feat: add reviewed follow-up audio patient enrichment
This commit is contained in:
@@ -73,6 +73,18 @@ class AuthMiddleware
|
||||
// 当前访问路径
|
||||
$accessUri = strtolower($request->controller() . '/' . $request->action());
|
||||
|
||||
// This group must never use the legacy unregistered-route bypass.
|
||||
if (str_starts_with($accessUri, 'tcm.followupaudio/')) {
|
||||
$allowed = ['capabilities', 'uploadsession', 'uploadchunk', 'uploadcomplete',
|
||||
'create', 'lists', 'detail', 'savedraft', 'apply', 'retry', 'audio'];
|
||||
$action = substr($accessUri, strlen('tcm.followupaudio/'));
|
||||
$uris = $this->formatUrl($adminAuthCache->getAdminUri() ?? []);
|
||||
if (in_array($action, $allowed, true) && in_array('tcm.diagnosis/edit', $uris, true)) {
|
||||
return $next($request); // The service also checks the current patient scope and daily permissions.
|
||||
}
|
||||
return JsonService::fail('权限不足,无法访问或操作');
|
||||
}
|
||||
|
||||
// 获客助手的子接口多数不是独立菜单权限。整组动作统一绑定页面权限,
|
||||
// 共享操作人的动态页面权限也必须先经过这一层,再由业务层校验具体方案。
|
||||
if (str_starts_with($accessUri, 'firstvisit.wecompromotion/')) {
|
||||
|
||||
Reference in New Issue
Block a user