后端 (Laravel 10 + Sanctum): - RBAC 四层权限系统 (users→roles→permissions→menus) - 门店隔离中间件 (BelongsToStore Trait + StoreIsolation Middleware) - 操作日志中间件 (自动记录写操作) - 权限检查中间件 (CheckPermission) - 16张数据库表迁移 (系统基础+RBAC+字典+配置) - 11个 Eloquent Model - Auth API (登录/登出/用户信息) - 系统设置模块 CRUD (门店/部门/职务/用户/角色/菜单/权限/字典/日志) - 45条 RESTful API 路由 - InitSeeder 初始数据 (超管/角色/76权限/31菜单) 前端 (Vue 3 + Element Plus + Vite): - Axios 请求封装 + Token 注入 - Pinia 状态管理 (user + permission store) - 动态路由 (服务端菜单→前端路由自动生成) - 后台布局 (侧边栏+顶栏+主内容区) - 登录页 + 仪表盘首页 - 系统设置 7 个 CRUD 页面 技术方案文档 (7卷): - 技术总览/数据库设计/API规范/RBAC设计/模块详设/小程序设计/部署方案
119 lines
3.0 KiB
PHP
119 lines
3.0 KiB
PHP
<?php
|
|
|
|
namespace App\Models;
|
|
|
|
use App\Enums\UserStatus;
|
|
use App\Traits\BelongsToStore;
|
|
use Illuminate\Database\Eloquent\Factories\HasFactory;
|
|
use Illuminate\Database\Eloquent\Relations\BelongsTo;
|
|
use Illuminate\Database\Eloquent\Relations\BelongsToMany;
|
|
use Illuminate\Database\Eloquent\SoftDeletes;
|
|
use Illuminate\Foundation\Auth\User as Authenticatable;
|
|
use Laravel\Sanctum\HasApiTokens;
|
|
|
|
class User extends Authenticatable
|
|
{
|
|
use HasApiTokens, HasFactory, SoftDeletes, BelongsToStore;
|
|
|
|
protected $fillable = [
|
|
'store_id', 'department_id', 'position_id',
|
|
'username', 'password', 'name', 'phone', 'email',
|
|
'avatar', 'status', 'is_super', 'last_login_at',
|
|
];
|
|
|
|
protected $hidden = ['password'];
|
|
|
|
protected function casts(): array
|
|
{
|
|
return [
|
|
'status' => UserStatus::class,
|
|
'is_super' => 'boolean',
|
|
'last_login_at' => 'datetime',
|
|
'password' => 'hashed',
|
|
];
|
|
}
|
|
|
|
public function department(): BelongsTo
|
|
{
|
|
return $this->belongsTo(Department::class);
|
|
}
|
|
|
|
public function position(): BelongsTo
|
|
{
|
|
return $this->belongsTo(Position::class);
|
|
}
|
|
|
|
public function roles(): BelongsToMany
|
|
{
|
|
return $this->belongsToMany(Role::class, 'role_user');
|
|
}
|
|
|
|
/**
|
|
* 获取用户所有权限标识
|
|
*/
|
|
public function getAllPermissionCodes(): array
|
|
{
|
|
if ($this->is_super) {
|
|
return ['*'];
|
|
}
|
|
|
|
return $this->roles()
|
|
->with('permissions')
|
|
->get()
|
|
->pluck('permissions')
|
|
->flatten()
|
|
->pluck('code')
|
|
->unique()
|
|
->values()
|
|
->toArray();
|
|
}
|
|
|
|
/**
|
|
* 检查是否有指定权限
|
|
*/
|
|
public function hasPermission(string $code): bool
|
|
{
|
|
if ($this->is_super) {
|
|
return true;
|
|
}
|
|
|
|
return in_array($code, $this->getAllPermissionCodes());
|
|
}
|
|
|
|
/**
|
|
* 获取用户菜单树
|
|
*/
|
|
public function getMenuTree(): array
|
|
{
|
|
if ($this->is_super) {
|
|
$menus = Menu::where('status', 1)->orderBy('sort')->get();
|
|
} else {
|
|
$permissionCodes = $this->getAllPermissionCodes();
|
|
$menus = Menu::where('status', 1)
|
|
->where(function ($q) use ($permissionCodes) {
|
|
$q->whereIn('permission_code', $permissionCodes)
|
|
->orWhereNull('permission_code');
|
|
})
|
|
->orderBy('sort')
|
|
->get();
|
|
}
|
|
|
|
return self::buildTree($menus->toArray());
|
|
}
|
|
|
|
private static function buildTree(array $items, int $parentId = 0): array
|
|
{
|
|
$tree = [];
|
|
foreach ($items as $item) {
|
|
if ($item['parent_id'] == $parentId) {
|
|
$children = self::buildTree($items, $item['id']);
|
|
if ($children) {
|
|
$item['children'] = $children;
|
|
}
|
|
$tree[] = $item;
|
|
}
|
|
}
|
|
return $tree;
|
|
}
|
|
}
|