admin_role.go 7.8 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257
  1. package repository
  2. import (
  3. "github.com/pkg/errors"
  4. "gorm.io/gorm"
  5. "sghgogs.com/sghblog/authorization-service/domain/model/base"
  6. req "sghgogs.com/sghblog/authorization-service/domain/model/request"
  7. pb "sghgogs.com/sghblog/authorization-service/proto"
  8. )
  9. func (u *Repository) GetAdminRole(roleId int64) (req.AdminRole, error) {
  10. var role req.AdminRole
  11. // status := []string{"enabled", "disabled"}
  12. // Where("status <> ?", "deleted")
  13. return role, u.db.Where("id = ?", roleId).
  14. Preload("Users", "status = ?", pb.StatusEnum_ENABLED).
  15. Preload("Permissions", "status = ?", pb.StatusEnum_ENABLED).
  16. First(&role).Error
  17. }
  18. // NOT EXISTS (
  19. // SELECT 1
  20. // FROM admin_user_role
  21. // WHERE admin_role.id = admin_user_role.admin_role_id
  22. // AND admin_user_role.admin_user_id = ?
  23. // )
  24. // 这个查询的核心部分是 NOT EXISTS 子查询。让我们一步步解释它的组成部分:
  25. // SELECT 1: 子查询选择一个虚拟的常数 1,因为我们只关心是否存在匹配的记录而不关心具体的值。这是一种常见的惯例。
  26. // FROM admin_user_role: 子查询从 admin_user_role 表中选取数据。
  27. // WHERE admin_role.id = admin_user_role.admin_role_id: 子查询中的条件,它将 admin_user_role 表中的记录与外部查询中的 admin_roles 表中的角色进行匹配。
  28. // AND admin_user_role.admin_user_id = ?: 子查询中的另一个条件,它确保与指定用户ID相关联的记录。
  29. // 现在,NOT EXISTS 子查询的含义是:如果在 admin_user_role 表中找不到匹配条件的记录(即不存在这样的记录),那么返回真。这意味着,外部查询将返回那些在 admin_roles 表中存在但在 admin_user_role 表中没有关联用户的角色。
  30. // 你可以将这个查询理解为:“查找在 admin_roles 表中,但在 admin_user_role 表中没有关联用户的角色”。
  31. func (u *Repository) GetUnassignedAdminRoles(userId int64) ([]req.AdminRole, int64, error) {
  32. var roles []req.AdminRole
  33. var totalCount int64
  34. tx := u.db.Model(req.AdminRole{}).
  35. Where("NOT EXISTS (SELECT 1 FROM admin_user_role WHERE admin_role.id = admin_user_role.admin_role_id AND admin_user_role.admin_user_id = ?)", userId)
  36. tx.Count(&totalCount)
  37. return roles, totalCount, tx.Find(&roles).Error
  38. }
  39. func (u *Repository) CreateAdminRole(role *req.AdminRole, adminUsers []int64, adminPermissions []int64) error {
  40. // 开始事务
  41. tx := u.db.Begin()
  42. // 错误处理
  43. defer func() {
  44. if r := recover(); r != nil {
  45. tx.Rollback()
  46. }
  47. }()
  48. if err := tx.Create(&role).Error; err != nil {
  49. tx.Rollback()
  50. return err
  51. }
  52. if len(adminUsers) > 0 {
  53. if _, err := u.getAdminUserValidIDs(adminUsers); err != nil {
  54. tx.Rollback()
  55. return err
  56. }
  57. users := make([]req.AdminUser, 0)
  58. for _, ID := range adminUsers {
  59. users = append(users, req.AdminUser{ID: ID})
  60. }
  61. if err := tx.Model(&role).Association("Users").Append(&users); err != nil {
  62. tx.Rollback()
  63. return err
  64. }
  65. }
  66. if len(adminPermissions) > 0 {
  67. if _, err := u.getAdminPermissionValidIDs(adminPermissions); err != nil {
  68. tx.Rollback()
  69. return err
  70. }
  71. permissions := make([]req.AdminPermission, 0)
  72. for _, ID := range adminPermissions {
  73. permissions = append(permissions, req.AdminPermission{ID: ID})
  74. }
  75. if err := tx.Model(&role).Association("Permissions").Append(&permissions); err != nil {
  76. tx.Rollback()
  77. return err
  78. }
  79. }
  80. return tx.Commit().Error
  81. }
  82. func (u *Repository) ListAdminRoles(query *pb.ListAdminRolesRequest) ([]req.AdminRole, int64, error) {
  83. var totalCount int64
  84. tx := u.db.Model(&req.AdminRole{}).Order("id desc").
  85. Preload("Users", "status = ?", pb.StatusEnum_ENABLED).
  86. Preload("Permissions", "status = ?", pb.StatusEnum_ENABLED)
  87. if query.Keyword != "" {
  88. tx.Where("name = ?", query.Keyword)
  89. }
  90. if base.IsStatusEnum(query.Status) {
  91. tx.Where("status = ?", query.Status)
  92. }
  93. tx.Count(&totalCount)
  94. roles := make([]req.AdminRole, 0)
  95. return roles, totalCount, tx.Limit(int(query.PageSize)).Offset(int((query.Page - 1) * query.PageSize)).Find(&roles).Error
  96. }
  97. // UpdateAdminRole 更新角色信息
  98. func (u *Repository) UpdateAdminRole(updateRole *pb.UpdateAdminRoleRequest) error {
  99. // 开始事务
  100. tx := u.db.Begin()
  101. // 错误处理
  102. defer func() {
  103. if r := recover(); r != nil {
  104. tx.Rollback()
  105. }
  106. }()
  107. var role req.AdminRole
  108. if err := tx.First(&role, updateRole.RoleId).Error; err != nil {
  109. tx.Rollback()
  110. return err
  111. }
  112. if err := tx.Model(&role).Association("Users").Clear(); err != nil {
  113. tx.Rollback()
  114. return err
  115. }
  116. if err := tx.Model(&role).Association("Permissions").Clear(); err != nil {
  117. tx.Rollback()
  118. return err
  119. }
  120. if len(updateRole.Users) > 0 {
  121. if _, err := u.getAdminUserValidIDs(updateRole.Users); err != nil {
  122. tx.Rollback()
  123. return err
  124. }
  125. users := make([]req.AdminUser, 0)
  126. for _, ID := range updateRole.Users {
  127. users = append(users, req.AdminUser{ID: ID})
  128. }
  129. if err := tx.Model(&role).Association("Users").Append(&users); err != nil {
  130. tx.Rollback()
  131. return err
  132. }
  133. }
  134. if len(updateRole.Permissions) > 0 {
  135. if _, err := u.getAdminUserValidIDs(updateRole.Permissions); err != nil {
  136. tx.Rollback()
  137. return err
  138. }
  139. permissions := make([]req.AdminPermission, 0)
  140. for _, ID := range updateRole.Permissions {
  141. permissions = append(permissions, req.AdminPermission{ID: ID})
  142. }
  143. if err := tx.Model(&role).Association("Permissions").Append(&permissions); err != nil {
  144. tx.Rollback()
  145. return err
  146. }
  147. }
  148. if err := tx.Model(&role).Updates(map[string]interface{}{
  149. "description": updateRole.Description,
  150. }).Error; err != nil {
  151. tx.Rollback()
  152. return err
  153. }
  154. return tx.Commit().Error
  155. }
  156. // IsAdminRoleExists 假设有一个方法用于检查角色是否存在
  157. func (u *Repository) IsAdminRoleExists(identifier interface{}) (bool, error) {
  158. var role req.AdminRole
  159. if err := u.db.Where("id = ? OR name = ?", identifier, identifier).First(&role).Error; err != nil {
  160. if errors.Is(err, gorm.ErrRecordNotFound) {
  161. return false, nil // 记录不存在,角色不存在
  162. }
  163. return false, err // 发生其他错误
  164. }
  165. return true, nil
  166. }
  167. // DeleteAdminRole 彻底删除
  168. func (u *Repository) DeleteAdminRole(roleId int64) error {
  169. // 开始事务
  170. tx := u.db.Begin()
  171. // 错误处理
  172. defer func() {
  173. if r := recover(); r != nil {
  174. tx.Rollback()
  175. }
  176. }()
  177. var role req.AdminRole
  178. // 1.查询角色
  179. if err := tx.First(&role, roleId).Error; err != nil {
  180. tx.Rollback()
  181. return err
  182. }
  183. // 2 删除关联用户
  184. if err := tx.Model(&role).Association("Users").Clear(); err != nil {
  185. tx.Rollback()
  186. return err
  187. }
  188. // 3 移除关联权限
  189. if err := tx.Model(&role).Association("Permissions").Clear(); err != nil {
  190. tx.Rollback()
  191. return err
  192. }
  193. // 4. 彻底删除
  194. if err := tx.Model(&req.AdminRole{}).Delete(&req.AdminRole{
  195. ID: roleId,
  196. }).Error; err != nil {
  197. tx.Rollback()
  198. return err
  199. }
  200. return tx.Commit().Error
  201. }
  202. func (u *Repository) RetrieveEnabledRoles() ([]req.AdminRole, error) {
  203. roles := make([]req.AdminRole, 0)
  204. return roles, u.db.Model(req.AdminRole{}).
  205. Order("id desc").
  206. Select("ID", "Name", "Description").
  207. Where("status = ?", pb.StatusEnum_ENABLED).
  208. Find(&roles).Error
  209. }
  210. func (u *Repository) ToggleAdminRole(adminRole *pb.ToggleAdminRoleRequest) error {
  211. // 开始事务
  212. tx := u.db.Begin()
  213. // 错误处理
  214. defer func() {
  215. if r := recover(); r != nil {
  216. tx.Rollback()
  217. }
  218. }()
  219. var role req.AdminRole
  220. // 1.查询角色
  221. if err := tx.First(&role, adminRole.RoleId).Error; err != nil {
  222. tx.Rollback()
  223. return err
  224. }
  225. if adminRole.Status == pb.StatusEnum_DELETED {
  226. // 1.1 删除关联用户
  227. if err := tx.Model(&role).Association("Users").Clear(); err != nil {
  228. tx.Rollback()
  229. return err
  230. }
  231. // 1.2 移除关联权限
  232. if err := tx.Model(&role).Association("Permissions").Clear(); err != nil {
  233. tx.Rollback()
  234. return err
  235. }
  236. }
  237. // 2. 更新状态
  238. if err := tx.Model(&role).Updates(map[string]interface{}{
  239. "status": adminRole.Status,
  240. }).Error; err != nil {
  241. tx.Rollback()
  242. return err
  243. }
  244. return tx.Commit().Error
  245. }