| 123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257 |
- <?php
- /**
- * ACL权限管理仓库.
- *
- * @author nj <nj@gmail.com>
- * @date 2020-01-22 22:37:21
- */
- declare(strict_types=1);
- namespace App\Repositories\Utils;
- use Hyperf\DbConnection\Db;
- use Hyperf\HttpServer\Router\Router;
- class AccessControllerListsRepository
- {
- private $config = [];
- private $roleId = 0;
- public function init($config = [], $role_id = 0)
- {
- $this->config = config('manage_acl');
- if ($config) {
- $this->config = array_merge($this->config, $config);
- }
- $this->roleId = $role_id;
- }
- public function getController(
- $config = [],
- $controller_path = '',
- $controller_suffix = '',
- $str_namespace = ''
- ) {
- if (empty($config)) {
- $config = $this->config;
- }
- $controller_path = empty($controller_path) ? app_path() . '/Controller' : rtrim($controller_path, '/');
- $controller_suffix = empty($controller_suffix) ? 'Controller' : $controller_suffix;
- if ($str_namespace) {
- $str_namespace = "\\". trim($str_namespace, "\\") . "\\";
- }
- $return_data = [];
- if (is_dir($controller_path)) {
- foreach (glob($controller_path . '/*'. $controller_suffix .'.php') as $filename) {
- $class_name = basename($filename, '.php');
- $controller = str_replace($controller_suffix, '', $class_name);
- $class_obj_name = $str_namespace ? $str_namespace . $class_name : $class_name;
- $class_methods = get_class_methods($class_obj_name);
- if (is_array($class_methods)) {
- foreach ($class_methods as $action) {
- //过滤魔术方法
- if (substr($action, 0, 2) != '__' && !in_array($action, $config['AUTH_FILTER_METHOD'])) {
- $return_data[$controller][$action] = -1;
- }
- }
- }
- }
- }
- if ($return_data) {
- foreach ($return_data as $key => $value) {
- $data = $condition = [];
- $data[$config['AUTH_TABLE']['resource']['field']['pid']] = 0;
- $condition[] = [
- $config['AUTH_TABLE']['resource']['field']['pid'] => 0
- ];
- $data[$config['AUTH_TABLE']['resource']['field']['operate']] = $key;
- $condition[] = [
- $config['AUTH_TABLE']['resource']['field']['operate'] => $key
- ];
- $db_res = DB::table($config['AUTH_TABLE']['resource']['name']);
- if ($condition) {
- foreach ($condition as $k1 => $v1) {
- foreach ($v1 as $k2 => $v2) {
- $db_res->where($k2, '=', $v2);
- }
- }
- }
- $info = $db_res->first();
- if (empty($info)) {
- $pid = DB::table($config['AUTH_TABLE']['resource']['name'])->insertGetId($data);
- } else {
- $pid = $info->{$config['AUTH_TABLE']['resource']['field']['id']};
- }
- if (is_array($value)) {
- foreach ($value as $k2 => $v2) {
- $data = $condition = [];
- $data[$config['AUTH_TABLE']['resource']['field']['pid']] = $pid;
- $condition[] = [
- $config['AUTH_TABLE']['resource']['field']['pid'] => $pid
- ];
- $data[$config['AUTH_TABLE']['resource']['field']['operate']] = $k2;
- $condition[] = [
- $config['AUTH_TABLE']['resource']['field']['operate'] => $k2
- ];
- $db_res = DB::table($config['AUTH_TABLE']['resource']['name']);
- if ($condition) {
- foreach ($condition as $k1 => $v1) {
- foreach ($v1 as $k2 => $v2) {
- $db_res->where($k2, '=', $v2);
- }
- }
- }
- $info = $db_res->first();
- if (empty($info)) {
- DB::table($config['AUTH_TABLE']['resource']['name'])->insertGetId($data);
- }
- }
- }
- }
- }
- return $return_data;
- }
- public function checkLogin()
- {
- return true;
- }
- public function getRolePower($role_id = 0)
- {
- if (empty($role_id) || empty($this->config['AUTH_TABLE']['role']['field']['power'])) {
- return false;
- }
- $role_info = DB::table($this->config['AUTH_TABLE']['role']['name'])
- ->where($this->config['AUTH_TABLE']['role']['field']['id'], '=', $role_id)->first();
- if (empty($role_info)) {
- return false;
- }
- if ($role_info->{$this->config['AUTH_TABLE']['role']['field']['power']} == -1) {
- $power = -1;
- } else {
- $resource = DB::table($this->config['AUTH_TABLE']['resource']['name'])->get();
- if (empty($resource)) {
- return false;
- }
- $power_value = explode(',', $role_info->{$this->config['AUTH_TABLE']['role']['field']['power']});
- $power = $resource2 = [];
- foreach ($resource as $k => $v) {
- $resource2[$v->{$this->config['AUTH_TABLE']['resource']['field']['id']}] = $v;
- }
- foreach ($resource2 as $k => $v) {
- if ($v->{$this->config['AUTH_TABLE']['resource']['field']['pid']} != 0
- && in_array($v->{$this->config['AUTH_TABLE']['resource']['field']['id']}, $power_value)) {
- $controller = $resource2[$v->{$this->config['AUTH_TABLE']['resource']['field']['pid']}]
- ->{$this->config['AUTH_TABLE']['resource']['field']['operate']};//模块
- $action = $v->{$this->config['AUTH_TABLE']['resource']['field']['operate']};//操作方法
- $power[$controller][$action] = -1;
- }
- }
- }
- return $power;
- }
- private function noPower()
- {
- return -999;
- }
- public function check($controller_suffix = 'Controller')
- {
- $routeAction = $this->getCurrentRouteHandler();
- preg_match_all('/([a-z0-9A-Z]+\\\)?(\w+)@(\w+)/', $routeAction, $matchs);
- $controller_full = $matchs[2][0]; //类名
- $controller = str_replace($controller_suffix, '', $controller_full);
- $action = $matchs[3][0]; //方法名
- //不需要认证的模块,则放行
- if (isset($this->config['AUTH_LOGIN_NO'][$controller]) && (($this->config['AUTH_LOGIN_NO'][$controller] == '*') || in_array($action, $this->config['AUTH_LOGIN_NO'][$controller]))) {
- return true;
- }
- $power = $this->getRolePower($this->roleId);
- // 临时的,记得删除-1 Todo.
- // $power = -1;
- if ($power == -1) {
- return true;
- } else {
- $privilege = trans('permission') ? trans('permission') : [];
- $controller = str_replace('Controller', '', $controller);
- if ($privilege) {
- if (isset($privilege[$controller]['power_rule']['module_hidden'])) {
- if ($privilege[$controller]['power_rule']['module_hidden'] == 0) {
- if (isset($privilege[$controller][$action])) {
- if (isset($privilege[$controller]['power_rule'][$action]) &&
- $privilege[$controller]['power_rule'][$action] == 1) {
- return true;
- } else {
- if (isset($power[$controller][$action]) && $power[$controller][$action] == -1) {
- return true;
- }
- }
- } else { //没有设置$privilege[$controller][$action]一律通过
- return true;
- }
- } elseif ($privilege[$controller]['power_rule']['module_hidden'] == 1) {
- return true;
- }
- }
- }
- }
- return $this->noPower();
- }
- /**
- * 检查模块和操作权限
- * @param string $controller 控制器
- * @param null $action 动作
- * @return bool
- */
- public function checkPower($controller, $action = null)
- {
- if (empty($controller)) {
- return false;
- }
- $power = $this->getRolePower($this->roleId);
- if (empty($power)) {
- return false;
- }
- if ($power == -1) {
- return true;
- }
- if (empty($action) && isset($power[$controller]) && !empty($power[$controller])) {
- return true;
- } elseif (isset($power[$controller][$action])) {
- return true;
- } else {
- return false;
- }
- }
- /**
- * 获取当前路由话柄.
- * @return string
- */
- private function getCurrentRouteHandler()
- {
- $request = request();
- $currentUri = $request->getRequestUri();
- $currentMethod = $request->getMethod();
- $routeData = Router::getData();
- if (isset($routeData[0][$currentMethod][$currentUri])) {
- return $routeData[0][$currentMethod][$currentUri]->callback;
- } else {
- return '';
- }
- }
- }
|