package casbin_adapter_service import ( "fmt" "gfast/app/model/admin/casbin_rule" "github.com/casbin/casbin/v2" "github.com/casbin/casbin/v2/model" "github.com/casbin/casbin/v2/persist" "github.com/gogf/gf/frame/g" "sync" ) type Adapter struct{} var Enforcer *casbin.SyncedEnforcer var EnforcerErr error var once sync.Once //获取adapter单例对象 func GetEnforcer() (*casbin.SyncedEnforcer, error) { once.Do(func() { _, EnforcerErr = newAdapter() }) return Enforcer, EnforcerErr } //初始化adapter操作 func newAdapter() (a *Adapter, err error) { a = new(Adapter) err = a.initPolicy() return } func (a *Adapter) initPolicy() error { // Because the DB is empty at first, // so we need to load the policy from the file adapter (.CSV) first. e, err := casbin.NewSyncedEnforcer(g.Cfg().GetString("casbin.modelFile"), g.Cfg().GetString("casbin.policyFile")) if err != nil { return err } // This is a trick to save the current policy to the DB. // We can't call e.SavePolicy() because the adapter in the enforcer is still the file adapter. // The current policy means the policy in the Casbin enforcer (aka in memory). //err = a.SavePolicy(e.GetModel()) //if err != nil { // return err //} //set adapter e.SetAdapter(a) // Clear the current policy. e.ClearPolicy() Enforcer = e // Load the policy from DB. err = a.LoadPolicy(e.GetModel()) if err != nil { return err } return nil } // SavePolicy saves policy to database. func (a *Adapter) SavePolicy(model model.Model) (err error) { err = a.dropTable() if err != nil { return } err = a.createTable() if err != nil { return } for ptype, ast := range model["p"] { for _, rule := range ast.Policy { line := savePolicyLine(ptype, rule) _, err := casbin_rule.Model.Data(&line).Insert() if err != nil { return err } } } for ptype, ast := range model["g"] { for _, rule := range ast.Policy { line := savePolicyLine(ptype, rule) _, err := casbin_rule.Model.Data(&line).Insert() if err != nil { return err } } } return } func (a *Adapter) dropTable() (err error) { _, err = g.DB("default").Exec(fmt.Sprintf("DROP TABLE %s", casbin_rule.Table)) return } func (a *Adapter) createTable() (err error) { _, err = g.DB("default").Exec(fmt.Sprintf("CREATE TABLE IF NOT EXISTS %s (ptype VARCHAR(10), v0 VARCHAR(256), v1 VARCHAR(256), v2 VARCHAR(256), v3 VARCHAR(256), v4 VARCHAR(256), v5 VARCHAR(256))", casbin_rule.Table)) return } // LoadPolicy loads policy from database. func (a *Adapter) LoadPolicy(model model.Model) error { var lines []casbin_rule.Entity if err := casbin_rule.Model.M.Scan(&lines); err != nil { return err } for _, line := range lines { loadPolicyLine(line, model) } return nil } // AddPolicy adds a policy rule to the storage. func (a *Adapter) AddPolicy(sec string, ptype string, rule []string) error { line := savePolicyLine(ptype, rule) _, err := casbin_rule.Model.M.Data(&line).Insert() return err } // RemovePolicy removes a policy rule from the storage. func (a *Adapter) RemovePolicy(sec string, ptype string, rule []string) error { line := savePolicyLine(ptype, rule) err := rawDelete(a, line) return err } // RemoveFilteredPolicy removes policy rules that match the filter from the storage. func (a *Adapter) RemoveFilteredPolicy(sec string, ptype string, fieldIndex int, fieldValues ...string) error { line := casbin_rule.Entity{} line.Ptype = ptype if fieldIndex <= 0 && 0 < fieldIndex+len(fieldValues) { line.V0 = fieldValues[0-fieldIndex] } if fieldIndex <= 1 && 1 < fieldIndex+len(fieldValues) { line.V1 = fieldValues[1-fieldIndex] } if fieldIndex <= 2 && 2 < fieldIndex+len(fieldValues) { line.V2 = fieldValues[2-fieldIndex] } if fieldIndex <= 3 && 3 < fieldIndex+len(fieldValues) { line.V3 = fieldValues[3-fieldIndex] } if fieldIndex <= 4 && 4 < fieldIndex+len(fieldValues) { line.V4 = fieldValues[4-fieldIndex] } if fieldIndex <= 5 && 5 < fieldIndex+len(fieldValues) { line.V5 = fieldValues[5-fieldIndex] } err := rawDelete(a, line) return err } func loadPolicyLine(line casbin_rule.Entity, model model.Model) { lineText := line.Ptype if line.V0 != "" { lineText += ", " + line.V0 } if line.V1 != "" { lineText += ", " + line.V1 } if line.V2 != "" { lineText += ", " + line.V2 } if line.V3 != "" { lineText += ", " + line.V3 } if line.V4 != "" { lineText += ", " + line.V4 } if line.V5 != "" { lineText += ", " + line.V5 } persist.LoadPolicyLine(lineText, model) } func savePolicyLine(ptype string, rule []string) casbin_rule.Entity { line := casbin_rule.Entity{} line.Ptype = ptype if len(rule) > 0 { line.V0 = rule[0] } if len(rule) > 1 { line.V1 = rule[1] } if len(rule) > 2 { line.V2 = rule[2] } if len(rule) > 3 { line.V3 = rule[3] } if len(rule) > 4 { line.V4 = rule[4] } if len(rule) > 5 { line.V5 = rule[5] } return line } func rawDelete(a *Adapter, line casbin_rule.Entity) error { db := casbin_rule.Model db.Where("ptype = ?", line.Ptype) if line.V0 != "" { db = db.Where("v0 = ?", line.V0) } if line.V1 != "" { db = db.Where("v1 = ?", line.V1) } if line.V2 != "" { db = db.Where("v2 = ?", line.V2) } if line.V3 != "" { db = db.Where("v3 = ?", line.V3) } if line.V4 != "" { db = db.Where("v4 = ?", line.V4) } if line.V5 != "" { db = db.Where("v5 = ?", line.V5) } _, err := db.Delete() return err }