LoginController.php 26 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742
  1. <?php
  2. declare (strict_types = 1);
  3. namespace App\Controller;
  4. use App\JsonRpc\UserServiceInterface;
  5. use App\Tools\CommonService;
  6. use App\Tools\PublicData;
  7. use App\Tools\Result;
  8. use Hyperf\Context\Context;
  9. use PHPStan\Type\Accessory\OversizedArrayType;
  10. use PHPUnit\Exception;
  11. use function Hyperf\Support\env;
  12. use Hyperf\Di\Annotation\Inject;
  13. use Hyperf\HttpServer\Annotation\AutoController;
  14. use Hyperf\Validation\Contract\ValidatorFactoryInterface;
  15. use \Phper666\JWTAuth\JWT;
  16. use App\Model\UserToken;
  17. use Hyperf\HttpServer\Response;
  18. use Hyperf\HttpMessage\Cookie\Cookie;
  19. use App\Controller\UserController;
  20. use App\JsonRpc\WebsiteServiceInterface;
  21. /**
  22. * @AutoController()
  23. */
  24. class LoginController extends AbstractController
  25. {
  26. #[Inject]
  27. protected ValidatorFactoryInterface $validationFactory;
  28. // protected JWT $JWT;
  29. /**
  30. * @var UserServiceInterface
  31. */
  32. #[Inject]
  33. private $userServiceClient;
  34. /**
  35. * @var WebsiteServiceInterface
  36. */
  37. #[Inject]
  38. private $websiteServiceClient;
  39. /**
  40. * @var Response
  41. */
  42. // private $response;
  43. // public function __construct(Jwt $JWT)
  44. // {
  45. // $this->JWT = $JWT;
  46. // }
  47. public function login(Jwt $jwt)
  48. {
  49. $reqData = $this->request->all();
  50. $validator = $this->validationFactory->make(
  51. $reqData,
  52. [
  53. 'username' => 'required',
  54. 'password' => 'required',
  55. 'type' => 'required',
  56. // 'code' => 'required',
  57. ],
  58. [
  59. 'username.required' => '用户名不能为空',
  60. 'password.required' => '密码不能为空',
  61. 'type.required' => '登录方式必填',
  62. // 'code.required' => 'code方式必填',
  63. ]
  64. );
  65. if ($validator->fails()) {
  66. $errorMessage = $validator->errors()->first();
  67. return Result::error($errorMessage);
  68. }
  69. // $comm = new CommonService();
  70. // $redis = $this->container->get(\Hyperf\Redis\Redis::class);
  71. // $code = $redis->get($reqData['code']);
  72. // if (empty($code)) {
  73. // return Result::error("验证码已过期");
  74. // }
  75. // if (strtolower($code) != strtolower($reqData['captcha'])) {
  76. // return Result::error("验证码错误");
  77. // }
  78. $where = [];
  79. if ($reqData['type'] == 1) { //密码登录
  80. $where = [
  81. 'user_name' => $reqData['username'],
  82. ];
  83. }
  84. $userInfos = $this->userServiceClient->verifyUserInfo($where);
  85. if ($userInfos['code'] == 0) {
  86. return Result::error("用户不存在");
  87. }
  88. if($userInfos['data']['status']==0){
  89. return Result::error("用户已经冻结");
  90. }
  91. if (md5(md5($reqData['password']) . $userInfos['data']['salt']) != $userInfos['data']['password']) {
  92. return Result::error("登陆密码错误");
  93. }
  94. if($userInfos['data']['type_id']!=10000){
  95. $authData = [
  96. 'id'=>$userInfos['data']['sszq'],
  97. 'SiteId'=>Context::get("SiteId")
  98. ];
  99. var_dump("参数:",$authData);
  100. $resultAuth = $this->checkUserAuth($authData);
  101. if(!$resultAuth){
  102. return Result::error("您没有权限登陆此网站");
  103. }
  104. }
  105. $userData = [
  106. 'uid' => $userInfos['data']['id'], // 如果使用单点登录,必须存在配置文件中的sso_key的值,一般设置为用户的id
  107. 'user_name' => $userInfos['data']['user_name'],
  108. 'mobile' => $userInfos['data']['mobile'],
  109. 'email' => $userInfos['data']['email'],
  110. 'level_id' => $userInfos['data']['level_id'],
  111. 'type_id' => $userInfos['data']['type_id'],
  112. ];
  113. // 使用默认场景登录
  114. $token = $jwt->getToken('default', $userData);
  115. // 检查是否有旧的token
  116. $old_token = UserToken::where('user_id', $userData['uid'])->first();
  117. if (!empty($old_token)) {
  118. $jwt->logout($old_token->token);
  119. try {
  120. $jwt->verifyToken($old_token->token);
  121. }catch (\Exception $exception){
  122. $code = $exception->getCode();
  123. if ($code== 400) {
  124. $new_token = UserToken::where('user_id', $userData['uid'])->update(['token' => $token->toString()]);
  125. if (empty($new_token)) {
  126. return Result::error("Token过期失败!");
  127. }
  128. } else{
  129. return Result::error("Token过期失败!");
  130. }
  131. }
  132. }else{
  133. $usernew_token = $token->toString();
  134. $user_token = UserToken::create([
  135. 'user_id' => $userData['uid'],
  136. 'token' => $usernew_token
  137. ]);
  138. if (empty($user_token)) {
  139. return Result::error("登录失败!");
  140. }
  141. }
  142. $data = [
  143. 'token' => $token->toString(),
  144. 'exp' => $jwt->getTTL($token->toString()),
  145. ];
  146. return Result::success($data);
  147. }
  148. /**
  149. * @return void
  150. */
  151. public function checkVerifyCode(Jwt $jwt)
  152. {
  153. //其它信息暂时不管 先以openid
  154. $reqData = $this->request->all();
  155. $validator = $this->validationFactory->make(
  156. $reqData,
  157. [
  158. 'token' => 'required',
  159. ],
  160. [
  161. 'token.required' => 'token不能为空',
  162. ]
  163. );
  164. if ($validator->fails()) {
  165. $errorMessage = $validator->errors()->first();
  166. return Result::error($errorMessage);
  167. }
  168. $userInfo = $jwt->getClaimsByToken($reqData['token']);
  169. if ($userInfo) {
  170. return Result::success(['token' => $reqData['token']]);
  171. } else {
  172. return Result::error("token无效");
  173. }
  174. }
  175. /**
  176. * 注册或登陆
  177. * @return void
  178. */
  179. public function registerOrLogin(Jwt $jwt)
  180. {
  181. //获取access_token
  182. $reqData = $this->request->all();
  183. $validator = $this->validationFactory->make(
  184. $reqData,
  185. [
  186. 'code' => 'required',
  187. ],
  188. [
  189. 'code.required' => 'code不能为空',
  190. ]
  191. );
  192. if ($validator->fails()) {
  193. $errorMessage = $validator->errors()->first();
  194. return Result::error($errorMessage);
  195. }
  196. $url = env("WECHAT") . "cgi-bin/token?appid=" . env("APPID") . "&secret=" . env("APP_SECRET") . "&grant_type=client_credential";
  197. $result = PublicData::http_get($url);
  198. $accessTokenData = json_decode($result, true);
  199. //获取openid
  200. $url = env("WECHAT") . "sns/jscode2session?appid=" . env("APPID") . "&secret=" . env("APP_SECRET") . "&js_code=" . $reqData['loginCode'] . "&grant_type=authorization_code";
  201. $result = PublicData::http_get($url);
  202. $openInfoData = json_decode($result, true);
  203. if (isset($openInfoData['errcode']) && in_array($openInfoData['errcode'], [40163, 40029])) {
  204. return Result::error($openInfoData['errmsg']);
  205. }
  206. $data = [
  207. 'code' => $reqData['code'],
  208. 'openid' => $openInfoData['openid'],
  209. ];
  210. // 将数组转换为JSON字符串
  211. $jsonData = json_encode($data);
  212. // 初始化cURL会话
  213. $ch = curl_init(env("WECHAT") . "wxa/business/getuserphonenumber?access_token=" . $accessTokenData['access_token']);
  214. // 设置cURL选项 Todo 这里有一万个wc 封装成post方法就报错,后期再研究
  215. curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
  216. curl_setopt($ch, CURLOPT_POST, true);
  217. curl_setopt($ch, CURLOPT_POSTFIELDS, $jsonData);
  218. curl_setopt($ch, CURLOPT_HTTPHEADER, [
  219. 'Content-Type: application/json',
  220. 'Content-Length: ' . strlen($jsonData),
  221. ]);
  222. // 执行cURL会话
  223. $response = curl_exec($ch);
  224. // 检查是否有错误发生
  225. if (curl_errno($ch)) {
  226. return Result::error("获取手机号失败");
  227. }
  228. // 关闭cURL会话
  229. curl_close($ch);
  230. $response = json_decode($response, true);
  231. if ($response['errcode'] == '40029') {
  232. return Result::error($openInfoData['errmsg']);
  233. }
  234. // 打印响应内容
  235. var_dump($openInfoData, $response);
  236. //根据openid 获取token
  237. $checkUserInfo = $this->userServiceClient->verifyUserInfo([
  238. 'user_name' => $response['phone_info']['purePhoneNumber'],
  239. ]);
  240. var_dump("检测返回值用户信息:",$checkUserInfo);
  241. if ($checkUserInfo['code'] == 0) {
  242. $salt = rand(1, 999999);
  243. $createUserData = [
  244. 'user_name' => $response['phone_info']['purePhoneNumber'],
  245. 'salt' => $salt,
  246. 'password' => $openInfoData['openid'],
  247. 'type_id' => 20000,
  248. 'mobile'=>$response['phone_info']['purePhoneNumber'],
  249. 'other'=>[],
  250. 'city_arr_id'=>[],
  251. 'address_arr_id'=>[]
  252. ];
  253. $checkUserInfo = $this->userServiceClient->createUser($createUserData);
  254. }
  255. var_dump("返回值用户信息:",$checkUserInfo);
  256. //根据openid和手机号判断是否注册,未注册直接注册
  257. $wechatReqData = [
  258. 'openid' => $openInfoData['openid'],
  259. 'purePhoneNumber' => $response['phone_info']['purePhoneNumber'],
  260. ];
  261. $wechatInfo = $this->userServiceClient->getWechatInfo($wechatReqData);
  262. if ($wechatInfo['code'] == 0) {
  263. $wechatData = [
  264. 'openid' => $openInfoData['openid'],
  265. 'phoneNumber' => $response['phone_info']['phoneNumber'],
  266. 'purePhoneNumber' => $response['phone_info']['purePhoneNumber'],
  267. 'countryCode' => $response['phone_info']['countryCode'],
  268. 'watermark' => json_encode($response['phone_info']['watermark']),
  269. 'user_id' => $checkUserInfo['data']['id'] ?? 0,
  270. ];
  271. var_dump("##插入的值:",$wechatData);
  272. $this->userServiceClient->addWechatInfo($wechatData);
  273. }
  274. var_dump($checkUserInfo);
  275. $userData = [
  276. 'uid' => $checkUserInfo['data']['id'] ?? 0, // 如果使用单点登录,必须存在配置文件中的sso_key的值,一般设置为用户的id
  277. 'user_name' => $response['phone_info']['phoneNumber'] ?? '',
  278. 'mobile' => $checkUserInfo['data']['mobile'] ?? '',
  279. 'email' => $checkUserInfo['data']['email'] ?? '',
  280. // 'rong_token' => $userInfos['data']['rong_token'],
  281. 'level_id' => $checkUserInfo['data']['level_id'] ?? '',
  282. 'type_id' => $checkUserInfo['data']['type_id'] ?? '',
  283. ];
  284. // 使用默认场景登录
  285. $token = $jwt->getToken('default', $userData);
  286. $data = [
  287. 'token' => $token->toString(),
  288. 'exp' => $jwt->getTTL($token->toString()),
  289. ];
  290. return Result::success($data);
  291. }
  292. public function getToken(JWT $jwt)
  293. {
  294. $reqData = $this->request->all();
  295. $userInfos = $this->userServiceClient->getUserInfo((int) $reqData['id']);
  296. $userData = [
  297. 'uid' => $userInfos['data']['id'], // 如果使用单点登录,必须存在配置文件中的sso_key的值,一般设置为用户的id
  298. 'user_name' => $userInfos['data']['user_name'],
  299. 'mobile' => $userInfos['data']['mobile'],
  300. 'email' => $userInfos['data']['email'],
  301. 'level_id' => $userInfos['data']['level_id'],
  302. 'type_id' => $userInfos['data']['type_id'],
  303. ];
  304. var_dump($userInfos);
  305. // 使用默认场景登录
  306. $token = $jwt->getToken('default', $userData);
  307. return Result::success($token->toString());
  308. }
  309. public function httpPost()
  310. {
  311. }
  312. # http头部必须携带token才能访问的路由
  313. public function getData(Jwt $jwt)
  314. {
  315. // var_dump($this->UserId);
  316. $h = $this->request->getHeaders();
  317. // var_dump($this->request->getHeaders());
  318. // $a= 'eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJwaHBlcjY2Ni9qd3QiLCJ1aWQiOjMyLCJ1c2VyX25hbWUiOiIxIiwicm9sZV9pZCI6MSwibW9iaWxlIjoiMTU4MDEyNDU3NTUiLCJlbWFpbCI6IjVAcXEuY29tIiwicm9uZ190b2tlbiI6IiIsImxldmVsX2lkIjo4LCJqd3Rfc2NlbmUiOiJkZWZhdWx0IiwianRpIjoiZGVmYXVsdF82Njc1MjJkZDQ3YWYxMi41MTE5MjI5MiIsImlhdCI6MTcxODk1MjY2OSwibmJmIjoxNzE4OTUyNjY5LCJleHAiOjE3MjE1NDQ2Njl9.e0JW8fgNrwBdFgmQ8GNtES2ME1SbcbIih5MsQWzT6sk';
  319. $arr = $jwt->getClaimsByToken($h['token'][0]);
  320. var_dump($h['token'][0], "+++++++++++", $arr, "===####");
  321. return $this->response->json(['code' => 0, 'msg' => 'success', 'data' => ['a' => 1]]);
  322. }
  323. /**
  324. * 检测用户权限
  325. * @return void
  326. */
  327. public function checkUserAuth($data)
  328. {
  329. // var_dump("进没进来呢::",$data);
  330. $websiteGroup = [
  331. 'id'=>$data['id']
  332. ];
  333. $result = $this->userServiceClient->getWebsiteGroupInfo($websiteGroup);
  334. // var_dump("checkUserAuth:",$result);
  335. if($result['code']==200){
  336. if($data['SiteId'] && $result['data']['web_ids']){
  337. if(in_array($data['SiteId'],json_decode($result['data']['web_ids'],true))){
  338. return true;
  339. }else{
  340. return false;
  341. }
  342. }else{
  343. return false;
  344. }
  345. }
  346. }
  347. /**
  348. * 查询登陆状态
  349. * @return array
  350. * @throws \Psr\Container\ContainerExceptionInterface
  351. * @throws \Psr\Container\NotFoundExceptionInterface
  352. * @throws \RedisException
  353. */
  354. public function loginStatus(Jwt $jwt)
  355. {
  356. $header = $this->request->getHeader('userurl');
  357. $origin = $header[0];
  358. $logindevice = explode("//", $origin);
  359. if(!isset($logindevice[1]) && !$logindevice[1]){
  360. return Result::error('userurl不存在,请登录');
  361. }
  362. $reqData = $this->request->all();
  363. $validator = $this->validationFactory->make(
  364. $reqData,
  365. [
  366. 'token' => 'required',
  367. ],
  368. [
  369. 'token.required' => 'token不能为空',
  370. ]
  371. );
  372. if ($validator->fails()) {
  373. $errorMessage = $validator->errors()->first();
  374. return Result::error($errorMessage);
  375. }
  376. try {
  377. $jwt->verifyToken($reqData['token']);
  378. $results = $this->checkAuth([
  379. 'token'=>$reqData['token'],
  380. 'userurl'=>$logindevice[1]
  381. ]);
  382. if($results['code']==200){
  383. return Result::success(['isLogin' => true]);
  384. }elseif($results['code']==-1){
  385. return Result::error("没有权限登陆".$logindevice[1]."这个域名",-1);
  386. }elseif($results['code']==-2){
  387. return Result::error("token已过期",-2);
  388. }else{
  389. return Result::error("参数错误");
  390. }
  391. }catch(\Exception $e){
  392. return Result::error('token已过期:'.$e->getMessage(),-2);
  393. }
  394. }
  395. /**
  396. *登陆
  397. * @return void
  398. */
  399. public function loginapi()
  400. {
  401. $reqData = $this->request->all();
  402. $validator = $this->validationFactory->make(
  403. $reqData,
  404. [
  405. 'token' => 'required',
  406. ],
  407. [
  408. 'token.required' => 'token不能为空',
  409. ]
  410. );
  411. if ($validator->fails()) {
  412. $errorMessage = $validator->errors()->first();
  413. return Result::error($errorMessage);
  414. }
  415. $redis = $this->container->get(\Hyperf\Redis\Redis::class);
  416. $ticket = md5($reqData['token']);
  417. $res = $redis->set('ticket:' . $ticket, $reqData['token'], 3600*24);
  418. if ($res){
  419. return Result::success(['ticket' => $ticket ,'isSave' => 1]);
  420. } else {
  421. return Result::error('存储失败');
  422. }
  423. }
  424. public function logoutapi(Jwt $jwt)
  425. {
  426. $reqData = $this->request->all();
  427. $validator = $this->validationFactory->make(
  428. $reqData,
  429. [
  430. 'token' => 'required',
  431. ],
  432. [
  433. 'token.required' => 'token不能为空',
  434. ]
  435. );
  436. if ($validator->fails()) {
  437. $errorMessage = $validator->errors()->first();
  438. return Result::error($errorMessage);
  439. }
  440. $redis = $this->container->get(\Hyperf\Redis\Redis::class);
  441. $ticket = md5($reqData['token']);
  442. $isDel = 0;
  443. if ($redis->exists('ticket:' . $ticket)) {
  444. $res = $redis->del('ticket:' . $ticket);
  445. if (!!$res && $res == 1) $isDel = 1;
  446. }else{
  447. $isDel = 1;
  448. }
  449. try {
  450. $jwt->logout($reqData['token']);
  451. }catch (\Exception $e){
  452. return Result::success(['isDel' => $isDel]);
  453. }
  454. return Result::success(['isDel' => $isDel]);
  455. }
  456. public function goLogin()
  457. {
  458. // 获取请求数据并设置默认值
  459. $reqData = $this->request->all();
  460. // 安全过滤 Admin-Token 和 ticket
  461. $cookieList = $this->request->getCookieParams();
  462. // 安全过滤 Admin-Token 和 ticket
  463. $adminToken = !empty($cookieList['Admin-Token']) ? $this->sanitizeInput($cookieList['Admin-Token']) : '';
  464. $ticket = !empty($reqData['ticket']) ? $this->sanitizeInput($reqData['ticket']) : '';
  465. $backurl = $this->sanitizeBackUrl($reqData['backurl'] ?? $_SERVER['HTTP_REFERER'] ?? '');
  466. // 校验 THE_HOST 环境变量
  467. $theHost = env("THE_HOST");
  468. if (empty($theHost)) {
  469. return Result::error('系统配置错误:THE_HOST 未定义');
  470. }
  471. var_dump("admintoken:",$adminToken);
  472. // 如果存在 adminToken,则进行登录校验
  473. if (!empty($adminToken)) {
  474. // 处理登录
  475. $redis = $this->container->get(\Hyperf\Redis\Redis::class);
  476. var_dump("ticket1111:",$ticket);
  477. if(!empty($ticket)){
  478. if (!empty($ticket) && $redis->exists('ticket:' . $ticket)) {
  479. if(isset($reqData['userurl']) && $reqData['userurl']){
  480. $resultR = $this->checkAuth([
  481. 'token'=>$redis->get('ticket:' . $ticket),
  482. 'userurl'=>$reqData['userurl']
  483. ]);
  484. if($resultR['code']==-1){
  485. return $this->response->redirect($this->fun_http('http://'.$theHost.'/#/loginAlert'), 302);
  486. }
  487. }else{
  488. $backurl = rtrim($backurl, '/');
  489. return $this->response->redirect($this->fun_http($backurl . '?ticket=' . $ticket . '&admintoken=' . urlencode($adminToken)), 302);
  490. }
  491. }else{
  492. var_dump("222222222:");
  493. return $this->response->redirect($this->fun_http('http://'.$theHost.'/#/login?backurl='.urlencode($backurl)), 302);
  494. }
  495. }else{
  496. $ticket = md5($adminToken);
  497. }
  498. var_dump("333333333333333:");
  499. return $this->response->redirect($this->fun_http($backurl . '?ticket=' . $ticket . '&admintoken=' . urlencode($adminToken)), 302);
  500. }else{
  501. var_dump("444444444444444:");
  502. return $this->response->redirect($this->fun_http('http://'.$theHost.'/#/login?backurl='.urlencode($backurl)), 302);
  503. }
  504. }
  505. /**
  506. * 安全过滤输入数据
  507. * @param string $input
  508. * @return string
  509. */
  510. private function sanitizeInput(string $input): string
  511. {
  512. return htmlspecialchars(trim($input), ENT_QUOTES, 'UTF-8');
  513. }
  514. /**
  515. * 校验并清理 backurl
  516. * @param string $backurl
  517. * @return string
  518. */
  519. private function sanitizeBackUrl(string $backurl): string
  520. {
  521. // 解码并去除多余字符
  522. $decodedUrl = urldecode($backurl);
  523. return filter_var($decodedUrl, FILTER_VALIDATE_URL) ?: '';
  524. }
  525. /**
  526. * 跳转到目标页面
  527. * @param string $backurl
  528. * @param string $ticket
  529. * @param string $adminToken
  530. */
  531. private function redirectWithTicket(string $backurl, string $ticket, string $adminToken)
  532. {
  533. $backurl = rtrim($backurl, '/');
  534. $redirectUrl = $this->fun_http($backurl . '?ticket=' . $ticket . '&admintoken=' . urlencode($adminToken));
  535. // $loginUrl = 'http://' . $theHost . '/#/login?backurl=' . urlencode($backurl);
  536. // return $this->response->redirect($loginUrl, 302);
  537. return $this->response->redirect($redirectUrl, 302);
  538. }
  539. /**
  540. * 处理 URL
  541. * @param string $url
  542. * @return string
  543. */
  544. private function fun_http(string $url): string
  545. {
  546. // 确保 URL 以 http 或 https 开头
  547. if (!preg_match('/^https?:\/\//i', $url)) {
  548. $url = 'http://' . $url;
  549. }
  550. return $url;
  551. }
  552. /**
  553. * 退出
  554. * @return void
  555. */
  556. public function logout(Jwt $jwt)
  557. {
  558. $reqData = $this->request->all();
  559. $validator = $this->validationFactory->make(
  560. $reqData,
  561. [
  562. 'backurl' => 'required',
  563. 'admintoken' => 'required',
  564. ],
  565. [
  566. 'backurl.required' => 'backurl不能为空',
  567. 'admintoken.required' => 'admintoken不能为空',
  568. ]
  569. );
  570. if ($validator->fails()) {
  571. $errorMessage = $validator->errors()->first();
  572. return Result::error($errorMessage);
  573. }
  574. $redis = $this->container->get(\Hyperf\Redis\Redis::class);
  575. $ticket = md5($reqData['admintoken']);
  576. $res = $redis->del('ticket:' . $ticket);
  577. var_dump("删除redis:", $res);
  578. var_dump("获取redis:", $redis->get('ticket:' . $ticket));
  579. // 获取所有 Cookie
  580. $cookies = $this->request->getCookieParams();
  581. var_dump("获取cookie:", $cookies);
  582. if($cookies){
  583. foreach ($cookies as $name => $value) {
  584. if($name){
  585. $expire = time() - 3600; // 设置过期时间为过去的时间
  586. $cookie = new Cookie((string)$name, '', $expire, '/');
  587. $this->response = $this->response->withCookie($cookie);
  588. }
  589. }
  590. }
  591. try {
  592. $jwt->logout($reqData['admintoken']);
  593. } catch (\Exception $e) {
  594. var_dump("返回错误信息:", $e->getMessage());
  595. }
  596. $backurl = $this->fun_http($reqData['backurl']);
  597. var_dump("返回地址:", $backurl);
  598. return $this->response->redirect($backurl, 302);
  599. }
  600. /**
  601. * 登录回调
  602. * @return void
  603. */
  604. public function backlogin()
  605. {
  606. $reqData = $this->request->all();
  607. var_dump("===============接收参数:",$reqData);
  608. $validator = $this->validationFactory->make(
  609. $reqData,
  610. [
  611. 'backurl' => 'required',
  612. 'token' => 'required',
  613. ],
  614. [
  615. 'backurl.required' => 'backurl不能为空',
  616. 'token.required' => 'token不能为空',
  617. ]
  618. );
  619. if ($validator->fails()) {
  620. $errorMessage = $validator->errors()->first();
  621. return Result::error($errorMessage);
  622. }
  623. $redis = $this->container->get(\Hyperf\Redis\Redis::class);
  624. $ticket = md5($reqData['token']);
  625. $res = $redis->set('ticket:' . $ticket, $reqData['token'], 3600*24);
  626. var_dump("===============返回值:",$res);
  627. $expire = time()+3600*24;
  628. $cookieName = 'Admin-Token';
  629. // 创建 Cookie 实例
  630. $cookie = new Cookie($cookieName, $reqData['token'], $expire, '/');
  631. // 清空 Cookie
  632. $r = $this->response = $this->response->withCookie($cookie);
  633. var_dump("设置token:", $r);
  634. if($res && !empty($ticket)){
  635. $url = $reqData['backurl'] . '/?ticket=' . $ticket . '&admintoken=' . urlencode($reqData['token']);
  636. $url = $this->fun_http($url);
  637. var_dump("跳转地址gogo:",$url);
  638. return $this->response->redirect($url, 302);
  639. }
  640. }
  641. /**
  642. * 检测用户是否有权限
  643. * @param $data
  644. * @return void
  645. * $data['token]
  646. * $data['userurl']
  647. */
  648. public function checkAuth($data)
  649. {
  650. $jwt = new JWT();
  651. $ver =$jwt->getClaimsByToken($data['token']);
  652. $tokenTime = $jwt->getTokenDynamicCacheTime($data['token']);
  653. if($tokenTime==0){
  654. return Result::error("token已过期,请重新登录",-2);
  655. }
  656. if(isset($data['userurl']) && $data['userurl']){
  657. $result = $this->websiteServiceClient->getWebsiteId(['website_url'=>$data['userurl']]);
  658. if(!isset($result['data']['id']) || !$result['data']['id']){
  659. return Result::error("网站不存在...",-2);
  660. }
  661. if($ver['type_id']!=10000){
  662. $userInfo = $this->userServiceClient->getUserInfo($ver['uid']);
  663. if($userInfo['code'] == 200 && isset($userInfo['data']) && !empty($userInfo['data']['sszq'])){
  664. $sszq = $userInfo['data']['sszq'];
  665. //组id
  666. $authData = [
  667. 'id' => $sszq,
  668. 'SiteId' => $result['data']['id']
  669. ];
  670. // 调用 LoginController 中的 checkUserAuth 方法
  671. $resultAuth = $this->checkUserAuth($authData);
  672. if (!$resultAuth) {
  673. // 如果没有权限,返回错误响应
  674. return Result::error("没有权限登陆此网站...",-1);
  675. }else{
  676. return Result::success([]);
  677. }
  678. }else{
  679. return Result::error("用户没有群组...",-2);
  680. }
  681. }else{
  682. return Result::success([]);
  683. }
  684. }else{
  685. return Result::error("userurl不能为空...",-2);
  686. }
  687. }
  688. }