TokenController.java 14 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327
  1. package com.zd.auth.controller;
  2. import cn.hutool.core.util.RandomUtil;
  3. import com.zd.auth.form.LoginBody;
  4. import com.zd.auth.form.RegisterBody;
  5. import com.zd.auth.service.SysLoginService;
  6. import com.zd.chemical.api.fegin.RemoteStockService;
  7. import com.zd.common.core.exception.ServiceException;
  8. import com.zd.common.core.redis.RedisService;
  9. import com.zd.common.core.security.TokenService;
  10. import com.zd.common.core.utils.IdUtils;
  11. import com.zd.common.core.utils.StringUtils;
  12. import com.zd.model.constant.*;
  13. import com.zd.model.domain.AjaxResult;
  14. import com.zd.model.domain.R;
  15. import com.zd.model.entity.LoginUser;
  16. import com.zd.model.entity.SysUser;
  17. import com.zd.system.api.feign.RemoteUserService;
  18. import org.slf4j.Logger;
  19. import org.slf4j.LoggerFactory;
  20. import org.springframework.beans.BeanUtils;
  21. import org.springframework.beans.factory.annotation.Autowired;
  22. import org.springframework.data.redis.core.RedisTemplate;
  23. import org.springframework.web.bind.annotation.DeleteMapping;
  24. import org.springframework.web.bind.annotation.PostMapping;
  25. import org.springframework.web.bind.annotation.RequestBody;
  26. import org.springframework.web.bind.annotation.RestController;
  27. import javax.annotation.Resource;
  28. import javax.servlet.http.HttpServletRequest;
  29. import java.util.List;
  30. import java.util.Map;
  31. import java.util.Objects;
  32. import java.util.concurrent.TimeUnit;
  33. import static com.zd.model.constant.BaseConstants.CODE_EXPIRATION;
  34. /**
  35. * token 控制
  36. *
  37. * @author zd
  38. */
  39. @RestController
  40. public class TokenController {
  41. private final Logger logger = LoggerFactory.getLogger(TokenController.class);
  42. @Autowired
  43. private TokenService tokenService;
  44. @Autowired
  45. private SysLoginService sysLoginService;
  46. @Autowired
  47. private RemoteUserService remoteUserService;
  48. @Autowired
  49. private RedisService redisService;
  50. @Autowired
  51. private RemoteStockService stockService;
  52. @Resource
  53. private RedisTemplate<String, String> redisTemplate;
  54. @PostMapping("login")
  55. public R<?> login(@RequestBody LoginBody form) {
  56. // 用户登录
  57. String authType = form.getAuthType() == null ? BaseConstants.GRANT_TYPE_PASSWORD : form.getAuthType();
  58. LoginUser userInfo;
  59. if (Objects.equals(authType, BaseConstants.GRANT_TYPE_MOBILE)) {
  60. String key = BaseConstants.DEFAULT_CODE_KEY + BaseConstants.GRANT_TYPE_MOBILE + "@" + form.getUsername();
  61. String code = redisTemplate.opsForValue().get(key);
  62. if (form.getPassword().equals(code)) {
  63. R<LoginUser> userR = remoteUserService.getUserInfo(form.getUsername(), SecurityConstants.INNER);
  64. if (userR.getCode() == HttpStatus.SUCCESS && userR.getData() != null) {
  65. userInfo = userR.getData();
  66. } else {
  67. throw new ServiceException("系统异常");
  68. }
  69. } else {
  70. throw new ServiceException("验证码不正确", 503);
  71. }
  72. } else {
  73. userInfo = sysLoginService.login(form.getUsername(), UserConstants.USER_LOGIN_PC, form.getPassword());
  74. }
  75. userInfo.setLoginType(UserConstants.USER_LOGIN_PC);
  76. Map<String, Object> data = tokenService.createToken(userInfo);
  77. //这里判断输入的密码,是否和默认配置密码一样,如果一样,需要提示跳转设置密码
  78. AjaxResult resultPassword = remoteUserService.getConfigKey("sys.user.initPassword");
  79. if ((resultPassword.get("code") + "").equals("200")) {
  80. String defaultPassword = (String) resultPassword.get("msg");
  81. if (defaultPassword != null && defaultPassword.equals(form.getPassword())) {
  82. data.put("reset_password", true);
  83. } else {
  84. data.put("reset_password", false);
  85. }
  86. }
  87. // 区分大屏用户
  88. // 查询大屏链接
  89. AjaxResult result = remoteUserService.getRouters(userInfo.getUserid());
  90. try {
  91. List<Map<String, Object>> routers = (List<Map<String, Object>>) result.get("data");
  92. Map<String, Object> dataMenu = routers.stream().filter(
  93. a -> "https://www.sxitdlc.com".equals(a.get("path") + "")).findFirst().orElse(null);
  94. if (dataMenu != null) {
  95. String tokenKey = "login_screen:";
  96. Integer type;
  97. if (userInfo.getSysUser().isAdmin()) {
  98. type = 1;
  99. } else {
  100. result = remoteUserService.selectAuthUserPower(userInfo.getUserid());
  101. Map<String, Object> map = (Map<String, Object>) result.get("data");
  102. type = Integer.parseInt(map.get("type") + "");
  103. }
  104. if (type == null) {
  105. // 没有大屏权限
  106. type = 3;
  107. data.put("screen_token", "");
  108. } else if (redisService.hasKey(tokenKey + userInfo.getUserid())) {
  109. String token = redisService.getCacheObject(tokenKey + userInfo.getUserid());
  110. commLogin(userInfo, token);
  111. data.put("screen_token", token);
  112. } else {
  113. String token = IdUtils.fastUUID();
  114. commLogin(userInfo, token);
  115. redisService.setCacheObject(tokenKey + userInfo.getUserid(), token);
  116. // 获取大屏TOKEN
  117. data.put("screen_token", token);
  118. }
  119. data.put("screen_type", type);
  120. } else {
  121. // 没有大屏权限
  122. data.put("screen_type", 3);
  123. data.put("screen_token", "");
  124. }
  125. } catch (Exception e) {
  126. // 没有大屏权限
  127. data.put("screen_type", 3);
  128. data.put("screen_token", "");
  129. }
  130. // 获取登录token
  131. return R.ok(data);
  132. }
  133. //公共登录方法
  134. private void commLogin(LoginUser userInfo, String token) {
  135. LoginUser loginUser = new LoginUser();
  136. BeanUtils.copyProperties(userInfo, loginUser);
  137. loginUser.setToken(token);
  138. redisService.setCacheObject(CacheConstants.LOGIN_TOKEN_KEY + token, loginUser);
  139. }
  140. /**
  141. * 一体机登录
  142. * 小程序登录也在用
  143. */
  144. @PostMapping("/one/login")
  145. public R<?> oneLogin(@RequestBody LoginBody form) {
  146. // 用户登录
  147. LoginUser userInfo = sysLoginService.login(form.getUsername(), UserConstants.USER_LOGIN_WX, form.getPassword());
  148. userInfo.setLoginType(UserConstants.USER_LOGIN_WX);
  149. // 获取登录token
  150. return R.ok(tokenService.createProgramToken(userInfo));
  151. }
  152. /**
  153. * 发送验证码
  154. */
  155. @PostMapping("/send/code")
  156. public R<?> send(@RequestBody LoginBody form) {
  157. String username = form.getUsername();
  158. R<LoginUser> userR = remoteUserService.getUserInfo(username, SecurityConstants.INNER);
  159. if (userR.getCode() != HttpStatus.SUCCESS || userR.getData() == null) {
  160. throw new ServiceException("用户不存在", 530);
  161. }
  162. String key = BaseConstants.DEFAULT_CODE_KEY + BaseConstants.GRANT_TYPE_MOBILE + "@" + username;
  163. String code = RandomUtil.randomNumbers(6);
  164. redisTemplate.opsForValue().set(key, code, CODE_EXPIRATION, TimeUnit.MINUTES);
  165. logger.info("========================>{}<=========================", code);
  166. String countKey = BaseConstants.DEFAULT_CODE_KEY + "@" + username + "_COUNT";
  167. String count = redisTemplate.opsForValue().get(countKey);
  168. if (StringUtils.isEmpty(count)) {
  169. redisTemplate.opsForValue().set(countKey, "1", 60, TimeUnit.MINUTES);
  170. } else {
  171. if (count != null) {
  172. int i = Integer.parseInt(count);
  173. if (i >= 5) {
  174. throw new ServiceException("验证码发送超过限制,请一小时后再试", 530);
  175. }
  176. i++;
  177. redisTemplate.opsForValue().set(countKey, i + "", 60, TimeUnit.MINUTES);
  178. }
  179. }
  180. return stockService.sendSydSms(code, 2, null, form.getUsername());
  181. }
  182. /**
  183. * 学习一体机 用户端登录
  184. * 接口修改为分两步操作,1 刷卡获取人员信息和token , 2 人脸验证之后再调用一次实现真实登录
  185. * type : 1 和 2
  186. */
  187. @PostMapping("/learn/login")
  188. public R<?> learnLogin(HttpServletRequest request, @RequestBody Map<String, Object> params) {
  189. int type = org.apache.commons.lang3.StringUtils.isNotBlank((String) params.get("type")) ? Integer.parseInt((String) params.get("type")) : 1;
  190. String machineCode = params.get("machineCode") == null ? "" : (String) params.get("machineCode");
  191. // 用户登录
  192. String username = (String) params.get("userName");
  193. int aioType = params.get("aioType") == null ? UserConstants.USER_LOGIN_AIO : Integer.parseInt(params.get("aioType") + "");
  194. logger.error("学习机登录,加密前:" + username + ",设备编码:" + machineCode);
  195. if (UserConstants.USER_LOGIN_HXP == aioType) {
  196. // TODO 终端传参数据有问题,暂临时后端处理
  197. // username = username.replaceAll("%00", "")
  198. // .replaceAll("%02", "")
  199. // .replaceAll("%03", "")
  200. // .replaceAll("%0A", "")
  201. // .replaceAll("%0D", "")
  202. // .trim();
  203. } else {
  204. // 查询用户信息
  205. if (StringUtils.isNumeric(username)) {
  206. username = Long.toHexString(Long.parseLong(username)).toUpperCase();
  207. logger.error("学习机登录,加密后:" + username);
  208. } else {
  209. logger.error("通过卡号未找到用户");
  210. return R.fail("无效卡号或未绑定用户,请联系管理员!");
  211. }
  212. }
  213. R<SysUser> user = remoteUserService.getUserInfoByCardNum(username, SecurityConstants.INNER);
  214. if (R.FAIL == user.getCode()) {
  215. throw new ServiceException(user.getMsg());
  216. }
  217. if (StringUtils.isNull(user.getData())) {
  218. return R.fail("登录用户不存在!");
  219. }
  220. R<LoginUser> userResult = remoteUserService.getUserInfo(user.getData().getUserName(), aioType, SecurityConstants.INNER);
  221. if (R.FAIL == userResult.getCode() || 503 == userResult.getCode()) {
  222. return R.fail(userResult.getMsg());
  223. }
  224. if (userResult.getData() != null) {
  225. LoginUser userInfo = userResult.getData();
  226. userInfo.setLoginType(aioType);
  227. userInfo.setMachineCode(machineCode);
  228. if (userInfo.getSysUser() == null) {
  229. return R.fail("登录用户不存在!");
  230. }
  231. Map<String, Object> map = null;
  232. if (type == 1) {
  233. // 获取登录token
  234. map = tokenService.createToken(userInfo);
  235. } else if (type == 2) {
  236. // 资源删除
  237. LoginUser loginUser = tokenService.getLoginUser(request);
  238. if (StringUtils.isNotNull(loginUser)) {
  239. // 删除用户缓存记录
  240. tokenService.delLoginUser(loginUser.getToken());
  241. }
  242. map = tokenService.createToken(userInfo);
  243. if (UserConstants.USER_LOGIN_HXP == aioType) {
  244. map.put("positionName", userInfo.getSysUser().getPositionName());
  245. map.put("cabinetLock", userInfo.isCabinetLock());
  246. map.put("airBottle", userInfo.isAirBottle());
  247. } else if (UserConstants.USER_LOGIN_AIO == aioType) {
  248. if (redisService.hasKey(CacheConstants.LEARN_USER_KEY + userInfo.getSysUser().getUserId())) {
  249. LoginUser userCache = redisService.getCacheObject(CacheConstants.LEARN_USER_KEY + userInfo.getSysUser().getUserId());
  250. if (!machineCode.equals(userCache.getMachineCode())) {
  251. return R.fail("签到失败,不能重复签到!");
  252. }
  253. }
  254. // 记录学习一体机用户登录状态
  255. redisService.setCacheObject(CacheConstants.LEARN_USER_KEY + userInfo.getSysUser().getUserId(), userInfo, BaseConstants.TOKEN_EXPIRE * 60, TimeUnit.SECONDS);
  256. }
  257. }
  258. return R.ok(map);
  259. } else {
  260. return R.fail("登录用户不存在!");
  261. }
  262. }
  263. /**
  264. * 学习一体机 用户退出登录
  265. */
  266. @PostMapping("/learn/loginOut")
  267. public R<?> learnLoginOut(HttpServletRequest request) {
  268. LoginUser loginUser = tokenService.getLoginUser(request);
  269. if (StringUtils.isNotNull(loginUser)) {
  270. SysUser user = loginUser.getSysUser();
  271. // 删除用户缓存记录
  272. tokenService.delLoginUser(loginUser.getToken());
  273. // 记录用户退出日志
  274. sysLoginService.logout(user);
  275. // 删除一体机登录状态
  276. redisService.deleteObject(CacheConstants.LEARN_USER_KEY + loginUser.getUserid());
  277. }
  278. return R.ok();
  279. }
  280. @DeleteMapping("logout")
  281. public R<?> logout(HttpServletRequest request) {
  282. LoginUser loginUser = tokenService.getLoginUser(request);
  283. if (StringUtils.isNotNull(loginUser)) {
  284. SysUser user = loginUser.getSysUser();
  285. // 删除用户缓存记录
  286. tokenService.delLoginUser(loginUser.getToken());
  287. // 记录用户退出日志
  288. sysLoginService.logout(user);
  289. }
  290. return R.ok();
  291. }
  292. @PostMapping("refresh")
  293. public R<?> refresh(HttpServletRequest request) {
  294. LoginUser loginUser = tokenService.getLoginUser(request);
  295. if (StringUtils.isNotNull(loginUser)) {
  296. // 刷新令牌有效期
  297. tokenService.refreshToken(loginUser);
  298. return R.ok();
  299. }
  300. return R.ok();
  301. }
  302. @PostMapping("register")
  303. public R<?> register(@RequestBody RegisterBody registerBody) {
  304. // 用户注册
  305. sysLoginService.register(registerBody.getUsername(), registerBody.getPassword());
  306. return R.ok();
  307. }
  308. }