change_check.js 3.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687
  1. 'use strict';
  2. /**
  3. *
  4. *
  5. * @author Ellisran
  6. * @date 2020/10/15
  7. * @version
  8. */
  9. const status = require('../const/audit').flow.status;
  10. const shenpiConst = require('../const/shenpi');
  11. const _ = require('lodash');
  12. module.exports = options => {
  13. /**
  14. * 标段校验 中间件
  15. * 1. 读取标段数据(包括属性)
  16. * 2. 检验用户是否可见标段(不校验具体权限)
  17. *
  18. * @param {function} next - 中间件继续执行的方法
  19. * @return {void}
  20. */
  21. return function* changeCheck(next) {
  22. try {
  23. // 获取revise
  24. const cid = this.params.cid || this.request.body.cid;
  25. if (!cid) {
  26. throw '您访问的变更令不存在';
  27. }
  28. const change = yield this.service.change.getDataByCondition({ cid });
  29. // 读取原报、审核人数据
  30. change.auditors = yield this.service.changeAudit.getListGroupByTimes(change.cid, change.times);
  31. change.curAuditor = yield this.service.changeAudit.getCurAuditor(change.cid, change.times);
  32. if (!change) throw '变更令数据有误';
  33. // 权限相关
  34. // todo 校验权限 (变更参与人)
  35. const accountId = this.session.sessionUser.accountId,
  36. auditorIds = _.map(change.auditors, 'uid'),
  37. shareIds = [];
  38. const permission = this.session.sessionUser.permission;
  39. if (accountId === change.uid) { // 原报
  40. if (change.curAuditor) {
  41. change.readOnly = change.curAuditor.uid !== accountId;
  42. } else {
  43. change.readOnly = change.status !== status.uncheck && change.status !== status.back && change.status !== status.revise;
  44. }
  45. } else if (this.tender.isTourist) {
  46. change.readOnly = true;
  47. } else if (auditorIds.indexOf(accountId) !== -1) { // 审批人
  48. if (change.status === status.uncheck) {
  49. throw '您无权查看该数据';
  50. }
  51. change.readOnly = true;
  52. } else if (shareIds.indexOf(accountId) !== -1 || (permission !== null && permission.tender !== undefined && permission.tender.indexOf('2') !== -1)) { // 分享人
  53. if (change.status === status.uncheck) {
  54. throw '您无权查看该数据';
  55. }
  56. change.readOnly = true;
  57. } else { // 其他不可见
  58. throw '您无权查看该数据';
  59. }
  60. this.change = change;
  61. if ((change.status === status.uncheck || change.status === status.back || change.status === status.revise) && change.tp_decimal !== this.tender.info.decimal.tp) {
  62. this.change.tp_decimal = this.tender.info.decimal.tp;
  63. yield this.service.change.updateDecimalAndTp();
  64. }
  65. yield next;
  66. } catch (err) {
  67. console.log(err);
  68. // 输出错误到日志
  69. if (err.stack) {
  70. this.logger.error(err);
  71. } else {
  72. this.getLogger('fail').info(JSON.stringify({
  73. error: err,
  74. project: this.session.sessionProject,
  75. user: this.session.sessionUser,
  76. body: this.session.body,
  77. }));
  78. }
  79. // 重定向值标段管理
  80. this.redirect(this.request.headers.referer);
  81. }
  82. };
  83. };