e99d55ee9f65e33e55f852d9fe6705ac5813d588.svn-base 19 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523
  1. package org.jeecg.modules.system.controller;
  2. import cn.hutool.core.util.RandomUtil;
  3. import com.alibaba.fastjson.JSONObject;
  4. import com.aliyuncs.exceptions.ClientException;
  5. import com.baomidou.mybatisplus.core.conditions.query.LambdaQueryWrapper;
  6. import io.swagger.annotations.Api;
  7. import io.swagger.annotations.ApiOperation;
  8. import lombok.extern.slf4j.Slf4j;
  9. import org.apache.shiro.SecurityUtils;
  10. import org.jeecg.common.api.vo.Result;
  11. import org.jeecg.common.constant.CacheConstant;
  12. import org.jeecg.common.constant.CommonConstant;
  13. import org.jeecg.common.system.api.ISysBaseAPI;
  14. import org.jeecg.common.system.util.JwtUtil;
  15. import org.jeecg.common.system.vo.LoginUser;
  16. import org.jeecg.common.util.*;
  17. import org.jeecg.common.util.encryption.AesEncryptUtil;
  18. import org.jeecg.common.util.encryption.EncryptedString;
  19. import org.jeecg.modules.base.service.BaseCommonService;
  20. import org.jeecg.modules.system.entity.SysDepart;
  21. import org.jeecg.modules.system.entity.SysTenant;
  22. import org.jeecg.modules.system.entity.SysUser;
  23. import org.jeecg.modules.system.model.SysLoginModel;
  24. import org.jeecg.modules.system.service.*;
  25. import org.jeecg.modules.system.util.RandImageUtil;
  26. import org.springframework.beans.BeanUtils;
  27. import org.springframework.beans.factory.annotation.Autowired;
  28. import org.springframework.web.bind.annotation.*;
  29. import javax.annotation.Resource;
  30. import javax.servlet.http.HttpServletRequest;
  31. import javax.servlet.http.HttpServletResponse;
  32. import java.util.*;
  33. /**
  34. * @Author scott
  35. * @since 2018-12-17
  36. */
  37. @RestController
  38. @RequestMapping("/sys")
  39. @Api(tags="用户登录")
  40. @Slf4j
  41. public class LoginController {
  42. @Autowired
  43. private ISysUserService sysUserService;
  44. @Autowired
  45. private ISysBaseAPI sysBaseAPI;
  46. @Autowired
  47. private ISysLogService logService;
  48. @Autowired
  49. private RedisUtil redisUtil;
  50. @Autowired
  51. private ISysDepartService sysDepartService;
  52. @Autowired
  53. private ISysTenantService sysTenantService;
  54. @Autowired
  55. private ISysDictService sysDictService;
  56. @Resource
  57. private BaseCommonService baseCommonService;
  58. private static final String BASE_CHECK_CODES = "qwertyuiplkjhgfdsazxcvbnmQWERTYUPLKJHGFDSAZXCVBNM1234567890";
  59. @ApiOperation("登录接口")
  60. @RequestMapping(value = "/login", method = RequestMethod.POST)
  61. public Result<JSONObject> login(@RequestBody SysLoginModel sysLoginModel) throws Exception {
  62. Result<JSONObject> result = new Result<JSONObject>();
  63. String username = sysLoginModel.getUsername();
  64. String password = sysLoginModel.getPassword();
  65. //update-begin--Author:scott Date:20190805 for:暂时注释掉密码加密逻辑,有点问题
  66. //前端密码加密,后端进行密码解密
  67. password = AesEncryptUtil.desEncrypt(sysLoginModel.getPassword().replaceAll("%2B", "\\+")).trim();//密码解密
  68. //update-begin--Author:scott Date:20190805 for:暂时注释掉密码加密逻辑,有点问题
  69. //update-begin-author:taoyan date:20190828 for:校验验证码
  70. String captcha = sysLoginModel.getCaptcha();
  71. if(captcha==null){
  72. result.error500("验证码无效");
  73. return result;
  74. }
  75. String lowerCaseCaptcha = captcha.toLowerCase();
  76. String realKey = MD5Util.MD5Encode(lowerCaseCaptcha+sysLoginModel.getCheckKey(), "utf-8");
  77. Object checkCode = redisUtil.get(realKey);
  78. //当进入登录页时,有一定几率出现验证码错误 #1714
  79. if(checkCode==null || !checkCode.toString().equals(lowerCaseCaptcha)) {
  80. result.error500("验证码错误");
  81. return result;
  82. }
  83. //update-end-author:taoyan date:20190828 for:校验验证码
  84. //1. 校验用户是否有效
  85. //update-begin-author:wangshuai date:20200601 for: 登录代码验证用户是否注销bug,if条件永远为false
  86. LambdaQueryWrapper<SysUser> queryWrapper = new LambdaQueryWrapper<>();
  87. queryWrapper.eq(SysUser::getUsername,username);
  88. SysUser sysUser = sysUserService.getOne(queryWrapper);
  89. //update-end-author:wangshuai date:20200601 for: 登录代码验证用户是否注销bug,if条件永远为false
  90. result = sysUserService.checkUserIsEffective(sysUser);
  91. if(!result.isSuccess()) {
  92. return result;
  93. }
  94. //2. 校验用户名或密码是否正确
  95. String userpassword = PasswordUtil.encrypt(username, password, sysUser.getSalt());
  96. String syspassword = sysUser.getPassword();
  97. if (!syspassword.equals(userpassword)) {
  98. result.error500("用户名或密码错误");
  99. return result;
  100. }
  101. //用户登录信息
  102. userInfo(sysUser, result);
  103. //update-begin--Author:liusq Date:20210126 for:登录成功,删除redis中的验证码
  104. redisUtil.del(realKey);
  105. //update-begin--Author:liusq Date:20210126 for:登录成功,删除redis中的验证码
  106. LoginUser loginUser = new LoginUser();
  107. BeanUtils.copyProperties(sysUser, loginUser);
  108. baseCommonService.addLog("用户名: " + username + ",登录成功!", CommonConstant.LOG_TYPE_1, null,loginUser);
  109. //update-end--Author:wangshuai Date:20200714 for:登录日志没有记录人员
  110. return result;
  111. }
  112. /**
  113. * 退出登录
  114. * @param request
  115. * @param response
  116. * @return
  117. */
  118. @RequestMapping(value = "/logout")
  119. public Result<Object> logout(HttpServletRequest request,HttpServletResponse response) {
  120. //用户退出逻辑
  121. String token = request.getHeader(CommonConstant.X_ACCESS_TOKEN);
  122. if(oConvertUtils.isEmpty(token)) {
  123. return Result.error("退出登录失败!");
  124. }
  125. String username = JwtUtil.getUsername(token);
  126. LoginUser sysUser = sysBaseAPI.getUserByName(username);
  127. if(sysUser!=null) {
  128. //update-begin--Author:wangshuai Date:20200714 for:登出日志没有记录人员
  129. baseCommonService.addLog("用户名: "+sysUser.getRealname()+",退出成功!", CommonConstant.LOG_TYPE_1, null,sysUser);
  130. //update-end--Author:wangshuai Date:20200714 for:登出日志没有记录人员
  131. log.info(" 用户名: "+sysUser.getRealname()+",退出成功! ");
  132. //清空用户登录Token缓存
  133. redisUtil.del(CommonConstant.PREFIX_USER_TOKEN + token);
  134. //清空用户登录Shiro权限缓存
  135. redisUtil.del(CommonConstant.PREFIX_USER_SHIRO_CACHE + sysUser.getId());
  136. //清空用户的缓存信息(包括部门信息),例如sys:cache:user::<username>
  137. redisUtil.del(String.format("%s::%s", CacheConstant.SYS_USERS_CACHE, sysUser.getUsername()));
  138. //调用shiro的logout
  139. SecurityUtils.getSubject().logout();
  140. return Result.ok("退出登录成功!");
  141. }else {
  142. return Result.error("Token无效!");
  143. }
  144. }
  145. /**
  146. * 获取访问量
  147. * @return
  148. */
  149. @GetMapping("loginfo")
  150. public Result<JSONObject> loginfo() {
  151. Result<JSONObject> result = new Result<JSONObject>();
  152. JSONObject obj = new JSONObject();
  153. //update-begin--Author:zhangweijian Date:20190428 for:传入开始时间,结束时间参数
  154. // 获取一天的开始和结束时间
  155. Calendar calendar = new GregorianCalendar();
  156. calendar.set(Calendar.HOUR_OF_DAY, 0);
  157. calendar.set(Calendar.MINUTE, 0);
  158. calendar.set(Calendar.SECOND, 0);
  159. calendar.set(Calendar.MILLISECOND, 0);
  160. Date dayStart = calendar.getTime();
  161. calendar.add(Calendar.DATE, 1);
  162. Date dayEnd = calendar.getTime();
  163. // 获取系统访问记录
  164. Long totalVisitCount = logService.findTotalVisitCount();
  165. obj.put("totalVisitCount", totalVisitCount);
  166. Long todayVisitCount = logService.findTodayVisitCount(dayStart,dayEnd);
  167. obj.put("todayVisitCount", todayVisitCount);
  168. Long todayIp = logService.findTodayIp(dayStart,dayEnd);
  169. //update-end--Author:zhangweijian Date:20190428 for:传入开始时间,结束时间参数
  170. obj.put("todayIp", todayIp);
  171. result.setResult(obj);
  172. result.success("登录成功");
  173. return result;
  174. }
  175. /**
  176. * 获取访问量
  177. * @return
  178. */
  179. @GetMapping("visitInfo")
  180. public Result<List<Map<String,Object>>> visitInfo() {
  181. Result<List<Map<String,Object>>> result = new Result<List<Map<String,Object>>>();
  182. Calendar calendar = new GregorianCalendar();
  183. calendar.set(Calendar.HOUR_OF_DAY,0);
  184. calendar.set(Calendar.MINUTE,0);
  185. calendar.set(Calendar.SECOND,0);
  186. calendar.set(Calendar.MILLISECOND,0);
  187. calendar.add(Calendar.DAY_OF_MONTH, 1);
  188. Date dayEnd = calendar.getTime();
  189. calendar.add(Calendar.DAY_OF_MONTH, -7);
  190. Date dayStart = calendar.getTime();
  191. List<Map<String,Object>> list = logService.findVisitCount(dayStart, dayEnd);
  192. result.setResult(oConvertUtils.toLowerCasePageList(list));
  193. return result;
  194. }
  195. /**
  196. * 登陆成功选择用户当前部门
  197. * @param user
  198. * @return
  199. */
  200. @RequestMapping(value = "/selectDepart", method = RequestMethod.POST)
  201. public Result<JSONObject> selectDepart(@RequestBody SysUser user) {
  202. Result<JSONObject> result = new Result<JSONObject>();
  203. String username = user.getUsername();
  204. if(oConvertUtils.isEmpty(username)) {
  205. LoginUser sysUser = (LoginUser)SecurityUtils.getSubject().getPrincipal();
  206. username = sysUser.getUsername();
  207. }
  208. String orgCode= user.getOrgCode();
  209. this.sysUserService.updateUserDepart(username, orgCode);
  210. SysUser sysUser = sysUserService.getUserByName(username);
  211. JSONObject obj = new JSONObject();
  212. obj.put("userInfo", sysUser);
  213. result.setResult(obj);
  214. return result;
  215. }
  216. /**
  217. * 短信登录接口
  218. *
  219. * @param jsonObject
  220. * @return
  221. */
  222. @PostMapping(value = "/sms")
  223. public Result<String> sms(@RequestBody JSONObject jsonObject) {
  224. Result<String> result = new Result<String>();
  225. String mobile = jsonObject.get("mobile").toString();
  226. //手机号模式 登录模式: "2" 注册模式: "1"
  227. String smsmode=jsonObject.get("smsmode").toString();
  228. log.info(mobile);
  229. if(oConvertUtils.isEmpty(mobile)){
  230. result.setMessage("手机号不允许为空!");
  231. result.setSuccess(false);
  232. return result;
  233. }
  234. Object object = redisUtil.get(mobile);
  235. if (object != null) {
  236. result.setMessage("验证码10分钟内,仍然有效!");
  237. result.setSuccess(false);
  238. return result;
  239. }
  240. //随机数
  241. String captcha = RandomUtil.randomNumbers(6);
  242. JSONObject obj = new JSONObject();
  243. obj.put("code", captcha);
  244. try {
  245. boolean b = false;
  246. //注册模板
  247. if (CommonConstant.SMS_TPL_TYPE_1.equals(smsmode)) {
  248. SysUser sysUser = sysUserService.getUserByPhone(mobile);
  249. if(sysUser!=null) {
  250. result.error500(" 手机号已经注册,请直接登录!");
  251. baseCommonService.addLog("手机号已经注册,请直接登录!", CommonConstant.LOG_TYPE_1, null);
  252. return result;
  253. }
  254. b = DySmsHelper.sendSms(mobile, obj, DySmsEnum.REGISTER_TEMPLATE_CODE);
  255. }else {
  256. //登录模式,校验用户有效性
  257. SysUser sysUser = sysUserService.getUserByPhone(mobile);
  258. result = sysUserService.checkUserIsEffective(sysUser);
  259. if(!result.isSuccess()) {
  260. String message = result.getMessage();
  261. if("该用户不存在,请注册".equals(message)){
  262. result.error500("该用户不存在或未绑定手机号");
  263. }
  264. return result;
  265. }
  266. /**
  267. * smsmode 短信模板方式 0 .登录模板、1.注册模板、2.忘记密码模板
  268. */
  269. if (CommonConstant.SMS_TPL_TYPE_0.equals(smsmode)) {
  270. //登录模板
  271. b = DySmsHelper.sendSms(mobile, obj, DySmsEnum.LOGIN_TEMPLATE_CODE);
  272. } else if(CommonConstant.SMS_TPL_TYPE_2.equals(smsmode)) {
  273. //忘记密码模板
  274. b = DySmsHelper.sendSms(mobile, obj, DySmsEnum.FORGET_PASSWORD_TEMPLATE_CODE);
  275. }
  276. }
  277. if (b == false) {
  278. result.setMessage("短信验证码发送失败,请稍后重试");
  279. result.setSuccess(false);
  280. return result;
  281. }
  282. //验证码10分钟内有效
  283. redisUtil.set(mobile, captcha, 600);
  284. //update-begin--Author:scott Date:20190812 for:issues#391
  285. //result.setResult(captcha);
  286. //update-end--Author:scott Date:20190812 for:issues#391
  287. result.setSuccess(true);
  288. } catch (ClientException e) {
  289. e.printStackTrace();
  290. result.error500(" 短信接口未配置,请联系管理员!");
  291. return result;
  292. }
  293. return result;
  294. }
  295. /**
  296. * 手机号登录接口
  297. *
  298. * @param jsonObject
  299. * @return
  300. */
  301. @ApiOperation("手机号登录接口")
  302. @PostMapping("/phoneLogin")
  303. public Result<JSONObject> phoneLogin(@RequestBody JSONObject jsonObject) {
  304. Result<JSONObject> result = new Result<JSONObject>();
  305. String phone = jsonObject.getString("mobile");
  306. //校验用户有效性
  307. SysUser sysUser = sysUserService.getUserByPhone(phone);
  308. result = sysUserService.checkUserIsEffective(sysUser);
  309. if(!result.isSuccess()) {
  310. return result;
  311. }
  312. String smscode = jsonObject.getString("captcha");
  313. Object code = redisUtil.get(phone);
  314. if (!smscode.equals(code)) {
  315. result.setMessage("手机验证码错误");
  316. return result;
  317. }
  318. //用户信息
  319. userInfo(sysUser, result);
  320. //添加日志
  321. baseCommonService.addLog("用户名: " + sysUser.getUsername() + ",登录成功!", CommonConstant.LOG_TYPE_1, null);
  322. return result;
  323. }
  324. /**
  325. * 用户信息
  326. *
  327. * @param sysUser
  328. * @param result
  329. * @return
  330. */
  331. private Result<JSONObject> userInfo(SysUser sysUser, Result<JSONObject> result) {
  332. String syspassword = sysUser.getPassword();
  333. String username = sysUser.getUsername();
  334. // 获取用户部门信息
  335. JSONObject obj = new JSONObject();
  336. List<SysDepart> departs = sysDepartService.queryUserDeparts(sysUser.getId());
  337. obj.put("departs", departs);
  338. if (departs == null || departs.size() == 0) {
  339. obj.put("multi_depart", 0);
  340. } else if (departs.size() == 1) {
  341. sysUserService.updateUserDepart(username, departs.get(0).getOrgCode());
  342. obj.put("multi_depart", 1);
  343. } else {
  344. //查询当前是否有登录部门
  345. // update-begin--Author:wangshuai Date:20200805 for:如果用戶为选择部门,数据库为存在上一次登录部门,则取一条存进去
  346. SysUser sysUserById = sysUserService.getById(sysUser.getId());
  347. if(oConvertUtils.isEmpty(sysUserById.getOrgCode())){
  348. sysUserService.updateUserDepart(username, departs.get(0).getOrgCode());
  349. }
  350. // update-end--Author:wangshuai Date:20200805 for:如果用戶为选择部门,数据库为存在上一次登录部门,则取一条存进去
  351. obj.put("multi_depart", 2);
  352. }
  353. // update-begin--Author:sunjianlei Date:20210802 for:获取用户租户信息
  354. String tenantIds = sysUser.getRelTenantIds();
  355. if (oConvertUtils.isNotEmpty(tenantIds)) {
  356. List<String> tenantIdList = Arrays.asList(tenantIds.split(","));
  357. // 该方法仅查询有效的租户,如果返回0个就说明所有的租户均无效。
  358. List<SysTenant> tenantList = sysTenantService.queryEffectiveTenant(tenantIdList);
  359. if (tenantList.size() == 0) {
  360. result.error500("与该用户关联的租户均已被冻结,无法登录!");
  361. return result;
  362. } else {
  363. obj.put("tenantList", tenantList);
  364. }
  365. }
  366. // update-end--Author:sunjianlei Date:20210802 for:获取用户租户信息
  367. // 生成token
  368. String token = JwtUtil.sign(username, syspassword);
  369. // 设置token缓存有效时间
  370. redisUtil.set(CommonConstant.PREFIX_USER_TOKEN + token, token);
  371. redisUtil.expire(CommonConstant.PREFIX_USER_TOKEN + token, JwtUtil.EXPIRE_TIME * 2 / 1000);
  372. obj.put("token", token);
  373. obj.put("userInfo", sysUser);
  374. obj.put("sysAllDictItems", sysDictService.queryAllDictItems());
  375. result.setResult(obj);
  376. result.success("登录成功");
  377. return result;
  378. }
  379. /**
  380. * 获取加密字符串
  381. * @return
  382. */
  383. @GetMapping(value = "/getEncryptedString")
  384. public Result<Map<String,String>> getEncryptedString(){
  385. Result<Map<String,String>> result = new Result<Map<String,String>>();
  386. Map<String,String> map = new HashMap<String,String>();
  387. map.put("key", EncryptedString.key);
  388. map.put("iv",EncryptedString.iv);
  389. result.setResult(map);
  390. return result;
  391. }
  392. /**
  393. * 后台生成图形验证码 :有效
  394. * @param response
  395. * @param key
  396. */
  397. @ApiOperation("获取验证码")
  398. @GetMapping(value = "/randomImage/{key}")
  399. public Result<String> randomImage(HttpServletResponse response,@PathVariable String key){
  400. Result<String> res = new Result<String>();
  401. try {
  402. String code = RandomUtil.randomString(BASE_CHECK_CODES,4);
  403. String lowerCaseCode = code.toLowerCase();
  404. String realKey = MD5Util.MD5Encode(lowerCaseCode+key, "utf-8");
  405. redisUtil.set(realKey, lowerCaseCode, 60);
  406. String base64 = RandImageUtil.generate(code);
  407. res.setSuccess(true);
  408. res.setResult(base64);
  409. } catch (Exception e) {
  410. res.error500("获取验证码出错"+e.getMessage());
  411. e.printStackTrace();
  412. }
  413. return res;
  414. }
  415. /**
  416. * app登录
  417. * @param sysLoginModel
  418. * @return
  419. * @throws Exception
  420. */
  421. @RequestMapping(value = "/mLogin", method = RequestMethod.POST)
  422. public Result<JSONObject> mLogin(@RequestBody SysLoginModel sysLoginModel) throws Exception {
  423. Result<JSONObject> result = new Result<JSONObject>();
  424. String username = sysLoginModel.getUsername();
  425. String password = sysLoginModel.getPassword();
  426. //1. 校验用户是否有效
  427. SysUser sysUser = sysUserService.getUserByName(username);
  428. result = sysUserService.checkUserIsEffective(sysUser);
  429. if(!result.isSuccess()) {
  430. return result;
  431. }
  432. //2. 校验用户名或密码是否正确
  433. String userpassword = PasswordUtil.encrypt(username, password, sysUser.getSalt());
  434. String syspassword = sysUser.getPassword();
  435. if (!syspassword.equals(userpassword)) {
  436. result.error500("用户名或密码错误");
  437. return result;
  438. }
  439. String orgCode = sysUser.getOrgCode();
  440. if(oConvertUtils.isEmpty(orgCode)) {
  441. //如果当前用户无选择部门 查看部门关联信息
  442. List<SysDepart> departs = sysDepartService.queryUserDeparts(sysUser.getId());
  443. if (departs == null || departs.size() == 0) {
  444. result.error500("用户暂未归属部门,不可登录!");
  445. return result;
  446. }
  447. orgCode = departs.get(0).getOrgCode();
  448. sysUser.setOrgCode(orgCode);
  449. this.sysUserService.updateUserDepart(username, orgCode);
  450. }
  451. JSONObject obj = new JSONObject();
  452. //用户登录信息
  453. obj.put("userInfo", sysUser);
  454. // 生成token
  455. String token = JwtUtil.sign(username, syspassword);
  456. // 设置超时时间
  457. redisUtil.set(CommonConstant.PREFIX_USER_TOKEN + token, token);
  458. redisUtil.expire(CommonConstant.PREFIX_USER_TOKEN + token, JwtUtil.EXPIRE_TIME*2 / 1000);
  459. //token 信息
  460. obj.put("token", token);
  461. result.setResult(obj);
  462. result.setSuccess(true);
  463. result.setCode(200);
  464. baseCommonService.addLog("用户名: " + username + ",登录成功[移动端]!", CommonConstant.LOG_TYPE_1, null);
  465. return result;
  466. }
  467. /**
  468. * 图形验证码
  469. * @param sysLoginModel
  470. * @return
  471. */
  472. @RequestMapping(value = "/checkCaptcha", method = RequestMethod.POST)
  473. public Result<?> checkCaptcha(@RequestBody SysLoginModel sysLoginModel){
  474. String captcha = sysLoginModel.getCaptcha();
  475. String checkKey = sysLoginModel.getCheckKey();
  476. if(captcha==null){
  477. return Result.error("验证码无效");
  478. }
  479. String lowerCaseCaptcha = captcha.toLowerCase();
  480. String realKey = MD5Util.MD5Encode(lowerCaseCaptcha+checkKey, "utf-8");
  481. Object checkCode = redisUtil.get(realKey);
  482. if(checkCode==null || !checkCode.equals(lowerCaseCaptcha)) {
  483. return Result.error("验证码错误");
  484. }
  485. return Result.ok();
  486. }
  487. }