"""集团后台管理员俱乐部上下文。""" from jituan.constants import ( ADMIN_ROLE_LABELS, DATA_SCOPE_ALL, DATA_SCOPE_SINGLE, CLUB_ID_DEFAULT, SUPER_ADMIN_PHONES, ) from jituan.models import AdminAssignment, Club GROUP_MANAGE_ROLES = frozenset({ 'GROUP_OWNER', 'GROUP_SUPER_ADMIN', }) def build_admin_club_context(user): """ 根据 admin_assignment + 超管推断后台登录后的俱乐部上下文。 返回 dict 供前端存储与请求头使用。 """ yonghuid = user.UserUID is_super = is_system_super_admin(user) assignments = list( AdminAssignment.query.filter(yonghuid=yonghuid, status=1).order_by('-is_primary', 'club_id') ) clubs_qs = Club.query.filter(status=1).order_by('sort_order', 'club_id') all_clubs = [ {'club_id': c.club_id, 'name': c.name} for c in clubs_qs ] # 系统超管:始终集团视角 + 全部俱乐部(不受任职记录限制) if is_super: role_code = 'GROUP_SUPER_ADMIN' if assignments: primary = next((a for a in assignments if a.is_primary), assignments[0]) role_code = primary.role_code or role_code return _pack( scope=DATA_SCOPE_ALL, club_id=CLUB_ID_DEFAULT, is_group_admin=True, assignments=assignments, clubs=all_clubs, can_switch_club=True, role_code=role_code, role_name=ADMIN_ROLE_LABELS.get(role_code, role_code), ) if not assignments: return _pack( scope=DATA_SCOPE_SINGLE, club_id=CLUB_ID_DEFAULT, is_group_admin=False, assignments=[], clubs=all_clubs, can_switch_club=False, role_code='CLUB_ADMIN', role_name='子公司客服(默认)', ) primary = next((a for a in assignments if a.is_primary), assignments[0]) has_group = any( a.club_id is None or a.data_scope == DATA_SCOPE_ALL for a in assignments ) allowed_club_ids = {a.club_id for a in assignments if a.club_id} if has_group: scope = DATA_SCOPE_ALL club_id = CLUB_ID_DEFAULT else: scope = DATA_SCOPE_SINGLE club_id = primary.club_id or CLUB_ID_DEFAULT visible_clubs = all_clubs if has_group else [ c for c in all_clubs if c['club_id'] in allowed_club_ids ] role_code = primary.role_code or 'CLUB_ADMIN' return _pack( scope=scope, club_id=club_id, is_group_admin=has_group, assignments=assignments, clubs=visible_clubs, can_switch_club=has_group or len(visible_clubs) > 1, role_code=role_code, role_name=ADMIN_ROLE_LABELS.get(role_code, role_code), ) def is_system_super_admin(user): """系统级超管(Django 超管 / admin 账号 / 白名单手机号),非俱乐部 000001 角色。""" return ( bool(user.IsSuperuser) or user.UserType == 'admin' or getattr(user, 'Phone', '') in SUPER_ADMIN_PHONES ) def is_kefu_backend_account(user): """可登录客服后台:超管 / UserType=kefu / KefuProfile / 旧表 user_role 有绑定。""" if is_system_super_admin(user): return True if getattr(user, 'UserType', '') == 'kefu': return True try: kefu = user.KefuProfile if kefu.zhuangtai == 1: return True except Exception: pass from backend.utils import has_legacy_backend_binding return has_legacy_backend_binding(user) def can_manage_admin_assignments(user, permissions=None): """是否可维护数据范围任职、俱乐部密钥等集团级配置(不含俱乐部 000001)。""" if is_system_super_admin(user): return True ctx = build_admin_club_context(user) if ctx.get('is_group_admin') and ctx.get('role_code') in GROUP_MANAGE_ROLES: return True return any( a.role_code in GROUP_MANAGE_ROLES and (a.club_id is None or a.data_scope == DATA_SCOPE_ALL) for a in AdminAssignment.query.filter(yonghuid=user.UserUID, status=1) ) def _pack(scope, club_id, is_group_admin, assignments, clubs, can_switch_club, role_code, role_name): return { 'scope': scope, 'club_id': club_id, 'is_group_admin': is_group_admin, 'role_code': role_code, 'role_name': role_name, 'perm_source': 'gvsdsdk', 'perm_note': ( '【功能权限】在「角色管理」绑 gvsdsdk 角色(如 caiwu、dingdan、000001);' '【数据范围】在「数据范围配置」维护任职(能看/管哪个俱乐部)。两套独立。' ), 'assignments': [ { 'club_id': a.club_id, 'role_code': a.role_code, 'role_name': ADMIN_ROLE_LABELS.get(a.role_code, a.role_code), 'data_scope': a.data_scope, 'is_primary': a.is_primary, } for a in assignments ], 'clubs': clubs, 'can_switch_club': can_switch_club, }