feat: 网关管理模块 + RBAC权限认证 + 组织架构 + 审计日志
- 网关管理:GatewayEntity/Service/Controller CRUD + 测试连接;设备 GatewayId 外键关联 - JWT 认证:登录签发 Token(权限编码写入 Claims)、RequirePermission 权限过滤器、CurrentUser 上下文 - RBAC:用户/角色/权限实体与 CRUD,预定义 4 角色 + 6 权限种子(admin/admin123) - 组织架构:sys_org 固定层级树(公司/实验室/部门/班组白夜班),层级校验,用户挂 OrgId/岗位/技能标签 - 数据权限:角色 DataScope(全部/本组织及下级),用户列表按组织子树过滤 - 防锁死保护:禁止删/禁自己,保证至少一名活跃管理员,角色摘除 user:manage 前校验 - 审计日志:AuditRecorder 接入设备增删改/指令下发/登录登出/组织变更,AuditController 查询 - 设备指令下发按网关表取连接参数;设备列表支持 gatewayId/productId 筛选 Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,58 @@
|
||||
using Microsoft.Extensions.Logging;
|
||||
using Model.Entity.System;
|
||||
using ORM;
|
||||
using Service.Interface;
|
||||
using SqlSugar;
|
||||
|
||||
namespace Service.Implement
|
||||
{
|
||||
/// <summary>
|
||||
/// 审计日志记录器实现:操作人/角色自动取自 ICurrentUser(JWT Claims),失败不抛出(审计不应阻断业务)
|
||||
/// </summary>
|
||||
public class AuditRecorder : IAuditRecorder
|
||||
{
|
||||
private readonly ICurrentUser _currentUser;
|
||||
private readonly ILogger<AuditRecorder> _logger;
|
||||
|
||||
public AuditRecorder(ICurrentUser currentUser, ILogger<AuditRecorder> logger)
|
||||
{
|
||||
_currentUser = currentUser;
|
||||
_logger = logger;
|
||||
}
|
||||
|
||||
public async Task RecordAsync(string operationType, string operationTarget, long targetId,
|
||||
long deviceId = 0, string? oldValue = null, string? newValue = null,
|
||||
string? ip = null, string? description = null)
|
||||
{
|
||||
try
|
||||
{
|
||||
var now = DateTime.Now;
|
||||
var roleId = _currentUser.RoleIds.FirstOrDefault();
|
||||
var roleName = _currentUser.RoleNames.FirstOrDefault();
|
||||
await SqlSugarContext.DbContext.Insertable(new AuditLogEntity
|
||||
{
|
||||
UserId = _currentUser.UserId,
|
||||
UserName = _currentUser.UserName,
|
||||
RoleId = roleId,
|
||||
RoleName = roleName ?? "",
|
||||
OperationType = operationType,
|
||||
OperationTarget = operationTarget,
|
||||
TargetId = targetId,
|
||||
DeviceId = deviceId,
|
||||
OldValue = oldValue,
|
||||
NewValue = newValue,
|
||||
Ip = ip,
|
||||
Description = description,
|
||||
OperateTime = now,
|
||||
CreateTime = now
|
||||
}).ExecuteCommandAsync();
|
||||
}
|
||||
catch (Exception ex)
|
||||
{
|
||||
// 审计失败只记日志,不阻断业务
|
||||
_logger.LogError(ex, "写审计日志失败({OperationType} {OperationTarget} {TargetId})",
|
||||
operationType, operationTarget, targetId);
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user