导航菜单

  • 0.api
  • 0.Async
  • 0.module
  • 1.ES2015
  • 2.Promise
  • 3.Node
  • 4.NodeInstall
  • 5.REPL
  • 6.NodeCore
  • 7.module&NPM
  • 8.Encoding
  • 9.Buffer
  • 10.fs
  • 11.Stream-1
  • 11.Stream-2
  • 11.Stream-3
  • 11.Stream-4
  • 12-Network-2
  • 12.NetWork-3
  • 12.Network-1
  • 13.tcp
  • 14.http-1
  • 14.http-2
  • 15.compress
  • 16.crypto
  • 17.process
  • 18.yargs
  • 19.cache
  • 20.action
  • 21.https
  • 22.cookie
  • 23.session
  • 24.express-1
  • 24.express-2
  • 24.express-3
  • 24.express-4
  • 25.koa-1
  • 26.webpack-1-basic
  • 26.webpack-2-optimize
  • 26.webpack-3-file
  • 26.webpack-4.tapable
  • 26.webpack-5-AST
  • 26.webpack-6-sources
  • 26.webpack-7-loader
  • 26.webpack-8-plugin
  • 26.webpack-9-hand
  • 26.webpack-10-prepare
  • 28.redux
  • 28.redux-jwt-back
  • 28.redux-jwt-front
  • 29.mongodb-1
  • 29.mongodb-2
  • 29.mongodb-3
  • 29.mongodb-4
  • 29.mongodb-5
  • 29.mongodb-6
  • 30.cms-1-mysql
  • 30.cms-2-mysql
  • 30.cms-3-mysql
  • 30.cms-4-nunjucks
  • 30.cms-5-mock
  • 30.cms-6-egg
  • 30.cms-7-api
  • 30.cms-8-roadhog
  • 30.cms-9-yaml
  • 30.cms-10-umi
  • 30.cms-12-dva
  • 30.cms-13-dva-ant
  • 30.cms-14-front
  • 30.cms-15-deploy
  • 31.dva
  • 31.cms-13-dva-antdesign
  • 33.redis
  • 34.unittest
  • 35.jwt
  • 36.websocket-1
  • 36.websocket-2
  • 38.chat-api-1
  • 38.chat-api-2
  • 38.chat-3
  • 38.chat-api-3
  • 38.chat
  • 38.chat2
  • 38.chat2
  • 39.crawl-0
  • 39.crawl-1
  • 39.crawl-2
  • 40.deploy
  • 41.safe
  • 42.test
  • 43.nginx
  • 44.enzyme
  • 45.docker
  • 46.elastic
  • 47.oauth
  • 48.wxpay
  • index
  • 52.UML
  • 53.design
  • index
  • 54.linux
  • 57.ts
  • 56.react-ssr
  • 58.ts_react
  • 59.ketang
  • 59.ketang2
  • 61.1.devops-linux
  • 61.2.devops-vi
  • 61.3.devops-user
  • 61.4.devops-auth
  • 61.5.devops-shell
  • 61.6.devops-install
  • 61.7.devops-system
  • 61.8.devops-service
  • 61.9.devops-network
  • 61.10.devops-nginx
  • 61.11.devops-docker
  • 61.12.devops-jekins
  • 61.13.devops-groovy
  • 61.14.devops-php
  • 61.15.devops-java
  • 61.16.devops-node
  • 61.17.devops-k8s
  • 62.1.react-basic
  • 62.2.react-state
  • 62.3.react-high
  • 62.4.react-optimize
  • 62.5.react-hooks
  • 62.6.react-immutable
  • 62.7.react-mobx
  • 62.8.react-source
  • 63.1.redux
  • 63.2.redux-middleware
  • 63.3.redux-hooks
  • 63.4.redux-saga
  • 63.5.redux-saga-hand
  • 64.1.router
  • 64.2.router-connected
  • 65.1.typescript
  • 65.2.typescript
  • 65.3.typescript
  • 65.4.antd
  • 65.4.definition
  • 66-1.vue-base
  • 66-2.vue-component
  • 66-3.vue-cli3.0
  • 66-4.$message组件
  • 66-5.Form组件
  • 66-6.tree
  • 66-7.vue-router-apply
  • 66-8.axios-apply
  • 66-9.vuex-apply
  • 66-10.jwt-vue
  • 66-11.vue-ssr
  • 66-12.nuxt-apply
  • 66-13.pwa
  • 66-14.vue单元测试
  • 66-15.权限校验
  • 67-1-network
  • 68-2-wireshark
  • 7.npm2
  • 69-hooks
  • 70-deploy
  • 71-hmr
  • 72.deploy
  • 73.import
  • 74.mobile
  • 75.webpack-1.文件分析
  • 75.webpack-2.loader
  • 75.webpack-3.源码流程
  • 75.webpack-4.tapable
  • 75.webpack-5.prepare
  • 75.webpack-6.resolve
  • 75.webpack-7.loader
  • 75.webpack-8.module
  • 75.webpack-9.chunk
  • 75.webpack-10.asset
  • 75.webpack-11.实现
  • 76.react_optimize
  • 77.ts_ketang_back
  • 77.ts_ketang_front
  • 78.vue-domdiff
  • 79.grammar
  • 80.tree
  • 81.axios
  • 82.1.react
  • 82.2.react-high
  • 82.3.react-router
  • 82.4.redux
  • 82.5.redux_middleware
  • 82.6.connected
  • 82.7.saga
  • 82.8.dva
  • 82.8.dva-source
  • 82.9.roadhog
  • 82.10.umi
  • 82.11.antdesign
  • 82.12.ketang-front
  • 82.12.ketang-back
  • 83.upload
  • 84.graphql
  • 85.antpro
  • 86.1.uml
  • 86.2.design
  • 87.postcss
  • 88.react16-1
  • 89.nextjs
  • 90.react-test
  • 91.react-ts
  • 92.rbac
  • 93.tsnode
  • 94.1.JavaScript
  • 94.2.JavaScript
  • 94.3.MODULE
  • 94.4.EventLoop
  • 94.5.文件上传
  • 94.6.https
  • 94.7. nginx
  • 95.1. react
  • 95.2.react
  • 96.1.react16
  • 96.2.fiber
  • 96.3.fiber
  • 97.serverless
  • 98.websocket
  • 100.1.react-basic
  • 101.1.monitor
  • 101.2.monitor
  • 102.java
  • 103.1.webpack-usage
  • 103.2.webpack-bundle
  • 103.3.webpack-ast
  • 103.4.webpack-flow
  • 103.5.webpack-loader
  • 103.6.webpack-tapable
  • 103.7.webpack-plugin
  • 103.8.webpack-optimize1
  • 103.9.webpack-optimize2
  • 103.10.webpack-hand
  • 103.11.webpack-hmr
  • 103.11.webpack5
  • 103.13.splitChunks
  • 103.14.webpack-sourcemap
  • 103.15.webpack-compiler1
  • 103.15.webpack-compiler2
  • 103.16.rollup.1
  • 103.16.rollup.2
  • 103.16.rollup.3
  • 103.16.vite.basic
  • 103.16.vite.source
  • 103.16.vite.plugin
  • 103.16.vite.1
  • 103.16.vite.2
  • 103.17.polyfill
  • 104.1.binary
  • 104.2.binary
  • 105.skeleton
  • 106.1.react
  • 106.2.react_hooks
  • 106.3.react_router
  • 106.4.redux
  • 106.5.redux_middleware
  • 106.6.connected-react-router
  • 106.6.redux-first-history
  • 106.7.redux-saga
  • 106.8.dva
  • 106.9.umi
  • 106.10.ketang
  • 106.11.antdesign
  • 106.12.antpro
  • 106.13.router-6
  • 106.14.ssr
  • 106.15.nextjs
  • 106.16.1.cms
  • 106.16.2.cms
  • 106.16.3.cms
  • 106.16.4.cms
  • 106.16.mobx
  • 106.17.fomily
  • 107.fiber
  • 108.http
  • 109.1.webpack_usage
  • 109.2.webpack_source
  • 109.3.dll
  • 110.nest.js
  • 111.xstate
  • 112.Form
  • 113.redux-saga
  • 114.react+typescript
  • 115.immer
  • 116.pro5
  • 117.css-loader
  • 118.1.umi-core
  • 119.2.module-federation
  • 119.1.module-federation
  • 120.create-react-app
  • 121.react-scripts
  • 122.react-optimize
  • 123.jsx-runtime
  • 124.next.js
  • 125.1.linux
  • 125.2.linux-vi
  • 125.3.linux-user
  • 125.4.linux-auth
  • 125.5.linux-shell
  • 125.6.linux-install
  • 125.7.linux-system
  • 125.8.linux-service
  • 125.9.linux-network
  • 125.10.nginx
  • 125.11.docker
  • 125.12.ci
  • 125.13.k8s
  • 125.14.k8s
  • 125.15.k8s
  • 125.16.k8s
  • 126.11.react-1
  • 126.12.react-2
  • 126.12.react-3
  • 126.12.react-4
  • 126.12.react-5
  • 126.12.react-6
  • 126.12.react-7
  • 126.12.react-8
  • 127.frontend
  • 128.rollup
  • 129.px2rem-loader
  • 130.health
  • 131.hooks
  • 132.keepalive
  • 133.vue-cli
  • 134.react18
  • 134.2.react18
  • 134.3.react18
  • 135.function
  • 136.toolkit
  • 137.lerna
  • 138.create-vite
  • 139.cli
  • 140.antd
  • 141.react-dnd
  • 142.1.link
  • 143.1.gulp
  • 143.2.stream
  • 143.3.gulp
  • 144.1.closure
  • 144.2.v8
  • 144.3.gc
  • 145.react-router-v6
  • 146.browser
  • 147.lighthouse
  • 148.1.basic
  • 148.2.basic
  • 148.3.basic
  • 148.4.basic
  • 148.5.basic
  • 149.1.vite
  • 149.2.vite
  • 149.3.vite
  • 149.4.vite
  • 150.react-window
  • 151.react-query
  • 152.useRequest
  • 153.transition
  • 154.emotion
  • 155.1.formily
  • 155.2.formily
  • 155.3.formily
  • 155.3.1.mobx.usage
  • 155.3.2.mobx.source
  • 156.vue-loader
  • 103.11.mf
  • 157.1.react18
  • 158.umi4
  • 159.rxjs
  • 159.rxjs2
  • 160.bff
  • 161.zustand
  • 162.vscode
  • 163.emp
  • 164.cors
  • 1.RBAC
    • 1.1 示意图
    • 1.2 表设计
    • 1.2.1 用户表(user)
    • 1.2.2 角色表(role)
    • 1.2.3 权限表(permission)
    • 1.2.4 角色用户表(role_user)
    • 1.2.5 角色权限(role_permission)
    • 1.2.6 数据库脚本
  • 2. 后端
    • 2.1.初始化项目
    • 2.2.支持MYSQL
      • 2.2.1 安装
      • 2.2.2 开启插件
      • 2.2.3 配置数据源
      • 2.2.4 配置声明文件
      • 2.2.4 使用mysql
    • 2.3.Passport
      • 2.3.1 安装
      • 2.3.2 config\plugin.ts
      • 2.3.3 typings\index.d.ts
      • 2.3.4 app.ts
      • 2.3.5 app\controller\user.ts
      • 2.3.6 middleware\auth.ts
      • 2.3.7 app\router.ts
      • 2.3.8 config\config.default.ts
      • 2.3.9 测试
  • 3. 前端
    • 3.1. 启动项目
    • 3.2. 设置代理
      • 3.2.1 config\config.ts
    • 3.3. 前端项目
      • 3.3.1 config\config.ts
      • 3.3.2 User\index.tsx

1.RBAC #

  • 基于角色的权限访问控制(Role-Based Access Control)
  • RBAC(Role-Based Access Control,基于角色的访问控制),就是用户通过角色与权限进行关联
  • 一个用户拥有若干角色,每一个角色拥有若干权限。这样,就构造成用户-角色-权限的授权模型
  • 在这种模型中,用户与角色之间,角色与权限之间一般是多对多的关系
  • 在RBAC中最重要的概念包括:用户(User),角色(Role),权限(Permission)

1.1 示意图 #

rbacimage

1.2 表设计 #

1.2.1 用户表(user) #

字段 字段名 类型 默认
id ID int(11)
userName 用户名 varchar(255)
password 密码 varchar(255)
CREATE TABLE `user`  (
  `id` int(11) NOT NULL AUTO_INCREMENT,
  `userName` varchar(255),
  `password` varchar(255),
  PRIMARY KEY (`id`) 
)

INSERT INTO `user` VALUES (1, 'isadmin', '123456');
INSERT INTO `user` VALUES (2, 'isuser', '123456');

1.2.2 角色表(role) #

字段 字段名 类型 默认
id ID int(11)
name 名称 varchar(255)
desc 描述 varchar(255)
CREATE TABLE `role`  (
  `id` int(11) NOT NULL AUTO_INCREMENT,
  `name` varchar(255) ,
  `desc` varchar(255) ,
  PRIMARY KEY (`id`) 
) E

INSERT INTO `role` VALUES (1, 'admin', '管理员');
INSERT INTO `role` VALUES (2, 'user', '普通用户');

1.2.3 权限表(permission) #

字段 字段名 类型 默认
id ID int(11)
name 名称 varchar(255)
parent_id 父ID int(11)
icon 图标 varchar(255)
key 路径 varchar(255)
type 类型 varchar(32)
CREATE TABLE `permission`  (
  `id` int(11) NOT NULL AUTO_INCREMENT,
  `name` varchar(255) ,
  `parent_id` int(11) NULL DEFAULT NULL,
  `icon` varchar(255) ,
  `key` varchar(255) ,
  `type` varchar(255) ,
  PRIMARY KEY (`id`) 
);

INSERT INTO `permission` VALUES (1, '授权平台', 0, 'desktop', '/api', 'menu');
INSERT INTO `permission` VALUES (2, '角色管理', 1, 'team', '/api/role', 'menu');
INSERT INTO `permission` VALUES (3, '用户管理', 1, 'user', '/api/user', 'menu');
INSERT INTO `permission` VALUES (4, '权限管理', 1, 'idcard', '/api/resource', 'menu');
INSERT INTO `permission` VALUES (5, '添加用户', 3, 'team', '/api/user/add', 'button');
INSERT INTO `permission` VALUES (6, '删除用户', 3, 'team', '/api/user/delete', 'button');

1.2.4 角色用户表(role_user) #

字段 字段名 类型
role_id 角色ID int(11)
user_id 用户ID int(11)
DROP TABLE IF EXISTS `role_user`;
CREATE TABLE `role_user`  (
  `role_id` int(11) NOT NULL,
  `user_id` int(11) NOT NULL,
  PRIMARY KEY (`user_id`, `role_id`) 
) 

INSERT INTO `role_user` VALUES (1, 1);
INSERT INTO `role_user` VALUES (2, 2);

1.2.5 角色权限(role_permission) #

字段 字段名 类型
role_id 角色ID int(11)
permission_id 资源ID int(11)
CREATE TABLE `role_permission`  (
  `role_id` int(11) NOT NULL,
  `permission_id` int(255) NOT NULL,
  PRIMARY KEY (`role_id`, `permission_id`) 
) 

INSERT INTO `role_permission` VALUES (1, 1);
INSERT INTO `role_permission` VALUES (1, 2);
INSERT INTO `role_permission` VALUES (1, 3);
INSERT INTO `role_permission` VALUES (1, 4);
INSERT INTO `role_permission` VALUES (1, 5);
INSERT INTO `role_permission` VALUES (1, 6);
INSERT INTO `role_permission` VALUES (2, 1);
INSERT INTO `role_permission` VALUES (2, 4);

1.2.6 数据库脚本 #

  • cms.sql

2. 后端 #

2.1.初始化项目 #

  • egg.js
  • api
mkdir client-side
cd client-side
cnpm init egg --type=ts
cnpm i 
cnpm run dev

2.2.支持MYSQL #

  • mysql

2.2.1 安装 #

cnpm i --save egg-mysql

2.2.2 开启插件 #

  • config\plugin.ts
import { EggPlugin } from 'egg';

const plugin: EggPlugin = {
+  mysql: {
+    enable: true,
+    package: 'egg-mysql'
+  }
};
export default plugin;

2.2.3 配置数据源 #

config\config.default.ts

import { EggAppConfig, EggAppInfo, PowerPartial } from 'egg';

export default (appInfo: EggAppInfo) => {
  const config = {} as PowerPartial<EggAppConfig>;

  // override config from framework / plugin
  // use for cookie sign key, should change to your own and keep security
  config.keys = appInfo.name + '_1580620890875_8931';

  // add your egg config in here
  config.middleware = [];

+  config.mysql = {
+    // 单数据库信息配置
+    client: {
+      // host
+      host: 'localhost',
+      // 端口号
+      port: '3306',
+      // 用户名
+      user: 'root',
+      // 密码
+      password: 'root',
+      // 数据库名
+      database: 'cms'
+    },
+    // 是否加载到 app 上,默认开启
+    app: true,
+    // 是否加载到 agent 上,默认关闭
+    agent: false,
+  };
  // add your special config in here
  const bizConfig = {
    sourceUrl: `https://github.com/eggjs/examples/tree/master/${appInfo.name}`,
  };

  // the return config will combines to EggAppConfig
  return {
    ...config,
    ...bizConfig,
  };
};

2.2.4 配置声明文件 #

  • config\config.default.ts
import 'egg';

declare module 'egg' {
+    interface Application {
+        mysql: any;
+    }
}

2.2.4 使用mysql #

  • app\controller\home.ts
import { Controller } from 'egg';

export default class HomeController extends Controller {
  public async index() {
    const { ctx } = this;
+    let users = await this.app.mysql.select('user');
+    ctx.body = {
+      success: true,
+      data: users
+    };
    //ctx.body = await ctx.service.test.sayHi('egg');
  }
}

2.3.Passport #

  • passport

2.3.1 安装 #

cnpm i --save egg-passport passport-local

2.3.2 config\plugin.ts #

config\plugin.ts

import { EggPlugin } from 'egg';

const plugin: EggPlugin = {
  mysql: {
    enable: true,
    package: 'egg-mysql'
  },
+  passport: {
+    enable: true,
+    package: 'egg-passport'
+  },
+  passportLocal: {
+    enable: true,
+    package: 'egg-passport-local'
+  }
};

export default plugin;

2.3.3 typings\index.d.ts #

typings\index.d.ts

import 'egg';

declare module 'egg' {
    interface Application {
         mysql: any;
+        passport: any;
    }
}

2.3.4 app.ts #

app.ts

import { Application, IBoot } from 'egg';
import { Strategy } from 'passport-local';
export default class FooBoot implements IBoot {
    private readonly app: Application;

    constructor(app: Application) {
        this.app = app;
    }
    configDidLoad() {
        //Config, plugin files have loaded.
        let { app } = this;
        app.passport.use(new Strategy({ usernameField: 'userName', passReqToCallback: true }, async (req, userName, password, done) => {
            const users = await this.app.mysql.select('user', { where: { userName, password }, limit: 1, offset: 0, });
            if (users && users.length > 0) {
                let user = users[0];
                let roles = await this.app.mysql.query(`SELECT role.* FROM user INNER JOIN role_user ON user.id = role_user.user_id inner JOIN role ON role_user.role_id=role.id WHERE user.id=?`, [user.id]);
                user.currentAuthority = roles.map(role => role.name);
                return done(null, user);
            } else {
                req.ctx.isAuthenticated() && req.ctx.logout();
                return done(null, false);
            }
        }));
    }
}

2.3.5 app\controller\user.ts #

app\controller\user.ts

import { Controller } from 'egg';

export default class userController extends Controller {
  public async loginCallback() {
    let { ctx } = this;
    if (ctx.isAuthenticated()) {
      ctx.body = {
        status: 'ok',
        type: ctx.user.type,
        currentAuthority: ctx.user.currentAuthority
      }
    } else {
      ctx.body = {
        success: false,
        error: '用户名或密码错误'
      }
    }
  }
  public async addUser2() {
    let { ctx } = this;
    if (ctx.isAuthenticated()) {
      let user = ctx.user;
      let url = ctx.url;
      let permissions = await this.app.mysql.query(`SELECT permission.key FROM user INNER JOIN role_user ON user.id = role_user.user_id inner JOIN role_permission ON role_user.role_id=role_permission.role_id  INNER JOIN permission ON role_permission.permission_id = permission.id  WHERE user.id=?`, [user.id]);
      let allowed = permissions.map(item => item.key).includes(url);
      if (allowed) {
        ctx.body = {
          success: true,
          error: '添加用户成功'
        }
      } else {
        ctx.body = {
          success: false,
          error: '用户未授权'
        }
      }
    } else {
      ctx.body = {
        success: false,
        error: '用户未授权'
      }
    }
  }
  public async addUser() {
    let { ctx } = this;
    ctx.body = {
      success: true,
      error: '添加用户成功'
    }
  }
}

2.3.6 middleware\auth.ts #

app\middleware\auth.ts

module.exports = (_options, _app) => {
    return async function (ctx, next) {
        if (ctx.isAuthenticated()) {
            let user = ctx.user;
            let url = ctx.url;
            let permissions = await ctx.app.mysql.query(`SELECT permission.key FROM user INNER JOIN role_user ON user.id = role_user.user_id inner JOIN role_permission ON role_user.role_id=role_permission.role_id  INNER JOIN permission ON role_permission.permission_id = permission.id  WHERE user.id=?`, [user.id]);
            let allowed = permissions.map(item => item.key).includes(url);
            if (allowed) {
                await next();
            } else {
                ctx.body = { success: false, error: '用户未授权' };
            }
        } else {
            ctx.body = { success: false, error: '用户未授权' };
        }
    }
}

2.3.7 app\router.ts #

  • middleware

app\router.ts

import { Application } from 'egg';
export default (app: Application) => {
  const { controller, router } = app;
  router.get('/', controller.home.index);
+  const localStrategy = app.passport.authenticate('local', { successRedirect: '/server/api/loginCallback', failureRedirect: '/server/api/loginCallback' });
+  router.post('/api/login/account', localStrategy);
+  const auth = app.middleware.auth();
+  router.post('/api/user/add', auth, controller.user.addUser);
+  router.get('/api/loginCallback', controller.user.loginCallback);
};

2.3.8 config\config.default.ts #

  • config\config.default.ts
  • csrf
+  config.security = {
+    csrf: false
+  }

2.3.9 测试 #

  • insomnia
  • window
  • debug

ctrl+shift+p

Debug: Toggle Auto Attach

3. 前端 #

3.1. 启动项目 #

  • create-umi
umi -v
umi ui

3.2. 设置代理 #

3.2.1 config\config.ts #

config\config.ts

+  proxy: {
+    '/server/api/': {
+      target: 'http://localhost:7001/',
+      changeOrigin: true,
+      pathRewrite: { '^/server': '' },
+    },
+  },

3.3. 前端项目 #

3.3.1 config\config.ts #

config\config.ts

  routes: [
    {
      path: '/user',
      component: '../layouts/UserLayout',
      routes: [
        {
          name: 'login',
          path: '/user/login',
          component: './user/login',
        },
      ],
    },
    {
      path: '/',
      component: '../layouts/SecurityLayout',
      routes: [
        {
          path: '/',
          component: '../layouts/BasicLayout',
          authority: ['admin', 'user'],
          routes: [
            {
              path: '/',
              redirect: '/welcome',
            },
            {
              path: '/welcome',
              name: 'welcome',
              icon: 'smile',
              component: './Welcome',
            },
            {
              path: '/admin',
              name: '权限平台',
              icon: 'crown',
              //component: './Admin',
              //authority: ['admin'],
              routes: [
                {
                  name: '角色管理',
                  icon: 'smile',
                  path: '/admin/role',
                  component: './admin/Role',
                  authority: ['admin']
                },
                {
                  name: '用户管理',
                  icon: 'smile',
                  path: '/admin/user',
                  component: './admin/User',
                  authority: ['admin', 'user']
                },
                {
                  name: '权限管理',
                  icon: 'smile',
                  path: '/admin/permission',
                  component: './admin/Permission',
                  authority: ['admin']
                },
              ],
            },
            {
              component: './404',
            },
          ],
        },
        {
          component: './404',
        },
      ],
    },
    {
      component: './404',
    },
  ],

3.3.2 User\index.tsx #

src\pages\admin\User\index.tsx

+import { queryRule, updateRule, addUser, removeRule } from './service';
+import Authorized from '@/utils/Authorized';
+<Authorized authority={['admin', 'user']} noMatch={null}>
+            <Button icon={'plus'} type="primary" onClick={() => handleModalVisible(true)}>
+              新建
+           </Button>
+</Authorized>

访问验证

请输入访问令牌

Token不正确,请重新输入