Files
zyt/server/app/mcp/catalog/review/system.php
T
2026-09-24 09:45:44 +08:00

163 lines
17 KiB
PHP
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
<?php
/**
* AI 数据目录人工审核:系统设置、员工与权限、组织架构、文章、渠道、消息通知、装修、定时任务、开发工具,
* 以及根级控制器(config/、file/、login/、desktop/、iam/)。字段说明见 README.md。
*
* 审核结论概要:
* - 开放:员工账号列表(强制数据范围)、角色列表、部门列表/部门树(数据范围版)、岗位列表、文章与栏目列表、数据字典。
* - 待整改:员工详情、文章详情(无逐条校验,且对应列表不支持按 id 过滤,无法用 via 校验)。
* - 不开放:各类配置(含 AppSecret/存储密钥/短信密钥/支付配置)、开发工具、定时任务、系统日志与环境、
* 登录/IAM/桌面端会话、素材中心、装修;与列表字段相同的下拉/详情接口按“重复”不开放。
* 本文件没有使用 'builtin' 校验,也没有 handler。
*/
return [
// ---------------- 员工与权限 ----------------
// AdminLists::queryWhere 只有 apply_data_scope=1 时才按数据范围过滤(后台医生/医助列表页都传 1),这里固定为 1;
// progress_board 会改为“面诊进度”口径(按挂号反查医生),不开放。
'auth.admin/lists' => [
'status' => 'open', 'kind' => 'list', 'name' => '员工账号列表(含医生、医助)',
'params_allow' => [
'name' => '姓名(模糊)', 'account' => '登录账号(模糊)',
'role_id' => '角色ID(1 医生、2 医助,其他见 auth.role/lists)', 'exclude_disabled' => '传 1 排除已停用(禁止登录)的账号',
],
'forbid' => ['progress_board'], 'force' => ['apply_data_scope' => 1],
'note' => '按调用账号的数据范围(本人/本部门/本部门及下级/全部)过滤,与后台医生、医助列表一致;含职称、科室、擅长、学历、从业经历、荣誉、角色/部门/岗位名称。role_id 对应角色没有成员时后台不按角色过滤。手机号按权限脱敏',
],
// AdminLogic::detail 只有 AdminValidate::checkAdmin(账号存在)校验,不按数据范围;AdminLists 不支持按 id 过滤,via 只能核对前 50 条
'auth.admin/detail' => ['status' => 'pending', 'kind' => 'detail', 'name' => '员工账号详情',
'reason' => '详情接口只校验账号存在,不按数据范围校验(任何有权限的账号可看任意员工,含执业证号、资质图片、企业微信 userid);员工列表不支持按 id 过滤,无法用列表做逐条校验。医生职称、科室、擅长、简介等请用 auth.admin/lists'],
'auth.admin/mySelf' => ['status' => 'excluded', 'reason' => '登录会话接口:返回当前账号的菜单树和按钮权限;当前账号信息请用 zyt_whoami'],
'auth.menu/route' => ['status' => 'excluded', 'reason' => '登录会话接口:当前账号的后台路由菜单'],
'auth.menu/lists' => ['status' => 'excluded', 'reason' => '后台菜单与权限点配置,属系统配置'],
'auth.menu/all' => ['status' => 'excluded', 'reason' => '后台菜单树(权限配置下拉),属系统配置'],
'auth.menu/detail' => ['status' => 'excluded', 'reason' => '后台菜单与权限点配置,属系统配置'],
'auth.role/lists' => [
'status' => 'open', 'kind' => 'list', 'name' => '角色列表', 'params_allow' => [],
'note' => '后台本身不按数据范围过滤:拥有该权限的账号可看到全部。data_scope:1 全部、2 本部门及下级、3 本部门、4 仅本人;num 为成员数;menu_id 为授权的菜单/权限ID(可用 fields 省略)',
],
'auth.role/all' => ['status' => 'excluded', 'reason' => '角色下拉选项接口,内容与角色列表(auth.role/lists)相同'],
'auth.role/detail' => ['status' => 'excluded', 'reason' => '单个角色的权限配置,字段与角色列表(auth.role/lists)相同'],
// ---------------- 组织架构 ----------------
'dept.dept/lists' => [
'status' => 'open', 'kind' => 'report', 'name' => '部门列表(树)',
'params_allow' => ['name' => '部门名称(模糊)', 'status' => '状态:1 正常、0 停用'],
'note' => '后台本身不按数据范围过滤:拥有该权限的账号可看到全部。返回部门树(children 为下级),admin_count 为含下级部门的人数;负责人电话按权限脱敏',
],
// DeptController::all:apply_data_scope=1 时走 DeptLogic::getAllDataScoped(与业绩看板部门下拉同一套可见范围)
'dept.dept/all' => [
'status' => 'open', 'kind' => 'report', 'name' => '部门树(按数据范围)', 'params_allow' => [], 'force' => ['apply_data_scope' => 1],
'note' => '按调用账号的数据范围收窄的部门树(保留必要的上级节点),含停用部门;用于查部门ID(如业绩统计的 dept_ids)',
],
'dept.dept/detail' => ['status' => 'excluded', 'reason' => '单个部门字段与部门列表(dept.dept/lists)相同'],
'dept.dept/leaderDept' => ['status' => 'excluded', 'reason' => '表单“上级部门”下拉接口,内容已包含在部门列表中'],
'dept.jobs/lists' => [
'status' => 'open', 'kind' => 'list', 'name' => '岗位列表',
'params_allow' => ['name' => '岗位名称(模糊)', 'code' => '岗位编码', 'status' => '状态:1 正常、0 停用'],
'note' => '后台本身不按数据范围过滤:拥有该权限的账号可看到全部',
],
'dept.jobs/all' => ['status' => 'excluded', 'reason' => '岗位下拉选项接口,内容与岗位列表(dept.jobs/lists)相同'],
'dept.jobs/detail' => ['status' => 'excluded', 'reason' => '单个岗位字段与岗位列表(dept.jobs/lists)相同'],
// ---------------- 文章资讯 ----------------
'article.article/lists' => [
'status' => 'open', 'kind' => 'list', 'name' => '文章资讯列表',
'params_allow' => ['title' => '标题(模糊)', 'cid' => '栏目ID(见 article.articleCate/lists)', 'is_show' => '是否显示:1 显示、0 隐藏'],
'note' => '后台本身不按数据范围过滤:拥有该权限的账号可看到全部。content 为正文 HTML,列表中过长会截断',
],
// ArticleLogic::detail 直接 Article::findOrEmpty($id);ArticleLists 只支持 title/cid/is_show 过滤
'article.article/detail' => ['status' => 'pending', 'kind' => 'detail', 'name' => '文章详情',
'reason' => '详情接口按 id 直接读取、没有逐条校验;文章为公开资讯不涉及数据范围,但文章列表不支持按 id 过滤,无法配置列表校验。正文可先用 article.article/lists 查看(过长截断)'],
'article.articleCate/lists' => [
'status' => 'open', 'kind' => 'list', 'name' => '文章栏目列表', 'params_allow' => [],
'note' => '后台本身不按数据范围过滤:拥有该权限的账号可看到全部。article_count 为栏目下文章数',
],
'article.articleCate/all' => ['status' => 'excluded', 'reason' => '栏目下拉选项接口,内容与文章栏目列表(article.articleCate/lists)相同'],
'article.articleCate/detail' => ['status' => 'excluded', 'reason' => '单个栏目字段与文章栏目列表(article.articleCate/lists)相同'],
// ---------------- 数据字典 ----------------
// ConfigController::dict 在后台是免登录接口(notNeedLogin),只读 DictData(代码→名称对照),无凭据;
// 未在菜单登记,这里以 AI 助手使用权限 ai.mcp/access 作为权限点(比后台免登录更严)。
'config/dict' => [
'status' => 'open', 'kind' => 'report', 'perm' => 'ai.mcp/access', 'domain' => '系统设置', 'name' => '数据字典(代码→名称对照)',
'params_allow' => ['type' => '字典类型值,多个用英文逗号分隔,如 diagnosis_type,syndrome_type,past_history'],
'note' => '返回 {类型值: [{name 名称, value 代码, status 1 正常/0 停用}]},用于解读诊单、处方里的代码。常用类型:diagnosis_type 诊断类型、syndrome_type 证型、past_history 既往史、diabetes_type 糖尿病类型、appetite 口腔感觉、water_intake 每日饮水量、diet_condition 饮食情况、weight_change 体重变化、body_feeling 肢体感觉、sleep_condition 睡眠、eye_condition 眼睛、head_feeling 头部感觉、sweat_condition 出汗、skin_condition 皮肤、urine_condition 小便、stool_condition 大便、kidney_condition 腰肾、fatty_liver_degree 脂肪肝程度、sex 性别',
],
'setting.dict.dictType/lists' => [
'status' => 'open', 'kind' => 'list', 'name' => '字典类型列表',
'params_allow' => ['name' => '字典名称(模糊)', 'type' => '字典类型值(模糊),如 diagnosis_type', 'status' => '状态:1 正常、0 停用'],
'note' => '后台本身不按数据范围过滤:拥有该权限的账号可看到全部。type 即 config/dict 的类型值',
],
'setting.dict.dictData/lists' => [
'status' => 'open', 'kind' => 'list', 'name' => '字典数据列表',
'params_allow' => ['name' => '选项名称(模糊)', 'type_value' => '字典类型值(模糊),如 syndrome_type', 'type_id' => '字典类型ID', 'status' => '状态:1 正常、0 停用'],
'note' => '后台本身不按数据范围过滤:拥有该权限的账号可看到全部。value 为代码、name 为名称',
],
'setting.dict.dictType/all' => ['status' => 'excluded', 'reason' => '字典类型下拉接口,内容与字典类型列表(setting.dict.dictType/lists)相同'],
'setting.dict.dictType/detail' => ['status' => 'excluded', 'reason' => '单个字典类型字段与字典类型列表相同'],
'setting.dict.dictData/detail' => ['status' => 'excluded', 'reason' => '单个字典数据字段与字典数据列表相同'],
// ---------------- 系统设置(配置类一律不开放) ----------------
'config/getConfig' => ['status' => 'excluded', 'reason' => '后台站点基础配置(免登录接口:名称、logo、文件域名、版本号),不属于业务数据'],
'setting.storage/lists' => ['status' => 'excluded', 'reason' => '存储引擎配置,属系统配置'],
'setting.storage/detail' => ['status' => 'excluded', 'reason' => '返回对象存储 access_key/secret_key 等凭据'],
'setting.pay.payConfig/getConfig' => ['status' => 'excluded', 'reason' => '返回支付配置(商户号、密钥、证书等凭据)'],
'setting.pay.payConfig/lists' => ['status' => 'excluded', 'reason' => '支付配置列表,属支付系统配置'],
'setting.pay.payWay/getPayWay' => ['status' => 'excluded', 'reason' => '各端支付方式配置,属支付系统配置'],
'setting.transactionSettings/getConfig' => ['status' => 'excluded', 'reason' => '交易设置(未支付订单自动取消时长等),属系统配置'],
'setting.customerService/getConfig' => ['status' => 'excluded', 'reason' => '客服配置(二维码、微信、电话),属系统配置'],
'setting.hotSearch/getConfig' => ['status' => 'excluded', 'reason' => '用户端热门搜索配置,属系统配置'],
'setting.user.user/getConfig' => ['status' => 'excluded', 'reason' => '用户端默认头像等配置,属系统配置'],
'setting.user.user/getRegisterConfig' => ['status' => 'excluded', 'reason' => '用户端登录注册方式配置,属系统配置'],
'setting.web.webSetting/getWebsite' => ['status' => 'excluded', 'reason' => '网站信息配置,属系统配置'],
'setting.web.webSetting/getCopyright' => ['status' => 'excluded', 'reason' => '网站备案配置,属系统配置'],
'setting.web.webSetting/getAgreement' => ['status' => 'excluded', 'reason' => '服务协议/隐私政策配置,属系统配置'],
'setting.web.webSetting/getSiteStatistics' => ['status' => 'excluded', 'reason' => '站点统计代码配置,属系统配置'],
'setting.desktopWorkstation/getConfig' => ['status' => 'excluded', 'reason' => '医生工作站桌面端升级配置(安装包地址等),属系统配置'],
'setting.desktopWorkstation/check' => ['status' => 'excluded', 'reason' => '桌面端免登录升级检测接口,不属于后台账号数据'],
'setting.system.system/info' => ['status' => 'excluded', 'reason' => '服务器环境信息(操作系统、Web 服务器、PHP 版本、目录权限)'],
'setting.system.log/lists' => ['status' => 'excluded', 'reason' => '系统操作日志:含各账号的请求参数原文和来源 IP,可能夹带密码、密钥和患者信息'],
// ---------------- 渠道设置(凭据与第三方平台配置) ----------------
'channel.mnpSettings/getConfig' => ['status' => 'excluded', 'reason' => '返回微信小程序 AppID/AppSecret 等凭据'],
'channel.officialAccountSetting/getConfig' => ['status' => 'excluded', 'reason' => '返回公众号 AppSecret、Token、EncodingAESKey 等凭据'],
'channel.openSetting/getConfig' => ['status' => 'excluded', 'reason' => '返回微信开放平台 AppSecret 等凭据'],
'channel.appSetting/getConfig' => ['status' => 'excluded', 'reason' => 'APP 下载地址配置,属渠道配置'],
'channel.webPageSetting/getConfig' => ['status' => 'excluded', 'reason' => 'H5 渠道开关配置,属渠道配置'],
'channel.officialAccountMenu/detail' => ['status' => 'excluded', 'reason' => '公众号自定义菜单配置,属渠道配置'],
'channel.officialAccountReply/lists' => ['status' => 'excluded', 'reason' => '公众号自动回复规则配置,属渠道配置'],
'channel.officialAccountReply/detail' => ['status' => 'excluded', 'reason' => '公众号自动回复规则配置,属渠道配置'],
'channel.officialAccountReply/index' => ['status' => 'excluded', 'reason' => '公众号服务器消息回调(免登录,调用微信 SDK 应答),不是查询接口'],
// ---------------- 消息通知 ----------------
'notice.smsConfig/getConfig' => ['status' => 'excluded', 'reason' => '返回短信服务商配置(含 app_key/secret_key 等凭据)'],
'notice.smsConfig/detail' => ['status' => 'excluded', 'reason' => '返回短信服务商 app_key/secret_key 等凭据'],
'notice.notice/settingLists' => ['status' => 'excluded', 'reason' => '通知场景与模板配置,属系统配置'],
'notice.notice/detail' => ['status' => 'excluded', 'reason' => '通知模板配置(短信/公众号/小程序模板ID与内容),属系统配置'],
// ---------------- 装修、素材 ----------------
'decorate.page/detail' => ['status' => 'excluded', 'reason' => '用户端页面装修配置,不属于业务数据'],
'decorate.tabbar/detail' => ['status' => 'excluded', 'reason' => '用户端底部导航装修配置,不属于业务数据'],
'decorate.data/article' => ['status' => 'excluded', 'reason' => '装修组件取数接口(最新文章),文章请用 article.article/lists'],
'decorate.data/pc' => ['status' => 'excluded', 'reason' => 'PC 端装修信息(更新时间、访问地址),不属于业务数据'],
'file/lists' => ['status' => 'excluded', 'reason' => '素材中心:当前账号上传的文件及地址,属上传/文件管理'],
'file/listCate' => ['status' => 'excluded', 'reason' => '素材中心分组,属上传/文件管理'],
// ---------------- 定时任务、开发工具 ----------------
'crontab.crontab/lists' => ['status' => 'excluded', 'reason' => '定时任务配置(命令、参数、执行状态),属系统运维'],
'crontab.crontab/detail' => ['status' => 'excluded', 'reason' => '定时任务配置,属系统运维'],
'crontab.crontab/expression' => ['status' => 'excluded', 'reason' => 'cron 表达式解析工具,不属于业务数据'],
'tools.generator/dataTable' => ['status' => 'excluded', 'reason' => '开发工具:列出数据库全部数据表'],
'tools.generator/generateTable' => ['status' => 'excluded', 'reason' => '开发工具:代码生成器已导入的数据表'],
'tools.generator/detail' => ['status' => 'excluded', 'reason' => '开发工具:数据表字段结构与代码生成配置'],
'tools.generator/getModels' => ['status' => 'excluded', 'reason' => '开发工具:列出程序模型类'],
// ---------------- 登录、IAM、桌面端会话 ----------------
'login/logout' => ['status' => 'excluded', 'reason' => '退出登录(让登录令牌失效),会改变会话状态'],
'login/workWechatConfig' => ['status' => 'excluded', 'reason' => '登录页企业微信扫码配置(免登录接口)'],
'login/checkDbColumn' => ['status' => 'excluded', 'reason' => '免登录调试接口,返回数据库名、表名和字段结构'],
'iam/config' => ['status' => 'excluded', 'reason' => '统一账号(IAM)登录配置(免登录接口)'],
'desktop/session' => ['status' => 'excluded', 'reason' => '企业微信客服桌面端会话接口(返回登录身份与权限)'],
];