edb.go 14 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454
  1. package data_manage_permission
  2. import (
  3. "eta/eta_api/utils"
  4. "fmt"
  5. "github.com/beego/beego/v2/client/orm"
  6. "strconv"
  7. "time"
  8. )
  9. // EdbInfoPermission
  10. // @Description: 指标权限表
  11. type EdbInfoPermission struct {
  12. EdbInfoPermissionId int64 `json:"edb_info_permission_id" orm:"column(edb_info_permission_id);pk"`
  13. EdbInfoId int32 `json:"edb_info_id"` // 指标id
  14. EdbInfoType int32 `json:"edb_info_type"` // 指标类型,0:普通指标,1:预测指标
  15. SysUserId int32 `json:"sys_user_id"` // 系统用户id
  16. ModifyTime time.Time `json:"modify_time"` // 变更时间
  17. CreateTime time.Time `json:"create_time"` // 关系建立时间
  18. }
  19. // EdbClassifyPermission
  20. // @Description: 指标分类权限表
  21. type EdbClassifyPermission struct {
  22. EdbClassifyPermissionId int64 `json:"edb_classify_permission_id" orm:"column(edb_classify_permission_id);pk"`
  23. EdbClassifyId int32 `json:"edb_classify_id"` // 分类id
  24. EdbClassifyType int32 `json:"edb_classify_type"` // 分类类型,0:普通指标分类,1:预测指标分类
  25. SysUserId int32 `json:"sys_user_id"` // 系统用户id
  26. ModifyTime time.Time `json:"modify_time"` // 变更时间
  27. CreateTime time.Time `json:"create_time"` // 关系建立时间
  28. }
  29. // SetIsPermissionEdbChartByEdbClassifyIdList
  30. // @Description: 设置指标分类是否涉密
  31. // @author: Roc
  32. // @datetime 2024-03-27 14:15:42
  33. // @param classifyIdList []int
  34. func SetIsPermissionEdbChartByEdbClassifyIdList(classifyIdList []int, classifyType int) (err error) {
  35. num := len(classifyIdList)
  36. if num <= 0 {
  37. return
  38. }
  39. o, err := orm.NewOrmUsingDB("data").Begin()
  40. if err != nil {
  41. return
  42. }
  43. defer func() {
  44. if err != nil {
  45. _ = o.Rollback()
  46. } else {
  47. _ = o.Commit()
  48. }
  49. }()
  50. //// 获取已经配置涉密的分类权限
  51. //edbClassifyList := make([]*EdbClassify, 0)
  52. //sql := `SELECT * FROM edb_classify WHERE is_join_permission = ? `
  53. //_, err = o.Raw(sql, 1).QueryRows(&edbClassifyList)
  54. //if err != nil {
  55. // return
  56. //}
  57. //edbClassifyMap := make(map[int]*EdbClassify)
  58. //for _, v := range edbClassifyList {
  59. // edbClassifyMap[v.ClassifyId] = v
  60. //}
  61. // 先将所有已经设置了涉密的分类设置为不涉密
  62. sql := `UPDATE edb_classify SET is_join_permission=?,modify_time=now() WHERE is_join_permission = 1 AND classify_type = ?`
  63. _, err = o.Raw(sql, 0, classifyType).Exec()
  64. if err != nil {
  65. return
  66. }
  67. if len(classifyIdList) > 0 {
  68. // 将对应的分类设置为涉密
  69. sql = `UPDATE edb_classify SET is_join_permission=?,modify_time=now() WHERE classify_type = ? AND classify_id in (` + utils.GetOrmInReplace(num) + `) `
  70. _, err = o.Raw(sql, 1, classifyType, classifyIdList).Exec()
  71. if err != nil {
  72. return
  73. }
  74. }
  75. return
  76. }
  77. // SetPermissionByEdbIdList
  78. // @Description: 根据指标ID列表设置指标的用户权限
  79. // @author: Roc
  80. // @datetime 2024-03-27 14:03:42
  81. // @param edbIdList []string
  82. // @param userIdList []int
  83. // @param chartInfoType int
  84. // @return err error
  85. func SetPermissionByEdbIdList(edbIdList []string, userIdList []int, edbInfoType int) (err error) {
  86. edbNum := len(edbIdList)
  87. if edbNum <= 0 {
  88. return
  89. }
  90. o, err := orm.NewOrmUsingDB("data").Begin()
  91. if err != nil {
  92. return
  93. }
  94. defer func() {
  95. if err != nil {
  96. _ = o.Rollback()
  97. } else {
  98. _ = o.Commit()
  99. }
  100. }()
  101. // 获取已经配置的指标权限用户
  102. edbInfoPermissionList := make([]*EdbInfoPermission, 0)
  103. sql := `SELECT * FROM edb_info_permission WHERE edb_info_type = ? AND edb_info_id in (` + utils.GetOrmInReplace(edbNum) + `) `
  104. _, err = o.Raw(sql, edbInfoType, edbIdList).QueryRows(&edbInfoPermissionList)
  105. if err != nil {
  106. return
  107. }
  108. edbInfoPermissionMap := make(map[string]*EdbInfoPermission)
  109. for _, v := range edbInfoPermissionList {
  110. edbInfoPermissionMap[fmt.Sprint(v.EdbInfoId, "_", v.SysUserId)] = v
  111. }
  112. // 标记指标是否纳入权限管控
  113. {
  114. // 默认 标记指标为纳入权限管控
  115. isJoinPermission := 1
  116. // 用户不选的情况下,说明是要给这些指标移除权限管控
  117. if len(userIdList) <= 0 {
  118. // 标记指标为不纳入权限管控
  119. isJoinPermission = 0
  120. }
  121. sql = `UPDATE edb_info SET is_join_permission=?,modify_time=now() WHERE edb_info_type = ? AND edb_info_id in (` + utils.GetOrmInReplace(edbNum) + `) `
  122. _, err = o.Raw(sql, isJoinPermission, edbInfoType, edbIdList).Exec()
  123. if err != nil {
  124. return
  125. }
  126. }
  127. // 待添加的配置项
  128. addList := make([]*EdbInfoPermission, 0)
  129. // 遍历待配置的指标和用户,筛选出需要添加的配置项
  130. for _, edbInfoIdStr := range edbIdList {
  131. edbInfoId, tmpErr := strconv.ParseInt(edbInfoIdStr, 10, 64)
  132. if tmpErr != nil {
  133. err = tmpErr
  134. return
  135. }
  136. for _, userId := range userIdList {
  137. key := fmt.Sprint(edbInfoId, "_", userId)
  138. if _, ok := edbInfoPermissionMap[key]; ok {
  139. // 如果存在那么就移除,说明不需要处理了
  140. delete(edbInfoPermissionMap, key)
  141. } else {
  142. // 如果不存在,那么就添加
  143. addList = append(addList, &EdbInfoPermission{
  144. //PermissionId: 0,
  145. EdbInfoId: int32(edbInfoId),
  146. SysUserId: int32(userId),
  147. EdbInfoType: int32(edbInfoType),
  148. ModifyTime: time.Now(),
  149. CreateTime: time.Now(),
  150. })
  151. }
  152. }
  153. }
  154. // 添加待配置项
  155. if len(addList) > 0 {
  156. _, err = o.InsertMulti(500, addList)
  157. if err != nil {
  158. return
  159. }
  160. }
  161. // 移除废弃的配置项
  162. {
  163. // 待移除的配置项
  164. deletePermissionIdList := make([]int64, 0)
  165. for _, v := range edbInfoPermissionMap {
  166. deletePermissionIdList = append(deletePermissionIdList, v.EdbInfoPermissionId)
  167. }
  168. deletePermissionIdNum := len(deletePermissionIdList)
  169. if deletePermissionIdNum > 0 {
  170. sql = "DELETE FROM edb_info_permission WHERE edb_info_permission_id in (" + utils.GetOrmInReplace(deletePermissionIdNum) + ")"
  171. _, err = o.Raw(sql, deletePermissionIdList).Exec()
  172. if err != nil {
  173. return
  174. }
  175. }
  176. }
  177. return
  178. }
  179. // SetPermissionByEdbClassifyIdList
  180. // @Description: 根据指标分类ID列表设置分类的用户权限
  181. // @author: Roc
  182. // @datetime 2024-03-28 14:53:04
  183. // @param classifyIdList []int
  184. // @param userIdList []int
  185. // @return err error
  186. func SetPermissionByEdbClassifyIdList(classifyIdList []int, userIdList []int, classifyType int) (err error) {
  187. userNum := len(userIdList)
  188. if userNum <= 0 {
  189. return
  190. }
  191. o, err := orm.NewOrmUsingDB("data").Begin()
  192. if err != nil {
  193. return
  194. }
  195. defer func() {
  196. if err != nil {
  197. _ = o.Rollback()
  198. } else {
  199. _ = o.Commit()
  200. }
  201. }()
  202. // 获取当前选择用户已经配置的指标分类权限
  203. classifyPermissionList := make([]*EdbClassifyPermission, 0)
  204. sql := `SELECT * FROM edb_classify_permission WHERE edb_classify_type = ? AND sys_user_id in (` + utils.GetOrmInReplace(userNum) + `) `
  205. _, err = o.Raw(sql, classifyType, userIdList).QueryRows(&classifyPermissionList)
  206. if err != nil {
  207. return
  208. }
  209. classifyPermissionMap := make(map[string]*EdbClassifyPermission)
  210. for _, v := range classifyPermissionList {
  211. classifyPermissionMap[fmt.Sprint(v.EdbClassifyId, "_", v.SysUserId)] = v
  212. }
  213. // 待添加的配置项
  214. addList := make([]*EdbClassifyPermission, 0)
  215. // 遍历待配置的指标和用户,筛选出需要添加的配置项
  216. for _, userId := range userIdList {
  217. for _, classifyId := range classifyIdList {
  218. key := fmt.Sprint(classifyId, "_", userId)
  219. if _, ok := classifyPermissionMap[key]; ok {
  220. // 如果存在那么就移除,说明不需要处理了
  221. delete(classifyPermissionMap, key)
  222. } else {
  223. // 如果不存在,那么就提那家
  224. addList = append(addList, &EdbClassifyPermission{
  225. //PermissionId: 0,
  226. EdbClassifyId: int32(classifyId),
  227. EdbClassifyType: int32(classifyType),
  228. SysUserId: int32(userId),
  229. ModifyTime: time.Now(),
  230. CreateTime: time.Now(),
  231. })
  232. }
  233. }
  234. }
  235. // 添加待配置项
  236. if len(addList) > 0 {
  237. _, err = o.InsertMulti(500, addList)
  238. if err != nil {
  239. return
  240. }
  241. }
  242. // 移除废弃的配置项
  243. {
  244. // 获取移除的配置项
  245. deletePermissionIdList := make([]int64, 0)
  246. for _, v := range classifyPermissionMap {
  247. deletePermissionIdList = append(deletePermissionIdList, v.EdbClassifyPermissionId)
  248. }
  249. deletePermissionIdNum := len(deletePermissionIdList)
  250. if deletePermissionIdNum > 0 {
  251. sql = "DELETE FROM edb_classify_permission WHERE edb_classify_permission_id in (" + utils.GetOrmInReplace(deletePermissionIdNum) + ")"
  252. _, err = o.Raw(sql, deletePermissionIdList).Exec()
  253. if err != nil {
  254. return
  255. }
  256. }
  257. }
  258. return
  259. }
  260. // GetPermissionEdbClassifyIdListByUserId
  261. // @Description: 根据用户ID获取已经配置的分类id列表
  262. // @author: Roc
  263. // @datetime 2024-03-29 16:24:46
  264. // @param userId int
  265. // @param classifyType int
  266. // @return edbClassifyIdList []int
  267. // @return err error
  268. func GetPermissionEdbClassifyIdListByUserId(userId int, classifyType int) (edbClassifyIdList []int, err error) {
  269. o := orm.NewOrmUsingDB("data")
  270. sql := `SELECT edb_classify_id FROM edb_classify_permission WHERE edb_classify_type = ? AND sys_user_id = ? `
  271. _, err = o.Raw(sql, classifyType, userId).QueryRows(&edbClassifyIdList)
  272. return
  273. }
  274. // GetPermissionEdbIdListByDataId
  275. // @Description: 根据资产(指标、图表、表格)ID获取已经配置的用户id列表
  276. // @author: Roc
  277. // @datetime 2024-03-29 16:24:46
  278. // @param dataId int
  279. // @param edbInfoType int
  280. // @return edbIdList []int
  281. // @return err error
  282. func GetPermissionEdbIdListByDataId(dataId int, edbInfoType int) (edbIdList []int, err error) {
  283. o := orm.NewOrmUsingDB("data")
  284. sql := `SELECT sys_user_id FROM edb_info_permission WHERE edb_info_type = ? AND edb_info_id= ? `
  285. _, err = o.Raw(sql, edbInfoType, dataId).QueryRows(&edbIdList)
  286. return
  287. }
  288. // GetPermissionEdbIdList
  289. // @Description: 获取用户权限的指标列表
  290. // @author: Roc
  291. // @datetime 2024-03-28 16:50:47
  292. // @param userId int
  293. // @param edbInfoId int
  294. // @return idList []int
  295. // @return err error
  296. func GetPermissionEdbIdList(userId, edbInfoId int) (idList []int, err error) {
  297. pars := []interface{}{userId}
  298. o := orm.NewOrmUsingDB("data")
  299. sql := `SELECT edb_info_id FROM edb_info_permission WHERE sys_user_id = ? `
  300. if edbInfoId > 0 {
  301. sql += ` AND edb_info_id = ? `
  302. pars = append(pars, edbInfoId)
  303. }
  304. _, err = o.Raw(sql, pars).QueryRows(&idList)
  305. return
  306. }
  307. // GetPermissionEdbClassifyIdList
  308. // @Description: 获取用户权限的指标分类列表
  309. // @author: Roc
  310. // @datetime 2024-03-28 16:50:47
  311. // @param userId int
  312. // @param classifyId int
  313. // @return idList []int
  314. // @return err error
  315. func GetPermissionEdbClassifyIdList(userId, classifyId int) (idList []int, err error) {
  316. pars := []interface{}{userId}
  317. o := orm.NewOrmUsingDB("data")
  318. sql := `SELECT edb_classify_id FROM edb_classify_permission WHERE sys_user_id = ? `
  319. if classifyId > 0 {
  320. sql += ` AND edb_classify_id = ? `
  321. pars = append(pars, classifyId)
  322. }
  323. _, err = o.Raw(sql, pars).QueryRows(&idList)
  324. return
  325. }
  326. // InheritParentClassifyByEdbClassifyId
  327. // @Description: 继承父级分类的指标权限信息
  328. // @author: Roc
  329. // @datetime 2024-04-07 21:02:51
  330. // @param source int
  331. // @param classifyType int
  332. // @param classifyId int
  333. // @param parentClassifyId int
  334. // @param classifyName string
  335. // @param uniqueCode string
  336. // @return err error
  337. func InheritParentClassifyByEdbClassifyId(source, classifyType, classifyId, parentClassifyId int, classifyName, uniqueCode string) (err error) {
  338. o, err := orm.NewOrmUsingDB("data").Begin()
  339. if err != nil {
  340. return
  341. }
  342. defer func() {
  343. if err != nil {
  344. _ = o.Rollback()
  345. } else {
  346. _ = o.Commit()
  347. }
  348. }()
  349. // 将对应的分类设置为涉密
  350. sql := `UPDATE edb_classify SET is_join_permission=?,modify_time=now() WHERE classify_type = ? AND classify_id = ? `
  351. _, err = o.Raw(sql, 1, classifyType, classifyId).Exec()
  352. if err != nil {
  353. return
  354. }
  355. // 添加未授权记录
  356. {
  357. // 获取父级未授权的用户记录
  358. var parentRecordItems []*DataPermissionClassifyNoAuthRecord
  359. sql = `SELECT * FROM data_permission_classify_no_auth_record WHERE classify_id = ? AND source = ? AND sub_source = ? ORDER BY data_permission_classify_no_auth_record_id desc LIMIT ?,? `
  360. _, err = o.Raw(sql, parentClassifyId, source, classifyType).QueryRows(&parentRecordItems)
  361. addNoAuthRecordItems := make([]*DataPermissionClassifyNoAuthRecord, 0)
  362. for _, v := range parentRecordItems {
  363. addNoAuthRecordItems = append(addNoAuthRecordItems, &DataPermissionClassifyNoAuthRecord{
  364. DataPermissionClassifyNoAuthRecordId: 0,
  365. Source: v.Source,
  366. SubSource: v.SubSource,
  367. OpUniqueCode: uniqueCode,
  368. ClassifyId: fmt.Sprint(classifyId),
  369. ClassifyName: classifyName,
  370. SysUserId: v.SysUserId,
  371. CreateTime: time.Now(),
  372. })
  373. }
  374. // 添加待配置项
  375. if len(addNoAuthRecordItems) > 0 {
  376. _, err = o.InsertMulti(500, addNoAuthRecordItems)
  377. if err != nil {
  378. return
  379. }
  380. }
  381. }
  382. // 添加授权记录
  383. {
  384. // 获取父级分类已经授权的用户
  385. parentClassifyPermissionList := make([]*EdbClassifyPermission, 0)
  386. sql = `SELECT * FROM edb_classify_permission WHERE edb_classify_type = ? AND edb_classify_id = ? `
  387. _, err = o.Raw(sql, classifyType, parentClassifyId).QueryRows(&parentClassifyPermissionList)
  388. if err != nil {
  389. return
  390. }
  391. addList := make([]*EdbClassifyPermission, 0)
  392. for _, v := range parentClassifyPermissionList {
  393. // 如果不存在,那么就提那家
  394. addList = append(addList, &EdbClassifyPermission{
  395. //PermissionId: 0,
  396. EdbClassifyId: int32(classifyId),
  397. EdbClassifyType: int32(classifyType),
  398. SysUserId: v.SysUserId,
  399. ModifyTime: time.Now(),
  400. CreateTime: time.Now(),
  401. })
  402. }
  403. // 添加待配置项
  404. if len(addList) > 0 {
  405. _, err = o.InsertMulti(500, addList)
  406. if err != nil {
  407. return
  408. }
  409. }
  410. }
  411. return
  412. }