package service import ( "errors" "go-admin/app/admin/models" "go-admin/app/goauto/access" "gorm.io/gorm" ) func validatePurchaserMenuSelection(db *gorm.DB, menuIDs []int) error { if len(menuIDs) == 0 { return nil } hardHiddenNames := make([]string, 0) for _, module := range access.GoAutoModules() { if module.PurchaserHardHidden { hardHiddenNames = append(hardHiddenNames, module.RouteName, module.RouteName+"Root") } } var count int64 if err := db.Model(&models.SysMenu{}). Where("menu_id IN ? AND menu_name IN ?", menuIDs, hardHiddenNames). Count(&count).Error; err != nil { return err } if count > 0 { return errors.New("采购员角色不能配置 AI 规格匹配菜单") } return nil } func policiesForRole(roleKey string, menus []models.SysMenu) [][]string { policies := make([][]string, 0) seen := make(map[string]struct{}) if roleKey == access.RolePurchaser { for _, permission := range access.PurchaserAPIs() { key := permission.Path + "\x00" + permission.Method if _, exists := seen[key]; exists { continue } seen[key] = struct{}{} policies = append(policies, []string{roleKey, permission.Path, permission.Method}) } return policies } for _, menu := range menus { for _, api := range menu.SysApi { key := api.Path + "\x00" + api.Action if _, exists := seen[key]; exists { continue } seen[key] = struct{}{} policies = append(policies, []string{roleKey, api.Path, api.Action}) } } return policies }