feat: 增强代理和玩家管理功能
- 在多个控制器中更新权限检查逻辑,确保管理员能够更灵活地管理代理和玩家。 - 在 AdminPlayerStoreController 中引入对玩家创建能力的验证,确保只有具备相应权限的管理员能够创建玩家。 - 更新请求验证逻辑,新增 credit_limit、rebate_rate 和 extra_rebate_rate 字段,以支持更细粒度的玩家管理。 - 在 AgentNodeProfileController 中添加对父代理能力授予的验证,确保子代理的权限在父代理范围内。 - 引入 AgentProfileFieldRules 以简化代理资料更新请求的规则定义,提升代码复用性。
This commit is contained in:
@@ -7,6 +7,7 @@ use App\Models\AdminUser;
|
||||
use App\Models\AgentNode;
|
||||
use App\Models\AgentProfile;
|
||||
use App\Support\AdminUserStatus;
|
||||
use App\Support\AgentPlatformRole;
|
||||
use Illuminate\Support\Facades\DB;
|
||||
use Illuminate\Validation\ValidationException;
|
||||
|
||||
@@ -16,25 +17,6 @@ final class AgentNodeService
|
||||
private readonly AgentProfileService $agentProfileService,
|
||||
) {}
|
||||
|
||||
/** @var list<string> */
|
||||
private const BASE_AGENT_ROLE_SLUGS = [
|
||||
'prd.agent.view',
|
||||
'prd.tickets.view',
|
||||
'prd.report.view',
|
||||
'prd.wallet_reconcile.view',
|
||||
'prd.wallet_reconcile.view_cs',
|
||||
];
|
||||
|
||||
/** @var list<string> */
|
||||
private const CHILD_AGENT_MANAGE_SLUGS = ['prd.agent.manage', 'prd.agent.profile.manage'];
|
||||
|
||||
/** @var list<string> */
|
||||
private const PLAYER_MANAGE_SLUGS = [
|
||||
'prd.users.manage',
|
||||
'prd.users.view_finance',
|
||||
'prd.users.view_cs',
|
||||
];
|
||||
|
||||
/**
|
||||
* @param array{
|
||||
* parent_id: int,
|
||||
@@ -120,19 +102,7 @@ final class AgentNodeService
|
||||
$node->path = (string) $parent->path.$node->id.'/';
|
||||
$node->save();
|
||||
|
||||
$role = AdminRole::query()->create([
|
||||
'slug' => 'agent_owner_'.$node->id,
|
||||
'code' => 'agent_owner_'.$node->id,
|
||||
'name' => '代理账号',
|
||||
'description' => '系统自动生成的一代理一账号默认角色',
|
||||
'status' => $status === 0 ? 0 : 1,
|
||||
'is_system' => false,
|
||||
'sort_order' => 0,
|
||||
'scope_type' => AdminRole::SCOPE_AGENT,
|
||||
'owner_agent_id' => $node->id,
|
||||
'delegated_from_role_id' => null,
|
||||
]);
|
||||
$role->syncLegacyPermissionSlugs($this->buildRoleSlugsForNewChild($payload, $actor));
|
||||
AgentPlatformRole::resolve();
|
||||
|
||||
$user = AdminUser::query()->create([
|
||||
'username' => $username,
|
||||
@@ -148,9 +118,9 @@ final class AgentNodeService
|
||||
'is_primary' => true,
|
||||
'granted_at' => now(),
|
||||
]);
|
||||
$user->syncAgentRoleIds((int) $node->id, [(int) $role->id]);
|
||||
AgentPlatformRole::assignPrimaryOperator($user, $node);
|
||||
|
||||
$profile = $this->agentProfileService->upsertForNode($node, [
|
||||
$this->agentProfileService->upsertForNode($node, [
|
||||
'total_share_rate' => (float) ($payload['total_share_rate'] ?? 0),
|
||||
'credit_limit' => (int) ($payload['credit_limit'] ?? 0),
|
||||
'rebate_limit' => (float) ($payload['rebate_limit'] ?? 0),
|
||||
@@ -161,8 +131,6 @@ final class AgentNodeService
|
||||
'can_create_player' => (bool) ($payload['can_create_player'] ?? true),
|
||||
], $parent);
|
||||
|
||||
$this->syncPrimaryOwnerRoleFromProfile($node, $profile);
|
||||
|
||||
return $node->fresh(['adminSite']);
|
||||
});
|
||||
}
|
||||
@@ -352,32 +320,7 @@ final class AgentNodeService
|
||||
}
|
||||
|
||||
return DB::transaction(function () use ($node, $username, $password, $email, $status): AdminUser {
|
||||
$role = AdminRole::query()
|
||||
->where('owner_agent_id', $node->id)
|
||||
->where('slug', 'agent_owner_'.$node->id)
|
||||
->first();
|
||||
|
||||
if ($role === null) {
|
||||
$role = AdminRole::query()->create([
|
||||
'slug' => 'agent_owner_'.$node->id,
|
||||
'code' => 'agent_owner_'.$node->id,
|
||||
'name' => '代理账号',
|
||||
'description' => '系统自动生成的一代理一账号默认角色',
|
||||
'status' => $status === 0 ? 0 : 1,
|
||||
'is_system' => false,
|
||||
'sort_order' => 0,
|
||||
'scope_type' => AdminRole::SCOPE_AGENT,
|
||||
'owner_agent_id' => $node->id,
|
||||
'delegated_from_role_id' => null,
|
||||
]);
|
||||
}
|
||||
|
||||
$profile = AgentProfile::query()->where('agent_node_id', $node->id)->first();
|
||||
$role->syncLegacyPermissionSlugs(
|
||||
$profile !== null
|
||||
? $this->roleSlugsFromProfile($profile)
|
||||
: $this->defaultOwnerRoleSlugs(),
|
||||
);
|
||||
AgentPlatformRole::resolve();
|
||||
|
||||
$user = AdminUser::query()->create([
|
||||
'username' => $username,
|
||||
@@ -393,93 +336,12 @@ final class AgentNodeService
|
||||
'is_primary' => true,
|
||||
'granted_at' => now(),
|
||||
]);
|
||||
$user->syncAgentRoleIds((int) $node->id, [(int) $role->id]);
|
||||
AgentPlatformRole::assignPrimaryOperator($user, $node);
|
||||
|
||||
return $user;
|
||||
});
|
||||
}
|
||||
|
||||
/**
|
||||
* @return list<string>
|
||||
*/
|
||||
private function defaultOwnerRoleSlugs(): array
|
||||
{
|
||||
return array_values(array_unique(array_merge(
|
||||
self::BASE_AGENT_ROLE_SLUGS,
|
||||
self::PLAYER_MANAGE_SLUGS,
|
||||
)));
|
||||
}
|
||||
|
||||
public function syncPrimaryOwnerRoleFromProfile(AgentNode $node, ?AgentProfile $profile = null): void
|
||||
{
|
||||
$profile ??= AgentProfile::query()->where('agent_node_id', $node->id)->first();
|
||||
if ($profile === null) {
|
||||
return;
|
||||
}
|
||||
|
||||
$role = AdminRole::query()
|
||||
->where('owner_agent_id', $node->id)
|
||||
->where('slug', 'agent_owner_'.$node->id)
|
||||
->first();
|
||||
|
||||
if ($role === null) {
|
||||
return;
|
||||
}
|
||||
|
||||
$role->syncLegacyPermissionSlugs($this->roleSlugsFromProfile($profile));
|
||||
}
|
||||
|
||||
/**
|
||||
* @param array<string, mixed> $payload
|
||||
* @return list<string>
|
||||
*/
|
||||
private function buildRoleSlugsForNewChild(array $payload, AdminUser $actor): array
|
||||
{
|
||||
$slugs = self::BASE_AGENT_ROLE_SLUGS;
|
||||
if ((bool) ($payload['can_create_child_agent'] ?? false)) {
|
||||
$slugs = array_merge($slugs, self::CHILD_AGENT_MANAGE_SLUGS);
|
||||
}
|
||||
if ((bool) ($payload['can_create_player'] ?? true)) {
|
||||
$slugs = array_merge($slugs, self::PLAYER_MANAGE_SLUGS);
|
||||
}
|
||||
|
||||
return $this->filterSlugsByActor($actor, $slugs);
|
||||
}
|
||||
|
||||
/**
|
||||
* @return list<string>
|
||||
*/
|
||||
private function roleSlugsFromProfile(AgentProfile $profile): array
|
||||
{
|
||||
$slugs = self::BASE_AGENT_ROLE_SLUGS;
|
||||
if ($profile->can_create_child_agent) {
|
||||
$slugs = array_merge($slugs, self::CHILD_AGENT_MANAGE_SLUGS);
|
||||
}
|
||||
if ($profile->can_create_player) {
|
||||
$slugs = array_merge($slugs, self::PLAYER_MANAGE_SLUGS);
|
||||
}
|
||||
|
||||
return array_values(array_unique($slugs));
|
||||
}
|
||||
|
||||
/**
|
||||
* @param list<string> $slugs
|
||||
* @return list<string>
|
||||
*/
|
||||
private function filterSlugsByActor(AdminUser $actor, array $slugs): array
|
||||
{
|
||||
if ($actor->isSuperAdmin()) {
|
||||
return array_values(array_unique($slugs));
|
||||
}
|
||||
|
||||
$mine = array_fill_keys($actor->adminPermissionSlugs(), true);
|
||||
|
||||
return array_values(array_filter(
|
||||
$slugs,
|
||||
static fn (string $slug): bool => isset($mine[$slug]),
|
||||
));
|
||||
}
|
||||
|
||||
private function resolveCodeForCreate(AgentNode $parent, mixed $rawCode, string $username): string
|
||||
{
|
||||
$preferred = trim((string) $rawCode);
|
||||
|
||||
Reference in New Issue
Block a user