fix(aihr): restrict candidate interview flow roles

This commit is contained in:
2026-07-15 01:11:08 +08:00
parent 1b3997d410
commit cb429908e0
4 changed files with 42 additions and 0 deletions
@@ -46,16 +46,25 @@ public class AihrInterviewController {
@PostMapping("/start")
public R<StartResponse> start(@RequestBody StartRequest request) {
if (!canUseInterviewFlow()) {
return R.fail("无权进行面试");
}
return R.ok(interviewService.start(bindAppCandidate(request)));
}
@PostMapping("/answer")
public R<AnswerResponse> answer(@RequestBody AnswerRequest request) {
if (!canUseInterviewFlow()) {
return R.fail("无权进行面试");
}
return R.ok(interviewService.answer(request, currentAppUsername()));
}
@PostMapping("/finish")
public R<FinishResponse> finish(@RequestBody FinishRequest request) {
if (!canUseInterviewFlow()) {
return R.fail("无权进行面试");
}
return R.ok(interviewService.finish(request, currentAppUsername()));
}
@@ -114,6 +123,18 @@ public class AihrInterviewController {
return username == null ? "" : username.trim();
}
private static boolean canUseInterviewFlow() {
LoginUser loginUser = LoginHelper.getLoginUser();
if (loginUser == null) {
return false;
}
if (UserType.APP_USER.getUserType().equals(loginUser.getUserType())) {
return true;
}
return UserType.SYS_USER.getUserType().equals(loginUser.getUserType())
&& StpUtil.hasRoleOr(TenantConstants.SUPER_ADMIN_ROLE_KEY, HR_OPERATOR_ROLE);
}
private static String appCandidateName(String username) {
return username.matches("1[3-9]\\d{9}") ? "候选人" + username.substring(username.length() - 4) : username;
}
@@ -147,6 +147,24 @@ class AihrInterviewServiceTest {
assertTrue(controllerSource.contains("return R.fail(\"无权查看面试记录\")"));
}
@Test
@Tag("dev")
void interviewFlowRequiresCandidateOrHrRole() throws Exception {
Path source = Path.of("src/main/java/org/dromara/aihr/controller/AihrInterviewController.java");
if (!Files.exists(source)) {
source = Path.of("ruoyi-modules/ruoyi-aihr/src/main/java/org/dromara/aihr/controller/AihrInterviewController.java");
}
String controllerSource = Files.readString(source);
assertTrue(controllerSource.contains("private static boolean canUseInterviewFlow()"));
assertTrue(controllerSource.contains("UserType.APP_USER.getUserType().equals(loginUser.getUserType())"));
assertTrue(controllerSource.contains("StpUtil.hasRoleOr(TenantConstants.SUPER_ADMIN_ROLE_KEY, HR_OPERATOR_ROLE)"));
assertTrue(controllerSource.contains("return R.fail(\"无权进行面试\")"));
String guard = "if (!canUseInterviewFlow())";
int guardOccurrences = (controllerSource.length() - controllerSource.replace(guard, "").length()) / guard.length();
assertEquals(3, guardOccurrences);
}
@Test
@Tag("dev")
void reviewResultPersistsHumanScoreWithoutChangingAiScore() {