fix(auth): 完善权限控制与强制改密流程

This commit is contained in:
xy
2026-09-17 16:33:09 +08:00
parent 81922d774f
commit 61b4b19f55
22 changed files with 618 additions and 59 deletions
+26 -2
View File
@@ -1,8 +1,18 @@
import { computed, ref } from 'vue'
import { defineStore } from 'pinia'
import { getCurrentUser, login as loginRequest, logout as logoutRequest } from '@/api/auth'
import type { AuthenticatedUser, LoginRequest, LoginResponse } from '@/types/auth'
import {
changePassword as changePasswordRequest,
getCurrentUser,
login as loginRequest,
logout as logoutRequest,
} from '@/api/auth'
import type {
AuthenticatedUser,
LoginRequest,
LoginResponse,
PasswordChangeRequest,
} from '@/types/auth'
import { clearAuthStorage, readStoredAuthSession, saveAuthSession } from '@/utils/auth-storage'
const dataScopeLabels: Record<AuthenticatedUser['dataScope'], string> = {
@@ -25,6 +35,7 @@ export const useLoginStore = defineStore('login', () => {
let currentUserRequest: Promise<AuthenticatedUser> | null = null
const isLoggedIn = computed(() => Boolean(token.value))
const isReadOnly = computed(() => user.value?.dataScope === 'READ_ONLY_ALL')
const userName = computed(() => user.value?.displayName || user.value?.username || '医护用户')
const department = computed(() => getUserContext(user.value))
@@ -41,6 +52,10 @@ export const useLoginStore = defineStore('login', () => {
)
}
function hasWritePermission(required: string | string[]) {
return !isReadOnly.value && hasPermission(required)
}
function setSession(session: LoginResponse) {
saveAuthSession(session)
token.value = session.token
@@ -117,17 +132,26 @@ export const useLoginStore = defineStore('login', () => {
}
}
async function changePassword(payload: PasswordChangeRequest) {
await changePasswordRequest(payload)
// 服务端会递增 authEpoch;当前令牌随即失效,必须使用新密码重新登录。
clearSession()
}
return {
token,
expiresAt,
user,
isLoggedIn,
isReadOnly,
userName,
department,
login,
refreshCurrentUser,
ensureCurrentUser,
hasPermission,
hasWritePermission,
changePassword,
logout,
clearSession,
}