fix(aihr): scope practice audio access
This commit is contained in:
+10
@@ -119,6 +119,16 @@ public class AihrMobileController {
|
||||
|
||||
@GetMapping("/oss/{ossId}")
|
||||
public void oss(@PathVariable Long ossId, HttpServletResponse response) throws IOException {
|
||||
LoginUser loginUser = LoginHelper.getLoginUser();
|
||||
if (loginUser == null) {
|
||||
response.sendError(HttpServletResponse.SC_UNAUTHORIZED);
|
||||
return;
|
||||
}
|
||||
if (UserType.APP_USER.getUserType().equals(loginUser.getUserType())
|
||||
&& !mobileSeedService.canReadPracticeAudio(ossId, currentAppUsername())) {
|
||||
response.sendError(HttpServletResponse.SC_FORBIDDEN, "无权访问该录音");
|
||||
return;
|
||||
}
|
||||
ossService.download(ossId, response);
|
||||
}
|
||||
|
||||
|
||||
+4
@@ -88,6 +88,10 @@ public class AihrMobileSeedService {
|
||||
return practiceSeedService.historyDetail(id, extPartyId);
|
||||
}
|
||||
|
||||
public boolean canReadPracticeAudio(Long ossId, String identity) {
|
||||
return practiceSeedService.canReadPracticeAudio(ossId, identity);
|
||||
}
|
||||
|
||||
public boolean markReviewed(Long id) {
|
||||
return markReviewed(id, null);
|
||||
}
|
||||
|
||||
+16
@@ -1221,6 +1221,22 @@ public class AihrPracticeSeedService {
|
||||
return detail == null || isBlank(extPartyId) || !extPartyId.equals(reviewExtPartyId(id)) ? null : detail;
|
||||
}
|
||||
|
||||
public boolean canReadPracticeAudio(Long ossId, String identity) {
|
||||
ensureAudioTable();
|
||||
if (ossId == null || isBlank(identity)) {
|
||||
return false;
|
||||
}
|
||||
List<String> sessionParties = jdbcTemplate.query("""
|
||||
SELECT s.ext_party_id
|
||||
FROM aihr_practice_audio a
|
||||
JOIN aihr_practice_session s
|
||||
ON s.tenant_id = a.tenant_id AND s.session_id = a.session_id
|
||||
WHERE a.tenant_id = ? AND a.oss_id = ? AND s.mode = 'mobile'
|
||||
""", (rs, rowNum) -> rs.getString("ext_party_id"), TENANT_ID, ossId);
|
||||
String owner = identity.trim();
|
||||
return sessionParties.stream().anyMatch(party -> owner.equals(party) || inTeamScope(owner, party));
|
||||
}
|
||||
|
||||
@Transactional(rollbackFor = Exception.class)
|
||||
public boolean markReviewed(Long id) {
|
||||
return markReviewed(id, null);
|
||||
|
||||
Reference in New Issue
Block a user