import uuid from fastapi import APIRouter, Depends, HTTPException, status from sqlalchemy.ext.asyncio import AsyncSession from app.core.deps import get_operator_role_label, get_current_user, get_db_session, require_study_not_locked, require_api_permission from app.crud import audit as audit_crud from app.crud import site as site_crud from app.crud import subject as subject_crud from app.crud import subject_history as history_crud from app.crud import study as study_crud from app.schemas.subject_history import SubjectHistoryCreate, SubjectHistoryRead, SubjectHistoryUpdate router = APIRouter() async def _ensure_study_exists(db: AsyncSession, study_id: uuid.UUID): study = await study_crud.get(db, study_id) if not study: raise HTTPException(status_code=status.HTTP_404_NOT_FOUND, detail="项目不存在") return study async def _ensure_subject_active(db: AsyncSession, subject) -> None: if not subject or not subject.site_id: return site = await site_crud.get_site(db, subject.site_id) if not site or not site.is_active: raise HTTPException(status_code=status.HTTP_403_FORBIDDEN, detail="中心已停用") @router.post( "/histories", response_model=SubjectHistoryRead, status_code=status.HTTP_201_CREATED, dependencies=[Depends(require_api_permission("subject_histories:create"))], ) async def create_history( study_id: uuid.UUID, subject_id: uuid.UUID, history_in: SubjectHistoryCreate, db: AsyncSession = Depends(get_db_session), current_user=Depends(get_current_user), ) -> SubjectHistoryRead: await _ensure_study_exists(db, study_id) subject = await subject_crud.get_subject(db, subject_id) if not subject or subject.study_id != study_id: raise HTTPException(status_code=status.HTTP_404_NOT_FOUND, detail="参与者不存在") await _ensure_subject_active(db, subject) if history_in.subject_id != subject_id: raise HTTPException(status_code=status.HTTP_400_BAD_REQUEST, detail="参与者不匹配") history = await history_crud.create_history(db, study_id, history_in, created_by=current_user.id) await audit_crud.log_action( db, study_id=study_id, entity_type="subject_history", entity_id=history.id, action="CREATE_SUBJECT_HISTORY", detail="病史记录已创建", operator_id=current_user.id, operator_role=await get_operator_role_label(db, study_id, current_user), ) return SubjectHistoryRead.model_validate(history) @router.get( "/histories", response_model=list[SubjectHistoryRead], dependencies=[Depends(require_api_permission("subject_histories:list"))], ) async def list_histories( study_id: uuid.UUID, subject_id: uuid.UUID, skip: int = 0, limit: int = 200, db: AsyncSession = Depends(get_db_session), ) -> list[SubjectHistoryRead]: await _ensure_study_exists(db, study_id) subject = await subject_crud.get_subject(db, subject_id) if not subject or subject.study_id != study_id: raise HTTPException(status_code=status.HTTP_404_NOT_FOUND, detail="参与者不存在") items = await history_crud.list_histories(db, study_id, subject_id, skip=skip, limit=limit) return [SubjectHistoryRead.model_validate(item) for item in items] @router.get( "/histories/{history_id}", response_model=SubjectHistoryRead, dependencies=[Depends(require_api_permission("subject_histories:read"))], ) async def get_history( study_id: uuid.UUID, subject_id: uuid.UUID, history_id: uuid.UUID, db: AsyncSession = Depends(get_db_session), ) -> SubjectHistoryRead: await _ensure_study_exists(db, study_id) subject = await subject_crud.get_subject(db, subject_id) if not subject or subject.study_id != study_id: raise HTTPException(status_code=status.HTTP_404_NOT_FOUND, detail="参与者不存在") history = await history_crud.get_history(db, history_id) if not history or history.study_id != study_id or history.subject_id != subject_id: raise HTTPException(status_code=status.HTTP_404_NOT_FOUND, detail="病史记录不存在") return SubjectHistoryRead.model_validate(history) @router.patch( "/histories/{history_id}", response_model=SubjectHistoryRead, dependencies=[Depends(require_api_permission("subject_histories:update"))], ) async def update_history( study_id: uuid.UUID, subject_id: uuid.UUID, history_id: uuid.UUID, history_in: SubjectHistoryUpdate, db: AsyncSession = Depends(get_db_session), current_user=Depends(get_current_user), ) -> SubjectHistoryRead: await _ensure_study_exists(db, study_id) subject = await subject_crud.get_subject(db, subject_id) if not subject or subject.study_id != study_id: raise HTTPException(status_code=status.HTTP_404_NOT_FOUND, detail="参与者不存在") history = await history_crud.get_history(db, history_id) if not history or history.study_id != study_id or history.subject_id != subject_id: raise HTTPException(status_code=status.HTTP_404_NOT_FOUND, detail="病史记录不存在") history = await history_crud.update_history(db, history, history_in) await audit_crud.log_action( db, study_id=study_id, entity_type="subject_history", entity_id=history_id, action="UPDATE_SUBJECT_HISTORY", detail="病史记录已更新", operator_id=current_user.id, operator_role=await get_operator_role_label(db, study_id, current_user), ) return SubjectHistoryRead.model_validate(history) @router.delete( "/histories/{history_id}", status_code=status.HTTP_204_NO_CONTENT, dependencies=[Depends(require_api_permission("subject_histories:delete"))], ) async def delete_history( study_id: uuid.UUID, subject_id: uuid.UUID, history_id: uuid.UUID, db: AsyncSession = Depends(get_db_session), current_user=Depends(get_current_user), ) -> None: await _ensure_study_exists(db, study_id) subject = await subject_crud.get_subject(db, subject_id) if not subject or subject.study_id != study_id: raise HTTPException(status_code=status.HTTP_404_NOT_FOUND, detail="参与者不存在") history = await history_crud.get_history(db, history_id) if not history or history.study_id != study_id or history.subject_id != subject_id: raise HTTPException(status_code=status.HTTP_404_NOT_FOUND, detail="病史记录不存在") await history_crud.delete_history(db, history) await audit_crud.log_action( db, study_id=study_id, entity_type="subject_history", entity_id=history_id, action="DELETE_SUBJECT_HISTORY", detail="病史记录已删除", operator_id=current_user.id, operator_role=await get_operator_role_label(db, study_id, current_user), )