Files
pj0235-eai_agentplatform/eai_agentplatform/backend-go/internal/api/system.go
T
eaiadminandClaude Code 19cf6fb5f2 refactor: 后端仓库层收口(A3:考试/部门/学习/证书/档案/公司介绍)
把 A 档剩余对象的 api 裸查询全部收进仓库,api 层裸 store.DB 从 182 降到 99,
剩下的全是 B 档(任务/项目/笔记等尚无仓库的对象)与 C 档(报表聚合查询)。

按对象补齐的仓库方法:
- QuestionRepo:List 重写(status 档位改为显式 all/空/具体值)、
  ListByIDs(判分不过滤 status)、ListActiveByIDs(下发剔除停用)、
  ActivePool(抽题口径,主流程与蓝图共用)、DomainMap(能力雷达反查域)
- ExamPaperRepo.List;ExamRecordRepo.ListByUserChronological(趋势图正序)
- DepartmentRepo.ListByStatus / CountByName
- UserRepo.ListEmployees / CountActiveByDepartment / RenameDepartment
- LearningProgressRepo.ListAll;CertificateRepo.ListAll / GetByExamRecord
- MediaFileRepo.ListApprovedByBindType

顺带修掉两处隐患:
- CertificateRepo.GetByUserAndExam 按不存在的 exam_id 列查,一调即 SQL 报错,
  换成按 exam_record_id 的 GetByExamRecord(颁发幂等本来就该按考试记录)
- exam.go 与 system.go 各声明了一个 ExamRecordRepo 变量,同一个仓库两份变量
  会导致测试覆写时行为分叉,统一为一个 examRecordRepo

考证来源(趋势图正序 vs 列表页倒序)与抽题口径(岗位蓝图/岗位知识映射两条路径)
各自抽成单一出处,避免两处手写漂移。聚合与百分比计算仍留在 handler,未搬进仓库。

验证:tmp 验证程序走真实路由 + 真实 HTTP,对 DB 副本跑 111 项断言全绿
(覆盖停用题仍可判分、错题重练剔除停用题、趋势正序、改名同步 user.department
且 updated_at 仍刷新、未通过的正式考不发证书、公司介绍只出 approved 素材等)。
另对其中 8 条关键语义做了变异测试:逐条注入反向实现,确认断言确实会失败,
并因此发现并修掉验证程序自身一处漏洞(写语句的约束错误只在 rows.Err() 浮出,
原先未检查,导致一条断言实为空断言)。

原始 data/eai_agentplatform.db 全程未触碰,md5 复核一致。

Co-Authored-By: Claude Code <noreply@anthropic.com>
2026-09-19 01:41:33 +08:00

352 lines
9.7 KiB
Go
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
package api
import (
"encoding/csv"
"encoding/json"
"strconv"
"strings"
"time"
"github.com/gin-gonic/gin"
"eai_agentplatform/backend/internal/auth"
"eai_agentplatform/backend/internal/model"
"eai_agentplatform/backend/internal/repository"
"eai_agentplatform/backend/internal/web"
)
// systemConfigRepo 声明在此;examRecordRepo 与考试域同属一个对象,
// 统一声明在 exam.go 的「考试域仓库」块内,避免同一个仓库有两份变量导致覆写时行为分叉。
var (
userRepo repository.UserRepo
configRepo repository.SystemConfigRepo
)
func init() {
userRepo = repository.UserRepo{}
configRepo = repository.SystemConfigRepo{}
}
// ============ 用户管理(管理员) ============
// ListUsers GET /api/system/users —— 含考试统计(考试次数/通过数/最近成绩)
func ListUsers(c *gin.Context) {
var items []model.User
userRepo.Query().Type(&model.User{}).Order("id ASC").Find(&items)
// 获取考试记录
var recs []model.ExamRecord
examRecordRepo.Inner().Model(&model.ExamRecord{}).Order("submitted_at DESC").Find(&recs)
type stat struct {
ExamCount int
PassedCount int
LatestScore *int
LatestPassed *bool
LatestExamName string
LatestSubmittedAt *time.Time
}
stats := map[uint]*stat{}
for _, r := range recs {
s := stats[r.UserID]
if s == nil {
s = &stat{}
stats[r.UserID] = s
}
s.ExamCount++
if r.Passed {
s.PassedCount++
}
if s.LatestSubmittedAt == nil {
sc, ps := r.Score, r.Passed
t := r.SubmittedAt
s.LatestScore, s.LatestPassed = &sc, &ps
s.LatestExamName = r.ExamName
s.LatestSubmittedAt = &t
}
}
out := make([]gin.H, 0, len(items))
for _, u := range items {
h := gin.H{
"id": u.ID, "username": u.Username, "full_name": u.FullName,
"role": u.Role, "status": u.Status, "ai_points": u.AiPoints,
"department": u.Department, "position": u.Position, "hire_batch": u.HireBatch,
"position_id": u.PositionID,
"created_at": u.CreatedAt,
"exam_count": 0, "passed_count": 0,
"latest_score": nil, "latest_passed": nil, "latest_exam_name": "", "latest_submitted_at": nil,
}
if s := stats[u.ID]; s != nil {
h["exam_count"] = s.ExamCount
h["passed_count"] = s.PassedCount
h["latest_score"] = s.LatestScore
h["latest_passed"] = s.LatestPassed
h["latest_exam_name"] = s.LatestExamName
h["latest_submitted_at"] = s.LatestSubmittedAt
}
out = append(out, h)
}
web.OK(c, out)
}
// CreateUser POST /api/system/users —— {username,password,full_name,role,department,position,hire_batch}
func CreateUser(c *gin.Context) {
var req struct {
Username string `json:"username"`
Password string `json:"password"`
FullName string `json:"full_name"`
Role string `json:"role"`
Department string `json:"department"`
Position string `json:"position"`
HireBatch string `json:"hire_batch"`
}
if err := c.ShouldBindJSON(&req); err != nil || req.Username == "" || req.Password == "" || req.FullName == "" {
web.Fail(c, web.NewBadRequest("username/password/full_name 必填"))
return
}
if req.Role != "admin" && req.Role != "employee" {
req.Role = "employee"
}
_, found := userRepo.GetByUsername(req.Username)
if found {
web.Fail(c, web.NewConflictError("用户名已存在"))
return
}
hash, err := auth.HashPassword(req.Password)
if err != nil {
web.Fail(c, web.NewBadRequest("密码加密失败"))
return
}
u := model.User{
Username: req.Username, PasswordHash: hash, FullName: req.FullName,
Role: req.Role, Status: "active", AiPoints: defaultAiPoints(),
Department: req.Department, Position: req.Position, HireBatch: req.HireBatch,
}
if req.Role == "admin" {
u.AiPoints = 999999
}
if !userRepo.Insert(&u) {
web.Fail(c, web.NewBadRequest("创建用户失败"))
return
}
web.OK(c, u)
}
// UpdateUser PUT /api/system/users/{id} —— 编辑(可选改密/禁用/改角色)
func UpdateUser(c *gin.Context) {
id, ok := parseID(c, "id")
if !ok {
return
}
u, found := userRepo.GetByID(id)
if !found {
web.Fail(c, web.NewNotFoundError("用户不存在"))
return
}
var req struct {
FullName string `json:"full_name"`
Role string `json:"role"`
Status string `json:"status"`
Password string `json:"password"`
AiPoints *int `json:"ai_points"`
Department string `json:"department"`
Position string `json:"position"`
HireBatch string `json:"hire_batch"`
}
if err := c.ShouldBindJSON(&req); err != nil {
web.Fail(c, web.NewBadRequest("请求参数错误"))
return
}
if req.FullName != "" {
u.FullName = req.FullName
}
if req.Role == "admin" || req.Role == "employee" {
u.Role = req.Role
}
if req.Status == "active" || req.Status == "disabled" {
u.Status = req.Status
}
if req.Department != "" {
u.Department = req.Department
}
if req.Position != "" {
u.Position = req.Position
}
if req.HireBatch != "" {
u.HireBatch = req.HireBatch
}
if req.Password != "" {
hash, err := auth.HashPassword(req.Password)
if err != nil {
web.Fail(c, web.NewBadRequest("密码加密失败"))
return
}
u.PasswordHash = hash
}
if req.AiPoints != nil {
if *req.AiPoints < 0 {
web.Fail(c, web.NewBadRequest("ai_points 不能为负"))
return
}
u.AiPoints = *req.AiPoints
}
if !userRepo.Update(&u) {
web.Fail(c, web.NewBadRequest("更新用户失败"))
return
}
web.OK(c, u)
}
// defaultAiPoints 读取新用户默认 AI 算力点(system_config.ai_points_default,缺省 100)
func defaultAiPoints() int {
val := configRepo.GetByKey("ai_points_default")
if v, err := strconv.Atoi(strings.TrimSpace(val)); err == nil {
return v
}
return 100
}
// ============ 成绩管理(管理员) ============
// ListExamRecords GET /api/system/exam-records?user_id=&paper_id=
func ListExamRecords(c *gin.Context) {
items := examRecordRepo.List(c.Query("user_id"), c.Query("paper_id"))
web.OK(c, items)
}
// pointerUint 将字符串解析为 *uint;空串返回 nil。
func pointerUint(s string) *uint {
if s == "" {
return nil
}
if v, err := strconv.ParseUint(s, 10, 32); err == nil {
uv := uint(v)
return &uv
}
return nil
}
// GetExamRecord GET /api/system/exam-records/{id} —— 详情
func GetExamRecord(c *gin.Context) {
id, ok := parseID(c, "id")
if !ok {
return
}
rec, found := examRecordRepo.GetByID(id)
if !found {
web.Fail(c, web.NewNotFoundError("考试记录不存在"))
return
}
var detail any
_ = json.Unmarshal([]byte(rec.DetailJSON), &detail)
web.OK(c, gin.H{
"id": rec.ID, "user_id": rec.UserID, "paper_id": rec.PaperID, "exam_name": rec.ExamName,
"score": rec.Score, "total_score": rec.TotalScore, "pass_score": rec.PassScore, "passed": rec.Passed,
"correct_count": rec.CorrectCount, "wrong_count": rec.WrongCount,
"detail": detail, "submitted_at": rec.SubmittedAt,
})
}
// DeleteExamRecord DELETE /api/system/exam-records/{id} —— 删除成绩记录(用于重置正式考重考资格)
func DeleteExamRecord(c *gin.Context) {
id, ok := parseID(c, "id")
if !ok {
return
}
if !examRecordRepo.Remove(id) {
web.Fail(c, web.NewBadRequest("删除考试记录失败"))
return
}
web.OK(c, gin.H{"id": id, "deleted": true})
}
// ExportExamRecords GET /api/system/exam-records/export —— 导出 CSV(支持 user_id/paper_id 过滤)
func ExportExamRecords(c *gin.Context) {
var items []model.ExamRecord
q := repository.DB.Model(&model.ExamRecord{})
if uid := c.Query("user_id"); uid != "" {
q = q.Where("user_id = ?", uid)
}
if pid := c.Query("paper_id"); pid != "" {
q = q.Where("paper_id = ?", pid)
}
if err := q.Order("submitted_at DESC").Find(&items).Error; err != nil {
web.Fail(c, web.NewBadRequest("查询成绩失败"))
return
}
// 用户名映射
var users []model.User
repository.DB.Find(&users)
nameMap := map[uint]model.User{}
for _, u := range users {
nameMap[u.ID] = u
}
c.Header("Content-Type", "text/csv; charset=utf-8")
c.Header("Content-Disposition", `attachment; filename="exam_records.csv"`)
c.Writer.WriteString("\xEF\xBB\xBF") // UTF-8 BOM,兼容 Excel
w := csv.NewWriter(c.Writer)
_ = w.Write([]string{"编号", "用户名", "姓名", "部门", "考试名称", "得分", "总分", "结果", "答对", "答错", "提交时间"})
for _, r := range items {
u := nameMap[r.UserID]
passed := "未通过"
if r.Passed {
passed = "通过"
}
_ = w.Write([]string{
strconv.FormatUint(uint64(r.ID), 10),
u.Username,
u.FullName,
u.Department,
r.ExamName,
strconv.Itoa(r.Score),
strconv.Itoa(r.TotalScore),
passed,
strconv.Itoa(r.CorrectCount),
strconv.Itoa(r.WrongCount),
r.SubmittedAt.Format("2006-01-02 15:04:05"),
})
}
w.Flush()
}
// ============ 系统参数配置(管理员) ============
// GetConfig GET /api/system/config —— 所有系统参数
func GetConfig(c *gin.Context) {
items := configRepo.List()
type cfgItem struct {
Key string `json:"config_key"`
Value string `json:"config_value"`
Description string `json:"description"`
}
out := make([]cfgItem, 0, len(items))
for _, it := range items {
out = append(out, cfgItem{Key: it.ConfigKey, Value: it.ConfigValue, Description: it.Description})
}
web.OK(c, gin.H{"configs": out})
}
// UpdateConfig PUT /api/system/config —— {configs: {key: value}}
func UpdateConfig(c *gin.Context) {
var req struct {
Configs map[string]string `json:"configs"`
}
if err := c.ShouldBindJSON(&req); err != nil || len(req.Configs) == 0 {
web.Fail(c, web.NewBadRequest("configs 必填"))
return
}
configRepo.BulkUpsert(toSystemConfigs(req.Configs))
web.OK(c, gin.H{"updated": len(req.Configs)})
}
func toSystemConfigs(m map[string]string) []model.SystemConfig {
items := make([]model.SystemConfig, 0, len(m))
for k, v := range m {
items = append(items, model.SystemConfig{ConfigKey: k, ConfigValue: v})
}
return items
}