feat: add RBAC control for outbound list module
Co-authored-by: aider (openai/DeepSeek-V3.2-Thinking) <aider@aider.chat>
This commit is contained in:
@ -8,6 +8,66 @@ import traceback
|
|||||||
outbound_bp = Blueprint('outbound', __name__, url_prefix='/outbound')
|
outbound_bp = Blueprint('outbound', __name__, url_prefix='/outbound')
|
||||||
|
|
||||||
|
|
||||||
|
# ==============================================================================
|
||||||
|
# 辅助函数:获取当前用户的完整权限列表(基于角色查询)
|
||||||
|
# ==============================================================================
|
||||||
|
def get_current_user_permissions():
|
||||||
|
"""
|
||||||
|
返回当前用户拥有的所有权限码列表(包括菜单和元素)
|
||||||
|
此函数根据角色查询数据库得到权限。
|
||||||
|
"""
|
||||||
|
from flask_jwt_extended import get_jwt
|
||||||
|
from app.services.auth_service import AuthService
|
||||||
|
claims = get_jwt()
|
||||||
|
user_role = claims.get('role')
|
||||||
|
if not user_role:
|
||||||
|
return []
|
||||||
|
# 超级管理员返回所有字段权限
|
||||||
|
if user_role == 'super_admin':
|
||||||
|
return ['outbound_list:*']
|
||||||
|
perm_dict = AuthService.get_user_permissions(user_role)
|
||||||
|
# 合并菜单和元素权限
|
||||||
|
perms = perm_dict.get('menus', []) + perm_dict.get('elements', [])
|
||||||
|
return perms
|
||||||
|
|
||||||
|
|
||||||
|
def filter_item_by_permissions(item_dict, user_permissions):
|
||||||
|
"""
|
||||||
|
根据用户权限过滤 item 字典,无权限的字段值置为 None
|
||||||
|
"""
|
||||||
|
# 字段名到权限码的映射(与前端 permissionMap 保持一致)
|
||||||
|
field_to_perm = {
|
||||||
|
'outbound_no': 'outbound_list:outbound_no',
|
||||||
|
'outbound_time': 'outbound_list:outbound_time',
|
||||||
|
'outbound_type': 'outbound_list:outbound_type',
|
||||||
|
'total_amount': 'outbound_list:total_amount',
|
||||||
|
'consumer_name': 'outbound_list:consumer_name',
|
||||||
|
'operator_name': 'outbound_list:operator_name',
|
||||||
|
'remark': 'outbound_list:remark',
|
||||||
|
'signature_path': 'outbound_list:signature_path',
|
||||||
|
# 明细字段
|
||||||
|
'sku': 'outbound_list:sku',
|
||||||
|
'name': 'outbound_list:name',
|
||||||
|
'material_type': 'outbound_list:material_type',
|
||||||
|
'category': 'outbound_list:category',
|
||||||
|
'spec_model': 'outbound_list:spec_model',
|
||||||
|
'quantity': 'outbound_list:quantity',
|
||||||
|
'unit_price': 'outbound_list:unit_price',
|
||||||
|
'subtotal': 'outbound_list:subtotal',
|
||||||
|
}
|
||||||
|
# 如果用户是超级管理员且有 'outbound_list:*',则不过滤
|
||||||
|
if 'outbound_list:*' in user_permissions:
|
||||||
|
return item_dict
|
||||||
|
for field, perm_code in field_to_perm.items():
|
||||||
|
if field in item_dict and perm_code not in user_permissions:
|
||||||
|
item_dict[field] = None
|
||||||
|
# 如果 item_dict 中包含 items 列表,递归处理每个子项
|
||||||
|
if 'items' in item_dict and isinstance(item_dict['items'], list):
|
||||||
|
for sub_item in item_dict['items']:
|
||||||
|
filter_item_by_permissions(sub_item, user_permissions)
|
||||||
|
return item_dict
|
||||||
|
|
||||||
|
|
||||||
# --------------------------------------------------------
|
# --------------------------------------------------------
|
||||||
# 1. 扫码查询库存接口 (关联三个库存表)
|
# 1. 扫码查询库存接口 (关联三个库存表)
|
||||||
# GET /api/v1/outbound/scan?barcode=...
|
# GET /api/v1/outbound/scan?barcode=...
|
||||||
@ -105,7 +165,7 @@ def create_outbound():
|
|||||||
# --------------------------------------------------------
|
# --------------------------------------------------------
|
||||||
@outbound_bp.route('', methods=['GET'])
|
@outbound_bp.route('', methods=['GET'])
|
||||||
@jwt_required()
|
@jwt_required()
|
||||||
@permission_required('outbound_selection')
|
@permission_required('outbound_list')
|
||||||
def get_outbound_list():
|
def get_outbound_list():
|
||||||
try:
|
try:
|
||||||
page = int(request.args.get('page', 1))
|
page = int(request.args.get('page', 1))
|
||||||
@ -116,6 +176,11 @@ def get_outbound_list():
|
|||||||
# ★ [修改] 调用分组查询服务
|
# ★ [修改] 调用分组查询服务
|
||||||
result = OutboundService.get_grouped_list(page, limit, keyword)
|
result = OutboundService.get_grouped_list(page, limit, keyword)
|
||||||
|
|
||||||
|
# 字段级脱敏
|
||||||
|
user_permissions = get_current_user_permissions()
|
||||||
|
if result.get('items'):
|
||||||
|
result['items'] = [filter_item_by_permissions(item, user_permissions) for item in result['items']]
|
||||||
|
|
||||||
return jsonify({
|
return jsonify({
|
||||||
'code': 200,
|
'code': 200,
|
||||||
'msg': '获取成功',
|
'msg': '获取成功',
|
||||||
|
|||||||
@ -20,7 +20,7 @@
|
|||||||
value-format="YYYY-MM-DD"
|
value-format="YYYY-MM-DD"
|
||||||
/>
|
/>
|
||||||
<el-button type="primary" class="filter-item" style="margin-left: 10px;" @click="fetchData">查询</el-button>
|
<el-button type="primary" class="filter-item" style="margin-left: 10px;" @click="fetchData">查询</el-button>
|
||||||
<el-button type="success" class="filter-item" @click="$router.push('/outbound/create')">新建出库</el-button>
|
<el-button v-if="userStore.hasPermission('outbound_create:operation')" type="success" class="filter-item" @click="$router.push('/outbound/create')">新建出库</el-button>
|
||||||
</div>
|
</div>
|
||||||
|
|
||||||
<el-table
|
<el-table
|
||||||
@ -35,18 +35,18 @@
|
|||||||
<div style="padding: 10px 40px; background: #fafafa;">
|
<div style="padding: 10px 40px; background: #fafafa;">
|
||||||
<h4 style="margin: 0 0 10px 0; color: #409EFF;">商品明细 (按单价降序)</h4>
|
<h4 style="margin: 0 0 10px 0; color: #409EFF;">商品明细 (按单价降序)</h4>
|
||||||
<el-table :data="props.row.items" border size="small">
|
<el-table :data="props.row.items" border size="small">
|
||||||
<el-table-column prop="sku" label="SKU" width="150" />
|
<el-table-column v-if="hasColumnPermission('sku')" prop="sku" label="SKU" width="150" />
|
||||||
|
|
||||||
<el-table-column prop="name" label="名称" min-width="150" show-overflow-tooltip />
|
<el-table-column v-if="hasColumnPermission('name')" prop="name" label="名称" min-width="150" show-overflow-tooltip />
|
||||||
<el-table-column prop="material_type" label="类型" width="120" show-overflow-tooltip />
|
<el-table-column v-if="hasColumnPermission('material_type')" prop="material_type" label="类型" width="120" show-overflow-tooltip />
|
||||||
<el-table-column prop="category" label="类别" width="120" show-overflow-tooltip />
|
<el-table-column v-if="hasColumnPermission('category')" prop="category" label="类别" width="120" show-overflow-tooltip />
|
||||||
<el-table-column prop="spec_model" label="规格型号" min-width="150" show-overflow-tooltip />
|
<el-table-column v-if="hasColumnPermission('spec_model')" prop="spec_model" label="规格型号" min-width="150" show-overflow-tooltip />
|
||||||
|
|
||||||
<el-table-column prop="quantity" label="数量" width="100" />
|
<el-table-column v-if="hasColumnPermission('quantity')" prop="quantity" label="数量" width="100" />
|
||||||
<el-table-column prop="unit_price" label="单价" width="120">
|
<el-table-column v-if="hasColumnPermission('unit_price')" prop="unit_price" label="单价" width="120">
|
||||||
<template #default="{row}">¥{{ row.unit_price }}</template>
|
<template #default="{row}">¥{{ row.unit_price }}</template>
|
||||||
</el-table-column>
|
</el-table-column>
|
||||||
<el-table-column prop="subtotal" label="小计">
|
<el-table-column v-if="hasColumnPermission('subtotal')" prop="subtotal" label="小计">
|
||||||
<template #default="{row}">
|
<template #default="{row}">
|
||||||
<span style="color: #F56C6C; font-weight: bold;">¥{{ row.subtotal.toFixed(2) }}</span>
|
<span style="color: #F56C6C; font-weight: bold;">¥{{ row.subtotal.toFixed(2) }}</span>
|
||||||
</template>
|
</template>
|
||||||
@ -56,33 +56,33 @@
|
|||||||
</template>
|
</template>
|
||||||
</el-table-column>
|
</el-table-column>
|
||||||
|
|
||||||
<el-table-column prop="outbound_no" label="出库单号" min-width="200" show-overflow-tooltip />
|
<el-table-column v-if="hasColumnPermission('outbound_no')" prop="outbound_no" label="出库单号" min-width="200" show-overflow-tooltip />
|
||||||
|
|
||||||
<el-table-column prop="outbound_time" label="出库时间" width="170" align="center">
|
<el-table-column v-if="hasColumnPermission('outbound_time')" prop="outbound_time" label="出库时间" width="170" align="center">
|
||||||
<template #default="{ row }">
|
<template #default="{ row }">
|
||||||
<span>{{ row.outbound_time ? row.outbound_time.substring(0, 16) : '' }}</span>
|
<span>{{ row.outbound_time ? row.outbound_time.substring(0, 16) : '' }}</span>
|
||||||
</template>
|
</template>
|
||||||
</el-table-column>
|
</el-table-column>
|
||||||
|
|
||||||
<el-table-column prop="outbound_type" label="类型" width="100" align="center">
|
<el-table-column v-if="hasColumnPermission('outbound_type')" prop="outbound_type" label="类型" width="100" align="center">
|
||||||
<template #default="{ row }">
|
<template #default="{ row }">
|
||||||
<el-tag :type="getTagType(row.outbound_type)">{{ formatType(row.outbound_type) }}</el-tag>
|
<el-tag :type="getTagType(row.outbound_type)">{{ formatType(row.outbound_type) }}</el-tag>
|
||||||
</template>
|
</template>
|
||||||
</el-table-column>
|
</el-table-column>
|
||||||
|
|
||||||
<el-table-column prop="total_amount" label="总金额" width="120" align="right">
|
<el-table-column v-if="hasColumnPermission('total_amount')" prop="total_amount" label="总金额" width="120" align="right">
|
||||||
<template #default="{ row }">
|
<template #default="{ row }">
|
||||||
<span style="color: #F56C6C; font-weight: bold; font-size: 15px;">¥{{ row.total_amount }}</span>
|
<span style="color: #F56C6C; font-weight: bold; font-size: 15px;">¥{{ row.total_amount }}</span>
|
||||||
</template>
|
</template>
|
||||||
</el-table-column>
|
</el-table-column>
|
||||||
|
|
||||||
<el-table-column prop="consumer_name" label="领用/客户" min-width="120" show-overflow-tooltip />
|
<el-table-column v-if="hasColumnPermission('consumer_name')" prop="consumer_name" label="领用/客户" min-width="120" show-overflow-tooltip />
|
||||||
|
|
||||||
<el-table-column prop="operator_name" label="操作员" min-width="100" show-overflow-tooltip />
|
<el-table-column v-if="hasColumnPermission('operator_name')" prop="operator_name" label="操作员" min-width="100" show-overflow-tooltip />
|
||||||
|
|
||||||
<el-table-column prop="remark" label="备注" min-width="150" show-overflow-tooltip />
|
<el-table-column v-if="hasColumnPermission('remark')" prop="remark" label="备注" min-width="150" show-overflow-tooltip />
|
||||||
|
|
||||||
<el-table-column label="签名" width="120" align="center">
|
<el-table-column v-if="hasColumnPermission('signature_path')" label="签名" width="120" align="center">
|
||||||
<template #default="{ row }">
|
<template #default="{ row }">
|
||||||
<div v-if="row.signature_path" class="signature-cell">
|
<div v-if="row.signature_path" class="signature-cell">
|
||||||
<el-image
|
<el-image
|
||||||
@ -121,6 +121,39 @@
|
|||||||
import { ref, onMounted, reactive } from 'vue'
|
import { ref, onMounted, reactive } from 'vue'
|
||||||
import { getOutboundList } from '@/api/outbound'
|
import { getOutboundList } from '@/api/outbound'
|
||||||
import { Picture } from '@element-plus/icons-vue'
|
import { Picture } from '@element-plus/icons-vue'
|
||||||
|
import { useUserStore } from '@/stores/user'
|
||||||
|
|
||||||
|
const userStore = useUserStore()
|
||||||
|
|
||||||
|
// 列与权限Code的映射关系(数据库中的code)
|
||||||
|
const permissionMap: Record<string, string> = {
|
||||||
|
outbound_no: 'outbound_list:outbound_no',
|
||||||
|
outbound_time: 'outbound_list:outbound_time',
|
||||||
|
outbound_type: 'outbound_list:outbound_type',
|
||||||
|
total_amount: 'outbound_list:total_amount',
|
||||||
|
consumer_name: 'outbound_list:consumer_name',
|
||||||
|
operator_name: 'outbound_list:operator_name',
|
||||||
|
remark: 'outbound_list:remark',
|
||||||
|
signature_path: 'outbound_list:signature_path',
|
||||||
|
// 明细列
|
||||||
|
sku: 'outbound_list:sku',
|
||||||
|
name: 'outbound_list:name',
|
||||||
|
material_type: 'outbound_list:material_type',
|
||||||
|
category: 'outbound_list:category',
|
||||||
|
spec_model: 'outbound_list:spec_model',
|
||||||
|
quantity: 'outbound_list:quantity',
|
||||||
|
unit_price: 'outbound_list:unit_price',
|
||||||
|
subtotal: 'outbound_list:subtotal',
|
||||||
|
}
|
||||||
|
|
||||||
|
// 检查列权限
|
||||||
|
const hasColumnPermission = (prop: string) => {
|
||||||
|
if (userStore.role === 'SUPER_ADMIN' || userStore.username === 'IRIS') {
|
||||||
|
return true
|
||||||
|
}
|
||||||
|
const code = permissionMap[prop]
|
||||||
|
return code ? userStore.hasPermission(code) : false
|
||||||
|
}
|
||||||
|
|
||||||
const list = ref([])
|
const list = ref([])
|
||||||
const total = ref(0)
|
const total = ref(0)
|
||||||
|
|||||||
Reference in New Issue
Block a user