越权问题
All checks were successful
构建并部署到测试环境(无 SSH) / build-and-deploy (push) Successful in 8m14s

This commit is contained in:
2026-07-28 18:44:39 +08:00
parent dc080436bf
commit b3a215b19e
4 changed files with 22 additions and 3 deletions

View File

@@ -29,7 +29,7 @@ func (q *PaymentStatusQuery) Get(ctx context.Context, rechargeID uint) (*dto.Age
return nil, errors.New(errors.CodeInvalidParam, "代理充值支付状态查询参数无效")
}
var recharge model.AgentRechargeRecord
rechargeQuery := middleware.ApplyShopFilter(ctx, q.db.WithContext(ctx).Model(&model.AgentRechargeRecord{}))
rechargeQuery := middleware.ApplyStrictShopFilter(ctx, q.db.WithContext(ctx).Model(&model.AgentRechargeRecord{}))
if err := rechargeQuery.Where("id = ?", rechargeID).First(&recharge).Error; err != nil {
if err == gorm.ErrRecordNotFound {
return nil, errors.New(errors.CodeForbidden, "无权限操作该资源或资源不存在")

View File

@@ -444,7 +444,7 @@ func (s *Service) List(ctx context.Context, req *dto.AgentRechargeListRequest) (
pageSize = constants.DefaultPageSize
}
query := middleware.ApplyShopFilter(ctx, s.db.WithContext(ctx).Model(&model.AgentRechargeRecord{}))
query := middleware.ApplyStrictShopFilter(ctx, s.db.WithContext(ctx).Model(&model.AgentRechargeRecord{}))
if req.ShopID != nil {
query = query.Where("shop_id = ?", *req.ShopID)

View File

@@ -49,7 +49,7 @@ func (s *AgentRechargeStore) GetByRechargeNo(ctx context.Context, rechargeNo str
// GetByID 根据 ID 查询
func (s *AgentRechargeStore) GetByID(ctx context.Context, id uint) (*model.AgentRechargeRecord, error) {
var record model.AgentRechargeRecord
query := middleware.ApplyShopFilter(ctx, s.db.WithContext(ctx).Model(&model.AgentRechargeRecord{}))
query := middleware.ApplyStrictShopFilter(ctx, s.db.WithContext(ctx).Model(&model.AgentRechargeRecord{}))
if err := query.First(&record, id).Error; err != nil {
return nil, err
}

View File

@@ -32,6 +32,25 @@ func ApplyShopFilter(ctx context.Context, query *gorm.DB) *gorm.DB {
return query.Where("shop_id IN ?", shopIDs)
}
// ApplyStrictShopFilter 严格应用店铺数据权限过滤
// 超管和平台用户不限制;代理用户仅能访问自己及下级店铺;其他用户返回空结果
// 代理用户的权限范围缺失时降级为当前店铺,当前店铺也缺失时返回空结果
func ApplyStrictShopFilter(ctx context.Context, query *gorm.DB) *gorm.DB {
switch GetUserTypeFromContext(ctx) {
case constants.UserTypeSuperAdmin, constants.UserTypePlatform:
return query
case constants.UserTypeAgent:
shopIDs := GetSubordinateShopIDs(ctx)
if len(shopIDs) > 0 {
return query.Where("shop_id IN ?", shopIDs)
}
if shopID := GetShopIDFromContext(ctx); shopID > 0 {
return query.Where("shop_id = ?", shopID)
}
}
return query.Where("1 = 0")
}
// ApplyEnterpriseFilter 应用企业数据权限过滤
// 非企业用户:不添加条件
// 企业用户WHERE enterprise_id = ?