Files
group_fqcd_jr/app/repository/identity_repository.py
T
张胜宇 e239eb778b docs: 品牌全量口径统一为「南方基金」+ 作废文档清理
1) 客服 Agent 四份交付文档 + 构建脚手架:品牌由包装占位 XX科技 / 旧名 南方财富
   统一为南方基金(热线 400-889-8899 / 官网 nffund.com),系统名改为「智能服务系统」;
   同步追加 §0.4 修订记录行,工程记录行保留原占位字面以支撑硬编码扫描验收。
2) 开发文档:清理 28 份已作废/残留文档(14 份移出归档 + 14 份仓库副本),
   新增《文档规整方案与开发前待决事项-2026-09-17》。
3) 客服agent 四份交付文档首次纳入本分支。
2026-09-17 15:15:22 +08:00

62 lines
3.1 KiB
Python
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
from datetime import UTC, datetime
from sqlalchemy import text
from sqlalchemy.ext.asyncio import AsyncSession
from app.core.contracts import RequestContext
from app.core.errors import UnauthorizedAgentError
class IdentityRepository:
"""Read existing RBAC tables; never authorize from client role claims."""
def __init__(self, session: AsyncSession) -> None:
self.session = session
async def load_context(self, identity: RequestContext) -> RequestContext:
now = datetime.now(UTC).replace(tzinfo=None)
params = {"user_id": int(identity.user_id), "now": now}
status = await self.session.scalar(
text("SELECT status FROM sys_user WHERE id=:user_id"), params
)
if status != "正常":
raise UnauthorizedAgentError("账号不存在或未启用")
rows = (await self.session.execute(text("""
SELECT r.role_code, p.permission_code, p.data_scope
FROM sys_user_role ur JOIN sys_role r ON r.id=ur.role_id
LEFT JOIN sys_role_permission rp ON rp.role_id=r.id
LEFT JOIN sys_permission p ON p.id=rp.permission_id
WHERE ur.user_id=:user_id AND r.status='active'
AND ur.assigned_at<=:now AND (ur.expires_at IS NULL OR ur.expires_at>:now)
"""), params)).mappings().all()
roles = tuple(sorted({str(row["role_code"]) for row in rows}))
scopes: dict[str, str] = {}
rank = {"self": 0, "own_customers": 1, "all": 2}
for row in rows:
if row["permission_code"] and row["data_scope"] in rank:
code, scope = str(row["permission_code"]), str(row["data_scope"])
if code not in scopes or rank[scope] > rank[scopes[code]]:
scopes[code] = scope
customers = (await self.session.scalars(text("""
SELECT customer_id FROM sys_customer_assignment
WHERE employee_id=:user_id AND assigned_at<=:now
AND (unassigned_at IS NULL OR unassigned_at>:now)
"""), params)).all()
# data_scope 取该身份所有权限里的**最高**范围。
#
# 原先这里写死 "self",于是上面刚算出来的 scope 白算了:permission_scopes 里
# 明明有 all,data_scope 却永远是 self,凡是按 `context.data_scope == "all"`
# 判断能否看全量的路径全部走不通(风控的 risk_query_service.py:198、
# risk_analysis_service.py:126、risk_evidence_archive_service.py:218、
# risk_action_service.py:212 都是这样判断的)。实测 9002(risk_operator) 与
# 9003(admin) 拿着 all 级权限却什么都查不到。
#
# 没有 all 权限的角色行为不变(如 customer 仍是 self),所以这不放松任何既有边界。
data_scope = max(scopes.values(), key=lambda value: rank[value]) if scopes else "self"
return identity.model_copy(update={
"roles": roles, "permissions": tuple(sorted(scopes)),
"permission_scopes": scopes, "data_scope": data_scope,
"customer_ids": tuple(str(value) for value in customers),
"portal": "api",
})