model = model('Admin'); $this->childrenAdminIds = $this->auth->getChildrenAdminIds($this->auth->isSuperAdmin());//下级管理员 $this->childrenGroupIds = $this->auth->getChildrenGroupIds($this->auth->isSuperAdmin());//下级角色组 /*dump($this->childrenAdminIds); dump($this->childrenGroupIds); exit;*/ $groupList = collection(AuthGroup::where('id', 'in', $this->childrenGroupIds)->select())->toArray(); Tree::instance()->init($groupList); $groupdata = []; if ($this->auth->isSuperAdmin()) { $result = Tree::instance()->getTreeList(Tree::instance()->getTreeArray(0)); foreach ($result as $k => $v) { $groupdata[$v['id']] = $v['name']; } } else { $result = []; $groups = $this->auth->getGroups(); foreach ($groups as $m => $n) { $childlist = Tree::instance()->getTreeList(Tree::instance()->getTreeArray($n['id'])); $temp = []; foreach ($childlist as $k => $v) { $temp[$v['id']] = $v['name']; } $result[__($n['name'])] = $temp; } $groupdata = $result; } /*$this->view->assign('groupdata', $groupdata); $this->assignconfig("admin", ['id' => $this->auth->id]);*/ } /** * 查看 */ public function index() { $childrenGroupIds = $this->childrenGroupIds; $groupName = AuthGroup::where('id', 'in', $childrenGroupIds) ->column('id,name'); $authGroupList = AuthGroupAccess::where('group_id', 'in', $childrenGroupIds) ->field('uid,group_id') ->select(); $adminGroupName = []; foreach ($authGroupList as $k => $v) { if (isset($groupName[$v['group_id']])) { $adminGroupName[$v['uid']][$v['group_id']] = $groupName[$v['group_id']]; } } $groups = $this->auth->getGroups(); foreach ($groups as $m => $n) { $adminGroupName[$this->auth->id][$n['id']] = $n['name']; } $list = Db::name('pc_admin') ->where('company_id',$this->auth->company_id) //多此一举 ->where('id', 'in', $this->childrenAdminIds) ->field(['password', 'salt', 'token'], true) ->order('id', 'asc') ->paginate(); $list2 = $list->items(); foreach ($list2 as $k => &$v) { $v['avatar'] = localpath_to_netpath($v['avatar']); $groups = isset($adminGroupName[$v['id']]) ? $adminGroupName[$v['id']] : []; $v['groups'] = implode(',', array_keys($groups)); $v['groups_text'] = implode(',', array_values($groups)); } unset($v); $result = array("total" => $list->total(), "list" => $list2); $this->success(1,$result); } /** * 添加 */ public function add() { $params = [ 'username' => input('username',''),//手机号 'nickname' => input('nickname',''),//姓名 'password' => input('password',''),//密码 'gonghao' => input('gonghao',''), //工号 'avatar' => input('avatar',''), //头像 ]; $group_id = input('group_id',0); if(empty($group_id)){ $this->error(); } Db::startTrans(); try { if (!Validate::is($params['password'], '\S{6,30}')) { exception(__("Please input correct password")); } $params['mobile'] = $params['username']; $params['company_id'] = $this->auth->company_id; $params['salt'] = Random::alnum(); $params['password'] = $this->auth->getEncryptPassword($params['password'], $params['salt']); // $params['avatar'] = '/assets/img/avatar.png'; //设置新管理员默认头像。 $result = $this->model->validate('Admin.add')->save($params); if ($result === false) { exception($this->model->getError()); } $group = [$group_id]; //过滤不允许的组别,避免越权 $group = array_intersect($this->childrenGroupIds, $group); if (!$group) { exception(__('The parent group exceeds permission limit')); } $dataset = []; foreach ($group as $value) { $dataset[] = ['uid' => $this->model->id, 'group_id' => $value]; } model('AuthGroupAccess')->saveAll($dataset); Db::commit(); } catch (\Exception $e) { Db::rollback(); $this->error($e->getMessage()); } $this->success(); } public function info(){ $ids = input('id',0); $row = $this->model->get(['id' => $ids]); if (!$row) { $this->error(__('No Results were found')); } if (!in_array($row->id, $this->childrenAdminIds)) { $this->error(__('You have no permission')); } $grouplist = $this->auth->getGroups($row['id']); $groupids = []; foreach ($grouplist as $k => $v) { $groupids = $v['id']; } $row['groupids'] = $groupids; $row['avatar'] = localpath_to_netpath($row['avatar']); unset($row['password']); unset($row['salt']); $this->success(1,$row); } /** * 编辑 */ public function edit() { $ids = input('id',0); $row = $this->model->get(['id' => $ids]); if (!$row) { $this->error(__('No Results were found')); } if (!in_array($row->id, $this->childrenAdminIds)) { $this->error(__('You have no permission')); } $params = [ 'username' => input('username',''),//手机号 'nickname' => input('nickname',''),//姓名 'password' => input('password',''),//密码 'gonghao' => input('gonghao',''), //工号 'avatar' => input('avatar',''), //头像 ]; $group_id = input('group_id',0); if(empty($group_id)){ $this->error(); } Db::startTrans(); try { if ($params['password']) { if (!Validate::is($params['password'], '\S{6,30}')) { exception(__("Please input correct password")); } $params['salt'] = Random::alnum(); $params['password'] = $this->auth->getEncryptPassword($params['password'], $params['salt']); } else { unset($params['password'], $params['salt']); } $params['mobile'] = $params['username']; //这里需要针对username和email做唯一验证 $adminValidate = \think\Loader::validate('Admin'); $adminValidate->rule([ 'mobile' => 'require|regex:1\d{10}|unique:PcAdmin,mobile,' . $row->id, 'username' => 'require|regex:1\d{10}|unique:PcAdmin,username,' . $row->id, 'password' => 'regex:\S{32}', ]); $result = $row->validate('Admin.edit')->save($params); if ($result === false) { exception($row->getError()); } // 先移除所有权限 model('AuthGroupAccess')->where('uid', $row->id)->delete(); $group = [$group_id]; // 过滤不允许的组别,避免越权 $group = array_intersect($this->childrenGroupIds, $group); if (!$group) { exception(__('The parent group exceeds permission limit')); } $dataset = []; foreach ($group as $value) { $dataset[] = ['uid' => $row->id, 'group_id' => $value]; } model('AuthGroupAccess')->saveAll($dataset); Db::commit(); } catch (\Exception $e) { Db::rollback(); $this->error($e->getMessage()); } $this->success(); } /** * 删除 */ public function del() { $ids = input('ids',''); if ($ids) { $ids = array_intersect($this->childrenAdminIds, array_filter(explode(',', $ids))); // 避免越权删除管理员 $childrenGroupIds = $this->childrenGroupIds; $adminList = $this->model->where('id', 'in', $ids)->where('id', 'in', function ($query) use ($childrenGroupIds) { $query->name('pc_auth_group_access')->where('group_id', 'in', $childrenGroupIds)->field('uid'); })->select(); if ($adminList) { $deleteIds = []; foreach ($adminList as $k => $v) { $deleteIds[] = $v->id; } $deleteIds = array_values(array_diff($deleteIds, [$this->auth->id])); if ($deleteIds) { Db::startTrans(); try { $this->model->destroy($deleteIds); model('AuthGroupAccess')->where('uid', 'in', $deleteIds)->delete(); Db::commit(); } catch (\Exception $e) { Db::rollback(); $this->error($e->getMessage()); } $this->success(); } $this->error(__('No rows were deleted')); } } $this->error(__('You have no permission')); } /** * 设置客服 */ public function set_kefu(){ $id = input('id',0); $is_kefu = input('is_kefu',1); if($is_kefu == 1){ $count = Db::name('pc_admin')->where('company_id',$this->auth->company_id)->where('is_kefu',1)->count(); if($count >= 10){ $this->error('最多只能设置10个客服'); } } Db::name('pc_admin')->where('id',$id)->update(['is_kefu'=>$is_kefu]); $this->success(); } /** * 下拉搜索 */ public function selectpage() { $this->dataLimit = 'auth'; $this->dataLimitField = 'id'; return parent::selectpage(); } }