已完善实验管理权限:
校级管理员可查看全部实验项目与成绩单。 学院管理员仅可查看本学院开课,或由本学院教师承担/管理的实验课。 场次取消、参与学生查看也同步执行上述范围校验,避免通过场次 ID 越权。 增加覆盖:校级全量、学院自有课程、跨学院管理课程可见、无关学院课程不可见。
This commit is contained in:
1 parent
1e45ede5be
commit
5872c06042
3 files changed
+97
-9
No files matched your search
@@ -1141,8 +1141,13 @@ public sealed class ExperimentGradesController(
|
||||
var scope = currentUserDataScope.Current;
|
||||
if (scope.Scope == DataScope.All) return source;
|
||||
if (scope.Scope == DataScope.College)
|
||||
{
|
||||
if (!scope.CollegeId.HasValue) return source.Where(_ => false);
|
||||
var collegeId = scope.CollegeId.Value;
|
||||
return source.Where(x =>
|
||||
x.Course!.CollegeId == scope.RestrictedCollegeId);
|
||||
x.Course!.CollegeId == collegeId ||
|
||||
x.Teachers.Any(item => item.Teacher!.CollegeId == collegeId));
|
||||
}
|
||||
if (scope.IsInRole(SystemRoles.Teacher))
|
||||
return source.Where(x => x.Teachers.Any(item =>
|
||||
item.Teacher!.UserId == scope.UserId));
|
||||
|
||||
@@ -1058,6 +1058,10 @@ public sealed class ExperimentsController(
|
||||
.Include(x => x.ExperimentProject)
|
||||
.ThenInclude(x => x!.TeachingTask)
|
||||
.ThenInclude(x => x!.Course)
|
||||
.Include(x => x.ExperimentProject)
|
||||
.ThenInclude(x => x!.TeachingTask)
|
||||
.ThenInclude(x => x!.Teachers)
|
||||
.ThenInclude(x => x.Teacher)
|
||||
.Include(x => x.Instructors)
|
||||
.ThenInclude(x => x.Teacher)
|
||||
.FirstOrDefaultAsync(x => x.Id == id, cancellationToken);
|
||||
@@ -1124,6 +1128,12 @@ public sealed class ExperimentsController(
|
||||
{
|
||||
var session = await db.ExperimentSessions.AsNoTracking()
|
||||
.Include(x => x.ExperimentProject)
|
||||
.ThenInclude(x => x!.TeachingTask)
|
||||
.ThenInclude(x => x!.Course)
|
||||
.Include(x => x.ExperimentProject)
|
||||
.ThenInclude(x => x!.TeachingTask)
|
||||
.ThenInclude(x => x!.Teachers)
|
||||
.ThenInclude(x => x.Teacher)
|
||||
.Include(x => x.Instructors)
|
||||
.ThenInclude(x => x.Teacher)
|
||||
.FirstOrDefaultAsync(x => x.Id == id, cancellationToken);
|
||||
@@ -1541,8 +1551,13 @@ public sealed class ExperimentsController(
|
||||
var scope = currentUserDataScope.Current;
|
||||
if (scope.Scope == DataScope.All) return source;
|
||||
if (scope.Scope == DataScope.College)
|
||||
{
|
||||
if (!scope.CollegeId.HasValue) return source.Where(_ => false);
|
||||
var collegeId = scope.CollegeId.Value;
|
||||
return source.Where(x =>
|
||||
x.Course!.CollegeId == scope.RestrictedCollegeId);
|
||||
x.Course!.CollegeId == collegeId ||
|
||||
x.Teachers.Any(item => item.Teacher!.CollegeId == collegeId));
|
||||
}
|
||||
if (scope.IsInRole(SystemRoles.Teacher))
|
||||
return source.Where(x =>
|
||||
x.Teachers.Any(item =>
|
||||
@@ -1560,8 +1575,15 @@ public sealed class ExperimentsController(
|
||||
private bool CanManageSession(ExperimentSession session)
|
||||
{
|
||||
var scope = currentUserDataScope.Current;
|
||||
if (scope.Scope is DataScope.All or DataScope.College)
|
||||
return true;
|
||||
if (scope.Scope == DataScope.All) return true;
|
||||
if (scope.Scope == DataScope.College && scope.CollegeId.HasValue)
|
||||
{
|
||||
var collegeId = scope.CollegeId.Value;
|
||||
var task = session.ExperimentProject?.TeachingTask;
|
||||
return task?.Course?.CollegeId == collegeId ||
|
||||
task?.Teachers.Any(item =>
|
||||
item.Teacher?.CollegeId == collegeId) == true;
|
||||
}
|
||||
return scope.IsInRole(SystemRoles.Teacher) &&
|
||||
session.Instructors.Any(instructor =>
|
||||
instructor.Teacher?.UserId == scope.UserId);
|
||||
|
||||
Reference in new issue
Block a user