Authored by weiqingting

提交

... ... @@ -145,8 +145,7 @@ module.exports={
});
},
gray: function (req, callback){
var result = { code: 400, message: "没有权限" };
console.log("gray-1");
var result = { code: 201, message: "没有权限" };
if (req.session && req.session.user) {
var user = req.session.user;
var path = req.route?req.route.path[0]:req.originalUrl.replace(/\?.+/, '');
... ... @@ -157,30 +156,24 @@ module.exports={
'x-client-ip': req.ip,
'x-shop-id': user.auth.shopId
};
console.log("gray-2");
if (path && user.right[path]) {
request({
url: Iaccount.isUsedMenuAuth,
method: 'POST',
form: '[' + user.auth.pid + ',' + user.auth.role_id + ', "' + path + '", "", "", ' + Iaccount.WEBSITE + ']'
}, function (error, httpResponse, rebody) {
console.log("gray-2");
if (!error && httpResponse.statusCode == 200) {
result = { code: 200, message: "具有权限" };
console.log("gray-3");
return callback(error, result);
} else {
console.log("gray-4");
return callback(error, result);
}
});
} else {
console.log("gray-5");
result = { code: 201, message: "不受权限控制" };
result = { code: 200, message: "不受权限控制" };
return callback(null, result);
}
} else {
console.log("gray-5");
return callback(null,result);
}
},
... ...
... ... @@ -3,7 +3,9 @@ module.exports=function(app) {
app.get("/login","common.Login");
app.get("/logout","common.Login");
app.get("/logout","common.Login",function (req) {
delete req.session.user;
});
app.post("/login", "common_login", function (login, req, res){
if (login.code == 200) {
... ...
... ... @@ -145,8 +145,7 @@ module.exports={
});
},
gray: function (req, callback){
var result = { code: 400, message: "没有权限" };
console.log("gray-1");
var result = { code: 201, message: "没有权限" };
if (req.session && req.session.user) {
var user = req.session.user;
var path = req.route?req.route.path[0]:req.originalUrl.replace(/\?.+/, '');
... ... @@ -157,30 +156,24 @@ module.exports={
'x-client-ip': req.ip,
'x-shop-id': user.auth.shopId
};
console.log("gray-2");
if (path && user.right[path]) {
request({
url: Iaccount.isUsedMenuAuth,
method: 'POST',
form: '[' + user.auth.pid + ',' + user.auth.role_id + ', "' + path + '", "", "", ' + Iaccount.WEBSITE + ']'
}, function (error, httpResponse, rebody) {
console.log("gray-2");
if (!error && httpResponse.statusCode == 200) {
result = { code: 200, message: "具有权限" };
console.log("gray-3");
return callback(error, result);
} else {
console.log("gray-4");
return callback(error, result);
}
});
} else {
console.log("gray-5");
result = { code: 201, message: "不受权限控制" };
result = { code: 200, message: "不受权限控制" };
return callback(null, result);
}
} else {
console.log("gray-5");
return callback(null,result);
}
},
... ...