common.security.module.wechat.mini.WechatMiniAuthenticationProvider;
import com.njzscloud.common.security.module.wechat.mini.WechatMiniLoginPreparer;
import com.njzscloud.common.security.permission.DefaultPermissionManager;
import com.njzscloud.common.security.permission.DefaultPermissionLoader;
import com.njzscloud.common.security.permission.PermissionLoader;
import com.njzscloud.common.security.permission.PermissionManager;
import com.njzscloud.common.security.support.*;
import com.njzscloud.common.security.support.controller.VerificationCodeController;
import jakarta.servlet.http.HttpServletRequest;
import lombok.RequiredArgsConstructor;
import lombok.extern.slf4j.Slf4j;
import org.springframework.beans.factory.ObjectProvider;
@ -54,9 +57,19 @@ public class WebSecurityAutoConfiguration {
}
@Bean
@ConditionalOnMissingBean(PermissionManager.class)
public PermissionManager permissionManager() {
return new DefaultPermissionManager();
@ConditionalOnMissingBean(PermissionLoader.class)
public PermissionLoader permissionLoader() {
return new DefaultPermissionLoader();
}
@Bean
public PermissionController permissionController(PermissionManager permissionManager) {
return new PermissionController(permissionManager);
}
@Bean
public PermissionManager permissionManager(PermissionLoader permissionLoader) {
return new PermissionManager(permissionLoader);
}
@Bean
@ -135,7 +148,7 @@ public class WebSecurityAutoConfiguration {
List<LoginPreparer> loginPreparers = loginPreparerObjectProvider.orderedStream().collect(Collectors.toList());
List<AuthenticationProvider> authenticationProviders = abstractAuthenticationProviderObjectProvider.orderedStream().collect(Collectors.toList());
ProviderManager providerManager = new ProviderManager(authenticationProviders);
String[] authAllows = webSecurityProperties.getAuthAllows().toArray(new String[0]);
LogoutPostHandler logoutPostHandler = new LogoutPostHandler();
return http
@ -146,15 +159,17 @@ public class WebSecurityAutoConfiguration {
.securityContext(it -> it.securityContextRepository(new TokenSecurityContextRepository()))
.authorizeHttpRequests(it -> it
.requestMatchers(authAllows).permitAll()
.anyRequest()
.access((AuthorizationManager<RequestAuthorizationContext>) (authentication, object) -> {
// 获取当前请求路径
String requestPath = object.getRequest().getRequestURI();
HttpServletRequest request = object.getRequest();
// 获取当前认证用户
Authentication auth = authentication.get();
int vote = permissionManager.vote(auth, request);
return new AuthorizationDecision(true);
return new AuthorizationDecision(vote >= 0);
})
)
// .addFilter(securityInterceptor)
@ -181,7 +196,7 @@ public class WebSecurityAutoConfiguration {
if (CollUtil.isNotEmpty(authIgnore)) {
ignoring.requestMatchers(ArrayUtil.toArray(authIgnore, String.class));
}
ignoring.requestMatchers("/error");
// ignoring.requestMatchers("/error");
};
}
}

View File

@ -20,5 +20,9 @@ public class WebSecurityProperties {
* , Ant
*/
private Set<String> authIgnores = CollUtil.empty(Set.class);
/**
* 访
*/
private Set<String> authAllows = CollUtil.empty(Set.class);
}

View File

@ -1,9 +1,14 @@
package com.njzscloud.common.security.contant;
import cn.hutool.core.collection.CollUtil;
import com.njzscloud.common.core.ienum.DictInt;
import lombok.Getter;
import lombok.RequiredArgsConstructor;
import java.util.Arrays;
import java.util.List;
import java.util.Optional;
/**
* client_code
*
@ -11,21 +16,43 @@ import lombok.RequiredArgsConstructor;
@Getter
@RequiredArgsConstructor
public enum ClientCode implements DictInt {
PC(0, "电脑端"),
WX_MINI_APP(1, "微信小程序"),
PC(1, "电脑端"),
WX_MINI_APP(2, "微信小程序"),
;
private final Integer val;
private final String txt;
public static int getClientCode(List<Integer> clients) {
if (CollUtil.isEmpty(clients)) return 0;
var clientCode = 0;
for (var client : clients) {
clientCode |= client;
}
return clientCode;
}
public static List<ClientCode> getClients(int clientCode) {
return Arrays.stream(ClientCode.class.getEnumConstants()).filter(it -> it.hasClient(clientCode)).toList();
}
public static boolean valid(int clientCode) {
Optional<Integer> max = Arrays.stream(ClientCode.class.getEnumConstants())
.map(ClientCode::getVal)
.reduce((a, b) -> a | b);
return max.orElse(0) >= clientCode;
}
public static Optional<ClientCode> getClient(int clientCode) {
return Arrays.stream(ClientCode.class.getEnumConstants()).filter(it -> it.hasClient(clientCode)).findFirst();
}
/**
*
*/
public boolean hasPermission(int clientCode) {
var mask = 1 << this.val;
return (clientCode & mask) == 0;
public boolean hasClient(int clientCode) {
return (this.val & clientCode) != 0;
}
}

View File

@ -13,6 +13,7 @@ public final class Constants {
public static final String ROLE_AUTHENTICATED = "ROLE_AUTHENTICATED";
public static final String ROLE_ANONYMOUS = "ROLE_ANONYMOUS";
public static final String ROLE_ADMIN = "ROLE_ADMIN";
public static final String ROLE_NONE = "ROLE_NONE";
// Redis 订阅频道 权限更新
public static final String REDIS_TOPIC_PERMISSION_UPDATE = "permission_update";

View File

@ -0,0 +1,23 @@
package com.njzscloud.common.security.controller;
import com.njzscloud.common.core.utils.R;
import com.njzscloud.common.security.permission.PermissionManager;
import lombok.RequiredArgsConstructor;
import lombok.extern.slf4j.Slf4j;
import org.springframework.web.bind.annotation.GetMapping;
import org.springframework.web.bind.annotation.RequestMapping;
import org.springframework.web.bind.annotation.RestController;
@Slf4j
@RestController
@RequestMapping("/permission")
@RequiredArgsConstructor
public class PermissionController {
private final PermissionManager permissionManager;
@GetMapping("/refresh_cache")
public R<?> refresh() {
permissionManager.refresh();
return R.success();
}
}

View File

@ -0,0 +1,14 @@
package com.njzscloud.common.security.permission;
import java.util.List;
/**
* <br/>
* 访
*/
public class DefaultPermissionLoader implements PermissionLoader {
@Override
public List<RolePermission> load() {
return null;
}
}

View File

@ -1,24 +0,0 @@
package com.njzscloud.common.security.permission;
import com.njzscloud.common.security.contant.EndpointAccessModel;
import java.util.Collections;
import java.util.List;
/**
* <br/>
* 访
*/
public class DefaultPermissionManager extends PermissionManager {
private final List<RolePermission> DEFAULT_ROLE_PERMISSIONS = Collections.singletonList(
new RolePermission()
.setEndpoint("/**")
.setAccessModel(EndpointAccessModel.LOGINED)
);
@Override
protected List<RolePermission> load() {
return DEFAULT_ROLE_PERMISSIONS;
}
}

View File

@ -0,0 +1,7 @@
package com.njzscloud.common.security.permission;
import java.util.List;
public interface PermissionLoader {
List<RolePermission> load();
}

View File

@ -1,14 +1,19 @@
package com.njzscloud.common.security.permission;
import cn.hutool.core.collection.CollUtil;
import cn.hutool.core.lang.Assert;
import cn.hutool.core.map.MapUtil;
import cn.hutool.core.util.StrUtil;
import com.njzscloud.common.security.contant.Constants;
import com.njzscloud.common.security.contant.EndpointAccessModel;
import com.njzscloud.common.security.ex.ForbiddenAccessException;
import com.njzscloud.common.security.ex.MissingPermissionException;
import jakarta.servlet.http.HttpServletRequest;
import lombok.RequiredArgsConstructor;
import lombok.extern.slf4j.Slf4j;
import org.springframework.http.HttpMethod;
import org.springframework.security.core.Authentication;
import org.springframework.security.core.GrantedAuthority;
import org.springframework.security.web.servlet.util.matcher.PathPatternRequestMatcher;
import java.util.*;
@ -18,7 +23,9 @@ import java.util.concurrent.locks.ReentrantLock;
*
*/
@Slf4j
public abstract class PermissionManager {
@RequiredArgsConstructor
public class PermissionManager {
private static final int ACCESS_GRANTED = 1;
private static final ReentrantLock PERMISSION_CACHE_LOCK = new ReentrantLock();
/**
@ -27,6 +34,27 @@ public abstract class PermissionManager {
private Map<PathPatternRequestMatcher, Collection<String>> PERMISSION_CACHE;
private Set<PathPatternRequestMatcher> FORBIDDEN_CACHE;
private static final int ACCESS_ABSTAIN = 0;
private static final int ACCESS_DENIED = -1;
private final PermissionLoader permissionLoader;
public int vote(Authentication authentication, HttpServletRequest request) {
Collection<String> attributes = extractAuthorities(request);
if (authentication == null) {
return ACCESS_DENIED;
}
int result = ACCESS_ABSTAIN;
Collection<? extends GrantedAuthority> authorities = authentication.getAuthorities();
for (String attribute : attributes) {
result = ACCESS_DENIED;
for (GrantedAuthority authority : authorities) {
if (attribute.equals(authority.getAuthority())) {
return ACCESS_GRANTED;
}
}
}
return result;
}
/**
*
@ -68,9 +96,10 @@ public abstract class PermissionManager {
private void load0() {
// if (log.isDebugEnabled()) log.debug("开始加载权限");
List<RolePermission> rolePermissions = load();
List<RolePermission> rolePermissions = permissionLoader.load();
if (rolePermissions == null) rolePermissions = new ArrayList<>();
if (rolePermissions == null) rolePermissions = Collections.emptyList();
rolePermissions.add(RolePermission.DEFAULT);
Map<PathPatternRequestMatcher, Collection<String>> permissionMap = new LinkedHashMap<>();
@ -80,7 +109,7 @@ public abstract class PermissionManager {
String endpoint = rolePermission.getEndpoint();
String method = rolePermission.getMethod();
EndpointAccessModel accessModel = rolePermission.getAccessModel();
HttpMethod httpMethod = HttpMethod.valueOf(method);
HttpMethod httpMethod = method == null ? null : HttpMethod.valueOf(method);
PathPatternRequestMatcher pathRequestMatcher = PathPatternRequestMatcher.withDefaults().matcher(httpMethod, endpoint);
if (accessModel == EndpointAccessModel.FORBIDDEN) {
forbiddenSet.add(pathRequestMatcher);
@ -97,6 +126,7 @@ public abstract class PermissionManager {
} else if (accessModel == EndpointAccessModel.AUTHENTICATED) {
String role = rolePermission.getRole();
if (StrUtil.isNotBlank(role)) configAttributes.add(role);
else configAttributes.add(Constants.ROLE_NONE);
}
}
@ -106,13 +136,6 @@ public abstract class PermissionManager {
// if (log.isDebugEnabled()) log.debug("本地权限缓存已加载:\n{}", Jackson.toJsonStr(this.getAllRelation()));
}
/**
*
*
* @return List&lt;RolePermission&gt;
*/
abstract protected List<RolePermission> load();
/**
*
*
@ -138,6 +161,16 @@ public abstract class PermissionManager {
return CollUtil.empty(Set.class);
}
public Collection<String> getAttributes(HttpServletRequest request) {
Collection<String> permission = this.extractAuthorities(request);
String requestURI = request.getRequestURI();
String method = request.getMethod();
String endpoint = method.toUpperCase() + " " + requestURI;
Assert.notEmpty(permission, () -> new MissingPermissionException(StrUtil.format("请求: 【{}】 未指定权限", endpoint)));
return permission;
}
/**
*
*

View File

@ -1,43 +0,0 @@
package com.njzscloud.common.security.permission;
import cn.hutool.core.lang.Assert;
import cn.hutool.core.util.StrUtil;
import com.njzscloud.common.security.ex.MissingPermissionException;
import jakarta.servlet.http.HttpServletRequest;
import lombok.RequiredArgsConstructor;
import lombok.extern.slf4j.Slf4j;
import org.springframework.security.web.FilterInvocation;
import java.util.Collection;
@Slf4j
@RequiredArgsConstructor
public class PermissionSecurityMetaDataSource {
// org.springframework.security.config.annotation.web.configurers.UrlAuthorizationConfigurer
// org.springframework.security.access.vote.RoleVoter PermissionAuthorizationConfigurer
private final PermissionManager permissionManager;
// private final boolean rejectPublicInvocations;
public Collection<String> getAttributes(Object object) throws IllegalArgumentException {
HttpServletRequest request = ((FilterInvocation) object).getRequest();
Collection<String> permission = permissionManager.extractAuthorities(request);
String requestURI = request.getRequestURI();
String method = request.getMethod();
String endpoint = method.toUpperCase() + " " + requestURI;
Assert.notEmpty(permission, () -> new MissingPermissionException(StrUtil.format("请求: 【{}】 未指定权限", endpoint)));
// if (log.isDebugEnabled()) log.debug("允许访问接口:【{}】的角色:【{}】", endpoint, permission);
return permission;
}
public Collection<String> getAllConfigAttributes() {
return permissionManager.getAll();
}
public boolean supports(Class<?> clazz) {
return FilterInvocation.class.isAssignableFrom(clazz);
}
}

View File

@ -23,23 +23,13 @@ public class PermissionVoter {
int result = ACCESS_ABSTAIN;
Collection<? extends GrantedAuthority> authorities = authentication.getAuthorities();
for (String attribute : attributes) {
if (this.supports(attribute)) {
result = ACCESS_DENIED;
for (GrantedAuthority authority : authorities) {
if (attribute.equals(authority.getAuthority())) {
return ACCESS_GRANTED;
}
result = ACCESS_DENIED;
for (GrantedAuthority authority : authorities) {
if (attribute.equals(authority.getAuthority())) {
return ACCESS_GRANTED;
}
}
}
return result;
}
public boolean supports(String attribute) {
return true;
}
public boolean supports(Class<?> clazz) {
return true;
}
}

View File

@ -12,6 +12,9 @@ import lombok.experimental.Accessors;
@Setter
@Accessors(chain = true)
public class RolePermission {
public static RolePermission DEFAULT = new RolePermission()
.setEndpoint("/**")
.setAccessModel(EndpointAccessModel.LOGINED);
/**
*

View File

@ -116,7 +116,8 @@ public abstract class AbstractAuthenticationProvider implements AuthenticationPr
Assert.isFalse(userDetail.getDisabled(), () -> new UserLoginException(ExceptionMsg.CLI_ERR_MSG, "用户已被禁用"));
ClientCode clientCode = loginForm.getClientCode();
Integer code = userDetail.getClientCode();
Assert.isTrue(clientCode.hasPermission(code), () -> new UserLoginException(ExceptionMsg.CLI_ERR_MSG, "当前用户无权使用:" + clientCode.getTxt()));
userDetail.setClient(clientCode.getVal());
Assert.isTrue(clientCode.hasClient(code), () -> new UserLoginException(ExceptionMsg.CLI_ERR_MSG, "当前用户无权使用:" + clientCode.getTxt()));
}
/**

View File

@ -23,7 +23,7 @@ public interface IAuthService {
return null;
}
default UserDetail my(Long userId) {
default UserDetail my(Long userId, Integer client) {
return null;
}
}

View File

@ -44,6 +44,7 @@ public class UserDetail implements CredentialsContainer, Principal {
private Long accountId;
private Long tenantId;
private Integer clientCode;
private Integer client;
private String tenantName;
/**
*

View File

@ -54,10 +54,15 @@
<groupId>com.njzscloud</groupId>
<artifactId>njzscloud-common-ws</artifactId>
</dependency>
<!-- <dependency>
<dependency>
<groupId>com.njzscloud</groupId>
<artifactId>njzscloud-common-cache</artifactId>
<version>0.0.1</version>
</dependency>
<dependency>
<groupId>com.njzscloud</groupId>
<artifactId>njzscloud-common-redis</artifactId>
</dependency> -->
</dependency>
<dependency>
<groupId>com.njzscloud</groupId>
<artifactId>njzscloud-common-security</artifactId>

View File

@ -7,6 +7,7 @@ import lombok.Setter;
import lombok.ToString;
import lombok.experimental.Accessors;
import java.time.LocalDate;
import java.time.LocalDateTime;
/**
@ -48,12 +49,12 @@ public class OrgEntity {
/**
*
*/
private LocalDateTime licenseStartTime;
private LocalDate licenseStartTime;
/**
*
*/
private LocalDateTime licenseEndTime;
private LocalDate licenseEndTime;
/**
*
@ -68,12 +69,12 @@ public class OrgEntity {
/**
*
*/
private LocalDateTime idcardStartTime;
private LocalDate idcardStartTime;
/**
*
*/
private LocalDateTime idcardEndTime;
private LocalDate idcardEndTime;
/**
*

View File

@ -1,5 +1,7 @@
package com.njzscloud.dispose.sys.auth.controller;
import cn.hutool.core.lang.Assert;
import com.njzscloud.common.core.ex.Exceptions;
import com.njzscloud.common.core.utils.R;
import com.njzscloud.common.security.support.UserDetail;
import com.njzscloud.common.security.util.SecurityUtil;
@ -25,8 +27,12 @@ public class AuthController {
*/
@GetMapping("/my")
public R<UserDetail> my() {
Long userId = SecurityUtil.currentUserId();
UserDetail userDetail = SecurityUtil.loginUser();
Long userId = userDetail.getUserId();
Integer client = userDetail.getClient();
return R.success(authService.my(userId));
Assert.notNull(client, () -> Exceptions.exception("客户端信息错误"));
return R.success(authService.my(userId, client));
}
}

View File

@ -2,6 +2,7 @@ package com.njzscloud.dispose.sys.auth.mapper;
import com.baomidou.mybatisplus.core.conditions.query.QueryWrapper;
import com.njzscloud.dispose.sys.auth.pojo.result.EndpointResource;
import com.njzscloud.dispose.sys.auth.pojo.result.IdentityInfo;
import com.njzscloud.dispose.sys.auth.pojo.result.MenuResource;
import com.njzscloud.dispose.sys.auth.pojo.result.MyResult;
import org.apache.ibatis.annotations.Mapper;
@ -17,7 +18,9 @@ public interface AuthMapper {
Set<String> selectRole(@Param("userId") Long userId);
List<MenuResource> selectUserMenu(@Param("userId") Long userId);
List<MenuResource> selectUserMenu(@Param("userId") Long userId, @Param("client") Integer client);
List<EndpointResource> selectUserEndpoint(@Param("userId") Long userId);
List<IdentityInfo> selectUserIdentity(@Param("userId") Long userId);
}

View File

@ -1,5 +1,6 @@
package com.njzscloud.dispose.sys.auth.pojo.result;
import com.njzscloud.common.security.contant.EndpointAccessModel;
import lombok.Getter;
import lombok.Setter;
import lombok.ToString;
@ -37,7 +38,7 @@ public class EndpointResource {
/**
* 访; endpoint_access_model
*/
private String accessModel;
private EndpointAccessModel accessModel;
/**
*

View File

@ -0,0 +1,165 @@
package com.njzscloud.dispose.sys.auth.pojo.result;
import com.njzscloud.dispose.cst.customer.constant.IdentityCategory;
import com.njzscloud.dispose.cst.customer.constant.SettlementWay;
import com.njzscloud.dispose.cst.org.constant.OrgCategory;
import lombok.Getter;
import lombok.Setter;
import lombok.ToString;
import lombok.experimental.Accessors;
import java.time.LocalDate;
@Getter
@Setter
@ToString
@Accessors(chain = true)
public class IdentityInfo {
/**
* PingTai-->ChanFei-->QingYun-->XiaoNa-->CaiGou-->
*/
private IdentityCategory identityCategory;
private Long customerId;
/**
* Idcst_org.id
*/
private Long orgId;
/**
*
*/
private String customerName;
/**
*
*/
private String phone;
/**
* YueJie-->YuE-->XianFu-->
*/
private SettlementWay settlementWay;
/**
* 0-->1-->
*/
private Boolean manager;
/**
* GeTiHu-->QiYe-->
*/
private OrgCategory orgCategory;
/**
*
*/
private String uscc;
/**
*
*/
private String orgName;
/**
*
*/
private String businessLicense;
/**
*
*/
private LocalDate licenseStartTime;
/**
*
*/
private LocalDate licenseEndTime;
/**
*
*/
private String legalRepresentative;
/**
*
*/
private String idcard;
/**
*
*/
private LocalDate idcardStartTime;
/**
*
*/
private LocalDate idcardEndTime;
/**
*
*/
private String idcardFront;
/**
*
*/
private String idcardBack;
/**
*
*/
private String province;
/**
*
*/
private String city;
/**
*
*/
private String area;
/**
*
*/
private String town;
/**
*
*/
private String provinceName;
/**
*
*/
private String cityName;
/**
*
*/
private String areaName;
/**
*
*/
private String townName;
/**
*
*/
private String address;
/**
*
*/
private Double lng;
/**
*
*/
private Double lat;
}

View File

@ -16,6 +16,7 @@ public class MyResult extends UserDetail {
private List<MenuResource> menus;
private List<EndpointResource> endpoints;
private List<IdentityInfo> identities;
private List<Map<String, Object>> setting;

View File

@ -1,14 +1,17 @@
package com.njzscloud.dispose.sys.auth.service;
import cn.hutool.core.bean.BeanUtil;
import cn.hutool.core.lang.Assert;
import cn.hutool.core.util.StrUtil;
import com.baomidou.mybatisplus.core.toolkit.Wrappers;
import com.njzscloud.common.core.ex.Exceptions;
import com.njzscloud.common.security.module.password.PasswordLoginForm;
import com.njzscloud.common.security.module.wechat.mini.WechatMiniLoginForm;
import com.njzscloud.common.security.support.IAuthService;
import com.njzscloud.common.security.support.UserDetail;
import com.njzscloud.dispose.sys.auth.mapper.AuthMapper;
import com.njzscloud.dispose.sys.auth.pojo.result.EndpointResource;
import com.njzscloud.dispose.sys.auth.pojo.result.IdentityInfo;
import com.njzscloud.dispose.sys.auth.pojo.result.MenuResource;
import com.njzscloud.dispose.sys.auth.pojo.result.MyResult;
import lombok.RequiredArgsConstructor;
@ -22,6 +25,9 @@ import java.util.Set;
import static com.njzscloud.common.security.contant.Constants.ROLE_ANONYMOUS;
import static com.njzscloud.common.security.contant.Constants.ROLE_AUTHENTICATED;
/**
*
*/
@Slf4j
@Service
@RequiredArgsConstructor
@ -53,14 +59,17 @@ public class AuthService implements IAuthService {
*
*/
@Override
public UserDetail my(Long userId) {
UserDetail userDetail = authMapper.selectUser(Wrappers.query().eq("a.id", userId).eq("a.deleted", 0));
List<MenuResource> menuResources = authMapper.selectUserMenu(userId);
public UserDetail my(Long userId, Integer client) {
UserDetail userDetail = authMapper.selectUser(Wrappers.query().eq("b.id", userId).eq("a.deleted", 0));
Assert.notNull(userDetail, () -> Exceptions.exception("未查询到用户信息"));
List<MenuResource> menuResources = authMapper.selectUserMenu(userId, client);
List<EndpointResource> endpointResources = authMapper.selectUserEndpoint(userId);
List<IdentityInfo> identityInfoList = authMapper.selectUserIdentity(userId);
Set<String> roles = authMapper.selectRole(userId);
roles.add(ROLE_AUTHENTICATED);
roles.add(ROLE_ANONYMOUS);
return BeanUtil.copyProperties(userDetail, MyResult.class)
.setIdentities(identityInfoList)
.setMenus(menuResources)
.setEndpoints(endpointResources)
.setRoles(roles)

View File

@ -4,6 +4,9 @@ import com.njzscloud.common.core.ienum.DictStr;
import lombok.Getter;
import lombok.RequiredArgsConstructor;
import java.util.Arrays;
import java.util.Optional;
/**
* request_method
* HTTP
@ -18,4 +21,9 @@ public enum RequestMethod implements DictStr {
private final String val;
private final String txt;
public static RequestMethod resolve(String name) {
Optional<RequestMethod> first = Arrays.stream(RequestMethod.class.getEnumConstants()).filter(it -> it.val.equals(name)).findFirst();
return first.orElse(null);
}
}

View File

@ -5,11 +5,16 @@ import com.njzscloud.dispose.sys.endpoint.pojo.entity.EndpointEntity;
import com.njzscloud.dispose.sys.endpoint.pojo.param.EndpointSearchParam;
import com.njzscloud.dispose.sys.endpoint.pojo.result.EndpointDetailResult;
import com.njzscloud.dispose.sys.endpoint.service.EndpointService;
import com.njzscloud.dispose.sys.resource.pojo.result.ControllerMappingResult;
import lombok.RequiredArgsConstructor;
import lombok.extern.slf4j.Slf4j;
import org.springframework.web.bind.annotation.*;
import org.springframework.web.method.HandlerMethod;
import org.springframework.web.servlet.mvc.condition.RequestMethodsRequestCondition;
import org.springframework.web.servlet.mvc.method.RequestMappingInfo;
import org.springframework.web.servlet.mvc.method.annotation.RequestMappingHandlerMapping;
import java.util.List;
import java.util.*;
/**
*
@ -21,6 +26,64 @@ import java.util.List;
public class EndpointController {
private final EndpointService endpointService;
private final RequestMappingHandlerMapping requestMappingHandlerMapping;
public List<ControllerMappingResult> scanAllControllerMappings() {
List<ControllerMappingResult> result = new ArrayList<>();
// 1. 获取所有RequestMappingInfo包含映射规则和对应的HandlerMethod
Map<RequestMappingInfo, HandlerMethod> handlerMethods = requestMappingHandlerMapping.getHandlerMethods();
// 2. 遍历解析每个映射规则
for (Map.Entry<RequestMappingInfo, HandlerMethod> entry : handlerMethods.entrySet()) {
RequestMappingInfo requestMappingInfo = entry.getKey();
HandlerMethod handlerMethod = entry.getValue();
// 封装DTO
ControllerMappingResult dto = new ControllerMappingResult();
// === 解析控制器类信息 ===
Class<?> controllerClass = handlerMethod.getBeanType();
dto.setControllerClassName(controllerClass.getCanonicalName());
// === 解析类级@RequestMapping路径 ===
RequestMapping classRequestMapping = controllerClass.getAnnotation(RequestMapping.class);
String classPath = "";
if (classRequestMapping != null && classRequestMapping.value().length > 0) {
classPath = classRequestMapping.value()[0]; // 取第一个路径(支持数组,通常只用一个)
// 处理路径格式:确保以/开头避免拼接错误如类路径是endpoint → 补为/endpoint
if (!classPath.startsWith("/")) {
classPath = "/" + classPath;
}
}
// === 解析方法级路径 ===
Set<String> methodPatterns = requestMappingInfo.getPatternValues();
// 方法路径通常只有一个,取第一个即可
String methodPath = methodPatterns.iterator().next();
// === 拼接完整URL ===
String fullUrl = classPath + methodPath;
// 处理重复的/(如类路径/endpoint + 方法路径/add → /endpoint/add类路径/endpoint/ + 方法路径/add → /endpoint/add
fullUrl = fullUrl.replaceAll("//+", "/");
dto.setFullUrl(fullUrl);
// === 解析请求方法GET/POST等 ===
RequestMethodsRequestCondition methodsCondition = requestMappingInfo.getMethodsCondition();
Set<RequestMethod> methods = methodsCondition.getMethods();
Optional<RequestMethod> first = methods.stream().findFirst();
Optional<String> s = first.map(Enum::name);
dto.setHttpMethods(s.orElse(""));
// === 解析方法名 ===
dto.setMethodName(handlerMethod.getMethod().getName());
result.add(dto);
}
return result;
}
/**
*
@ -65,4 +128,13 @@ public class EndpointController {
return R.success(endpointService.listAll(endpointSearchParam));
}
/**
*
*/
@GetMapping("/reload")
public R<?> reload() {
endpointService.saveAll(scanAllControllerMappings());
return R.success();
}
}

View File

@ -5,15 +5,21 @@ import cn.hutool.core.util.StrUtil;
import com.baomidou.mybatisplus.core.toolkit.Wrappers;
import com.baomidou.mybatisplus.extension.service.IService;
import com.baomidou.mybatisplus.extension.service.impl.ServiceImpl;
import com.njzscloud.common.core.utils.GroupUtil;
import com.njzscloud.common.security.contant.EndpointAccessModel;
import com.njzscloud.dispose.sys.endpoint.contant.RequestMethod;
import com.njzscloud.dispose.sys.endpoint.mapper.EndpointMapper;
import com.njzscloud.dispose.sys.endpoint.pojo.entity.EndpointEntity;
import com.njzscloud.dispose.sys.endpoint.pojo.param.EndpointSearchParam;
import com.njzscloud.dispose.sys.endpoint.pojo.result.EndpointDetailResult;
import com.njzscloud.dispose.sys.resource.pojo.result.ControllerMappingResult;
import lombok.extern.slf4j.Slf4j;
import org.springframework.stereotype.Service;
import org.springframework.transaction.annotation.Transactional;
import java.util.List;
import java.util.Map;
import java.util.Set;
import java.util.stream.Collectors;
/**
@ -64,4 +70,24 @@ public class EndpointService extends ServiceImpl<EndpointMapper, EndpointEntity>
.map(it -> BeanUtil.copyProperties(it, EndpointDetailResult.class))
.collect(Collectors.toList());
}
@Transactional(rollbackFor = Exception.class)
public void saveAll(List<ControllerMappingResult> controllerMappingResults) {
List<EndpointEntity> oldEndpoints = this.list();
Map<String, EndpointEntity> map = GroupUtil.k_o(oldEndpoints, it -> it.getRequestMethod() + it.getEndpointPath());
Set<String> endpointPaths = map.keySet();
List<EndpointEntity> list = controllerMappingResults
.stream()
.filter(it -> it.getControllerClassName().startsWith("com.njzscloud") && !endpointPaths.contains(it.getHttpMethods() + it.getFullUrl()))
.map(it -> new EndpointEntity()
.setEndpointPath(it.getFullUrl())
.setRoutingPath("")
.setMemo("")
.setAccessModel(EndpointAccessModel.LOGINED)
.setRequestMethod(RequestMethod.resolve(it.getHttpMethods())))
.toList();
this.saveBatch(list);
}
}

View File

@ -2,6 +2,7 @@ package com.njzscloud.dispose.sys.menu.pojo.entity;
import com.baomidou.mybatisplus.annotation.*;
import com.njzscloud.common.mp.support.handler.j.JsonTypeHandler;
import com.njzscloud.common.security.contant.ClientCode;
import com.njzscloud.dispose.sys.menu.contant.MenuCategory;
import lombok.Getter;
import lombok.Setter;
@ -26,6 +27,9 @@ public class MenuEntity {
private Long id;
private String sn;
private ClientCode clientCode;
/**
* Id; 1 0
*/

View File

@ -4,8 +4,10 @@ import cn.hutool.core.util.StrUtil;
import com.njzscloud.common.mvc.validator.Constrained;
import com.njzscloud.common.mvc.validator.Constraint;
import com.njzscloud.common.mvc.validator.ValidRule;
import com.njzscloud.common.security.contant.ClientCode;
import com.njzscloud.dispose.sys.menu.contant.MenuCategory;
import jakarta.validation.constraints.NotBlank;
import jakarta.validation.constraints.NotNull;
import lombok.Getter;
import lombok.Setter;
@ -16,6 +18,9 @@ import lombok.Setter;
@Setter
@Constraint
public class MenuAddParam implements Constrained {
@NotNull
private ClientCode clientCode;
/**
* Id; 1 0
*/

View File

@ -3,6 +3,7 @@ package com.njzscloud.dispose.sys.menu.pojo.param;
import com.njzscloud.common.mvc.validator.Constrained;
import com.njzscloud.common.mvc.validator.Constraint;
import com.njzscloud.common.mvc.validator.ValidRule;
import com.njzscloud.common.security.contant.ClientCode;
import lombok.Getter;
import lombok.Setter;
import lombok.experimental.Accessors;
@ -20,6 +21,7 @@ public class MenuModifyParam implements Constrained {
* Id
*/
private Long id;
private ClientCode clientCode;
/**
* Id; 1 0

View File

@ -16,6 +16,7 @@ public class MenuSearchParam {
private Long pid;
private Integer clientCode;
/**
*

View File

@ -1,5 +1,6 @@
package com.njzscloud.dispose.sys.menu.pojo.result;
import com.njzscloud.common.security.contant.ClientCode;
import com.njzscloud.dispose.sys.menu.contant.MenuCategory;
import lombok.EqualsAndHashCode;
import lombok.Getter;
@ -22,6 +23,8 @@ public class MenuDetailResult {
*/
private Long id;
private String sn;
private ClientCode clientCode;
/**
* Id; 1 0
*/

View File

@ -195,11 +195,13 @@ public class MenuService extends ServiceImpl<MenuMapper, MenuEntity> implements
Long pid = menuSearchParam.getPid();
String title = menuSearchParam.getTitle();
String routeName = menuSearchParam.getRouteName();
return this.list(Wrappers.<MenuEntity>lambdaQuery()
.eq(pid != null, MenuEntity::getPid, pid)
.like(StrUtil.isNotBlank(title), MenuEntity::getTitle, title)
.like(StrUtil.isNotBlank(routeName), MenuEntity::getRouteName, routeName)
.orderByAsc(Arrays.asList(MenuEntity::getTier, MenuEntity::getSort, MenuEntity::getId)))
Integer clientCode = menuSearchParam.getClientCode();
return this.list(Wrappers.<MenuEntity>query()
.eq(pid != null, "pid", pid)
.and(clientCode != null && clientCode >= 0, it -> it.ne("clientCode & " + clientCode, 0))
.like(StrUtil.isNotBlank(title), "title", title)
.like(StrUtil.isNotBlank(routeName), "route_name", routeName)
.orderByAsc(Arrays.asList("tier", "sort", "id")))
.stream()
.map(it -> BeanUtil.copyProperties(it, MenuDetailResult.class))
.collect(Collectors.toList());

View File

@ -3,6 +3,7 @@ package com.njzscloud.dispose.sys.resource.mapper;
import com.baomidou.mybatisplus.core.conditions.query.QueryWrapper;
import com.baomidou.mybatisplus.core.mapper.BaseMapper;
import com.baomidou.mybatisplus.core.toolkit.Constants;
import com.njzscloud.common.security.permission.RolePermission;
import com.njzscloud.dispose.sys.resource.pojo.entity.ResourceEntity;
import org.apache.ibatis.annotations.Mapper;
import org.apache.ibatis.annotations.Param;
@ -17,4 +18,7 @@ public interface ResourceMapper extends BaseMapper<ResourceEntity> {
List<String> occupied(@Param(Constants.WRAPPER) QueryWrapper<Object> ew);
List<ResourceEntity> listRoleRes(@Param("roleId") String roleId);
List<RolePermission> loadPermission();
}

View File

@ -0,0 +1,29 @@
package com.njzscloud.dispose.sys.resource.pojo.result;
import lombok.Getter;
import lombok.Setter;
import lombok.ToString;
import lombok.experimental.Accessors;
@Getter
@Setter
@ToString
@Accessors(chain = true)
public class ControllerMappingResult {
/**
* com.xxx.controller.EndpointController
*/
private String controllerClassName;
/**
* add
*/
private String methodName;
/**
* /endpoint/add
*/
private String fullUrl;
/**
* GET/POST/PUT/DELETE
*/
private String httpMethods;
}

View File

@ -3,6 +3,8 @@ package com.njzscloud.dispose.sys.resource.service;
import com.baomidou.mybatisplus.core.toolkit.Wrappers;
import com.baomidou.mybatisplus.extension.service.IService;
import com.baomidou.mybatisplus.extension.service.impl.ServiceImpl;
import com.njzscloud.common.security.permission.PermissionLoader;
import com.njzscloud.common.security.permission.RolePermission;
import com.njzscloud.dispose.sys.resource.contant.ResourceOrigin;
import com.njzscloud.dispose.sys.resource.mapper.ResourceMapper;
import com.njzscloud.dispose.sys.resource.pojo.entity.ResourceEntity;
@ -19,8 +21,7 @@ import java.util.List;
@Slf4j
@Service
@RequiredArgsConstructor
public class ResourceService extends ServiceImpl<ResourceMapper, ResourceEntity> implements IService<ResourceEntity> {
public class ResourceService extends ServiceImpl<ResourceMapper, ResourceEntity> implements PermissionLoader, IService<ResourceEntity> {
/**
*
*/
@ -45,4 +46,9 @@ public class ResourceService extends ServiceImpl<ResourceMapper, ResourceEntity>
public List<ResourceEntity> listRoleRes(String roleId) {
return baseMapper.listRoleRes(roleId);
}
@Override
public List<RolePermission> load() {
return baseMapper.loadPermission();
}
}

View File

@ -17,7 +17,7 @@ import lombok.Setter;
import lombok.ToString;
import lombok.experimental.Accessors;
import java.time.LocalDateTime;
import java.time.LocalDate;
import java.util.List;
@Getter
@ -106,7 +106,7 @@ public class UserRegisterParam implements Constrained {
/**
* ; client_code
*/
private ClientCode clientCode;
private Integer clientCode;
@Override
public ValidRule[] rules() {
@ -115,9 +115,9 @@ public class UserRegisterParam implements Constrained {
|| (StrUtil.isNotBlank(phone) && StrUtil.isNotBlank(secret))
|| StrUtil.isNotBlank(wechatCode), "账号信息不能为空"),
ValidRule.of(() -> clientCode != null, "客户端信息不能为空"),
ValidRule.of(() -> clientCode > 0 && ClientCode.valid(clientCode), "客户端信息无效"),
};
}
}
@Getter
@ -194,12 +194,12 @@ public class UserRegisterParam implements Constrained {
/**
*
*/
private LocalDateTime licenseStartTime;
private LocalDate licenseStartTime;
/**
*
*/
private LocalDateTime licenseEndTime;
private LocalDate licenseEndTime;
/**
*
@ -214,12 +214,14 @@ public class UserRegisterParam implements Constrained {
/**
*
*/
private LocalDateTime idcardStartTime;
@NotNull(message = "法人身份证有效期不能为空")
private LocalDate idcardStartTime;
/**
*
*/
private LocalDateTime idcardEndTime;
@NotNull(message = "法人身份证有效期不能为空")
private LocalDate idcardEndTime;
/**
*

View File

@ -4,8 +4,9 @@ spring:
username: root
password: admin888999
security:
auth-ignores:
auth-allows:
- /oss/**
- /endpoint/reload
oss:
type: ali

View File

@ -1,4 +1,4 @@
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE mapper PUBLIC "-//mybatis.org//DTD Mapper 3.0//EN" "http://mybatis.org/dtd/mybatis-3-mapper.dtd">
<mapper namespace="com.njzscloud.dispose.cst.customer.pojo.entity.CustomerEntity">
<mapper namespace="com.njzscloud.dispose.cst.customer.mapper.CustomerMapper">
</mapper>

View File

@ -13,7 +13,6 @@
<select id="selectUser" resultMap="selectUserMap">
SELECT a.id account_id,
a.user_id,
a.user_id id,
a.secret,
b.nickname,
b.avatar,
@ -50,6 +49,7 @@
FROM sys_role a
INNER JOIN sys_user_role b ON b.role_id = a.id AND b.user_id = #{userId})
WHERE a.deleted = 0
AND a.client_code <![CDATA[ & ]]> ${client} != 0
</select>
<select id="selectUserEndpoint" resultType="com.njzscloud.dispose.sys.auth.pojo.result.EndpointResource">
@ -65,5 +65,41 @@
FROM sys_role a
INNER JOIN sys_user_role b ON b.role_id = a.id AND b.user_id = #{userId})
</select>
<select id="selectUserIdentity" resultType="com.njzscloud.dispose.sys.auth.pojo.result.IdentityInfo">
SELECT a.identity_category,
a.id customer_id,
a.org_id,
a.customer_name,
a.phone,
a.settlement_way,
a.manager,
b.org_category,
b.uscc,
b.org_name,
b.business_license,
b.license_start_time,
b.license_end_time,
b.legal_representative,
b.idcard,
b.idcard_start_time,
b.idcard_end_time,
b.idcard_front,
b.idcard_back,
b.province,
b.city,
b.area,
b.town,
b.province_name,
b.city_name,
b.area_name,
b.town_name,
b.address,
b.lng,
b.lat
FROM cst_customer a
LEFT JOIN cst_org b ON b.id = a.org_id AND b.deleted = 0
WHERE a.deleted = 0
AND a.user_id = #{userId}
</select>
</mapper>

View File

@ -21,4 +21,15 @@
INNER JOIN sys_role_resource b ON b.res_id = a.id
WHERE b.role_id = ${roleId}
</select>
<select id="loadPermission" resultType="com.njzscloud.common.security.permission.RolePermission">
SELECT b.request_method,
b.endpoint_path endpoint,
b.access_model,
d.role_code `role`
FROM sys_resource a
INNER JOIN sys_endpoint b ON b.id = a.data_id
LEFT JOIN sys_role_resource c ON c.res_id = a.id
LEFT JOIN sys_role d ON d.id = c.role_id
WHERE a.table_name = 'sys_endpoint'
</select>
</mapper>

View File

@ -81,6 +81,11 @@
<artifactId>njzscloud-common-mvc</artifactId>
<version>0.0.1</version>
</dependency>
<dependency>
<groupId>com.njzscloud</groupId>
<artifactId>njzscloud-common-cache</artifactId>
<version>0.0.1</version>
</dependency>
<dependency>
<groupId>com.njzscloud</groupId>
<artifactId>njzscloud-common-redis</artifactId>

View File

@ -5899,6 +5899,71 @@
"attr20": "",
"origin": "IMPORT"
},
{
"id": "7D98C996-2848-4BDB-9A41-27A1E3A209FD",
"defKey": "client_code",
"defName": "客户端",
"intro": "位权码",
"baseDataType": "INT",
"bizDomainType": "",
"dbDataType": "INT",
"dataLen": "",
"numScale": "",
"primaryKey": 0,
"notNull": 1,
"autoIncrement": 0,
"defaultValue": "0",
"stndDictId": "",
"stndFieldId": "",
"stndDictKey": "client_code",
"stndFieldKey": "",
"stndComplianceLevel": "",
"stndComplianceType": "",
"dictFrom": "Manual",
"dictItems": [
{
"itemKey": "0",
"itemName": "WEB 后台",
"intro": "第 0 位",
"id": "68123977-C53D-4AAA-9B8E-44CCFFF96518"
},
{
"itemKey": "1",
"itemName": "微信小程序",
"intro": "第 1 位",
"id": "0AB3C4CB-01C5-40E7-8C3C-C5EF71BC4BAC"
},
{
"itemKey": "2",
"itemName": "手机 APP",
"intro": "第 2 位",
"id": "22B26C48-0C87-442F-ABDC-D9E9D2D2DB9D"
}
],
"fieldTier": "",
"mark": null,
"attr1": "",
"attr2": "",
"attr3": "",
"attr4": "",
"attr5": "",
"attr6": "",
"attr7": "",
"attr8": "",
"attr9": "",
"attr10": "",
"attr11": "",
"attr12": "",
"attr13": "",
"attr14": "",
"attr15": "",
"attr16": "",
"attr17": "",
"attr18": "PDManer",
"attr19": "68EE2E5E-F775-458D-8686-B8834995C062",
"attr20": "",
"origin": "UI"
},
{
"id": "887EF609-A47C-45A4-942C-8AA5DA81AD76",
"defKey": "sn",
@ -6240,9 +6305,9 @@
"dataLen": 1,
"numScale": "",
"primaryKey": 0,
"notNull": 0,
"notNull": 1,
"autoIncrement": 0,
"defaultValue": "",
"defaultValue": "0",
"stndDictId": "",
"stndDictKey": "",
"stndFieldId": "",
@ -6324,9 +6389,9 @@
"dataLen": 128,
"numScale": "",
"primaryKey": 0,
"notNull": 0,
"notNull": 1,
"autoIncrement": 0,
"defaultValue": "",
"defaultValue": "''",
"stndDictId": "",
"stndDictKey": "",
"stndFieldId": "",
@ -6366,9 +6431,9 @@
"dataLen": 255,
"numScale": "",
"primaryKey": 0,
"notNull": 0,
"notNull": 1,
"autoIncrement": 0,
"defaultValue": "",
"defaultValue": "''",
"stndDictId": "",
"stndFieldId": "",
"stndDictKey": "",
@ -22933,9 +22998,9 @@
"defKey": "license_start_time",
"defName": "营业执照有效期",
"intro": null,
"baseDataType": "DATETIME",
"baseDataType": "DATE",
"bizDomainType": "",
"dbDataType": "DATETIME",
"dbDataType": "DATE",
"dataLen": null,
"numScale": null,
"primaryKey": 0,
@ -22979,9 +23044,9 @@
"defKey": "license_end_time",
"defName": "营业执照有效期",
"intro": null,
"baseDataType": "DATETIME",
"baseDataType": "DATE",
"bizDomainType": "",
"dbDataType": "DATETIME",
"dbDataType": "DATE",
"dataLen": null,
"numScale": null,
"primaryKey": 0,
@ -23117,9 +23182,9 @@
"defKey": "idcard_start_time",
"defName": "法人身份证有效期",
"intro": null,
"baseDataType": "DATETIME",
"baseDataType": "DATE",
"bizDomainType": "",
"dbDataType": "DATETIME",
"dbDataType": "DATE",
"dataLen": "",
"numScale": null,
"primaryKey": 0,
@ -23163,9 +23228,9 @@
"defKey": "idcard_end_time",
"defName": "法人身份证有效期",
"intro": null,
"baseDataType": "DATETIME",
"baseDataType": "DATE",
"bizDomainType": "",
"dbDataType": "DATETIME",
"dbDataType": "DATE",
"dataLen": "",
"numScale": null,
"primaryKey": 0,
@ -42968,7 +43033,7 @@
"readonly": false,
"allowWs": false
},
"updateTime": 1765359635412,
"signature": "e1b11ecff62865e7eb000c6c88e1e638",
"updateTime": 1765434816305,
"signature": "f39d1018f0ed556230f3489a43a16da7",
"branchId": "1111"
}