LoginController.php 21 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611
  1. <?php
  2. declare (strict_types = 1);
  3. namespace App\Controller;
  4. use App\JsonRpc\UserServiceInterface;
  5. use App\Tools\CommonService;
  6. use App\Tools\PublicData;
  7. use App\Tools\Result;
  8. use Hyperf\Context\Context;
  9. use PHPStan\Type\Accessory\OversizedArrayType;
  10. use function Hyperf\Support\env;
  11. use Hyperf\Di\Annotation\Inject;
  12. use Hyperf\HttpServer\Annotation\AutoController;
  13. use Hyperf\Validation\Contract\ValidatorFactoryInterface;
  14. use \Phper666\JWTAuth\JWT;
  15. use App\Model\UserToken;
  16. use Hyperf\HttpServer\Response;
  17. /**
  18. * @AutoController()
  19. */
  20. class LoginController extends AbstractController
  21. {
  22. #[Inject]
  23. protected ValidatorFactoryInterface $validationFactory;
  24. /**
  25. * @var UserServiceInterface
  26. */
  27. #[Inject]
  28. private $userServiceClient;
  29. /**
  30. * @var Response
  31. */
  32. // private $response;
  33. // public function __construct(Response $response)
  34. // {
  35. // $this->response = $response;
  36. // }
  37. public function login(Jwt $jwt)
  38. {
  39. $reqData = $this->request->all();
  40. $validator = $this->validationFactory->make(
  41. $reqData,
  42. [
  43. 'username' => 'required',
  44. 'password' => 'required',
  45. 'type' => 'required',
  46. // 'code' => 'required',
  47. ],
  48. [
  49. 'username.required' => '用户名不能为空',
  50. 'password.required' => '密码不能为空',
  51. 'type.required' => '登录方式必填',
  52. // 'code.required' => 'code方式必填',
  53. ]
  54. );
  55. if ($validator->fails()) {
  56. $errorMessage = $validator->errors()->first();
  57. return Result::error($errorMessage);
  58. }
  59. // $comm = new CommonService();
  60. // $redis = $this->container->get(\Hyperf\Redis\Redis::class);
  61. // $code = $redis->get($reqData['code']);
  62. // if (empty($code)) {
  63. // return Result::error("验证码已过期");
  64. // }
  65. // if (strtolower($code) != strtolower($reqData['captcha'])) {
  66. // return Result::error("验证码错误");
  67. // }
  68. $where = [];
  69. if ($reqData['type'] == 1) { //密码登录
  70. $where = [
  71. 'user_name' => $reqData['username'],
  72. ];
  73. }
  74. $userInfos = $this->userServiceClient->verifyUserInfo($where);
  75. if ($userInfos['code'] == 0) {
  76. return Result::error("用户不存在");
  77. }
  78. if($userInfos['data']['status']==0){
  79. return Result::error("用户已经冻结");
  80. }
  81. if (md5(md5($reqData['password']) . $userInfos['data']['salt']) != $userInfos['data']['password']) {
  82. return Result::error("登陆密码错误");
  83. }
  84. if($userInfos['data']['type_id']!=10000){
  85. $authData = [
  86. 'id'=>$userInfos['data']['sszq'],
  87. 'SiteId'=>Context::get("SiteId")
  88. ];
  89. var_dump("参数:",$authData);
  90. $resultAuth = $this->checkUserAuth($authData);
  91. if(!$resultAuth){
  92. return Result::error("您没有权限登陆此网站");
  93. }
  94. }
  95. $userData = [
  96. 'uid' => $userInfos['data']['id'], // 如果使用单点登录,必须存在配置文件中的sso_key的值,一般设置为用户的id
  97. 'user_name' => $userInfos['data']['user_name'],
  98. 'mobile' => $userInfos['data']['mobile'],
  99. 'email' => $userInfos['data']['email'],
  100. 'level_id' => $userInfos['data']['level_id'],
  101. 'type_id' => $userInfos['data']['type_id'],
  102. ];
  103. // 使用默认场景登录
  104. $token = $jwt->getToken('default', $userData);
  105. // 检查是否有旧的token
  106. $old_token = UserToken::where('user_id', $userData['uid'])->first();
  107. if (!empty($old_token)) {
  108. $jwt->logout($old_token->token);
  109. try {
  110. $jwt->verifyToken($old_token->token);
  111. }catch (\Exception $exception){
  112. $code = $exception->getCode();
  113. if ($code== 400) {
  114. $new_token = UserToken::where('user_id', $userData['uid'])->update(['token' => $token->toString()]);
  115. if (empty($new_token)) {
  116. return Result::error("Token过期失败!");
  117. }
  118. } else{
  119. return Result::error("Token过期失败!");
  120. }
  121. }
  122. }else{
  123. $usernew_token = $token->toString();
  124. $user_token = UserToken::create([
  125. 'user_id' => $userData['uid'],
  126. 'token' => $usernew_token
  127. ]);
  128. if (empty($user_token)) {
  129. return Result::error("登录失败!");
  130. }
  131. }
  132. $data = [
  133. 'token' => $token->toString(),
  134. 'exp' => $jwt->getTTL($token->toString()),
  135. ];
  136. return Result::success($data);
  137. }
  138. /**
  139. * @return void
  140. */
  141. public function checkVerifyCode(Jwt $jwt)
  142. {
  143. //其它信息暂时不管 先以openid
  144. $reqData = $this->request->all();
  145. $validator = $this->validationFactory->make(
  146. $reqData,
  147. [
  148. 'token' => 'required',
  149. ],
  150. [
  151. 'token.required' => 'token不能为空',
  152. ]
  153. );
  154. if ($validator->fails()) {
  155. $errorMessage = $validator->errors()->first();
  156. return Result::error($errorMessage);
  157. }
  158. $userInfo = $jwt->getClaimsByToken($reqData['token']);
  159. if ($userInfo) {
  160. return Result::success(['token' => $reqData['token']]);
  161. } else {
  162. return Result::error("token无效");
  163. }
  164. }
  165. /**
  166. * 注册或登陆
  167. * @return void
  168. */
  169. public function registerOrLogin(Jwt $jwt)
  170. {
  171. //获取access_token
  172. $reqData = $this->request->all();
  173. $validator = $this->validationFactory->make(
  174. $reqData,
  175. [
  176. 'code' => 'required',
  177. ],
  178. [
  179. 'code.required' => 'code不能为空',
  180. ]
  181. );
  182. if ($validator->fails()) {
  183. $errorMessage = $validator->errors()->first();
  184. return Result::error($errorMessage);
  185. }
  186. $url = env("WECHAT") . "cgi-bin/token?appid=" . env("APPID") . "&secret=" . env("APP_SECRET") . "&grant_type=client_credential";
  187. $result = PublicData::http_get($url);
  188. $accessTokenData = json_decode($result, true);
  189. //获取openid
  190. $url = env("WECHAT") . "sns/jscode2session?appid=" . env("APPID") . "&secret=" . env("APP_SECRET") . "&js_code=" . $reqData['loginCode'] . "&grant_type=authorization_code";
  191. $result = PublicData::http_get($url);
  192. $openInfoData = json_decode($result, true);
  193. if (isset($openInfoData['errcode']) && in_array($openInfoData['errcode'], [40163, 40029])) {
  194. return Result::error($openInfoData['errmsg']);
  195. }
  196. $data = [
  197. 'code' => $reqData['code'],
  198. 'openid' => $openInfoData['openid'],
  199. ];
  200. // 将数组转换为JSON字符串
  201. $jsonData = json_encode($data);
  202. // 初始化cURL会话
  203. $ch = curl_init(env("WECHAT") . "wxa/business/getuserphonenumber?access_token=" . $accessTokenData['access_token']);
  204. // 设置cURL选项 Todo 这里有一万个wc 封装成post方法就报错,后期再研究
  205. curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
  206. curl_setopt($ch, CURLOPT_POST, true);
  207. curl_setopt($ch, CURLOPT_POSTFIELDS, $jsonData);
  208. curl_setopt($ch, CURLOPT_HTTPHEADER, [
  209. 'Content-Type: application/json',
  210. 'Content-Length: ' . strlen($jsonData),
  211. ]);
  212. // 执行cURL会话
  213. $response = curl_exec($ch);
  214. // 检查是否有错误发生
  215. if (curl_errno($ch)) {
  216. return Result::error("获取手机号失败");
  217. }
  218. // 关闭cURL会话
  219. curl_close($ch);
  220. $response = json_decode($response, true);
  221. if ($response['errcode'] == '40029') {
  222. return Result::error($openInfoData['errmsg']);
  223. }
  224. // 打印响应内容
  225. var_dump($openInfoData, $response);
  226. //根据openid 获取token
  227. $checkUserInfo = $this->userServiceClient->verifyUserInfo([
  228. 'user_name' => $response['phone_info']['purePhoneNumber'],
  229. ]);
  230. if ($checkUserInfo['code'] == 0) {
  231. $salt = rand(1, 999999);
  232. $createUserData = [
  233. 'user_name' => $response['phone_info']['purePhoneNumber'],
  234. 'salt' => $salt,
  235. 'password' => $openInfoData['openid'],
  236. 'type_id' => 20000,
  237. ];
  238. $checkUserInfo = $this->userServiceClient->createUser($createUserData);
  239. }
  240. //根据openid和手机号判断是否注册,未注册直接注册
  241. $wechatReqData = [
  242. 'openid' => $openInfoData['openid'],
  243. 'purePhoneNumber' => $response['phone_info']['purePhoneNumber'],
  244. ];
  245. $wechatInfo = $this->userServiceClient->getWechatInfo($wechatReqData);
  246. if ($wechatInfo['code'] == 0) {
  247. $wechatData = [
  248. 'openid' => $openInfoData['openid'],
  249. 'phoneNumber' => $response['phone_info']['phoneNumber'],
  250. 'purePhoneNumber' => $response['phone_info']['purePhoneNumber'],
  251. 'countryCode' => $response['phone_info']['countryCode'],
  252. 'watermark' => json_encode($response['phone_info']['watermark']),
  253. 'user_id' => $checkUserInfo['data']['id'],
  254. ];
  255. $this->userServiceClient->addWechatInfo($wechatData);
  256. }
  257. var_dump($checkUserInfo);
  258. $userData = [
  259. 'uid' => $checkUserInfo['data']['id'], // 如果使用单点登录,必须存在配置文件中的sso_key的值,一般设置为用户的id
  260. 'user_name' => $response['phone_info']['phoneNumber'],
  261. 'mobile' => $checkUserInfo['data']['mobile'] ?? '',
  262. 'email' => $checkUserInfo['data']['email'],
  263. // 'rong_token' => $userInfos['data']['rong_token'],
  264. 'level_id' => $checkUserInfo['data']['level_id'],
  265. 'type_id' => $checkUserInfo['data']['type_id'],
  266. ];
  267. // 使用默认场景登录
  268. $token = $jwt->getToken('default', $userData);
  269. $data = [
  270. 'token' => $token->toString(),
  271. 'exp' => $jwt->getTTL($token->toString()),
  272. ];
  273. return Result::success($data);
  274. }
  275. public function getToken(JWT $jwt)
  276. {
  277. $reqData = $this->request->all();
  278. $userInfos = $this->userServiceClient->getUserInfo((int) $reqData['id']);
  279. $userData = [
  280. 'uid' => $userInfos['data']['id'], // 如果使用单点登录,必须存在配置文件中的sso_key的值,一般设置为用户的id
  281. 'user_name' => $userInfos['data']['user_name'],
  282. 'mobile' => $userInfos['data']['mobile'],
  283. 'email' => $userInfos['data']['email'],
  284. 'level_id' => $userInfos['data']['level_id'],
  285. 'type_id' => $userInfos['data']['type_id'],
  286. ];
  287. var_dump($userInfos);
  288. // 使用默认场景登录
  289. $token = $jwt->getToken('default', $userData);
  290. return Result::success($token->toString());
  291. }
  292. public function httpPost()
  293. {
  294. }
  295. # http头部必须携带token才能访问的路由
  296. public function getData(Jwt $jwt)
  297. {
  298. // var_dump($this->UserId);
  299. $h = $this->request->getHeaders();
  300. // var_dump($this->request->getHeaders());
  301. // $a= 'eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJwaHBlcjY2Ni9qd3QiLCJ1aWQiOjMyLCJ1c2VyX25hbWUiOiIxIiwicm9sZV9pZCI6MSwibW9iaWxlIjoiMTU4MDEyNDU3NTUiLCJlbWFpbCI6IjVAcXEuY29tIiwicm9uZ190b2tlbiI6IiIsImxldmVsX2lkIjo4LCJqd3Rfc2NlbmUiOiJkZWZhdWx0IiwianRpIjoiZGVmYXVsdF82Njc1MjJkZDQ3YWYxMi41MTE5MjI5MiIsImlhdCI6MTcxODk1MjY2OSwibmJmIjoxNzE4OTUyNjY5LCJleHAiOjE3MjE1NDQ2Njl9.e0JW8fgNrwBdFgmQ8GNtES2ME1SbcbIih5MsQWzT6sk';
  302. $arr = $jwt->getClaimsByToken($h['token'][0]);
  303. var_dump($h['token'][0], "+++++++++++", $arr, "===####");
  304. return $this->response->json(['code' => 0, 'msg' => 'success', 'data' => ['a' => 1]]);
  305. }
  306. /**
  307. * 检测用户权限
  308. * @return void
  309. */
  310. public function checkUserAuth($data)
  311. {
  312. $websiteGroup = [
  313. 'id'=>$data['id']
  314. ];
  315. $result = $this->userServiceClient->getWebsiteGroupInfo($websiteGroup);
  316. if($result['code']==200){
  317. if($data['SiteId'] && $result['data']['web_ids']){
  318. if(in_array($data['SiteId'],json_decode($result['data']['web_ids'],true))){
  319. return true;
  320. }
  321. }else{
  322. return false;
  323. }
  324. }
  325. }
  326. /**
  327. * 查询登陆状态
  328. * @return array
  329. * @throws \Psr\Container\ContainerExceptionInterface
  330. * @throws \Psr\Container\NotFoundExceptionInterface
  331. * @throws \RedisException
  332. */
  333. public function loginStatus(Jwt $jwt)
  334. {
  335. $reqData = $this->request->all();
  336. $validator = $this->validationFactory->make(
  337. $reqData,
  338. [
  339. 'token' => 'required',
  340. ],
  341. [
  342. 'token.required' => 'token不能为空',
  343. ]
  344. );
  345. if ($validator->fails()) {
  346. $errorMessage = $validator->errors()->first();
  347. return Result::error($errorMessage);
  348. }
  349. try {
  350. $status = $jwt->verifyToken($reqData['token']);
  351. var_dump("状态:",$status);
  352. return Result::success(['isLogin' => true]);
  353. }catch(\Exception $e){
  354. return Result::error('token已过期:'.$e->getMessage());
  355. }
  356. }
  357. /**
  358. *登陆
  359. * @return void
  360. */
  361. public function loginapi()
  362. {
  363. $reqData = $this->request->all();
  364. $validator = $this->validationFactory->make(
  365. $reqData,
  366. [
  367. 'token' => 'required',
  368. ],
  369. [
  370. 'token.required' => 'token不能为空',
  371. ]
  372. );
  373. if ($validator->fails()) {
  374. $errorMessage = $validator->errors()->first();
  375. return Result::error($errorMessage);
  376. }
  377. $redis = $this->container->get(\Hyperf\Redis\Redis::class);
  378. $ticket = md5($reqData['token']);
  379. $res = $redis->set('ticket:' . $ticket, $reqData['token'], 3600*24);
  380. if ($res){
  381. return Result::success(['ticket' => $ticket ,'isSave' => 1]);
  382. } else {
  383. return Result::error('存储失败');
  384. }
  385. }
  386. public function logoutapi(Jwt $jwt)
  387. {
  388. $reqData = $this->request->all();
  389. $validator = $this->validationFactory->make(
  390. $reqData,
  391. [
  392. 'token' => 'required',
  393. ],
  394. [
  395. 'token.required' => 'token不能为空',
  396. ]
  397. );
  398. if ($validator->fails()) {
  399. $errorMessage = $validator->errors()->first();
  400. return Result::error($errorMessage);
  401. }
  402. $redis = $this->container->get(\Hyperf\Redis\Redis::class);
  403. $ticket = md5($reqData['token']);
  404. $isDel = 0;
  405. if ($redis->exists('ticket:' . $ticket)) {
  406. $res = $redis->del('ticket:' . $ticket);
  407. if (!!$res && $res == 1) $isDel = 1;
  408. }else{
  409. $isDel = 1;
  410. }
  411. $jwt->logout($reqData['token']);
  412. return Result::success(['isDel' => $isDel]);
  413. }
  414. public function goLogin()
  415. {
  416. // 获取请求数据并设置默认值
  417. $reqData = $this->request->all();
  418. // 安全过滤 Admin-Token 和 ticket
  419. $adminToken = !empty($_COOKIE['Admin-Token']) ? $this->sanitizeInput($_COOKIE['Admin-Token']) : '';
  420. $ticket = !empty($reqData['ticket']) ? $this->sanitizeInput($reqData['ticket']) : '';
  421. $backurl = $this->sanitizeBackUrl($reqData['backurl'] ?? $_SERVER['HTTP_REFERER'] ?? '');
  422. // 校验 THE_HOST 环境变量
  423. $theHost = env("THE_HOST");
  424. if (empty($theHost)) {
  425. return Result::error('系统配置错误:THE_HOST 未定义');
  426. }
  427. // 如果存在 adminToken,则进行登录校验
  428. if (!empty($adminToken)) {
  429. try {
  430. $redis = $this->container->get(\Hyperf\Redis\Redis::class);
  431. // 如果 ticket 存在且有效,则直接跳转
  432. if (!empty($ticket) && $redis->exists('ticket:' . $ticket)) {
  433. $this->redirectWithTicket($backurl, $ticket, $adminToken);
  434. // return;
  435. }
  436. // 如果 ticket 不存在或无效,则重新生成 ticket 并跳转
  437. if (empty($ticket)) {
  438. $ticket = md5($adminToken);
  439. }
  440. // 跳转到目标页面
  441. $this->redirectWithTicket($backurl, $ticket, $adminToken);
  442. // return;
  443. } catch (\Throwable $e) {
  444. // 记录异常日志
  445. // \Hyperf\Logger\LoggerFactory::get('default')->error('Redis 操作失败: ' . $e->getMessage());
  446. // 捕获 Redis 异常,返回错误信息
  447. return Result::error('系统错误:Redis 操作失败');
  448. }
  449. }
  450. // 如果没有 adminToken,则跳转到登录页面
  451. $loginUrl = 'http://' . $theHost . '/#/login?backurl=' . urlencode($backurl);
  452. return $this->response->redirect($loginUrl, 302);
  453. }
  454. /**
  455. * 安全过滤输入数据
  456. * @param string $input
  457. * @return string
  458. */
  459. private function sanitizeInput(string $input): string
  460. {
  461. return htmlspecialchars(trim($input), ENT_QUOTES, 'UTF-8');
  462. }
  463. /**
  464. * 校验并清理 backurl
  465. * @param string $backurl
  466. * @return string
  467. */
  468. private function sanitizeBackUrl(string $backurl): string
  469. {
  470. // 解码并去除多余字符
  471. $decodedUrl = urldecode($backurl);
  472. return filter_var($decodedUrl, FILTER_VALIDATE_URL) ?: '';
  473. }
  474. /**
  475. * 跳转到目标页面
  476. * @param string $backurl
  477. * @param string $ticket
  478. * @param string $adminToken
  479. */
  480. private function redirectWithTicket(string $backurl, string $ticket, string $adminToken)
  481. {
  482. $backurl = rtrim($backurl, '/');
  483. $redirectUrl = $this->fun_http($backurl . '?ticket=' . $ticket . '&admintoken=' . urlencode($adminToken));
  484. return $this->response->redirect($redirectUrl, 302);
  485. }
  486. /**
  487. * 处理 URL
  488. * @param string $url
  489. * @return string
  490. */
  491. private function fun_http(string $url): string
  492. {
  493. // 确保 URL 以 http 或 https 开头
  494. if (!preg_match('/^https?:\/\//i', $url)) {
  495. $url = 'http://' . $url;
  496. }
  497. return $url;
  498. }
  499. /**
  500. * 退出
  501. * @return void
  502. */
  503. public function logout(Jwt $jwt)
  504. {
  505. $reqData = $this->request->all();
  506. $validator = $this->validationFactory->make(
  507. $reqData,
  508. [
  509. 'backurl' => 'required',
  510. 'admintoken' => 'required',
  511. ],
  512. [
  513. 'backurl.required' => 'backurl不能为空',
  514. 'admintoken.required' => 'admintoken不能为空',
  515. ]
  516. );
  517. if ($validator->fails()) {
  518. $errorMessage = $validator->errors()->first();
  519. return Result::error($errorMessage);
  520. }
  521. $redis = $this->container->get(\Hyperf\Redis\Redis::class);
  522. $ticket = md5($reqData['admintoken']);
  523. $isDel = 0;
  524. if ($redis->exists('ticket:' . $ticket)) {
  525. $res = $redis->del('ticket:' . $ticket);
  526. if (!!$res && $res == 1) $isDel = 1;
  527. }else{
  528. $isDel = 1;
  529. }
  530. setcookie("Admin-Token", "", time(), "/");
  531. $jwt->logout($reqData['admintoken']);
  532. $backurl = $this->fun_http($reqData['backurl']);
  533. return $this->response->redirect($backurl, 302);
  534. }
  535. /**
  536. * 登录回调
  537. * @return void
  538. */
  539. public function backlogin()
  540. {
  541. $reqData = $this->request->all();
  542. $validator = $this->validationFactory->make(
  543. $reqData,
  544. [
  545. 'backurl' => 'required',
  546. 'token' => 'required',
  547. ],
  548. [
  549. 'backurl.required' => 'backurl不能为空',
  550. 'token.required' => 'token不能为空',
  551. ]
  552. );
  553. if ($validator->fails()) {
  554. $errorMessage = $validator->errors()->first();
  555. return Result::error($errorMessage);
  556. }
  557. $redis = $this->container->get(\Hyperf\Redis\Redis::class);
  558. $ticket = md5($reqData['token']);
  559. $res = $redis->set('ticket:' . $ticket, $reqData['token'], 3600*24);
  560. if($res && !empty($ticket)){
  561. $url = $reqData['backurl'] . '/?ticket=' . $ticket . '&admintoken=' . urlencode($reqData['token']);
  562. $url = $this->fun_http($url);
  563. return $this->response->redirect($url, 302);
  564. }
  565. }
  566. }