feat(aihr): 重构运营后台与租户知识治理
- 重构运营总览、侧栏和内容运营工作台\n- 增加大喇叭、成果审核与运营统计链路\n- 补齐租户、知识空间、分类和知识维护闭环\n- 加固标签页租户上下文、停用租户写保护与迁移预检
This commit is contained in:
+86
-9
@@ -2,23 +2,29 @@ package org.dromara.common.tenant.helper;
|
||||
|
||||
import cn.dev33.satoken.context.SaHolder;
|
||||
import cn.dev33.satoken.context.model.SaStorage;
|
||||
import cn.dev33.satoken.stp.StpUtil;
|
||||
import cn.hutool.core.collection.CollectionUtil;
|
||||
import cn.hutool.core.convert.Convert;
|
||||
import cn.hutool.core.util.ObjectUtil;
|
||||
import cn.hutool.crypto.SecureUtil;
|
||||
import com.baomidou.mybatisplus.core.plugins.IgnoreStrategy;
|
||||
import com.baomidou.mybatisplus.core.plugins.InterceptorIgnoreHelper;
|
||||
import lombok.AccessLevel;
|
||||
import lombok.NoArgsConstructor;
|
||||
import lombok.extern.slf4j.Slf4j;
|
||||
import org.dromara.common.core.constant.GlobalConstants;
|
||||
import org.dromara.common.core.exception.ServiceException;
|
||||
import org.dromara.common.core.utils.SpringUtils;
|
||||
import org.dromara.common.core.utils.StringUtils;
|
||||
import org.dromara.common.core.utils.reflect.ReflectUtils;
|
||||
import org.dromara.common.redis.utils.RedisUtils;
|
||||
import org.dromara.common.satoken.utils.LoginHelper;
|
||||
|
||||
import java.time.Duration;
|
||||
import java.util.Objects;
|
||||
import java.util.Stack;
|
||||
import java.util.function.Supplier;
|
||||
import java.util.regex.Pattern;
|
||||
|
||||
/**
|
||||
* 租户助手
|
||||
@@ -31,6 +37,14 @@ public class TenantHelper {
|
||||
|
||||
private static final String DYNAMIC_TENANT_KEY = GlobalConstants.GLOBAL_REDIS_KEY + "dynamicTenant";
|
||||
|
||||
/** Page-scoped frontend context; its value is opaque and never a tenant id. */
|
||||
public static final String DYNAMIC_TENANT_CONTEXT_HEADER = "X-AIHR-Tenant-Context";
|
||||
|
||||
/** Client echo of the displayed tenant, used only to reject stale requests. */
|
||||
public static final String EXPECTED_TENANT_HEADER = "X-AIHR-Expected-Tenant";
|
||||
|
||||
private static final Pattern DYNAMIC_TENANT_CONTEXT_PATTERN = Pattern.compile("[A-Za-z0-9_-]{16,128}");
|
||||
|
||||
private static final ThreadLocal<String> TEMP_DYNAMIC_TENANT = new ThreadLocal<>();
|
||||
|
||||
private static final ThreadLocal<Stack<Integer>> REENTRANT_IGNORE = ThreadLocal.withInitial(Stack::new);
|
||||
@@ -135,8 +149,8 @@ public class TenantHelper {
|
||||
TEMP_DYNAMIC_TENANT.set(tenantId);
|
||||
return;
|
||||
}
|
||||
String cacheKey = DYNAMIC_TENANT_KEY + ":" + LoginHelper.getUserId();
|
||||
RedisUtils.setCacheObject(cacheKey, tenantId);
|
||||
String cacheKey = dynamicTenantCacheKey();
|
||||
RedisUtils.setCacheObject(cacheKey, tenantId, dynamicTenantTtl());
|
||||
SaHolder.getStorage().set(cacheKey, tenantId);
|
||||
}
|
||||
|
||||
@@ -158,7 +172,7 @@ public class TenantHelper {
|
||||
return tenantId;
|
||||
}
|
||||
SaStorage storage = SaHolder.getStorage();
|
||||
String cacheKey = DYNAMIC_TENANT_KEY + ":" + LoginHelper.getUserId();
|
||||
String cacheKey = dynamicTenantCacheKey();
|
||||
tenantId = storage.getString(cacheKey);
|
||||
// 如果为 -1 说明已经查过redis并且不存在值 则直接返回null
|
||||
if (StringUtils.isNotBlank(tenantId)) {
|
||||
@@ -181,7 +195,7 @@ public class TenantHelper {
|
||||
return;
|
||||
}
|
||||
TEMP_DYNAMIC_TENANT.remove();
|
||||
String cacheKey = DYNAMIC_TENANT_KEY + ":" + LoginHelper.getUserId();
|
||||
String cacheKey = dynamicTenantCacheKey();
|
||||
RedisUtils.deleteObject(cacheKey);
|
||||
SaHolder.getStorage().delete(cacheKey);
|
||||
}
|
||||
@@ -192,11 +206,12 @@ public class TenantHelper {
|
||||
* @param handle 处理执行方法
|
||||
*/
|
||||
public static void dynamic(String tenantId, Runnable handle) {
|
||||
setDynamic(tenantId);
|
||||
String previousTenantId = TEMP_DYNAMIC_TENANT.get();
|
||||
TEMP_DYNAMIC_TENANT.set(tenantId);
|
||||
try {
|
||||
handle.run();
|
||||
} finally {
|
||||
clearDynamic();
|
||||
restoreTemporaryDynamicTenant(previousTenantId);
|
||||
}
|
||||
}
|
||||
|
||||
@@ -206,11 +221,12 @@ public class TenantHelper {
|
||||
* @param handle 处理执行方法
|
||||
*/
|
||||
public static <T> T dynamic(String tenantId, Supplier<T> handle) {
|
||||
setDynamic(tenantId);
|
||||
String previousTenantId = TEMP_DYNAMIC_TENANT.get();
|
||||
TEMP_DYNAMIC_TENANT.set(tenantId);
|
||||
try {
|
||||
return handle.get();
|
||||
} finally {
|
||||
clearDynamic();
|
||||
restoreTemporaryDynamicTenant(previousTenantId);
|
||||
}
|
||||
}
|
||||
|
||||
@@ -221,11 +237,72 @@ public class TenantHelper {
|
||||
if (!isEnable()) {
|
||||
return null;
|
||||
}
|
||||
String tenantId = TenantHelper.getDynamic();
|
||||
String temporaryTenantId = TEMP_DYNAMIC_TENANT.get();
|
||||
String dynamicTenantId = TenantHelper.getDynamic();
|
||||
String tenantId = dynamicTenantId;
|
||||
if (StringUtils.isBlank(tenantId)) {
|
||||
tenantId = LoginHelper.getTenantId();
|
||||
}
|
||||
if (StringUtils.isBlank(temporaryTenantId)) {
|
||||
verifyExpectedTenant(dynamicTenantId, tenantId);
|
||||
}
|
||||
return tenantId;
|
||||
}
|
||||
|
||||
/**
|
||||
* A dynamic tenant is selected from a browser page. Scope it to the
|
||||
* current Sa-Token and the page's opaque context identifier so tabs that
|
||||
* share a login token cannot overwrite one another's working tenant.
|
||||
*/
|
||||
private static String dynamicTenantCacheKey() {
|
||||
String tokenValue = StpUtil.getTokenValue();
|
||||
String sessionScope;
|
||||
if (StringUtils.isNotBlank(tokenValue)) {
|
||||
sessionScope = DYNAMIC_TENANT_KEY + ":token:" + SecureUtil.md5(tokenValue);
|
||||
} else {
|
||||
sessionScope = DYNAMIC_TENANT_KEY + ":user:" + LoginHelper.getUserId();
|
||||
}
|
||||
String requestContextId = requestContextId();
|
||||
return StringUtils.isBlank(requestContextId) ? sessionScope : sessionScope + ":tab:" + SecureUtil.md5(requestContextId);
|
||||
}
|
||||
|
||||
private static Duration dynamicTenantTtl() {
|
||||
long tokenTimeout = StpUtil.getTokenTimeout();
|
||||
return tokenTimeout > 0 ? Duration.ofSeconds(tokenTimeout) : Duration.ofHours(12);
|
||||
}
|
||||
|
||||
private static void restoreTemporaryDynamicTenant(String previousTenantId) {
|
||||
if (previousTenantId == null) {
|
||||
TEMP_DYNAMIC_TENANT.remove();
|
||||
} else {
|
||||
TEMP_DYNAMIC_TENANT.set(previousTenantId);
|
||||
}
|
||||
}
|
||||
|
||||
private static void verifyExpectedTenant(String dynamicTenantId, String effectiveTenantId) {
|
||||
if (StringUtils.isBlank(requestContextId())) {
|
||||
return;
|
||||
}
|
||||
String expectedTenantId = requestHeader(EXPECTED_TENANT_HEADER);
|
||||
if (StringUtils.isNotBlank(dynamicTenantId) && !Objects.equals(dynamicTenantId, expectedTenantId)) {
|
||||
throw new ServiceException("租户上下文已变更,请刷新后重试", 409);
|
||||
}
|
||||
if (StringUtils.isNotBlank(expectedTenantId) && !Objects.equals(expectedTenantId, effectiveTenantId)) {
|
||||
throw new ServiceException("租户上下文已变更,请刷新后重试", 409);
|
||||
}
|
||||
}
|
||||
|
||||
private static String requestContextId() {
|
||||
String requestContextId = requestHeader(DYNAMIC_TENANT_CONTEXT_HEADER);
|
||||
return requestContextId != null && DYNAMIC_TENANT_CONTEXT_PATTERN.matcher(requestContextId).matches() ? requestContextId : null;
|
||||
}
|
||||
|
||||
private static String requestHeader(String name) {
|
||||
try {
|
||||
return SaHolder.getRequest().getHeader(name);
|
||||
} catch (Exception ignored) {
|
||||
return null;
|
||||
}
|
||||
}
|
||||
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user