DataPermi.cs 4.0 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101
  1. using Infrastructure;
  2. using SqlSugar.IOC;
  3. using ZR.Model;
  4. using ZR.Model.Models;
  5. using ZR.Model.System;
  6. namespace ZR.ServiceCore.SqlSugar
  7. {
  8. public enum DataPermiEnum
  9. {
  10. None = 0,
  11. /// <summary>
  12. /// 全部数据权限
  13. /// </summary>
  14. All = 1,
  15. /// <summary>
  16. /// 仅本人数据权限
  17. /// </summary>
  18. SELF = 5,
  19. /// <summary>
  20. /// 部门数据权限
  21. /// </summary>
  22. DEPT = 3,
  23. /// <summary>
  24. /// 自定数据权限
  25. /// </summary>
  26. CUSTOM = 2,
  27. /// <summary>
  28. /// 部门及以下数据权限
  29. /// </summary>
  30. DEPT_CHILD = 4
  31. }
  32. /// <summary>
  33. /// 数据权限
  34. /// </summary>
  35. public class DataPermi
  36. {
  37. /// <summary>
  38. /// 数据过滤
  39. /// </summary>
  40. /// <param name="configId">多库id</param>
  41. public static void FilterData(string configId)
  42. {
  43. //获取当前用户的信息
  44. var user = JwtUtil.GetLoginUser(App.HttpContext);
  45. if (user == null || user.RoleKeys == null) return;
  46. var db = DbScoped.SugarScope.GetConnectionScope(configId);
  47. var expUser = Expressionable.Create<SysUser>().And(it => it.DelFlag == 0);
  48. var expRole = Expressionable.Create<SysRole>();
  49. var expLoginlog = Expressionable.Create<SysLogininfor>();
  50. var expSysMsg = Expressionable.Create<SysUserMsg>().And(it => it.IsDelete == 0);
  51. var expDept = Expressionable.Create<SysDept>();
  52. db.QueryFilter.AddTableFilter(expSysMsg.ToExpression());
  53. //管理员不过滤
  54. if (user.RoleKeys.Any(f => f.Equals(GlobalConstant.AdminRole))) return;
  55. foreach (var role in user.Roles.OrderBy(f => f.DataScope))
  56. {
  57. var dataScope = (DataPermiEnum)role.DataScope;
  58. if (DataPermiEnum.All.Equals(dataScope))//所有权限
  59. {
  60. break;
  61. }
  62. else if (DataPermiEnum.CUSTOM.Equals(dataScope))//自定数据权限
  63. {
  64. //" OR {}.dept_id IN ( SELECT dept_id FROM sys_role_dept WHERE role_id = {} ) ", deptAlias, role.getRoleId()));
  65. expUser.Or(it => SqlFunc.Subqueryable<SysRoleDept>().Where(f => f.DeptId == it.DeptId && f.RoleId == role.RoleId).Any());
  66. }
  67. else if (DataPermiEnum.DEPT.Equals(dataScope))//本部门数据
  68. {
  69. expUser.And(it => it.DeptId == user.DeptId);
  70. expDept.And(it => it.DeptId == user.DeptId);
  71. }
  72. else if (DataPermiEnum.DEPT_CHILD.Equals(dataScope))//本部门及以下数据
  73. {
  74. //SQl OR {}.dept_id IN ( SELECT dept_id FROM sys_dept WHERE dept_id = {} or find_in_set( {} , ancestors ) )
  75. var allChildDepts = db.Queryable<SysDept>().ToChildList(it => it.ParentId, user.DeptId);
  76. var allDeptId = allChildDepts.Select(f => f.DeptId).ToList();
  77. expUser.Or(it => allDeptId.Contains(it.DeptId));
  78. expDept.And(it => allDeptId.Contains(it.DeptId));
  79. }
  80. else if (DataPermiEnum.SELF.Equals(dataScope))//仅本人数据
  81. {
  82. expUser.Or(it => it.UserId == user.UserId);
  83. expRole.Or(it => user.RoleKeys.Contains(it.RoleKey));
  84. expLoginlog.And(it => it.UserName == user.UserName);
  85. }
  86. }
  87. db.QueryFilter.AddTableFilter(expDept.ToExpression());
  88. db.QueryFilter.AddTableFilter(expUser.ToExpression());
  89. db.QueryFilter.AddTableFilter(expRole.ToExpression());
  90. db.QueryFilter.AddTableFilter(expLoginlog.ToExpression());
  91. db.QueryFilter.AddTableFilter<UserOnlineLog>(f => f.UserId == user.UserId, QueryFilterProvider.FilterJoinPosition.Where);
  92. }
  93. }
  94. }