UserController.php 8.9 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275
  1. <?php
  2. namespace App\Http\Controllers\API;
  3. use App\Http\Controllers\Controller;
  4. use App\Http\Requests\API\User\AdminUpdateRequest;
  5. use App\Http\Requests\API\User\BatchCreateRequest;
  6. use App\Http\Requests\API\User\CreateCompanyUserRequest;
  7. use App\Http\Requests\API\User\CreateRequest;
  8. use App\Http\Requests\API\User\UpdateRequest;
  9. use App\Http\Resources\API\UserInfoResource;
  10. use App\Http\Resources\API\UserSimpleResource;
  11. use App\Models\Department;
  12. use App\Models\Enums\RequirementStatus;
  13. use App\Models\Menu;
  14. use App\Models\Permission;
  15. use App\Models\Role;
  16. use App\Models\User;
  17. use Illuminate\Contracts\Encryption\DecryptException;
  18. use Illuminate\Http\Request;
  19. use Illuminate\Support\Facades\Auth;
  20. use Illuminate\Support\Facades\Cache;
  21. use Illuminate\Support\Facades\Crypt;
  22. use Illuminate\Support\Facades\DB;
  23. use Illuminate\Support\Facades\Hash;
  24. use function Laravel\Prompts\password;
  25. use function Nette\Utils\isEmpty;
  26. class UserController extends Controller
  27. {
  28. public function details()
  29. {
  30. $user = Auth::user();
  31. $menus = Menu::query()->where("group", \request("group", "web"))
  32. ->get();
  33. // ->filter(fn(Menu $menu) => Auth::user()->can($menu->permission));
  34. $userPerminssion=$user->role->permissions->pluck('name')->toArray();
  35. $flattenedPaths = [];
  36. foreach ($menus as $index=> $menu) {
  37. if(in_array($menu->permission,$userPerminssion)){
  38. $individualPaths = explode(',', $menu->path);
  39. $flattenedPaths = array_merge($flattenedPaths, $individualPaths);
  40. }
  41. }
  42. $userHasMenu=Menu::query()->whereIn('id',$flattenedPaths)->pluck('name')->toArray();
  43. $user->menus = $userHasMenu;
  44. return new UserInfoResource($user);
  45. }
  46. public function assignRole(Request $request, string $id)
  47. {
  48. $user = User::query()->findOrFail($id);
  49. $roleName = $request->get('role_name');
  50. if ($roleName) {
  51. $role = Role::query()->where("guard_name", "api")->where('name', $roleName)->firstOrFail();
  52. $user->role_id = $role->id;
  53. $user->save();
  54. }
  55. $roles = $roleName ? [$roleName] : [];
  56. $user->syncRoles($roles);
  57. return $this->noContent();
  58. }
  59. public function index(Request $request){
  60. $pageSize=$request->get('page_size') ?? 10;
  61. $sort=$request->input('sort','desc');
  62. //超管能看到所有用户
  63. if(Auth::user()->super_admin){
  64. $user = User::query()->filter($request->all())->orderBy('created_at',$sort)->paginate($pageSize);
  65. return UserSimpleResource::collection($user);
  66. }
  67. //普通管理员能看到自己公司的用户
  68. $user=User::query()
  69. ->where('company_id',Auth::user()->company_id)
  70. ->filter($request->all())->orderBy('created_at',$sort)->paginate($pageSize);
  71. return UserSimpleResource::collection($user);
  72. }
  73. public function publicSearch(Request $request){
  74. $pageSize=$request->get('page_size') ?? 10;
  75. $sort=$request->input('sort','desc');
  76. $user=User::query()
  77. ->where('company_id',Auth::user()->company_id)
  78. ->filter($request->all())->orderBy('created_at',$sort)->paginate($pageSize);
  79. return UserSimpleResource::collection($user);
  80. }
  81. /**
  82. * add a new User
  83. * @return \Illuminate\Http\Response
  84. */
  85. public function store(CreateRequest $request){
  86. $password = Hash::make($request->password);
  87. $userRequest=$request->all();
  88. $userRequest['password']=$password;
  89. $user=User::create([
  90. ...$userRequest,
  91. 'created_by' => Auth::id(),
  92. ]);
  93. // TODO:发送邮箱给目标用户
  94. $roleId = $request->get('role_id');
  95. $role = Role::query()->findOrFail($roleId);
  96. $user->syncRoles($role);
  97. return $this->created();
  98. }
  99. /**
  100. * batchCreate User,为ditto时参考上一条
  101. * @return \Illuminate\Http\Response
  102. */
  103. public function batchStore(BatchCreateRequest $request){
  104. $userData = $request->users;
  105. DB::transaction(function () use ($userData) {
  106. foreach ($userData as $k => $data) {
  107. $user = new User();
  108. if ($k != 0) {
  109. // $userData[$k]["department_id"] = $userData[$k]["department_id"] == 'ditto' ? $userData[$k - 1]["department_id"] : $userData[$k]["department_id"];
  110. $userData[$k]["role_id"] = $userData[$k]["role_id"] == 'ditto' ? $userData[$k - 1]["role_id"] : $userData[$k]["role_id"];
  111. }
  112. $userData[$k]['password'] = Hash::make($userData[$k]['password']);
  113. $role = Role::query()->findOrFail($userData[$k]["role_id"]);
  114. $user->syncRoles($role);
  115. $user->fill([
  116. ...$userData[$k],
  117. 'created_by' => Auth::id(),
  118. ]);
  119. // TODO:发送邮箱给目标用户
  120. $user->save();
  121. }
  122. });
  123. // TODO:发送邮箱给目标用户
  124. return $this->created();
  125. }
  126. /**
  127. * enable or ban users 启用或禁用用户
  128. * @param Request $request
  129. * @return \Illuminate\Http\Response
  130. */
  131. public function status(Request $request,string $status){
  132. //只能删除自己公司的;超管除外
  133. if (Auth::user()->super_admin){
  134. User::whereIn('id', $request->user_id)->update(['status' => $status]);
  135. }
  136. else{
  137. User::whereIn('id', $request->user_id)->where('company_id',Auth::user()->company_id)->update(['status' => $status]);
  138. }
  139. return $this->created();
  140. }
  141. public function destroy(string $id)
  142. {
  143. $user = User::query()->findOrFail($id);
  144. $user->delete();
  145. return $this->noContent();
  146. }
  147. public function show(string $id)
  148. {
  149. $user = User::query()->findOrFail($id);
  150. return new UserInfoResource($user);
  151. }
  152. public function update(UpdateRequest $request,string $id)
  153. {
  154. $user = User::findOrFail($id);
  155. $newPassword=null;
  156. // 如果用户是超级管理员或具有相应权限
  157. if (Auth::user()->super_admin || Auth::user()->can('user.assign-role')) {
  158. $user->fill([
  159. ...$request->except(['username']),
  160. 'password' => $request->password ? Hash::make($request->password) : $user->password,
  161. ]);
  162. $roleId = $request->get('role_id');
  163. if ($roleId) {
  164. $role = Role::findOrFail($roleId);
  165. $user->syncRoles([$role]);
  166. }
  167. } else {
  168. // 如果用户不是超级管理员且没有编辑角色的权限
  169. $user->fill([
  170. ...$request->except(['role_id', 'department_id', 'company_id']),
  171. 'password' => $request->password ? Hash::make($request->password) : $user->password,
  172. ]);
  173. }
  174. $user->save();
  175. return $this->noContent();
  176. }
  177. public function auth4sToken(Request $request){
  178. $key=$request->get('key');
  179. $user=Cache::get($key);
  180. return $this->success([
  181. 'data'=>$user
  182. ]);
  183. }
  184. // public function byDepartment(Request $request){
  185. // $departmentIds = $request->get("department", []);
  186. //
  187. // $emptyResponse = $this->success([
  188. // 'data' => [],
  189. // ]);
  190. //
  191. // if (! $departmentIds) {
  192. // return $emptyResponse;
  193. // }
  194. //
  195. // $users = User::query()->filter($request->all())->where('company_id',Auth::user()->company_id)->whereIn("department_id",$departmentIds)->get();
  196. //
  197. // return UserSimpleResource::collection($users);
  198. //
  199. // }
  200. // /**
  201. // * @param CreateRequest $request
  202. // * @return \Illuminate\Http\Response
  203. // * 修改个人信息
  204. // */
  205. // public function updateInfo(UpdateRequest $request)
  206. // {
  207. // $user = User::findOrFail(Auth::user()->id);
  208. // $user->fill([
  209. // ...$request->except(['username','role_id','department_id','company_id'])
  210. // ]);
  211. // $user->save();
  212. // return $this->noContent();
  213. // }
  214. //
  215. // /**
  216. // * @param AdminUpdateRequest $request 修改主体
  217. // * @param string $id 用户id
  218. // * @return \Illuminate\Http\Response
  219. // * 超管修改用户的信息
  220. // */
  221. // public function updateUserInfo(AdminUpdateRequest $request, string $id)
  222. // {
  223. // $user = User::findOrFail($id);
  224. // $user->fill([
  225. // ...$request->all()
  226. // ]);
  227. // $user->save();
  228. // return $this->noContent();
  229. //
  230. // }
  231. // /**
  232. // * 注册用户
  233. // * @return \Illuminate\Http\Response
  234. // */
  235. // public function registerCompanyUser(CreateCompanyUserRequest $request){
  236. // $password = Hash::make($request->password);
  237. // $userRequest=$request->all();
  238. // $userRequest['password']=$password;
  239. // User::create([
  240. // ...$userRequest,
  241. // 'created_by' => Auth::id(),
  242. // ]);
  243. // return $this->created();
  244. // }
  245. }