AccessControllerListsRepository.php 9.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257
  1. <?php
  2. /**
  3. * ACL权限管理仓库.
  4. *
  5. * @author nj <nj@gmail.com>
  6. * @date 2020-01-22 22:37:21
  7. */
  8. declare(strict_types=1);
  9. namespace App\Repositories\Utils;
  10. use Hyperf\DbConnection\Db;
  11. use Hyperf\HttpServer\Router\Router;
  12. class AccessControllerListsRepository
  13. {
  14. private $config = [];
  15. private $roleId = 0;
  16. public function init($config = [], $role_id = 0)
  17. {
  18. $this->config = config('manage_acl');
  19. if ($config) {
  20. $this->config = array_merge($this->config, $config);
  21. }
  22. $this->roleId = $role_id;
  23. }
  24. public function getController(
  25. $config = [],
  26. $controller_path = '',
  27. $controller_suffix = '',
  28. $str_namespace = ''
  29. ) {
  30. if (empty($config)) {
  31. $config = $this->config;
  32. }
  33. $controller_path = empty($controller_path) ? app_path() . '/Controller' : rtrim($controller_path, '/');
  34. $controller_suffix = empty($controller_suffix) ? 'Controller' : $controller_suffix;
  35. if ($str_namespace) {
  36. $str_namespace = "\\". trim($str_namespace, "\\") . "\\";
  37. }
  38. $return_data = [];
  39. if (is_dir($controller_path)) {
  40. foreach (glob($controller_path . '/*'. $controller_suffix .'.php') as $filename) {
  41. $class_name = basename($filename, '.php');
  42. $controller = str_replace($controller_suffix, '', $class_name);
  43. $class_obj_name = $str_namespace ? $str_namespace . $class_name : $class_name;
  44. $class_methods = get_class_methods($class_obj_name);
  45. if (is_array($class_methods)) {
  46. foreach ($class_methods as $action) {
  47. //过滤魔术方法
  48. if (substr($action, 0, 2) != '__' && !in_array($action, $config['AUTH_FILTER_METHOD'])) {
  49. $return_data[$controller][$action] = -1;
  50. }
  51. }
  52. }
  53. }
  54. }
  55. if ($return_data) {
  56. foreach ($return_data as $key => $value) {
  57. $data = $condition = [];
  58. $data[$config['AUTH_TABLE']['resource']['field']['pid']] = 0;
  59. $condition[] = [
  60. $config['AUTH_TABLE']['resource']['field']['pid'] => 0
  61. ];
  62. $data[$config['AUTH_TABLE']['resource']['field']['operate']] = $key;
  63. $condition[] = [
  64. $config['AUTH_TABLE']['resource']['field']['operate'] => $key
  65. ];
  66. $db_res = DB::table($config['AUTH_TABLE']['resource']['name']);
  67. if ($condition) {
  68. foreach ($condition as $k1 => $v1) {
  69. foreach ($v1 as $k2 => $v2) {
  70. $db_res->where($k2, '=', $v2);
  71. }
  72. }
  73. }
  74. $info = $db_res->first();
  75. if (empty($info)) {
  76. $pid = DB::table($config['AUTH_TABLE']['resource']['name'])->insertGetId($data);
  77. } else {
  78. $pid = $info->{$config['AUTH_TABLE']['resource']['field']['id']};
  79. }
  80. if (is_array($value)) {
  81. foreach ($value as $k2 => $v2) {
  82. $data = $condition = [];
  83. $data[$config['AUTH_TABLE']['resource']['field']['pid']] = $pid;
  84. $condition[] = [
  85. $config['AUTH_TABLE']['resource']['field']['pid'] => $pid
  86. ];
  87. $data[$config['AUTH_TABLE']['resource']['field']['operate']] = $k2;
  88. $condition[] = [
  89. $config['AUTH_TABLE']['resource']['field']['operate'] => $k2
  90. ];
  91. $db_res = DB::table($config['AUTH_TABLE']['resource']['name']);
  92. if ($condition) {
  93. foreach ($condition as $k1 => $v1) {
  94. foreach ($v1 as $k2 => $v2) {
  95. $db_res->where($k2, '=', $v2);
  96. }
  97. }
  98. }
  99. $info = $db_res->first();
  100. if (empty($info)) {
  101. DB::table($config['AUTH_TABLE']['resource']['name'])->insertGetId($data);
  102. }
  103. }
  104. }
  105. }
  106. }
  107. return $return_data;
  108. }
  109. public function checkLogin()
  110. {
  111. return true;
  112. }
  113. public function getRolePower($role_id = 0)
  114. {
  115. if (empty($role_id) || empty($this->config['AUTH_TABLE']['role']['field']['power'])) {
  116. return false;
  117. }
  118. $role_info = DB::table($this->config['AUTH_TABLE']['role']['name'])
  119. ->where($this->config['AUTH_TABLE']['role']['field']['id'], '=', $role_id)->first();
  120. if (empty($role_info)) {
  121. return false;
  122. }
  123. if ($role_info->{$this->config['AUTH_TABLE']['role']['field']['power']} == -1) {
  124. $power = -1;
  125. } else {
  126. $resource = DB::table($this->config['AUTH_TABLE']['resource']['name'])->get();
  127. if (empty($resource)) {
  128. return false;
  129. }
  130. $power_value = explode(',', $role_info->{$this->config['AUTH_TABLE']['role']['field']['power']});
  131. $power = $resource2 = [];
  132. foreach ($resource as $k => $v) {
  133. $resource2[$v->{$this->config['AUTH_TABLE']['resource']['field']['id']}] = $v;
  134. }
  135. foreach ($resource2 as $k => $v) {
  136. if ($v->{$this->config['AUTH_TABLE']['resource']['field']['pid']} != 0
  137. && in_array($v->{$this->config['AUTH_TABLE']['resource']['field']['id']}, $power_value)) {
  138. $controller = $resource2[$v->{$this->config['AUTH_TABLE']['resource']['field']['pid']}]
  139. ->{$this->config['AUTH_TABLE']['resource']['field']['operate']};//模块
  140. $action = $v->{$this->config['AUTH_TABLE']['resource']['field']['operate']};//操作方法
  141. $power[$controller][$action] = -1;
  142. }
  143. }
  144. }
  145. return $power;
  146. }
  147. private function noPower()
  148. {
  149. return -999;
  150. }
  151. public function check($controller_suffix = 'Controller')
  152. {
  153. $routeAction = $this->getCurrentRouteHandler();
  154. preg_match_all('/([a-z0-9A-Z]+\\\)?(\w+)@(\w+)/', $routeAction, $matchs);
  155. $controller_full = $matchs[2][0]; //类名
  156. $controller = str_replace($controller_suffix, '', $controller_full);
  157. $action = $matchs[3][0]; //方法名
  158. //不需要认证的模块,则放行
  159. if (isset($this->config['AUTH_LOGIN_NO'][$controller]) && (($this->config['AUTH_LOGIN_NO'][$controller] == '*') || in_array($action, $this->config['AUTH_LOGIN_NO'][$controller]))) {
  160. return true;
  161. }
  162. $power = $this->getRolePower($this->roleId);
  163. // 临时的,记得删除-1 Todo.
  164. // $power = -1;
  165. if ($power == -1) {
  166. return true;
  167. } else {
  168. $privilege = trans('permission') ? trans('permission') : [];
  169. $controller = str_replace('Controller', '', $controller);
  170. if ($privilege) {
  171. if (isset($privilege[$controller]['power_rule']['module_hidden'])) {
  172. if ($privilege[$controller]['power_rule']['module_hidden'] == 0) {
  173. if (isset($privilege[$controller][$action])) {
  174. if (isset($privilege[$controller]['power_rule'][$action]) &&
  175. $privilege[$controller]['power_rule'][$action] == 1) {
  176. return true;
  177. } else {
  178. if (isset($power[$controller][$action]) && $power[$controller][$action] == -1) {
  179. return true;
  180. }
  181. }
  182. } else { //没有设置$privilege[$controller][$action]一律通过
  183. return true;
  184. }
  185. } elseif ($privilege[$controller]['power_rule']['module_hidden'] == 1) {
  186. return true;
  187. }
  188. }
  189. }
  190. }
  191. return $this->noPower();
  192. }
  193. /**
  194. * 检查模块和操作权限
  195. * @param string $controller 控制器
  196. * @param null $action 动作
  197. * @return bool
  198. */
  199. public function checkPower($controller, $action = null)
  200. {
  201. if (empty($controller)) {
  202. return false;
  203. }
  204. $power = $this->getRolePower($this->roleId);
  205. if (empty($power)) {
  206. return false;
  207. }
  208. if ($power == -1) {
  209. return true;
  210. }
  211. if (empty($action) && isset($power[$controller]) && !empty($power[$controller])) {
  212. return true;
  213. } elseif (isset($power[$controller][$action])) {
  214. return true;
  215. } else {
  216. return false;
  217. }
  218. }
  219. /**
  220. * 获取当前路由话柄.
  221. * @return string
  222. */
  223. private function getCurrentRouteHandler()
  224. {
  225. $request = request();
  226. $currentUri = $request->getRequestUri();
  227. $currentMethod = $request->getMethod();
  228. $routeData = Router::getData();
  229. if (isset($routeData[0][$currentMethod][$currentUri])) {
  230. return $routeData[0][$currentMethod][$currentUri]->callback;
  231. } else {
  232. return '';
  233. }
  234. }
  235. }