model = model('Admin'); $this->service = new AdminService(); $this->childrenAdminIds = $this->auth->getChildrenAdminIds(true); $this->childrenGroupIds = $this->auth->getChildrenGroupIds(true); $groupList = collection(AuthGroup::where('id', 'in', $this->childrenGroupIds)->select())->toArray(); Tree::instance()->init($groupList); $groupdata = []; if ($this->auth->isSuperAdmin()) { $result = Tree::instance()->getTreeList(Tree::instance()->getTreeArray(1)); foreach ($result as $k => $v) { $groupdata[$v['id']] = $v['name']; } } else { $result = []; $groups = $this->auth->getGroups(); foreach ($groups as $m => $n) { $childlist = Tree::instance()->getTreeList(Tree::instance()->getTreeArray($n['id'])); $temp = []; foreach ($childlist as $k => $v) { $temp[$v['id']] = $v['name']; } $result[__($n['name'])] = $temp; } $groupdata = $result; } $this->view->assign('groupdata', $groupdata); $this->assignconfig("admin", ['id' => $this->auth->id]); } /** * 查看 */ public function index() { $institution_id = $this->request->get("institution_id", ''); if ($this->request->isAjax()) { //如果发送的来源是Selectpage,则转发到Selectpage if ($this->request->request('keyField')) { return $this->selectpage(); } $childrenGroupIds = $this->childrenGroupIds; $groupName = AuthGroup::where('id', 'in', $childrenGroupIds) ->column('id,name'); $authGroupList = AuthGroupAccess::where('group_id', 'in', $childrenGroupIds) ->field('uid,group_id') ->select(); $adminGroupName = []; foreach ($authGroupList as $k => $v) { if (isset($groupName[$v['group_id']])) { $adminGroupName[$v['uid']][$v['group_id']] = $groupName[$v['group_id']]; } } $groups = $this->auth->getGroups(); foreach ($groups as $m => $n) { $adminGroupName[$this->auth->id][$n['id']] = $n['name']; } // 机构搜索 $filter = $this->request->param('institution_text'); $searchInsIds = false; if(!empty($filter)){ $searchInsIds = explode(',', $filter); } list($where, $sort, $order, $offset, $limit) = $this->buildparams(); // 仅可见当前机构以及下级机构下的管理员 if($this->auth->isSuperAdmin()){ if(!empty($searchInsIds)){ $visible_ids = $this->service->getVisibleUid($searchInsIds); $more = ['id'=>['in', $visible_ids]]; } else { $more = false ; } $childInsIds = AuthInstitutionAccess::where(true)->column('institution_id'); } else { $childInsIds = $this->auth->getUserInfo()['institution']['child_institution']; $searchIds = $searchInsIds ? $searchInsIds : $childInsIds; $visible_ids = $this->service->getVisibleUid($searchIds); $more = ['id'=>['in', $visible_ids]]; } // 机构名称 $insName = Institution::whereIn('id',$childInsIds)->column('id,name'); $authInsList = AuthInstitutionAccess::whereIn('institution_id',$childInsIds)->field('uid,institution_id')->select(); $adminInsName = []; foreach ($authInsList as $k => $v) { if (isset($insName[$v['institution_id']])) { $adminInsName[$v['uid']][$v['institution_id']] = $insName[$v['institution_id']]; } } $group_where = false; if($this->request->has('group_id')){ $admin_ids = model(AuthGroupAccess::class) ->where('group_id', $this->request->param('group_id')) ->column('uid'); $group_where = [ 'id' => ['in', $admin_ids] ]; } if(empty($institution_id)) { $total = $this->model ->where($where) ->where($group_where) ->where('id', 'in', $this->childrenAdminIds) ->where($more) ->order($sort, $order) ->count(); $list = $this->model ->where($where) ->where($group_where) ->where('id', 'in', $this->childrenAdminIds) ->where($more) ->field(['password', 'salt', 'token'], true) ->order($sort, $order) ->limit($offset, $limit) ->select(); }else{ $total = $this->model ->alias('a') ->join(['fa_auth_institution_access'=>'i'],'i.uid=a.id') ->where('i.institution_id',$institution_id) ->where($where) ->where($group_where) ->where('a.id', 'in', $this->childrenAdminIds) ->where($more) ->order($sort, $order) ->count(); $list = $this->model ->alias('a') ->join(['fa_auth_institution_access'=>'i'],'i.uid=a.id') ->where('i.institution_id',$institution_id) ->where($where) ->where($group_where) ->where('a.id', 'in', $this->childrenAdminIds) ->where($more) ->field(['a.password', 'a.salt', 'a.token'], true) ->order($sort, $order) ->limit($offset, $limit) ->select(); } // 获取机构名称 foreach ($list as $k => &$v) { foreach ($v->toArray() as $k1 => $v1) { $v[strtolower($k1)] = $v1; } $groups = isset($adminGroupName[$v['id']]) ? $adminGroupName[$v['id']] : []; $v['groups'] = implode(',', array_keys($groups)); $v['groups_text'] = implode(',', array_values($groups)); $institution = isset($adminInsName[$v['id']]) ? $adminInsName[$v['id']] : []; $v['institution'] = implode(',', array_keys($institution)); $v['institution_text'] = implode(',', array_values($institution)); } unset($v); $result = array("total" => $total, "rows" => $list); return json($result); } return $this->view->fetch(); } /** * 添加 */ public function add() { if ($this->request->isPost()) { $this->token(); $params = $this->request->post("row/a"); if ($params) { if(!preg_match("/^(?=.*[a-z])(?=.*[A-Z])(?=.*\d)[\s\S]{8,16}$/",$params['password'])) { $this->error("至少8-16个字符,至少1个大写字母,1个小写字母和1个数字,其他可以是任意字符"); } $params['salt'] = Random::alnum(); $params['password'] = md5(md5($params['password']) . $params['salt']); $params['avatar'] = '/assets/img/avatar.png'; //设置新管理员默认头像。 $result = $this->model->validate('Admin.add')->save($params); if ($result === false) { $this->error($this->model->getError()); } $group = $this->request->post("group/a"); //过滤不允许的组别,避免越权 $group = array_intersect($this->childrenGroupIds, $group); foreach ($group as $value) { $dataset[] = ['uid' => $this->model->id, 'group_id' => $value]; } model('AuthGroupAccess')->saveAll($dataset); // 添加机构 $institution_ids = explode(',',$this->request->post('institution')); $this->service->saveInstitutionAccess($this->model->id, $institution_ids); $this->success(); } $this->error(); } return $this->view->fetch(); } /** * 编辑 */ public function edit($ids = null) { $row = $this->model->get(['id' => $ids]); if (!$row) { $this->error(__('No Results were found')); } if (!in_array($row->id, $this->childrenAdminIds)) { $this->error(__('You have no permission')); } if ($this->request->isPost()) { $this->token(); $params = $this->request->post("row/a"); if ($params) { if ($params['password']) { if(!preg_match("/^(?=.*[a-z])(?=.*[A-Z])(?=.*\d)[\s\S]{8,16}$/",$params['password'])) { $this->error("至少8-16个字符,至少1个大写字母,1个小写字母和1个数字,其他可以是任意字符"); } $params['salt'] = Random::alnum(); $params['password'] = md5(md5($params['password']) . $params['salt']); } else { unset($params['password'], $params['salt']); } //这里需要针对username和email做唯一验证 $adminValidate = \think\Loader::validate('Admin'); $adminValidate->rule([ 'username' => 'require|regex:\w{3,12}|unique:admin,username,' . $row->id, // 'email' => 'require|email|unique:admin,email,' . $row->id, 'password' => 'regex:\S{32}', ]); $result = $row->validate('Admin.edit')->save($params); if ($result === false) { $this->error($row->getError()); } // 先移除所有权限 model('AuthGroupAccess')->where('uid', $row->id)->delete(); $group = $this->request->post("group/a"); // 过滤不允许的组别,避免越权 $group = array_intersect($this->childrenGroupIds, $group); $dataset = []; foreach ($group as $value) { $dataset[] = ['uid' => $row->id, 'group_id' => $value]; } model('AuthGroupAccess')->saveAll($dataset); // 添加机构 $institution_ids = explode(',',$this->request->post('institution')); $this->service->saveInstitutionAccess($ids, $institution_ids); $this->success(); } $this->error(); } $grouplist = $this->auth->getGroups($row['id']); $groupids = []; foreach ($grouplist as $k => $v) { $groupids[] = $v['id']; } $institution = implode(',',AuthInstitutionAccess::where('uid',$ids)->column('institution_id')); $this->view->assign("row", $row); $this->view->assign("groupids", $groupids); $this->view->assign("institution", $institution); return $this->view->fetch(); } /** * 删除 */ public function del($ids = "") { if ($ids) { $ids = array_intersect($this->childrenAdminIds, array_filter(explode(',', $ids))); // 避免越权删除管理员 $childrenGroupIds = $this->childrenGroupIds; $adminList = $this->model->where('id', 'in', $ids)->where('id', 'in', function ($query) use ($childrenGroupIds) { $query->name('auth_group_access')->where('group_id', 'in', $childrenGroupIds)->field('uid'); })->select(); if ($adminList) { $deleteIds = []; foreach ($adminList as $k => $v) { $deleteIds[] = $v->id; } $deleteIds = array_values(array_diff($deleteIds, [$this->auth->id])); if ($deleteIds) { $this->model->destroy($deleteIds); model('AuthGroupAccess')->where('uid', 'in', $deleteIds)->delete(); $this->success(); } } } $this->error(__('You have no permission')); } /** * 批量更新 * @internal */ public function multi($ids = "") { // 管理员禁止批量操作 $this->error(); } /** * 下拉搜索 */ public function selectpage() { $this->dataLimit = 'auth'; $this->dataLimitField = 'id'; return parent::selectpage(); } }