From a985e6ba578b4ec28a25932f871c4df76ce092f2 Mon Sep 17 00:00:00 2001
From: chenhaozhe <cgz@hz-kingdee.com>
Date: 星期二, 12 五月 2026 15:02:39 +0800
Subject: [PATCH] 模块添加自定义标签鉴权 在Token启用的情况下。通过自定义标签定义的modname和Operate 判断用户是否有访问模块的权限
---
WebAPI/Controllers/XSGL/Xs_SeOrderChangeBillController.cs | 8 ++++++++
1 files changed, 8 insertions(+), 0 deletions(-)
diff --git a/WebAPI/Controllers/XSGL/Xs_SeOrderChangeBillController.cs b/WebAPI/Controllers/XSGL/Xs_SeOrderChangeBillController.cs
index 67f8f3b..1a660df 100644
--- a/WebAPI/Controllers/XSGL/Xs_SeOrderChangeBillController.cs
+++ b/WebAPI/Controllers/XSGL/Xs_SeOrderChangeBillController.cs
@@ -8,10 +8,12 @@
using System.Data.SqlClient;
using System.Web.Http;
using WebAPI.Models;
+using WebAPI.Utility;
namespace WebAPI.Controllers
{
//閿�鍞鍗曞彉鏇村崟Controller
+ [Permission(HModName = "Xs_SeOrderChangeBill")]
public class Xs_SeOrderChangeBillController : ApiController
{
//鑾峰彇绯荤粺鍙傛暟
@@ -31,6 +33,7 @@
/// </summary>
[Route("Xs_SeOrderChangeBill/list")]
[HttpGet]
+ [Permission(HModName = "Xs_SeOrderChangeBill", Operate = "_Query")]
public object getXs_SeOrderChangeBill(string sWhere, string user)
{
try
@@ -86,6 +89,7 @@
#region 閿�鍞鍗曞彉鏇村崟淇濆瓨 鏂板/缂栬緫
[Route("Xs_SeOrderChangeBill/SaveXs_SeOrderChangeBill")]
[HttpPost]
+ [Permission(HModName = "Xs_SeOrderChangeBill", Operate = "_Edit")]
public object SaveXs_SeOrderChangeBill([FromBody] JObject msg)
{
var _value = msg["msg"].ToString();
@@ -315,6 +319,7 @@
/// </summary>
[Route("Xs_SeOrderChangeBill/delete")]
[HttpGet]
+ [Permission(HModName = "Xs_SeOrderChangeBill", Operate = "_Drop")]
public object deleteXs_SeOrderChangeBill(string HInterID, string user)
{
try
@@ -448,6 +453,7 @@
/// <returns></returns>
[Route("Xs_SeOrderChangeBill/AuditXs_SeOrderChangeBill")]
[HttpGet]
+ [Permission(HModName = "Xs_SeOrderChangeBill", Operate = "_Check")]
public object AuditXs_SeOrderChangeBill(int HInterID, int IsAudit, string CurUserName)
{
string ModRightNameCheck = "Xs_SeOrderChangeBill_Check";
@@ -749,6 +755,7 @@
/// <returns></returns>
[Route("Xs_SeOrderChangeBill/CloseXs_SeOrderChangeBill")]
[HttpGet]
+ [Permission(HModName = "Xs_SeOrderChangeBill", Operate = "_Close")]
public object CloseXs_SeOrderChangeBill(int HInterID, int IsAudit, string CurUserName)
{
string ModRightNameCheck = "Xs_SeOrderChangeBill_Close";
@@ -894,6 +901,7 @@
/// <returns></returns>
[Route("Xs_SeOrderChangeBill/DeleteXs_SeOrderChangeBill")]
[HttpGet]
+ [Permission(HModName = "Xs_SeOrderChangeBill", Operate = "_Delete")]
public object DeleteXs_SeOrderChangeBill(int HInterID, int IsAudit, string CurUserName)
{
string ModRightNameCheck = "Xs_SeOrderChangeBill_Delete";
--
Gitblit v1.9.1