BaseController.php 18 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491
  1. <?php
  2. /**
  3. * Created by PhpStorm.
  4. * User: Leo
  5. * Date: 2017/9/3
  6. * Time: 下午3:05
  7. */
  8. namespace backendApi\modules\v1\controllers;
  9. use common\helpers\Date;
  10. use common\helpers\Tool;
  11. use common\models\UserInfo;
  12. use common\models\UserSystem;
  13. use \Yii;
  14. use common\components\ActiveRecord;
  15. use common\helpers\Form;
  16. use yii\db\Exception;
  17. use yii\web\HttpException;
  18. class BaseController extends \yii\rest\ActiveController {
  19. /**
  20. * 不让控制器直接选择model类直接返回数据
  21. * @return array
  22. */
  23. public function actions() {
  24. return [];
  25. }
  26. /**
  27. * 校验管理员权限
  28. * @param $action
  29. * @return bool|mixed
  30. * @throws HttpException
  31. * @throws \yii\web\BadRequestHttpException
  32. */
  33. public function beforeAction($action) {
  34. $parentBeforeAction = parent::beforeAction($action);
  35. // 动态返回语言:zh-CN | en-US
  36. if (!Yii::$app->request->isOptions) {
  37. Yii::$app->language = Yii::$app->request->headers->get('language') ?? 'zh-CN';
  38. Yii::$app->sourceLanguage = (Yii::$app->request->headers->get('language') ?? 'zh-CN') == 'zh-CN' ? 'en-US' : 'zh-CN';
  39. }
  40. // 增加的判断用户登录后未操作后的超时
  41. if (Yii::$app->getUser()->getUserInfo()){
  42. $adminId = Yii::$app->getUser()->getUserInfo()['id'];
  43. $redisKey = 'admin:timeOut';
  44. $lastTime = '';
  45. if (!Yii::$app->tokenRedis->hget($redisKey, $adminId)) {
  46. $lastTime = time();
  47. }else{
  48. $lastTime = Yii::$app->tokenRedis->hget($redisKey, $adminId);
  49. }
  50. $currentTime = time();
  51. $timeOut = Yii::$app->params['operationTimeOut'];
  52. if ($currentTime - $lastTime > $timeOut) {
  53. return self::notice(Yii::t('ctx', 'notConnection'), 402);
  54. } else {
  55. Yii::$app->tokenRedis->hset($redisKey, $adminId, time());
  56. }
  57. }
  58. // 校验用户权限
  59. if (!Yii::$app->user->validateAdminAction($this->id, $this->action->id)) {
  60. // 兼容处理,拉取页面的权限使用menu的权限来判断
  61. if ($this->id == 'oauth' && $this->action->id == 'page') {
  62. $request = Yii::$app->request;
  63. $sqlCode = $request->get('code', '');// 获取页面的编码值
  64. $menu = require Yii::getAlias('@backendApi/config/menu.php');// 获取此页面code,对应的权限值
  65. $pagePermission = $this->checkPagePermission($sqlCode, $menu);
  66. if (empty($pagePermission)) {
  67. return self::notice(Yii::t('ctx', 'noPermission'), 403);
  68. }
  69. if(!Yii::$app->user->validateAdminAction($pagePermission['controller'], $pagePermission['action'])) {
  70. return self::notice(Yii::t('ctx', 'noPermission'), 403);
  71. } else {
  72. return $parentBeforeAction;
  73. }
  74. }
  75. return self::notice(Yii::t('ctx', 'noPermission'), 403);
  76. }
  77. return $parentBeforeAction;
  78. }
  79. public function checkPagePermission($sqlCode, $menu, &$ret=[]){
  80. foreach($menu as $key => $parentMenu){
  81. // 判断是否存在此值
  82. if(isset($parentMenu['schemaApi']) && $parentMenu['schemaApi'] == $sqlCode){
  83. $ret = $parentMenu;
  84. }
  85. // 判断子菜单是否存在
  86. if(isset($parentMenu['child']) && !empty($parentMenu['child'])){
  87. self::checkPagePermission($sqlCode, $parentMenu['child'], $ret);
  88. }
  89. }
  90. return $ret;
  91. }
  92. /**
  93. * 返回结果集
  94. * @param $dataOrErrorMessage
  95. * @param int $code
  96. * @return mixed
  97. * @throws HttpException
  98. */
  99. public static function notice($dataOrErrorMessage, $code = 0) {
  100. if ($code === 0) {
  101. return $dataOrErrorMessage;
  102. } else {
  103. throw new HttpException($code, $dataOrErrorMessage, $code);
  104. }
  105. }
  106. /**
  107. * 编辑方法
  108. * @param $formModelClass
  109. * @param $successMsg
  110. * @param string|null $scenario
  111. * @param array|null $methodAndParam
  112. * [
  113. * 'edit', // form 调用对象的方法名
  114. * 'param1', // form 调用对象的方法的第一个参数
  115. * 'param2', // form 调用对象的方法的第二个参数
  116. * 'param3', // form 调用对象的方法的第三个参数
  117. * ]
  118. * @param callable|null $beforeFun
  119. * @param callable|null $afterFun
  120. * @return mixed
  121. * @throws HttpException
  122. */
  123. public static function edit($formModelClass, $successMsg, string $scenario = null, array $methodAndParam = null, callable $beforeFun = null, callable $afterFun = null) {
  124. $id = Yii::$app->request->get('id', 0);
  125. $formModel = new $formModelClass();
  126. $formModel->scenario = 'add';
  127. if ($id) {
  128. $formModel->scenario = 'edit';
  129. $formModel->id = $id;
  130. }
  131. if ($scenario !== null) {
  132. $formModel->scenario = $scenario;
  133. }
  134. if ($beforeFun) $beforeFun($formModel);
  135. if ($methodAndParam === null) {
  136. $method = 'edit';
  137. $param = [];
  138. } else {
  139. $method = $methodAndParam[0];
  140. $param = $methodAndParam;
  141. unset($param[0]);
  142. }
  143. if ($formModel->load(Yii::$app->request->post(), '') && $result = call_user_func_array([&$formModel, $method], $param)) {
  144. if ($afterFun) $afterFun($formModel, $result);
  145. return static::notice($successMsg);
  146. } else {
  147. return static::notice(Form::formatErrorsForApi($formModel->getErrors()), 422);
  148. }
  149. }
  150. /**
  151. * 隐藏方法
  152. *
  153. */
  154. public static function hide($modelClass, $statusTo, callable $beforeFun = null, callable $afterFun = null) {
  155. $selected = \Yii::$app->request->get('selected');
  156. if (!$selected) {
  157. $selected = \Yii::$app->request->post('selected');
  158. }
  159. if (!$selected) {
  160. return self::notice('must select one item to hide', 500); // 必须选择一条删除数据
  161. }
  162. if (is_array($selected)) {
  163. $condition = ['AND', ['IN', 'ID', $selected]];
  164. $params = [];
  165. } else {
  166. $condition = 'ID=:ID';
  167. $params = [':ID' => $selected];
  168. }
  169. $transaction = \Yii::$app->db->beginTransaction();
  170. try {
  171. if (!is_array($selected)) {
  172. $selected = [$selected];
  173. }
  174. if ($beforeFun) $beforeFun($selected);
  175. if ($statusTo == 'hide') {
  176. $modelClass::updateAll(['STATUS' => 0], $condition, $params);
  177. $stateStr = 'hide';
  178. } else {
  179. $modelClass::updateAll(['STATUS' => 1], $condition, $params);
  180. $stateStr = 'Unhide';
  181. }
  182. if ($afterFun) $afterFun($selected);
  183. $transaction->commit();
  184. return self::notice($stateStr.' successfully'); // 隐藏/取消隐藏 成功
  185. } catch (Exception $e) {
  186. $transaction->rollBack();
  187. return self::notice($e->getMessage(), 500);
  188. }
  189. }
  190. /**
  191. * 删除方法
  192. * @param $modelClass
  193. * @param callable|null $beforeFun
  194. * @param callable|null $afterFun
  195. * @param bool $isDelData
  196. * @return mixed
  197. * @throws Exception
  198. * @throws HttpException
  199. */
  200. public static function delete($modelClass, callable $beforeFun = null, callable $afterFun = null, $isDelData = true) {
  201. $selected = \Yii::$app->request->get('selected');
  202. if (!$selected) {
  203. $selected = \Yii::$app->request->post('selected');
  204. }
  205. if (!$selected) {
  206. return self::notice('must select one item to delete', 500);// 必须选择一条删除数据
  207. }
  208. // 是否存在 DONT_DEL 字段
  209. if (ActiveRecord::isExistsField($modelClass, 'DONT_DEL')) {
  210. $isDontDelField = true;
  211. } else {
  212. $isDontDelField = false;
  213. }
  214. if (is_array($selected)) {
  215. if ($isDontDelField) {
  216. $condition = ['AND', ['IN', 'ID', $selected], ['<>', 'DONT_DEL', 1]];
  217. } else {
  218. $condition = ['AND', ['IN', 'ID', $selected]];
  219. }
  220. // $condition = 'ID IN ('.implode(',', $selected).') AND DONT_DEL<>1';
  221. $params = [];
  222. } else {
  223. if ($isDontDelField) {
  224. $condition = 'ID=:ID AND DONT_DEL<>1';
  225. } else {
  226. $condition = 'ID=:ID';
  227. }
  228. //$condition = ['AND', ['ID'=>$selected], ['<>', 'DONT_DEL', 1]];
  229. $params = [':ID' => $selected];
  230. }
  231. $transaction = \Yii::$app->db->beginTransaction();
  232. try {
  233. if (!is_array($selected)) {
  234. $selected = [$selected];
  235. }
  236. if ($beforeFun) $beforeFun($selected);
  237. if ($isDelData) {
  238. // 真实删除数据
  239. if (!$modelClass::deleteAll($condition, $params)) {
  240. throw new Exception('failed to delete');//删除失败
  241. }
  242. } else {
  243. // 设置IS_DEL字段为1
  244. $modelClass::updateAll(['IS_DEL' => 1, 'DELETED_AT' => Date::nowTime()], $condition, $params);
  245. }
  246. if ($afterFun) $afterFun($selected);
  247. $transaction->commit();
  248. return self::notice('delete successfully');//删除成功
  249. } catch (Exception $e) {
  250. $transaction->rollBack();
  251. return self::notice($e->getMessage(), 500);
  252. }
  253. }
  254. /**
  255. * 筛选条件
  256. * @param array $tableParams
  257. * [
  258. * '筛选提交参数名' => '表名.字段名',
  259. * 'userIds' => 'USER_INFO.USER_ID',
  260. * 'userName' => 'USER_INFO.USER_NAME',
  261. * ]
  262. *
  263. * get提交的值
  264. * [
  265. * 'userIds' => 'in,asdsa,asdsads',
  266. * 'userName' => 'like,test',
  267. * 'createdAt' => '>=,2018-11-26,date'
  268. * ]
  269. * @return array
  270. */
  271. public function filterCondition(array $tableParams = []) {
  272. $allGet = Yii::$app->request->get();
  273. $condition = '';
  274. $params = [];
  275. foreach ($tableParams as $getParam => $tableField) {
  276. if (isset($allGet[$getParam]) && $allGet[$getParam]) {
  277. $getValue = trim($allGet[$getParam], ", \t\n\r\0\x0B");
  278. $bindParam = strtoupper($getParam);
  279. if (strpos($getValue, '|') > 0) {
  280. $condition .= ' AND (';
  281. $chidValueArr = explode('|', $getValue);
  282. foreach ($chidValueArr as $k => $value) {
  283. if ($k == 0) {
  284. $result = $this->_getConditionAndParams($value, $tableField, $bindParam . $k, '');
  285. } else {
  286. $result = $this->_getConditionAndParams($value, $tableField, $bindParam . $k, 'OR');
  287. }
  288. $condition .= $result['condition'];
  289. $params += $result['params'];
  290. }
  291. $condition .= ')';
  292. } else {
  293. $result = $this->_getConditionAndParams($getValue, $tableField, $bindParam);
  294. $condition .= $result['condition'];
  295. $params += $result['params'];
  296. }
  297. }
  298. }
  299. return [
  300. 'condition' => $condition,
  301. 'params' => $params,
  302. 'request' => $allGet,
  303. ];
  304. }
  305. /**
  306. * 获取条件
  307. * @param $getValue
  308. * @param $tableField
  309. * @param $bindParam
  310. * @param string $relation
  311. * @return array
  312. */
  313. private function _getConditionAndParams($getValue, $tableField, $bindParam, $relation = 'AND') {
  314. $condition = '';
  315. $params = [];
  316. $isDate = false;
  317. $filterModel = '';
  318. if (strpos($getValue, ',') > 0) {
  319. $getValueArr = explode(',', $getValue);
  320. $getSymbol = strtoupper($getValueArr[0]);
  321. if ($getSymbol == 'IN') {
  322. $bindValueArr = $getValueArr;
  323. unset($bindValueArr[0]);
  324. $bindValue = implode("','", $bindValueArr);
  325. $bindValue = "'$bindValue'";
  326. } else {
  327. $bindValue = $getValueArr[1];
  328. $filterModel = end($getValueArr);
  329. reset($getValueArr);
  330. if($filterModel == 'date'){
  331. if( $getSymbol !== '>=' && $getSymbol !== '<=' && $getSymbol !== '>' && $getSymbol !== '<' ) {
  332. throw new \Exception("Incorrect date format");//日期筛选格式不对
  333. }
  334. $bindValue = strtotime($getValueArr[1]);
  335. $isDate = true;
  336. $relation = $relation ? 'AND' : '';
  337. }
  338. elseif($filterModel == 'area'){
  339. $bindValue = array_slice($getValueArr, 1, 3);
  340. }
  341. }
  342. } else {
  343. $getSymbol = '=';
  344. $bindValue = $getValue;
  345. }
  346. if ($getSymbol == 'LIKE') {
  347. $condition .= ' ' . $relation . ' INSTR(' . $tableField . ',:' . $bindParam . ')>0';
  348. } elseif ($getSymbol == strtoupper('notLike')) {
  349. $condition .= ' ' . $relation . ' INSTR(' . $tableField . ',:' . $bindParam . ')=0';
  350. } elseif ($getSymbol == 'IN') {
  351. $condition .= ' ' . $relation . ' ' . $tableField . ' IN (' . $bindValue . ')';
  352. } else {
  353. if ($isDate && $getSymbol == '=') {
  354. $condition .= ' ' . $relation . ' ' . $tableField . '>=:' . $bindParam . 's';
  355. $condition .= ' AND ' . $tableField . '<=:' . $bindParam . 'e';
  356. }
  357. elseif($filterModel == 'area'){
  358. if($bindValue[0]){
  359. $condition .= ' AND '.$tableField['FIELD'][0].'=:'.$tableField['BIND'][0];
  360. if(isset($bindValue[1])&&$bindValue[1]&&$bindValue[1]!='area'){
  361. $condition .= ' AND '.$tableField['FIELD'][1].'=:'.$tableField['BIND'][1];
  362. if(isset($bindValue[2])&&$bindValue[2]&&$bindValue[2]!='area'){
  363. $condition .= ' AND '.$tableField['FIELD'][2].'=:'.$tableField['BIND'][2];
  364. }
  365. }
  366. }
  367. }
  368. else {
  369. if($getSymbol!=='=' && $relation=='OR'){
  370. $relation = 'AND';
  371. }
  372. $condition .= ' ' . $relation . ' ' . $tableField . $getSymbol . ':' . $bindParam;
  373. }
  374. }
  375. if ($getSymbol != 'IN') {
  376. if ($isDate && $getSymbol == '=') {
  377. $params[':' . $bindParam . 's'] = $bindValue;
  378. $params[':' . $bindParam . 'e'] = $bindValue + 86399;
  379. }
  380. if ($filterModel == 'area') {
  381. if($bindValue[0]){
  382. $params[':'.$tableField['BIND'][0]] = $bindValue[0];
  383. if(isset($bindValue[1])&&$bindValue[1]&&$bindValue[1]!='area'){
  384. $params[':'.$tableField['BIND'][1]] = $bindValue[1];
  385. if(isset($bindValue[2])&&$bindValue[2]&&$bindValue[2]!='area'){
  386. $params[':'.$tableField['BIND'][2]] = $bindValue[2];
  387. }
  388. }
  389. }
  390. }
  391. else {
  392. $params[':' . $bindParam] = $bindValue;
  393. }
  394. }
  395. return ['condition' => $condition, 'params' => $params];
  396. }
  397. /**
  398. * 筛选条件
  399. * @param string $tableName
  400. * @param array $otherParams
  401. * [
  402. * '筛选提交参数名' => '表名.字段名',
  403. * 'userName' => 'USER_INFO.USER_NAME',
  404. * ]
  405. * 或者
  406. * [
  407. * '筛选提交参数名' => ['表名.字段名', '符号'],
  408. * 'userName' => ['USER_INFO.USER_NAME', '<'],
  409. * ]
  410. * @return array
  411. */
  412. public function filterConditionBak($tableName = '', array $otherParams = []) {
  413. $dateRange = Yii::$app->request->get('dateRange', '');
  414. $condition = '';
  415. $params = [];
  416. if ($tableName) {
  417. $tableName = $tableName . '.';
  418. }
  419. if ($dateRange) {
  420. $condition .= " AND {$tableName}CREATED_AT>:CREATED_START AND {$tableName}CREATED_AT<:CREATED_END";
  421. $params[':CREATED_START'] = Date::utcToTime($dateRange[0]);
  422. $params[':CREATED_END'] = Date::utcToTime($dateRange[1]);
  423. }
  424. $requestParams = [];
  425. foreach ($otherParams as $getParam => $field) {
  426. $getValue = Yii::$app->request->get($getParam, '');
  427. $requestParams[$getParam] = $getValue;
  428. if ($getValue === 'all') $getValue = '';
  429. if ($getValue !== '') {
  430. if (is_string($field)) {
  431. $condition .= " AND $field=:" . strtoupper($getParam);
  432. $params[':' . strtoupper($getParam)] = $getValue;
  433. } elseif (is_array($field)) {
  434. if (count($field) == 1) {
  435. $condition .= " AND {$field[0]}=:" . strtoupper($getParam);
  436. $params[':' . strtoupper($getParam)] = $getValue;
  437. } elseif (count($field) == 2) {
  438. if (strtolower($field[1]) == 'in') {
  439. $getValue = Tool::filterSpecialChar($getValue);
  440. if ($getValue) {
  441. $getValue = explode(',', $getValue);
  442. $getValue = implode("','", $getValue);
  443. $getValue = "'$getValue'";
  444. $condition .= " AND {$field[0]} IN ({$getValue})";
  445. }
  446. } else {
  447. $condition .= " AND {$field[0]}{$field[1]}:" . strtoupper($getParam);
  448. $params[':' . strtoupper($getParam)] = $getValue;
  449. }
  450. }
  451. }
  452. }
  453. }
  454. // 请求的参数也一并返回
  455. $request = array_merge([
  456. 'dateRange' => $dateRange,
  457. ], $requestParams);
  458. return [
  459. 'condition' => $condition,
  460. 'params' => $params,
  461. 'request' => $request,
  462. ];
  463. }
  464. }