diff --git a/par-api/src/main/java/com/par/api/controller/AdminController.java b/par-api/src/main/java/com/par/api/controller/AdminController.java index 515b76a..4e834bd 100644 --- a/par-api/src/main/java/com/par/api/controller/AdminController.java +++ b/par-api/src/main/java/com/par/api/controller/AdminController.java @@ -120,7 +120,7 @@ public class AdminController { } /** - * 设置用户信任等级 + * 设置用户信任等级(禁止修改管理员、禁止提升为管理员) */ @PostMapping("/accounts/{accountId}/trust-level") public ApiResponse setTrustLevel( @@ -130,13 +130,24 @@ public class AdminController { checkAdmin(request); - var account = accountMapper.selectById(accountId); - if (account == null) { + var target = accountMapper.selectById(accountId); + if (target == null) { return ApiResponse.error(404, "Account not found"); } - account.setTrustLevel(TrustLevel.fromValue(level)); - accountMapper.updateById(account); + // 禁止修改管理员 + if (target.getTrustLevel() == TrustLevel.ADMIN) { + return ApiResponse.error(403, "不能修改管理员账户的信任等级"); + } + + // 禁止将用户设置为管理员 + TrustLevel newLevel = TrustLevel.fromValue(level); + if (newLevel == TrustLevel.ADMIN) { + return ApiResponse.error(403, "不能通过此接口提升为管理员,请直接操作数据库"); + } + + target.setTrustLevel(newLevel); + accountMapper.updateById(target); log.info("Trust level updated: accountId={}, level={}", accountId, level); return ApiResponse.success(); diff --git a/web/src/views/Users.vue b/web/src/views/Users.vue index 5887435..ea9d622 100644 --- a/web/src/views/Users.vue +++ b/web/src/views/Users.vue @@ -9,7 +9,7 @@ @@ -21,13 +21,37 @@ - + + + + + + + {{ levelForm.email }} + + + + + + + + + + @@ -36,12 +60,20 @@ import api from '../api' const users = ref([]) const loading = ref(false) +const dialogVisible = ref(false) +const saving = ref(false) +const levelForm = reactive({ id: null, email: '', level: '' }) const trustLevelType = (level) => { const map = { MEMBER: '', TRUSTED: 'warning', ADMIN: 'danger' } return map[level] || '' } +const trustLevelLabel = (level) => { + const map = { MEMBER: '普通成员', TRUSTED: '受信任', ADMIN: '管理员' } + return map[level] || level +} + const fetchUsers = async () => { loading.value = true try { @@ -54,19 +86,28 @@ const fetchUsers = async () => { } } -const handleSetLevel = async (row) => { +const handleSetLevel = (row) => { + levelForm.id = row.id + levelForm.email = row.email + levelForm.level = row.trustLevel === 'ADMIN' ? '' : row.trustLevel + dialogVisible.value = true +} + +const confirmSetLevel = async () => { + if (!levelForm.level) { + ElMessage.warning('请选择等级') + return + } + saving.value = true try { - const { value: level } = await ElMessageBox.prompt('请输入信任等级 (MEMBER/TRUSTED/ADMIN)', '设置信任等级', { - inputValue: row.trustLevel, - confirmButtonText: '确认', - cancelButtonText: '取消', - inputValidator: (v) => ['MEMBER', 'TRUSTED', 'ADMIN'].includes(v) ? true : '无效等级' - }) - await api.users.setTrustLevel(row.id, level) + await api.users.setTrustLevel(levelForm.id, levelForm.level) ElMessage.success('设置成功') + dialogVisible.value = false fetchUsers() } catch (e) { - if (e !== 'cancel') ElMessage.error(e.response?.data?.message || '操作失败') + ElMessage.error(e.response?.data?.message || '操作失败') + } finally { + saving.value = false } }