Files
Django/jituan/services/admin_context.py

156 lines
4.9 KiB
Python
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
"""集团后台管理员俱乐部上下文。"""
from jituan.constants import (
ADMIN_ROLE_LABELS,
DATA_SCOPE_ALL,
DATA_SCOPE_SINGLE,
CLUB_ID_DEFAULT,
SUPER_ADMIN_PHONES,
)
from jituan.models import AdminAssignment, Club
GROUP_MANAGE_ROLES = frozenset({
'GROUP_OWNER',
'GROUP_SUPER_ADMIN',
})
def build_admin_club_context(user):
"""
根据 admin_assignment + 超管推断后台登录后的俱乐部上下文。
返回 dict 供前端存储与请求头使用。
"""
yonghuid = user.UserUID
is_super = is_system_super_admin(user)
assignments = list(
AdminAssignment.query.filter(yonghuid=yonghuid, status=1).order_by('-is_primary', 'club_id')
)
clubs_qs = Club.query.filter(status=1).order_by('sort_order', 'club_id')
all_clubs = [
{'club_id': c.club_id, 'name': c.name}
for c in clubs_qs
]
# 系统超管:始终集团视角 + 全部俱乐部(不受任职记录限制)
if is_super:
role_code = 'GROUP_SUPER_ADMIN'
if assignments:
primary = next((a for a in assignments if a.is_primary), assignments[0])
role_code = primary.role_code or role_code
return _pack(
scope=DATA_SCOPE_ALL,
club_id=CLUB_ID_DEFAULT,
is_group_admin=True,
assignments=assignments,
clubs=all_clubs,
can_switch_club=True,
role_code=role_code,
role_name=ADMIN_ROLE_LABELS.get(role_code, role_code),
)
if not assignments:
return _pack(
scope=DATA_SCOPE_SINGLE,
club_id=CLUB_ID_DEFAULT,
is_group_admin=False,
assignments=[],
clubs=all_clubs,
can_switch_club=False,
role_code='CLUB_ADMIN',
role_name='子公司客服(默认)',
)
primary = next((a for a in assignments if a.is_primary), assignments[0])
has_group = any(
a.club_id is None or a.data_scope == DATA_SCOPE_ALL
for a in assignments
)
allowed_club_ids = {a.club_id for a in assignments if a.club_id}
if has_group:
scope = DATA_SCOPE_ALL
club_id = CLUB_ID_DEFAULT
else:
scope = DATA_SCOPE_SINGLE
club_id = primary.club_id or CLUB_ID_DEFAULT
visible_clubs = all_clubs if has_group else [
c for c in all_clubs if c['club_id'] in allowed_club_ids
]
role_code = primary.role_code or 'CLUB_ADMIN'
return _pack(
scope=scope,
club_id=club_id,
is_group_admin=has_group,
assignments=assignments,
clubs=visible_clubs,
can_switch_club=has_group or len(visible_clubs) > 1,
role_code=role_code,
role_name=ADMIN_ROLE_LABELS.get(role_code, role_code),
)
def is_system_super_admin(user):
"""系统级超管Django 超管 / admin 账号 / 白名单手机号),非俱乐部 000001 角色。"""
return (
bool(user.IsSuperuser)
or user.UserType == 'admin'
or getattr(user, 'Phone', '') in SUPER_ADMIN_PHONES
)
def is_kefu_backend_account(user):
"""可登录客服后台:超管 / UserType=kefu / 有正常 KefuProfile。"""
if is_system_super_admin(user):
return True
if getattr(user, 'UserType', '') == 'kefu':
return True
try:
return user.KefuProfile.zhuangtai == 1
except Exception:
return False
def can_manage_admin_assignments(user, permissions=None):
"""是否可维护数据范围任职、俱乐部密钥等集团级配置(不含俱乐部 000001"""
if is_system_super_admin(user):
return True
ctx = build_admin_club_context(user)
if ctx.get('is_group_admin') and ctx.get('role_code') in GROUP_MANAGE_ROLES:
return True
return any(
a.role_code in GROUP_MANAGE_ROLES
and (a.club_id is None or a.data_scope == DATA_SCOPE_ALL)
for a in AdminAssignment.query.filter(yonghuid=user.UserUID, status=1)
)
def _pack(scope, club_id, is_group_admin, assignments, clubs, can_switch_club,
role_code, role_name):
return {
'scope': scope,
'club_id': club_id,
'is_group_admin': is_group_admin,
'role_code': role_code,
'role_name': role_name,
'perm_source': 'gvsdsdk',
'perm_note': (
'【功能权限】在「角色管理」绑 gvsdsdk 角色(如 caiwu、dingdan、000001'
'【数据范围】在「数据范围配置」维护任职(能看/管哪个俱乐部)。两套独立。'
),
'assignments': [
{
'club_id': a.club_id,
'role_code': a.role_code,
'role_name': ADMIN_ROLE_LABELS.get(a.role_code, a.role_code),
'data_scope': a.data_scope,
'is_primary': a.is_primary,
}
for a in assignments
],
'clubs': clubs,
'can_switch_club': can_switch_club,
}