Browse Source

added access right LANE for car line

production
Fai Luk 5 hours ago
parent
commit
12eac49634
3 changed files with 23 additions and 7 deletions
  1. +8
    -0
      src/main/java/com/ffii/fpsms/config/security/SecurityConfig.java
  2. +7
    -7
      src/main/java/com/ffii/fpsms/modules/pickOrder/web/TruckLaneScheduleController.kt
  3. +8
    -0
      src/main/resources/db/changelog/changes/20260929_truck_lane_authority/01_add_truck_lane_authority.sql

+ 8
- 0
src/main/java/com/ffii/fpsms/config/security/SecurityConfig.java View File

@@ -79,6 +79,7 @@ public class SecurityConfig {
* FP-MTMS Version Checklist | Functions Ref. No. 51 | v1.0.1 | 2026-08-06 * FP-MTMS Version Checklist | Functions Ref. No. 51 | v1.0.1 | 2026-08-06
* FP-MTMS Version Checklist | Functions Ref. No. 3 | v1.0.7 | 2026-09-08 * FP-MTMS Version Checklist | Functions Ref. No. 3 | v1.0.7 | 2026-09-08
* (stockAdjustment/submit and GET /latestRemarks → INVENTORY_ADJUST) * (stockAdjustment/submit and GET /latestRemarks → INVENTORY_ADJUST)
* Route board truck APIs → ADMIN / TRUCK_LANE / TESTING
*/ */
@Bean @Bean
@Order(1) @Order(1)
@@ -140,6 +141,13 @@ public class SecurityConfig {
.hasAnyAuthority("ADMIN", "M18_SYNC") .hasAnyAuthority("ADMIN", "M18_SYNC")
.requestMatchers(HttpMethod.GET, "/m18/test/product-by-code") .requestMatchers(HttpMethod.GET, "/m18/test/product-by-code")
.hasAnyAuthority("ADMIN", "M18_SYNC") .hasAnyAuthority("ADMIN", "M18_SYNC")
/* 車線看板 (/settings/shop/board):ADMIN / TRUCK_LANE / TESTING */
.requestMatchers("/truck/**")
.hasAnyAuthority("ADMIN", "TRUCK_LANE", "TESTING")
.requestMatchers("/truckLaneVersion/**")
.hasAnyAuthority("ADMIN", "TRUCK_LANE", "TESTING")
.requestMatchers("/truckLaneSchedule/**")
.hasAnyAuthority("ADMIN", "TRUCK_LANE", "TESTING")
.anyRequest().authenticated()) .anyRequest().authenticated())
.httpBasic(httpBasic -> httpBasic.authenticationEntryPoint( .httpBasic(httpBasic -> httpBasic.authenticationEntryPoint(
(request, response, authException) -> sendUnauthorizedJson(response, "Unauthorized", "UNAUTHORIZED"))) (request, response, authException) -> sendUnauthorizedJson(response, "Unauthorized", "UNAUTHORIZED")))


+ 7
- 7
src/main/java/com/ffii/fpsms/modules/pickOrder/web/TruckLaneScheduleController.kt View File

@@ -22,13 +22,13 @@ import java.time.LocalDateTime
open class TruckLaneScheduleController @Autowired constructor( open class TruckLaneScheduleController @Autowired constructor(
private val truckLaneScheduleService: TruckLaneScheduleService, private val truckLaneScheduleService: TruckLaneScheduleService,
) { ) {
@PreAuthorize("hasAnyAuthority('ADMIN','TESTING')")
@PreAuthorize("hasAnyAuthority('ADMIN','TESTING','TRUCK_LANE')")
@PostMapping @PostMapping
open fun create(@Valid @RequestBody request: CreateTruckLaneScheduleRequest): TruckLaneScheduleResponse { open fun create(@Valid @RequestBody request: CreateTruckLaneScheduleRequest): TruckLaneScheduleResponse {
return truckLaneScheduleService.createManual(request) return truckLaneScheduleService.createManual(request)
} }


@PreAuthorize("hasAnyAuthority('ADMIN','TESTING')")
@PreAuthorize("hasAnyAuthority('ADMIN','TESTING','TRUCK_LANE')")
@PostMapping("/planFromRouteExcel") @PostMapping("/planFromRouteExcel")
@Throws(ServletRequestBindingException::class) @Throws(ServletRequestBindingException::class)
open fun planFromRouteExcel(request: HttpServletRequest): ResponseEntity<RouteExcelSchedulePlanResponse> { open fun planFromRouteExcel(request: HttpServletRequest): ResponseEntity<RouteExcelSchedulePlanResponse> {
@@ -66,19 +66,19 @@ open class TruckLaneScheduleController @Autowired constructor(
return truckLaneScheduleService.getById(id) return truckLaneScheduleService.getById(id)
} }


@PreAuthorize("hasAnyAuthority('ADMIN','TESTING')")
@PreAuthorize("hasAnyAuthority('ADMIN','TESTING','TRUCK_LANE')")
@PostMapping("/{id}/cancel") @PostMapping("/{id}/cancel")
open fun cancel(@PathVariable id: Long): TruckLaneScheduleResponse { open fun cancel(@PathVariable id: Long): TruckLaneScheduleResponse {
return truckLaneScheduleService.cancel(id) return truckLaneScheduleService.cancel(id)
} }


@PreAuthorize("hasAnyAuthority('ADMIN','TESTING')")
@PreAuthorize("hasAnyAuthority('ADMIN','TESTING','TRUCK_LANE')")
@PostMapping("/{id}/applyNow") @PostMapping("/{id}/applyNow")
open fun applyNow(@PathVariable id: Long): TruckLaneScheduleResponse { open fun applyNow(@PathVariable id: Long): TruckLaneScheduleResponse {
return truckLaneScheduleService.applyNow(id) return truckLaneScheduleService.applyNow(id)
} }


@PreAuthorize("hasAnyAuthority('ADMIN','TESTING')")
@PreAuthorize("hasAnyAuthority('ADMIN','TESTING','TRUCK_LANE')")
@PostMapping("/{id}/retry-failed") @PostMapping("/{id}/retry-failed")
open fun retryFailed( open fun retryFailed(
@PathVariable id: Long, @PathVariable id: Long,
@@ -87,7 +87,7 @@ open class TruckLaneScheduleController @Autowired constructor(
return truckLaneScheduleService.retryFailed(id, request?.executeAt) return truckLaneScheduleService.retryFailed(id, request?.executeAt)
} }


@PreAuthorize("hasAnyAuthority('ADMIN','TESTING')")
@PreAuthorize("hasAnyAuthority('ADMIN','TESTING','TRUCK_LANE')")
@PostMapping("/{id}/reactivate") @PostMapping("/{id}/reactivate")
open fun reactivateCancelled( open fun reactivateCancelled(
@PathVariable id: Long, @PathVariable id: Long,
@@ -124,7 +124,7 @@ open class TruckLaneScheduleController @Autowired constructor(
} }
} }


@PreAuthorize("hasAnyAuthority('ADMIN','TESTING')")
@PreAuthorize("hasAnyAuthority('ADMIN','TESTING','TRUCK_LANE')")
@PostMapping("/importExcel") @PostMapping("/importExcel")
@Throws(ServletRequestBindingException::class) @Throws(ServletRequestBindingException::class)
open fun importExcel( open fun importExcel(


+ 8
- 0
src/main/resources/db/changelog/changes/20260929_truck_lane_authority/01_add_truck_lane_authority.sql View File

@@ -0,0 +1,8 @@
--liquibase formatted sql

--changeset fpsms:add_truck_lane_authority
--preconditions onFail:MARK_RAN
--precondition-sql-check expectedResult:0 SELECT COUNT(*) FROM authority WHERE authority = 'TRUCK_LANE'
--comment: Route board (/settings/shop/board): ADMIN or TRUCK_LANE (車線)
INSERT IGNORE INTO `authority` (`authority`, `name`, `module`, `description`)
VALUES ('TRUCK_LANE', '車線', 'SHOP', 'Allow maintaining shop route board / truck lanes');

Loading…
Cancel
Save