Commit 94c341f2a8e909f5d1fe4bc0c37baabb4096fbcd
1 parent
8bf84c92
chore(usr): REQ-USR-004 review approve + 归档 spec/plan/review
Showing
4 changed files
with
532 additions
and
1 deletions
docs/08-模块任务管理.md
docs/superpowers/plans/2026-05-15-REQ-USR-004.md
0 → 100644
| 1 | +--- | |
| 2 | +req_id: REQ-USR-004 | |
| 3 | +date: 2026-05-15 | |
| 4 | +spec_ref: docs/superpowers/specs/2026-05-15-REQ-USR-004.md | |
| 5 | +--- | |
| 6 | + | |
| 7 | +# REQ-USR-004 查询用户 Implementation Plan | |
| 8 | + | |
| 9 | +> **Execution:** Parent skill `feature-tdd` executes this plan task-by-task. Steps use checkbox (`- [ ]`) syntax for tracking. | |
| 10 | + | |
| 11 | +**Goal:** 实现 `GET /api/v1/users` 分页 + 多字段筛选 + 排序的用户列表查询;服务端做白名单 + 类型转换 + 越界矫正;输出 PageResult<UserListItemVo>(JOIN sys_employee/sys_department 取员工名 / 部门名)。 | |
| 12 | + | |
| 13 | +**Architecture:** | |
| 14 | +- 复用 REQ-USR-002 / 003 已建的鉴权 + 角色守卫 + 异常处理。 | |
| 15 | +- 新增 `UserListService` 单一职责;动态 SQL 通过 MyBatis XML(@Select script 也可,本任务用 XML 便于维护)实现 JOIN + WHERE 动态拼接。 | |
| 16 | +- 白名单映射:queryField / sortField / matchMode / sortOrder 全部在 service 层校验后才进 SQL。 | |
| 17 | +- 越界矫正在 service 层:先查目标 page,若 records 为空但 total>0 → 重算 lastPage 再查。 | |
| 18 | +- PageResult 引入为通用类(放 common.response 包,供后续 REQ 复用)。 | |
| 19 | + | |
| 20 | +**Tech Stack:** 复用 Spring Boot 3 + MyBatis-Plus(本 REQ 用 mapper XML 写动态查询)+ Jakarta Validation。 | |
| 21 | + | |
| 22 | +--- | |
| 23 | + | |
| 24 | +## Schema 改动 | |
| 25 | + | |
| 26 | +无。 | |
| 27 | + | |
| 28 | +--- | |
| 29 | + | |
| 30 | +## 文件变更清单 | |
| 31 | + | |
| 32 | +**新增(通用)**: | |
| 33 | +- `backend/src/main/java/com/xly/erp/common/response/PageResult.java` | |
| 34 | + | |
| 35 | +**新增(业务)**: | |
| 36 | +- `backend/src/main/java/com/xly/erp/module/usr/dto/UserQueryReq.java` | |
| 37 | +- `backend/src/main/java/com/xly/erp/module/usr/vo/UserListItemVo.java` | |
| 38 | +- `backend/src/main/java/com/xly/erp/module/usr/service/UserListService.java` | |
| 39 | +- `backend/src/main/java/com/xly/erp/module/usr/service/impl/UserListServiceImpl.java` | |
| 40 | +- `backend/src/main/resources/mapper/usr/SysUserMapper.xml` | |
| 41 | + | |
| 42 | +**修改**: | |
| 43 | +- `backend/src/main/java/com/xly/erp/common/response/ErrorCode.java`(新增 INVALID_ENUM_PARAM=40003) | |
| 44 | +- `backend/src/main/java/com/xly/erp/module/usr/mapper/SysUserMapper.java`(新增 selectByQuery + countByQuery) | |
| 45 | +- `backend/src/main/java/com/xly/erp/module/usr/controller/UserController.java`(新增 GET / list 方法) | |
| 46 | + | |
| 47 | +**测试**: | |
| 48 | +- `backend/src/test/java/com/xly/erp/module/usr/dto/UserQueryReqValidationTest.java` | |
| 49 | +- `backend/src/test/java/com/xly/erp/module/usr/service/UserListServiceImplTest.java` | |
| 50 | +- `backend/src/test/java/com/xly/erp/module/usr/controller/UserControllerListTest.java` | |
| 51 | + | |
| 52 | +--- | |
| 53 | + | |
| 54 | +## 约束常量 | |
| 55 | + | |
| 56 | +**ErrorCode 新增**: | |
| 57 | + | |
| 58 | +| 常量 | 值 | HTTP | | |
| 59 | +|---|---|---| | |
| 60 | +| `INVALID_ENUM_PARAM` | `40003` | 400 | | |
| 61 | + | |
| 62 | +> ErrorCode.toHttpStatus(40003) → 400/100=400,已在现有映射,新增常量即可。 | |
| 63 | + | |
| 64 | +**白名单常量**(全部定义在 `UserListServiceImpl` 的 `static final Map`): | |
| 65 | + | |
| 66 | +``` | |
| 67 | +SORT_FIELDS = {"tCreateDate", "tLastLoginDate", "sUsername", "sUserCode"} | |
| 68 | + | |
| 69 | +QUERY_FIELD_TO_SQL = { | |
| 70 | + "username": "u.sUsername", | |
| 71 | + "employeeName": "e.sEmployeeName", | |
| 72 | + "userCode": "u.sUserCode", | |
| 73 | + "departmentName": "d.sDepartmentName", | |
| 74 | + "userType": "u.sUserType", | |
| 75 | + "isDeleted": "u.iIsDeleted", | |
| 76 | + "lastLoginDate": "u.tLastLoginDate", | |
| 77 | + "createdBy": "u.sCreatedBy" | |
| 78 | +} | |
| 79 | + | |
| 80 | +MATCH_MODES = {"contains", "notContains", "equals"} | |
| 81 | +SORT_ORDERS = {"asc", "desc"} | |
| 82 | + | |
| 83 | +USER_TYPES = {"NORMAL", "SUPER_ADMIN"} | |
| 84 | + | |
| 85 | +DEFAULT_PAGE = 1 | |
| 86 | +DEFAULT_SIZE = 20 | |
| 87 | +MAX_SIZE = 100 | |
| 88 | +DEFAULT_SORT_FIELD = "tCreateDate" | |
| 89 | +DEFAULT_SORT_ORDER = "desc" | |
| 90 | +DEFAULT_MATCH_MODE = "contains" | |
| 91 | +``` | |
| 92 | + | |
| 93 | +**API 形状**: | |
| 94 | + | |
| 95 | +``` | |
| 96 | +GET /api/v1/users?page=1&size=20&sortField=tCreateDate&sortOrder=desc | |
| 97 | + &queryField=username&matchMode=contains&queryValue=ali | |
| 98 | + &userType=NORMAL&isDeleted=false | |
| 99 | +@RequireSuperAdmin | |
| 100 | +→ Result<PageResult<UserListItemVo>> | |
| 101 | + | |
| 102 | +PageResult<T> { | |
| 103 | + List<T> records; | |
| 104 | + long total; | |
| 105 | + int page; | |
| 106 | + int size; | |
| 107 | +} | |
| 108 | + | |
| 109 | +UserListItemVo { | |
| 110 | + Integer userId, String username, String employeeName, String userCode, | |
| 111 | + String departmentName, String userType, String language, | |
| 112 | + Boolean isDeleted, LocalDateTime lastLoginDate, | |
| 113 | + String createdBy, LocalDateTime createdDate | |
| 114 | +} | |
| 115 | + | |
| 116 | +UserQueryReq { | |
| 117 | + Integer page, // @Min(1) | |
| 118 | + Integer size, // @Min(1) @Max(100) | |
| 119 | + String sortField, | |
| 120 | + String sortOrder, | |
| 121 | + String queryField, | |
| 122 | + String matchMode, | |
| 123 | + String queryValue, | |
| 124 | + String userType, | |
| 125 | + Boolean isDeleted | |
| 126 | +} | |
| 127 | +``` | |
| 128 | + | |
| 129 | +--- | |
| 130 | + | |
| 131 | +## 任务步骤 | |
| 132 | + | |
| 133 | +### Task 1: ErrorCode 新增 40003 + PageResult 通用类 | |
| 134 | + | |
| 135 | +**Files:** | |
| 136 | +- Modify: `backend/src/main/java/com/xly/erp/common/response/ErrorCode.java` | |
| 137 | +- Create: `backend/src/main/java/com/xly/erp/common/response/PageResult.java` | |
| 138 | +- Modify: `backend/src/test/java/com/xly/erp/common/response/ErrorCodeTest.java` | |
| 139 | + | |
| 140 | +**API shape:** | |
| 141 | +- `ErrorCode.INVALID_ENUM_PARAM = 40003` | |
| 142 | +- `ErrorCode.toHttpStatus(40003) == 400` | |
| 143 | +- `PageResult<T> { records: List<T>; total: long; page: int; size: int }` + @Builder | |
| 144 | + | |
| 145 | +- [ ] **Step 1: 写失败测试** `ErrorCodeTest#httpMappings_coverNewCodes_v004` 验 40003→400 | |
| 146 | +- [ ] **Step 2: 实现最小代码** | |
| 147 | +- [ ] **Step 3: 子会话验证 PASS** | |
| 148 | +- [ ] **Step 4: Commit** `feat(usr): ErrorCode 新增 40003 + PageResult 通用类 REQ-USR-004` | |
| 149 | + | |
| 150 | +### Task 2: UserQueryReq DTO + UserListItemVo | |
| 151 | + | |
| 152 | +**Files:** | |
| 153 | +- Create: `backend/src/main/java/com/xly/erp/module/usr/dto/UserQueryReq.java` | |
| 154 | +- Create: `backend/src/main/java/com/xly/erp/module/usr/vo/UserListItemVo.java` | |
| 155 | +- Create: `backend/src/test/java/com/xly/erp/module/usr/dto/UserQueryReqValidationTest.java` | |
| 156 | + | |
| 157 | +**API shape:** | |
| 158 | +- `UserQueryReq` 所有字段可选;jakarta 注解只用 `@Min(1)`(page)、`@Min(1) @Max(100)`(size);其他枚举值在 service 层做白名单校验(不用 @Pattern,因为 @Pattern 失败会落到 40001,本 REQ 要 40003) | |
| 159 | +- `UserListItemVo` 字段同 spec § 输出 | |
| 160 | + | |
| 161 | +- [ ] **Step 1: 写失败测试** 5 个用例: | |
| 162 | + - 全空合法(PATCH 风格) | |
| 163 | + - page=0 → @Min(1) 失败 | |
| 164 | + - size=101 → @Max(100) 失败 | |
| 165 | + - size=0 → @Min(1) 失败 | |
| 166 | + - 全合法字段 → pass | |
| 167 | +- [ ] **Step 2: 实现最小代码** | |
| 168 | +- [ ] **Step 3: 子会话验证 PASS** | |
| 169 | +- [ ] **Step 4: Commit** `feat(usr): UserQueryReq + UserListItemVo + PageResult REQ-USR-004` | |
| 170 | + | |
| 171 | +### Task 3: SysUserMapper.selectByQuery + countByQuery (XML) | |
| 172 | + | |
| 173 | +**Files:** | |
| 174 | +- Modify: `backend/src/main/java/com/xly/erp/module/usr/mapper/SysUserMapper.java`(声明方法) | |
| 175 | +- Create: `backend/src/main/resources/mapper/usr/SysUserMapper.xml`(动态 SQL) | |
| 176 | +- Modify: `backend/src/main/resources/application.yml`(mybatis-plus.mapper-locations: classpath*:/mapper/**/*.xml) | |
| 177 | +- Modify: `backend/src/main/resources/application-test.yml`(同上) | |
| 178 | +- Create: `backend/src/test/java/com/xly/erp/module/usr/mapper/SysUserMapperQueryTest.java` | |
| 179 | + | |
| 180 | +**API shape:** | |
| 181 | +- `SysUserMapper#selectByQuery(@Param("p") QueryParams p) : List<UserListItemRow>` | |
| 182 | +- `SysUserMapper#countByQuery(@Param("p") QueryParams p) : long` | |
| 183 | +- `QueryParams` — 内部 record / DTO,包含已通过白名单校验的字段:`sqlSortField`(列名), `sqlSortOrder`(asc/desc), `sqlQueryColumn`(已映射列名 OR null), `matchMode`, `queryValue`, `userType`, `isDeleted`(Integer 0/1 或 null), `offset`, `limit` | |
| 184 | + | |
| 185 | +> service 层把 spec 入参规范化为 `QueryParams`,mapper XML 用 `${}` 拼接 `sqlSortField` / `sqlSortOrder` / `sqlQueryColumn`(白名单值),用 `#{}` 绑定 queryValue / userType / isDeleted / offset / limit。 | |
| 186 | + | |
| 187 | +XML 关键片段(仅作为 plan 锁定的契约,TDD 实现可改细节): | |
| 188 | + | |
| 189 | +```xml | |
| 190 | +<sql id="baseFrom"> | |
| 191 | + FROM sys_user u | |
| 192 | + LEFT JOIN sys_employee e ON e.iIncrement = u.iEmployeeId | |
| 193 | + LEFT JOIN sys_department d ON d.iIncrement = e.iDepartmentId | |
| 194 | +</sql> | |
| 195 | + | |
| 196 | +<sql id="whereClause"> | |
| 197 | + <where> | |
| 198 | + <if test="p.sqlQueryColumn != null and p.queryValue != null and p.queryValue != ''"> | |
| 199 | + <choose> | |
| 200 | + <when test="p.matchMode == 'contains'"> | |
| 201 | + AND ${p.sqlQueryColumn} LIKE CONCAT('%', #{p.queryValue}, '%') | |
| 202 | + </when> | |
| 203 | + <when test="p.matchMode == 'notContains'"> | |
| 204 | + AND (${p.sqlQueryColumn} NOT LIKE CONCAT('%', #{p.queryValue}, '%') | |
| 205 | + OR ${p.sqlQueryColumn} IS NULL) | |
| 206 | + </when> | |
| 207 | + <otherwise> | |
| 208 | + AND ${p.sqlQueryColumn} = #{p.queryValue} | |
| 209 | + </otherwise> | |
| 210 | + </choose> | |
| 211 | + </if> | |
| 212 | + <if test="p.userType != null">AND u.sUserType = #{p.userType}</if> | |
| 213 | + <if test="p.isDeleted != null">AND u.iIsDeleted = #{p.isDeleted}</if> | |
| 214 | + </where> | |
| 215 | +</sql> | |
| 216 | + | |
| 217 | +<select id="selectByQuery" resultType="com.xly.erp.module.usr.vo.UserListItemVo"> | |
| 218 | + SELECT u.iIncrement AS userId, u.sUsername AS username, | |
| 219 | + e.sEmployeeName AS employeeName, u.sUserCode AS userCode, | |
| 220 | + d.sDepartmentName AS departmentName, u.sUserType AS userType, | |
| 221 | + u.sLanguage AS language, u.iIsDeleted AS isDeleted, | |
| 222 | + u.tLastLoginDate AS lastLoginDate, u.sCreatedBy AS createdBy, | |
| 223 | + u.tCreateDate AS createdDate | |
| 224 | + <include refid="baseFrom"/> | |
| 225 | + <include refid="whereClause"/> | |
| 226 | + ORDER BY u.${p.sqlSortField} ${p.sqlSortOrder} | |
| 227 | + LIMIT #{p.offset}, #{p.limit} | |
| 228 | +</select> | |
| 229 | + | |
| 230 | +<select id="countByQuery" resultType="long"> | |
| 231 | + SELECT COUNT(*) | |
| 232 | + <include refid="baseFrom"/> | |
| 233 | + <include refid="whereClause"/> | |
| 234 | +</select> | |
| 235 | +``` | |
| 236 | + | |
| 237 | +> MyBatis-Plus 默认 `mapper-locations: classpath*:/mapper/**/*.xml`,但需在 application.yml 显式声明以确保 XML 被加载。当前 application.yml 仅声明了 mybatis-plus 配置项,未声明 mapper-locations;本任务添加。 | |
| 238 | + | |
| 239 | +- [ ] **Step 1: 写失败测试** `SysUserMapperQueryTest`: | |
| 240 | + - `count_noFilters_returnsAllRows` | |
| 241 | + - `select_withSortByUsername_ascending` | |
| 242 | + - `select_withQueryFieldUsername_contains` | |
| 243 | + - `select_joinsEmployeeAndDepartment_returnsBothNames` | |
| 244 | +- [ ] **Step 2: 实现最小代码** | |
| 245 | +- [ ] **Step 3: 子会话验证 PASS** | |
| 246 | +- [ ] **Step 4: Commit** `feat(usr): SysUserMapper 动态查询 XML + JOIN 员工/部门 REQ-USR-004` | |
| 247 | + | |
| 248 | +### Task 4: UserListService 白名单 + 越界矫正 | |
| 249 | + | |
| 250 | +**Files:** | |
| 251 | +- Create: `backend/src/main/java/com/xly/erp/module/usr/service/UserListService.java` | |
| 252 | +- Create: `backend/src/main/java/com/xly/erp/module/usr/service/impl/UserListServiceImpl.java` | |
| 253 | +- Create: `backend/src/test/java/com/xly/erp/module/usr/service/UserListServiceImplTest.java` | |
| 254 | + | |
| 255 | +**API shape:** | |
| 256 | +- `UserListService#list(UserQueryReq req) : PageResult<UserListItemVo>` | |
| 257 | +- 内部规范化流程: | |
| 258 | + 1. 应用默认值(page=1, size=20, sortField=tCreateDate, sortOrder=desc, matchMode=contains) | |
| 259 | + 2. 白名单校验:sortField / sortOrder / queryField / matchMode / userType — 不在白名单抛 `BizException(40003)` 或 `BizException(40001)` 按入参类型决定 | |
| 260 | + 3. queryField→sqlQueryColumn 映射;queryValue 转换(对 isDeleted 列:'true'→1, 'false'→0;其他不在 {true,false,0,1} 抛 40001) | |
| 261 | + 4. 越界矫正:先查 `selectByQuery(目标 page)`;若 records 空 && total>0 → 重算 lastPage 再查;响应 page 反映实际页 | |
| 262 | + | |
| 263 | +> userType 入参既可作 explicit query param 也可作 queryField=userType+queryValue。两条路径都要走白名单校验。 | |
| 264 | + | |
| 265 | +- [ ] **Step 1: 写失败测试** 12 个用例覆盖 spec 验收 5-21 | |
| 266 | +- [ ] **Step 2: 实现最小代码** | |
| 267 | +- [ ] **Step 3: 子会话验证 PASS** | |
| 268 | +- [ ] **Step 4: Commit** `feat(usr): UserListService 白名单校验 + 动态查询 + 越界矫正 REQ-USR-004` | |
| 269 | + | |
| 270 | +### Task 5: UserController GET / + 端到端测试 | |
| 271 | + | |
| 272 | +**Files:** | |
| 273 | +- Modify: `backend/src/main/java/com/xly/erp/module/usr/controller/UserController.java`(追加 GET / 方法) | |
| 274 | +- Create: `backend/src/test/java/com/xly/erp/module/usr/controller/UserControllerListTest.java` | |
| 275 | + | |
| 276 | +**API shape:** | |
| 277 | +- `@GetMapping @RequireSuperAdmin list(@Valid UserQueryReq req) : Result<PageResult<UserListItemVo>>` | |
| 278 | +- 用 `@ModelAttribute` 或省略让 Spring 默认从 query 绑定 DTO | |
| 279 | + | |
| 280 | +端到端测试(覆盖 spec § 验收 1-26): | |
| 281 | + | |
| 282 | +GET 路径(admin token): | |
| 283 | +- `list_default_returnsAllUsersSortedByCreateDateDesc` | |
| 284 | +- `list_pagination_secondPage` | |
| 285 | +- `list_sizeOver100_returns400_40001` | |
| 286 | +- `list_pageZero_returns400_40001` | |
| 287 | +- `list_sortByUsernameAsc` | |
| 288 | +- `list_sortFieldInvalid_returns400_40003` | |
| 289 | +- `list_sortOrderInvalid_returns400_40001` | |
| 290 | +- `list_queryByUsernameContains` | |
| 291 | +- `list_queryByUsernameEquals_returnsExactOne` | |
| 292 | +- `list_queryByUsernameNotContains` | |
| 293 | +- `list_queryByEmployeeName_joinsCorrectly` | |
| 294 | +- `list_queryByDepartmentName_multiLevelJoin` | |
| 295 | +- `list_queryByUserType_equals` | |
| 296 | +- `list_queryByIsDeletedTrue_filtersDeleted` | |
| 297 | +- `list_queryFieldInvalid_returns400_40003` | |
| 298 | +- `list_matchModeInvalid_returns400_40003` | |
| 299 | +- `list_queryFieldWithoutValue_skipsCondition` | |
| 300 | +- `list_explicitUserTypeFilter` | |
| 301 | +- `list_explicitUserTypeInvalid_returns400_40001` | |
| 302 | +- `list_explicitIsDeletedFalse_filtersActiveOnly` | |
| 303 | +- `list_composedFilters_andSemantics`(queryField+queryValue + userType + isDeleted) | |
| 304 | +- `list_pageBeyondTotal_returnsLastPage` | |
| 305 | +- `list_normalUserToken_returns403_40301` | |
| 306 | +- `list_noAuthHeader_returns401_40101` | |
| 307 | +- `list_responseDoesNotContainPasswordField` | |
| 308 | +- `list_emptyTable_returnsZeroTotal`(drop + recreate 用户为空时) | |
| 309 | + | |
| 310 | +- [ ] **Step 1: 写失败测试** | |
| 311 | +- [ ] **Step 2: 实现最小代码** | |
| 312 | +- [ ] **Step 3: 子会话验证 PASS** | |
| 313 | +- [ ] **Step 4: Commit** `feat(usr): GET /api/v1/users controller + 端到端测试 REQ-USR-004` | |
| 314 | + | |
| 315 | +--- | |
| 316 | + | |
| 317 | +## 提交计划 | |
| 318 | + | |
| 319 | +| Task | Commit message | | |
| 320 | +|---|---| | |
| 321 | +| 1 | `feat(usr): ErrorCode 新增 40003 + PageResult 通用类 REQ-USR-004` | | |
| 322 | +| 2 | `feat(usr): UserQueryReq + UserListItemVo + PageResult REQ-USR-004` | | |
| 323 | +| 3 | `feat(usr): SysUserMapper 动态查询 XML + JOIN 员工/部门 REQ-USR-004` | | |
| 324 | +| 4 | `feat(usr): UserListService 白名单校验 + 动态查询 + 越界矫正 REQ-USR-004` | | |
| 325 | +| 5 | `feat(usr): GET /api/v1/users controller + 端到端测试 REQ-USR-004` | | ... | ... |
docs/superpowers/reviews/2026-05-15-REQ-USR-004.md
0 → 100644
| 1 | +--- | |
| 2 | +req_id: REQ-USR-004 | |
| 3 | +date: 2026-05-15 | |
| 4 | +round: 2 | |
| 5 | +reviewer: superpower-code-reviewer | |
| 6 | +--- | |
| 7 | + | |
| 8 | +# Review: REQ-USR-004 — round 2 | |
| 9 | + | |
| 10 | +## 结论 | |
| 11 | +approve | |
| 12 | + | |
| 13 | +## Must-fix | |
| 14 | +(无) | |
| 15 | + | |
| 16 | +## Nice-to-have | |
| 17 | + | |
| 18 | +- backend/src/main/java/com/xly/erp/module/usr/service/impl/UserListServiceImpl.java:148 — `normalizeQueryValue` 用全限定 `java.time.LocalDate.parse` 而非顶部 import,纯风格瑕疵 | |
| 19 | +- matchMode 白名单校验在 forced-equals 覆盖之前;调用方传 matchMode=contains + queryField=isDeleted 时白名单接受 contains 再静默覆盖为 equals — 行为正确但稍不透明,可加 logger.debug 留痕 | |
| 20 | +- UserListServiceImplTest 末尾 `@Autowired JdbcTemplate jdbc` 字段定义在测试方法之后,风格不一致;建议挪到类顶部 | |
| 21 | +- round 1 已标记『推迟』的 4 项保持不变(queryField=userType 不走 USER_TYPES 白名单;UserQueryParams public 可变字段;list_emptyTable_returnsZeroTotal 命名;mapper ORDER BY 硬编码 u.* 前缀) | |
| 22 | + | |
| 23 | +## 反例 / 测试覆盖缺口 | |
| 24 | + | |
| 25 | +Round 2 测试覆盖完整:spec § 业务规则 3 的 isDeleted/lastLoginDate matchMode 强制 equals + 类型归一化由 3 个新测试明确断言;spec § 验收 1-26 由 198+3 测试映射;spec § 验收 26 空表场景由 list_emptyTable_returnsZeroTotal(虽命名不准)覆盖。Reviewer 子会话无本地 MySQL,未独立复跑 mvn test;信任 commit 8bf84c9 + 主会话 feature-verify 报告的 201/0 结果。 | |
| 26 | + | |
| 27 | +## 本轮变更归档 | |
| 28 | + | |
| 29 | +Round 1 全部修复落地: | |
| 30 | + | |
| 31 | +| # | 项目 | 状态 | | |
| 32 | +|---|------|-----| | |
| 33 | +| M1 | EQUALS_ONLY_FIELDS 强制 matchMode=equals | ✓ 仅在 queryField+queryValue 都非空时覆盖,scoped 严格,不影响其他路径 | | |
| 34 | +| M2 | lastLoginDate 类型归一化 | ✓ 支持 LocalDateTime / LocalDate,非法值抛 40001 | | |
| 35 | +| M3 | queryValue 用 isBlank 判空 | ✓ | | |
| 36 | +| M4 | docs/05 错误码补 sortField + 40101 | ✓ | | |
| 37 | +| Test | 新增 3 个回归测试 | ✓ | | |
| 38 | + | |
| 39 | +未引入新回归。verdict=approve。 | ... | ... |
docs/superpowers/specs/2026-05-15-REQ-USR-004.md
0 → 100644
| 1 | +--- | |
| 2 | +req_id: REQ-USR-004 | |
| 3 | +date: 2026-05-15 | |
| 4 | +module: module_usr | |
| 5 | +--- | |
| 6 | + | |
| 7 | +# Spec: REQ-USR-004 — 查询用户 | |
| 8 | + | |
| 9 | +## 目标 | |
| 10 | + | |
| 11 | +`GET /api/v1/users`:超级管理员分页 + 多字段筛选 + 排序查询用户列表,单条记录聚合 sys_user + sys_employee + sys_department 信息(部门名、员工名)。只读,无写副作用,不返回密码。 | |
| 12 | + | |
| 13 | +## 输入 / 触发 | |
| 14 | + | |
| 15 | +HTTP 入口 `GET /api/v1/users`,要求 `Authorization: Bearer <accessToken>` + `userType=SUPER_ADMIN`。 | |
| 16 | + | |
| 17 | +**Query 参数**(全部可选): | |
| 18 | + | |
| 19 | +| 参数 | 类型 | 默认 | 校验 | | |
| 20 | +|---|---|---|---| | |
| 21 | +| `page` | int | 1 | `@Min(1)`;< 1 返 40001;大于总页数返"最后一页"数据(不是空列表) | | |
| 22 | +| `size` | int | 20 | `@Min(1) @Max(100)`;越界返 40001 | | |
| 23 | +| `sortField` | string | `tCreateDate` | 白名单:`tCreateDate` / `tLastLoginDate` / `sUsername` / `sUserCode`;不在白名单返 40003 | | |
| 24 | +| `sortOrder` | string | `desc` | `asc` / `desc`;其他值返 40001 | | |
| 25 | +| `queryField` | string | (不筛选) | 白名单:`username` / `employeeName` / `userCode` / `departmentName` / `userType` / `isDeleted` / `lastLoginDate` / `createdBy`;不在白名单返 40003 | | |
| 26 | +| `matchMode` | string | `contains` | `contains` / `notContains` / `equals`;不在白名单返 40003 | | |
| 27 | +| `queryValue` | string | (不筛选) | 任意字符串;空字符串或 null 视为不应用此条件;与 queryField 配对使用——只提供 queryField 不提供 queryValue 也视为不应用 | | |
| 28 | +| `userType` | string | (不筛选) | 若提供,必须是 `NORMAL` / `SUPER_ADMIN`;其他返 40001 | | |
| 29 | +| `isDeleted` | boolean | (不筛选) | true / false | | |
| 30 | + | |
| 31 | +> **复合规则**:所有筛选条件用 `AND` 拼接:queryField+queryValue 提供时构成一条动态条件;userType / isDeleted 作为额外固定条件叠加。 | |
| 32 | + | |
| 33 | +## 输出 / 结果 | |
| 34 | + | |
| 35 | +**成功 200**:`Result<PageResult<UserListItemVo>>` | |
| 36 | + | |
| 37 | +```json | |
| 38 | +{ | |
| 39 | + "code": 200, | |
| 40 | + "message": "操作成功", | |
| 41 | + "data": { | |
| 42 | + "records": [ | |
| 43 | + { | |
| 44 | + "userId": 42, | |
| 45 | + "username": "alice", | |
| 46 | + "employeeName": "张三", | |
| 47 | + "userCode": "U001", | |
| 48 | + "departmentName": "技术部", | |
| 49 | + "userType": "NORMAL", | |
| 50 | + "language": "zh-CN", | |
| 51 | + "isDeleted": false, | |
| 52 | + "lastLoginDate": "2026-05-15T08:00:00", | |
| 53 | + "createdBy": "admin", | |
| 54 | + "createdDate": "2026-05-15T07:00:00" | |
| 55 | + } | |
| 56 | + ], | |
| 57 | + "total": 17, | |
| 58 | + "page": 1, | |
| 59 | + "size": 20 | |
| 60 | + } | |
| 61 | +} | |
| 62 | +``` | |
| 63 | + | |
| 64 | +字段: | |
| 65 | +- `userId` = sys_user.iIncrement | |
| 66 | +- `username` / `userCode` / `userType` / `language` / `isDeleted` / `lastLoginDate` / `createdBy` / `createdDate` 直接来自 sys_user | |
| 67 | +- `employeeName` = LEFT JOIN sys_employee.sEmployeeName(用户未关联职员时返回 null) | |
| 68 | +- `departmentName` = LEFT JOIN sys_department.sDepartmentName via sys_employee.iDepartmentId(未关联或部门软删时返回 null) | |
| 69 | + | |
| 70 | +**失败**: | |
| 71 | + | |
| 72 | +| HTTP | code | 含义 | 触发 | | |
| 73 | +|---|---|---|---| | |
| 74 | +| 400 | 40001 | 分页 / 类型 / 排序参数错误 | page<1 / size<1 / size>100 / sortOrder 非 asc-desc / userType 非枚举 | | |
| 75 | +| 400 | 40003 | queryField / matchMode / sortField 不在白名单 | 用户传非法枚举值 | | |
| 76 | +| 401 | 40101 | 未携带或无效 Token | 鉴权层 | | |
| 77 | +| 403 | 40301 | 非超级管理员 | 角色守卫 | | |
| 78 | + | |
| 79 | +## 业务规则 | |
| 80 | + | |
| 81 | +1. **鉴权**:复用 `@RequireSuperAdmin` + JwtHandlerInterceptor。 | |
| 82 | +2. **白名单映射**(service 层维护静态 Map<String, String>): | |
| 83 | + - `sortField` 入参 → SQL 列名:`tCreateDate`/`tLastLoginDate`/`sUsername`/`sUserCode` 均与列名同名(直接使用)。**禁止用户传任意列名**——必须白名单匹配。 | |
| 84 | + - `queryField` 入参 → SQL 列引用(含 JOIN 别名): | |
| 85 | + - `username` → `u.sUsername` | |
| 86 | + - `employeeName` → `e.sEmployeeName` | |
| 87 | + - `userCode` → `u.sUserCode` | |
| 88 | + - `departmentName` → `d.sDepartmentName` | |
| 89 | + - `userType` → `u.sUserType` | |
| 90 | + - `isDeleted` → `u.iIsDeleted` | |
| 91 | + - `lastLoginDate` → `u.tLastLoginDate` | |
| 92 | + - `createdBy` → `u.sCreatedBy` | |
| 93 | +3. **matchMode 处理**: | |
| 94 | + - `contains` → `LIKE CONCAT('%', #{queryValue}, '%')` | |
| 95 | + - `notContains` → `NOT LIKE CONCAT('%', #{queryValue}, '%') OR <col> IS NULL` | |
| 96 | + - `equals` → `= #{queryValue}` | |
| 97 | + - 对 `isDeleted`(int)/ `lastLoginDate`(datetime)这类非字符串字段:无论 matchMode 一律按 `equals` 处理(service 层规范化 queryValue 为对应类型;非法值返 40001)。 | |
| 98 | +4. **空 queryValue**:queryField 给了但 queryValue 为 null / 空串 → 跳过此条件,不参与 WHERE。 | |
| 99 | +5. **空 queryField + 有 queryValue**:跳过(缺 queryField 没法应用)。 | |
| 100 | +6. **越界 page**:先按入参 page/size 查;若返回 records 为空但 total > 0,service 层用 `lastPage = (total + size - 1) / size` 重新查一次并返回 lastPage 的数据。响应 `page` 字段反映**实际返回的页码**(即 lastPage),让前端能感知矫正。 | |
| 101 | +7. **排序 SQL**:在 ORDER BY 前用白名单映射列名 + asc/desc 拼接;用 MyBatis 字符串替换(`${}`)但只限白名单值(白名单已校验,安全)。 | |
| 102 | +8. **不返回密码**:UserListItemVo 不含 sPasswordHash 字段;mapper SELECT 列表显式列出业务列。 | |
| 103 | +9. **N+1 防御**:JOIN 而非多次查询;单查询返回所有字段。 | |
| 104 | +10. **空查询**:所有筛选都空时返回全表分页(admin 用例需要"全部 用户"视图)。 | |
| 105 | + | |
| 106 | +## 边界与约束 | |
| 107 | + | |
| 108 | +- **白名单兜底**:所有动态字段(queryField / matchMode / sortField / sortOrder)必须 service 层先做白名单检查,再拼到 SQL;用户输入永远不直接进 ORDER BY / SELECT。 | |
| 109 | +- **MyBatis 注入**:用 `#{}` 参数化输入;只有列名 / 排序方向用 `${}`(已白名单约束)。 | |
| 110 | +- **size 上限 100**:与 docs/04 § 3.2 一致。 | |
| 111 | +- **作废用户参与查询**:默认不过滤;用户通过 `isDeleted=false` 显式过滤启用账号。 | |
| 112 | +- **登录追踪**:本 REQ 不修改 tLastLoginDate / iFailedLoginCount / tLockUntil — 纯查询。 | |
| 113 | +- **不实现**: | |
| 114 | + - 多字段同时筛选(spec 仅允许单一 queryField,多字段筛选推迟) | |
| 115 | + - 自定义列展示(前端事) | |
| 116 | + - 导出 / 导入(YAGNI) | |
| 117 | + | |
| 118 | +## 依赖的 schema 表 / 字段 | |
| 119 | + | |
| 120 | +只读 `sys_user`(V1 已建): | |
| 121 | +- 读列:iIncrement, sUsername, sUserCode, sUserType, sLanguage, iIsDeleted, tLastLoginDate, sCreatedBy, tCreateDate, iEmployeeId | |
| 122 | +- 排序 / 筛选列:sUsername, sUserCode, sUserType, iIsDeleted, tLastLoginDate, sCreatedBy, tCreateDate | |
| 123 | + | |
| 124 | +只读 `sys_employee`(V1 已建): | |
| 125 | +- LEFT JOIN:iIncrement = u.iEmployeeId | |
| 126 | +- 读 / 筛选列:sEmployeeName, iDepartmentId | |
| 127 | + | |
| 128 | +只读 `sys_department`(V1 已建): | |
| 129 | +- LEFT JOIN:iIncrement = e.iDepartmentId | |
| 130 | +- 读 / 筛选列:sDepartmentName | |
| 131 | + | |
| 132 | +**本 REQ 不需要新增 migration**。 | |
| 133 | + | |
| 134 | +## 依赖的接口 | |
| 135 | + | |
| 136 | +- 本 REQ 提供:`GET /api/v1/users` | |
| 137 | + | |
| 138 | +## 验收标准 | |
| 139 | + | |
| 140 | +后端集成测试: | |
| 141 | + | |
| 142 | +1. **admin token + 默认参数** → 200,返回所有用户(按 tCreateDate desc);total = 实际行数;不含密码字段 | |
| 143 | +2. **page=2 size=2** → 返回第 2 页 2 条;page=2,total 不变 | |
| 144 | +3. **size > 100** → 400 / 40001 | |
| 145 | +4. **page < 1** → 400 / 40001 | |
| 146 | +5. **sortField=sUsername sortOrder=asc** → 按 username 升序返回 | |
| 147 | +6. **sortField=nonExisting** → 400 / 40003 | |
| 148 | +7. **sortOrder=foo** → 400 / 40001 | |
| 149 | +8. **queryField=username matchMode=contains queryValue=ali** → 返回含 "ali" 的用户 | |
| 150 | +9. **queryField=username matchMode=equals queryValue=alice** → 仅返回 alice | |
| 151 | +10. **queryField=username matchMode=notContains queryValue=ali** → 不含 alice 但含 admin / bob_deleted | |
| 152 | +11. **queryField=employeeName matchMode=contains queryValue=张** → 返回员工名含张的用户(JOIN) | |
| 153 | +12. **queryField=departmentName matchMode=equals queryValue=技术部** → 返回部门=技术部的用户(多级 JOIN) | |
| 154 | +13. **queryField=userType matchMode=equals queryValue=SUPER_ADMIN** → 仅 admin | |
| 155 | +14. **queryField=isDeleted matchMode=equals queryValue=true** → 仅 bob_deleted | |
| 156 | +15. **queryField=invalid** → 400 / 40003 | |
| 157 | +16. **matchMode=invalid** → 400 / 40003 | |
| 158 | +17. **queryField 提供但 queryValue 为空** → 跳过条件,返回全表(不报错) | |
| 159 | +18. **userType=NORMAL** explicit 参数 → 仅 NORMAL 用户 | |
| 160 | +19. **userType=INVALID** → 400 / 40001 | |
| 161 | +20. **isDeleted=false** explicit → 仅启用用户 | |
| 162 | +21. **复合:queryField=username queryValue=al userType=NORMAL isDeleted=false** → 仅匹配三条件的用户(alice) | |
| 163 | +22. **page 越界(page=999 size=10,total=3)** → 200,返回最后一页(page=1,1 个 records 或更少),total=3 | |
| 164 | +23. **NORMAL token** → 403 / 40301 | |
| 165 | +24. **无 token** → 401 / 40101 | |
| 166 | +25. **响应不含 sPasswordHash 字段** → JSON 没有 password 相关字段 | |
| 167 | +26. **空表(无用户)** → 200,records=[],total=0 | ... | ... |