This commit is contained in:
2025-05-11 00:09:36 +08:00
parent ea926fe7d2
commit ef9227cc01
15 changed files with 243 additions and 19 deletions

View File

@@ -41,8 +41,23 @@
throw new ArticleNotExistsException(request.Id); throw new ArticleNotExistsException(request.Id);
} }
var identityUser = await _db.Users.FindAsync(_identity.Id);
if (identityUser == null)
{
throw new UserNotExistsException(_identity.Id);
}
if (!string.IsNullOrEmpty(request.Slug) && if (!identityUser.IsSystemUser())
{
if (article.UserId != identityUser.Id)
{
throw new AccessDeniedException();
}
}
if (!string.IsNullOrEmpty(request.Slug) &&
article.IsSlugDifferent(request.Slug) && article.IsSlugDifferent(request.Slug) &&
await _articleService.IsSlugInUse(request.Slug)) await _articleService.IsSlugInUse(request.Slug))
{ {

View File

@@ -34,6 +34,22 @@
{ {
throw new ArticleNotExistsException(request.Id); throw new ArticleNotExistsException(request.Id);
} }
var identityUser = await _db.Users.FindAsync(_identity.Id);
if (identityUser == null)
{
throw new UserNotExistsException(_identity.Id);
}
if (!identityUser.IsSystemUser())
{
if (article.UserId != identityUser.Id)
{
throw new AccessDeniedException();
}
}
article.UpdateDraft(request.Title, request.Content, request.Summary, request.Tags, request.Slug, request.CoverUrl, authorObject, categoryObject); article.UpdateDraft(request.Title, request.Content, request.Summary, request.Tags, request.Slug, request.CoverUrl, authorObject, categoryObject);
_db.Articles.Update(article); _db.Articles.Update(article);

View File

@@ -2,12 +2,38 @@
{ {
public record DeleteCategoryCommand(int Id) : IRequest<Unit>; public record DeleteCategoryCommand(int Id) : IRequest<Unit>;
public class DeleteCategoryCommandHandler(BlogDbContext db) : IRequestHandler<DeleteCategoryCommand, Unit> public class DeleteCategoryCommandHandler(
BlogDbContext db,
IIdentityContext identity) : IRequestHandler<DeleteCategoryCommand, Unit>
{ {
private readonly BlogDbContext _db = db; private readonly BlogDbContext _db = db;
private readonly IIdentityContext _identity = identity;
public async Task<Unit> Handle(DeleteCategoryCommand request, CancellationToken cancellationToken) public async Task<Unit> Handle(DeleteCategoryCommand request, CancellationToken cancellationToken)
{ {
var identityUser = await _db.Users.FindAsync(_identity.Id);
if (identityUser == null)
{
throw new UserNotExistsException(_identity.Id);
}
if (!identityUser.IsSystemUser())
{
throw new AccessDeniedException();
}
var hasArticlesInCategory = await _db.Articles.AnyAsync(x => x.CategoryId == request.Id, cancellationToken);
if (hasArticlesInCategory)
{
throw new DeleteCategoryException("分类下还有文章,无法删除!");
}
var categoryCount = await _db.Categories.CountAsync(cancellationToken);
if (categoryCount <= 1)
{
throw new DeleteCategoryException("至少要保留一个分类!");
}
var category = await _db.Categories.FindAsync(request.Id); var category = await _db.Categories.FindAsync(request.Id);
if (category != null) if (category != null)
{ {

View File

@@ -4,12 +4,26 @@
public record DeleteCommentCommandResponse(int Id); public record DeleteCommentCommandResponse(int Id);
public class DeleteCommentCommandHandler(BlogDbContext db) : IRequestHandler<DeleteCommentCommand, DeleteCommentCommandResponse> public class DeleteCommentCommandHandler(
BlogDbContext db,
IIdentityContext identity) : IRequestHandler<DeleteCommentCommand, DeleteCommentCommandResponse>
{ {
private readonly BlogDbContext _db = db; private readonly BlogDbContext _db = db;
private readonly IIdentityContext _identity = identity;
public async Task<DeleteCommentCommandResponse> Handle(DeleteCommentCommand request, CancellationToken cancellationToken) public async Task<DeleteCommentCommandResponse> Handle(DeleteCommentCommand request, CancellationToken cancellationToken)
{ {
var identityUser = await _db.Users.FindAsync(_identity.Id);
if (identityUser == null)
{
throw new UserNotExistsException(_identity.Id);
}
if (!identityUser.IsSystemUser())
{
throw new AccessDeniedException();
}
var comment = await _db.Comments.FindAsync(request.Id); var comment = await _db.Comments.FindAsync(request.Id);
if (comment != null) if (comment != null)
{ {

View File

@@ -1,4 +1,6 @@
namespace Yes.Application.Admins.Configurations using static Dapper.SqlMapper;
namespace Yes.Application.Admins.Configurations
{ {
public record UpdateConfigurationCommand( public record UpdateConfigurationCommand(
string Name, string Name,
@@ -19,14 +21,33 @@
public record UpdateConfigurationCommandResponse(int Id); public record UpdateConfigurationCommandResponse(int Id);
public class UpdateConfigurationCommandHandler(IOptionsMonitor<BlogSettings> options, IMapper mapper, IConfigurationService configurationService) : IRequestHandler<UpdateConfigurationCommand, Unit> public class UpdateConfigurationCommandHandler(
IOptionsMonitor<BlogSettings> options,
IMapper mapper,
IConfigurationService configurationService,
BlogDbContext db,
IIdentityContext identity) : IRequestHandler<UpdateConfigurationCommand, Unit>
{ {
private readonly BlogSettings _settings = options.CurrentValue; private readonly BlogSettings _settings = options.CurrentValue;
private readonly IMapper _mapper = mapper; private readonly IMapper _mapper = mapper;
private readonly IConfigurationService _configurationService = configurationService; private readonly IConfigurationService _configurationService = configurationService;
private readonly BlogDbContext _db = db;
private readonly IIdentityContext _identity = identity;
public async Task<Unit> Handle(UpdateConfigurationCommand request, CancellationToken cancellationToken) public async Task<Unit> Handle(UpdateConfigurationCommand request, CancellationToken cancellationToken)
{ {
var identityUser = await _db.Users.FindAsync(_identity.Id);
if (identityUser == null)
{
throw new UserNotExistsException(_identity.Id);
}
if (!identityUser.IsSystemUser())
{
throw new AccessDeniedException();
}
_mapper.Map(request, _settings); _mapper.Map(request, _settings);
await _configurationService.SaveConfiguration(_settings); await _configurationService.SaveConfiguration(_settings);

View File

@@ -37,6 +37,20 @@
throw new ArticleNotExistsException(request.Id); throw new ArticleNotExistsException(request.Id);
} }
var identityUser = await _db.Users.FindAsync(_identity.Id);
if (identityUser == null)
{
throw new UserNotExistsException(_identity.Id);
}
if (!identityUser.IsSystemUser())
{
if (page.UserId != identityUser.Id)
{
throw new AccessDeniedException();
}
}
if (!string.IsNullOrEmpty(request.Slug) && if (!string.IsNullOrEmpty(request.Slug) &&
request.Slug != page.Id.ToString() && request.Slug != page.Id.ToString() &&

View File

@@ -9,15 +9,31 @@
IOptionsMonitor<BlogSettings> options, IOptionsMonitor<BlogSettings> options,
IMapper mapper, IMapper mapper,
IThemeService themeService, IThemeService themeService,
IConfigurationService configurationService IConfigurationService configurationService,
) : IRequestHandler<UpdateThemeCommand, Unit> BlogDbContext db,
IIdentityContext identity
) : IRequestHandler<UpdateThemeCommand, Unit>
{ {
private readonly BlogSettings _settings = options.CurrentValue; private readonly BlogSettings _settings = options.CurrentValue;
private readonly IMapper _mapper = mapper; private readonly IMapper _mapper = mapper;
private readonly IThemeService _themeService = themeService; private readonly IThemeService _themeService = themeService;
private readonly IConfigurationService _configurationService = configurationService; private readonly IConfigurationService _configurationService = configurationService;
private readonly BlogDbContext _db = db;
private readonly IIdentityContext _identity = identity;
public async Task<Unit> Handle(UpdateThemeCommand request, CancellationToken cancellationToken) public async Task<Unit> Handle(UpdateThemeCommand request, CancellationToken cancellationToken)
{ {
var identityUser = await _db.Users.FindAsync(_identity.Id);
if (identityUser == null)
{
throw new UserNotExistsException(_identity.Id);
}
if (!identityUser.IsSystemUser())
{
throw new AccessDeniedException();
}
_themeService.CheckThemeExists(request.Theme); _themeService.CheckThemeExists(request.Theme);
_mapper.Map(request, _settings); _mapper.Map(request, _settings);

View File

@@ -9,13 +9,28 @@
public class UpdateThemeFileCommandHandler( public class UpdateThemeFileCommandHandler(
IThemeService themeService, IThemeService themeService,
IWebHostEnvironment env IWebHostEnvironment env,
BlogDbContext db,
IIdentityContext identity
) : IRequestHandler<UpdateThemeFileCommand, Unit> ) : IRequestHandler<UpdateThemeFileCommand, Unit>
{ {
private readonly IThemeService _themeService = themeService; private readonly IThemeService _themeService = themeService;
private readonly IWebHostEnvironment _env = env; private readonly IWebHostEnvironment _env = env;
private readonly BlogDbContext _db = db;
private readonly IIdentityContext _identity = identity;
public async Task<Unit> Handle(UpdateThemeFileCommand request, CancellationToken cancellationToken) public async Task<Unit> Handle(UpdateThemeFileCommand request, CancellationToken cancellationToken)
{ {
var identityUser = await _db.Users.FindAsync(_identity.Id);
if (identityUser == null)
{
throw new UserNotExistsException(_identity.Id);
}
if (!identityUser.IsSystemUser())
{
throw new AccessDeniedException();
}
var themeName = request.ThemeName; var themeName = request.ThemeName;
var fileName = request.FileName; var fileName = request.FileName;
var content = request.Content; var content = request.Content;

View File

@@ -1,18 +1,32 @@
 namespace Yes.Application.Admins.Themes
namespace Yes.Application.Admins.Themes
{ {
public record UploadThemeCommand(IFormFile File) : IRequest<UploadThemeCommandResponse>; public record UploadThemeCommand(IFormFile File) : IRequest<UploadThemeCommandResponse>;
public record UploadThemeCommandResponse(string DirName); public record UploadThemeCommandResponse(string DirName);
public class UploadThemeCommandHandler(IWebHostEnvironment env, public class UploadThemeCommandHandler(
IWebHostEnvironment env,
BlogDbContext db,
IIdentityContext identity,
IOptionsMonitor<BlogSettings> options) : IRequestHandler<UploadThemeCommand, UploadThemeCommandResponse> IOptionsMonitor<BlogSettings> options) : IRequestHandler<UploadThemeCommand, UploadThemeCommandResponse>
{ {
private readonly IWebHostEnvironment _env = env; private readonly IWebHostEnvironment _env = env;
private readonly BlogSettings _settings = options.CurrentValue; private readonly BlogSettings _settings = options.CurrentValue;
private readonly BlogDbContext _db = db;
private readonly IIdentityContext _identity = identity;
public async Task<UploadThemeCommandResponse> Handle(UploadThemeCommand request, CancellationToken cancellationToken) public async Task<UploadThemeCommandResponse> Handle(UploadThemeCommand request, CancellationToken cancellationToken)
{ {
var identityUser = await _db.Users.FindAsync(_identity.Id);
if (identityUser == null)
{
throw new UserNotExistsException(_identity.Id);
}
if (!identityUser.IsSystemUser())
{
throw new AccessDeniedException();
}
try try
{ {

View File

@@ -9,12 +9,25 @@
public record CreateUserCommandResponse(int Id); public record CreateUserCommandResponse(int Id);
public class CreateUserCommandHandler(BlogDbContext db) : IRequestHandler<CreateUserCommand, CreateUserCommandResponse> public class CreateUserCommandHandler(BlogDbContext db, IIdentityContext identity) : IRequestHandler<CreateUserCommand, CreateUserCommandResponse>
{ {
private readonly BlogDbContext _db = db; private readonly BlogDbContext _db = db;
private readonly IIdentityContext _identity = identity;
public async Task<CreateUserCommandResponse> Handle(CreateUserCommand request, CancellationToken cancellationToken) public async Task<CreateUserCommandResponse> Handle(CreateUserCommand request, CancellationToken cancellationToken)
{ {
var identityUser = await _db.Users.FindAsync(_identity.Id);
if (identityUser == null)
{
throw new UserNotExistsException(_identity.Id);
}
if (!identityUser.IsSystemUser())
{
throw new AccessDeniedException();
}
var user = UserEntity.Create(request.Name, request.Email, request.NickName, request.Password); var user = UserEntity.Create(request.Name, request.Email, request.NickName, request.Password);
await _db.Users.AddAsync(user); await _db.Users.AddAsync(user);
await _db.SaveChangesAsync(); await _db.SaveChangesAsync();

View File

@@ -2,12 +2,24 @@
{ {
public record DeleteUserCommand(int Id) : IRequest<Unit>; public record DeleteUserCommand(int Id) : IRequest<Unit>;
public class DeleteUserCommandHandler(BlogDbContext db) : IRequestHandler<DeleteUserCommand, Unit> public class DeleteUserCommandHandler(BlogDbContext db, IIdentityContext identity) : IRequestHandler<DeleteUserCommand, Unit>
{ {
private readonly BlogDbContext _db = db; private readonly BlogDbContext _db = db;
private readonly IIdentityContext _identity = identity;
public async Task<Unit> Handle(DeleteUserCommand request, CancellationToken cancellationToken) public async Task<Unit> Handle(DeleteUserCommand request, CancellationToken cancellationToken)
{ {
var identityUser = await _db.Users.FindAsync(_identity.Id);
if (identityUser == null)
{
throw new UserNotExistsException(_identity.Id);
}
if (!identityUser.IsSystemUser())
{
throw new AccessDeniedException();
}
var user = await _db.Users.FindAsync(request.Id); var user = await _db.Users.FindAsync(request.Id);
if (user == null) if (user == null)
{ {

View File

@@ -9,12 +9,23 @@
) : IRequest<Unit>; ) : IRequest<Unit>;
public class UpdateUserCommandHandler(BlogDbContext db) : IRequestHandler<UpdateUserCommand, Unit> public class UpdateUserCommandHandler(BlogDbContext db, IIdentityContext identity) : IRequestHandler<UpdateUserCommand, Unit>
{ {
private readonly BlogDbContext _db = db; private readonly BlogDbContext _db = db;
private readonly IIdentityContext _identity = identity;
public async Task<Unit> Handle(UpdateUserCommand request, CancellationToken cancellationToken) public async Task<Unit> Handle(UpdateUserCommand request, CancellationToken cancellationToken)
{ {
var identityUser = await _db.Users.FindAsync(_identity.Id);
if (identityUser == null)
{
throw new UserNotExistsException(_identity.Id);
}
if (!identityUser.IsSystemUser())
{
throw new AccessDeniedException();
}
var user = await _db.Users.FindAsync(request.Id); var user = await _db.Users.FindAsync(request.Id);
if (user == null) if (user == null)
{ {

View File

@@ -0,0 +1,22 @@
namespace Yes.Domain.Core.Exceptions
{
public class AccessDeniedException : BaseException
{
public AccessDeniedException()
: base("访问被拒绝:没有足够的权限执行此操作。")
{
}
public AccessDeniedException(string message)
: base(message)
{
}
public AccessDeniedException(string resourceName, string requiredPermission)
: this($"访问被拒绝:对资源 '{resourceName}' 需要权限 '{requiredPermission}'。")
{
}
}
}

View File

@@ -1,6 +1,6 @@
namespace Yes.Domain.Core.Exceptions namespace Yes.Domain.Core.Exceptions
{ {
public class CategoryNotExistsException : Exception public class CategoryNotExistsException : BaseException
{ {
public CategoryNotExistsException(int categoryId) : base($"分类id{categoryId}不存在!") public CategoryNotExistsException(int categoryId) : base($"分类id{categoryId}不存在!")
{ {

View File

@@ -0,0 +1,15 @@
namespace Yes.Domain.Core.Exceptions
{
public class DeleteCategoryException : BaseException
{
public DeleteCategoryException(string message) : base(message)
{
}
public DeleteCategoryException() : base($"删除分类失败!")
{
}
}
}