From a985e6ba578b4ec28a25932f871c4df76ce092f2 Mon Sep 17 00:00:00 2001
From: chenhaozhe <cgz@hz-kingdee.com>
Date: 星期二, 12 五月 2026 15:02:39 +0800
Subject: [PATCH] 模块添加自定义标签鉴权 在Token启用的情况下。通过自定义标签定义的modname和Operate 判断用户是否有访问模块的权限

---
 WebAPI/Controllers/XSGL/Xs_SeOrderChangeBillController.cs |    8 ++++++++
 1 files changed, 8 insertions(+), 0 deletions(-)

diff --git a/WebAPI/Controllers/XSGL/Xs_SeOrderChangeBillController.cs b/WebAPI/Controllers/XSGL/Xs_SeOrderChangeBillController.cs
index 67f8f3b..1a660df 100644
--- a/WebAPI/Controllers/XSGL/Xs_SeOrderChangeBillController.cs
+++ b/WebAPI/Controllers/XSGL/Xs_SeOrderChangeBillController.cs
@@ -8,10 +8,12 @@
 using System.Data.SqlClient;
 using System.Web.Http;
 using WebAPI.Models;
+using WebAPI.Utility;
 
 namespace WebAPI.Controllers
 {
     //閿�鍞鍗曞彉鏇村崟Controller
+    [Permission(HModName = "Xs_SeOrderChangeBill")]
     public class Xs_SeOrderChangeBillController : ApiController
     {
         //鑾峰彇绯荤粺鍙傛暟
@@ -31,6 +33,7 @@
         /// </summary>
         [Route("Xs_SeOrderChangeBill/list")]
         [HttpGet]
+        [Permission(HModName = "Xs_SeOrderChangeBill", Operate = "_Query")]
         public object getXs_SeOrderChangeBill(string sWhere, string user)
         {
             try
@@ -86,6 +89,7 @@
         #region 閿�鍞鍗曞彉鏇村崟淇濆瓨 鏂板/缂栬緫
         [Route("Xs_SeOrderChangeBill/SaveXs_SeOrderChangeBill")]
         [HttpPost]
+        [Permission(HModName = "Xs_SeOrderChangeBill", Operate = "_Edit")]
         public object SaveXs_SeOrderChangeBill([FromBody] JObject msg)
         {
             var _value = msg["msg"].ToString();
@@ -315,6 +319,7 @@
         /// </summary>
         [Route("Xs_SeOrderChangeBill/delete")]
         [HttpGet]
+        [Permission(HModName = "Xs_SeOrderChangeBill", Operate = "_Drop")]
         public object deleteXs_SeOrderChangeBill(string HInterID, string user)
         {
             try
@@ -448,6 +453,7 @@
         /// <returns></returns>
         [Route("Xs_SeOrderChangeBill/AuditXs_SeOrderChangeBill")]
         [HttpGet]
+        [Permission(HModName = "Xs_SeOrderChangeBill", Operate = "_Check")]
         public object AuditXs_SeOrderChangeBill(int HInterID, int IsAudit, string CurUserName)
         {
             string ModRightNameCheck = "Xs_SeOrderChangeBill_Check";
@@ -749,6 +755,7 @@
         /// <returns></returns>
         [Route("Xs_SeOrderChangeBill/CloseXs_SeOrderChangeBill")]
         [HttpGet]
+        [Permission(HModName = "Xs_SeOrderChangeBill", Operate = "_Close")]
         public object CloseXs_SeOrderChangeBill(int HInterID, int IsAudit, string CurUserName)
         {
             string ModRightNameCheck = "Xs_SeOrderChangeBill_Close";
@@ -894,6 +901,7 @@
         /// <returns></returns>
         [Route("Xs_SeOrderChangeBill/DeleteXs_SeOrderChangeBill")]
         [HttpGet]
+        [Permission(HModName = "Xs_SeOrderChangeBill", Operate = "_Delete")]
         public object DeleteXs_SeOrderChangeBill(int HInterID, int IsAudit, string CurUserName)
         {
             string ModRightNameCheck = "Xs_SeOrderChangeBill_Delete";

--
Gitblit v1.9.1