163 lines
17 KiB
PHP
163 lines
17 KiB
PHP
<?php
|
||
/**
|
||
* AI 数据目录人工审核:系统设置、员工与权限、组织架构、文章、渠道、消息通知、装修、定时任务、开发工具,
|
||
* 以及根级控制器(config/、file/、login/、desktop/、iam/)。字段说明见 README.md。
|
||
*
|
||
* 审核结论概要:
|
||
* - 开放:员工账号列表(强制数据范围)、角色列表、部门列表/部门树(数据范围版)、岗位列表、文章与栏目列表、数据字典。
|
||
* - 待整改:员工详情、文章详情(无逐条校验,且对应列表不支持按 id 过滤,无法用 via 校验)。
|
||
* - 不开放:各类配置(含 AppSecret/存储密钥/短信密钥/支付配置)、开发工具、定时任务、系统日志与环境、
|
||
* 登录/IAM/桌面端会话、素材中心、装修;与列表字段相同的下拉/详情接口按“重复”不开放。
|
||
* 本文件没有使用 'builtin' 校验,也没有 handler。
|
||
*/
|
||
|
||
return [
|
||
// ---------------- 员工与权限 ----------------
|
||
// AdminLists::queryWhere 只有 apply_data_scope=1 时才按数据范围过滤(后台医生/医助列表页都传 1),这里固定为 1;
|
||
// progress_board 会改为“面诊进度”口径(按挂号反查医生),不开放。
|
||
'auth.admin/lists' => [
|
||
'status' => 'open', 'kind' => 'list', 'name' => '员工账号列表(含医生、医助)',
|
||
'params_allow' => [
|
||
'name' => '姓名(模糊)', 'account' => '登录账号(模糊)',
|
||
'role_id' => '角色ID(1 医生、2 医助,其他见 auth.role/lists)', 'exclude_disabled' => '传 1 排除已停用(禁止登录)的账号',
|
||
],
|
||
'forbid' => ['progress_board'], 'force' => ['apply_data_scope' => 1],
|
||
'note' => '按调用账号的数据范围(本人/本部门/本部门及下级/全部)过滤,与后台医生、医助列表一致;含职称、科室、擅长、学历、从业经历、荣誉、角色/部门/岗位名称。role_id 对应角色没有成员时后台不按角色过滤。手机号按权限脱敏',
|
||
],
|
||
// AdminLogic::detail 只有 AdminValidate::checkAdmin(账号存在)校验,不按数据范围;AdminLists 不支持按 id 过滤,via 只能核对前 50 条
|
||
'auth.admin/detail' => ['status' => 'pending', 'kind' => 'detail', 'name' => '员工账号详情',
|
||
'reason' => '详情接口只校验账号存在,不按数据范围校验(任何有权限的账号可看任意员工,含执业证号、资质图片、企业微信 userid);员工列表不支持按 id 过滤,无法用列表做逐条校验。医生职称、科室、擅长、简介等请用 auth.admin/lists'],
|
||
'auth.admin/mySelf' => ['status' => 'excluded', 'reason' => '登录会话接口:返回当前账号的菜单树和按钮权限;当前账号信息请用 zyt_whoami'],
|
||
'auth.menu/route' => ['status' => 'excluded', 'reason' => '登录会话接口:当前账号的后台路由菜单'],
|
||
'auth.menu/lists' => ['status' => 'excluded', 'reason' => '后台菜单与权限点配置,属系统配置'],
|
||
'auth.menu/all' => ['status' => 'excluded', 'reason' => '后台菜单树(权限配置下拉),属系统配置'],
|
||
'auth.menu/detail' => ['status' => 'excluded', 'reason' => '后台菜单与权限点配置,属系统配置'],
|
||
'auth.role/lists' => [
|
||
'status' => 'open', 'kind' => 'list', 'name' => '角色列表', 'params_allow' => [],
|
||
'note' => '后台本身不按数据范围过滤:拥有该权限的账号可看到全部。data_scope:1 全部、2 本部门及下级、3 本部门、4 仅本人;num 为成员数;menu_id 为授权的菜单/权限ID(可用 fields 省略)',
|
||
],
|
||
'auth.role/all' => ['status' => 'excluded', 'reason' => '角色下拉选项接口,内容与角色列表(auth.role/lists)相同'],
|
||
'auth.role/detail' => ['status' => 'excluded', 'reason' => '单个角色的权限配置,字段与角色列表(auth.role/lists)相同'],
|
||
|
||
// ---------------- 组织架构 ----------------
|
||
'dept.dept/lists' => [
|
||
'status' => 'open', 'kind' => 'report', 'name' => '部门列表(树)',
|
||
'params_allow' => ['name' => '部门名称(模糊)', 'status' => '状态:1 正常、0 停用'],
|
||
'note' => '后台本身不按数据范围过滤:拥有该权限的账号可看到全部。返回部门树(children 为下级),admin_count 为含下级部门的人数;负责人电话按权限脱敏',
|
||
],
|
||
// DeptController::all:apply_data_scope=1 时走 DeptLogic::getAllDataScoped(与业绩看板部门下拉同一套可见范围)
|
||
'dept.dept/all' => [
|
||
'status' => 'open', 'kind' => 'report', 'name' => '部门树(按数据范围)', 'params_allow' => [], 'force' => ['apply_data_scope' => 1],
|
||
'note' => '按调用账号的数据范围收窄的部门树(保留必要的上级节点),含停用部门;用于查部门ID(如业绩统计的 dept_ids)',
|
||
],
|
||
'dept.dept/detail' => ['status' => 'excluded', 'reason' => '单个部门字段与部门列表(dept.dept/lists)相同'],
|
||
'dept.dept/leaderDept' => ['status' => 'excluded', 'reason' => '表单“上级部门”下拉接口,内容已包含在部门列表中'],
|
||
'dept.jobs/lists' => [
|
||
'status' => 'open', 'kind' => 'list', 'name' => '岗位列表',
|
||
'params_allow' => ['name' => '岗位名称(模糊)', 'code' => '岗位编码', 'status' => '状态:1 正常、0 停用'],
|
||
'note' => '后台本身不按数据范围过滤:拥有该权限的账号可看到全部',
|
||
],
|
||
'dept.jobs/all' => ['status' => 'excluded', 'reason' => '岗位下拉选项接口,内容与岗位列表(dept.jobs/lists)相同'],
|
||
'dept.jobs/detail' => ['status' => 'excluded', 'reason' => '单个岗位字段与岗位列表(dept.jobs/lists)相同'],
|
||
|
||
// ---------------- 文章资讯 ----------------
|
||
'article.article/lists' => [
|
||
'status' => 'open', 'kind' => 'list', 'name' => '文章资讯列表',
|
||
'params_allow' => ['title' => '标题(模糊)', 'cid' => '栏目ID(见 article.articleCate/lists)', 'is_show' => '是否显示:1 显示、0 隐藏'],
|
||
'note' => '后台本身不按数据范围过滤:拥有该权限的账号可看到全部。content 为正文 HTML,列表中过长会截断',
|
||
],
|
||
// ArticleLogic::detail 直接 Article::findOrEmpty($id);ArticleLists 只支持 title/cid/is_show 过滤
|
||
'article.article/detail' => ['status' => 'pending', 'kind' => 'detail', 'name' => '文章详情',
|
||
'reason' => '详情接口按 id 直接读取、没有逐条校验;文章为公开资讯不涉及数据范围,但文章列表不支持按 id 过滤,无法配置列表校验。正文可先用 article.article/lists 查看(过长截断)'],
|
||
'article.articleCate/lists' => [
|
||
'status' => 'open', 'kind' => 'list', 'name' => '文章栏目列表', 'params_allow' => [],
|
||
'note' => '后台本身不按数据范围过滤:拥有该权限的账号可看到全部。article_count 为栏目下文章数',
|
||
],
|
||
'article.articleCate/all' => ['status' => 'excluded', 'reason' => '栏目下拉选项接口,内容与文章栏目列表(article.articleCate/lists)相同'],
|
||
'article.articleCate/detail' => ['status' => 'excluded', 'reason' => '单个栏目字段与文章栏目列表(article.articleCate/lists)相同'],
|
||
|
||
// ---------------- 数据字典 ----------------
|
||
// ConfigController::dict 在后台是免登录接口(notNeedLogin),只读 DictData(代码→名称对照),无凭据;
|
||
// 未在菜单登记,这里以 AI 助手使用权限 ai.mcp/access 作为权限点(比后台免登录更严)。
|
||
'config/dict' => [
|
||
'status' => 'open', 'kind' => 'report', 'perm' => 'ai.mcp/access', 'domain' => '系统设置', 'name' => '数据字典(代码→名称对照)',
|
||
'params_allow' => ['type' => '字典类型值,多个用英文逗号分隔,如 diagnosis_type,syndrome_type,past_history'],
|
||
'note' => '返回 {类型值: [{name 名称, value 代码, status 1 正常/0 停用}]},用于解读诊单、处方里的代码。常用类型:diagnosis_type 诊断类型、syndrome_type 证型、past_history 既往史、diabetes_type 糖尿病类型、appetite 口腔感觉、water_intake 每日饮水量、diet_condition 饮食情况、weight_change 体重变化、body_feeling 肢体感觉、sleep_condition 睡眠、eye_condition 眼睛、head_feeling 头部感觉、sweat_condition 出汗、skin_condition 皮肤、urine_condition 小便、stool_condition 大便、kidney_condition 腰肾、fatty_liver_degree 脂肪肝程度、sex 性别',
|
||
],
|
||
'setting.dict.dictType/lists' => [
|
||
'status' => 'open', 'kind' => 'list', 'name' => '字典类型列表',
|
||
'params_allow' => ['name' => '字典名称(模糊)', 'type' => '字典类型值(模糊),如 diagnosis_type', 'status' => '状态:1 正常、0 停用'],
|
||
'note' => '后台本身不按数据范围过滤:拥有该权限的账号可看到全部。type 即 config/dict 的类型值',
|
||
],
|
||
'setting.dict.dictData/lists' => [
|
||
'status' => 'open', 'kind' => 'list', 'name' => '字典数据列表',
|
||
'params_allow' => ['name' => '选项名称(模糊)', 'type_value' => '字典类型值(模糊),如 syndrome_type', 'type_id' => '字典类型ID', 'status' => '状态:1 正常、0 停用'],
|
||
'note' => '后台本身不按数据范围过滤:拥有该权限的账号可看到全部。value 为代码、name 为名称',
|
||
],
|
||
'setting.dict.dictType/all' => ['status' => 'excluded', 'reason' => '字典类型下拉接口,内容与字典类型列表(setting.dict.dictType/lists)相同'],
|
||
'setting.dict.dictType/detail' => ['status' => 'excluded', 'reason' => '单个字典类型字段与字典类型列表相同'],
|
||
'setting.dict.dictData/detail' => ['status' => 'excluded', 'reason' => '单个字典数据字段与字典数据列表相同'],
|
||
|
||
// ---------------- 系统设置(配置类一律不开放) ----------------
|
||
'config/getConfig' => ['status' => 'excluded', 'reason' => '后台站点基础配置(免登录接口:名称、logo、文件域名、版本号),不属于业务数据'],
|
||
'setting.storage/lists' => ['status' => 'excluded', 'reason' => '存储引擎配置,属系统配置'],
|
||
'setting.storage/detail' => ['status' => 'excluded', 'reason' => '返回对象存储 access_key/secret_key 等凭据'],
|
||
'setting.pay.payConfig/getConfig' => ['status' => 'excluded', 'reason' => '返回支付配置(商户号、密钥、证书等凭据)'],
|
||
'setting.pay.payConfig/lists' => ['status' => 'excluded', 'reason' => '支付配置列表,属支付系统配置'],
|
||
'setting.pay.payWay/getPayWay' => ['status' => 'excluded', 'reason' => '各端支付方式配置,属支付系统配置'],
|
||
'setting.transactionSettings/getConfig' => ['status' => 'excluded', 'reason' => '交易设置(未支付订单自动取消时长等),属系统配置'],
|
||
'setting.customerService/getConfig' => ['status' => 'excluded', 'reason' => '客服配置(二维码、微信、电话),属系统配置'],
|
||
'setting.hotSearch/getConfig' => ['status' => 'excluded', 'reason' => '用户端热门搜索配置,属系统配置'],
|
||
'setting.user.user/getConfig' => ['status' => 'excluded', 'reason' => '用户端默认头像等配置,属系统配置'],
|
||
'setting.user.user/getRegisterConfig' => ['status' => 'excluded', 'reason' => '用户端登录注册方式配置,属系统配置'],
|
||
'setting.web.webSetting/getWebsite' => ['status' => 'excluded', 'reason' => '网站信息配置,属系统配置'],
|
||
'setting.web.webSetting/getCopyright' => ['status' => 'excluded', 'reason' => '网站备案配置,属系统配置'],
|
||
'setting.web.webSetting/getAgreement' => ['status' => 'excluded', 'reason' => '服务协议/隐私政策配置,属系统配置'],
|
||
'setting.web.webSetting/getSiteStatistics' => ['status' => 'excluded', 'reason' => '站点统计代码配置,属系统配置'],
|
||
'setting.desktopWorkstation/getConfig' => ['status' => 'excluded', 'reason' => '医生工作站桌面端升级配置(安装包地址等),属系统配置'],
|
||
'setting.desktopWorkstation/check' => ['status' => 'excluded', 'reason' => '桌面端免登录升级检测接口,不属于后台账号数据'],
|
||
'setting.system.system/info' => ['status' => 'excluded', 'reason' => '服务器环境信息(操作系统、Web 服务器、PHP 版本、目录权限)'],
|
||
'setting.system.log/lists' => ['status' => 'excluded', 'reason' => '系统操作日志:含各账号的请求参数原文和来源 IP,可能夹带密码、密钥和患者信息'],
|
||
|
||
// ---------------- 渠道设置(凭据与第三方平台配置) ----------------
|
||
'channel.mnpSettings/getConfig' => ['status' => 'excluded', 'reason' => '返回微信小程序 AppID/AppSecret 等凭据'],
|
||
'channel.officialAccountSetting/getConfig' => ['status' => 'excluded', 'reason' => '返回公众号 AppSecret、Token、EncodingAESKey 等凭据'],
|
||
'channel.openSetting/getConfig' => ['status' => 'excluded', 'reason' => '返回微信开放平台 AppSecret 等凭据'],
|
||
'channel.appSetting/getConfig' => ['status' => 'excluded', 'reason' => 'APP 下载地址配置,属渠道配置'],
|
||
'channel.webPageSetting/getConfig' => ['status' => 'excluded', 'reason' => 'H5 渠道开关配置,属渠道配置'],
|
||
'channel.officialAccountMenu/detail' => ['status' => 'excluded', 'reason' => '公众号自定义菜单配置,属渠道配置'],
|
||
'channel.officialAccountReply/lists' => ['status' => 'excluded', 'reason' => '公众号自动回复规则配置,属渠道配置'],
|
||
'channel.officialAccountReply/detail' => ['status' => 'excluded', 'reason' => '公众号自动回复规则配置,属渠道配置'],
|
||
'channel.officialAccountReply/index' => ['status' => 'excluded', 'reason' => '公众号服务器消息回调(免登录,调用微信 SDK 应答),不是查询接口'],
|
||
|
||
// ---------------- 消息通知 ----------------
|
||
'notice.smsConfig/getConfig' => ['status' => 'excluded', 'reason' => '返回短信服务商配置(含 app_key/secret_key 等凭据)'],
|
||
'notice.smsConfig/detail' => ['status' => 'excluded', 'reason' => '返回短信服务商 app_key/secret_key 等凭据'],
|
||
'notice.notice/settingLists' => ['status' => 'excluded', 'reason' => '通知场景与模板配置,属系统配置'],
|
||
'notice.notice/detail' => ['status' => 'excluded', 'reason' => '通知模板配置(短信/公众号/小程序模板ID与内容),属系统配置'],
|
||
|
||
// ---------------- 装修、素材 ----------------
|
||
'decorate.page/detail' => ['status' => 'excluded', 'reason' => '用户端页面装修配置,不属于业务数据'],
|
||
'decorate.tabbar/detail' => ['status' => 'excluded', 'reason' => '用户端底部导航装修配置,不属于业务数据'],
|
||
'decorate.data/article' => ['status' => 'excluded', 'reason' => '装修组件取数接口(最新文章),文章请用 article.article/lists'],
|
||
'decorate.data/pc' => ['status' => 'excluded', 'reason' => 'PC 端装修信息(更新时间、访问地址),不属于业务数据'],
|
||
'file/lists' => ['status' => 'excluded', 'reason' => '素材中心:当前账号上传的文件及地址,属上传/文件管理'],
|
||
'file/listCate' => ['status' => 'excluded', 'reason' => '素材中心分组,属上传/文件管理'],
|
||
|
||
// ---------------- 定时任务、开发工具 ----------------
|
||
'crontab.crontab/lists' => ['status' => 'excluded', 'reason' => '定时任务配置(命令、参数、执行状态),属系统运维'],
|
||
'crontab.crontab/detail' => ['status' => 'excluded', 'reason' => '定时任务配置,属系统运维'],
|
||
'crontab.crontab/expression' => ['status' => 'excluded', 'reason' => 'cron 表达式解析工具,不属于业务数据'],
|
||
'tools.generator/dataTable' => ['status' => 'excluded', 'reason' => '开发工具:列出数据库全部数据表'],
|
||
'tools.generator/generateTable' => ['status' => 'excluded', 'reason' => '开发工具:代码生成器已导入的数据表'],
|
||
'tools.generator/detail' => ['status' => 'excluded', 'reason' => '开发工具:数据表字段结构与代码生成配置'],
|
||
'tools.generator/getModels' => ['status' => 'excluded', 'reason' => '开发工具:列出程序模型类'],
|
||
|
||
// ---------------- 登录、IAM、桌面端会话 ----------------
|
||
'login/logout' => ['status' => 'excluded', 'reason' => '退出登录(让登录令牌失效),会改变会话状态'],
|
||
'login/workWechatConfig' => ['status' => 'excluded', 'reason' => '登录页企业微信扫码配置(免登录接口)'],
|
||
'login/checkDbColumn' => ['status' => 'excluded', 'reason' => '免登录调试接口,返回数据库名、表名和字段结构'],
|
||
'iam/config' => ['status' => 'excluded', 'reason' => '统一账号(IAM)登录配置(免登录接口)'],
|
||
'desktop/session' => ['status' => 'excluded', 'reason' => '企业微信客服桌面端会话接口(返回登录身份与权限)'],
|
||
];
|