SNAPSHOT W7 已部署稳定态 — 凯迪ERP+OA一体化平台 (MET 73.3%)

恢复点(restore point)。别人改崩后可 git reset --hard 回到此提交。

== 此快照内容 ==
- 后端 oa-backend: 734 控制器 / 711 实体 (Spring Boot 3.2.5 + SQLite, 端口8091)
- 前端 modern-ui/app: Vue3+Vite, 约700页 (构建产物已在 oa-backend/src/main/resources/static)
- 数据库 oa-backend/data/oa.db: 含全部演示数据 (强制入库, 6.6MB)
- 交接文档 go.md + go-code-reference/endpoints/entities/database.md
- 多代理建设脚本 .claude/wf-*.js

== 状态 ==
- 对 凯迪科技ERP_20260507.xlsx 合规 MET ~73.3% (PARTIAL 75: 34可建+6种子/bug+35外部硬天花板)
- 安全: 5轮红队+5轮复检, default-deny分级鉴权, 连续零可利用
- W3~W7 累计补完436缺口; W8末轮(40缺口)为半成品(源码树可编译但未集成)
- 运行: cd oa-backend; java -jar build/libs/oa-backend-0.1.0.jar --server.port=8091; admin/123456

== 排除(gitignore, 可再生) ==
node_modules / oa-backend/build / .jdks / *.log / Backup-ERP-* / 弃用的OFBiz核心(只保留modern-ui)
完整文件夹备份见同目录 Backup-ERP-20260615-191517/ (含上述全部, 仅缺 node_modules)

时间戳: 20260615-191517

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
Qiufeng
2026-06-15 19:19:15 +08:00
co-authored by Claude Opus 4.8
commit 5e51dc3f56
10584 changed files with 2501339 additions and 0 deletions
@@ -0,0 +1,117 @@
package com.kaidi.oa.web;
import com.kaidi.oa.common.ApiException;
import com.kaidi.oa.common.ApiResp;
import com.kaidi.oa.common.HtmlSanitizer;
import com.kaidi.oa.common.NotFoundException;
import com.kaidi.oa.domain.Announcement;
import com.kaidi.oa.repository.AnnouncementRepository;
import org.springframework.web.bind.annotation.DeleteMapping;
import org.springframework.web.bind.annotation.GetMapping;
import org.springframework.web.bind.annotation.PathVariable;
import org.springframework.web.bind.annotation.PostMapping;
import org.springframework.web.bind.annotation.PutMapping;
import org.springframework.web.bind.annotation.RequestBody;
import org.springframework.web.bind.annotation.RequestMapping;
import org.springframework.web.bind.annotation.RequestParam;
import org.springframework.web.bind.annotation.RestController;
import java.time.Instant;
import java.util.List;
/** News / announcements. category is one of 新闻 / 公告. */
@RestController
@RequestMapping("/api/oa/announcements")
public class AnnouncementController {
private final AnnouncementRepository announcementRepo;
public AnnouncementController(AnnouncementRepository announcementRepo) {
this.announcementRepo = announcementRepo;
}
@GetMapping
public ApiResp<List<Announcement>> list(
@RequestParam(required = false) String category,
@RequestParam(defaultValue = "0") int pageNo,
@RequestParam(defaultValue = "200") int pageSize) {
List<Announcement> list = (category == null || category.isBlank())
? announcementRepo.findAllByOrderByTopDescPublishedAtDesc()
: announcementRepo.findByCategoryOrderByTopDescPublishedAtDesc(category);
return ApiResp.ok(page(list, pageNo, pageSize));
}
/** 内存切片:pageNo 从 0 起;pageSize<=0 取默认 200、超过 500 截为 500,避免全表载入。 */
private static final int DEFAULT_PAGE_SIZE = 200;
private static final int MAX_PAGE_SIZE = 500;
private static <T> List<T> page(List<T> list, int pageNo, int pageSize) {
if (pageSize <= 0) {
pageSize = DEFAULT_PAGE_SIZE;
} else if (pageSize > MAX_PAGE_SIZE) {
pageSize = MAX_PAGE_SIZE;
}
long fromL = (long) Math.max(0, pageNo) * pageSize;
if (fromL >= list.size()) {
return List.of();
}
int from = (int) fromL;
return list.subList(from, Math.min(from + pageSize, list.size()));
}
@GetMapping("/{id}")
public ApiResp<Announcement> get(@PathVariable Long id) {
return ApiResp.ok(announcementRepo.findById(id)
.orElseThrow(() -> new NotFoundException("announcement not found: " + id)));
}
public record CreateAnnouncementRequest(
String category, String title, String content, String author, Boolean top, String publishRange) {
}
@PostMapping
public ApiResp<Announcement> create(@RequestBody CreateAnnouncementRequest req) {
if (req.title() == null || req.title().isBlank()) {
throw new ApiException(400, "title is required");
}
Announcement a = new Announcement();
a.setCategory(req.category() == null ? "公告" : req.category());
a.setTitle(req.title());
a.setContent(HtmlSanitizer.sanitize(req.content()));
a.setAuthor(req.author());
a.setTop(Boolean.TRUE.equals(req.top()));
a.setPublishRange(req.publishRange());
a.setPublishedAt(Instant.now());
return ApiResp.ok(announcementRepo.save(a));
}
public record UpdateAnnouncementRequest(String title, String content, String category, String publishRange) {
}
/** PUT /{id} -> 编辑已发布的新闻/公告 (title/content/category/publishRange)。 */
@PutMapping("/{id}")
public ApiResp<Announcement> update(@PathVariable Long id, @RequestBody UpdateAnnouncementRequest req) {
Announcement a = announcementRepo.findById(id)
.orElseThrow(() -> new NotFoundException("announcement not found: " + id));
if (req.title() != null) {
if (req.title().isBlank()) {
throw new ApiException(400, "标题不能为空");
}
a.setTitle(req.title().trim());
}
if (req.content() != null) a.setContent(HtmlSanitizer.sanitize(req.content()));
if (req.category() != null) a.setCategory(req.category());
if (req.publishRange() != null) a.setPublishRange(req.publishRange());
return ApiResp.ok(announcementRepo.save(a));
}
/** DELETE /{id} -> 撤回新闻/公告。 */
@DeleteMapping("/{id}")
public ApiResp<Void> delete(@PathVariable Long id) {
if (!announcementRepo.existsById(id)) {
throw new NotFoundException("announcement not found: " + id);
}
announcementRepo.deleteById(id);
return ApiResp.ok(null);
}
}