fix(aihr): restrict case read access
This commit is contained in:
+14
@@ -68,11 +68,17 @@ public class AihrCaseController {
|
||||
|
||||
@GetMapping("/records")
|
||||
public R<List<RecordResponse>> records(@RequestParam(value = "limit", required = false) Integer limit) {
|
||||
if (!canViewCases()) {
|
||||
return R.fail("无权查看案例素材");
|
||||
}
|
||||
return R.ok(caseService.records(limit, currentProjectScopes()));
|
||||
}
|
||||
|
||||
@GetMapping("/records/{caseId}")
|
||||
public R<DetailResponse> detail(@PathVariable String caseId) {
|
||||
if (!canViewCases()) {
|
||||
return R.fail("无权查看案例素材");
|
||||
}
|
||||
DetailResponse detail = caseService.detail(caseId, currentProjectScopes());
|
||||
return detail == null ? R.fail("案例不存在或无权访问") : R.ok(detail);
|
||||
}
|
||||
@@ -97,4 +103,12 @@ public class AihrCaseController {
|
||||
&& UserType.APP_USER.getUserType().equals(loginUser.getUserType())
|
||||
&& caseService.isCaseContributor(loginUser.getUsername());
|
||||
}
|
||||
|
||||
private boolean canViewCases() {
|
||||
LoginUser loginUser = LoginHelper.getLoginUser();
|
||||
if (loginUser != null && UserType.SYS_USER.getUserType().equals(loginUser.getUserType())) {
|
||||
return StpUtil.hasRoleOr(TenantConstants.SUPER_ADMIN_ROLE_KEY, HR_OPERATOR_ROLE);
|
||||
}
|
||||
return loginUser != null && UserType.APP_USER.getUserType().equals(loginUser.getUserType());
|
||||
}
|
||||
}
|
||||
|
||||
+1
@@ -140,6 +140,7 @@ class AihrCaseServiceTest {
|
||||
|
||||
assertTrue(controllerSource.contains("StpUtil.hasRoleOr"));
|
||||
assertTrue(controllerSource.contains("HR_OPERATOR_ROLE = \"hr_operator\""));
|
||||
assertTrue(controllerSource.contains("private boolean canViewCases()"));
|
||||
}
|
||||
|
||||
@Test
|
||||
|
||||
Reference in New Issue
Block a user