修复: 判断工作项是否在组织内以及是否有组织的权限

This commit is contained in:
yystopf 2024-10-25 11:49:36 +08:00
parent cf519788d1
commit 3958944bf1
2 changed files with 21 additions and 2 deletions

View File

@ -7,6 +7,24 @@ class ChangeIssueStatusByMessageJob < ApplicationJob
# Implement, Implements, Implemented, Implementing, implement, implements, implemented, implementing # Implement, Implements, Implemented, Implementing, implement, implements, implemented, implementing
# 以上关键词后接 issue_id 例如Closes #234 Closes #123, #245, #992 # 以上关键词后接 issue_id 例如Closes #234 Closes #123, #245, #992
def get_pm_issue_data(user, org, pm_project_id, issue_id)
url = URI("#{EduSetting.get("pms_server_url")}/api/pms/#{org.login}/pmsProjectIssues/#{issue_id}?pmProjectId=#{pm_project_id}")
https = Net::HTTP.new(url.host, url.port)
https.use_ssl = true
request = Net::HTTP::Get.new(url)
request["Cookie"] = "autologin_trustie=#{Token.get_or_create_permanent_login_token(user, 'autologin')&.value}"
response = https.request(request)
puts response.read_body
return JSON.parse(response.read_body)['code'].to_i == 200
rescue
return false
end
def perform(commitsha, project, user, tag_issue_id_content, status_id=1) def perform(commitsha, project, user, tag_issue_id_content, status_id=1)
Rails.logger.info "需要操作的issue_id内容为 #{tag_issue_id_content}" Rails.logger.info "需要操作的issue_id内容为 #{tag_issue_id_content}"
tag_issue_id_content = tag_issue_id_content.gsub(/\s+/, '') tag_issue_id_content = tag_issue_id_content.gsub(/\s+/, '')
@ -15,7 +33,8 @@ class ChangeIssueStatusByMessageJob < ApplicationJob
issue = project.issues.issue_issue.where(project_issues_index: issue_id).where.not(id: issue_id).take || Issue.issue_issue.find_by_id(issue_id) issue = project.issues.issue_issue.where(project_issues_index: issue_id).where.not(id: issue_id).take || Issue.issue_issue.find_by_id(issue_id)
next unless issue.present? # issue不存在 跳过 next unless issue.present? # issue不存在 跳过
next if issue.project.present? && !user.admin? && !issue.project.member?(user) # issue归属项目用户没有修改issue的权限跳过 next if issue.project.present? && !user.admin? && !issue.project.member?(user) # issue归属项目用户没有修改issue的权限跳过
next if issue.pm_project_id.present? && project.owner.is_a?(Organization) && !project.owner.is_member?(user.id) # issue是组织下工作项不具备组织的访问权限跳过 next if issue.pm_project_id.present? && !user.admin? && project.owner.is_a?(Organization) && get_pm_issue_data(user, project.owner, issue.pm_project_id, issue.id) # issue是组织下工作项不具备组织的访问权限跳过
issue_project = issue.project || Project.new(id: 0, user_id: 0, name: 'pm_mm', identifier: 'pm_mm', is_public:true) issue_project = issue.project || Project.new(id: 0, user_id: 0, name: 'pm_mm', identifier: 'pm_mm', is_public:true)
if issue.pm_project_id.present? if issue.pm_project_id.present?
Api::Pm::Issues::UpdateService.call(issue_project, issue, {status_id: status_id}, user, "Project##{project.id}@#{commitsha}") Api::Pm::Issues::UpdateService.call(issue_project, issue, {status_id: status_id}, user, "Project##{project.id}@#{commitsha}")

View File

@ -88,7 +88,7 @@ class Journal < ApplicationRecord
if self.operate_by.starts_with?("Project#") if self.operate_by.starts_with?("Project#")
project_id, commit_sha = self.operate_by.scan(/#(\d+).*?@(\w+)/)[0] project_id, commit_sha = self.operate_by.scan(/#(\d+).*?@(\w+)/)[0]
project =Project.find_by_id(project_id) project =Project.find_by_id(project_id)
return "通过<a href=\"#{Rails.application.config_for(:configuration)['platform_url']}/#{project&.owner&.login}/#{project&.identifier}/commits/#{commit_sha}\">#{project&.owner&.real_name}/#{project&.name} 提交 #{commit_sha[0...10]}</a>" return "通过 #{project&.owner&.real_name}/#{project&.name} 提交 <a href=\"#{Rails.application.config_for(:configuration)['platform_url']}/#{project&.owner&.login}/#{project&.identifier}/commits/#{commit_sha}\">#{commit_sha[0...10]}</a>"
end end
rescue rescue
return '' return ''