Compare commits
410
Commits
1.0.0.RELEASE
...
master
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
115585c00d | ||
|
|
b208087f74 | ||
|
|
3debece5d3 | ||
|
|
97eda740fe | ||
|
|
372b0030c3 | ||
|
|
12c31a8e8a | ||
|
|
490f538261 | ||
|
|
9f64f7bdac | ||
|
|
96b93b08a1 | ||
|
|
3bfcd1d21f | ||
|
|
c55e47ba4d | ||
|
|
29c6e5dbb6 | ||
|
|
0ebc9394ad | ||
|
|
da453c839e | ||
|
|
3986210925 | ||
|
|
5bcc28a492 | ||
|
|
000330dbd7 | ||
|
|
ad7b79129e | ||
|
|
4da732538f | ||
|
|
041447585c | ||
|
|
49d1db3571 | ||
|
|
d9286699bf | ||
|
|
d5dd7302ad | ||
|
|
9561e8ae00 | ||
|
|
d9e690b5e9 | ||
|
|
d49b3c1a79 | ||
|
|
7340e45f4b | ||
|
|
ee8bf1cbfc | ||
|
|
634dabb8cc | ||
|
|
23db487356 | ||
|
|
c5b70d90fb | ||
|
|
552bf77924 | ||
|
|
ac1f82e81d | ||
|
|
41bda82c60 | ||
|
|
da5917344e | ||
|
|
feed91dcd0 | ||
|
|
5153daf7da | ||
|
|
155af93c77 | ||
|
|
0db36a6218 | ||
|
|
de4f2c6d52 | ||
|
|
fa6cc47063 | ||
|
|
c9b08a07f4 | ||
|
|
145ccbfb3e | ||
|
|
40d0ea956d | ||
|
|
184c4ad80d | ||
|
|
ba7cc42628 | ||
|
|
cb5e352e8d | ||
|
|
8a99864b41 | ||
|
|
de644f0f34 | ||
|
|
2ee703d2eb | ||
|
|
3c4377915b | ||
|
|
f9ad038805 | ||
|
|
e27fa53ec8 | ||
|
|
ed1f402c04 | ||
|
|
52838222db | ||
|
|
de36a9936a | ||
|
|
3bb59d3786 | ||
|
|
fa7e62b12b | ||
|
|
b6a64f15dc | ||
|
|
813363f0d4 | ||
|
|
517d6f3d7f | ||
|
|
83eb664a45 | ||
|
|
61be7a09c6 | ||
|
|
9f8fe2c83e | ||
|
|
830b9b246d | ||
|
|
d4a1b0ec57 | ||
|
|
43370ad078 | ||
|
|
22fa797809 | ||
|
|
1c6ac42b96 | ||
|
|
149f12ce18 | ||
|
|
a9b304ab5a | ||
|
|
b7833142b0 | ||
|
|
6def11b009 | ||
|
|
15b5fa4dd8 | ||
|
|
bbc545494b | ||
|
|
4b26a5ddcc | ||
|
|
a7e0b18396 | ||
|
|
da83a2a3f2 | ||
|
|
0037087c1e | ||
|
|
5266ea4fc6 | ||
|
|
dad768cb18 | ||
|
|
175b3f5f5b | ||
|
|
eb4f95e2bd | ||
|
|
a8642dcf29 | ||
|
|
1cadad5076 | ||
|
|
fabe7a09bf | ||
|
|
874084492e | ||
|
|
dff1cc18ce | ||
|
|
21408f1bf3 | ||
|
|
f59767096b | ||
|
|
57f2ce1413 | ||
|
|
60674d7ab7 | ||
|
|
e984df7cd0 | ||
|
|
1245dc541f | ||
|
|
61f82f826b | ||
|
|
5ea61e40d0 | ||
|
|
c09bca8419 | ||
|
|
05d19f1dad | ||
|
|
9aa7420da7 | ||
|
|
a476856ce1 | ||
|
|
009ab8effe | ||
|
|
749e25d22d | ||
|
|
8ca48511e9 | ||
|
|
2683e1214c | ||
|
|
af6fb5d273 | ||
|
|
2e806f1dcf | ||
|
|
8a51e19cc0 | ||
|
|
f02362859d | ||
|
|
a37e6928d2 | ||
|
|
dbb03e3e44 | ||
|
|
4a55d8feb2 | ||
|
|
9abb4ae6a9 | ||
|
|
09c210363e | ||
|
|
895377714c | ||
|
|
0db116d729 | ||
|
|
e4e04f5c1a | ||
|
|
db118f04ff | ||
|
|
201ba7915e | ||
|
|
7ea6fd0f58 | ||
|
|
fa48eac75a | ||
|
|
e199410bcb | ||
|
|
c058e03fbf | ||
|
|
10ae5f39f0 | ||
|
|
dbea226c89 | ||
|
|
442279ab0d | ||
|
|
a2c6de82df | ||
|
|
757bafa8d2 | ||
|
|
4cabce3a8b | ||
|
|
c8140399c4 | ||
|
|
5596f32940 | ||
|
|
6cd58bbd9d | ||
|
|
90b6564ce6 | ||
|
|
917579684e | ||
|
|
4e7a85bead | ||
|
|
d71e2e220f | ||
|
|
f60a7dfd85 | ||
|
|
b3b5547116 | ||
|
|
3690b8c22a | ||
|
|
c6b71d2dfe | ||
|
|
47dffad5a7 | ||
|
|
c760302ff8 | ||
|
|
384385dd10 | ||
|
|
7c68c8f572 | ||
|
|
c035e024e4 | ||
|
|
7743580873 | ||
|
|
d4dcb55a36 | ||
|
|
7ce0e0192e | ||
|
|
1cf2a6a2e2 | ||
|
|
8e4d9a9151 | ||
|
|
65bf586d0c | ||
|
|
9896d87968 | ||
|
|
9d618d1fde | ||
|
|
12a6baf599 | ||
|
|
157a83711f | ||
|
|
0d0998ec3c | ||
|
|
7ceb114822 | ||
|
|
acc1b7d10b | ||
|
|
6685310b5f | ||
|
|
631d86e22a | ||
|
|
f45d202af6 | ||
|
|
85d60365cf | ||
|
|
1c4edb9cee | ||
|
|
251cd14810 | ||
|
|
575fc3fa88 | ||
|
|
31a6c83222 | ||
|
|
a340533ff9 | ||
|
|
361e3c1bba | ||
|
|
5b5e989f8a | ||
|
|
6092922bc2 | ||
|
|
c2d12db216 | ||
|
|
392301bec5 | ||
|
|
39b8a43685 | ||
|
|
08713149b1 | ||
|
|
cbe5894c1d | ||
|
|
72bf49d19e | ||
|
|
1c11295163 | ||
|
|
9e6b085ac5 | ||
|
|
a1a318da44 | ||
|
|
c86488d5bd | ||
|
|
a88af0091b | ||
|
|
0569d32784 | ||
|
|
d71f8ce368 | ||
|
|
787c657818 | ||
|
|
5c9d8f4c36 | ||
|
|
7e6d48510c | ||
|
|
4a93167036 | ||
|
|
ab4a13bd4f | ||
|
|
4e20962935 | ||
|
|
964d81a377 | ||
|
|
e18a50ba30 | ||
|
|
34f12842b0 | ||
|
|
24aed42d69 | ||
|
|
0b4dbf4259 | ||
|
|
38301b8376 | ||
|
|
347ee49d46 | ||
|
|
5d10a304b3 | ||
|
|
2364ebb519 | ||
|
|
c5a8a1a653 | ||
|
|
186cc7e5a1 | ||
|
|
43fd86a2ce | ||
|
|
08b2249e45 | ||
|
|
bced84f92d | ||
|
|
269cc154ab | ||
|
|
ac333f6027 | ||
|
|
16e04fd8f2 | ||
|
|
75adf7393c | ||
|
|
2a523a3b41 | ||
|
|
990b8dd73e | ||
|
|
3a73465365 | ||
|
|
df756f9f0b | ||
|
|
fb993d3ade | ||
|
|
0fb0937a8e | ||
|
|
7c91bb3e0d | ||
|
|
c849c5cfed | ||
|
|
c0b179eff1 | ||
|
|
910227ef0c | ||
|
|
3dcc167c27 | ||
|
|
bf7f826250 | ||
|
|
25abd7e564 | ||
|
|
035dd21d11 | ||
|
|
9c920fefcc | ||
|
|
8e9d3519e4 | ||
|
|
e2ec08df62 | ||
|
|
6ef0de9d9e | ||
|
|
c7448f7833 | ||
|
|
a3c9ba1e3a | ||
|
|
54ac9cefa3 | ||
|
|
196d53aa88 | ||
|
|
67b1462453 | ||
|
|
0ad00448d8 | ||
|
|
5b8c441b8b | ||
|
|
7f7e142dc4 | ||
|
|
d36d312c9b | ||
|
|
b92c450be4 | ||
|
|
7bef64f632 | ||
|
|
133774ced7 | ||
|
|
51db1944ed | ||
|
|
23aebc2513 | ||
|
|
417471bd79 | ||
|
|
61f0ea26a0 | ||
|
|
54a9acaf18 | ||
|
|
d6404fc1b4 | ||
|
|
d4a298234d | ||
|
|
bd494c5aa1 | ||
|
|
0e5a389c12 | ||
|
|
b178f7fea5 | ||
|
|
2c89cdb344 | ||
|
|
9189e0cb58 | ||
|
|
7368cb58b7 | ||
|
|
627c51df8a | ||
|
|
3bf759aaac | ||
|
|
7d406a9b06 | ||
|
|
42895b182f | ||
|
|
21ba21bdf6 | ||
|
|
18d773ed9b | ||
|
|
f1fc957e3d | ||
|
|
fd42cae20f | ||
|
|
0b3406b55e | ||
|
|
1b63075333 | ||
|
|
2c94ad94e6 | ||
|
|
83964bfa78 | ||
|
|
b2207e277f | ||
|
|
017272cbde | ||
|
|
f6d7d7d84c | ||
|
|
123f62f9d5 | ||
|
|
656548eb64 | ||
|
|
60cf94cc05 | ||
|
|
883e7f88d5 | ||
|
|
078b838374 | ||
|
|
490302960a | ||
|
|
d865081199 | ||
|
|
8e356923c7 | ||
|
|
c811b895d7 | ||
|
|
8c4039dbb2 | ||
|
|
8ca32d3d77 | ||
|
|
dc1e9afe0c | ||
|
|
6220f979bf | ||
|
|
6ec05fd3f9 | ||
|
|
8c3e43b85b | ||
|
|
248145b821 | ||
|
|
261a983678 | ||
|
|
1a7e457054 | ||
|
|
7ae59415e8 | ||
|
|
c50d5e7921 | ||
|
|
af873bf45e | ||
|
|
4384a3000c | ||
|
|
72a951a2b6 | ||
|
|
38a5136e69 | ||
|
|
96dbeb0cbd | ||
|
|
936c37c65c | ||
|
|
e51c86c83f | ||
|
|
71a25f4774 | ||
|
|
56563657e8 | ||
|
|
6bfb10e4a4 | ||
|
|
70cb8eb35b | ||
|
|
cdea48c7d4 | ||
|
|
fba22bbcbf | ||
|
|
14f96abdb3 | ||
|
|
28ff95bf0d | ||
|
|
6cee5a6104 | ||
|
|
3add95e910 | ||
|
|
1db1064c11 | ||
|
|
f75928119e | ||
|
|
9051e8138c | ||
|
|
8396f49105 | ||
|
|
c664c70bbc | ||
|
|
7a503cd94a | ||
|
|
7a9aeec8db | ||
|
|
2c57bc36ea | ||
|
|
c0fc70425b | ||
|
|
f95944a781 | ||
|
|
589e0c8ce7 | ||
|
|
6e0ff64893 | ||
|
|
044e432eb7 | ||
|
|
5887079ade | ||
|
|
724e0817a5 | ||
|
|
9caa7a22e5 | ||
|
|
c2042d5f80 | ||
|
|
51f17c9539 | ||
|
|
27ed99ee27 | ||
|
|
7eb41e9754 | ||
|
|
c7f266a482 | ||
|
|
f2d444b877 | ||
|
|
9e59035300 | ||
|
|
b0ed2100a2 | ||
|
|
6f0c86fba6 | ||
|
|
c71562a12f | ||
|
|
a7fa415545 | ||
|
|
24d2523385 | ||
|
|
d30a3d79de | ||
|
|
860d5778cc | ||
|
|
23dbe9ee9c | ||
|
|
9114964ef2 | ||
|
|
56615528b9 | ||
|
|
1b5c54daf9 | ||
|
|
c0a3f5243b | ||
|
|
d22eb22f74 | ||
|
|
7eeb4c2489 | ||
|
|
d691c444ae | ||
|
|
83c23ea276 | ||
|
|
cff67d152f | ||
|
|
ad67c289d3 | ||
|
|
4a4d8f763d | ||
|
|
dfc734c13a | ||
|
|
654f441d05 | ||
|
|
48eebc1c95 | ||
|
|
3c1764e58d | ||
|
|
233241c962 | ||
|
|
30f9774ab1 | ||
|
|
a255c746d4 | ||
|
|
eac2a1c941 | ||
|
|
110a5faaff | ||
|
|
f3cfdcf580 | ||
|
|
34a1066cd0 | ||
|
|
67d05c39f3 | ||
|
|
fa49130c4f | ||
|
|
5b76973d9c | ||
|
|
0d57a2a8f2 | ||
|
|
78b7dae880 | ||
|
|
04a89144ba | ||
|
|
3b3eecc1d1 | ||
|
|
ca92d949dd | ||
|
|
663c7925e3 | ||
|
|
76b2ad6f58 | ||
|
|
fd8dcfee40 | ||
|
|
0a60c1960d | ||
|
|
28021df2ab | ||
|
|
6d42b6d56c | ||
|
|
3b467f42fe | ||
|
|
e37749c669 | ||
|
|
2cbbf25060 | ||
|
|
986ae4e4bc | ||
|
|
103aaf4911 | ||
|
|
7038ce64a6 | ||
|
|
9b8525ca1e | ||
|
|
254ce53387 | ||
|
|
0ff0c456b0 | ||
|
|
57a54090bb | ||
|
|
e3d3424ee1 | ||
|
|
99b2f611ec | ||
|
|
a675d78b82 | ||
|
|
62bd10cc60 | ||
|
|
9e8a5357be | ||
|
|
5faf88283f | ||
|
|
14a32e6d3c | ||
|
|
5e08f3e49b | ||
|
|
d9a5bcb0de | ||
|
|
48633729fb | ||
|
|
f274e060f4 | ||
|
|
9784f7816a | ||
|
|
f93a36c094 | ||
|
|
375d3a10b2 | ||
|
|
a1fbf5a0ae | ||
|
|
10035cc158 | ||
|
|
3b1150ad1f | ||
|
|
73222e854c | ||
|
|
3db99422b7 | ||
|
|
d876c8309f | ||
|
|
e0738aa5b2 | ||
|
|
f051693690 | ||
|
|
c6ffbbc062 | ||
|
|
2836fc1139 | ||
|
|
e111f4a763 | ||
|
|
3d5e4b9e9b | ||
|
|
8f4054e576 | ||
|
|
3ea4edd117 | ||
|
|
2f0df0a700 | ||
|
|
a709095dc2 | ||
|
|
4a8ac0ac83 | ||
|
|
b9301046da |
@@ -0,0 +1,11 @@
|
||||
# 构建的相关文件
|
||||
README.md
|
||||
|
||||
# Python 相关文件
|
||||
migrations/
|
||||
instance/
|
||||
flask_session/
|
||||
venv/
|
||||
.idea/
|
||||
*.log
|
||||
*.db
|
||||
+17
-2
@@ -114,5 +114,20 @@ dmypy.json
|
||||
# Pyre type checker
|
||||
.pyre/
|
||||
|
||||
#ide
|
||||
.idea/
|
||||
# idea
|
||||
.idea/
|
||||
|
||||
# 迁移文件
|
||||
migrations/
|
||||
|
||||
# sqlite
|
||||
*.db
|
||||
|
||||
# 文件上传
|
||||
static/upload/
|
||||
|
||||
# flask session
|
||||
flask_session/
|
||||
|
||||
# WorkBuddy 运行时目录(不应纳入版本管理)
|
||||
.workbuddy/
|
||||
@@ -1,23 +1,21 @@
|
||||
<div align="center">
|
||||
<br/>
|
||||
<br/>
|
||||
<img src="https://gitee.com/pear-admin/Pear-Admin-Layui/raw/master/admin/images/logo.png" width="90px" style="margin-top:30px;"/>
|
||||
<h1 align="center">
|
||||
Pear Admin Flask
|
||||
</h1>
|
||||
<h4 align="center">
|
||||
开 箱 即 用 的 Flask 快 速 开 发 平 台
|
||||
</h4>
|
||||
|
||||
[预 览](http://flask.pearadmin.com) | [官 网](http://www.pearadmin.com/) | [群聊](https://jq.qq.com/?_wv=1027&k=5OdSmve) | [社区](http://forum.pearadmin.com/)
|
||||
</h4>
|
||||
|
||||
[预览](https://pear.lovepikachu.top/) | [官网](http://www.pearadmin.com/) | [群聊](docs/source/_static/qqgroup.jpg) | [文档](https://lab.lovepikachu.top/document/pear-admin-flask)
|
||||
|
||||
<p align="center">
|
||||
<a href="#">
|
||||
<img src="https://img.shields.io/badge/pear%20admin%20flask-1.0.0-green" alt="Pear Admin Layui Version">
|
||||
<img src="https://img.shields.io/badge/pear%20admin%20flask-2.0.0-green" alt="Pear Admin Layui Version">
|
||||
</a>
|
||||
<a href="#">
|
||||
<img src="https://img.shields.io/badge/Python-3.6+-green.svg" alt="Python Version">
|
||||
<img src="https://img.shields.io/badge/Python-3.8+-green.svg" alt="Python Version">
|
||||
</a>
|
||||
<a href="#">
|
||||
<img src="https://img.shields.io/badge/Mysql-5.3.2+-green.svg" alt="Mysql Version">
|
||||
@@ -26,23 +24,19 @@
|
||||
</div>
|
||||
|
||||
<div align="center">
|
||||
<img width="92%" style="border-radius:10px;margin-top:20px;margin-bottom:20px;box-shadow: 2px 0 6px gray;" src="https://images.gitee.com/uploads/images/2020/1019/104805_042b888c_4835367.png" />
|
||||
<img width="92%" style="border-radius:10px;margin-top:20px;margin-bottom:20px;box-shadow: 2px 0 6px gray;" src="docs/source/_static/feature.png" />
|
||||
</div>
|
||||
|
||||
#### 项目简介
|
||||
>Pear Admin Flask 基于 Flask 的后台管理系统,拥抱应用广泛的python语言,通过使用本系统,即可快速构建你的功能业务
|
||||
>
|
||||
>项目旨在为python开发者提供一个后台管理系统的模板,成为您构建信息管理系统,物联网后台....等等应用时灵活,简单的工具
|
||||
>
|
||||
>各位Python爱好者多多指教
|
||||
# 项目简介
|
||||
|
||||
Pear Admin Flask 分为 Common / Simple 两个版本:
|
||||
> **⚠️注意** Pear Admin Flask 已同步主项目 Pear Admin Layui 4.0,部分页面变化较大,如果是从旧的框架迁移,请查阅 [从旧项目迁移](https://lab.lovepikachu.top/document/pear-admin-flask/welcome/migration.html) 章节。另外,可以在此查看 [更新日志](https://lab.lovepikachu.top/document/pear-admin-flask/welcome/update.html#v2-0-0-4-0-5) 。
|
||||
|
||||
[** Common 通用版本 **](https://gitee.com/pear-admin/pear-admin-flask/tree/master/)
|
||||
Pear Admin Flask 基于 Flask 的后台管理系统,拥抱应用广泛的python语言,通过使用本系统,即可快速构建你的功能业务
|
||||
项目旨在为 python 开发者提供一个后台管理系统的模板,可以快速构建信息管理系统。
|
||||
|
||||
[** Simple 简洁版本 **](https://gitee.com/pear-admin/pear-admin-flask/tree/simple/)
|
||||
项目使用 flask-sqlalchemy + 权限验证 + marshmallow 序列化与数据验证,以此方式集成了若干不同的功能。
|
||||
|
||||
#### 内置功能
|
||||
# 内置功能
|
||||
|
||||
- [x] 用户管理:用户是系统操作者,该功能主要完成系统用户配置。
|
||||
- [x] 权限管理:配置系统菜单,操作权限,按钮权限标识等。
|
||||
@@ -51,162 +45,192 @@ Pear Admin Flask 分为 Common / Simple 两个版本:
|
||||
- [x] 登录日志:系统登录日志记录查询包含登录异常。
|
||||
- [x] 服务监控:监视当前系统CPU、内存、磁盘、python版本,运行时长等相关信息。
|
||||
- [x] 文件上传: 图片上传示例
|
||||
- [ ] 代码生成: 构想中....
|
||||
|
||||
#### 项目结构
|
||||
# 项目分支说明
|
||||
|
||||
> **⚠️注意** Pear Admin Flask 不仅仅只提供一种对于 Pear Admin 后端的实现方式,所以提供了不同的分支版本,不同分支版本各有其优劣,并且由不同的开发者维护。
|
||||
|
||||
| 分支名称 | 特点 |
|
||||
|------------------------------------------------------------------|------------------------|
|
||||
| master(您目前浏览的分支版本) | 功能齐全,处于开发阶段,代码量较大。 |
|
||||
| [main](https://gitee.com/pear-admin/pear-admin-flask/tree/main/) | 功能精简,代码量小,处于开发阶段,易于维护。 |
|
||||
| [mini](https://gitee.com/pear-admin/pear-admin-flask/tree/mini/) | 不再更新,是最初版本的镜像。 |
|
||||
|
||||
|
||||
> **⚠️注意** 由于 master 分支项目需要,暂时移除了 Flask-APScheduler 定时任务 功能。
|
||||
|
||||
# 版本支持情况
|
||||
|
||||
经过测试,此项目的(master分支)运行要求是 `>= Python 3.8` ,推荐使用 `Python 3.11`。
|
||||
|
||||
> **💡提示** 由于 Flask 中使用的 Werkzeug 模块更新,Flask 官方并未进行更新,所以可能会出现 ImportError 。
|
||||
> 此类情况的出现可以通过正确安装 `requirements.txt` 中的模块(以及其对应版本)解决。
|
||||
|
||||
# 项目结构
|
||||
|
||||
## 应用结构
|
||||
|
||||
```应用结构
|
||||
Pear Admin Flask (master)
|
||||
├─applications # 项目核心模块
|
||||
│ ├─common # 公共模块(初始化数据库、公用函数)
|
||||
│ ├─extensions # 注册项目插件
|
||||
│ ├─schemas # 序列化模型
|
||||
│ ├─models # 数据库模型
|
||||
│ ├─views # 视图部分
|
||||
│ ├─config.py # 项目配置
|
||||
│ └─__init__.py # 项目初始化入口
|
||||
├─docs # 文档说明
|
||||
├─static # 静态资源文件
|
||||
├─templates # 静态模板文件
|
||||
└─app.py # 程序入口
|
||||
```
|
||||
|
||||
## 资源结构
|
||||
|
||||
```资源结构
|
||||
Pear Admin Flask
|
||||
│
|
||||
├─applications
|
||||
│ │
|
||||
│ ├─config
|
||||
│ │ │
|
||||
│ │ ├─ common.py #普通配置
|
||||
│ │ │
|
||||
│ │ └─ database.py #数据库配置
|
||||
│ │
|
||||
│ ├─models
|
||||
│ │ │
|
||||
│ │ └─admin.py #基本模型
|
||||
│ │
|
||||
│ ├─service
|
||||
│ │ │
|
||||
│ │ ├─admin
|
||||
│ │ │ │
|
||||
│ │ │ ├─ file.py #file视图的数据操作
|
||||
│ │ │ │
|
||||
│ │ │ ├─ index.py #index视图的数据操作
|
||||
│ │ │ │
|
||||
│ │ │ ├─ power.py #power视图的数据操作
|
||||
│ │ │ │
|
||||
│ │ │ ├─ role.py #role视图的数据操作
|
||||
│ │ │ │
|
||||
│ │ │ └─ user.py #user视图的数据操作
|
||||
│ │ │
|
||||
│ │ ├─ admin_log.py #存储日志
|
||||
│ │ │
|
||||
│ │ ├─ deBug.py #deBug工具栏初始化
|
||||
│ │ │
|
||||
│ │ ├─ login.py #flask_login初始化
|
||||
│ │ │
|
||||
│ │ ├─ CaptchaTool.py #验证码
|
||||
│ │ │
|
||||
│ │ ├─ OriginalDb.py #原生sql查询封装
|
||||
│ │ │
|
||||
│ │ ├─ route_auth.py #权限
|
||||
│ │ │
|
||||
│ │ └─ upload.py #上传
|
||||
│ │
|
||||
│ └─views
|
||||
│ │
|
||||
│ ├─admin #前台视图
|
||||
│ │ │
|
||||
│ │ ├─index.py #主视图
|
||||
│ │ │
|
||||
│ │ ├─user.py #用户视图
|
||||
│ │ │
|
||||
│ │ ├─role.py #角色视图
|
||||
│ │ │
|
||||
│ │ ├─power.py #权限视图
|
||||
│ │ │
|
||||
│ │ ├─monitor.py #系统监控
|
||||
│ │ │
|
||||
│ │ ├─file.py #文件上传
|
||||
│ │ │
|
||||
│ │ ├─admin_log.py #系统日志
|
||||
│ │ │
|
||||
│ │ ├─context_processor.py #全局模板函数注册
|
||||
│ │ │
|
||||
│ │ ├─error.py #错误处理
|
||||
│ │ │
|
||||
│ │ └─init.py #蓝图注册
|
||||
│ │
|
||||
│ └─index #前台视图
|
||||
│
|
||||
├─dev #数据库初始化
|
||||
│
|
||||
├─migrations
|
||||
│
|
||||
├─readmes
|
||||
│
|
||||
├─static #静态资源
|
||||
│ │
|
||||
│ └─upload #文件上传地址
|
||||
│
|
||||
└─templates
|
||||
│
|
||||
├─admin #前台模板
|
||||
│
|
||||
├─errors #错误模板
|
||||
│
|
||||
└─index #前台模板
|
||||
├─static # 项目设定的 Flask 资源文件夹
|
||||
│ ├─admin # pear admin flask 的后端资源文件(与 pear admin layui 同步)
|
||||
│ ├─index # pear admin flask 的前端资源文件
|
||||
│ └─upload # 用户上传保存目录
|
||||
└─templates # 项目设定的 Flask 模板文件夹
|
||||
├─admin # pear admin flask 的后端管理页面模板
|
||||
│ ├─admin_log # 日志页面
|
||||
│ ├─common # 基本模板页面(头部模板与页脚模板)
|
||||
│ ├─console # 系统监控页面模板
|
||||
│ ├─dept # 部门管理页面模板
|
||||
│ ├─dict # 数据字典页面模板
|
||||
│ ├─mail # 邮件管理页面模板
|
||||
│ ├─photo # 图片上传页面模板
|
||||
│ ├─power # 权限(菜单)管理页面模板
|
||||
│ ├─role # 角色管理页面模板
|
||||
│ ├─task # 任务设置页面模板
|
||||
│ └─user # 用户管理页面模板
|
||||
├─errors # 错误页面模板
|
||||
└─index # 主页模板
|
||||
```
|
||||
|
||||
# 项目安装
|
||||
|
||||
|
||||
#### 项目安装
|
||||
## 从仓库获取
|
||||
|
||||
```bash
|
||||
# 下 载
|
||||
# 克隆仓库 / 手动下载
|
||||
git clone https://gitee.com/pear-admin/pear-admin-flask
|
||||
|
||||
# 安 装
|
||||
pip install -r requirement.txt
|
||||
|
||||
# 配 置
|
||||
applications\config\database.py
|
||||
|
||||
cd pear-admin-flask # 进入到项目目录
|
||||
```
|
||||
|
||||
#### 修改配置
|
||||
## 修改配置
|
||||
|
||||
> **💡提示** 配置文件位于 `applications/config.py` ,打开配置文件看到的是位于 `BaseConfig` 类下的默认配置文件,您可以编写自己的配置类并继承 `BaseConfig` 类。
|
||||
项目启动时,会调用 `applications/__init__.py` ,这个文件中加载了程序的配置,所以在您编写了自己的类后不要忘记在文件 `applications/__init__.py` 中修改使用的配置类。
|
||||
|
||||
> **⚠️注意** 配置文件中对于数据库的配置有所更改,请查看代码中的注释修改配置。
|
||||
|
||||
```python
|
||||
# 主 机
|
||||
HOST = '127.0.0.1'
|
||||
# 部分配置信息如下所示
|
||||
|
||||
# 端 口
|
||||
PORT = '3306'
|
||||
# 验证密钥(⚠️ 一定要记得修改 ⚠️)
|
||||
SECRET_KEY = "pear-system-flask"
|
||||
|
||||
# 数 据 库
|
||||
DATABASE = 'PearAdminFlask'
|
||||
# 数据库的配置信息
|
||||
SQLALCHEMY_DATABASE_URI = 'sqlite:///../pear.db'
|
||||
|
||||
# 账 户
|
||||
USERNAME = 'root'
|
||||
|
||||
# 密 码
|
||||
PASSWORD = 'root'
|
||||
# 默认日志等级
|
||||
LOG_LEVEL = logging.WARN
|
||||
|
||||
# flask-mail配置
|
||||
MAIL_SERVER = 'smtp.qq.com'
|
||||
MAIL_USE_TLS = False
|
||||
MAIL_USE_SSL = True
|
||||
MAIL_PORT = 465
|
||||
MAIL_USERNAME = '123@qq.com'
|
||||
MAIL_PASSWORD = 'XXXXX' # 生成的授权码
|
||||
MAIL_DEFAULT_SENDER = MAIL_USERNAME
|
||||
```
|
||||
|
||||
#### Venv 安装
|
||||
|
||||
## 虚拟环境安装项目(推荐)
|
||||
|
||||
> **💡提示** 为了保证项目所依赖的库不影响其他部署在同一主机上的项目,我们推荐使用虚拟环境安装。
|
||||
|
||||
```bash
|
||||
python -m venv venv
|
||||
|
||||
# 进入虚拟环境下
|
||||
venv\Scripts\activate.bat # Windows 提示命令符
|
||||
venv\Scripts\Activate.ps1 # Windows Powershell
|
||||
source venv/bin/activate # Linux
|
||||
|
||||
# 使用 pip 安装
|
||||
pip install -r requirements.txt
|
||||
```
|
||||
|
||||
#### 运行项目
|
||||
## 直接安装项目
|
||||
|
||||
```bash
|
||||
# 进 入 目 录
|
||||
cd dev
|
||||
|
||||
# 初 始 化 数 据 库
|
||||
python initDb.py
|
||||
|
||||
# 如 果 报 模 块 路 径 错 误
|
||||
python dev/initDb.py
|
||||
|
||||
# 使用 pip 安装
|
||||
pip install -r requirements.txt
|
||||
# 同时你可以选择以模块的方式调用 pip
|
||||
python -m pip install -r requirements.txt
|
||||
```
|
||||
|
||||
执行 flask run 命令启动项目
|
||||
# 运行项目
|
||||
|
||||
+ 一般情况运行项目
|
||||
|
||||
```bash
|
||||
# 初始化数据库
|
||||
flask db init
|
||||
flask db migrate
|
||||
flask db upgrade
|
||||
flask admin init
|
||||
|
||||
# 运行项目
|
||||
flask --app app.py run -h 0.0.0.0 -p 8000 --debug
|
||||
|
||||
# 或者直接调用 app.py
|
||||
python app.py
|
||||
```
|
||||
|
||||
+ 使用 docker-compose 运行项目
|
||||
|
||||
```bash
|
||||
git clone https://gitee.com/pear-admin/pear-admin-flask
|
||||
|
||||
# 安装 docker-compose
|
||||
curl -L https://github.com/docker/compose/releases/download/1.26.2/docker-compose-`uname -s`-`uname -m` > /usr/local/bin/docker-compose
|
||||
chmod +x /usr/local/bin/docker-compose
|
||||
ln -s /usr/local/bin/docker-compose /usr/bin/docker-compose
|
||||
|
||||
# 运行如下命令,有输出版本,表示 docker-compose 可以用了
|
||||
docker-compose --version
|
||||
|
||||
# 在当前目录执行如下命令即可以运行 app
|
||||
docker-compose -f dockercompose.yaml up
|
||||
|
||||
# 看到如下表示运行成功,由于 pip 下载慢,需要一些时间,请耐心等待;如果安装失败,重新执行上面的命令即可。
|
||||
|
||||
# 运行后在浏览器访问 127.0.0.1:5000
|
||||
|
||||
#如果要停止容器运行,在当前文件夹执行如下命令:
|
||||
docker-compose -f dockercompose.yaml down
|
||||
```
|
||||
|
||||
|
||||
#### 预览项目
|
||||
# 预览项目
|
||||
|
||||
| | |
|
||||
| ---------------------- | ---------------------- |
|
||||
|  |  |
|
||||
|  |  |
|
||||
|
||||
|
||||
# 其他说明
|
||||
|
||||
## 项目初始用户以及其密码
|
||||
|
||||
默认用户为 `admin` ,密码默认为 `123456` 。
|
||||
|
||||
|
||||
| | |
|
||||
|---------------------|---------------------|
|
||||
|  |  |
|
||||
| |  |
|
||||
|  |  |
|
||||
@@ -0,0 +1,6 @@
|
||||
from applications import create_app
|
||||
|
||||
app = create_app()
|
||||
|
||||
if __name__ == '__main__':
|
||||
app.run()
|
||||
@@ -0,0 +1,24 @@
|
||||
import os
|
||||
from flask import Flask
|
||||
from applications.common.script import init_script
|
||||
from applications.config import BaseConfig
|
||||
from applications.extensions import init_plugs
|
||||
from applications.view import init_bps
|
||||
|
||||
|
||||
def create_app():
|
||||
app = Flask(os.path.abspath(os.path.join(os.path.dirname(__file__), "..")))
|
||||
|
||||
# 引入配置
|
||||
app.config.from_object(BaseConfig)
|
||||
|
||||
# 注册flask组件
|
||||
init_plugs(app)
|
||||
|
||||
# 注册蓝图
|
||||
init_bps(app)
|
||||
|
||||
# 注册命令
|
||||
init_script(app)
|
||||
|
||||
return app
|
||||
|
||||
@@ -0,0 +1,96 @@
|
||||
from io import BytesIO
|
||||
from flask import make_response
|
||||
from flask_login import current_user
|
||||
|
||||
from applications.common.utils.validate import str_escape
|
||||
from applications.common.utils.captcha import vieCode
|
||||
from applications.extensions import db
|
||||
from applications.models import AdminLog
|
||||
|
||||
|
||||
def get_captcha():
|
||||
"""
|
||||
生成验证码图片及其对应的验证码字符串。
|
||||
|
||||
:return: 返回验证码图片的响应对象和验证码字符串。
|
||||
"""
|
||||
image, code = vieCode().GetCodeImage()
|
||||
code = ''.join(code).lower()
|
||||
out = BytesIO()
|
||||
image.save(out, 'png')
|
||||
out.seek(0)
|
||||
resp = make_response(out.read())
|
||||
resp.content_type = 'image/png'
|
||||
return resp, code
|
||||
|
||||
|
||||
def normal_log(method, url, ip, user_agent, desc, uid, is_access):
|
||||
"""
|
||||
记录通用日志信息到数据库。
|
||||
|
||||
:param method: 请求方法(如 GET、POST)。
|
||||
:param url: 请求的 URL。
|
||||
:param ip: 客户端的 IP 地址。
|
||||
:param user_agent: 客户端的 User-Agent 信息。
|
||||
:param desc: 日志描述信息。
|
||||
:param uid: 用户 ID。
|
||||
:param is_access: 是否成功访问(True 或 False)。
|
||||
:return: 返回日志记录的 ID。
|
||||
"""
|
||||
info = {
|
||||
'method': method,
|
||||
'url': url,
|
||||
'ip': ip,
|
||||
'user_agent': user_agent,
|
||||
'desc': desc,
|
||||
'uid': uid,
|
||||
'success': int(is_access)
|
||||
}
|
||||
log = AdminLog(
|
||||
url=info.get('url'),
|
||||
ip=info.get('ip'),
|
||||
user_agent=info.get('user_agent'),
|
||||
desc=info.get('desc'),
|
||||
uid=info.get('uid'),
|
||||
method=info.get('method'),
|
||||
success=info.get('success')
|
||||
)
|
||||
db.session.add(log)
|
||||
db.session.commit()
|
||||
return log.id
|
||||
|
||||
|
||||
def login_log(request, uid, is_access):
|
||||
"""
|
||||
记录用户登录日志。
|
||||
|
||||
:param request: Flask 请求对象。
|
||||
:param uid: 用户 ID。
|
||||
:param is_access: 是否成功登录(True 或 False)。
|
||||
:return: 返回日志记录的 ID。
|
||||
"""
|
||||
method = request.method
|
||||
url = request.path
|
||||
ip = request.remote_addr
|
||||
user_agent = str_escape(request.headers.get('User-Agent'))
|
||||
desc = str_escape(request.form.get('username'))
|
||||
return normal_log(method, url, ip, user_agent, desc, uid, is_access)
|
||||
|
||||
|
||||
def admin_log(request, is_access, desc=None):
|
||||
"""
|
||||
记录管理员操作日志。
|
||||
|
||||
:param request: Flask 请求对象。
|
||||
:param is_access: 是否成功操作(True 或 False)。
|
||||
:param desc: 日志描述信息(可选)。如果未提供,则从请求数据中提取。
|
||||
:return: 返回日志记录的 ID。
|
||||
"""
|
||||
method = request.method
|
||||
url = request.path
|
||||
ip = request.remote_addr
|
||||
user_agent = str_escape(request.headers.get('User-Agent'))
|
||||
request_data = request.json if request.headers.get('Content-Type') == 'application/json' else request.values
|
||||
if desc is None:
|
||||
desc = str_escape(str(dict(request_data)))
|
||||
return normal_log(method, url, ip, user_agent, desc, current_user.id, is_access)
|
||||
@@ -0,0 +1,119 @@
|
||||
import datetime
|
||||
from marshmallow import Schema
|
||||
from marshmallow_sqlalchemy import SQLAlchemyAutoSchema
|
||||
from applications.extensions import db, ma
|
||||
|
||||
|
||||
class LogicalDeleteMixin(object):
|
||||
"""
|
||||
逻辑删除混入类,为模型提供软删除功能。
|
||||
|
||||
示例:
|
||||
class Test(db.Model, LogicalDeleteMixin):
|
||||
__tablename__ = 'admin_test'
|
||||
id = db.Column(db.Integer, primary_key=True, comment='角色ID')
|
||||
|
||||
# 软删除
|
||||
Test.query.filter_by(id=1).soft_delete()
|
||||
|
||||
# 查询所有未删除的记录
|
||||
Test.query.logic_all()
|
||||
"""
|
||||
create_at = db.Column(db.DateTime, default=datetime.datetime.now, comment='创建时间')
|
||||
update_at = db.Column(db.DateTime, default=datetime.datetime.now, onupdate=datetime.datetime.now, comment='更新时间')
|
||||
delete_at = db.Column(db.DateTime, comment='删除时间')
|
||||
|
||||
|
||||
def auto_model_jsonify(data, model: db.Model):
|
||||
"""
|
||||
自动序列化模型数据为 JSON 格式,无需手动定义 Schema。
|
||||
|
||||
示例:
|
||||
power_data = curd.auto_model_jsonify(model=Dept, data=dept)
|
||||
|
||||
:param data: 需要序列化的 SQLAlchemy 查询结果。
|
||||
:param model: SQLAlchemy 模型类。
|
||||
:return: 返回序列化后的 JSON 数据。
|
||||
"""
|
||||
def get_model():
|
||||
return model
|
||||
|
||||
class AutoSchema(SQLAlchemyAutoSchema):
|
||||
class Meta(Schema):
|
||||
model = get_model()
|
||||
include_fk = True # 包含外键
|
||||
include_relationships = True # 包含关联关系
|
||||
load_instance = True # 反序列化时加载为模型实例
|
||||
|
||||
common_schema = AutoSchema(many=True) # 支持序列化多个对象
|
||||
output = common_schema.dump(data)
|
||||
return output
|
||||
|
||||
|
||||
def model_to_dicts(schema: ma.Schema, data):
|
||||
"""
|
||||
使用指定的 Schema 序列化 SQLAlchemy 查询结果。
|
||||
|
||||
:param schema: Marshmallow Schema 类。
|
||||
:param data: SQLAlchemy 查询结果。
|
||||
:return: 返回序列化后的数据,返回字典。
|
||||
"""
|
||||
common_schema = schema(many=True) # 支持序列化多个对象
|
||||
output = common_schema.dump(data)
|
||||
return output
|
||||
|
||||
|
||||
def get_one_by_id(model: db.Model, id):
|
||||
"""
|
||||
根据 ID 查询单个记录。
|
||||
|
||||
:param model: SQLAlchemy 模型类。
|
||||
:param id: 记录的主键 ID。
|
||||
:return: 返回查询到的记录,如果未找到则返回 None。
|
||||
"""
|
||||
return model.query.filter_by(id=id).first()
|
||||
|
||||
|
||||
def delete_one_by_id(model: db.Model, id):
|
||||
"""
|
||||
根据 ID 删除单个记录。
|
||||
|
||||
:param model: SQLAlchemy 模型类。
|
||||
:param id: 记录的主键 ID。
|
||||
:return: 返回删除操作影响的行数。
|
||||
"""
|
||||
r = model.query.filter_by(id=id).delete()
|
||||
db.session.commit()
|
||||
return r
|
||||
|
||||
|
||||
def enable_status(model: db.Model, id):
|
||||
"""
|
||||
启用指定 ID 的记录。
|
||||
|
||||
:param model: SQLAlchemy 模型类。
|
||||
:param id: 记录的主键 ID。
|
||||
:return: 如果操作成功返回 True,否则返回 False。
|
||||
"""
|
||||
enable = 1
|
||||
role = model.query.filter_by(id=id).update({"enable": enable})
|
||||
if role:
|
||||
db.session.commit()
|
||||
return True
|
||||
return False
|
||||
|
||||
|
||||
def disable_status(model: db.Model, id):
|
||||
"""
|
||||
停用指定 ID 的记录。
|
||||
|
||||
:param model: SQLAlchemy 模型类。
|
||||
:param id: 记录的主键 ID。
|
||||
:return: 如果操作成功返回 True,否则返回 False。
|
||||
"""
|
||||
enable = 0
|
||||
role = model.query.filter_by(id=id).update({"enable": enable})
|
||||
if role:
|
||||
db.session.commit()
|
||||
return True
|
||||
return False
|
||||
@@ -0,0 +1,173 @@
|
||||
from sqlalchemy import and_, func
|
||||
from applications.extensions import db
|
||||
|
||||
|
||||
class ModelFilter:
|
||||
"""
|
||||
ORM 多条件查询构造器,支持多种查询条件组合,自动转义特殊字符防止SQL注入。
|
||||
|
||||
示例:
|
||||
mf = ModelFilter()
|
||||
mf.exact('name', 'John')
|
||||
mf.vague('email', 'example.com')
|
||||
query = User.query.filter(mf.get_filter(User))
|
||||
"""
|
||||
filter_field = {} # 存储字段过滤条件
|
||||
filter_list = [] # 存储最终的过滤条件列表
|
||||
|
||||
# 查询类型常量
|
||||
type_exact = "exact" # 精确匹配
|
||||
type_neq = "neq" # 不等于
|
||||
type_greater = "greater" # 大于
|
||||
type_less = "less" # 小于
|
||||
type_vague = "vague" # 模糊匹配
|
||||
type_contains = "contains" # 包含
|
||||
type_between = "between" # 范围查询
|
||||
|
||||
def __init__(self):
|
||||
"""初始化过滤条件存储字典和列表。"""
|
||||
self.filter_field = {}
|
||||
self.filter_list = []
|
||||
|
||||
@staticmethod
|
||||
def escape_like(value: str, escape_char: str = '\\') -> str:
|
||||
"""
|
||||
转义LIKE查询中的特殊字符(%, _ 和转义字符本身)
|
||||
|
||||
:param value: 需要转义的原始字符串
|
||||
:param escape_char: 转义字符(默认反斜杠)
|
||||
:return: 转义后的安全字符串
|
||||
"""
|
||||
return (
|
||||
value.replace(escape_char, escape_char * 2)
|
||||
.replace('%', escape_char + '%')
|
||||
.replace('_', escape_char + '_')
|
||||
)
|
||||
|
||||
def exact(self, field_name, value):
|
||||
"""
|
||||
添加精确匹配条件(自动处理字符串类型参数)
|
||||
|
||||
:param field_name: 模型字段名称
|
||||
:param value: 匹配的值(自动过滤空字符串)
|
||||
"""
|
||||
if value is not None and value != '':
|
||||
# 字符串类型自动调用escape_like(防止特殊字符影响精确匹配)
|
||||
processed_value = self.escape_like(str(value)) if isinstance(value, str) else value
|
||||
self.filter_field[field_name] = {"data": processed_value, "type": self.type_exact}
|
||||
|
||||
def neq(self, field_name, value):
|
||||
"""
|
||||
添加不等于条件(自动处理字符串类型参数)
|
||||
|
||||
:param field_name: 模型字段名称
|
||||
:param value: 不匹配的值(自动过滤空字符串)
|
||||
"""
|
||||
if value is not None and value != '':
|
||||
# 字符串类型自动调用escape_like
|
||||
processed_value = self.escape_like(str(value)) if isinstance(value, str) else value
|
||||
self.filter_field[field_name] = {"data": processed_value, "type": self.type_neq}
|
||||
|
||||
def greater(self, field_name, value):
|
||||
"""
|
||||
添加大于条件(数值/日期比较)
|
||||
|
||||
:param field_name: 模型字段名称
|
||||
:param value: 比较的数值/日期
|
||||
"""
|
||||
if value is not None and value != '':
|
||||
self.filter_field[field_name] = {"data": value, "type": self.type_greater}
|
||||
|
||||
def less(self, field_name, value):
|
||||
"""
|
||||
添加小于条件(数值/日期比较)
|
||||
|
||||
:param field_name: 模型字段名称
|
||||
:param value: 比较的数值/日期
|
||||
"""
|
||||
if value is not None and value != '':
|
||||
self.filter_field[field_name] = {"data": value, "type": self.type_less}
|
||||
|
||||
def vague(self, field_name, value: str):
|
||||
"""
|
||||
添加安全模糊匹配(自动转义特殊字符,左右加%)
|
||||
|
||||
:param field_name: 模型字段名称
|
||||
:param value: 需要模糊匹配的字符串(自动过滤空值)
|
||||
"""
|
||||
if value and value != '':
|
||||
escaped_value = self.escape_like(value)
|
||||
self.filter_field[field_name] = {"data": f'%{escaped_value}%', "type": self.type_vague}
|
||||
|
||||
def left_vague(self, field_name, value: str):
|
||||
"""
|
||||
添加安全左模糊匹配(自动转义特殊字符,左侧加%)
|
||||
|
||||
:param field_name: 模型字段名称
|
||||
:param value: 需要左模糊匹配的字符串
|
||||
"""
|
||||
if value and value != '':
|
||||
escaped_value = self.escape_like(value)
|
||||
self.filter_field[field_name] = {"data": f'%{escaped_value}', "type": self.type_vague}
|
||||
|
||||
def right_vague(self, field_name, value: str):
|
||||
"""
|
||||
添加安全右模糊匹配(自动转义特殊字符,右侧加%)
|
||||
|
||||
:param field_name: 模型字段名称
|
||||
:param value: 需要右模糊匹配的字符串
|
||||
"""
|
||||
if value and value != '':
|
||||
escaped_value = self.escape_like(value)
|
||||
self.filter_field[field_name] = {"data": f'{escaped_value}%', "type": self.type_vague}
|
||||
|
||||
def contains(self, field_name, value: str):
|
||||
"""
|
||||
添加安全包含条件(自动转义特殊字符,等效于vague)
|
||||
|
||||
:param field_name: 模型字段名称
|
||||
:param value: 需要包含的字符串
|
||||
"""
|
||||
if value and value != '':
|
||||
escaped_value = self.escape_like(value)
|
||||
self.filter_field[field_name] = {"data": f'%{escaped_value}%', "type": self.type_contains}
|
||||
|
||||
def between(self, field_name, value1, value2):
|
||||
"""
|
||||
添加范围查询条件(自动过滤无效值)
|
||||
|
||||
:param field_name: 模型字段名称
|
||||
:param value1: 范围起始值
|
||||
:param value2: 范围结束值
|
||||
"""
|
||||
if all([v is not None and v != '' for v in [value1, value2]]):
|
||||
self.filter_field[field_name] = {"data": [value1, value2], "type": self.type_between}
|
||||
|
||||
def get_filter(self, model: db.Model):
|
||||
"""
|
||||
生成安全的SQLAlchemy过滤条件
|
||||
|
||||
:param model: SQLAlchemy 模型类
|
||||
:return: 组合后的过滤条件(使用and_连接)
|
||||
"""
|
||||
for k, v in self.filter_field.items():
|
||||
field = getattr(model, k)
|
||||
data = v.get("data")
|
||||
query_type = v.get("type")
|
||||
|
||||
if query_type == self.type_vague:
|
||||
self.filter_list.append(field.like(data, escape='\\'))
|
||||
elif query_type == self.type_contains:
|
||||
self.filter_list.append(field.like(data, escape='\\'))
|
||||
elif query_type == self.type_exact:
|
||||
self.filter_list.append(field == data)
|
||||
elif query_type == self.type_neq:
|
||||
self.filter_list.append(field != data)
|
||||
elif query_type == self.type_greater:
|
||||
self.filter_list.append(field > data)
|
||||
elif query_type == self.type_less:
|
||||
self.filter_list.append(field < data)
|
||||
elif query_type == self.type_between:
|
||||
self.filter_list.append(field.between(data[0], data[1]))
|
||||
|
||||
return and_(*self.filter_list)
|
||||
@@ -0,0 +1,11 @@
|
||||
from flask import Flask
|
||||
|
||||
from .admin import admin_cli
|
||||
from .check import check_cli
|
||||
from applications.extensions.init_plugins import broadcast_execute
|
||||
|
||||
|
||||
def init_script(app: Flask):
|
||||
app.cli.add_command(admin_cli)
|
||||
app.cli.add_command(check_cli)
|
||||
broadcast_execute(app, 'event_finish')
|
||||
@@ -0,0 +1,247 @@
|
||||
import click
|
||||
import json
|
||||
import datetime
|
||||
import os
|
||||
from flask.cli import AppGroup
|
||||
from applications.extensions import db
|
||||
from applications.models import User, Role, Dept, Power
|
||||
|
||||
# 1. 定义命令组
|
||||
admin_cli = AppGroup("admin", help="系统数据管理:包括初始化、导入和导出")
|
||||
|
||||
# 2. 定义数据存储的文件夹名称
|
||||
DATA_DIR = "app_data"
|
||||
|
||||
|
||||
# --- 辅助工具类 ---
|
||||
class DateEncoder(json.JSONEncoder):
|
||||
def default(self, obj):
|
||||
if isinstance(obj, datetime.datetime):
|
||||
return obj.strftime('%Y-%m-%d %H:%M:%S')
|
||||
return json.JSONEncoder.default(self, obj)
|
||||
|
||||
|
||||
def parse_time(item):
|
||||
"""辅助函数:尝试将字典中的时间字符串转换为 datetime 对象"""
|
||||
for k, v in item.items():
|
||||
if k in ['create_at', 'create_time', 'update_at'] and isinstance(v, str):
|
||||
try:
|
||||
item[k] = datetime.datetime.strptime(v, '%Y-%m-%d %H:%M:%S')
|
||||
except ValueError:
|
||||
pass
|
||||
return item
|
||||
|
||||
|
||||
def model_to_dict(obj):
|
||||
"""将 SQLAlchemy 模型对象转换为字典"""
|
||||
data = {}
|
||||
for c in obj.__table__.columns:
|
||||
val = getattr(obj, c.name)
|
||||
data[c.name] = val
|
||||
return data
|
||||
|
||||
|
||||
def ensure_dir_exists():
|
||||
"""
|
||||
确保数据文件夹存在。
|
||||
修改:路径基于当前脚本文件的位置,而不是执行命令的位置。
|
||||
"""
|
||||
# 获取当前脚本(admin_cli.py)所在的目录
|
||||
current_script_dir = os.path.dirname(os.path.abspath(__file__))
|
||||
|
||||
# 拼接得到 app_data 的绝对路径
|
||||
base_path = os.path.join(current_script_dir, DATA_DIR)
|
||||
|
||||
if not os.path.exists(base_path):
|
||||
os.makedirs(base_path)
|
||||
return base_path
|
||||
|
||||
|
||||
# --- 核心逻辑:导入数据 ---
|
||||
def import_logic(file_path, is_force):
|
||||
"""具体的导入逻辑封装"""
|
||||
if not os.path.exists(file_path):
|
||||
click.echo(f"错误: 找不到文件 {file_path}")
|
||||
return False
|
||||
|
||||
click.echo(f"正在读取文件: {file_path}")
|
||||
with open(file_path, 'r', encoding='utf-8') as f:
|
||||
raw_data = json.load(f)
|
||||
|
||||
if is_force:
|
||||
click.echo("警告: 正在清空旧数据...")
|
||||
try:
|
||||
db.session.query(User).delete()
|
||||
db.session.query(Role).delete()
|
||||
db.session.query(Power).delete()
|
||||
db.session.query(Dept).delete()
|
||||
# 新增:清空 Nav 表
|
||||
from applications.models import Nav
|
||||
db.session.query(Nav).delete()
|
||||
db.session.commit()
|
||||
except Exception as e:
|
||||
db.session.rollback()
|
||||
click.echo(f"清空数据失败: {str(e)}")
|
||||
return False
|
||||
|
||||
try:
|
||||
# 1. 导入部门
|
||||
count_dept = 0
|
||||
for item in raw_data.get("depts", []):
|
||||
item = parse_time(item)
|
||||
if not Dept.query.get(item['id']):
|
||||
db.session.add(Dept(**item))
|
||||
count_dept += 1
|
||||
db.session.commit()
|
||||
|
||||
# 2. 导入权限
|
||||
count_power = 0
|
||||
for item in raw_data.get("powers", []):
|
||||
item = parse_time(item)
|
||||
if not Power.query.get(item['id']):
|
||||
db.session.add(Power(**item))
|
||||
count_power += 1
|
||||
db.session.commit()
|
||||
|
||||
# 3. 导入角色
|
||||
count_role = 0
|
||||
for item in raw_data.get("roles", []):
|
||||
item = parse_time(item)
|
||||
power_ids = item.pop('power_ids', [])
|
||||
|
||||
role = Role.query.get(item['id'])
|
||||
if not role:
|
||||
role = Role(**item)
|
||||
db.session.add(role)
|
||||
count_role += 1
|
||||
|
||||
if power_ids:
|
||||
powers = Power.query.filter(Power.id.in_(power_ids)).all()
|
||||
role.power = powers
|
||||
db.session.commit()
|
||||
|
||||
# 4. 导入用户
|
||||
count_user = 0
|
||||
for item in raw_data.get("users", []):
|
||||
item = parse_time(item)
|
||||
role_ids = item.pop('role_ids', [])
|
||||
|
||||
user = User.query.get(item['id'])
|
||||
if not user:
|
||||
user = User(**item)
|
||||
db.session.add(user)
|
||||
count_user += 1
|
||||
|
||||
if role_ids:
|
||||
roles = Role.query.filter(Role.id.in_(role_ids)).all()
|
||||
user.role = roles
|
||||
db.session.commit()
|
||||
|
||||
# 5. 导入公开导航(Nav 表)
|
||||
from applications.models import Nav
|
||||
count_nav = 0
|
||||
for item in raw_data.get("navs", []):
|
||||
item = parse_time(item)
|
||||
if not Nav.query.get(item.get('id')) if item.get('id') else True:
|
||||
db.session.add(Nav(**item))
|
||||
count_nav += 1
|
||||
db.session.commit()
|
||||
|
||||
click.echo(f"导入成功! 新增: 部门{count_dept}, 权限{count_power}, 角色{count_role}, 用户{count_user}, 导航{count_nav}")
|
||||
return True
|
||||
|
||||
except Exception as e:
|
||||
db.session.rollback()
|
||||
click.echo(f"导入失败,已回滚。错误信息: {str(e)}")
|
||||
return False
|
||||
|
||||
|
||||
# --- 命令:init (系统初始化) ---
|
||||
@admin_cli.command("init", help="系统初始化:读取 app_data/init.json 并导入数据库")
|
||||
@click.option('--force', is_flag=True, help='是否强制清空旧数据再导入')
|
||||
def init_db(force):
|
||||
"""
|
||||
系统初始化命令。
|
||||
默认读取当前脚本同级目录下 app_data/init.json 文件。
|
||||
"""
|
||||
base_path = ensure_dir_exists()
|
||||
target_file = os.path.join(base_path, 'init.json')
|
||||
|
||||
if not os.path.exists(target_file):
|
||||
click.echo(f"错误:在 {base_path} 目录下未找到 init.json 文件。")
|
||||
click.echo(f"请先将基础数据文件放入该位置,或运行 export 生成。")
|
||||
return
|
||||
|
||||
import_logic(target_file, force)
|
||||
|
||||
|
||||
# --- 命令:export (导出) ---
|
||||
@admin_cli.command("export", help="导出数据:将数据库数据保存为 JSON 文件")
|
||||
@click.option('--name', default=None, help='指定导出文件名,不带后缀。如果不填则使用时间戳。')
|
||||
def export_data(name):
|
||||
"""
|
||||
导出数据到当前脚本同级目录下的 app_data 文件夹。
|
||||
"""
|
||||
base_path = ensure_dir_exists()
|
||||
|
||||
if name:
|
||||
filename = f"{name}.json"
|
||||
else:
|
||||
now_str = datetime.datetime.now().strftime('%Y%m%d_%H%M%S')
|
||||
filename = f"data_{now_str}.json"
|
||||
|
||||
file_path = os.path.join(base_path, filename)
|
||||
click.echo(f"准备导出数据到: {file_path} ...")
|
||||
|
||||
data = {
|
||||
"depts": [],
|
||||
"powers": [],
|
||||
"roles": [],
|
||||
"users": [],
|
||||
"navs": []
|
||||
}
|
||||
|
||||
# 1. 导出部门
|
||||
data["depts"] = [model_to_dict(d) for d in Dept.query.order_by(Dept.id).all()]
|
||||
# 2. 导出权限
|
||||
data["powers"] = [model_to_dict(p) for p in Power.query.order_by(Power.id).all()]
|
||||
# 3. 导出角色
|
||||
roles = Role.query.order_by(Role.id).all()
|
||||
for r in roles:
|
||||
r_dict = model_to_dict(r)
|
||||
r_dict['power_ids'] = [p.id for p in r.power]
|
||||
data["roles"].append(r_dict)
|
||||
# 4. 导出用户
|
||||
users = User.query.order_by(User.id).all()
|
||||
for u in users:
|
||||
u_dict = model_to_dict(u)
|
||||
u_dict['role_ids'] = [r.id for r in u.role]
|
||||
data["users"].append(u_dict)
|
||||
|
||||
# 5. 导出公开导航
|
||||
from applications.models import Nav
|
||||
data["navs"] = [model_to_dict(n) for n in Nav.query.order_by(Nav.category, Nav.sort, Nav.id).all()]
|
||||
|
||||
try:
|
||||
with open(file_path, 'w', encoding='utf-8') as f:
|
||||
json.dump(data, f, cls=DateEncoder, ensure_ascii=False, indent=4)
|
||||
click.echo(f"导出成功!")
|
||||
except Exception as e:
|
||||
click.echo(f"导出失败: {str(e)}")
|
||||
|
||||
|
||||
# --- 命令:import (指定文件导入) ---
|
||||
@admin_cli.command("import", help="导入数据:从指定的 JSON 文件恢复数据")
|
||||
@click.option('--file', required=True, help='要导入的文件名 (需包含路径或位于 app_data 下)')
|
||||
@click.option('--force', is_flag=True, help='是否强制清空旧数据')
|
||||
def import_data(file, force):
|
||||
"""
|
||||
从指定文件导入数据。
|
||||
"""
|
||||
# 如果用户只提供了文件名,没有路径,则假设在 app_data 目录下
|
||||
if not os.path.dirname(file):
|
||||
file_path = os.path.join(ensure_dir_exists(), file)
|
||||
else:
|
||||
file_path = file
|
||||
|
||||
import_logic(file_path, force)
|
||||
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,95 @@
|
||||
import re
|
||||
import inspect
|
||||
from flask.cli import AppGroup
|
||||
from flask import current_app
|
||||
|
||||
check_cli = AppGroup('check', help='Commands for checking application aspects.')
|
||||
|
||||
@check_cli.command('auth')
|
||||
def check_auth():
|
||||
"""检查路由视图函数的 @login_required 和 @authorize(...) 装饰器使用情况。"""
|
||||
app = current_app
|
||||
if not app:
|
||||
print("错误:未在应用上下文中运行。请使用 'flask check auth' 命令。")
|
||||
return
|
||||
|
||||
print("\n" + "="*120)
|
||||
print("Flask 路由鉴权装饰器检查报告".center(120))
|
||||
print("="*120)
|
||||
# 调整列宽以适应更长的权限字符串
|
||||
header_format = "{:<35} {:<35} {:<30} {:<20} {:<30}"
|
||||
row_format = "{:<35} {:<35} {:<30} {:<20} {:<30}"
|
||||
print(header_format.format("Endpoint", "URL Rule", "View Function", "@login_required", "@authorize(...)"))
|
||||
print("-" * 120)
|
||||
|
||||
has_missing_auth = False # 标记是否有缺失鉴权的路由
|
||||
|
||||
with app.app_context():
|
||||
for rule in app.url_map.iter_rules():
|
||||
if rule.endpoint == 'static':
|
||||
continue
|
||||
|
||||
view_func = app.view_functions.get(rule.endpoint)
|
||||
if not view_func:
|
||||
continue
|
||||
|
||||
# --- 获取源代码 ---
|
||||
try:
|
||||
# 使用 getsourcelines 可能更稳定,获取整个函数定义
|
||||
source_lines = inspect.getsourcelines(view_func)[0]
|
||||
source_code = "".join(source_lines)
|
||||
except (OSError, TypeError):
|
||||
# 如果无法获取源代码(如 C 扩展),则跳过
|
||||
source_code = ""
|
||||
|
||||
# --- 检查 @login_required 装饰器 ---
|
||||
# 匹配常见的形式,包括可能的模块前缀
|
||||
has_login_required = bool(re.search(r"@.*login_required", source_code))
|
||||
|
||||
# --- 检查 @authorize 装饰器并提取权限 ---
|
||||
authorize_permissions_list = []
|
||||
# 改进的正则表达式:
|
||||
# @ : 匹配 @ 符号
|
||||
# (?:.*?\.)? : 非捕获组,匹配可能的模块名和点 (例如 auth.)
|
||||
# authorize : 匹配 authorize 函数名
|
||||
# \( : 匹配左圆括号
|
||||
# ([^)]*) : 捕获组,匹配括号内的所有内容 (非右括号字符)
|
||||
# \) : 匹配右圆括号
|
||||
# 这个模式会找到 @authorize(...) 的整个调用
|
||||
authorize_calls = re.findall(r"@.*?authorize\s*\(([^)]*)\)", source_code, re.DOTALL)
|
||||
|
||||
for call_args in authorize_calls:
|
||||
# 在找到的参数字符串中,再次使用正则提取被引号包围的权限字符串
|
||||
# 匹配单引号或双引号内的内容
|
||||
permissions_found = re.findall(r"['\"]([^'\"]+)['\"]", call_args)
|
||||
authorize_permissions_list.extend(permissions_found)
|
||||
|
||||
# 将找到的所有权限字符串用逗号连接
|
||||
authorize_permissions = ", ".join(authorize_permissions_list) if authorize_permissions_list else "N/A"
|
||||
|
||||
# --- 判断是否可能缺失鉴权 ---
|
||||
# 简单判断:如果既没有 login_required 也没有 authorize 权限,则标记
|
||||
if not has_login_required and not authorize_permissions_list:
|
||||
has_missing_auth = True
|
||||
|
||||
# --- 格式化输出 ---
|
||||
login_status = "✅ Yes" if has_login_required else "❌ No"
|
||||
auth_status = authorize_permissions if authorize_permissions != "N/A" else "❌ N/A"
|
||||
|
||||
# 格式化字符串长度
|
||||
def truncate(s, length):
|
||||
return s if len(s) <= length else s[:length-2] + ".."
|
||||
|
||||
endpoint_str = truncate(rule.endpoint, 34)
|
||||
rule_str = truncate(str(rule), 34)
|
||||
func_name_str = truncate(view_func.__name__, 29)
|
||||
|
||||
print(row_format.format(endpoint_str, rule_str, func_name_str, login_status, auth_status))
|
||||
|
||||
print("-" * 120)
|
||||
if has_missing_auth:
|
||||
print("\n⚠️ 注意:以上标记为 '❌ No' 和 '❌ N/A' 的路由可能缺少鉴权,请仔细检查!")
|
||||
else:
|
||||
print("\n✅ 所有路由似乎都应用了至少一种鉴权机制。")
|
||||
print("="*120 + "\n")
|
||||
|
||||
@@ -0,0 +1,55 @@
|
||||
import time
|
||||
|
||||
cache_dict = {}
|
||||
|
||||
|
||||
def cache_set_internal(key, value, expired=5):
|
||||
"""
|
||||
程序内部实现的记录缓存,用于简单、体量不大的缓存记录,在程序结束后销毁。对于高速、体量大的环境请配置 Redis 等服务自行记录。
|
||||
记录缓存,存储键值对,并记录当前时间作为缓存的时间戳。
|
||||
|
||||
:param key: 键
|
||||
:param value: 值
|
||||
:param expired: 过期时间(秒),默认5秒
|
||||
"""
|
||||
cache_dict[key] = {
|
||||
'value': value,
|
||||
'expired_time': time.time() + expired
|
||||
}
|
||||
|
||||
|
||||
def cache_get_internal(key):
|
||||
"""
|
||||
获取缓存,根据键从缓存中获取值,并检查是否过期。
|
||||
|
||||
:param key: 键
|
||||
:return: 如果缓存存在且未过期,返回缓存的值;否则返回 None
|
||||
"""
|
||||
if key in cache_dict:
|
||||
cache_item = cache_dict[key]
|
||||
if time.time() < cache_item['expired_time']:
|
||||
return cache_item['value']
|
||||
else:
|
||||
# 如果缓存已过期,删除该缓存
|
||||
del cache_dict[key]
|
||||
return None
|
||||
|
||||
|
||||
def cache_auto_internal(key, call, expired=5):
|
||||
"""
|
||||
如果缓存存在直接返回缓存内容,缓存不存在或者过期执行 call 函数,并取得返回值记录并返回。
|
||||
|
||||
:param key: 键
|
||||
:param call: 获取新值的地方
|
||||
:param expired: 过期时间(秒),默认5秒
|
||||
"""
|
||||
|
||||
data = cache_get_internal(key)
|
||||
|
||||
if data is not None:
|
||||
return data
|
||||
|
||||
data = call()
|
||||
cache_set_internal(key, data, expired)
|
||||
|
||||
return data
|
||||
@@ -0,0 +1,135 @@
|
||||
import random, math
|
||||
from PIL import Image, ImageDraw, ImageFont, ImageFilter
|
||||
|
||||
|
||||
class vieCode:
|
||||
__fontSize = 20 # 字体大小
|
||||
__width = 120 # 画布宽度
|
||||
__heigth = 45 # 画布高度
|
||||
__length = 4 # 验证码长度
|
||||
__draw = None # 画布对象
|
||||
__img = None # 图片对象
|
||||
__code = None # 验证码字符
|
||||
__str = None # 自定义验证码字符集
|
||||
__inCurve = True # 是否绘制干扰曲线
|
||||
__inNoise = True # 是否绘制干扰点
|
||||
__type = 2 # 验证码类型:1-纯字母,2-数字字母混合
|
||||
__fontPatn = 'applications/common/utils/fonts/captcha.ttf' # 字体路径
|
||||
|
||||
def GetCodeImage(self, size=80, length=4):
|
||||
"""
|
||||
生成验证码图片及其对应的验证码字符。
|
||||
|
||||
:param size: 验证码字体大小,默认为 80。
|
||||
:param length: 验证码字符长度,默认为 4。
|
||||
:return: 返回验证码图片对象和验证码字符。
|
||||
"""
|
||||
# 准备基础数据
|
||||
self.__length = length
|
||||
self.__fontSize = size
|
||||
self.__width = self.__fontSize * self.__length
|
||||
self.__heigth = int(self.__fontSize * 1.5)
|
||||
|
||||
# 生成验证码图片
|
||||
self.__createCode()
|
||||
self.__createImage()
|
||||
self.__createNoise()
|
||||
self.__printString()
|
||||
self.__cerateFilter()
|
||||
|
||||
return self.__img, self.__code
|
||||
|
||||
def __cerateFilter(self):
|
||||
"""
|
||||
对验证码图片进行模糊处理,增加识别难度。
|
||||
"""
|
||||
self.__img = self.__img.filter(ImageFilter.BLUR)
|
||||
filter = ImageFilter.ModeFilter(8)
|
||||
self.__img = self.__img.filter(filter)
|
||||
|
||||
def __createCode(self):
|
||||
"""
|
||||
生成验证码字符。
|
||||
"""
|
||||
# 是否使用自定义字符集
|
||||
if not self.__str:
|
||||
# 源文本
|
||||
number = "3456789"
|
||||
srcLetter = "qwertyuipasdfghjkzxcvbnmQWERTYUIOPASDFGHJKLZXCVBNM"
|
||||
srcUpper = srcLetter.upper()
|
||||
if self.__type == 1:
|
||||
self.__str = number
|
||||
else:
|
||||
self.__str = srcLetter + srcUpper + number
|
||||
|
||||
# 随机生成验证码字符
|
||||
self.__code = random.sample(self.__str, self.__length)
|
||||
|
||||
def __createImage(self):
|
||||
"""
|
||||
创建画布并设置背景颜色。
|
||||
"""
|
||||
bgColor = (random.randint(200, 255), random.randint(200, 255), random.randint(200, 255))
|
||||
self.__img = Image.new('RGB', (self.__width, self.__heigth), bgColor)
|
||||
self.__draw = ImageDraw.Draw(self.__img)
|
||||
|
||||
def __createNoise(self):
|
||||
"""
|
||||
在验证码图片上绘制干扰点。
|
||||
"""
|
||||
if not self.__inNoise:
|
||||
return
|
||||
font = ImageFont.truetype(self.__fontPatn, int(self.__fontSize / 1.5))
|
||||
for i in range(5):
|
||||
# 干扰点颜色
|
||||
noiseColor = (random.randint(150, 200), random.randint(150, 200), random.randint(150, 200))
|
||||
putStr = random.sample(self.__str, 2)
|
||||
for j in range(2):
|
||||
# 绘制干扰点
|
||||
size = (random.randint(-10, self.__width), random.randint(-10, self.__heigth))
|
||||
self.__draw.text(size, putStr[j], font=font, fill=noiseColor)
|
||||
|
||||
def __createCurve(self):
|
||||
"""
|
||||
在验证码图片上绘制干扰曲线。
|
||||
"""
|
||||
if not self.__inCurve:
|
||||
return
|
||||
x = y = 0
|
||||
|
||||
# 计算曲线系数
|
||||
a = random.uniform(1, self.__heigth / 2)
|
||||
b = random.uniform(-self.__width / 4, self.__heigth / 4)
|
||||
f = random.uniform(-self.__heigth / 4, self.__heigth / 4)
|
||||
t = random.uniform(self.__heigth, self.__width * 2)
|
||||
xend = random.randint(self.__width / 2, self.__width * 2)
|
||||
w = (2 * math.pi) / t
|
||||
|
||||
# 绘制曲线
|
||||
color = (random.randint(30, 150), random.randint(30, 150), random.randint(30, 150))
|
||||
for x in range(xend):
|
||||
if w != 0:
|
||||
for k in range(int(self.__heigth / 10)):
|
||||
y = a * math.sin(w * x + f) + b + self.__heigth / 2
|
||||
i = int(self.__fontSize / 5)
|
||||
while i > 0:
|
||||
px = x + i
|
||||
py = y + i + k
|
||||
self.__draw.point((px, py), color)
|
||||
i -= i
|
||||
|
||||
def __printString(self):
|
||||
"""
|
||||
在画布上打印验证码字符。
|
||||
"""
|
||||
font = ImageFont.truetype(self.__fontPatn, self.__fontSize)
|
||||
x = 0
|
||||
# 打印字符到画布
|
||||
for i in range(self.__length):
|
||||
# 设置字体随机颜色
|
||||
color = (random.randint(30, 150), random.randint(30, 150), random.randint(30, 150))
|
||||
# 计算坐标
|
||||
x = random.uniform(self.__fontSize * i * 0.95, self.__fontSize * i * 1.1)
|
||||
y = self.__fontSize * random.uniform(0.3, 0.5)
|
||||
# 打印字符
|
||||
self.__draw.text((x, y), self.__code[i], font=font, fill=color)
|
||||
Binary file not shown.
@@ -0,0 +1,41 @@
|
||||
from flask import jsonify, request
|
||||
|
||||
|
||||
def success_api(msg: str = "成功"):
|
||||
"""
|
||||
返回成功的 API 响应。
|
||||
|
||||
:param msg: 成功消息内容,默认为 "成功"。
|
||||
:return: 返回 JSON 格式的响应,包含 `success` 和 `msg` 字段。
|
||||
"""
|
||||
return jsonify(success=True, msg=msg)
|
||||
|
||||
|
||||
def fail_api(msg: str = "失败"):
|
||||
"""
|
||||
返回失败的 API 响应。
|
||||
|
||||
:param msg: 失败消息内容,默认为 "失败"。
|
||||
:return: 返回 JSON 格式的响应,包含 `success` 和 `msg` 字段。
|
||||
"""
|
||||
return jsonify(success=False, msg=msg)
|
||||
|
||||
|
||||
def table_api(msg: str = "", count=0, data=None, limit=10):
|
||||
"""
|
||||
返回动态表格渲染所需的 API 响应。
|
||||
|
||||
:param msg: 响应消息内容,默认为空字符串。
|
||||
:param count: 数据总数,默认为 0。
|
||||
:param data: 表格数据,默认为 None。
|
||||
:param limit: 每页数据条数,默认为 10。
|
||||
:return: 返回 JSON 格式的响应,包含 `msg`、`code`、`data`、`count` 和 `limit` 字段。
|
||||
"""
|
||||
res = {
|
||||
'msg': msg,
|
||||
'code': 0,
|
||||
'data': data,
|
||||
'count': count,
|
||||
'limit': min(request.args.get('limit', default=10, type=int), 90)
|
||||
}
|
||||
return jsonify(res)
|
||||
@@ -0,0 +1,93 @@
|
||||
"""
|
||||
集成了对 Pear Admin Flask 二次开发的邮件操作模块,并提供了相应的示例。
|
||||
"""
|
||||
from flask import current_app
|
||||
from flask_mail import Message
|
||||
|
||||
from applications.common.curd import model_to_dicts
|
||||
from applications.common.helper import ModelFilter
|
||||
from applications.extensions import db, flask_mail
|
||||
from applications.models import Mail
|
||||
from applications.schemas import MailOutSchema
|
||||
|
||||
|
||||
def get_all(receiver=None, subject=None, content=None):
|
||||
"""
|
||||
获取邮件列表,支持根据接收者、主题和内容进行筛选。
|
||||
|
||||
返回的列表中的字典结构如下::
|
||||
|
||||
{
|
||||
"content": "", # HTML 内容
|
||||
"create_at": "2022-12-25T10:51:17", # 创建时间
|
||||
"id": 17, # 邮件ID
|
||||
"realname": "超级管理", # 创建者姓名
|
||||
"receiver": "", # 接收者
|
||||
"subject": "" # 邮件主题
|
||||
}
|
||||
|
||||
:param receiver: 接收者邮箱地址,支持模糊查询。
|
||||
:param subject: 邮件主题,支持模糊查询。
|
||||
:param content: 邮件内容,支持模糊查询。
|
||||
:return: 返回符合条件的邮件列表。
|
||||
"""
|
||||
# 构造查询条件
|
||||
mf = ModelFilter()
|
||||
if receiver:
|
||||
mf.contains(field_name="receiver", value=receiver)
|
||||
if subject:
|
||||
mf.contains(field_name="subject", value=subject)
|
||||
if content:
|
||||
mf.exact(field_name="content", value=content)
|
||||
|
||||
# 查询邮件数据并分页
|
||||
mail = Mail.query.filter(mf.get_filter(Mail)).layui_paginate()
|
||||
return model_to_dicts(schema=MailOutSchema, data=mail.items)
|
||||
|
||||
|
||||
def add(receiver, subject, content, user_id):
|
||||
"""
|
||||
发送一封邮件,并将发送记录保存到数据库。 **该方法被邮件发送的视图函数调用。**
|
||||
|
||||
:param receiver: 接收者邮箱地址,多个邮箱用英文分号隔开。
|
||||
:param subject: 邮件主题。
|
||||
:param content: 邮件内容(HTML 格式)。
|
||||
:param user_id: 发送者用户ID,表示谁发送了这封邮件。
|
||||
可以使用 `from flask_login import current_user; current_user.id` 获取当前登录用户的ID。
|
||||
:return: 发送成功返回 True,失败报错。
|
||||
"""
|
||||
send_mail(subject=subject, recipients=receiver.split(";"), content=content)
|
||||
|
||||
# 保存邮件记录到数据库
|
||||
mail = Mail(receiver=receiver, subject=subject, content=content, user_id=user_id)
|
||||
db.session.add(mail)
|
||||
db.session.commit()
|
||||
return True
|
||||
|
||||
|
||||
def delete(id):
|
||||
"""
|
||||
删除指定的邮件记录。
|
||||
|
||||
:param id: 邮件ID。
|
||||
:return: 删除成功返回 True,失败返回 False。
|
||||
"""
|
||||
res = Mail.query.filter_by(id=id).delete()
|
||||
if not res:
|
||||
return False
|
||||
db.session.commit()
|
||||
return True
|
||||
|
||||
|
||||
def send_mail(subject, recipients, content):
|
||||
"""
|
||||
发送邮件(不记录发送日志)。
|
||||
|
||||
注意:如果发送失败会抛出异常,请使用 try-except 进行捕获。
|
||||
|
||||
:param subject: 邮件主题。
|
||||
:param recipients: 接收者邮箱地址,多个邮箱用英文分号隔开。
|
||||
:param content: 邮件内容(HTML 格式)。
|
||||
"""
|
||||
message = Message(subject=subject, recipients=recipients, html=content)
|
||||
flask_mail.send(message)
|
||||
@@ -0,0 +1,44 @@
|
||||
from functools import wraps
|
||||
from flask import abort, request, jsonify, session, current_app
|
||||
from flask_login import login_required, current_user
|
||||
from applications.common.admin import admin_log
|
||||
|
||||
|
||||
def authorize(power: str, log: bool = False):
|
||||
"""
|
||||
用户权限判断,用于判断目前会话用户是否拥有访问权限。
|
||||
在模板中有与之对应的全局非修饰函数 authorize ,此函数定义位于 `applications/extensions/init_template_directives.py` 。
|
||||
|
||||
:param power: 权限标识
|
||||
:type power: str
|
||||
:param log: 是否记录日志, defaults to False
|
||||
:type log: bool, optional
|
||||
"""
|
||||
def decorator(func):
|
||||
@login_required
|
||||
@wraps(func)
|
||||
def wrapper(*args, **kwargs):
|
||||
# 定义管理员的id为1
|
||||
if current_user.username == current_app.config.get("SUPERADMIN"):
|
||||
|
||||
if log:
|
||||
admin_log(request=request, is_access=True)
|
||||
|
||||
return func(*args, **kwargs)
|
||||
|
||||
if not power in session.get('permissions'):
|
||||
if log:
|
||||
admin_log(request=request, is_access=False)
|
||||
if request.method == 'GET':
|
||||
abort(403)
|
||||
else:
|
||||
return jsonify(success=False, msg="权限不足!")
|
||||
|
||||
if log:
|
||||
admin_log(request=request, is_access=True)
|
||||
|
||||
return func(*args, **kwargs)
|
||||
|
||||
return wrapper
|
||||
|
||||
return decorator
|
||||
@@ -0,0 +1,36 @@
|
||||
import os
|
||||
from flask import current_app
|
||||
from sqlalchemy import desc
|
||||
from applications.extensions import db
|
||||
from applications.extensions.init_upload import photos
|
||||
from applications.models import Photo
|
||||
from applications.schemas import PhotoOutSchema
|
||||
from applications.common.curd import model_to_dicts
|
||||
|
||||
|
||||
def get_photo(page, limit):
|
||||
photo = Photo.query.order_by(desc(Photo.create_time)).paginate(page=page, per_page=limit, error_out=False)
|
||||
count = Photo.query.count()
|
||||
data = model_to_dicts(schema=PhotoOutSchema, data=photo.items)
|
||||
return data, count
|
||||
|
||||
|
||||
def upload_one(photo, mime):
|
||||
filename = photos.save(photo)
|
||||
file_url = '/_uploads/photos/' + filename
|
||||
# file_url = photos.url(filename)
|
||||
upload_url = current_app.config.get("UPLOADED_PHOTOS_DEST")
|
||||
size = os.path.getsize(upload_url + '/' + filename)
|
||||
photo = Photo(name=filename, href=file_url, mime=mime, size=size)
|
||||
db.session.add(photo)
|
||||
db.session.commit()
|
||||
return file_url
|
||||
|
||||
|
||||
def delete_photo_by_id(_id):
|
||||
photo_name = Photo.query.filter_by(id=_id).first().name
|
||||
photo = Photo.query.filter_by(id=_id).delete()
|
||||
db.session.commit()
|
||||
upload_url = current_app.config.get("UPLOADED_PHOTOS_DEST")
|
||||
os.remove(upload_url + '/' + photo_name)
|
||||
return photo
|
||||
@@ -0,0 +1,240 @@
|
||||
# XSS 过滤
|
||||
import validators
|
||||
from markupsafe import escape
|
||||
from validators import validator
|
||||
|
||||
|
||||
def str_escape(s):
|
||||
"""
|
||||
对字符串进行 XSS 过滤,返回转义后的安全字符串。
|
||||
|
||||
:param s: 需要转义的字符串。
|
||||
:return: 返回转义后的字符串,如果输入为空则返回 None。
|
||||
"""
|
||||
if not s:
|
||||
return None
|
||||
return str(escape(s))
|
||||
|
||||
|
||||
def between(*args, **kwargs):
|
||||
"""
|
||||
验证数字是否介于最小值和最大值之间。
|
||||
适用于整数、浮点数、小数和日期等类型。
|
||||
|
||||
:param value: 需要验证的数字。
|
||||
:param min: 数字的最小值(可选)。
|
||||
:param max: 数字的最大值(可选)。
|
||||
:return: 如果验证成功返回 True,否则返回 ValidationFailure。
|
||||
|
||||
示例:
|
||||
>>> between(5, min=2)
|
||||
True
|
||||
|
||||
>>> between(13.2, min=13, max=14)
|
||||
True
|
||||
|
||||
>>> between(500, max=400)
|
||||
ValidationFailure(func=between, args=...)
|
||||
"""
|
||||
return validators.between(*args, **kwargs)
|
||||
|
||||
|
||||
def domain(*args, **kwargs):
|
||||
"""
|
||||
验证给定值是否为有效的域名。
|
||||
|
||||
:param value: 需要验证的域名字符串。
|
||||
:return: 如果验证成功返回 True,否则返回 ValidationFailure。
|
||||
|
||||
示例:
|
||||
>>> domain('example.com')
|
||||
True
|
||||
|
||||
>>> domain('example.com/')
|
||||
ValidationFailure(func=domain, ...)
|
||||
"""
|
||||
return validators.domain(*args, **kwargs)
|
||||
|
||||
|
||||
def email(*args, **kwargs):
|
||||
"""
|
||||
验证给定值是否为有效的电子邮件地址。
|
||||
|
||||
:param value: 需要验证的电子邮件地址。
|
||||
:return: 如果验证成功返回 True,否则返回 ValidationFailure。
|
||||
|
||||
示例:
|
||||
>>> email('someone@example.com')
|
||||
True
|
||||
|
||||
>>> email('bogus@@')
|
||||
ValidationFailure(func=email, ...)
|
||||
"""
|
||||
return validators.email(*args, **kwargs)
|
||||
|
||||
|
||||
def iban(*args, **kwargs):
|
||||
"""
|
||||
验证给定值是否为有效的 IBAN 代码。
|
||||
|
||||
:param value: 需要验证的 IBAN 代码。
|
||||
:return: 如果验证成功返回 True,否则返回 ValidationFailure。
|
||||
|
||||
示例:
|
||||
>>> iban('DE29100500001061045672')
|
||||
True
|
||||
|
||||
>>> iban('123456')
|
||||
ValidationFailure(func=iban, ...)
|
||||
"""
|
||||
return validators.iban(*args, **kwargs)
|
||||
|
||||
|
||||
def ipv4(*args, **kwargs):
|
||||
"""
|
||||
验证给定值是否为有效的 IPv4 地址。
|
||||
|
||||
:param value: 需要验证的 IPv4 地址。
|
||||
:return: 如果验证成功返回 True,否则返回 ValidationFailure。
|
||||
|
||||
示例:
|
||||
>>> ipv4('123.0.0.7')
|
||||
True
|
||||
|
||||
>>> ipv4('900.80.70.11')
|
||||
ValidationFailure(func=ipv4, args={'value': '900.80.70.11'})
|
||||
"""
|
||||
return validators.ipv4(*args, **kwargs)
|
||||
|
||||
|
||||
def ipv6(*args, **kwargs):
|
||||
"""
|
||||
验证给定值是否为有效的 IPv6 地址。
|
||||
|
||||
:param value: 需要验证的 IPv6 地址。
|
||||
:return: 如果验证成功返回 True,否则返回 ValidationFailure。
|
||||
|
||||
示例:
|
||||
>>> ipv6('abcd:ef::42:1')
|
||||
True
|
||||
|
||||
>>> ipv6('abc.0.0.1')
|
||||
ValidationFailure(func=ipv6, args={'value': 'abc.0.0.1'})
|
||||
"""
|
||||
return validators.ipv6(*args, **kwargs)
|
||||
|
||||
|
||||
def length(*args, **kwargs):
|
||||
"""
|
||||
验证给定字符串的长度是否在指定范围内。
|
||||
|
||||
:param value: 需要验证的字符串。
|
||||
:param min: 字符串的最小长度(可选)。
|
||||
:param max: 字符串的最大长度(可选)。
|
||||
:return: 如果验证成功返回 True,否则返回 ValidationFailure。
|
||||
|
||||
示例:
|
||||
>>> length('something', min=2)
|
||||
True
|
||||
|
||||
>>> length('something', min=9, max=9)
|
||||
True
|
||||
|
||||
>>> length('something', max=5)
|
||||
ValidationFailure(func=length, ...)
|
||||
"""
|
||||
return validators.length(*args, **kwargs)
|
||||
|
||||
|
||||
def mac_address(*args, **kwargs):
|
||||
"""
|
||||
验证给定值是否为有效的 MAC 地址。
|
||||
|
||||
:param value: 需要验证的 MAC 地址。
|
||||
:return: 如果验证成功返回 True,否则返回 ValidationFailure。
|
||||
|
||||
示例:
|
||||
>>> mac_address('01:23:45:67:ab:CD')
|
||||
True
|
||||
|
||||
>>> mac_address('00:00:00:00:00')
|
||||
ValidationFailure(func=mac_address, args={'value': '00:00:00:00:00'})
|
||||
"""
|
||||
return validators.mac_address(*args, **kwargs)
|
||||
|
||||
|
||||
def slug(*args, **kwargs):
|
||||
"""
|
||||
验证给定值是否为有效的 Slug 格式。
|
||||
有效的 Slug 只能包含字母数字字符、连字符和下划线。
|
||||
|
||||
:param value: 需要验证的字符串。
|
||||
:return: 如果验证成功返回 True,否则返回 ValidationFailure。
|
||||
|
||||
示例:
|
||||
>>> slug('my.slug')
|
||||
ValidationFailure(func=slug, args={'value': 'my.slug'})
|
||||
|
||||
>>> slug('my-slug-2134')
|
||||
True
|
||||
"""
|
||||
return validators.slug(*args, **kwargs)
|
||||
|
||||
|
||||
def url(*args, **kwargs):
|
||||
"""
|
||||
验证给定值是否为有效的 URL。
|
||||
|
||||
:param value: 需要验证的 URL。
|
||||
:param public: 是否仅允许公共 URL(可选)。
|
||||
:return: 如果验证成功返回 True,否则返回 ValidationFailure。
|
||||
|
||||
示例:
|
||||
>>> url('http://foobar.dk')
|
||||
True
|
||||
|
||||
>>> url('http://10.0.0.1')
|
||||
True
|
||||
|
||||
>>> url('http://foobar.d')
|
||||
ValidationFailure(func=url, ...)
|
||||
|
||||
>>> url('http://10.0.0.1', public=True)
|
||||
ValidationFailure(func=url, ...)
|
||||
"""
|
||||
return validators.url(*args, **kwargs)
|
||||
|
||||
|
||||
def uuid(*args, **kwargs):
|
||||
"""
|
||||
验证给定值是否为有效的 UUID。
|
||||
|
||||
:param value: 需要验证的 UUID。
|
||||
:return: 如果验证成功返回 True,否则返回 ValidationFailure。
|
||||
|
||||
示例:
|
||||
>>> uuid('2bc1c94f-0deb-43e9-92a1-4775189ec9f8')
|
||||
True
|
||||
|
||||
>>> uuid('2bc1c94f 0deb-43e9-92a1-4775189ec9f8')
|
||||
ValidationFailure(func=uuid, ...)
|
||||
"""
|
||||
return validators.uuid(*args, **kwargs)
|
||||
|
||||
|
||||
@validator
|
||||
def even(value):
|
||||
"""
|
||||
验证给定值是否为偶数。
|
||||
|
||||
:param value: 需要验证的数字。
|
||||
:return: 如果是偶数返回 True,否则返回 ValidationFailure。
|
||||
|
||||
示例:
|
||||
>>> even(4)
|
||||
True
|
||||
|
||||
>>> even(5)
|
||||
ValidationFailure(func=even, args={'value': 5})
|
||||
"""
|
||||
return not (value % 2)
|
||||
@@ -0,0 +1,84 @@
|
||||
import logging
|
||||
from datetime import timedelta
|
||||
|
||||
|
||||
class BaseConfig:
|
||||
# 超级管理员账号
|
||||
SUPERADMIN = 'admin'
|
||||
|
||||
# 系统名称
|
||||
SYSTEM_NAME = 'Pear Admin'
|
||||
|
||||
# 主题面板的链接列表配置
|
||||
SYSTEM_PANEL_LINKS = [
|
||||
{
|
||||
"icon": "layui-icon layui-icon-auz",
|
||||
"title": "官方网站",
|
||||
"href": "http://www.pearadmin.com"
|
||||
},
|
||||
{
|
||||
"icon": "layui-icon layui-icon-auz",
|
||||
"title": "开发文档",
|
||||
"href": "http://www.pearadmin.com"
|
||||
},
|
||||
{
|
||||
"icon": "layui-icon layui-icon-auz",
|
||||
"title": "开源地址",
|
||||
"href": "https://gitee.com/Jmysy/Pear-Admin-Layui"
|
||||
}
|
||||
]
|
||||
|
||||
# 上传图片目标文件夹
|
||||
UPLOADED_PHOTOS_DEST = 'static/upload'
|
||||
UPLOADED_FILES_ALLOW = ['gif', 'jpg', 'jpeg', 'png', 'webp']
|
||||
UPLOADS_AUTOSERVE = True
|
||||
|
||||
# JSON 配置
|
||||
JSON_AS_ASCII = False
|
||||
|
||||
# 配置多个数据库连接的连接串写法示例
|
||||
# HOSTNAME: 指数据库的IP地址、USERNAME:指数据库登录的用户名、PASSWORD:指数据库登录密码、PORT:指数据库开放的端口、DATABASE:指需要连接的数据库名称
|
||||
# MSSQL: f"mssql+pymssql://{USERNAME}:{PASSWORD}@{HOSTNAME}:{PORT}/{DATABASE}?charset=cp936"
|
||||
# MySQL: f"mysql+pymysql://{USERNAME}:{PASSWORD}@{HOSTNAME}:{PORT}/{DATABASE}?charset=utf8mb4"
|
||||
# Oracle: f"oracle+cx_oracle://{USERNAME}:{PASSWORD}@{HOSTNAME}:{PORT}/{DATABASE}"
|
||||
# SQLite "sqlite:/// database.db"
|
||||
# Postgres f"postgresql+psycopg2://{USERNAME}:{PASSWORD}@{HOSTNAME}:{PORT}/{DATABASE}"
|
||||
# Oracle的第二种连接方式
|
||||
# dsnStr = cx_Oracle.makedsn({HOSTNAME}, 1521, service_name='orcl')
|
||||
# connect_str = "oracle://%s:%s@%s" % ('{USERNAME}', ' {PASSWORD}', dsnStr)
|
||||
|
||||
# 在SQLALCHEMY_BINDS 中设置:'{数据库连接别名}': '{连接串}'
|
||||
# 最后在models的数据模型class中,在__tablename__前设置 __bind_key__ = '{数据库连接别名}' 即可,表示该数据模型不使用默认的数据库连接,改用“SQLALCHEMY_BINDS”中设置的其他数据库连接
|
||||
# SQLALCHEMY_BINDS = {
|
||||
# 'testMySQL': 'mysql+pymysql://test:123456@192.168.1.1:3306/test?charset=utf8',
|
||||
# 'testMsSQL': 'mssql+pymssql://test:123456@192.168.1.1:1433/test?charset=cp936',
|
||||
# 'testOracle': 'oracle+cx_oracle://test:123456@192.168.1.1:1521/test',
|
||||
# 'testSQLite': 'sqlite:///database.db
|
||||
# }
|
||||
|
||||
# 数据库的配置信息
|
||||
SQLALCHEMY_DATABASE_URI = 'sqlite:///../pear.db'
|
||||
|
||||
# 默认日志等级
|
||||
LOG_LEVEL = logging.WARN
|
||||
|
||||
# 发信设置
|
||||
MAIL_SERVER = 'smtp.qq.com'
|
||||
MAIL_USE_TLS = False
|
||||
MAIL_USE_SSL = True
|
||||
MAIL_PORT = 465
|
||||
MAIL_USERNAME = '123@qq.com'
|
||||
MAIL_PASSWORD = 'XXXXX' # 生成的授权码
|
||||
MAIL_DEFAULT_SENDER = MAIL_USERNAME
|
||||
|
||||
# 插件配置,填写插件的文件名名称,默认不启用插件。
|
||||
PLUGIN_ENABLE_FOLDERS = []
|
||||
|
||||
# Session 设置
|
||||
PERMANENT_SESSION_LIFETIME = timedelta(days=7)
|
||||
|
||||
SESSION_TYPE = "filesystem" # 默认使用文件系统来保存会话
|
||||
SESSION_PERMANENT = False # 会话是否持久化
|
||||
SESSION_USE_SIGNER = True # 是否对发送到浏览器上 session 的 cookie 值进行加密
|
||||
|
||||
SECRET_KEY = "pear-system-flask"
|
||||
@@ -1,9 +0,0 @@
|
||||
# 密钥配置(flask session需要) 记得修改
|
||||
import os
|
||||
|
||||
SECRET_KEY = 'pear-admin-flask'
|
||||
|
||||
UPLOADED_PHOTOS_DEST = 'static/upload'
|
||||
UPLOADED_FILES_ALLOW = ['gif','jpg']
|
||||
|
||||
JSON_AS_ASCII = False
|
||||
@@ -1,13 +0,0 @@
|
||||
# 数据库连接
|
||||
HOST = '127.0.0.1'
|
||||
PORT = '3306'
|
||||
DATABASE = 'PearAdminFlask'
|
||||
USERNAME = 'root'
|
||||
PASSWORD = 'root'
|
||||
|
||||
DB_URI = "mysql+pymysql://{username}:{password}@{host}:{port}/{db}?charset=utf8".format(username=USERNAME,password=PASSWORD, host=HOST,port=PORT, db=DATABASE)
|
||||
|
||||
SQLALCHEMY_DATABASE_URI = DB_URI
|
||||
SQLALCHEMY_TRACK_MODIFICATIONS = True
|
||||
SQLALCHEMY_ECHO = False
|
||||
SQLALCHEMY_POOL_RECYCLE=8
|
||||
@@ -0,0 +1,34 @@
|
||||
from flask import Flask
|
||||
from .init_sqlalchemy import db, ma, init_databases
|
||||
from .init_login import init_login_manager
|
||||
from .init_template_directives import init_template_directives
|
||||
from .init_error_views import init_error_views
|
||||
from .init_mail import init_mail, mail as flask_mail
|
||||
from .init_upload import init_upload
|
||||
from .init_migrate import init_migrate
|
||||
from .init_session import init_session
|
||||
from .init_limit import init_limit
|
||||
from .init_plugins import register_plugin, broadcast_execute
|
||||
|
||||
|
||||
def init_plugs(app: Flask) -> None:
|
||||
# 注册插件a
|
||||
register_plugin(app)
|
||||
broadcast_execute(app, 'event_begin')
|
||||
|
||||
# 注册 Flask 功能
|
||||
init_login_manager(app)
|
||||
init_databases(app)
|
||||
init_mail(app)
|
||||
init_upload(app)
|
||||
init_migrate(app)
|
||||
init_session(app)
|
||||
init_limit(app)
|
||||
|
||||
# 系统蓝图相关
|
||||
init_template_directives(app)
|
||||
init_error_views(app)
|
||||
|
||||
# 初始化插件
|
||||
broadcast_execute(app, 'event_init')
|
||||
broadcast_execute(app, 'event_finish')
|
||||
@@ -0,0 +1,25 @@
|
||||
from flask import render_template, jsonify
|
||||
|
||||
|
||||
def init_error_views(app):
|
||||
@app.errorhandler(403)
|
||||
def page_not_found(e):
|
||||
return render_template('errors/403.html'), 403
|
||||
|
||||
@app.errorhandler(404)
|
||||
def page_not_found(e):
|
||||
return render_template('errors/404.html'), 404
|
||||
|
||||
@app.errorhandler(405)
|
||||
def page_not_found(e):
|
||||
return render_template('errors/404.html'), 404
|
||||
|
||||
@app.errorhandler(500)
|
||||
def internal_server_error(e):
|
||||
return render_template('errors/500.html'), 500
|
||||
|
||||
@app.errorhandler(429)
|
||||
def ratelimit_exceeded(e):
|
||||
return jsonify(
|
||||
success=False, msg="请求频率超限,请稍后再试。"
|
||||
)
|
||||
@@ -0,0 +1,20 @@
|
||||
from flask_limiter import Limiter
|
||||
from flask_login import current_user
|
||||
from flask import request, Flask
|
||||
|
||||
|
||||
# 定义 key 函数:优先使用 current_user.id,否则用 IP
|
||||
def get_user_identifier():
|
||||
# 注意:current_user 可能是 AnonymousUserMixin(未登录)
|
||||
if hasattr(current_user, 'id') and current_user.is_authenticated:
|
||||
return str(current_user.id) # 用户 ID 作为 key
|
||||
return request.remote_addr # 未登录用户则按 IP 限流
|
||||
|
||||
limiter = Limiter(
|
||||
key_func=get_user_identifier,
|
||||
# default_limits=["100 per hour"], # 可选全局默认
|
||||
storage_uri="memory://" # 生产建议: "redis://localhost:6379"
|
||||
)
|
||||
|
||||
def init_limit(app: Flask) -> None:
|
||||
limiter.init_app(app)
|
||||
@@ -1,15 +1,14 @@
|
||||
from flask_login import LoginManager
|
||||
|
||||
|
||||
def init_flask_login(app):
|
||||
def init_login_manager(app):
|
||||
login_manager = LoginManager()
|
||||
login_manager.init_app(app)
|
||||
|
||||
login_manager.login_view = 'adminIndex.login'
|
||||
login_manager.login_message = u'请登录以访问此页面'
|
||||
login_manager.login_view = 'system.passport.login'
|
||||
|
||||
@login_manager.user_loader
|
||||
def load_user(user_id):
|
||||
from applications.models.admin import User
|
||||
from applications.models import User
|
||||
user = User.query.get(int(user_id))
|
||||
return user
|
||||
@@ -0,0 +1,8 @@
|
||||
from flask import Flask
|
||||
from flask_mail import Mail
|
||||
|
||||
mail = Mail()
|
||||
|
||||
|
||||
def init_mail(app: Flask):
|
||||
mail.init_app(app)
|
||||
@@ -0,0 +1,11 @@
|
||||
from flask import Flask
|
||||
|
||||
from applications.extensions.init_sqlalchemy import db
|
||||
from flask_migrate import Migrate
|
||||
from applications.models import *
|
||||
|
||||
migrate = Migrate()
|
||||
|
||||
|
||||
def init_migrate(app: Flask):
|
||||
migrate.init_app(app, db)
|
||||
@@ -0,0 +1,61 @@
|
||||
import os
|
||||
|
||||
from flask import Flask
|
||||
from flask import Blueprint
|
||||
|
||||
import json
|
||||
import importlib
|
||||
|
||||
plugin_bp = Blueprint('plugin', __name__, url_prefix='/plugin')
|
||||
|
||||
PLUGIN_ENABLE_FOLDERS = []
|
||||
PLUGIN_IMPORTLIB = []
|
||||
|
||||
|
||||
def register_plugin(app: Flask):
|
||||
"""
|
||||
获取所有插件并加载
|
||||
"""
|
||||
global PLUGIN_ENABLE_FOLDERS
|
||||
app.register_blueprint(plugin_bp)
|
||||
# 载入插件过程
|
||||
# plugin_folder 配置的是插件的文件夹名
|
||||
PLUGIN_ENABLE_FOLDERS = app.config['PLUGIN_ENABLE_FOLDERS']
|
||||
|
||||
for plugin_folder in PLUGIN_ENABLE_FOLDERS:
|
||||
|
||||
plugin_info = {
|
||||
'plugin_name': plugin_folder
|
||||
}
|
||||
|
||||
try:
|
||||
if os.path.exists("plugins/" + plugin_folder + "/__init__.json"):
|
||||
with open("plugins/" + plugin_folder + "/__init__.json", "r", encoding='utf-8') as f:
|
||||
plugin_info = json.loads(f.read())
|
||||
|
||||
# 将插件全部载入
|
||||
PLUGIN_IMPORTLIB.append(importlib.import_module('plugins.' + plugin_folder))
|
||||
|
||||
print(f" * Plugin: Loaded plugin: {plugin_info['plugin_name']} .")
|
||||
except BaseException as e:
|
||||
info = f" * Plugin: Crash a error when loading {plugin_info['plugin_name'] if len(plugin_info) != 0 else 'plugin'} :" + "\n"
|
||||
app.logger.error(info)
|
||||
app.logger.exception(e)
|
||||
|
||||
|
||||
def broadcast_execute(app: Flask, function_name):
|
||||
for plugin in PLUGIN_IMPORTLIB:
|
||||
|
||||
try:
|
||||
# 初始化完成事件
|
||||
try:
|
||||
getattr(plugin, function_name)(app)
|
||||
except AttributeError: # 没有插件启用事件就不调用
|
||||
pass
|
||||
|
||||
except BaseException as e:
|
||||
app.logger.exception(e)
|
||||
|
||||
if function_name == 'event_finish':
|
||||
with app.app_context():
|
||||
broadcast_execute(app, 'event_context')
|
||||
@@ -0,0 +1,7 @@
|
||||
from flask_session import Session
|
||||
|
||||
sess = Session()
|
||||
|
||||
|
||||
def init_session(app):
|
||||
sess.init_app(app)
|
||||
@@ -0,0 +1,123 @@
|
||||
import datetime
|
||||
import os
|
||||
|
||||
from flask import Flask, request
|
||||
from flask_sqlalchemy import SQLAlchemy
|
||||
from flask_sqlalchemy.query import Query as BaseQuery
|
||||
from flask_marshmallow import Marshmallow
|
||||
from marshmallow import fields
|
||||
from marshmallow.validate import (
|
||||
URL, Email, Range, Length, Equal, Regexp,
|
||||
Predicate, NoneOf, OneOf, ContainsOnly
|
||||
)
|
||||
|
||||
URL.default_message = '无效的链接'
|
||||
Email.default_message = '无效的邮箱地址'
|
||||
Range.message_min = '不能小于{min}'
|
||||
Range.message_max = '不能小于{max}'
|
||||
Range.message_all = '不能超过{min}和{max}这个范围'
|
||||
Length.message_min = '长度不得小于{min}位'
|
||||
Length.message_max = '长度不得大于{max}位'
|
||||
Length.message_all = '长度不能超过{min}和{max}这个范围'
|
||||
Length.message_equal = '长度必须等于{equal}位'
|
||||
Equal.default_message = '必须等于{other}'
|
||||
Regexp.default_message = '非法输入'
|
||||
Predicate.default_message = '非法输入'
|
||||
NoneOf.default_message = '非法输入'
|
||||
OneOf.default_message = '无效的选择'
|
||||
ContainsOnly.default_message = '一个或多个无效的选择'
|
||||
|
||||
fields.Field.default_error_messages = {
|
||||
"required": "缺少必要数据",
|
||||
"null": "数据不能为空",
|
||||
"validator_failed": "非法数据",
|
||||
}
|
||||
|
||||
fields.Str.default_error_messages = {
|
||||
'invalid': "不是合法文本"
|
||||
}
|
||||
|
||||
fields.Int.default_error_messages = {
|
||||
"invalid": "不是合法整数"
|
||||
}
|
||||
|
||||
fields.Number.default_error_messages = {
|
||||
"invalid": "不是合法数字"
|
||||
}
|
||||
|
||||
fields.Boolean.default_error_messages = {
|
||||
"invalid": "不是合法布尔值"
|
||||
}
|
||||
|
||||
|
||||
class Query(BaseQuery):
|
||||
def soft_delete(self):
|
||||
return self.update({"delete_at": datetime.datetime.now()})
|
||||
|
||||
def logic_all(self):
|
||||
return self.filter_by(delete_at=None).all()
|
||||
|
||||
def all_json(self, schema: Marshmallow().Schema):
|
||||
return schema(many=True).dump(self.all())
|
||||
|
||||
def layui_paginate(self, page=None, limit=None):
|
||||
if page is None:
|
||||
page = request.args.get('page', type=int)
|
||||
if limit is None:
|
||||
limit = min(request.args.get('limit', default=10, type=int), 90)
|
||||
|
||||
return self.paginate(page=page,
|
||||
per_page=limit,
|
||||
error_out=False
|
||||
)
|
||||
|
||||
def layui_paginate_json(self, schema, page=None, limit=None):
|
||||
if page is None:
|
||||
page = request.args.get('page', 1, type=int) # 添加默认值
|
||||
if limit is None:
|
||||
limit = request.args.get('limit', 10, type=int) # 添加默认值
|
||||
|
||||
_res = self.paginate(
|
||||
page=page,
|
||||
per_page=limit,
|
||||
error_out=False
|
||||
)
|
||||
return schema(many=True).dump(_res.items), _res.total, _res.page, _res.per_page
|
||||
|
||||
def layui_paginate_db_json(self, page=None, limit=None):
|
||||
if page is None:
|
||||
page = request.args.get('page', 1, type=int) # 添加默认值
|
||||
if limit is None:
|
||||
limit = request.args.get('limit', 10, type=int) # 添加默认值
|
||||
|
||||
_res = self.paginate(
|
||||
page=page,
|
||||
per_page=limit,
|
||||
error_out=False
|
||||
)
|
||||
|
||||
# 获取查询的列名列表
|
||||
column_names = [col["name"] for col in self.column_descriptions]
|
||||
|
||||
# 将元组转换为字典(支持单列或多列)
|
||||
data = [
|
||||
dict(zip(column_names, row))
|
||||
for row in _res.items
|
||||
]
|
||||
|
||||
return data, _res.total, _res.page, _res.per_page
|
||||
|
||||
|
||||
db = SQLAlchemy(query_class=Query)
|
||||
ma = Marshmallow()
|
||||
|
||||
|
||||
def init_databases(app: Flask):
|
||||
db.init_app(app)
|
||||
ma.init_app(app)
|
||||
if os.environ.get('WERKZEUG_RUN_MAIN') == 'true':
|
||||
with app.app_context():
|
||||
try:
|
||||
db.engine.connect()
|
||||
except Exception as e:
|
||||
exit(f"数据库连接失败: {e}")
|
||||
@@ -0,0 +1,17 @@
|
||||
from flask import session, current_app
|
||||
from flask_login import current_user
|
||||
from flask_wtf.csrf import generate_csrf
|
||||
|
||||
|
||||
def init_template_directives(app):
|
||||
@app.template_global()
|
||||
def authorize(power):
|
||||
if current_user.username != current_app.config.get("SUPERADMIN"):
|
||||
return bool(power in session.get('permissions'))
|
||||
else:
|
||||
return True
|
||||
|
||||
@app.template_global()
|
||||
def csrf_input():
|
||||
return f'<input type="hidden" name="csrf_token" value="{generate_csrf()}">'
|
||||
|
||||
@@ -0,0 +1,9 @@
|
||||
from flask import Flask
|
||||
from flask_uploads import configure_uploads
|
||||
from flask_uploads import UploadSet, IMAGES
|
||||
|
||||
photos = UploadSet('photos', IMAGES)
|
||||
|
||||
|
||||
def init_upload(app: Flask):
|
||||
configure_uploads(app, photos)
|
||||
@@ -1,3 +1,11 @@
|
||||
from flask_sqlalchemy import SQLAlchemy
|
||||
|
||||
db = SQLAlchemy()
|
||||
from .admin_dept import Dept
|
||||
from .admin_dict import DictType, DictData
|
||||
from .admin_log import AdminLog
|
||||
from .admin_photo import Photo
|
||||
from .admin_power import Power
|
||||
from .admin_role import Role
|
||||
from .admin_role_power import role_power
|
||||
from .admin_user import User
|
||||
from .admin_user_role import user_role
|
||||
from .admin_mail import Mail
|
||||
from .admin_nav import Nav
|
||||
|
||||
@@ -1,93 +0,0 @@
|
||||
import datetime
|
||||
from flask_login import UserMixin
|
||||
from werkzeug.security import generate_password_hash, check_password_hash
|
||||
from applications.models import db
|
||||
|
||||
|
||||
class User(db.Model, UserMixin):
|
||||
__tablename__ = 'admin_user'
|
||||
id = db.Column(db.Integer, primary_key=True, autoincrement=True, comment='用户ID')
|
||||
username = db.Column(db.String(20), comment='用户名')
|
||||
realname =db.Column(db.String(20), comment='真实名字')
|
||||
password_hash = db.Column(db.String(128), comment='哈希密码')
|
||||
enable = db.Column(db.Integer, default=0, comment='启用')
|
||||
create_at = db.Column(db.DateTime, default=datetime.datetime.now, comment='创建时间')
|
||||
update_at = db.Column(db.DateTime, default=datetime.datetime.now, onupdate=datetime.datetime.now, comment='创建时间')
|
||||
role = db.relationship('Role',secondary="admin_user_role", backref=db.backref('user'),lazy = 'dynamic')
|
||||
# power = db.relationship('Power',secondary="admin_user_role", backref=db.backref('user'))
|
||||
|
||||
def set_password(self, password):
|
||||
self.password_hash = generate_password_hash(password)
|
||||
|
||||
def validate_password(self, password):
|
||||
return check_password_hash(self.password_hash, password)
|
||||
|
||||
|
||||
# 创建中间表
|
||||
user_role = db.Table(
|
||||
"admin_user_role", # 中间表名称
|
||||
db.Column("id", db.Integer, primary_key=True, autoincrement=True, comment='标识'), # 主键
|
||||
db.Column("user_id", db.Integer, db.ForeignKey("admin_user.id"), comment='用户编号'), # 属性 外键
|
||||
db.Column("role_id", db.Integer, db.ForeignKey("admin_role.id"), comment='角色编号'), # 属性 外键
|
||||
)
|
||||
|
||||
|
||||
class Role(db.Model):
|
||||
__tablename__ = 'admin_role'
|
||||
id = db.Column(db.Integer, primary_key=True, comment='角色ID')
|
||||
name = db.Column(db.String(255), comment='角色名称')
|
||||
code = db.Column(db.String(255), comment='角色标识')
|
||||
enable = db.Column(db.Integer, comment='是否启用')
|
||||
remark = db.Column(db.String(255), comment='备注')
|
||||
details = db.Column(db.String(255), comment='详情')
|
||||
sort = db.Column(db.Integer, comment='排序')
|
||||
create_time = db.Column(db.DateTime, default=datetime.datetime.now, comment='创建时间')
|
||||
update_time = db.Column(db.DateTime, default=datetime.datetime.now, onupdate=datetime.datetime.now, comment='更新时间')
|
||||
power = db.relationship('Power',secondary="admin_role_power", backref=db.backref('role'))
|
||||
|
||||
# 创建中间表
|
||||
role_power = db.Table(
|
||||
"admin_role_power", # 中间表名称
|
||||
db.Column("id", db.Integer, primary_key=True, autoincrement=True, comment='标识'), # 主键
|
||||
db.Column("power_id", db.Integer, db.ForeignKey("admin_power.id"), comment='用户编号'), # 属性 外键
|
||||
db.Column("role_id", db.Integer, db.ForeignKey("admin_role.id"), comment='角色编号'), # 属性 外键
|
||||
)
|
||||
|
||||
|
||||
class Power(db.Model):
|
||||
__tablename__ = 'admin_power'
|
||||
id = db.Column(db.Integer, primary_key=True, comment='权限编号')
|
||||
name = db.Column(db.String(255), comment='权限名称')
|
||||
type = db.Column(db.String(1), comment='权限类型')
|
||||
code = db.Column(db.String(30), comment='权限标识')
|
||||
url = db.Column(db.String(255), comment='权限路径')
|
||||
open_type = db.Column(db.String(10), comment='打开方式')
|
||||
parent_id = db.Column(db.Integer, comment='父类编号')
|
||||
icon = db.Column(db.String(128), comment='图标')
|
||||
sort = db.Column(db.Integer, comment='排序')
|
||||
create_time = db.Column(db.DateTime, default=datetime.datetime.now, comment='创建时间')
|
||||
update_time = db.Column(db.DateTime, default=datetime.datetime.now, onupdate=datetime.datetime.now, comment='更新时间')
|
||||
enable = db.Column(db.Integer, comment='是否开启')
|
||||
|
||||
|
||||
class AdminLog(db.Model):
|
||||
__tablename__ = 'admin_admin_log'
|
||||
id = db.Column(db.Integer, primary_key=True)
|
||||
method = db.Column(db.String(10))
|
||||
uid = db.Column(db.Integer)
|
||||
url = db.Column(db.String(255))
|
||||
desc = db.Column(db.Text)
|
||||
ip = db.Column(db.String(255))
|
||||
success = db.Column(db.Integer)
|
||||
user_agent = db.Column(db.Text)
|
||||
create_time = db.Column(db.DateTime, default=datetime.datetime.now)
|
||||
|
||||
|
||||
class Photo(db.Model):
|
||||
__tablename__ = 'admin_photo'
|
||||
id = db.Column(db.Integer, primary_key=True)
|
||||
name = db.Column(db.String(255), nullable=False)
|
||||
href = db.Column(db.String(255))
|
||||
mime = db.Column(db.CHAR(50), nullable=False)
|
||||
size = db.Column(db.CHAR(30), nullable=False)
|
||||
create_time = db.Column(db.DateTime, default=datetime.datetime.now)
|
||||
@@ -0,0 +1,18 @@
|
||||
import datetime
|
||||
from applications.extensions import db
|
||||
|
||||
|
||||
class Dept(db.Model):
|
||||
__tablename__ = 'admin_dept'
|
||||
id = db.Column(db.Integer, primary_key=True, comment="部门ID")
|
||||
parent_id = db.Column(db.Integer, comment="父级编号")
|
||||
dept_name = db.Column(db.String(50), comment="部门名称")
|
||||
sort = db.Column(db.Integer, comment="排序")
|
||||
leader = db.Column(db.String(50), comment="负责人")
|
||||
phone = db.Column(db.String(20), comment="联系方式")
|
||||
email = db.Column(db.String(50), comment="邮箱")
|
||||
status = db.Column(db.Integer, comment='状态(1开启,0关闭)')
|
||||
remark = db.Column(db.Text, comment="备注")
|
||||
address = db.Column(db.String(255), comment="详细地址")
|
||||
create_at = db.Column(db.DateTime, default=datetime.datetime.now, comment='创建时间')
|
||||
update_at = db.Column(db.DateTime, default=datetime.datetime.now, onupdate=datetime.datetime.now, comment='更新时间')
|
||||
@@ -0,0 +1,26 @@
|
||||
import datetime
|
||||
from applications.extensions import db
|
||||
|
||||
|
||||
class DictType(db.Model):
|
||||
__tablename__ = 'admin_dict_type'
|
||||
id = db.Column(db.Integer, primary_key=True)
|
||||
type_name = db.Column(db.String(255), comment='字典类型名称')
|
||||
type_code = db.Column(db.String(255), comment='字典类型标识')
|
||||
description = db.Column(db.String(255), comment='字典类型描述')
|
||||
enable = db.Column(db.Integer, comment='是否开启')
|
||||
create_time = db.Column(db.DateTime, default=datetime.datetime.now, comment='创建时间')
|
||||
update_time = db.Column(db.DateTime, default=datetime.datetime.now, onupdate=datetime.datetime.now, comment='更新时间')
|
||||
|
||||
|
||||
class DictData(db.Model):
|
||||
__tablename__ = 'admin_dict_data'
|
||||
id = db.Column(db.Integer, primary_key=True)
|
||||
data_label = db.Column(db.String(255), comment='字典类型名称')
|
||||
data_value = db.Column(db.String(255), comment='字典类型标识')
|
||||
type_code = db.Column(db.String(255), comment='字典类型描述')
|
||||
is_default = db.Column(db.Integer, comment='是否默认')
|
||||
enable = db.Column(db.Integer, comment='是否开启')
|
||||
remark = db.Column(db.String(255), comment='备注')
|
||||
create_time = db.Column(db.DateTime, default=datetime.datetime.now, comment='创建时间')
|
||||
update_time = db.Column(db.DateTime, default=datetime.datetime.now, onupdate=datetime.datetime.now, comment='更新时间')
|
||||
@@ -0,0 +1,14 @@
|
||||
import datetime
|
||||
from applications.extensions import db
|
||||
|
||||
class AdminLog(db.Model):
|
||||
__tablename__ = 'admin_admin_log'
|
||||
id = db.Column(db.Integer, primary_key=True)
|
||||
method = db.Column(db.String(10))
|
||||
uid = db.Column(db.Integer)
|
||||
url = db.Column(db.String(255))
|
||||
desc = db.Column(db.Text)
|
||||
ip = db.Column(db.String(255))
|
||||
success = db.Column(db.Integer)
|
||||
user_agent = db.Column(db.Text)
|
||||
create_time = db.Column(db.DateTime, default=datetime.datetime.now)
|
||||
@@ -0,0 +1,12 @@
|
||||
import datetime
|
||||
from applications.extensions import db
|
||||
|
||||
|
||||
class Mail(db.Model):
|
||||
__tablename__ = 'admin_mail'
|
||||
id = db.Column(db.Integer, primary_key=True, autoincrement=True, comment='邮件编号')
|
||||
receiver = db.Column(db.String(1024), comment='收件人邮箱')
|
||||
subject = db.Column(db.String(128), comment='邮件主题')
|
||||
content = db.Column(db.Text(), comment='邮件正文')
|
||||
user_id = db.Column(db.Integer, comment='发送人id')
|
||||
create_at = db.Column(db.DateTime, default=datetime.datetime.now, comment='创建时间')
|
||||
@@ -0,0 +1,69 @@
|
||||
"""
|
||||
前台公开导航模型。
|
||||
|
||||
Nav 用于「公开访问的导航聚合页」,与 admin_power 表完全解耦:
|
||||
- admin_power 控制后台管理菜单,需要登录
|
||||
- public_nav 控制前台公开导航,无需登录
|
||||
|
||||
后续若要做前台用户(收藏、提交链接),只需加独立 User 模型,
|
||||
不需要碰 RBAC。
|
||||
"""
|
||||
import datetime
|
||||
from applications.extensions import db
|
||||
|
||||
|
||||
class Nav(db.Model):
|
||||
__tablename__ = 'public_nav'
|
||||
|
||||
id = db.Column(db.Integer, primary_key=True, autoincrement=True, comment='导航ID')
|
||||
|
||||
# 分类名(如"开发工具"/"AI"/"设计资源"),用于首页聚合展示
|
||||
category = db.Column(db.String(50), nullable=False, comment='分类', index=True)
|
||||
|
||||
# 单条导航的标题
|
||||
title = db.Column(db.String(100), nullable=False, comment='标题')
|
||||
|
||||
# 链接 URL(站内或外链)
|
||||
url = db.Column(db.String(255), nullable=False, comment='链接')
|
||||
|
||||
# 简短描述(鼠标悬停时可见)
|
||||
description = db.Column(db.String(255), default='', comment='简介')
|
||||
|
||||
# layui-icon 的 class 名,例如 "layui-icon-website"
|
||||
icon = db.Column(db.String(100), default='layui-icon-link', comment='图标')
|
||||
|
||||
# 同分类下的显示顺序
|
||||
sort = db.Column(db.Integer, default=0, comment='排序')
|
||||
|
||||
# 1=启用,0=禁用(禁用后前台不再展示,后台列表仍可见)
|
||||
status = db.Column(db.Integer, default=1, comment='状态(1启用,0关闭)')
|
||||
|
||||
# 1=外链(新窗口打开),0=站内(当前窗口)
|
||||
is_external = db.Column(db.Integer, default=1, comment='是否外链')
|
||||
|
||||
# 创建者(后台管理员用户名,便于追溯),非空约束放宽以便匿名维护
|
||||
create_by = db.Column(db.String(50), default='admin', comment='创建者')
|
||||
|
||||
create_at = db.Column(db.DateTime, default=datetime.datetime.now, comment='创建时间')
|
||||
update_at = db.Column(
|
||||
db.DateTime,
|
||||
default=datetime.datetime.now,
|
||||
onupdate=datetime.datetime.now,
|
||||
comment='更新时间',
|
||||
)
|
||||
|
||||
def to_dict(self):
|
||||
"""方便模板直接读取"""
|
||||
return {
|
||||
'id': self.id,
|
||||
'category': self.category,
|
||||
'title': self.title,
|
||||
'url': self.url,
|
||||
'description': self.description or '',
|
||||
'icon': self.icon or 'layui-icon-link',
|
||||
'sort': self.sort or 0,
|
||||
'status': self.status,
|
||||
'is_external': self.is_external,
|
||||
'create_by': self.create_by,
|
||||
'create_at': self.create_at.strftime('%Y-%m-%d %H:%M:%S') if self.create_at else '',
|
||||
}
|
||||
@@ -0,0 +1,12 @@
|
||||
import datetime
|
||||
from applications.extensions import db
|
||||
|
||||
|
||||
class Photo(db.Model):
|
||||
__tablename__ = 'admin_photo'
|
||||
id = db.Column(db.Integer, primary_key=True)
|
||||
name = db.Column(db.String(255), nullable=False)
|
||||
href = db.Column(db.String(255))
|
||||
mime = db.Column(db.CHAR(50), nullable=False)
|
||||
size = db.Column(db.CHAR(30), nullable=False)
|
||||
create_time = db.Column(db.DateTime, default=datetime.datetime.now)
|
||||
@@ -0,0 +1,18 @@
|
||||
import datetime
|
||||
from applications.extensions import db
|
||||
|
||||
|
||||
class Power(db.Model):
|
||||
__tablename__ = 'admin_power'
|
||||
id = db.Column(db.Integer, primary_key=True, comment='权限编号')
|
||||
name = db.Column(db.String(255), comment='权限名称')
|
||||
type = db.Column(db.String(1), comment='权限类型')
|
||||
code = db.Column(db.String(30), comment='权限标识')
|
||||
url = db.Column(db.String(255), comment='权限路径')
|
||||
open_type = db.Column(db.String(10), comment='打开方式')
|
||||
parent_id = db.Column(db.Integer, comment='父类编号')
|
||||
icon = db.Column(db.String(128), comment='图标')
|
||||
sort = db.Column(db.Integer, comment='排序')
|
||||
create_time = db.Column(db.DateTime, default=datetime.datetime.now, comment='创建时间')
|
||||
update_time = db.Column(db.DateTime, default=datetime.datetime.now, onupdate=datetime.datetime.now, comment='更新时间')
|
||||
enable = db.Column(db.Integer, comment='是否开启')
|
||||
@@ -0,0 +1,16 @@
|
||||
import datetime
|
||||
from applications.extensions import db
|
||||
|
||||
|
||||
class Role(db.Model):
|
||||
__tablename__ = 'admin_role'
|
||||
id = db.Column(db.Integer, primary_key=True, comment='角色ID')
|
||||
name = db.Column(db.String(255), comment='角色名称')
|
||||
code = db.Column(db.String(255), comment='角色标识')
|
||||
enable = db.Column(db.Integer, comment='是否启用')
|
||||
remark = db.Column(db.String(255), comment='备注')
|
||||
details = db.Column(db.String(255), comment='详情')
|
||||
sort = db.Column(db.Integer, comment='排序')
|
||||
create_time = db.Column(db.DateTime, default=datetime.datetime.now, comment='创建时间')
|
||||
update_time = db.Column(db.DateTime, default=datetime.datetime.now, onupdate=datetime.datetime.now, comment='更新时间')
|
||||
power = db.relationship('Power', secondary="admin_role_power", backref=db.backref('role'))
|
||||
@@ -0,0 +1,9 @@
|
||||
from applications.extensions import db
|
||||
|
||||
# 创建中间表
|
||||
role_power = db.Table(
|
||||
"admin_role_power", # 中间表名称
|
||||
db.Column("id", db.Integer, primary_key=True, autoincrement=True, comment='标识'), # 主键
|
||||
db.Column("power_id", db.Integer, db.ForeignKey("admin_power.id"), comment='用户编号'), # 属性 外键
|
||||
db.Column("role_id", db.Integer, db.ForeignKey("admin_role.id"), comment='角色编号'), # 属性 外键
|
||||
)
|
||||
@@ -0,0 +1,25 @@
|
||||
import datetime
|
||||
from flask_login import UserMixin
|
||||
from werkzeug.security import generate_password_hash, check_password_hash
|
||||
from applications.extensions import db
|
||||
|
||||
|
||||
class User(db.Model, UserMixin):
|
||||
__tablename__ = 'admin_user'
|
||||
id = db.Column(db.Integer, primary_key=True, autoincrement=True, comment='用户ID')
|
||||
username = db.Column(db.String(20), comment='用户名')
|
||||
realname = db.Column(db.String(20), comment='真实名字')
|
||||
avatar = db.Column(db.String(255), comment='头像', default="/static/system/admin/images/avatar.jpg")
|
||||
remark = db.Column(db.String(255), comment='备注')
|
||||
password_hash = db.Column(db.String(128), comment='哈希密码')
|
||||
enable = db.Column(db.Integer, default=0, comment='启用')
|
||||
dept_id = db.Column(db.Integer, comment='部门id')
|
||||
create_at = db.Column(db.DateTime, default=datetime.datetime.now, comment='创建时间')
|
||||
update_at = db.Column(db.DateTime, default=datetime.datetime.now, onupdate=datetime.datetime.now, comment='创建时间')
|
||||
role = db.relationship('Role', secondary="admin_user_role", backref=db.backref('user'), lazy='dynamic')
|
||||
|
||||
def set_password(self, password):
|
||||
self.password_hash = generate_password_hash(password)
|
||||
|
||||
def validate_password(self, password):
|
||||
return check_password_hash(self.password_hash, password)
|
||||
@@ -0,0 +1,9 @@
|
||||
from applications.extensions import db
|
||||
|
||||
# 创建中间表
|
||||
user_role = db.Table(
|
||||
"admin_user_role", # 中间表名称
|
||||
db.Column("id", db.Integer, primary_key=True, autoincrement=True, comment='标识'), # 主键
|
||||
db.Column("user_id", db.Integer, db.ForeignKey("admin_user.id"), comment='用户编号'), # 属性 外键
|
||||
db.Column("role_id", db.Integer, db.ForeignKey("admin_role.id"), comment='角色编号'), # 属性 外键
|
||||
)
|
||||
@@ -0,0 +1,9 @@
|
||||
|
||||
from .admin_role import RoleOutSchema
|
||||
from .admin_power import PowerOutSchema, PowerOutSchema2
|
||||
from .admin_dict import DictDataOutSchema, DictTypeOutSchema
|
||||
from .admin_dept import DeptSchema
|
||||
from .admin_log import LogOutSchema
|
||||
from .admin_photo import PhotoOutSchema
|
||||
from .admin_mail import MailOutSchema
|
||||
from .admin_nav import NavOutSchema, NavManageSchema
|
||||
@@ -0,0 +1,12 @@
|
||||
from flask_marshmallow.sqla import SQLAlchemyAutoSchema
|
||||
|
||||
from applications.models import Dept
|
||||
|
||||
|
||||
class DeptSchema(SQLAlchemyAutoSchema):
|
||||
class Meta:
|
||||
model = Dept # table = models.Album.__table__
|
||||
# include_relationships = True # 输出模型对象时同时对外键,是否也一并进行处理
|
||||
include_fk = True # 序列化阶段是否也一并返回主键
|
||||
# fields= ["id","name"] # 启动的字段列表
|
||||
# exclude = ["id","name"] # 排除字段列表
|
||||
@@ -0,0 +1,21 @@
|
||||
from applications.extensions import ma
|
||||
from marshmallow import fields
|
||||
|
||||
|
||||
class DictTypeOutSchema(ma.Schema):
|
||||
id = fields.Str(attribute="id")
|
||||
typeName = fields.Str(attribute="type_name")
|
||||
typeCode = fields.Str(attribute="type_code")
|
||||
description = fields.Str(attribute="description")
|
||||
createTime = fields.Str(attribute="create_time")
|
||||
updateName = fields.Str(attribute="update_time")
|
||||
remark = fields.Str()
|
||||
enable = fields.Str()
|
||||
|
||||
|
||||
class DictDataOutSchema(ma.Schema):
|
||||
dataId = fields.Str(attribute="id")
|
||||
dataLabel = fields.Str(attribute="data_label")
|
||||
dataValue = fields.Str(attribute="data_value")
|
||||
remark = fields.Str()
|
||||
enable = fields.Str()
|
||||
@@ -0,0 +1,14 @@
|
||||
from applications.extensions import ma
|
||||
from marshmallow import fields
|
||||
|
||||
|
||||
class LogOutSchema(ma.Schema):
|
||||
id = fields.Integer()
|
||||
method = fields.Str()
|
||||
uid = fields.Str()
|
||||
url = fields.Str()
|
||||
desc = fields.Str()
|
||||
ip = fields.Str()
|
||||
user_agent = fields.Str()
|
||||
success = fields.Bool()
|
||||
create_time = fields.DateTime()
|
||||
@@ -0,0 +1,19 @@
|
||||
from applications.extensions import ma
|
||||
from marshmallow import fields
|
||||
from applications.models import User
|
||||
|
||||
|
||||
# 用户models的序列化类
|
||||
class MailOutSchema(ma.Schema):
|
||||
id = fields.Integer()
|
||||
receiver = fields.Str()
|
||||
subject = fields.Str()
|
||||
content = fields.Str()
|
||||
realname = fields.Method("get_realname")
|
||||
create_at = fields.DateTime()
|
||||
|
||||
def get_realname(self, obj):
|
||||
if obj.user_id != None:
|
||||
return User.query.filter_by(id=obj.user_id).first().realname
|
||||
else:
|
||||
return None
|
||||
@@ -0,0 +1,17 @@
|
||||
from flask_marshmallow.sqla import SQLAlchemyAutoSchema
|
||||
|
||||
from applications.models import Nav
|
||||
|
||||
|
||||
class NavOutSchema(SQLAlchemyAutoSchema):
|
||||
"""前台展示用:序列化 Nav 对象为 JSON"""
|
||||
class Meta:
|
||||
model = Nav
|
||||
include_fk = True
|
||||
|
||||
|
||||
class NavManageSchema(SQLAlchemyAutoSchema):
|
||||
"""后台管理用:同上,前缀分开便于将来按需差异化"""
|
||||
class Meta:
|
||||
model = Nav
|
||||
include_fk = True
|
||||
@@ -0,0 +1,12 @@
|
||||
from applications.extensions import ma
|
||||
from marshmallow import fields
|
||||
|
||||
|
||||
class PhotoOutSchema(ma.Schema):
|
||||
id = fields.Integer()
|
||||
name = fields.Str()
|
||||
href = fields.Str()
|
||||
mime = fields.Str()
|
||||
size = fields.Str()
|
||||
ext = fields.Str()
|
||||
create_time = fields.DateTime()
|
||||
@@ -0,0 +1,44 @@
|
||||
from flask_marshmallow.sqla import SQLAlchemyAutoSchema
|
||||
|
||||
from applications.extensions import ma
|
||||
from marshmallow import fields
|
||||
|
||||
from applications.models import Power
|
||||
|
||||
|
||||
class PowerSchema(SQLAlchemyAutoSchema):
|
||||
class Meta:
|
||||
model = Power # table = models.Album.__table__
|
||||
# include_relationships = True # 输出模型对象时同时对外键,是否也一并进行处理
|
||||
include_fk = True # 序列化阶段是否也一并返回主键
|
||||
# fields= ["id","name"] # 启动的字段列表
|
||||
# exclude = ["id","name"] # 排除字段列表
|
||||
|
||||
# 权限models序列化类
|
||||
class PowerOutSchema(ma.Schema):
|
||||
id = fields.Integer()
|
||||
title = fields.Str(attribute="name")
|
||||
type = fields.Str()
|
||||
code = fields.Str()
|
||||
href = fields.Str(attribute="url")
|
||||
openType = fields.Str(attribute="open_type")
|
||||
parent_id = fields.Integer()
|
||||
icon = fields.Str()
|
||||
sort = fields.Integer()
|
||||
create_time = fields.DateTime()
|
||||
update_time = fields.DateTime()
|
||||
enable = fields.Integer()
|
||||
|
||||
|
||||
class PowerOutSchema2(ma.Schema): # 序列化类
|
||||
powerId = fields.Str(attribute="id")
|
||||
powerName = fields.Str(attribute="name")
|
||||
powerType = fields.Str(attribute="type")
|
||||
powerUrl = fields.Str(attribute="url")
|
||||
openType = fields.Str(attribute="open_type")
|
||||
parentId = fields.Str(attribute="parent_id")
|
||||
icon = fields.Str()
|
||||
sort = fields.Integer()
|
||||
create_time = fields.DateTime()
|
||||
update_time = fields.DateTime()
|
||||
enable = fields.Integer()
|
||||
@@ -0,0 +1,12 @@
|
||||
from flask_marshmallow.sqla import SQLAlchemyAutoSchema
|
||||
|
||||
from applications.models import Role
|
||||
|
||||
|
||||
class RoleOutSchema(SQLAlchemyAutoSchema):
|
||||
class Meta:
|
||||
model = Role # table = models.Album.__table__
|
||||
# include_relationships = True # 输出模型对象时同时对外键,是否也一并进行处理
|
||||
include_fk = True # 序列化阶段是否也一并返回主键
|
||||
# fields= ["id","name"] # 启动的字段列表
|
||||
# exclude = ["id","name"] # 排除字段列表
|
||||
@@ -1,26 +0,0 @@
|
||||
from captcha.image import ImageCaptcha
|
||||
from PIL import Image
|
||||
import random
|
||||
|
||||
|
||||
# 定义随机方法
|
||||
def random_captcha():
|
||||
# 定义一个容器
|
||||
captcha_text = []
|
||||
for i in range(4):
|
||||
# 定义验证码字符
|
||||
c = random.choice(['0', '1', '2', '4', '6', '8'])
|
||||
captcha_text.append(c)
|
||||
# 返回一个随机生成的字符串
|
||||
return ''.join(captcha_text)
|
||||
|
||||
|
||||
# 生成验证码方法
|
||||
def gen_captcha():
|
||||
# 定义图片对象
|
||||
image = ImageCaptcha()
|
||||
# 获取字符串
|
||||
captcha_text = random_captcha()
|
||||
# 生成图像
|
||||
captcha_image = Image.open(image.generate(captcha_text))
|
||||
return captcha_text, captcha_image
|
||||
@@ -1,106 +0,0 @@
|
||||
import datetime
|
||||
import json
|
||||
|
||||
import pymysql
|
||||
from applications.config.database import HOST, USERNAME, PASSWORD, DATABASE, PORT
|
||||
|
||||
DB_CONFIG = {
|
||||
"host": HOST,
|
||||
"port": int(PORT),
|
||||
"user": USERNAME,
|
||||
"password": PASSWORD,
|
||||
"db": DATABASE,
|
||||
"charset": "utf8"
|
||||
}
|
||||
|
||||
|
||||
class SQLManager(object):
|
||||
|
||||
# 初始化实例方法
|
||||
def __init__(self):
|
||||
self.conn = None
|
||||
self.cursor = None
|
||||
self.connect()
|
||||
|
||||
# 连接数据库
|
||||
def connect(self):
|
||||
self.conn = pymysql.connect(
|
||||
host=DB_CONFIG.get('host'),
|
||||
port=DB_CONFIG.get('port'),
|
||||
user=DB_CONFIG.get('user'),
|
||||
passwd=DB_CONFIG.get('password'),
|
||||
db=DB_CONFIG.get('db'),
|
||||
)
|
||||
self.cursor = self.conn.cursor(cursor=pymysql.cursors.DictCursor)
|
||||
|
||||
# 查询多条数据
|
||||
|
||||
def get_list(self, sql, args=None):
|
||||
self.cursor.execute(sql, args)
|
||||
result = self.cursor.fetchall()
|
||||
return result
|
||||
|
||||
# 查询多条数据后关闭
|
||||
def get_list_close(self, sql, args=None):
|
||||
self.cursor.execute(sql, args)
|
||||
result = self.cursor.fetchall()
|
||||
self.close()
|
||||
return result
|
||||
|
||||
# 查询单条数据
|
||||
def get_one(self, sql, args=None):
|
||||
self.cursor.execute(sql, args)
|
||||
result = self.cursor.fetchone()
|
||||
return result
|
||||
|
||||
# 查询单条数据后关闭
|
||||
def get_one_close(self, sql, args=None):
|
||||
self.cursor.execute(sql, args)
|
||||
result = self.cursor.fetchone()
|
||||
self.close()
|
||||
return result
|
||||
|
||||
# 执行单条SQL语句
|
||||
def moddify(self, sql, args=None):
|
||||
self.cursor.execute(sql, args)
|
||||
self.conn.commit()
|
||||
|
||||
# 执行多条SQL语句
|
||||
def multi_modify(self, sql, args=None):
|
||||
self.cursor.executemany(sql, args)
|
||||
self.conn.commit()
|
||||
|
||||
# 创建单条记录的语句
|
||||
def create(self, sql, args=None):
|
||||
self.cursor.execute(sql, args)
|
||||
self.conn.commit()
|
||||
last_id = self.cursor.lastrowid
|
||||
return last_id
|
||||
|
||||
# 关闭数据库cursor和连接
|
||||
def close(self):
|
||||
self.cursor.close()
|
||||
self.conn.close()
|
||||
|
||||
# 进入with语句自动执行
|
||||
def __enter__(self):
|
||||
return self
|
||||
|
||||
# 退出with语句块自动执行
|
||||
def __exit__(self, exc_type, exc_val, exc_tb):
|
||||
self.close()
|
||||
|
||||
|
||||
"""
|
||||
原生查询dict的datetime解析器
|
||||
用法
|
||||
json.dumps(dictxxx, cls=DateEncoder)
|
||||
"""
|
||||
|
||||
|
||||
class DateEncoder(json.JSONEncoder):
|
||||
def default(self, obj):
|
||||
if isinstance(obj, datetime.datetime):
|
||||
return obj.strftime("%Y-%m-%d %H:%M:%S")
|
||||
else:
|
||||
return json.JSONEncoder.default(self, obj)
|
||||
@@ -1,47 +0,0 @@
|
||||
import os
|
||||
from flask import current_app
|
||||
from flask_marshmallow import Marshmallow
|
||||
from marshmallow import fields
|
||||
from sqlalchemy import desc
|
||||
from applications.models import db
|
||||
from applications.models.admin import Photo
|
||||
from applications.service.upload import photos
|
||||
ma = Marshmallow()
|
||||
|
||||
|
||||
class PhotoSchema(ma.Schema):
|
||||
id = fields.Integer()
|
||||
name = fields.Str()
|
||||
href = fields.Str()
|
||||
mime = fields.Str()
|
||||
size = fields.Str()
|
||||
ext = fields.Str()
|
||||
create_time = fields.DateTime()
|
||||
|
||||
|
||||
def get_photo(page, limit):
|
||||
photo = Photo.query.order_by(desc(Photo.create_time)).paginate(page=page, per_page=limit, error_out=False)
|
||||
count = Photo.query.count()
|
||||
role_schema = PhotoSchema(many=True)
|
||||
output = role_schema.dump(photo.items)
|
||||
return output, count
|
||||
|
||||
|
||||
def upload_one(photo,mime):
|
||||
filename = photos.save(photo)
|
||||
file_url = photos.url(filename)
|
||||
|
||||
upload_url = current_app.config.get("UPLOADED_PHOTOS_DEST")
|
||||
size = os.path.getsize(upload_url + '/' + filename)
|
||||
photo = Photo(name=filename, href=file_url, mime=mime, size=size)
|
||||
db.session.add(photo)
|
||||
db.session.commit()
|
||||
return upload_url
|
||||
|
||||
def delete_photo_by_id(id):
|
||||
photo_name = Photo.query.filter_by(id=id).first().name
|
||||
photo = Photo.query.filter_by(id=id).delete()
|
||||
db.session.commit()
|
||||
upload_url = current_app.config.get("UPLOADED_PHOTOS_DEST")
|
||||
os.remove(upload_url + '/' + photo_name)
|
||||
return photo
|
||||
@@ -1,93 +0,0 @@
|
||||
from io import BytesIO
|
||||
from flask import session, make_response
|
||||
from flask_login import current_user
|
||||
from flask_marshmallow import Marshmallow
|
||||
from marshmallow import fields
|
||||
from applications.models.admin import Power
|
||||
from applications.service.CaptchaTool import gen_captcha
|
||||
|
||||
ma = Marshmallow()
|
||||
|
||||
|
||||
# 权限models序列化类
|
||||
class PowerSchema(ma.Schema):
|
||||
id = fields.Integer()
|
||||
title = fields.Str(attribute="name")
|
||||
type = fields.Str()
|
||||
code = fields.Str()
|
||||
href = fields.Str(attribute="url")
|
||||
open_type = fields.Str()
|
||||
parent_id = fields.Integer()
|
||||
icon = fields.Str()
|
||||
sort = fields.Integer()
|
||||
create_time = fields.DateTime()
|
||||
update_time = fields.DateTime()
|
||||
enable = fields.Integer()
|
||||
|
||||
|
||||
# 授权路由存入session
|
||||
def add_auth_session():
|
||||
role = current_user.role
|
||||
user_power = []
|
||||
for i in role:
|
||||
if i.enable == 0:
|
||||
continue
|
||||
for p in i.power:
|
||||
if p.enable == 0:
|
||||
continue
|
||||
user_power.append(p.code)
|
||||
session['permissions'] = user_power
|
||||
|
||||
|
||||
# 生成菜单树
|
||||
def make_menu_tree():
|
||||
# power0 = Power.query.filter(
|
||||
# Power.type == 0,
|
||||
# ).all()
|
||||
# power1 = Power.query.filter(
|
||||
# Power.type == 1
|
||||
# ).all()
|
||||
role = current_user.role
|
||||
power0 = []
|
||||
power1 = []
|
||||
for i in role:
|
||||
if i.enable == 0:
|
||||
continue
|
||||
for p in i.power:
|
||||
if p.enable == 0:
|
||||
continue
|
||||
if int(p.type) == 0:
|
||||
power0.append(p)
|
||||
else:
|
||||
power1.append(p)
|
||||
|
||||
power_schema = PowerSchema(many=True) # 用已继承ma.ModelSchema类的自定制类生成序列化类
|
||||
power0_dict = power_schema.dump(power0) # 生成可序列化对象
|
||||
power1_dict = power_schema.dump(power1) # 生成可序列化对象
|
||||
power0_dict = sorted(power0_dict, key=lambda i: i['sort'])
|
||||
power1_dict = sorted(power1_dict, key=lambda i: i['sort'])
|
||||
# print(power0)
|
||||
# print(power1)
|
||||
|
||||
menu = []
|
||||
|
||||
for p0 in power0_dict:
|
||||
for p1 in power1_dict:
|
||||
if p0.get('id') == p1.get('parent_id'):
|
||||
if p0.get("children") is None:
|
||||
p0['children'] = []
|
||||
p0['children'].append(p1)
|
||||
menu.append(p0)
|
||||
return menu
|
||||
|
||||
|
||||
# 生成验证码
|
||||
def get_captcha():
|
||||
code, image = gen_captcha()
|
||||
out = BytesIO()
|
||||
session["code"] = code
|
||||
image.save(out, 'png')
|
||||
out.seek(0)
|
||||
resp = make_response(out.read())
|
||||
resp.content_type = 'image/png'
|
||||
return resp, code
|
||||
@@ -1,130 +0,0 @@
|
||||
from flask_marshmallow import Marshmallow
|
||||
from marshmallow import fields
|
||||
|
||||
from applications.models import db
|
||||
from applications.models.admin import Power, Role
|
||||
|
||||
ma = Marshmallow()
|
||||
|
||||
|
||||
class PowerSchema(ma.Schema): # 序列化类
|
||||
powerId = fields.Str(attribute="id")
|
||||
powerName = fields.Str(attribute="name")
|
||||
powerType = fields.Str(attribute="type")
|
||||
powerUrl = fields.Str(attribute="url")
|
||||
openType = fields.Str(attribute="pen_type")
|
||||
parentId = fields.Str(attribute="parent_id")
|
||||
icon = fields.Str()
|
||||
sort = fields.Integer()
|
||||
create_time = fields.DateTime()
|
||||
update_time = fields.DateTime()
|
||||
enable = fields.Integer()
|
||||
|
||||
|
||||
def get_power_dict():
|
||||
power = Power.query.all()
|
||||
power_schema = PowerSchema(many=True)
|
||||
power_dict = power_schema.dump(power)
|
||||
return power_dict
|
||||
|
||||
|
||||
# 选择父节点
|
||||
def select_parent():
|
||||
power = Power.query.all()
|
||||
power_schema = PowerSchema(many=True)
|
||||
power_dict = power_schema.dump(power)
|
||||
power_dict.append({"powerId": 0, "powerName": "顶级权限", "parentId": -1})
|
||||
return power_dict
|
||||
|
||||
|
||||
# 增加权限
|
||||
def save_power(req):
|
||||
icon = req.get("icon")
|
||||
openType = req.get("openType")
|
||||
parentId = req.get("parentId")
|
||||
powerCode = req.get("powerCode")
|
||||
powerName = req.get("powerName")
|
||||
powerType = req.get("powerType")
|
||||
powerUrl = req.get("powerUrl")
|
||||
sort = req.get("sort")
|
||||
power = Power(
|
||||
icon=icon,
|
||||
open_type=openType,
|
||||
parent_id=parentId,
|
||||
code=powerCode,
|
||||
name=powerName,
|
||||
type=powerType,
|
||||
url=powerUrl,
|
||||
sort=sort,
|
||||
enable=1
|
||||
)
|
||||
r = db.session.add(power)
|
||||
db.session.commit()
|
||||
return r
|
||||
|
||||
|
||||
# 根据id查询权限
|
||||
def get_power_by_id(id):
|
||||
p = Power.query.filter_by(id=id).first()
|
||||
return p
|
||||
|
||||
|
||||
# 更新权限
|
||||
def update_power(req_json):
|
||||
id = req_json.get("powerId")
|
||||
data = {
|
||||
"icon": req_json.get("icon"),
|
||||
"open_type": req_json.get("openType"),
|
||||
"parent_id": req_json.get("parentId"),
|
||||
"code": req_json.get("powerCode"),
|
||||
"name": req_json.get("powerName"),
|
||||
"type": req_json.get("powerType"),
|
||||
"url": req_json.get("powerUrl"),
|
||||
"sort": req_json.get("sort")
|
||||
}
|
||||
print(data)
|
||||
power = Power.query.filter_by(id=id).update(data)
|
||||
db.session.commit()
|
||||
print(power)
|
||||
return power
|
||||
|
||||
|
||||
# 启动权限
|
||||
def enable_status(id):
|
||||
enable = 1
|
||||
user = Power.query.filter_by(id=id).update({"enable": enable})
|
||||
if user:
|
||||
db.session.commit()
|
||||
return True
|
||||
return False
|
||||
|
||||
|
||||
# 停用权限
|
||||
def disable_status(id):
|
||||
enable = 0
|
||||
user = Power.query.filter_by(id=id).update({"enable": enable})
|
||||
if user:
|
||||
db.session.commit()
|
||||
return True
|
||||
return False
|
||||
|
||||
|
||||
# 删除权限(目前没有判断父节点自动删除子节点)
|
||||
def remove_power(id):
|
||||
power = Power.query.filter_by(id=id).first()
|
||||
role_id_list = []
|
||||
roles = power.role
|
||||
for role in roles:
|
||||
role_id_list.append(role.id)
|
||||
roles = Role.query.filter(Role.id.in_(role_id_list)).all()
|
||||
for p in roles:
|
||||
power.role.remove(p)
|
||||
r = Power.query.filter_by(id=id).delete()
|
||||
db.session.commit()
|
||||
return r
|
||||
|
||||
|
||||
# 批量删除权限
|
||||
def batch_remove(ids):
|
||||
for id in ids:
|
||||
remove_power(id)
|
||||
@@ -1,180 +0,0 @@
|
||||
from flask import jsonify
|
||||
from flask_marshmallow import Marshmallow
|
||||
from marshmallow import fields
|
||||
from sqlalchemy import and_
|
||||
|
||||
from applications.models import db
|
||||
from applications.models.admin import Role, Power, User
|
||||
|
||||
ma = Marshmallow()
|
||||
|
||||
|
||||
class RoleSchema(ma.Schema):
|
||||
id = fields.Integer()
|
||||
roleName = fields.Str(attribute="name")
|
||||
roleCode = fields.Str(attribute="code")
|
||||
enable = fields.Str()
|
||||
remark = fields.Str()
|
||||
details = fields.Str()
|
||||
sort = fields.Integer()
|
||||
create_at = fields.DateTime()
|
||||
update_at = fields.DateTime()
|
||||
|
||||
|
||||
class PowerSchema(ma.Schema): # 序列化类
|
||||
powerId = fields.Str(attribute="id")
|
||||
powerName = fields.Str(attribute="name")
|
||||
powerType = fields.Str(attribute="type")
|
||||
powerUrl = fields.Str(attribute="url")
|
||||
openType = fields.Str(attribute="pen_type")
|
||||
parentId = fields.Str(attribute="parent_id")
|
||||
icon = fields.Str()
|
||||
sort = fields.Integer()
|
||||
create_time = fields.DateTime()
|
||||
update_time = fields.DateTime()
|
||||
enable = fields.Integer()
|
||||
|
||||
|
||||
# 获取角色对象
|
||||
def get_role_data(page, limit, filters):
|
||||
role = Role.query.filter(and_(*[getattr(Role, k).like(v) for k, v in filters.items()])).paginate(page=page,
|
||||
per_page=limit,
|
||||
error_out=False)
|
||||
count = Role.query.count()
|
||||
return role, count
|
||||
|
||||
|
||||
# 获取角色dict
|
||||
def get_role_data_dict(page, limit, filters):
|
||||
role, count = get_role_data(page, limit, filters)
|
||||
role_schema = RoleSchema(many=True) # 用已继承ma.ModelSchema类的自定制类生成序列化类
|
||||
output = role_schema.dump(role.items) # 生成可序列化对象
|
||||
return output, count
|
||||
|
||||
|
||||
# 增加角色
|
||||
def add_role(req):
|
||||
details = req.get("details")
|
||||
enable = req.get("enable")
|
||||
roleCode = req.get("roleCode")
|
||||
roleName = req.get("roleName")
|
||||
sort = req.get("sort")
|
||||
role = Role(
|
||||
details=details,
|
||||
enable=enable,
|
||||
code=roleCode,
|
||||
name=roleName,
|
||||
sort=sort
|
||||
)
|
||||
db.session.add(role)
|
||||
db.session.commit()
|
||||
|
||||
|
||||
# 通过id获取角色
|
||||
def get_role_by_id(id):
|
||||
r = Role.query.filter_by(id=id).first()
|
||||
return r
|
||||
|
||||
|
||||
# 更新角色
|
||||
def update_role(req_json):
|
||||
id = req_json.get("roleId")
|
||||
data = {
|
||||
"code": req_json.get("roleCode"),
|
||||
"name": req_json.get("roleName"),
|
||||
"sort": req_json.get("sort"),
|
||||
"enable": req_json.get("enable"),
|
||||
"details": req_json.get("details")
|
||||
}
|
||||
print(data)
|
||||
role = Role.query.filter_by(id=id).update(data)
|
||||
db.session.commit()
|
||||
return role
|
||||
|
||||
|
||||
# 获取角色的权限
|
||||
def get_role_power(id):
|
||||
role = Role.query.filter_by(id=id).first()
|
||||
check_powers = role.power
|
||||
check_powers_list = []
|
||||
for cp in check_powers:
|
||||
check_powers_list.append(cp.id)
|
||||
powers = Power.query.all()
|
||||
power_schema = PowerSchema(many=True) # 用已继承ma.ModelSchema类的自定制类生成序列化类
|
||||
output = power_schema.dump(powers) # 生成可序列化对象
|
||||
for i in output:
|
||||
if int(i.get("powerId")) in check_powers_list:
|
||||
i["checkArr"] = "1"
|
||||
else:
|
||||
i["checkArr"] = "0"
|
||||
return output
|
||||
|
||||
|
||||
# 更新角色权限
|
||||
def update_role_power(id, power_list):
|
||||
role = Role.query.filter_by(id=id).first()
|
||||
power_id_list = []
|
||||
for p in role.power:
|
||||
power_id_list.append(p.id)
|
||||
print(p.id)
|
||||
print(power_id_list)
|
||||
powers = Power.query.filter(Power.id.in_(power_id_list)).all()
|
||||
for p in powers:
|
||||
role.power.remove(p)
|
||||
powers = Power.query.filter(Power.id.in_(power_list)).all()
|
||||
for p in powers:
|
||||
role.power.append(p)
|
||||
db.session.commit()
|
||||
|
||||
|
||||
# 启动角色
|
||||
def enable_status(id):
|
||||
enable = 1
|
||||
role = Role.query.filter_by(id=id).update({"enable": enable})
|
||||
if role:
|
||||
db.session.commit()
|
||||
return True
|
||||
return False
|
||||
|
||||
|
||||
# 停用角色
|
||||
def disable_status(id):
|
||||
enable = 0
|
||||
role = Role.query.filter_by(id=id).update({"enable": enable})
|
||||
if role:
|
||||
db.session.commit()
|
||||
return True
|
||||
return False
|
||||
|
||||
|
||||
|
||||
|
||||
# 删除角色
|
||||
def remove_role(id):
|
||||
role = Role.query.filter_by(id=id).first()
|
||||
# 删除该角色的权限
|
||||
power_id_list = []
|
||||
for p in role.power:
|
||||
power_id_list.append(p.id)
|
||||
|
||||
powers = Power.query.filter(Power.id.in_(power_id_list)).all()
|
||||
for p in powers:
|
||||
role.power.remove(p)
|
||||
user_id_list = []
|
||||
for u in role.user:
|
||||
user_id_list.append(u.id)
|
||||
users = User.query.filter(User.id.in_(user_id_list)).all()
|
||||
for u in users:
|
||||
role.user.remove(u)
|
||||
r = Role.query.filter_by(id=id).delete()
|
||||
db.session.commit()
|
||||
return r
|
||||
|
||||
|
||||
# 批量删除
|
||||
def batch_remove(ids):
|
||||
# role = Role.query.filter(Role.id.in_(ids)).delete(synchronize_session=False)
|
||||
# db.session.commit()
|
||||
for id in ids:
|
||||
remove_role(id)
|
||||
|
||||
@@ -1,142 +0,0 @@
|
||||
from flask import jsonify
|
||||
from flask_login import current_user
|
||||
from flask_marshmallow import Marshmallow
|
||||
from marshmallow import fields
|
||||
from sqlalchemy import and_
|
||||
from sqlalchemy.sql import exists
|
||||
|
||||
from applications.models import db
|
||||
from applications.models.admin import User, Role
|
||||
from sqlalchemy.orm.dynamic import AppenderQuery
|
||||
|
||||
ma = Marshmallow()
|
||||
|
||||
|
||||
# 用户models的序列化类
|
||||
class UserSchema(ma.Schema):
|
||||
id = fields.Integer()
|
||||
username = fields.Str()
|
||||
realname = fields.Str()
|
||||
enable = fields.Integer()
|
||||
create_at = fields.DateTime()
|
||||
update_at = fields.DateTime()
|
||||
|
||||
|
||||
'''
|
||||
获取用户的sqlalchemy对象
|
||||
分页器
|
||||
'''
|
||||
|
||||
|
||||
def get_user_data(page, limit, filters):
|
||||
user = User.query.filter(and_(*[getattr(User, k).like(v) for k, v in filters.items()])).paginate(page=page,
|
||||
per_page=limit,
|
||||
error_out=False)
|
||||
count = User.query.count()
|
||||
return user, count
|
||||
|
||||
|
||||
'''
|
||||
获取用户的dict数据
|
||||
分页器
|
||||
'''
|
||||
|
||||
|
||||
def get_user_data_dict(page, limit, filters):
|
||||
user, count = get_user_data(page, limit, filters)
|
||||
user_schema = UserSchema(many=True) # 用已继承ma.ModelSchema类的自定制类生成序列化类
|
||||
output = user_schema.dump(user.items) # 生成可序列化对象
|
||||
return output, count
|
||||
|
||||
|
||||
'''
|
||||
通过名称获取用户
|
||||
'''
|
||||
|
||||
|
||||
def get_user_by_name(username):
|
||||
return User.query.filter_by(username=username).first()
|
||||
|
||||
|
||||
# 判断用户是否存在
|
||||
def is_user_exists(username):
|
||||
res = User.query.filter_by(username=username).count()
|
||||
return bool(res)
|
||||
|
||||
|
||||
# 增加用户
|
||||
def add_user(username, realName, password):
|
||||
user = User(username=username, realname=realName)
|
||||
user.set_password(password)
|
||||
db.session.add(user)
|
||||
db.session.commit()
|
||||
return user.id
|
||||
|
||||
|
||||
# 增加用户角色
|
||||
def add_user_role(id, roles_list):
|
||||
user = User.query.filter_by(id=id).first()
|
||||
roles = Role.query.filter(Role.id.in_(roles_list)).all()
|
||||
for r in roles:
|
||||
user.role.append(r)
|
||||
db.session.commit()
|
||||
|
||||
|
||||
# 更新用户信息
|
||||
def update_user(id, username, realname):
|
||||
user = User.query.filter_by(id=id).update({'username': username, 'realname': realname})
|
||||
db.session.commit()
|
||||
return user
|
||||
|
||||
|
||||
def delete_by_id(id):
|
||||
user = User.query.filter_by(id=id).first()
|
||||
roles_id = []
|
||||
for role in user.role:
|
||||
roles_id.append(role.id)
|
||||
roles = Role.query.filter(Role.id.in_(roles_id)).all()
|
||||
for r in roles:
|
||||
user.role.remove(r)
|
||||
res = User.query.filter_by(id=id).delete()
|
||||
db.session.commit()
|
||||
return res
|
||||
|
||||
|
||||
# 启动用户
|
||||
def enable_status(id):
|
||||
enable = 1
|
||||
user = User.query.filter_by(id=id).update({"enable": enable})
|
||||
if user:
|
||||
db.session.commit()
|
||||
return True
|
||||
return False
|
||||
|
||||
|
||||
# 停用用户
|
||||
def disable_status(id):
|
||||
enable = 0
|
||||
user = User.query.filter_by(id=id).update({"enable": enable})
|
||||
if user:
|
||||
db.session.commit()
|
||||
return True
|
||||
return False
|
||||
|
||||
|
||||
# 批量删除
|
||||
def batch_remove(ids):
|
||||
for id in ids:
|
||||
delete_by_id(id)
|
||||
|
||||
|
||||
def update_user_role(id, roles_list):
|
||||
user = User.query.filter_by(id=id).first()
|
||||
roles_id = []
|
||||
for role in user.role:
|
||||
roles_id.append(role.id)
|
||||
roles = Role.query.filter(Role.id.in_(roles_id)).all()
|
||||
for r in roles:
|
||||
user.role.remove(r)
|
||||
roles = Role.query.filter(Role.id.in_(roles_list)).all()
|
||||
for r in roles:
|
||||
user.role.append(r)
|
||||
db.session.commit()
|
||||
@@ -1,56 +0,0 @@
|
||||
from flask_login import current_user
|
||||
|
||||
from applications.models import db
|
||||
from applications.models.admin import AdminLog
|
||||
|
||||
|
||||
def login_log(request,uid, is_access):
|
||||
info = {
|
||||
'method': request.method,
|
||||
'url': request.path,
|
||||
'ip': request.remote_addr,
|
||||
'user_agent': request.headers.get('User-Agent'),
|
||||
'desc': request.form.get('username'),
|
||||
'uid': uid,
|
||||
'success': int(is_access)
|
||||
|
||||
}
|
||||
log = AdminLog(
|
||||
url=info.get('url'),
|
||||
ip=info.get('ip'),
|
||||
user_agent=info.get('user_agent'),
|
||||
desc=info.get('desc'),
|
||||
uid=info.get('uid'),
|
||||
method=info.get('method'),
|
||||
success = info.get('success')
|
||||
)
|
||||
db.session.add(log)
|
||||
db.session.flush()
|
||||
db.session.commit()
|
||||
return log.id
|
||||
|
||||
|
||||
def admin_log(request, is_access):
|
||||
info = {
|
||||
'method': request.method,
|
||||
'url': request.path,
|
||||
'ip': request.remote_addr,
|
||||
'user_agent': request.headers.get('User-Agent'),
|
||||
'desc': str(dict(request.values)),
|
||||
'uid': current_user.id,
|
||||
'success':int(is_access)
|
||||
|
||||
}
|
||||
log = AdminLog(
|
||||
url=info.get('url'),
|
||||
ip=info.get('ip'),
|
||||
user_agent=info.get('user_agent'),
|
||||
desc=info.get('desc'),
|
||||
uid=info.get('uid'),
|
||||
method=info.get('method'),
|
||||
success=info.get('success')
|
||||
)
|
||||
db.session.add(log)
|
||||
db.session.commit()
|
||||
|
||||
return log.id
|
||||
@@ -1,6 +0,0 @@
|
||||
from flask_debugtoolbar import DebugToolbarExtension
|
||||
|
||||
|
||||
def OpenDug(app):
|
||||
toolbar = DebugToolbarExtension()
|
||||
toolbar.init_app(app)
|
||||
@@ -1,40 +0,0 @@
|
||||
from functools import wraps
|
||||
from flask import abort, request, jsonify, session
|
||||
from flask_login import login_required
|
||||
from applications.service.admin_log import admin_log
|
||||
|
||||
|
||||
def authorize(power: str):
|
||||
def decorator(func):
|
||||
@login_required
|
||||
@wraps(func)
|
||||
def wrapper(*args, **kwargs):
|
||||
if not power in session.get('permissions'):
|
||||
if request.method == 'GET':
|
||||
abort(403)
|
||||
else:
|
||||
return jsonify(success=False, msg="权限不足!")
|
||||
return func(*args, **kwargs)
|
||||
|
||||
return wrapper
|
||||
|
||||
return decorator
|
||||
|
||||
|
||||
def authorize_and_log(power: str):
|
||||
def decorator(func):
|
||||
@login_required
|
||||
@wraps(func)
|
||||
def wrapper(*args, **kwargs):
|
||||
if not power in session['permissions']:
|
||||
admin_log(request=request, is_access=False)
|
||||
if request.method == 'GET':
|
||||
abort(403)
|
||||
else:
|
||||
return jsonify(success=False, msg="权限不足!")
|
||||
admin_log(request=request, is_access=True)
|
||||
return func(*args, **kwargs)
|
||||
|
||||
return wrapper
|
||||
|
||||
return decorator
|
||||
@@ -1,4 +0,0 @@
|
||||
from flask_uploads import UploadSet, IMAGES
|
||||
|
||||
|
||||
photos = UploadSet('photos', IMAGES)
|
||||
@@ -0,0 +1,14 @@
|
||||
from applications.view.system import register_system_bps
|
||||
from applications.view.public import bp as public_bp # public 包的入口就是 nav_bp
|
||||
from applications.extensions.init_plugins import broadcast_execute
|
||||
|
||||
|
||||
def init_bps(app):
|
||||
# 前台公开蓝图(无需登录)
|
||||
app.register_blueprint(public_bp)
|
||||
|
||||
# 后台系统蓝图(需要登录 + 权限码)
|
||||
register_system_bps(app)
|
||||
|
||||
# 插件初始化函数
|
||||
broadcast_execute(app, 'event_init')
|
||||
@@ -0,0 +1,13 @@
|
||||
"""
|
||||
前台公开蓝图:导航聚合页 / 分类详情页
|
||||
|
||||
URL 前缀:/site(避免与后台 / 路由冲突)
|
||||
鉴权要求:无(任何用户都可访问,含未登录匿名用户)
|
||||
|
||||
注意:不要给这些视图加 @authorize 装饰器,否则会强制登录_required。
|
||||
"""
|
||||
from applications.view.public.nav import bp as nav_bp
|
||||
|
||||
|
||||
# 把 nav 蓝图作为 public 包的对外入口
|
||||
bp = nav_bp
|
||||
@@ -0,0 +1,80 @@
|
||||
"""
|
||||
前台导航页视图(无需登录)。
|
||||
|
||||
URL 路径(挂在根路径下,便于匿名访问):
|
||||
- GET /site 公开导航聚合首页(按分类展示所有启用的导航)
|
||||
- GET /site/category/<name> 分类详情:展示指定分类下所有启用的导航
|
||||
- GET /site/api/navs JSON 接口(供前端动态加载)
|
||||
|
||||
注意:
|
||||
- 这些视图**不加** @authorize,避免 login_required 强制登录。
|
||||
- 使用 url_prefix='/site' 避免与后台 / 路由冲突(后台 / 是登录后的工作台)。
|
||||
"""
|
||||
from collections import OrderedDict
|
||||
|
||||
from flask import Blueprint, render_template, request, jsonify
|
||||
|
||||
from applications.models import Nav
|
||||
|
||||
bp = Blueprint('public_nav', __name__, url_prefix='/site')
|
||||
|
||||
|
||||
@bp.get('/')
|
||||
def index():
|
||||
"""
|
||||
公开首页:按 category 分组聚合,渲染模板
|
||||
"""
|
||||
groups = _grouped_navs()
|
||||
total = sum(len(items) for items in groups.values())
|
||||
return render_template(
|
||||
'public/index.html',
|
||||
groups=groups,
|
||||
total=total,
|
||||
site_name='BWStudio · 导航',
|
||||
)
|
||||
|
||||
|
||||
@bp.get('/category/<string:name>')
|
||||
def category_detail(name: str):
|
||||
"""
|
||||
分类详情页:列出指定分类下所有启用的导航
|
||||
"""
|
||||
items = (
|
||||
Nav.query
|
||||
.filter(Nav.category == name, Nav.status == 1)
|
||||
.order_by(Nav.sort.asc(), Nav.id.asc())
|
||||
.all()
|
||||
)
|
||||
return render_template(
|
||||
'public/category.html',
|
||||
category=name,
|
||||
items=items,
|
||||
site_name='BWStudio · 导航',
|
||||
)
|
||||
|
||||
|
||||
@bp.get('/api/navs')
|
||||
def api_navs():
|
||||
"""
|
||||
JSON 接口:返回按分类聚合的导航数据
|
||||
可用于首页卡片动态加载、第三方嵌入等
|
||||
"""
|
||||
return jsonify({
|
||||
'success': True,
|
||||
'msg': '请求成功',
|
||||
'data': _grouped_navs(),
|
||||
})
|
||||
|
||||
|
||||
def _grouped_navs() -> "OrderedDict[str, list]":
|
||||
"""按 category 分组,组内按 sort asc 排序"""
|
||||
items = (
|
||||
Nav.query
|
||||
.filter(Nav.status == 1)
|
||||
.order_by(Nav.category.asc(), Nav.sort.asc(), Nav.id.asc())
|
||||
.all()
|
||||
)
|
||||
groups = OrderedDict()
|
||||
for item in items:
|
||||
groups.setdefault(item.category, []).append(item.to_dict())
|
||||
return groups
|
||||
@@ -0,0 +1,36 @@
|
||||
from flask import Flask, Blueprint
|
||||
|
||||
from applications.view.system.dict import bp as dict_bp
|
||||
from applications.view.system.file import bp as file_bp
|
||||
from applications.view.system.index import bp as index_bp
|
||||
from applications.view.system.log import bp as log_bp
|
||||
from applications.view.system.mail import bp as mail_bp
|
||||
from applications.view.system.monitor import bp as monitor_bp
|
||||
from applications.view.system.nav import bp as nav_bp
|
||||
from applications.view.system.passport import bp as passport_bp
|
||||
from applications.view.system.power import bp as power_bp
|
||||
from applications.view.system.rights import bp as right_bp
|
||||
from applications.view.system.role import bp as role_bp
|
||||
from applications.view.system.user import bp as user_bp
|
||||
from applications.view.system.dept import bp as dept_bp
|
||||
|
||||
# 创建sys
|
||||
system_bp = Blueprint('system', __name__, url_prefix='/system')
|
||||
|
||||
|
||||
def register_system_bps(app: Flask):
|
||||
# 在admin_bp下注册子蓝图
|
||||
system_bp.register_blueprint(user_bp)
|
||||
system_bp.register_blueprint(file_bp)
|
||||
system_bp.register_blueprint(monitor_bp)
|
||||
system_bp.register_blueprint(log_bp)
|
||||
system_bp.register_blueprint(power_bp)
|
||||
system_bp.register_blueprint(role_bp)
|
||||
system_bp.register_blueprint(dict_bp)
|
||||
system_bp.register_blueprint(mail_bp)
|
||||
system_bp.register_blueprint(passport_bp)
|
||||
system_bp.register_blueprint(right_bp)
|
||||
system_bp.register_blueprint(dept_bp)
|
||||
system_bp.register_blueprint(nav_bp)
|
||||
app.register_blueprint(index_bp)
|
||||
app.register_blueprint(system_bp)
|
||||
@@ -0,0 +1,181 @@
|
||||
from flask import Blueprint, render_template, request, jsonify
|
||||
|
||||
from applications.common import curd
|
||||
from applications.common.utils import validate
|
||||
from applications.common.utils.http import success_api, fail_api, table_api
|
||||
from applications.common.utils.rights import authorize
|
||||
from applications.common.utils.validate import str_escape
|
||||
from applications.extensions import db
|
||||
from applications.extensions.init_limit import limiter
|
||||
from applications.models import Dept, User
|
||||
from applications.schemas import DeptSchema
|
||||
|
||||
bp = Blueprint('dept', __name__, url_prefix='/dept')
|
||||
|
||||
@bp.get('/')
|
||||
@authorize("system:dept:main", log=True)
|
||||
def main():
|
||||
return render_template('system/dept/main.html')
|
||||
|
||||
|
||||
@bp.post('/data')
|
||||
@limiter.limit("60 per minute")
|
||||
@authorize("system:dept:main", log=True)
|
||||
def data():
|
||||
dept = Dept.query.order_by(Dept.sort).all()
|
||||
data = DeptSchema(many=True).dump(dept)
|
||||
|
||||
# 创建一个字典,用于存储每个节点的子节点
|
||||
tree = {}
|
||||
for item in data:
|
||||
item["children"] = []
|
||||
tree[item["id"]] = item
|
||||
|
||||
# 构建树形结构
|
||||
root_nodes = []
|
||||
for item in data:
|
||||
parent_id = item["parent_id"] if item["parent_id"] != 0 else None
|
||||
if parent_id is None:
|
||||
root_nodes.append(item)
|
||||
else:
|
||||
if parent_id in tree:
|
||||
tree[parent_id]["children"].append(item)
|
||||
|
||||
return table_api(msg="请求成功", data=root_nodes)
|
||||
|
||||
|
||||
@bp.get('/add')
|
||||
@authorize("system:dept:add", log=True)
|
||||
def add():
|
||||
return render_template('system/dept/add.html')
|
||||
|
||||
|
||||
@bp.get('/tree')
|
||||
@authorize("system:dept:main", log=True)
|
||||
def tree():
|
||||
dept = Dept.query.order_by(Dept.sort).all()
|
||||
power_data = curd.model_to_dicts(schema=DeptSchema, data=dept)
|
||||
res = {
|
||||
"status": {"code": 200, "message": "默认"},
|
||||
"data": power_data
|
||||
|
||||
}
|
||||
return jsonify(res)
|
||||
|
||||
|
||||
@bp.post('/save')
|
||||
@authorize("system:dept:add", log=True)
|
||||
def save():
|
||||
req_json = request.get_json(force=True)
|
||||
dept = Dept(
|
||||
parent_id=req_json.get('parentId'),
|
||||
dept_name=str_escape(req_json.get('deptName')),
|
||||
sort=str_escape(req_json.get('sort')),
|
||||
leader=str_escape(req_json.get('leader')),
|
||||
phone=str_escape(req_json.get('phone')),
|
||||
email=str_escape(req_json.get('email')),
|
||||
status=str_escape(req_json.get('status')),
|
||||
address=str_escape(req_json.get('address'))
|
||||
)
|
||||
r = db.session.add(dept)
|
||||
db.session.commit()
|
||||
return success_api(msg="添加部门成功")
|
||||
|
||||
|
||||
@bp.get('/edit')
|
||||
@authorize("system:dept:edit", log=True)
|
||||
def edit():
|
||||
_id = request.args.get("deptId")
|
||||
dept = curd.get_one_by_id(model=Dept, id=_id)
|
||||
return render_template('system/dept/edit.html', dept=dept)
|
||||
|
||||
|
||||
# 启用
|
||||
@bp.put('/enable')
|
||||
@authorize("system:dept:edit", log=True)
|
||||
def enable():
|
||||
id = request.get_json(force=True).get('deptId')
|
||||
if id:
|
||||
enable = 1
|
||||
d = Dept.query.filter_by(id=id).update({"status": enable})
|
||||
if d:
|
||||
db.session.commit()
|
||||
return success_api(msg="启用部门成功")
|
||||
return fail_api(msg="出错啦")
|
||||
return fail_api(msg="数据错误")
|
||||
|
||||
|
||||
# 禁用
|
||||
@bp.put('/disable')
|
||||
@authorize("system:dept:edit", log=True)
|
||||
def dis_enable():
|
||||
id = request.get_json(force=True).get('deptId')
|
||||
if id:
|
||||
enable = 0
|
||||
d = Dept.query.filter_by(id=id).update({"status": enable})
|
||||
if d:
|
||||
db.session.commit()
|
||||
return success_api(msg="禁用部门成功")
|
||||
return fail_api(msg="出错啦")
|
||||
return fail_api(msg="数据错误")
|
||||
|
||||
|
||||
@bp.put('/update')
|
||||
@authorize("system:dept:edit", log=True)
|
||||
def update():
|
||||
json = request.get_json(force=True)
|
||||
# id = json.get("deptId"),
|
||||
id = str_escape(json.get("deptId"))
|
||||
data = {
|
||||
"dept_name": validate.str_escape(json.get("deptName")),
|
||||
"sort": validate.str_escape(json.get("sort")),
|
||||
"leader": validate.str_escape(json.get("leader")),
|
||||
"phone": validate.str_escape(json.get("phone")),
|
||||
"email": validate.str_escape(json.get("email")),
|
||||
"status": validate.str_escape(json.get("status")),
|
||||
"address": validate.str_escape(json.get("address"))
|
||||
}
|
||||
d = Dept.query.filter_by(id=id).update(data)
|
||||
if not d:
|
||||
return fail_api(msg="更新部门失败")
|
||||
db.session.commit()
|
||||
return success_api(msg="更新部门成功")
|
||||
|
||||
|
||||
@bp.delete('/remove/<int:_id>')
|
||||
@authorize("system:dept:remove", log=True)
|
||||
def remove(_id):
|
||||
d = Dept.query.filter_by(id=_id).delete()
|
||||
|
||||
if not d:
|
||||
return fail_api(msg="删除部门失败")
|
||||
|
||||
User.query.filter_by(dept_id=_id).update({"dept_id": None})
|
||||
db.session.commit()
|
||||
|
||||
return success_api(msg="删除部门成功")
|
||||
|
||||
# 批量删除
|
||||
@bp.delete('/batchRemove')
|
||||
@authorize("system:dept:remove", log=True)
|
||||
def batch_remove():
|
||||
ids = request.form.getlist('ids[]')
|
||||
|
||||
if not ids:
|
||||
return fail_api(msg="未提供删除 ID")
|
||||
|
||||
for id in ids:
|
||||
|
||||
if not id.isdigit():
|
||||
db.session.rollback()
|
||||
return fail_api(msg="参数提供错误")
|
||||
|
||||
d = Dept.query.filter_by(id=id).delete()
|
||||
|
||||
if not d:
|
||||
return fail_api(msg="删除部门失败")
|
||||
|
||||
User.query.filter_by(dept_id=id).update({"dept_id": None})
|
||||
|
||||
db.session.commit()
|
||||
return success_api(msg="删除部门成功")
|
||||
@@ -0,0 +1,299 @@
|
||||
from flask import Blueprint, render_template, request, jsonify
|
||||
from flask_wtf.csrf import validate_csrf
|
||||
from wtforms.validators import ValidationError
|
||||
|
||||
from applications.common import curd
|
||||
from applications.common.helper import ModelFilter
|
||||
from applications.common.utils.http import table_api, success_api, fail_api
|
||||
from applications.common.utils.rights import authorize
|
||||
from applications.common.utils.validate import str_escape
|
||||
from applications.extensions import db
|
||||
from applications.extensions.init_limit import limiter
|
||||
from applications.models import DictType, DictData
|
||||
from applications.schemas import DictTypeOutSchema, DictDataOutSchema
|
||||
|
||||
bp = Blueprint('dict', __name__, url_prefix='/dict')
|
||||
|
||||
|
||||
# 数据字典
|
||||
@bp.get('/')
|
||||
@authorize("system:dict:main")
|
||||
def main():
|
||||
return render_template('system/dict/main.html')
|
||||
|
||||
|
||||
@bp.get('/dictType/data')
|
||||
@limiter.limit("60 per minute")
|
||||
@authorize("system:dict:main")
|
||||
def dict_type_data():
|
||||
# 获取请求参数
|
||||
type_name = str_escape(request.args.get('typeName', type=str))
|
||||
# 查询参数构造
|
||||
mf = ModelFilter()
|
||||
if type_name:
|
||||
mf.vague(field_name="type_name", value=type_name)
|
||||
# orm查询
|
||||
# 使用分页获取data需要.items
|
||||
dict_all = DictType.query.filter(mf.get_filter(DictType)).layui_paginate()
|
||||
count = dict_all.total
|
||||
data = curd.model_to_dicts(schema=DictTypeOutSchema, data=dict_all.items)
|
||||
|
||||
return table_api(data=data, count=count)
|
||||
|
||||
|
||||
@bp.get('/dictType/add')
|
||||
@authorize("system:dict:add", log=True)
|
||||
def dict_type_add():
|
||||
return render_template('system/dict/add.html')
|
||||
|
||||
|
||||
@bp.post('/dictType/save')
|
||||
@authorize("system:dict:add", log=True)
|
||||
def dict_type_save():
|
||||
req_json = request.get_json(force=True)
|
||||
try:
|
||||
validate_csrf(req_json.get("csrf_token"))
|
||||
except ValidationError:
|
||||
return fail_api(msg='非法请求')
|
||||
data = {
|
||||
'type_name': str_escape(req_json.get("typeName")),
|
||||
'type_code': str_escape(req_json.get("typeCode")),
|
||||
'enable': str_escape(req_json.get("enable")),
|
||||
'description': str_escape(req_json.get("description"))
|
||||
}
|
||||
|
||||
description = data['description']
|
||||
del data['description']
|
||||
|
||||
if not all(data.values()):
|
||||
return fail_api(msg="参数提供不足")
|
||||
|
||||
if description is not None:
|
||||
data['description'] = description
|
||||
|
||||
d = DictType(**data)
|
||||
db.session.add(d)
|
||||
db.session.commit()
|
||||
if d.id is None:
|
||||
return fail_api(msg="增加失败")
|
||||
return success_api(msg="增加成功")
|
||||
|
||||
|
||||
# 编辑字典类型
|
||||
@bp.get('/dictType/edit')
|
||||
@authorize("system:dict:edit", log=True)
|
||||
def dict_type_edit():
|
||||
_id = request.args.get('dictTypeId', type=int)
|
||||
dict_type = DictType.query.filter_by(id=_id).first()
|
||||
return render_template('system/dict/edit.html', dict_type=dict_type)
|
||||
|
||||
|
||||
# 编辑字典类型
|
||||
@bp.put('/dictType/update')
|
||||
@authorize("system:dict:edit", log=True)
|
||||
def dict_type_update():
|
||||
req_json = request.get_json(force=True)
|
||||
id = str_escape(req_json.get("id"))
|
||||
|
||||
data = {
|
||||
"description": str_escape(req_json.get("description")),
|
||||
"enable": str_escape(req_json.get("enable")),
|
||||
"type_code": str_escape(req_json.get("typeCode")),
|
||||
"type_name": str_escape(req_json.get("typeName"))
|
||||
}
|
||||
|
||||
if id is None:
|
||||
return fail_api(msg="字典类型不存在")
|
||||
|
||||
description = data['description']
|
||||
del data['description']
|
||||
|
||||
if not all(data.values()):
|
||||
return fail_api(msg="参数提供不足")
|
||||
|
||||
data['description'] = description
|
||||
|
||||
DictType.query.filter_by(id=id).update(data)
|
||||
db.session.commit()
|
||||
return success_api(msg="更新成功")
|
||||
|
||||
|
||||
# 启用字典
|
||||
@bp.put('/dictType/enable')
|
||||
@authorize("system:dict:edit", log=True)
|
||||
def dict_type_enable():
|
||||
_id = request.get_json(force=True).get('id')
|
||||
if _id:
|
||||
res = curd.enable_status(DictType, _id)
|
||||
if not res:
|
||||
return fail_api(msg="出错啦")
|
||||
return success_api("启用成功")
|
||||
return fail_api(msg="数据错误")
|
||||
|
||||
|
||||
# 禁用字典
|
||||
@bp.put('/dictType/disable')
|
||||
@authorize("system:dict:edit", log=True)
|
||||
def dict_type_dis_enable():
|
||||
_id = request.get_json(force=True).get('id')
|
||||
if _id:
|
||||
res = curd.disable_status(DictType, _id)
|
||||
if not res:
|
||||
return fail_api(msg="出错啦")
|
||||
return success_api("禁用成功")
|
||||
return fail_api(msg="数据错误")
|
||||
|
||||
|
||||
# 删除字典类型
|
||||
@bp.delete('/dictType/remove/<int:_id>')
|
||||
@authorize("system:dict:remove", log=True)
|
||||
def dict_type_delete(_id):
|
||||
DictData.query.filter_by(
|
||||
type_code=DictType.query.filter_by(id=_id).first().type_code
|
||||
).all()
|
||||
res = DictType.query.filter_by(id=_id).delete()
|
||||
|
||||
if not res:
|
||||
return fail_api(msg="删除失败")
|
||||
|
||||
db.session.commit()
|
||||
return success_api(msg="删除成功")
|
||||
|
||||
|
||||
@bp.get('/dictData/data')
|
||||
@limiter.limit("60 per minute")
|
||||
@authorize("system:dict:main", log=True)
|
||||
def dict_code_data():
|
||||
type_code = str_escape(request.args.get('typeCode', type=str))
|
||||
dict_data = DictData.query.filter_by(type_code=type_code).layui_paginate()
|
||||
count = dict_data.total
|
||||
data = curd.model_to_dicts(schema=DictDataOutSchema, data=dict_data.items)
|
||||
return table_api(data=data, count=count)
|
||||
|
||||
|
||||
# 增加字典数据
|
||||
@bp.get('/dictData/add')
|
||||
@authorize("system:dict:add", log=True)
|
||||
def dict_data_add():
|
||||
type_code = request.args.get('typeCode', type=str)
|
||||
return render_template('system/dict/data/add.html', type_code=type_code)
|
||||
|
||||
|
||||
# 增加字典数据
|
||||
@bp.post('/dictData/save')
|
||||
@authorize("system:dict:add", log=True)
|
||||
def dict_data_save():
|
||||
req_json = request.get_json(force=True)
|
||||
|
||||
|
||||
data_label = str_escape(req_json.get("dataLabel"))
|
||||
data_value = str_escape(req_json.get("dataValue"))
|
||||
enable = str_escape(req_json.get("enable"))
|
||||
remark = str_escape(req_json.get("remark"))
|
||||
type_code = str_escape(req_json.get("typeCode"))
|
||||
|
||||
d = DictData(data_label=data_label, data_value=data_value, enable=enable, remark=remark, type_code=type_code)
|
||||
db.session.add(d)
|
||||
db.session.commit()
|
||||
if not d.id:
|
||||
return jsonify(success=False, msg="增加失败")
|
||||
return jsonify(success=True, msg="增加成功")
|
||||
|
||||
|
||||
# 编辑字典数据
|
||||
@bp.get('/dictData/edit')
|
||||
@authorize("system:dict:edit", log=True)
|
||||
def dict_data_edit():
|
||||
_id = request.args.get('dataId', type=str)
|
||||
dict_data = curd.get_one_by_id(DictData, _id)
|
||||
return render_template('system/dict/data/edit.html', dict_data=dict_data)
|
||||
|
||||
|
||||
# 编辑字典数据
|
||||
@bp.put('/dictData/update')
|
||||
@authorize("system:dict:edit", log=True)
|
||||
def dict_data_update():
|
||||
req_json = request.get_json(force=True)
|
||||
id = req_json.get("dataId")
|
||||
DictData.query.filter_by(id=id).update({
|
||||
"data_label": str_escape(req_json.get("dataLabel")),
|
||||
"data_value": str_escape(req_json.get("dataValue")),
|
||||
"enable": str_escape(req_json.get("enable")),
|
||||
"remark": str_escape(req_json.get("remark")),
|
||||
"type_code": str_escape(req_json.get("typeCode"))
|
||||
})
|
||||
db.session.commit()
|
||||
return success_api(msg="更新成功")
|
||||
|
||||
|
||||
# 启用字典数据
|
||||
@bp.put('/dictData/enable')
|
||||
@authorize("system:dict:edit", log=True)
|
||||
def dict_data_enable():
|
||||
_id = request.get_json(force=True).get('dataId')
|
||||
if _id:
|
||||
res = curd.enable_status(model=DictData, id=_id)
|
||||
if not res:
|
||||
return fail_api(msg="出错啦")
|
||||
return success_api(msg="启动成功")
|
||||
return fail_api(msg="数据错误")
|
||||
|
||||
|
||||
# 禁用字典数据
|
||||
@bp.put('/dictData/disable')
|
||||
@authorize("system:dict:edit", log=True)
|
||||
def dict_data_disenable():
|
||||
_id = request.get_json(force=True).get('dataId')
|
||||
if _id:
|
||||
res = curd.disable_status(model=DictData, id=_id)
|
||||
if not res:
|
||||
return fail_api(msg="出错啦")
|
||||
return success_api(msg="禁用成功")
|
||||
return fail_api(msg="数据错误")
|
||||
|
||||
|
||||
# 删除字典数据
|
||||
@bp.delete('dictData/remove/<int:id>')
|
||||
@authorize("system:dict:remove", log=True)
|
||||
def dict_data_delete(id):
|
||||
res = curd.delete_one_by_id(model=DictData, id=id)
|
||||
if not res:
|
||||
return fail_api(msg="删除失败")
|
||||
return success_api(msg="删除成功")
|
||||
|
||||
|
||||
# 批量删除字典
|
||||
@bp.delete('dictData/batchRemoveDictType')
|
||||
@authorize("system:dict:remove", log=True)
|
||||
def dict_type_batch_remove():
|
||||
ids = request.form.getlist('ids[]')
|
||||
|
||||
for _id in ids:
|
||||
DictData.query.filter_by(
|
||||
type_code=DictType.query.filter_by(id=_id).first().type_code
|
||||
).all()
|
||||
|
||||
res = DictType.query.filter_by(id=_id).delete()
|
||||
|
||||
if res == 0:
|
||||
db.session.rollback()
|
||||
return fail_api(msg="删除失败,请重试")
|
||||
|
||||
db.session.commit()
|
||||
return success_api(msg="删除成功")
|
||||
|
||||
|
||||
# 批量删除字典数据
|
||||
@bp.delete('dictData/batchRemoveDictData')
|
||||
@authorize("system:dict:remove", log=True)
|
||||
def dict_data_batch_remove():
|
||||
ids = request.form.getlist('ids[]')
|
||||
|
||||
for _id in ids:
|
||||
res = curd.delete_one_by_id(model=DictData, id=_id)
|
||||
if not res:
|
||||
db.session.rollback()
|
||||
return fail_api(msg="删除失败,请重试")
|
||||
|
||||
db.session.commit()
|
||||
return success_api(msg="删除成功")
|
||||
@@ -0,0 +1,85 @@
|
||||
import os
|
||||
from flask import Blueprint, request, render_template, jsonify, current_app
|
||||
|
||||
from applications.common.utils.http import fail_api, success_api, table_api
|
||||
from applications.common.utils.rights import authorize
|
||||
from applications.extensions import db
|
||||
from applications.extensions.init_limit import limiter
|
||||
from applications.models import Photo
|
||||
from applications.common.utils import upload as upload_curd
|
||||
|
||||
bp = Blueprint('adminFile', __name__, url_prefix='/file')
|
||||
|
||||
|
||||
# 图片管理
|
||||
@bp.get('/')
|
||||
@authorize("system:file:main")
|
||||
def index():
|
||||
return render_template('system/photo/photo.html')
|
||||
|
||||
|
||||
# 图片数据
|
||||
@bp.get('/table')
|
||||
@limiter.limit("60 per minute")
|
||||
@authorize("system:file:main")
|
||||
def table():
|
||||
page = request.args.get('page', type=int)
|
||||
limit = request.args.get('limit', type=int)
|
||||
data, count = upload_curd.get_photo(page=page, limit=limit)
|
||||
return table_api(data=data, count=count)
|
||||
|
||||
|
||||
# 上传
|
||||
@bp.get('/upload')
|
||||
@authorize("system:file:add", log=True)
|
||||
def upload():
|
||||
return render_template('system/photo/photo_add.html')
|
||||
|
||||
|
||||
# 上传接口
|
||||
@bp.post('/upload')
|
||||
@authorize("system:file:add", log=True)
|
||||
def upload_api():
|
||||
if 'file' in request.files:
|
||||
photo = request.files['file']
|
||||
mime = request.files['file'].content_type
|
||||
|
||||
file_url = upload_curd.upload_one(photo=photo, mime=mime)
|
||||
res = {
|
||||
"msg": "上传成功",
|
||||
"code": 0,
|
||||
"success": True,
|
||||
"data":
|
||||
{"src": file_url}
|
||||
}
|
||||
return jsonify(res)
|
||||
return fail_api()
|
||||
|
||||
|
||||
# 图片删除
|
||||
@bp.route('/delete', methods=['GET', 'POST'])
|
||||
@authorize("system:file:delete", log=True)
|
||||
def delete():
|
||||
_id = request.form.get('id')
|
||||
res = upload_curd.delete_photo_by_id(_id)
|
||||
if res:
|
||||
return success_api(msg="删除成功")
|
||||
else:
|
||||
return fail_api(msg="删除失败")
|
||||
|
||||
|
||||
# 图片批量删除
|
||||
@bp.route('/batchRemove', methods=['GET', 'POST'])
|
||||
@authorize("system:file:delete", log=True)
|
||||
def batch_remove():
|
||||
ids = request.form.getlist('ids[]')
|
||||
photo_name = Photo.query.filter(Photo.id.in_(ids)).all()
|
||||
upload_url = current_app.config.get("UPLOADED_PHOTOS_DEST")
|
||||
for p in photo_name:
|
||||
os.remove(upload_url + '/' + p.name)
|
||||
photo = Photo.query.filter(Photo.id.in_(ids)).delete(synchronize_session=False)
|
||||
db.session.commit()
|
||||
if photo:
|
||||
return success_api(msg="删除成功")
|
||||
else:
|
||||
return fail_api(msg="删除失败")
|
||||
@@ -0,0 +1,14 @@
|
||||
from flask import Blueprint, render_template
|
||||
from flask_login import login_required, current_user
|
||||
|
||||
bp = Blueprint('index', __name__, url_prefix='/')
|
||||
|
||||
|
||||
# 首页
|
||||
@bp.get('/')
|
||||
@login_required
|
||||
def index():
|
||||
user = current_user
|
||||
return render_template('system/index.html', user=user)
|
||||
|
||||
|
||||
@@ -0,0 +1,43 @@
|
||||
from flask import Blueprint, request, render_template
|
||||
from sqlalchemy import desc
|
||||
from applications.common.utils.http import table_api
|
||||
from applications.common.utils.rights import authorize
|
||||
from applications.models import AdminLog
|
||||
from applications.schemas import LogOutSchema
|
||||
from applications.common.curd import model_to_dicts
|
||||
|
||||
bp = Blueprint('log', __name__, url_prefix='/log')
|
||||
|
||||
|
||||
# 日志管理
|
||||
@bp.get('/')
|
||||
@authorize("system:log:main")
|
||||
def index():
|
||||
return render_template('system/admin_log/main.html')
|
||||
|
||||
|
||||
# 登录日志
|
||||
@bp.get('/loginLog')
|
||||
@authorize("system:log:main")
|
||||
def login_log():
|
||||
# orm查询
|
||||
# 使用分页获取data需要.items
|
||||
log = AdminLog.query.filter_by(
|
||||
url='/system/passport/login'
|
||||
).order_by(desc(AdminLog.create_time)).layui_paginate()
|
||||
count = log.total
|
||||
return table_api(data=model_to_dicts(schema=LogOutSchema, data=log.items), count=count)
|
||||
|
||||
|
||||
# 操作日志
|
||||
@bp.get('/operateLog')
|
||||
@authorize("system:log:main")
|
||||
def operate_log():
|
||||
# orm查询
|
||||
# 使用分页获取data需要.items
|
||||
log = AdminLog.query.filter(
|
||||
AdminLog.url != '/system/passport/login'
|
||||
).order_by(
|
||||
desc(AdminLog.create_time)).layui_paginate()
|
||||
count = log.total
|
||||
return table_api(data=model_to_dicts(schema=LogOutSchema, data=log.items), count=count)
|
||||
@@ -0,0 +1,98 @@
|
||||
from flask import Blueprint, render_template, request, current_app
|
||||
from flask_login import current_user
|
||||
|
||||
from applications.common.curd import model_to_dicts
|
||||
from applications.common.helper import ModelFilter
|
||||
from applications.common.utils.http import table_api, fail_api, success_api
|
||||
from applications.common.utils.rights import authorize
|
||||
from applications.common.utils.validate import str_escape
|
||||
from applications.extensions import db
|
||||
from applications.extensions.init_limit import limiter
|
||||
from applications.models import Mail
|
||||
from applications.schemas import MailOutSchema
|
||||
from applications.common.utils import mail
|
||||
from applications.common.admin import admin_log
|
||||
|
||||
bp = Blueprint('adminMail', __name__, url_prefix='/mail')
|
||||
|
||||
|
||||
# 用户管理
|
||||
@bp.get('/')
|
||||
@authorize("system:mail:main")
|
||||
def main():
|
||||
return render_template('system/mail/main.html')
|
||||
|
||||
|
||||
# 用户分页查询
|
||||
@bp.get('/data')
|
||||
@limiter.limit("60 per minute")
|
||||
@authorize("system:mail:main")
|
||||
def data():
|
||||
# 获取请求参数
|
||||
receiver = str_escape(request.args.get("receiver"))
|
||||
subject = str_escape(request.args.get('subject'))
|
||||
content = str_escape(request.args.get('content'))
|
||||
# 查询参数构造
|
||||
mf = ModelFilter()
|
||||
if receiver:
|
||||
mf.contains(field_name="receiver", value=receiver)
|
||||
if subject:
|
||||
mf.contains(field_name="subject", value=subject)
|
||||
if content:
|
||||
mf.exact(field_name="content", value=content)
|
||||
# orm查询
|
||||
# 使用分页获取data需要.items
|
||||
mail = Mail.query.filter(mf.get_filter(Mail)).layui_paginate()
|
||||
count = mail.total
|
||||
# 返回api
|
||||
return table_api(data=model_to_dicts(schema=MailOutSchema, data=mail.items), count=count)
|
||||
|
||||
|
||||
# 用户增加
|
||||
@bp.get('/add')
|
||||
@authorize("system:mail:add", log=True)
|
||||
def add():
|
||||
return render_template('system/mail/add.html')
|
||||
|
||||
|
||||
@bp.post('/save')
|
||||
@authorize("system:mail:add", log=True)
|
||||
def save():
|
||||
req_json = request.get_json(force=True)
|
||||
receiver = str_escape(req_json.get("receiver"))
|
||||
subject = str_escape(req_json.get('subject'))
|
||||
content = str_escape(req_json.get('content'))
|
||||
user_id = current_user.id
|
||||
|
||||
try:
|
||||
if mail.add(receiver=receiver, subject=subject, content=content, user_id=user_id):
|
||||
return success_api(msg="增加成功")
|
||||
except Exception as e:
|
||||
current_app.log_exception(e)
|
||||
admin_log(request, False, desc="发送日志失败:" + str(e))
|
||||
|
||||
return success_api(msg="发送失败,请检查日志。")
|
||||
|
||||
|
||||
# 删除用户
|
||||
@bp.delete('/remove/<int:id>')
|
||||
@authorize("system:mail:remove", log=True)
|
||||
def delete(id):
|
||||
res = Mail.query.filter_by(id=id).delete()
|
||||
if not res:
|
||||
return fail_api(msg="删除失败")
|
||||
db.session.commit()
|
||||
return success_api(msg="删除成功")
|
||||
|
||||
|
||||
# 批量删除
|
||||
@bp.delete('/batchRemove')
|
||||
@authorize("system:mail:remove", log=True)
|
||||
def batch_remove():
|
||||
ids = request.form.getlist('ids[]')
|
||||
for id in ids:
|
||||
res = Mail.query.filter_by(id=id).delete()
|
||||
if not res:
|
||||
return fail_api(msg="批量删除失败")
|
||||
db.session.commit()
|
||||
return success_api(msg="批量删除成功")
|
||||
@@ -0,0 +1,170 @@
|
||||
import os
|
||||
import re
|
||||
import sys
|
||||
import time
|
||||
import psutil
|
||||
import platform
|
||||
|
||||
from datetime import datetime
|
||||
|
||||
from flask import Blueprint, render_template
|
||||
|
||||
from applications.common.utils.http import table_api, success_api
|
||||
from applications.common.utils.rights import authorize
|
||||
from applications.common.utils.cache import cache_auto_internal
|
||||
|
||||
|
||||
bp = Blueprint('adminMonitor', __name__, url_prefix='/monitor')
|
||||
|
||||
|
||||
def get_disk_partitions_list():
|
||||
disk_partitions_list = []
|
||||
# 判断是否在容器中
|
||||
if not os.path.exists('/.dockerenv'):
|
||||
disk_partitions = psutil.disk_partitions()
|
||||
for i in disk_partitions:
|
||||
try:
|
||||
a = psutil.disk_usage(i.mountpoint)
|
||||
except PermissionError:
|
||||
continue
|
||||
|
||||
disk_partitions_dict = {
|
||||
'device': i.device,
|
||||
'fstype': i.fstype,
|
||||
'total': a.total,
|
||||
'used': a.used,
|
||||
'free': a.free,
|
||||
'percent': a.percent
|
||||
}
|
||||
disk_partitions_list.append(disk_partitions_dict)
|
||||
else:
|
||||
try:
|
||||
usage = psutil.disk_usage('/')
|
||||
except PermissionError:
|
||||
pass
|
||||
|
||||
disk_partitions_list.append({
|
||||
'device': '/', # 设备名称(根文件系统)
|
||||
'fstype': psutil.disk_partitions()[0].fstype, # 文件系统类型
|
||||
'total': usage.total, # 总容量(字节)
|
||||
'used': usage.used, # 已用空间(字节)
|
||||
'free': usage.free, # 可用空间(字节)
|
||||
'percent': usage.percent # 使用百分比
|
||||
})
|
||||
|
||||
return disk_partitions_list
|
||||
|
||||
def get_basic_info():
|
||||
# 主机名称
|
||||
hostname = platform.node()
|
||||
# 系统版本
|
||||
system_version = platform.platform()
|
||||
# Python 版本
|
||||
python_version = platform.python_version()
|
||||
|
||||
# 开机时间
|
||||
boot_time = datetime.fromtimestamp(psutil.boot_time()).replace(microsecond=0)
|
||||
up_time = datetime.now().replace(microsecond=0) - boot_time
|
||||
up_time_list = re.split(r':', str(up_time))
|
||||
up_time_format = "{} 小时 {} 分钟 {} 秒".format(up_time_list[0], up_time_list[1], up_time_list[2])
|
||||
up_time_format = up_time_format.replace("days,", "天")
|
||||
|
||||
return {
|
||||
'hostname': hostname,
|
||||
'system_version': system_version,
|
||||
'python_version': python_version,
|
||||
'boot_time': boot_time,
|
||||
'up_time_format': up_time_format
|
||||
}
|
||||
|
||||
# 系统监控
|
||||
@bp.get('/')
|
||||
@authorize("system:monitor:main")
|
||||
def main():
|
||||
|
||||
|
||||
# 当前时间
|
||||
time_now = time.strftime('%H:%M:%S ', time.localtime(time.time()))
|
||||
return render_template(
|
||||
'system/monitor.html',
|
||||
time_now=time_now,
|
||||
**get_basic_info()
|
||||
)
|
||||
|
||||
|
||||
# 图表 api
|
||||
@bp.get('/polling')
|
||||
@authorize("system:monitor:main")
|
||||
def ajax_polling():
|
||||
# 获取 CPU 核心数
|
||||
cpu_count = cache_auto_internal('cpu_count', lambda: psutil.cpu_count(), expired=999999999)
|
||||
|
||||
# 获取 CPU 使用率
|
||||
cpus_percent = cache_auto_internal('cpus_percent',
|
||||
lambda: psutil.cpu_percent(interval=1, percpu=False),
|
||||
expired=5)
|
||||
|
||||
# 每个 CPU 的使用率
|
||||
cpu_percent_per_core = cache_auto_internal('cpu_percent_per_core',
|
||||
lambda: list(enumerate(psutil.cpu_percent(interval=1, percpu=True))),
|
||||
expired=5)
|
||||
|
||||
# 获取空闲率、等待率
|
||||
cpu_times_percent = cache_auto_internal('cpu_times_percent',
|
||||
lambda: psutil.cpu_times_percent(interval=1, percpu=False),
|
||||
expired=5)
|
||||
|
||||
# 内存信息
|
||||
memory_information = cache_auto_internal('memory_information',
|
||||
psutil.virtual_memory,
|
||||
expired=5)
|
||||
|
||||
# 硬盘信息
|
||||
disk_partitions_list = cache_auto_internal('disk_partitions_list',
|
||||
get_disk_partitions_list,
|
||||
expired=5)
|
||||
|
||||
# 系统信息
|
||||
basic_info = cache_auto_internal('basic_info',
|
||||
get_basic_info,
|
||||
expired=5)
|
||||
|
||||
memory_usage = memory_information.percent
|
||||
memory_used = memory_information.used
|
||||
memory_total = memory_information.total
|
||||
memory_free = memory_information.free
|
||||
|
||||
cpu_idle_percent = cpu_times_percent.idle
|
||||
if hasattr(cpu_times_percent, 'iowait'):
|
||||
cpu_wait_percent = cpu_times_percent.iowait
|
||||
else:
|
||||
cpu_wait_percent = "-"
|
||||
|
||||
return table_api(msg="请求成功",
|
||||
count=0,
|
||||
data={
|
||||
'cpu_count': cpu_count,
|
||||
'cpus_percent': cpus_percent,
|
||||
'cpu_idle_percent': cpu_idle_percent,
|
||||
'cpu_wait_percent': cpu_wait_percent,
|
||||
'cpu_percent_per_core': cpu_percent_per_core,
|
||||
'memory_used': memory_used,
|
||||
'memory_total': memory_total,
|
||||
'memory_free': memory_free,
|
||||
'memory_usage': memory_usage,
|
||||
'disk_partitions_list': disk_partitions_list,
|
||||
'time_now': time.strftime('%H:%M:%S', time.localtime(time.time())),
|
||||
'basic_info': basic_info
|
||||
})
|
||||
|
||||
|
||||
# 关闭程序
|
||||
@bp.get('/kill')
|
||||
@authorize("system:monitor:main")
|
||||
def kill():
|
||||
# 注:若是多 worker 则不生效
|
||||
return success_api(msg="关闭命令已发送,请修改代码以生效。")
|
||||
for proc in psutil.process_iter():
|
||||
if proc.pid == os.getpid():
|
||||
proc.kill()
|
||||
sys.exit(1)
|
||||
@@ -0,0 +1,142 @@
|
||||
"""
|
||||
后台导航管理视图(需要登录 + 权限码 system:nav:*)
|
||||
|
||||
提供 Nav 模型的 CRUD 接口,供后台管理员维护前台公开导航。
|
||||
"""
|
||||
from flask import Blueprint, render_template, request
|
||||
from flask_login import current_user
|
||||
|
||||
from applications.common.utils.http import table_api, fail_api, success_api
|
||||
from applications.common.utils.rights import authorize
|
||||
from applications.common.utils.validate import str_escape
|
||||
from applications.extensions import db
|
||||
from applications.extensions.init_limit import limiter
|
||||
from applications.models import Nav
|
||||
from applications.schemas import NavManageSchema
|
||||
|
||||
bp = Blueprint('nav', __name__, url_prefix='/nav')
|
||||
|
||||
|
||||
@bp.get('/')
|
||||
@authorize("system:nav:main")
|
||||
def main():
|
||||
"""导航管理主页"""
|
||||
return render_template('system/nav/main.html')
|
||||
|
||||
|
||||
@bp.get('/data')
|
||||
@limiter.limit("60 per minute")
|
||||
@authorize("system:nav:main")
|
||||
def data():
|
||||
"""表格数据接口"""
|
||||
keyword = str_escape(request.args.get('keyword', type=str))
|
||||
category = str_escape(request.args.get('category', type=str))
|
||||
|
||||
query = Nav.query
|
||||
if keyword:
|
||||
query = query.filter(
|
||||
db.or_(
|
||||
Nav.title.contains(keyword),
|
||||
Nav.url.contains(keyword),
|
||||
Nav.description.contains(keyword),
|
||||
)
|
||||
)
|
||||
if category:
|
||||
query = query.filter(Nav.category == category)
|
||||
|
||||
items = query.order_by(Nav.category.asc(), Nav.sort.asc(), Nav.id.asc()).all()
|
||||
data = NavManageSchema(many=True).dump(items)
|
||||
return table_api(msg="请求成功", data=data, count=len(data))
|
||||
|
||||
|
||||
@bp.get('/add')
|
||||
@authorize("system:nav:add", log=True)
|
||||
def add():
|
||||
return render_template('system/nav/add.html')
|
||||
|
||||
|
||||
@bp.post('/save')
|
||||
@authorize("system:nav:add", log=True)
|
||||
def save():
|
||||
req = request.get_json(force=True)
|
||||
try:
|
||||
nav = Nav(
|
||||
category=str_escape(req.get('category')),
|
||||
title=str_escape(req.get('title')),
|
||||
url=str_escape(req.get('url')),
|
||||
description=str_escape(req.get('description')),
|
||||
icon=str_escape(req.get('icon')) or 'layui-icon-link',
|
||||
sort=int(req.get('sort') or 0),
|
||||
status=int(req.get('status') or 1),
|
||||
is_external=int(req.get('isExternal') or 1),
|
||||
create_by=current_user.username if current_user.is_authenticated else 'admin',
|
||||
)
|
||||
db.session.add(nav)
|
||||
db.session.commit()
|
||||
except Exception as e:
|
||||
db.session.rollback()
|
||||
return fail_api(msg=f"新增失败:{e}")
|
||||
return success_api(msg="新增成功")
|
||||
|
||||
|
||||
@bp.get('/edit')
|
||||
@authorize("system:nav:edit", log=True)
|
||||
def edit():
|
||||
nav_id = request.args.get("navId", type=int)
|
||||
nav = Nav.query.get(nav_id)
|
||||
if not nav:
|
||||
return fail_api(msg="导航不存在")
|
||||
return render_template('system/nav/edit.html', nav=nav)
|
||||
|
||||
|
||||
@bp.put('/update')
|
||||
@authorize("system:nav:edit", log=True)
|
||||
def update():
|
||||
req = request.get_json(force=True)
|
||||
nav_id = req.get('id')
|
||||
nav = Nav.query.get(nav_id)
|
||||
if not nav:
|
||||
return fail_api(msg="导航不存在")
|
||||
try:
|
||||
nav.category = str_escape(req.get('category')) or nav.category
|
||||
nav.title = str_escape(req.get('title')) or nav.title
|
||||
nav.url = str_escape(req.get('url')) or nav.url
|
||||
nav.description = str_escape(req.get('description'))
|
||||
nav.icon = str_escape(req.get('icon')) or 'layui-icon-link'
|
||||
nav.sort = int(req.get('sort') or 0)
|
||||
nav.status = int(req.get('status') or 1)
|
||||
nav.is_external = int(req.get('isExternal') or 1)
|
||||
db.session.commit()
|
||||
except Exception as e:
|
||||
db.session.rollback()
|
||||
return fail_api(msg=f"更新失败:{e}")
|
||||
return success_api(msg="更新成功")
|
||||
|
||||
|
||||
@bp.delete('/remove/<int:_id>')
|
||||
@authorize("system:nav:remove", log=True)
|
||||
def remove(_id):
|
||||
nav = Nav.query.get(_id)
|
||||
if not nav:
|
||||
return fail_api(msg="导航不存在")
|
||||
db.session.delete(nav)
|
||||
db.session.commit()
|
||||
return success_api(msg="删除成功")
|
||||
|
||||
|
||||
@bp.put('/enable')
|
||||
@authorize("system:nav:edit", log=True)
|
||||
def enable():
|
||||
nav_id = request.get_json(force=True).get('navId')
|
||||
Nav.query.filter_by(id=nav_id).update({"status": 1})
|
||||
db.session.commit()
|
||||
return success_api(msg="已启用")
|
||||
|
||||
|
||||
@bp.put('/disable')
|
||||
@authorize("system:nav:edit", log=True)
|
||||
def disable():
|
||||
nav_id = request.get_json(force=True).get('navId')
|
||||
Nav.query.filter_by(id=nav_id).update({"status": 0})
|
||||
db.session.commit()
|
||||
return success_api(msg="已禁用")
|
||||
@@ -0,0 +1,91 @@
|
||||
from flask import Blueprint, session, redirect, url_for, render_template, request
|
||||
from flask_login import current_user, login_user, login_required, logout_user
|
||||
|
||||
from applications.common.admin import get_captcha, login_log
|
||||
from applications.common.utils.http import fail_api, success_api
|
||||
from applications.models import User
|
||||
|
||||
bp = Blueprint('passport', __name__, url_prefix='/passport')
|
||||
|
||||
|
||||
# 获取验证码
|
||||
@bp.get('/getCaptcha')
|
||||
def captcha():
|
||||
resp, code = get_captcha()
|
||||
session["code"] = code
|
||||
return resp
|
||||
|
||||
|
||||
# 登录
|
||||
@bp.get('/login')
|
||||
def login():
|
||||
if current_user.is_authenticated:
|
||||
return redirect(url_for('index.index'))
|
||||
return render_template('system/login.html')
|
||||
|
||||
|
||||
# 登录
|
||||
@bp.post('/login')
|
||||
def login_post():
|
||||
req = request.form
|
||||
username = req.get('username')
|
||||
password = req.get('password')
|
||||
remember = bool(req.get('remember-me'))
|
||||
code = req.get('captcha').__str__().lower()
|
||||
|
||||
if not username or not password or not code:
|
||||
return fail_api(msg="用户名或密码没有输入")
|
||||
s_code = session.get("code", None)
|
||||
session["code"] = None
|
||||
|
||||
if not all([code, s_code]):
|
||||
return fail_api(msg="参数错误")
|
||||
|
||||
if code != s_code:
|
||||
return fail_api(msg="验证码错误")
|
||||
user = User.query.filter_by(username=username).first()
|
||||
|
||||
if not user:
|
||||
return fail_api(msg="不存在的用户")
|
||||
|
||||
if user.enable == 0:
|
||||
return fail_api(msg="用户被暂停使用")
|
||||
|
||||
if username == user.username and user.validate_password(password):
|
||||
# 登录
|
||||
login_user(user, remember=remember)
|
||||
# 记录登录日志
|
||||
login_log(request, uid=user.id, is_access=True)
|
||||
# 授权路由存入session
|
||||
role = current_user.role
|
||||
user_power = []
|
||||
for i in role:
|
||||
if i.enable == 0:
|
||||
continue
|
||||
for p in i.power:
|
||||
if p.enable == 0:
|
||||
continue
|
||||
user_power.append(p.code)
|
||||
session['permissions'] = user_power
|
||||
# # 角色存入session
|
||||
# roles = []
|
||||
# for role in current_user.role.all():
|
||||
# roles.append(role.id)
|
||||
# session['role'] = [roles]
|
||||
|
||||
return success_api(msg="登录成功")
|
||||
|
||||
login_log(request, uid=user.id, is_access=False)
|
||||
return fail_api(msg="用户名或密码错误")
|
||||
|
||||
|
||||
# 退出登录
|
||||
@bp.post('/logout')
|
||||
@login_required
|
||||
def logout():
|
||||
logout_user()
|
||||
|
||||
if 'permissions' in session:
|
||||
session.pop('permissions')
|
||||
|
||||
return success_api(msg="注销成功")
|
||||
@@ -0,0 +1,203 @@
|
||||
from flask import Blueprint, render_template, request, jsonify
|
||||
|
||||
from applications.common import curd
|
||||
from applications.common.utils.http import success_api, fail_api, table_api
|
||||
from applications.common.utils.rights import authorize
|
||||
from applications.common.utils.validate import str_escape
|
||||
from applications.extensions import db
|
||||
from applications.extensions.init_limit import limiter
|
||||
from applications.models import Power
|
||||
from applications.schemas import PowerOutSchema2
|
||||
from applications.schemas.admin_power import PowerSchema
|
||||
|
||||
bp = Blueprint('power', __name__, url_prefix='/power')
|
||||
|
||||
|
||||
@bp.get('/')
|
||||
@authorize("system:power:main")
|
||||
def index():
|
||||
return render_template('system/power/main.html')
|
||||
|
||||
|
||||
@bp.post('/data')
|
||||
@limiter.limit("60 per minute")
|
||||
@authorize("system:power:main")
|
||||
def data():
|
||||
power = Power.query.all()
|
||||
data = PowerSchema(many=True).dump(power)
|
||||
|
||||
# 创建一个字典,用于存储每个节点的子节点
|
||||
tree = {}
|
||||
for item in data:
|
||||
item["children"] = []
|
||||
tree[item["id"]] = item
|
||||
|
||||
# 构建树形结构
|
||||
root_nodes = []
|
||||
for item in data:
|
||||
parent_id = item["parent_id"] if item["parent_id"] != 0 else None
|
||||
if parent_id is None:
|
||||
root_nodes.append(item)
|
||||
else:
|
||||
if parent_id in tree:
|
||||
tree[parent_id]["children"].append(item)
|
||||
|
||||
return table_api(msg="请求成功", data=root_nodes)
|
||||
|
||||
|
||||
@bp.get('/add')
|
||||
@authorize("system:power:add", log=True)
|
||||
def add():
|
||||
return render_template('system/power/add.html')
|
||||
|
||||
|
||||
@bp.get('/selectParent')
|
||||
@authorize("system:power:main", log=True)
|
||||
def select_parent():
|
||||
power = Power.query.all()
|
||||
res = curd.model_to_dicts(schema=PowerOutSchema2, data=power)
|
||||
res.append({"powerId": 0, "powerName": "顶级权限", "parentId": -1})
|
||||
res = {
|
||||
"status": {"code": 200, "message": "默认"},
|
||||
"data": res
|
||||
|
||||
}
|
||||
return jsonify(res)
|
||||
|
||||
|
||||
# 增加
|
||||
@bp.post('/save')
|
||||
@authorize("system:power:add", log=True)
|
||||
def save():
|
||||
req = request.get_json(force=True)
|
||||
|
||||
data = {
|
||||
"icon": str_escape(req.get("icon")),
|
||||
"open_type": str_escape(req.get("openType")),
|
||||
"parent_id": str_escape(req.get("parentId")),
|
||||
"code": str_escape(req.get("powerCode")),
|
||||
"name": str_escape(req.get("powerName")),
|
||||
"type": str_escape(req.get("powerType")),
|
||||
"url": str_escape(req.get("powerUrl")),
|
||||
"sort": str_escape(req.get("sort"))
|
||||
}
|
||||
|
||||
if not data['sort'].isdigit():
|
||||
return fail_api(msg="参数 sort 需为整数")
|
||||
|
||||
power = Power(**data)
|
||||
db.session.add(power)
|
||||
db.session.commit()
|
||||
return success_api(msg="权限添加成功")
|
||||
|
||||
|
||||
# 权限编辑
|
||||
@bp.get('/edit/<int:_id>')
|
||||
@authorize("system:power:edit", log=True)
|
||||
def edit(_id):
|
||||
power = curd.get_one_by_id(Power, _id)
|
||||
icon = str(power.icon).split()
|
||||
if len(icon) == 2:
|
||||
icon = icon[1]
|
||||
else:
|
||||
icon = None
|
||||
return render_template('system/power/edit.html', power=power, icon=icon)
|
||||
|
||||
|
||||
# 权限更新
|
||||
@bp.put('/update')
|
||||
@authorize("system:power:edit", log=True)
|
||||
def update():
|
||||
req_json = request.get_json(force=True)
|
||||
id = request.get_json(force=True).get("powerId")
|
||||
|
||||
data = {
|
||||
"icon": str_escape(req_json.get("icon")),
|
||||
"open_type": str_escape(req_json.get("openType")),
|
||||
"parent_id": str_escape(req_json.get("parentId")),
|
||||
"code": str_escape(req_json.get("powerCode")),
|
||||
"name": str_escape(req_json.get("powerName")),
|
||||
"type": str_escape(req_json.get("powerType")),
|
||||
"url": str_escape(req_json.get("powerUrl")),
|
||||
"sort": str_escape(req_json.get("sort"))
|
||||
}
|
||||
|
||||
if not data['sort'].isdigit():
|
||||
return fail_api(msg="参数 sort 需为整数")
|
||||
|
||||
res = Power.query.filter_by(id=id).update(data)
|
||||
db.session.commit()
|
||||
if not res:
|
||||
return fail_api(msg="更新权限失败")
|
||||
return success_api(msg="更新权限成功")
|
||||
|
||||
|
||||
# 启用权限
|
||||
@bp.put('/enable')
|
||||
@authorize("system:power:edit", log=True)
|
||||
def enable():
|
||||
_id = request.get_json(force=True).get('powerId')
|
||||
if _id:
|
||||
res = curd.enable_status(Power, _id)
|
||||
if not res:
|
||||
return fail_api(msg="出错啦")
|
||||
return success_api(msg="启用成功")
|
||||
return fail_api(msg="数据错误")
|
||||
|
||||
|
||||
# 禁用权限
|
||||
@bp.put('/disable')
|
||||
@authorize("system:power:edit", log=True)
|
||||
def dis_enable():
|
||||
_id = request.get_json(force=True).get('powerId')
|
||||
if id:
|
||||
res = curd.disable_status(Power, _id)
|
||||
if not res:
|
||||
return fail_api(msg="出错啦")
|
||||
return success_api(msg="禁用成功")
|
||||
return fail_api(msg="数据错误")
|
||||
|
||||
|
||||
# 权限删除
|
||||
@bp.delete('/remove/<int:id>')
|
||||
@authorize("system:power:remove", log=True)
|
||||
def remove(id):
|
||||
power = Power.query.filter_by(id=id).first()
|
||||
|
||||
if power:
|
||||
power.role = []
|
||||
|
||||
r = Power.query.filter_by(id=id).delete()
|
||||
db.session.commit()
|
||||
|
||||
if r:
|
||||
return success_api(msg="删除成功")
|
||||
else:
|
||||
return fail_api(msg="删除失败")
|
||||
|
||||
|
||||
# 批量删除
|
||||
@bp.delete('/batchRemove')
|
||||
@authorize("system:power:remove", log=True)
|
||||
def batch_remove():
|
||||
ids = request.form.getlist('ids[]')
|
||||
|
||||
if not ids:
|
||||
return fail_api(msg="未提供删除 ID")
|
||||
|
||||
for id in ids:
|
||||
|
||||
if not id.isdigit():
|
||||
db.session.rollback()
|
||||
return fail_api(msg="参数提供错误")
|
||||
|
||||
id = int(id)
|
||||
|
||||
power = Power.query.filter_by(id=id).first()
|
||||
if power:
|
||||
# 清空关联的角色(如果需要)
|
||||
power.role = []
|
||||
db.session.delete(power)
|
||||
|
||||
db.session.commit()
|
||||
return success_api(msg="批量删除成功")
|
||||
@@ -0,0 +1,265 @@
|
||||
import copy
|
||||
from collections import OrderedDict
|
||||
|
||||
from flask import jsonify, current_app, Blueprint, render_template
|
||||
from flask_login import login_required, current_user
|
||||
|
||||
from ...common.utils.http import table_api
|
||||
from ...models import Power
|
||||
from ...schemas import PowerOutSchema
|
||||
|
||||
bp = Blueprint('rights', __name__, url_prefix='/rights')
|
||||
|
||||
|
||||
# 渲染配置
|
||||
@bp.get('/configs')
|
||||
@login_required
|
||||
def configs():
|
||||
# 网站配置
|
||||
config = dict(logo={
|
||||
# 网站名称
|
||||
"title": current_app.config.get("SYSTEM_NAME"),
|
||||
# 网站图标
|
||||
"image": "/static/system/admin/images/logo.png"
|
||||
# 菜单配置
|
||||
}, menu={
|
||||
# 菜单数据来源
|
||||
"data": "/system/rights/menu",
|
||||
"collaspe": False,
|
||||
# 是否同时只打开一个菜单目录
|
||||
"accordion": True,
|
||||
"method": "GET",
|
||||
# 是否开启多系统菜单模式
|
||||
"control": False,
|
||||
# 顶部菜单宽度 PX
|
||||
"controlWidth": 500,
|
||||
# 默认选中的菜单项
|
||||
"select": "0",
|
||||
# 是否开启异步菜单,false 时 data 属性设置为菜单数据,false 时为 json 文件或后端接口
|
||||
"async": True
|
||||
}, tab={
|
||||
# 是否开启多选项卡
|
||||
"enable": True,
|
||||
# 切换选项卡时,是否刷新页面状态
|
||||
"keepState": True,
|
||||
# 是否开启 Tab 记忆
|
||||
"session": True,
|
||||
# 预加载
|
||||
"preload": False,
|
||||
# 最大可打开的选项卡数量
|
||||
"max": 30,
|
||||
"index": {
|
||||
# 标识 ID , 建议与菜单项中的 ID 一致
|
||||
"id": "10",
|
||||
# 页面地址
|
||||
"href": "/system/rights/welcome",
|
||||
# 标题
|
||||
"title": "首页"
|
||||
}
|
||||
}, theme={
|
||||
# 默认主题色,对应 colors 配置中的 ID 标识
|
||||
"defaultColor": "2",
|
||||
# 默认的菜单主题 dark-theme 黑 / light-theme 白
|
||||
"defaultMenu": "dark-theme",
|
||||
# 是否允许用户切换主题,false 时关闭自定义主题面板
|
||||
"allowCustom": True
|
||||
}, colors=[{
|
||||
"id": "1",
|
||||
"color": "#2d8cf0"
|
||||
},
|
||||
{
|
||||
"id": "2",
|
||||
"color": "#5FB878"
|
||||
},
|
||||
{
|
||||
"id": "3",
|
||||
"color": "#1E9FFF"
|
||||
}, {
|
||||
"id": "4",
|
||||
"color": "#FFB800"
|
||||
}, {
|
||||
"id": "5",
|
||||
"color": "darkgray"
|
||||
}
|
||||
], links=current_app.config.get("SYSTEM_PANEL_LINKS"), other={
|
||||
# 主页动画时长
|
||||
"keepLoad": 0,
|
||||
# 布局顶部主题
|
||||
"autoHead": False
|
||||
}, header={
|
||||
'message': '/system/rights/message'
|
||||
})
|
||||
return jsonify(config)
|
||||
|
||||
|
||||
# 消息
|
||||
@bp.get('/message')
|
||||
@login_required
|
||||
def message():
|
||||
return dict(code=200,
|
||||
data=[
|
||||
{
|
||||
"id": 1,
|
||||
"title": "通知",
|
||||
"children": [
|
||||
{
|
||||
"id": 11,
|
||||
"avatar": "https://gw.alipayobjects.com/zos/rmsportal/ThXAXghbEsBCCSDihZxY.png",
|
||||
"title": "你收到了 14 份新周报",
|
||||
"context": "这是消息内容。",
|
||||
"form": "就眠仪式",
|
||||
"time": "刚刚"
|
||||
},
|
||||
{
|
||||
"id": 12,
|
||||
"avatar": "https://gw.alipayobjects.com/zos/rmsportal/OKJXDXrmkNshAMvwtvhu.png",
|
||||
"title": "曲妮妮 已通过第三轮面试",
|
||||
"context": "这是消息内容。",
|
||||
"form": "就眠仪式",
|
||||
"time": "刚刚"
|
||||
},
|
||||
{
|
||||
"id": 11,
|
||||
"avatar": "https://gw.alipayobjects.com/zos/rmsportal/kISTdvpyTAhtGxpovNWd.png",
|
||||
"title": "可以区分多种通知类型",
|
||||
"context": "这是消息内容。",
|
||||
"form": "就眠仪式",
|
||||
"time": "刚刚"
|
||||
},
|
||||
{
|
||||
"id": 12,
|
||||
"avatar": "https://gw.alipayobjects.com/zos/rmsportal/GvqBnKhFgObvnSGkDsje.png",
|
||||
"title": "左侧图标用于区分不同的类型",
|
||||
"context": "这是消息内容。",
|
||||
"form": "就眠仪式",
|
||||
"time": "刚刚"
|
||||
},
|
||||
{
|
||||
"id": 11,
|
||||
"avatar": "https://gw.alipayobjects.com/zos/rmsportal/ThXAXghbEsBCCSDihZxY.png",
|
||||
"title": "内容不要超过两行字",
|
||||
"context": "这是消息内容。",
|
||||
"form": "就眠仪式",
|
||||
"time": "刚刚"
|
||||
}
|
||||
]
|
||||
},
|
||||
{
|
||||
"id": 2,
|
||||
"title": "消息",
|
||||
"children": [
|
||||
{
|
||||
"id": 11,
|
||||
"avatar": "https://gw.alipayobjects.com/zos/rmsportal/ThXAXghbEsBCCSDihZxY.png",
|
||||
"title": "你收到了 14 份新周报",
|
||||
"context": "这是消息内容。",
|
||||
"form": "就眠仪式",
|
||||
"time": "刚刚"
|
||||
},
|
||||
{
|
||||
"id": 12,
|
||||
"avatar": "https://gw.alipayobjects.com/zos/rmsportal/OKJXDXrmkNshAMvwtvhu.png",
|
||||
"title": "曲妮妮 已通过第三轮面试",
|
||||
"context": "这是消息内容。",
|
||||
"form": "就眠仪式",
|
||||
"time": "刚刚"
|
||||
},
|
||||
{
|
||||
"id": 11,
|
||||
"avatar": "https://gw.alipayobjects.com/zos/rmsportal/kISTdvpyTAhtGxpovNWd.png",
|
||||
"title": "可以区分多种通知类型",
|
||||
"context": "这是消息内容。",
|
||||
"form": "就眠仪式",
|
||||
"time": "刚刚"
|
||||
},
|
||||
{
|
||||
"id": 12,
|
||||
"avatar": "https://gw.alipayobjects.com/zos/rmsportal/GvqBnKhFgObvnSGkDsje.png",
|
||||
"title": "左侧图标用于区分不同的类型",
|
||||
"context": "这是消息内容。",
|
||||
"form": "就眠仪式",
|
||||
"time": "刚刚"
|
||||
},
|
||||
{
|
||||
"id": 11,
|
||||
"avatar": "https://gw.alipayobjects.com/zos/rmsportal/ThXAXghbEsBCCSDihZxY.png",
|
||||
"title": "内容不要超过两行字",
|
||||
"context": "这是消息内容。",
|
||||
"form": "就眠仪式",
|
||||
"time": "刚刚"
|
||||
}
|
||||
]
|
||||
},
|
||||
{
|
||||
"id": 3,
|
||||
"title": "代办",
|
||||
"children": []
|
||||
}
|
||||
])
|
||||
|
||||
|
||||
# 菜单
|
||||
@bp.get('/menu')
|
||||
@login_required
|
||||
def menu():
|
||||
if current_user.username != current_app.config.get("SUPERADMIN"):
|
||||
role = current_user.role
|
||||
powers = []
|
||||
for i in role:
|
||||
# 如果角色没有被启用就直接跳过
|
||||
if i.enable == 0:
|
||||
continue
|
||||
# 变量角色用户的权限
|
||||
for p in i.power:
|
||||
# 如果权限关闭了就直接跳过
|
||||
if p.enable == 0:
|
||||
continue
|
||||
# 一二级菜单
|
||||
if int(p.type) in [0, 1] and p not in powers:
|
||||
powers.append(p)
|
||||
|
||||
power_schema = PowerOutSchema(many=True) # 用已继承 ma.ModelSchema 类的自定制类生成序列化类
|
||||
power_dict = power_schema.dump(powers) # 生成可序列化对象
|
||||
power_dict.sort(key=lambda x: (x['parent_id'], x['id']), reverse=True)
|
||||
|
||||
menu_dict = OrderedDict()
|
||||
for _dict in power_dict:
|
||||
if _dict['id'] in menu_dict:
|
||||
# 当前节点添加子节点
|
||||
_dict['children'] = copy.deepcopy(menu_dict[_dict['id']])
|
||||
_dict['children'].sort(key=lambda item: item['sort'])
|
||||
# 删除子节点
|
||||
del menu_dict[_dict['id']]
|
||||
|
||||
if _dict['parent_id'] not in menu_dict:
|
||||
menu_dict[_dict['parent_id']] = [_dict]
|
||||
else:
|
||||
menu_dict[_dict['parent_id']].append(_dict)
|
||||
return jsonify(sorted(menu_dict.get(0), key=lambda item: item['sort']))
|
||||
else:
|
||||
powers = Power.query.filter(Power.enable == 1).all()
|
||||
power_schema = PowerOutSchema(many=True) # 用已继承 ma.ModelSchema 类的自定制类生成序列化类
|
||||
power_dict = power_schema.dump(powers) # 生成可序列化对象
|
||||
power_dict.sort(key=lambda x: (x['parent_id'], x['id']), reverse=True)
|
||||
|
||||
menu_dict = OrderedDict()
|
||||
for _dict in power_dict:
|
||||
if _dict['id'] in menu_dict:
|
||||
# 当前节点添加子节点
|
||||
_dict['children'] = copy.deepcopy(menu_dict[_dict['id']])
|
||||
_dict['children'].sort(key=lambda item: item['sort'])
|
||||
# 删除子节点
|
||||
del menu_dict[_dict['id']]
|
||||
|
||||
if _dict['parent_id'] not in menu_dict:
|
||||
menu_dict[_dict['parent_id']] = [_dict]
|
||||
else:
|
||||
menu_dict[_dict['parent_id']].append(_dict)
|
||||
return jsonify(sorted(menu_dict.get(0), key=lambda item: item['sort']))
|
||||
|
||||
|
||||
# 控制台页面
|
||||
@bp.get('/welcome')
|
||||
@login_required
|
||||
def welcome():
|
||||
return render_template('system/analysis/main.html')
|
||||
@@ -0,0 +1,208 @@
|
||||
from flask import Blueprint, render_template, request, jsonify
|
||||
from flask_login import login_required
|
||||
|
||||
from applications.common.curd import model_to_dicts, enable_status, disable_status, get_one_by_id
|
||||
from applications.common.utils.http import table_api, success_api, fail_api
|
||||
from applications.common.utils.rights import authorize
|
||||
from applications.common.utils.validate import str_escape
|
||||
from applications.extensions import db
|
||||
from applications.extensions.init_limit import limiter
|
||||
from applications.models import Role, Power, User
|
||||
from applications.schemas import RoleOutSchema, PowerOutSchema2
|
||||
|
||||
bp = Blueprint('role', __name__, url_prefix='/role')
|
||||
|
||||
# 用户管理
|
||||
@bp.get('/')
|
||||
@authorize("system:role:main")
|
||||
def main():
|
||||
return render_template('system/role/main.html')
|
||||
|
||||
|
||||
# 表格数据
|
||||
@bp.get('/data')
|
||||
@limiter.limit("60 per minute")
|
||||
@authorize("system:role:main")
|
||||
def table():
|
||||
role_name = str_escape(request.args.get('roleName', type=str))
|
||||
role_code = str_escape(request.args.get('roleCode', type=str))
|
||||
filters = []
|
||||
if role_name:
|
||||
filters.append(Role.name.contains(role_name))
|
||||
if role_code:
|
||||
filters.append(Role.code.contains(role_code))
|
||||
roles = Role.query.filter(*filters).layui_paginate()
|
||||
return table_api(data=RoleOutSchema(many=True).dump(roles), count=roles.total)
|
||||
|
||||
|
||||
# 角色增加
|
||||
@bp.get('/add')
|
||||
@authorize("system:role:add", log=True)
|
||||
def add():
|
||||
return render_template('system/role/add.html')
|
||||
|
||||
|
||||
# 角色增加
|
||||
@bp.post('/save')
|
||||
@authorize("system:role:add", log=True)
|
||||
def save():
|
||||
req = request.get_json(force=True)
|
||||
|
||||
data = {
|
||||
"details": str_escape(req.get("details")),
|
||||
"enable": str_escape(req.get("enable")),
|
||||
"code": str_escape(req.get("roleCode")), # 角色标识
|
||||
"name": str_escape(req.get("roleName")), # 角色名称
|
||||
"sort": str_escape(req.get("sort"))
|
||||
}
|
||||
|
||||
details = data.get('details')
|
||||
del data['details']
|
||||
|
||||
if not all(data.values()):
|
||||
return fail_api(msg="参数不足")
|
||||
|
||||
data['details'] = details
|
||||
|
||||
# 参数效验
|
||||
if not data['sort'].isdigit():
|
||||
return fail_api(msg="参数 sort 需为整数")
|
||||
|
||||
role = Role(**data)
|
||||
db.session.add(role)
|
||||
db.session.commit()
|
||||
return success_api(msg="添加角色成功")
|
||||
|
||||
|
||||
# 角色授权
|
||||
@bp.get('/power/<int:_id>')
|
||||
@authorize("system:role:power", log=True)
|
||||
def power(_id):
|
||||
return render_template('system/role/power.html', id=_id)
|
||||
|
||||
|
||||
# 获取角色权限
|
||||
@bp.get('/getRolePower/<int:id>')
|
||||
@authorize("system:role:main", log=True)
|
||||
def get_role_power(id):
|
||||
role = Role.query.filter_by(id=id).first()
|
||||
check_powers = role.power
|
||||
check_powers_list = []
|
||||
for cp in check_powers:
|
||||
check_powers_list.append(cp.id)
|
||||
powers = Power.query.all()
|
||||
power_schema = PowerOutSchema2(many=True) # 用已继承ma.ModelSchema类的自定制类生成序列化类
|
||||
output = power_schema.dump(powers) # 生成可序列化对象
|
||||
for i in output:
|
||||
if int(i.get("powerId")) in check_powers_list:
|
||||
i["checkArr"] = "1"
|
||||
else:
|
||||
i["checkArr"] = "0"
|
||||
res = {
|
||||
"data": output,
|
||||
"status": {"code": 200, "message": "默认"}
|
||||
}
|
||||
return jsonify(res)
|
||||
|
||||
|
||||
# 保存角色权限
|
||||
@bp.put('/saveRolePower')
|
||||
@authorize("system:role:edit", log=True)
|
||||
def save_role_power():
|
||||
req_form = request.form
|
||||
power_ids = req_form.get("powerIds")
|
||||
power_list = power_ids.split(',')
|
||||
role_id = req_form.get("roleId")
|
||||
role = Role.query.filter_by(id=role_id).first()
|
||||
|
||||
if not role:
|
||||
return fail_api(msg="角色不存在")
|
||||
|
||||
powers = Power.query.filter(Power.id.in_(power_list)).all()
|
||||
role.power = powers
|
||||
|
||||
db.session.commit()
|
||||
return success_api(msg="授权成功")
|
||||
|
||||
|
||||
# 角色编辑
|
||||
@bp.get('/edit/<int:id>')
|
||||
@authorize("system:role:edit", log=True)
|
||||
def edit(id):
|
||||
r = get_one_by_id(model=Role, id=id)
|
||||
return render_template('system/role/edit.html', role=r)
|
||||
|
||||
|
||||
# 更新角色
|
||||
@bp.put('/update')
|
||||
@authorize("system:role:edit", log=True)
|
||||
def update():
|
||||
req_json = request.get_json(force=True)
|
||||
id = req_json.get("roleId")
|
||||
|
||||
data = {
|
||||
"code": str_escape(req_json.get("roleCode")),
|
||||
"name": str_escape(req_json.get("roleName")),
|
||||
"sort": str_escape(req_json.get("sort")),
|
||||
"enable": str_escape(req_json.get("enable")),
|
||||
"details": str_escape(req_json.get("details"))
|
||||
}
|
||||
|
||||
if not data['enable'].isdigit():
|
||||
return fail_api(msg="参数 enable 需为整数")
|
||||
|
||||
if not data['sort'].isdigit():
|
||||
return fail_api(msg="参数 sort 需为整数")
|
||||
|
||||
role = Role.query.filter_by(id=id).update(data)
|
||||
db.session.commit()
|
||||
if not role:
|
||||
return fail_api(msg="更新角色失败")
|
||||
|
||||
return success_api(msg="更新角色成功")
|
||||
|
||||
|
||||
# 启用用户
|
||||
@bp.put('/enable')
|
||||
@authorize("system:role:edit", log=True)
|
||||
def enable():
|
||||
_id = request.get_json(force=True).get('roleId')
|
||||
if _id:
|
||||
res = enable_status(Role, _id)
|
||||
if not res:
|
||||
return fail_api(msg="出错啦")
|
||||
return success_api(msg="启动成功")
|
||||
return fail_api(msg="数据错误")
|
||||
|
||||
|
||||
# 禁用用户
|
||||
@bp.put('/disable')
|
||||
@authorize("system:role:edit", log=True)
|
||||
def dis_enable():
|
||||
_id = request.get_json(force=True).get('roleId')
|
||||
if _id:
|
||||
res = disable_status(Role, _id)
|
||||
if not res:
|
||||
return fail_api(msg="出错啦")
|
||||
return success_api(msg="禁用成功")
|
||||
return fail_api(msg="数据错误")
|
||||
|
||||
|
||||
# 角色删除
|
||||
@bp.delete('/remove/<int:id>')
|
||||
@authorize("system:role:remove", log=True)
|
||||
def remove(id):
|
||||
role = Role.query.filter_by(id=id).first()
|
||||
|
||||
if not role:
|
||||
return fail_api(msg="角色不存在")
|
||||
|
||||
# 删除该角色的权限和用户
|
||||
role.power = []
|
||||
role.user = []
|
||||
|
||||
r = Role.query.filter_by(id=id).delete()
|
||||
db.session.commit()
|
||||
if not r:
|
||||
return fail_api(msg="角色删除失败")
|
||||
return success_api(msg="角色删除成功")
|
||||
@@ -0,0 +1,236 @@
|
||||
from flask import Blueprint, render_template, request
|
||||
from flask_login import login_required, current_user
|
||||
from sqlalchemy import desc
|
||||
|
||||
from applications.common import curd
|
||||
from applications.common.curd import enable_status, disable_status
|
||||
from applications.common.utils.http import table_api, fail_api, success_api
|
||||
from applications.common.utils.rights import authorize
|
||||
from applications.common.utils.validate import str_escape
|
||||
from applications.extensions import db
|
||||
from applications.extensions.init_limit import limiter
|
||||
from applications.models import Role, Dept
|
||||
from applications.models import User, AdminLog
|
||||
|
||||
bp = Blueprint('user', __name__, url_prefix='/user')
|
||||
|
||||
|
||||
# 用户管理
|
||||
@bp.get('/')
|
||||
@authorize("system:user:main")
|
||||
def main():
|
||||
return render_template('system/user/main.html')
|
||||
|
||||
|
||||
# 用户分页查询
|
||||
@bp.get('/data')
|
||||
@limiter.limit("60 per minute")
|
||||
@authorize("system:user:main")
|
||||
def data():
|
||||
# 获取请求参数
|
||||
real_name = str_escape(request.args.get('realname', type=str))
|
||||
|
||||
username = str_escape(request.args.get('username', type=str))
|
||||
dept_id = request.args.get('deptId', type=int)
|
||||
|
||||
filters = []
|
||||
if real_name:
|
||||
filters.append(User.realname.contains(real_name))
|
||||
if username:
|
||||
filters.append(User.username.contains(username))
|
||||
if dept_id:
|
||||
filters.append(User.dept_id == dept_id)
|
||||
|
||||
# print(*filters)
|
||||
query = db.session.query(
|
||||
User,
|
||||
Dept
|
||||
).filter(*filters).outerjoin(Dept, User.dept_id == Dept.id).layui_paginate()
|
||||
|
||||
return table_api(
|
||||
data=[{
|
||||
'id': user.id,
|
||||
'username': user.username,
|
||||
'realname': user.realname,
|
||||
'enable': user.enable,
|
||||
'create_at': user.create_at,
|
||||
'update_at': user.update_at,
|
||||
'dept_name': dept.dept_name if dept else None
|
||||
} for user, dept in query.items],
|
||||
count=query.total)
|
||||
|
||||
# 用户增加
|
||||
@bp.get('/add')
|
||||
@authorize("system:user:add", log=True)
|
||||
def add():
|
||||
roles = Role.query.all()
|
||||
return render_template('system/user/add.html', roles=roles)
|
||||
|
||||
|
||||
@bp.post('/save')
|
||||
@authorize("system:user:add", log=True)
|
||||
def save():
|
||||
req_json = request.get_json(force=True)
|
||||
a = req_json.get("roleIds")
|
||||
username = str_escape(req_json.get('username'))
|
||||
real_name = str_escape(req_json.get('realName'))
|
||||
password = str_escape(req_json.get('password'))
|
||||
dept_id = str_escape(req_json.get('deptId'))
|
||||
role_ids = a.split(',')
|
||||
|
||||
if not username or not real_name or not password:
|
||||
return fail_api(msg="账号姓名密码不得为空")
|
||||
|
||||
if bool(User.query.filter_by(username=username).count()):
|
||||
return fail_api(msg="用户已经存在")
|
||||
|
||||
user = User(username=username, realname=real_name, enable=1, dept_id=dept_id)
|
||||
user.set_password(password)
|
||||
db.session.add(user)
|
||||
roles = Role.query.filter(Role.id.in_(role_ids)).all()
|
||||
for r in roles:
|
||||
user.role.append(r)
|
||||
|
||||
db.session.commit()
|
||||
return success_api(msg="增加成功")
|
||||
|
||||
|
||||
# 删除用户
|
||||
@bp.delete('/remove/<int:id>')
|
||||
@authorize("system:user:remove", log=True)
|
||||
def delete(id):
|
||||
user = User.query.filter_by(id=id).first()
|
||||
user.role = []
|
||||
|
||||
res = User.query.filter_by(id=id).delete()
|
||||
db.session.commit()
|
||||
if not res:
|
||||
return fail_api(msg="删除失败")
|
||||
return success_api(msg="删除成功")
|
||||
|
||||
|
||||
# 编辑用户
|
||||
@bp.get('/edit/<int:id>')
|
||||
@authorize("system:user:edit", log=True)
|
||||
def edit(id):
|
||||
user = curd.get_one_by_id(User, id)
|
||||
roles = Role.query.all()
|
||||
checked_roles = []
|
||||
for r in user.role:
|
||||
checked_roles.append(r.id)
|
||||
return render_template('system/user/edit.html', user=user, roles=roles, checked_roles=checked_roles)
|
||||
|
||||
|
||||
# 编辑用户
|
||||
@bp.put('/update')
|
||||
@authorize("system:user:edit", log=True)
|
||||
def update():
|
||||
req_json = request.get_json(force=True)
|
||||
a = str_escape(req_json.get("roleIds"))
|
||||
id = str_escape(req_json.get("userId"))
|
||||
username = str_escape(req_json.get('username'))
|
||||
real_name = str_escape(req_json.get('realName'))
|
||||
dept_id = str_escape(req_json.get('deptId'))
|
||||
role_ids = a.split(',')
|
||||
User.query.filter_by(id=id).update({'username': username, 'realname': real_name, 'dept_id': dept_id})
|
||||
u = User.query.filter_by(id=id).first()
|
||||
|
||||
roles = Role.query.filter(Role.id.in_(role_ids)).all()
|
||||
u.role = roles
|
||||
|
||||
db.session.commit()
|
||||
return success_api(msg="更新成功")
|
||||
|
||||
|
||||
# 个人中心
|
||||
@bp.get('/center')
|
||||
@login_required
|
||||
def center():
|
||||
user_info = current_user
|
||||
user_logs = AdminLog.query.filter_by(url='/passport/login').filter_by(uid=current_user.id).order_by(
|
||||
desc(AdminLog.create_time)).limit(10)
|
||||
return render_template('system/user/center.html', user_info=user_info, user_logs=user_logs)
|
||||
|
||||
|
||||
# 修改头像
|
||||
@bp.get('/profile')
|
||||
@login_required
|
||||
def profile():
|
||||
return render_template('system/user/profile.html')
|
||||
|
||||
|
||||
# 修改头像
|
||||
@bp.put('/updateAvatar')
|
||||
@login_required
|
||||
def update_avatar():
|
||||
url = request.get_json(force=True).get("avatar").get("src")
|
||||
r = User.query.filter_by(id=current_user.id).update({"avatar": url})
|
||||
db.session.commit()
|
||||
if not r:
|
||||
return fail_api(msg="出错啦")
|
||||
return success_api(msg="修改成功")
|
||||
|
||||
|
||||
# 修改当前用户信息
|
||||
@bp.put('/updateInfo')
|
||||
@login_required
|
||||
def update_info():
|
||||
req_json = request.get_json(force=True)
|
||||
r = User.query.filter_by(id=current_user.id).update(
|
||||
{"realname": req_json.get("realName"), "remark": req_json.get("details")})
|
||||
db.session.commit()
|
||||
if not r:
|
||||
return fail_api(msg="出错啦")
|
||||
return success_api(msg="更新成功")
|
||||
|
||||
|
||||
# 修改当前用户密码
|
||||
@bp.get('/editPassword')
|
||||
@login_required
|
||||
def edit_password():
|
||||
return render_template('system/user/edit_password.html')
|
||||
|
||||
|
||||
# 修改当前用户密码
|
||||
@bp.put('/editPassword')
|
||||
@login_required
|
||||
def edit_password_put():
|
||||
res_json = request.get_json(force=True)
|
||||
if res_json.get("newPassword") == '':
|
||||
return fail_api("新密码不得为空")
|
||||
if res_json.get("newPassword") != res_json.get("confirmPassword"):
|
||||
return fail_api("两次密码不一样")
|
||||
user = current_user
|
||||
is_right = user.validate_password(res_json.get("oldPassword"))
|
||||
if not is_right:
|
||||
return fail_api("旧密码错误")
|
||||
user.set_password(res_json.get("newPassword"))
|
||||
db.session.add(user)
|
||||
db.session.commit()
|
||||
return success_api("更改成功")
|
||||
|
||||
|
||||
# 启用用户
|
||||
@bp.put('/enable')
|
||||
@authorize("system:user:edit", log=True)
|
||||
def enable():
|
||||
_id = request.get_json(force=True).get('userId')
|
||||
if _id:
|
||||
res = enable_status(model=User, id=_id)
|
||||
if not res:
|
||||
return fail_api(msg="出错啦")
|
||||
return success_api(msg="启动成功")
|
||||
return fail_api(msg="数据错误")
|
||||
|
||||
|
||||
# 禁用用户
|
||||
@bp.put('/disable')
|
||||
@authorize("system:user:edit", log=True)
|
||||
def dis_enable():
|
||||
_id = request.get_json(force=True).get('userId')
|
||||
if _id:
|
||||
res = disable_status(model=User, id=_id)
|
||||
if not res:
|
||||
return fail_api(msg="出错啦")
|
||||
return success_api(msg="禁用成功")
|
||||
return fail_api(msg="数据错误")
|
||||
@@ -1,7 +0,0 @@
|
||||
from applications.views.admin import init_adminViews
|
||||
from applications.views.index import init_indexViews
|
||||
|
||||
|
||||
def init_view(app):
|
||||
init_adminViews(app)
|
||||
init_indexViews(app)
|
||||
@@ -1,22 +0,0 @@
|
||||
from applications.views.admin.index import admin_index
|
||||
from applications.views.admin.user import admin_user
|
||||
from applications.views.admin.file import admin_file
|
||||
from applications.views.admin.monitor import admin_Monitor
|
||||
from applications.views.admin.admin_log import admin_log
|
||||
from applications.views.admin.power import admin_power
|
||||
from applications.views.admin.role import admin_role
|
||||
"""
|
||||
初始化蓝图
|
||||
|
||||
"""
|
||||
|
||||
|
||||
def init_adminViews(app):
|
||||
|
||||
app.register_blueprint(admin_index)
|
||||
app.register_blueprint(admin_user)
|
||||
app.register_blueprint(admin_file)
|
||||
app.register_blueprint(admin_Monitor)
|
||||
app.register_blueprint(admin_log)
|
||||
app.register_blueprint(admin_power)
|
||||
app.register_blueprint(admin_role)
|
||||
@@ -1,88 +0,0 @@
|
||||
from flask import Blueprint, request, render_template, jsonify
|
||||
from flask_login import login_required
|
||||
from flask_marshmallow import Marshmallow
|
||||
from marshmallow import fields
|
||||
from sqlalchemy import desc
|
||||
from applications.models.admin import AdminLog
|
||||
|
||||
ma = Marshmallow()
|
||||
admin_log = Blueprint('adminLog', __name__, url_prefix='/admin/log')
|
||||
|
||||
|
||||
# ----------------------------------------------------------
|
||||
# ------------------------- 日志管理 --------------------------
|
||||
# ----------------------------------------------------------
|
||||
|
||||
|
||||
@admin_log.route('/')
|
||||
@login_required
|
||||
def index():
|
||||
return render_template('admin/admin_log/main.html')
|
||||
|
||||
|
||||
class LogSchema(ma.Schema): # 序列化类
|
||||
id = fields.Integer()
|
||||
method = fields.Str()
|
||||
uid = fields.Str()
|
||||
url = fields.Str()
|
||||
desc = fields.Str()
|
||||
ip = fields.Str()
|
||||
user_agent = fields.Str()
|
||||
success = fields.Bool()
|
||||
create_time = fields.DateTime()
|
||||
|
||||
|
||||
# ==========================================================
|
||||
# 登录日志
|
||||
# ==========================================================
|
||||
|
||||
|
||||
@admin_log.route('/loginLog')
|
||||
@login_required
|
||||
def loginLog():
|
||||
page = request.args.get('page', type=int)
|
||||
limit = request.args.get('limit', type=int)
|
||||
log = AdminLog.query.filter_by(url='/admin/login').order_by(desc(AdminLog.create_time)).paginate(page=page,
|
||||
per_page=limit,
|
||||
error_out=False)
|
||||
count = AdminLog.query.filter_by(url='/admin/login').count()
|
||||
role_schema = LogSchema(many=True)
|
||||
output = role_schema.dump(log.items)
|
||||
res = {
|
||||
'msg': "",
|
||||
'code': 0,
|
||||
'data': output,
|
||||
'count': count,
|
||||
'limit': "10"
|
||||
|
||||
}
|
||||
|
||||
return jsonify(res)
|
||||
|
||||
|
||||
# ==========================================================
|
||||
# 操作日志
|
||||
# ==========================================================
|
||||
|
||||
|
||||
@admin_log.route('/operateLog')
|
||||
@login_required
|
||||
def operateLog():
|
||||
page = request.args.get('page', type=int)
|
||||
limit = request.args.get('limit', type=int)
|
||||
log = AdminLog.query.filter(AdminLog.url != '/admin/login').order_by(desc(AdminLog.create_time)).paginate(page=page,
|
||||
per_page=limit,
|
||||
error_out=False)
|
||||
count = AdminLog.query.filter(AdminLog.url != '/admin/login').count()
|
||||
role_schema = LogSchema(many=True)
|
||||
output = role_schema.dump(log.items)
|
||||
res = {
|
||||
'msg': "",
|
||||
'code': 0,
|
||||
'data': output,
|
||||
'count': count,
|
||||
'limit': "10"
|
||||
|
||||
}
|
||||
|
||||
return jsonify(res)
|
||||
@@ -1,11 +0,0 @@
|
||||
from flask import session
|
||||
|
||||
|
||||
def init_template_global(app):
|
||||
@app.template_global()
|
||||
def authorize(power):
|
||||
# print(power)
|
||||
# print(session.get('permissions'))
|
||||
return bool(power in session.get('permissions'))
|
||||
|
||||
|
||||
@@ -1,16 +0,0 @@
|
||||
from flask import render_template
|
||||
|
||||
|
||||
def init_error(app):
|
||||
|
||||
@app.errorhandler(403)
|
||||
def page_not_found(e):
|
||||
return render_template('errors/403.html'), 403
|
||||
|
||||
@app.errorhandler(404)
|
||||
def page_not_found(e):
|
||||
return render_template('errors/404.html'), 404
|
||||
|
||||
@app.errorhandler(500)
|
||||
def internal_server_error(e):
|
||||
return render_template('errors/500.html'), 500
|
||||
@@ -1,83 +0,0 @@
|
||||
import os
|
||||
from flask import Blueprint, request, render_template, jsonify, current_app
|
||||
from flask_login import login_required
|
||||
from applications.models import db
|
||||
from applications.models.admin import Photo
|
||||
from applications.service.admin.file import get_photo, upload_one, delete_photo_by_id
|
||||
from applications.service.route_auth import authorize_and_log
|
||||
|
||||
admin_file = Blueprint('adminFile', __name__, url_prefix='/admin/file')
|
||||
|
||||
|
||||
# 图片管理
|
||||
@admin_file.route('/')
|
||||
@authorize_and_log("admin:file:main")
|
||||
def index():
|
||||
return render_template('admin/photo/photo.html')
|
||||
|
||||
|
||||
# 图片数据
|
||||
@admin_file.route('/table')
|
||||
@authorize_and_log("admin:file:main")
|
||||
def table():
|
||||
page = request.args.get('page', type=int)
|
||||
limit = request.args.get('limit', type=int)
|
||||
data, count = get_photo(page=page, limit=limit)
|
||||
res = {
|
||||
'msg': "",
|
||||
'code': 0,
|
||||
'data': data,
|
||||
'count': count,
|
||||
'limit': "10"
|
||||
|
||||
}
|
||||
return jsonify(res)
|
||||
|
||||
|
||||
# 上传接口
|
||||
@admin_file.route('/upload', methods=['GET', 'POST'])
|
||||
@authorize_and_log("admin:file:add")
|
||||
def upload():
|
||||
if request.method == 'POST' and 'file' in request.files:
|
||||
photo = request.files['file']
|
||||
mime = request.files['file'].content_type
|
||||
file_url = upload_one(photo=photo, mime=mime)
|
||||
res = {
|
||||
"msg": "上传成功",
|
||||
"code": 0,
|
||||
"data":
|
||||
{"src": file_url}
|
||||
}
|
||||
return jsonify(res)
|
||||
|
||||
return render_template('admin/photo/photo_add.html')
|
||||
|
||||
|
||||
# 图片删除
|
||||
@admin_file.route('/delete', methods=['GET', 'POST'])
|
||||
@authorize_and_log("admin:file:delete")
|
||||
def delete():
|
||||
id = request.form.get('id')
|
||||
res = delete_photo_by_id(id)
|
||||
if res:
|
||||
return jsonify(msg="删除成功", code=200)
|
||||
else:
|
||||
return jsonify(msg="删除失败", code=999)
|
||||
|
||||
|
||||
# 图片批量删除
|
||||
@admin_file.route('/batchRemove', methods=['GET', 'POST'])
|
||||
@authorize_and_log("admin:file:delete")
|
||||
def batchRemove():
|
||||
ids = request.form.getlist('ids[]')
|
||||
photo_name = Photo.query.filter(Photo.id.in_(ids)).all()
|
||||
upload_url = current_app.config.get("UPLOADED_PHOTOS_DEST")
|
||||
for p in photo_name:
|
||||
os.remove(upload_url + '/' + p.name)
|
||||
photo = Photo.query.filter(Photo.id.in_(ids)).delete(synchronize_session=False)
|
||||
db.session.commit()
|
||||
if photo:
|
||||
return jsonify(msg="删除成功", code=200)
|
||||
else:
|
||||
res = {"msg": "删除失败", "code": 999}
|
||||
return res
|
||||
@@ -1,89 +0,0 @@
|
||||
from flask import Blueprint, render_template, jsonify, request, session, redirect, url_for
|
||||
from flask_login import login_user, login_required, logout_user, current_user
|
||||
from applications.service.admin.index import add_auth_session, make_menu_tree, get_captcha
|
||||
from applications.service.admin_log import login_log
|
||||
from applications.models.admin import User
|
||||
|
||||
admin_index = Blueprint('adminIndex', __name__, url_prefix='/admin')
|
||||
|
||||
|
||||
# 首页
|
||||
@admin_index.route('/')
|
||||
@login_required
|
||||
def index():
|
||||
realname = current_user.realname
|
||||
return render_template('admin/index.html', realname=realname)
|
||||
|
||||
|
||||
# 获取验证码
|
||||
@admin_index.route('/getCaptcha', methods=["GET"])
|
||||
def getCaptcha():
|
||||
resp,code=get_captcha()
|
||||
session["code"] = code
|
||||
return resp
|
||||
|
||||
|
||||
# 登录
|
||||
@admin_index.route('/login', methods=['GET', 'POST'])
|
||||
def login():
|
||||
if request.method == 'POST':
|
||||
req = request.form
|
||||
username = req.get('username')
|
||||
password = req.get('password')
|
||||
code = req.get('captcha')
|
||||
|
||||
if not username or not password or not code:
|
||||
return jsonify(msg="用户名或密码没有输入", code=0,success=False)
|
||||
s_code = session.get("code", None)
|
||||
|
||||
if not all([code, s_code]):
|
||||
return jsonify(msg="参数错误", code=0,success=False)
|
||||
|
||||
if code != s_code:
|
||||
return jsonify(msg="验证码错误", code=0,success=False)
|
||||
user = User.query.filter_by(username=username).first()
|
||||
|
||||
if user is None:
|
||||
return jsonify(msg="不存在的用户", code=0,success=False)
|
||||
|
||||
if user.enable is 0:
|
||||
return jsonify(msg="用户被暂停使用", code=0,success=False)
|
||||
|
||||
if username == user.username and user.validate_password(password):
|
||||
# 登录
|
||||
login_user(user)
|
||||
# 记录登录日志
|
||||
login_log(request, uid=user.id, is_access=True)
|
||||
# 存入权限
|
||||
add_auth_session()
|
||||
return jsonify(msg="登录成功", code=1,success=True)
|
||||
login_log(request,uid=user.id, is_access=False)
|
||||
return jsonify(msg="用户名或密码错误", code=0,success=False)
|
||||
print(current_user.is_authenticated)
|
||||
if current_user.is_authenticated:
|
||||
return redirect(url_for('adminIndex.index'))
|
||||
return render_template('admin/login.html')
|
||||
|
||||
|
||||
# 退出登录
|
||||
@admin_index.route('/logout', methods=['GET', 'POST'])
|
||||
@login_required
|
||||
def logout():
|
||||
logout_user()
|
||||
session.pop('permissions')
|
||||
return jsonify(msg="注销成功", success=True)
|
||||
|
||||
|
||||
# 菜单
|
||||
@admin_index.route('/menu')
|
||||
@login_required
|
||||
def menu():
|
||||
menu_tree = make_menu_tree()
|
||||
return jsonify(menu_tree)
|
||||
|
||||
|
||||
# 控制台页面
|
||||
@admin_index.route('/welcome')
|
||||
@login_required
|
||||
def welcome():
|
||||
return render_template('admin/console/console.html')
|
||||
@@ -1,74 +0,0 @@
|
||||
import os
|
||||
import platform
|
||||
import re
|
||||
from datetime import datetime
|
||||
|
||||
import psutil
|
||||
from flask import Blueprint, render_template
|
||||
from flask_marshmallow import Marshmallow
|
||||
|
||||
from applications.service.route_auth import authorize_and_log
|
||||
|
||||
ma = Marshmallow()
|
||||
admin_Monitor = Blueprint('adminMonitor', __name__, url_prefix='/admin/monitor')
|
||||
|
||||
|
||||
# 系统监控
|
||||
@admin_Monitor.route('/')
|
||||
@authorize_and_log("admin:monitor:main")
|
||||
def main():
|
||||
# 主机名称
|
||||
hostname = platform.node()
|
||||
# 系统版本
|
||||
system_version = platform.platform()
|
||||
# python版本
|
||||
python_version = platform.python_version()
|
||||
# 逻辑cpu数量
|
||||
cpu_count = psutil.cpu_count()
|
||||
# cup使用率
|
||||
cpus_percent = psutil.cpu_percent(interval=0.1)
|
||||
# 内存
|
||||
memory_information = psutil.virtual_memory()
|
||||
# 内存使用率
|
||||
memory_usage = memory_information.percent
|
||||
memory_used = str(round(memory_information.used / 1024 / 1024))
|
||||
memory_total = str(round(memory_information.total / 1024 / 1024))
|
||||
memory_free = str(round(memory_information.free / 1024 / 1024))
|
||||
# 磁盘信息
|
||||
|
||||
disk_partitions_list = []
|
||||
# 判断是否在容器中
|
||||
if not os.path.exists('/.dockerenv'):
|
||||
disk_partitions = psutil.disk_partitions()
|
||||
for i in disk_partitions:
|
||||
a = psutil.disk_usage(i.device)
|
||||
disk_partitions_dict = {
|
||||
'device': i.device,
|
||||
'fstype': i.fstype,
|
||||
'total': str(round(a.total / 1024 / 1024)),
|
||||
'used': str(round(a.used / 1024 / 1024)),
|
||||
'free': str(round(a.free / 1024 / 1024)),
|
||||
'percent': a.percent
|
||||
}
|
||||
disk_partitions_list.append(disk_partitions_dict)
|
||||
|
||||
# 开机时间
|
||||
boot_time = datetime.fromtimestamp(psutil.boot_time()).replace(microsecond=0)
|
||||
up_time = datetime.now().replace(microsecond=0) - boot_time
|
||||
up_time_list = re.split(r':', str(up_time))
|
||||
up_time_format = " {} 小时{} 分钟{} 秒".format(up_time_list[0], up_time_list[1], up_time_list[2])
|
||||
|
||||
return render_template('admin/monitor.html',
|
||||
hostname=hostname,
|
||||
system_version=system_version,
|
||||
python_version=python_version,
|
||||
cpus_percent=cpus_percent,
|
||||
memory_usage=memory_usage,
|
||||
cpu_count=cpu_count,
|
||||
memory_used=memory_used,
|
||||
memory_total=memory_total,
|
||||
memory_free=memory_free,
|
||||
boot_time=boot_time,
|
||||
up_time_format=up_time_format,
|
||||
disk_partitions_list=disk_partitions_list
|
||||
)
|
||||
@@ -1,121 +0,0 @@
|
||||
from flask import Blueprint, render_template, request, jsonify
|
||||
from flask_login import login_required
|
||||
from applications.service.admin.power import get_power_dict, select_parent, save_power, remove_power, get_power_by_id, \
|
||||
update_power, enable_status, disable_status, batch_remove
|
||||
from applications.service.route_auth import authorize_and_log
|
||||
|
||||
admin_power = Blueprint('adminPower', __name__, url_prefix='/admin/power')
|
||||
|
||||
|
||||
@admin_power.route('/')
|
||||
@authorize_and_log("admin:power:main")
|
||||
def index():
|
||||
return render_template('admin/power/main.html')
|
||||
|
||||
|
||||
@admin_power.route('/data')
|
||||
@authorize_and_log("admin:power:main")
|
||||
def data():
|
||||
power_data = get_power_dict()
|
||||
res = {
|
||||
"data": power_data
|
||||
}
|
||||
return jsonify(res)
|
||||
|
||||
|
||||
@admin_power.route('/add')
|
||||
@authorize_and_log("admin:power:add")
|
||||
def add():
|
||||
return render_template('admin/power/add.html')
|
||||
|
||||
|
||||
@admin_power.route('/selectParent')
|
||||
@authorize_and_log("admin:power:main")
|
||||
def selectParent():
|
||||
power_data = select_parent()
|
||||
res = {
|
||||
"status": {"code": 200, "message": "默认"},
|
||||
"data": power_data
|
||||
|
||||
}
|
||||
return jsonify(res)
|
||||
|
||||
|
||||
# 增加
|
||||
@admin_power.route('/save', methods=['POST'])
|
||||
@authorize_and_log("admin:power:add")
|
||||
def save():
|
||||
req = request.json
|
||||
save_power(req)
|
||||
return jsonify(msg="成功", success=True)
|
||||
|
||||
|
||||
# 权限编辑
|
||||
@admin_power.route('/edit/<int:id>', methods=['GET', 'POST'])
|
||||
@authorize_and_log("admin:power:edit")
|
||||
def edit(id):
|
||||
power = get_power_by_id(id)
|
||||
icon = str(power.icon).split()
|
||||
if len(icon) == 2:
|
||||
icon = icon[1]
|
||||
else:
|
||||
icon = None
|
||||
return render_template('admin/power/edit.html', power=power, icon=icon)
|
||||
|
||||
|
||||
# 权限更新
|
||||
@admin_power.route('/update', methods=['PUT'])
|
||||
@authorize_and_log("admin:power:edit")
|
||||
def update():
|
||||
res = update_power(request.json)
|
||||
if not res:
|
||||
return jsonify(success=False, msg="更新权限失败")
|
||||
return jsonify(success=True, msg="更新权限成功")
|
||||
|
||||
|
||||
# 启用用户
|
||||
@admin_power.route('/enable', methods=['PUT'])
|
||||
@authorize_and_log("admin:power:edit")
|
||||
def enable():
|
||||
id = request.json.get('powerId')
|
||||
print(id)
|
||||
if id:
|
||||
res = enable_status(id)
|
||||
if not res:
|
||||
return jsonify(msg="出错啦", success=False)
|
||||
return jsonify(msg="启动成功", success=True)
|
||||
return jsonify(msg="数据错误", success=False)
|
||||
|
||||
|
||||
# 禁用用户
|
||||
@admin_power.route('/disable', methods=['PUT'])
|
||||
@authorize_and_log("admin:power:edit")
|
||||
def disenable():
|
||||
id = request.json.get('powerId')
|
||||
print(id)
|
||||
if id:
|
||||
res = disable_status(id)
|
||||
if not res:
|
||||
return jsonify(msg="出错啦", success=False)
|
||||
return jsonify(msg="禁用成功", success=True)
|
||||
return jsonify(msg="数据错误", success=False)
|
||||
|
||||
|
||||
# 权限删除
|
||||
@admin_power.route('/remove/<int:id>', methods=['DELETE'])
|
||||
@authorize_and_log("admin:power:remove")
|
||||
def remove(id):
|
||||
r = remove_power(id)
|
||||
if r:
|
||||
return jsonify(success=True, msg="删除成功")
|
||||
else:
|
||||
return jsonify(success=False, msg="删除失败")
|
||||
|
||||
|
||||
# 批量删除
|
||||
@admin_power.route('/batchRemove', methods=['DELETE'])
|
||||
@authorize_and_log("admin:power:remove")
|
||||
def batchRemove():
|
||||
ids = request.form.getlist('ids[]')
|
||||
batch_remove(ids)
|
||||
return jsonify(success=True, msg="批量删除成功")
|
||||
@@ -1,153 +0,0 @@
|
||||
from flask import Blueprint, render_template, request, jsonify
|
||||
from flask_login import login_required
|
||||
|
||||
from applications.service.admin.role import get_role_data_dict, add_role, get_role_power, update_role_power, \
|
||||
get_role_by_id, update_role, remove_role, batch_remove, enable_status, disable_status
|
||||
from applications.service.route_auth import authorize_and_log
|
||||
|
||||
admin_role = Blueprint('adminRole', __name__, url_prefix='/admin/role')
|
||||
|
||||
|
||||
# 用户管理
|
||||
@admin_role.route('/')
|
||||
@authorize_and_log("admin:role:main")
|
||||
def main():
|
||||
return render_template('admin/role/main.html')
|
||||
|
||||
|
||||
# 表格数据
|
||||
@admin_role.route('/data')
|
||||
@authorize_and_log("admin:role:main")
|
||||
def table():
|
||||
page = request.args.get('page', type=int)
|
||||
limit = request.args.get('limit', type=int)
|
||||
roleName = request.args.get('roleName', type=str)
|
||||
roleCode = request.args.get('roleCode', type=str)
|
||||
filters = {}
|
||||
if roleName:
|
||||
filters["name"] = ('%' + roleName + '%')
|
||||
if roleCode:
|
||||
filters["code"] = ('%' + roleCode + '%')
|
||||
data, count = get_role_data_dict(page=page, limit=limit, filters=filters)
|
||||
res = {
|
||||
'msg': "",
|
||||
'code': 0,
|
||||
'data': data,
|
||||
'count': count,
|
||||
'limit': "10"
|
||||
|
||||
}
|
||||
return jsonify(res)
|
||||
|
||||
|
||||
# 角色增加
|
||||
@admin_role.route('/add')
|
||||
@authorize_and_log("admin:role:add")
|
||||
@login_required
|
||||
def add():
|
||||
return render_template('admin/role/add.html')
|
||||
|
||||
|
||||
# 角色增加
|
||||
@admin_role.route('/save', methods=['POST'])
|
||||
@authorize_and_log("admin:role:add")
|
||||
def save():
|
||||
req = request.json
|
||||
add_role(req=req)
|
||||
return jsonify(msg="成功", success=True)
|
||||
|
||||
|
||||
# 角色授权
|
||||
@admin_role.route('/power/<int:id>')
|
||||
@authorize_and_log("admin:role:power")
|
||||
def power(id):
|
||||
return render_template('admin/role/power.html', id=id)
|
||||
|
||||
|
||||
# 获取角色权限
|
||||
@admin_role.route('/getRolePower/<int:id>')
|
||||
@authorize_and_log("admin:role:main")
|
||||
def getRolePower(id):
|
||||
powers = get_role_power(id)
|
||||
res = {
|
||||
"data": powers,
|
||||
"status": {"code": 200, "message": "默认"}
|
||||
}
|
||||
return jsonify(res)
|
||||
|
||||
|
||||
# 保存角色权限
|
||||
@admin_role.route('/saveRolePower', methods=['PUT'])
|
||||
@authorize_and_log("admin:role:edit")
|
||||
def saveRolePower():
|
||||
req_form = request.form
|
||||
powerIds = req_form.get("powerIds")
|
||||
power_list = powerIds.split(',')
|
||||
roleId = req_form.get("roleId")
|
||||
update_role_power(id=roleId, power_list=power_list)
|
||||
return jsonify(success=True, msg="授权成功")
|
||||
|
||||
|
||||
# 角色编辑
|
||||
@admin_role.route('/edit/<int:id>', methods=['GET', 'POST'])
|
||||
@authorize_and_log("admin:role:edit")
|
||||
def edit(id):
|
||||
role = get_role_by_id(id)
|
||||
return render_template('admin/role/edit.html', role=role)
|
||||
|
||||
|
||||
# 更新角色
|
||||
@admin_role.route('/update', methods=['PUT'])
|
||||
@authorize_and_log("admin:role:edit")
|
||||
def update():
|
||||
res = update_role(request.json)
|
||||
if not res:
|
||||
return jsonify(success=False, msg="更新角色失败")
|
||||
return jsonify(success=True, msg="更新角色成功")
|
||||
|
||||
# 启用用户
|
||||
@admin_role.route('/enable', methods=['PUT'])
|
||||
@authorize_and_log("admin:role:edit")
|
||||
def enable():
|
||||
id = request.json.get('roleId')
|
||||
print(id)
|
||||
if id:
|
||||
res = enable_status(id)
|
||||
if not res:
|
||||
return jsonify(msg="出错啦", success=False)
|
||||
return jsonify(msg="启动成功", success=True)
|
||||
return jsonify(msg="数据错误", success=False)
|
||||
|
||||
|
||||
# 禁用用户
|
||||
@admin_role.route('/disable', methods=['PUT'])
|
||||
@authorize_and_log("admin:role:edit")
|
||||
def disenable():
|
||||
id = request.json.get('roleId')
|
||||
print(id)
|
||||
if id:
|
||||
res = disable_status(id)
|
||||
if not res:
|
||||
return jsonify(msg="出错啦", success=False)
|
||||
return jsonify(msg="禁用成功", success=True)
|
||||
return jsonify(msg="数据错误", success=False)
|
||||
|
||||
|
||||
# 角色删除
|
||||
@admin_role.route('/remove/<int:id>', methods=['DELETE'])
|
||||
@authorize_and_log("admin:role:remove")
|
||||
def remove(id):
|
||||
res = remove_role(id)
|
||||
if not res:
|
||||
return jsonify(success=False, msg="角色删除失败")
|
||||
return jsonify(success=True, msg="角色删除成功")
|
||||
|
||||
|
||||
# 批量删除
|
||||
@admin_role.route('/batchRemove', methods=['DELETE'])
|
||||
@authorize_and_log("admin:role:remove")
|
||||
@login_required
|
||||
def batchRemove():
|
||||
ids = request.form.getlist('ids[]')
|
||||
batch_remove(ids)
|
||||
return jsonify(success=True,msg="批量删除成功")
|
||||
@@ -1,144 +0,0 @@
|
||||
from flask import Blueprint, render_template, request, jsonify
|
||||
from flask_login import login_required
|
||||
from applications.models.admin import User, Role
|
||||
from applications.service.admin.user import get_user_data_dict, add_user, delete_by_id, \
|
||||
batch_remove, update_user, update_user_role, is_user_exists, add_user_role, enable_status, disable_status
|
||||
from applications.service.route_auth import authorize_and_log
|
||||
|
||||
admin_user = Blueprint('adminUser', __name__, url_prefix='/admin/user')
|
||||
|
||||
|
||||
# 用户管理
|
||||
@admin_user.route('/')
|
||||
@authorize_and_log("admin:user:main")
|
||||
def main():
|
||||
return render_template('admin/user/main.html')
|
||||
|
||||
|
||||
# 用户分页查询
|
||||
@admin_user.route('/data')
|
||||
@authorize_and_log("admin:user:main")
|
||||
def data():
|
||||
page = request.args.get('page', type=int)
|
||||
limit = request.args.get('limit', type=int)
|
||||
realName = request.args.get('realName', type=str)
|
||||
username = request.args.get('username', type=str)
|
||||
filters = {}
|
||||
if realName:
|
||||
filters["realname"] = ('%' + realName + '%')
|
||||
if username:
|
||||
filters["username"] = ('%' + username + '%')
|
||||
data, count = get_user_data_dict(page=page, limit=limit, filters=filters)
|
||||
res = {
|
||||
'msg': "",
|
||||
'code': 0,
|
||||
'data': data,
|
||||
'count': count,
|
||||
'limit': "10"
|
||||
|
||||
}
|
||||
return jsonify(res)
|
||||
|
||||
|
||||
# 用户增加
|
||||
@admin_user.route('/add')
|
||||
@authorize_and_log("admin:user:add")
|
||||
def add():
|
||||
roles = Role.query.all()
|
||||
return render_template('admin/user/add.html', roles=roles)
|
||||
|
||||
|
||||
@admin_user.route('/save', methods=['POST'])
|
||||
@authorize_and_log("admin:user:add")
|
||||
def save():
|
||||
req_json = request.json
|
||||
a = req_json.get("roleIds")
|
||||
username = req_json.get('username')
|
||||
realName = req_json.get('realName')
|
||||
password = req_json.get('password')
|
||||
role_ids = a.split(',')
|
||||
|
||||
if not username or not realName or not password:
|
||||
return jsonify(success=False, msg="账号姓名密码不得为空")
|
||||
|
||||
if is_user_exists(username):
|
||||
return jsonify(success=False, msg="用户已经存在")
|
||||
|
||||
id = add_user(username, realName, password)
|
||||
add_user_role(id, role_ids)
|
||||
|
||||
return jsonify(success=True, msg="增加成功")
|
||||
|
||||
|
||||
# 删除用户
|
||||
@admin_user.route('/remove/<int:id>', methods=['DELETE'])
|
||||
@authorize_and_log("admin:user:remove")
|
||||
def delete(id):
|
||||
res = delete_by_id(id)
|
||||
if not res:
|
||||
return jsonify(msg="删除失败", success=False)
|
||||
return jsonify(msg="删除成功", success=True)
|
||||
|
||||
|
||||
# 编辑用户
|
||||
@admin_user.route('/edit/<int:id>', methods=['GET', 'POST'])
|
||||
@authorize_and_log("admin:user:edit")
|
||||
def edit(id):
|
||||
user = User.query.filter_by(id=id).first()
|
||||
roles = Role.query.all()
|
||||
checked_roles = []
|
||||
for r in user.role:
|
||||
checked_roles.append(r.id)
|
||||
return render_template('admin/user/edit.html', user=user, roles=roles, checked_roles=checked_roles)
|
||||
|
||||
# 编辑用户
|
||||
@admin_user.route('/update', methods=['PUT'])
|
||||
@authorize_and_log("admin:user:edit")
|
||||
def update():
|
||||
req_json = request.json
|
||||
a = req_json.get("roleIds")
|
||||
id = req_json.get("userId")
|
||||
username = req_json.get('username')
|
||||
realName = req_json.get('realName')
|
||||
role_ids = a.split(',')
|
||||
update_user(id, username, realName)
|
||||
update_user_role(id, role_ids)
|
||||
return jsonify(success=True, msg="更新成功")
|
||||
|
||||
|
||||
# 启用用户
|
||||
@admin_user.route('/enable', methods=['PUT'])
|
||||
@authorize_and_log("admin:user:edit")
|
||||
def enable():
|
||||
id = request.json.get('userId')
|
||||
print(id)
|
||||
if id:
|
||||
res = enable_status(id)
|
||||
if not res:
|
||||
return jsonify(msg="出错啦", success=False)
|
||||
return jsonify(msg="启动成功", success=True)
|
||||
return jsonify(msg="数据错误", success=False)
|
||||
|
||||
|
||||
# 禁用用户
|
||||
@admin_user.route('/disable', methods=['PUT'])
|
||||
@authorize_and_log("admin:user:edit")
|
||||
def disenable():
|
||||
id = request.json.get('userId')
|
||||
print(id)
|
||||
if id:
|
||||
res = disable_status(id)
|
||||
if not res:
|
||||
return jsonify(msg="出错啦", success=False)
|
||||
return jsonify(msg="禁用成功", success=True)
|
||||
return jsonify(msg="数据错误", success=False)
|
||||
|
||||
|
||||
# 批量删除
|
||||
@admin_user.route('/batchRemove', methods=['DELETE'])
|
||||
@authorize_and_log("admin:user:remove")
|
||||
def batchRemove():
|
||||
ids = request.form.getlist('ids[]')
|
||||
batch_remove(ids)
|
||||
return jsonify(success=True, msg="批量删除成功")
|
||||
|
||||
@@ -1,10 +0,0 @@
|
||||
from applications.views.index.index import index_index
|
||||
|
||||
|
||||
def init_indexViews(app):
|
||||
"""
|
||||
初始化蓝图
|
||||
|
||||
"""
|
||||
|
||||
app.register_blueprint(index_index)
|
||||
@@ -1,11 +0,0 @@
|
||||
from flask import Blueprint,render_template
|
||||
|
||||
index_index = Blueprint('Index', __name__, url_prefix='/')
|
||||
from flask_marshmallow import Marshmallow
|
||||
|
||||
ma = Marshmallow()
|
||||
|
||||
|
||||
@index_index.route('/')
|
||||
def index():
|
||||
return render_template('index/index.html')
|
||||
@@ -0,0 +1,25 @@
|
||||
FROM python:3.11-bookworm
|
||||
|
||||
# 设置时区
|
||||
ENV TIME_ZONE Asia/Shanghai
|
||||
RUN echo "${TIME_ZONE}" > /etc/timezone \
|
||||
&& ln -sf /usr/share/zoneinfo/${TIME_ZONE} /etc/localtime
|
||||
|
||||
WORKDIR /app
|
||||
|
||||
# 1. [优化] 先只拷贝依赖文件,利用 Docker 缓存
|
||||
# 只要 requirements.txt 没变,这一步和 pip install 就会直接用缓存,极大加快构建速度
|
||||
COPY requirements.txt /app/
|
||||
|
||||
# 2. 安装依赖 (使用清华源)
|
||||
RUN python3 -m pip install --no-cache-dir -r requirements.txt -i https://pypi.tuna.tsinghua.edu.cn/simple/ \
|
||||
&& python3 -m pip install --no-cache-dir gunicorn -i https://pypi.tuna.tsinghua.edu.cn/simple/
|
||||
|
||||
# 3. 拷贝其余项目代码
|
||||
COPY . /app/
|
||||
|
||||
# 4. 确保脚本有执行权限 (直接处理源路径,防止移动失败)
|
||||
RUN chmod +x /app/deploy/dev/start.sh
|
||||
|
||||
# 5. 指定启动入口
|
||||
CMD ["/bin/bash", "/app/deploy/dev/start.sh"]
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user