Refactor privilege management to support hierarchical privilege keys
- Updated privilege key structure to use a 3- or 4-part dotted hierarchy (e.g., `GROUP.PARENT.MODULE`). - Modified the `RequirePrivilege` decorator to accept multiple keys, allowing for OR logic in privilege checks. - Enhanced `PrivilegesGuard` to validate against multiple privilege keys, improving access control logic. - Created migration scripts to update existing privilege keys in the database to the new format. - Updated related services, controllers, and tests to accommodate the new privilege key structure and validation logic.
This commit is contained in:
@@ -18,7 +18,10 @@ import { BEARER_AUTH_NAME } from '../../../common/swagger/setup-swagger';
|
||||
import { SalesOrderDto, ListSalesOrdersQueryDto } from './dto/sales-order.dto';
|
||||
import { SalesOrdersService } from './sales-orders.service';
|
||||
|
||||
export const SALES_ORDER_PRIVILEGE_KEY = 'SALES.ORDER';
|
||||
export const SALES_ORDER_PRIVILEGE_KEYS = [
|
||||
'ADMIN.SALES.ACTIVITIES.ORDER',
|
||||
'MOBILE.SALES.ORDER',
|
||||
] as const;
|
||||
|
||||
@ApiTags('sales-orders')
|
||||
@ApiBearerAuth(BEARER_AUTH_NAME)
|
||||
@@ -28,7 +31,7 @@ export class SalesOrdersReadController {
|
||||
|
||||
@Get()
|
||||
@Pagination()
|
||||
@RequirePrivilege(SALES_ORDER_PRIVILEGE_KEY, 'view')
|
||||
@RequirePrivilege(SALES_ORDER_PRIVILEGE_KEYS, 'view')
|
||||
@ApiOperation({ summary: 'List sales orders' })
|
||||
@ApiOkResponse({
|
||||
schema: {
|
||||
@@ -50,7 +53,7 @@ export class SalesOrdersReadController {
|
||||
}
|
||||
|
||||
@Get(':id')
|
||||
@RequirePrivilege(SALES_ORDER_PRIVILEGE_KEY, 'view')
|
||||
@RequirePrivilege(SALES_ORDER_PRIVILEGE_KEYS, 'view')
|
||||
@ApiOperation({ summary: 'Get sales order detail' })
|
||||
@ApiOkResponse({ type: SalesOrderDto })
|
||||
@ApiNotFoundResponse()
|
||||
|
||||
Reference in New Issue
Block a user