后台添加权限管理
This commit is contained in:
@@ -1,8 +1,11 @@
|
||||
import { GMUserModel } from '@db/GMUser';
|
||||
import { GMUserGroupModel } from '@db/GMUserGroup'
|
||||
import { GMGroupModel } from '@db/GMGroup'
|
||||
import { ApiModel } from '@db/Api';
|
||||
|
||||
module.exports = () => {
|
||||
return async function tokenParser(ctx, next) {
|
||||
console.log(ctx.request.headers)
|
||||
|
||||
if (!ctx.request.headers || !ctx.request.headers.token) {
|
||||
console.error('token not found');
|
||||
ctx.body = {
|
||||
@@ -20,6 +23,34 @@ module.exports = () => {
|
||||
};
|
||||
return;
|
||||
}
|
||||
const url = ctx.request.url;
|
||||
let apiResult = await ApiModel.getApi(url);
|
||||
if(!apiResult) {
|
||||
ctx.body = {
|
||||
"status": "error",
|
||||
"data": "未找到该接口"
|
||||
};
|
||||
return;
|
||||
}
|
||||
let userGroups = await GMUserGroupModel.getUserGroupByUid(user.uid, 1);
|
||||
let flag = 0;
|
||||
for(let userGroup of userGroups) {
|
||||
let { groupId } = userGroup;
|
||||
let group = await GMGroupModel.getGroupById(groupId);
|
||||
if(group) {
|
||||
if(group.apis.includes(apiResult.apiId)) {
|
||||
flag = 1; break;
|
||||
}
|
||||
}
|
||||
}
|
||||
if(flag != 1) {
|
||||
ctx.body = {
|
||||
"status": "error",
|
||||
"data": "您没有权限访问该接口"
|
||||
};
|
||||
return;
|
||||
}
|
||||
console.log(user.uid, ctx.request.url, new Date());
|
||||
ctx.user = user;
|
||||
await next();
|
||||
};
|
||||
|
||||
Reference in New Issue
Block a user