fix: 多俱乐部下单 openid;集团超管可切俱乐部

This commit is contained in:
XingQue
2026-06-24 20:45:40 +08:00
parent 08fc8f50f3
commit a693e35177
4 changed files with 81 additions and 25 deletions

View File

@@ -8,6 +8,12 @@ from jituan.constants import (
)
from jituan.models import AdminAssignment, Club
GROUP_MANAGE_ROLES = frozenset({
'GROUP_OWNER',
'GROUP_SUPER_ADMIN',
})
def build_admin_club_context(user):
"""
根据 admin_assignment + 超管推断后台登录后的俱乐部上下文。
@@ -30,16 +36,21 @@ def build_admin_club_context(user):
for c in clubs_qs
]
if is_super and not assignments:
# 系统超管:始终集团视角 + 全部俱乐部(不受任职记录限制)
if is_super:
role_code = 'GROUP_SUPER_ADMIN'
if assignments:
primary = next((a for a in assignments if a.is_primary), assignments[0])
role_code = primary.role_code or role_code
return _pack(
scope=DATA_SCOPE_ALL,
club_id=CLUB_ID_DEFAULT,
is_group_admin=True,
assignments=[],
assignments=assignments,
clubs=all_clubs,
can_switch_club=True,
role_code='GROUP_SUPER_ADMIN',
role_name=ADMIN_ROLE_LABELS['GROUP_SUPER_ADMIN'],
role_code=role_code,
role_name=ADMIN_ROLE_LABELS.get(role_code, role_code),
)
if not assignments:
@@ -55,7 +66,10 @@ def build_admin_club_context(user):
)
primary = next((a for a in assignments if a.is_primary), assignments[0])
has_group = any(a.club_id is None or a.data_scope == DATA_SCOPE_ALL for a in assignments)
has_group = any(
a.club_id is None or a.data_scope == DATA_SCOPE_ALL
for a in assignments
)
allowed_club_ids = {a.club_id for a in assignments if a.club_id}
if has_group:
@@ -82,6 +96,26 @@ def build_admin_club_context(user):
)
def can_manage_admin_assignments(user, permissions=None):
"""是否可维护数据范围任职(超管 / 000001 / 集团超管任职)。"""
permissions = permissions or []
is_super = (
bool(user.IsSuperuser)
or user.UserType == 'admin'
or getattr(user, 'Phone', '') in SUPER_ADMIN_PHONES
)
if is_super or '000001' in permissions:
return True
ctx = build_admin_club_context(user)
if ctx.get('is_group_admin') and ctx.get('role_code') in GROUP_MANAGE_ROLES:
return True
return any(
a.role_code in GROUP_MANAGE_ROLES
and (a.club_id is None or a.data_scope == DATA_SCOPE_ALL)
for a in AdminAssignment.query.filter(yonghuid=user.UserUID, status=1)
)
def _pack(scope, club_id, is_group_admin, assignments, clubs, can_switch_club,
role_code, role_name):
return {
@@ -91,7 +125,10 @@ def _pack(scope, club_id, is_group_admin, assignments, clubs, can_switch_club,
'role_code': role_code,
'role_name': role_name,
'perm_source': 'gvsdsdk',
'perm_note': '功能菜单权限仍由 gvsdsdk UserRole→Permission 控制;本表仅管数据范围',
'perm_note': (
'【功能权限】在「角色管理」绑 gvsdsdk 角色(如 caiwu、dingdan、000001'
'【数据范围】在「数据范围配置」维护任职(能看/管哪个俱乐部)。两套独立。'
),
'assignments': [
{
'club_id': a.club_id,

View File

@@ -12,7 +12,7 @@ from rest_framework_simplejwt.tokens import RefreshToken
from jituan.constants import SUPER_ADMIN_PHONES, ADMIN_ROLE_LABELS, CLUB_ID_DEFAULT, DATA_SCOPE_ALL, DATA_SCOPE_SINGLE
from jituan.models import Club, AdminAssignment
from jituan.services.admin_context import build_admin_club_context
from jituan.services.admin_context import build_admin_club_context, can_manage_admin_assignments
from jituan.services.wechat_login import login_or_register_by_club
from jituan.services.caiwu_stats import build_caiwu_payload
from jituan.services.szxx_stats import build_szxx_payload
@@ -247,8 +247,8 @@ class ClubAdminAssignmentListView(APIView):
action = (request.data.get('action') or 'list').strip()
if action in ('create', 'update', 'delete'):
if not is_super or '000001' not in permissions:
return Response({'code': 403, 'msg': '仅超级管理员可维护任职数据'}, status=403)
if not can_manage_admin_assignments(user, permissions):
return Response({'code': 403, 'msg': '无权限维护任职数据(需超管或集团超管任职)'}, status=403)
if action == 'create':
yonghuid = (request.data.get('yonghuid') or '').strip()
@@ -328,11 +328,11 @@ class ClubAdminAssignmentListView(APIView):
'msg': 'ok',
'data': {
'list': self._list_rows(qs.to_list()),
'can_manage': is_super and '000001' in permissions,
'can_manage': can_manage_admin_assignments(user, permissions),
'perm_note': (
'【功能权限】在「角色管理」里给账号绑 gvsdsdk 角色perm_code 如 caiwu、002ab'
'【功能权限】在「角色管理」里给账号绑 gvsdsdk 角色perm_code 如 caiwu、002ab、000001'
'【数据范围】在本页维护 admin_assignment能看哪个俱乐部/集团汇总)。'
'两套独立,超管需有 000001 权限码'
'两套独立:集团高管需在本页配「集团全部」任职 + 角色管理里勾功能菜单'
),
'current_context': build_admin_club_context(user),
},