fix(auth): 完善权限控制与强制改密流程
This commit is contained in:
@@ -1,8 +1,18 @@
|
||||
import { computed, ref } from 'vue'
|
||||
import { defineStore } from 'pinia'
|
||||
|
||||
import { getCurrentUser, login as loginRequest, logout as logoutRequest } from '@/api/auth'
|
||||
import type { AuthenticatedUser, LoginRequest, LoginResponse } from '@/types/auth'
|
||||
import {
|
||||
changePassword as changePasswordRequest,
|
||||
getCurrentUser,
|
||||
login as loginRequest,
|
||||
logout as logoutRequest,
|
||||
} from '@/api/auth'
|
||||
import type {
|
||||
AuthenticatedUser,
|
||||
LoginRequest,
|
||||
LoginResponse,
|
||||
PasswordChangeRequest,
|
||||
} from '@/types/auth'
|
||||
import { clearAuthStorage, readStoredAuthSession, saveAuthSession } from '@/utils/auth-storage'
|
||||
|
||||
const dataScopeLabels: Record<AuthenticatedUser['dataScope'], string> = {
|
||||
@@ -25,6 +35,7 @@ export const useLoginStore = defineStore('login', () => {
|
||||
let currentUserRequest: Promise<AuthenticatedUser> | null = null
|
||||
|
||||
const isLoggedIn = computed(() => Boolean(token.value))
|
||||
const isReadOnly = computed(() => user.value?.dataScope === 'READ_ONLY_ALL')
|
||||
const userName = computed(() => user.value?.displayName || user.value?.username || '医护用户')
|
||||
const department = computed(() => getUserContext(user.value))
|
||||
|
||||
@@ -41,6 +52,10 @@ export const useLoginStore = defineStore('login', () => {
|
||||
)
|
||||
}
|
||||
|
||||
function hasWritePermission(required: string | string[]) {
|
||||
return !isReadOnly.value && hasPermission(required)
|
||||
}
|
||||
|
||||
function setSession(session: LoginResponse) {
|
||||
saveAuthSession(session)
|
||||
token.value = session.token
|
||||
@@ -117,17 +132,26 @@ export const useLoginStore = defineStore('login', () => {
|
||||
}
|
||||
}
|
||||
|
||||
async function changePassword(payload: PasswordChangeRequest) {
|
||||
await changePasswordRequest(payload)
|
||||
// 服务端会递增 authEpoch;当前令牌随即失效,必须使用新密码重新登录。
|
||||
clearSession()
|
||||
}
|
||||
|
||||
return {
|
||||
token,
|
||||
expiresAt,
|
||||
user,
|
||||
isLoggedIn,
|
||||
isReadOnly,
|
||||
userName,
|
||||
department,
|
||||
login,
|
||||
refreshCurrentUser,
|
||||
ensureCurrentUser,
|
||||
hasPermission,
|
||||
hasWritePermission,
|
||||
changePassword,
|
||||
logout,
|
||||
clearSession,
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user