Files
lotteryLaravel/app/Http/Controllers/Api/V1/Admin/Draw/AdminDrawIndexController.php
kang 1dcd4716c5 refactor: 更新权限管理与请求验证逻辑
- 在多个控制器中将权限检查从 hasAdminPermission 更新为 hasPermissionCode,以增强权限管理的灵活性。
- 引入 AdminScopePolicy,优化基于代理节点的权限和数据过滤逻辑,确保管理员能够更精确地控制访问权限。
- 在请求验证中添加 agent_node_id 字段,确保 API 接口支持代理节点的相关操作。
- 更新 AdminUser 模型,新增 hasPermissionCode 方法,以支持更细粒度的权限检查。
- 优化审计日志记录逻辑,确保在处理请求时能够准确记录管理员的操作。
2026-06-03 10:07:38 +08:00

167 lines
6.1 KiB
PHP

<?php
namespace App\Http\Controllers\Api\V1\Admin\Draw;
use Carbon\Carbon;
use App\Models\AdminUser;
use App\Models\Draw;
use App\Models\TicketItem;
use App\Models\TicketOrder;
use Illuminate\Http\Request;
use App\Support\AdminApiList;
use App\Support\AdminScopeContext;
use App\Support\AdminScopePolicy;
use App\Services\LotterySettings;
use Illuminate\Http\JsonResponse;
use App\Http\Controllers\Controller;
use Illuminate\Contracts\Pagination\LengthAwarePaginator;
/**
* GET /api/v1/admin/draws — 期号列表。
*/
final class AdminDrawIndexController extends Controller
{
public function __invoke(Request $request): JsonResponse
{
$admin = $request->lotteryAdmin();
abort_if($admin === null, 401);
$p = AdminApiList::readPaging($request);
$drawNo = trim((string) $request->query('draw_no', ''));
$status = trim((string) $request->query('status', ''));
$scope = AdminScopePolicy::resolveContext($request, $admin);
$q = Draw::query()->orderByDesc('draw_time')->orderByDesc('id');
if ($drawNo !== '') {
$q->where('draw_no', 'like', '%'.$drawNo.'%');
}
if ($status !== '') {
$q->where('status', $status);
}
/** @var LengthAwarePaginator $paginator */
$paginator = $q->paginate($p['perPage'], ['*'], 'page', $p['page']);
$statsByDrawId = $this->aggregateListStats(
$paginator->getCollection()->pluck('id')->map(fn ($id) => (int) $id)->all(),
$scope,
);
return AdminApiList::jsonWith($paginator, fn (Draw $row) => $this->row($row, $statsByDrawId), [
'schedule' => [
'timezone' => LotterySettings::drawTimezone(),
'interval_minutes' => LotterySettings::drawIntervalMinutes(),
'betting_window_seconds' => LotterySettings::drawBettingWindowSeconds(),
'close_before_draw_seconds' => LotterySettings::drawCloseBeforeDrawSeconds(),
],
]);
}
/**
* @param list<int> $drawIds
* @return array<int, array{total_bet_minor: int, total_payout_minor: int, profit_loss_minor: int}>
*/
private function aggregateListStats(array $drawIds, AdminScopeContext $scope): array
{
if ($drawIds === []) {
return [];
}
$betQuery = TicketOrder::query()->whereIn('draw_id', $drawIds);
$this->scopeOrdersToVisiblePlayers($betQuery, $scope);
$betByDraw = $betQuery
->groupBy('draw_id')
->selectRaw('draw_id, COALESCE(SUM(total_actual_deduct), 0) AS total_bet')
->pluck('total_bet', 'draw_id');
$payoutQuery = TicketItem::query()->whereIn('draw_id', $drawIds);
$this->scopeTicketItemsToVisiblePlayers($payoutQuery, $scope);
$payoutRows = $payoutQuery
->groupBy('draw_id')
->selectRaw(
'draw_id, COALESCE(SUM(win_amount), 0) AS win, COALESCE(SUM(jackpot_win_amount), 0) AS jackpot',
)
->get()
->keyBy('draw_id');
$stats = [];
foreach ($drawIds as $drawId) {
$bet = (int) ($betByDraw[$drawId] ?? $betByDraw[(string) $drawId] ?? 0);
$payoutRow = $payoutRows->get($drawId) ?? $payoutRows->get((string) $drawId);
$payout = (int) ($payoutRow->win ?? 0) + (int) ($payoutRow->jackpot ?? 0);
$stats[$drawId] = [
'total_bet_minor' => $bet,
'total_payout_minor' => $payout,
'profit_loss_minor' => $bet - $payout,
];
}
return $stats;
}
/**
* @param \Illuminate\Database\Eloquent\Builder<TicketOrder> $query
*/
private function scopeOrdersToVisiblePlayers($query, AdminScopeContext $scope): void
{
if ($scope->isSuperAdmin() && $scope->effectiveRequestedAgentNodeId() === null) {
return;
}
$query->whereHas('player', function ($playerQuery) use ($scope): void {
AdminScopePolicy::applyPlayerFilters($playerQuery, $scope);
});
}
/**
* @param \Illuminate\Database\Eloquent\Builder<TicketItem> $query
*/
private function scopeTicketItemsToVisiblePlayers($query, AdminScopeContext $scope): void
{
if ($scope->isSuperAdmin() && $scope->effectiveRequestedAgentNodeId() === null) {
return;
}
$query->whereHas('player', function ($playerQuery) use ($scope): void {
AdminScopePolicy::applyPlayerFilters($playerQuery, $scope);
});
}
/**
* @param array<int, array{total_bet_minor: int, total_payout_minor: int, profit_loss_minor: int}> $statsByDrawId
* @return array<string, mixed>
*/
private function row(Draw $draw, array $statsByDrawId): array
{
$stats = $statsByDrawId[(int) $draw->id] ?? [
'total_bet_minor' => 0,
'total_payout_minor' => 0,
'profit_loss_minor' => 0,
];
return [
'id' => (int) $draw->id,
'draw_no' => $draw->draw_no,
'business_date' => $draw->business_date instanceof Carbon
? $draw->business_date->format('Y-m-d')
: (string) $draw->business_date,
'sequence_no' => (int) $draw->sequence_no,
'status' => $draw->status,
'start_time' => $draw->start_time?->toIso8601String(),
'close_time' => $draw->close_time?->toIso8601String(),
'draw_time' => $draw->draw_time?->toIso8601String(),
'cooling_end_time' => $draw->cooling_end_time?->toIso8601String(),
'result_source' => $draw->result_source,
'current_result_version' => (int) $draw->current_result_version,
'settle_version' => (int) $draw->settle_version,
'is_reopened' => (bool) $draw->is_reopened,
'total_bet_minor' => $stats['total_bet_minor'],
'total_payout_minor' => $stats['total_payout_minor'],
'profit_loss_minor' => $stats['profit_loss_minor'],
'updated_at' => $draw->updated_at?->toIso8601String(),
];
}
}