柯里化在rbac中实现权限校验与业务逻辑解耦,通过函数工厂批量生成带权限守门员的页面或操作;预设view/edit/manage/admin等语义化权限等级,并封装为checkpermission校验函数;利用withauthguard等柯里化高阶函数包装路由组件,统一维护校验逻辑;支持组合权限、异步校验及按钮级权限联动,确保全链路权限语义一致。

柯里化在 RBAC 权限控制中,核心作用是把“权限校验逻辑”和“业务行为”解耦,实现「一次定义、多处复用、按需生成」——不是写一堆 if 判断,而是用函数工厂批量产出带权限守门员的页面或操作。
预设 Permission 等级,封装成校验策略
先定义清晰的权限等级语义,比如:
-
view:可查看列表/详情(如
user:view) -
edit:可修改(
user:edit) -
manage:可增删改导出(
user:manage) -
admin:通配符兜底(
*:*:*或system:admin)
再把这些语义封装为可复用的校验函数,例如:
const checkPermission = (requiredCode) => {
const userPerms = getCurrentUserPermissions(); // 从 store / token / session 读取
if (userPerms.includes('*:*:*')) return true;
return userPerms.includes(requiredCode);
};
用柯里化批量生成页面拦截器
把路由组件包装成「带权限守门员的版本」,不重复写守卫逻辑:
const withAuthGuard = (permissionCode) => (Component) => {
return (props) => {
if (!checkPermission(permissionCode)) {
return <navigate to="/403" replace></navigate>;
}
return <component></component>;
};
};
然后直接复用:
const UserListPage = withAuthGuard('user:view')(UserList)const UserEditPage = withAuthGuard('user:edit')(UserEdit)const OrderExportPage = withAuthGuard('order:export')(OrderExport)
每个页面都自动获得独立权限校验,且校验逻辑集中维护,改一处全生效。
支持组合权限与异步校验的增强写法
真实场景常需「多个权限任一满足」或「需后端动态确认」,柯里化仍适用:
const withPermissionCheck = ({
validate, // 函数,返回 boolean 或 Promise<boolean>
fallback = () => <forbiddenpage></forbiddenpage>
}) => (Component) => (props) => {
const [authorized, setAuth] = useState(null);
useEffect(() => {
const run = async () => {
const ok = await validate();
setAuth(ok);
};
run();
}, []);
if (authorized === null) return <loading></loading>;
if (authorized === false) return fallback();
return <component></component>;
};</boolean>
使用示例:
withPermissionCheck({ validate: () => hasPerm(['user:edit', 'user:manage']) })withPermissionCheck({ validate: () => api.checkScope('finance:report') })
和按钮/操作级权限联动,保持统一语义
页面拦截器和按钮显隐共用同一套权限码体系,避免前后端口径不一致:
- 菜单渲染时:用
hasPerm('user:list')控制是否显示「用户管理」菜单项 - 页面内按钮:用
hasPerm('user:delete')控制「删除」按钮是否渲染或禁用 - API 调用前:同样调用
hasPerm('user:import')再发请求
所有判断都基于同一个 checkPermission 函数,柯里化只是它对外暴露的「组装接口」,不是额外抽象层。











