fix(aihr): isolate mobile home from system users
This commit is contained in:
+6
-3
@@ -68,9 +68,12 @@ public class AihrMobileController {
|
||||
}
|
||||
LoginUser loginUser = LoginHelper.getLoginUser();
|
||||
String identity = currentAppUsername();
|
||||
if (loginUser != null
|
||||
&& UserType.APP_USER.getUserType().equals(loginUser.getUserType())
|
||||
&& supervisorRoleRequested(role)) {
|
||||
if (loginUser == null
|
||||
|| !UserType.APP_USER.getUserType().equals(loginUser.getUserType())
|
||||
|| identity.isBlank()) {
|
||||
return R.ok(mobileSeedService.publicHome(role));
|
||||
}
|
||||
if (supervisorRoleRequested(role)) {
|
||||
mobileSeedService.requireSupervisorIdentity(identity);
|
||||
}
|
||||
return R.ok(mobileSeedService.home(role, identity));
|
||||
|
||||
+1
@@ -415,6 +415,7 @@ public class AihrPracticeSeedServiceTest {
|
||||
assertTrue(controllerSource.contains("@SaIgnore\n @GetMapping(\"/home/{role}\")"));
|
||||
assertTrue(controllerSource.contains("if (!LoginHelper.isLogin())"));
|
||||
assertTrue(controllerSource.contains("return R.ok(mobileSeedService.publicHome(role))"));
|
||||
assertTrue(controllerSource.contains("!UserType.APP_USER.getUserType().equals(loginUser.getUserType())"));
|
||||
assertTrue(controllerSource.contains("return R.ok(mobileSeedService.home(role, identity))"));
|
||||
assertTrue(controllerSource.contains("mobileSeedService.requireSupervisorIdentity(identity)"));
|
||||
assertTrue(controllerSource.contains("private static boolean supervisorRoleRequested(String role)"));
|
||||
|
||||
@@ -172,3 +172,4 @@
|
||||
- 2026-07-14 BRD G3 项目范围复核:发现主管身份和团队范围查询仍使用 `LIMIT 1`,同一手机号关联多个在职项目时可能只取首个项目,导致主管团队数据漏项;现改为收集全部主管/项目经理项目编码并合并其在职成员与手机号范围,保留一线员工仅查看本人数据的降级边界。新增多项目范围回归测试;AIHR 全量测试 `70/70` 通过,未修改生产环境。
|
||||
- 2026-07-14 发布差异复核:本地最新提交 `2f36476e` 已包含主管多项目范围修复,但 `release-preflight.sh` 因两份既有未提交 Figma 文档阻断;生产根站和 `/h5/` 均返回 `200`,生产管理端仍加载旧资源 `index-CJZ3Ax3Z.js`。本轮未执行生产写入、静态资源同步或服务重启,不能把本地权限修复视为线上已生效。
|
||||
- 2026-07-14 BRD 4.4 每日三题口径复核:当前 `ensureDailyDrills` 以“移动端训练记录少于 3 次”作为新员工近似条件;`aihr_org_snapshot` 只有快照日期,没有入职/任职起始日期,因此不能证明“入职 3 个月内”,也不能用账号创建时间替代。当前保留该近似仅用于 Demo;正式试点需由组织同步提供并确认 `hire_date/entry_date` 字段后,再把每日派题资格改为真实任职日期判断。
|
||||
- 2026-07-14 BRD G3 移动首页权限复核:发现公开首页方法对已登录 SYS 用户仍可能调用全局统计分支;现要求只有 APP 用户且身份非空才读取员工/主管动态数据,后台系统用户和异常身份统一返回无业务统计的公开 seed。AIHR 全量测试 `70/70` 通过,未修改生产环境。
|
||||
|
||||
@@ -336,6 +336,7 @@ contains mobile-uni/src/services/home.ts "auth: isLoggedIn()"
|
||||
contains backend/ruoyi-modules/ruoyi-aihr/src/main/java/org/dromara/aihr/service/AihrMobileSeedService.java "public HomeResponse publicHome(String role)"
|
||||
contains backend/ruoyi-modules/ruoyi-aihr/src/main/java/org/dromara/aihr/controller/AihrMobileController.java "return R.ok(mobileSeedService.publicHome(role))"
|
||||
contains backend/ruoyi-modules/ruoyi-aihr/src/main/java/org/dromara/aihr/controller/AihrMobileController.java "mobileSeedService.home(role, identity)"
|
||||
contains backend/ruoyi-modules/ruoyi-aihr/src/main/java/org/dromara/aihr/controller/AihrMobileController.java "!UserType.APP_USER.getUserType().equals(loginUser.getUserType())"
|
||||
contains backend/ruoyi-modules/ruoyi-aihr/src/main/java/org/dromara/aihr/controller/AihrMobileController.java "supervisorRoleRequested"
|
||||
contains backend/ruoyi-modules/ruoyi-aihr/src/main/java/org/dromara/aihr/service/AihrPracticeSeedService.java "public MobileTeamMetrics mobileTeamMetrics(String supervisorExtPartyId)"
|
||||
contains mobile-uni/src/services/practice.ts "/api/train/practice/start"
|
||||
|
||||
Reference in New Issue
Block a user