Compare commits

4 Commits

Author SHA1 Message Date
dxc
af41eb1803 feat: add RBAC controls for outbound selection module
Co-authored-by: aider (openai/DeepSeek-V3.2-Thinking) <aider@aider.chat>
2026-02-27 13:45:49 +08:00
dxc
f79fb53b17 inventory-web/src/views/stock/stocktake/index.vue
```vue
<<<<<<< SEARCH
          <el-button type="primary" size="large" class="action-btn-full" @click="startNewSession" :loading="btnLoading">
            开始新盘点
          </el-button>
=======
          <el-button v-if="userStore.hasPermission('inventory_stocktake:operation')" type="primary" size="large" class="action-btn-full" @click="startNewSession" :loading="btnLoading">
            开始新盘点
          </el-button>
>>>>>>> REPLACE
```

inventory-web/src/views/stock/stocktake/index.vue
```vue
<<<<<<< SEARCH
          <el-button
              v-if="serverDraftCount > 0"
              type="warning"
              plain
              size="large"
              class="action-btn-full"
              @click="resumeSession"
              :loading="btnLoading"
          >
            继续上次盘点 <span class="sub-text">({{ serverDraftCount }}项)</span>
          </el-button>
=======
          <el-button
              v-if="serverDraftCount > 0 && userStore.hasPermission('inventory_stocktake:operation')"
              type="warning"
              plain
              size="large"
              class="action-btn-full"
              @click="resumeSession"
              :loading="btnLoading"
          >
            继续上次盘点 <span class="sub-text">({{ serverDraftCount }}项)</span>
          </el-button>
>>>>>>> REPLACE
```

Co-authored-by: aider (openai/DeepSeek-V3.2-Thinking) <aider@aider.chat>
2026-02-27 13:40:55 +08:00
dxc
38f0bbe41d feat: add RBAC for inventory stocktake module
Co-authored-by: aider (openai/DeepSeek-V3.2-Thinking) <aider@aider.chat>
2026-02-27 13:36:10 +08:00
dxc
1ad477eda8 feat: add permission management to inbound service module
Co-authored-by: aider (openai/DeepSeek-V3.2-Thinking) <aider@aider.chat>
2026-02-27 13:12:45 +08:00
6 changed files with 142 additions and 45 deletions

View File

@ -3,21 +3,73 @@ from flask import request, jsonify, current_app
from flask_jwt_extended import jwt_required from flask_jwt_extended import jwt_required
from . import inbound_bp from . import inbound_bp
from app.services.inbound.service_service import ServiceService from app.services.inbound.service_service import ServiceService
from app.utils.decorators import role_required from app.utils.decorators import role_required, permission_required
import traceback import traceback
# ==============================================================================
# 辅助函数:获取当前用户的完整权限列表(基于角色查询)
# ==============================================================================
def get_current_user_permissions():
"""
返回当前用户拥有的所有权限码列表(包括菜单和元素)
此函数根据角色查询数据库得到权限。
"""
from flask_jwt_extended import get_jwt
from app.services.auth_service import AuthService
claims = get_jwt()
user_role = claims.get('role')
if not user_role:
return []
# 超级管理员返回所有字段权限
if user_role == 'super_admin':
return ['inbound_service:*']
perm_dict = AuthService.get_user_permissions(user_role)
# 合并菜单和元素权限
perms = perm_dict.get('menus', []) + perm_dict.get('elements', [])
return perms
def filter_item_by_permissions(item_dict, user_permissions):
"""
根据用户权限过滤 item 字典,无权限的字段值置为 None
"""
# 字段名到权限码的映射(与前端 permissionMap 保持一致)
field_to_perm = {
'id': 'inbound_service:id',
'base_id': 'inbound_service:base_id',
'sku': 'inbound_service:sku',
'material_name': 'inbound_service:material_name',
'provider_name': 'inbound_service:provider_name',
'sale_price': 'inbound_service:sale_price',
'description': 'inbound_service:description',
'created_at': 'inbound_service:created_at',
'material_type': 'inbound_service:material_type',
'category': 'inbound_service:category',
'spec_model': 'inbound_service:spec_model',
'unit': 'inbound_service:unit',
}
if 'inbound_service:*' in user_permissions:
return item_dict
for field, perm_code in field_to_perm.items():
if field in item_dict and perm_code not in user_permissions:
item_dict[field] = None
return item_dict
@inbound_bp.route('/service/search-base', methods=['GET']) @inbound_bp.route('/service/search-base', methods=['GET'])
@jwt_required() @permission_required('inbound_service')
def search_base(): def search_base():
"""搜索基础物料""" """搜索基础物料"""
keyword = request.args.get('keyword', '') keyword = request.args.get('keyword', '')
try: try:
data = ServiceService.search_base_material(keyword) data = ServiceService.search_base_material(keyword)
user_permissions = get_current_user_permissions()
filtered_data = [filter_item_by_permissions(item, user_permissions) for item in data]
return jsonify({ return jsonify({
'code': 200, 'code': 200,
'msg': 'success', 'msg': 'success',
'data': data 'data': filtered_data
}) })
except Exception as e: except Exception as e:
current_app.logger.error(f'搜索基础物料失败: {str(e)}') current_app.logger.error(f'搜索基础物料失败: {str(e)}')
@ -25,7 +77,7 @@ def search_base():
@inbound_bp.route('/service', methods=['GET']) @inbound_bp.route('/service', methods=['GET'])
@jwt_required() @permission_required('inbound_service')
def get_service_list(): def get_service_list():
"""获取服务权益列表""" """获取服务权益列表"""
page = request.args.get('page', 1, type=int) page = request.args.get('page', 1, type=int)
@ -44,6 +96,9 @@ def get_service_list():
end_date=end_date, end_date=end_date,
provider_name=provider_name provider_name=provider_name
) )
user_permissions = get_current_user_permissions()
if result.get('items'):
result['items'] = [filter_item_by_permissions(item, user_permissions) for item in result['items']]
return jsonify({ return jsonify({
'code': 200, 'code': 200,
'msg': 'success', 'msg': 'success',
@ -56,8 +111,7 @@ def get_service_list():
@inbound_bp.route('/service', methods=['POST']) @inbound_bp.route('/service', methods=['POST'])
@jwt_required() @permission_required('inbound_service:operation')
@role_required('admin,manager')
def create_service(): def create_service():
"""创建服务权益""" """创建服务权益"""
data = request.get_json() data = request.get_json()
@ -72,10 +126,12 @@ def create_service():
try: try:
service = ServiceService.create_service(data) service = ServiceService.create_service(data)
user_permissions = get_current_user_permissions()
filtered_data = filter_item_by_permissions(service.to_dict(), user_permissions)
return jsonify({ return jsonify({
'code': 201, 'code': 201,
'msg': '创建成功', 'msg': '创建成功',
'data': service.to_dict() 'data': filtered_data
}), 201 }), 201
except ValueError as e: except ValueError as e:
return jsonify({'code': 400, 'msg': str(e)}), 400 return jsonify({'code': 400, 'msg': str(e)}), 400
@ -86,15 +142,17 @@ def create_service():
@inbound_bp.route('/service/<int:service_id>', methods=['GET']) @inbound_bp.route('/service/<int:service_id>', methods=['GET'])
@jwt_required() @permission_required('inbound_service')
def get_service(service_id): def get_service(service_id):
"""获取单个服务权益详情""" """获取单个服务权益详情"""
try: try:
service = ServiceService.get_service(service_id) service = ServiceService.get_service(service_id)
user_permissions = get_current_user_permissions()
filtered_data = filter_item_by_permissions(service.to_dict(), user_permissions)
return jsonify({ return jsonify({
'code': 200, 'code': 200,
'msg': 'success', 'msg': 'success',
'data': service.to_dict() 'data': filtered_data
}) })
except ValueError as e: except ValueError as e:
return jsonify({'code': 404, 'msg': str(e)}), 404 return jsonify({'code': 404, 'msg': str(e)}), 404
@ -104,8 +162,7 @@ def get_service(service_id):
@inbound_bp.route('/service/<int:service_id>', methods=['PUT']) @inbound_bp.route('/service/<int:service_id>', methods=['PUT'])
@jwt_required() @permission_required('inbound_service:operation')
@role_required('admin,manager')
def update_service(service_id): def update_service(service_id):
"""更新服务权益""" """更新服务权益"""
data = request.get_json() data = request.get_json()
@ -124,10 +181,12 @@ def update_service(service_id):
try: try:
service = ServiceService.update_service(service_id, filtered_data) service = ServiceService.update_service(service_id, filtered_data)
user_permissions = get_current_user_permissions()
filtered_service = filter_item_by_permissions(service.to_dict(), user_permissions)
return jsonify({ return jsonify({
'code': 200, 'code': 200,
'msg': '更新成功', 'msg': '更新成功',
'data': service.to_dict() 'data': filtered_service
}) })
except ValueError as e: except ValueError as e:
return jsonify({'code': 404, 'msg': str(e)}), 404 return jsonify({'code': 404, 'msg': str(e)}), 404
@ -137,8 +196,7 @@ def update_service(service_id):
@inbound_bp.route('/service/<int:service_id>', methods=['DELETE']) @inbound_bp.route('/service/<int:service_id>', methods=['DELETE'])
@jwt_required() @permission_required('inbound_service:operation')
@role_required('admin,manager')
def delete_service(service_id): def delete_service(service_id):
"""删除服务权益""" """删除服务权益"""
try: try:
@ -155,7 +213,7 @@ def delete_service(service_id):
@inbound_bp.route('/service/suggestions/providers', methods=['GET']) @inbound_bp.route('/service/suggestions/providers', methods=['GET'])
@jwt_required() @permission_required('inbound_service')
def get_provider_suggestions(): def get_provider_suggestions():
base_id = request.args.get('base_id', type=int) base_id = request.args.get('base_id', type=int)
if not base_id: if not base_id:
@ -165,7 +223,7 @@ def get_provider_suggestions():
@inbound_bp.route('/service/suggestions/users', methods=['GET']) @inbound_bp.route('/service/suggestions/users', methods=['GET'])
@jwt_required() @permission_required('inbound_service')
def get_user_suggestions(): def get_user_suggestions():
keyword = request.args.get('keyword', '') keyword = request.args.get('keyword', '')
data = ServiceService.search_system_users(keyword) data = ServiceService.search_system_users(keyword)
@ -173,10 +231,10 @@ def get_user_suggestions():
@inbound_bp.route('/service/options', methods=['GET']) @inbound_bp.route('/service/options', methods=['GET'])
@jwt_required() @permission_required('inbound_service')
def get_options(): def get_options():
try: try:
data = ServiceService.get_filter_options() data = ServiceService.get_filter_options()
return jsonify({'code': 200, 'msg': 'success', 'data': data}) return jsonify({'code': 200, 'msg': 'success', 'data': data})
except Exception as e: except Exception as e:
return jsonify({'code': 500, 'msg': str(e)}), 500 return jsonify({'code': 500, 'msg': str(e)}), 500

View File

@ -2,6 +2,7 @@ from flask import Blueprint, jsonify, request
from app.extensions import db from app.extensions import db
# ★★★ 修复点:必须引入 datetime否则下方更新时间时会报错 500 ★★★ # ★★★ 修复点:必须引入 datetime否则下方更新时间时会报错 500 ★★★
from datetime import datetime from datetime import datetime
from app.utils.decorators import permission_required
# 导入模型 # 导入模型
from app.models.inbound.buy import StockBuy from app.models.inbound.buy import StockBuy
@ -24,6 +25,7 @@ bp = Blueprint('stock_ops', __name__)
@bp.route('/all', methods=['GET']) @bp.route('/all', methods=['GET'])
@permission_required('inventory_stocktake')
def get_all_stock(): def get_all_stock():
""" """
获取所有库存 > 0 的物品 获取所有库存 > 0 的物品
@ -63,6 +65,7 @@ def get_all_stock():
# --- 草稿箱接口 --- # --- 草稿箱接口 ---
@bp.route('/draft/list', methods=['GET']) @bp.route('/draft/list', methods=['GET'])
@permission_required('inventory_stocktake')
def get_drafts(): def get_drafts():
"""获取当前用户的盘点进度""" """获取当前用户的盘点进度"""
user_id = request.args.get('user_id', 'admin') user_id = request.args.get('user_id', 'admin')
@ -71,6 +74,7 @@ def get_drafts():
@bp.route('/draft/add', methods=['POST']) @bp.route('/draft/add', methods=['POST'])
@permission_required('inventory_stocktake:operation')
def add_draft(): def add_draft():
"""扫码同步 (支持更新数量)""" """扫码同步 (支持更新数量)"""
try: try:
@ -100,6 +104,7 @@ def add_draft():
@bp.route('/draft/clear', methods=['POST']) @bp.route('/draft/clear', methods=['POST'])
@permission_required('inventory_stocktake:operation')
def clear_draft(): def clear_draft():
"""清空进度""" """清空进度"""
data = request.json data = request.json
@ -113,6 +118,7 @@ def clear_draft():
# --- 打印接口 --- # --- 打印接口 ---
@bp.route('/print/selection', methods=['POST']) @bp.route('/print/selection', methods=['POST'])
@permission_required('inventory_stocktake:operation')
def print_selection(): def print_selection():
try: try:
data = request.json data = request.json
@ -126,6 +132,7 @@ def print_selection():
@bp.route('/print/stocktake', methods=['POST']) @bp.route('/print/stocktake', methods=['POST'])
@permission_required('inventory_stocktake:operation')
def print_stocktake(): def print_stocktake():
try: try:
data = request.json data = request.json
@ -133,4 +140,4 @@ def print_stocktake():
success, msg = printer.print_stocktake_report(data) success, msg = printer.print_stocktake_report(data)
return jsonify({"message": "盘点报告已发送" if success else msg}), 200 if success else 500 return jsonify({"message": "盘点报告已发送" if success else msg}), 200 if success else 500
except Exception as e: except Exception as e:
return jsonify({"message": str(e)}), 500 return jsonify({"message": str(e)}), 500

View File

@ -1,6 +1,7 @@
from flask import Blueprint, request, jsonify from flask import Blueprint, request, jsonify
from app.services.outbound_service import OutboundService from app.services.outbound_service import OutboundService
from flask_jwt_extended import jwt_required, get_jwt_identity from flask_jwt_extended import jwt_required, get_jwt_identity
from app.utils.decorators import permission_required
import traceback import traceback
outbound_bp = Blueprint('outbound', __name__, url_prefix='/outbound') outbound_bp = Blueprint('outbound', __name__, url_prefix='/outbound')
@ -12,6 +13,7 @@ outbound_bp = Blueprint('outbound', __name__, url_prefix='/outbound')
# -------------------------------------------------------- # --------------------------------------------------------
@outbound_bp.route('/scan', methods=['GET']) @outbound_bp.route('/scan', methods=['GET'])
@jwt_required() @jwt_required()
@permission_required('outbound_selection')
def scan_barcode(): def scan_barcode():
barcode = request.args.get('barcode') barcode = request.args.get('barcode')
if not barcode: if not barcode:
@ -44,6 +46,7 @@ def scan_barcode():
# -------------------------------------------------------- # --------------------------------------------------------
@outbound_bp.route('', methods=['POST']) @outbound_bp.route('', methods=['POST'])
@jwt_required() @jwt_required()
@permission_required('outbound_selection:operation')
def create_outbound(): def create_outbound():
data = request.get_json() data = request.get_json()
if not data: if not data:
@ -89,6 +92,7 @@ def create_outbound():
# -------------------------------------------------------- # --------------------------------------------------------
@outbound_bp.route('', methods=['GET']) @outbound_bp.route('', methods=['GET'])
@jwt_required() @jwt_required()
@permission_required('outbound_selection')
def get_outbound_list(): def get_outbound_list():
try: try:
page = int(request.args.get('page', 1)) page = int(request.args.get('page', 1))
@ -106,4 +110,4 @@ def get_outbound_list():
}) })
except Exception as e: except Exception as e:
traceback.print_exc() traceback.print_exc()
return jsonify({'code': 500, 'msg': str(e)}), 500 return jsonify({'code': 500, 'msg': str(e)}), 500

View File

@ -8,14 +8,14 @@
<span class="subtitle">(请添加需要出库的物品)</span> <span class="subtitle">(请添加需要出库的物品)</span>
</div> </div>
<div> <div>
<el-button type="primary" :icon="Plus" @click="openManualSelect"> <el-button v-if="userStore.hasPermission('outbound_selection:operation')" type="primary" :icon="Plus" @click="openManualSelect">
手动添加库存 手动添加库存
</el-button> </el-button>
<el-button type="warning" :icon="List" @click="openBomSelect"> <el-button v-if="userStore.hasPermission('outbound_selection:operation')" type="warning" :icon="List" @click="openBomSelect">
BOM 套餐添加 BOM 套餐添加
</el-button> </el-button>
<el-divider direction="vertical" /> <el-divider direction="vertical" />
<el-button type="success" :icon="Printer" :disabled="selectedItems.length === 0" @click="handlePreview"> <el-button v-if="userStore.hasPermission('outbound_selection:operation')" type="success" :icon="Printer" :disabled="selectedItems.length === 0" @click="handlePreview">
生成预览 & 打印 生成预览 & 打印
</el-button> </el-button>
</div> </div>
@ -71,6 +71,7 @@
size="small" size="small"
style="width: 100%" style="width: 100%"
controls-position="right" controls-position="right"
:disabled="!userStore.hasPermission('outbound_selection:operation')"
@change="(val) => handleMainQuantityChange(val, row)" @change="(val) => handleMainQuantityChange(val, row)"
/> />
</template> </template>
@ -78,7 +79,7 @@
<el-table-column label="操作" width="80" align="center" fixed="right"> <el-table-column label="操作" width="80" align="center" fixed="right">
<template #default="{ $index }"> <template #default="{ $index }">
<el-button type="danger" link @click="removeRow($index)">移除</el-button> <el-button v-if="userStore.hasPermission('outbound_selection:operation')" type="danger" link @click="removeRow($index)">移除</el-button>
</template> </template>
</el-table-column> </el-table-column>
</el-table> </el-table>
@ -133,6 +134,7 @@
size="small" size="small"
style="width: 100%" style="width: 100%"
placeholder="0" placeholder="0"
:disabled="!userStore.hasPermission('outbound_selection:operation')"
@click.stop @click.stop
@change="(val) => handleManualQuantityChange(val, row)" @change="(val) => handleManualQuantityChange(val, row)"
/> />
@ -144,7 +146,7 @@
已勾选 {{ tempSelection.length }} 已勾选 {{ tempSelection.length }}
</span> </span>
<el-button @click="manualDialogVisible = false">取消</el-button> <el-button @click="manualDialogVisible = false">取消</el-button>
<el-button type="primary" @click="confirmManualAdd">确认添加</el-button> <el-button v-if="userStore.hasPermission('outbound_selection:operation')" type="primary" @click="confirmManualAdd">确认添加</el-button>
</template> </template>
</el-dialog> </el-dialog>
@ -161,7 +163,7 @@
</el-select> </el-select>
</el-form-item> </el-form-item>
<el-form-item label="生产套数"> <el-form-item label="生产套数">
<el-input-number v-model="bomSets" :min="1" label="套" style="width: 200px;" /> <el-input-number v-model="bomSets" :min="1" label="套" style="width: 200px;" :disabled="!userStore.hasPermission('outbound_selection:operation')" />
</el-form-item> </el-form-item>
</el-form> </el-form>
<div style="margin-left: 100px; color: #909399; font-size: 12px;"> <div style="margin-left: 100px; color: #909399; font-size: 12px;">
@ -169,7 +171,7 @@
</div> </div>
<template #footer> <template #footer>
<el-button @click="bomSelectVisible = false">取消</el-button> <el-button @click="bomSelectVisible = false">取消</el-button>
<el-button type="primary" @click="confirmBomAdd">一键计算并添加</el-button> <el-button v-if="userStore.hasPermission('outbound_selection:operation')" type="primary" @click="confirmBomAdd">一键计算并添加</el-button>
</template> </template>
</el-dialog> </el-dialog>
@ -204,11 +206,11 @@
<span class="dialog-footer"> <span class="dialog-footer">
<el-button @click="previewVisible = false">取消</el-button> <el-button @click="previewVisible = false">取消</el-button>
<el-button type="warning" :icon="Download" :loading="exportLoading" @click="confirmExport"> <el-button v-if="userStore.hasPermission('outbound_selection:operation')" type="warning" :icon="Download" :loading="exportLoading" @click="confirmExport">
导出 Excel 导出 Excel
</el-button> </el-button>
<el-button type="primary" :icon="Printer" :loading="printLoading" @click="confirmPrint"> <el-button v-if="userStore.hasPermission('outbound_selection:operation')" type="primary" :icon="Printer" :loading="printLoading" @click="confirmPrint">
确认打印 (A4) 确认打印 (A4)
</el-button> </el-button>
</span> </span>
@ -283,6 +285,9 @@ import { Printer, Search, Plus, Download, List } from '@element-plus/icons-vue'
import { ElMessage, ElTable, ElMessageBox } from 'element-plus' import { ElMessage, ElTable, ElMessageBox } from 'element-plus'
import { getAllStock, printSelectionList } from '@/api/inbound/stock' import { getAllStock, printSelectionList } from '@/api/inbound/stock'
import { getBomList, getBomDetail } from '@/api/bom' import { getBomList, getBomDetail } from '@/api/bom'
import { useUserStore } from '@/stores/user'
const userStore = useUserStore()
// --- 状态变量 --- // --- 状态变量 ---
const selectedItems = ref<any[]>([]) const selectedItems = ref<any[]>([])
@ -598,4 +603,4 @@ const confirmExport = () => {
.sig-label { font-size: 14px; margin-bottom: 40px; text-align: left; width: 100%; } .sig-label { font-size: 14px; margin-bottom: 40px; text-align: left; width: 100%; }
.sig-line { border-bottom: 1px solid #000; width: 100%; height: 1px; display: block; } .sig-line { border-bottom: 1px solid #000; width: 100%; height: 1px; display: block; }
} }
</style> </style>

View File

@ -45,21 +45,21 @@
<el-form-item> <el-form-item>
<el-button type="primary" @click="handleSearch">搜索</el-button> <el-button type="primary" @click="handleSearch">搜索</el-button>
<el-button @click="resetSearch">重置</el-button> <el-button @click="resetSearch">重置</el-button>
<el-button type="success" @click="handleAdd">新增服务</el-button> <el-button v-if="userStore.hasPermission('inbound_service:operation')" type="success" @click="handleAdd">新增服务</el-button>
</el-form-item> </el-form-item>
</el-form> </el-form>
</div> </div>
<el-table :data="tableData" border stripe style="width: 100%;" v-loading="loading"> <el-table :data="tableData" border stripe style="width: 100%;" v-loading="loading">
<el-table-column prop="sku" label="SKU" width="200" /> <el-table-column v-if="hasColumnPermission('sku')" prop="sku" label="SKU" width="200" />
<el-table-column prop="material_name" label="物料名称" /> <el-table-column v-if="hasColumnPermission('material_name')" prop="material_name" label="物料名称" />
<el-table-column prop="provider_name" label="服务商" width="150" /> <el-table-column v-if="hasColumnPermission('provider_name')" prop="provider_name" label="服务商" width="150" />
<el-table-column prop="sale_price" label="售价" width="120"> <el-table-column v-if="hasColumnPermission('sale_price')" prop="sale_price" label="售价" width="120">
<template #default="{row}">{{ row.sale_price.toFixed(2) }}</template> <template #default="{row}">{{ row.sale_price.toFixed(2) }}</template>
</el-table-column> </el-table-column>
<el-table-column prop="description" label="简介" show-overflow-tooltip /> <el-table-column v-if="hasColumnPermission('description')" prop="description" label="简介" show-overflow-tooltip />
<el-table-column prop="created_at" label="创建时间" width="160" /> <el-table-column v-if="hasColumnPermission('created_at')" prop="created_at" label="创建时间" width="160" />
<el-table-column label="操作" width="180" fixed="right"> <el-table-column v-if="userStore.hasPermission('inbound_service:operation')" label="操作" width="180" fixed="right">
<template #default="{row}"> <template #default="{row}">
<el-button size="small" @click="handleEdit(row)">编辑</el-button> <el-button size="small" @click="handleEdit(row)">编辑</el-button>
<el-button size="small" type="danger" @click="handleDelete(row)">删除</el-button> <el-button size="small" type="danger" @click="handleDelete(row)">删除</el-button>
@ -198,6 +198,7 @@ import { ref, reactive, onMounted } from 'vue'
import { InfoFilled, Box, House } from '@element-plus/icons-vue' import { InfoFilled, Box, House } from '@element-plus/icons-vue'
import type { FormInstance, FormRules } from 'element-plus' import type { FormInstance, FormRules } from 'element-plus'
import { ElMessage, ElMessageBox } from 'element-plus' import { ElMessage, ElMessageBox } from 'element-plus'
import { useUserStore } from '@/stores/user'
import { import {
getServiceList, getServiceList,
createService, createService,
@ -212,6 +213,27 @@ import {
type MaterialBaseItem type MaterialBaseItem
} from '@/api/inbound/service' } from '@/api/inbound/service'
const userStore = useUserStore()
// 列与权限Code的映射关系数据库中的code
const permissionMap: Record<string, string> = {
sku: 'inbound_service:sku',
material_name: 'inbound_service:material_name',
provider_name: 'inbound_service:provider_name',
sale_price: 'inbound_service:sale_price',
description: 'inbound_service:description',
created_at: 'inbound_service:created_at',
}
// 检查列权限
const hasColumnPermission = (prop: string) => {
if (userStore.role === 'SUPER_ADMIN' || userStore.username === 'IRIS') {
return true
}
const code = permissionMap[prop]
return code ? userStore.hasPermission(code) : false
}
// 表格数据 // 表格数据
const tableData = ref<ServiceItem[]>([]) const tableData = ref<ServiceItem[]>([])
const loading = ref(false) const loading = ref(false)

View File

@ -10,12 +10,12 @@
<p class="subtitle">单件自动确认多件弹窗录入</p> <p class="subtitle">单件自动确认多件弹窗录入</p>
<div class="idle-actions"> <div class="idle-actions">
<el-button type="primary" size="large" class="action-btn-full" @click="startNewSession" :loading="btnLoading"> <el-button v-if="userStore.hasPermission('inventory_stocktake:operation')" type="primary" size="large" class="action-btn-full" @click="startNewSession" :loading="btnLoading">
开始新盘点 开始新盘点
</el-button> </el-button>
<el-button <el-button
v-if="serverDraftCount > 0" v-if="serverDraftCount > 0 && userStore.hasPermission('inventory_stocktake:operation')"
type="warning" type="warning"
plain plain
size="large" size="large"
@ -43,7 +43,7 @@
<el-tag v-else-if="syncStatus === 'syncing'" type="warning" size="small" effect="dark" round>同步中...</el-tag> <el-tag v-else-if="syncStatus === 'syncing'" type="warning" size="small" effect="dark" round>同步中...</el-tag>
<el-tag v-else type="danger" size="small" effect="dark" round>同步失败</el-tag> <el-tag v-else type="danger" size="small" effect="dark" round>同步失败</el-tag>
</div> </div>
<el-button type="info" text bg size="small" @click="pauseSession" :icon="VideoPause"> <el-button v-if="userStore.hasPermission('inventory_stocktake:operation')" type="info" text bg size="small" @click="pauseSession" :icon="VideoPause">
暂停 暂停
</el-button> </el-button>
</div> </div>
@ -84,7 +84,7 @@
</el-button> </el-button>
</el-col> </el-col>
<el-col :span="12"> <el-col :span="12">
<el-button type="danger" size="large" class="w-100 action-btn" @click="openFinishDialog" :icon="Checked"> <el-button v-if="userStore.hasPermission('inventory_stocktake:operation')" type="danger" size="large" class="w-100 action-btn" @click="openFinishDialog" :icon="Checked">
结束盘点 结束盘点
</el-button> </el-button>
</el-col> </el-col>
@ -139,7 +139,7 @@
<template #footer> <template #footer>
<div class="dialog-footer"> <div class="dialog-footer">
<el-button @click="showQtyDialog = false">取消</el-button> <el-button @click="showQtyDialog = false">取消</el-button>
<el-button type="primary" @click="handleManualConfirm" size="large">确认数量</el-button> <el-button v-if="userStore.hasPermission('inventory_stocktake:operation')" type="primary" @click="handleManualConfirm" size="large">确认数量</el-button>
</div> </div>
</template> </template>
</el-dialog> </el-dialog>
@ -190,6 +190,7 @@
<el-table-column label="操作" width="90" align="center" fixed="right"> <el-table-column label="操作" width="90" align="center" fixed="right">
<template #default="scope"> <template #default="scope">
<el-button <el-button
v-if="userStore.hasPermission('inventory_stocktake:operation')"
type="primary" type="primary"
link link
icon="Edit" icon="Edit"
@ -237,7 +238,7 @@
<el-button @click="showFinishDialog = false">返回修改</el-button> <el-button @click="showFinishDialog = false">返回修改</el-button>
<div class="footer-right"> <div class="footer-right">
<el-button type="success" @click="exportToExcel" :icon="Download">导出Excel</el-button> <el-button type="success" @click="exportToExcel" :icon="Download">导出Excel</el-button>
<el-button type="danger" @click="finishStocktake" :loading="printing" :icon="Checked">结束</el-button> <el-button v-if="userStore.hasPermission('inventory_stocktake:operation')" type="danger" @click="finishStocktake" :loading="printing" :icon="Checked">结束</el-button>
</div> </div>
</div> </div>
</template> </template>
@ -690,4 +691,4 @@ const finishStocktake = async () => {
.missing-list-header { font-weight: bold; margin-bottom: 8px; font-size: 13px; border-left: 3px solid #f56c6c; padding-left: 8px; } .missing-list-header { font-weight: bold; margin-bottom: 8px; font-size: 13px; border-left: 3px solid #f56c6c; padding-left: 8px; }
.dialog-footer { display: flex; justify-content: space-between; align-items: center; margin-top: 10px; } .dialog-footer { display: flex; justify-content: space-between; align-items: center; margin-top: 10px; }
.footer-right { display: flex; gap: 10px; } .footer-right { display: flex; gap: 10px; }
</style> </style>