casbin_rbac.go 845 B

123456789101112131415161718192021222324252627282930313233343536
  1. package middleware
  2. import (
  3. "strconv"
  4. "strings"
  5. "github.com/gin-gonic/gin"
  6. "server/global"
  7. "server/model/common/response"
  8. "server/service"
  9. "server/utils"
  10. )
  11. var casbinService = service.ServiceGroupApp.SystemServiceGroup.CasbinService
  12. // CasbinHandler 拦截器
  13. func CasbinHandler() gin.HandlerFunc {
  14. return func(c *gin.Context) {
  15. waitUse, _ := utils.GetClaims(c)
  16. //获取请求的PATH
  17. path := c.Request.URL.Path
  18. obj := strings.TrimPrefix(path, global.GVA_CONFIG.System.RouterPrefix)
  19. // 获取请求方法
  20. act := c.Request.Method
  21. // 获取用户的角色
  22. sub := strconv.Itoa(int(waitUse.AuthorityId))
  23. e := casbinService.Casbin() // 判断策略中是否存在
  24. success, _ := e.Enforce(sub, obj, act)
  25. if !success {
  26. response.FailWithDetailed(gin.H{}, "权限不足", c)
  27. c.Abort()
  28. return
  29. }
  30. c.Next()
  31. }
  32. }