Admin.php 18 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483
  1. <?php
  2. /**
  3. * @copyright Copyright (c) 2021 勾股工作室
  4. * @license https://opensource.org/licenses/Apache-2.0
  5. * @link https://www.gougucms.com
  6. */
  7. declare (strict_types = 1);
  8. namespace app\admin\controller;
  9. use app\admin\BaseController;
  10. use app\admin\model\Admin as AdminList;
  11. use app\admin\validate\AdminCheck;
  12. use avatars\MDAvatars;
  13. use think\exception\ValidateException;
  14. use think\facade\Db;
  15. use think\facade\View;
  16. use think\facade\Session;
  17. use think\App;
  18. use think\facade\Cache;
  19. use app\admin\controller\Role;
  20. use app\admin\model\Department as DepartmentModel;
  21. class Admin extends BaseController
  22. {
  23. public function __construct(App $app)
  24. {
  25. parent::__construct($app);
  26. $this->Role = new Role($this->app);
  27. $this->Department = new DepartmentModel();
  28. }
  29. public function index()
  30. {
  31. if (request()->isAjax()) {
  32. // 获取单位名称
  33. $session_admin = get_config('app.session_admin');
  34. $id = Session::get($session_admin)['id'];
  35. $unit_name = Db::name('admin')->where('id', $id)->value('unit_name');
  36. $admin_permission = Db::name('admin')->where('id', $id)->value('permission');
  37. // halt($unit_name);
  38. $param = get_params();
  39. if (!empty($param['keywords'])) {
  40. $where[] = ['id|username|nickname|desc|mobile', 'like', '%' . $param['keywords'] . '%'];
  41. }
  42. $where = array();
  43. $permission = array();
  44. $where[] = ['status', '>=', 0];
  45. if($admin_permission == 0){
  46. $permission[] = ['unit_name', '=',$unit_name];
  47. }
  48. $rows = empty($param['limit']) ? get_config('app.page_size') : $param['limit'];
  49. $admin = AdminList::where($where)->with('Department')
  50. ->where($permission)
  51. ->order('create_time asc')
  52. ->paginate($rows, false, ['query' => $param])
  53. ->each(function ($item, $key) {
  54. $groupId = Db::name('AdminGroupAccess')->where(['uid' => $item->id])->column('group_id');
  55. $groupName = Db::name('AdminGroup')->where('id', 'in', $groupId)->column('title');
  56. $item->groupName = implode(',', $groupName);
  57. $item->last_login_time = empty($item->last_login_time) ? '-' : date('Y-m-d H:i', $item->last_login_time);
  58. })->toArray();
  59. // dump($admin);
  60. if(get_login_admin('user_type') == -1){
  61. $admin_ = $admin['data'];
  62. unset($admin['data'][count($admin['data']) - 1]); //移除超级管理
  63. }
  64. return table_assign(0, '', $admin);
  65. } else {
  66. View::assign('user_type', get_login_admin('user_type'));
  67. return view();
  68. }
  69. }
  70. //添加
  71. public function add()
  72. {
  73. if (request()->isAjax()) {
  74. $param = get_params();
  75. // halt($param);
  76. if (!empty($param['id']) && $param['id'] > 0) { //对已存在账号的编辑
  77. try {
  78. validate(AdminCheck::class)->scene('edit')->check($param);
  79. } catch (ValidateException $e) {
  80. // 验证失败 输出错误信息
  81. return to_assign(1, $e->getError());
  82. }
  83. if (!empty($param['edit_pwd'])) {
  84. //重置密码
  85. if (empty($param['edit_pwd_confirm']) or $param['edit_pwd_confirm'] !== $param['edit_pwd']) {
  86. return to_assign(1, '两次密码不一致');
  87. }
  88. $param['salt'] = set_salt(20);
  89. $param['pwd'] = set_password($param['edit_pwd'], $param['salt']);
  90. }
  91. // halt($param);
  92. // 启动事务
  93. Db::startTrans();
  94. try {
  95. // halt($param);
  96. Db::name('Admin')->where(['id' => $param['id']])->strict(false)->field(true)->update($param); //更新密码
  97. Db::name('AdminGroupAccess')->where(['uid' => $param['id']])->delete(); //先删除权限组
  98. foreach ($param['group_id'] as $k => $v) {
  99. //为了系统安全,只有系统所有者才可创建id为1的管理员分组
  100. if ($v == 1 and get_login_admin('id') !== 1) {
  101. throw new ValidateException("你没有权限创建系统所有者", 1);
  102. }
  103. $data[$k] = [
  104. 'uid' => $param['id'],
  105. 'group_id' => $v,
  106. ];
  107. $param['admin_group_id'] = $v;
  108. }
  109. Db::name('AdminGroupAccess')->strict(false)->field(true)->insertAll($data); //再新增权限组
  110. if (!isset($param['thumb']) || $param['thumb'] == '') {
  111. $char = mb_substr($param['nickname'], 0, 1, 'utf-8');
  112. Db::name('Admin')->where('id', $param['id'])->update(['thumb' => $this->to_avatars($char)]);
  113. }
  114. //
  115. if($param['is_principal'] == 1){
  116. // $res = Db::name('Department')->where('id', $param['did'])->value('leader_id');
  117. // halt($res);
  118. $res = Db::name('Department')->where('id', $param['did'])->update(['leader_id' => $param['id']]);
  119. // $this->Department->where('id', $param['did'])->force()->save(['leader_id' => $param['id']]);
  120. // halt($res);
  121. }
  122. // 获取单位名称
  123. $unit_name = self::get_unitName($param['id']);
  124. $data = [
  125. 'unit_name' => $unit_name,
  126. 'user_type' => Db::name('Department')->where('id', $unit_name)->value('type'),
  127. 'admin_group_id' => $param['admin_group_id'],
  128. ];
  129. // unset($data['group_id']);
  130. // halt($data);
  131. $res = Db::name('admin')->where('id', $param['id'])->data($data)->update();
  132. // halt($res);
  133. add_log('edit', $param['id'], $param);
  134. //清除菜单\权限缓存
  135. clear_cache('adminMenu');
  136. clear_cache('adminRules');
  137. // 提交事务
  138. Db::commit();
  139. } catch (\Exception $e) {
  140. // 回滚事务
  141. Db::rollback();
  142. return to_assign(1, '提交失败:' . $e->getMessage());
  143. }
  144. } else { //新增账号
  145. // halt($param);
  146. try {
  147. validate(AdminCheck::class)->scene('add')->check($param);
  148. } catch (ValidateException $e) {
  149. // 验证失败 输出错误信息
  150. return to_assign(1, $e->getError());
  151. }
  152. $param['salt'] = set_salt(20);
  153. $param['pwd'] = set_password($param['pwd'], $param['salt']);
  154. // 启动事务
  155. Db::startTrans();
  156. try {
  157. foreach ($param['group_id'] as $k => $v) {
  158. $param['admin_group_id'] = $v;
  159. }
  160. // halt($param);
  161. $uid = Db::name('Admin')->strict(false)->field(true)->insertGetId($param);
  162. unset($param['admin_group_id']);
  163. if($param['is_principal'] == 1){
  164. Db::name('department')->where('id', $param['did'])->data(['leader_id' => $uid])->update();
  165. }
  166. // halt($uid);
  167. foreach ($param['group_id'] as $k => $v) {
  168. //为了系统安全,只有系统所有者才可创建id为1的管理员分组
  169. if ($v == 1 and get_login_admin('id') !== 1) {
  170. throw new ValidateException("你没有权限创建系统所有者", 1);
  171. }
  172. $data[$k] = [
  173. 'uid' => $uid,
  174. 'group_id' => $v,
  175. ];
  176. }
  177. Db::name('AdminGroupAccess')->strict(false)->field(true)->insertAll($data);
  178. if (!isset($param['thumb']) || $param['thumb'] == '') {
  179. $char = mb_substr($param['nickname'], 0, 1, 'utf-8');
  180. Db::name('Admin')->where('id', $uid)->update(['thumb' => $this->to_avatars($char)]);
  181. }
  182. // 获取单位名称
  183. $unit_name = self::get_unitName($uid);
  184. $data = [
  185. 'unit_name' => $unit_name,
  186. 'user_type' => Db::name('Department')->where('id', $unit_name)->value('type'),
  187. ];
  188. // halt($data);
  189. Db::name('admin')->where('id', $uid)->data($data)->update();
  190. add_log('add', $uid, $param);
  191. // 提交事务
  192. Db::commit();
  193. } catch (\Exception $e) {
  194. // 回滚事务
  195. Db::rollback();
  196. return to_assign(1, '提交失败:' . $e->getMessage());
  197. }
  198. }
  199. return to_assign(0,"操作成功");
  200. }else{
  201. $id = empty(get_params('id')) ? 0 : get_params('id');
  202. // dump($id);
  203. $permission = Db::name('admin')->where('id', get_login_admin('id'))->value('permission');
  204. $unit_name = Db::name('admin')->where('id', get_login_admin('id'))->value('unit_name');
  205. $group_id = Db::name('AdminGroupAccess')->where('uid', get_login_admin('id'))->value('group_id');
  206. $where_d = array();
  207. $where_p = array();
  208. $where_g = array();
  209. if($permission == 0){
  210. $where_d[] = ['unit_name', '=', $unit_name];
  211. $where_p[] = ['did', '=', $unit_name];
  212. $where_g[] = [
  213. ['unit_name', '=', $unit_name],
  214. ];
  215. }
  216. $department = Db::name('Department')
  217. ->where('status', '>=', 0)
  218. ->where($where_d)
  219. ->select()
  220. ->toArray();
  221. // dump($department);
  222. $department = set_recursion($department);
  223. // dump($department);
  224. $position = Db::name('Position')
  225. ->where('status', '>=', 0)
  226. ->where($where_p)
  227. ->order('create_time asc')
  228. ->select()
  229. ->toArray();
  230. foreach($position as $key => $value){
  231. $dep = Db::name('Department')->where('id', $value['did'])->value('title');
  232. $position[$key]['did_title'] = $dep;
  233. }
  234. $group = Db::name('AdminGroup')
  235. ->where($where_g)
  236. ->select()->toarray();
  237. if($permission == 1){
  238. $group = Db::name('AdminGroup')
  239. ->where('unit_name', '=', $unit_name)
  240. ->select()->toarray();
  241. // dump($group);
  242. }
  243. $group_mine = Db::name('AdminGroup')->where('id', $group_id)->select()->toArray();
  244. // dump($permission);
  245. if(get_login_admin('user_type') == -1){
  246. unset($group[0]); //移除超管权限组
  247. }
  248. $group = array_merge($group_mine, $group);
  249. if ($id > 0) {
  250. $admin = get_admin(get_params('id'));
  251. // dump($admin);
  252. // $did = get_login_admin('did');
  253. $leader_id = Db::name('Department')->where('id', $admin['did'])->value('leader_id');
  254. // dump($leader_id);
  255. if($leader_id == $id){
  256. $is_principal = 1;
  257. }else{
  258. $is_principal = 0;
  259. }
  260. View::assign('is_principal', $is_principal);
  261. View::assign('admin', $admin);
  262. }
  263. // dump($group);
  264. // dump($department);
  265. View::assign('permission', $permission);
  266. View::assign('department', $department);
  267. View::assign('position', $position);
  268. View::assign('group', $group);
  269. View::assign('id', $id);
  270. return view();
  271. }
  272. }
  273. public function to_avatars($char)
  274. {
  275. $defaultData = array('A', 'B', 'C', 'D', 'E', 'F', 'G', 'H', 'I', 'J', 'K', 'L', 'M', 'N',
  276. 'O', 'P', 'Q', 'R', 'S', 'T', 'U', 'V', 'W', 'S', 'Y', 'Z',
  277. '0', '1', '2', '3', '4', '5', '6', '7', '8', '9',
  278. '零', '壹', '贰', '叁', '肆', '伍', '陆', '柒', '捌', '玖', '拾',
  279. '一', '二', '三', '四', '五', '六', '七', '八', '九', '十');
  280. if (isset($char)) {
  281. $Char = $char;
  282. } else {
  283. $Char = $defaultData[mt_rand(0, count($defaultData) - 1)];
  284. }
  285. $OutputSize = min(512, empty($_GET['size']) ? 36 : intval($_GET['size']));
  286. $Avatar = new MDAvatars($Char, 256, 1);
  287. $avatar_name = '/avatars/avatar_256_' . set_salt(10) . time() . '.png';
  288. $path = get_config('filesystem.disks.public.url') . $avatar_name;
  289. $res = $Avatar->Save('.' . $path, 256);
  290. $Avatar->Free();
  291. /*
  292. if ($res) {
  293. //写入到附件表
  294. $data = [];
  295. $data['filepath'] = $path;
  296. $data['name'] = $Char;
  297. $data['mimetype'] = 'image/png';
  298. $data['fileext'] = 'png';
  299. $data['filesize'] = 0;
  300. $data['filename'] = $avatar_name;
  301. $data['sha1'] = '';
  302. $data['md5'] = '';
  303. $data['module'] = \think\facade\App::initialize()->http->getName();
  304. $data['action'] = app('request')->action();
  305. $data['uploadip'] = app('request')->ip();
  306. $data['create_time'] = time();
  307. $data['user_id'] = get_login_admin('id') ? get_login_admin('id') : 0;
  308. if ($data['module'] = 'admin') {
  309. //通过后台上传的文件直接审核通过
  310. $data['status'] = 1;
  311. $data['admin_id'] = $data['user_id'];
  312. $data['audit_time'] = time();
  313. }
  314. $data['use'] = 'avatar'; //附件用处
  315. $fid = Db::name('file')->insertGetId($data);
  316. return $fid;
  317. }
  318. */
  319. return $path;
  320. }
  321. //查看
  322. public function view()
  323. {
  324. $id = get_params('id');
  325. $rule = get_admin_rule();
  326. $user_groups = Db::name('AdminGroupAccess')
  327. ->alias('a')
  328. ->join("AdminGroup g", "a.group_id=g.id", 'LEFT')
  329. ->where("a.uid='{$id}' and g.status='1'")
  330. ->select()
  331. ->toArray();
  332. $groups = $user_groups ?: [];
  333. $rules = [];
  334. foreach ($groups as $g) {
  335. $rules = array_merge($rules, explode(',', trim($g['rules'], ',')));
  336. }
  337. $rules = array_unique($rules);
  338. $role_rule = create_tree_list(0, $rule, $rules);
  339. $role_rule = $this->Role->remove_checked_false($role_rule);
  340. $department = get_department();
  341. // dump($department);
  342. $position = Db::name('Position')->where('status', '>=', 0)->order('create_time asc')->select();
  343. View::assign('department', $department);
  344. View::assign('position', $position);
  345. View::assign('role_rule', $role_rule);
  346. View::assign('admin', get_admin($id));
  347. add_log('view', get_params('id'));
  348. return view('', ['admin' => get_admin(get_params('id'))]);
  349. }
  350. //删除
  351. public function delete()
  352. {
  353. $id = get_params("id");
  354. if($id == 1){
  355. return to_assign(0, "超级管理员,不能删除");
  356. }
  357. $data['status'] = '-1';
  358. $data['id'] = $id;
  359. $data['update_time'] = time();
  360. if (Db::name('Admin')->update($data) !== false) {
  361. add_log('delete', $id);
  362. return to_assign(0, "删除管理员成功");
  363. } else {
  364. return to_assign(1, "删除失败");
  365. }
  366. }
  367. //管理员操作日志
  368. public function log()
  369. {
  370. if (request()->isAjax()) {
  371. $param = get_params();
  372. $where = array();
  373. if (!empty($param['keywords'])) {
  374. $where[] = ['nickname|rule_menu|param_id', 'like', '%' . $param['keywords'] . '%'];
  375. }
  376. if (!empty($param['title_cate'])) {
  377. $where['title'] = $param['title_cate'];
  378. }
  379. if (!empty($param['rule_menu'])) {
  380. $where['rule_menu'] = $param['rule_menu'];
  381. }
  382. $rows = empty($param['limit']) ? get_config('app.page_size') : $param['limit'];
  383. $content = DB::name('AdminLog')
  384. ->field("id,uid,nickname,title,content,rule_menu,ip,param_id,param,FROM_UNIXTIME(create_time,'%Y-%m-%d %H:%i:%s') create_time")
  385. ->order('create_time desc')
  386. ->where($where)
  387. ->paginate($rows, false, ['query' => $param]);
  388. $content->toArray();
  389. foreach ($content as $k => $v) {
  390. $data = $v;
  391. $param_array = json_decode($v['param'], true);
  392. if(is_array($param_array)){
  393. $param_value = '';
  394. foreach ($param_array as $key => $value) {
  395. if (is_array($value)) {
  396. $value = implode(',', $value);
  397. }
  398. $param_value .= $key . ':' . $value . '&nbsp;&nbsp;|&nbsp;&nbsp;';
  399. }
  400. $data['param'] = $param_value;
  401. }
  402. else{
  403. $data['param'] = $param_array;
  404. }
  405. $content->offsetSet($k, $data);
  406. }
  407. return table_assign(0, '', $content);
  408. } else {
  409. return view();
  410. }
  411. }
  412. public function get_unitName($id){
  413. $did = Db::name('Admin')->where('id', $id)->value('did');
  414. $pid = $did;
  415. while($pid != 0){
  416. $value = Db::name('department')->where('id', $pid)->column('id,pid,title')[0];
  417. $id = $value['id'];
  418. $pid = $value['pid'];
  419. $title = $value['title'];
  420. }
  421. // halt($value);
  422. return $id;
  423. }
  424. }