function.go 5.9 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226
  1. package utils
  2. import (
  3. "database/sql"
  4. "errors"
  5. "gfast/app/model/admin/user"
  6. "gfast/app/model/admin/user_online"
  7. "gfast/library/response"
  8. "github.com/goflyfox/gtoken/gtoken"
  9. "github.com/gogf/gf/crypto/gaes"
  10. "github.com/gogf/gf/crypto/gmd5"
  11. "github.com/gogf/gf/encoding/gbase64"
  12. "github.com/gogf/gf/frame/g"
  13. "github.com/gogf/gf/net/ghttp"
  14. "github.com/gogf/gf/os/gtime"
  15. "github.com/gogf/gf/util/gconv"
  16. "github.com/gogf/gf/util/gvalid"
  17. "github.com/mojocn/base64Captcha"
  18. "github.com/mssola/user_agent"
  19. "strings"
  20. )
  21. const AdminCbcPublicKey = "HqmP1KLMuz09Q0Bu"
  22. var (
  23. AdminMultiLogin bool //是否允许后台管理员多端登陆
  24. AdminPageNum = 20 //后台分页长度
  25. NotCheckAuthAdminIds []int //无需验证权限的用户id
  26. )
  27. //获取数字验证码
  28. func GetVerifyImgDigit() (idKeyC string, base64stringC string) {
  29. driver := &base64Captcha.DriverDigit{80, 240, 5, 0.7, 5}
  30. store := base64Captcha.DefaultMemStore
  31. c := base64Captcha.NewCaptcha(driver, store)
  32. idKeyC, base64stringC, err := c.Generate()
  33. if err != nil {
  34. g.Log().Error(err)
  35. }
  36. return
  37. }
  38. //获取字母数字混合验证码
  39. func GetVerifyImgString() (idKeyC string, base64stringC string) {
  40. driver := &base64Captcha.DriverString{
  41. Height: 80,
  42. Width: 240,
  43. NoiseCount: 50,
  44. ShowLineOptions: 20,
  45. Length: 4,
  46. Source: "abcdefghijklmnopqrstuvwxyz0123456789",
  47. }
  48. driver = driver.ConvertFonts()
  49. store := base64Captcha.DefaultMemStore
  50. c := base64Captcha.NewCaptcha(driver, store)
  51. idKeyC, base64stringC, err := c.Generate()
  52. if err != nil {
  53. g.Log().Error(err)
  54. }
  55. return
  56. }
  57. //验证输入的验证码是否正确
  58. func VerifyString(id, answer string) bool {
  59. driver := new(base64Captcha.DriverString)
  60. store := base64Captcha.DefaultMemStore
  61. c := base64Captcha.NewCaptcha(driver, store)
  62. return c.Verify(id, answer, true)
  63. }
  64. //AdminLogin 后台用户登陆验证
  65. func AdminLogin(r *ghttp.Request) (string, interface{}) {
  66. data := r.GetFormMapStrStr()
  67. rules := map[string]string{
  68. "idValueC": "required",
  69. "username": "required",
  70. "password": "required",
  71. }
  72. msgs := map[string]interface{}{
  73. "idValueC": "请输入验证码",
  74. "username": "账号不能为空",
  75. "password": "密码不能为空",
  76. }
  77. if e := gvalid.CheckMap(data, rules, msgs); e != nil {
  78. response.JsonExit(r, response.ErrorCode, e.String())
  79. }
  80. //判断验证码是否正确
  81. /*if !VerifyString(data["idKeyC"], data["idValueC"]) {
  82. response.JsonExit(r, response.ErrorCode, "验证码输入错误")
  83. }*/
  84. password := EncryptCBC(data["password"], AdminCbcPublicKey)
  85. var keys string
  86. if AdminMultiLogin {
  87. keys = data["username"] + password + gmd5.MustEncryptString(r.GetClientIp())
  88. } else {
  89. keys = data["username"] + password
  90. }
  91. if err, user := signIn(data["username"], password, r); err != nil {
  92. response.JsonExit(r, response.ErrorCode, err.Error())
  93. } else {
  94. r.SetParam("userInfo", user)
  95. return keys, user
  96. }
  97. return keys, nil
  98. }
  99. // 后台登录返回方法
  100. func AdminLoginAfter(r *ghttp.Request, respData gtoken.Resp) {
  101. if !respData.Success() {
  102. r.Response.WriteJson(respData)
  103. } else {
  104. token := respData.GetString("token")
  105. uuid := respData.GetString("uuid")
  106. var userInfo *user.Entity
  107. r.GetParamVar("userInfo").Struct(&userInfo)
  108. //保存用户在线状态token到数据库
  109. userAgent := r.Header.Get("User-Agent")
  110. ua := user_agent.New(userAgent)
  111. os := ua.OS()
  112. explorer, _ := ua.Browser()
  113. entity := user_online.Entity{
  114. Uuid: uuid,
  115. Token: token,
  116. CreateTime: gconv.Uint64(gtime.Timestamp()),
  117. UserName: userInfo.UserName,
  118. Ip: r.GetClientIp(),
  119. Explorer: explorer,
  120. Os: os,
  121. }
  122. entity.Save()
  123. r.Response.WriteJson(gtoken.Succ(g.Map{
  124. "token": token,
  125. }))
  126. }
  127. }
  128. //gtoken验证后返回
  129. func AuthAfterFunc(r *ghttp.Request, respData gtoken.Resp) {
  130. if r.Method == "OPTIONS" || respData.Success() {
  131. r.Middleware.Next()
  132. } else {
  133. respData.Msg = "用户信息验证失败"
  134. response := r.Response
  135. options := response.DefaultCORSOptions()
  136. response.CORS(options)
  137. response.WriteJson(respData)
  138. r.ExitAll()
  139. }
  140. }
  141. //后台退出登陆
  142. func AdminLoginOut(r *ghttp.Request) bool {
  143. //删除在线用户状态
  144. authHeader := r.Header.Get("Authorization")
  145. if authHeader != "" {
  146. parts := strings.SplitN(authHeader, " ", 2)
  147. if len(parts) == 2 && parts[0] == "Bearer" && parts[1] != "" {
  148. //删除在线用户状态操作
  149. user_online.Model.Delete("token", parts[1])
  150. }
  151. }
  152. authHeader = r.GetString("token")
  153. if authHeader != "" {
  154. //删除在线用户状态操作
  155. user_online.Model.Delete("token", authHeader)
  156. }
  157. return true
  158. }
  159. //字符串加密
  160. func EncryptCBC(plainText, publicKey string) string {
  161. key := []byte(publicKey)
  162. b, e := gaes.EncryptCBC([]byte(plainText), key, key)
  163. if e != nil {
  164. g.Log().Error(e.Error())
  165. return ""
  166. }
  167. return gbase64.EncodeToString(b)
  168. }
  169. //字符串解密
  170. func DecryptCBC(plainText, publicKey string) string {
  171. key := []byte(publicKey)
  172. plainTextByte, e := gbase64.DecodeString(plainText)
  173. if e != nil {
  174. g.Log().Error(e.Error())
  175. return ""
  176. }
  177. b, e := gaes.DecryptCBC(plainTextByte, key, key)
  178. if e != nil {
  179. g.Log().Error(e.Error())
  180. return ""
  181. }
  182. return gbase64.EncodeToString(b)
  183. }
  184. // 用户登录,成功返回用户信息,否则返回nil
  185. func signIn(username, password string, r *ghttp.Request) (error, *user.User) {
  186. user, err := user.Model.Where("user_name=? and user_password=?", username, password).One()
  187. if err != nil && err != sql.ErrNoRows {
  188. return err, nil
  189. }
  190. if user == nil {
  191. return errors.New("账号或密码错误"), nil
  192. }
  193. //判断用户状态
  194. if user.UserStatus == 0 {
  195. return errors.New("用户已被冻结"), nil
  196. }
  197. returnData := *user
  198. //更新登陆时间及ip
  199. user.LastLoginTime = gconv.Int(gtime.Timestamp())
  200. user.LastLoginIp = r.GetClientIp()
  201. user.Update()
  202. return nil, &returnData
  203. }
  204. //日期字符串转时间戳(秒)
  205. func StrToTimestamp(dateStr string) int64 {
  206. tm, err := gtime.StrToTime(dateStr)
  207. if err != nil {
  208. g.Log().Error(err)
  209. return 0
  210. }
  211. return tm.Timestamp()
  212. }