package com.ruoyi.framework.aspectj;
import com.baomidou.mybatisplus.core.conditions.query.QueryWrapper;
import com.ruoyi.common.core.domain.BaseEntityExt;
import com.ruoyi.common.utils.BdTools;
import com.ruoyi.common.utils.StringUtils;
import com.ruoyi.common.utils.http.HttpUtils;
import com.ruoyi.common.utils.security.ShiroUtils;
import com.ruoyi.framework.aspectj.lang.annotation.DataScope;
import com.ruoyi.common.core.domain.BaseEntity;
import com.ruoyi.project.system.role.domain.SysRole;
import com.ruoyi.project.system.user.domain.SysUser;
import org.aspectj.lang.JoinPoint;
import org.aspectj.lang.Signature;
import org.aspectj.lang.annotation.Aspect;
import org.aspectj.lang.annotation.Before;
import org.aspectj.lang.annotation.Pointcut;
import org.aspectj.lang.reflect.MethodSignature;
import org.slf4j.Logger;
import org.slf4j.LoggerFactory;
import org.springframework.stereotype.Component;
import java.lang.reflect.Method;
/**
* 数据过滤处理
*
* @author ruoyi
*/
@Aspect
@Component
public class DataScopeAspect
{
private static final Logger log = LoggerFactory.getLogger(DataScopeAspect.class);
/**
* 全部数据权限
*/
public static final String DATA_SCOPE_ALL = "1";
/**
* 自定数据权限
*/
public static final String DATA_SCOPE_CUSTOM = "2";
/**
* 部门数据权限
*/
public static final String DATA_SCOPE_DEPT = "3";
/**
* 数据权限过滤关键字
*/
public static final String DATA_SCOPE = "dataScope";
// 配置织入点
@Pointcut("@annotation(com.ruoyi.framework.aspectj.lang.annotation.DataScope)")
public void dataScopePointCut()
{
}
@Before("dataScopePointCut()")
public void doBefore(JoinPoint point) throws Throwable
{
handleDataScope(point);
}
protected void handleDataScope(final JoinPoint joinPoint)
{
// 获得注解
DataScope controllerDataScope = getAnnotationLog(joinPoint);
if (controllerDataScope == null)
{
return;
}
// 获取当前的用户
SysUser currentUser = ShiroUtils.getSysUser();
if (currentUser != null)
{
// 如果是超级管理员,则不过滤数据
if (!currentUser.isAdmin())
{
dataScopeFilter(joinPoint, currentUser, controllerDataScope.tableAlias());
}
}
}
/**
* 数据范围过滤
*
* @param joinPoint 切点
* @param user 用户
* @param alias 别名
*/
public static void dataScopeFilter(JoinPoint joinPoint, SysUser user, String alias)
{
StringBuilder sqlString = new StringBuilder();
for (SysRole role : user.getRoles())
{
String dataScope = role.getDataScope();
if (DATA_SCOPE_ALL.equals(dataScope))
{
sqlString = new StringBuilder();
break;
}
else if (DATA_SCOPE_CUSTOM.equals(dataScope))
{
if (BdTools.isEmpty(alias)){
sqlString.append(StringUtils.format(
" OR dept_id IN ( SELECT dept_id FROM sys_role_dept WHERE role_id = {} ) ",
role.getRoleId()));
} else {
sqlString.append(StringUtils.format(
" OR {}.dept_id IN ( SELECT dept_id FROM sys_role_dept WHERE role_id = {} ) ", alias,
role.getRoleId()));
}
}
else if (DATA_SCOPE_DEPT.equals(dataScope))
{
sqlString.append(StringUtils.format(" OR {}.dept_id = {} ", alias, user.getDeptId()));
}
}
if (StringUtils.isNotBlank(sqlString.toString()))
{
System.out.println(joinPoint.getArgs()[0]);
// 判断第一个参数是 baseEntity 类型
if (BaseEntity.class.isInstance(joinPoint.getArgs()[0])){
BaseEntity baseEntity = (BaseEntity) joinPoint.getArgs()[0];
baseEntity.getParams().put(DATA_SCOPE, " AND (" + sqlString.substring(4) + ")");
} else if (BaseEntityExt.class.isInstance(joinPoint.getArgs()[0])){
// 判断第一个参数是 BaseEntityExt 类型
BaseEntityExt baseEntityExt = (BaseEntityExt) joinPoint.getArgs()[0];
baseEntityExt.getParams().put(DATA_SCOPE, " AND (" + sqlString.substring(4) + ")");
} else if (QueryWrapper.class.isInstance(joinPoint.getArgs()[0])){
// 判断第一个参数是 queryWrapper 类型
QueryWrapper queryWrapper = (QueryWrapper) joinPoint.getArgs()[0];
Object obj = queryWrapper.getEntity();
if (BdTools.notEmpty(obj)){
if (BaseEntity.class.isInstance(obj)){
((BaseEntity)queryWrapper.getEntity()).getParams().put(DATA_SCOPE, " AND (" + sqlString.substring(4) + ")");
} else if (BaseEntityExt.class.isInstance(obj)){
((BaseEntityExt)queryWrapper.getEntity()).getParams().put(DATA_SCOPE, " AND (" + sqlString.substring(4) + ")");
}
} else {
log.error("查询未添加泛型, 数据权限未控制");
}
}
}
}
/**
* 是否存在注解,如果存在就获取
*/
private DataScope getAnnotationLog(JoinPoint joinPoint)
{
Signature signature = joinPoint.getSignature();
MethodSignature methodSignature = (MethodSignature) signature;
Method method = methodSignature.getMethod();
if (method != null)
{
return method.getAnnotation(DataScope.class);
}
return null;
}
}
若依数据权限类
最新推荐文章于 2024-07-24 15:14:27 发布