新增全局协作台账并统一工作台管理界面
新增与项目平级的协作台账,提供空白模板、独立账号授权和在线编辑。 复用共享库的访问权限与历史版本界面,拆分信息维护入口并统一工作台卡片样式。 补充在线文档字体构建支持、数据库表结构升级和回归测试。 不包含本地台账内容、账号授权记录或历史文件迁移数据。
This commit is contained in:
@@ -0,0 +1,41 @@
|
||||
"""Account-level ledger permissions, independent of study membership."""
|
||||
from sqlalchemy import select
|
||||
from fastapi import HTTPException
|
||||
|
||||
from app.core.deps import is_system_admin
|
||||
from app.models.collaboration import CollaborationMember
|
||||
|
||||
|
||||
def is_ledger(item) -> bool:
|
||||
return getattr(item, "scope", "PROJECT") == "LEDGER"
|
||||
|
||||
|
||||
async def role_for(db, item, user) -> str | None:
|
||||
if not user or not user.is_active:
|
||||
return None
|
||||
if is_system_admin(user) or item.owner_id == user.id:
|
||||
return "MANAGER"
|
||||
return await db.scalar(select(CollaborationMember.role).where(
|
||||
CollaborationMember.file_id == item.id, CollaborationMember.user_id == user.id,
|
||||
))
|
||||
|
||||
|
||||
async def can_edit(db, item, user) -> bool:
|
||||
return item.status == "ACTIVE" and await role_for(db, item, user) in {"EDITOR", "MANAGER"}
|
||||
|
||||
|
||||
async def can_manage(db, item, user) -> bool:
|
||||
return await role_for(db, item, user) == "MANAGER"
|
||||
|
||||
|
||||
async def can_export(db, item, user) -> bool:
|
||||
role = await role_for(db, item, user)
|
||||
return role == "MANAGER" or (role in {"EDITOR", "VIEWER"} and item.allow_export)
|
||||
|
||||
|
||||
async def require_access(db, item, user, *, manage=False):
|
||||
role = await role_for(db, item, user)
|
||||
if role not in {"VIEWER", "EDITOR", "MANAGER"}:
|
||||
raise HTTPException(404, "台账不存在或未获授权")
|
||||
if manage and role != "MANAGER":
|
||||
raise HTTPException(403, "仅台账管理人员可以执行此操作")
|
||||
Reference in New Issue
Block a user