Browse Source

feat(inspection): 添加特殊权限控制和界面优化

- 新增 SRM0004 特殊权限检查功能,控制审核任务查看范围
- 实现权限验证后才加载数据,避免数据泄露风险
- 无权限时强制按当前用户过滤审核任务查询
- 排程页面限制 Planner 只能查看自己名下数据
- 调整表格列宽度以改善界面显示效果
- 移除不再使用的负责区域列显示
master
qiankanghui 1 week ago
parent
commit
fd05ecc4e5
  1. 6
      src/views/modules/inspection/com_inspectionScheduleView.vue
  2. 27
      src/views/modules/inspection/inspectionRequestAudit.vue
  3. 3
      src/views/modules/inspection/inspectionScheduleList.vue

6
src/views/modules/inspection/com_inspectionScheduleView.vue

@ -22,9 +22,9 @@
style="width: 100%;" style="width: 100%;"
:max-height="qcTableHeight" :max-height="qcTableHeight"
class="qc-table"> class="qc-table">
<el-table-column prop="qcName" label="姓名" width="80" align="center" />
<el-table-column prop="region" label="负责区域" min-width="90" show-overflow-tooltip />
<el-table-column label="操作" width="80" align="center" fixed="right">
<el-table-column prop="qcName" label="姓名" width="125" align="center" />
<!-- <el-table-column prop="region" label="负责区域" min-width="90" show-overflow-tooltip />-->
<el-table-column label="操作" width="125" align="center" fixed="right">
<template slot-scope="scope"> <template slot-scope="scope">
<!-- 只有当主表选中了数据且状态为已下达或已排程时才显示排程按钮 --> <!-- 只有当主表选中了数据且状态为已下达或已排程时才显示排程按钮 -->
<el-link <el-link

27
src/views/modules/inspection/inspectionRequestAudit.vue

@ -123,6 +123,7 @@
<script> <script>
import { searchInspectionRequestHeaderList, auditInspectionRequest } from '@/api/inspection/inspectionRequestHeader.js' import { searchInspectionRequestHeaderList, auditInspectionRequest } from '@/api/inspection/inspectionRequestHeader.js'
import { getPermissionValue } from '@/api/sys/specialSecurity.js'
import Chooselist from '@/views/modules/common/Chooselist_eam' import Chooselist from '@/views/modules/common/Chooselist_eam'
import ComInspectionRequestDetail from './com_inspectionRequestDetail.vue' import ComInspectionRequestDetail from './com_inspectionRequestDetail.vue'
import ComInspectionRequestDetailTab from './com_inspectionRequestDetailTab.vue' import ComInspectionRequestDetailTab from './com_inspectionRequestDetailTab.vue'
@ -146,6 +147,8 @@ export default {
tagNo: '', tagNo: '',
searchType: '', searchType: '',
activeTab: 'base', activeTab: 'base',
// SRM0004 特殊权限:有权限可查看所有审核任务,无权限仅能查看自己作为 planner 的数据
canViewAllTasks: false,
searchData: { searchData: {
requestNo: '', requestNo: '',
supplierNo: '', supplierNo: '',
@ -464,7 +467,8 @@ export default {
const calculatedHeight = (window.innerHeight - 220) / 2 const calculatedHeight = (window.innerHeight - 220) / 2
this.height = calculatedHeight this.height = calculatedHeight
this.detailHeight = calculatedHeight this.detailHeight = calculatedHeight
this.loadMainOrReminder()
// 先确认 SRM0004 权限再加载,避免首次查询泄漏他人数据
this.checkViewAllPermission()
}) })
}, },
watch: { watch: {
@ -493,6 +497,23 @@ export default {
} }
return '' return ''
}, },
// 查询 SRM0004 特殊权限:是否允许查看所有审核任务
checkViewAllPermission () {
const username = this.$store.state.user.name || ''
if (!username) {
this.canViewAllTasks = false
this.loadMainOrReminder()
return
}
getPermissionValue(username, 'SRM0004').then(({ data }) => {
this.canViewAllTasks = !!(data && data.code === 0 && String(data.value).trim() === 'Y')
this.loadMainOrReminder()
}).catch(error => {
console.error('查询查看所有审核任务权限失败:', error)
this.canViewAllTasks = false
this.loadMainOrReminder()
})
},
loadMainOrReminder () { loadMainOrReminder () {
// 首页跳转带入的 planner 条件仅首次生效 - rqrq // 首页跳转带入的 planner 条件仅首次生效 - rqrq
const plannerAccount = this.getRoutePlannerAccount() const plannerAccount = this.getRoutePlannerAccount()
@ -550,6 +571,10 @@ export default {
this.searchData.limit = this.pageSize this.searchData.limit = this.pageSize
this.searchData.page = this.pageIndex this.searchData.page = this.pageIndex
this.searchData.status = 'Confirmed' // 强制只查询已确认的 this.searchData.status = 'Confirmed' // 强制只查询已确认的
// 无 SRM0004 权限时,强制只查当前用户作为 planner 的数据
if (!this.canViewAllTasks) {
this.searchData.plannerAccount = this.$store.state.user.name
}
// 后端查询字段使用 planStartDateStr/planEndDateStr - rqrq // 后端查询字段使用 planStartDateStr/planEndDateStr - rqrq
this.searchData.planStartDateStr = this.searchData.planStartDate || '' this.searchData.planStartDateStr = this.searchData.planStartDate || ''
this.searchData.planEndDateStr = this.searchData.planEndDate || '' this.searchData.planEndDateStr = this.searchData.planEndDate || ''

3
src/views/modules/inspection/inspectionScheduleList.vue

@ -233,6 +233,7 @@ export default {
requestNo: '', requestNo: '',
supplierNo: '', supplierNo: '',
supplierName: '', supplierName: '',
plannerAccount: '',
status: 'AUDITED', // 默认状态为已审核 status: 'AUDITED', // 默认状态为已审核
qcOperator: '', qcOperator: '',
createBy: '', createBy: '',
@ -603,6 +604,8 @@ export default {
getMainData () { getMainData () {
this.searchData.limit = this.pageSize this.searchData.limit = this.pageSize
this.searchData.page = this.pageIndex this.searchData.page = this.pageIndex
// 排程页仅限 Planner 查看自己名下的数据,强制按当前登录账号过滤
this.searchData.plannerAccount = this.$store.state.user.name
// 后端查询字段使用 planStartDateStr/planEndDateStr - rqrq // 后端查询字段使用 planStartDateStr/planEndDateStr - rqrq
this.searchData.planStartDateStr = this.searchData.planStartDate || '' this.searchData.planStartDateStr = this.searchData.planStartDate || ''
this.searchData.planEndDateStr = this.searchData.planEndDate || '' this.searchData.planEndDateStr = this.searchData.planEndDate || ''

Loading…
Cancel
Save