LoginController.php 21 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620
  1. <?php
  2. declare (strict_types = 1);
  3. namespace App\Controller;
  4. use App\JsonRpc\UserServiceInterface;
  5. use App\Tools\CommonService;
  6. use App\Tools\PublicData;
  7. use App\Tools\Result;
  8. use Hyperf\Context\Context;
  9. use PHPStan\Type\Accessory\OversizedArrayType;
  10. use PHPUnit\Exception;
  11. use function Hyperf\Support\env;
  12. use Hyperf\Di\Annotation\Inject;
  13. use Hyperf\HttpServer\Annotation\AutoController;
  14. use Hyperf\Validation\Contract\ValidatorFactoryInterface;
  15. use \Phper666\JWTAuth\JWT;
  16. use App\Model\UserToken;
  17. use Hyperf\HttpServer\Response;
  18. /**
  19. * @AutoController()
  20. */
  21. class LoginController extends AbstractController
  22. {
  23. #[Inject]
  24. protected ValidatorFactoryInterface $validationFactory;
  25. /**
  26. * @var UserServiceInterface
  27. */
  28. #[Inject]
  29. private $userServiceClient;
  30. /**
  31. * @var Response
  32. */
  33. // private $response;
  34. // public function __construct(Response $response)
  35. // {
  36. // $this->response = $response;
  37. // }
  38. public function login(Jwt $jwt)
  39. {
  40. $reqData = $this->request->all();
  41. $validator = $this->validationFactory->make(
  42. $reqData,
  43. [
  44. 'username' => 'required',
  45. 'password' => 'required',
  46. 'type' => 'required',
  47. // 'code' => 'required',
  48. ],
  49. [
  50. 'username.required' => '用户名不能为空',
  51. 'password.required' => '密码不能为空',
  52. 'type.required' => '登录方式必填',
  53. // 'code.required' => 'code方式必填',
  54. ]
  55. );
  56. if ($validator->fails()) {
  57. $errorMessage = $validator->errors()->first();
  58. return Result::error($errorMessage);
  59. }
  60. // $comm = new CommonService();
  61. // $redis = $this->container->get(\Hyperf\Redis\Redis::class);
  62. // $code = $redis->get($reqData['code']);
  63. // if (empty($code)) {
  64. // return Result::error("验证码已过期");
  65. // }
  66. // if (strtolower($code) != strtolower($reqData['captcha'])) {
  67. // return Result::error("验证码错误");
  68. // }
  69. $where = [];
  70. if ($reqData['type'] == 1) { //密码登录
  71. $where = [
  72. 'user_name' => $reqData['username'],
  73. ];
  74. }
  75. $userInfos = $this->userServiceClient->verifyUserInfo($where);
  76. if ($userInfos['code'] == 0) {
  77. return Result::error("用户不存在");
  78. }
  79. if($userInfos['data']['status']==0){
  80. return Result::error("用户已经冻结");
  81. }
  82. if (md5(md5($reqData['password']) . $userInfos['data']['salt']) != $userInfos['data']['password']) {
  83. return Result::error("登陆密码错误");
  84. }
  85. if($userInfos['data']['type_id']!=10000){
  86. $authData = [
  87. 'id'=>$userInfos['data']['sszq'],
  88. 'SiteId'=>Context::get("SiteId")
  89. ];
  90. var_dump("参数:",$authData);
  91. $resultAuth = $this->checkUserAuth($authData);
  92. if(!$resultAuth){
  93. return Result::error("您没有权限登陆此网站");
  94. }
  95. }
  96. $userData = [
  97. 'uid' => $userInfos['data']['id'], // 如果使用单点登录,必须存在配置文件中的sso_key的值,一般设置为用户的id
  98. 'user_name' => $userInfos['data']['user_name'],
  99. 'mobile' => $userInfos['data']['mobile'],
  100. 'email' => $userInfos['data']['email'],
  101. 'level_id' => $userInfos['data']['level_id'],
  102. 'type_id' => $userInfos['data']['type_id'],
  103. ];
  104. // 使用默认场景登录
  105. $token = $jwt->getToken('default', $userData);
  106. // 检查是否有旧的token
  107. $old_token = UserToken::where('user_id', $userData['uid'])->first();
  108. if (!empty($old_token)) {
  109. $jwt->logout($old_token->token);
  110. try {
  111. $jwt->verifyToken($old_token->token);
  112. }catch (\Exception $exception){
  113. $code = $exception->getCode();
  114. if ($code== 400) {
  115. $new_token = UserToken::where('user_id', $userData['uid'])->update(['token' => $token->toString()]);
  116. if (empty($new_token)) {
  117. return Result::error("Token过期失败!");
  118. }
  119. } else{
  120. return Result::error("Token过期失败!");
  121. }
  122. }
  123. }else{
  124. $usernew_token = $token->toString();
  125. $user_token = UserToken::create([
  126. 'user_id' => $userData['uid'],
  127. 'token' => $usernew_token
  128. ]);
  129. if (empty($user_token)) {
  130. return Result::error("登录失败!");
  131. }
  132. }
  133. $data = [
  134. 'token' => $token->toString(),
  135. 'exp' => $jwt->getTTL($token->toString()),
  136. ];
  137. return Result::success($data);
  138. }
  139. /**
  140. * @return void
  141. */
  142. public function checkVerifyCode(Jwt $jwt)
  143. {
  144. //其它信息暂时不管 先以openid
  145. $reqData = $this->request->all();
  146. $validator = $this->validationFactory->make(
  147. $reqData,
  148. [
  149. 'token' => 'required',
  150. ],
  151. [
  152. 'token.required' => 'token不能为空',
  153. ]
  154. );
  155. if ($validator->fails()) {
  156. $errorMessage = $validator->errors()->first();
  157. return Result::error($errorMessage);
  158. }
  159. $userInfo = $jwt->getClaimsByToken($reqData['token']);
  160. if ($userInfo) {
  161. return Result::success(['token' => $reqData['token']]);
  162. } else {
  163. return Result::error("token无效");
  164. }
  165. }
  166. /**
  167. * 注册或登陆
  168. * @return void
  169. */
  170. public function registerOrLogin(Jwt $jwt)
  171. {
  172. //获取access_token
  173. $reqData = $this->request->all();
  174. $validator = $this->validationFactory->make(
  175. $reqData,
  176. [
  177. 'code' => 'required',
  178. ],
  179. [
  180. 'code.required' => 'code不能为空',
  181. ]
  182. );
  183. if ($validator->fails()) {
  184. $errorMessage = $validator->errors()->first();
  185. return Result::error($errorMessage);
  186. }
  187. $url = env("WECHAT") . "cgi-bin/token?appid=" . env("APPID") . "&secret=" . env("APP_SECRET") . "&grant_type=client_credential";
  188. $result = PublicData::http_get($url);
  189. $accessTokenData = json_decode($result, true);
  190. //获取openid
  191. $url = env("WECHAT") . "sns/jscode2session?appid=" . env("APPID") . "&secret=" . env("APP_SECRET") . "&js_code=" . $reqData['loginCode'] . "&grant_type=authorization_code";
  192. $result = PublicData::http_get($url);
  193. $openInfoData = json_decode($result, true);
  194. if (isset($openInfoData['errcode']) && in_array($openInfoData['errcode'], [40163, 40029])) {
  195. return Result::error($openInfoData['errmsg']);
  196. }
  197. $data = [
  198. 'code' => $reqData['code'],
  199. 'openid' => $openInfoData['openid'],
  200. ];
  201. // 将数组转换为JSON字符串
  202. $jsonData = json_encode($data);
  203. // 初始化cURL会话
  204. $ch = curl_init(env("WECHAT") . "wxa/business/getuserphonenumber?access_token=" . $accessTokenData['access_token']);
  205. // 设置cURL选项 Todo 这里有一万个wc 封装成post方法就报错,后期再研究
  206. curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
  207. curl_setopt($ch, CURLOPT_POST, true);
  208. curl_setopt($ch, CURLOPT_POSTFIELDS, $jsonData);
  209. curl_setopt($ch, CURLOPT_HTTPHEADER, [
  210. 'Content-Type: application/json',
  211. 'Content-Length: ' . strlen($jsonData),
  212. ]);
  213. // 执行cURL会话
  214. $response = curl_exec($ch);
  215. // 检查是否有错误发生
  216. if (curl_errno($ch)) {
  217. return Result::error("获取手机号失败");
  218. }
  219. // 关闭cURL会话
  220. curl_close($ch);
  221. $response = json_decode($response, true);
  222. if ($response['errcode'] == '40029') {
  223. return Result::error($openInfoData['errmsg']);
  224. }
  225. // 打印响应内容
  226. var_dump($openInfoData, $response);
  227. //根据openid 获取token
  228. $checkUserInfo = $this->userServiceClient->verifyUserInfo([
  229. 'user_name' => $response['phone_info']['purePhoneNumber'],
  230. ]);
  231. if ($checkUserInfo['code'] == 0) {
  232. $salt = rand(1, 999999);
  233. $createUserData = [
  234. 'user_name' => $response['phone_info']['purePhoneNumber'],
  235. 'salt' => $salt,
  236. 'password' => $openInfoData['openid'],
  237. 'type_id' => 20000,
  238. ];
  239. $checkUserInfo = $this->userServiceClient->createUser($createUserData);
  240. }
  241. //根据openid和手机号判断是否注册,未注册直接注册
  242. $wechatReqData = [
  243. 'openid' => $openInfoData['openid'],
  244. 'purePhoneNumber' => $response['phone_info']['purePhoneNumber'],
  245. ];
  246. $wechatInfo = $this->userServiceClient->getWechatInfo($wechatReqData);
  247. if ($wechatInfo['code'] == 0) {
  248. $wechatData = [
  249. 'openid' => $openInfoData['openid'],
  250. 'phoneNumber' => $response['phone_info']['phoneNumber'],
  251. 'purePhoneNumber' => $response['phone_info']['purePhoneNumber'],
  252. 'countryCode' => $response['phone_info']['countryCode'],
  253. 'watermark' => json_encode($response['phone_info']['watermark']),
  254. 'user_id' => $checkUserInfo['data']['id'],
  255. ];
  256. $this->userServiceClient->addWechatInfo($wechatData);
  257. }
  258. var_dump($checkUserInfo);
  259. $userData = [
  260. 'uid' => $checkUserInfo['data']['id'], // 如果使用单点登录,必须存在配置文件中的sso_key的值,一般设置为用户的id
  261. 'user_name' => $response['phone_info']['phoneNumber'],
  262. 'mobile' => $checkUserInfo['data']['mobile'] ?? '',
  263. 'email' => $checkUserInfo['data']['email'],
  264. // 'rong_token' => $userInfos['data']['rong_token'],
  265. 'level_id' => $checkUserInfo['data']['level_id'],
  266. 'type_id' => $checkUserInfo['data']['type_id'],
  267. ];
  268. // 使用默认场景登录
  269. $token = $jwt->getToken('default', $userData);
  270. $data = [
  271. 'token' => $token->toString(),
  272. 'exp' => $jwt->getTTL($token->toString()),
  273. ];
  274. return Result::success($data);
  275. }
  276. public function getToken(JWT $jwt)
  277. {
  278. $reqData = $this->request->all();
  279. $userInfos = $this->userServiceClient->getUserInfo((int) $reqData['id']);
  280. $userData = [
  281. 'uid' => $userInfos['data']['id'], // 如果使用单点登录,必须存在配置文件中的sso_key的值,一般设置为用户的id
  282. 'user_name' => $userInfos['data']['user_name'],
  283. 'mobile' => $userInfos['data']['mobile'],
  284. 'email' => $userInfos['data']['email'],
  285. 'level_id' => $userInfos['data']['level_id'],
  286. 'type_id' => $userInfos['data']['type_id'],
  287. ];
  288. var_dump($userInfos);
  289. // 使用默认场景登录
  290. $token = $jwt->getToken('default', $userData);
  291. return Result::success($token->toString());
  292. }
  293. public function httpPost()
  294. {
  295. }
  296. # http头部必须携带token才能访问的路由
  297. public function getData(Jwt $jwt)
  298. {
  299. // var_dump($this->UserId);
  300. $h = $this->request->getHeaders();
  301. // var_dump($this->request->getHeaders());
  302. // $a= 'eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJwaHBlcjY2Ni9qd3QiLCJ1aWQiOjMyLCJ1c2VyX25hbWUiOiIxIiwicm9sZV9pZCI6MSwibW9iaWxlIjoiMTU4MDEyNDU3NTUiLCJlbWFpbCI6IjVAcXEuY29tIiwicm9uZ190b2tlbiI6IiIsImxldmVsX2lkIjo4LCJqd3Rfc2NlbmUiOiJkZWZhdWx0IiwianRpIjoiZGVmYXVsdF82Njc1MjJkZDQ3YWYxMi41MTE5MjI5MiIsImlhdCI6MTcxODk1MjY2OSwibmJmIjoxNzE4OTUyNjY5LCJleHAiOjE3MjE1NDQ2Njl9.e0JW8fgNrwBdFgmQ8GNtES2ME1SbcbIih5MsQWzT6sk';
  303. $arr = $jwt->getClaimsByToken($h['token'][0]);
  304. var_dump($h['token'][0], "+++++++++++", $arr, "===####");
  305. return $this->response->json(['code' => 0, 'msg' => 'success', 'data' => ['a' => 1]]);
  306. }
  307. /**
  308. * 检测用户权限
  309. * @return void
  310. */
  311. public function checkUserAuth($data)
  312. {
  313. $websiteGroup = [
  314. 'id'=>$data['id']
  315. ];
  316. $result = $this->userServiceClient->getWebsiteGroupInfo($websiteGroup);
  317. if($result['code']==200){
  318. if($data['SiteId'] && $result['data']['web_ids']){
  319. if(in_array($data['SiteId'],json_decode($result['data']['web_ids'],true))){
  320. return true;
  321. }
  322. }else{
  323. return false;
  324. }
  325. }
  326. }
  327. /**
  328. * 查询登陆状态
  329. * @return array
  330. * @throws \Psr\Container\ContainerExceptionInterface
  331. * @throws \Psr\Container\NotFoundExceptionInterface
  332. * @throws \RedisException
  333. */
  334. public function loginStatus(Jwt $jwt)
  335. {
  336. $reqData = $this->request->all();
  337. $validator = $this->validationFactory->make(
  338. $reqData,
  339. [
  340. 'token' => 'required',
  341. ],
  342. [
  343. 'token.required' => 'token不能为空',
  344. ]
  345. );
  346. if ($validator->fails()) {
  347. $errorMessage = $validator->errors()->first();
  348. return Result::error($errorMessage);
  349. }
  350. try {
  351. $status = $jwt->verifyToken($reqData['token']);
  352. var_dump("状态:",$status);
  353. return Result::success(['isLogin' => true]);
  354. }catch(\Exception $e){
  355. return Result::error('token已过期:'.$e->getMessage());
  356. }
  357. }
  358. /**
  359. *登陆
  360. * @return void
  361. */
  362. public function loginapi()
  363. {
  364. $reqData = $this->request->all();
  365. $validator = $this->validationFactory->make(
  366. $reqData,
  367. [
  368. 'token' => 'required',
  369. ],
  370. [
  371. 'token.required' => 'token不能为空',
  372. ]
  373. );
  374. if ($validator->fails()) {
  375. $errorMessage = $validator->errors()->first();
  376. return Result::error($errorMessage);
  377. }
  378. $redis = $this->container->get(\Hyperf\Redis\Redis::class);
  379. $ticket = md5($reqData['token']);
  380. $res = $redis->set('ticket:' . $ticket, $reqData['token'], 3600*24);
  381. if ($res){
  382. return Result::success(['ticket' => $ticket ,'isSave' => 1]);
  383. } else {
  384. return Result::error('存储失败');
  385. }
  386. }
  387. public function logoutapi(Jwt $jwt)
  388. {
  389. $reqData = $this->request->all();
  390. $validator = $this->validationFactory->make(
  391. $reqData,
  392. [
  393. 'token' => 'required',
  394. ],
  395. [
  396. 'token.required' => 'token不能为空',
  397. ]
  398. );
  399. if ($validator->fails()) {
  400. $errorMessage = $validator->errors()->first();
  401. return Result::error($errorMessage);
  402. }
  403. $redis = $this->container->get(\Hyperf\Redis\Redis::class);
  404. $ticket = md5($reqData['token']);
  405. $isDel = 0;
  406. if ($redis->exists('ticket:' . $ticket)) {
  407. $res = $redis->del('ticket:' . $ticket);
  408. if (!!$res && $res == 1) $isDel = 1;
  409. }else{
  410. $isDel = 1;
  411. }
  412. try {
  413. $jwt->logout($reqData['token']);
  414. }catch (\Exception $e){
  415. return Result::success(['isDel' => $isDel]);
  416. }
  417. return Result::success(['isDel' => $isDel]);
  418. }
  419. public function goLogin()
  420. {
  421. // 获取请求数据并设置默认值
  422. $reqData = $this->request->all();
  423. // 安全过滤 Admin-Token 和 ticket
  424. $adminToken = !empty($_COOKIE['Admin-Token']) ? $this->sanitizeInput($_COOKIE['Admin-Token']) : '';
  425. $ticket = !empty($reqData['ticket']) ? $this->sanitizeInput($reqData['ticket']) : '';
  426. $backurl = $this->sanitizeBackUrl($reqData['backurl'] ?? $_SERVER['HTTP_REFERER'] ?? '');
  427. // 校验 THE_HOST 环境变量
  428. $theHost = env("THE_HOST");
  429. if (empty($theHost)) {
  430. return Result::error('系统配置错误:THE_HOST 未定义');
  431. }
  432. // 如果存在 adminToken,则进行登录校验
  433. if (!empty($adminToken)) {
  434. try {
  435. $redis = $this->container->get(\Hyperf\Redis\Redis::class);
  436. // 如果 ticket 存在且有效,则直接跳转
  437. if (!empty($ticket) && $redis->exists('ticket:' . $ticket)) {
  438. $this->redirectWithTicket($backurl, $ticket, $adminToken);
  439. // return;
  440. }
  441. // 如果 ticket 不存在或无效,则重新生成 ticket 并跳转
  442. if (empty($ticket)) {
  443. $ticket = md5($adminToken);
  444. }
  445. // 跳转到目标页面
  446. $this->redirectWithTicket($backurl, $ticket, $adminToken);
  447. // return;
  448. } catch (\Throwable $e) {
  449. // 记录异常日志
  450. // \Hyperf\Logger\LoggerFactory::get('default')->error('Redis 操作失败: ' . $e->getMessage());
  451. // 捕获 Redis 异常,返回错误信息
  452. return Result::error('系统错误:Redis 操作失败');
  453. }
  454. }
  455. // 如果没有 adminToken,则跳转到登录页面
  456. $loginUrl = 'http://' . $theHost . '/#/login?backurl=' . urlencode($backurl);
  457. return $this->response->redirect($loginUrl, 302);
  458. }
  459. /**
  460. * 安全过滤输入数据
  461. * @param string $input
  462. * @return string
  463. */
  464. private function sanitizeInput(string $input): string
  465. {
  466. return htmlspecialchars(trim($input), ENT_QUOTES, 'UTF-8');
  467. }
  468. /**
  469. * 校验并清理 backurl
  470. * @param string $backurl
  471. * @return string
  472. */
  473. private function sanitizeBackUrl(string $backurl): string
  474. {
  475. // 解码并去除多余字符
  476. $decodedUrl = urldecode($backurl);
  477. return filter_var($decodedUrl, FILTER_VALIDATE_URL) ?: '';
  478. }
  479. /**
  480. * 跳转到目标页面
  481. * @param string $backurl
  482. * @param string $ticket
  483. * @param string $adminToken
  484. */
  485. private function redirectWithTicket(string $backurl, string $ticket, string $adminToken)
  486. {
  487. $backurl = rtrim($backurl, '/');
  488. $redirectUrl = $this->fun_http($backurl . '?ticket=' . $ticket . '&admintoken=' . urlencode($adminToken));
  489. return $this->response->redirect($redirectUrl, 302);
  490. }
  491. /**
  492. * 处理 URL
  493. * @param string $url
  494. * @return string
  495. */
  496. private function fun_http(string $url): string
  497. {
  498. // 确保 URL 以 http 或 https 开头
  499. if (!preg_match('/^https?:\/\//i', $url)) {
  500. $url = 'http://' . $url;
  501. }
  502. return $url;
  503. }
  504. /**
  505. * 退出
  506. * @return void
  507. */
  508. public function logout(Jwt $jwt)
  509. {
  510. $reqData = $this->request->all();
  511. $validator = $this->validationFactory->make(
  512. $reqData,
  513. [
  514. 'backurl' => 'required',
  515. 'admintoken' => 'required',
  516. ],
  517. [
  518. 'backurl.required' => 'backurl不能为空',
  519. 'admintoken.required' => 'admintoken不能为空',
  520. ]
  521. );
  522. if ($validator->fails()) {
  523. $errorMessage = $validator->errors()->first();
  524. return Result::error($errorMessage);
  525. }
  526. $redis = $this->container->get(\Hyperf\Redis\Redis::class);
  527. $ticket = md5($reqData['admintoken']);
  528. $isDel = 0;
  529. if ($redis->exists('ticket:' . $ticket)) {
  530. $res = $redis->del('ticket:' . $ticket);
  531. if (!!$res && $res == 1) $isDel = 1;
  532. }else{
  533. $isDel = 1;
  534. }
  535. // setcookie("Admin-Token", "", time(), "/");
  536. try {
  537. $jwt->logout($reqData['admintoken']);
  538. }catch (\Exception $e){
  539. $backurl = $this->fun_http($reqData['backurl']);
  540. return $this->response->redirect($backurl, 302);
  541. }
  542. $backurl = $this->fun_http($reqData['backurl']);
  543. return $this->response->redirect($backurl, 302);
  544. }
  545. /**
  546. * 登录回调
  547. * @return void
  548. */
  549. public function backlogin()
  550. {
  551. $reqData = $this->request->all();
  552. $validator = $this->validationFactory->make(
  553. $reqData,
  554. [
  555. 'backurl' => 'required',
  556. 'token' => 'required',
  557. ],
  558. [
  559. 'backurl.required' => 'backurl不能为空',
  560. 'token.required' => 'token不能为空',
  561. ]
  562. );
  563. if ($validator->fails()) {
  564. $errorMessage = $validator->errors()->first();
  565. return Result::error($errorMessage);
  566. }
  567. $redis = $this->container->get(\Hyperf\Redis\Redis::class);
  568. $ticket = md5($reqData['token']);
  569. $res = $redis->set('ticket:' . $ticket, $reqData['token'], 3600*24);
  570. if($res && !empty($ticket)){
  571. $url = $reqData['backurl'] . '/?ticket=' . $ticket . '&admintoken=' . urlencode($reqData['token']);
  572. $url = $this->fun_http($url);
  573. return $this->response->redirect($url, 302);
  574. }
  575. }
  576. }