LoginController.php 27 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756
  1. <?php
  2. declare(strict_types=1);
  3. namespace App\Controller;
  4. use App\JsonRpc\UserServiceInterface;
  5. use App\Tools\CommonService;
  6. use App\Tools\PublicData;
  7. use App\Tools\Result;
  8. use Hyperf\Context\Context;
  9. use PHPStan\Type\Accessory\OversizedArrayType;
  10. use PHPUnit\Exception;
  11. use function Hyperf\Support\env;
  12. use Hyperf\Di\Annotation\Inject;
  13. use Hyperf\HttpServer\Annotation\AutoController;
  14. use Hyperf\Validation\Contract\ValidatorFactoryInterface;
  15. use \Phper666\JWTAuth\JWT;
  16. use App\Model\UserToken;
  17. use Hyperf\HttpServer\Response;
  18. use Hyperf\HttpMessage\Cookie\Cookie;
  19. use App\Controller\UserController;
  20. use App\JsonRpc\WebsiteServiceInterface;
  21. /**
  22. * @AutoController()
  23. */
  24. class LoginController extends AbstractController
  25. {
  26. #[Inject]
  27. protected ValidatorFactoryInterface $validationFactory;
  28. // protected JWT $JWT;
  29. /**
  30. * @var UserServiceInterface
  31. */
  32. #[Inject]
  33. private $userServiceClient;
  34. /**
  35. * @var WebsiteServiceInterface
  36. */
  37. #[Inject]
  38. private $websiteServiceClient;
  39. /**
  40. * @var Response
  41. */
  42. // private $response;
  43. // public function __construct(Jwt $JWT)
  44. // {
  45. // $this->JWT = $JWT;
  46. // }
  47. public function login(Jwt $jwt)
  48. {
  49. $reqData = $this->request->all();
  50. $validator = $this->validationFactory->make(
  51. $reqData,
  52. [
  53. 'username' => 'required',
  54. 'password' => 'required',
  55. 'type' => 'required',
  56. // 'code' => 'required',
  57. ],
  58. [
  59. 'username.required' => '用户名不能为空',
  60. 'password.required' => '密码不能为空',
  61. 'type.required' => '登录方式必填',
  62. // 'code.required' => 'code方式必填',
  63. ]
  64. );
  65. if ($validator->fails()) {
  66. $errorMessage = $validator->errors()->first();
  67. return Result::error($errorMessage);
  68. }
  69. // $comm = new CommonService();
  70. // $redis = $this->container->get(\Hyperf\Redis\Redis::class);
  71. // $code = $redis->get($reqData['code']);
  72. // if (empty($code)) {
  73. // return Result::error("验证码已过期");
  74. // }
  75. // if (strtolower($code) != strtolower($reqData['captcha'])) {
  76. // return Result::error("验证码错误");
  77. // }
  78. $where = [];
  79. if ($reqData['type'] == 1) { //密码登录
  80. $where = [
  81. 'user_name' => $reqData['username'],
  82. ];
  83. }
  84. $userInfos = $this->userServiceClient->verifyUserInfo($where);
  85. if ($userInfos['code'] == 0) {
  86. return Result::error("用户不存在");
  87. }
  88. if ($userInfos['data']['status'] == 0) {
  89. return Result::error("用户已经冻结");
  90. }
  91. if (md5(md5($reqData['password']) . $userInfos['data']['salt']) != $userInfos['data']['password']) {
  92. return Result::error("登陆密码错误");
  93. }
  94. if ($userInfos['data']['type_id'] != 10000) {
  95. $authData = [
  96. 'id' => $userInfos['data']['sszq'],
  97. 'SiteId' => Context::get("SiteId")
  98. ];
  99. var_dump("参数:", $authData);
  100. $resultAuth = $this->checkUserAuth($authData);
  101. if (!$resultAuth) {
  102. return Result::error("您没有权限登陆此网站");
  103. }
  104. }
  105. $userData = [
  106. 'uid' => $userInfos['data']['id'], // 如果使用单点登录,必须存在配置文件中的sso_key的值,一般设置为用户的id
  107. 'user_name' => $userInfos['data']['user_name'],
  108. 'mobile' => $userInfos['data']['mobile'],
  109. 'email' => $userInfos['data']['email'],
  110. 'level_id' => $userInfos['data']['level_id'],
  111. 'type_id' => $userInfos['data']['type_id'],
  112. 'metadata' => [
  113. 'user_id' => $userInfos['data']['id'] ?? 0,
  114. ],
  115. 'iss' => 'web', // 与 Go 系统保持一致
  116. ];
  117. // 使用默认场景登录
  118. $token = $jwt->getToken('default', $userData);
  119. // 检查是否有旧的token
  120. $old_token = UserToken::where('user_id', $userData['uid'])->first();
  121. if (!empty($old_token)) {
  122. $jwt->logout($old_token->token);
  123. try {
  124. $jwt->verifyToken($old_token->token);
  125. } catch (\Exception $exception) {
  126. $code = $exception->getCode();
  127. if ($code == 400) {
  128. $new_token = UserToken::where('user_id', $userData['uid'])->update(['token' => $token->toString()]);
  129. if (empty($new_token)) {
  130. return Result::error("Token过期失败!");
  131. }
  132. } else {
  133. return Result::error("Token过期失败!");
  134. }
  135. }
  136. } else {
  137. $usernew_token = $token->toString();
  138. $user_token = UserToken::create([
  139. 'user_id' => $userData['uid'],
  140. 'token' => $usernew_token
  141. ]);
  142. if (empty($user_token)) {
  143. return Result::error("登录失败!");
  144. }
  145. }
  146. $claims = [
  147. 'iss' => 'web', // 与 Go 系统保持一致
  148. 'metadata' => [
  149. 'user_id' => $userInfos['data']['id'] ?? 0,
  150. ],
  151. // 可以保留其他字段,但要确保 Go 系统也能处理
  152. // 'exp' => time() + 3600,
  153. // 'iat' => time(),
  154. // 'jti' => md5(uniqid($userInfos['data']['id'] . $userInfos['data']['mobile'] ?? '', true)),
  155. ];
  156. $token_im = $jwt->getToken('default', $claims);
  157. $data = [
  158. 'token' => $token->toString(),
  159. 'token_im' => $token_im->toString(),
  160. 'exp' => $jwt->getTTL($token->toString()),
  161. ];
  162. return Result::success($data);
  163. }
  164. /**
  165. * @return void
  166. */
  167. public function checkVerifyCode(Jwt $jwt)
  168. {
  169. //其它信息暂时不管 先以openid
  170. $reqData = $this->request->all();
  171. $validator = $this->validationFactory->make(
  172. $reqData,
  173. [
  174. 'token' => 'required',
  175. ],
  176. [
  177. 'token.required' => 'token不能为空',
  178. ]
  179. );
  180. if ($validator->fails()) {
  181. $errorMessage = $validator->errors()->first();
  182. return Result::error($errorMessage);
  183. }
  184. $userInfo = $jwt->getClaimsByToken($reqData['token']);
  185. if ($userInfo) {
  186. return Result::success(['token' => $reqData['token']]);
  187. } else {
  188. return Result::error("token无效");
  189. }
  190. }
  191. /**
  192. * 注册或登陆
  193. * @return void
  194. */
  195. public function registerOrLogin(Jwt $jwt)
  196. {
  197. //获取access_token
  198. $reqData = $this->request->all();
  199. $validator = $this->validationFactory->make(
  200. $reqData,
  201. [
  202. 'code' => 'required',
  203. ],
  204. [
  205. 'code.required' => 'code不能为空',
  206. ]
  207. );
  208. if ($validator->fails()) {
  209. $errorMessage = $validator->errors()->first();
  210. return Result::error($errorMessage);
  211. }
  212. $url = env("WECHAT") . "cgi-bin/token?appid=" . env("APPID") . "&secret=" . env("APP_SECRET") . "&grant_type=client_credential";
  213. $result = PublicData::http_get($url);
  214. $accessTokenData = json_decode($result, true);
  215. //获取openid
  216. $url = env("WECHAT") . "sns/jscode2session?appid=" . env("APPID") . "&secret=" . env("APP_SECRET") . "&js_code=" . $reqData['loginCode'] . "&grant_type=authorization_code";
  217. $result = PublicData::http_get($url);
  218. $openInfoData = json_decode($result, true);
  219. if (isset($openInfoData['errcode']) && in_array($openInfoData['errcode'], [40163, 40029])) {
  220. return Result::error($openInfoData['errmsg']);
  221. }
  222. $data = [
  223. 'code' => $reqData['code'],
  224. 'openid' => $openInfoData['openid'],
  225. ];
  226. // 将数组转换为JSON字符串
  227. $jsonData = json_encode($data);
  228. // 初始化cURL会话
  229. $ch = curl_init(env("WECHAT") . "wxa/business/getuserphonenumber?access_token=" . $accessTokenData['access_token']);
  230. // 设置cURL选项 Todo 这里有一万个wc 封装成post方法就报错,后期再研究
  231. curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
  232. curl_setopt($ch, CURLOPT_POST, true);
  233. curl_setopt($ch, CURLOPT_POSTFIELDS, $jsonData);
  234. curl_setopt($ch, CURLOPT_HTTPHEADER, [
  235. 'Content-Type: application/json',
  236. 'Content-Length: ' . strlen($jsonData),
  237. ]);
  238. // 执行cURL会话
  239. $response = curl_exec($ch);
  240. // 检查是否有错误发生
  241. if (curl_errno($ch)) {
  242. return Result::error("获取手机号失败");
  243. }
  244. // 关闭cURL会话
  245. curl_close($ch);
  246. $response = json_decode($response, true);
  247. if ($response['errcode'] == '40029') {
  248. return Result::error($openInfoData['errmsg']);
  249. }
  250. // 打印响应内容
  251. var_dump($openInfoData, $response);
  252. //根据openid 获取token
  253. $checkUserInfo = $this->userServiceClient->verifyUserInfo([
  254. 'user_name' => $response['phone_info']['purePhoneNumber'],
  255. ]);
  256. var_dump("检测返回值用户信息:", $checkUserInfo);
  257. if ($checkUserInfo['code'] == 0) {
  258. $salt = rand(1, 999999);
  259. $createUserData = [
  260. 'user_name' => $response['phone_info']['purePhoneNumber'],
  261. 'salt' => $salt,
  262. 'password' => $openInfoData['openid'],
  263. 'type_id' => 20000,
  264. 'mobile' => $response['phone_info']['purePhoneNumber'],
  265. 'other' => [],
  266. 'city_arr_id' => [],
  267. 'address_arr_id' => []
  268. ];
  269. $checkUserInfo = $this->userServiceClient->createUser($createUserData);
  270. }
  271. var_dump("返回值用户信息:", $checkUserInfo);
  272. //根据openid和手机号判断是否注册,未注册直接注册
  273. $wechatReqData = [
  274. 'openid' => $openInfoData['openid'],
  275. 'purePhoneNumber' => $response['phone_info']['purePhoneNumber'],
  276. ];
  277. $wechatInfo = $this->userServiceClient->getWechatInfo($wechatReqData);
  278. if ($wechatInfo['code'] == 0) {
  279. $wechatData = [
  280. 'openid' => $openInfoData['openid'],
  281. 'phoneNumber' => $response['phone_info']['phoneNumber'],
  282. 'purePhoneNumber' => $response['phone_info']['purePhoneNumber'],
  283. 'countryCode' => $response['phone_info']['countryCode'],
  284. 'watermark' => json_encode($response['phone_info']['watermark']),
  285. 'user_id' => $checkUserInfo['data']['id'] ?? 0,
  286. ];
  287. var_dump("##插入的值:", $wechatData);
  288. $this->userServiceClient->addWechatInfo($wechatData);
  289. }
  290. var_dump($checkUserInfo);
  291. $userData = [
  292. 'uid' => $checkUserInfo['data']['id'] ?? 0, // 如果使用单点登录,必须存在配置文件中的sso_key的值,一般设置为用户的id
  293. 'user_name' => $response['phone_info']['phoneNumber'] ?? '',
  294. 'mobile' => $checkUserInfo['data']['mobile'] ?? '',
  295. 'email' => $checkUserInfo['data']['email'] ?? '',
  296. // 'rong_token' => $userInfos['data']['rong_token'],
  297. 'level_id' => $checkUserInfo['data']['level_id'] ?? '',
  298. 'type_id' => $checkUserInfo['data']['type_id'] ?? '',
  299. ];
  300. // 使用默认场景登录
  301. $token = $jwt->getToken('default', $userData);
  302. $data = [
  303. 'token' => $token->toString(),
  304. 'exp' => $jwt->getTTL($token->toString()),
  305. ];
  306. return Result::success($data);
  307. }
  308. public function getToken(JWT $jwt)
  309. {
  310. $reqData = $this->request->all();
  311. $userInfos = $this->userServiceClient->getUserInfo((int) $reqData['id']);
  312. $userData = [
  313. 'uid' => $userInfos['data']['id'], // 如果使用单点登录,必须存在配置文件中的sso_key的值,一般设置为用户的id
  314. 'user_name' => $userInfos['data']['user_name'],
  315. 'mobile' => $userInfos['data']['mobile'],
  316. 'email' => $userInfos['data']['email'],
  317. 'level_id' => $userInfos['data']['level_id'],
  318. 'type_id' => $userInfos['data']['type_id'],
  319. ];
  320. var_dump($userInfos);
  321. // 使用默认场景登录
  322. $token = $jwt->getToken('default', $userData);
  323. return Result::success($token->toString());
  324. }
  325. public function httpPost() {}
  326. # http头部必须携带token才能访问的路由
  327. public function getData(Jwt $jwt)
  328. {
  329. // var_dump($this->UserId);
  330. $h = $this->request->getHeaders();
  331. // var_dump($this->request->getHeaders());
  332. // $a= 'eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJwaHBlcjY2Ni9qd3QiLCJ1aWQiOjMyLCJ1c2VyX25hbWUiOiIxIiwicm9sZV9pZCI6MSwibW9iaWxlIjoiMTU4MDEyNDU3NTUiLCJlbWFpbCI6IjVAcXEuY29tIiwicm9uZ190b2tlbiI6IiIsImxldmVsX2lkIjo4LCJqd3Rfc2NlbmUiOiJkZWZhdWx0IiwianRpIjoiZGVmYXVsdF82Njc1MjJkZDQ3YWYxMi41MTE5MjI5MiIsImlhdCI6MTcxODk1MjY2OSwibmJmIjoxNzE4OTUyNjY5LCJleHAiOjE3MjE1NDQ2Njl9.e0JW8fgNrwBdFgmQ8GNtES2ME1SbcbIih5MsQWzT6sk';
  333. $arr = $jwt->getClaimsByToken($h['token'][0]);
  334. // var_dump($h['token'][0], "+++++++++++", $arr, "===####");
  335. return $this->response->json(['code' => 0, 'msg' => 'success', 'data' => ['a' => 1]]);
  336. }
  337. /**
  338. * 检测用户权限
  339. * @return void
  340. */
  341. public function checkUserAuth($data)
  342. {
  343. // var_dump("进没进来呢::",$data);
  344. $websiteGroup = [
  345. 'id' => $data['id']
  346. ];
  347. $result = $this->userServiceClient->getWebsiteGroupInfo($websiteGroup);
  348. var_dump("checkUserAuth:", $result);
  349. if ($result['code'] == 200) {
  350. if ($data['SiteId'] && $result['data']['web_ids']) {
  351. if (in_array($data['SiteId'], json_decode($result['data']['web_ids'], true))) {
  352. return true;
  353. } else {
  354. return false;
  355. }
  356. } else {
  357. return false;
  358. }
  359. }
  360. }
  361. /**
  362. * 查询登陆状态
  363. * @return array
  364. * @throws \Psr\Container\ContainerExceptionInterface
  365. * @throws \Psr\Container\NotFoundExceptionInterface
  366. * @throws \RedisException
  367. */
  368. public function loginStatus(Jwt $jwt)
  369. {
  370. $header = $this->request->getHeader('userurl');
  371. $origin = $header[0];
  372. $logindevice = explode("//", $origin);
  373. if (!isset($logindevice[1]) && !$logindevice[1]) {
  374. return Result::error('userurl不存在,请登录');
  375. }
  376. $reqData = $this->request->all();
  377. $validator = $this->validationFactory->make(
  378. $reqData,
  379. [
  380. 'token' => 'required',
  381. ],
  382. [
  383. 'token.required' => 'token不能为空',
  384. ]
  385. );
  386. if ($validator->fails()) {
  387. $errorMessage = $validator->errors()->first();
  388. return Result::error($errorMessage);
  389. }
  390. try {
  391. $jwt->verifyToken($reqData['token']);
  392. $results = $this->checkAuth([
  393. 'token' => $reqData['token'],
  394. 'userurl' => $logindevice[1]
  395. ]);
  396. if ($results['code'] == 200) {
  397. return Result::success(['isLogin' => true]);
  398. } elseif ($results['code'] == -1) {
  399. return Result::error("没有权限登陆" . $logindevice[1] . "这个域名", -1);
  400. } elseif ($results['code'] == -2) {
  401. return Result::error("token已过期", -2);
  402. } else {
  403. return Result::error("参数错误");
  404. }
  405. } catch (\Exception $e) {
  406. return Result::error('token已过期:' . $e->getMessage(), -2);
  407. }
  408. }
  409. /**
  410. *登陆
  411. * @return void
  412. */
  413. public function loginapi()
  414. {
  415. $reqData = $this->request->all();
  416. $validator = $this->validationFactory->make(
  417. $reqData,
  418. [
  419. 'token' => 'required',
  420. ],
  421. [
  422. 'token.required' => 'token不能为空',
  423. ]
  424. );
  425. if ($validator->fails()) {
  426. $errorMessage = $validator->errors()->first();
  427. return Result::error($errorMessage);
  428. }
  429. $redis = $this->container->get(\Hyperf\Redis\Redis::class);
  430. $ticket = md5($reqData['token']);
  431. $res = $redis->set('ticket:' . $ticket, $reqData['token'], 3600 * 24);
  432. if ($res) {
  433. return Result::success(['ticket' => $ticket, 'isSave' => 1]);
  434. } else {
  435. return Result::error('存储失败');
  436. }
  437. }
  438. public function logoutapi(Jwt $jwt)
  439. {
  440. $reqData = $this->request->all();
  441. $validator = $this->validationFactory->make(
  442. $reqData,
  443. [
  444. 'token' => 'required',
  445. ],
  446. [
  447. 'token.required' => 'token不能为空',
  448. ]
  449. );
  450. // 用im_post 申请退出
  451. $imPostUrl = env("IM_POST_URL");
  452. $option = [
  453. 'authorization' => 'Bearer ' . $reqData['token'],
  454. ];
  455. $result = PublicData::im_post($imPostUrl . 'auth/logout', ['token' => $reqData['token']], $option);
  456. var_dump("IM退出返回值:", $result);
  457. var_dump("url:", $imPostUrl . 'auth/logout');
  458. if ($validator->fails()) {
  459. $errorMessage = $validator->errors()->first();
  460. return Result::error($errorMessage);
  461. }
  462. $redis = $this->container->get(\Hyperf\Redis\Redis::class);
  463. $ticket = md5($reqData['token']);
  464. $isDel = 0;
  465. if ($redis->exists('ticket:' . $ticket)) {
  466. $res = $redis->del('ticket:' . $ticket);
  467. if (!!$res && $res == 1) $isDel = 1;
  468. } else {
  469. $isDel = 1;
  470. }
  471. try {
  472. $jwt->logout($reqData['token']);
  473. } catch (\Exception $e) {
  474. return Result::success(['isDel' => $isDel]);
  475. }
  476. return Result::success(['isDel' => $isDel]);
  477. }
  478. public function goLogin()
  479. {
  480. // 获取请求数据并设置默认值
  481. $reqData = $this->request->all();
  482. // 安全过滤 Admin-Token 和 ticket
  483. $cookieList = $this->request->getCookieParams();
  484. // 安全过滤 Admin-Token 和 ticket
  485. $adminToken = !empty($cookieList['Admin-Token']) ? $this->sanitizeInput($cookieList['Admin-Token']) : '';
  486. $ticket = !empty($reqData['ticket']) ? $this->sanitizeInput($reqData['ticket']) : '';
  487. $backurl = $this->sanitizeBackUrl($reqData['backurl'] ?? $_SERVER['HTTP_REFERER'] ?? '');
  488. // 校验 THE_HOST 环境变量
  489. $theHost = env("THE_HOST");
  490. if (empty($theHost)) {
  491. return Result::error('系统配置错误:THE_HOST 未定义');
  492. }
  493. var_dump("admintoken:", $adminToken);
  494. // 如果存在 adminToken,则进行登录校验
  495. if (!empty($adminToken)) {
  496. // 处理登录
  497. $redis = $this->container->get(\Hyperf\Redis\Redis::class);
  498. var_dump("ticket1111:", $ticket);
  499. if (!empty($ticket)) {
  500. if (!empty($ticket) && $redis->exists('ticket:' . $ticket)) {
  501. if (isset($reqData['userurl']) && $reqData['userurl']) {
  502. $resultR = $this->checkAuth([
  503. 'token' => $redis->get('ticket:' . $ticket),
  504. 'userurl' => $reqData['userurl']
  505. ]);
  506. if ($resultR['code'] == -1) {
  507. return $this->response->redirect($this->fun_http('http://' . $theHost . '/#/loginAlert'), 302);
  508. }
  509. } else {
  510. $backurl = rtrim($backurl, '/');
  511. return $this->response->redirect($this->fun_http($backurl . '?ticket=' . $ticket . '&admintoken=' . urlencode($adminToken)), 302);
  512. }
  513. } else {
  514. var_dump("222222222:");
  515. return $this->response->redirect($this->fun_http('http://' . $theHost . '/#/login?backurl=' . urlencode($backurl)), 302);
  516. }
  517. } else {
  518. $ticket = md5($adminToken);
  519. }
  520. var_dump("333333333333333:");
  521. return $this->response->redirect($this->fun_http($backurl . '?ticket=' . $ticket . '&admintoken=' . urlencode($adminToken)), 302);
  522. } else {
  523. var_dump("444444444444444:");
  524. return $this->response->redirect($this->fun_http('http://' . $theHost . '/#/login?backurl=' . urlencode($backurl)), 302);
  525. }
  526. }
  527. /**
  528. * 安全过滤输入数据
  529. * @param string $input
  530. * @return string
  531. */
  532. private function sanitizeInput(string $input): string
  533. {
  534. return htmlspecialchars(trim($input), ENT_QUOTES, 'UTF-8');
  535. }
  536. /**
  537. * 校验并清理 backurl
  538. * @param string $backurl
  539. * @return string
  540. */
  541. private function sanitizeBackUrl(string $backurl): string
  542. {
  543. // 解码并去除多余字符
  544. $decodedUrl = urldecode($backurl);
  545. return filter_var($decodedUrl, FILTER_VALIDATE_URL) ?: '';
  546. }
  547. /**
  548. * 跳转到目标页面
  549. * @param string $backurl
  550. * @param string $ticket
  551. * @param string $adminToken
  552. */
  553. private function redirectWithTicket(string $backurl, string $ticket, string $adminToken)
  554. {
  555. $backurl = rtrim($backurl, '/');
  556. $redirectUrl = $this->fun_http($backurl . '?ticket=' . $ticket . '&admintoken=' . urlencode($adminToken));
  557. // $loginUrl = 'http://' . $theHost . '/#/login?backurl=' . urlencode($backurl);
  558. // return $this->response->redirect($loginUrl, 302);
  559. return $this->response->redirect($redirectUrl, 302);
  560. }
  561. /**
  562. * 处理 URL
  563. * @param string $url
  564. * @return string
  565. */
  566. private function fun_http(string $url): string
  567. {
  568. // 确保 URL 以 http 或 https 开头
  569. if (!preg_match('/^https?:\/\//i', $url)) {
  570. $url = 'http://' . $url;
  571. }
  572. return $url;
  573. }
  574. /**
  575. * 退出
  576. * @return void
  577. */
  578. public function logout(Jwt $jwt)
  579. {
  580. $reqData = $this->request->all();
  581. $validator = $this->validationFactory->make(
  582. $reqData,
  583. [
  584. 'backurl' => 'required',
  585. 'admintoken' => 'required',
  586. ],
  587. [
  588. 'backurl.required' => 'backurl不能为空',
  589. 'admintoken.required' => 'admintoken不能为空',
  590. ]
  591. );
  592. if ($validator->fails()) {
  593. $errorMessage = $validator->errors()->first();
  594. return Result::error($errorMessage);
  595. }
  596. $redis = $this->container->get(\Hyperf\Redis\Redis::class);
  597. $ticket = md5($reqData['admintoken']);
  598. $res = $redis->del('ticket:' . $ticket);
  599. var_dump("删除redis:", $res);
  600. var_dump("获取redis:", $redis->get('ticket:' . $ticket));
  601. // 获取所有 Cookie
  602. $cookies = $this->request->getCookieParams();
  603. var_dump("获取cookie:", $cookies);
  604. if ($cookies) {
  605. foreach ($cookies as $name => $value) {
  606. if ($name) {
  607. $expire = time() - 3600; // 设置过期时间为过去的时间
  608. $cookie = new Cookie((string)$name, '', $expire, '/');
  609. $this->response = $this->response->withCookie($cookie);
  610. }
  611. }
  612. }
  613. try {
  614. $jwt->logout($reqData['admintoken']);
  615. } catch (\Exception $e) {
  616. var_dump("返回错误信息:", $e->getMessage());
  617. }
  618. $backurl = $this->fun_http($reqData['backurl']);
  619. var_dump("返回地址:", $backurl);
  620. return $this->response->redirect($backurl, 302);
  621. }
  622. /**
  623. * 登录回调
  624. * @return void
  625. */
  626. public function backlogin()
  627. {
  628. $reqData = $this->request->all();
  629. var_dump("===============接收参数:", $reqData);
  630. $validator = $this->validationFactory->make(
  631. $reqData,
  632. [
  633. 'backurl' => 'required',
  634. 'token' => 'required',
  635. ],
  636. [
  637. 'backurl.required' => 'backurl不能为空',
  638. 'token.required' => 'token不能为空',
  639. ]
  640. );
  641. if ($validator->fails()) {
  642. $errorMessage = $validator->errors()->first();
  643. return Result::error($errorMessage);
  644. }
  645. $redis = $this->container->get(\Hyperf\Redis\Redis::class);
  646. $ticket = md5($reqData['token']);
  647. $res = $redis->set('ticket:' . $ticket, $reqData['token'], 3600 * 24);
  648. var_dump("===============返回值:", $res);
  649. $expire = time() + 3600 * 24;
  650. $cookieName = 'Admin-Token';
  651. // 创建 Cookie 实例
  652. $cookie = new Cookie($cookieName, $reqData['token'], $expire, '/');
  653. // 清空 Cookie
  654. $r = $this->response = $this->response->withCookie($cookie);
  655. var_dump("设置token:", $r);
  656. if ($res && !empty($ticket)) {
  657. $url = $reqData['backurl'] . '/?ticket=' . $ticket . '&admintoken=' . urlencode($reqData['token']);
  658. $url = $this->fun_http($url);
  659. var_dump("跳转地址gogo:", $url);
  660. return $this->response->redirect($url, 302);
  661. }
  662. }
  663. /**
  664. * 检测用户是否有权限
  665. * @param $data
  666. * @return void
  667. * $data['token]
  668. * $data['userurl']
  669. */
  670. public function checkAuth($data)
  671. {
  672. $jwt = new JWT();
  673. $ver = $jwt->getClaimsByToken($data['token']);
  674. $tokenTime = $jwt->getTokenDynamicCacheTime($data['token']);
  675. if ($tokenTime == 0) {
  676. return Result::error("token已过期,请重新登录", -2);
  677. }
  678. if (isset($data['userurl']) && $data['userurl']) {
  679. $result = $this->websiteServiceClient->getWebsiteId(['website_url' => $data['userurl']]);
  680. if (!isset($result['data']['id']) || !$result['data']['id']) {
  681. return Result::error("网站不存在...", -2);
  682. }
  683. if ($ver['type_id'] != 10000) {
  684. $userInfo = $this->userServiceClient->getUserInfo($ver['uid']);
  685. if ($userInfo['code'] == 200 && isset($userInfo['data']) && !empty($userInfo['data']['sszq'])) {
  686. $sszq = $userInfo['data']['sszq'];
  687. //组id
  688. $authData = [
  689. 'id' => $sszq,
  690. 'SiteId' => $result['data']['id']
  691. ];
  692. // 调用 LoginController 中的 checkUserAuth 方法
  693. $resultAuth = $this->checkUserAuth($authData);
  694. if (!$resultAuth) {
  695. // 如果没有权限,返回错误响应
  696. return Result::error("没有权限登陆此网站...", -1);
  697. } else {
  698. return Result::success([]);
  699. }
  700. } else {
  701. return Result::error("用户没有群组...", -2);
  702. }
  703. } else {
  704. return Result::success([]);
  705. }
  706. } else {
  707. return Result::error("userurl不能为空...", -2);
  708. }
  709. }
  710. }