LoginController.php 25 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710
  1. <?php
  2. declare (strict_types = 1);
  3. namespace App\Controller;
  4. use App\JsonRpc\UserServiceInterface;
  5. use App\Tools\CommonService;
  6. use App\Tools\PublicData;
  7. use App\Tools\Result;
  8. use Hyperf\Context\Context;
  9. use PHPStan\Type\Accessory\OversizedArrayType;
  10. use PHPUnit\Exception;
  11. use function Hyperf\Support\env;
  12. use Hyperf\Di\Annotation\Inject;
  13. use Hyperf\HttpServer\Annotation\AutoController;
  14. use Hyperf\Validation\Contract\ValidatorFactoryInterface;
  15. use \Phper666\JWTAuth\JWT;
  16. use App\Model\UserToken;
  17. use Hyperf\HttpServer\Response;
  18. use Hyperf\HttpMessage\Cookie\Cookie;
  19. use App\Controller\UserController;
  20. use App\JsonRpc\WebsiteServiceInterface;
  21. /**
  22. * @AutoController()
  23. */
  24. class LoginController extends AbstractController
  25. {
  26. #[Inject]
  27. protected ValidatorFactoryInterface $validationFactory;
  28. // protected JWT $JWT;
  29. /**
  30. * @var UserServiceInterface
  31. */
  32. #[Inject]
  33. private $userServiceClient;
  34. /**
  35. * @var WebsiteServiceInterface
  36. */
  37. #[Inject]
  38. private $websiteServiceClient;
  39. /**
  40. * @var Response
  41. */
  42. // private $response;
  43. // public function __construct(Jwt $JWT)
  44. // {
  45. // $this->JWT = $JWT;
  46. // }
  47. public function login(Jwt $jwt)
  48. {
  49. $reqData = $this->request->all();
  50. $validator = $this->validationFactory->make(
  51. $reqData,
  52. [
  53. 'username' => 'required',
  54. 'password' => 'required',
  55. 'type' => 'required',
  56. // 'code' => 'required',
  57. ],
  58. [
  59. 'username.required' => '用户名不能为空',
  60. 'password.required' => '密码不能为空',
  61. 'type.required' => '登录方式必填',
  62. // 'code.required' => 'code方式必填',
  63. ]
  64. );
  65. if ($validator->fails()) {
  66. $errorMessage = $validator->errors()->first();
  67. return Result::error($errorMessage);
  68. }
  69. // $comm = new CommonService();
  70. // $redis = $this->container->get(\Hyperf\Redis\Redis::class);
  71. // $code = $redis->get($reqData['code']);
  72. // if (empty($code)) {
  73. // return Result::error("验证码已过期");
  74. // }
  75. // if (strtolower($code) != strtolower($reqData['captcha'])) {
  76. // return Result::error("验证码错误");
  77. // }
  78. $where = [];
  79. if ($reqData['type'] == 1) { //密码登录
  80. $where = [
  81. 'user_name' => $reqData['username'],
  82. ];
  83. }
  84. $userInfos = $this->userServiceClient->verifyUserInfo($where);
  85. if ($userInfos['code'] == 0) {
  86. return Result::error("用户不存在");
  87. }
  88. if($userInfos['data']['status']==0){
  89. return Result::error("用户已经冻结");
  90. }
  91. if (md5(md5($reqData['password']) . $userInfos['data']['salt']) != $userInfos['data']['password']) {
  92. return Result::error("登陆密码错误");
  93. }
  94. if($userInfos['data']['type_id']!=10000){
  95. $authData = [
  96. 'id'=>$userInfos['data']['sszq'],
  97. 'SiteId'=>Context::get("SiteId")
  98. ];
  99. var_dump("参数:",$authData);
  100. $resultAuth = $this->checkUserAuth($authData);
  101. if(!$resultAuth){
  102. return Result::error("您没有权限登陆此网站");
  103. }
  104. }
  105. $userData = [
  106. 'uid' => $userInfos['data']['id'], // 如果使用单点登录,必须存在配置文件中的sso_key的值,一般设置为用户的id
  107. 'user_name' => $userInfos['data']['user_name'],
  108. 'mobile' => $userInfos['data']['mobile'],
  109. 'email' => $userInfos['data']['email'],
  110. 'level_id' => $userInfos['data']['level_id'],
  111. 'type_id' => $userInfos['data']['type_id'],
  112. ];
  113. // 使用默认场景登录
  114. $token = $jwt->getToken('default', $userData);
  115. // 检查是否有旧的token
  116. $old_token = UserToken::where('user_id', $userData['uid'])->first();
  117. if (!empty($old_token)) {
  118. $jwt->logout($old_token->token);
  119. try {
  120. $jwt->verifyToken($old_token->token);
  121. }catch (\Exception $exception){
  122. $code = $exception->getCode();
  123. if ($code== 400) {
  124. $new_token = UserToken::where('user_id', $userData['uid'])->update(['token' => $token->toString()]);
  125. if (empty($new_token)) {
  126. return Result::error("Token过期失败!");
  127. }
  128. } else{
  129. return Result::error("Token过期失败!");
  130. }
  131. }
  132. }else{
  133. $usernew_token = $token->toString();
  134. $user_token = UserToken::create([
  135. 'user_id' => $userData['uid'],
  136. 'token' => $usernew_token
  137. ]);
  138. if (empty($user_token)) {
  139. return Result::error("登录失败!");
  140. }
  141. }
  142. $data = [
  143. 'token' => $token->toString(),
  144. 'exp' => $jwt->getTTL($token->toString()),
  145. ];
  146. return Result::success($data);
  147. }
  148. /**
  149. * @return void
  150. */
  151. public function checkVerifyCode(Jwt $jwt)
  152. {
  153. //其它信息暂时不管 先以openid
  154. $reqData = $this->request->all();
  155. $validator = $this->validationFactory->make(
  156. $reqData,
  157. [
  158. 'token' => 'required',
  159. ],
  160. [
  161. 'token.required' => 'token不能为空',
  162. ]
  163. );
  164. if ($validator->fails()) {
  165. $errorMessage = $validator->errors()->first();
  166. return Result::error($errorMessage);
  167. }
  168. $userInfo = $jwt->getClaimsByToken($reqData['token']);
  169. if ($userInfo) {
  170. return Result::success(['token' => $reqData['token']]);
  171. } else {
  172. return Result::error("token无效");
  173. }
  174. }
  175. /**
  176. * 注册或登陆
  177. * @return void
  178. */
  179. public function registerOrLogin(Jwt $jwt)
  180. {
  181. //获取access_token
  182. $reqData = $this->request->all();
  183. $validator = $this->validationFactory->make(
  184. $reqData,
  185. [
  186. 'code' => 'required',
  187. ],
  188. [
  189. 'code.required' => 'code不能为空',
  190. ]
  191. );
  192. if ($validator->fails()) {
  193. $errorMessage = $validator->errors()->first();
  194. return Result::error($errorMessage);
  195. }
  196. $url = env("WECHAT") . "cgi-bin/token?appid=" . env("APPID") . "&secret=" . env("APP_SECRET") . "&grant_type=client_credential";
  197. $result = PublicData::http_get($url);
  198. $accessTokenData = json_decode($result, true);
  199. //获取openid
  200. $url = env("WECHAT") . "sns/jscode2session?appid=" . env("APPID") . "&secret=" . env("APP_SECRET") . "&js_code=" . $reqData['loginCode'] . "&grant_type=authorization_code";
  201. $result = PublicData::http_get($url);
  202. $openInfoData = json_decode($result, true);
  203. if (isset($openInfoData['errcode']) && in_array($openInfoData['errcode'], [40163, 40029])) {
  204. return Result::error($openInfoData['errmsg']);
  205. }
  206. $data = [
  207. 'code' => $reqData['code'],
  208. 'openid' => $openInfoData['openid'],
  209. ];
  210. // 将数组转换为JSON字符串
  211. $jsonData = json_encode($data);
  212. // 初始化cURL会话
  213. $ch = curl_init(env("WECHAT") . "wxa/business/getuserphonenumber?access_token=" . $accessTokenData['access_token']);
  214. // 设置cURL选项 Todo 这里有一万个wc 封装成post方法就报错,后期再研究
  215. curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
  216. curl_setopt($ch, CURLOPT_POST, true);
  217. curl_setopt($ch, CURLOPT_POSTFIELDS, $jsonData);
  218. curl_setopt($ch, CURLOPT_HTTPHEADER, [
  219. 'Content-Type: application/json',
  220. 'Content-Length: ' . strlen($jsonData),
  221. ]);
  222. // 执行cURL会话
  223. $response = curl_exec($ch);
  224. // 检查是否有错误发生
  225. if (curl_errno($ch)) {
  226. return Result::error("获取手机号失败");
  227. }
  228. // 关闭cURL会话
  229. curl_close($ch);
  230. $response = json_decode($response, true);
  231. if ($response['errcode'] == '40029') {
  232. return Result::error($openInfoData['errmsg']);
  233. }
  234. // 打印响应内容
  235. var_dump($openInfoData, $response);
  236. //根据openid 获取token
  237. $checkUserInfo = $this->userServiceClient->verifyUserInfo([
  238. 'user_name' => $response['phone_info']['purePhoneNumber'],
  239. ]);
  240. if ($checkUserInfo['code'] == 0) {
  241. $salt = rand(1, 999999);
  242. $createUserData = [
  243. 'user_name' => $response['phone_info']['purePhoneNumber'],
  244. 'salt' => $salt,
  245. 'password' => $openInfoData['openid'],
  246. 'type_id' => 20000,
  247. ];
  248. $checkUserInfo = $this->userServiceClient->createUser($createUserData);
  249. }
  250. //根据openid和手机号判断是否注册,未注册直接注册
  251. $wechatReqData = [
  252. 'openid' => $openInfoData['openid'],
  253. 'purePhoneNumber' => $response['phone_info']['purePhoneNumber'],
  254. ];
  255. $wechatInfo = $this->userServiceClient->getWechatInfo($wechatReqData);
  256. if ($wechatInfo['code'] == 0) {
  257. $wechatData = [
  258. 'openid' => $openInfoData['openid'],
  259. 'phoneNumber' => $response['phone_info']['phoneNumber'],
  260. 'purePhoneNumber' => $response['phone_info']['purePhoneNumber'],
  261. 'countryCode' => $response['phone_info']['countryCode'],
  262. 'watermark' => json_encode($response['phone_info']['watermark']),
  263. 'user_id' => $checkUserInfo['data']['id'],
  264. ];
  265. $this->userServiceClient->addWechatInfo($wechatData);
  266. }
  267. var_dump($checkUserInfo);
  268. $userData = [
  269. 'uid' => $checkUserInfo['data']['id'], // 如果使用单点登录,必须存在配置文件中的sso_key的值,一般设置为用户的id
  270. 'user_name' => $response['phone_info']['phoneNumber'],
  271. 'mobile' => $checkUserInfo['data']['mobile'] ?? '',
  272. 'email' => $checkUserInfo['data']['email'],
  273. // 'rong_token' => $userInfos['data']['rong_token'],
  274. 'level_id' => $checkUserInfo['data']['level_id'],
  275. 'type_id' => $checkUserInfo['data']['type_id'],
  276. ];
  277. // 使用默认场景登录
  278. $token = $jwt->getToken('default', $userData);
  279. $data = [
  280. 'token' => $token->toString(),
  281. 'exp' => $jwt->getTTL($token->toString()),
  282. ];
  283. return Result::success($data);
  284. }
  285. public function getToken(JWT $jwt)
  286. {
  287. $reqData = $this->request->all();
  288. $userInfos = $this->userServiceClient->getUserInfo((int) $reqData['id']);
  289. $userData = [
  290. 'uid' => $userInfos['data']['id'], // 如果使用单点登录,必须存在配置文件中的sso_key的值,一般设置为用户的id
  291. 'user_name' => $userInfos['data']['user_name'],
  292. 'mobile' => $userInfos['data']['mobile'],
  293. 'email' => $userInfos['data']['email'],
  294. 'level_id' => $userInfos['data']['level_id'],
  295. 'type_id' => $userInfos['data']['type_id'],
  296. ];
  297. var_dump($userInfos);
  298. // 使用默认场景登录
  299. $token = $jwt->getToken('default', $userData);
  300. return Result::success($token->toString());
  301. }
  302. public function httpPost()
  303. {
  304. }
  305. # http头部必须携带token才能访问的路由
  306. public function getData(Jwt $jwt)
  307. {
  308. // var_dump($this->UserId);
  309. $h = $this->request->getHeaders();
  310. // var_dump($this->request->getHeaders());
  311. // $a= 'eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJwaHBlcjY2Ni9qd3QiLCJ1aWQiOjMyLCJ1c2VyX25hbWUiOiIxIiwicm9sZV9pZCI6MSwibW9iaWxlIjoiMTU4MDEyNDU3NTUiLCJlbWFpbCI6IjVAcXEuY29tIiwicm9uZ190b2tlbiI6IiIsImxldmVsX2lkIjo4LCJqd3Rfc2NlbmUiOiJkZWZhdWx0IiwianRpIjoiZGVmYXVsdF82Njc1MjJkZDQ3YWYxMi41MTE5MjI5MiIsImlhdCI6MTcxODk1MjY2OSwibmJmIjoxNzE4OTUyNjY5LCJleHAiOjE3MjE1NDQ2Njl9.e0JW8fgNrwBdFgmQ8GNtES2ME1SbcbIih5MsQWzT6sk';
  312. $arr = $jwt->getClaimsByToken($h['token'][0]);
  313. var_dump($h['token'][0], "+++++++++++", $arr, "===####");
  314. return $this->response->json(['code' => 0, 'msg' => 'success', 'data' => ['a' => 1]]);
  315. }
  316. /**
  317. * 检测用户权限
  318. * @return void
  319. */
  320. public function checkUserAuth($data)
  321. {
  322. $websiteGroup = [
  323. 'id'=>$data['id']
  324. ];
  325. $result = $this->userServiceClient->getWebsiteGroupInfo($websiteGroup);
  326. if($result['code']==200){
  327. if($data['SiteId'] && $result['data']['web_ids']){
  328. if(in_array($data['SiteId'],json_decode($result['data']['web_ids'],true))){
  329. return true;
  330. }
  331. }else{
  332. return false;
  333. }
  334. }
  335. }
  336. /**
  337. * 查询登陆状态
  338. * @return array
  339. * @throws \Psr\Container\ContainerExceptionInterface
  340. * @throws \Psr\Container\NotFoundExceptionInterface
  341. * @throws \RedisException
  342. */
  343. public function loginStatus(Jwt $jwt)
  344. {
  345. $reqData = $this->request->all();
  346. $validator = $this->validationFactory->make(
  347. $reqData,
  348. [
  349. 'token' => 'required',
  350. ],
  351. [
  352. 'token.required' => 'token不能为空',
  353. ]
  354. );
  355. if ($validator->fails()) {
  356. $errorMessage = $validator->errors()->first();
  357. return Result::error($errorMessage);
  358. }
  359. try {
  360. $status = $jwt->verifyToken($reqData['token']);
  361. // var_dump("状态:",$status);
  362. return Result::success(['isLogin' => true]);
  363. }catch(\Exception $e){
  364. return Result::error('token已过期:'.$e->getMessage());
  365. }
  366. }
  367. /**
  368. *登陆
  369. * @return void
  370. */
  371. public function loginapi()
  372. {
  373. $reqData = $this->request->all();
  374. $validator = $this->validationFactory->make(
  375. $reqData,
  376. [
  377. 'token' => 'required',
  378. ],
  379. [
  380. 'token.required' => 'token不能为空',
  381. ]
  382. );
  383. if ($validator->fails()) {
  384. $errorMessage = $validator->errors()->first();
  385. return Result::error($errorMessage);
  386. }
  387. $redis = $this->container->get(\Hyperf\Redis\Redis::class);
  388. $ticket = md5($reqData['token']);
  389. $res = $redis->set('ticket:' . $ticket, $reqData['token'], 3600*24);
  390. if ($res){
  391. return Result::success(['ticket' => $ticket ,'isSave' => 1]);
  392. } else {
  393. return Result::error('存储失败');
  394. }
  395. }
  396. public function logoutapi(Jwt $jwt)
  397. {
  398. $reqData = $this->request->all();
  399. $validator = $this->validationFactory->make(
  400. $reqData,
  401. [
  402. 'token' => 'required',
  403. ],
  404. [
  405. 'token.required' => 'token不能为空',
  406. ]
  407. );
  408. if ($validator->fails()) {
  409. $errorMessage = $validator->errors()->first();
  410. return Result::error($errorMessage);
  411. }
  412. $redis = $this->container->get(\Hyperf\Redis\Redis::class);
  413. $ticket = md5($reqData['token']);
  414. $isDel = 0;
  415. if ($redis->exists('ticket:' . $ticket)) {
  416. $res = $redis->del('ticket:' . $ticket);
  417. if (!!$res && $res == 1) $isDel = 1;
  418. }else{
  419. $isDel = 1;
  420. }
  421. try {
  422. $jwt->logout($reqData['token']);
  423. }catch (\Exception $e){
  424. return Result::success(['isDel' => $isDel]);
  425. }
  426. return Result::success(['isDel' => $isDel]);
  427. }
  428. public function goLogin()
  429. {
  430. // 获取请求数据并设置默认值
  431. $reqData = $this->request->all();
  432. // 安全过滤 Admin-Token 和 ticket
  433. $cookieList = $this->request->getCookieParams();
  434. // 安全过滤 Admin-Token 和 ticket
  435. $adminToken = !empty($cookieList['Admin-Token']) ? $this->sanitizeInput($cookieList['Admin-Token']) : '';
  436. $ticket = !empty($reqData['ticket']) ? $this->sanitizeInput($reqData['ticket']) : '';
  437. $backurl = $this->sanitizeBackUrl($reqData['backurl'] ?? $_SERVER['HTTP_REFERER'] ?? '');
  438. // 校验 THE_HOST 环境变量
  439. $theHost = env("THE_HOST");
  440. if (empty($theHost)) {
  441. return Result::error('系统配置错误:THE_HOST 未定义');
  442. }
  443. var_dump("admintoken:",$adminToken);
  444. // 如果存在 adminToken,则进行登录校验
  445. if (!empty($adminToken)) {
  446. // 处理登录
  447. $redis = $this->container->get(\Hyperf\Redis\Redis::class);
  448. var_dump("ticket1111:",$ticket);
  449. if(!empty($ticket)){
  450. if (!empty($ticket) && $redis->exists('ticket:' . $ticket)) {
  451. if(isset($reqData['userurl']) && $reqData['userurl']){
  452. $resultR = $this->checkAuth([
  453. 'token'=>$redis->get('ticket:' . $ticket),
  454. 'userurl'=>$reqData['userurl']
  455. ]);
  456. if($resultR['code']==-1){
  457. return $this->response->redirect($this->fun_http('http://'.$theHost.'/#/loginAlert'), 302);
  458. }
  459. }else{
  460. $backurl = rtrim($backurl, '/');
  461. return $this->response->redirect($this->fun_http($backurl . '?ticket=' . $ticket . '&admintoken=' . urlencode($adminToken)), 302);
  462. }
  463. }else{
  464. var_dump("222222222:");
  465. return $this->response->redirect($this->fun_http('http://'.$theHost.'/#/login?backurl='.urlencode($backurl)), 302);
  466. }
  467. }else{
  468. $ticket = md5($adminToken);
  469. }
  470. var_dump("333333333333333:");
  471. return $this->response->redirect($this->fun_http($backurl . '?ticket=' . $ticket . '&admintoken=' . urlencode($adminToken)), 302);
  472. }else{
  473. var_dump("444444444444444:");
  474. return $this->response->redirect($this->fun_http('http://'.$theHost.'/#/login?backurl='.urlencode($backurl)), 302);
  475. }
  476. }
  477. /**
  478. * 安全过滤输入数据
  479. * @param string $input
  480. * @return string
  481. */
  482. private function sanitizeInput(string $input): string
  483. {
  484. return htmlspecialchars(trim($input), ENT_QUOTES, 'UTF-8');
  485. }
  486. /**
  487. * 校验并清理 backurl
  488. * @param string $backurl
  489. * @return string
  490. */
  491. private function sanitizeBackUrl(string $backurl): string
  492. {
  493. // 解码并去除多余字符
  494. $decodedUrl = urldecode($backurl);
  495. return filter_var($decodedUrl, FILTER_VALIDATE_URL) ?: '';
  496. }
  497. /**
  498. * 跳转到目标页面
  499. * @param string $backurl
  500. * @param string $ticket
  501. * @param string $adminToken
  502. */
  503. private function redirectWithTicket(string $backurl, string $ticket, string $adminToken)
  504. {
  505. $backurl = rtrim($backurl, '/');
  506. $redirectUrl = $this->fun_http($backurl . '?ticket=' . $ticket . '&admintoken=' . urlencode($adminToken));
  507. // $loginUrl = 'http://' . $theHost . '/#/login?backurl=' . urlencode($backurl);
  508. // return $this->response->redirect($loginUrl, 302);
  509. return $this->response->redirect($redirectUrl, 302);
  510. }
  511. /**
  512. * 处理 URL
  513. * @param string $url
  514. * @return string
  515. */
  516. private function fun_http(string $url): string
  517. {
  518. // 确保 URL 以 http 或 https 开头
  519. if (!preg_match('/^https?:\/\//i', $url)) {
  520. $url = 'http://' . $url;
  521. }
  522. return $url;
  523. }
  524. /**
  525. * 退出
  526. * @return void
  527. */
  528. public function logout(Jwt $jwt)
  529. {
  530. $reqData = $this->request->all();
  531. $validator = $this->validationFactory->make(
  532. $reqData,
  533. [
  534. 'backurl' => 'required',
  535. 'admintoken' => 'required',
  536. ],
  537. [
  538. 'backurl.required' => 'backurl不能为空',
  539. 'admintoken.required' => 'admintoken不能为空',
  540. ]
  541. );
  542. if ($validator->fails()) {
  543. $errorMessage = $validator->errors()->first();
  544. return Result::error($errorMessage);
  545. }
  546. $redis = $this->container->get(\Hyperf\Redis\Redis::class);
  547. $ticket = md5($reqData['admintoken']);
  548. $res = $redis->del('ticket:' . $ticket);
  549. var_dump("删除redis:", $res);
  550. var_dump("获取redis:", $redis->get('ticket:' . $ticket));
  551. // 获取所有 Cookie
  552. $cookies = $this->request->getCookieParams();
  553. var_dump("获取cookie:", $cookies);
  554. if($cookies){
  555. foreach ($cookies as $name => $value) {
  556. if($name){
  557. $expire = time() - 3600; // 设置过期时间为过去的时间
  558. $cookie = new Cookie((string)$name, '', $expire, '/');
  559. $this->response = $this->response->withCookie($cookie);
  560. }
  561. }
  562. }
  563. try {
  564. $jwt->logout($reqData['admintoken']);
  565. } catch (\Exception $e) {
  566. var_dump("返回错误信息:", $e->getMessage());
  567. }
  568. $backurl = $this->fun_http($reqData['backurl']);
  569. var_dump("返回地址:", $backurl);
  570. return $this->response->redirect($backurl, 302);
  571. }
  572. /**
  573. * 登录回调
  574. * @return void
  575. */
  576. public function backlogin()
  577. {
  578. $reqData = $this->request->all();
  579. var_dump("===============接收参数:",$reqData);
  580. $validator = $this->validationFactory->make(
  581. $reqData,
  582. [
  583. 'backurl' => 'required',
  584. 'token' => 'required',
  585. ],
  586. [
  587. 'backurl.required' => 'backurl不能为空',
  588. 'token.required' => 'token不能为空',
  589. ]
  590. );
  591. if ($validator->fails()) {
  592. $errorMessage = $validator->errors()->first();
  593. return Result::error($errorMessage);
  594. }
  595. $redis = $this->container->get(\Hyperf\Redis\Redis::class);
  596. $ticket = md5($reqData['token']);
  597. $res = $redis->set('ticket:' . $ticket, $reqData['token'], 3600*24);
  598. var_dump("===============返回值:",$res);
  599. $expire = time()+3600*24;
  600. $cookieName = 'Admin-Token';
  601. // 创建 Cookie 实例
  602. $cookie = new Cookie($cookieName, $reqData['token'], $expire, '/');
  603. // 清空 Cookie
  604. $r = $this->response = $this->response->withCookie($cookie);
  605. var_dump("设置token:", $r);
  606. if($res && !empty($ticket)){
  607. $url = $reqData['backurl'] . '/?ticket=' . $ticket . '&admintoken=' . urlencode($reqData['token']);
  608. $url = $this->fun_http($url);
  609. var_dump("跳转地址gogo:",$url);
  610. return $this->response->redirect($url, 302);
  611. }
  612. }
  613. /**
  614. * 检测用户是否有权限
  615. * @param $data
  616. * @return void
  617. * $data['token]
  618. * $data['userurl']
  619. */
  620. public function checkAuth($data)
  621. {
  622. $jwt = new JWT();
  623. $ver =$jwt->getClaimsByToken($data['token']);
  624. $tokenTime = $jwt->getTokenDynamicCacheTime($data['token']);
  625. if($tokenTime==0){
  626. return Result::error("token已过期,请重新登录",-1);
  627. }
  628. if(isset($data['userurl']) && $data['userurl']){
  629. $result = $this->websiteServiceClient->getWebsiteId(['website_url'=>$data['userurl']]);
  630. if(!isset($result['data']['id']) || !$result['data']['id']){
  631. return Result::error("网站不存在...",-1);
  632. }
  633. if($ver['type_id']!=10000){
  634. $userInfo = $this->userServiceClient->getUserInfo($ver['uid']);
  635. if($userInfo['code'] == 200 && isset($userInfo['data']) && !empty($userInfo['data']['sszq'])){
  636. $sszq = $userInfo['data']['sszq'];
  637. //组id
  638. $authData = [
  639. 'id' => $sszq,
  640. 'SiteId' => $result['data']['id']
  641. ];
  642. // 调用 LoginController 中的 checkUserAuth 方法
  643. $resultAuth = $this->checkUserAuth($authData);
  644. if (!$resultAuth) {
  645. // 如果没有权限,返回错误响应
  646. return Result::error("没有权限登陆此网站...",-1);
  647. }
  648. }else{
  649. return Result::error("用户没有群组...",-1);
  650. }
  651. }
  652. }else{
  653. return Result::error("userurl不能为空...",-1);
  654. }
  655. }
  656. }