middleware.go 3.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135
  1. /*
  2. * @desc:中间件
  3. * @company:云南奇讯科技有限公司
  4. * @Author: yixiaohu<yxh669@qq.com>
  5. * @Date: 2022/9/23 15:05
  6. */
  7. package middleware
  8. import (
  9. "fmt"
  10. "github.com/gogf/gf/v2/frame/g"
  11. "github.com/gogf/gf/v2/net/ghttp"
  12. "github.com/gogf/gf/v2/text/gstr"
  13. "github.com/gogf/gf/v2/util/gconv"
  14. commonService "github.com/tiger1103/gfast/v3/internal/app/common/service"
  15. "github.com/tiger1103/gfast/v3/internal/app/system/model"
  16. "github.com/tiger1103/gfast/v3/internal/app/system/service"
  17. "github.com/tiger1103/gfast/v3/library/libResponse"
  18. )
  19. func init() {
  20. service.RegisterMiddleware(New())
  21. }
  22. func New() *sMiddleware {
  23. return &sMiddleware{}
  24. }
  25. type sMiddleware struct{}
  26. // Ctx 自定义上下文对象
  27. func (s *sMiddleware) Ctx(r *ghttp.Request) {
  28. ctx := r.GetCtx()
  29. // 初始化登录用户信息
  30. data, err := service.GfToken().ParseToken(r)
  31. if err != nil {
  32. // 执行下一步请求逻辑
  33. r.Middleware.Next()
  34. }
  35. if data != nil {
  36. context := new(model.Context)
  37. err = gconv.Struct(data.Data, &context.User)
  38. if err != nil {
  39. g.Log().Error(ctx, err)
  40. // 执行下一步请求逻辑
  41. r.Middleware.Next()
  42. }
  43. service.Context().Init(r, context)
  44. }
  45. // 执行下一步请求逻辑
  46. r.Middleware.Next()
  47. }
  48. // Auth 权限判断处理中间件
  49. func (s *sMiddleware) Auth(r *ghttp.Request) {
  50. ctx := r.GetCtx()
  51. //获取登陆用户id
  52. adminId := service.Context().GetUserId(ctx)
  53. accessParams := r.Get("accessParams").Strings()
  54. accessParamsStr := ""
  55. if len(accessParams) > 0 && accessParams[0] != "undefined" {
  56. accessParamsStr = "?" + gstr.Join(accessParams, "&")
  57. }
  58. url := gstr.TrimLeft(r.Request.URL.Path, "/") + accessParamsStr
  59. /*if r.Method != "GET" && adminId != 1 && url!="api/v1/system/login" {
  60. libResponse.FailJson(true, r, "对不起!演示系统,不能删改数据!")
  61. }*/
  62. //获取无需验证权限的用户id
  63. tagSuperAdmin := false
  64. service.SysUser().NotCheckAuthAdminIds(ctx).Iterator(func(v interface{}) bool {
  65. if gconv.Uint64(v) == adminId {
  66. tagSuperAdmin = true
  67. return false
  68. }
  69. return true
  70. })
  71. if tagSuperAdmin {
  72. r.Middleware.Next()
  73. //不要再往后面执行
  74. return
  75. }
  76. //获取地址对应的菜单id
  77. menuList, err := service.SysAuthRule().GetMenuList(ctx)
  78. if err != nil {
  79. g.Log().Error(ctx, err)
  80. libResponse.FailJson(true, r, "请求数据失败")
  81. }
  82. var menu *model.SysAuthRuleInfoRes
  83. for _, m := range menuList {
  84. ms := gstr.SubStr(m.Name, 0, gstr.Pos(m.Name, "?"))
  85. if m.Name == url || ms == url {
  86. menu = m
  87. break
  88. }
  89. }
  90. //只验证存在数据库中的规则
  91. if menu != nil {
  92. //若是不登录能访问的接口则不判断权限
  93. excludePaths := g.Cfg().MustGet(ctx, "gfToken.excludePaths").Strings()
  94. for _, p := range excludePaths {
  95. if gstr.Equal(menu.Name, gstr.TrimLeft(p, "/")) {
  96. r.Middleware.Next()
  97. return
  98. }
  99. }
  100. //若存在不需要验证的条件则跳过
  101. if gstr.Equal(menu.Condition, "nocheck") {
  102. r.Middleware.Next()
  103. return
  104. }
  105. menuId := menu.Id
  106. //菜单没存数据库不验证权限
  107. if menuId != 0 {
  108. //判断权限操作
  109. enforcer, err := commonService.CasbinEnforcer(ctx)
  110. if err != nil {
  111. g.Log().Error(ctx, err)
  112. libResponse.FailJson(true, r, "获取权限失败")
  113. }
  114. hasAccess := false
  115. hasAccess, err = enforcer.Enforce(fmt.Sprintf("%s%d", service.SysUser().GetCasBinUserPrefix(), adminId), gconv.String(menuId), "All")
  116. if err != nil {
  117. g.Log().Error(ctx, err)
  118. libResponse.FailJson(true, r, "判断权限失败")
  119. }
  120. if !hasAccess {
  121. libResponse.FailJson(true, r, "没有访问权限")
  122. }
  123. }
  124. } else if menu == nil && accessParamsStr != "" {
  125. libResponse.FailJson(true, r, "没有访问权限")
  126. }
  127. r.Middleware.Next()
  128. }