Compare commits

..

4 Commits

@ -0,0 +1,118 @@
<%@ page import="weaver.conn.RecordSet" %>
<%@ page import="weaver.general.Util" %>
<%@ page import="org.apache.commons.lang3.StringUtils" %>
<%@ page import="com.alibaba.fastjson.JSONObject" %>
<%@ page import="java.util.List" %>
<%@ page import="java.util.ArrayList" %>
<%@ page import="weaver.hrm.User" %>
<%@ page import="weaver.hrm.HrmUserVarify" %>
<%@ page import="weaver.general.BaseBean" %>
<%@ page import="weaver.hrm.resource.ResourceComInfo" %>
<%@ page import="weaver.interfaces.hzzx.cominfo.PropBean" %>
<%@ page contentType="text/html;charset=UTF-8" %>
<%
BaseBean bb = new BaseBean();
ResourceComInfo resourceComInfo = new ResourceComInfo();
String userManagerId = "";
String userDeptId = "";
String userid = request.getParameter("userid");
if(StringUtils.isNotBlank(userid)){
userManagerId = resourceComInfo.getManagerID(userid);
userDeptId = resourceComInfo.getDepartmentID(userid);
}
String allDeptLeaders = getDepartmentLeader(userDeptId);
bb.writeLog("userManagerId:"+userManagerId);
bb.writeLog("userDeptId:"+userDeptId);
bb.writeLog("allDeptLeaders:"+allDeptLeaders);
User user = HrmUserVarify.getUser (request , response) ;
int currentUserId = user.getUID();
boolean checkRight = false;
String leader_roleid = PropBean.getUfPropValue("leader.roleid");
List<String> leaderList = queryHrmRoleUserByRole(leader_roleid);
String hr_roleid = PropBean.getUfPropValue("hr.roleid");
List<String> hrList = queryHrmRoleUserByRole(hr_roleid);
if(leaderList.contains(currentUserId) || hrList.contains(currentUserId)){
checkRight = true;
}else if((","+allDeptLeaders+",").contains(","+currentUserId+",")){
checkRight = true;
}else if(String.valueOf(currentUserId).equals(userManagerId)){
checkRight = true;
}else if(userid.equals(currentUserId+"")){
checkRight = true;
}else if(currentUserId == 1){
checkRight = true;
}
JSONObject jsonObject = new JSONObject();
jsonObject.put("userid",userid);
jsonObject.put("checkright",checkRight);
jsonObject.put("currentuserid",currentUserId);
%>
<%!
public List<String> queryHrmRoleUserByRole(String roleid){
BaseBean bb = new BaseBean();
List<String> userList = new ArrayList<>();
try{
RecordSet rs = new RecordSet();
String jobtitleSql = " WHERE (a.jobtitle = b.resourceid AND b.resourcetype=5 AND (b.jobtitlelevel=1 OR (b.jobtitlelevel=2 AND ','||b.subdepid ||',' LIKE '%,'||a.subcompanyid1||',%') OR (b.jobtitlelevel=3 AND ','||b.subdepid||',' LIKE '%,' || a.departmentid ||',%')))";
String sql =" select distinct t.resourceid from ( \n" +
" select a.id as resourceid from HrmResource a, HrmRoleMembers b \n" +
" where (a.id=b.resourceid and b.resourcetype =1 ) and b.roleid = " + roleid +
" union all \n" +
" select a.id AS resourceid from HrmResourceManager a, HrmRoleMembers b \n" +
" where (a.id=b.resourceid and b.resourcetype in(7,8)) and b.roleid =" + roleid +
" union all \n" +
" select a.id as resourceid from HrmResource a, HrmRoleMembers b \n" +
" where (a.subcompanyid1 = b.resourceid and a.seclevel>=b.seclevelfrom and a.seclevel<=b.seclevelto and b.resourcetype=2) and b.roleid=" +roleid +
" union all \n" +
" select a.id as resourceid FROM HrmResource a, HrmRoleMembers b \n" +
" WHERE (a.departmentid = b.resourceid and a.seclevel>=b.seclevelfrom and a.seclevel<=b.seclevelto and b.resourcetype=3) and b.roleid =" + roleid +
" union all \n" +
" SELECT a.id as resourceid FROM HrmResource a, HrmRoleMembers b \n" + jobtitleSql + " and b.roleid = " + roleid +
" ) t " ;
bb.writeLog("queryHrmRoleUserByRole:sql:"+sql);
rs.executeQuery(sql);
while (rs.next()){
String resourceid = rs.getString("resourceid");
userList.add(resourceid);
}
}catch (Exception e){
bb.writeLog("queryHrmRoleUserByRole:e:"+e);
}
return userList;
}
/***
*
* @param deptid
* @return
*/
public String getDepartmentLeader(String deptid){
RecordSet rs = new RecordSet();
BaseBean bb = new BaseBean();
bb.writeLog("getDepartmentLeader:deptid:"+deptid);
String bmfzrs = "";
try {
String sql =" with tem_table(dep_id,departmentname,supdepid,curlevel) as (\n" +
" select id, departmentname,supdepid, 1 as level from HrmDepartment whereid=" + deptid+
" union all\n" +
" select a.id,a.departmentname,a.supdepid,b.curlevel+1 from Hrmdepartment a inner join tem_table b on (a.id = b.supdepid)\n" +
" )\n" +
" select bmfzr from hrmdepartmentdefined where deptid in (select dep_id from tem_table)";
rs.executeQuery(sql,new Object[]{deptid});
while(rs.next()){
String bmfzr = Util.null2String(rs.getString("bmfzr"));
bmfzrs += StringUtils.isBlank(bmfzrs) ? bmfzr :","+bmfzr ;
}
}catch (Exception e){
bb.writeLog("e:"+e);
}
return bmfzrs;
}
%>
<%=jsonObject.toJSONString() %>

@ -41,6 +41,7 @@ import com.engine.portal.biz.nonstandardfunction.SysModuleInfoBiz;
import com.engine.hrm.util.face.ValidateFieldManager;
import com.engine.hrm.util.face.bean.CheckItemBean;
import ln.LN;
import org.apache.commons.collections.CollectionUtils;
import org.apache.commons.lang3.StringUtils;
import weaver.hrm.definedfield.HrmFieldComInfo;
import weaver.hrm.job.JobCallComInfo;
@ -3661,21 +3662,39 @@ public class HrmResourceBaseService extends BaseBean {
userManagerId = resourceComInfo.getManagerID(userid);
userDeptId = resourceComInfo.getDepartmentID(userid);
}
String deptLeaderId = getDepartmentLeader(userDeptId);
String allDeptLeaders = getDepartmentLeader(userDeptId);
bb.writeLog("userManagerId:"+userManagerId);
bb.writeLog("userDeptId:"+userDeptId);
bb.writeLog("deptLeaderId:"+deptLeaderId);
String leader_roleid = "30";
List<String> leaderList = queryHrmRoleUserByRole(leader_roleid);
String hr_roleid = "30";
List<String> hrList = queryHrmRoleUserByRole(hr_roleid);
if(leaderList.contains(currentUserId) || hrList.contains(currentUserId)){
bb.writeLog("allDeptLeaders:"+allDeptLeaders);
// String leader_roleid = "30";
// List<String> leaderList = queryHrmRoleUserByRole(leader_roleid);
// String hr_roleid = "29";
// List<String> hrList = queryHrmRoleUserByRole(hr_roleid);
//判断是否是指定角色29、30
boolean hasAccess = false;
HrmCommonService hrmCommonService = new HrmCommonServiceImpl();
List<String> roleIds = new ArrayList<>(Arrays.asList(hrmCommonService.getRoleIds(currentUserId).split(",")));
List<String> accessRoleIds = new ArrayList<>();
accessRoleIds.add("29");
accessRoleIds.add("30");
roleIds.retainAll(accessRoleIds);
hasAccess = CollectionUtils.isNotEmpty(roleIds);
new BaseBean().writeLog("currentUserId"+currentUserId+"roleIds"+roleIds+"hasAccess"+hasAccess);
if(hasAccess){
back = true;
}else if((","+deptLeaderId+",").contains(","+currentUserId+",")){
}else if((","+allDeptLeaders+",").contains(","+currentUserId+",")){
back = true;
}else if(String.valueOf(currentUserId).equals(userManagerId)){
back = true;
}else if(String.valueOf(currentUserId).equals(userid)){
//自己看自己可以看
back = true;
}else if(currentUserId == 1){
//系统管理员可以看所有
back = true;
}else{
back = false;
}
@ -3731,16 +3750,22 @@ public class HrmResourceBaseService extends BaseBean {
RecordSet rs = new RecordSet();
BaseBean bb = new BaseBean();
bb.writeLog("getDepartmentLeader:deptid:"+deptid);
String bmfzr = "";
String bmfzrs = "";
try {
String sql = " select bmfzr from hrmdepartmentdefined where deptid = ?";
String sql =" with tem_table(dep_id,departmentname,supdepid,curlevel) as (\n" +
" select id, departmentname,supdepid, 1 as level from HrmDepartment where id=" + deptid+
" union all\n" +
" select a.id,a.departmentname,a.supdepid,b.curlevel+1 from Hrmdepartment a inner join tem_table b on (a.id = b.supdepid)\n" +
" )\n" +
" select bmfzr from hrmdepartmentdefined where deptid in (select dep_id from tem_table)";
rs.executeQuery(sql,new Object[]{deptid});
if(rs.next()){
bmfzr = Util.null2String(rs.getString("bmfzr"));
while(rs.next()){
String bmfzr = Util.null2String(rs.getString("bmfzr"));
bmfzrs += StringUtils.isBlank(bmfzrs) ? bmfzr :","+bmfzr ;
}
}catch (Exception e){
bb.writeLog("e:"+e);
}
return bmfzr;
return bmfzrs;
}
}

@ -0,0 +1,73 @@
package weaver.interfaces.hzzx.cominfo;
import org.apache.commons.lang.StringUtils;
import weaver.conn.RecordSet;
import weaver.general.BaseBean;
import weaver.general.Util;
public class PropBean {
public static BaseBean bb = new BaseBean();
public static String active = Util.null2String(bb.getPropValue("developProp","active")).toUpperCase();
/***
*
* @param pkey
* @return
*/
public static String getUfPropValue(String pkey)
{
BaseBean baseBean = new BaseBean();
if(StringUtils.isEmpty(pkey)){
return "";
}
if(StringUtils.isEmpty(active)){
active = Util.null2String(baseBean.getPropValue("developProp","active")).toUpperCase();
}
String pvalue = "";
try{
RecordSet rs = new RecordSet();
String sql = " SELECT DEVVALUE,TESTVALUE,PRODVALUE FROM UF_PROP WHERE PKEY = ?";
rs.executeQuery(sql,new Object[]{pkey.trim()});
if(rs.next()){
pvalue = Util.null2String(rs.getString(active+"VALUE"));
}
}catch (Exception e){
e.printStackTrace();
bb.writeLog("propbean-e:"+e);
}
return pvalue;
}
/***
*
* @param pkey
* @return
*/
public String getUfPropValueStatic(String pkey)
{
BaseBean baseBean = new BaseBean();
if(StringUtils.isEmpty(pkey)){
return "";
}
String active = Util.null2String(baseBean.getPropValue("developProp","active")).toUpperCase();
String pvalue = "";
try{
RecordSet rs = new RecordSet();
String sql = " SELECT DEVVALUE,TESTVALUE,PRODVALUE FROM UF_PROP WHERE PKEY = ?";
rs.executeQuery(sql,new Object[]{pkey.trim()});
if(rs.next()){
pvalue = Util.null2String(rs.getString(active+"VALUE"));
}
baseBean.writeLog("pvalue:"+pvalue);
}catch (Exception e){
e.printStackTrace();
bb.writeLog("propbean-e:"+e);
}
return pvalue;
}
}
Loading…
Cancel
Save