Commit f90c43b3 authored by 孙磊's avatar 孙磊

权限优化

Signed-off-by: 孙磊's avatarsunlei <sunlei@romens.cn>
parent 5126de11
...@@ -37,14 +37,6 @@ class AuthorityRoleController extends BaseController ...@@ -37,14 +37,6 @@ class AuthorityRoleController extends BaseController
{ {
$model = new $this->modelClass; $model = new $this->modelClass;
$params = Yii::$app->request->queryParams; $params = Yii::$app->request->queryParams;
//权限信息
$rbac = new ShopRbacUser();
$userGuid = Yii::$app->user->identity->GUID;
$userinfo = $rbac->getRbacUserInfo($userGuid);
if ($userinfo['ROLE_ID'] != USER_ROLE_HEADQUARTERS_ADMIN) {
throw new BadRequestHttpException('您没有查看角色列表的权限,请联系管理员');
}
$model->attributes = $params; $model->attributes = $params;
if ($model->validate()) { if ($model->validate()) {
//所有输入数据都有效 all inputs are valid //所有输入数据都有效 all inputs are valid
...@@ -121,14 +113,6 @@ class AuthorityRoleController extends BaseController ...@@ -121,14 +113,6 @@ class AuthorityRoleController extends BaseController
*/ */
public function actionAddAuthorityRole() public function actionAddAuthorityRole()
{ {
//权限信息
$rbac = new ShopRbacUser();
$userGuid = Yii::$app->user->identity->GUID;
$userinfo = $rbac->getRbacUserInfo($userGuid);
if ($userinfo['ROLE_ID'] != USER_ROLE_HEADQUARTERS_ADMIN) {
throw new BadRequestHttpException('您没有添加角色的权限,请联系管理员');
}
$params = Yii::$app->getRequest()->post(); $params = Yii::$app->getRequest()->post();
$model = new $this->modelClass(); $model = new $this->modelClass();
...@@ -173,14 +157,6 @@ class AuthorityRoleController extends BaseController ...@@ -173,14 +157,6 @@ class AuthorityRoleController extends BaseController
*/ */
public function actionReviseAuthorityRole() public function actionReviseAuthorityRole()
{ {
//权限信息
$rbac = new ShopRbacUser();
$userGuid = Yii::$app->user->identity->GUID;
$userinfo = $rbac->getRbacUserInfo($userGuid);
if ($userinfo['ROLE_ID'] != USER_ROLE_HEADQUARTERS_ADMIN) {
throw new BadRequestHttpException('您没有修改角色的权限,请联系管理员');
}
$id = Yii::$app->getRequest()->post('ID'); $id = Yii::$app->getRequest()->post('ID');
$model = $this->modelClass::findOne($id); $model = $this->modelClass::findOne($id);
if (!$model) { if (!$model) {
...@@ -288,13 +264,6 @@ class AuthorityRoleController extends BaseController ...@@ -288,13 +264,6 @@ class AuthorityRoleController extends BaseController
*/ */
public function actionAssignAuthorityRole() public function actionAssignAuthorityRole()
{ {
//权限信息
$rbac = new ShopRbacUser();
$userGuid = Yii::$app->user->identity->GUID;
$userinfo = $rbac->getRbacUserInfo($userGuid);
if ($userinfo['ROLE_ID'] != USER_ROLE_HEADQUARTERS_ADMIN) {
throw new BadRequestHttpException('您没有给角色分配权限的权限,请联系管理员');
}
$params = Yii::$app->getRequest()->post(); $params = Yii::$app->getRequest()->post();
$model = new ShopRbacRoleAccess(); $model = new ShopRbacRoleAccess();
$model->scenario = 'create'; //创建的场景 $model->scenario = 'create'; //创建的场景
......
...@@ -43,14 +43,6 @@ class BranchServiceTypeController extends BaseController ...@@ -43,14 +43,6 @@ class BranchServiceTypeController extends BaseController
*/ */
public function actionBranchServiceList() public function actionBranchServiceList()
{ {
//权限信息
$rbac = new ShopRbacUser();
$userGuid = Yii::$app->user->identity->GUID;
$userinfo = $rbac->getRbacUserInfo($userGuid);
if ($userinfo['ROLE_ID'] != USER_ROLE_HEADQUARTERS_ADMIN) {
throw new BadRequestHttpException('您没有查看门店服务类目列表的权限,请联系管理员');
}
$model = new $this->modelClass(); $model = new $this->modelClass();
//用户输入数据赋值到模型属性 //用户输入数据赋值到模型属性
$model->CODE = Yii::$app->request->get('code'); $model->CODE = Yii::$app->request->get('code');
...@@ -259,14 +251,6 @@ class BranchServiceTypeController extends BaseController ...@@ -259,14 +251,6 @@ class BranchServiceTypeController extends BaseController
*/ */
public function actionBranchServiceImport() public function actionBranchServiceImport()
{ {
//权限信息
$rbac = new ShopRbacUser();
$userGuid = Yii::$app->user->identity->GUID;
$userinfo = $rbac->getRbacUserInfo($userGuid);
if ($userinfo['ROLE_ID'] != USER_ROLE_HEADQUARTERS_ADMIN) {
throw new BadRequestHttpException('您没有导入门店服务类目的权限,请联系管理员');
}
$model = new UploadFiles(); $model = new UploadFiles();
if (Yii::$app->request->isPost) { if (Yii::$app->request->isPost) {
//多文件用getInstances //多文件用getInstances
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment