Skip to content

Add data permission condition for filter data #648

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 1 commit into from
May 31, 2025
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 5 additions & 2 deletions backend/app/admin/model/role.py
Original file line number Diff line number Diff line change
Expand Up @@ -4,9 +4,9 @@

from typing import TYPE_CHECKING

from sqlalchemy import String
from sqlalchemy import Boolean, String
from sqlalchemy.dialects.mysql import LONGTEXT
from sqlalchemy.dialects.postgresql import TEXT
from sqlalchemy.dialects.postgresql import INTEGER, TEXT
from sqlalchemy.orm import Mapped, mapped_column, relationship

from backend.app.admin.model.m2m import sys_role_data_scope, sys_role_menu, sys_user_role
Expand All @@ -24,6 +24,9 @@ class Role(Base):
id: Mapped[id_key] = mapped_column(init=False)
name: Mapped[str] = mapped_column(String(20), unique=True, comment='角色名称')
status: Mapped[int] = mapped_column(default=1, comment='角色状态(0停用 1正常)')
is_filter_scopes: Mapped[bool] = mapped_column(
Boolean().with_variant(INTEGER, 'postgresql'), default=False, comment='过滤数据权限(0否 1是)'
)
remark: Mapped[str | None] = mapped_column(
LONGTEXT().with_variant(TEXT, 'postgresql'), default=None, comment='备注'
)
Expand Down
1 change: 1 addition & 0 deletions backend/app/admin/schema/role.py
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,7 @@ class RoleSchemaBase(SchemaBase):

name: str = Field(description='角色名称')
status: StatusType = Field(StatusType.enable, description='状态')
is_filter_scopes: bool = Field(False, description='过滤数据权限')
remark: str | None = Field(None, description='备注')


Expand Down
5 changes: 5 additions & 0 deletions backend/common/security/permission.py
Original file line number Diff line number Diff line change
Expand Up @@ -56,6 +56,11 @@ async def filter_data_permission(db: AsyncSession, request: Request) -> ColumnEl
:param request: FastAPI 请求对象
:return:
"""
# 是否过滤数据权限
for role in request.user.roles:
if role.is_filter_scopes:
return or_(1 == 1)

# 获取数据范围
unique_data_scopes = {}
for role in request.user.roles:
Expand Down