- 시스템 관리자 화면: 「시스템 설정」을 리소스 현황 아래로 · 제목 줄 오른쪽에 회사 고르기(기본 자기 회사) - 고른 회사 = sessionStorage aislo.adminCompany · 프로젝트 · 사용자 관리 · 가입 요청 · 회사 관리 · 팀원 추가가 그 회사 것 - 카드 해시에 &company=<id> · 회사 관리자 · 개인 화면은 그대로 · 임시 보관함은 사람 것이라 그대로 - 서버: /admin/projects · /admin/join-requests · /admin/members(POST · invite)에 company_id(_scope_company 한 곳 · 시스템 관리자만 남의 회사) · /admin/users 에 회사 거르기 - 라우터 700줄 넘어 나눔: 권한 도우미 B01_Dashboard_Scope · 회사 자산 B01_Dashboard_Router_Assets(본체가 include) - 시험 test_b01_settings_cards 보탬 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Ly2oHAaTDYRjcniAmHR81z
37 lines
1.5 KiB
Python
37 lines
1.5 KiB
Python
"""B01_Dashboard 권한 · 회사 범위 도우미 — 라우터 둘(본체 · 자산)이 함께 씀."""
|
|
|
|
from typing import Any
|
|
|
|
from fastapi import Depends, HTTPException
|
|
|
|
from common_util.common_util_auth import verify_session
|
|
|
|
|
|
async def require_company_admin(
|
|
session: dict[str, Any] = Depends(verify_session),
|
|
) -> dict[str, Any]:
|
|
if session["role"] not in ("ADMIN", "SYSTEM_ADMIN") and not session["is_master"]:
|
|
raise HTTPException(status_code=403, detail="회사 관리자 권한이 필요합니다.")
|
|
return session
|
|
|
|
|
|
def _require_company_id(session: dict[str, Any]) -> int:
|
|
company_id = session.get("company_id")
|
|
if company_id is None:
|
|
raise HTTPException(status_code=403, detail="회사 연결이 필요합니다.")
|
|
return int(company_id)
|
|
|
|
|
|
def _same_company(session: dict[str, Any], company_id: int | None) -> bool:
|
|
return company_id is not None and int(session.get("company_id") or 0) == int(company_id)
|
|
|
|
|
|
def _scope_company(session: dict[str, Any], company_id: int | None) -> int:
|
|
"""회사 범위 자원의 회사 — 시스템관리자면 인자 우선(대시보드 회사 고르기) · 남은 세션 회사."""
|
|
if session["role"] == "SYSTEM_ADMIN" and company_id is not None:
|
|
return int(company_id)
|
|
own = _require_company_id(session)
|
|
if company_id is not None and int(company_id) != own:
|
|
raise HTTPException(status_code=403, detail="다른 회사의 자료는 볼 수 없습니다.")
|
|
return own
|