LoginController.php 26 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735
  1. <?php
  2. declare (strict_types = 1);
  3. namespace App\Controller;
  4. use App\JsonRpc\UserServiceInterface;
  5. use App\Tools\CommonService;
  6. use App\Tools\PublicData;
  7. use App\Tools\Result;
  8. use Hyperf\Context\Context;
  9. use PHPStan\Type\Accessory\OversizedArrayType;
  10. use PHPUnit\Exception;
  11. use function Hyperf\Support\env;
  12. use Hyperf\Di\Annotation\Inject;
  13. use Hyperf\HttpServer\Annotation\AutoController;
  14. use Hyperf\Validation\Contract\ValidatorFactoryInterface;
  15. use \Phper666\JWTAuth\JWT;
  16. use App\Model\UserToken;
  17. use Hyperf\HttpServer\Response;
  18. use Hyperf\HttpMessage\Cookie\Cookie;
  19. use App\Controller\UserController;
  20. use App\JsonRpc\WebsiteServiceInterface;
  21. /**
  22. * @AutoController()
  23. */
  24. class LoginController extends AbstractController
  25. {
  26. #[Inject]
  27. protected ValidatorFactoryInterface $validationFactory;
  28. // protected JWT $JWT;
  29. /**
  30. * @var UserServiceInterface
  31. */
  32. #[Inject]
  33. private $userServiceClient;
  34. /**
  35. * @var WebsiteServiceInterface
  36. */
  37. #[Inject]
  38. private $websiteServiceClient;
  39. /**
  40. * @var Response
  41. */
  42. // private $response;
  43. // public function __construct(Jwt $JWT)
  44. // {
  45. // $this->JWT = $JWT;
  46. // }
  47. public function login(Jwt $jwt)
  48. {
  49. $reqData = $this->request->all();
  50. $validator = $this->validationFactory->make(
  51. $reqData,
  52. [
  53. 'username' => 'required',
  54. 'password' => 'required',
  55. 'type' => 'required',
  56. // 'code' => 'required',
  57. ],
  58. [
  59. 'username.required' => '用户名不能为空',
  60. 'password.required' => '密码不能为空',
  61. 'type.required' => '登录方式必填',
  62. // 'code.required' => 'code方式必填',
  63. ]
  64. );
  65. if ($validator->fails()) {
  66. $errorMessage = $validator->errors()->first();
  67. return Result::error($errorMessage);
  68. }
  69. // $comm = new CommonService();
  70. // $redis = $this->container->get(\Hyperf\Redis\Redis::class);
  71. // $code = $redis->get($reqData['code']);
  72. // if (empty($code)) {
  73. // return Result::error("验证码已过期");
  74. // }
  75. // if (strtolower($code) != strtolower($reqData['captcha'])) {
  76. // return Result::error("验证码错误");
  77. // }
  78. $where = [];
  79. if ($reqData['type'] == 1) { //密码登录
  80. $where = [
  81. 'user_name' => $reqData['username'],
  82. ];
  83. }
  84. $userInfos = $this->userServiceClient->verifyUserInfo($where);
  85. if ($userInfos['code'] == 0) {
  86. return Result::error("用户不存在");
  87. }
  88. if($userInfos['data']['status']==0){
  89. return Result::error("用户已经冻结");
  90. }
  91. if (md5(md5($reqData['password']) . $userInfos['data']['salt']) != $userInfos['data']['password']) {
  92. return Result::error("登陆密码错误");
  93. }
  94. if($userInfos['data']['type_id']!=10000){
  95. $authData = [
  96. 'id'=>$userInfos['data']['sszq'],
  97. 'SiteId'=>Context::get("SiteId")
  98. ];
  99. var_dump("参数:",$authData);
  100. $resultAuth = $this->checkUserAuth($authData);
  101. if(!$resultAuth){
  102. return Result::error("您没有权限登陆此网站");
  103. }
  104. }
  105. $userData = [
  106. 'uid' => $userInfos['data']['id'], // 如果使用单点登录,必须存在配置文件中的sso_key的值,一般设置为用户的id
  107. 'user_name' => $userInfos['data']['user_name'],
  108. 'mobile' => $userInfos['data']['mobile'],
  109. 'email' => $userInfos['data']['email'],
  110. 'level_id' => $userInfos['data']['level_id'],
  111. 'type_id' => $userInfos['data']['type_id'],
  112. ];
  113. // 使用默认场景登录
  114. $token = $jwt->getToken('default', $userData);
  115. // 检查是否有旧的token
  116. $old_token = UserToken::where('user_id', $userData['uid'])->first();
  117. if (!empty($old_token)) {
  118. $jwt->logout($old_token->token);
  119. try {
  120. $jwt->verifyToken($old_token->token);
  121. }catch (\Exception $exception){
  122. $code = $exception->getCode();
  123. if ($code== 400) {
  124. $new_token = UserToken::where('user_id', $userData['uid'])->update(['token' => $token->toString()]);
  125. if (empty($new_token)) {
  126. return Result::error("Token过期失败!");
  127. }
  128. } else{
  129. return Result::error("Token过期失败!");
  130. }
  131. }
  132. }else{
  133. $usernew_token = $token->toString();
  134. $user_token = UserToken::create([
  135. 'user_id' => $userData['uid'],
  136. 'token' => $usernew_token
  137. ]);
  138. if (empty($user_token)) {
  139. return Result::error("登录失败!");
  140. }
  141. }
  142. $data = [
  143. 'token' => $token->toString(),
  144. 'exp' => $jwt->getTTL($token->toString()),
  145. ];
  146. return Result::success($data);
  147. }
  148. /**
  149. * @return void
  150. */
  151. public function checkVerifyCode(Jwt $jwt)
  152. {
  153. //其它信息暂时不管 先以openid
  154. $reqData = $this->request->all();
  155. $validator = $this->validationFactory->make(
  156. $reqData,
  157. [
  158. 'token' => 'required',
  159. ],
  160. [
  161. 'token.required' => 'token不能为空',
  162. ]
  163. );
  164. if ($validator->fails()) {
  165. $errorMessage = $validator->errors()->first();
  166. return Result::error($errorMessage);
  167. }
  168. $userInfo = $jwt->getClaimsByToken($reqData['token']);
  169. if ($userInfo) {
  170. return Result::success(['token' => $reqData['token']]);
  171. } else {
  172. return Result::error("token无效");
  173. }
  174. }
  175. /**
  176. * 注册或登陆
  177. * @return void
  178. */
  179. public function registerOrLogin(Jwt $jwt)
  180. {
  181. //获取access_token
  182. $reqData = $this->request->all();
  183. $validator = $this->validationFactory->make(
  184. $reqData,
  185. [
  186. 'code' => 'required',
  187. ],
  188. [
  189. 'code.required' => 'code不能为空',
  190. ]
  191. );
  192. if ($validator->fails()) {
  193. $errorMessage = $validator->errors()->first();
  194. return Result::error($errorMessage);
  195. }
  196. $url = env("WECHAT") . "cgi-bin/token?appid=" . env("APPID") . "&secret=" . env("APP_SECRET") . "&grant_type=client_credential";
  197. $result = PublicData::http_get($url);
  198. $accessTokenData = json_decode($result, true);
  199. //获取openid
  200. $url = env("WECHAT") . "sns/jscode2session?appid=" . env("APPID") . "&secret=" . env("APP_SECRET") . "&js_code=" . $reqData['loginCode'] . "&grant_type=authorization_code";
  201. $result = PublicData::http_get($url);
  202. $openInfoData = json_decode($result, true);
  203. if (isset($openInfoData['errcode']) && in_array($openInfoData['errcode'], [40163, 40029])) {
  204. return Result::error($openInfoData['errmsg']);
  205. }
  206. $data = [
  207. 'code' => $reqData['code'],
  208. 'openid' => $openInfoData['openid'],
  209. ];
  210. // 将数组转换为JSON字符串
  211. $jsonData = json_encode($data);
  212. // 初始化cURL会话
  213. $ch = curl_init(env("WECHAT") . "wxa/business/getuserphonenumber?access_token=" . $accessTokenData['access_token']);
  214. // 设置cURL选项 Todo 这里有一万个wc 封装成post方法就报错,后期再研究
  215. curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
  216. curl_setopt($ch, CURLOPT_POST, true);
  217. curl_setopt($ch, CURLOPT_POSTFIELDS, $jsonData);
  218. curl_setopt($ch, CURLOPT_HTTPHEADER, [
  219. 'Content-Type: application/json',
  220. 'Content-Length: ' . strlen($jsonData),
  221. ]);
  222. // 执行cURL会话
  223. $response = curl_exec($ch);
  224. // 检查是否有错误发生
  225. if (curl_errno($ch)) {
  226. return Result::error("获取手机号失败");
  227. }
  228. // 关闭cURL会话
  229. curl_close($ch);
  230. $response = json_decode($response, true);
  231. if ($response['errcode'] == '40029') {
  232. return Result::error($openInfoData['errmsg']);
  233. }
  234. // 打印响应内容
  235. var_dump($openInfoData, $response);
  236. //根据openid 获取token
  237. $checkUserInfo = $this->userServiceClient->verifyUserInfo([
  238. 'user_name' => $response['phone_info']['purePhoneNumber'],
  239. ]);
  240. if ($checkUserInfo['code'] == 0) {
  241. $salt = rand(1, 999999);
  242. $createUserData = [
  243. 'user_name' => $response['phone_info']['purePhoneNumber'],
  244. 'salt' => $salt,
  245. 'password' => $openInfoData['openid'],
  246. 'type_id' => 20000,
  247. ];
  248. $checkUserInfo = $this->userServiceClient->createUser($createUserData);
  249. }
  250. //根据openid和手机号判断是否注册,未注册直接注册
  251. $wechatReqData = [
  252. 'openid' => $openInfoData['openid'],
  253. 'purePhoneNumber' => $response['phone_info']['purePhoneNumber'],
  254. ];
  255. $wechatInfo = $this->userServiceClient->getWechatInfo($wechatReqData);
  256. if ($wechatInfo['code'] == 0) {
  257. $wechatData = [
  258. 'openid' => $openInfoData['openid'],
  259. 'phoneNumber' => $response['phone_info']['phoneNumber'],
  260. 'purePhoneNumber' => $response['phone_info']['purePhoneNumber'],
  261. 'countryCode' => $response['phone_info']['countryCode'],
  262. 'watermark' => json_encode($response['phone_info']['watermark']),
  263. 'user_id' => $checkUserInfo['data']['id'],
  264. ];
  265. $this->userServiceClient->addWechatInfo($wechatData);
  266. }
  267. var_dump($checkUserInfo);
  268. $userData = [
  269. 'uid' => $checkUserInfo['data']['id'], // 如果使用单点登录,必须存在配置文件中的sso_key的值,一般设置为用户的id
  270. 'user_name' => $response['phone_info']['phoneNumber'],
  271. 'mobile' => $checkUserInfo['data']['mobile'] ?? '',
  272. 'email' => $checkUserInfo['data']['email'],
  273. // 'rong_token' => $userInfos['data']['rong_token'],
  274. 'level_id' => $checkUserInfo['data']['level_id'],
  275. 'type_id' => $checkUserInfo['data']['type_id'],
  276. ];
  277. // 使用默认场景登录
  278. $token = $jwt->getToken('default', $userData);
  279. $data = [
  280. 'token' => $token->toString(),
  281. 'exp' => $jwt->getTTL($token->toString()),
  282. ];
  283. return Result::success($data);
  284. }
  285. public function getToken(JWT $jwt)
  286. {
  287. $reqData = $this->request->all();
  288. $userInfos = $this->userServiceClient->getUserInfo((int) $reqData['id']);
  289. $userData = [
  290. 'uid' => $userInfos['data']['id'], // 如果使用单点登录,必须存在配置文件中的sso_key的值,一般设置为用户的id
  291. 'user_name' => $userInfos['data']['user_name'],
  292. 'mobile' => $userInfos['data']['mobile'],
  293. 'email' => $userInfos['data']['email'],
  294. 'level_id' => $userInfos['data']['level_id'],
  295. 'type_id' => $userInfos['data']['type_id'],
  296. ];
  297. var_dump($userInfos);
  298. // 使用默认场景登录
  299. $token = $jwt->getToken('default', $userData);
  300. return Result::success($token->toString());
  301. }
  302. public function httpPost()
  303. {
  304. }
  305. # http头部必须携带token才能访问的路由
  306. public function getData(Jwt $jwt)
  307. {
  308. // var_dump($this->UserId);
  309. $h = $this->request->getHeaders();
  310. // var_dump($this->request->getHeaders());
  311. // $a= 'eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJwaHBlcjY2Ni9qd3QiLCJ1aWQiOjMyLCJ1c2VyX25hbWUiOiIxIiwicm9sZV9pZCI6MSwibW9iaWxlIjoiMTU4MDEyNDU3NTUiLCJlbWFpbCI6IjVAcXEuY29tIiwicm9uZ190b2tlbiI6IiIsImxldmVsX2lkIjo4LCJqd3Rfc2NlbmUiOiJkZWZhdWx0IiwianRpIjoiZGVmYXVsdF82Njc1MjJkZDQ3YWYxMi41MTE5MjI5MiIsImlhdCI6MTcxODk1MjY2OSwibmJmIjoxNzE4OTUyNjY5LCJleHAiOjE3MjE1NDQ2Njl9.e0JW8fgNrwBdFgmQ8GNtES2ME1SbcbIih5MsQWzT6sk';
  312. $arr = $jwt->getClaimsByToken($h['token'][0]);
  313. var_dump($h['token'][0], "+++++++++++", $arr, "===####");
  314. return $this->response->json(['code' => 0, 'msg' => 'success', 'data' => ['a' => 1]]);
  315. }
  316. /**
  317. * 检测用户权限
  318. * @return void
  319. */
  320. public function checkUserAuth($data)
  321. {
  322. // var_dump("进没进来呢::",$data);
  323. $websiteGroup = [
  324. 'id'=>$data['id']
  325. ];
  326. $result = $this->userServiceClient->getWebsiteGroupInfo($websiteGroup);
  327. // var_dump("checkUserAuth:",$result);
  328. if($result['code']==200){
  329. if($data['SiteId'] && $result['data']['web_ids']){
  330. if(in_array($data['SiteId'],json_decode($result['data']['web_ids'],true))){
  331. return true;
  332. }else{
  333. return false;
  334. }
  335. }else{
  336. return false;
  337. }
  338. }
  339. }
  340. /**
  341. * 查询登陆状态
  342. * @return array
  343. * @throws \Psr\Container\ContainerExceptionInterface
  344. * @throws \Psr\Container\NotFoundExceptionInterface
  345. * @throws \RedisException
  346. */
  347. public function loginStatus(Jwt $jwt)
  348. {
  349. $header = $this->request->getHeader('userurl');
  350. $origin = $header[0];
  351. $logindevice = explode("//", $origin);
  352. if(!isset($logindevice[1]) && !$logindevice[1]){
  353. return Result::error('userurl不存在,请登录');
  354. }
  355. $reqData = $this->request->all();
  356. $validator = $this->validationFactory->make(
  357. $reqData,
  358. [
  359. 'token' => 'required',
  360. ],
  361. [
  362. 'token.required' => 'token不能为空',
  363. ]
  364. );
  365. if ($validator->fails()) {
  366. $errorMessage = $validator->errors()->first();
  367. return Result::error($errorMessage);
  368. }
  369. try {
  370. $jwt->verifyToken($reqData['token']);
  371. $results = $this->checkAuth([
  372. 'token'=>$reqData['token'],
  373. 'userurl'=>$logindevice[1]
  374. ]);
  375. if($results['code']==200){
  376. return Result::success(['isLogin' => true]);
  377. }elseif($results['code']==-1){
  378. return Result::error("没有权限登陆".$logindevice[1]."这个域名",-1);
  379. }elseif($results['code']==-2){
  380. return Result::error("token已过期",-2);
  381. }else{
  382. return Result::error("参数错误");
  383. }
  384. }catch(\Exception $e){
  385. return Result::error('token已过期:'.$e->getMessage(),-2);
  386. }
  387. }
  388. /**
  389. *登陆
  390. * @return void
  391. */
  392. public function loginapi()
  393. {
  394. $reqData = $this->request->all();
  395. $validator = $this->validationFactory->make(
  396. $reqData,
  397. [
  398. 'token' => 'required',
  399. ],
  400. [
  401. 'token.required' => 'token不能为空',
  402. ]
  403. );
  404. if ($validator->fails()) {
  405. $errorMessage = $validator->errors()->first();
  406. return Result::error($errorMessage);
  407. }
  408. $redis = $this->container->get(\Hyperf\Redis\Redis::class);
  409. $ticket = md5($reqData['token']);
  410. $res = $redis->set('ticket:' . $ticket, $reqData['token'], 3600*24);
  411. if ($res){
  412. return Result::success(['ticket' => $ticket ,'isSave' => 1]);
  413. } else {
  414. return Result::error('存储失败');
  415. }
  416. }
  417. public function logoutapi(Jwt $jwt)
  418. {
  419. $reqData = $this->request->all();
  420. $validator = $this->validationFactory->make(
  421. $reqData,
  422. [
  423. 'token' => 'required',
  424. ],
  425. [
  426. 'token.required' => 'token不能为空',
  427. ]
  428. );
  429. if ($validator->fails()) {
  430. $errorMessage = $validator->errors()->first();
  431. return Result::error($errorMessage);
  432. }
  433. $redis = $this->container->get(\Hyperf\Redis\Redis::class);
  434. $ticket = md5($reqData['token']);
  435. $isDel = 0;
  436. if ($redis->exists('ticket:' . $ticket)) {
  437. $res = $redis->del('ticket:' . $ticket);
  438. if (!!$res && $res == 1) $isDel = 1;
  439. }else{
  440. $isDel = 1;
  441. }
  442. try {
  443. $jwt->logout($reqData['token']);
  444. }catch (\Exception $e){
  445. return Result::success(['isDel' => $isDel]);
  446. }
  447. return Result::success(['isDel' => $isDel]);
  448. }
  449. public function goLogin()
  450. {
  451. // 获取请求数据并设置默认值
  452. $reqData = $this->request->all();
  453. // 安全过滤 Admin-Token 和 ticket
  454. $cookieList = $this->request->getCookieParams();
  455. // 安全过滤 Admin-Token 和 ticket
  456. $adminToken = !empty($cookieList['Admin-Token']) ? $this->sanitizeInput($cookieList['Admin-Token']) : '';
  457. $ticket = !empty($reqData['ticket']) ? $this->sanitizeInput($reqData['ticket']) : '';
  458. $backurl = $this->sanitizeBackUrl($reqData['backurl'] ?? $_SERVER['HTTP_REFERER'] ?? '');
  459. // 校验 THE_HOST 环境变量
  460. $theHost = env("THE_HOST");
  461. if (empty($theHost)) {
  462. return Result::error('系统配置错误:THE_HOST 未定义');
  463. }
  464. var_dump("admintoken:",$adminToken);
  465. // 如果存在 adminToken,则进行登录校验
  466. if (!empty($adminToken)) {
  467. // 处理登录
  468. $redis = $this->container->get(\Hyperf\Redis\Redis::class);
  469. var_dump("ticket1111:",$ticket);
  470. if(!empty($ticket)){
  471. if (!empty($ticket) && $redis->exists('ticket:' . $ticket)) {
  472. if(isset($reqData['userurl']) && $reqData['userurl']){
  473. $resultR = $this->checkAuth([
  474. 'token'=>$redis->get('ticket:' . $ticket),
  475. 'userurl'=>$reqData['userurl']
  476. ]);
  477. if($resultR['code']==-1){
  478. return $this->response->redirect($this->fun_http('http://'.$theHost.'/#/loginAlert'), 302);
  479. }
  480. }else{
  481. $backurl = rtrim($backurl, '/');
  482. return $this->response->redirect($this->fun_http($backurl . '?ticket=' . $ticket . '&admintoken=' . urlencode($adminToken)), 302);
  483. }
  484. }else{
  485. var_dump("222222222:");
  486. return $this->response->redirect($this->fun_http('http://'.$theHost.'/#/login?backurl='.urlencode($backurl)), 302);
  487. }
  488. }else{
  489. $ticket = md5($adminToken);
  490. }
  491. var_dump("333333333333333:");
  492. return $this->response->redirect($this->fun_http($backurl . '?ticket=' . $ticket . '&admintoken=' . urlencode($adminToken)), 302);
  493. }else{
  494. var_dump("444444444444444:");
  495. return $this->response->redirect($this->fun_http('http://'.$theHost.'/#/login?backurl='.urlencode($backurl)), 302);
  496. }
  497. }
  498. /**
  499. * 安全过滤输入数据
  500. * @param string $input
  501. * @return string
  502. */
  503. private function sanitizeInput(string $input): string
  504. {
  505. return htmlspecialchars(trim($input), ENT_QUOTES, 'UTF-8');
  506. }
  507. /**
  508. * 校验并清理 backurl
  509. * @param string $backurl
  510. * @return string
  511. */
  512. private function sanitizeBackUrl(string $backurl): string
  513. {
  514. // 解码并去除多余字符
  515. $decodedUrl = urldecode($backurl);
  516. return filter_var($decodedUrl, FILTER_VALIDATE_URL) ?: '';
  517. }
  518. /**
  519. * 跳转到目标页面
  520. * @param string $backurl
  521. * @param string $ticket
  522. * @param string $adminToken
  523. */
  524. private function redirectWithTicket(string $backurl, string $ticket, string $adminToken)
  525. {
  526. $backurl = rtrim($backurl, '/');
  527. $redirectUrl = $this->fun_http($backurl . '?ticket=' . $ticket . '&admintoken=' . urlencode($adminToken));
  528. // $loginUrl = 'http://' . $theHost . '/#/login?backurl=' . urlencode($backurl);
  529. // return $this->response->redirect($loginUrl, 302);
  530. return $this->response->redirect($redirectUrl, 302);
  531. }
  532. /**
  533. * 处理 URL
  534. * @param string $url
  535. * @return string
  536. */
  537. private function fun_http(string $url): string
  538. {
  539. // 确保 URL 以 http 或 https 开头
  540. if (!preg_match('/^https?:\/\//i', $url)) {
  541. $url = 'http://' . $url;
  542. }
  543. return $url;
  544. }
  545. /**
  546. * 退出
  547. * @return void
  548. */
  549. public function logout(Jwt $jwt)
  550. {
  551. $reqData = $this->request->all();
  552. $validator = $this->validationFactory->make(
  553. $reqData,
  554. [
  555. 'backurl' => 'required',
  556. 'admintoken' => 'required',
  557. ],
  558. [
  559. 'backurl.required' => 'backurl不能为空',
  560. 'admintoken.required' => 'admintoken不能为空',
  561. ]
  562. );
  563. if ($validator->fails()) {
  564. $errorMessage = $validator->errors()->first();
  565. return Result::error($errorMessage);
  566. }
  567. $redis = $this->container->get(\Hyperf\Redis\Redis::class);
  568. $ticket = md5($reqData['admintoken']);
  569. $res = $redis->del('ticket:' . $ticket);
  570. var_dump("删除redis:", $res);
  571. var_dump("获取redis:", $redis->get('ticket:' . $ticket));
  572. // 获取所有 Cookie
  573. $cookies = $this->request->getCookieParams();
  574. var_dump("获取cookie:", $cookies);
  575. if($cookies){
  576. foreach ($cookies as $name => $value) {
  577. if($name){
  578. $expire = time() - 3600; // 设置过期时间为过去的时间
  579. $cookie = new Cookie((string)$name, '', $expire, '/');
  580. $this->response = $this->response->withCookie($cookie);
  581. }
  582. }
  583. }
  584. try {
  585. $jwt->logout($reqData['admintoken']);
  586. } catch (\Exception $e) {
  587. var_dump("返回错误信息:", $e->getMessage());
  588. }
  589. $backurl = $this->fun_http($reqData['backurl']);
  590. var_dump("返回地址:", $backurl);
  591. return $this->response->redirect($backurl, 302);
  592. }
  593. /**
  594. * 登录回调
  595. * @return void
  596. */
  597. public function backlogin()
  598. {
  599. $reqData = $this->request->all();
  600. var_dump("===============接收参数:",$reqData);
  601. $validator = $this->validationFactory->make(
  602. $reqData,
  603. [
  604. 'backurl' => 'required',
  605. 'token' => 'required',
  606. ],
  607. [
  608. 'backurl.required' => 'backurl不能为空',
  609. 'token.required' => 'token不能为空',
  610. ]
  611. );
  612. if ($validator->fails()) {
  613. $errorMessage = $validator->errors()->first();
  614. return Result::error($errorMessage);
  615. }
  616. $redis = $this->container->get(\Hyperf\Redis\Redis::class);
  617. $ticket = md5($reqData['token']);
  618. $res = $redis->set('ticket:' . $ticket, $reqData['token'], 3600*24);
  619. var_dump("===============返回值:",$res);
  620. $expire = time()+3600*24;
  621. $cookieName = 'Admin-Token';
  622. // 创建 Cookie 实例
  623. $cookie = new Cookie($cookieName, $reqData['token'], $expire, '/');
  624. // 清空 Cookie
  625. $r = $this->response = $this->response->withCookie($cookie);
  626. var_dump("设置token:", $r);
  627. if($res && !empty($ticket)){
  628. $url = $reqData['backurl'] . '/?ticket=' . $ticket . '&admintoken=' . urlencode($reqData['token']);
  629. $url = $this->fun_http($url);
  630. var_dump("跳转地址gogo:",$url);
  631. return $this->response->redirect($url, 302);
  632. }
  633. }
  634. /**
  635. * 检测用户是否有权限
  636. * @param $data
  637. * @return void
  638. * $data['token]
  639. * $data['userurl']
  640. */
  641. public function checkAuth($data)
  642. {
  643. $jwt = new JWT();
  644. $ver =$jwt->getClaimsByToken($data['token']);
  645. $tokenTime = $jwt->getTokenDynamicCacheTime($data['token']);
  646. if($tokenTime==0){
  647. return Result::error("token已过期,请重新登录",-2);
  648. }
  649. if(isset($data['userurl']) && $data['userurl']){
  650. $result = $this->websiteServiceClient->getWebsiteId(['website_url'=>$data['userurl']]);
  651. if(!isset($result['data']['id']) || !$result['data']['id']){
  652. return Result::error("网站不存在...",-2);
  653. }
  654. if($ver['type_id']!=10000){
  655. $userInfo = $this->userServiceClient->getUserInfo($ver['uid']);
  656. if($userInfo['code'] == 200 && isset($userInfo['data']) && !empty($userInfo['data']['sszq'])){
  657. $sszq = $userInfo['data']['sszq'];
  658. //组id
  659. $authData = [
  660. 'id' => $sszq,
  661. 'SiteId' => $result['data']['id']
  662. ];
  663. // 调用 LoginController 中的 checkUserAuth 方法
  664. $resultAuth = $this->checkUserAuth($authData);
  665. if (!$resultAuth) {
  666. // 如果没有权限,返回错误响应
  667. return Result::error("没有权限登陆此网站...",-1);
  668. }else{
  669. return Result::success([]);
  670. }
  671. }else{
  672. return Result::error("用户没有群组...",-2);
  673. }
  674. }else{
  675. return Result::success([]);
  676. }
  677. }else{
  678. return Result::error("userurl不能为空...",-2);
  679. }
  680. }
  681. }