UserService.cs 20 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626
  1. using System.Collections.Generic;
  2. using System.Linq;
  3. using System.Threading.Tasks;
  4. using Microsoft.AspNetCore.Mvc;
  5. using Microsoft.AspNetCore.Http;
  6. using Microsoft.Extensions.Options;
  7. using ZhonTai.Admin.Core.Attributes;
  8. using ZhonTai.Admin.Core.Configs;
  9. using ZhonTai.Common.Helpers;
  10. using ZhonTai.Admin.Core.Dto;
  11. using ZhonTai.Admin.Domain.Api;
  12. using ZhonTai.Admin.Domain.PermissionApi;
  13. using ZhonTai.Admin.Domain.Role;
  14. using ZhonTai.Admin.Domain.RolePermission;
  15. using ZhonTai.Admin.Domain.Tenant;
  16. using ZhonTai.Admin.Domain.User;
  17. using ZhonTai.Admin.Domain.UserRole;
  18. using ZhonTai.Admin.Services.Auth.Dto;
  19. using ZhonTai.Admin.Services.User.Dto;
  20. using ZhonTai.DynamicApi;
  21. using ZhonTai.DynamicApi.Attributes;
  22. using ZhonTai.Admin.Core.Helpers;
  23. using ZhonTai.Admin.Core.Consts;
  24. using ZhonTai.Admin.Domain.UserStaff;
  25. using ZhonTai.Admin.Domain.Org;
  26. using System.Data;
  27. using ZhonTai.Admin.Domain.TenantPermission;
  28. using FreeSql;
  29. using ZhonTai.Admin.Domain.User.Dto;
  30. using ZhonTai.Admin.Domain.RoleOrg;
  31. using ZhonTai.Admin.Domain.UserOrg;
  32. namespace ZhonTai.Admin.Services.User;
  33. /// <summary>
  34. /// 用户服务
  35. /// </summary>
  36. [DynamicApi(Area = AdminConsts.AreaName)]
  37. public class UserService : BaseService, IUserService, IDynamicApi
  38. {
  39. private AppConfig _appConfig => LazyGetRequiredService<AppConfig>();
  40. private IUserRepository _userRepository => LazyGetRequiredService<IUserRepository>();
  41. private IOrgRepository _orgRepository => LazyGetRequiredService<IOrgRepository>();
  42. private ITenantRepository _tenantRepository => LazyGetRequiredService<ITenantRepository>();
  43. private IApiRepository _apiRepository => LazyGetRequiredService<IApiRepository>();
  44. private IUserStaffRepository _staffRepository => LazyGetRequiredService<IUserStaffRepository>();
  45. private IUserRoleRepository _userRoleRepository => LazyGetRequiredService<IUserRoleRepository>();
  46. private IRoleOrgRepository _roleOrgRepository => LazyGetRequiredService<IRoleOrgRepository>();
  47. private IUserOrgRepository _userOrgRepository => LazyGetRequiredService<IUserOrgRepository>();
  48. public UserService()
  49. {
  50. }
  51. /// <summary>
  52. /// 查询用户
  53. /// </summary>
  54. /// <param name="id"></param>
  55. /// <returns></returns>
  56. public async Task<UserGetOutput> GetAsync(long id)
  57. {
  58. var userEntity = await _userRepository.Select
  59. .WhereDynamic(id)
  60. .IncludeMany(a => a.Roles.Select(b => new RoleEntity { Id = b.Id, Name = b.Name }))
  61. .IncludeMany(a => a.Orgs.Select(b => new OrgEntity { Id = b.Id, Name = b.Name }))
  62. .ToOneAsync(a => new
  63. {
  64. a.Id,
  65. a.UserName,
  66. a.Name,
  67. a.Mobile,
  68. a.Email,
  69. a.Roles,
  70. a.Orgs,
  71. a.OrgId,
  72. a.ManagerUserId,
  73. ManagerUserName = a.ManagerUser.Name,
  74. Staff = new
  75. {
  76. a.Staff.JobNumber,
  77. a.Staff.Sex,
  78. a.Staff.Position,
  79. a.Staff.Introduce
  80. }
  81. });
  82. var output = Mapper.Map<UserGetOutput>(userEntity);
  83. return output;
  84. }
  85. /// <summary>
  86. /// 查询分页
  87. /// </summary>
  88. /// <param name="input"></param>
  89. /// <returns></returns>
  90. [HttpPost]
  91. public async Task<PageOutput<UserGetPageOutput>> GetPageAsync(PageInput<long?> input)
  92. {
  93. var orgId = input.Filter;
  94. var list = await _userRepository.Select
  95. .WhereIf(orgId.HasValue && orgId > 0, a => _userOrgRepository.Where(b => b.UserId == a.Id && b.OrgId == orgId).Any())
  96. .WhereDynamicFilter(input.DynamicFilter)
  97. .Count(out var total)
  98. .OrderByDescending(true, a => a.Id)
  99. .IncludeMany(a => a.Roles.Select(b => new RoleEntity { Name = b.Name }))
  100. .Page(input.CurrentPage, input.PageSize)
  101. .ToListAsync(a => new UserGetPageOutput { Roles = a.Roles });
  102. if(orgId.HasValue && orgId > 0)
  103. {
  104. var managerUserIds = await _userOrgRepository.Select.Where(a => a.OrgId == orgId && a.IsManager == true).ToListAsync(a => a.UserId);
  105. if (managerUserIds.Any())
  106. {
  107. var managerUsers = list.Where(a => managerUserIds.Contains(a.Id));
  108. foreach (var managerUser in managerUsers)
  109. {
  110. managerUser.IsManager = true;
  111. }
  112. }
  113. }
  114. var data = new PageOutput<UserGetPageOutput>()
  115. {
  116. List = Mapper.Map<List<UserGetPageOutput>>(list),
  117. Total = total
  118. };
  119. return data;
  120. }
  121. /// <summary>
  122. /// 查询登录用户信息
  123. /// </summary>
  124. /// <param name="id"></param>
  125. /// <returns></returns>
  126. [NonAction]
  127. public async Task<AuthLoginOutput> GetLoginUserAsync(long id)
  128. {
  129. var output = new ResultOutput<AuthLoginOutput>();
  130. var entityDto = await _userRepository.Select.DisableGlobalFilter(FilterNames.Tenant)
  131. .WhereDynamic(id).ToOneAsync<AuthLoginOutput>();
  132. if (_appConfig.Tenant && entityDto?.TenantId.Value > 0)
  133. {
  134. var tenant = await _tenantRepository.Select.DisableGlobalFilter(FilterNames.Tenant)
  135. .WhereDynamic(entityDto.TenantId).ToOneAsync(a => new { a.TenantType, a.DbKey });
  136. entityDto.TenantType = tenant.TenantType;
  137. entityDto.DbKey = tenant.DbKey;
  138. }
  139. return entityDto;
  140. }
  141. /// <summary>
  142. /// 获得数据权限
  143. /// </summary>
  144. /// <returns></returns>
  145. [NonAction]
  146. public async Task<DataPermissionDto> GetDataPermissionAsync()
  147. {
  148. if (!(User?.Id > 0))
  149. {
  150. return null;
  151. }
  152. var key = CacheKeys.DataPermission + User.Id;
  153. return await Cache.GetOrSetAsync(key, async () =>
  154. {
  155. using (_userRepository.DataFilter.Disable(FilterNames.Self, FilterNames.Data))
  156. {
  157. var user = await _userRepository.Select
  158. .IncludeMany(a => a.Roles.Select(b => new RoleEntity
  159. {
  160. Id = b.Id,
  161. DataScope = b.DataScope
  162. }))
  163. .WhereDynamic(User.Id)
  164. .ToOneAsync(a => new
  165. {
  166. a.OrgId,
  167. a.Roles
  168. });
  169. if (user == null)
  170. return null;
  171. //数据范围
  172. DataScope dataScope = DataScope.Self;
  173. var customRoleIds = new List<long>();
  174. user.Roles?.ToList().ForEach(role =>
  175. {
  176. if (role.DataScope == DataScope.Custom)
  177. {
  178. customRoleIds.Add(role.Id);
  179. }
  180. else if (role.DataScope <= dataScope)
  181. {
  182. dataScope = role.DataScope;
  183. }
  184. });
  185. //部门列表
  186. var orgIds = new List<long>();
  187. if (dataScope != DataScope.All)
  188. {
  189. //本部门
  190. if (dataScope == DataScope.Dept)
  191. {
  192. orgIds.Add(user.OrgId);
  193. }
  194. //本部门和下级部门
  195. else if (dataScope == DataScope.DeptWithChild)
  196. {
  197. orgIds = await _orgRepository
  198. .Where(a => a.Id == user.OrgId)
  199. .AsTreeCte()
  200. .ToListAsync(a => a.Id);
  201. }
  202. //指定部门
  203. if (customRoleIds.Count > 0)
  204. {
  205. var customRoleOrgIds = await _roleOrgRepository.Select.Where(a => customRoleIds.Contains(a.RoleId)).ToListAsync(a => a.OrgId);
  206. orgIds = orgIds.Concat(customRoleOrgIds).ToList();
  207. }
  208. }
  209. return new DataPermissionDto
  210. {
  211. OrgId = user.OrgId,
  212. OrgIds = orgIds.Distinct().ToList(),
  213. DataScope = dataScope
  214. };
  215. }
  216. });
  217. }
  218. /// <summary>
  219. /// 查询用户基本信息
  220. /// </summary>
  221. /// <returns></returns>
  222. public async Task<UserUpdateBasicInput> GetBasicAsync()
  223. {
  224. if (!(User?.Id > 0))
  225. {
  226. throw ResultOutput.Exception("未登录!");
  227. }
  228. var data = await _userRepository.GetAsync<UserUpdateBasicInput>(User.Id);
  229. return data;
  230. }
  231. /// <summary>
  232. /// 查询用户权限信息
  233. /// </summary>
  234. /// <returns></returns>
  235. public async Task<IList<UserPermissionsOutput>> GetPermissionsAsync()
  236. {
  237. var key = CacheKeys.UserPermissions + User.Id;
  238. var result = await Cache.GetOrSetAsync(key, async () =>
  239. {
  240. if (User.TenantAdmin)
  241. {
  242. var cloud = LazyGetRequiredService<FreeSqlCloud>();
  243. var db = cloud.Use(DbKeys.AppDb);
  244. return await db.Select<ApiEntity>()
  245. .Where(a => db.Select<TenantPermissionEntity, PermissionApiEntity>()
  246. .InnerJoin((b, c) => b.PermissionId == c.PermissionId && b.TenantId == User.TenantId)
  247. .Where((b, c) => c.ApiId == a.Id).Any())
  248. .ToListAsync<UserPermissionsOutput>();
  249. }
  250. return await _apiRepository
  251. .Where(a => _apiRepository.Orm.Select<UserRoleEntity, RolePermissionEntity, PermissionApiEntity>()
  252. .InnerJoin((b, c, d) => b.RoleId == c.RoleId && b.UserId == User.Id)
  253. .InnerJoin((b, c, d) => c.PermissionId == d.PermissionId)
  254. .Where((b, c, d) => d.ApiId == a.Id).Any())
  255. .ToListAsync<UserPermissionsOutput>();
  256. });
  257. return result;
  258. }
  259. /// <summary>
  260. /// 新增用户
  261. /// </summary>
  262. /// <param name="input"></param>
  263. /// <returns></returns>
  264. [AdminTransaction]
  265. public virtual async Task<long> AddAsync(UserAddInput input)
  266. {
  267. if (await _userRepository.Select.AnyAsync(a => a.UserName == input.UserName))
  268. {
  269. throw ResultOutput.Exception($"账号已存在");
  270. }
  271. if (input.Mobile.NotNull() && await _userRepository.Select.AnyAsync(a => a.Mobile == input.Mobile))
  272. {
  273. throw ResultOutput.Exception($"手机号已存在");
  274. }
  275. if (input.Email.NotNull() && await _userRepository.Select.AnyAsync(a => a.Email == input.Email))
  276. {
  277. throw ResultOutput.Exception($"邮箱已存在");
  278. }
  279. // 用户信息
  280. if (input.Password.IsNull())
  281. {
  282. input.Password = _appConfig.DefaultPassword;
  283. }
  284. input.Password = MD5Encrypt.Encrypt32(input.Password);
  285. var entity = Mapper.Map<UserEntity>(input);
  286. var user = await _userRepository.InsertAsync(entity);
  287. var userId = user.Id;
  288. //用户角色
  289. if (input.RoleIds != null && input.RoleIds.Any())
  290. {
  291. var roles = input.RoleIds.Select(roleId => new UserRoleEntity
  292. {
  293. UserId = userId,
  294. RoleId = roleId
  295. }).ToList();
  296. await _userRoleRepository.InsertAsync(roles);
  297. }
  298. // 员工信息
  299. var staff = Mapper.Map<UserStaffEntity>(input.Staff);
  300. staff.Id = userId;
  301. await _staffRepository.InsertAsync(staff);
  302. //所属部门
  303. if (input.OrgIds != null && input.OrgIds.Any())
  304. {
  305. var orgs = input.OrgIds.Select(orgId => new UserOrgEntity
  306. {
  307. UserId = userId,
  308. OrgId = orgId
  309. }).ToList();
  310. await _userOrgRepository.InsertAsync(orgs);
  311. }
  312. return userId;
  313. }
  314. /// <summary>
  315. /// 修改用户
  316. /// </summary>
  317. /// <param name="input"></param>
  318. /// <returns></returns>
  319. [AdminTransaction]
  320. public virtual async Task UpdateAsync(UserUpdateInput input)
  321. {
  322. var user = await _userRepository.GetAsync(input.Id);
  323. if (!(user?.Id > 0))
  324. {
  325. throw ResultOutput.Exception("用户不存在");
  326. }
  327. if (input.Id == input.ManagerUserId)
  328. {
  329. throw ResultOutput.Exception("直属主管不能是自己");
  330. }
  331. if (await _userRepository.Select.AnyAsync(a => a.Id != input.Id && a.UserName == input.UserName))
  332. {
  333. throw ResultOutput.Exception($"账号已存在");
  334. }
  335. if (input.Mobile.NotNull() && await _userRepository.Select.AnyAsync(a => a.Id != input.Id && a.Mobile == input.Mobile))
  336. {
  337. throw ResultOutput.Exception($"手机号已存在");
  338. }
  339. if (input.Email.NotNull() && await _userRepository.Select.AnyAsync(a => a.Id != input.Id && a.Email == input.Email))
  340. {
  341. throw ResultOutput.Exception($"邮箱已存在");
  342. }
  343. Mapper.Map(input, user);
  344. await _userRepository.UpdateAsync(user);
  345. var userId = user.Id;
  346. // 用户角色
  347. await _userRoleRepository.DeleteAsync(a => a.UserId == userId);
  348. if (input.RoleIds != null && input.RoleIds.Any())
  349. {
  350. var roles = input.RoleIds.Select(roleId => new UserRoleEntity
  351. {
  352. UserId = userId,
  353. RoleId = roleId
  354. }).ToList();
  355. await _userRoleRepository.InsertAsync(roles);
  356. }
  357. // 员工信息
  358. var staff = await _staffRepository.GetAsync(userId);
  359. if(staff == null)
  360. {
  361. staff = new UserStaffEntity();
  362. }
  363. Mapper.Map(input.Staff, staff);
  364. staff.Id = userId;
  365. await _staffRepository.InsertOrUpdateAsync(staff);
  366. //所属部门
  367. await _userOrgRepository.DeleteAsync(a => a.UserId == userId);
  368. if (input.OrgIds != null && input.OrgIds.Any())
  369. {
  370. var orgs = input.OrgIds.Select(orgId => new UserOrgEntity
  371. {
  372. UserId = userId,
  373. OrgId = orgId
  374. }).ToList();
  375. await _userOrgRepository.InsertAsync(orgs);
  376. }
  377. await Cache.DelAsync(CacheKeys.DataPermission + user.Id);
  378. }
  379. /// <summary>
  380. /// 更新用户基本信息
  381. /// </summary>
  382. /// <param name="input"></param>
  383. /// <returns></returns>
  384. public async Task UpdateBasicAsync(UserUpdateBasicInput input)
  385. {
  386. var entity = await _userRepository.GetAsync(input.Id);
  387. entity = Mapper.Map(input, entity);
  388. await _userRepository.UpdateAsync(entity);
  389. }
  390. /// <summary>
  391. /// 修改用户密码
  392. /// </summary>
  393. /// <param name="input"></param>
  394. /// <returns></returns>
  395. public async Task ChangePasswordAsync(UserChangePasswordInput input)
  396. {
  397. if (input.ConfirmPassword != input.NewPassword)
  398. {
  399. throw ResultOutput.Exception("新密码和确认密码不一致");
  400. }
  401. var entity = await _userRepository.GetAsync(input.Id);
  402. var oldPassword = MD5Encrypt.Encrypt32(input.OldPassword);
  403. if (oldPassword != entity.Password)
  404. {
  405. throw ResultOutput.Exception("旧密码不正确");
  406. }
  407. entity.Password = MD5Encrypt.Encrypt32(input.NewPassword);
  408. await _userRepository.UpdateAsync(entity);
  409. }
  410. /// <summary>
  411. /// 重置密码
  412. /// </summary>
  413. /// <param name="input"></param>
  414. /// <returns></returns>
  415. public async Task<string> ResetPasswordAsync(UserResetPasswordInput input)
  416. {
  417. var entity = await _userRepository.GetAsync(input.Id);
  418. var password = input.Password;
  419. if (password.IsNull())
  420. {
  421. password = _appConfig.DefaultPassword;
  422. }
  423. if (password.IsNull())
  424. {
  425. password = "111111";
  426. }
  427. entity.Password = MD5Encrypt.Encrypt32(password);
  428. await _userRepository.UpdateAsync(entity);
  429. return password;
  430. }
  431. /// <summary>
  432. /// 设置主管
  433. /// </summary>
  434. /// <param name="input"></param>
  435. /// <returns></returns>
  436. public async Task SetManagerAsync(UserSetManagerInput input)
  437. {
  438. var entity = await _userOrgRepository.Where(a => a.UserId == input.UserId && a.OrgId == input.OrgId).FirstAsync();
  439. entity.IsManager = input.IsManager;
  440. await _userOrgRepository.UpdateAsync(entity);
  441. }
  442. /// <summary>
  443. /// 彻底删除用户
  444. /// </summary>
  445. /// <param name="id"></param>
  446. /// <returns></returns>
  447. [AdminTransaction]
  448. public virtual async Task DeleteAsync(long id)
  449. {
  450. var user = await _userRepository.Select.WhereDynamic(id).ToOneAsync(a => new { a.Type });
  451. if(user == null)
  452. {
  453. throw ResultOutput.Exception("用户不存在");
  454. }
  455. if(user.Type == UserType.PlatformAdmin || user.Type == UserType.TenantAdmin)
  456. {
  457. throw ResultOutput.Exception("平台管理员禁止删除");
  458. }
  459. //删除用户角色
  460. await _userRoleRepository.DeleteAsync(a => a.UserId == id);
  461. //删除用户所属部门
  462. await _userOrgRepository.DeleteAsync(a => a.UserId == id);
  463. //删除员工
  464. await _staffRepository.DeleteAsync(a => a.Id == id);
  465. //删除用户
  466. await _userRepository.DeleteAsync(a => a.Id == id);
  467. await Cache.DelAsync(CacheKeys.DataPermission + id);
  468. }
  469. /// <summary>
  470. /// 批量彻底删除用户
  471. /// </summary>
  472. /// <param name="ids"></param>
  473. /// <returns></returns>
  474. [AdminTransaction]
  475. public virtual async Task BatchDeleteAsync(long[] ids)
  476. {
  477. var admin = await _userRepository.Select.Where(a => ids.Contains(a.Id) &&
  478. (a.Type == UserType.PlatformAdmin || a.Type == UserType.TenantAdmin)).AnyAsync();
  479. if (admin)
  480. {
  481. throw ResultOutput.Exception("平台管理员禁止删除");
  482. }
  483. //删除用户角色
  484. await _userRoleRepository.DeleteAsync(a => ids.Contains(a.UserId));
  485. //删除用户所属部门
  486. await _userOrgRepository.DeleteAsync(a => ids.Contains(a.UserId));
  487. //删除员工
  488. await _staffRepository.DeleteAsync(a => ids.Contains(a.Id));
  489. //删除用户
  490. await _userRepository.DeleteAsync(a => ids.Contains(a.Id));
  491. foreach (var userId in ids)
  492. {
  493. await Cache.DelAsync(CacheKeys.DataPermission + userId);
  494. }
  495. }
  496. /// <summary>
  497. /// 删除用户
  498. /// </summary>
  499. /// <param name="id"></param>
  500. /// <returns></returns>
  501. [AdminTransaction]
  502. public virtual async Task SoftDeleteAsync(long id)
  503. {
  504. var user = await _userRepository.Select.WhereDynamic(id).ToOneAsync(a => new { a.Type });
  505. if (user == null)
  506. {
  507. throw ResultOutput.Exception("用户不存在");
  508. }
  509. if (user.Type == UserType.PlatformAdmin || user.Type == UserType.TenantAdmin)
  510. {
  511. throw ResultOutput.Exception("平台管理员禁止删除");
  512. }
  513. await _userRoleRepository.DeleteAsync(a => a.UserId == id);
  514. await _userOrgRepository.DeleteAsync(a => a.UserId == id);
  515. await _staffRepository.SoftDeleteAsync(a => a.Id == id);
  516. await _userRepository.SoftDeleteAsync(id);
  517. await Cache.DelAsync(CacheKeys.DataPermission + id);
  518. }
  519. /// <summary>
  520. /// 批量删除用户
  521. /// </summary>
  522. /// <param name="ids"></param>
  523. /// <returns></returns>
  524. [AdminTransaction]
  525. public virtual async Task BatchSoftDeleteAsync(long[] ids)
  526. {
  527. var admin = await _userRepository.Select.Where(a => ids.Contains(a.Id) &&
  528. (a.Type == UserType.PlatformAdmin || a.Type == UserType.TenantAdmin)).AnyAsync();
  529. if (admin)
  530. {
  531. throw ResultOutput.Exception("平台管理员禁止删除");
  532. }
  533. await _userRoleRepository.DeleteAsync(a => ids.Contains(a.UserId));
  534. await _userOrgRepository.DeleteAsync(a => ids.Contains(a.UserId));
  535. await _staffRepository.SoftDeleteAsync(a => ids.Contains(a.Id));
  536. await _userRepository.SoftDeleteAsync(ids);
  537. foreach (var userId in ids)
  538. {
  539. await Cache.DelAsync(CacheKeys.DataPermission + userId);
  540. }
  541. }
  542. /// <summary>
  543. /// 上传头像
  544. /// </summary>
  545. /// <param name="file"></param>
  546. /// <returns></returns>
  547. [HttpPost]
  548. [Login]
  549. public async Task<string> AvatarUpload([FromForm] IFormFile file)
  550. {
  551. var uploadConfig = LazyGetRequiredService<IOptionsMonitor<UploadConfig>>().CurrentValue;
  552. var uploadHelper = LazyGetRequiredService<UploadHelper>();
  553. var config = uploadConfig.Avatar;
  554. var fileInfo = await uploadHelper.UploadAsync(file, config, new { User.Id });
  555. return fileInfo.FileRelativePath;
  556. }
  557. }