DataScopeAspect.java 5.1 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160
  1. package com.ruoyi.framework.aspectj;
  2. import java.lang.reflect.Method;
  3. import org.aspectj.lang.JoinPoint;
  4. import org.aspectj.lang.Signature;
  5. import org.aspectj.lang.annotation.Aspect;
  6. import org.aspectj.lang.annotation.Before;
  7. import org.aspectj.lang.annotation.Pointcut;
  8. import org.aspectj.lang.reflect.MethodSignature;
  9. import org.springframework.stereotype.Component;
  10. import com.ruoyi.common.utils.ServletUtils;
  11. import com.ruoyi.common.utils.StringUtils;
  12. import com.ruoyi.common.utils.spring.SpringUtils;
  13. import com.ruoyi.framework.aspectj.lang.annotation.DataScope;
  14. import com.ruoyi.framework.security.LoginUser;
  15. import com.ruoyi.framework.security.service.TokenService;
  16. import com.ruoyi.framework.web.domain.BaseEntity;
  17. import com.ruoyi.project.system.domain.SysRole;
  18. import com.ruoyi.project.system.domain.SysUser;
  19. /**
  20. * 数据过滤处理
  21. *
  22. * @author ruoyi
  23. */
  24. @Aspect
  25. @Component
  26. public class DataScopeAspect
  27. {
  28. /**
  29. * 全部数据权限
  30. */
  31. public static final String DATA_SCOPE_ALL = "1";
  32. /**
  33. * 自定数据权限
  34. */
  35. public static final String DATA_SCOPE_CUSTOM = "2";
  36. /**
  37. * 部门数据权限
  38. */
  39. public static final String DATA_SCOPE_DEPT = "3";
  40. /**
  41. * 部门及以下数据权限
  42. */
  43. public static final String DATA_SCOPE_DEPT_AND_CHILD = "4";
  44. /**
  45. * 仅本人数据权限
  46. */
  47. public static final String DATA_SCOPE_SELF = "5";
  48. // 配置织入点
  49. @Pointcut("@annotation(com.ruoyi.framework.aspectj.lang.annotation.DataScope)")
  50. public void dataScopePointCut()
  51. {
  52. }
  53. @Before("dataScopePointCut()")
  54. public void doBefore(JoinPoint point) throws Throwable
  55. {
  56. handleDataScope(point);
  57. }
  58. protected void handleDataScope(final JoinPoint joinPoint)
  59. {
  60. // 获得注解
  61. DataScope controllerDataScope = getAnnotationLog(joinPoint);
  62. if (controllerDataScope == null)
  63. {
  64. return;
  65. }
  66. // 获取当前的用户
  67. LoginUser loginUser = SpringUtils.getBean(TokenService.class).getLoginUser(ServletUtils.getRequest());
  68. SysUser currentUser = loginUser.getUser();
  69. if (currentUser != null)
  70. {
  71. // 如果是超级管理员,则不过滤数据
  72. if (!currentUser.isAdmin())
  73. {
  74. dataScopeFilter(joinPoint, currentUser, controllerDataScope.deptAlias(),
  75. controllerDataScope.userAlias());
  76. }
  77. }
  78. }
  79. /**
  80. * 数据范围过滤
  81. *
  82. * @param joinPoint 切点
  83. * @param user 用户
  84. * @param alias 别名
  85. */
  86. public static void dataScopeFilter(JoinPoint joinPoint, SysUser user, String deptAlias, String userAlias)
  87. {
  88. StringBuilder sqlString = new StringBuilder();
  89. for (SysRole role : user.getRoles())
  90. {
  91. String dataScope = role.getDataScope();
  92. if (DATA_SCOPE_ALL.equals(dataScope))
  93. {
  94. sqlString = new StringBuilder();
  95. break;
  96. }
  97. else if (DATA_SCOPE_CUSTOM.equals(dataScope))
  98. {
  99. sqlString.append(StringUtils.format(
  100. " OR {}.dept_id IN ( SELECT dept_id FROM sys_role_dept WHERE role_id = {} ) ", deptAlias,
  101. role.getRoleId()));
  102. }
  103. else if (DATA_SCOPE_DEPT.equals(dataScope))
  104. {
  105. sqlString.append(StringUtils.format(" OR {}.dept_id = {} ", deptAlias, user.getDeptId()));
  106. }
  107. else if (DATA_SCOPE_DEPT_AND_CHILD.equals(dataScope))
  108. {
  109. sqlString.append(StringUtils.format(
  110. " OR {}.dept_id IN ( SELECT dept_id FROM sys_dept WHERE dept_id = {} or find_in_set( {} , ancestors ) )",
  111. deptAlias, user.getDeptId(), user.getDeptId()));
  112. }
  113. else if (DATA_SCOPE_SELF.equals(dataScope))
  114. {
  115. if (StringUtils.isNotBlank(userAlias))
  116. {
  117. sqlString.append(StringUtils.format(" OR {}.user_id = {} ", userAlias, user.getUserId()));
  118. }
  119. else
  120. {
  121. // 数据权限为仅本人且没有userAlias别名不查询任何数据
  122. sqlString.append(" OR 1=0 ");
  123. }
  124. }
  125. }
  126. if (StringUtils.isNotBlank(sqlString.toString()))
  127. {
  128. BaseEntity baseEntity = (BaseEntity) joinPoint.getArgs()[0];
  129. baseEntity.setDataScope(" AND (" + sqlString.substring(4) + ")");
  130. }
  131. }
  132. /**
  133. * 是否存在注解,如果存在就获取
  134. */
  135. private DataScope getAnnotationLog(JoinPoint joinPoint)
  136. {
  137. Signature signature = joinPoint.getSignature();
  138. MethodSignature methodSignature = (MethodSignature) signature;
  139. Method method = methodSignature.getMethod();
  140. if (method != null)
  141. {
  142. return method.getAnnotation(DataScope.class);
  143. }
  144. return null;
  145. }
  146. }