Admin.php 7.0 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230
  1. <?php
  2. namespace app\admin\controller\auth;
  3. use app\common\controller\Backend;
  4. use fast\Random;
  5. use fast\Tree;
  6. /**
  7. * 管理员管理
  8. *
  9. * @icon fa fa-users
  10. * @remark 一个管理员可以有多个角色组,左侧的菜单根据管理员所拥有的权限进行生成
  11. */
  12. class Admin extends Backend
  13. {
  14. protected $model = null;
  15. //当前登录管理员所有子节点组别
  16. protected $childrenIds = [];
  17. public function _initialize()
  18. {
  19. parent::_initialize();
  20. $this->model = model('Admin');
  21. $groups = $this->auth->getGroups();
  22. // 取出所有分组
  23. $grouplist = model('AuthGroup')->all(['status' => 'normal']);
  24. $objlist = [];
  25. foreach ($groups as $K => $v)
  26. {
  27. // 取出包含自己的所有子节点
  28. $childrenlist = Tree::instance()->init($grouplist)->getChildren($v['id'], TRUE);
  29. $obj = Tree::instance()->init($childrenlist)->getTreeArray($v['pid']);
  30. $objlist = array_merge($objlist, Tree::instance()->getTreeList($obj));
  31. }
  32. $groupdata = [];
  33. foreach ($objlist as $k => $v)
  34. {
  35. $groupdata[$v['id']] = $v['name'];
  36. }
  37. $this->childrenIds = array_keys($groupdata);
  38. $this->view->assign('groupdata', $groupdata);
  39. }
  40. /**
  41. * 查看
  42. */
  43. public function index()
  44. {
  45. if ($this->request->isAjax())
  46. {
  47. $groupData = model('AuthGroup')->where('status', 'normal')->column('id,name');
  48. $childrenAdminIds = [];
  49. $authGroupList = model('AuthGroupAccess')
  50. ->field('uid,group_id')
  51. ->where('group_id', 'in', $this->childrenIds)
  52. ->select();
  53. $adminGroupName = [];
  54. foreach ($authGroupList as $k => $v)
  55. {
  56. $childrenAdminIds[] = $v['uid'];
  57. if (isset($groupData[$v['group_id']]))
  58. $adminGroupName[$v['uid']][$v['group_id']] = $groupData[$v['group_id']];
  59. }
  60. list($where, $sort, $order, $offset, $limit) = $this->buildparams();
  61. $total = $this->model
  62. ->where($where)
  63. ->where('id', 'in', $childrenAdminIds)
  64. ->order($sort, $order)
  65. ->count();
  66. $list = $this->model
  67. ->where($where)
  68. ->where('id', 'in', $childrenAdminIds)
  69. ->field(['password', 'salt', 'token'], true)
  70. ->order($sort, $order)
  71. ->limit($offset, $limit)
  72. ->select();
  73. foreach ($list as $k => &$v)
  74. {
  75. $groups = isset($adminGroupName[$v['id']]) ? $adminGroupName[$v['id']] : [];
  76. $v['groups'] = implode(',', array_keys($groups));
  77. $v['groups_text'] = implode(',', array_values($groups));
  78. }
  79. $result = array("total" => $total, "rows" => $list);
  80. return json($result);
  81. }
  82. return $this->view->fetch();
  83. }
  84. /**
  85. * 添加
  86. */
  87. public function add()
  88. {
  89. if ($this->request->isPost())
  90. {
  91. $this->code = -1;
  92. $params = $this->request->post("row/a");
  93. if ($params)
  94. {
  95. $params['salt'] = Random::alnum();
  96. $params['password'] = md5(md5($params['password']) . $params['salt']);
  97. $params['avatar'] = '/assets/img/avatar.png'; //设置新管理员默认头像。
  98. $admin = $this->model->create($params);
  99. $group = $this->request->post("group/a");
  100. //过滤不允许的组别,避免越权
  101. $group = array_intersect($this->childrenIds, $group);
  102. $dataset = [];
  103. foreach ($group as $value)
  104. {
  105. $dataset[] = ['uid' => $admin->id, 'group_id' => $value];
  106. }
  107. model('AuthGroupAccess')->saveAll($dataset);
  108. $this->code = 1;
  109. }
  110. return;
  111. }
  112. return $this->view->fetch();
  113. }
  114. /**
  115. * 编辑
  116. */
  117. public function edit($ids = NULL)
  118. {
  119. $row = $this->model->get(['id' => $ids]);
  120. if (!$row)
  121. $this->error(__('No Results were found'));
  122. if ($this->request->isPost())
  123. {
  124. $this->code = -1;
  125. $params = $this->request->post("row/a");
  126. if ($params)
  127. {
  128. if ($params['password'])
  129. {
  130. $params['salt'] = Random::alnum();
  131. $params['password'] = md5(md5($params['password']) . $params['salt']);
  132. }
  133. else
  134. {
  135. unset($params['password'], $params['salt']);
  136. }
  137. $row->save($params);
  138. // 先移除所有权限
  139. model('AuthGroupAccess')->where('uid', $row->id)->delete();
  140. $group = $this->request->post("group/a");
  141. // 过滤不允许的组别,避免越权
  142. $group = array_intersect($this->childrenIds, $group);
  143. $dataset = [];
  144. foreach ($group as $value)
  145. {
  146. $dataset[] = ['uid' => $row->id, 'group_id' => $value];
  147. }
  148. model('AuthGroupAccess')->saveAll($dataset);
  149. $this->code = 1;
  150. }
  151. return;
  152. }
  153. $grouplist = $this->auth->getGroups($row['id']);
  154. $groupids = [];
  155. foreach ($grouplist as $k => $v)
  156. {
  157. $groupids[] = $v['id'];
  158. }
  159. $this->view->assign("row", $row);
  160. $this->view->assign("groupids", $groupids);
  161. return $this->view->fetch();
  162. }
  163. /**
  164. * 删除
  165. */
  166. public function del($ids = "")
  167. {
  168. $this->code = -1;
  169. if ($ids)
  170. {
  171. // 避免越权删除管理员
  172. $childrenGroupIds = $this->childrenIds;
  173. $adminList = $this->model->where('id', 'in', $ids)->where('id', 'in', function($query) use($childrenGroupIds) {
  174. $query->name('auth_group_access')->where('group_id', 'in', $childrenGroupIds)->field('uid');
  175. })->select();
  176. if ($adminList)
  177. {
  178. $deleteIds = [];
  179. foreach ($adminList as $k => $v)
  180. {
  181. $deleteIds[] = $v->id;
  182. }
  183. $deleteIds = array_diff($deleteIds, [$this->auth->id]);
  184. if ($deleteIds)
  185. {
  186. $this->model->destroy($deleteIds);
  187. model('AuthGroupAccess')->where('uid', 'in', $deleteIds)->delete();
  188. $this->code = 1;
  189. }
  190. }
  191. }
  192. return;
  193. }
  194. /**
  195. * 批量更新
  196. * @internal
  197. */
  198. public function multi($ids = "")
  199. {
  200. // 管理员禁止批量操作
  201. $this->code = -1;
  202. }
  203. }