UserController.php 8.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269
  1. <?php
  2. namespace App\Http\Controllers\API;
  3. use App\Http\Controllers\Controller;
  4. use App\Http\Requests\API\User\AdminUpdateRequest;
  5. use App\Http\Requests\API\User\BatchCreateRequest;
  6. use App\Http\Requests\API\User\CreateCompanyUserRequest;
  7. use App\Http\Requests\API\User\CreateRequest;
  8. use App\Http\Requests\API\User\UpdateRequest;
  9. use App\Http\Resources\API\UserInfoResource;
  10. use App\Http\Resources\API\UserSimpleResource;
  11. use App\Models\Department;
  12. use App\Models\Enums\RequirementStatus;
  13. use App\Models\Menu;
  14. use App\Models\Permission;
  15. use App\Models\Role;
  16. use App\Models\User;
  17. use Illuminate\Contracts\Encryption\DecryptException;
  18. use Illuminate\Http\Request;
  19. use Illuminate\Support\Facades\Auth;
  20. use Illuminate\Support\Facades\Cache;
  21. use Illuminate\Support\Facades\Crypt;
  22. use Illuminate\Support\Facades\DB;
  23. use Illuminate\Support\Facades\Hash;
  24. use function Laravel\Prompts\password;
  25. use function Nette\Utils\isEmpty;
  26. class UserController extends Controller
  27. {
  28. public function details()
  29. {
  30. $user = Auth::user();
  31. $menus = Menu::query()->where("group", \request("group", "web"))
  32. ->get();
  33. // ->filter(fn(Menu $menu) => Auth::user()->can($menu->permission));
  34. $userPerminssion=$user->role->permissions->pluck('name')->toArray();
  35. $flattenedPaths = [];
  36. foreach ($menus as $index=> $menu) {
  37. if(in_array($menu->permission,$userPerminssion)){
  38. $individualPaths = explode(',', $menu->path);
  39. $flattenedPaths = array_merge($flattenedPaths, $individualPaths);
  40. }
  41. }
  42. $userHasMenu=Menu::query()->whereIn('id',$flattenedPaths)->pluck('name')->toArray();
  43. $user->menus = $userHasMenu;
  44. return new UserInfoResource($user);
  45. }
  46. public function assignRole(Request $request, string $id)
  47. {
  48. $user = User::query()->findOrFail($id);
  49. $roleName = $request->get('role_name');
  50. if ($roleName) {
  51. $role = Role::query()->where("guard_name", "api")->where('name', $roleName)->firstOrFail();
  52. $user->role_id = $role->id;
  53. $user->save();
  54. }
  55. $roles = $roleName ? [$roleName] : [];
  56. $user->syncRoles($roles);
  57. return $this->noContent();
  58. }
  59. public function index(Request $request){
  60. $pageSize=$request->get('page_size') ?? 10;
  61. $sort=$request->input('sort','desc');
  62. //超管能看到所有用户
  63. if(Auth::user()->super_admin){
  64. $user = User::query()->filter($request->all())->with(['department'])->orderBy('created_at',$sort)->paginate($pageSize);
  65. return UserSimpleResource::collection($user);
  66. }
  67. //普通管理员能看到自己公司的用户
  68. $user=User::query()
  69. ->where('company_id',Auth::user()->company_id)
  70. ->filter($request->all())->with(['department'])->orderBy('created_at',$sort)->paginate($pageSize);
  71. return UserSimpleResource::collection($user);
  72. }
  73. public function publicSearch(Request $request){
  74. $pageSize=$request->get('page_size') ?? 10;
  75. $sort=$request->input('sort','desc');
  76. $user=User::query()
  77. ->where('company_id',Auth::user()->company_id)
  78. ->filter($request->all())->orderBy('created_at',$sort)->paginate($pageSize);
  79. return UserSimpleResource::collection($user);
  80. }
  81. /**
  82. * add a new User
  83. * @return \Illuminate\Http\Response
  84. */
  85. public function store(CreateRequest $request){
  86. $password = Hash::make($request->password);
  87. $userRequest=$request->all();
  88. $userRequest['password']=$password;
  89. $user=User::create([
  90. ...$userRequest,
  91. 'created_by' => Auth::id(),
  92. ]);
  93. // TODO:发送邮箱给目标用户
  94. $roleId = $request->get('role_id');
  95. $role = Role::query()->findOrFail($roleId);
  96. $user->syncRoles($role);
  97. return $this->created();
  98. }
  99. /**
  100. * batchCreate User,为ditto时参考上一条
  101. * @return \Illuminate\Http\Response
  102. */
  103. public function batchStore(BatchCreateRequest $request){
  104. $userData = $request->users;
  105. DB::transaction(function () use ($userData) {
  106. foreach ($userData as $k => $data) {
  107. $user = new User();
  108. if ($k != 0) {
  109. // $userData[$k]["department_id"] = $userData[$k]["department_id"] == 'ditto' ? $userData[$k - 1]["department_id"] : $userData[$k]["department_id"];
  110. $userData[$k]["role_id"] = $userData[$k]["role_id"] == 'ditto' ? $userData[$k - 1]["role_id"] : $userData[$k]["role_id"];
  111. }
  112. $userData[$k]['password'] = Hash::make($userData[$k]['password']);
  113. $role = Role::query()->findOrFail($userData[$k]["role_id"]);
  114. $user->syncRoles($role);
  115. $user->fill([
  116. ...$userData[$k],
  117. 'created_by' => Auth::id(),
  118. ]);
  119. // TODO:发送邮箱给目标用户
  120. $user->save();
  121. }
  122. });
  123. // TODO:发送邮箱给目标用户
  124. return $this->created();
  125. }
  126. /**
  127. * enable or ban users 启用或禁用用户
  128. * @param Request $request
  129. * @return \Illuminate\Http\Response
  130. */
  131. public function status(Request $request,string $status){
  132. //只能删除自己公司的;超管除外
  133. if (Auth::user()->super_admin){
  134. User::whereIn('id', $request->user_id)->update(['status' => $status]);
  135. }
  136. else{
  137. User::whereIn('id', $request->user_id)->where('company_id',Auth::user()->company_id)->update(['status' => $status]);
  138. }
  139. return $this->created();
  140. }
  141. public function destroy(string $id)
  142. {
  143. $user = User::query()->findOrFail($id);
  144. $user->delete();
  145. return $this->noContent();
  146. }
  147. public function show(string $id)
  148. {
  149. $user = User::query()->findOrFail($id);
  150. return new UserInfoResource($user);
  151. }
  152. public function update(UpdateRequest $request,string $id)
  153. {
  154. $user = User::findOrFail($id);
  155. $newPassword=null;
  156. // 如果用户是超级管理员或具有相应权限
  157. if (Auth::user()->super_admin || Auth::user()->can('user.assign-role')) {
  158. $user->fill([
  159. ...$request->except(['username']),
  160. 'password' => $request->password ? Hash::make($request->password) : $user->password,
  161. ]);
  162. $roleId = $request->get('role_id');
  163. if ($roleId) {
  164. $role = Role::findOrFail($roleId);
  165. $user->syncRoles([$role]);
  166. }
  167. } else {
  168. // 如果用户不是超级管理员且没有编辑角色的权限
  169. $user->fill([
  170. ...$request->except(['role_id', 'department_id', 'company_id']),
  171. 'password' => $request->password ? Hash::make($request->password) : $user->password,
  172. ]);
  173. }
  174. $user->save();
  175. return $this->noContent();
  176. }
  177. // public function byDepartment(Request $request){
  178. // $departmentIds = $request->get("department", []);
  179. //
  180. // $emptyResponse = $this->success([
  181. // 'data' => [],
  182. // ]);
  183. //
  184. // if (! $departmentIds) {
  185. // return $emptyResponse;
  186. // }
  187. //
  188. // $users = User::query()->filter($request->all())->where('company_id',Auth::user()->company_id)->whereIn("department_id",$departmentIds)->get();
  189. //
  190. // return UserSimpleResource::collection($users);
  191. //
  192. // }
  193. // /**
  194. // * @param CreateRequest $request
  195. // * @return \Illuminate\Http\Response
  196. // * 修改个人信息
  197. // */
  198. // public function updateInfo(UpdateRequest $request)
  199. // {
  200. // $user = User::findOrFail(Auth::user()->id);
  201. // $user->fill([
  202. // ...$request->except(['username','role_id','department_id','company_id'])
  203. // ]);
  204. // $user->save();
  205. // return $this->noContent();
  206. // }
  207. //
  208. // /**
  209. // * @param AdminUpdateRequest $request 修改主体
  210. // * @param string $id 用户id
  211. // * @return \Illuminate\Http\Response
  212. // * 超管修改用户的信息
  213. // */
  214. // public function updateUserInfo(AdminUpdateRequest $request, string $id)
  215. // {
  216. // $user = User::findOrFail($id);
  217. // $user->fill([
  218. // ...$request->all()
  219. // ]);
  220. // $user->save();
  221. // return $this->noContent();
  222. //
  223. // }
  224. // /**
  225. // * 注册用户
  226. // * @return \Illuminate\Http\Response
  227. // */
  228. // public function registerCompanyUser(CreateCompanyUserRequest $request){
  229. // $password = Hash::make($request->password);
  230. // $userRequest=$request->all();
  231. // $userRequest['password']=$password;
  232. // User::create([
  233. // ...$userRequest,
  234. // 'created_by' => Auth::id(),
  235. // ]);
  236. // return $this->created();
  237. // }
  238. }