cup 3 роки тому
батько
коміт
0271197232

+ 7 - 0
mp-admin/src/main/java/com/qs/mp/web/controller/api/admin/CouponPkgMgrController.java

@@ -20,6 +20,7 @@ import io.swagger.annotations.ApiResponse;
 import io.swagger.annotations.ApiResponses;
 import org.apache.commons.lang3.StringUtils;
 import org.springframework.beans.factory.annotation.Autowired;
+import org.springframework.security.access.prepost.PreAuthorize;
 import org.springframework.stereotype.Component;
 import org.springframework.web.bind.annotation.*;
 
@@ -43,6 +44,7 @@ public class CouponPkgMgrController extends BaseApiController {
 
 
     @PostMapping("/create")
+    @PreAuthorize("@ss.hasPermi('business:couponPkg:add')")
     @ApiOperation("创建券包")
     public AjaxResult create(@RequestBody CouponPkgParam couponPkgParam) {
 
@@ -53,6 +55,7 @@ public class CouponPkgMgrController extends BaseApiController {
 
 
     @PostMapping("/update")
+    @PreAuthorize("@ss.hasPermi('business:couponPkg:edit')")
     @ApiOperation("更新券包")
     public AjaxResult update(@RequestBody CouponPkgParam couponPkgParam) {
 
@@ -62,6 +65,7 @@ public class CouponPkgMgrController extends BaseApiController {
     }
 
     @PostMapping("/list")
+    @PreAuthorize("@ss.hasPermi('business:couponPkg:list')")
     @ApiOperation("券包列表")
     @ApiResponses(
             @ApiResponse(code = 200, message = "券包列表", response = CouponPkg.class)
@@ -83,6 +87,7 @@ public class CouponPkgMgrController extends BaseApiController {
     }
 
     @PostMapping("/detail/{id}")
+    @PreAuthorize("@ss.hasPermi('business:couponPkg:query')")
     @ApiOperation("券包详情")
     @ApiResponses(
             @ApiResponse(code = 200, message = "券包详情", response = CouponPkgVO.class)
@@ -93,6 +98,7 @@ public class CouponPkgMgrController extends BaseApiController {
     }
 
     @PostMapping("/status")
+    @PreAuthorize("@ss.hasPermi('business:couponPkg:on')")
     @ApiOperation("券包上下架")
     public AjaxResult status(@RequestBody CouponPkgStatusParam couponPkgStatusParam) {
 
@@ -111,6 +117,7 @@ public class CouponPkgMgrController extends BaseApiController {
     }
 
     @PostMapping("/delete/{id}")
+    @PreAuthorize("@ss.hasPermi('business:couponPkg:remove')")
     @ApiOperation("删除券包")
     public AjaxResult delete(@PathVariable("id") Long id) {
         couponPkgService.delete(id);