fix(aihr): restrict mobile personal data reads

This commit is contained in:
2026-07-14 13:10:16 +08:00
parent dd601c3482
commit ebd7236388
3 changed files with 13 additions and 1 deletions
@@ -215,7 +215,15 @@ public class AihrMobileController {
private static String ownMobileExtPartyId(String requested) {
String username = currentAppUsername();
return username.isBlank() ? requested : username;
if (!username.isBlank()) {
return username;
}
LoginUser loginUser = LoginHelper.getLoginUser();
if (loginUser != null && UserType.SYS_USER.getUserType().equals(loginUser.getUserType())
&& !StpUtil.hasRoleOr(TenantConstants.SUPER_ADMIN_ROLE_KEY, "hr_operator")) {
throw new ServiceException("无权访问员工个人数据");
}
return requested;
}
private static String scopedAssignmentExtPartyId(String requested) {
@@ -472,6 +472,9 @@ public class AihrPracticeSeedServiceTest {
assertTrue(controllerSource.contains("catch (RuntimeException ex)"));
assertTrue(controllerSource.contains("private String supervisorScopeExtPartyId()"));
assertTrue(controllerSource.contains("mobileSeedService.requireSupervisorIdentity(currentAppUsername())"));
assertTrue(controllerSource.contains("无权访问员工个人数据"));
assertTrue(controllerSource.contains("UserType.SYS_USER.getUserType().equals(loginUser.getUserType())"));
assertTrue(controllerSource.contains("StpUtil.hasRoleOr(TenantConstants.SUPER_ADMIN_ROLE_KEY, \"hr_operator\")"));
assertTrue(controllerSource.contains("@SaCheckLogin\npublic class AihrMobileController"));
assertTrue(controllerSource.contains("@SaIgnore\n @GetMapping(\"/home/{role}\")"));
assertTrue(controllerSource.contains("if (!LoginHelper.isLogin())"));