You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
 
 
 
 
 
 

172 lines
5.3 KiB

package console
import (
"time"
"yunyan/pb"
"github.com/gin-gonic/gin"
)
// 后台账号管理 handlers(仅超管可访问,路由已用 requireIdentity(Admin) 守卫)。
// 角色 Identity:1 超管 / 2 管理员 / 3 代理商 / 4 运营。账号存 console 主库 console_account 表,
// 密码 bcrypt 哈希。引导超管(yaml AdminAccount)不入表,故列表里看不到,也不能被改/删。
// validIdentity 限定可分配的角色取值(1~4)。
func validIdentity(idt pb.Identity) bool {
return idt >= pb.Identity_Admin && idt <= pb.Identity_Operator
}
// accountsList 账号列表(Password 字段 json:"-",不外泄)。
func (this *serverComp) accountsList(c *gin.Context) {
list, err := this.module.model.listAccounts()
if err != nil {
writeErr(c, pb.ErrorCode_DBError, err.Error())
return
}
writeOK(c, list)
}
// accountsAdd 新建账号。校验用户名唯一(且不撞引导超管)、角色合法、密码非空。
func (this *serverComp) accountsAdd(c *gin.Context) {
var req struct {
Username string `json:"username"`
Password string `json:"password"`
Identity pb.Identity `json:"identity"`
Remark string `json:"remark"`
Enabled bool `json:"enabled"`
Access string `json:"access"` // 可访问页面 CSV
Apps string `json:"apps"` // 绑定应用名称 CSV
Regions string `json:"regions"` // 绑定区域代码 CSV
Products string `json:"products"` // 绑定产品 id CSV
}
if err := c.ShouldBindJSON(&req); err != nil {
writeErr(c, pb.ErrorCode_ReqParameterError, err.Error())
return
}
if req.Username == "" || req.Password == "" {
writeErr(c, pb.ErrorCode_ReqParameterError, "用户名和密码必填")
return
}
if !validIdentity(req.Identity) {
writeErr(c, pb.ErrorCode_ReqParameterError, "角色非法(1超管/2管理员/3代理商/4运营)")
return
}
if req.Username == this.options.AdminAccount {
writeErr(c, pb.ErrorCode_ReqParameterError, "用户名与引导超管冲突,请换一个")
return
}
if exist, _ := this.module.model.getAccountByName(req.Username); exist != nil && exist.Id != 0 {
writeErr(c, pb.ErrorCode_ReqParameterError, "用户名已存在")
return
}
hash, err := hashPassword(req.Password)
if err != nil {
writeErr(c, pb.ErrorCode_SystemError, err.Error())
return
}
now := time.Now().Unix()
model := &Account{
Username: req.Username,
Password: hash,
Identity: req.Identity,
Enabled: req.Enabled,
Remark: req.Remark,
Access: req.Access,
Apps: req.Apps,
Regions: req.Regions,
Products: req.Products,
Createtime: now,
Updatetime: now,
}
if err := this.module.model.addAccount(model); err != nil {
writeErr(c, pb.ErrorCode_DBError, err.Error())
return
}
writeOK(c, model)
}
// accountsUpdate 改账号(角色/启用/备注;不在此改密码,改密走 resetpwd)。
func (this *serverComp) accountsUpdate(c *gin.Context) {
var req struct {
Id uint32 `json:"id"`
Identity pb.Identity `json:"identity"`
Remark string `json:"remark"`
Enabled bool `json:"enabled"`
Access string `json:"access"`
Apps string `json:"apps"`
Regions string `json:"regions"`
Products string `json:"products"`
}
if err := c.ShouldBindJSON(&req); err != nil || req.Id == 0 {
writeErr(c, pb.ErrorCode_ReqParameterError, "id 必填")
return
}
if !validIdentity(req.Identity) {
writeErr(c, pb.ErrorCode_ReqParameterError, "角色非法(1超管/2管理员/3代理商/4运营)")
return
}
model, err := this.module.model.getAccount(req.Id)
if err != nil || model.Id == 0 {
writeErr(c, pb.ErrorCode_DBError, "账号不存在")
return
}
model.Identity = req.Identity
model.Remark = req.Remark
model.Enabled = req.Enabled
model.Access = req.Access
model.Apps = req.Apps
model.Regions = req.Regions
model.Products = req.Products
model.Updatetime = time.Now().Unix()
if err := this.module.model.saveAccount(model); err != nil {
writeErr(c, pb.ErrorCode_DBError, err.Error())
return
}
writeOK(c, model)
}
// accountsResetPwd 重置某账号密码(bcrypt 重新哈希)。
func (this *serverComp) accountsResetPwd(c *gin.Context) {
var req struct {
Id uint32 `json:"id"`
Password string `json:"password"`
}
if err := c.ShouldBindJSON(&req); err != nil || req.Id == 0 || req.Password == "" {
writeErr(c, pb.ErrorCode_ReqParameterError, "id 和新密码必填")
return
}
model, err := this.module.model.getAccount(req.Id)
if err != nil || model.Id == 0 {
writeErr(c, pb.ErrorCode_DBError, "账号不存在")
return
}
hash, err := hashPassword(req.Password)
if err != nil {
writeErr(c, pb.ErrorCode_SystemError, err.Error())
return
}
model.Password = hash
model.Updatetime = time.Now().Unix()
if err := this.module.model.saveAccount(model); err != nil {
writeErr(c, pb.ErrorCode_DBError, err.Error())
return
}
writeOK(c, gin.H{"id": req.Id})
}
// accountsDel 删除账号。
func (this *serverComp) accountsDel(c *gin.Context) {
var req struct {
Id uint32 `json:"id"`
}
if err := c.ShouldBindJSON(&req); err != nil || req.Id == 0 {
writeErr(c, pb.ErrorCode_ReqParameterError, "id 必填")
return
}
if err := this.module.model.delAccount(req.Id); err != nil {
writeErr(c, pb.ErrorCode_DBError, err.Error())
return
}
writeOK(c, gin.H{"id": req.Id})
}