fix(auth): 完善权限控制与强制改密流程
This commit is contained in:
@@ -33,6 +33,7 @@ import type {
|
||||
} from '@/api/workbench/types'
|
||||
import NewSigningTaskDialog from '@/components/signing/NewSigningTaskDialog.vue'
|
||||
import { useAppStore } from '@/stores/app'
|
||||
import { useLoginStore } from '@/stores/login'
|
||||
import type { SigningFieldProgress } from '@/utils/signing-document'
|
||||
import { downloadSigningPdf } from '@/utils/signing-pdf'
|
||||
|
||||
@@ -46,6 +47,7 @@ import type { SigningFilterForm, SigningFilterOption, SigningTaskAction } from '
|
||||
|
||||
const route = useRoute()
|
||||
const appStore = useAppStore()
|
||||
const loginStore = useLoginStore()
|
||||
|
||||
const STATUS_VALUES: SigningTaskStatus[] = [
|
||||
'pending',
|
||||
@@ -113,6 +115,24 @@ const pdfExporting = ref(false)
|
||||
let listRequestId = 0
|
||||
let detailRequestId = 0
|
||||
|
||||
function canWrite(permission: string) {
|
||||
return (
|
||||
!loginStore.isReadOnly && (isSigningMockEnabled || loginStore.hasWritePermission(permission))
|
||||
)
|
||||
}
|
||||
|
||||
function canRead(permission: string) {
|
||||
return isSigningMockEnabled || loginStore.hasPermission(permission)
|
||||
}
|
||||
|
||||
const canCreateTask = computed(() => canWrite('sign:task:create'))
|
||||
const canDeliveryWrite = computed(() => canWrite('sign:delivery:write'))
|
||||
const canReopenTask = computed(() => canWrite('sign:task:reopen'))
|
||||
const canVoidTask = computed(() => canWrite('sign:task:void'))
|
||||
const canViewEvents = computed(() => canRead('sign:task:event:query'))
|
||||
const canViewArtifacts = computed(() => canRead('sign:artifact:query'))
|
||||
const canDownloadArtifacts = computed(() => canRead('sign:artifact:download'))
|
||||
|
||||
const campusOptions = computed<SigningFilterOption<WorkbenchCampus | 'all'>[]>(() => [
|
||||
{ label: '全部院区', value: 'all' },
|
||||
...appStore.campuses.map((campus) => ({ label: campus, value: campus })),
|
||||
@@ -244,9 +264,9 @@ async function loadTaskDetail(id: string | null) {
|
||||
}
|
||||
|
||||
detailLoading.value = true
|
||||
eventsLoading.value = true
|
||||
eventsLoading.value = canViewEvents.value
|
||||
eventsError.value = false
|
||||
artifactsLoading.value = true
|
||||
artifactsLoading.value = canViewArtifacts.value
|
||||
artifactsError.value = false
|
||||
taskEvents.value = []
|
||||
artifacts.value = []
|
||||
@@ -255,8 +275,8 @@ async function loadTaskDetail(id: string | null) {
|
||||
try {
|
||||
const [detailResult, eventsResult, artifactsResult] = await Promise.allSettled([
|
||||
getSigningTaskDetail(id, signingApiOptions.value),
|
||||
getSigningTaskEvents(id),
|
||||
getSigningArtifacts(id),
|
||||
canViewEvents.value ? getSigningTaskEvents(id) : Promise.resolve([]),
|
||||
canViewArtifacts.value ? getSigningArtifacts(id) : Promise.resolve([]),
|
||||
])
|
||||
|
||||
if (requestId === detailRequestId) {
|
||||
@@ -410,6 +430,20 @@ async function handleTaskAction(action: SigningTaskAction) {
|
||||
return
|
||||
}
|
||||
|
||||
const allowed =
|
||||
isSigningMockEnabled ||
|
||||
(action === 'create-pad-session' && canDeliveryWrite.value) ||
|
||||
(action === 'resend-sms' && canDeliveryWrite.value) ||
|
||||
(action === 'reopen' && canReopenTask.value) ||
|
||||
(action === 'void' && canVoidTask.value) ||
|
||||
((action === 'download-pdf' || action === 'download-signature' || action === 'print') &&
|
||||
canDownloadArtifacts.value)
|
||||
|
||||
if (!allowed) {
|
||||
ElMessage.warning('当前账号没有执行此操作的权限')
|
||||
return
|
||||
}
|
||||
|
||||
if (action === 'pad-sign') {
|
||||
if (!isSigningMockEnabled) {
|
||||
ElMessage.info('手写板设备签署接口待接入')
|
||||
@@ -564,6 +598,11 @@ async function exportSignedPdf() {
|
||||
}
|
||||
|
||||
async function downloadArtifact(artifact: SigningArtifact) {
|
||||
if (!canDownloadArtifacts.value) {
|
||||
ElMessage.warning('当前账号没有下载签署文件的权限')
|
||||
return
|
||||
}
|
||||
|
||||
try {
|
||||
const blob = await downloadSigningArtifact(artifact.id)
|
||||
const url = URL.createObjectURL(blob)
|
||||
@@ -708,6 +747,7 @@ onMounted(() => {
|
||||
:departments="departmentOptions"
|
||||
:documents="documentOptions"
|
||||
:visit-types="visitTypeOptions"
|
||||
:can-create="canCreateTask"
|
||||
@add="newDialogVisible = true"
|
||||
@search="handleSearch"
|
||||
/>
|
||||
@@ -736,6 +776,12 @@ onMounted(() => {
|
||||
:artifacts-error="artifactsError"
|
||||
:pad-session-status="padSessionStatus"
|
||||
:pad-session-loading="padSessionLoading"
|
||||
:can-delivery-write="canDeliveryWrite"
|
||||
:can-reopen="canReopenTask"
|
||||
:can-void="canVoidTask"
|
||||
:can-view-audit="canViewEvents"
|
||||
:can-view-artifacts="canViewArtifacts"
|
||||
:can-download-artifact="canDownloadArtifacts"
|
||||
@action="handleTaskAction"
|
||||
@download-artifact="downloadArtifact"
|
||||
@selection-change="handleSelectionChange"
|
||||
|
||||
Reference in New Issue
Block a user