fix=>权限和租户可以同时忽略,并且可重入忽略

This commit is contained in:
amadeus5201 2024-08-20 17:17:45 +08:00
parent 28a359836a
commit bedf08b1d5
2 changed files with 56 additions and 58 deletions

View File

@ -10,10 +10,7 @@ import lombok.AccessLevel;
import lombok.NoArgsConstructor; import lombok.NoArgsConstructor;
import org.dromara.common.core.utils.reflect.ReflectUtils; import org.dromara.common.core.utils.reflect.ReflectUtils;
import java.util.HashMap; import java.util.*;
import java.util.Map;
import java.util.Objects;
import java.util.Stack;
import java.util.function.Supplier; import java.util.function.Supplier;
/** /**
@ -28,8 +25,23 @@ public class DataPermissionHelper {
private static final String DATA_PERMISSION_KEY = "data:permission"; private static final String DATA_PERMISSION_KEY = "data:permission";
private static final Stack<Integer> REENTRANT_IGNORE_PERMISSION_STACK = new Stack<>(); private static final ThreadLocal<Stack<Integer>> REENTRANT_IGNORE_PERMISSION = new ThreadLocal<>();
private static Stack<Integer> getReentrantIgnorePermissionStack() {
return Optional.ofNullable(REENTRANT_IGNORE_PERMISSION.get()).orElseGet(() -> {
REENTRANT_IGNORE_PERMISSION.set(new Stack<>());
return REENTRANT_IGNORE_PERMISSION.get();
});
}
private static void clearReentrantIgnore() {
REENTRANT_IGNORE_PERMISSION.remove();
}
private static void reentrantIgnoreIncrement() {
Stack<Integer> reentrantStack = getReentrantIgnorePermissionStack();
reentrantStack.push(reentrantStack.size() + 1);
}
/** /**
* 从上下文中获取指定键的变量值并将其转换为指定的类型 * 从上下文中获取指定键的变量值并将其转换为指定的类型
* *
@ -80,18 +92,12 @@ public class DataPermissionHelper {
IgnoreStrategy ignoreStrategy = IGNORE_STRATEGY_LOCAL.get(); IgnoreStrategy ignoreStrategy = IGNORE_STRATEGY_LOCAL.get();
if (ignoreStrategy == null) { if (ignoreStrategy == null) {
InterceptorIgnoreHelper.handle(IgnoreStrategy.builder().dataPermission(true).build()); InterceptorIgnoreHelper.handle(IgnoreStrategy.builder().dataPermission(true).build());
REENTRANT_IGNORE_PERMISSION_STACK.push(1);
} else {
if (Boolean.TRUE.equals(ignoreStrategy.getDataPermission())) {
if (REENTRANT_IGNORE_PERMISSION_STACK.isEmpty()) {
throw new IllegalStateException("ignore data permission error");
}
REENTRANT_IGNORE_PERMISSION_STACK.push(REENTRANT_IGNORE_PERMISSION_STACK.peek() + 1);
} else { } else {
if (!Boolean.TRUE.equals(ignoreStrategy.getDataPermission())) {
ignoreStrategy.setDataPermission(true); ignoreStrategy.setDataPermission(true);
REENTRANT_IGNORE_PERMISSION_STACK.push(1);
} }
} }
reentrantIgnoreIncrement();
} }
/** /**
@ -101,28 +107,19 @@ public class DataPermissionHelper {
ThreadLocal<IgnoreStrategy> IGNORE_STRATEGY_LOCAL = (ThreadLocal<IgnoreStrategy>) ReflectUtils.getStaticFieldValue(ReflectUtils.getField(InterceptorIgnoreHelper.class, "IGNORE_STRATEGY_LOCAL")); ThreadLocal<IgnoreStrategy> IGNORE_STRATEGY_LOCAL = (ThreadLocal<IgnoreStrategy>) ReflectUtils.getStaticFieldValue(ReflectUtils.getField(InterceptorIgnoreHelper.class, "IGNORE_STRATEGY_LOCAL"));
IgnoreStrategy ignoreStrategy = IGNORE_STRATEGY_LOCAL.get(); IgnoreStrategy ignoreStrategy = IGNORE_STRATEGY_LOCAL.get();
if (ignoreStrategy != null) { if (ignoreStrategy != null) {
boolean empty = REENTRANT_IGNORE_PERMISSION_STACK.isEmpty(); boolean noOtherIgnoreStrategy = !Boolean.TRUE.equals(ignoreStrategy.getTenantLine())
int pop = empty ? 1 : REENTRANT_IGNORE_PERMISSION_STACK.pop();
boolean shouldClear = !Boolean.TRUE.equals(ignoreStrategy.getTenantLine())
&& !Boolean.TRUE.equals(ignoreStrategy.getDynamicTableName()) && !Boolean.TRUE.equals(ignoreStrategy.getDynamicTableName())
&& !Boolean.TRUE.equals(ignoreStrategy.getBlockAttack()) && !Boolean.TRUE.equals(ignoreStrategy.getBlockAttack())
&& !Boolean.TRUE.equals(ignoreStrategy.getIllegalSql()) && !Boolean.TRUE.equals(ignoreStrategy.getIllegalSql())
&& CollectionUtil.isEmpty(ignoreStrategy.getOthers()); && CollectionUtil.isEmpty(ignoreStrategy.getOthers());
if (shouldClear) { Stack<Integer> reentrantStack = getReentrantIgnorePermissionStack();
if (empty) { boolean empty = reentrantStack.isEmpty() || reentrantStack.pop() == 1;
if (noOtherIgnoreStrategy && empty) {
InterceptorIgnoreHelper.clearIgnoreStrategy(); InterceptorIgnoreHelper.clearIgnoreStrategy();
} else { } else if (empty) {
if (pop == 1) { if (Boolean.TRUE.equals(ignoreStrategy.getDataPermission())) {
InterceptorIgnoreHelper.clearIgnoreStrategy();
}
}
} else {
if (empty) {
ignoreStrategy.setDataPermission(false); ignoreStrategy.setDataPermission(false);
} else { clearReentrantIgnore();
if (pop == 1) {
ignoreStrategy.setDataPermission(false);
}
} }
} }
} }

View File

@ -16,6 +16,7 @@ import org.dromara.common.core.utils.reflect.ReflectUtils;
import org.dromara.common.redis.utils.RedisUtils; import org.dromara.common.redis.utils.RedisUtils;
import org.dromara.common.satoken.utils.LoginHelper; import org.dromara.common.satoken.utils.LoginHelper;
import java.util.Optional;
import java.util.Stack; import java.util.Stack;
import java.util.function.Supplier; import java.util.function.Supplier;
@ -32,8 +33,24 @@ public class TenantHelper {
private static final ThreadLocal<String> TEMP_DYNAMIC_TENANT = new TransmittableThreadLocal<>(); private static final ThreadLocal<String> TEMP_DYNAMIC_TENANT = new TransmittableThreadLocal<>();
private static final Stack<Integer> REENTRANT_IGNORE_TENANT_STACK = new Stack<>();
private static final ThreadLocal<Stack<Integer>> REENTRANT_IGNORE_TENANT = new ThreadLocal<>();
private static Stack<Integer> getReentrantIgnoreTenantStack() {
return Optional.ofNullable(REENTRANT_IGNORE_TENANT.get()).orElseGet(() -> {
REENTRANT_IGNORE_TENANT.set(new Stack<>());
return REENTRANT_IGNORE_TENANT.get();
});
}
private static void clearReentrantIgnore() {
REENTRANT_IGNORE_TENANT.remove();
}
private static void reentrantIgnoreIncrement() {
Stack<Integer> reentrantStack = getReentrantIgnoreTenantStack();
reentrantStack.push(reentrantStack.size() + 1);
}
/** /**
* 租户功能是否启用 * 租户功能是否启用
*/ */
@ -49,18 +66,12 @@ public class TenantHelper {
IgnoreStrategy ignoreStrategy = IGNORE_STRATEGY_LOCAL.get(); IgnoreStrategy ignoreStrategy = IGNORE_STRATEGY_LOCAL.get();
if (ignoreStrategy == null) { if (ignoreStrategy == null) {
InterceptorIgnoreHelper.handle(IgnoreStrategy.builder().tenantLine(true).build()); InterceptorIgnoreHelper.handle(IgnoreStrategy.builder().tenantLine(true).build());
REENTRANT_IGNORE_TENANT_STACK.push(1);
} else {
if (Boolean.TRUE.equals(ignoreStrategy.getTenantLine())) {
if (REENTRANT_IGNORE_TENANT_STACK.isEmpty()) {
throw new IllegalStateException("ignore tenant error");
}
REENTRANT_IGNORE_TENANT_STACK.push(REENTRANT_IGNORE_TENANT_STACK.peek() + 1);
} else { } else {
if (!Boolean.TRUE.equals(ignoreStrategy.getTenantLine())) {
ignoreStrategy.setTenantLine(true); ignoreStrategy.setTenantLine(true);
REENTRANT_IGNORE_TENANT_STACK.push(1);
} }
} }
reentrantIgnoreIncrement();
} }
/** /**
@ -70,29 +81,19 @@ public class TenantHelper {
ThreadLocal<IgnoreStrategy> IGNORE_STRATEGY_LOCAL = (ThreadLocal<IgnoreStrategy>) ReflectUtils.getStaticFieldValue(ReflectUtils.getField(InterceptorIgnoreHelper.class, "IGNORE_STRATEGY_LOCAL")); ThreadLocal<IgnoreStrategy> IGNORE_STRATEGY_LOCAL = (ThreadLocal<IgnoreStrategy>) ReflectUtils.getStaticFieldValue(ReflectUtils.getField(InterceptorIgnoreHelper.class, "IGNORE_STRATEGY_LOCAL"));
IgnoreStrategy ignoreStrategy = IGNORE_STRATEGY_LOCAL.get(); IgnoreStrategy ignoreStrategy = IGNORE_STRATEGY_LOCAL.get();
if (ignoreStrategy != null) { if (ignoreStrategy != null) {
boolean empty = REENTRANT_IGNORE_TENANT_STACK.isEmpty(); boolean noOtherIgnoreStrategy = !Boolean.TRUE.equals(ignoreStrategy.getDynamicTableName())
int pop = empty ? 1 : REENTRANT_IGNORE_TENANT_STACK.pop();
boolean shouldClear = !Boolean.TRUE.equals(ignoreStrategy.getDynamicTableName())
&& !Boolean.TRUE.equals(ignoreStrategy.getBlockAttack()) && !Boolean.TRUE.equals(ignoreStrategy.getBlockAttack())
&& !Boolean.TRUE.equals(ignoreStrategy.getIllegalSql()) && !Boolean.TRUE.equals(ignoreStrategy.getIllegalSql())
&& !Boolean.TRUE.equals(ignoreStrategy.getDataPermission()) && !Boolean.TRUE.equals(ignoreStrategy.getDataPermission())
&& CollectionUtil.isEmpty(ignoreStrategy.getOthers()); && CollectionUtil.isEmpty(ignoreStrategy.getOthers());
if (shouldClear) { Stack<Integer> reentrantStack = getReentrantIgnoreTenantStack();
if (empty) { boolean empty = reentrantStack.isEmpty() || reentrantStack.pop() == 1;
if (noOtherIgnoreStrategy && empty) {
InterceptorIgnoreHelper.clearIgnoreStrategy(); InterceptorIgnoreHelper.clearIgnoreStrategy();
} else { clearReentrantIgnore();
if (pop == 1) { } else if (empty) {
InterceptorIgnoreHelper.clearIgnoreStrategy(); ignoreStrategy.setDataPermission(false);
} clearReentrantIgnore();
}
} else {
if (empty) {
ignoreStrategy.setTenantLine(false);
} else {
if (pop == 1) {
ignoreStrategy.setTenantLine(false);
}
}
} }
} }
} }