Compare commits

..
34 Commits
Author SHA1 Message Date
timi cd3d522d4f Merge pull request 'v1.0.24' (#34) from dev into master
Reviewed-on: #34
2026-08-22 09:56:13 +00:00
timi 181c5078e9 Merge pull request 'v1.0.23' (#33) from dev into master
Reviewed-on: #33
2026-08-22 09:51:37 +00:00
timi e97f46e6b4 Merge pull request 'v1.0.22' (#32) from dev into master
Reviewed-on: #32
2026-08-21 17:31:33 +00:00
timi c0f89deb83 Merge pull request 'v1.0.22' (#31) from dev into master
Reviewed-on: #31
2026-08-21 17:28:32 +00:00
timi ce695463d3 Merge pull request 'v1.0.21' (#30) from dev into master
Reviewed-on: #30
2026-08-21 07:29:34 +00:00
timi 83c683d473 Merge pull request 'v1.0.20' (#29) from dev into master
Reviewed-on: #29
2026-08-21 07:25:32 +00:00
timi 9555474b0b Merge pull request 'v1.0.19' (#28) from dev into master
Reviewed-on: #28
2026-08-21 05:52:36 +00:00
timi a150f9e017 Merge pull request 'v1.0.18' (#27) from dev into master
Reviewed-on: #27
2026-08-20 17:40:22 +00:00
timi ecd2fa1c33 Merge pull request 'v1.0.17' (#26) from dev into master
Reviewed-on: #26
2026-08-19 17:30:35 +00:00
timi e3236d262d Merge pull request 'v1.0.16' (#25) from dev into master
Reviewed-on: #25
2026-08-16 03:37:08 +00:00
timi c8e2e16ba5 Merge pull request 'v1.0.15' (#24) from dev into master
Reviewed-on: #24
2026-08-15 17:49:51 +00:00
timi 99b44faf09 Merge pull request 'v1.0.15' (#23) from dev into master
Reviewed-on: #23
2026-08-15 17:45:26 +00:00
timi b3e3cbf84b Merge pull request 'v1.0.14' (#22) from dev into master
Reviewed-on: #22
2026-08-14 17:31:11 +00:00
timi 0aee11d824 Merge pull request 'v1.0.14' (#21) from dev into master
Reviewed-on: #21
2026-08-14 17:26:10 +00:00
timi fcf358a768 Merge pull request 'v1.0.13' (#20) from dev into master
Reviewed-on: #20
2026-08-13 09:52:26 +00:00
timi 619369104c Merge pull request 'v1.0.12' (#19) from dev into master
Reviewed-on: #19
2026-08-12 17:02:43 +00:00
timi 4f1408b9d0 Merge pull request 'v1.0.11' (#18) from dev into master
Reviewed-on: #18
2026-08-11 16:49:08 +00:00
timi 029eea70cc Merge pull request 'v1.0.10' (#17) from dev into master
Reviewed-on: #17
2026-08-11 16:45:36 +00:00
timi 22b1e65385 Merge pull request 'v1.0.9' (#16) from dev into master
Reviewed-on: #16
2026-08-11 16:01:10 +00:00
timi 2170c48763 Merge pull request 'v1.0.8' (#15) from dev into master
Reviewed-on: #15
2026-08-03 16:36:19 +00:00
timi c2d1c48aae Merge pull request 'v0.0.18' (#14) from dev into master
Reviewed-on: #14
2026-08-03 11:59:20 +00:00
timi e14958c643 Merge pull request 'v0.0.18' (#13) from dev into master
Reviewed-on: #13
2026-08-03 11:58:16 +00:00
timi da288338cd Merge pull request 'v1.0.7' (#12) from dev into master
Reviewed-on: #12
2026-08-01 09:34:18 +00:00
timi ea430f2468 Merge pull request 'v1.0.6' (#11) from dev into master
Reviewed-on: #11
2026-08-01 09:03:48 +00:00
timi f76f79744a Merge pull request 'v1.0.5' (#10) from dev into master
Reviewed-on: #10
2026-08-01 08:52:52 +00:00
timi 19daaff907 Merge pull request 'v1.0.4' (#9) from dev into master
Reviewed-on: #9
2026-08-01 03:13:00 +00:00
timi db94d8f932 Merge pull request 'v1.0.3' (#8) from dev into master
Reviewed-on: #8
2026-07-31 17:19:48 +00:00
timi 53618fe362 Merge pull request 'v1.0.3' (#7) from dev into master
Reviewed-on: #7
2026-07-31 17:13:37 +00:00
timi 523edffc4e Merge pull request 'v1.0.2' (#6) from dev into master
Reviewed-on: #6
2026-04-13 10:28:11 +00:00
timi c7ddb1a8b0 Merge pull request 'v1.0.1' (#5) from dev into master
Reviewed-on: #5
2026-04-12 16:17:02 +00:00
timi 45c9fc814a Merge pull request 'v1.0.0' (#4) from dev into master
Reviewed-on: #4
2026-04-09 05:16:04 +00:00
timi 407dc13ac4 Merge pull request 'v1.0.0' (#3) from dev into master
Reviewed-on: #3
2026-04-09 04:09:16 +00:00
timi 0c06bf16c2 Merge pull request 'v1.0.0' (#2) from dev into master
Reviewed-on: #2
2026-04-09 04:03:43 +00:00
timi 1db39e77d3 Merge pull request 'v1.0.0' (#1) from dev into master
Reviewed-on: #1
2026-04-08 08:48:12 +00:00
14 changed files with 140 additions and 312 deletions
+1 -1
View File
@@ -11,7 +11,7 @@
<groupId>com.imyeyu.timiserverapi</groupId> <groupId>com.imyeyu.timiserverapi</groupId>
<artifactId>TimiServerAPI</artifactId> <artifactId>TimiServerAPI</artifactId>
<version>1.0.25</version> <version>1.0.24</version>
<packaging>jar</packaging> <packaging>jar</packaging>
<name>TimiServerAPI</name> <name>TimiServerAPI</name>
<description>imyeyu.com API</description> <description>imyeyu.com API</description>
@@ -3,11 +3,9 @@ package com.imyeyu.api.modules.gao.controller;
import com.imyeyu.api.modules.gao.annotation.RequireGaoPermission; import com.imyeyu.api.modules.gao.annotation.RequireGaoPermission;
import com.imyeyu.api.modules.gao.bean.GaoPermissionCode; import com.imyeyu.api.modules.gao.bean.GaoPermissionCode;
import com.imyeyu.api.modules.gao.service.GaoCustomerChartService; import com.imyeyu.api.modules.gao.service.GaoCustomerChartService;
import com.imyeyu.api.modules.gao.service.GaoStoreScopeService;
import com.imyeyu.api.modules.gao.vo.GaoCustomerChartReq; import com.imyeyu.api.modules.gao.vo.GaoCustomerChartReq;
import com.imyeyu.api.modules.gao.vo.GaoEventRecordCalendarView; import com.imyeyu.api.modules.gao.vo.GaoEventRecordCalendarView;
import com.imyeyu.api.modules.gao.vo.GaoEventRecordDailyStatView; import com.imyeyu.api.modules.gao.vo.GaoEventRecordDailyStatView;
import com.imyeyu.java.bean.timi.TimiException;
import com.imyeyu.spring.annotation.AOPLog; import com.imyeyu.spring.annotation.AOPLog;
import com.imyeyu.spring.annotation.RequestRateLimit; import com.imyeyu.spring.annotation.RequestRateLimit;
import lombok.RequiredArgsConstructor; import lombok.RequiredArgsConstructor;
@@ -28,7 +26,6 @@ import java.util.List;
public class GaoCustomerChartController { public class GaoCustomerChartController {
private final GaoCustomerChartService service; private final GaoCustomerChartService service;
private final GaoStoreScopeService storeScopeService;
/// 查询客户登记每日统计,可同时支撑登记趋势和登记事件结构图表 /// 查询客户登记每日统计,可同时支撑登记趋势和登记事件结构图表
@AOPLog @AOPLog
@@ -36,8 +33,6 @@ public class GaoCustomerChartController {
@RequireGaoPermission(GaoPermissionCode.STAT_READ) @RequireGaoPermission(GaoPermissionCode.STAT_READ)
@PostMapping("/event/record/daily") @PostMapping("/event/record/daily")
public List<GaoEventRecordDailyStatView> eventRecordDaily(@RequestBody GaoCustomerChartReq req) { public List<GaoEventRecordDailyStatView> eventRecordDaily(@RequestBody GaoCustomerChartReq req) {
TimiException.required(req, "not found req");
req.setStoreId(storeScopeService.resolveStoreId(req.getStoreId()));
return service.eventRecordDailyStat(req); return service.eventRecordDailyStat(req);
} }
@@ -47,8 +42,6 @@ public class GaoCustomerChartController {
@RequireGaoPermission(GaoPermissionCode.STAT_READ) @RequireGaoPermission(GaoPermissionCode.STAT_READ)
@PostMapping("/event/record/calendar") @PostMapping("/event/record/calendar")
public List<GaoEventRecordCalendarView> eventRecordCalendar(@RequestBody GaoCustomerChartReq req) { public List<GaoEventRecordCalendarView> eventRecordCalendar(@RequestBody GaoCustomerChartReq req) {
TimiException.required(req, "not found req");
req.setStoreId(storeScopeService.resolveStoreId(req.getStoreId()));
return service.eventRecordCalendar(req); return service.eventRecordCalendar(req);
} }
} }
@@ -1,17 +1,21 @@
package com.imyeyu.api.modules.gao.controller; package com.imyeyu.api.modules.gao.controller;
import com.fasterxml.jackson.annotation.JsonView; import com.fasterxml.jackson.annotation.JsonView;
import com.imyeyu.api.bean.ModuleCode;
import com.imyeyu.api.modules.common.entity.Attachment; import com.imyeyu.api.modules.common.entity.Attachment;
import com.imyeyu.api.modules.common.service.AttachmentService; import com.imyeyu.api.modules.common.service.AttachmentService;
import com.imyeyu.api.modules.gao.annotation.RequireGaoPermission; import com.imyeyu.api.modules.gao.annotation.RequireGaoPermission;
import com.imyeyu.api.modules.gao.bean.GaoPermissionCode; import com.imyeyu.api.modules.gao.bean.GaoPermissionCode;
import com.imyeyu.api.modules.gao.bean.GaoRoleCode;
import com.imyeyu.api.modules.gao.entity.GaoCustomer; import com.imyeyu.api.modules.gao.entity.GaoCustomer;
import com.imyeyu.api.modules.gao.service.GaoCustomerService; import com.imyeyu.api.modules.gao.service.GaoCustomerService;
import com.imyeyu.api.modules.gao.service.GaoStoreScopeService; import com.imyeyu.api.modules.gao.service.GaoStoreService;
import com.imyeyu.api.modules.gao.vo.GaoCustomerDailyStateView; import com.imyeyu.api.modules.gao.vo.GaoCustomerDailyStateView;
import com.imyeyu.api.modules.gao.vo.GaoCustomerGenderStatView; import com.imyeyu.api.modules.gao.vo.GaoCustomerGenderStatView;
import com.imyeyu.api.modules.gao.vo.GaoCustomerPage; import com.imyeyu.api.modules.gao.vo.GaoCustomerPage;
import com.imyeyu.api.modules.gao.vo.GaoCustomerTrendStateReq; import com.imyeyu.api.modules.gao.vo.GaoCustomerTrendStateReq;
import com.imyeyu.api.modules.user.service.RoleChecker;
import com.imyeyu.api.modules.user.service.UserLoginService;
import com.imyeyu.api.modules.user.service.UserService; import com.imyeyu.api.modules.user.service.UserService;
import com.imyeyu.java.TimiJava; import com.imyeyu.java.TimiJava;
import com.imyeyu.java.bean.timi.TimiException; import com.imyeyu.java.bean.timi.TimiException;
@@ -46,9 +50,11 @@ import java.util.Map;
public class GaoCustomerController { public class GaoCustomerController {
private final UserService userService; private final UserService userService;
private final RoleChecker roleChecker;
private final AttachmentService attachmentService; private final AttachmentService attachmentService;
private final GaoCustomerService service; private final GaoCustomerService service;
private final GaoStoreScopeService storeScopeService; private final GaoStoreService gaoStoreService;
private final UserLoginService userLoginService;
@AOPLog @AOPLog
@RequestRateLimit @RequestRateLimit
@@ -56,8 +62,6 @@ public class GaoCustomerController {
@PostMapping("/list") @PostMapping("/list")
@JsonView(ResponseView.Public.class) @JsonView(ResponseView.Public.class)
public PageResult<GaoCustomer> list(@RequestBody GaoCustomerPage page) { public PageResult<GaoCustomer> list(@RequestBody GaoCustomerPage page) {
TimiException.required(page, "not found page");
page.setStoreId(storeScopeService.resolveStoreId(page.getStoreId()));
PageResult<GaoCustomer> result = service.pageByQuery(page); PageResult<GaoCustomer> result = service.pageByQuery(page);
List<String> idList = result.getList().stream().map(GaoCustomer::getId).distinct().toList(); List<String> idList = result.getList().stream().map(GaoCustomer::getId).distinct().toList();
@@ -75,8 +79,6 @@ public class GaoCustomerController {
@JsonView(ResponseView.Public.class) @JsonView(ResponseView.Public.class)
public GaoCustomer detail(@RequestParam String id) { public GaoCustomer detail(@RequestParam String id) {
GaoCustomer customer = service.get(id); GaoCustomer customer = service.get(id);
TimiException.required(customer, "not found customer");
storeScopeService.checkStoreId(customer.getStoreId());
if (TimiJava.isNotEmpty(customer.getIntroducerCustomerId())) { if (TimiJava.isNotEmpty(customer.getIntroducerCustomerId())) {
GaoCustomer introducerCustomer = service.get(customer.getIntroducerCustomerId()); GaoCustomer introducerCustomer = service.get(customer.getIntroducerCustomerId());
introducerCustomer.setAttachmentList(attachmentService.listByBizId(Attachment.BizType.GAO_CUSTOMER, introducerCustomer.getId())); introducerCustomer.setAttachmentList(attachmentService.listByBizId(Attachment.BizType.GAO_CUSTOMER, introducerCustomer.getId()));
@@ -95,7 +97,9 @@ public class GaoCustomerController {
@PostMapping("/create") @PostMapping("/create")
@JsonView(ResponseView.Public.class) @JsonView(ResponseView.Public.class)
public String create(@RequestBody GaoCustomer customer) { public String create(@RequestBody GaoCustomer customer) {
customer.setStoreId(storeScopeService.resolveStoreId(customer.getStoreId())); if (!roleChecker.hasAny(ModuleCode.GAO, GaoRoleCode.GLOBAL_MANAGER.name())) {
customer.setStoreId(gaoStoreService.getByUserId(userLoginService.getRequireLoginUserId()).getId());
}
service.create(customer); service.create(customer);
return customer.getId(); return customer.getId();
} }
@@ -105,12 +109,9 @@ public class GaoCustomerController {
@RequireGaoPermission(GaoPermissionCode.CUSTOMER_UPDATE) @RequireGaoPermission(GaoPermissionCode.CUSTOMER_UPDATE)
@PostMapping("/update") @PostMapping("/update")
public void update(@RequestBody GaoCustomer customer) { public void update(@RequestBody GaoCustomer customer) {
TimiException.required(customer, "not found customer"); if (!roleChecker.hasAny(ModuleCode.GAO, GaoRoleCode.GLOBAL_MANAGER.name())) {
TimiException.required(customer.getId(), "not found customer.id"); customer.setStoreId(gaoStoreService.getByUserId(userLoginService.getRequireLoginUserId()).getId());
GaoCustomer dbCustomer = service.get(customer.getId()); }
TimiException.required(dbCustomer, "not found customer");
storeScopeService.checkStoreId(dbCustomer.getStoreId());
customer.setStoreId(dbCustomer.getStoreId());
service.updateWithAttachment(customer); service.updateWithAttachment(customer);
} }
@@ -119,9 +120,6 @@ public class GaoCustomerController {
@RequireGaoPermission(GaoPermissionCode.CUSTOMER_DELETE) @RequireGaoPermission(GaoPermissionCode.CUSTOMER_DELETE)
@PostMapping("/delete") @PostMapping("/delete")
public void delete(@RequestParam String id) { public void delete(@RequestParam String id) {
GaoCustomer customer = service.get(id);
TimiException.required(customer, "not found customer");
storeScopeService.checkStoreId(customer.getStoreId());
service.delete(id); service.delete(id);
} }
@@ -133,7 +131,6 @@ public class GaoCustomerController {
public GaoCustomer findById(@RequestParam String id) { public GaoCustomer findById(@RequestParam String id) {
GaoCustomer customer = service.get(id); GaoCustomer customer = service.get(id);
TimiException.required(customer, "not found customer"); TimiException.required(customer, "not found customer");
storeScopeService.checkStoreId(customer.getStoreId());
customer.setAttachmentList(attachmentService.listByBizId(Attachment.BizType.GAO_CUSTOMER, customer.getId())); customer.setAttachmentList(attachmentService.listByBizId(Attachment.BizType.GAO_CUSTOMER, customer.getId()));
return customer; return customer;
} }
@@ -144,7 +141,7 @@ public class GaoCustomerController {
@PostMapping("/find/code") @PostMapping("/find/code")
@JsonView(ResponseView.Public.class) @JsonView(ResponseView.Public.class)
public GaoCustomer findByCode(@RequestParam String storeId, @RequestParam String code) { public GaoCustomer findByCode(@RequestParam String storeId, @RequestParam String code) {
GaoCustomer customer = service.getByCode(storeScopeService.resolveStoreId(storeId), code); GaoCustomer customer = service.getByCode(storeId, code);
if (customer == null) { if (customer == null) {
return null; return null;
} }
@@ -158,7 +155,7 @@ public class GaoCustomerController {
@PostMapping("/find/name") @PostMapping("/find/name")
@JsonView(ResponseView.Public.class) @JsonView(ResponseView.Public.class)
public GaoCustomer findByName(@RequestParam String storeId, @RequestParam String name) { public GaoCustomer findByName(@RequestParam String storeId, @RequestParam String name) {
GaoCustomer customer = service.getByName(storeScopeService.resolveStoreId(storeId), name); GaoCustomer customer = service.getByName(storeId, name);
if (customer == null) { if (customer == null) {
return null; return null;
} }
@@ -172,12 +169,6 @@ public class GaoCustomerController {
@RequireGaoPermission(GaoPermissionCode.CUSTOMER_EXPORT) @RequireGaoPermission(GaoPermissionCode.CUSTOMER_EXPORT)
@PostMapping("/export") @PostMapping("/export")
public void export(@RequestBody Page<GaoCustomer> page) throws IOException { public void export(@RequestBody Page<GaoCustomer> page) throws IOException {
TimiException.required(page, "not found page");
if (!storeScopeService.hasGlobalScope()) {
GaoCustomer example = TimiJava.defaultIfNull(page.getEqualsExample(), new GaoCustomer());
example.setStoreId(storeScopeService.resolveStoreId(example.getStoreId()));
page.setEqualsExample(example);
}
HttpServletResponse resp = TimiSpring.getResponse(); HttpServletResponse resp = TimiSpring.getResponse();
String contentDisposition = Network.getFileDownloadHeader("客户列表-%s.xlsx".formatted(Time.serialize.format(Time.now()))); String contentDisposition = Network.getFileDownloadHeader("客户列表-%s.xlsx".formatted(Time.serialize.format(Time.now())));
resp.setContentType("application/vnd.openxmlformats-officedocument.spreadsheetml.sheet"); resp.setContentType("application/vnd.openxmlformats-officedocument.spreadsheetml.sheet");
@@ -191,9 +182,6 @@ public class GaoCustomerController {
@PostMapping("/invited/list") @PostMapping("/invited/list")
@JsonView(ResponseView.Public.class) @JsonView(ResponseView.Public.class)
public List<GaoCustomer> listInvited(@RequestParam String introducerCustomerId) { public List<GaoCustomer> listInvited(@RequestParam String introducerCustomerId) {
GaoCustomer introducerCustomer = service.get(introducerCustomerId);
TimiException.required(introducerCustomer, "not found introducerCustomer");
storeScopeService.checkStoreId(introducerCustomer.getStoreId());
List<GaoCustomer> result = service.listInvited(introducerCustomerId); List<GaoCustomer> result = service.listInvited(introducerCustomerId);
List<String> idList = result.stream().map(GaoCustomer::getId).distinct().toList(); List<String> idList = result.stream().map(GaoCustomer::getId).distinct().toList();
Map<String, List<Attachment>> attachMap = attachmentService.mapByBizIdList(Attachment.BizType.GAO_CUSTOMER, idList); Map<String, List<Attachment>> attachMap = attachmentService.mapByBizIdList(Attachment.BizType.GAO_CUSTOMER, idList);
@@ -208,9 +196,6 @@ public class GaoCustomerController {
@RequireGaoPermission(GaoPermissionCode.CUSTOMER_UPDATE) @RequireGaoPermission(GaoPermissionCode.CUSTOMER_UPDATE)
@PostMapping("/invite/save") @PostMapping("/invite/save")
public void saveInvite(@RequestParam String introducerCustomerId, @RequestParam String customerId) { public void saveInvite(@RequestParam String introducerCustomerId, @RequestParam String customerId) {
GaoCustomer customer = service.get(customerId);
TimiException.required(customer, "not found customer");
storeScopeService.checkStoreId(customer.getStoreId());
service.saveInviteRelation(introducerCustomerId, customerId); service.saveInviteRelation(introducerCustomerId, customerId);
} }
@@ -219,9 +204,6 @@ public class GaoCustomerController {
@RequireGaoPermission(GaoPermissionCode.CUSTOMER_UPDATE) @RequireGaoPermission(GaoPermissionCode.CUSTOMER_UPDATE)
@PostMapping("/invite/delete") @PostMapping("/invite/delete")
public void deleteInvite(@RequestParam String customerId) { public void deleteInvite(@RequestParam String customerId) {
GaoCustomer customer = service.get(customerId);
TimiException.required(customer, "not found customer");
storeScopeService.checkStoreId(customer.getStoreId());
service.deleteInviteRelation(customerId); service.deleteInviteRelation(customerId);
} }
@@ -231,8 +213,6 @@ public class GaoCustomerController {
@RequireGaoPermission(GaoPermissionCode.CUSTOMER_READ) @RequireGaoPermission(GaoPermissionCode.CUSTOMER_READ)
@PostMapping("/state/daily") @PostMapping("/state/daily")
public List<GaoCustomerDailyStateView> dailyStat(@RequestBody GaoCustomerTrendStateReq req) { public List<GaoCustomerDailyStateView> dailyStat(@RequestBody GaoCustomerTrendStateReq req) {
TimiException.required(req, "not found req");
req.setStoreId(storeScopeService.resolveStoreId(req.getStoreId()));
return service.stateDailyTrend(req); return service.stateDailyTrend(req);
} }
@@ -242,6 +222,6 @@ public class GaoCustomerController {
@RequireGaoPermission(GaoPermissionCode.CUSTOMER_READ) @RequireGaoPermission(GaoPermissionCode.CUSTOMER_READ)
@PostMapping("/state/gender") @PostMapping("/state/gender")
public List<GaoCustomerGenderStatView> genderStat(@RequestParam String storeId) { public List<GaoCustomerGenderStatView> genderStat(@RequestParam String storeId) {
return service.stateGender(storeScopeService.resolveStoreId(storeId)); return service.stateGender(storeId);
} }
} }
@@ -1,12 +1,14 @@
package com.imyeyu.api.modules.gao.controller; package com.imyeyu.api.modules.gao.controller;
import com.imyeyu.api.bean.ModuleCode;
import com.imyeyu.api.modules.gao.annotation.RequireGaoPermission; import com.imyeyu.api.modules.gao.annotation.RequireGaoPermission;
import com.imyeyu.api.modules.gao.bean.GaoPermissionCode; import com.imyeyu.api.modules.gao.bean.GaoPermissionCode;
import com.imyeyu.api.modules.gao.bean.GaoRoleCode;
import com.imyeyu.api.modules.gao.entity.GaoEvent; import com.imyeyu.api.modules.gao.entity.GaoEvent;
import com.imyeyu.api.modules.gao.service.GaoEventService; import com.imyeyu.api.modules.gao.service.GaoEventService;
import com.imyeyu.api.modules.gao.service.GaoStoreScopeService; import com.imyeyu.api.modules.gao.service.GaoStoreService;
import com.imyeyu.java.TimiJava; import com.imyeyu.api.modules.user.service.RoleChecker;
import com.imyeyu.java.bean.timi.TimiException; import com.imyeyu.api.modules.user.service.UserLoginService;
import com.imyeyu.spring.annotation.AOPLog; import com.imyeyu.spring.annotation.AOPLog;
import com.imyeyu.spring.annotation.RequestRateLimit; import com.imyeyu.spring.annotation.RequestRateLimit;
import com.imyeyu.spring.bean.Page; import com.imyeyu.spring.bean.Page;
@@ -31,19 +33,15 @@ import java.util.Map;
public class GaoEventController { public class GaoEventController {
private final GaoEventService service; private final GaoEventService service;
private final GaoStoreScopeService storeScopeService; private final RoleChecker roleChecker;
private final GaoStoreService gaoStoreService;
private final UserLoginService userLoginService;
@AOPLog @AOPLog
@RequestRateLimit @RequestRateLimit
@RequireGaoPermission(GaoPermissionCode.EVENT_READ) @RequireGaoPermission(GaoPermissionCode.EVENT_READ)
@PostMapping("/list") @PostMapping("/list")
public PageResult<GaoEvent> list(@RequestBody Page<GaoEvent> page) { public PageResult<GaoEvent> list(@RequestBody Page<GaoEvent> page) {
TimiException.required(page, "not found page");
if (!storeScopeService.hasGlobalScope()) {
GaoEvent example = TimiJava.defaultIfNull(page.getEqualsExample(), new GaoEvent());
example.setStoreId(storeScopeService.resolveStoreId(example.getStoreId()));
page.setEqualsExample(example);
}
PageResult<GaoEvent> result = service.page(page); PageResult<GaoEvent> result = service.page(page);
Map<String, List<String>> roleMap = service.mapRoleCodeListByEventIdList(result.getList().stream().map(GaoEvent::getId).toList()); Map<String, List<String>> roleMap = service.mapRoleCodeListByEventIdList(result.getList().stream().map(GaoEvent::getId).toList());
for (GaoEvent event : result.getList()) { for (GaoEvent event : result.getList()) {
@@ -54,10 +52,9 @@ public class GaoEventController {
@AOPLog @AOPLog
@RequestRateLimit @RequestRateLimit
@RequireGaoPermission(GaoPermissionCode.EVENT_READ)
@PostMapping("/list/valid") @PostMapping("/list/valid")
public List<GaoEvent> listValid(@RequestParam String storeId) { public List<GaoEvent> listValid(@RequestParam String storeId) {
return service.listValid(storeScopeService.resolveStoreId(storeId)); return service.listValid(storeId);
} }
@AOPLog @AOPLog
@@ -66,8 +63,6 @@ public class GaoEventController {
@PostMapping("/detail") @PostMapping("/detail")
public GaoEvent detail(@RequestParam String id) { public GaoEvent detail(@RequestParam String id) {
GaoEvent event = service.get(id); GaoEvent event = service.get(id);
TimiException.required(event, "not found event");
storeScopeService.checkStoreId(event.getStoreId());
event.setRoleCodeList(service.listRoleCode(event.getId())); event.setRoleCodeList(service.listRoleCode(event.getId()));
return event; return event;
} }
@@ -77,7 +72,9 @@ public class GaoEventController {
@RequireGaoPermission(GaoPermissionCode.EVENT_CREATE) @RequireGaoPermission(GaoPermissionCode.EVENT_CREATE)
@PostMapping("/create") @PostMapping("/create")
public void create(@RequestBody GaoEvent event) { public void create(@RequestBody GaoEvent event) {
event.setStoreId(storeScopeService.resolveStoreId(event.getStoreId())); if (!roleChecker.hasAny(ModuleCode.GAO, GaoRoleCode.GLOBAL_MANAGER.name())) {
event.setStoreId(gaoStoreService.getByUserId(userLoginService.getRequireLoginUserId()).getId());
}
service.create(event); service.create(event);
} }
@@ -86,12 +83,9 @@ public class GaoEventController {
@RequireGaoPermission(GaoPermissionCode.EVENT_UPDATE) @RequireGaoPermission(GaoPermissionCode.EVENT_UPDATE)
@PostMapping("/update") @PostMapping("/update")
public void update(@RequestBody GaoEvent event) { public void update(@RequestBody GaoEvent event) {
TimiException.required(event, "not found event"); if (!roleChecker.hasAny(ModuleCode.GAO, GaoRoleCode.GLOBAL_MANAGER.name())) {
TimiException.required(event.getId(), "not found event.id"); event.setStoreId(gaoStoreService.getByUserId(userLoginService.getRequireLoginUserId()).getId());
GaoEvent dbEvent = service.get(event.getId()); }
TimiException.required(dbEvent, "not found event");
storeScopeService.checkStoreId(dbEvent.getStoreId());
event.setStoreId(dbEvent.getStoreId());
service.update(event); service.update(event);
} }
@@ -100,11 +94,6 @@ public class GaoEventController {
@RequireGaoPermission(GaoPermissionCode.EVENT_UPDATE) @RequireGaoPermission(GaoPermissionCode.EVENT_UPDATE)
@PostMapping("/sort") @PostMapping("/sort")
public void sort(@RequestBody List<String> idList) { public void sort(@RequestBody List<String> idList) {
for (String id : TimiJava.safeIterable(idList)) {
GaoEvent event = service.get(id);
TimiException.required(event, "not found event");
storeScopeService.checkStoreId(event.getStoreId());
}
service.sort(idList); service.sort(idList);
} }
@@ -113,9 +102,6 @@ public class GaoEventController {
@RequireGaoPermission(GaoPermissionCode.EVENT_DELETE) @RequireGaoPermission(GaoPermissionCode.EVENT_DELETE)
@PostMapping("/delete") @PostMapping("/delete")
public void delete(@RequestParam String id) { public void delete(@RequestParam String id) {
GaoEvent event = service.get(id);
TimiException.required(event, "not found event");
storeScopeService.checkStoreId(event.getStoreId());
service.delete(id); service.delete(id);
} }
} }
@@ -1,24 +1,27 @@
package com.imyeyu.api.modules.gao.controller; package com.imyeyu.api.modules.gao.controller;
import com.fasterxml.jackson.annotation.JsonView; import com.fasterxml.jackson.annotation.JsonView;
import com.imyeyu.api.bean.ModuleCode;
import com.imyeyu.api.modules.common.entity.Attachment; import com.imyeyu.api.modules.common.entity.Attachment;
import com.imyeyu.api.modules.common.service.AttachmentService; import com.imyeyu.api.modules.common.service.AttachmentService;
import com.imyeyu.api.modules.gao.annotation.RequireGaoPermission; import com.imyeyu.api.modules.gao.annotation.RequireGaoPermission;
import com.imyeyu.api.modules.gao.bean.GaoPermissionCode; import com.imyeyu.api.modules.gao.bean.GaoPermissionCode;
import com.imyeyu.api.modules.gao.bean.GaoRoleCode;
import com.imyeyu.api.modules.gao.entity.GaoCustomer; import com.imyeyu.api.modules.gao.entity.GaoCustomer;
import com.imyeyu.api.modules.gao.entity.GaoEvent; import com.imyeyu.api.modules.gao.entity.GaoEvent;
import com.imyeyu.api.modules.gao.entity.GaoEventRecord; import com.imyeyu.api.modules.gao.entity.GaoEventRecord;
import com.imyeyu.api.modules.gao.service.GaoCustomerService; import com.imyeyu.api.modules.gao.service.GaoCustomerService;
import com.imyeyu.api.modules.gao.service.GaoEventRecordService; import com.imyeyu.api.modules.gao.service.GaoEventRecordService;
import com.imyeyu.api.modules.gao.service.GaoEventService; import com.imyeyu.api.modules.gao.service.GaoEventService;
import com.imyeyu.api.modules.gao.service.GaoStoreScopeService; import com.imyeyu.api.modules.gao.service.GaoStoreService;
import com.imyeyu.api.modules.gao.vo.GaoCustomerEventRankView; import com.imyeyu.api.modules.gao.vo.GaoCustomerEventRankView;
import com.imyeyu.api.modules.gao.vo.GaoEventRecordPage; import com.imyeyu.api.modules.gao.vo.GaoEventRecordPage;
import com.imyeyu.api.modules.gao.vo.GaoEventRecordPageResult; import com.imyeyu.api.modules.gao.vo.GaoEventRecordPageResult;
import com.imyeyu.api.modules.gao.vo.GaoEventRecordRankPage; import com.imyeyu.api.modules.gao.vo.GaoEventRecordRankPage;
import com.imyeyu.api.modules.user.service.RoleChecker;
import com.imyeyu.api.modules.user.service.UserLoginService;
import com.imyeyu.api.modules.user.service.UserService; import com.imyeyu.api.modules.user.service.UserService;
import com.imyeyu.java.TimiJava; import com.imyeyu.java.TimiJava;
import com.imyeyu.java.bean.timi.TimiException;
import com.imyeyu.network.Network; import com.imyeyu.network.Network;
import com.imyeyu.spring.TimiSpring; import com.imyeyu.spring.TimiSpring;
import com.imyeyu.spring.annotation.AOPLog; import com.imyeyu.spring.annotation.AOPLog;
@@ -49,11 +52,13 @@ import java.util.Map;
public class GaoEventRecordController { public class GaoEventRecordController {
private final UserService userService; private final UserService userService;
private final RoleChecker roleChecker;
private final GaoEventService eventService; private final GaoEventService eventService;
private final AttachmentService attachmentService; private final AttachmentService attachmentService;
private final GaoCustomerService customerService; private final GaoCustomerService customerService;
private final GaoStoreScopeService storeScopeService; private final GaoStoreService gaoStoreService;
private final GaoEventRecordService service; private final GaoEventRecordService service;
private final UserLoginService userLoginService;
@AOPLog @AOPLog
@RequestRateLimit @RequestRateLimit
@@ -61,8 +66,6 @@ public class GaoEventRecordController {
@PostMapping("/list") @PostMapping("/list")
@JsonView(ResponseView.Public.class) @JsonView(ResponseView.Public.class)
public GaoEventRecordPageResult list(@RequestBody GaoEventRecordPage page) { public GaoEventRecordPageResult list(@RequestBody GaoEventRecordPage page) {
TimiException.required(page, "not found page");
page.setStoreId(storeScopeService.resolveStoreId(page.getStoreId()));
PageResult<GaoEventRecord> pageResult = service.pageByRange(page); PageResult<GaoEventRecord> pageResult = service.pageByRange(page);
GaoEventRecordPageResult result = new GaoEventRecordPageResult(); GaoEventRecordPageResult result = new GaoEventRecordPageResult();
result.setTotal(pageResult.getTotal()); result.setTotal(pageResult.getTotal());
@@ -105,8 +108,6 @@ public class GaoEventRecordController {
@JsonView(ResponseView.Public.class) @JsonView(ResponseView.Public.class)
public GaoEventRecord detail(@RequestParam String id) { public GaoEventRecord detail(@RequestParam String id) {
GaoEventRecord record = service.get(id); GaoEventRecord record = service.get(id);
TimiException.required(record, "not found event record");
storeScopeService.checkStoreId(record.getStoreId());
record.setCustomer(customerService.get(record.getCustomerId())); record.setCustomer(customerService.get(record.getCustomerId()));
record.getCustomer().setAttachmentList(attachmentService.listByBizId(Attachment.BizType.GAO_CUSTOMER, record.getCustomerId())); record.getCustomer().setAttachmentList(attachmentService.listByBizId(Attachment.BizType.GAO_CUSTOMER, record.getCustomerId()));
record.setEvent(eventService.get(record.getEventId())); record.setEvent(eventService.get(record.getEventId()));
@@ -120,7 +121,9 @@ public class GaoEventRecordController {
@RequireGaoPermission(GaoPermissionCode.EVENT_RECORD_CREATE) @RequireGaoPermission(GaoPermissionCode.EVENT_RECORD_CREATE)
@PostMapping("/create") @PostMapping("/create")
public void create(@RequestBody GaoEventRecord record) { public void create(@RequestBody GaoEventRecord record) {
resolveCreateRecordStore(record); if (!roleChecker.hasAny(ModuleCode.GAO, GaoRoleCode.GLOBAL_MANAGER.name())) {
record.setStoreId(gaoStoreService.getByUserId(userLoginService.getRequireLoginUserId()).getId());
}
service.create(record); service.create(record);
} }
@@ -129,8 +132,11 @@ public class GaoEventRecordController {
@RequireGaoPermission(GaoPermissionCode.EVENT_RECORD_CREATE) @RequireGaoPermission(GaoPermissionCode.EVENT_RECORD_CREATE)
@PostMapping("/create/batch") @PostMapping("/create/batch")
public void createBatch(@RequestBody List<GaoEventRecord> recordList) { public void createBatch(@RequestBody List<GaoEventRecord> recordList) {
for (GaoEventRecord record : TimiJava.safeIterable(recordList)) { if (!roleChecker.hasAny(ModuleCode.GAO, GaoRoleCode.GLOBAL_MANAGER.name())) {
resolveCreateRecordStore(record); String storeId = gaoStoreService.getBelongIdByRequiredLoginUserId();
for (GaoEventRecord record : recordList) {
record.setStoreId(storeId);
}
} }
service.createBatch(recordList); service.createBatch(recordList);
} }
@@ -140,17 +146,11 @@ public class GaoEventRecordController {
@RequireGaoPermission(GaoPermissionCode.EVENT_RECORD_CREATE) @RequireGaoPermission(GaoPermissionCode.EVENT_RECORD_CREATE)
@PostMapping("/create/customer") @PostMapping("/create/customer")
public void createWithCustomer(@RequestBody GaoCustomer customer) { public void createWithCustomer(@RequestBody GaoCustomer customer) {
TimiException.required(customer, "not found customer"); if (!roleChecker.hasAny(ModuleCode.GAO, GaoRoleCode.GLOBAL_MANAGER.name())) {
if (TimiJava.isNotEmpty(customer.getId())) { String storeId = gaoStoreService.getBelongIdByRequiredLoginUserId();
GaoCustomer dbCustomer = customerService.get(customer.getId()); for (GaoEventRecord record : TimiJava.safeIterable(customer.getEventRecordList())) {
TimiException.required(dbCustomer, "not found customer"); record.setStoreId(storeId);
storeScopeService.checkStoreId(dbCustomer.getStoreId()); }
customer.setStoreId(dbCustomer.getStoreId());
} else {
customer.setStoreId(storeScopeService.resolveStoreId(customer.getStoreId()));
}
for (GaoEventRecord record : TimiJava.safeIterable(customer.getEventRecordList())) {
resolveCreateRecordStore(record);
} }
service.createWithCustomer(customer); service.createWithCustomer(customer);
} }
@@ -160,12 +160,9 @@ public class GaoEventRecordController {
@RequireGaoPermission(GaoPermissionCode.EVENT_RECORD_UPDATE) @RequireGaoPermission(GaoPermissionCode.EVENT_RECORD_UPDATE)
@PostMapping("/update") @PostMapping("/update")
public void update(@RequestBody GaoEventRecord record) { public void update(@RequestBody GaoEventRecord record) {
TimiException.required(record, "not found event record"); if (!roleChecker.hasAny(ModuleCode.GAO, GaoRoleCode.GLOBAL_MANAGER.name())) {
TimiException.required(record.getId(), "not found event record.id"); record.setStoreId(gaoStoreService.getBelongIdByRequiredLoginUserId());
GaoEventRecord dbRecord = service.get(record.getId()); }
TimiException.required(dbRecord, "not found event record");
storeScopeService.checkStoreId(dbRecord.getStoreId());
record.setStoreId(dbRecord.getStoreId());
service.update(record); service.update(record);
} }
@@ -174,9 +171,6 @@ public class GaoEventRecordController {
@RequireGaoPermission(GaoPermissionCode.EVENT_RECORD_DELETE) @RequireGaoPermission(GaoPermissionCode.EVENT_RECORD_DELETE)
@PostMapping("/delete") @PostMapping("/delete")
public void delete(@RequestParam String id) { public void delete(@RequestParam String id) {
GaoEventRecord record = service.get(id);
TimiException.required(record, "not found event record");
storeScopeService.checkStoreId(record.getStoreId());
service.delete(id); service.delete(id);
} }
@@ -186,8 +180,6 @@ public class GaoEventRecordController {
@RequireGaoPermission(GaoPermissionCode.EVENT_RECORD_EXPORT) @RequireGaoPermission(GaoPermissionCode.EVENT_RECORD_EXPORT)
@PostMapping("/export") @PostMapping("/export")
public void export(@RequestBody GaoEventRecordPage page) throws IOException { public void export(@RequestBody GaoEventRecordPage page) throws IOException {
TimiException.required(page, "not found page");
page.setStoreId(storeScopeService.resolveStoreId(page.getStoreId()));
HttpServletResponse resp = TimiSpring.getResponse(); HttpServletResponse resp = TimiSpring.getResponse();
String contentDisposition = Network.getFileDownloadHeader("登记事件记录-%s.xlsx".formatted(Time.serialize.format(Time.now()))); String contentDisposition = Network.getFileDownloadHeader("登记事件记录-%s.xlsx".formatted(Time.serialize.format(Time.now())));
resp.setContentType("application/vnd.openxmlformats-officedocument.spreadsheetml.sheet"); resp.setContentType("application/vnd.openxmlformats-officedocument.spreadsheetml.sheet");
@@ -201,8 +193,6 @@ public class GaoEventRecordController {
@RequireGaoPermission(GaoPermissionCode.STAT_READ) @RequireGaoPermission(GaoPermissionCode.STAT_READ)
@PostMapping("/rank") @PostMapping("/rank")
public PageResult<GaoCustomerEventRankView> eventRank(@RequestBody GaoEventRecordRankPage page) { public PageResult<GaoCustomerEventRankView> eventRank(@RequestBody GaoEventRecordRankPage page) {
TimiException.required(page, "not found page");
page.setStoreId(storeScopeService.resolveStoreId(page.getStoreId()));
PageResult<GaoCustomerEventRankView> result = service.pageRankByRange(page); PageResult<GaoCustomerEventRankView> result = service.pageRankByRange(page);
List<String> customerIdList = result.getList().stream().map(GaoCustomerEventRankView::getCustomerId).distinct().toList(); List<String> customerIdList = result.getList().stream().map(GaoCustomerEventRankView::getCustomerId).distinct().toList();
if (customerIdList.isEmpty()) { if (customerIdList.isEmpty()) {
@@ -219,12 +209,4 @@ public class GaoEventRecordController {
} }
return result; return result;
} }
private void resolveCreateRecordStore(GaoEventRecord record) {
TimiException.required(record, "not found event record");
GaoEvent event = eventService.get(record.getEventId());
TimiException.required(event, "not found event");
storeScopeService.checkStoreId(event.getStoreId());
record.setStoreId(event.getStoreId());
}
} }
@@ -1,11 +1,14 @@
package com.imyeyu.api.modules.gao.controller; package com.imyeyu.api.modules.gao.controller;
import com.imyeyu.api.bean.ModuleCode;
import com.imyeyu.api.modules.gao.annotation.RequireGaoPermission; import com.imyeyu.api.modules.gao.annotation.RequireGaoPermission;
import com.imyeyu.api.modules.gao.bean.GaoPermissionCode; import com.imyeyu.api.modules.gao.bean.GaoPermissionCode;
import com.imyeyu.api.modules.gao.bean.GaoRoleCode;
import com.imyeyu.api.modules.gao.entity.GaoPointAccount; import com.imyeyu.api.modules.gao.entity.GaoPointAccount;
import com.imyeyu.api.modules.gao.service.GaoPointAccountService; import com.imyeyu.api.modules.gao.service.GaoPointAccountService;
import com.imyeyu.api.modules.gao.service.GaoStoreScopeService; import com.imyeyu.api.modules.gao.service.GaoStoreService;
import com.imyeyu.api.modules.gao.vo.GaoPointAccountPage; import com.imyeyu.api.modules.gao.vo.GaoPointAccountPage;
import com.imyeyu.api.modules.user.service.RoleChecker;
import com.imyeyu.java.bean.timi.TimiException; import com.imyeyu.java.bean.timi.TimiException;
import com.imyeyu.spring.annotation.AOPLog; import com.imyeyu.spring.annotation.AOPLog;
import com.imyeyu.spring.annotation.RequestRateLimit; import com.imyeyu.spring.annotation.RequestRateLimit;
@@ -26,7 +29,8 @@ import org.springframework.web.bind.annotation.RestController;
@RequestMapping("/gao/customer/point") @RequestMapping("/gao/customer/point")
public class GaoPointAccountController { public class GaoPointAccountController {
private final GaoStoreScopeService storeScopeService; private final RoleChecker roleChecker;
private final GaoStoreService storeService;
private final GaoPointAccountService accountService; private final GaoPointAccountService accountService;
@AOPLog @AOPLog
@@ -35,7 +39,7 @@ public class GaoPointAccountController {
@PostMapping("/account/list") @PostMapping("/account/list")
public PageResult<GaoPointAccount> list(@RequestBody GaoPointAccountPage page) { public PageResult<GaoPointAccount> list(@RequestBody GaoPointAccountPage page) {
TimiException.required(page, "not found page"); TimiException.required(page, "not found page");
page.setStoreId(storeScopeService.resolveStoreId(page.getStoreId())); page.setStoreId(resolveStoreId(page.getStoreId()));
return accountService.pageByQuery(page); return accountService.pageByQuery(page);
} }
@@ -44,7 +48,7 @@ public class GaoPointAccountController {
@RequireGaoPermission(GaoPermissionCode.POINT_ACCOUNT_READ) @RequireGaoPermission(GaoPermissionCode.POINT_ACCOUNT_READ)
@PostMapping("/account/detail/customer") @PostMapping("/account/detail/customer")
public GaoPointAccount detail(@RequestParam String customerId, @RequestParam(required = false) String storeId) { public GaoPointAccount detail(@RequestParam String customerId, @RequestParam(required = false) String storeId) {
storeId = storeScopeService.resolveStoreId(storeId); storeId = resolveStoreId(storeId);
return accountService.getByCustomerId(storeId, customerId); return accountService.getByCustomerId(storeId, customerId);
} }
@@ -53,6 +57,13 @@ public class GaoPointAccountController {
@RequireGaoPermission(GaoPermissionCode.POINT_ACCOUNT_READ) @RequireGaoPermission(GaoPermissionCode.POINT_ACCOUNT_READ)
@PostMapping("/account/detail") @PostMapping("/account/detail")
public GaoPointAccount detailById(@RequestParam String id, @RequestParam(required = false) String storeId) { public GaoPointAccount detailById(@RequestParam String id, @RequestParam(required = false) String storeId) {
return accountService.getByIdAndStoreId(storeScopeService.resolveStoreId(storeId), id); return accountService.getByIdAndStoreId(resolveStoreId(storeId), id);
}
private String resolveStoreId(String requestedStoreId) {
if (roleChecker.hasAny(ModuleCode.GAO, GaoRoleCode.GLOBAL_MANAGER.name())) {
return requestedStoreId;
}
return storeService.getBelongIdByRequiredLoginUserId();
} }
} }
@@ -1,13 +1,16 @@
package com.imyeyu.api.modules.gao.controller; package com.imyeyu.api.modules.gao.controller;
import com.imyeyu.api.bean.ModuleCode;
import com.imyeyu.api.modules.gao.annotation.RequireGaoPermission; import com.imyeyu.api.modules.gao.annotation.RequireGaoPermission;
import com.imyeyu.api.modules.gao.bean.GaoPermissionCode; import com.imyeyu.api.modules.gao.bean.GaoPermissionCode;
import com.imyeyu.api.modules.gao.bean.GaoRoleCode;
import com.imyeyu.api.modules.gao.entity.GaoPointLedger; import com.imyeyu.api.modules.gao.entity.GaoPointLedger;
import com.imyeyu.api.modules.gao.service.GaoPointLedgerService; import com.imyeyu.api.modules.gao.service.GaoPointLedgerService;
import com.imyeyu.api.modules.gao.service.GaoPointTriggerService; import com.imyeyu.api.modules.gao.service.GaoPointTriggerService;
import com.imyeyu.api.modules.gao.service.GaoStoreScopeService; import com.imyeyu.api.modules.gao.service.GaoStoreService;
import com.imyeyu.api.modules.gao.vo.GaoPointAdjustRequest; import com.imyeyu.api.modules.gao.vo.GaoPointAdjustRequest;
import com.imyeyu.api.modules.gao.vo.GaoPointLedgerPage; import com.imyeyu.api.modules.gao.vo.GaoPointLedgerPage;
import com.imyeyu.api.modules.user.service.RoleChecker;
import com.imyeyu.java.bean.timi.TimiException; import com.imyeyu.java.bean.timi.TimiException;
import com.imyeyu.spring.annotation.AOPLog; import com.imyeyu.spring.annotation.AOPLog;
import com.imyeyu.spring.annotation.RequestRateLimit; import com.imyeyu.spring.annotation.RequestRateLimit;
@@ -27,7 +30,8 @@ import org.springframework.web.bind.annotation.RestController;
@RequestMapping("/gao/customer/point") @RequestMapping("/gao/customer/point")
public class GaoPointLedgerController { public class GaoPointLedgerController {
private final GaoStoreScopeService storeScopeService; private final RoleChecker roleChecker;
private final GaoStoreService storeService;
private final GaoPointLedgerService ledgerService; private final GaoPointLedgerService ledgerService;
private final GaoPointTriggerService triggerService; private final GaoPointTriggerService triggerService;
@@ -37,7 +41,7 @@ public class GaoPointLedgerController {
@PostMapping("/ledger/list") @PostMapping("/ledger/list")
public PageResult<GaoPointLedger> list(@RequestBody GaoPointLedgerPage page) { public PageResult<GaoPointLedger> list(@RequestBody GaoPointLedgerPage page) {
TimiException.required(page, "not found page"); TimiException.required(page, "not found page");
page.setStoreId(storeScopeService.resolveStoreId(page.getStoreId())); page.setStoreId(resolveStoreId(page.getStoreId()));
return ledgerService.pageByQuery(page); return ledgerService.pageByQuery(page);
} }
@@ -46,7 +50,14 @@ public class GaoPointLedgerController {
@RequireGaoPermission(GaoPermissionCode.POINT_ADJUST) @RequireGaoPermission(GaoPermissionCode.POINT_ADJUST)
@PostMapping("/adjust") @PostMapping("/adjust")
public void adjust(@RequestBody GaoPointAdjustRequest request) { public void adjust(@RequestBody GaoPointAdjustRequest request) {
request.setStoreId(storeScopeService.resolveStoreId(request.getStoreId())); request.setStoreId(resolveStoreId(request.getStoreId()));
triggerService.adjust(request); triggerService.adjust(request);
} }
private String resolveStoreId(String requestedStoreId) {
if (roleChecker.hasAny(ModuleCode.GAO, GaoRoleCode.GLOBAL_MANAGER.name())) {
return requestedStoreId;
}
return storeService.getBelongIdByRequiredLoginUserId();
}
} }
@@ -1,10 +1,13 @@
package com.imyeyu.api.modules.gao.controller; package com.imyeyu.api.modules.gao.controller;
import com.imyeyu.api.bean.ModuleCode;
import com.imyeyu.api.modules.gao.annotation.RequireGaoPermission; import com.imyeyu.api.modules.gao.annotation.RequireGaoPermission;
import com.imyeyu.api.modules.gao.bean.GaoPermissionCode; import com.imyeyu.api.modules.gao.bean.GaoPermissionCode;
import com.imyeyu.api.modules.gao.bean.GaoRoleCode;
import com.imyeyu.api.modules.gao.entity.GaoPointRule; import com.imyeyu.api.modules.gao.entity.GaoPointRule;
import com.imyeyu.api.modules.gao.service.GaoPointRuleService; import com.imyeyu.api.modules.gao.service.GaoPointRuleService;
import com.imyeyu.api.modules.gao.service.GaoStoreScopeService; import com.imyeyu.api.modules.gao.service.GaoStoreService;
import com.imyeyu.api.modules.user.service.RoleChecker;
import com.imyeyu.java.TimiJava; import com.imyeyu.java.TimiJava;
import com.imyeyu.java.bean.timi.TimiException; import com.imyeyu.java.bean.timi.TimiException;
import com.imyeyu.spring.annotation.AOPLog; import com.imyeyu.spring.annotation.AOPLog;
@@ -29,7 +32,8 @@ import java.util.List;
@RequestMapping("/gao/customer/point") @RequestMapping("/gao/customer/point")
public class GaoPointRuleController { public class GaoPointRuleController {
private final GaoStoreScopeService storeScopeService; private final RoleChecker roleChecker;
private final GaoStoreService storeService;
private final GaoPointRuleService ruleService; private final GaoPointRuleService ruleService;
@AOPLog @AOPLog
@@ -38,9 +42,9 @@ public class GaoPointRuleController {
@PostMapping("/rule/list") @PostMapping("/rule/list")
public PageResult<GaoPointRule> list(@RequestBody Page<GaoPointRule> page) { public PageResult<GaoPointRule> list(@RequestBody Page<GaoPointRule> page) {
TimiException.required(page, "not found page"); TimiException.required(page, "not found page");
if (!storeScopeService.hasGlobalScope()) { if (!isGlobalManager()) {
GaoPointRule example = TimiJava.defaultIfNull(page.getEqualsExample(), new GaoPointRule()); GaoPointRule example = TimiJava.defaultIfNull(page.getEqualsExample(), new GaoPointRule());
example.setStoreId(storeScopeService.resolveStoreId(example.getStoreId())); example.setStoreId(resolveStoreId(null));
page.setEqualsExample(example); page.setEqualsExample(example);
} }
return ruleService.page(page); return ruleService.page(page);
@@ -53,7 +57,7 @@ public class GaoPointRuleController {
public GaoPointRule detail(@RequestParam String id) { public GaoPointRule detail(@RequestParam String id) {
GaoPointRule rule = ruleService.get(id); GaoPointRule rule = ruleService.get(id);
TimiException.required(rule, "not found point rule"); TimiException.required(rule, "not found point rule");
storeScopeService.checkStoreId(rule.getStoreId()); checkStore(rule.getStoreId());
return rule; return rule;
} }
@@ -62,7 +66,7 @@ public class GaoPointRuleController {
@RequireGaoPermission(GaoPermissionCode.POINT_RULE_CREATE) @RequireGaoPermission(GaoPermissionCode.POINT_RULE_CREATE)
@PostMapping("/rule/create") @PostMapping("/rule/create")
public String create(@RequestBody GaoPointRule rule) { public String create(@RequestBody GaoPointRule rule) {
rule.setStoreId(storeScopeService.resolveStoreId(rule.getStoreId())); rule.setStoreId(resolveStoreId(rule.getStoreId()));
ruleService.create(rule); ruleService.create(rule);
return rule.getId(); return rule.getId();
} }
@@ -72,7 +76,7 @@ public class GaoPointRuleController {
@RequireGaoPermission(GaoPermissionCode.POINT_RULE_UPDATE) @RequireGaoPermission(GaoPermissionCode.POINT_RULE_UPDATE)
@PostMapping("/rule/update") @PostMapping("/rule/update")
public void update(@RequestBody GaoPointRule rule) { public void update(@RequestBody GaoPointRule rule) {
rule.setStoreId(storeScopeService.resolveStoreId(rule.getStoreId())); rule.setStoreId(resolveStoreId(rule.getStoreId()));
ruleService.update(rule); ruleService.update(rule);
} }
@@ -83,7 +87,7 @@ public class GaoPointRuleController {
public void sort(@RequestBody List<String> idList) { public void sort(@RequestBody List<String> idList) {
if (idList != null) { if (idList != null) {
for (GaoPointRule rule : ruleService.listByIdList(idList)) { for (GaoPointRule rule : ruleService.listByIdList(idList)) {
storeScopeService.checkStoreId(rule.getStoreId()); checkStore(rule.getStoreId());
} }
} }
ruleService.sort(idList); ruleService.sort(idList);
@@ -96,7 +100,24 @@ public class GaoPointRuleController {
public void delete(@RequestParam String id) { public void delete(@RequestParam String id) {
GaoPointRule rule = ruleService.get(id); GaoPointRule rule = ruleService.get(id);
TimiException.required(rule, "not found point rule"); TimiException.required(rule, "not found point rule");
storeScopeService.checkStoreId(rule.getStoreId()); checkStore(rule.getStoreId());
ruleService.delete(id); ruleService.delete(id);
} }
private String resolveStoreId(String requestedStoreId) {
if (isGlobalManager()) {
return requestedStoreId;
}
return storeService.getBelongIdByRequiredLoginUserId();
}
private void checkStore(String storeId) {
if (!isGlobalManager()) {
TimiException.requiredTrue(resolveStoreId(null).equals(storeId), "无权操作其他门店数据");
}
}
private boolean isGlobalManager() {
return roleChecker.hasAny(ModuleCode.GAO, GaoRoleCode.GLOBAL_MANAGER.name());
}
} }
@@ -4,9 +4,6 @@ import com.imyeyu.api.modules.gao.annotation.RequireGaoPermission;
import com.imyeyu.api.modules.gao.bean.GaoPermissionCode; import com.imyeyu.api.modules.gao.bean.GaoPermissionCode;
import com.imyeyu.api.modules.gao.entity.GaoStoreBusinessDay; import com.imyeyu.api.modules.gao.entity.GaoStoreBusinessDay;
import com.imyeyu.api.modules.gao.service.GaoStoreBusinessDayService; import com.imyeyu.api.modules.gao.service.GaoStoreBusinessDayService;
import com.imyeyu.api.modules.gao.service.GaoStoreScopeService;
import com.imyeyu.java.TimiJava;
import com.imyeyu.java.bean.timi.TimiException;
import com.imyeyu.spring.annotation.AOPLog; import com.imyeyu.spring.annotation.AOPLog;
import com.imyeyu.spring.annotation.RequestRateLimit; import com.imyeyu.spring.annotation.RequestRateLimit;
import com.imyeyu.spring.bean.Page; import com.imyeyu.spring.bean.Page;
@@ -30,17 +27,12 @@ import java.util.List;
public class GaoStoreBusinessDayController { public class GaoStoreBusinessDayController {
private final GaoStoreBusinessDayService service; private final GaoStoreBusinessDayService service;
private final GaoStoreScopeService storeScopeService;
@AOPLog @AOPLog
@RequestRateLimit @RequestRateLimit
@RequireGaoPermission(GaoPermissionCode.STORE_READ) @RequireGaoPermission(GaoPermissionCode.STORE_READ)
@PostMapping("/list") @PostMapping("/list")
public PageResult<GaoStoreBusinessDay> list(@RequestBody Page<GaoStoreBusinessDay> page) { public PageResult<GaoStoreBusinessDay> list(@RequestBody Page<GaoStoreBusinessDay> page) {
TimiException.required(page, "not found page");
GaoStoreBusinessDay example = TimiJava.defaultIfNull(page.getEqualsExample(), new GaoStoreBusinessDay());
example.setStoreId(storeScopeService.resolveStoreId(example.getStoreId()));
page.setEqualsExample(example);
return service.page(page); return service.page(page);
} }
@@ -49,7 +41,7 @@ public class GaoStoreBusinessDayController {
@RequireGaoPermission(GaoPermissionCode.STORE_READ) @RequireGaoPermission(GaoPermissionCode.STORE_READ)
@PostMapping("/calendar") @PostMapping("/calendar")
public List<GaoStoreBusinessDay> calendar(@RequestParam String storeId, @RequestParam Integer beginDateValue, @RequestParam Integer endDateValue) { public List<GaoStoreBusinessDay> calendar(@RequestParam String storeId, @RequestParam Integer beginDateValue, @RequestParam Integer endDateValue) {
return service.listByDateRange(storeScopeService.resolveStoreId(storeId), beginDateValue, endDateValue); return service.listByDateRange(storeId, beginDateValue, endDateValue);
} }
@AOPLog @AOPLog
@@ -57,10 +49,7 @@ public class GaoStoreBusinessDayController {
@RequireGaoPermission(GaoPermissionCode.STORE_READ) @RequireGaoPermission(GaoPermissionCode.STORE_READ)
@PostMapping("/detail") @PostMapping("/detail")
public GaoStoreBusinessDay detail(@RequestParam String id) { public GaoStoreBusinessDay detail(@RequestParam String id) {
GaoStoreBusinessDay businessDay = service.get(id); return service.get(id);
TimiException.required(businessDay, "not found businessDay");
storeScopeService.checkStoreId(businessDay.getStoreId());
return businessDay;
} }
@AOPLog @AOPLog
@@ -68,7 +57,6 @@ public class GaoStoreBusinessDayController {
@RequireGaoPermission(GaoPermissionCode.STORE_UPDATE) @RequireGaoPermission(GaoPermissionCode.STORE_UPDATE)
@PostMapping("/create") @PostMapping("/create")
public String create(@RequestBody GaoStoreBusinessDay businessDay) { public String create(@RequestBody GaoStoreBusinessDay businessDay) {
businessDay.setStoreId(storeScopeService.resolveStoreId(businessDay.getStoreId()));
service.create(businessDay); service.create(businessDay);
return businessDay.getId(); return businessDay.getId();
} }
@@ -78,12 +66,6 @@ public class GaoStoreBusinessDayController {
@RequireGaoPermission(GaoPermissionCode.STORE_UPDATE) @RequireGaoPermission(GaoPermissionCode.STORE_UPDATE)
@PostMapping("/update") @PostMapping("/update")
public void update(@RequestBody GaoStoreBusinessDay businessDay) { public void update(@RequestBody GaoStoreBusinessDay businessDay) {
TimiException.required(businessDay, "not found businessDay");
TimiException.required(businessDay.getId(), "not found businessDay.id");
GaoStoreBusinessDay dbBusinessDay = service.get(businessDay.getId());
TimiException.required(dbBusinessDay, "not found businessDay");
storeScopeService.checkStoreId(dbBusinessDay.getStoreId());
businessDay.setStoreId(dbBusinessDay.getStoreId());
service.update(businessDay); service.update(businessDay);
} }
@@ -92,9 +74,6 @@ public class GaoStoreBusinessDayController {
@RequireGaoPermission(GaoPermissionCode.STORE_DELETE) @RequireGaoPermission(GaoPermissionCode.STORE_DELETE)
@PostMapping("/delete") @PostMapping("/delete")
public void delete(@RequestParam String id) { public void delete(@RequestParam String id) {
GaoStoreBusinessDay businessDay = service.get(id);
TimiException.required(businessDay, "not found businessDay");
storeScopeService.checkStoreId(businessDay.getStoreId());
service.delete(id); service.delete(id);
} }
} }
@@ -3,14 +3,12 @@ package com.imyeyu.api.modules.gao.controller;
import com.imyeyu.api.modules.gao.annotation.RequireGaoPermission; import com.imyeyu.api.modules.gao.annotation.RequireGaoPermission;
import com.imyeyu.api.modules.gao.bean.GaoPermissionCode; import com.imyeyu.api.modules.gao.bean.GaoPermissionCode;
import com.imyeyu.api.modules.gao.service.GaoStoreChartService; import com.imyeyu.api.modules.gao.service.GaoStoreChartService;
import com.imyeyu.api.modules.gao.service.GaoStoreScopeService;
import com.imyeyu.api.modules.gao.vo.GaoCustomerDailyStateView; import com.imyeyu.api.modules.gao.vo.GaoCustomerDailyStateView;
import com.imyeyu.api.modules.gao.vo.GaoCustomerGenderStatView; import com.imyeyu.api.modules.gao.vo.GaoCustomerGenderStatView;
import com.imyeyu.api.modules.gao.vo.GaoEventRecordCalendarView; import com.imyeyu.api.modules.gao.vo.GaoEventRecordCalendarView;
import com.imyeyu.api.modules.gao.vo.GaoEventRecordDailyStatView; import com.imyeyu.api.modules.gao.vo.GaoEventRecordDailyStatView;
import com.imyeyu.api.modules.gao.vo.GaoEventRecordNumberValueDailyStatView; import com.imyeyu.api.modules.gao.vo.GaoEventRecordNumberValueDailyStatView;
import com.imyeyu.api.modules.gao.vo.GaoStoreChartReq; import com.imyeyu.api.modules.gao.vo.GaoStoreChartReq;
import com.imyeyu.java.bean.timi.TimiException;
import com.imyeyu.spring.annotation.AOPLog; import com.imyeyu.spring.annotation.AOPLog;
import com.imyeyu.spring.annotation.RequestRateLimit; import com.imyeyu.spring.annotation.RequestRateLimit;
import lombok.RequiredArgsConstructor; import lombok.RequiredArgsConstructor;
@@ -32,7 +30,6 @@ import java.util.List;
public class GaoStoreChartController { public class GaoStoreChartController {
private final GaoStoreChartService service; private final GaoStoreChartService service;
private final GaoStoreScopeService storeScopeService;
/// 查询客户增长趋势 /// 查询客户增长趋势
@AOPLog @AOPLog
@@ -40,8 +37,6 @@ public class GaoStoreChartController {
@RequireGaoPermission(GaoPermissionCode.STAT_READ) @RequireGaoPermission(GaoPermissionCode.STAT_READ)
@PostMapping("/customer/daily") @PostMapping("/customer/daily")
public List<GaoCustomerDailyStateView> customerDaily(@RequestBody GaoStoreChartReq req) { public List<GaoCustomerDailyStateView> customerDaily(@RequestBody GaoStoreChartReq req) {
TimiException.required(req, "not found req");
req.setStoreId(storeScopeService.resolveStoreId(req.getStoreId()));
return service.customerDailyTrend(req); return service.customerDailyTrend(req);
} }
@@ -51,7 +46,7 @@ public class GaoStoreChartController {
@RequireGaoPermission(GaoPermissionCode.STAT_READ) @RequireGaoPermission(GaoPermissionCode.STAT_READ)
@PostMapping("/customer/gender") @PostMapping("/customer/gender")
public List<GaoCustomerGenderStatView> customerGender(@RequestParam String storeId) { public List<GaoCustomerGenderStatView> customerGender(@RequestParam String storeId) {
return service.customerGender(storeScopeService.resolveStoreId(storeId)); return service.customerGender(storeId);
} }
/// 查询登记事件每日统计,可同时支撑登记趋势和事件结构图表 /// 查询登记事件每日统计,可同时支撑登记趋势和事件结构图表
@@ -60,8 +55,6 @@ public class GaoStoreChartController {
@RequireGaoPermission(GaoPermissionCode.STAT_READ) @RequireGaoPermission(GaoPermissionCode.STAT_READ)
@PostMapping("/event/record/daily") @PostMapping("/event/record/daily")
public List<GaoEventRecordDailyStatView> eventRecordDaily(@RequestBody GaoStoreChartReq req) { public List<GaoEventRecordDailyStatView> eventRecordDaily(@RequestBody GaoStoreChartReq req) {
TimiException.required(req, "not found req");
req.setStoreId(storeScopeService.resolveStoreId(req.getStoreId()));
return service.eventRecordDailyStat(req); return service.eventRecordDailyStat(req);
} }
@@ -71,8 +64,6 @@ public class GaoStoreChartController {
@RequireGaoPermission(GaoPermissionCode.STAT_READ) @RequireGaoPermission(GaoPermissionCode.STAT_READ)
@PostMapping("/event/record/number-value/daily") @PostMapping("/event/record/number-value/daily")
public List<GaoEventRecordNumberValueDailyStatView> eventRecordNumberValueDaily(@RequestBody GaoStoreChartReq req) { public List<GaoEventRecordNumberValueDailyStatView> eventRecordNumberValueDaily(@RequestBody GaoStoreChartReq req) {
TimiException.required(req, "not found req");
req.setStoreId(storeScopeService.resolveStoreId(req.getStoreId()));
return service.eventRecordNumberValueDailyStat(req); return service.eventRecordNumberValueDailyStat(req);
} }
@@ -82,8 +73,6 @@ public class GaoStoreChartController {
@RequireGaoPermission(GaoPermissionCode.STAT_READ) @RequireGaoPermission(GaoPermissionCode.STAT_READ)
@PostMapping("/event/record/calendar") @PostMapping("/event/record/calendar")
public List<GaoEventRecordCalendarView> eventRecordCalendar(@RequestBody GaoStoreChartReq req) { public List<GaoEventRecordCalendarView> eventRecordCalendar(@RequestBody GaoStoreChartReq req) {
TimiException.required(req, "not found req");
req.setStoreId(storeScopeService.resolveStoreId(req.getStoreId()));
return service.eventRecordCalendar(req); return service.eventRecordCalendar(req);
} }
} }
@@ -1,13 +1,13 @@
package com.imyeyu.api.modules.gao.controller; package com.imyeyu.api.modules.gao.controller;
import com.imyeyu.api.bean.ModuleCode;
import com.imyeyu.api.modules.gao.annotation.RequireGaoPermission; import com.imyeyu.api.modules.gao.annotation.RequireGaoPermission;
import com.imyeyu.api.modules.gao.bean.GaoPermissionCode; import com.imyeyu.api.modules.gao.bean.GaoPermissionCode;
import com.imyeyu.api.modules.gao.entity.GaoStore; import com.imyeyu.api.modules.gao.entity.GaoStore;
import com.imyeyu.api.modules.gao.service.GaoStoreScopeService;
import com.imyeyu.api.modules.gao.service.GaoStoreService; import com.imyeyu.api.modules.gao.service.GaoStoreService;
import com.imyeyu.api.modules.user.service.PermissionChecker;
import com.imyeyu.api.modules.user.service.UserLoginService; import com.imyeyu.api.modules.user.service.UserLoginService;
import com.imyeyu.java.TimiJava; import com.imyeyu.java.TimiJava;
import com.imyeyu.java.bean.timi.TimiException;
import com.imyeyu.network.Network; import com.imyeyu.network.Network;
import com.imyeyu.spring.TimiSpring; import com.imyeyu.spring.TimiSpring;
import com.imyeyu.spring.annotation.AOPLog; import com.imyeyu.spring.annotation.AOPLog;
@@ -37,20 +37,14 @@ import java.util.List;
public class GaoStoreController { public class GaoStoreController {
private final GaoStoreService service; private final GaoStoreService service;
private final GaoStoreScopeService storeScopeService;
private final UserLoginService userLoginService; private final UserLoginService userLoginService;
private final PermissionChecker permissionChecker;
@AOPLog @AOPLog
@RequestRateLimit @RequestRateLimit
@RequireGaoPermission(GaoPermissionCode.STORE_READ) @RequireGaoPermission(GaoPermissionCode.STORE_READ)
@PostMapping("/list") @PostMapping("/list")
public PageResult<GaoStore> list(@RequestBody Page<GaoStore> page) { public PageResult<GaoStore> list(@RequestBody Page<GaoStore> page) {
TimiException.required(page, "not found page");
if (!storeScopeService.hasGlobalScope()) {
GaoStore example = TimiJava.defaultIfNull(page.getEqualsExample(), new GaoStore());
example.setId(storeScopeService.resolveStoreId(example.getId()));
page.setEqualsExample(example);
}
return service.page(page); return service.page(page);
} }
@@ -59,9 +53,7 @@ public class GaoStoreController {
@RequireGaoPermission(GaoPermissionCode.STORE_READ) @RequireGaoPermission(GaoPermissionCode.STORE_READ)
@PostMapping("/detail") @PostMapping("/detail")
public GaoStore detail(@RequestParam String id) { public GaoStore detail(@RequestParam String id) {
GaoStore store = service.get(id); return service.get(id);
storeScopeService.checkStore(store);
return store;
} }
@AOPLog @AOPLog
@@ -78,13 +70,12 @@ public class GaoStoreController {
@RequireGaoPermission(GaoPermissionCode.STORE_UPDATE) @RequireGaoPermission(GaoPermissionCode.STORE_UPDATE)
@PostMapping("/update") @PostMapping("/update")
public void update(@RequestBody GaoStore store) { public void update(@RequestBody GaoStore store) {
if (storeScopeService.hasGlobalScope()) { if (permissionChecker.hasAny(ModuleCode.GAO, GaoPermissionCode.STORE_CREATE.getValue())) {
// 门店管理 // 门店管理
service.update(store); service.update(store);
} else { } else {
// 店长 // 店长
GaoStore dbStore = service.get(store.getId()); GaoStore dbStore = service.get(store.getId());
storeScopeService.checkStore(dbStore);
dbStore.setName(store.getName()); dbStore.setName(store.getName());
dbStore.setTelephone(store.getTelephone()); dbStore.setTelephone(store.getTelephone());
dbStore.setAddress(store.getAddress()); dbStore.setAddress(store.getAddress());
@@ -107,11 +98,6 @@ public class GaoStoreController {
@RequireGaoPermission(GaoPermissionCode.STORE_UPDATE) @RequireGaoPermission(GaoPermissionCode.STORE_UPDATE)
@PostMapping("/sort") @PostMapping("/sort")
public void sort(@RequestBody List<String> idList) { public void sort(@RequestBody List<String> idList) {
if (!storeScopeService.hasGlobalScope()) {
for (String id : TimiJava.safeIterable(idList)) {
storeScopeService.checkStore(service.get(id));
}
}
service.sort(idList); service.sort(idList);
} }
@@ -121,12 +107,6 @@ public class GaoStoreController {
@RequireGaoPermission(GaoPermissionCode.STORE_EXPORT) @RequireGaoPermission(GaoPermissionCode.STORE_EXPORT)
@PostMapping("/export") @PostMapping("/export")
public void export(@RequestBody Page<GaoStore> page) throws IOException { public void export(@RequestBody Page<GaoStore> page) throws IOException {
TimiException.required(page, "not found page");
if (!storeScopeService.hasGlobalScope()) {
GaoStore example = TimiJava.defaultIfNull(page.getEqualsExample(), new GaoStore());
example.setId(storeScopeService.resolveStoreId(example.getId()));
page.setEqualsExample(example);
}
HttpServletResponse resp = TimiSpring.getResponse(); HttpServletResponse resp = TimiSpring.getResponse();
String contentDisposition = Network.getFileDownloadHeader("门店列表-%s.xlsx".formatted(Time.serialize.format(Time.now()))); String contentDisposition = Network.getFileDownloadHeader("门店列表-%s.xlsx".formatted(Time.serialize.format(Time.now())));
resp.setContentType("application/vnd.openxmlformats-officedocument.spreadsheetml.sheet"); resp.setContentType("application/vnd.openxmlformats-officedocument.spreadsheetml.sheet");
@@ -6,8 +6,9 @@ import com.imyeyu.api.modules.common.entity.Attachment;
import com.imyeyu.api.modules.common.service.AttachmentService; import com.imyeyu.api.modules.common.service.AttachmentService;
import com.imyeyu.api.modules.gao.annotation.RequireGaoPermission; import com.imyeyu.api.modules.gao.annotation.RequireGaoPermission;
import com.imyeyu.api.modules.gao.bean.GaoPermissionCode; import com.imyeyu.api.modules.gao.bean.GaoPermissionCode;
import com.imyeyu.api.modules.gao.bean.GaoRoleCode;
import com.imyeyu.api.modules.gao.entity.GaoUser; import com.imyeyu.api.modules.gao.entity.GaoUser;
import com.imyeyu.api.modules.gao.service.GaoStoreScopeService; import com.imyeyu.api.modules.gao.service.GaoStoreService;
import com.imyeyu.api.modules.gao.service.GaoUserInviteService; import com.imyeyu.api.modules.gao.service.GaoUserInviteService;
import com.imyeyu.api.modules.gao.service.GaoUserService; import com.imyeyu.api.modules.gao.service.GaoUserService;
import com.imyeyu.api.modules.gao.vo.GaoUserInviteCreateRequest; import com.imyeyu.api.modules.gao.vo.GaoUserInviteCreateRequest;
@@ -18,13 +19,13 @@ import com.imyeyu.api.modules.gao.vo.GaoUserInviteValidateRequest;
import com.imyeyu.api.modules.gao.vo.GaoUserInviteValidateResponse; import com.imyeyu.api.modules.gao.vo.GaoUserInviteValidateResponse;
import com.imyeyu.api.modules.user.entity.Role; import com.imyeyu.api.modules.user.entity.Role;
import com.imyeyu.api.modules.user.entity.User; import com.imyeyu.api.modules.user.entity.User;
import com.imyeyu.api.modules.user.service.AuthorizationScopeService; import com.imyeyu.api.modules.user.service.RoleChecker;
import com.imyeyu.api.modules.user.service.RoleService;
import com.imyeyu.api.modules.user.service.UserLoginService; import com.imyeyu.api.modules.user.service.UserLoginService;
import com.imyeyu.api.modules.user.service.UserRoleService; import com.imyeyu.api.modules.user.service.UserRoleService;
import com.imyeyu.api.modules.user.service.UserService; import com.imyeyu.api.modules.user.service.UserService;
import com.imyeyu.api.modules.user.vo.LoginResponse; import com.imyeyu.api.modules.user.vo.LoginResponse;
import com.imyeyu.java.TimiJava; import com.imyeyu.java.TimiJava;
import com.imyeyu.java.bean.timi.TimiException;
import com.imyeyu.spring.annotation.AOPLog; import com.imyeyu.spring.annotation.AOPLog;
import com.imyeyu.spring.annotation.RequestRateLimit; import com.imyeyu.spring.annotation.RequestRateLimit;
import com.imyeyu.spring.bean.Page; import com.imyeyu.spring.bean.Page;
@@ -52,11 +53,12 @@ import java.util.UUID;
public class GaoUserController { public class GaoUserController {
private final UserService userService; private final UserService userService;
private final AuthorizationScopeService authorizationScopeService; private final RoleService roleService;
private final RoleChecker roleChecker;
private final GaoUserService service; private final GaoUserService service;
private final GaoUserInviteService inviteService; private final GaoUserInviteService inviteService;
private final UserRoleService userRoleService; private final UserRoleService userRoleService;
private final GaoStoreScopeService storeScopeService; private final GaoStoreService gaoStoreService;
private final UserLoginService userLoginService; private final UserLoginService userLoginService;
private final AttachmentService attachmentService; private final AttachmentService attachmentService;
@@ -91,11 +93,10 @@ public class GaoUserController {
@PostMapping("/list") @PostMapping("/list")
@JsonView(ResponseView.Public.class) @JsonView(ResponseView.Public.class)
public PageResult<GaoUser> list(@RequestBody Page<GaoUser> page) { public PageResult<GaoUser> list(@RequestBody Page<GaoUser> page) {
TimiException.required(page, "not found page"); if (!roleChecker.hasAny(ModuleCode.GAO, GaoRoleCode.GLOBAL_MANAGER.name())) {
if (!storeScopeService.hasGlobalScope()) {
// 非全局管理只能看所在店用户 // 非全局管理只能看所在店用户
page.setEqualsExample(TimiJava.defaultIfNull(page.getEqualsExample(), new GaoUser())); page.setEqualsExample(TimiJava.defaultIfNull(page.getEqualsExample(), new GaoUser()));
page.getEqualsExample().setStoreId(storeScopeService.resolveStoreId(page.getEqualsExample().getStoreId())); page.getEqualsExample().setStoreId(gaoStoreService.getByUserId(userLoginService.getRequireLoginUserId()).getId());
} }
PageResult<GaoUser> result = service.page(page); PageResult<GaoUser> result = service.page(page);
{ {
@@ -117,8 +118,6 @@ public class GaoUserController {
@JsonView(ResponseView.Public.class) @JsonView(ResponseView.Public.class)
public GaoUser detail(@RequestParam String id) { public GaoUser detail(@RequestParam String id) {
GaoUser result = service.get(id); GaoUser result = service.get(id);
TimiException.required(result, "not found gao user");
storeScopeService.checkStoreId(result.getStoreId());
{ {
User user = userService.get(result.getUserId()); User user = userService.get(result.getUserId());
user.setAttachmentList(attachmentService.listByBizId(Attachment.BizType.USER, user.getId())); user.setAttachmentList(attachmentService.listByBizId(Attachment.BizType.USER, user.getId()));
@@ -136,7 +135,9 @@ public class GaoUserController {
@PostMapping("/create") @PostMapping("/create")
@JsonView(ResponseView.Public.class) @JsonView(ResponseView.Public.class)
public GaoUser create(@RequestBody GaoUser gaoUser) { public GaoUser create(@RequestBody GaoUser gaoUser) {
gaoUser.setStoreId(storeScopeService.resolveStoreId(gaoUser.getStoreId())); if (!roleChecker.hasAny(ModuleCode.GAO, GaoRoleCode.GLOBAL_MANAGER.name())) {
gaoUser.setStoreId(gaoStoreService.getByUserId(userLoginService.getRequireLoginUserId()).getId());
}
service.create(gaoUser); service.create(gaoUser);
return service.get(gaoUser.getId()); return service.get(gaoUser.getId());
} }
@@ -147,12 +148,6 @@ public class GaoUserController {
@PostMapping("/update") @PostMapping("/update")
@JsonView(ResponseView.Public.class) @JsonView(ResponseView.Public.class)
public GaoUser update(@RequestBody GaoUser gaoUser) { public GaoUser update(@RequestBody GaoUser gaoUser) {
TimiException.required(gaoUser, "not found gao user");
TimiException.required(gaoUser.getId(), "not found gao user.id");
GaoUser dbGaoUser = service.get(gaoUser.getId());
TimiException.required(dbGaoUser, "not found gao user");
storeScopeService.checkStoreId(dbGaoUser.getStoreId());
gaoUser.setStoreId(dbGaoUser.getStoreId());
service.update(gaoUser); service.update(gaoUser);
return service.get(gaoUser.getId()); return service.get(gaoUser.getId());
} }
@@ -163,12 +158,6 @@ public class GaoUserController {
@PostMapping("/transfer/store") @PostMapping("/transfer/store")
@JsonView(ResponseView.Public.class) @JsonView(ResponseView.Public.class)
public GaoUser transferStore(@RequestBody GaoUser gaoUser) { public GaoUser transferStore(@RequestBody GaoUser gaoUser) {
TimiException.required(gaoUser, "not found gao user");
TimiException.required(gaoUser.getId(), "not found gao user.id");
GaoUser dbGaoUser = service.get(gaoUser.getId());
TimiException.required(dbGaoUser, "not found gao user");
storeScopeService.checkStoreId(dbGaoUser.getStoreId());
gaoUser.setStoreId(storeScopeService.resolveStoreId(gaoUser.getStoreId()));
service.transferStore(gaoUser); service.transferStore(gaoUser);
return service.get(gaoUser.getId()); return service.get(gaoUser.getId());
} }
@@ -178,9 +167,6 @@ public class GaoUserController {
@RequireGaoPermission(GaoPermissionCode.USER_DELETE) @RequireGaoPermission(GaoPermissionCode.USER_DELETE)
@PostMapping("/delete") @PostMapping("/delete")
public void delete(@RequestParam String id) { public void delete(@RequestParam String id) {
GaoUser gaoUser = service.get(id);
TimiException.required(gaoUser, "not found gao user");
storeScopeService.checkStoreId(gaoUser.getStoreId());
service.delete(id); service.delete(id);
} }
@@ -189,6 +175,7 @@ public class GaoUserController {
@RequireGaoPermission(GaoPermissionCode.USER_READ) @RequireGaoPermission(GaoPermissionCode.USER_READ)
@PostMapping("/role/list") @PostMapping("/role/list")
public List<Role> roleList() { public List<Role> roleList() {
return authorizationScopeService.listGrantableRole(userLoginService.getRequireLoginUserId(), ModuleCode.GAO); // TODO 此接口获取本模块所有角色,需要限制角色
return roleService.listByModuleCode(ModuleCode.GAO);
} }
} }
@@ -1,33 +0,0 @@
package com.imyeyu.api.modules.gao.service;
import com.imyeyu.api.modules.gao.entity.GaoStore;
/// GAO 门店资源范围服务
///
/// 同时拥有门店管理和店长角色时,按门店管理角色使用全局范围
///
/// @author Codex
/// @since 2026-08-23
public interface GaoStoreScopeService {
/// 判断当前用户是否拥有 GAO 全局范围
///
/// @return `true` 为允许访问全部门店
boolean hasGlobalScope();
/// 将请求门店 ID 解析为当前可用门店 ID
///
/// @param requestedStoreId 请求中的门店 ID,可为空
/// @return 门店 ID,全局范围可为空
String resolveStoreId(String requestedStoreId);
/// 检查门店是否在当前用户可管理范围内
///
/// @param storeId 门店 ID
void checkStoreId(String storeId);
/// 检查门店实体是否在当前用户可管理范围内
///
/// @param store 门店
void checkStore(GaoStore store);
}
@@ -1,58 +0,0 @@
package com.imyeyu.api.modules.gao.service.implement;
import com.imyeyu.api.bean.CoreRoleCode;
import com.imyeyu.api.bean.ModuleCode;
import com.imyeyu.api.modules.gao.bean.GaoRoleCode;
import com.imyeyu.api.modules.gao.entity.GaoStore;
import com.imyeyu.api.modules.gao.service.GaoStoreScopeService;
import com.imyeyu.api.modules.gao.service.GaoStoreService;
import com.imyeyu.api.modules.user.service.RoleChecker;
import com.imyeyu.java.TimiJava;
import com.imyeyu.java.bean.timi.TimiException;
import lombok.RequiredArgsConstructor;
import org.springframework.stereotype.Service;
/// GAO 门店资源范围服务实现
///
/// @author Codex
/// @since 2026-08-23
@Service
@RequiredArgsConstructor
public class GaoStoreScopeServiceImplement implements GaoStoreScopeService {
private final RoleChecker roleChecker;
private final GaoStoreService gaoStoreService;
@Override
public boolean hasGlobalScope() {
return roleChecker.hasAny(ModuleCode.CORE, CoreRoleCode.SYSTEM.name(), CoreRoleCode.ADMIN.name())
|| roleChecker.hasAny(ModuleCode.GAO, GaoRoleCode.GLOBAL_MANAGER.name());
}
@Override
public String resolveStoreId(String requestedStoreId) {
if (hasGlobalScope()) {
return requestedStoreId;
}
String currentStoreId = gaoStoreService.getBelongIdByRequiredLoginUserId();
if (TimiJava.isNotEmpty(requestedStoreId)) {
TimiException.requiredTrue(currentStoreId.equals(requestedStoreId), "无权操作其他门店");
}
return currentStoreId;
}
@Override
public void checkStoreId(String storeId) {
TimiException.required(storeId, "not found storeId");
if (!hasGlobalScope()) {
String currentStoreId = gaoStoreService.getBelongIdByRequiredLoginUserId();
TimiException.requiredTrue(currentStoreId.equals(storeId), "无权操作其他门店");
}
}
@Override
public void checkStore(GaoStore store) {
TimiException.required(store, "not found store");
checkStoreId(store.getId());
}
}