LoginController.php 21 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620
  1. <?php
  2. declare (strict_types = 1);
  3. namespace App\Controller;
  4. use App\JsonRpc\UserServiceInterface;
  5. use App\Tools\CommonService;
  6. use App\Tools\PublicData;
  7. use App\Tools\Result;
  8. use Hyperf\Context\Context;
  9. use PHPStan\Type\Accessory\OversizedArrayType;
  10. use PHPUnit\Exception;
  11. use function Hyperf\Support\env;
  12. use Hyperf\Di\Annotation\Inject;
  13. use Hyperf\HttpServer\Annotation\AutoController;
  14. use Hyperf\Validation\Contract\ValidatorFactoryInterface;
  15. use \Phper666\JWTAuth\JWT;
  16. use App\Model\UserToken;
  17. use Hyperf\HttpServer\Response;
  18. /**
  19. * @AutoController()
  20. */
  21. class LoginController extends AbstractController
  22. {
  23. #[Inject]
  24. protected ValidatorFactoryInterface $validationFactory;
  25. /**
  26. * @var UserServiceInterface
  27. */
  28. #[Inject]
  29. private $userServiceClient;
  30. /**
  31. * @var Response
  32. */
  33. // private $response;
  34. // public function __construct(Response $response)
  35. // {
  36. // $this->response = $response;
  37. // }
  38. public function login(Jwt $jwt)
  39. {
  40. $reqData = $this->request->all();
  41. $validator = $this->validationFactory->make(
  42. $reqData,
  43. [
  44. 'username' => 'required',
  45. 'password' => 'required',
  46. 'type' => 'required',
  47. // 'code' => 'required',
  48. ],
  49. [
  50. 'username.required' => '用户名不能为空',
  51. 'password.required' => '密码不能为空',
  52. 'type.required' => '登录方式必填',
  53. // 'code.required' => 'code方式必填',
  54. ]
  55. );
  56. if ($validator->fails()) {
  57. $errorMessage = $validator->errors()->first();
  58. return Result::error($errorMessage);
  59. }
  60. // $comm = new CommonService();
  61. // $redis = $this->container->get(\Hyperf\Redis\Redis::class);
  62. // $code = $redis->get($reqData['code']);
  63. // if (empty($code)) {
  64. // return Result::error("验证码已过期");
  65. // }
  66. // if (strtolower($code) != strtolower($reqData['captcha'])) {
  67. // return Result::error("验证码错误");
  68. // }
  69. $where = [];
  70. if ($reqData['type'] == 1) { //密码登录
  71. $where = [
  72. 'user_name' => $reqData['username'],
  73. ];
  74. }
  75. $userInfos = $this->userServiceClient->verifyUserInfo($where);
  76. if ($userInfos['code'] == 0) {
  77. return Result::error("用户不存在");
  78. }
  79. if($userInfos['data']['status']==0){
  80. return Result::error("用户已经冻结");
  81. }
  82. if (md5(md5($reqData['password']) . $userInfos['data']['salt']) != $userInfos['data']['password']) {
  83. return Result::error("登陆密码错误");
  84. }
  85. if($userInfos['data']['type_id']!=10000){
  86. $authData = [
  87. 'id'=>$userInfos['data']['sszq'],
  88. 'SiteId'=>Context::get("SiteId")
  89. ];
  90. var_dump("参数:",$authData);
  91. $resultAuth = $this->checkUserAuth($authData);
  92. if(!$resultAuth){
  93. return Result::error("您没有权限登陆此网站");
  94. }
  95. }
  96. $userData = [
  97. 'uid' => $userInfos['data']['id'], // 如果使用单点登录,必须存在配置文件中的sso_key的值,一般设置为用户的id
  98. 'user_name' => $userInfos['data']['user_name'],
  99. 'mobile' => $userInfos['data']['mobile'],
  100. 'email' => $userInfos['data']['email'],
  101. 'level_id' => $userInfos['data']['level_id'],
  102. 'type_id' => $userInfos['data']['type_id'],
  103. ];
  104. // 使用默认场景登录
  105. $token = $jwt->getToken('default', $userData);
  106. // 检查是否有旧的token
  107. $old_token = UserToken::where('user_id', $userData['uid'])->first();
  108. if (!empty($old_token)) {
  109. $jwt->logout($old_token->token);
  110. try {
  111. $jwt->verifyToken($old_token->token);
  112. }catch (\Exception $exception){
  113. $code = $exception->getCode();
  114. if ($code== 400) {
  115. $new_token = UserToken::where('user_id', $userData['uid'])->update(['token' => $token->toString()]);
  116. if (empty($new_token)) {
  117. return Result::error("Token过期失败!");
  118. }
  119. } else{
  120. return Result::error("Token过期失败!");
  121. }
  122. }
  123. }else{
  124. $usernew_token = $token->toString();
  125. $user_token = UserToken::create([
  126. 'user_id' => $userData['uid'],
  127. 'token' => $usernew_token
  128. ]);
  129. if (empty($user_token)) {
  130. return Result::error("登录失败!");
  131. }
  132. }
  133. $data = [
  134. 'token' => $token->toString(),
  135. 'exp' => $jwt->getTTL($token->toString()),
  136. ];
  137. return Result::success($data);
  138. }
  139. /**
  140. * @return void
  141. */
  142. public function checkVerifyCode(Jwt $jwt)
  143. {
  144. //其它信息暂时不管 先以openid
  145. $reqData = $this->request->all();
  146. $validator = $this->validationFactory->make(
  147. $reqData,
  148. [
  149. 'token' => 'required',
  150. ],
  151. [
  152. 'token.required' => 'token不能为空',
  153. ]
  154. );
  155. if ($validator->fails()) {
  156. $errorMessage = $validator->errors()->first();
  157. return Result::error($errorMessage);
  158. }
  159. $userInfo = $jwt->getClaimsByToken($reqData['token']);
  160. if ($userInfo) {
  161. return Result::success(['token' => $reqData['token']]);
  162. } else {
  163. return Result::error("token无效");
  164. }
  165. }
  166. /**
  167. * 注册或登陆
  168. * @return void
  169. */
  170. public function registerOrLogin(Jwt $jwt)
  171. {
  172. //获取access_token
  173. $reqData = $this->request->all();
  174. $validator = $this->validationFactory->make(
  175. $reqData,
  176. [
  177. 'code' => 'required',
  178. ],
  179. [
  180. 'code.required' => 'code不能为空',
  181. ]
  182. );
  183. if ($validator->fails()) {
  184. $errorMessage = $validator->errors()->first();
  185. return Result::error($errorMessage);
  186. }
  187. $url = env("WECHAT") . "cgi-bin/token?appid=" . env("APPID") . "&secret=" . env("APP_SECRET") . "&grant_type=client_credential";
  188. $result = PublicData::http_get($url);
  189. $accessTokenData = json_decode($result, true);
  190. //获取openid
  191. $url = env("WECHAT") . "sns/jscode2session?appid=" . env("APPID") . "&secret=" . env("APP_SECRET") . "&js_code=" . $reqData['loginCode'] . "&grant_type=authorization_code";
  192. $result = PublicData::http_get($url);
  193. $openInfoData = json_decode($result, true);
  194. if (isset($openInfoData['errcode']) && in_array($openInfoData['errcode'], [40163, 40029])) {
  195. return Result::error($openInfoData['errmsg']);
  196. }
  197. $data = [
  198. 'code' => $reqData['code'],
  199. 'openid' => $openInfoData['openid'],
  200. ];
  201. // 将数组转换为JSON字符串
  202. $jsonData = json_encode($data);
  203. // 初始化cURL会话
  204. $ch = curl_init(env("WECHAT") . "wxa/business/getuserphonenumber?access_token=" . $accessTokenData['access_token']);
  205. // 设置cURL选项 Todo 这里有一万个wc 封装成post方法就报错,后期再研究
  206. curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
  207. curl_setopt($ch, CURLOPT_POST, true);
  208. curl_setopt($ch, CURLOPT_POSTFIELDS, $jsonData);
  209. curl_setopt($ch, CURLOPT_HTTPHEADER, [
  210. 'Content-Type: application/json',
  211. 'Content-Length: ' . strlen($jsonData),
  212. ]);
  213. // 执行cURL会话
  214. $response = curl_exec($ch);
  215. // 检查是否有错误发生
  216. if (curl_errno($ch)) {
  217. return Result::error("获取手机号失败");
  218. }
  219. // 关闭cURL会话
  220. curl_close($ch);
  221. $response = json_decode($response, true);
  222. if ($response['errcode'] == '40029') {
  223. return Result::error($openInfoData['errmsg']);
  224. }
  225. // 打印响应内容
  226. var_dump($openInfoData, $response);
  227. //根据openid 获取token
  228. $checkUserInfo = $this->userServiceClient->verifyUserInfo([
  229. 'user_name' => $response['phone_info']['purePhoneNumber'],
  230. ]);
  231. if ($checkUserInfo['code'] == 0) {
  232. $salt = rand(1, 999999);
  233. $createUserData = [
  234. 'user_name' => $response['phone_info']['purePhoneNumber'],
  235. 'salt' => $salt,
  236. 'password' => $openInfoData['openid'],
  237. 'type_id' => 20000,
  238. ];
  239. $checkUserInfo = $this->userServiceClient->createUser($createUserData);
  240. }
  241. //根据openid和手机号判断是否注册,未注册直接注册
  242. $wechatReqData = [
  243. 'openid' => $openInfoData['openid'],
  244. 'purePhoneNumber' => $response['phone_info']['purePhoneNumber'],
  245. ];
  246. $wechatInfo = $this->userServiceClient->getWechatInfo($wechatReqData);
  247. if ($wechatInfo['code'] == 0) {
  248. $wechatData = [
  249. 'openid' => $openInfoData['openid'],
  250. 'phoneNumber' => $response['phone_info']['phoneNumber'],
  251. 'purePhoneNumber' => $response['phone_info']['purePhoneNumber'],
  252. 'countryCode' => $response['phone_info']['countryCode'],
  253. 'watermark' => json_encode($response['phone_info']['watermark']),
  254. 'user_id' => $checkUserInfo['data']['id'],
  255. ];
  256. $this->userServiceClient->addWechatInfo($wechatData);
  257. }
  258. var_dump($checkUserInfo);
  259. $userData = [
  260. 'uid' => $checkUserInfo['data']['id'], // 如果使用单点登录,必须存在配置文件中的sso_key的值,一般设置为用户的id
  261. 'user_name' => $response['phone_info']['phoneNumber'],
  262. 'mobile' => $checkUserInfo['data']['mobile'] ?? '',
  263. 'email' => $checkUserInfo['data']['email'],
  264. // 'rong_token' => $userInfos['data']['rong_token'],
  265. 'level_id' => $checkUserInfo['data']['level_id'],
  266. 'type_id' => $checkUserInfo['data']['type_id'],
  267. ];
  268. // 使用默认场景登录
  269. $token = $jwt->getToken('default', $userData);
  270. $data = [
  271. 'token' => $token->toString(),
  272. 'exp' => $jwt->getTTL($token->toString()),
  273. ];
  274. return Result::success($data);
  275. }
  276. public function getToken(JWT $jwt)
  277. {
  278. $reqData = $this->request->all();
  279. $userInfos = $this->userServiceClient->getUserInfo((int) $reqData['id']);
  280. $userData = [
  281. 'uid' => $userInfos['data']['id'], // 如果使用单点登录,必须存在配置文件中的sso_key的值,一般设置为用户的id
  282. 'user_name' => $userInfos['data']['user_name'],
  283. 'mobile' => $userInfos['data']['mobile'],
  284. 'email' => $userInfos['data']['email'],
  285. 'level_id' => $userInfos['data']['level_id'],
  286. 'type_id' => $userInfos['data']['type_id'],
  287. ];
  288. var_dump($userInfos);
  289. // 使用默认场景登录
  290. $token = $jwt->getToken('default', $userData);
  291. return Result::success($token->toString());
  292. }
  293. public function httpPost()
  294. {
  295. }
  296. # http头部必须携带token才能访问的路由
  297. public function getData(Jwt $jwt)
  298. {
  299. // var_dump($this->UserId);
  300. $h = $this->request->getHeaders();
  301. // var_dump($this->request->getHeaders());
  302. // $a= 'eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJwaHBlcjY2Ni9qd3QiLCJ1aWQiOjMyLCJ1c2VyX25hbWUiOiIxIiwicm9sZV9pZCI6MSwibW9iaWxlIjoiMTU4MDEyNDU3NTUiLCJlbWFpbCI6IjVAcXEuY29tIiwicm9uZ190b2tlbiI6IiIsImxldmVsX2lkIjo4LCJqd3Rfc2NlbmUiOiJkZWZhdWx0IiwianRpIjoiZGVmYXVsdF82Njc1MjJkZDQ3YWYxMi41MTE5MjI5MiIsImlhdCI6MTcxODk1MjY2OSwibmJmIjoxNzE4OTUyNjY5LCJleHAiOjE3MjE1NDQ2Njl9.e0JW8fgNrwBdFgmQ8GNtES2ME1SbcbIih5MsQWzT6sk';
  303. $arr = $jwt->getClaimsByToken($h['token'][0]);
  304. var_dump($h['token'][0], "+++++++++++", $arr, "===####");
  305. return $this->response->json(['code' => 0, 'msg' => 'success', 'data' => ['a' => 1]]);
  306. }
  307. /**
  308. * 检测用户权限
  309. * @return void
  310. */
  311. public function checkUserAuth($data)
  312. {
  313. $websiteGroup = [
  314. 'id'=>$data['id']
  315. ];
  316. $result = $this->userServiceClient->getWebsiteGroupInfo($websiteGroup);
  317. if($result['code']==200){
  318. if($data['SiteId'] && $result['data']['web_ids']){
  319. if(in_array($data['SiteId'],json_decode($result['data']['web_ids'],true))){
  320. return true;
  321. }
  322. }else{
  323. return false;
  324. }
  325. }
  326. }
  327. /**
  328. * 查询登陆状态
  329. * @return array
  330. * @throws \Psr\Container\ContainerExceptionInterface
  331. * @throws \Psr\Container\NotFoundExceptionInterface
  332. * @throws \RedisException
  333. */
  334. public function loginStatus(Jwt $jwt)
  335. {
  336. $reqData = $this->request->all();
  337. $validator = $this->validationFactory->make(
  338. $reqData,
  339. [
  340. 'token' => 'required',
  341. ],
  342. [
  343. 'token.required' => 'token不能为空',
  344. ]
  345. );
  346. if ($validator->fails()) {
  347. $errorMessage = $validator->errors()->first();
  348. return Result::error($errorMessage);
  349. }
  350. try {
  351. $status = $jwt->verifyToken($reqData['token']);
  352. var_dump("状态:",$status);
  353. return Result::success(['isLogin' => true]);
  354. }catch(\Exception $e){
  355. return Result::error('token已过期:'.$e->getMessage());
  356. }
  357. }
  358. /**
  359. *登陆
  360. * @return void
  361. */
  362. public function loginapi()
  363. {
  364. $reqData = $this->request->all();
  365. $validator = $this->validationFactory->make(
  366. $reqData,
  367. [
  368. 'token' => 'required',
  369. ],
  370. [
  371. 'token.required' => 'token不能为空',
  372. ]
  373. );
  374. if ($validator->fails()) {
  375. $errorMessage = $validator->errors()->first();
  376. return Result::error($errorMessage);
  377. }
  378. $redis = $this->container->get(\Hyperf\Redis\Redis::class);
  379. $ticket = md5($reqData['token']);
  380. $res = $redis->set('ticket:' . $ticket, $reqData['token'], 3600*24);
  381. if ($res){
  382. return Result::success(['ticket' => $ticket ,'isSave' => 1]);
  383. } else {
  384. return Result::error('存储失败');
  385. }
  386. }
  387. public function logoutapi(Jwt $jwt)
  388. {
  389. $reqData = $this->request->all();
  390. $validator = $this->validationFactory->make(
  391. $reqData,
  392. [
  393. 'token' => 'required',
  394. ],
  395. [
  396. 'token.required' => 'token不能为空',
  397. ]
  398. );
  399. if ($validator->fails()) {
  400. $errorMessage = $validator->errors()->first();
  401. return Result::error($errorMessage);
  402. }
  403. $redis = $this->container->get(\Hyperf\Redis\Redis::class);
  404. $ticket = md5($reqData['token']);
  405. $isDel = 0;
  406. if ($redis->exists('ticket:' . $ticket)) {
  407. $res = $redis->del('ticket:' . $ticket);
  408. if (!!$res && $res == 1) $isDel = 1;
  409. }else{
  410. $isDel = 1;
  411. }
  412. try {
  413. $jwt->logout($reqData['token']);
  414. }catch (\Exception $e){
  415. return Result::success(['isDel' => $isDel]);
  416. }
  417. return Result::success(['isDel' => $isDel]);
  418. }
  419. public function goLogin()
  420. {
  421. // 获取请求数据并设置默认值
  422. $reqData = $this->request->all();
  423. // 安全过滤 Admin-Token 和 ticket
  424. $cookieList = $this->request->getCookieParams();
  425. // 安全过滤 Admin-Token 和 ticket
  426. $adminToken = !empty($cookieList['Admin-Token']) ? $this->sanitizeInput($cookieList['Admin-Token']) : '';
  427. $ticket = !empty($reqData['ticket']) ? $this->sanitizeInput($reqData['ticket']) : '';
  428. $backurl = $this->sanitizeBackUrl($reqData['backurl'] ?? $_SERVER['HTTP_REFERER'] ?? '');
  429. // 校验 THE_HOST 环境变量
  430. $theHost = env("THE_HOST");
  431. if (empty($theHost)) {
  432. return Result::error('系统配置错误:THE_HOST 未定义');
  433. }
  434. // 如果存在 adminToken,则进行登录校验
  435. if (!empty($adminToken)) {
  436. // 处理登录
  437. $redis = $this->container->get(\Hyperf\Redis\Redis::class);
  438. if(!empty($ticket)){
  439. if (!empty($ticket) && $redis->exists('ticket:' . $ticket)) {
  440. $backurl = rtrim($backurl, '/');
  441. return $this->response->redirect($this->fun_http($backurl . '?ticket=' . $ticket . '&admintoken=' . urlencode($adminToken)), 302);
  442. }else{
  443. return $this->response->redirect($this-> fun_http('http://'.$theHost.'/#/login?backurl='.urlencode($backurl)), 302);
  444. }
  445. }else{
  446. $ticket = md5($adminToken);
  447. }
  448. return $this->response->redirect(fun_http($backurl . '?ticket=' . $ticket . '&admintoken=' . urlencode($adminToken)), 302);
  449. }else{
  450. return $this->response->redirect(fun_http('http://'.$theHost.'/#/login?backurl='.urlencode($backurl)), 302);
  451. }
  452. }
  453. /**
  454. * 安全过滤输入数据
  455. * @param string $input
  456. * @return string
  457. */
  458. private function sanitizeInput(string $input): string
  459. {
  460. return htmlspecialchars(trim($input), ENT_QUOTES, 'UTF-8');
  461. }
  462. /**
  463. * 校验并清理 backurl
  464. * @param string $backurl
  465. * @return string
  466. */
  467. private function sanitizeBackUrl(string $backurl): string
  468. {
  469. // 解码并去除多余字符
  470. $decodedUrl = urldecode($backurl);
  471. return filter_var($decodedUrl, FILTER_VALIDATE_URL) ?: '';
  472. }
  473. /**
  474. * 跳转到目标页面
  475. * @param string $backurl
  476. * @param string $ticket
  477. * @param string $adminToken
  478. */
  479. private function redirectWithTicket(string $backurl, string $ticket, string $adminToken)
  480. {
  481. $backurl = rtrim($backurl, '/');
  482. $redirectUrl = $this->fun_http($backurl . '?ticket=' . $ticket . '&admintoken=' . urlencode($adminToken));
  483. // $loginUrl = 'http://' . $theHost . '/#/login?backurl=' . urlencode($backurl);
  484. // return $this->response->redirect($loginUrl, 302);
  485. return $this->response->redirect($redirectUrl, 302);
  486. }
  487. /**
  488. * 处理 URL
  489. * @param string $url
  490. * @return string
  491. */
  492. private function fun_http(string $url): string
  493. {
  494. // 确保 URL 以 http 或 https 开头
  495. if (!preg_match('/^https?:\/\//i', $url)) {
  496. $url = 'http://' . $url;
  497. }
  498. return $url;
  499. }
  500. /**
  501. * 退出
  502. * @return void
  503. */
  504. public function logout(Jwt $jwt)
  505. {
  506. $reqData = $this->request->all();
  507. $validator = $this->validationFactory->make(
  508. $reqData,
  509. [
  510. 'backurl' => 'required',
  511. 'admintoken' => 'required',
  512. ],
  513. [
  514. 'backurl.required' => 'backurl不能为空',
  515. 'admintoken.required' => 'admintoken不能为空',
  516. ]
  517. );
  518. if ($validator->fails()) {
  519. $errorMessage = $validator->errors()->first();
  520. return Result::error($errorMessage);
  521. }
  522. $redis = $this->container->get(\Hyperf\Redis\Redis::class);
  523. $ticket = md5($reqData['admintoken']);
  524. $isDel = 0;
  525. if ($redis->exists('ticket:' . $ticket)) {
  526. $res = $redis->del('ticket:' . $ticket);
  527. if (!!$res && $res == 1) $isDel = 1;
  528. }else{
  529. $isDel = 1;
  530. }
  531. $this->response->withCookie("Admin-Token", '', time(), '/');
  532. // setcookie("Admin-Token", "", time(), "/");
  533. try {
  534. $jwt->logout($reqData['admintoken']);
  535. }catch (\Exception $e){
  536. $backurl = $this->fun_http($reqData['backurl']);
  537. return $this->response->redirect($backurl, 302);
  538. }
  539. $backurl = $this->fun_http($reqData['backurl']);
  540. return $this->response->redirect($backurl, 302);
  541. }
  542. /**
  543. * 登录回调
  544. * @return void
  545. */
  546. public function backlogin()
  547. {
  548. $reqData = $this->request->all();
  549. $validator = $this->validationFactory->make(
  550. $reqData,
  551. [
  552. 'backurl' => 'required',
  553. 'token' => 'required',
  554. ],
  555. [
  556. 'backurl.required' => 'backurl不能为空',
  557. 'token.required' => 'token不能为空',
  558. ]
  559. );
  560. if ($validator->fails()) {
  561. $errorMessage = $validator->errors()->first();
  562. return Result::error($errorMessage);
  563. }
  564. $redis = $this->container->get(\Hyperf\Redis\Redis::class);
  565. $ticket = md5($reqData['token']);
  566. $res = $redis->set('ticket:' . $ticket, $reqData['token'], 3600*24);
  567. if($res && !empty($ticket)){
  568. $url = $reqData['backurl'] . '/?ticket=' . $ticket . '&admintoken=' . urlencode($reqData['token']);
  569. $url = $this->fun_http($url);
  570. return $this->response->redirect($url, 302);
  571. }
  572. }
  573. }