AccessControllerListsRepository.php 9.2 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248
  1. <?php
  2. /**
  3. * ACL权限管理仓库.
  4. *
  5. * @author nj
  6. * @date 2021-01-22 22:37:21
  7. */
  8. namespace App\Repositories\Utils;
  9. use DB;
  10. use Route;
  11. class AccessControllerListsRepository
  12. {
  13. private $config = [];
  14. private $roleId = 0;
  15. public function init($config = [], $role_id = 0)
  16. {
  17. $this->config = config('manage_acl');
  18. if ($config) {
  19. $this->config = array_merge($this->config, $config);
  20. }
  21. $this->roleId = $role_id;
  22. }
  23. public function getController(
  24. $config = [],
  25. $controller_path = '',
  26. $controller_suffix = '',
  27. $str_namespace = ''
  28. ) {
  29. if (empty($config)) {
  30. $config = $this->config;
  31. }
  32. $controller_path = empty($controller_path) ? app_path() . '/Controller' : rtrim($controller_path, '/');
  33. $controller_suffix = empty($controller_suffix) ? 'Controller' : $controller_suffix;
  34. if ($str_namespace) {
  35. $str_namespace = "\\". trim($str_namespace, "\\") . "\\";
  36. }
  37. $return_data = [];
  38. if (is_dir($controller_path)) {
  39. foreach (glob($controller_path . '/*'. $controller_suffix .'.php') as $filename) {
  40. $class_name = basename($filename, '.php');
  41. $controller = str_replace($controller_suffix, '', $class_name);
  42. $class_obj_name = $str_namespace ? $str_namespace . $class_name : $class_name;
  43. $class_methods = get_class_methods($class_obj_name);
  44. if (is_array($class_methods)) {
  45. foreach ($class_methods as $action) {
  46. //过滤魔术方法
  47. if (substr($action, 0, 2) != '__' && !in_array($action, $config['AUTH_FILTER_METHOD'])) {
  48. $return_data[$controller][$action] = -1;
  49. }
  50. }
  51. }
  52. }
  53. }
  54. if ($return_data) {
  55. foreach ($return_data as $key => $value) {
  56. $data = $condition = [];
  57. $data[$config['AUTH_TABLE']['resource']['field']['pid']] = 0;
  58. $condition[] = [
  59. $config['AUTH_TABLE']['resource']['field']['pid'] => 0
  60. ];
  61. $data[$config['AUTH_TABLE']['resource']['field']['operate']] = $key;
  62. $condition[] = [
  63. $config['AUTH_TABLE']['resource']['field']['operate'] => $key
  64. ];
  65. $db_res = DB::table($config['AUTH_TABLE']['resource']['name']);
  66. if ($condition) {
  67. foreach ($condition as $k1 => $v1) {
  68. foreach ($v1 as $k2 => $v2) {
  69. $db_res->where($k2, '=', $v2);
  70. }
  71. }
  72. }
  73. $info = $db_res->first();
  74. if (empty($info)) {
  75. $pid = DB::table($config['AUTH_TABLE']['resource']['name'])->insertGetId($data);
  76. } else {
  77. $pid = $info->{$config['AUTH_TABLE']['resource']['field']['id']};
  78. }
  79. if (is_array($value)) {
  80. foreach ($value as $k2 => $v2) {
  81. $data = $condition = [];
  82. $data[$config['AUTH_TABLE']['resource']['field']['pid']] = $pid;
  83. $condition[] = [
  84. $config['AUTH_TABLE']['resource']['field']['pid'] => $pid
  85. ];
  86. $data[$config['AUTH_TABLE']['resource']['field']['operate']] = $k2;
  87. $condition[] = [
  88. $config['AUTH_TABLE']['resource']['field']['operate'] => $k2
  89. ];
  90. $db_res = DB::table($config['AUTH_TABLE']['resource']['name']);
  91. if ($condition) {
  92. foreach ($condition as $k1 => $v1) {
  93. foreach ($v1 as $k2 => $v2) {
  94. $db_res->where($k2, '=', $v2);
  95. }
  96. }
  97. }
  98. $info = $db_res->first();
  99. if (empty($info)) {
  100. DB::table($config['AUTH_TABLE']['resource']['name'])->insertGetId($data);
  101. }
  102. }
  103. }
  104. }
  105. }
  106. return $return_data;
  107. }
  108. public function checkLogin()
  109. {
  110. return true;
  111. }
  112. public function getRolePower($role_id = 0)
  113. {
  114. if (empty($role_id) || empty($this->config['AUTH_TABLE']['role']['field']['power'])) {
  115. return false;
  116. }
  117. $role_info = DB::table($this->config['AUTH_TABLE']['role']['name'])
  118. ->where($this->config['AUTH_TABLE']['role']['field']['id'], '=', $role_id)->first();
  119. if (empty($role_info)) {
  120. return false;
  121. }
  122. if ($role_info->{$this->config['AUTH_TABLE']['role']['field']['power']} == -1) {
  123. $power = -1;
  124. } else {
  125. $resource = DB::table($this->config['AUTH_TABLE']['resource']['name'])->get();
  126. if (empty($resource)) {
  127. return false;
  128. }
  129. $power_value = explode(',', $role_info->{$this->config['AUTH_TABLE']['role']['field']['power']});
  130. $power = $resource2 = [];
  131. foreach ($resource as $k => $v) {
  132. $resource2[$v->{$this->config['AUTH_TABLE']['resource']['field']['id']}] = $v;
  133. }
  134. foreach ($resource2 as $k => $v) {
  135. if ($v->{$this->config['AUTH_TABLE']['resource']['field']['pid']} != 0
  136. && in_array($v->{$this->config['AUTH_TABLE']['resource']['field']['id']}, $power_value)) {
  137. $controller = $resource2[$v->{$this->config['AUTH_TABLE']['resource']['field']['pid']}]
  138. ->{$this->config['AUTH_TABLE']['resource']['field']['operate']};//模块
  139. $action = $v->{$this->config['AUTH_TABLE']['resource']['field']['operate']};//操作方法
  140. $power[$controller][$action] = -1;
  141. }
  142. }
  143. }
  144. return $power;
  145. }
  146. private function noPower()
  147. {
  148. return -999;
  149. }
  150. public function check($controller_suffix = 'Controller')
  151. {
  152. $routeAction = self::getCurrentRouteHandler();
  153. preg_match_all('/([a-z0-9A-Z]+\\\)?(\w+)@(\w+)/', $routeAction, $matchs);
  154. $controller_full = $matchs[2][0]; //类名
  155. $controller = str_replace($controller_suffix, '', $controller_full);
  156. $action = $matchs[3][0]; //方法名
  157. //不需要认证的模块,则放行
  158. if (isset($this->config['AUTH_LOGIN_NO'][$controller]) && (($this->config['AUTH_LOGIN_NO'][$controller] == '*') || in_array($action, $this->config['AUTH_LOGIN_NO'][$controller]))) {
  159. return true;
  160. }
  161. $power = $this->getRolePower($this->roleId);
  162. // 临时的,记得删除-1 Todo.
  163. // $power = -1;
  164. if ($power == -1) {
  165. return true;
  166. } else {
  167. $privilege = trans('permission') ? trans('permission') : [];
  168. $controller = str_replace('Controller', '', $controller);
  169. if ($privilege) {
  170. if (isset($privilege[$controller]['power_rule']['module_hidden'])) {
  171. if ($privilege[$controller]['power_rule']['module_hidden'] == 0) {
  172. if (isset($privilege[$controller][$action])) {
  173. if (isset($privilege[$controller]['power_rule'][$action]) &&
  174. $privilege[$controller]['power_rule'][$action] == 1) {
  175. return true;
  176. } else {
  177. if (isset($power[$controller][$action]) && $power[$controller][$action] == -1) {
  178. return true;
  179. }
  180. }
  181. } else { //没有设置$privilege[$controller][$action]一律通过
  182. return true;
  183. }
  184. } elseif ($privilege[$controller]['power_rule']['module_hidden'] == 1) {
  185. return true;
  186. }
  187. }
  188. }
  189. }
  190. return $this->noPower();
  191. }
  192. /**
  193. * 检查模块和操作权限
  194. * @param string $controller 控制器
  195. * @param null $action 动作
  196. * @return bool
  197. */
  198. public function checkPower($controller, $action = null)
  199. {
  200. if (empty($controller)) {
  201. return false;
  202. }
  203. $power = $this->getRolePower($this->roleId);
  204. if (empty($power)) {
  205. return false;
  206. }
  207. if ($power == -1) {
  208. return true;
  209. }
  210. if (empty($action) && isset($power[$controller]) && !empty($power[$controller])) {
  211. return true;
  212. } elseif (isset($power[$controller][$action])) {
  213. return true;
  214. } else {
  215. return false;
  216. }
  217. }
  218. /**
  219. * 获取当前路由话柄.
  220. * @return string
  221. */
  222. private function getCurrentRouteHandler()
  223. {
  224. return Route::currentRouteAction();
  225. }
  226. }