LoginController.php 12 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332
  1. <?php
  2. declare (strict_types = 1);
  3. namespace App\Controller;
  4. use App\JsonRpc\UserServiceInterface;
  5. use App\Tools\CommonService;
  6. use App\Tools\PublicData;
  7. use App\Tools\Result;
  8. use function Hyperf\Support\env;
  9. use Hyperf\Di\Annotation\Inject;
  10. use Hyperf\HttpServer\Annotation\AutoController;
  11. use Hyperf\Validation\Contract\ValidatorFactoryInterface;
  12. use \Phper666\JWTAuth\JWT;
  13. use App\Model\UserToken;
  14. /**
  15. * @AutoController()
  16. */
  17. class LoginController extends AbstractController
  18. {
  19. #[Inject]
  20. protected ValidatorFactoryInterface $validationFactory;
  21. /**
  22. * @var UserServiceInterface
  23. */
  24. #[Inject]
  25. private $userServiceClient;
  26. public function login(Jwt $jwt)
  27. {
  28. $reqData = $this->request->all();
  29. $validator = $this->validationFactory->make(
  30. $reqData,
  31. [
  32. 'username' => 'required',
  33. 'password' => 'required',
  34. 'type' => 'required',
  35. 'code' => 'required',
  36. ],
  37. [
  38. 'username.required' => '用户名不能为空',
  39. 'password.required' => '密码不能为空',
  40. 'type.required' => '登录方式必填',
  41. 'code.required' => 'code方式必填',
  42. ]
  43. );
  44. if ($validator->fails()) {
  45. $errorMessage = $validator->errors()->first();
  46. return Result::error($errorMessage);
  47. }
  48. // $comm = new CommonService();
  49. $redis = $this->container->get(\Hyperf\Redis\Redis::class);
  50. $code = $redis->get($reqData['code']);
  51. if (empty($code)) {
  52. return Result::error("验证码已过期");
  53. }
  54. if (strtolower($code) != strtolower($reqData['captcha'])) {
  55. return Result::error("验证码错误");
  56. }
  57. $where = [];
  58. if ($reqData['type'] == 1) { //密码登录
  59. $where = [
  60. 'user_name' => $reqData['username'],
  61. ];
  62. }
  63. $userInfos = $this->userServiceClient->verifyUserInfo($where);
  64. if ($userInfos['code'] == 0) {
  65. return Result::error("用户不存在");
  66. }
  67. if($userInfos['data']['status']==0){
  68. return Result::error("用户已经冻结");
  69. }
  70. if (md5(md5($reqData['password']) . $userInfos['data']['salt']) != $userInfos['data']['password']) {
  71. return Result::error("登陆密码错误");
  72. }
  73. if($userInfos['data']['type_id']!=10000){
  74. $authData = [
  75. 'id'=>$userInfos['data']['sszq']
  76. ];
  77. $resultAuth = $this->checkUserAuth($authData);
  78. if(!$resultAuth){
  79. return Result::error("您没有权限登陆此网站");
  80. }
  81. }
  82. $userData = [
  83. 'uid' => $userInfos['data']['id'], // 如果使用单点登录,必须存在配置文件中的sso_key的值,一般设置为用户的id
  84. 'user_name' => $userInfos['data']['user_name'],
  85. 'mobile' => $userInfos['data']['mobile'],
  86. 'email' => $userInfos['data']['email'],
  87. 'level_id' => $userInfos['data']['level_id'],
  88. 'type_id' => $userInfos['data']['type_id'],
  89. ];
  90. // 使用默认场景登录
  91. $token = $jwt->getToken('default', $userData);
  92. // 检查是否有旧的token
  93. $old_token = UserToken::where('user_id', $userData['uid'])->first();
  94. if (!empty($old_token)) {
  95. $jwt->logout($old_token->token);
  96. try {
  97. $jwt->verifyToken($old_token->token);
  98. }catch (\Exception $exception){
  99. $code = $exception->getCode();
  100. if ($code== 400) {
  101. $new_token = UserToken::where('user_id', $userData['uid'])->update(['token' => $token->toString()]);
  102. if (empty($new_token)) {
  103. return Result::error("Token过期失败!");
  104. }
  105. } else{
  106. return Result::error("Token过期失败!");
  107. }
  108. }
  109. }else{
  110. $usernew_token = $token->toString();
  111. $user_token = UserToken::create([
  112. 'user_id' => $userData['uid'],
  113. 'token' => $usernew_token
  114. ]);
  115. if (empty($user_token)) {
  116. return Result::error("登录失败!");
  117. }
  118. }
  119. $data = [
  120. 'token' => $token->toString(),
  121. 'exp' => $jwt->getTTL($token->toString()),
  122. ];
  123. return Result::success($data);
  124. }
  125. /**
  126. * @return void
  127. */
  128. public function checkVerifyCode(Jwt $jwt)
  129. {
  130. //其它信息暂时不管 先以openid
  131. $reqData = $this->request->all();
  132. $validator = $this->validationFactory->make(
  133. $reqData,
  134. [
  135. 'token' => 'required',
  136. ],
  137. [
  138. 'token.required' => 'token不能为空',
  139. ]
  140. );
  141. if ($validator->fails()) {
  142. $errorMessage = $validator->errors()->first();
  143. return Result::error($errorMessage);
  144. }
  145. $userInfo = $jwt->getClaimsByToken($reqData['token']);
  146. if ($userInfo) {
  147. return Result::success(['token' => $reqData['token']]);
  148. } else {
  149. return Result::error("token无效");
  150. }
  151. }
  152. /**
  153. * 注册或登陆
  154. * @return void
  155. */
  156. public function registerOrLogin(Jwt $jwt)
  157. {
  158. //获取access_token
  159. $reqData = $this->request->all();
  160. $validator = $this->validationFactory->make(
  161. $reqData,
  162. [
  163. 'code' => 'required',
  164. ],
  165. [
  166. 'code.required' => 'code不能为空',
  167. ]
  168. );
  169. if ($validator->fails()) {
  170. $errorMessage = $validator->errors()->first();
  171. return Result::error($errorMessage);
  172. }
  173. $url = env("WECHAT") . "cgi-bin/token?appid=" . env("APPID") . "&secret=" . env("APP_SECRET") . "&grant_type=client_credential";
  174. $result = PublicData::http_get($url);
  175. $accessTokenData = json_decode($result, true);
  176. //获取openid
  177. $url = env("WECHAT") . "sns/jscode2session?appid=" . env("APPID") . "&secret=" . env("APP_SECRET") . "&js_code=" . $reqData['loginCode'] . "&grant_type=authorization_code";
  178. $result = PublicData::http_get($url);
  179. $openInfoData = json_decode($result, true);
  180. if (isset($openInfoData['errcode']) && in_array($openInfoData['errcode'], [40163, 40029])) {
  181. return Result::error($openInfoData['errmsg']);
  182. }
  183. $data = [
  184. 'code' => $reqData['code'],
  185. 'openid' => $openInfoData['openid'],
  186. ];
  187. // 将数组转换为JSON字符串
  188. $jsonData = json_encode($data);
  189. // 初始化cURL会话
  190. $ch = curl_init(env("WECHAT") . "wxa/business/getuserphonenumber?access_token=" . $accessTokenData['access_token']);
  191. // 设置cURL选项 Todo 这里有一万个wc 封装成post方法就报错,后期再研究
  192. curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
  193. curl_setopt($ch, CURLOPT_POST, true);
  194. curl_setopt($ch, CURLOPT_POSTFIELDS, $jsonData);
  195. curl_setopt($ch, CURLOPT_HTTPHEADER, [
  196. 'Content-Type: application/json',
  197. 'Content-Length: ' . strlen($jsonData),
  198. ]);
  199. // 执行cURL会话
  200. $response = curl_exec($ch);
  201. // 检查是否有错误发生
  202. if (curl_errno($ch)) {
  203. return Result::error("获取手机号失败");
  204. }
  205. // 关闭cURL会话
  206. curl_close($ch);
  207. $response = json_decode($response, true);
  208. if ($response['errcode'] == '40029') {
  209. return Result::error($openInfoData['errmsg']);
  210. }
  211. // 打印响应内容
  212. var_dump($openInfoData, $response);
  213. //根据openid 获取token
  214. $checkUserInfo = $this->userServiceClient->verifyUserInfo([
  215. 'user_name' => $response['phone_info']['purePhoneNumber'],
  216. ]);
  217. if ($checkUserInfo['code'] == 0) {
  218. $salt = rand(1, 999999);
  219. $createUserData = [
  220. 'user_name' => $response['phone_info']['purePhoneNumber'],
  221. 'salt' => $salt,
  222. 'password' => $openInfoData['openid'],
  223. 'type_id' => 20000,
  224. ];
  225. $checkUserInfo = $this->userServiceClient->createUser($createUserData);
  226. }
  227. //根据openid和手机号判断是否注册,未注册直接注册
  228. $wechatReqData = [
  229. 'openid' => $openInfoData['openid'],
  230. 'purePhoneNumber' => $response['phone_info']['purePhoneNumber'],
  231. ];
  232. $wechatInfo = $this->userServiceClient->getWechatInfo($wechatReqData);
  233. if ($wechatInfo['code'] == 0) {
  234. $wechatData = [
  235. 'openid' => $openInfoData['openid'],
  236. 'phoneNumber' => $response['phone_info']['phoneNumber'],
  237. 'purePhoneNumber' => $response['phone_info']['purePhoneNumber'],
  238. 'countryCode' => $response['phone_info']['countryCode'],
  239. 'watermark' => json_encode($response['phone_info']['watermark']),
  240. 'user_id' => $checkUserInfo['data']['id'],
  241. ];
  242. $this->userServiceClient->addWechatInfo($wechatData);
  243. }
  244. var_dump($checkUserInfo);
  245. $userData = [
  246. 'uid' => $checkUserInfo['data']['id'], // 如果使用单点登录,必须存在配置文件中的sso_key的值,一般设置为用户的id
  247. 'user_name' => $response['phone_info']['phoneNumber'],
  248. 'mobile' => $checkUserInfo['data']['mobile'] ?? '',
  249. 'email' => $checkUserInfo['data']['email'],
  250. // 'rong_token' => $userInfos['data']['rong_token'],
  251. 'level_id' => $checkUserInfo['data']['level_id'],
  252. 'type_id' => $checkUserInfo['data']['type_id'],
  253. ];
  254. // 使用默认场景登录
  255. $token = $jwt->getToken('default', $userData);
  256. $data = [
  257. 'token' => $token->toString(),
  258. 'exp' => $jwt->getTTL($token->toString()),
  259. ];
  260. return Result::success($data);
  261. }
  262. public function getToken(JWT $jwt)
  263. {
  264. $reqData = $this->request->all();
  265. $userInfos = $this->userServiceClient->getUserInfo((int) $reqData['id']);
  266. $userData = [
  267. 'uid' => $userInfos['data']['id'], // 如果使用单点登录,必须存在配置文件中的sso_key的值,一般设置为用户的id
  268. 'user_name' => $userInfos['data']['user_name'],
  269. 'mobile' => $userInfos['data']['mobile'],
  270. 'email' => $userInfos['data']['email'],
  271. 'level_id' => $userInfos['data']['level_id'],
  272. 'type_id' => $userInfos['data']['type_id'],
  273. ];
  274. var_dump($userInfos);
  275. // 使用默认场景登录
  276. $token = $jwt->getToken('default', $userData);
  277. return Result::success($token->toString());
  278. }
  279. public function httpPost()
  280. {
  281. }
  282. # http头部必须携带token才能访问的路由
  283. public function getData(Jwt $jwt)
  284. {
  285. // var_dump($this->UserId);
  286. $h = $this->request->getHeaders();
  287. // var_dump($this->request->getHeaders());
  288. // $a= 'eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJwaHBlcjY2Ni9qd3QiLCJ1aWQiOjMyLCJ1c2VyX25hbWUiOiIxIiwicm9sZV9pZCI6MSwibW9iaWxlIjoiMTU4MDEyNDU3NTUiLCJlbWFpbCI6IjVAcXEuY29tIiwicm9uZ190b2tlbiI6IiIsImxldmVsX2lkIjo4LCJqd3Rfc2NlbmUiOiJkZWZhdWx0IiwianRpIjoiZGVmYXVsdF82Njc1MjJkZDQ3YWYxMi41MTE5MjI5MiIsImlhdCI6MTcxODk1MjY2OSwibmJmIjoxNzE4OTUyNjY5LCJleHAiOjE3MjE1NDQ2Njl9.e0JW8fgNrwBdFgmQ8GNtES2ME1SbcbIih5MsQWzT6sk';
  289. $arr = $jwt->getClaimsByToken($h['token'][0]);
  290. var_dump($h['token'][0], "+++++++++++", $arr, "===####");
  291. return $this->response->json(['code' => 0, 'msg' => 'success', 'data' => ['a' => 1]]);
  292. }
  293. /**
  294. * 检测用户权限
  295. * @return void
  296. */
  297. public function checkUserAuth($data)
  298. {
  299. $websiteGroup = [
  300. 'id'=>$data['id']
  301. ];
  302. $result = $this->userServiceClient->getWebsiteGroupInfo($websiteGroup);
  303. var_dump("webids:",$result['data']['web_ids']);
  304. if($result['code']==200){
  305. if($data['siteId'] && $result['data']['web_ids']){
  306. if(in_array($data['siteId'],$result['data']['web_ids'])){
  307. return true;
  308. }
  309. }else{
  310. return false;
  311. }
  312. }
  313. }
  314. }