fix: 手机号查重硬校验 + portal 登录跨组织安全

问题:
1. 后端 createEmployee 只有身份证查重,没有手机号查重,
   同组织内可重复录入相同手机号,导致员工端登录混乱
2. portal 登录用 findFirst 按 phone 查,未考虑跨组织重复,
   多组织同手机号时会登录到错误员工
3. Contracts.tsx 的 AddEmployeeModal 完全没有手机号查重

修复:
1. contract.service.ts createEmployee 添加手机号查重硬校验
   (同组织内 phone 唯一,抛 DUPLICATE_PHONE 错误)
2. portal.routes.ts 密码登录改为 findMany 遍历校验密码,
   验证码登录改为 findMany 取第一个匹配
3. Contracts.tsx AddEmployeeModal 添加手机号查重和警告提示

Generated with [Devin](https://devin.ai)

Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
This commit is contained in:
selfrelease
2026-08-16 10:57:06 +08:00
parent 13f485a049
commit 6b3e1f9d46
3 changed files with 55 additions and 10 deletions
+10
View File
@@ -219,6 +219,16 @@ export async function createEmployee(orgId: string, userId: string, data: any) {
throw { code: 'DUPLICATE_ID_CARD', message: `证件号码已存在:${existing.name}${existing.department}${existing.status === 'ACTIVE' ? '在职' : '离职'}),请确认是否重复录入` }
}
}
// 手机号查重(同组织内不允许重复,影响员工端登录)
if (data.phone) {
const phoneExists = await prisma.employee.findFirst({
where: { orgId, phone: data.phone },
select: { id: true, name: true, department: true, status: true },
})
if (phoneExists) {
throw { code: 'DUPLICATE_PHONE', message: `手机号已存在:${phoneExists.name}${phoneExists.department}${phoneExists.status === 'ACTIVE' ? '在职' : '离职'}),员工端登录需手机号唯一,请确认是否重复录入` }
}
}
const org = await prisma.organization.findUnique({ where: { id: orgId } })
if (org && org.maxEmployees > 0) {