Auth.php 4.9 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145
  1. <?php namespace Manage\Lib;
  2. use Dever;
  3. class Auth
  4. {
  5. protected $login = true;
  6. protected $uid;
  7. protected $user;
  8. protected $system;
  9. protected $relation;
  10. public $data = array();
  11. public function __construct()
  12. {
  13. $info = Dever::load('common', 'manage')->auth();
  14. if (!$info && $this->login) {
  15. $info['uid'] = 1;
  16. $info['extend']['system_id'] = 1;
  17. $info['extend']['relation_id'] = 1;
  18. //Dever::error('请先登录');
  19. }
  20. $this->system = Dever::db('system', 'manage')->find($info['extend']['system_id']);
  21. if (!$this->system) {
  22. Dever::error('当前系统不存在');
  23. }
  24. $this->relation = Dever::db($this->system['relation_table'])->find($info['extend']['relation_id']);
  25. if (!$this->system) {
  26. Dever::error('当前系统设置错误');
  27. }
  28. $this->uid = $info['uid'];
  29. $this->user = Dever::db($this->system['relation_user_table'])->find($this->uid);
  30. if (!$this->user) {
  31. Dever::error('请先登录');
  32. }
  33. $this->user['auth'] = array('system' => '', 'menu' => '', 'func' => '');
  34. if ($this->user['role']) {
  35. $role = Dever::db($this->system['relation_role_table'])->select(array('id' => array('in', $this->user['role'])));
  36. foreach ($role as $k => $v) {
  37. $this->user['auth']['system'] .= $v['system'] . ',';
  38. $this->user['auth']['menu'] .= $v['menu'] . ',';
  39. $this->user['auth']['func'] .= $v['auth'] . ',';
  40. }
  41. }
  42. if ($this->user['auth']['system']) {
  43. $this->user['auth']['system'] = rtrim($this->user['auth']['system'], ',');
  44. }
  45. if ($this->user['auth']['menu']) {
  46. $this->user['auth']['menu'] = rtrim($this->user['auth']['menu'], ',');
  47. }
  48. if ($this->user['auth']['func']) {
  49. $this->user['auth']['func'] = ',' . $this->user['auth']['func'];
  50. }
  51. $this->user['select'] = $info['extend'] ?? false;
  52. if (!$this->user['select']) {
  53. $this->user['select'] = array('system_id' => 1, 'relation_id' => 1);
  54. }
  55. $this->checkSystem($this->user['select']['system_id']);
  56. }
  57. # 设置功能权限
  58. public function getFunc($key, $name, $sort = 1, $param = '')
  59. {
  60. if (!$key) {
  61. $key = md5(base64_encode($name));
  62. }
  63. /*
  64. if ($param) {
  65. if (is_array($param)) {
  66. $param = Dever::json_encode($name);
  67. }
  68. $key = $key . '_' . md5($param);
  69. }*/
  70. $data['menu_id'] = $this->menu['id'];
  71. $data['key'] = $key;
  72. $info = Dever::db('menu_func', 'manage')->find($data);
  73. $name = $this->menu['name'] . '-' . $name;
  74. if (!$info) {
  75. $data['name'] = $name;
  76. $data['sort'] = $sort;
  77. $id = Dever::db('menu_func', 'manage')->insert($data);
  78. Dever::db('menu', 'manage')->update($this->menu['id'], array('func' => 1));
  79. } else {
  80. if ($info['name'] != $name) {
  81. $data['name'] = $name;
  82. $data['sort'] = $sort;
  83. Dever::db('menu_func', 'manage')->update($info['id'], $data);
  84. Dever::db('menu', 'manage')->update($this->menu['id'], array('func' => 1));
  85. }
  86. $id = $info['id'];
  87. }
  88. if ($this->user['id'] == 1) {
  89. return $id;
  90. }
  91. if ($this->user['auth']['func'] && strstr($this->user['auth']['func'], ',' . $id . ',')) {
  92. return $id;
  93. }
  94. return false;
  95. }
  96. # 检测系统权限
  97. protected function checkSystem($system_id)
  98. {
  99. if ($this->user['id'] == 1) {
  100. return;
  101. }
  102. if ($this->user['auth']['system'] && !Dever::check($this->user['auth']['system'], $system_id)) {
  103. Dever::error('无系统权限');
  104. }
  105. }
  106. # 检测菜单权限
  107. protected function checkMenu($menu, $result = true)
  108. {
  109. if ($this->user['id'] == 1) {
  110. return;
  111. }
  112. if ($this->user['auth']['menu'] && !Dever::check($this->user['auth']['menu'], $menu)) {
  113. if ($result) {
  114. return true;
  115. }
  116. Dever::error('无访问权限');
  117. }
  118. if ($result) {
  119. return false;
  120. }
  121. }
  122. # 检测功能权限
  123. protected function checkFunc()
  124. {
  125. $id = Dever::input('func');
  126. if (!$id) {
  127. return false;
  128. }
  129. if ($this->user['id'] == 1) {
  130. return $id;
  131. }
  132. if ($this->user['auth']['func'] && strstr($this->user['auth']['func'], ',' . $id . ',')) {
  133. return $id;
  134. }
  135. Dever::error('无操作权限');
  136. }
  137. }