permission.php 10 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356
  1. <?php
  2. include($_SERVER['DOCUMENT_ROOT'] . "/Authorization/script/php/permission/check_right.php");
  3. ?>
  4. <!doctype html>
  5. <html class="fixed sidebar-left-collapsed">
  6. <head>
  7. <!-- Basic -->
  8. <meta charset="UTF-8">
  9. <title>帳號權限管理系統</title>
  10. <meta name="keywords" content="HTML5 Admin Template" />
  11. <meta name="description" content="JSOFT Admin - Responsive HTML5 Template">
  12. <meta name="author" content="JSOFT.net">
  13. <!-- Mobile Metas -->
  14. <meta name="viewport" content="width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=no" />
  15. <!-- Web Fonts -->
  16. <link href="http://fonts.googleapis.com/css?family=Open+Sans:300,400,600,700,800|Shadows+Into+Light" rel="stylesheet" type="text/css">
  17. <!-- Vendor CSS -->
  18. <link rel="stylesheet" href="assets/vendor/bootstrap/css/bootstrap.css" />
  19. <link rel="stylesheet" href="assets/vendor/font-awesome/css/font-awesome.css" />
  20. <link rel="stylesheet" href="assets/vendor/magnific-popup/magnific-popup.css" />
  21. <link rel="stylesheet" href="assets/vendor/bootstrap-datepicker/css/datepicker3.css" />
  22. <!-- Specific Page Vendor CSS -->
  23. <link rel="stylesheet" href="assets/vendor/select2/select2.css" />
  24. <link rel="stylesheet" href="assets/vendor/jquery-datatables-bs3/assets/css/datatables.css" />
  25. <!-- Theme CSS -->
  26. <link rel="stylesheet" href="assets/stylesheets/theme.css" />
  27. <!-- Skin CSS -->
  28. <link rel="stylesheet" href="assets/stylesheets/skins/default.css" />
  29. <!-- Theme Custom CSS -->
  30. <link rel="stylesheet" href="assets/stylesheets/theme-custom.css">
  31. <!-- Role Custom CSS -->
  32. <link rel="stylesheet" href="assets/stylesheets/role.css" />
  33. <!-- Head Libs -->
  34. <script src="assets/vendor/modernizr/modernizr.js"></script>
  35. <script src="assets/vendor/jquery/jquery.js"></script>
  36. <!-- Icon -->
  37. <link rel="shortcut icon" href="assets/images/favicon.ico" />
  38. <!-- vue3 -->
  39. <script src="https://unpkg.com/vue@next"></script>
  40. <script src="./script/js/global.js"></script>
  41. <script src="/Common/script/js/user-image.js"></script>
  42. <style>
  43. td {
  44. font-size: 20px;
  45. color: black;
  46. }
  47. select {
  48. font-size: 12px;
  49. color: black;
  50. }
  51. .right {
  52. position: absolute;
  53. right: 8px;
  54. }
  55. </style>
  56. <script type="application/javascript">
  57. var roles;
  58. var users;
  59. var groups;
  60. var groupDropdown;
  61. var checkManager = 0;
  62. var table;
  63. </script>
  64. </head>
  65. <body>
  66. <section id="outFrame">
  67. <!-- start: header -->
  68. <header-menu></header-menu>
  69. <!-- end: header -->
  70. <div>
  71. <!-- start: sidebar -->
  72. <side-bar></side-bar>
  73. <!-- end: sidebar -->
  74. <section role="main" class="content-body">
  75. <header class="page-header">
  76. <h2>{{pageHeader}}</h2>
  77. </header>
  78. </section>
  79. </div>
  80. </section>
  81. <section role="main" id="content" class="content-body" style="padding-top: 6vh;">
  82. <section class="panel">
  83. <header class="panel-heading">
  84. <div class="panel-actions">
  85. <a href="#" class="fa fa-caret-down"></a>
  86. <a href="#" class="fa fa-times"></a>
  87. </div>
  88. <h2 id="testID" class="panel-title">所有系統</h2>
  89. </header>
  90. <div class="panel-body">
  91. <table class="table table-bordered table-striped mb-none" id="datatable">
  92. <thead>
  93. <tr>
  94. <th>員工編號</th>
  95. <th>使用者帳號</th>
  96. <th>使用者名稱</th>
  97. <th>所屬部門</th>
  98. <th>使用者權限(點擊以刪除權限)</th>
  99. </tr>
  100. </thead>
  101. <tbody id="table-data">
  102. </tbody>
  103. </table>
  104. </div>
  105. </section>
  106. </section>
  107. <script>
  108. vm.mount('#outFrame');
  109. $(function() {
  110. getGroup();
  111. getDeptUser();
  112. });
  113. function getDeptUser() {
  114. $.ajax({
  115. url: "./script/php/API/get_dept_user.php",
  116. type: "POST",
  117. dataType: "json"
  118. }).done(function(result) {
  119. roles = result.permissions;
  120. users = result.users;
  121. users.forEach(function(data) {
  122. let btn = getPermissions(data.GroupID, data.GroupName, data.UserID);
  123. $('#table-data').append(`<tr>
  124. <td>${data.UserID}</td>
  125. <td>${data.Account}</td>
  126. <td>${data.UserName}</td>
  127. <td>${data.DepartmentID}</td>
  128. <td id="${data.UserID}">
  129. <div class="btn-group">
  130. <button type="button" class="mb-xs mt-xs mr-xs btn btn-default dropdown-toggle" data-toggle="dropdown">新增身分 <span class="caret"></span></button>
  131. <ul class="dropdown-menu" role="menu" style="cursor: default;">
  132. ${groupDropdown}
  133. </ul>
  134. </div>
  135. ${btn}
  136. </td>
  137. </tr>`);
  138. });
  139. }).error(function(error) {
  140. console.log(error);
  141. }).complete(function(e) {
  142. initTable();
  143. });
  144. }
  145. function getGroup() {
  146. $.ajax({
  147. url: "./script/php/API/get_group.php",
  148. type: "POST",
  149. dataType: "json"
  150. }).done(function(result) {
  151. groups = result;
  152. groupDropdown = '';
  153. groups.forEach(function(group) {
  154. groupDropdown += `<li class="li-${group.GroupID}"><a groupID="${group.GroupID}" class="groupDropdown" >${group.GroupName}</a></li>`;
  155. });
  156. }).error(function(error) {
  157. console.log(error);
  158. });
  159. }
  160. function getPermissions(groupIDs, groupNames, userID) {
  161. var result = "";
  162. groupIDs.forEach(function(groupID, index) {
  163. result += `<button id="btn-${userID}-${groupID}" onclick="delPermission('${userID}','${groupID}');" class="btn btn-${groupID}">${groupNames[index]}</button> `;
  164. if (groupID == 'Manager') {
  165. checkManager++;
  166. }
  167. });
  168. return result;
  169. }
  170. function addPermission(groupID, groupName, userID) {
  171. var result = "";
  172. user = users.find(user => user.UserID == userID);
  173. if (!user.GroupName.includes(groupName)) {
  174. addPermissionDB(user.UserID, groupID);
  175. result += `<button id="btn-${userID}-${groupID}" onclick="delPermission('${userID}','${groupID}');" class="btn btn-${groupID}">${groupName}</button> `;
  176. user.GroupName.push(groupName);
  177. user.GroupID.push(groupID);
  178. return result;
  179. } else {
  180. return result;
  181. }
  182. }
  183. function addPermissionDB(userID, groupID) {
  184. $.ajax({
  185. url: "./script/php/API/insert_role.php",
  186. type: "POST",
  187. dataType: "text",
  188. data: {
  189. UserID: userID,
  190. GroupID: groupID,
  191. }
  192. }).done(function(result) {
  193. if (result == 'success' && groupID == 'Manager') {
  194. checkManager++;
  195. alert('身分新增成功!');
  196. } else if (result == 'success') {
  197. alert('身分新增成功!');
  198. } else {
  199. console.log(result);
  200. }
  201. }).error(function(error) {
  202. console.log(error);
  203. });
  204. }
  205. function delPermission(userID, groupID) {
  206. if (groupID != 'User' && groupID != 'Guest') {
  207. if (groupID == 'Manager') {
  208. if (checkManager > 1) {
  209. delPermissionDB(userID, groupID);
  210. $(`#btn-${userID}-${groupID}`).remove();
  211. } else {
  212. alert('部門至少要有一名管理員!');
  213. }
  214. } else {
  215. delPermissionDB(userID, groupID);
  216. $(`#btn-${userID}-${groupID}`).remove();
  217. }
  218. } else {
  219. alert('身分最低為一般用戶!請勿刪除!');
  220. }
  221. }
  222. function delPermissionDB(userID, groupID) {
  223. $.ajax({
  224. url: "./script/php/API/delete_role.php",
  225. type: "POST",
  226. dataType: "text",
  227. data: {
  228. UserID: userID,
  229. GroupID: groupID,
  230. }
  231. }).done(function(result) {
  232. if (result == 'success' && groupID == 'Manager') {
  233. checkManager--;
  234. alert('身分刪除成功!');
  235. } else if (result == 'success') {
  236. alert('身分刪除成功!');
  237. } else {
  238. console.log(result);
  239. }
  240. }).error(function(error) {
  241. console.log(error);
  242. });
  243. }
  244. function initTable() {
  245. table = $('#datatable').DataTable({
  246. bProcessing: true,
  247. responsive: true,
  248. "searching": true,
  249. "pageLength": 10,
  250. "language": {
  251. "processing": "處理中...",
  252. "loadingRecords": "載入中...",
  253. "lengthMenu": "顯示 _MENU_ 項結果",
  254. "zeroRecords": "沒有符合的結果或是沒有資料",
  255. "info": "顯示第 _START_ 至 _END_ 項結果,共 _TOTAL_ 項",
  256. "infoEmpty": "顯示第 0 至 0 項結果,共 0 項",
  257. "infoFiltered": "(從 _MAX_ 項結果中過濾)",
  258. "infoPostFix": "",
  259. "search": "",
  260. "paginate": {
  261. "first": '<i class="fa fa-step-backward"></i>',
  262. "previous": '<i class="fa fa-backward"></i>',
  263. "next": '<i class="fa fa-forward"></i>',
  264. "last": '<i class="fa fa-step-forward"></i>'
  265. },
  266. "aria": {
  267. "sortAscending": ": 升冪排列",
  268. "sortDescending": ": 降冪排列"
  269. }
  270. },
  271. });
  272. $('body .dropdown-toggle').dropdown();
  273. $("body").on('click', '.groupDropdown', function(e) {
  274. let groupName = $(this).text();
  275. let groupID = $(this).attr('groupID');
  276. let userAccount = $(this).closest("td").attr('id');
  277. console.log($(this))
  278. $(this).closest("td").append(addPermission(groupID, groupName, userAccount));
  279. })
  280. }
  281. </script>
  282. <!-- Vendor -->
  283. <script src="assets/vendor/jquery-browser-mobile/jquery.browser.mobile.js"></script>
  284. <script src="https://cdn.jsdelivr.net/npm/bootstrap@4.6.2/dist/js/bootstrap.bundle.min.js" integrity="sha384-Fy6S3B9q64WdZWQUiU+q4/2Lc9npb8tCaSX9FK7E8HnRr0Jz8D6OP9dO5Vg3Q9ct" crossorigin="anonymous"></script>
  285. <script src="assets/vendor/nanoscroller/nanoscroller.js"></script>
  286. <script src="assets/vendor/bootstrap-datepicker/js/bootstrap-datepicker.js"></script>
  287. <script src="assets/vendor/magnific-popup/magnific-popup.js"></script>
  288. <script src="assets/vendor/jquery-placeholder/jquery.placeholder.js"></script>
  289. <!-- Specific Page Vendor -->
  290. <script src="assets/vendor/select2/select2.js"></script>
  291. <script src="assets/vendor/jquery-datatables/media/js/jquery.dataTables.js"></script>
  292. <script src="assets/vendor/jquery-datatables/extras/TableTools/js/dataTables.tableTools.min.js"></script>
  293. <script src="assets/vendor/jquery-datatables-bs3/assets/js/datatables.js"></script>
  294. <!-- Theme Base, Components and Settings -->
  295. <script src="assets/javascripts/theme.js"></script>
  296. <!-- Theme Custom -->
  297. <script src="assets/javascripts/theme.custom.js"></script>
  298. <!-- Theme Initialization Files -->
  299. <script src="assets/javascripts/theme.init.js"></script>
  300. <!-- Examples -->
  301. <script src="assets/javascripts/tables/examples.datatables.default.js"></script>
  302. <script src="assets/javascripts/tables/examples.datatables.row.with.details.js"></script>
  303. <script src="assets/javascripts/tables/examples.datatables.tabletools.js"></script>
  304. </body>
  305. </html>