149 lines
4.5 KiB
Java
Raw Normal View History

package com.ruoyi.system.service;
2020-02-13 10:48:51 +08:00
2020-07-20 10:41:32 +08:00
import com.ruoyi.common.core.domain.entity.SysRole;
import com.ruoyi.common.core.domain.model.LoginUser;
2021-08-19 17:37:44 +08:00
import com.ruoyi.common.utils.SecurityUtils;
import com.ruoyi.common.utils.StringUtils;
import org.springframework.stereotype.Service;
import org.springframework.util.CollectionUtils;
import java.util.Set;
2020-02-13 10:48:51 +08:00
/**
* RuoYi首创 自定义权限实现ss取自SpringSecurity首字母
*
2020-02-13 10:48:51 +08:00
* @author ruoyi
*/
@Service("ss")
2021-09-27 17:58:36 +08:00
public class PermissionService {
/**
* 所有权限标识
*/
2020-02-13 10:48:51 +08:00
private static final String ALL_PERMISSION = "*:*:*";
2021-09-27 17:58:36 +08:00
/**
* 管理员角色权限标识
*/
2020-02-13 10:48:51 +08:00
private static final String SUPER_ADMIN = "admin";
private static final String ROLE_DELIMETER = ",";
private static final String PERMISSION_DELIMETER = ",";
/**
* 验证用户是否具备某权限
*
2020-02-13 10:48:51 +08:00
* @param permission 权限字符串
* @return 用户是否具备某权限
*/
2021-09-27 17:58:36 +08:00
public boolean hasPermi(String permission) {
if (StringUtils.isEmpty(permission)) {
2020-02-13 10:48:51 +08:00
return false;
}
LoginUser loginUser = SecurityUtils.getLoginUser();
2021-09-27 17:58:36 +08:00
if (StringUtils.isNull(loginUser) || CollectionUtils.isEmpty(loginUser.getPermissions())) {
2020-02-13 10:48:51 +08:00
return false;
}
return hasPermissions(loginUser.getPermissions(), permission);
}
/**
* 验证用户是否不具备某权限 hasPermi逻辑相反
*
* @param permission 权限字符串
* @return 用户是否不具备某权限
*/
2021-09-27 17:58:36 +08:00
public boolean lacksPermi(String permission) {
2020-02-13 10:48:51 +08:00
return hasPermi(permission) != true;
}
/**
* 验证用户是否具有以下任意一个权限
*
* @param permissions PERMISSION_NAMES_DELIMETER 为分隔符的权限列表
* @return 用户是否具有以下任意一个权限
*/
2021-09-27 17:58:36 +08:00
public boolean hasAnyPermi(String permissions) {
if (StringUtils.isEmpty(permissions)) {
2020-02-13 10:48:51 +08:00
return false;
}
LoginUser loginUser = SecurityUtils.getLoginUser();
2021-09-27 17:58:36 +08:00
if (StringUtils.isNull(loginUser) || CollectionUtils.isEmpty(loginUser.getPermissions())) {
2020-02-13 10:48:51 +08:00
return false;
}
Set<String> authorities = loginUser.getPermissions();
2021-09-27 17:58:36 +08:00
for (String permission : permissions.split(PERMISSION_DELIMETER)) {
if (permission != null && hasPermissions(authorities, permission)) {
2020-02-13 10:48:51 +08:00
return true;
}
}
return false;
}
/**
* 判断用户是否拥有某个角色
*
2020-02-13 10:48:51 +08:00
* @param role 角色字符串
* @return 用户是否具备某角色
*/
2021-09-27 17:58:36 +08:00
public boolean hasRole(String role) {
if (StringUtils.isEmpty(role)) {
2020-02-13 10:48:51 +08:00
return false;
}
LoginUser loginUser = SecurityUtils.getLoginUser();
2021-09-27 17:58:36 +08:00
if (StringUtils.isNull(loginUser) || CollectionUtils.isEmpty(loginUser.getUser().getRoles())) {
2020-02-13 10:48:51 +08:00
return false;
}
2021-09-27 17:58:36 +08:00
for (SysRole sysRole : loginUser.getUser().getRoles()) {
2020-02-13 10:48:51 +08:00
String roleKey = sysRole.getRoleKey();
2021-09-27 17:58:36 +08:00
if (SUPER_ADMIN.equals(roleKey) || roleKey.equals(StringUtils.trim(role))) {
2020-02-13 10:48:51 +08:00
return true;
}
}
return false;
}
/**
* 验证用户是否不具备某角色 isRole逻辑相反
*
* @param role 角色名称
* @return 用户是否不具备某角色
*/
2021-09-27 17:58:36 +08:00
public boolean lacksRole(String role) {
2020-02-13 10:48:51 +08:00
return hasRole(role) != true;
}
/**
* 验证用户是否具有以下任意一个角色
*
* @param roles ROLE_NAMES_DELIMETER 为分隔符的角色列表
* @return 用户是否具有以下任意一个角色
*/
2021-09-27 17:58:36 +08:00
public boolean hasAnyRoles(String roles) {
if (StringUtils.isEmpty(roles)) {
2020-02-13 10:48:51 +08:00
return false;
}
LoginUser loginUser = SecurityUtils.getLoginUser();
2021-09-27 17:58:36 +08:00
if (StringUtils.isNull(loginUser) || CollectionUtils.isEmpty(loginUser.getUser().getRoles())) {
2020-02-13 10:48:51 +08:00
return false;
}
2021-09-27 17:58:36 +08:00
for (String role : roles.split(ROLE_DELIMETER)) {
if (hasRole(role)) {
2020-02-13 10:48:51 +08:00
return true;
}
}
return false;
}
/**
* 判断是否包含权限
*
2020-02-13 10:48:51 +08:00
* @param permissions 权限列表
2021-09-27 17:58:36 +08:00
* @param permission 权限字符串
2020-02-13 10:48:51 +08:00
* @return 用户是否具备某权限
*/
2021-09-27 17:58:36 +08:00
private boolean hasPermissions(Set<String> permissions, String permission) {
return permissions.contains(ALL_PERMISSION) || permissions.contains(StringUtils.trim(permission));
2020-02-13 10:48:51 +08:00
}
}