增加了手机操作端

This commit is contained in:
wushumin
2026-05-15 14:01:36 +08:00
parent 9aac78b8da
commit dd56e0861b
107 changed files with 23547 additions and 346 deletions

View File

@@ -26,8 +26,8 @@ class AdminAuthMiddleware implements MiddlewareInterface
return api_error('未登录或登录已过期', 401);
}
$permissionCode = $this->permissionCode($path);
if ($permissionCode !== '' && !$authService->hasPermission($adminInfo, $permissionCode)) {
$permissionCodes = $this->permissionCodes($path, (string)$request->method());
if ($permissionCodes && !$this->hasAnyPermission($authService, $adminInfo, $permissionCodes)) {
return api_error('无权访问该后台功能', 403);
}
@@ -37,33 +37,47 @@ class AdminAuthMiddleware implements MiddlewareInterface
return $handler($request);
}
private function permissionCode(string $path): string
private function hasAnyPermission(AdminAuthService $authService, array $adminInfo, array $permissionCodes): bool
{
foreach ($permissionCodes as $permissionCode) {
if ($authService->hasPermission($adminInfo, $permissionCode)) {
return true;
}
}
return false;
}
private function permissionCodes(string $path, string $method): array
{
return match (true) {
str_starts_with($path, '/api/admin/dashboard') => 'dashboard.view',
str_starts_with($path, '/api/admin/dashboard') => ['dashboard.view'],
str_starts_with($path, '/api/admin/orders') && strtoupper($method) === 'GET' => ['orders.manage', 'warehouse_workbench.manage'],
str_starts_with($path, '/api/admin/order/') && strtoupper($method) === 'GET' => ['orders.manage', 'warehouse_workbench.manage'],
str_starts_with($path, '/api/admin/orders'),
str_starts_with($path, '/api/admin/order/') => 'orders.manage',
str_starts_with($path, '/api/admin/order/') => ['orders.manage'],
str_starts_with($path, '/api/admin/appraisal-tasks'),
str_starts_with($path, '/api/admin/appraisal-task/') => 'appraisal_tasks.manage',
str_starts_with($path, '/api/admin/catalog/') => 'catalog.manage',
str_starts_with($path, '/api/admin/appraisal-task/') => ['appraisal_tasks.manage'],
str_starts_with($path, '/api/admin/catalog/') => ['catalog.manage'],
str_starts_with($path, '/api/admin/reports'),
str_starts_with($path, '/api/admin/report/') => 'reports.manage',
str_starts_with($path, '/api/admin/messages') => 'messages.manage',
str_starts_with($path, '/api/admin/report/') => ['reports.manage'],
str_starts_with($path, '/api/admin/messages') => ['messages.manage'],
str_starts_with($path, '/api/admin/tickets'),
str_starts_with($path, '/api/admin/ticket/') => 'tickets.manage',
str_starts_with($path, '/api/admin/ticket/') => ['tickets.manage'],
str_starts_with($path, '/api/admin/users'),
str_starts_with($path, '/api/admin/user/') => 'users.manage',
str_starts_with($path, '/api/admin/user/') => ['users.manage'],
str_starts_with($path, '/api/admin/customers'),
str_starts_with($path, '/api/admin/customer/') => 'customers.manage',
str_starts_with($path, '/api/admin/customer/') => ['customers.manage'],
str_starts_with($path, '/api/admin/warehouse-workbench/') => ['warehouse_workbench.manage'],
str_starts_with($path, '/api/admin/warehouses'),
str_starts_with($path, '/api/admin/warehouse/') => 'warehouses.manage',
str_starts_with($path, '/api/admin/material/') => 'materials.manage',
str_starts_with($path, '/api/admin/access/') => 'access.manage',
str_starts_with($path, '/api/admin/content/') => 'system.manage',
str_starts_with($path, '/api/admin/system-configs') => 'system.manage',
str_starts_with($path, '/api/admin/warehouse/') => ['warehouses.manage'],
str_starts_with($path, '/api/admin/material/') => ['materials.manage'],
str_starts_with($path, '/api/admin/access/') => ['access.manage'],
str_starts_with($path, '/api/admin/content/') => ['system.manage'],
str_starts_with($path, '/api/admin/system-configs') => ['system.manage'],
str_starts_with($path, '/api/admin/auth/me'),
str_starts_with($path, '/api/admin/auth/logout') => '',
default => '',
str_starts_with($path, '/api/admin/auth/logout') => [],
default => [],
};
}
}