diff --git a/Yes.Application/Admins/Articles/UpdateArticleCommandHandler.cs b/Yes.Application/Admins/Articles/UpdateArticleCommandHandler.cs index 43ef4e5..117b0cb 100644 --- a/Yes.Application/Admins/Articles/UpdateArticleCommandHandler.cs +++ b/Yes.Application/Admins/Articles/UpdateArticleCommandHandler.cs @@ -41,8 +41,23 @@ throw new ArticleNotExistsException(request.Id); } + var identityUser = await _db.Users.FindAsync(_identity.Id); + if (identityUser == null) + { + throw new UserNotExistsException(_identity.Id); + } - if (!string.IsNullOrEmpty(request.Slug) && + if (!identityUser.IsSystemUser()) + { + if (article.UserId != identityUser.Id) + { + throw new AccessDeniedException(); + } + } + + + + if (!string.IsNullOrEmpty(request.Slug) && article.IsSlugDifferent(request.Slug) && await _articleService.IsSlugInUse(request.Slug)) { diff --git a/Yes.Application/Admins/Articles/UpdateDraftCommandHandler.cs b/Yes.Application/Admins/Articles/UpdateDraftCommandHandler.cs index 70bbcdd..f2d1389 100644 --- a/Yes.Application/Admins/Articles/UpdateDraftCommandHandler.cs +++ b/Yes.Application/Admins/Articles/UpdateDraftCommandHandler.cs @@ -34,6 +34,22 @@ { throw new ArticleNotExistsException(request.Id); } + + var identityUser = await _db.Users.FindAsync(_identity.Id); + if (identityUser == null) + { + throw new UserNotExistsException(_identity.Id); + } + + if (!identityUser.IsSystemUser()) + { + if (article.UserId != identityUser.Id) + { + throw new AccessDeniedException(); + } + } + + article.UpdateDraft(request.Title, request.Content, request.Summary, request.Tags, request.Slug, request.CoverUrl, authorObject, categoryObject); _db.Articles.Update(article); diff --git a/Yes.Application/Admins/Categories/DeleteCategoryCommandHandler.cs b/Yes.Application/Admins/Categories/DeleteCategoryCommandHandler.cs index 14955f9..5d79830 100644 --- a/Yes.Application/Admins/Categories/DeleteCategoryCommandHandler.cs +++ b/Yes.Application/Admins/Categories/DeleteCategoryCommandHandler.cs @@ -2,12 +2,38 @@ { public record DeleteCategoryCommand(int Id) : IRequest; - public class DeleteCategoryCommandHandler(BlogDbContext db) : IRequestHandler + public class DeleteCategoryCommandHandler( + BlogDbContext db, + IIdentityContext identity) : IRequestHandler { private readonly BlogDbContext _db = db; + private readonly IIdentityContext _identity = identity; public async Task Handle(DeleteCategoryCommand request, CancellationToken cancellationToken) { + var identityUser = await _db.Users.FindAsync(_identity.Id); + if (identityUser == null) + { + throw new UserNotExistsException(_identity.Id); + } + + if (!identityUser.IsSystemUser()) + { + throw new AccessDeniedException(); + } + + var hasArticlesInCategory = await _db.Articles.AnyAsync(x => x.CategoryId == request.Id, cancellationToken); + if (hasArticlesInCategory) + { + throw new DeleteCategoryException("分类下还有文章,无法删除!"); + } + + var categoryCount = await _db.Categories.CountAsync(cancellationToken); + if (categoryCount <= 1) + { + throw new DeleteCategoryException("至少要保留一个分类!"); + } + var category = await _db.Categories.FindAsync(request.Id); if (category != null) { diff --git a/Yes.Application/Admins/Comments/DeleteCommentCommandHandler.cs b/Yes.Application/Admins/Comments/DeleteCommentCommandHandler.cs index 5ed52ae..77ba765 100644 --- a/Yes.Application/Admins/Comments/DeleteCommentCommandHandler.cs +++ b/Yes.Application/Admins/Comments/DeleteCommentCommandHandler.cs @@ -4,12 +4,26 @@ public record DeleteCommentCommandResponse(int Id); - public class DeleteCommentCommandHandler(BlogDbContext db) : IRequestHandler + public class DeleteCommentCommandHandler( + BlogDbContext db, + IIdentityContext identity) : IRequestHandler { private readonly BlogDbContext _db = db; - + private readonly IIdentityContext _identity = identity; public async Task Handle(DeleteCommentCommand request, CancellationToken cancellationToken) { + var identityUser = await _db.Users.FindAsync(_identity.Id); + if (identityUser == null) + { + throw new UserNotExistsException(_identity.Id); + } + + if (!identityUser.IsSystemUser()) + { + throw new AccessDeniedException(); + } + + var comment = await _db.Comments.FindAsync(request.Id); if (comment != null) { diff --git a/Yes.Application/Admins/Configurations/UpdateConfigurationCommandHandler.cs b/Yes.Application/Admins/Configurations/UpdateConfigurationCommandHandler.cs index 70cae03..aebec5f 100644 --- a/Yes.Application/Admins/Configurations/UpdateConfigurationCommandHandler.cs +++ b/Yes.Application/Admins/Configurations/UpdateConfigurationCommandHandler.cs @@ -1,4 +1,6 @@ -namespace Yes.Application.Admins.Configurations +using static Dapper.SqlMapper; + +namespace Yes.Application.Admins.Configurations { public record UpdateConfigurationCommand( string Name, @@ -19,14 +21,33 @@ public record UpdateConfigurationCommandResponse(int Id); - public class UpdateConfigurationCommandHandler(IOptionsMonitor options, IMapper mapper, IConfigurationService configurationService) : IRequestHandler + public class UpdateConfigurationCommandHandler( + IOptionsMonitor options, + IMapper mapper, + IConfigurationService configurationService, + BlogDbContext db, + IIdentityContext identity) : IRequestHandler { private readonly BlogSettings _settings = options.CurrentValue; private readonly IMapper _mapper = mapper; private readonly IConfigurationService _configurationService = configurationService; + private readonly BlogDbContext _db = db; + private readonly IIdentityContext _identity = identity; public async Task Handle(UpdateConfigurationCommand request, CancellationToken cancellationToken) { + + var identityUser = await _db.Users.FindAsync(_identity.Id); + if (identityUser == null) + { + throw new UserNotExistsException(_identity.Id); + } + + if (!identityUser.IsSystemUser()) + { + throw new AccessDeniedException(); + } + _mapper.Map(request, _settings); await _configurationService.SaveConfiguration(_settings); diff --git a/Yes.Application/Admins/Pages/UpdatePageCommandHandler.cs b/Yes.Application/Admins/Pages/UpdatePageCommandHandler.cs index 896b9fd..0987459 100644 --- a/Yes.Application/Admins/Pages/UpdatePageCommandHandler.cs +++ b/Yes.Application/Admins/Pages/UpdatePageCommandHandler.cs @@ -37,6 +37,20 @@ throw new ArticleNotExistsException(request.Id); } + var identityUser = await _db.Users.FindAsync(_identity.Id); + if (identityUser == null) + { + throw new UserNotExistsException(_identity.Id); + } + + if (!identityUser.IsSystemUser()) + { + if (page.UserId != identityUser.Id) + { + throw new AccessDeniedException(); + } + } + if (!string.IsNullOrEmpty(request.Slug) && request.Slug != page.Id.ToString() && diff --git a/Yes.Application/Admins/Themes/UpdateThemeCommandHandler.cs b/Yes.Application/Admins/Themes/UpdateThemeCommandHandler.cs index a6cada8..977f8f7 100644 --- a/Yes.Application/Admins/Themes/UpdateThemeCommandHandler.cs +++ b/Yes.Application/Admins/Themes/UpdateThemeCommandHandler.cs @@ -9,15 +9,31 @@ IOptionsMonitor options, IMapper mapper, IThemeService themeService, - IConfigurationService configurationService - ) : IRequestHandler + IConfigurationService configurationService, + BlogDbContext db, + IIdentityContext identity + ) : IRequestHandler { private readonly BlogSettings _settings = options.CurrentValue; private readonly IMapper _mapper = mapper; private readonly IThemeService _themeService = themeService; private readonly IConfigurationService _configurationService = configurationService; + private readonly BlogDbContext _db = db; + private readonly IIdentityContext _identity = identity; public async Task Handle(UpdateThemeCommand request, CancellationToken cancellationToken) { + var identityUser = await _db.Users.FindAsync(_identity.Id); + if (identityUser == null) + { + throw new UserNotExistsException(_identity.Id); + } + + if (!identityUser.IsSystemUser()) + { + throw new AccessDeniedException(); + } + + _themeService.CheckThemeExists(request.Theme); _mapper.Map(request, _settings); diff --git a/Yes.Application/Admins/Themes/UpdateThemeFileCommandHandler.cs b/Yes.Application/Admins/Themes/UpdateThemeFileCommandHandler.cs index abe2c59..4998ffc 100644 --- a/Yes.Application/Admins/Themes/UpdateThemeFileCommandHandler.cs +++ b/Yes.Application/Admins/Themes/UpdateThemeFileCommandHandler.cs @@ -9,13 +9,28 @@ public class UpdateThemeFileCommandHandler( IThemeService themeService, - IWebHostEnvironment env + IWebHostEnvironment env, + BlogDbContext db, + IIdentityContext identity ) : IRequestHandler { private readonly IThemeService _themeService = themeService; private readonly IWebHostEnvironment _env = env; + private readonly BlogDbContext _db = db; + private readonly IIdentityContext _identity = identity; public async Task Handle(UpdateThemeFileCommand request, CancellationToken cancellationToken) { + var identityUser = await _db.Users.FindAsync(_identity.Id); + if (identityUser == null) + { + throw new UserNotExistsException(_identity.Id); + } + + if (!identityUser.IsSystemUser()) + { + throw new AccessDeniedException(); + } + var themeName = request.ThemeName; var fileName = request.FileName; var content = request.Content; diff --git a/Yes.Application/Admins/Themes/UploadThemeCommandHandler.cs b/Yes.Application/Admins/Themes/UploadThemeCommandHandler.cs index 374e11a..3a6701f 100644 --- a/Yes.Application/Admins/Themes/UploadThemeCommandHandler.cs +++ b/Yes.Application/Admins/Themes/UploadThemeCommandHandler.cs @@ -1,18 +1,32 @@ - - -namespace Yes.Application.Admins.Themes +namespace Yes.Application.Admins.Themes { public record UploadThemeCommand(IFormFile File) : IRequest; public record UploadThemeCommandResponse(string DirName); - public class UploadThemeCommandHandler(IWebHostEnvironment env, + public class UploadThemeCommandHandler( + IWebHostEnvironment env, + BlogDbContext db, + IIdentityContext identity, IOptionsMonitor options) : IRequestHandler { private readonly IWebHostEnvironment _env = env; private readonly BlogSettings _settings = options.CurrentValue; + private readonly BlogDbContext _db = db; + private readonly IIdentityContext _identity = identity; public async Task Handle(UploadThemeCommand request, CancellationToken cancellationToken) { + var identityUser = await _db.Users.FindAsync(_identity.Id); + if (identityUser == null) + { + throw new UserNotExistsException(_identity.Id); + } + + if (!identityUser.IsSystemUser()) + { + throw new AccessDeniedException(); + } + try { diff --git a/Yes.Application/Admins/Users/CreateUserCommandHandler.cs b/Yes.Application/Admins/Users/CreateUserCommandHandler.cs index a7403f7..97ae78a 100644 --- a/Yes.Application/Admins/Users/CreateUserCommandHandler.cs +++ b/Yes.Application/Admins/Users/CreateUserCommandHandler.cs @@ -9,12 +9,25 @@ public record CreateUserCommandResponse(int Id); - public class CreateUserCommandHandler(BlogDbContext db) : IRequestHandler + public class CreateUserCommandHandler(BlogDbContext db, IIdentityContext identity) : IRequestHandler { private readonly BlogDbContext _db = db; + private readonly IIdentityContext _identity = identity; public async Task Handle(CreateUserCommand request, CancellationToken cancellationToken) { + var identityUser = await _db.Users.FindAsync(_identity.Id); + if (identityUser == null) + { + throw new UserNotExistsException(_identity.Id); + } + + if (!identityUser.IsSystemUser()) + { + throw new AccessDeniedException(); + } + + var user = UserEntity.Create(request.Name, request.Email, request.NickName, request.Password); await _db.Users.AddAsync(user); await _db.SaveChangesAsync(); diff --git a/Yes.Application/Admins/Users/DeleteUserCommandHandler.cs b/Yes.Application/Admins/Users/DeleteUserCommandHandler.cs index 3a37d99..cc5f234 100644 --- a/Yes.Application/Admins/Users/DeleteUserCommandHandler.cs +++ b/Yes.Application/Admins/Users/DeleteUserCommandHandler.cs @@ -2,12 +2,24 @@ { public record DeleteUserCommand(int Id) : IRequest; - public class DeleteUserCommandHandler(BlogDbContext db) : IRequestHandler + public class DeleteUserCommandHandler(BlogDbContext db, IIdentityContext identity) : IRequestHandler { private readonly BlogDbContext _db = db; - + private readonly IIdentityContext _identity = identity; public async Task Handle(DeleteUserCommand request, CancellationToken cancellationToken) { + var identityUser = await _db.Users.FindAsync(_identity.Id); + if (identityUser == null) + { + throw new UserNotExistsException(_identity.Id); + } + + if (!identityUser.IsSystemUser()) + { + throw new AccessDeniedException(); + } + + var user = await _db.Users.FindAsync(request.Id); if (user == null) { diff --git a/Yes.Application/Admins/Users/UpdateUserCommandHandler.cs b/Yes.Application/Admins/Users/UpdateUserCommandHandler.cs index 12c5250..dafc391 100644 --- a/Yes.Application/Admins/Users/UpdateUserCommandHandler.cs +++ b/Yes.Application/Admins/Users/UpdateUserCommandHandler.cs @@ -9,12 +9,23 @@ ) : IRequest; - public class UpdateUserCommandHandler(BlogDbContext db) : IRequestHandler + public class UpdateUserCommandHandler(BlogDbContext db, IIdentityContext identity) : IRequestHandler { private readonly BlogDbContext _db = db; - + private readonly IIdentityContext _identity = identity; public async Task Handle(UpdateUserCommand request, CancellationToken cancellationToken) { + var identityUser = await _db.Users.FindAsync(_identity.Id); + if (identityUser == null) + { + throw new UserNotExistsException(_identity.Id); + } + + if (!identityUser.IsSystemUser()) + { + throw new AccessDeniedException(); + } + var user = await _db.Users.FindAsync(request.Id); if (user == null) { diff --git a/Yes.Domain/Core/Exceptions/AccessDeniedException.cs b/Yes.Domain/Core/Exceptions/AccessDeniedException.cs new file mode 100644 index 0000000..606d6b9 --- /dev/null +++ b/Yes.Domain/Core/Exceptions/AccessDeniedException.cs @@ -0,0 +1,22 @@ +namespace Yes.Domain.Core.Exceptions +{ + public class AccessDeniedException : BaseException + { + + public AccessDeniedException() + : base("访问被拒绝:没有足够的权限执行此操作。") + { + } + + public AccessDeniedException(string message) + : base(message) + { + } + + public AccessDeniedException(string resourceName, string requiredPermission) + : this($"访问被拒绝:对资源 '{resourceName}' 需要权限 '{requiredPermission}'。") + { + + } + } +} diff --git a/Yes.Domain/Core/Exceptions/CategoryNotExistsException.cs b/Yes.Domain/Core/Exceptions/CategoryNotExistsException.cs index a05ad57..7f140ff 100644 --- a/Yes.Domain/Core/Exceptions/CategoryNotExistsException.cs +++ b/Yes.Domain/Core/Exceptions/CategoryNotExistsException.cs @@ -1,6 +1,6 @@ namespace Yes.Domain.Core.Exceptions { - public class CategoryNotExistsException : Exception + public class CategoryNotExistsException : BaseException { public CategoryNotExistsException(int categoryId) : base($"分类id{categoryId}不存在!") { diff --git a/Yes.Domain/Core/Exceptions/DeleteCategoryException.cs b/Yes.Domain/Core/Exceptions/DeleteCategoryException.cs new file mode 100644 index 0000000..0ec77f4 --- /dev/null +++ b/Yes.Domain/Core/Exceptions/DeleteCategoryException.cs @@ -0,0 +1,15 @@ +namespace Yes.Domain.Core.Exceptions +{ + public class DeleteCategoryException : BaseException + { + public DeleteCategoryException(string message) : base(message) + { + + } + + public DeleteCategoryException() : base($"删除分类失败!") + { + + } + } +}