Skip to content
Projects
Groups
Snippets
Help
This project
Loading...
Sign in / Register
Toggle navigation
T
tl_estate
Project
Project
Details
Activity
Cycle Analytics
Repository
Repository
Files
Commits
Branches
Tags
Contributors
Graph
Compare
Charts
Issues
0
Issues
0
List
Board
Labels
Milestones
Merge Requests
0
Merge Requests
0
CI / CD
CI / CD
Pipelines
Jobs
Schedules
Charts
Wiki
Wiki
Snippets
Snippets
Members
Members
Collapse sidebar
Close sidebar
Activity
Graph
Charts
Create a new issue
Jobs
Commits
Issue Boards
Open sidebar
hujun
tl_estate
Commits
3a433cf8
Commit
3a433cf8
authored
Jan 16, 2018
by
hujun
Browse files
Options
Browse Files
Download
Email Patches
Plain Diff
角色页面显示
parent
ff3bd825
Hide whitespace changes
Inline
Side-by-side
Showing
2 changed files
with
215 additions
and
215 deletions
+215
-215
AuthUntils.php
application/index/untils/AuthUntils.php
+75
-140
AuthUntils.php~HEAD_0
application/index/untils/AuthUntils.php~HEAD_0
+140
-75
No files found.
application/index/untils/AuthUntils.php
View file @
3a433cf8
...
@@ -8,13 +8,13 @@
...
@@ -8,13 +8,13 @@
// +----------------------------------------------------------------------
// +----------------------------------------------------------------------
// | Author: luofei614 <weibo.com/luofei614>
// | Author: luofei614 <weibo.com/luofei614>
// +----------------------------------------------------------------------
// +----------------------------------------------------------------------
namespace
app\index\u
ntils
;
namespace
app\index\u
til
;
use
think\Db
;
use
think\Db
;
use
think\Config
;
use
think\Config
;
use
think\Session
;
use
think\Session
;
use
think\Request
;
use
think\Request
;
use
think\Loader
;
use
think\Loader
;
/**
/**
* 权限认证类
* 权限认证类
...
@@ -72,189 +72,132 @@ DROP TABLE IF EXISTS `think_auth_group_access`;
...
@@ -72,189 +72,132 @@ DROP TABLE IF EXISTS `think_auth_group_access`;
) ENGINE=MyISAM DEFAULT CHARSET=utf8;
) ENGINE=MyISAM DEFAULT CHARSET=utf8;
*/
*/
class
AuthUntils
class
Auth
{
{
/**
* @var object 对象实例
*/
protected
static
$instance
;
/**
* 当前请求实例
* @var Request
*/
protected
$request
;
//默认配置
//默认配置
protected
$
config
=
[
protected
$
_config
=
array
(
'auth_on'
=>
1
,
// 权限
开关
'auth_on'
=>
true
,
// 认证
开关
'auth_type'
=>
1
,
// 认证方式,1为实时认证;2为登录认证。
'auth_type'
=>
1
,
// 认证方式,1为实时认证;2为登录认证。
'auth_group'
=>
'auth_group
'
,
// 用户组数据表名
'auth_group'
=>
'__AUTH_GROUP__
'
,
// 用户组数据表名
'auth_group_access'
=>
'auth_group_access'
,
// 用户-用户组关系表
'auth_group_access'
=>
'auth_group_access'
,
// 用户-用户组关系表
'auth_rule'
=>
'auth_rule'
,
// 权限规则表
'auth_rule'
=>
'auth_rule'
,
// 权限规则表
'auth_user'
=>
'agents'
,
// 用户信息表
'auth_user'
=>
'member'
// 用户信息表
];
);
/**
* 类架构函数
* Auth constructor.
*/
public
function
__construct
()
{
//可设置配置项 auth, 此配置项为数组。
if
(
$auth
=
Config
::
get
(
'auth'
))
{
$this
->
config
=
array_merge
(
$this
->
config
,
$auth
);
}
// 初始化request
$this
->
request
=
Request
::
instance
();
}
/**
public
function
__construct
()
{
* 初始化
$t
=
config
(
'auth_config'
);
* @access public
if
(
config
(
'auth_config'
))
{
* @param array $options 参数
//可设置配置项 auth_config, 此配置项为数组。
* @return \think\Request
$this
->
_config
=
array_merge
(
$this
->
_config
,
config
(
'auth_config'
));
*/
public
static
function
instance
(
$options
=
[])
{
if
(
is_null
(
self
::
$instance
))
{
self
::
$instance
=
new
static
(
$options
);
}
}
return
self
::
$instance
;
}
}
/**
/**
* 检查权限
* 检查权限
* @param $name string|array 需要验证的规则列表,支持逗号分隔的权限规则或索引数组
* @param name string|array 需要验证的规则列表,支持逗号分隔的权限规则或索引数组
* @param $uid int 认证用户的id
* @param uid int 认证用户的id
* @param int $type 认证类型
* @param string mode 执行check的模式
* @param string $mode 执行check的模式
* @param relation string 如果为 'or' 表示满足任一条规则即通过验证;如果为 'and'则表示需满足所有规则才能通过验证
* @param string $relation 如果为 'or' 表示满足任一条规则即通过验证;如果为 'and'则表示需满足所有规则才能通过验证
* @return boolean 通过验证返回true;失败返回false
* @return bool 通过验证返回true;失败返回false
*/
*/
public
function
check
(
$name
,
$uid
,
$type
=
1
,
$mode
=
'url'
,
$relation
=
'or'
)
public
function
check
(
$name
,
$uid
,
$type
=
1
,
$mode
=
'url'
,
$relation
=
'or'
)
{
{
if
(
!
$this
->
_config
[
'auth_on'
])
if
(
!
$this
->
config
[
'auth_on'
])
{
return
true
;
}
$count
=
Db
::
name
(
$this
->
config
[
'auth_rule'
])
->
where
(
'name'
,
$name
)
->
count
();
if
(
$count
==
0
)
{
return
true
;
return
true
;
}
$authList
=
$this
->
getAuthList
(
$uid
,
$type
);
//获取用户需要验证的所有有效规则列表
// 获取用户需要验证的所有有效规则列表
$authList
=
$this
->
getAuthList
(
$uid
,
$type
);
if
(
is_string
(
$name
))
{
if
(
is_string
(
$name
))
{
$name
=
strtolower
(
$name
);
$name
=
strtolower
(
$name
);
if
(
strpos
(
$name
,
','
)
!==
false
)
{
if
(
strpos
(
$name
,
','
)
!==
false
)
{
$name
=
explode
(
','
,
$name
);
$name
=
explode
(
','
,
$name
);
}
else
{
}
else
{
$name
=
[
$name
]
;
$name
=
array
(
$name
)
;
}
}
}
}
$list
=
[]
;
//保存验证通过的规则名
$list
=
array
()
;
//保存验证通过的规则名
if
(
'url'
==
$mode
)
{
if
(
$mode
==
'url'
)
{
$REQUEST
=
unserialize
(
strtolower
(
serialize
(
$
this
->
request
->
param
()
)));
$REQUEST
=
unserialize
(
strtolower
(
serialize
(
$
_REQUEST
)));
}
}
foreach
(
$authList
as
$auth
)
{
foreach
(
$authList
as
$auth
)
{
$query
=
preg_replace
(
'/^.+\?/U'
,
''
,
$auth
);
$query
=
preg_replace
(
'/^.+\?/U'
,
''
,
$auth
);
if
(
'url'
==
$mode
&&
$query
!=
$auth
)
{
if
(
$mode
==
'url'
&&
$query
!=
$auth
)
{
parse_str
(
$query
,
$param
);
//解析规则中的param
parse_str
(
$query
,
$param
);
//解析规则中的param
$intersect
=
array_intersect_assoc
(
$REQUEST
,
$param
);
$intersect
=
array_intersect_assoc
(
$REQUEST
,
$param
);
$auth
=
preg_replace
(
'/\?.*$/U'
,
''
,
$auth
);
$auth
=
preg_replace
(
'/\?.*$/U'
,
''
,
$auth
);
if
(
in_array
(
$auth
,
$name
)
&&
$intersect
==
$param
)
{
if
(
in_array
(
$auth
,
$name
)
&&
$intersect
==
$param
)
{
//如果节点相符且url参数满足
//如果节点相符且url参数满足
$list
[]
=
$auth
;
}
}
else
{
if
(
in_array
(
$auth
,
$name
))
{
$list
[]
=
$auth
;
$list
[]
=
$auth
;
}
}
}
else
if
(
in_array
(
$auth
,
$name
))
{
$list
[]
=
$auth
;
}
}
}
}
if
(
'or'
==
$relation
&&
!
empty
(
$list
))
{
if
(
$relation
==
'or'
and
!
empty
(
$list
))
{
return
true
;
return
true
;
}
}
$diff
=
array_diff
(
$name
,
$list
);
$diff
=
array_diff
(
$name
,
$list
);
if
(
'and'
==
$relation
&&
empty
(
$diff
))
{
if
(
$relation
==
'and'
and
empty
(
$diff
))
{
return
true
;
return
true
;
}
}
return
false
;
return
false
;
}
}
/**
/**
* 根据用户id获取用户组,返回值为数组
* 根据用户id获取用户组,返回值为数组
* @param
$
uid int 用户id
* @param uid int 用户id
* @return array 用户所属的用户组 array(
* @return array 用户所属的用户组 array(
*
array('uid'=>'用户id','group_id'=>'用户组id','title'=>'用户组名称','rules'=>'用户组拥有的规则id,多个,号隔开'),
* array('uid'=>'用户id','group_id'=>'用户组id','title'=>'用户组名称','rules'=>'用户组拥有的规则id,多个,号隔开'),
*
...)
* ...)
*/
*/
public
function
getGroups
(
$uid
=
''
)
public
function
getGroups
(
$uid
)
{
{
static
$groups
=
array
();
static
$groups
=
[];
if
(
isset
(
$groups
[
$uid
]))
if
(
isset
(
$groups
[
$uid
]))
{
return
$groups
[
$uid
];
return
$groups
[
$uid
];
}
$user_groups
=
\think\Db
::
name
(
$this
->
_config
[
'auth_group_access'
])
// 转换表名
->
alias
(
'a'
)
$auth_group_access
=
Loader
::
parseName
(
$this
->
config
[
'auth_group_access'
],
0
);
->
join
(
$this
->
_config
[
'auth_group'
]
.
" g"
,
"g.id=a.group_id"
)
$auth_group
=
Loader
::
parseName
(
$this
->
config
[
'auth_group'
],
0
);
->
where
(
"a.uid='
$uid
' and g.status='1'"
)
->
field
(
'uid,group_id,title,rules'
)
->
select
();
// 执行查询
$groups
[
$uid
]
=
$user_groups
?
$user_groups
:
array
();
// $user_groups = Db::view($auth_group_access, 'uid,group_id')
// ->view($auth_group, 'title,rules', "{$auth_group_access}.group_id={$auth_group}.id", 'LEFT')
// ->where("{$auth_group_access}.uid='{$uid}' and {$auth_group}.status='1'")
// ->select();
$user_groups
=
Db
::
name
(
$auth_group_access
)
->
alias
(
'a'
)
->
where
(
"a.uid='
$uid
' and g.status='1'"
)
->
join
(
$auth_group
.
' g'
,
'a.group_id=g.id'
)
->
select
();
$groups
[
$uid
]
=
$user_groups
?:
[];
return
$groups
[
$uid
];
return
$groups
[
$uid
];
}
}
/**
/**
* 获得权限列表
* 获得权限列表
* @param integer $uid 用户id
* @param integer $uid
用户id
* @param integer $type
* @param integer $type
* @return array
*/
*/
protected
function
getAuthList
(
$uid
,
$type
)
protected
function
getAuthList
(
$uid
,
$type
)
{
{
static
$_authList
=
array
();
//保存用户验证通过的权限列表
static
$_authList
=
[];
//保存用户验证通过的权限列表
$t
=
implode
(
','
,
(
array
)
$type
);
$t
=
implode
(
','
,
(
array
)
$type
);
if
(
isset
(
$_authList
[
$uid
.
$t
]))
{
if
(
isset
(
$_authList
[
$uid
.
$t
]))
{
return
$_authList
[
$uid
.
$t
];
return
$_authList
[
$uid
.
$t
];
}
}
if
(
2
==
$this
->
config
[
'auth_type'
]
&&
Session
::
has
(
'_auth_list_'
.
$uid
.
$t
))
{
if
(
$this
->
_config
[
'auth_type'
]
==
2
&&
isset
(
$_SESSION
[
'_auth_list_'
.
$uid
.
$t
]
))
{
return
Session
::
get
(
'_auth_list_'
.
$uid
.
$t
)
;
return
$_SESSION
[
'_auth_list_'
.
$uid
.
$t
]
;
}
}
//读取用户所属用户组
//读取用户所属用户组
$groups
=
$this
->
getGroups
(
$uid
);
$groups
=
$this
->
getGroups
(
$uid
);
$ids
=
[]
;
//保存用户所属用户组设置的所有权限规则id
$ids
=
array
()
;
//保存用户所属用户组设置的所有权限规则id
foreach
(
$groups
as
$g
)
{
foreach
(
$groups
as
$g
)
{
$ids
=
array_merge
(
$ids
,
explode
(
','
,
trim
(
$g
[
'rules'
],
','
)));
$ids
=
array_merge
(
$ids
,
explode
(
','
,
trim
(
$g
[
'rules'
],
','
)));
}
}
$ids
=
array_unique
(
$ids
);
$ids
=
array_unique
(
$ids
);
if
(
empty
(
$ids
))
{
if
(
empty
(
$ids
))
{
$_authList
[
$uid
.
$t
]
=
[]
;
$_authList
[
$uid
.
$t
]
=
array
()
;
return
array
();
return
[];
}
}
$map
=
array
(
$map
=
[
'id'
=>
array
(
'in'
,
$ids
),
'
id'
=>
[
'in'
,
$ids
]
,
'
type'
=>
$type
,
'
type'
=>
$type
'
status'
=>
1
,
]
;
)
;
//读取用户组所有权限规则
//读取用户组所有权限规则
$rules
=
Db
::
name
(
$this
->
config
[
'auth_rule'
])
->
where
(
$map
)
->
field
(
'condition,name'
)
->
select
();
$rules
=
\think\Db
::
name
(
$this
->
_
config
[
'auth_rule'
])
->
where
(
$map
)
->
field
(
'condition,name'
)
->
select
();
//循环规则,判断结果。
//循环规则,判断结果。
$authList
=
[];
//
$authList
=
array
();
//
foreach
(
$rules
as
$rule
)
{
foreach
(
$rules
as
$rule
)
{
if
(
!
empty
(
$rule
[
'condition'
]))
{
if
(
!
empty
(
$rule
[
'condition'
]))
{
//根据condition进行验证
//根据condition进行验证
$user
=
$this
->
getUserInfo
(
$uid
);
//获取用户信息,一维数组
$user
=
$this
->
getUserInfo
(
$uid
);
//获取用户信息,一维数组
$command
=
preg_replace
(
'/\{(\w*?)\}/'
,
'$user[\'\\1\']'
,
$rule
[
'condition'
]);
$command
=
preg_replace
(
'/\{(\w*?)\}/'
,
'$user[\'\\1\']'
,
$rule
[
'condition'
]);
//dump($command);//debug
@
(
eval
(
'$condition=('
.
$command
.
');'
));
@
(
eval
(
'$condition=('
.
$command
.
');'
));
if
(
$condition
)
{
if
(
$condition
)
{
$authList
[]
=
strtolower
(
$rule
[
'name'
]);
$authList
[]
=
strtolower
(
$rule
[
'name'
]);
...
@@ -265,30 +208,22 @@ class AuthUntils
...
@@ -265,30 +208,22 @@ class AuthUntils
}
}
}
}
$_authList
[
$uid
.
$t
]
=
$authList
;
$_authList
[
$uid
.
$t
]
=
$authList
;
if
(
2
==
$this
->
config
[
'auth_type'
]
)
{
if
(
$this
->
_config
[
'auth_type'
]
==
2
)
{
//规则列表结果保存到session
//规则列表结果保存到session
Session
::
set
(
'_auth_list_'
.
$uid
.
$t
,
$authList
)
;
$_SESSION
[
'_auth_list_'
.
$uid
.
$t
]
=
$authList
;
}
}
return
array_unique
(
$authList
);
return
array_unique
(
$authList
);
}
}
/**
/**
* 获得用户资料
* 获得用户资料,根据自己的情况读取数据库
* @param $uid
* @return mixed
*/
*/
protected
function
getUserInfo
(
$uid
)
protected
function
getUserInfo
(
$uid
)
{
{
static
$userinfo
=
array
();
static
$user_info
=
[];
if
(
!
isset
(
$userinfo
[
$uid
]))
{
$userinfo
[
$uid
]
=
\think\Db
::
name
(
$this
->
_config
[
'auth_user'
])
->
where
(
array
(
'uid'
=>
$uid
))
->
find
();
$user
=
Db
::
name
(
$this
->
config
[
'auth_user'
]);
// 获取用户表主键
$_pk
=
is_string
(
$user
->
getPk
())
?
$user
->
getPk
()
:
'uid'
;
if
(
!
isset
(
$user_info
[
$uid
]))
{
$user_info
[
$uid
]
=
$user
->
where
(
$_pk
,
$uid
)
->
find
();
}
}
return
$userinfo
[
$uid
];
return
$user_info
[
$uid
];
}
}
}
}
application/index/untils/Auth
.php
→
application/index/untils/Auth
Untils.php~HEAD_0
View file @
3a433cf8
...
@@ -8,13 +8,13 @@
...
@@ -8,13 +8,13 @@
// +----------------------------------------------------------------------
// +----------------------------------------------------------------------
// | Author: luofei614 <weibo.com/luofei614>
// | Author: luofei614 <weibo.com/luofei614>
// +----------------------------------------------------------------------
// +----------------------------------------------------------------------
namespace
app\index\u
til
;
namespace
app\index\u
ntils
;
use
think\Db
;
use
think\Db
;
use
think\Config
;
use
think\Config
;
use
think\Session
;
use
think\Session
;
use
think\Request
;
use
think\Request
;
use
think\Loader
;
use
think\Loader
;
/**
/**
* 权限认证类
* 权限认证类
...
@@ -72,132 +72,189 @@ DROP TABLE IF EXISTS `think_auth_group_access`;
...
@@ -72,132 +72,189 @@ DROP TABLE IF EXISTS `think_auth_group_access`;
) ENGINE=MyISAM DEFAULT CHARSET=utf8;
) ENGINE=MyISAM DEFAULT CHARSET=utf8;
*/
*/
class
Auth
{
class
AuthUntils
{
/**
* @var object 对象实例
*/
protected
static
$instance
;
/**
* 当前请求实例
* @var Request
*/
protected
$request
;
//默认配置
//默认配置
protected
$
_config
=
array
(
protected
$
config
=
[
'auth_on'
=>
true
,
// 认证
开关
'auth_on'
=>
1
,
// 权限
开关
'auth_type'
=>
1
,
// 认证方式,1为实时认证;2为登录认证。
'auth_type'
=>
1
,
// 认证方式,1为实时认证;2为登录认证。
'auth_group'
=>
'__AUTH_GROUP__
'
,
// 用户组数据表名
'auth_group'
=>
'auth_group
'
,
// 用户组数据表名
'auth_group_access'
=>
'auth_group_access'
,
// 用户-用户组关系表
'auth_group_access'
=>
'auth_group_access'
,
// 用户-用户组关系表
'auth_rule'
=>
'auth_rule'
,
// 权限规则表
'auth_rule'
=>
'auth_rule'
,
// 权限规则表
'auth_user'
=>
'member'
// 用户信息表
'auth_user'
=>
'agents'
,
// 用户信息表
);
];
/**
* 类架构函数
* Auth constructor.
*/
public
function
__construct
()
{
//可设置配置项 auth, 此配置项为数组。
if
(
$auth
=
Config
::
get
(
'auth'
))
{
$this
->
config
=
array_merge
(
$this
->
config
,
$auth
);
}
// 初始化request
$this
->
request
=
Request
::
instance
();
}
public
function
__construct
()
{
/**
$t
=
config
(
'auth_config'
);
* 初始化
if
(
config
(
'auth_config'
))
{
* @access public
//可设置配置项 auth_config, 此配置项为数组。
* @param array $options 参数
$this
->
_config
=
array_merge
(
$this
->
_config
,
config
(
'auth_config'
));
* @return \think\Request
*/
public
static
function
instance
(
$options
=
[])
{
if
(
is_null
(
self
::
$instance
))
{
self
::
$instance
=
new
static
(
$options
);
}
}
return
self
::
$instance
;
}
}
/**
/**
* 检查权限
* 检查权限
* @param name string|array 需要验证的规则列表,支持逗号分隔的权限规则或索引数组
* @param $name string|array 需要验证的规则列表,支持逗号分隔的权限规则或索引数组
* @param uid int 认证用户的id
* @param $uid int 认证用户的id
* @param string mode 执行check的模式
* @param int $type 认证类型
* @param relation string 如果为 'or' 表示满足任一条规则即通过验证;如果为 'and'则表示需满足所有规则才能通过验证
* @param string $mode 执行check的模式
* @return boolean 通过验证返回true;失败返回false
* @param string $relation 如果为 'or' 表示满足任一条规则即通过验证;如果为 'and'则表示需满足所有规则才能通过验证
* @return bool 通过验证返回true;失败返回false
*/
*/
public
function
check
(
$name
,
$uid
,
$type
=
1
,
$mode
=
'url'
,
$relation
=
'or'
)
{
public
function
check
(
$name
,
$uid
,
$type
=
1
,
$mode
=
'url'
,
$relation
=
'or'
)
if
(
!
$this
->
_config
[
'auth_on'
])
{
if
(
!
$this
->
config
[
'auth_on'
])
{
return
true
;
}
$count
=
Db
::
name
(
$this
->
config
[
'auth_rule'
])
->
where
(
'name'
,
$name
)
->
count
();
if
(
$count
==
0
)
{
return
true
;
return
true
;
$authList
=
$this
->
getAuthList
(
$uid
,
$type
);
//获取用户需要验证的所有有效规则列表
}
// 获取用户需要验证的所有有效规则列表
$authList
=
$this
->
getAuthList
(
$uid
,
$type
);
if
(
is_string
(
$name
))
{
if
(
is_string
(
$name
))
{
$name
=
strtolower
(
$name
);
$name
=
strtolower
(
$name
);
if
(
strpos
(
$name
,
','
)
!==
false
)
{
if
(
strpos
(
$name
,
','
)
!==
false
)
{
$name
=
explode
(
','
,
$name
);
$name
=
explode
(
','
,
$name
);
}
else
{
}
else
{
$name
=
array
(
$name
)
;
$name
=
[
$name
]
;
}
}
}
}
$list
=
array
()
;
//保存验证通过的规则名
$list
=
[]
;
//保存验证通过的规则名
if
(
$mode
==
'url'
)
{
if
(
'url'
==
$mode
)
{
$REQUEST
=
unserialize
(
strtolower
(
serialize
(
$
_REQUEST
)));
$REQUEST
=
unserialize
(
strtolower
(
serialize
(
$
this
->
request
->
param
()
)));
}
}
foreach
(
$authList
as
$auth
)
{
foreach
(
$authList
as
$auth
)
{
$query
=
preg_replace
(
'/^.+\?/U'
,
''
,
$auth
);
$query
=
preg_replace
(
'/^.+\?/U'
,
''
,
$auth
);
if
(
$mode
==
'url'
&&
$query
!=
$auth
)
{
if
(
'url'
==
$mode
&&
$query
!=
$auth
)
{
parse_str
(
$query
,
$param
);
//解析规则中的param
parse_str
(
$query
,
$param
);
//解析规则中的param
$intersect
=
array_intersect_assoc
(
$REQUEST
,
$param
);
$intersect
=
array_intersect_assoc
(
$REQUEST
,
$param
);
$auth
=
preg_replace
(
'/\?.*$/U'
,
''
,
$auth
);
$auth
=
preg_replace
(
'/\?.*$/U'
,
''
,
$auth
);
if
(
in_array
(
$auth
,
$name
)
&&
$intersect
==
$param
)
{
//如果节点相符且url参数满足
if
(
in_array
(
$auth
,
$name
)
&&
$intersect
==
$param
)
{
//如果节点相符且url参数满足
$list
[]
=
$auth
;
}
}
else
{
if
(
in_array
(
$auth
,
$name
))
{
$list
[]
=
$auth
;
$list
[]
=
$auth
;
}
}
}
else
if
(
in_array
(
$auth
,
$name
))
{
$list
[]
=
$auth
;
}
}
}
}
if
(
$relation
==
'or'
and
!
empty
(
$list
))
{
if
(
'or'
==
$relation
&&
!
empty
(
$list
))
{
return
true
;
return
true
;
}
}
$diff
=
array_diff
(
$name
,
$list
);
$diff
=
array_diff
(
$name
,
$list
);
if
(
$relation
==
'and'
and
empty
(
$diff
))
{
if
(
'and'
==
$relation
&&
empty
(
$diff
))
{
return
true
;
return
true
;
}
}
return
false
;
return
false
;
}
}
/**
/**
* 根据用户id获取用户组,返回值为数组
* 根据用户id获取用户组,返回值为数组
* @param uid int 用户id
* @param
$
uid int 用户id
* @return array 用户所属的用户组 array(
* @return array 用户所属的用户组 array(
* array('uid'=>'用户id','group_id'=>'用户组id','title'=>'用户组名称','rules'=>'用户组拥有的规则id,多个,号隔开'),
*
array('uid'=>'用户id','group_id'=>'用户组id','title'=>'用户组名称','rules'=>'用户组拥有的规则id,多个,号隔开'),
* ...)
*
...)
*/
*/
public
function
getGroups
(
$uid
)
{
public
function
getGroups
(
$uid
=
''
)
static
$groups
=
array
();
{
if
(
isset
(
$groups
[
$uid
]))
static
$groups
=
[];
if
(
isset
(
$groups
[
$uid
]))
{
return
$groups
[
$uid
];
return
$groups
[
$uid
];
$user_groups
=
\think\Db
::
name
(
$this
->
_config
[
'auth_group_access'
])
}
->
alias
(
'a'
)
// 转换表名
->
join
(
$this
->
_config
[
'auth_group'
]
.
" g"
,
"g.id=a.group_id"
)
$auth_group_access
=
Loader
::
parseName
(
$this
->
config
[
'auth_group_access'
],
0
);
->
where
(
"a.uid='
$uid
' and g.status='1'"
)
$auth_group
=
Loader
::
parseName
(
$this
->
config
[
'auth_group'
],
0
);
->
field
(
'uid,group_id,title,rules'
)
->
select
();
$groups
[
$uid
]
=
$user_groups
?
$user_groups
:
array
();
// 执行查询
// $user_groups = Db::view($auth_group_access, 'uid,group_id')
// ->view($auth_group, 'title,rules', "{$auth_group_access}.group_id={$auth_group}.id", 'LEFT')
// ->where("{$auth_group_access}.uid='{$uid}' and {$auth_group}.status='1'")
// ->select();
$user_groups
=
Db
::
name
(
$auth_group_access
)
->
alias
(
'a'
)
->
where
(
"a.uid='
$uid
' and g.status='1'"
)
->
join
(
$auth_group
.
' g'
,
'a.group_id=g.id'
)
->
select
();
$groups
[
$uid
]
=
$user_groups
?:
[];
return
$groups
[
$uid
];
return
$groups
[
$uid
];
}
}
/**
/**
* 获得权限列表
* 获得权限列表
* @param integer $uid
用户id
* @param integer $uid 用户id
* @param integer $type
* @param integer $type
* @return array
*/
*/
protected
function
getAuthList
(
$uid
,
$type
)
{
protected
function
getAuthList
(
$uid
,
$type
)
static
$_authList
=
array
();
//保存用户验证通过的权限列表
{
$t
=
implode
(
','
,
(
array
)
$type
);
static
$_authList
=
[];
//保存用户验证通过的权限列表
$t
=
implode
(
','
,
(
array
)
$type
);
if
(
isset
(
$_authList
[
$uid
.
$t
]))
{
if
(
isset
(
$_authList
[
$uid
.
$t
]))
{
return
$_authList
[
$uid
.
$t
];
return
$_authList
[
$uid
.
$t
];
}
}
if
(
$this
->
_config
[
'auth_type'
]
==
2
&&
isset
(
$_SESSION
[
'_auth_list_'
.
$uid
.
$t
]
))
{
if
(
2
==
$this
->
config
[
'auth_type'
]
&&
Session
::
has
(
'_auth_list_'
.
$uid
.
$t
))
{
return
$_SESSION
[
'_auth_list_'
.
$uid
.
$t
]
;
return
Session
::
get
(
'_auth_list_'
.
$uid
.
$t
)
;
}
}
//读取用户所属用户组
//读取用户所属用户组
$groups
=
$this
->
getGroups
(
$uid
);
$groups
=
$this
->
getGroups
(
$uid
);
$ids
=
array
()
;
//保存用户所属用户组设置的所有权限规则id
$ids
=
[]
;
//保存用户所属用户组设置的所有权限规则id
foreach
(
$groups
as
$g
)
{
foreach
(
$groups
as
$g
)
{
$ids
=
array_merge
(
$ids
,
explode
(
','
,
trim
(
$g
[
'rules'
],
','
)));
$ids
=
array_merge
(
$ids
,
explode
(
','
,
trim
(
$g
[
'rules'
],
','
)));
}
}
$ids
=
array_unique
(
$ids
);
$ids
=
array_unique
(
$ids
);
if
(
empty
(
$ids
))
{
if
(
empty
(
$ids
))
{
$_authList
[
$uid
.
$t
]
=
array
()
;
$_authList
[
$uid
.
$t
]
=
[]
;
return
array
();
}
return
[];
$map
=
array
(
}
'id'
=>
array
(
'in'
,
$ids
),
$map
=
[
'
type'
=>
$type
,
'
id'
=>
[
'in'
,
$ids
]
,
'
status'
=>
1
,
'
type'
=>
$type
)
;
]
;
//读取用户组所有权限规则
//读取用户组所有权限规则
$rules
=
\think\Db
::
name
(
$this
->
_
config
[
'auth_rule'
])
->
where
(
$map
)
->
field
(
'condition,name'
)
->
select
();
$rules
=
Db
::
name
(
$this
->
config
[
'auth_rule'
])
->
where
(
$map
)
->
field
(
'condition,name'
)
->
select
();
//循环规则,判断结果。
//循环规则,判断结果。
$authList
=
array
();
//
$authList
=
[];
//
foreach
(
$rules
as
$rule
)
{
foreach
(
$rules
as
$rule
)
{
if
(
!
empty
(
$rule
[
'condition'
]))
{
//根据condition进行验证
if
(
!
empty
(
$rule
[
'condition'
]))
{
$user
=
$this
->
getUserInfo
(
$uid
);
//获取用户信息,一维数组
//根据condition进行验证
$user
=
$this
->
getUserInfo
(
$uid
);
//获取用户信息,一维数组
$command
=
preg_replace
(
'/\{(\w*?)\}/'
,
'$user[\'\\1\']'
,
$rule
[
'condition'
]);
$command
=
preg_replace
(
'/\{(\w*?)\}/'
,
'$user[\'\\1\']'
,
$rule
[
'condition'
]);
//dump($command);//debug
@
(
eval
(
'$condition=('
.
$command
.
');'
));
@
(
eval
(
'$condition=('
.
$command
.
');'
));
if
(
$condition
)
{
if
(
$condition
)
{
$authList
[]
=
strtolower
(
$rule
[
'name'
]);
$authList
[]
=
strtolower
(
$rule
[
'name'
]);
...
@@ -208,22 +265,30 @@ class Auth {
...
@@ -208,22 +265,30 @@ class Auth {
}
}
}
}
$_authList
[
$uid
.
$t
]
=
$authList
;
$_authList
[
$uid
.
$t
]
=
$authList
;
if
(
$this
->
_config
[
'auth_type'
]
==
2
)
{
if
(
2
==
$this
->
config
[
'auth_type'
]
)
{
//规则列表结果保存到session
//规则列表结果保存到session
$_SESSION
[
'_auth_list_'
.
$uid
.
$t
]
=
$authList
;
Session
::
set
(
'_auth_list_'
.
$uid
.
$t
,
$authList
)
;
}
}
return
array_unique
(
$authList
);
return
array_unique
(
$authList
);
}
}
/**
/**
* 获得用户资料,根据自己的情况读取数据库
* 获得用户资料
* @param $uid
* @return mixed
*/
*/
protected
function
getUserInfo
(
$uid
)
{
protected
function
getUserInfo
(
$uid
)
static
$userinfo
=
array
();
{
if
(
!
isset
(
$userinfo
[
$uid
]))
{
static
$user_info
=
[];
$userinfo
[
$uid
]
=
\think\Db
::
name
(
$this
->
_config
[
'auth_user'
])
->
where
(
array
(
'uid'
=>
$uid
))
->
find
();
$user
=
Db
::
name
(
$this
->
config
[
'auth_user'
]);
// 获取用户表主键
$_pk
=
is_string
(
$user
->
getPk
())
?
$user
->
getPk
()
:
'uid'
;
if
(
!
isset
(
$user_info
[
$uid
]))
{
$user_info
[
$uid
]
=
$user
->
where
(
$_pk
,
$uid
)
->
find
();
}
}
return
$userinfo
[
$uid
];
}
return
$user_info
[
$uid
];
}
}
}
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment