绕过租户

This commit is contained in:
顾君禹
2025-09-12 14:34:08 +08:00
parent 1a3219c0db
commit b26968cc7c
4 changed files with 64 additions and 2 deletions

View File

@@ -178,4 +178,11 @@ public class UserController {
return success(userService.importUserList(list, updateSupport));
}
@PutMapping("/fix-tenant-id")
@Operation(summary = "修复用户租户ID", description = "为租户ID为空的用户设置当前租户ID")
@PreAuthorize("@ss.hasPermission('system:user:update')")
public CommonResult<Boolean> fixUserTenantId(@RequestParam("userId") Long userId) {
return success(userService.fixUserTenantId(userId));
}
}

View File

@@ -230,8 +230,15 @@ public class AdminAuthServiceImpl implements AdminAuthService {
// 创建访问令牌
OAuth2AccessTokenDO accessTokenDO = oauth2TokenService.createAccessToken(userId, getUserType().getValue(),
OAuth2ClientConstants.CLIENT_ID_DEFAULT, null);
// 获取用户信息并设置租户ID
AdminUserDO user = userService.getUser(userId);
if (user != null && user.getTenantId() != null) {
accessTokenDO.setTenantId(user.getTenantId());
} else {
log.warn("[createTokenAfterLoginSuccess][用户({}) 租户ID为空,可能导致登录后无法获取租户信息]", userId);
}
// 构建返回结果
return AuthConvert.INSTANCE.convert(accessTokenDO);
}
@@ -360,7 +367,6 @@ public class AdminAuthServiceImpl implements AdminAuthService {
user.setOpenid(reqVO.getOpenid());
userService.updateByid(user);
AuthLoginRespVO tokenAfterLoginSuccess = createTokenAfterLoginSuccess(user.getId(), user.getUsername(), LoginLogTypeEnum.LOGIN_SOCIAL);
tokenAfterLoginSuccess.setTenantId(user.getTenantId());
return tokenAfterLoginSuccess;
} catch (Exception e) {
log.error("[getPhoneNumber][解密手机号失败,encryptedData: {}, sessionKey: {}, iv: {}]",
@@ -392,6 +398,9 @@ public class AdminAuthServiceImpl implements AdminAuthService {
@Override
public AuthLoginRespVO getUserInfo(UserReqVO reqVO) {
AdminUserDO user = userService.getUserByMobile(reqVO.getPhone());
if (user == null) {
throw exception(USER_NOT_EXISTS);
}
// 创建 Token 令牌,记录登录日志
return createTokenAfterLoginSuccess(user.getId(), reqVO.getPhone(), LoginLogTypeEnum.LOGIN_USERNAME);
}

View File

@@ -215,4 +215,12 @@ public interface AdminUserService {
boolean isPasswordMatch(String rawPassword, String encodedPassword);
void updateByid(AdminUserDO user);
/**
* 修复用户租户ID
*
* @param userId 用户编号
* @return 是否修复成功
*/
Boolean fixUserTenantId(Long userId);
}

View File

@@ -12,6 +12,7 @@ import cn.iocoder.yudao.framework.common.util.collection.CollectionUtils;
import cn.iocoder.yudao.framework.common.util.object.BeanUtils;
import cn.iocoder.yudao.framework.common.util.validation.ValidationUtils;
import cn.iocoder.yudao.framework.datapermission.core.util.DataPermissionUtils;
import cn.iocoder.yudao.framework.tenant.core.context.TenantContextHolder;
import cn.iocoder.yudao.module.infra.api.config.ConfigApi;
import cn.iocoder.yudao.module.system.controller.admin.auth.vo.AuthRegisterReqVO;
import cn.iocoder.yudao.module.system.controller.admin.user.vo.profile.UserProfileUpdatePasswordReqVO;
@@ -161,6 +162,13 @@ public class AdminUserServiceImpl implements AdminUserService {
AdminUserDO user = BeanUtils.toBean(registerReqVO, AdminUserDO.class);
user.setStatus(CommonStatusEnum.ENABLE.getStatus()); // 默认开启
user.setPassword(encodePassword(registerReqVO.getPassword())); // 加密密码
// 设置租户ID
Long tenantId = TenantContextHolder.getTenantId();
if (tenantId != null) {
user.setTenantId(tenantId);
} else {
log.warn("[registerUser][注册用户时租户ID为空,可能导致用户无法正常访问系统]");
}
userMapper.insert(user);
return user.getId();
}
@@ -586,4 +594,34 @@ public class AdminUserServiceImpl implements AdminUserService {
return passwordEncoder.encode(password);
}
@Override
public Boolean fixUserTenantId(Long userId) {
// 获取用户信息
AdminUserDO user = userMapper.selectById(userId);
if (user == null) {
throw exception(USER_NOT_EXISTS);
}
// 如果用户已经有租户ID,则不需要修复
if (user.getTenantId() != null) {
log.info("[fixUserTenantId][用户已有租户ID,无需修复] 用户ID: {}, 租户ID: {}", userId, user.getTenantId());
return true;
}
// 获取当前租户ID
Long currentTenantId = TenantContextHolder.getTenantId();
if (currentTenantId == null) {
throw exception(USER_NOT_EXISTS, "当前租户上下文为空,无法修复用户租户ID");
}
// 更新用户的租户ID
AdminUserDO updateUser = new AdminUserDO();
updateUser.setId(userId);
updateUser.setTenantId(currentTenantId);
userMapper.updateById(updateUser);
log.info("[fixUserTenantId][用户租户ID修复成功] 用户ID: {}, 原租户ID: null, 新租户ID: {}", userId, currentTenantId);
return true;
}
}