Admin.php 19 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490
  1. <?php
  2. /**
  3. * @copyright Copyright (c) 2021 勾股工作室
  4. * @license https://opensource.org/licenses/Apache-2.0
  5. * @link https://www.gougucms.com
  6. */
  7. declare (strict_types = 1);
  8. namespace app\admin\controller;
  9. use app\admin\BaseController;
  10. use app\admin\model\Admin as AdminList;
  11. use app\admin\validate\AdminCheck;
  12. use avatars\MDAvatars;
  13. use think\exception\ValidateException;
  14. use think\facade\Db;
  15. use think\facade\View;
  16. use think\facade\Session;
  17. use think\App;
  18. use think\facade\Cache;
  19. use app\admin\controller\Role;
  20. use app\admin\model\Department as DepartmentModel;
  21. class Admin extends BaseController
  22. {
  23. public function __construct(App $app)
  24. {
  25. parent::__construct($app);
  26. $this->Role = new Role($this->app);
  27. $this->Department = new DepartmentModel();
  28. }
  29. public function index()
  30. {
  31. if (request()->isAjax()) {
  32. // 获取单位名称
  33. $session_admin = get_config('app.session_admin');
  34. $id = Session::get($session_admin)['id'];
  35. $unit_name = Db::name('admin')->where('id', $id)->value('unit_name');
  36. $admin_permission = Db::name('admin')->where('id', $id)->value('permission');
  37. // halt($unit_name);
  38. $param = get_params();
  39. if (!empty($param['keywords'])) {
  40. $where[] = ['id|username|nickname|desc|mobile', 'like', '%' . $param['keywords'] . '%'];
  41. }
  42. $where = array();
  43. $permission = array();
  44. $where[] = ['status', '>=', 0];
  45. if($admin_permission == 0){
  46. $permission[] = ['unit_name', '=',$unit_name];
  47. }
  48. $rows = empty($param['limit']) ? get_config('app.page_size') : $param['limit'];
  49. $admin = AdminList::where($where)->with('Department')
  50. ->where($permission)
  51. ->order('create_time asc')
  52. ->paginate($rows, false, ['query' => $param])
  53. ->each(function ($item, $key) {
  54. $groupId = Db::name('AdminGroupAccess')->where(['uid' => $item->id])->column('group_id');
  55. $groupName = Db::name('AdminGroup')->where('id', 'in', $groupId)->column('title');
  56. $item->groupName = implode(',', $groupName);
  57. $item->last_login_time = empty($item->last_login_time) ? '-' : date('Y-m-d H:i', $item->last_login_time);
  58. })->toArray();
  59. // dump($admin);
  60. if(get_login_admin('user_type') == -1){
  61. $admin_ = $admin['data'];
  62. unset($admin['data'][count($admin['data']) - 1]); //移除超级管理
  63. }
  64. return table_assign(0, '', $admin);
  65. } else {
  66. View::assign('user_type', get_login_admin('user_type'));
  67. return view();
  68. }
  69. }
  70. //添加
  71. public function add()
  72. {
  73. if (request()->isAjax()) {
  74. $param = get_params();
  75. if (!preg_match('/^(?=.*[A-Z])(?=.*[a-z])(?=.*\d)(?=.*[@$!%*?&])[A-Za-z\d@$!%*?&]{8,}$/', $param['pwd'])) {
  76. return to_assign(1, '密码必须至少包含8个字符,含有大小写字母、数字和特殊字符!');
  77. }
  78. // halt($param);
  79. if (!empty($param['id']) && $param['id'] > 0) { //对已存在账号的编辑
  80. try {
  81. validate(AdminCheck::class)->scene('edit')->check($param);
  82. } catch (ValidateException $e) {
  83. // 验证失败 输出错误信息
  84. return to_assign(1, $e->getError());
  85. }
  86. if (!empty($param['edit_pwd'])) {
  87. //重置密码
  88. if (empty($param['edit_pwd_confirm']) or $param['edit_pwd_confirm'] !== $param['edit_pwd']) {
  89. return to_assign(1, '两次密码不一致');
  90. }
  91. $param['salt'] = set_salt(20);
  92. $param['pwd'] = set_password($param['edit_pwd'], $param['salt']);
  93. }
  94. // halt($param);
  95. // 启动事务
  96. Db::startTrans();
  97. try {
  98. // halt($param);
  99. $param['last_password_change'] = time();
  100. Db::name('Admin')->where(['id' => $param['id']])->strict(false)->field(true)->update($param); //更新密码
  101. Db::name('AdminGroupAccess')->where(['uid' => $param['id']])->delete(); //先删除权限组
  102. foreach ($param['group_id'] as $k => $v) {
  103. //为了系统安全,只有系统所有者才可创建id为1的管理员分组
  104. if ($v == 1 and get_login_admin('id') !== 1) {
  105. throw new ValidateException("你没有权限创建系统所有者", 1);
  106. }
  107. $data[$k] = [
  108. 'uid' => $param['id'],
  109. 'group_id' => $v,
  110. ];
  111. $param['admin_group_id'] = $v;
  112. }
  113. Db::name('AdminGroupAccess')->strict(false)->field(true)->insertAll($data); //再新增权限组
  114. if (!isset($param['thumb']) || $param['thumb'] == '') {
  115. $char = mb_substr($param['nickname'], 0, 1, 'utf-8');
  116. Db::name('Admin')->where('id', $param['id'])->update(['thumb' => $this->to_avatars($char)]);
  117. }
  118. //
  119. if($param['is_principal'] == 1){
  120. // $res = Db::name('Department')->where('id', $param['did'])->value('leader_id');
  121. // halt($res);
  122. $res = Db::name('Department')->where('id', $param['did'])->update(['leader_id' => $param['id']]);
  123. // $this->Department->where('id', $param['did'])->force()->save(['leader_id' => $param['id']]);
  124. // halt($res);
  125. }
  126. // 获取单位名称
  127. $unit_name = self::get_unitName($param['id']);
  128. $data = [
  129. 'unit_name' => $unit_name,
  130. 'user_type' => Db::name('Department')->where('id', $unit_name)->value('type'),
  131. 'admin_group_id' => $param['admin_group_id'],
  132. ];
  133. // unset($data['group_id']);
  134. // halt($data);
  135. $res = Db::name('admin')->where('id', $param['id'])->data($data)->update();
  136. // halt($res);
  137. add_log('edit', $param['id'], $param);
  138. //清除菜单\权限缓存
  139. clear_cache('adminMenu');
  140. clear_cache('adminRules');
  141. // 提交事务
  142. Db::commit();
  143. } catch (\Exception $e) {
  144. // 回滚事务
  145. Db::rollback();
  146. return to_assign(1, '提交失败:' . $e->getMessage());
  147. }
  148. } else { //新增账号
  149. // halt($param);
  150. try {
  151. validate(AdminCheck::class)->scene('add')->check($param);
  152. } catch (ValidateException $e) {
  153. // 验证失败 输出错误信息
  154. return to_assign(1, $e->getError());
  155. }
  156. $param['salt'] = set_salt(20);
  157. $param['pwd'] = set_password($param['pwd'], $param['salt']);
  158. $param['last_password_change'] = time();
  159. // 启动事务
  160. Db::startTrans();
  161. try {
  162. foreach ($param['group_id'] as $k => $v) {
  163. $param['admin_group_id'] = $v;
  164. }
  165. // halt($param);
  166. $uid = Db::name('Admin')->strict(false)->field(true)->insertGetId($param);
  167. unset($param['admin_group_id']);
  168. if($param['is_principal'] == 1){
  169. Db::name('department')->where('id', $param['did'])->data(['leader_id' => $uid])->update();
  170. }
  171. // halt($uid);
  172. foreach ($param['group_id'] as $k => $v) {
  173. //为了系统安全,只有系统所有者才可创建id为1的管理员分组
  174. if ($v == 1 and get_login_admin('id') !== 1) {
  175. throw new ValidateException("你没有权限创建系统所有者", 1);
  176. }
  177. $data[$k] = [
  178. 'uid' => $uid,
  179. 'group_id' => $v,
  180. ];
  181. }
  182. Db::name('AdminGroupAccess')->strict(false)->field(true)->insertAll($data);
  183. if (!isset($param['thumb']) || $param['thumb'] == '') {
  184. $char = mb_substr($param['nickname'], 0, 1, 'utf-8');
  185. Db::name('Admin')->where('id', $uid)->update(['thumb' => $this->to_avatars($char)]);
  186. }
  187. // 获取单位名称
  188. $unit_name = self::get_unitName($uid);
  189. $data = [
  190. 'unit_name' => $unit_name,
  191. 'user_type' => Db::name('Department')->where('id', $unit_name)->value('type'),
  192. ];
  193. // halt($data);
  194. Db::name('admin')->where('id', $uid)->data($data)->update();
  195. add_log('add', $uid, $param);
  196. // 提交事务
  197. Db::commit();
  198. } catch (\Exception $e) {
  199. // 回滚事务
  200. Db::rollback();
  201. return to_assign(1, '提交失败:' . $e->getMessage());
  202. }
  203. }
  204. return to_assign(0,"操作成功");
  205. }else{
  206. $id = empty(get_params('id')) ? 0 : get_params('id');
  207. // dump($id);
  208. $permission = Db::name('admin')->where('id', get_login_admin('id'))->value('permission');
  209. $unit_name = Db::name('admin')->where('id', get_login_admin('id'))->value('unit_name');
  210. $group_id = Db::name('AdminGroupAccess')->where('uid', get_login_admin('id'))->value('group_id');
  211. $where_d = array();
  212. $where_p = array();
  213. $where_g = array();
  214. if($permission == 0){
  215. $where_d[] = ['unit_name', '=', $unit_name];
  216. $where_p[] = ['did', '=', $unit_name];
  217. $where_g[] = [
  218. ['unit_name', '=', $unit_name],
  219. ];
  220. }
  221. $department = Db::name('Department')
  222. ->where('status', '>=', 0)
  223. ->where($where_d)
  224. ->select()
  225. ->toArray();
  226. // dump($department);
  227. $department = set_recursion($department);
  228. // dump($department);
  229. $position = Db::name('Position')
  230. ->where('status', '>=', 0)
  231. ->where($where_p)
  232. ->order('create_time asc')
  233. ->select()
  234. ->toArray();
  235. foreach($position as $key => $value){
  236. $dep = Db::name('Department')->where('id', $value['did'])->value('title');
  237. $position[$key]['did_title'] = $dep;
  238. }
  239. $group = Db::name('AdminGroup')
  240. ->where($where_g)
  241. ->select()->toarray();
  242. if($permission == 1){
  243. $group = Db::name('AdminGroup')
  244. ->where('unit_name', '=', $unit_name)
  245. ->select()->toarray();
  246. // dump($group);
  247. }
  248. $group_mine = Db::name('AdminGroup')->where('id', $group_id)->select()->toArray();
  249. // dump($permission);
  250. if(get_login_admin('user_type') == -1){
  251. unset($group[0]); //移除超管权限组
  252. }
  253. $group = array_merge($group_mine, $group);
  254. if ($id > 0) {
  255. $admin = get_admin(get_params('id'));
  256. // dump($admin);
  257. // $did = get_login_admin('did');
  258. $leader_id = Db::name('Department')->where('id', $admin['did'])->value('leader_id');
  259. // dump($leader_id);
  260. if($leader_id == $id){
  261. $is_principal = 1;
  262. }else{
  263. $is_principal = 0;
  264. }
  265. View::assign('is_principal', $is_principal);
  266. View::assign('admin', $admin);
  267. }
  268. // dump($group);
  269. // dump($department);
  270. View::assign('permission', $permission);
  271. View::assign('department', $department);
  272. View::assign('position', $position);
  273. View::assign('group', $group);
  274. View::assign('id', $id);
  275. return view();
  276. }
  277. }
  278. public function to_avatars($char)
  279. {
  280. $defaultData = array('A', 'B', 'C', 'D', 'E', 'F', 'G', 'H', 'I', 'J', 'K', 'L', 'M', 'N',
  281. 'O', 'P', 'Q', 'R', 'S', 'T', 'U', 'V', 'W', 'S', 'Y', 'Z',
  282. '0', '1', '2', '3', '4', '5', '6', '7', '8', '9',
  283. '零', '壹', '贰', '叁', '肆', '伍', '陆', '柒', '捌', '玖', '拾',
  284. '一', '二', '三', '四', '五', '六', '七', '八', '九', '十');
  285. if (isset($char)) {
  286. $Char = $char;
  287. } else {
  288. $Char = $defaultData[mt_rand(0, count($defaultData) - 1)];
  289. }
  290. $OutputSize = min(512, empty($_GET['size']) ? 36 : intval($_GET['size']));
  291. $Avatar = new MDAvatars($Char, 256, 1);
  292. $avatar_name = '/avatars/avatar_256_' . set_salt(10) . time() . '.png';
  293. $path = get_config('filesystem.disks.public.url') . $avatar_name;
  294. $res = $Avatar->Save('.' . $path, 256);
  295. $Avatar->Free();
  296. /*
  297. if ($res) {
  298. //写入到附件表
  299. $data = [];
  300. $data['filepath'] = $path;
  301. $data['name'] = $Char;
  302. $data['mimetype'] = 'image/png';
  303. $data['fileext'] = 'png';
  304. $data['filesize'] = 0;
  305. $data['filename'] = $avatar_name;
  306. $data['sha1'] = '';
  307. $data['md5'] = '';
  308. $data['module'] = \think\facade\App::initialize()->http->getName();
  309. $data['action'] = app('request')->action();
  310. $data['uploadip'] = app('request')->ip();
  311. $data['create_time'] = time();
  312. $data['user_id'] = get_login_admin('id') ? get_login_admin('id') : 0;
  313. if ($data['module'] = 'admin') {
  314. //通过后台上传的文件直接审核通过
  315. $data['status'] = 1;
  316. $data['admin_id'] = $data['user_id'];
  317. $data['audit_time'] = time();
  318. }
  319. $data['use'] = 'avatar'; //附件用处
  320. $fid = Db::name('file')->insertGetId($data);
  321. return $fid;
  322. }
  323. */
  324. return $path;
  325. }
  326. //查看
  327. public function view()
  328. {
  329. $id = get_params('id');
  330. $rule = get_admin_rule();
  331. $user_groups = Db::name('AdminGroupAccess')
  332. ->alias('a')
  333. ->join("AdminGroup g", "a.group_id=g.id", 'LEFT')
  334. ->where("a.uid='{$id}' and g.status='1'")
  335. ->select()
  336. ->toArray();
  337. $groups = $user_groups ?: [];
  338. $rules = [];
  339. foreach ($groups as $g) {
  340. $rules = array_merge($rules, explode(',', trim($g['rules'], ',')));
  341. }
  342. $rules = array_unique($rules);
  343. $role_rule = create_tree_list(0, $rule, $rules);
  344. $role_rule = $this->Role->remove_checked_false($role_rule);
  345. $department = get_department();
  346. // dump($department);
  347. $position = Db::name('Position')->where('status', '>=', 0)->order('create_time asc')->select();
  348. View::assign('department', $department);
  349. View::assign('position', $position);
  350. View::assign('role_rule', $role_rule);
  351. View::assign('admin', get_admin($id));
  352. add_log('view', get_params('id'));
  353. return view('', ['admin' => get_admin(get_params('id'))]);
  354. }
  355. //删除
  356. public function delete()
  357. {
  358. $id = get_params("id");
  359. if($id == 1){
  360. return to_assign(0, "超级管理员,不能删除");
  361. }
  362. $data['status'] = '-1';
  363. $data['id'] = $id;
  364. $data['update_time'] = time();
  365. if (Db::name('Admin')->update($data) !== false) {
  366. add_log('delete', $id);
  367. return to_assign(0, "删除管理员成功");
  368. } else {
  369. return to_assign(1, "删除失败");
  370. }
  371. }
  372. //管理员操作日志
  373. public function log()
  374. {
  375. if (request()->isAjax()) {
  376. $param = get_params();
  377. $where = array();
  378. if (!empty($param['keywords'])) {
  379. $where[] = ['nickname|rule_menu|param_id', 'like', '%' . $param['keywords'] . '%'];
  380. }
  381. if (!empty($param['title_cate'])) {
  382. $where['title'] = $param['title_cate'];
  383. }
  384. if (!empty($param['rule_menu'])) {
  385. $where['rule_menu'] = $param['rule_menu'];
  386. }
  387. $rows = empty($param['limit']) ? get_config('app.page_size') : $param['limit'];
  388. $content = DB::name('AdminLog')
  389. ->field("id,uid,nickname,title,content,rule_menu,ip,param_id,param,FROM_UNIXTIME(create_time,'%Y-%m-%d %H:%i:%s') create_time")
  390. ->order('create_time desc')
  391. ->where($where)
  392. ->paginate($rows, false, ['query' => $param]);
  393. $content->toArray();
  394. foreach ($content as $k => $v) {
  395. $data = $v;
  396. $param_array = json_decode($v['param'], true);
  397. if(is_array($param_array)){
  398. $param_value = '';
  399. foreach ($param_array as $key => $value) {
  400. if (is_array($value)) {
  401. $value = implode(',', $value);
  402. }
  403. $param_value .= $key . ':' . $value . '&nbsp;&nbsp;|&nbsp;&nbsp;';
  404. }
  405. $data['param'] = $param_value;
  406. }
  407. else{
  408. $data['param'] = $param_array;
  409. }
  410. $content->offsetSet($k, $data);
  411. }
  412. return table_assign(0, '', $content);
  413. } else {
  414. return view();
  415. }
  416. }
  417. public function get_unitName($id){
  418. $did = Db::name('Admin')->where('id', $id)->value('did');
  419. $pid = $did;
  420. while($pid != 0){
  421. $value = Db::name('department')->where('id', $pid)->column('id,pid,title')[0];
  422. $id = $value['id'];
  423. $pid = $value['pid'];
  424. $title = $value['title'];
  425. }
  426. // halt($value);
  427. return $id;
  428. }
  429. }