fix(aihr): restrict candidate interview flow roles
This commit is contained in:
+21
@@ -46,16 +46,25 @@ public class AihrInterviewController {
|
||||
|
||||
@PostMapping("/start")
|
||||
public R<StartResponse> start(@RequestBody StartRequest request) {
|
||||
if (!canUseInterviewFlow()) {
|
||||
return R.fail("无权进行面试");
|
||||
}
|
||||
return R.ok(interviewService.start(bindAppCandidate(request)));
|
||||
}
|
||||
|
||||
@PostMapping("/answer")
|
||||
public R<AnswerResponse> answer(@RequestBody AnswerRequest request) {
|
||||
if (!canUseInterviewFlow()) {
|
||||
return R.fail("无权进行面试");
|
||||
}
|
||||
return R.ok(interviewService.answer(request, currentAppUsername()));
|
||||
}
|
||||
|
||||
@PostMapping("/finish")
|
||||
public R<FinishResponse> finish(@RequestBody FinishRequest request) {
|
||||
if (!canUseInterviewFlow()) {
|
||||
return R.fail("无权进行面试");
|
||||
}
|
||||
return R.ok(interviewService.finish(request, currentAppUsername()));
|
||||
}
|
||||
|
||||
@@ -114,6 +123,18 @@ public class AihrInterviewController {
|
||||
return username == null ? "" : username.trim();
|
||||
}
|
||||
|
||||
private static boolean canUseInterviewFlow() {
|
||||
LoginUser loginUser = LoginHelper.getLoginUser();
|
||||
if (loginUser == null) {
|
||||
return false;
|
||||
}
|
||||
if (UserType.APP_USER.getUserType().equals(loginUser.getUserType())) {
|
||||
return true;
|
||||
}
|
||||
return UserType.SYS_USER.getUserType().equals(loginUser.getUserType())
|
||||
&& StpUtil.hasRoleOr(TenantConstants.SUPER_ADMIN_ROLE_KEY, HR_OPERATOR_ROLE);
|
||||
}
|
||||
|
||||
private static String appCandidateName(String username) {
|
||||
return username.matches("1[3-9]\\d{9}") ? "候选人" + username.substring(username.length() - 4) : username;
|
||||
}
|
||||
|
||||
+18
@@ -147,6 +147,24 @@ class AihrInterviewServiceTest {
|
||||
assertTrue(controllerSource.contains("return R.fail(\"无权查看面试记录\")"));
|
||||
}
|
||||
|
||||
@Test
|
||||
@Tag("dev")
|
||||
void interviewFlowRequiresCandidateOrHrRole() throws Exception {
|
||||
Path source = Path.of("src/main/java/org/dromara/aihr/controller/AihrInterviewController.java");
|
||||
if (!Files.exists(source)) {
|
||||
source = Path.of("ruoyi-modules/ruoyi-aihr/src/main/java/org/dromara/aihr/controller/AihrInterviewController.java");
|
||||
}
|
||||
String controllerSource = Files.readString(source);
|
||||
|
||||
assertTrue(controllerSource.contains("private static boolean canUseInterviewFlow()"));
|
||||
assertTrue(controllerSource.contains("UserType.APP_USER.getUserType().equals(loginUser.getUserType())"));
|
||||
assertTrue(controllerSource.contains("StpUtil.hasRoleOr(TenantConstants.SUPER_ADMIN_ROLE_KEY, HR_OPERATOR_ROLE)"));
|
||||
assertTrue(controllerSource.contains("return R.fail(\"无权进行面试\")"));
|
||||
String guard = "if (!canUseInterviewFlow())";
|
||||
int guardOccurrences = (controllerSource.length() - controllerSource.replace(guard, "").length()) / guard.length();
|
||||
assertEquals(3, guardOccurrences);
|
||||
}
|
||||
|
||||
@Test
|
||||
@Tag("dev")
|
||||
void reviewResultPersistsHumanScoreWithoutChangingAiScore() {
|
||||
|
||||
Reference in New Issue
Block a user