SNAPSHOT W7 已部署稳定态 — 凯迪ERP+OA一体化平台 (MET 73.3%)
恢复点(restore point)。别人改崩后可 git reset --hard 回到此提交。 == 此快照内容 == - 后端 oa-backend: 734 控制器 / 711 实体 (Spring Boot 3.2.5 + SQLite, 端口8091) - 前端 modern-ui/app: Vue3+Vite, 约700页 (构建产物已在 oa-backend/src/main/resources/static) - 数据库 oa-backend/data/oa.db: 含全部演示数据 (强制入库, 6.6MB) - 交接文档 go.md + go-code-reference/endpoints/entities/database.md - 多代理建设脚本 .claude/wf-*.js == 状态 == - 对 凯迪科技ERP_20260507.xlsx 合规 MET ~73.3% (PARTIAL 75: 34可建+6种子/bug+35外部硬天花板) - 安全: 5轮红队+5轮复检, default-deny分级鉴权, 连续零可利用 - W3~W7 累计补完436缺口; W8末轮(40缺口)为半成品(源码树可编译但未集成) - 运行: cd oa-backend; java -jar build/libs/oa-backend-0.1.0.jar --server.port=8091; admin/123456 == 排除(gitignore, 可再生) == node_modules / oa-backend/build / .jdks / *.log / Backup-ERP-* / 弃用的OFBiz核心(只保留modern-ui) 完整文件夹备份见同目录 Backup-ERP-20260615-191517/ (含上述全部, 仅缺 node_modules) 时间戳: 20260615-191517 Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,70 @@
|
||||
package com.kaidi.oa.web;
|
||||
|
||||
import com.kaidi.oa.common.ApiException;
|
||||
import com.kaidi.oa.common.ApiResp;
|
||||
import com.kaidi.oa.domain.SysUser;
|
||||
import com.kaidi.oa.service.AuthService;
|
||||
import jakarta.servlet.http.HttpServletRequest;
|
||||
import jakarta.validation.constraints.NotBlank;
|
||||
import org.springframework.web.bind.annotation.GetMapping;
|
||||
import org.springframework.web.bind.annotation.PostMapping;
|
||||
import org.springframework.web.bind.annotation.RequestBody;
|
||||
import org.springframework.web.bind.annotation.RequestMapping;
|
||||
import org.springframework.web.bind.annotation.RestController;
|
||||
|
||||
import java.util.LinkedHashMap;
|
||||
import java.util.Map;
|
||||
|
||||
/**
|
||||
* Authentication endpoints. Issues an opaque token on login; the frontend sends
|
||||
* it back as a Bearer token. Session lookup and logout supported.
|
||||
*/
|
||||
@RestController
|
||||
@RequestMapping("/api/oa/auth")
|
||||
public class AuthController {
|
||||
|
||||
private final AuthService authService;
|
||||
private final CurrentUserResolver currentUser;
|
||||
|
||||
public AuthController(AuthService authService, CurrentUserResolver currentUser) {
|
||||
this.authService = authService;
|
||||
this.currentUser = currentUser;
|
||||
}
|
||||
|
||||
public record LoginRequest(@NotBlank String loginName, @NotBlank String password) {
|
||||
}
|
||||
|
||||
@PostMapping("/login")
|
||||
public ApiResp<Map<String, Object>> login(@RequestBody LoginRequest req) {
|
||||
AuthService.LoginResult result = authService.login(req.loginName(), req.password());
|
||||
return ApiResp.ok(toSession(result.user(), result.token()));
|
||||
}
|
||||
|
||||
@GetMapping("/session")
|
||||
public ApiResp<Map<String, Object>> session(HttpServletRequest request) {
|
||||
String token = currentUser.extractToken(request);
|
||||
SysUser user = authService.resolve(token);
|
||||
if (user == null) {
|
||||
throw new ApiException(401, "未登录或会话已过期");
|
||||
}
|
||||
return ApiResp.ok(toSession(user, token));
|
||||
}
|
||||
|
||||
@PostMapping("/logout")
|
||||
public ApiResp<Void> logout(HttpServletRequest request) {
|
||||
authService.logout(currentUser.extractToken(request));
|
||||
return ApiResp.ok();
|
||||
}
|
||||
|
||||
private Map<String, Object> toSession(SysUser user, String token) {
|
||||
Map<String, Object> map = new LinkedHashMap<>();
|
||||
map.put("token", token);
|
||||
map.put("id", user.getId());
|
||||
map.put("loginName", user.getLoginName());
|
||||
map.put("displayName", user.getDisplayName());
|
||||
map.put("deptId", user.getDeptId());
|
||||
map.put("title", user.getTitle());
|
||||
map.put("email", user.getEmail());
|
||||
return map;
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user