这三组接口此前是「上帝视角」且**匿名可访问**,现在全部挂 get_data_scope —— 既要求登录、又按业务分组范围过滤。顺带堵上了 AGENTS.md 点名的风险: /dashboard/people-history/export 此前匿名即可批量导出全员工时台账。 dashboard(11 个函数 / 24 处注入) · Product 主体 → product_where();Task、TaskLog 主体 → 先 join(Product) 再 task_where() · 「卡片数字」与「下钻明细」成对出现的地方用同一谓词,避免「按钮显示 2、点开却是 0 条」 · get_user_operations 的 func.count() 改为 func.count(TaskLog.id) —— 显式化,不依赖 join 形状(当前是 many-to-one 不会放大,但这样写更稳) · unread_notif **刻意不过滤**:Notification.task_id 可空,按 Product 过滤会漏掉 无任务关联的提醒(就地注释说明) · get_my_stats 本轮不动 —— 它按本人归因,语义上不受分组影响 analytics(4 个函数 / 9 条语句) · get_analytics_options 的 4 条独立语句全部处理 —— 它是筛选栏下拉的选项源, 不过滤的话维修组能在下拉里看到生产组的人(最易漏的一处) · get_device_records 的 product_id 查号是安全闸:范围外 SN 查不出 → 直接返回 [] screen(3 个函数) · month_production **不做特判** —— 维修组的「本月生产数」本来就该是 0 · get_wip_distribution 按范围裁剪工序柱子,但坚持「恒 0 才裁、有数必现」, 保证 total == sum(items) 在任何 scope 下都成立 实测(17 个端点):超管全部 200、匿名全部 401。 造 1 生产 + 1 售后产品后: 超管 products=2 / wip-matrix 2 行 / options 2 个型号 生产组 products=1 / wip-matrix 1 行 / options 1 个型号 维修组 products=1 / wip-matrix 1 行 / options 1 个型号 列表与统计口径一致;未分组用户在过渡期开关下仍走 ungrouped_fallback。 测试数据已还原。
86 lines
4.7 KiB
Python
86 lines
4.7 KiB
Python
"""效能分析 API — ECharts 数据源(个人能力图谱 / 设备流转对比 / 筛选选项)
|
||
|
||
⚠️ 2026-09 起不再是「上帝视角」:所有端点都挂了 get_data_scope,
|
||
结果按当前用户的业务分组范围过滤(超管不受限),且不再允许匿名访问。
|
||
"""
|
||
from datetime import datetime
|
||
|
||
from fastapi import APIRouter, Depends, Query
|
||
from sqlalchemy.ext.asyncio import AsyncSession
|
||
|
||
from app.core.database import get_db
|
||
from app.core.deps import get_data_scope
|
||
from app.services.data_scope_service import DataScope
|
||
from app.services.analytics_service import (
|
||
get_capability_profile, CapabilityResponse,
|
||
get_flow_compare, FlowResponse,
|
||
get_analytics_options, AnalyticsOptions,
|
||
get_device_records, DeviceRecord,
|
||
)
|
||
|
||
router = APIRouter(prefix="/analytics", tags=["效能分析"])
|
||
|
||
|
||
@router.get("/capability", response_model=CapabilityResponse)
|
||
async def capability_profile(
|
||
assignee_ids: str | None = Query(None, description="负责人ID,逗号分隔"),
|
||
spec_models: str | None = Query(None, description="规格型号,逗号分隔(可选)"),
|
||
since: str | None = Query(None, description="起始日期 ISO"),
|
||
until: str | None = Query(None, description="截止日期 ISO"),
|
||
mode: str = Query("workdays", description="耗时口径: workdays(工作小时,默认) / natural(自然小时)"),
|
||
db: AsyncSession = Depends(get_db),
|
||
scope: DataScope = Depends(get_data_scope),
|
||
):
|
||
"""个人能力图谱 — X 轴=设备身份证,分组柱状图(单台设备总耗时),按当前用户数据范围过滤。"""
|
||
since_dt = datetime.fromisoformat(since) if since else None
|
||
until_dt = datetime.fromisoformat(until) if until else None
|
||
ids = [s.strip() for s in assignee_ids.split(",") if s.strip()] if assignee_ids else None
|
||
specs = [s.strip() for s in spec_models.split(",") if s.strip()] if spec_models else None
|
||
return await get_capability_profile(
|
||
db, scope, assignee_ids=ids, spec_models=specs,
|
||
since=since_dt, until=until_dt, mode=mode,
|
||
)
|
||
|
||
|
||
@router.get("/flow", response_model=FlowResponse)
|
||
async def flow_compare(
|
||
product_sns: str | None = Query(None, description="身份证,逗号分隔"),
|
||
spec_models: str | None = Query(None, description="规格型号,逗号分隔(无 product_sns 时按型号取最近设备)"),
|
||
mode: str = Query("natural", description="时间口径: natural(自然小时) / workdays(工作小时,排除周末节假日)"),
|
||
since: str | None = Query(None, description="起始日期 ISO"),
|
||
until: str | None = Query(None, description="截止日期 ISO"),
|
||
db: AsyncSession = Depends(get_db),
|
||
scope: DataScope = Depends(get_data_scope),
|
||
):
|
||
"""设备流转对比 — 每台设备各操作人耗时(堆叠柱状,按人堆叠,识别瓶颈),按当前用户数据范围过滤。"""
|
||
sns = [s.strip() for s in product_sns.split(",") if s.strip()] if product_sns else None
|
||
specs = [s.strip() for s in spec_models.split(",") if s.strip()] if spec_models else None
|
||
since_dt = datetime.fromisoformat(since) if since else None
|
||
until_dt = datetime.fromisoformat(until) if until else None
|
||
return await get_flow_compare(db, scope, product_sns=sns, spec_models=specs, mode=mode, since=since_dt, until=until_dt)
|
||
|
||
|
||
@router.get("/options", response_model=AnalyticsOptions)
|
||
async def analytics_options(
|
||
assignee_ids: str | None = Query(None, description="负责人ID,逗号分隔(联动过滤型号)"),
|
||
spec_models: str | None = Query(None, description="规格型号,逗号分隔(联动过滤人员)"),
|
||
db: AsyncSession = Depends(get_db),
|
||
scope: DataScope = Depends(get_data_scope),
|
||
):
|
||
"""顶部筛选栏选项 — 负责人 + 规格型号 + 设备字典,支持动态联动;按当前用户数据范围过滤。"""
|
||
ids = [s.strip() for s in assignee_ids.split(",") if s.strip()] if assignee_ids else None
|
||
specs = [s.strip() for s in spec_models.split(",") if s.strip()] if spec_models else None
|
||
return await get_analytics_options(db, scope, assignee_ids=ids, spec_models=specs)
|
||
|
||
|
||
@router.get("/device-records", response_model=list[DeviceRecord])
|
||
async def device_records(
|
||
product_sn: str = Query(..., description="设备身份证"),
|
||
assignee_ids: str | None = Query(None, description="负责人ID,逗号分隔(可选,用于过滤)"),
|
||
db: AsyncSession = Depends(get_db),
|
||
scope: DataScope = Depends(get_data_scope),
|
||
):
|
||
"""某台设备的任务备注记录(含图片);可选按负责人过滤;范围外设备返回空。"""
|
||
ids = [s.strip() for s in assignee_ids.split(",") if s.strip()] if assignee_ids else None
|
||
return await get_device_records(db, scope, product_sn, assignee_ids=ids)
|