初始提交:企业级日报系统完整代码
功能特性: - JWT用户认证系统 - 日报CRUD管理 - 三级权限控制 - 多维度搜索过滤 - 统计分析功能 - 评论互动系统 - 响应式Cool Admin界面 - 暗色主题支持 技术栈: - 后端:Django 4.2.7 + DRF + SimpleJWT - 前端:Vue 3 + Element Plus + Pinia - 数据库:SQLite/PostgreSQL - 部署:Docker + Nginx 包含内容: - 完整的后端API代码 - 现代化前端界面 - 数据库迁移文件 - 部署脚本和文档 - 演示页面和测试工具
This commit is contained in:
50
backend/Dockerfile
Normal file
50
backend/Dockerfile
Normal file
@@ -0,0 +1,50 @@
|
||||
# 使用Python官方镜像
|
||||
FROM python:3.11-slim
|
||||
|
||||
# 设置工作目录
|
||||
WORKDIR /app
|
||||
|
||||
# 设置环境变量
|
||||
ENV PYTHONDONTWRITEBYTECODE=1 \
|
||||
PYTHONUNBUFFERED=1 \
|
||||
PIP_NO_CACHE_DIR=1 \
|
||||
PIP_DISABLE_PIP_VERSION_CHECK=1
|
||||
|
||||
# 安装系统依赖
|
||||
RUN apt-get update \
|
||||
&& apt-get install -y --no-install-recommends \
|
||||
build-essential \
|
||||
libpq-dev \
|
||||
gettext \
|
||||
curl \
|
||||
&& apt-get clean \
|
||||
&& rm -rf /var/lib/apt/lists/*
|
||||
|
||||
# 复制依赖文件
|
||||
COPY requirements.txt .
|
||||
|
||||
# 安装Python依赖
|
||||
RUN pip install --upgrade pip \
|
||||
&& pip install -r requirements.txt
|
||||
|
||||
# 复制项目文件
|
||||
COPY . .
|
||||
|
||||
# 创建静态文件和媒体文件目录
|
||||
RUN mkdir -p staticfiles media
|
||||
|
||||
# 设置权限
|
||||
RUN chmod +x deploy.py create_superuser.py
|
||||
|
||||
# 收集静态文件
|
||||
RUN python manage.py collectstatic --noinput
|
||||
|
||||
# 健康检查
|
||||
HEALTHCHECK --interval=30s --timeout=30s --start-period=5s --retries=3 \
|
||||
CMD curl -f http://localhost:8000/api/auth/login/ || exit 1
|
||||
|
||||
# 暴露端口
|
||||
EXPOSE 8000
|
||||
|
||||
# 启动命令
|
||||
CMD ["gunicorn", "config.wsgi:application", "--bind", "0.0.0.0:8000", "--workers", "4"]
|
1
backend/accounts/__init__.py
Normal file
1
backend/accounts/__init__.py
Normal file
@@ -0,0 +1 @@
|
||||
# 用户认证应用
|
25
backend/accounts/admin.py
Normal file
25
backend/accounts/admin.py
Normal file
@@ -0,0 +1,25 @@
|
||||
from django.contrib import admin
|
||||
from django.contrib.auth.admin import UserAdmin as BaseUserAdmin
|
||||
from .models import User
|
||||
|
||||
|
||||
@admin.register(User)
|
||||
class UserAdmin(BaseUserAdmin):
|
||||
"""用户管理"""
|
||||
list_display = ('username', 'email', 'first_name', 'last_name',
|
||||
'department', 'position', 'is_staff', 'is_active', 'date_joined')
|
||||
list_filter = ('is_staff', 'is_superuser', 'is_active', 'department')
|
||||
search_fields = ('username', 'first_name', 'last_name', 'email', 'phone')
|
||||
ordering = ('-date_joined',)
|
||||
|
||||
fieldsets = BaseUserAdmin.fieldsets + (
|
||||
('扩展信息', {
|
||||
'fields': ('phone', 'department', 'position', 'avatar')
|
||||
}),
|
||||
)
|
||||
|
||||
add_fieldsets = BaseUserAdmin.add_fieldsets + (
|
||||
('扩展信息', {
|
||||
'fields': ('email', 'first_name', 'last_name', 'phone', 'department', 'position')
|
||||
}),
|
||||
)
|
7
backend/accounts/apps.py
Normal file
7
backend/accounts/apps.py
Normal file
@@ -0,0 +1,7 @@
|
||||
from django.apps import AppConfig
|
||||
|
||||
|
||||
class AccountsConfig(AppConfig):
|
||||
default_auto_field = 'django.db.models.BigAutoField'
|
||||
name = 'accounts'
|
||||
verbose_name = '用户管理'
|
49
backend/accounts/migrations/0001_initial.py
Normal file
49
backend/accounts/migrations/0001_initial.py
Normal file
@@ -0,0 +1,49 @@
|
||||
# Generated by Django 4.2.7 on 2025-09-13 05:47
|
||||
|
||||
import django.contrib.auth.models
|
||||
import django.contrib.auth.validators
|
||||
from django.db import migrations, models
|
||||
import django.utils.timezone
|
||||
|
||||
|
||||
class Migration(migrations.Migration):
|
||||
|
||||
initial = True
|
||||
|
||||
dependencies = [
|
||||
('auth', '0012_alter_user_first_name_max_length'),
|
||||
]
|
||||
|
||||
operations = [
|
||||
migrations.CreateModel(
|
||||
name='User',
|
||||
fields=[
|
||||
('id', models.BigAutoField(auto_created=True, primary_key=True, serialize=False, verbose_name='ID')),
|
||||
('password', models.CharField(max_length=128, verbose_name='password')),
|
||||
('last_login', models.DateTimeField(blank=True, null=True, verbose_name='last login')),
|
||||
('is_superuser', models.BooleanField(default=False, help_text='Designates that this user has all permissions without explicitly assigning them.', verbose_name='superuser status')),
|
||||
('username', models.CharField(error_messages={'unique': 'A user with that username already exists.'}, help_text='Required. 150 characters or fewer. Letters, digits and @/./+/-/_ only.', max_length=150, unique=True, validators=[django.contrib.auth.validators.UnicodeUsernameValidator()], verbose_name='username')),
|
||||
('first_name', models.CharField(blank=True, max_length=150, verbose_name='first name')),
|
||||
('last_name', models.CharField(blank=True, max_length=150, verbose_name='last name')),
|
||||
('email', models.EmailField(blank=True, max_length=254, verbose_name='email address')),
|
||||
('is_staff', models.BooleanField(default=False, help_text='Designates whether the user can log into this admin site.', verbose_name='staff status')),
|
||||
('is_active', models.BooleanField(default=True, help_text='Designates whether this user should be treated as active. Unselect this instead of deleting accounts.', verbose_name='active')),
|
||||
('date_joined', models.DateTimeField(default=django.utils.timezone.now, verbose_name='date joined')),
|
||||
('phone', models.CharField(blank=True, max_length=11, null=True, verbose_name='手机号码')),
|
||||
('department', models.CharField(blank=True, max_length=100, null=True, verbose_name='部门')),
|
||||
('position', models.CharField(blank=True, max_length=100, null=True, verbose_name='职位')),
|
||||
('created_at', models.DateTimeField(auto_now_add=True, verbose_name='创建时间')),
|
||||
('updated_at', models.DateTimeField(auto_now=True, verbose_name='更新时间')),
|
||||
('groups', models.ManyToManyField(blank=True, help_text='The groups this user belongs to.', related_name='custom_user_set', related_query_name='custom_user', to='auth.group', verbose_name='groups')),
|
||||
('user_permissions', models.ManyToManyField(blank=True, help_text='Specific permissions for this user.', related_name='custom_user_set', related_query_name='custom_user', to='auth.permission', verbose_name='user permissions')),
|
||||
],
|
||||
options={
|
||||
'verbose_name': '用户',
|
||||
'verbose_name_plural': '用户',
|
||||
'db_table': 'auth_user_custom',
|
||||
},
|
||||
managers=[
|
||||
('objects', django.contrib.auth.models.UserManager()),
|
||||
],
|
||||
),
|
||||
]
|
0
backend/accounts/migrations/__init__.py
Normal file
0
backend/accounts/migrations/__init__.py
Normal file
39
backend/accounts/models.py
Normal file
39
backend/accounts/models.py
Normal file
@@ -0,0 +1,39 @@
|
||||
from django.contrib.auth.models import AbstractUser
|
||||
from django.db import models
|
||||
|
||||
|
||||
class User(AbstractUser):
|
||||
"""扩展用户模型"""
|
||||
phone = models.CharField('手机号码', max_length=11, blank=True, null=True)
|
||||
department = models.CharField('部门', max_length=100, blank=True, null=True)
|
||||
position = models.CharField('职位', max_length=100, blank=True, null=True)
|
||||
# 暂时移除头像字段,避免Pillow依赖
|
||||
# avatar = models.ImageField('头像', upload_to='avatars/', blank=True, null=True)
|
||||
created_at = models.DateTimeField('创建时间', auto_now_add=True)
|
||||
updated_at = models.DateTimeField('更新时间', auto_now=True)
|
||||
|
||||
# 解决反向访问器冲突
|
||||
groups = models.ManyToManyField(
|
||||
'auth.Group',
|
||||
verbose_name='groups',
|
||||
blank=True,
|
||||
help_text='The groups this user belongs to.',
|
||||
related_name="custom_user_set",
|
||||
related_query_name="custom_user",
|
||||
)
|
||||
user_permissions = models.ManyToManyField(
|
||||
'auth.Permission',
|
||||
verbose_name='user permissions',
|
||||
blank=True,
|
||||
help_text='Specific permissions for this user.',
|
||||
related_name="custom_user_set",
|
||||
related_query_name="custom_user",
|
||||
)
|
||||
|
||||
class Meta:
|
||||
verbose_name = '用户'
|
||||
verbose_name_plural = verbose_name
|
||||
db_table = 'auth_user_custom'
|
||||
|
||||
def __str__(self):
|
||||
return f'{self.username} - {self.first_name or self.username}'
|
74
backend/accounts/serializers.py
Normal file
74
backend/accounts/serializers.py
Normal file
@@ -0,0 +1,74 @@
|
||||
from rest_framework import serializers
|
||||
from django.contrib.auth import authenticate
|
||||
from django.contrib.auth.password_validation import validate_password
|
||||
from .models import User
|
||||
|
||||
|
||||
class UserRegistrationSerializer(serializers.ModelSerializer):
|
||||
"""用户注册序列化器"""
|
||||
password = serializers.CharField(write_only=True, validators=[validate_password])
|
||||
password_confirm = serializers.CharField(write_only=True)
|
||||
|
||||
class Meta:
|
||||
model = User
|
||||
fields = ('username', 'email', 'first_name', 'last_name',
|
||||
'phone', 'department', 'position', 'password', 'password_confirm')
|
||||
|
||||
def validate(self, attrs):
|
||||
if attrs['password'] != attrs['password_confirm']:
|
||||
raise serializers.ValidationError("密码不一致")
|
||||
return attrs
|
||||
|
||||
def create(self, validated_data):
|
||||
validated_data.pop('password_confirm', None)
|
||||
user = User.objects.create_user(**validated_data)
|
||||
return user
|
||||
|
||||
|
||||
class UserLoginSerializer(serializers.Serializer):
|
||||
"""用户登录序列化器"""
|
||||
username = serializers.CharField()
|
||||
password = serializers.CharField(write_only=True)
|
||||
|
||||
def validate(self, attrs):
|
||||
username = attrs.get('username')
|
||||
password = attrs.get('password')
|
||||
|
||||
if username and password:
|
||||
user = authenticate(username=username, password=password)
|
||||
if not user:
|
||||
raise serializers.ValidationError('用户名或密码错误')
|
||||
if not user.is_active:
|
||||
raise serializers.ValidationError('用户账号已被禁用')
|
||||
attrs['user'] = user
|
||||
else:
|
||||
raise serializers.ValidationError('用户名和密码不能为空')
|
||||
|
||||
return attrs
|
||||
|
||||
|
||||
class UserProfileSerializer(serializers.ModelSerializer):
|
||||
"""用户信息序列化器"""
|
||||
full_name = serializers.SerializerMethodField()
|
||||
|
||||
class Meta:
|
||||
model = User
|
||||
fields = ('id', 'username', 'email', 'first_name', 'last_name',
|
||||
'full_name', 'phone', 'department', 'position', 'avatar',
|
||||
'is_staff', 'is_superuser', 'date_joined')
|
||||
read_only_fields = ('id', 'username', 'is_staff', 'is_superuser', 'date_joined')
|
||||
|
||||
def get_full_name(self, obj):
|
||||
return f'{obj.first_name} {obj.last_name}'.strip() or obj.username
|
||||
|
||||
|
||||
class UserListSerializer(serializers.ModelSerializer):
|
||||
"""用户列表序列化器"""
|
||||
full_name = serializers.SerializerMethodField()
|
||||
|
||||
class Meta:
|
||||
model = User
|
||||
fields = ('id', 'username', 'full_name', 'email', 'department', 'position', 'is_active')
|
||||
|
||||
def get_full_name(self, obj):
|
||||
return f'{obj.first_name} {obj.last_name}'.strip() or obj.username
|
14
backend/accounts/urls.py
Normal file
14
backend/accounts/urls.py
Normal file
@@ -0,0 +1,14 @@
|
||||
from django.urls import path
|
||||
from rest_framework_simplejwt.views import TokenRefreshView
|
||||
from . import views
|
||||
|
||||
app_name = 'accounts'
|
||||
|
||||
urlpatterns = [
|
||||
path('register/', views.register, name='register'),
|
||||
path('login/', views.login, name='login'),
|
||||
path('logout/', views.logout, name='logout'),
|
||||
path('token/refresh/', TokenRefreshView.as_view(), name='token_refresh'),
|
||||
path('profile/', views.UserProfileView.as_view(), name='profile'),
|
||||
path('users/', views.UserListView.as_view(), name='user_list'),
|
||||
]
|
88
backend/accounts/views.py
Normal file
88
backend/accounts/views.py
Normal file
@@ -0,0 +1,88 @@
|
||||
from rest_framework import status, generics
|
||||
from rest_framework.decorators import api_view, permission_classes
|
||||
from rest_framework.permissions import AllowAny, IsAuthenticated
|
||||
from rest_framework.response import Response
|
||||
from rest_framework_simplejwt.tokens import RefreshToken
|
||||
from django.contrib.auth import get_user_model
|
||||
from .serializers import (
|
||||
UserRegistrationSerializer,
|
||||
UserLoginSerializer,
|
||||
UserProfileSerializer,
|
||||
UserListSerializer
|
||||
)
|
||||
|
||||
User = get_user_model()
|
||||
|
||||
|
||||
@api_view(['POST'])
|
||||
@permission_classes([AllowAny])
|
||||
def register(request):
|
||||
"""用户注册"""
|
||||
serializer = UserRegistrationSerializer(data=request.data)
|
||||
if serializer.is_valid():
|
||||
user = serializer.save()
|
||||
refresh = RefreshToken.for_user(user)
|
||||
return Response({
|
||||
'message': '注册成功',
|
||||
'user': UserProfileSerializer(user).data,
|
||||
'tokens': {
|
||||
'refresh': str(refresh),
|
||||
'access': str(refresh.access_token),
|
||||
}
|
||||
}, status=status.HTTP_201_CREATED)
|
||||
return Response(serializer.errors, status=status.HTTP_400_BAD_REQUEST)
|
||||
|
||||
|
||||
@api_view(['POST'])
|
||||
@permission_classes([AllowAny])
|
||||
def login(request):
|
||||
"""用户登录"""
|
||||
serializer = UserLoginSerializer(data=request.data)
|
||||
if serializer.is_valid():
|
||||
user = serializer.validated_data['user']
|
||||
refresh = RefreshToken.for_user(user)
|
||||
return Response({
|
||||
'message': '登录成功',
|
||||
'user': UserProfileSerializer(user).data,
|
||||
'tokens': {
|
||||
'refresh': str(refresh),
|
||||
'access': str(refresh.access_token),
|
||||
}
|
||||
})
|
||||
return Response(serializer.errors, status=status.HTTP_400_BAD_REQUEST)
|
||||
|
||||
|
||||
@api_view(['POST'])
|
||||
@permission_classes([IsAuthenticated])
|
||||
def logout(request):
|
||||
"""用户登出"""
|
||||
try:
|
||||
refresh_token = request.data.get('refresh_token')
|
||||
if refresh_token:
|
||||
token = RefreshToken(refresh_token)
|
||||
token.blacklist()
|
||||
return Response({'message': '登出成功'})
|
||||
except Exception as e:
|
||||
return Response({'error': '登出失败'}, status=status.HTTP_400_BAD_REQUEST)
|
||||
|
||||
|
||||
class UserProfileView(generics.RetrieveUpdateAPIView):
|
||||
"""用户信息查看和更新"""
|
||||
serializer_class = UserProfileSerializer
|
||||
permission_classes = [IsAuthenticated]
|
||||
|
||||
def get_object(self):
|
||||
return self.request.user
|
||||
|
||||
|
||||
class UserListView(generics.ListAPIView):
|
||||
"""用户列表(仅管理员可访问)"""
|
||||
queryset = User.objects.filter(is_active=True)
|
||||
serializer_class = UserListSerializer
|
||||
permission_classes = [IsAuthenticated]
|
||||
|
||||
def get_queryset(self):
|
||||
# 只有管理员可以查看所有用户列表
|
||||
if self.request.user.is_staff:
|
||||
return super().get_queryset()
|
||||
return User.objects.filter(id=self.request.user.id)
|
1
backend/config/__init__.py
Normal file
1
backend/config/__init__.py
Normal file
@@ -0,0 +1 @@
|
||||
# Django配置包
|
211
backend/config/settings.py
Normal file
211
backend/config/settings.py
Normal file
@@ -0,0 +1,211 @@
|
||||
"""
|
||||
Django settings for daily report system project.
|
||||
"""
|
||||
|
||||
import os
|
||||
from pathlib import Path
|
||||
from decouple import config
|
||||
from datetime import timedelta
|
||||
|
||||
# Build paths inside the project like this: BASE_DIR / 'subdir'.
|
||||
BASE_DIR = Path(__file__).resolve().parent.parent
|
||||
|
||||
# SECURITY WARNING: keep the secret key used in production secret!
|
||||
SECRET_KEY = config('SECRET_KEY', default='django-insecure-your-secret-key-here')
|
||||
|
||||
# SECURITY WARNING: don't run with debug turned on in production!
|
||||
DEBUG = config('DEBUG', default=True, cast=bool)
|
||||
|
||||
ALLOWED_HOSTS = ['*']
|
||||
|
||||
# Application definition
|
||||
INSTALLED_APPS = [
|
||||
'django.contrib.admin',
|
||||
'django.contrib.auth',
|
||||
'django.contrib.contenttypes',
|
||||
'django.contrib.sessions',
|
||||
'django.contrib.messages',
|
||||
'django.contrib.staticfiles',
|
||||
|
||||
# Third party apps
|
||||
'rest_framework',
|
||||
'rest_framework_simplejwt',
|
||||
'corsheaders',
|
||||
'django_filters',
|
||||
|
||||
# Local apps
|
||||
'daily_report',
|
||||
'accounts',
|
||||
]
|
||||
|
||||
MIDDLEWARE = [
|
||||
'corsheaders.middleware.CorsMiddleware',
|
||||
'django.middleware.security.SecurityMiddleware',
|
||||
'django.contrib.sessions.middleware.SessionMiddleware',
|
||||
'django.middleware.common.CommonMiddleware',
|
||||
'django.middleware.csrf.CsrfViewMiddleware',
|
||||
'django.contrib.auth.middleware.AuthenticationMiddleware',
|
||||
'django.contrib.messages.middleware.MessageMiddleware',
|
||||
'django.middleware.clickjacking.XFrameOptionsMiddleware',
|
||||
]
|
||||
|
||||
ROOT_URLCONF = 'config.urls'
|
||||
|
||||
TEMPLATES = [
|
||||
{
|
||||
'BACKEND': 'django.template.backends.django.DjangoTemplates',
|
||||
'DIRS': [],
|
||||
'APP_DIRS': True,
|
||||
'OPTIONS': {
|
||||
'context_processors': [
|
||||
'django.template.context_processors.debug',
|
||||
'django.template.context_processors.request',
|
||||
'django.contrib.auth.context_processors.auth',
|
||||
'django.contrib.messages.context_processors.messages',
|
||||
],
|
||||
},
|
||||
},
|
||||
]
|
||||
|
||||
WSGI_APPLICATION = 'config.wsgi.application'
|
||||
|
||||
# Database
|
||||
DATABASES = {
|
||||
'default': {
|
||||
'ENGINE': 'django.db.backends.sqlite3',
|
||||
'NAME': BASE_DIR / 'db.sqlite3',
|
||||
}
|
||||
}
|
||||
|
||||
# Password validation
|
||||
AUTH_PASSWORD_VALIDATORS = [
|
||||
{
|
||||
'NAME': 'django.contrib.auth.password_validation.UserAttributeSimilarityValidator',
|
||||
},
|
||||
{
|
||||
'NAME': 'django.contrib.auth.password_validation.MinimumLengthValidator',
|
||||
},
|
||||
{
|
||||
'NAME': 'django.contrib.auth.password_validation.CommonPasswordValidator',
|
||||
},
|
||||
{
|
||||
'NAME': 'django.contrib.auth.password_validation.NumericPasswordValidator',
|
||||
},
|
||||
]
|
||||
|
||||
# Internationalization
|
||||
LANGUAGE_CODE = 'zh-hans'
|
||||
TIME_ZONE = 'Asia/Shanghai'
|
||||
USE_I18N = True
|
||||
USE_TZ = True
|
||||
|
||||
# Static files (CSS, JavaScript, Images)
|
||||
STATIC_URL = '/static/'
|
||||
STATIC_ROOT = os.path.join(BASE_DIR, 'staticfiles')
|
||||
|
||||
MEDIA_URL = '/media/'
|
||||
MEDIA_ROOT = os.path.join(BASE_DIR, 'media')
|
||||
|
||||
# Default primary key field type
|
||||
DEFAULT_AUTO_FIELD = 'django.db.models.BigAutoField'
|
||||
|
||||
# 自定义用户模型
|
||||
AUTH_USER_MODEL = 'accounts.User'
|
||||
|
||||
# Django REST Framework
|
||||
REST_FRAMEWORK = {
|
||||
'DEFAULT_AUTHENTICATION_CLASSES': [
|
||||
'rest_framework_simplejwt.authentication.JWTAuthentication',
|
||||
],
|
||||
'DEFAULT_PERMISSION_CLASSES': [
|
||||
'rest_framework.permissions.IsAuthenticated',
|
||||
],
|
||||
'DEFAULT_PAGINATION_CLASS': 'rest_framework.pagination.PageNumberPagination',
|
||||
'PAGE_SIZE': 20,
|
||||
'DEFAULT_FILTER_BACKENDS': [
|
||||
'django_filters.rest_framework.DjangoFilterBackend',
|
||||
'rest_framework.filters.SearchFilter',
|
||||
'rest_framework.filters.OrderingFilter',
|
||||
],
|
||||
}
|
||||
|
||||
# Simple JWT
|
||||
SIMPLE_JWT = {
|
||||
'ACCESS_TOKEN_LIFETIME': timedelta(minutes=60),
|
||||
'REFRESH_TOKEN_LIFETIME': timedelta(days=7),
|
||||
'ROTATE_REFRESH_TOKENS': True,
|
||||
'BLACKLIST_AFTER_ROTATION': True,
|
||||
'UPDATE_LAST_LOGIN': False,
|
||||
|
||||
'ALGORITHM': 'HS256',
|
||||
'SIGNING_KEY': SECRET_KEY,
|
||||
'VERIFYING_KEY': None,
|
||||
'AUDIENCE': None,
|
||||
'ISSUER': None,
|
||||
'JWK_URL': None,
|
||||
'LEEWAY': 0,
|
||||
|
||||
'AUTH_HEADER_TYPES': ('Bearer',),
|
||||
'AUTH_HEADER_NAME': 'HTTP_AUTHORIZATION',
|
||||
'USER_ID_FIELD': 'id',
|
||||
'USER_ID_CLAIM': 'user_id',
|
||||
'USER_AUTHENTICATION_RULE': 'rest_framework_simplejwt.authentication.default_user_authentication_rule',
|
||||
|
||||
'AUTH_TOKEN_CLASSES': ('rest_framework_simplejwt.tokens.AccessToken',),
|
||||
'TOKEN_TYPE_CLAIM': 'token_type',
|
||||
'TOKEN_USER_CLASS': 'rest_framework_simplejwt.models.TokenUser',
|
||||
|
||||
'JTI_CLAIM': 'jti',
|
||||
|
||||
'SLIDING_TOKEN_REFRESH_EXP_CLAIM': 'refresh_exp',
|
||||
'SLIDING_TOKEN_LIFETIME': timedelta(minutes=60),
|
||||
'SLIDING_TOKEN_REFRESH_LIFETIME': timedelta(days=1),
|
||||
}
|
||||
|
||||
# CORS settings
|
||||
CORS_ALLOWED_ORIGINS = [
|
||||
"http://localhost:3000",
|
||||
"http://127.0.0.1:3000",
|
||||
"http://localhost:8080",
|
||||
"http://127.0.0.1:8080",
|
||||
]
|
||||
|
||||
CORS_ALLOW_CREDENTIALS = True
|
||||
|
||||
# Security settings
|
||||
SECURE_BROWSER_XSS_FILTER = True
|
||||
SECURE_CONTENT_TYPE_NOSNIFF = True
|
||||
X_FRAME_OPTIONS = 'DENY'
|
||||
|
||||
# Logging
|
||||
LOGGING = {
|
||||
'version': 1,
|
||||
'disable_existing_loggers': False,
|
||||
'formatters': {
|
||||
'verbose': {
|
||||
'format': '{levelname} {asctime} {module} {process:d} {thread:d} {message}',
|
||||
'style': '{',
|
||||
},
|
||||
'simple': {
|
||||
'format': '{levelname} {message}',
|
||||
'style': '{',
|
||||
},
|
||||
},
|
||||
'handlers': {
|
||||
'file': {
|
||||
'level': 'INFO',
|
||||
'class': 'logging.FileHandler',
|
||||
'filename': 'django.log',
|
||||
'formatter': 'verbose',
|
||||
},
|
||||
'console': {
|
||||
'level': 'DEBUG',
|
||||
'class': 'logging.StreamHandler',
|
||||
'formatter': 'simple',
|
||||
},
|
||||
},
|
||||
'root': {
|
||||
'handlers': ['console', 'file'],
|
||||
'level': 'INFO',
|
||||
},
|
||||
}
|
18
backend/config/urls.py
Normal file
18
backend/config/urls.py
Normal file
@@ -0,0 +1,18 @@
|
||||
"""
|
||||
URL configuration for daily report system project.
|
||||
"""
|
||||
from django.contrib import admin
|
||||
from django.urls import path, include
|
||||
from django.conf import settings
|
||||
from django.conf.urls.static import static
|
||||
|
||||
urlpatterns = [
|
||||
path('admin/', admin.site.urls),
|
||||
path('api/auth/', include('accounts.urls')),
|
||||
path('api/', include('daily_report.urls')),
|
||||
]
|
||||
|
||||
# 开发环境下提供媒体文件服务
|
||||
if settings.DEBUG:
|
||||
urlpatterns += static(settings.MEDIA_URL, document_root=settings.MEDIA_ROOT)
|
||||
urlpatterns += static(settings.STATIC_URL, document_root=settings.STATIC_ROOT)
|
11
backend/config/wsgi.py
Normal file
11
backend/config/wsgi.py
Normal file
@@ -0,0 +1,11 @@
|
||||
"""
|
||||
WSGI config for daily report system project.
|
||||
"""
|
||||
|
||||
import os
|
||||
|
||||
from django.core.wsgi import get_wsgi_application
|
||||
|
||||
os.environ.setdefault('DJANGO_SETTINGS_MODULE', 'config.settings')
|
||||
|
||||
application = get_wsgi_application()
|
85
backend/create_superuser.py
Normal file
85
backend/create_superuser.py
Normal file
@@ -0,0 +1,85 @@
|
||||
#!/usr/bin/env python
|
||||
"""
|
||||
创建超级用户脚本
|
||||
"""
|
||||
import os
|
||||
import sys
|
||||
import django
|
||||
|
||||
# 设置Django环境
|
||||
os.environ.setdefault('DJANGO_SETTINGS_MODULE', 'config.settings')
|
||||
django.setup()
|
||||
|
||||
from django.contrib.auth import get_user_model
|
||||
|
||||
User = get_user_model()
|
||||
|
||||
def create_superuser():
|
||||
"""创建超级用户"""
|
||||
username = 'admin'
|
||||
email = 'admin@example.com'
|
||||
password = 'admin123456'
|
||||
|
||||
if User.objects.filter(username=username).exists():
|
||||
print(f'超级用户 {username} 已存在')
|
||||
return
|
||||
|
||||
user = User.objects.create_superuser(
|
||||
username=username,
|
||||
email=email,
|
||||
password=password,
|
||||
first_name='管理员',
|
||||
last_name='',
|
||||
department='系统管理部',
|
||||
position='系统管理员'
|
||||
)
|
||||
|
||||
print(f'超级用户创建成功!')
|
||||
print(f'用户名: {username}')
|
||||
print(f'密码: {password}')
|
||||
print(f'邮箱: {email}')
|
||||
|
||||
# 创建一些测试用户
|
||||
create_test_users()
|
||||
|
||||
def create_test_users():
|
||||
"""创建测试用户"""
|
||||
test_users = [
|
||||
{
|
||||
'username': 'zhangsan',
|
||||
'email': 'zhangsan@example.com',
|
||||
'password': 'test123456',
|
||||
'first_name': '张',
|
||||
'last_name': '三',
|
||||
'department': '技术部',
|
||||
'position': '前端工程师'
|
||||
},
|
||||
{
|
||||
'username': 'lisi',
|
||||
'email': 'lisi@example.com',
|
||||
'password': 'test123456',
|
||||
'first_name': '李',
|
||||
'last_name': '四',
|
||||
'department': '技术部',
|
||||
'position': '后端工程师'
|
||||
},
|
||||
{
|
||||
'username': 'wangwu',
|
||||
'email': 'wangwu@example.com',
|
||||
'password': 'test123456',
|
||||
'first_name': '王',
|
||||
'last_name': '五',
|
||||
'department': '产品部',
|
||||
'position': '产品经理'
|
||||
}
|
||||
]
|
||||
|
||||
for user_data in test_users:
|
||||
if not User.objects.filter(username=user_data['username']).exists():
|
||||
User.objects.create_user(**user_data)
|
||||
print(f'测试用户 {user_data["username"]} 创建成功')
|
||||
else:
|
||||
print(f'测试用户 {user_data["username"]} 已存在')
|
||||
|
||||
if __name__ == '__main__':
|
||||
create_superuser()
|
1
backend/daily_report/__init__.py
Normal file
1
backend/daily_report/__init__.py
Normal file
@@ -0,0 +1 @@
|
||||
# 日报管理应用
|
96
backend/daily_report/admin.py
Normal file
96
backend/daily_report/admin.py
Normal file
@@ -0,0 +1,96 @@
|
||||
from django.contrib import admin
|
||||
from django.utils.html import format_html
|
||||
from .models import DailyReport, ReportComment
|
||||
|
||||
|
||||
@admin.register(DailyReport)
|
||||
class DailyReportAdmin(admin.ModelAdmin):
|
||||
"""日报管理"""
|
||||
list_display = (
|
||||
'id', 'user_info', 'report_date', 'work_summary_short',
|
||||
'next_day_plan_short', 'is_draft', 'created_at'
|
||||
)
|
||||
list_filter = ('is_draft', 'report_date', 'created_at')
|
||||
search_fields = ('user__username', 'user__first_name', 'user__last_name',
|
||||
'work_summary', 'next_day_plan')
|
||||
date_hierarchy = 'report_date'
|
||||
ordering = ('-report_date', '-created_at')
|
||||
readonly_fields = ('created_at', 'updated_at')
|
||||
|
||||
fieldsets = (
|
||||
('基本信息', {
|
||||
'fields': ('user', 'report_date', 'is_draft')
|
||||
}),
|
||||
('日报内容', {
|
||||
'fields': ('work_summary', 'next_day_plan', 'difficulties', 'suggestions')
|
||||
}),
|
||||
('时间信息', {
|
||||
'fields': ('created_at', 'updated_at'),
|
||||
'classes': ('collapse',)
|
||||
}),
|
||||
)
|
||||
|
||||
def user_info(self, obj):
|
||||
"""显示用户信息"""
|
||||
return format_html(
|
||||
'<strong>{}</strong><br><small>{} | {}</small>',
|
||||
obj.user.username,
|
||||
obj.user.department or '未设置部门',
|
||||
obj.user.position or '未设置职位'
|
||||
)
|
||||
user_info.short_description = '用户信息'
|
||||
|
||||
def work_summary_short(self, obj):
|
||||
"""工作总结简短显示"""
|
||||
return obj.work_summary[:50] + '...' if len(obj.work_summary) > 50 else obj.work_summary
|
||||
work_summary_short.short_description = '工作总结'
|
||||
|
||||
def next_day_plan_short(self, obj):
|
||||
"""明日计划简短显示"""
|
||||
return obj.next_day_plan[:50] + '...' if len(obj.next_day_plan) > 50 else obj.next_day_plan
|
||||
next_day_plan_short.short_description = '明日计划'
|
||||
|
||||
def get_queryset(self, request):
|
||||
"""优化查询"""
|
||||
return super().get_queryset(request).select_related('user')
|
||||
|
||||
|
||||
@admin.register(ReportComment)
|
||||
class ReportCommentAdmin(admin.ModelAdmin):
|
||||
"""日报评论管理"""
|
||||
list_display = ('id', 'report_info', 'user', 'content_short', 'created_at')
|
||||
list_filter = ('created_at', 'user')
|
||||
search_fields = ('user__username', 'content', 'report__user__username')
|
||||
ordering = ('-created_at',)
|
||||
readonly_fields = ('created_at', 'updated_at')
|
||||
|
||||
fieldsets = (
|
||||
('基本信息', {
|
||||
'fields': ('report', 'user')
|
||||
}),
|
||||
('评论内容', {
|
||||
'fields': ('content',)
|
||||
}),
|
||||
('时间信息', {
|
||||
'fields': ('created_at', 'updated_at'),
|
||||
'classes': ('collapse',)
|
||||
}),
|
||||
)
|
||||
|
||||
def report_info(self, obj):
|
||||
"""显示日报信息"""
|
||||
return format_html(
|
||||
'<strong>{}</strong><br><small>{}</small>',
|
||||
f'{obj.report.user.username} - {obj.report.report_date}',
|
||||
obj.report.work_summary[:30] + '...' if len(obj.report.work_summary) > 30 else obj.report.work_summary
|
||||
)
|
||||
report_info.short_description = '关联日报'
|
||||
|
||||
def content_short(self, obj):
|
||||
"""评论内容简短显示"""
|
||||
return obj.content[:50] + '...' if len(obj.content) > 50 else obj.content
|
||||
content_short.short_description = '评论内容'
|
||||
|
||||
def get_queryset(self, request):
|
||||
"""优化查询"""
|
||||
return super().get_queryset(request).select_related('user', 'report__user')
|
7
backend/daily_report/apps.py
Normal file
7
backend/daily_report/apps.py
Normal file
@@ -0,0 +1,7 @@
|
||||
from django.apps import AppConfig
|
||||
|
||||
|
||||
class DailyReportConfig(AppConfig):
|
||||
default_auto_field = 'django.db.models.BigAutoField'
|
||||
name = 'daily_report'
|
||||
verbose_name = '日报管理'
|
104
backend/daily_report/filters.py
Normal file
104
backend/daily_report/filters.py
Normal file
@@ -0,0 +1,104 @@
|
||||
import django_filters
|
||||
from django.contrib.auth import get_user_model
|
||||
from django.db import models
|
||||
from .models import DailyReport
|
||||
|
||||
User = get_user_model()
|
||||
|
||||
|
||||
class DailyReportFilter(django_filters.FilterSet):
|
||||
"""日报过滤器"""
|
||||
|
||||
# 日期范围过滤
|
||||
report_date_start = django_filters.DateFilter(
|
||||
field_name='report_date',
|
||||
lookup_expr='gte',
|
||||
label='开始日期'
|
||||
)
|
||||
report_date_end = django_filters.DateFilter(
|
||||
field_name='report_date',
|
||||
lookup_expr='lte',
|
||||
label='结束日期'
|
||||
)
|
||||
|
||||
# 用户过滤(仅管理员可用)
|
||||
user = django_filters.ModelChoiceFilter(
|
||||
queryset=User.objects.filter(is_active=True),
|
||||
label='提交人'
|
||||
)
|
||||
|
||||
# 用户名搜索
|
||||
user_username = django_filters.CharFilter(
|
||||
field_name='user__username',
|
||||
lookup_expr='icontains',
|
||||
label='用户名'
|
||||
)
|
||||
|
||||
# 姓名搜索
|
||||
user_name = django_filters.CharFilter(
|
||||
method='filter_user_name',
|
||||
label='姓名'
|
||||
)
|
||||
|
||||
# 部门过滤
|
||||
department = django_filters.CharFilter(
|
||||
field_name='user__department',
|
||||
lookup_expr='icontains',
|
||||
label='部门'
|
||||
)
|
||||
|
||||
# 工作总结搜索
|
||||
work_summary = django_filters.CharFilter(
|
||||
field_name='work_summary',
|
||||
lookup_expr='icontains',
|
||||
label='工作总结'
|
||||
)
|
||||
|
||||
# 明日计划搜索
|
||||
next_day_plan = django_filters.CharFilter(
|
||||
field_name='next_day_plan',
|
||||
lookup_expr='icontains',
|
||||
label='明日计划'
|
||||
)
|
||||
|
||||
# 草稿状态过滤
|
||||
is_draft = django_filters.BooleanFilter(
|
||||
field_name='is_draft',
|
||||
label='草稿状态'
|
||||
)
|
||||
|
||||
# 年月过滤
|
||||
year = django_filters.NumberFilter(
|
||||
field_name='report_date__year',
|
||||
label='年份'
|
||||
)
|
||||
month = django_filters.NumberFilter(
|
||||
field_name='report_date__month',
|
||||
label='月份'
|
||||
)
|
||||
|
||||
class Meta:
|
||||
model = DailyReport
|
||||
fields = []
|
||||
|
||||
def filter_user_name(self, queryset, name, value):
|
||||
"""按用户姓名过滤"""
|
||||
if not value:
|
||||
return queryset
|
||||
|
||||
return queryset.filter(
|
||||
models.Q(user__first_name__icontains=value) |
|
||||
models.Q(user__last_name__icontains=value) |
|
||||
models.Q(user__username__icontains=value)
|
||||
)
|
||||
|
||||
def __init__(self, *args, **kwargs):
|
||||
request = kwargs.pop('request', None)
|
||||
super().__init__(*args, **kwargs)
|
||||
|
||||
# 如果不是管理员,移除用户相关的过滤字段
|
||||
if request and not request.user.is_staff:
|
||||
self.filters.pop('user', None)
|
||||
self.filters.pop('user_username', None)
|
||||
self.filters.pop('user_name', None)
|
||||
self.filters.pop('department', None)
|
70
backend/daily_report/migrations/0001_initial.py
Normal file
70
backend/daily_report/migrations/0001_initial.py
Normal file
@@ -0,0 +1,70 @@
|
||||
# Generated by Django 4.2.7 on 2025-09-13 05:47
|
||||
|
||||
from django.conf import settings
|
||||
import django.core.validators
|
||||
from django.db import migrations, models
|
||||
import django.db.models.deletion
|
||||
|
||||
|
||||
class Migration(migrations.Migration):
|
||||
|
||||
initial = True
|
||||
|
||||
dependencies = [
|
||||
migrations.swappable_dependency(settings.AUTH_USER_MODEL),
|
||||
]
|
||||
|
||||
operations = [
|
||||
migrations.CreateModel(
|
||||
name='DailyReport',
|
||||
fields=[
|
||||
('id', models.BigAutoField(auto_created=True, primary_key=True, serialize=False, verbose_name='ID')),
|
||||
('work_summary', models.TextField(validators=[django.core.validators.MinLengthValidator(10, message='工作总结至少需要10个字符')], verbose_name='工作总结')),
|
||||
('next_day_plan', models.TextField(validators=[django.core.validators.MinLengthValidator(10, message='明日计划至少需要10个字符')], verbose_name='明日计划')),
|
||||
('difficulties', models.TextField(blank=True, help_text='可选:描述工作中遇到的问题或困难', null=True, verbose_name='遇到的困难')),
|
||||
('suggestions', models.TextField(blank=True, help_text='可选:对工作或团队的建议', null=True, verbose_name='建议或意见')),
|
||||
('report_date', models.DateField(help_text='填写日报对应的日期', verbose_name='日报日期')),
|
||||
('created_at', models.DateTimeField(auto_now_add=True, verbose_name='提交时间')),
|
||||
('updated_at', models.DateTimeField(auto_now=True, verbose_name='更新时间')),
|
||||
('is_draft', models.BooleanField(default=False, help_text='是否为草稿', verbose_name='草稿状态')),
|
||||
('user', models.ForeignKey(on_delete=django.db.models.deletion.CASCADE, related_name='daily_reports', to=settings.AUTH_USER_MODEL, verbose_name='提交人')),
|
||||
],
|
||||
options={
|
||||
'verbose_name': '日报',
|
||||
'verbose_name_plural': '日报',
|
||||
'ordering': ['-report_date', '-created_at'],
|
||||
},
|
||||
),
|
||||
migrations.CreateModel(
|
||||
name='ReportComment',
|
||||
fields=[
|
||||
('id', models.BigAutoField(auto_created=True, primary_key=True, serialize=False, verbose_name='ID')),
|
||||
('content', models.TextField(verbose_name='评论内容')),
|
||||
('created_at', models.DateTimeField(auto_now_add=True, verbose_name='评论时间')),
|
||||
('updated_at', models.DateTimeField(auto_now=True, verbose_name='更新时间')),
|
||||
('report', models.ForeignKey(on_delete=django.db.models.deletion.CASCADE, related_name='comments', to='daily_report.dailyreport', verbose_name='关联日报')),
|
||||
('user', models.ForeignKey(on_delete=django.db.models.deletion.CASCADE, to=settings.AUTH_USER_MODEL, verbose_name='评论人')),
|
||||
],
|
||||
options={
|
||||
'verbose_name': '日报评论',
|
||||
'verbose_name_plural': '日报评论',
|
||||
'ordering': ['-created_at'],
|
||||
},
|
||||
),
|
||||
migrations.AddIndex(
|
||||
model_name='dailyreport',
|
||||
index=models.Index(fields=['user', 'report_date'], name='daily_repor_user_id_f18440_idx'),
|
||||
),
|
||||
migrations.AddIndex(
|
||||
model_name='dailyreport',
|
||||
index=models.Index(fields=['report_date'], name='daily_repor_report__ee6559_idx'),
|
||||
),
|
||||
migrations.AddIndex(
|
||||
model_name='dailyreport',
|
||||
index=models.Index(fields=['-created_at'], name='daily_repor_created_005929_idx'),
|
||||
),
|
||||
migrations.AlterUniqueTogether(
|
||||
name='dailyreport',
|
||||
unique_together={('user', 'report_date')},
|
||||
),
|
||||
]
|
0
backend/daily_report/migrations/__init__.py
Normal file
0
backend/daily_report/migrations/__init__.py
Normal file
89
backend/daily_report/models.py
Normal file
89
backend/daily_report/models.py
Normal file
@@ -0,0 +1,89 @@
|
||||
from django.db import models
|
||||
from django.contrib.auth import get_user_model
|
||||
from django.core.validators import MinLengthValidator
|
||||
|
||||
User = get_user_model()
|
||||
|
||||
|
||||
class DailyReport(models.Model):
|
||||
"""日报模型"""
|
||||
user = models.ForeignKey(
|
||||
User,
|
||||
on_delete=models.CASCADE,
|
||||
verbose_name="提交人",
|
||||
related_name='daily_reports'
|
||||
)
|
||||
work_summary = models.TextField(
|
||||
"工作总结",
|
||||
validators=[MinLengthValidator(10, message="工作总结至少需要10个字符")]
|
||||
)
|
||||
next_day_plan = models.TextField(
|
||||
"明日计划",
|
||||
validators=[MinLengthValidator(10, message="明日计划至少需要10个字符")]
|
||||
)
|
||||
difficulties = models.TextField(
|
||||
"遇到的困难",
|
||||
blank=True,
|
||||
null=True,
|
||||
help_text="可选:描述工作中遇到的问题或困难"
|
||||
)
|
||||
suggestions = models.TextField(
|
||||
"建议或意见",
|
||||
blank=True,
|
||||
null=True,
|
||||
help_text="可选:对工作或团队的建议"
|
||||
)
|
||||
report_date = models.DateField("日报日期", help_text="填写日报对应的日期")
|
||||
created_at = models.DateTimeField("提交时间", auto_now_add=True)
|
||||
updated_at = models.DateTimeField("更新时间", auto_now=True)
|
||||
is_draft = models.BooleanField("草稿状态", default=False, help_text="是否为草稿")
|
||||
|
||||
class Meta:
|
||||
verbose_name = "日报"
|
||||
verbose_name_plural = verbose_name
|
||||
ordering = ['-report_date', '-created_at']
|
||||
unique_together = [['user', 'report_date']] # 每个用户每天只能有一份日报
|
||||
indexes = [
|
||||
models.Index(fields=['user', 'report_date']),
|
||||
models.Index(fields=['report_date']),
|
||||
models.Index(fields=['-created_at']),
|
||||
]
|
||||
|
||||
def __str__(self):
|
||||
return f'{self.user.username} - {self.report_date}'
|
||||
|
||||
@property
|
||||
def work_summary_preview(self):
|
||||
"""工作总结预览(前100个字符)"""
|
||||
return self.work_summary[:100] + '...' if len(self.work_summary) > 100 else self.work_summary
|
||||
|
||||
@property
|
||||
def next_day_plan_preview(self):
|
||||
"""明日计划预览(前100个字符)"""
|
||||
return self.next_day_plan[:100] + '...' if len(self.next_day_plan) > 100 else self.next_day_plan
|
||||
|
||||
|
||||
class ReportComment(models.Model):
|
||||
"""日报评论模型"""
|
||||
report = models.ForeignKey(
|
||||
DailyReport,
|
||||
on_delete=models.CASCADE,
|
||||
related_name='comments',
|
||||
verbose_name="关联日报"
|
||||
)
|
||||
user = models.ForeignKey(
|
||||
User,
|
||||
on_delete=models.CASCADE,
|
||||
verbose_name="评论人"
|
||||
)
|
||||
content = models.TextField("评论内容")
|
||||
created_at = models.DateTimeField("评论时间", auto_now_add=True)
|
||||
updated_at = models.DateTimeField("更新时间", auto_now=True)
|
||||
|
||||
class Meta:
|
||||
verbose_name = "日报评论"
|
||||
verbose_name_plural = verbose_name
|
||||
ordering = ['-created_at']
|
||||
|
||||
def __str__(self):
|
||||
return f'{self.user.username} 评论了 {self.report}'
|
65
backend/daily_report/permissions.py
Normal file
65
backend/daily_report/permissions.py
Normal file
@@ -0,0 +1,65 @@
|
||||
from rest_framework import permissions
|
||||
|
||||
|
||||
class IsOwnerOrStaff(permissions.BasePermission):
|
||||
"""
|
||||
自定义权限:只有日报的创建者或管理员才能访问
|
||||
"""
|
||||
|
||||
def has_object_permission(self, request, view, obj):
|
||||
# 读取权限:管理员可以查看所有日报,普通用户只能查看自己的日报
|
||||
if request.method in permissions.SAFE_METHODS:
|
||||
return obj.user == request.user or request.user.is_staff
|
||||
|
||||
# 写入权限:只有创建者或管理员可以修改/删除
|
||||
return obj.user == request.user or request.user.is_staff
|
||||
|
||||
|
||||
class IsOwnerOrStaffReadOnly(permissions.BasePermission):
|
||||
"""
|
||||
自定义权限:管理员可以查看所有日报,普通用户只能查看自己的日报
|
||||
管理员对他人日报只有只读权限
|
||||
"""
|
||||
|
||||
def has_object_permission(self, request, view, obj):
|
||||
# 如果是日报创建者,拥有完全权限
|
||||
if obj.user == request.user:
|
||||
return True
|
||||
|
||||
# 如果是管理员,只有读取权限
|
||||
if request.user.is_staff:
|
||||
return request.method in permissions.SAFE_METHODS
|
||||
|
||||
# 其他情况拒绝访问
|
||||
return False
|
||||
|
||||
|
||||
class IsCommentOwnerOrStaff(permissions.BasePermission):
|
||||
"""
|
||||
评论权限:只有评论创建者或管理员可以修改/删除评论
|
||||
"""
|
||||
|
||||
def has_object_permission(self, request, view, obj):
|
||||
# 读取权限:所有认证用户都可以查看评论
|
||||
if request.method in permissions.SAFE_METHODS:
|
||||
return True
|
||||
|
||||
# 写入权限:只有评论创建者或管理员可以修改/删除
|
||||
return obj.user == request.user or request.user.is_staff
|
||||
|
||||
|
||||
class CanViewReports(permissions.BasePermission):
|
||||
"""
|
||||
日报查看权限:管理员可以查看所有日报,普通用户只能查看自己的日报
|
||||
"""
|
||||
|
||||
def has_permission(self, request, view):
|
||||
return request.user and request.user.is_authenticated
|
||||
|
||||
def has_object_permission(self, request, view, obj):
|
||||
# 管理员可以查看所有日报
|
||||
if request.user.is_staff:
|
||||
return True
|
||||
|
||||
# 普通用户只能查看自己的日报
|
||||
return obj.user == request.user
|
131
backend/daily_report/serializers.py
Normal file
131
backend/daily_report/serializers.py
Normal file
@@ -0,0 +1,131 @@
|
||||
from rest_framework import serializers
|
||||
from django.contrib.auth import get_user_model
|
||||
from .models import DailyReport, ReportComment
|
||||
|
||||
User = get_user_model()
|
||||
|
||||
|
||||
class UserSimpleSerializer(serializers.ModelSerializer):
|
||||
"""用户简单信息序列化器"""
|
||||
full_name = serializers.SerializerMethodField()
|
||||
|
||||
class Meta:
|
||||
model = User
|
||||
fields = ('id', 'username', 'full_name', 'department', 'position')
|
||||
|
||||
def get_full_name(self, obj):
|
||||
return f'{obj.first_name} {obj.last_name}'.strip() or obj.username
|
||||
|
||||
|
||||
class ReportCommentSerializer(serializers.ModelSerializer):
|
||||
"""日报评论序列化器"""
|
||||
user = UserSimpleSerializer(read_only=True)
|
||||
|
||||
class Meta:
|
||||
model = ReportComment
|
||||
fields = ('id', 'user', 'content', 'created_at', 'updated_at')
|
||||
read_only_fields = ('id', 'created_at', 'updated_at')
|
||||
|
||||
def create(self, validated_data):
|
||||
validated_data['user'] = self.context['request'].user
|
||||
return super().create(validated_data)
|
||||
|
||||
|
||||
class DailyReportListSerializer(serializers.ModelSerializer):
|
||||
"""日报列表序列化器"""
|
||||
user = UserSimpleSerializer(read_only=True)
|
||||
work_summary_preview = serializers.ReadOnlyField()
|
||||
next_day_plan_preview = serializers.ReadOnlyField()
|
||||
comments_count = serializers.SerializerMethodField()
|
||||
|
||||
class Meta:
|
||||
model = DailyReport
|
||||
fields = (
|
||||
'id', 'user', 'work_summary_preview', 'next_day_plan_preview',
|
||||
'report_date', 'created_at', 'updated_at', 'is_draft', 'comments_count'
|
||||
)
|
||||
|
||||
def get_comments_count(self, obj):
|
||||
return obj.comments.count()
|
||||
|
||||
|
||||
class DailyReportDetailSerializer(serializers.ModelSerializer):
|
||||
"""日报详情序列化器"""
|
||||
user = UserSimpleSerializer(read_only=True)
|
||||
comments = ReportCommentSerializer(many=True, read_only=True)
|
||||
can_edit = serializers.SerializerMethodField()
|
||||
can_delete = serializers.SerializerMethodField()
|
||||
|
||||
class Meta:
|
||||
model = DailyReport
|
||||
fields = (
|
||||
'id', 'user', 'work_summary', 'next_day_plan', 'difficulties',
|
||||
'suggestions', 'report_date', 'created_at', 'updated_at',
|
||||
'is_draft', 'comments', 'can_edit', 'can_delete'
|
||||
)
|
||||
|
||||
def get_can_edit(self, obj):
|
||||
request = self.context.get('request')
|
||||
if not request or not request.user:
|
||||
return False
|
||||
return obj.user == request.user or request.user.is_staff
|
||||
|
||||
def get_can_delete(self, obj):
|
||||
request = self.context.get('request')
|
||||
if not request or not request.user:
|
||||
return False
|
||||
return obj.user == request.user or request.user.is_staff
|
||||
|
||||
|
||||
class DailyReportCreateUpdateSerializer(serializers.ModelSerializer):
|
||||
"""日报创建和更新序列化器"""
|
||||
|
||||
class Meta:
|
||||
model = DailyReport
|
||||
fields = (
|
||||
'work_summary', 'next_day_plan', 'difficulties',
|
||||
'suggestions', 'report_date', 'is_draft'
|
||||
)
|
||||
|
||||
def validate_report_date(self, value):
|
||||
"""验证日报日期"""
|
||||
request = self.context.get('request')
|
||||
if not request:
|
||||
return value
|
||||
|
||||
# 检查是否已存在该日期的日报(更新时排除当前记录)
|
||||
queryset = DailyReport.objects.filter(
|
||||
user=request.user,
|
||||
report_date=value
|
||||
)
|
||||
|
||||
# 如果是更新操作,排除当前记录
|
||||
if self.instance:
|
||||
queryset = queryset.exclude(id=self.instance.id)
|
||||
|
||||
if queryset.exists():
|
||||
raise serializers.ValidationError(f'您已在 {value} 提交过日报,每天只能提交一份日报。')
|
||||
|
||||
return value
|
||||
|
||||
def create(self, validated_data):
|
||||
validated_data['user'] = self.context['request'].user
|
||||
return super().create(validated_data)
|
||||
|
||||
|
||||
class DailyReportStatsSerializer(serializers.Serializer):
|
||||
"""日报统计序列化器"""
|
||||
total_reports = serializers.IntegerField()
|
||||
this_month_reports = serializers.IntegerField()
|
||||
this_week_reports = serializers.IntegerField()
|
||||
draft_reports = serializers.IntegerField()
|
||||
completion_rate = serializers.FloatField()
|
||||
|
||||
|
||||
class UserReportStatsSerializer(serializers.Serializer):
|
||||
"""用户日报统计序列化器"""
|
||||
user = UserSimpleSerializer()
|
||||
total_reports = serializers.IntegerField()
|
||||
this_month_reports = serializers.IntegerField()
|
||||
last_report_date = serializers.DateField()
|
||||
completion_rate = serializers.FloatField()
|
19
backend/daily_report/urls.py
Normal file
19
backend/daily_report/urls.py
Normal file
@@ -0,0 +1,19 @@
|
||||
from django.urls import path
|
||||
from . import views
|
||||
|
||||
app_name = 'daily_report'
|
||||
|
||||
urlpatterns = [
|
||||
# 日报相关URL
|
||||
path('reports/', views.DailyReportListCreateView.as_view(), name='report-list-create'),
|
||||
path('reports/<int:pk>/', views.DailyReportDetailView.as_view(), name='report-detail'),
|
||||
path('reports/<int:pk>/toggle-draft/', views.toggle_draft_status, name='toggle-draft'),
|
||||
|
||||
# 评论相关URL
|
||||
path('reports/<int:report_id>/comments/', views.ReportCommentListCreateView.as_view(), name='comment-list-create'),
|
||||
path('comments/<int:pk>/', views.ReportCommentDetailView.as_view(), name='comment-detail'),
|
||||
|
||||
# 统计相关URL
|
||||
path('stats/', views.report_stats, name='report-stats'),
|
||||
path('stats/users/', views.user_report_stats, name='user-report-stats'),
|
||||
]
|
205
backend/daily_report/views.py
Normal file
205
backend/daily_report/views.py
Normal file
@@ -0,0 +1,205 @@
|
||||
from rest_framework import generics, status, permissions
|
||||
from rest_framework.decorators import api_view, permission_classes
|
||||
from rest_framework.response import Response
|
||||
from django.db.models import Count, Q
|
||||
from django.utils import timezone
|
||||
from datetime import datetime, timedelta
|
||||
from django.contrib.auth import get_user_model
|
||||
from .models import DailyReport, ReportComment
|
||||
from .serializers import (
|
||||
DailyReportListSerializer,
|
||||
DailyReportDetailSerializer,
|
||||
DailyReportCreateUpdateSerializer,
|
||||
ReportCommentSerializer,
|
||||
DailyReportStatsSerializer,
|
||||
UserReportStatsSerializer
|
||||
)
|
||||
from .permissions import IsOwnerOrStaff, IsOwnerOrStaffReadOnly, IsCommentOwnerOrStaff
|
||||
from .filters import DailyReportFilter
|
||||
|
||||
User = get_user_model()
|
||||
|
||||
|
||||
class DailyReportListCreateView(generics.ListCreateAPIView):
|
||||
"""日报列表和创建视图"""
|
||||
permission_classes = [permissions.IsAuthenticated]
|
||||
filterset_class = DailyReportFilter
|
||||
search_fields = ['work_summary', 'next_day_plan', 'user__username', 'user__first_name', 'user__last_name']
|
||||
ordering_fields = ['report_date', 'created_at', 'updated_at']
|
||||
ordering = ['-report_date', '-created_at']
|
||||
|
||||
def get_queryset(self):
|
||||
"""根据用户权限返回不同的查询集"""
|
||||
user = self.request.user
|
||||
if user.is_staff:
|
||||
# 管理员可以查看所有日报
|
||||
return DailyReport.objects.select_related('user').prefetch_related('comments')
|
||||
else:
|
||||
# 普通用户只能查看自己的日报
|
||||
return DailyReport.objects.filter(user=user).select_related('user').prefetch_related('comments')
|
||||
|
||||
def get_serializer_class(self):
|
||||
if self.request.method == 'POST':
|
||||
return DailyReportCreateUpdateSerializer
|
||||
return DailyReportListSerializer
|
||||
|
||||
def get_filterset_kwargs(self, filterset_class):
|
||||
"""传递request给过滤器"""
|
||||
kwargs = super().get_filterset_kwargs(filterset_class)
|
||||
kwargs['request'] = self.request
|
||||
return kwargs
|
||||
|
||||
|
||||
class DailyReportDetailView(generics.RetrieveUpdateDestroyAPIView):
|
||||
"""日报详情、更新和删除视图"""
|
||||
permission_classes = [permissions.IsAuthenticated, IsOwnerOrStaffReadOnly]
|
||||
|
||||
def get_queryset(self):
|
||||
"""根据用户权限返回不同的查询集"""
|
||||
user = self.request.user
|
||||
if user.is_staff:
|
||||
return DailyReport.objects.select_related('user').prefetch_related('comments__user')
|
||||
else:
|
||||
return DailyReport.objects.filter(user=user).select_related('user').prefetch_related('comments__user')
|
||||
|
||||
def get_serializer_class(self):
|
||||
if self.request.method in ['PUT', 'PATCH']:
|
||||
return DailyReportCreateUpdateSerializer
|
||||
return DailyReportDetailSerializer
|
||||
|
||||
|
||||
class ReportCommentListCreateView(generics.ListCreateAPIView):
|
||||
"""日报评论列表和创建视图"""
|
||||
serializer_class = ReportCommentSerializer
|
||||
permission_classes = [permissions.IsAuthenticated]
|
||||
|
||||
def get_queryset(self):
|
||||
report_id = self.kwargs.get('report_id')
|
||||
return ReportComment.objects.filter(
|
||||
report_id=report_id
|
||||
).select_related('user', 'report')
|
||||
|
||||
def perform_create(self, serializer):
|
||||
report_id = self.kwargs.get('report_id')
|
||||
# 验证用户是否有权限查看该日报
|
||||
try:
|
||||
report = DailyReport.objects.get(id=report_id)
|
||||
if not (report.user == self.request.user or self.request.user.is_staff):
|
||||
raise permissions.PermissionDenied("您没有权限评论此日报")
|
||||
except DailyReport.DoesNotExist:
|
||||
raise generics.NotFound("日报不存在")
|
||||
|
||||
serializer.save(user=self.request.user, report_id=report_id)
|
||||
|
||||
|
||||
class ReportCommentDetailView(generics.RetrieveUpdateDestroyAPIView):
|
||||
"""日报评论详情、更新和删除视图"""
|
||||
serializer_class = ReportCommentSerializer
|
||||
permission_classes = [permissions.IsAuthenticated, IsCommentOwnerOrStaff]
|
||||
|
||||
def get_queryset(self):
|
||||
return ReportComment.objects.select_related('user', 'report')
|
||||
|
||||
|
||||
@api_view(['GET'])
|
||||
@permission_classes([permissions.IsAuthenticated])
|
||||
def report_stats(request):
|
||||
"""获取日报统计信息"""
|
||||
user = request.user
|
||||
|
||||
if user.is_staff:
|
||||
# 管理员查看全局统计
|
||||
queryset = DailyReport.objects.all()
|
||||
else:
|
||||
# 普通用户查看个人统计
|
||||
queryset = DailyReport.objects.filter(user=user)
|
||||
|
||||
now = timezone.now()
|
||||
this_month_start = now.replace(day=1, hour=0, minute=0, second=0, microsecond=0)
|
||||
this_week_start = now - timedelta(days=now.weekday())
|
||||
this_week_start = this_week_start.replace(hour=0, minute=0, second=0, microsecond=0)
|
||||
|
||||
total_reports = queryset.count()
|
||||
this_month_reports = queryset.filter(report_date__gte=this_month_start.date()).count()
|
||||
this_week_reports = queryset.filter(report_date__gte=this_week_start.date()).count()
|
||||
draft_reports = queryset.filter(is_draft=True).count()
|
||||
|
||||
# 计算完成率(本月)
|
||||
days_in_month = (now.replace(month=now.month+1, day=1) - timedelta(days=1)).day if now.month < 12 else 31
|
||||
current_day = now.day
|
||||
expected_reports = current_day if not user.is_staff else User.objects.filter(is_active=True).count() * current_day
|
||||
completion_rate = (this_month_reports / expected_reports * 100) if expected_reports > 0 else 0
|
||||
|
||||
stats = {
|
||||
'total_reports': total_reports,
|
||||
'this_month_reports': this_month_reports,
|
||||
'this_week_reports': this_week_reports,
|
||||
'draft_reports': draft_reports,
|
||||
'completion_rate': round(completion_rate, 2)
|
||||
}
|
||||
|
||||
serializer = DailyReportStatsSerializer(stats)
|
||||
return Response(serializer.data)
|
||||
|
||||
|
||||
@api_view(['GET'])
|
||||
@permission_classes([permissions.IsAuthenticated])
|
||||
def user_report_stats(request):
|
||||
"""获取用户日报统计信息(仅管理员)"""
|
||||
if not request.user.is_staff:
|
||||
return Response({'error': '权限不足'}, status=status.HTTP_403_FORBIDDEN)
|
||||
|
||||
users = User.objects.filter(is_active=True).annotate(
|
||||
total_reports=Count('daily_reports'),
|
||||
this_month_reports=Count(
|
||||
'daily_reports',
|
||||
filter=Q(daily_reports__report_date__gte=timezone.now().replace(day=1).date())
|
||||
)
|
||||
).prefetch_related('daily_reports')
|
||||
|
||||
stats_list = []
|
||||
for user in users:
|
||||
last_report = user.daily_reports.first()
|
||||
last_report_date = last_report.report_date if last_report else None
|
||||
|
||||
# 计算完成率
|
||||
current_day = timezone.now().day
|
||||
completion_rate = (user.this_month_reports / current_day * 100) if current_day > 0 else 0
|
||||
|
||||
stats_list.append({
|
||||
'user': user,
|
||||
'total_reports': user.total_reports,
|
||||
'this_month_reports': user.this_month_reports,
|
||||
'last_report_date': last_report_date,
|
||||
'completion_rate': round(completion_rate, 2)
|
||||
})
|
||||
|
||||
# 按完成率排序
|
||||
stats_list.sort(key=lambda x: x['completion_rate'], reverse=True)
|
||||
|
||||
serializer = UserReportStatsSerializer(stats_list, many=True)
|
||||
return Response(serializer.data)
|
||||
|
||||
|
||||
@api_view(['POST'])
|
||||
@permission_classes([permissions.IsAuthenticated])
|
||||
def toggle_draft_status(request, pk):
|
||||
"""切换日报的草稿状态"""
|
||||
try:
|
||||
report = DailyReport.objects.get(pk=pk)
|
||||
|
||||
# 检查权限
|
||||
if report.user != request.user and not request.user.is_staff:
|
||||
return Response({'error': '权限不足'}, status=status.HTTP_403_FORBIDDEN)
|
||||
|
||||
report.is_draft = not report.is_draft
|
||||
report.save()
|
||||
|
||||
status_text = '草稿' if report.is_draft else '已发布'
|
||||
return Response({
|
||||
'message': f'日报状态已更新为:{status_text}',
|
||||
'is_draft': report.is_draft
|
||||
})
|
||||
|
||||
except DailyReport.DoesNotExist:
|
||||
return Response({'error': '日报不存在'}, status=status.HTTP_404_NOT_FOUND)
|
88
backend/deploy.py
Normal file
88
backend/deploy.py
Normal file
@@ -0,0 +1,88 @@
|
||||
#!/usr/bin/env python
|
||||
"""
|
||||
部署脚本 - 自动化部署Django应用
|
||||
"""
|
||||
import os
|
||||
import sys
|
||||
import subprocess
|
||||
import django
|
||||
|
||||
# 设置Django环境
|
||||
os.environ.setdefault('DJANGO_SETTINGS_MODULE', 'config.settings')
|
||||
django.setup()
|
||||
|
||||
def run_command(command, description):
|
||||
"""运行命令并处理错误"""
|
||||
print(f"\n{'='*50}")
|
||||
print(f"执行: {description}")
|
||||
print(f"命令: {command}")
|
||||
print(f"{'='*50}")
|
||||
|
||||
result = subprocess.run(command, shell=True, capture_output=True, text=True)
|
||||
|
||||
if result.returncode == 0:
|
||||
print(f"✅ {description} - 成功")
|
||||
if result.stdout:
|
||||
print(result.stdout)
|
||||
else:
|
||||
print(f"❌ {description} - 失败")
|
||||
if result.stderr:
|
||||
print(result.stderr)
|
||||
return False
|
||||
return True
|
||||
|
||||
def deploy():
|
||||
"""执行部署流程"""
|
||||
print("🚀 开始部署企业级日报系统后端...")
|
||||
|
||||
# 1. 检查Python版本
|
||||
if not run_command("python --version", "检查Python版本"):
|
||||
return False
|
||||
|
||||
# 2. 安装依赖
|
||||
if not run_command("pip install -r requirements.txt", "安装Python依赖"):
|
||||
return False
|
||||
|
||||
# 3. 数据库迁移
|
||||
if not run_command("python manage.py makemigrations", "生成数据库迁移文件"):
|
||||
return False
|
||||
|
||||
if not run_command("python manage.py migrate", "执行数据库迁移"):
|
||||
return False
|
||||
|
||||
# 4. 创建超级用户
|
||||
print("\n📝 创建超级用户和测试用户...")
|
||||
try:
|
||||
exec(open('create_superuser.py').read())
|
||||
print("✅ 用户创建完成")
|
||||
except Exception as e:
|
||||
print(f"❌ 创建用户失败: {e}")
|
||||
|
||||
# 5. 收集静态文件
|
||||
if not run_command("python manage.py collectstatic --noinput", "收集静态文件"):
|
||||
return False
|
||||
|
||||
# 6. 运行测试
|
||||
if not run_command("python manage.py check", "检查系统配置"):
|
||||
return False
|
||||
|
||||
print("\n🎉 后端部署完成!")
|
||||
print("\n📋 部署信息:")
|
||||
print("- 管理员账号: admin / admin123456")
|
||||
print("- 测试用户: zhangsan / test123456")
|
||||
print("- API地址: http://localhost:8000/api/")
|
||||
print("- 管理后台: http://localhost:8000/admin/")
|
||||
print("\n🚀 启动服务: python manage.py runserver")
|
||||
|
||||
return True
|
||||
|
||||
if __name__ == '__main__':
|
||||
try:
|
||||
success = deploy()
|
||||
sys.exit(0 if success else 1)
|
||||
except KeyboardInterrupt:
|
||||
print("\n\n⚠️ 部署被用户中断")
|
||||
sys.exit(1)
|
||||
except Exception as e:
|
||||
print(f"\n\n❌ 部署失败: {e}")
|
||||
sys.exit(1)
|
12
backend/env.example
Normal file
12
backend/env.example
Normal file
@@ -0,0 +1,12 @@
|
||||
# Django配置
|
||||
SECRET_KEY=your-secret-key-here
|
||||
DEBUG=True
|
||||
|
||||
# 数据库配置(可选,默认使用SQLite)
|
||||
# DATABASE_URL=postgresql://username:password@localhost:5432/daily_report_db
|
||||
|
||||
# 跨域配置
|
||||
CORS_ALLOWED_ORIGINS=http://localhost:3000,http://127.0.0.1:3000
|
||||
|
||||
# 其他配置
|
||||
ALLOWED_HOSTS=localhost,127.0.0.1
|
22
backend/manage.py
Normal file
22
backend/manage.py
Normal file
@@ -0,0 +1,22 @@
|
||||
#!/usr/bin/env python
|
||||
"""Django's command-line utility for administrative tasks."""
|
||||
import os
|
||||
import sys
|
||||
|
||||
|
||||
def main():
|
||||
"""Run administrative tasks."""
|
||||
os.environ.setdefault('DJANGO_SETTINGS_MODULE', 'config.settings')
|
||||
try:
|
||||
from django.core.management import execute_from_command_line
|
||||
except ImportError as exc:
|
||||
raise ImportError(
|
||||
"Couldn't import Django. Are you sure it's installed and "
|
||||
"available on your PYTHONPATH environment variable? Did you "
|
||||
"forget to activate a virtual environment?"
|
||||
) from exc
|
||||
execute_from_command_line(sys.argv)
|
||||
|
||||
|
||||
if __name__ == '__main__':
|
||||
main()
|
6
backend/requirements.txt
Normal file
6
backend/requirements.txt
Normal file
@@ -0,0 +1,6 @@
|
||||
Django==4.2.7
|
||||
djangorestframework==3.14.0
|
||||
djangorestframework-simplejwt==5.3.0
|
||||
django-cors-headers==4.3.1
|
||||
python-decouple==3.8
|
||||
django-filter==23.3
|
Reference in New Issue
Block a user