service.go 6.1 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223
  1. package service
  2. import (
  3. "database/sql"
  4. "errors"
  5. "gfast/app/model/admin/sys_login_log"
  6. "gfast/app/model/admin/user"
  7. "gfast/app/model/admin/user_online"
  8. "gfast/library/response"
  9. "gfast/library/utils"
  10. "github.com/goflyfox/gtoken/gtoken"
  11. "github.com/gogf/gf/crypto/gmd5"
  12. "github.com/gogf/gf/frame/g"
  13. "github.com/gogf/gf/net/ghttp"
  14. "github.com/gogf/gf/os/gtime"
  15. "github.com/gogf/gf/text/gstr"
  16. "github.com/gogf/gf/util/gconv"
  17. "github.com/gogf/gf/util/gvalid"
  18. "github.com/mojocn/base64Captcha"
  19. "github.com/mssola/user_agent"
  20. "strings"
  21. )
  22. //版本号
  23. const Version = "1.0.02"
  24. var (
  25. AdminMultiLogin bool //是否允许后台管理员多端登陆
  26. AdminPageNum = 20 //后台分页长度
  27. NotCheckAuthAdminIds []int //无需验证权限的用户id
  28. )
  29. //获取数字验证码
  30. func GetVerifyImgDigit() (idKeyC string, base64stringC string) {
  31. driver := &base64Captcha.DriverDigit{80, 240, 5, 0.7, 5}
  32. store := base64Captcha.DefaultMemStore
  33. c := base64Captcha.NewCaptcha(driver, store)
  34. idKeyC, base64stringC, err := c.Generate()
  35. if err != nil {
  36. g.Log().Error(err)
  37. }
  38. return
  39. }
  40. //获取字母数字混合验证码
  41. func GetVerifyImgString() (idKeyC string, base64stringC string) {
  42. driver := &base64Captcha.DriverString{
  43. Height: 80,
  44. Width: 240,
  45. NoiseCount: 50,
  46. ShowLineOptions: 20,
  47. Length: 4,
  48. Source: "abcdefghijklmnopqrstuvwxyz0123456789",
  49. Fonts: []string{"chromohv.ttf"},
  50. }
  51. driver = driver.ConvertFonts()
  52. store := base64Captcha.DefaultMemStore
  53. c := base64Captcha.NewCaptcha(driver, store)
  54. idKeyC, base64stringC, err := c.Generate()
  55. if err != nil {
  56. g.Log().Error(err)
  57. }
  58. return
  59. }
  60. //验证输入的验证码是否正确
  61. func VerifyString(id, answer string) bool {
  62. driver := new(base64Captcha.DriverString)
  63. store := base64Captcha.DefaultMemStore
  64. c := base64Captcha.NewCaptcha(driver, store)
  65. answer = gstr.ToLower(answer)
  66. return c.Verify(id, answer, true)
  67. }
  68. func FrontLogin(r *ghttp.Request) (string, interface{}) {
  69. g.Log().Println("front login test...")
  70. return "test", nil
  71. }
  72. //AdminLogin 后台用户登陆验证
  73. func AdminLogin(r *ghttp.Request) (string, interface{}) {
  74. data := r.GetFormMapStrStr()
  75. rules := map[string]string{
  76. "idValueC": "required",
  77. "username": "required",
  78. "password": "required",
  79. }
  80. msgs := map[string]interface{}{
  81. "idValueC": "请输入验证码",
  82. "username": "账号不能为空",
  83. "password": "密码不能为空",
  84. }
  85. if e := gvalid.CheckMap(data, rules, msgs); e != nil {
  86. response.JsonExit(r, response.ErrorCode, e.String())
  87. }
  88. //判断验证码是否正确
  89. if !VerifyString(data["idKeyC"], data["idValueC"]) {
  90. response.JsonExit(r, response.ErrorCode, "验证码输入错误")
  91. }
  92. password := utils.EncryptCBC(data["password"], utils.AdminCbcPublicKey)
  93. var keys string
  94. if AdminMultiLogin {
  95. keys = data["username"] + password + gmd5.MustEncryptString(utils.GetClientIp(r))
  96. } else {
  97. keys = data["username"] + password
  98. }
  99. ip := utils.GetClientIp(r)
  100. userAgent := r.Header.Get("User-Agent")
  101. if err, user := signIn(data["username"], password, r); err != nil {
  102. go loginLog(0, data["username"], ip, userAgent, err.Error())
  103. response.JsonExit(r, response.ErrorCode, err.Error())
  104. } else {
  105. //判断是否后台用户
  106. if user.IsAdmin != 1 {
  107. response.JsonExit(r, response.ErrorCode, "抱歉!此用户不属于后台管理员!")
  108. }
  109. r.SetParam("userInfo", user)
  110. go loginLog(1, data["username"], ip, userAgent, "登录成功")
  111. return keys, user
  112. }
  113. return keys, nil
  114. }
  115. // 后台登录返回方法
  116. func AdminLoginAfter(r *ghttp.Request, respData gtoken.Resp) {
  117. if !respData.Success() {
  118. r.Response.WriteJson(respData)
  119. } else {
  120. token := respData.GetString("token")
  121. uuid := respData.GetString("uuid")
  122. var userInfo *user.Entity
  123. r.GetParamVar("userInfo").Struct(&userInfo)
  124. //保存用户在线状态token到数据库
  125. userAgent := r.Header.Get("User-Agent")
  126. ua := user_agent.New(userAgent)
  127. os := ua.OS()
  128. explorer, _ := ua.Browser()
  129. entity := user_online.Entity{
  130. Uuid: uuid,
  131. Token: token,
  132. CreateTime: gconv.Uint64(gtime.Timestamp()),
  133. UserName: userInfo.UserName,
  134. Ip: utils.GetClientIp(r),
  135. Explorer: explorer,
  136. Os: os,
  137. }
  138. entity.Save()
  139. r.Response.WriteJson(gtoken.Succ(g.Map{
  140. "token": token,
  141. }))
  142. }
  143. }
  144. //gtoken验证后返回
  145. func AuthAfterFunc(r *ghttp.Request, respData gtoken.Resp) {
  146. if r.Method == "OPTIONS" || respData.Success() {
  147. r.Middleware.Next()
  148. } else {
  149. respData.Msg = "用户信息验证失败"
  150. response := r.Response
  151. options := response.DefaultCORSOptions()
  152. response.CORS(options)
  153. response.WriteJson(respData)
  154. r.ExitAll()
  155. }
  156. }
  157. //后台退出登陆
  158. func AdminLoginOut(r *ghttp.Request) bool {
  159. //删除在线用户状态
  160. authHeader := r.Header.Get("Authorization")
  161. if authHeader != "" {
  162. parts := strings.SplitN(authHeader, " ", 2)
  163. if len(parts) == 2 && parts[0] == "Bearer" && parts[1] != "" {
  164. //删除在线用户状态操作
  165. user_online.Model.Delete("token", parts[1])
  166. }
  167. }
  168. authHeader = r.GetString("token")
  169. if authHeader != "" {
  170. //删除在线用户状态操作
  171. user_online.Model.Delete("token", authHeader)
  172. }
  173. return true
  174. }
  175. // 用户登录,成功返回用户信息,否则返回nil
  176. func signIn(username, password string, r *ghttp.Request) (error, *user.User) {
  177. user, err := user.Model.Where("user_name=? and user_password=?", username, password).One()
  178. if err != nil && err != sql.ErrNoRows {
  179. return err, nil
  180. }
  181. if user == nil {
  182. return errors.New("账号或密码错误"), nil
  183. }
  184. //判断用户状态
  185. if user.UserStatus == 0 {
  186. return errors.New("用户已被冻结"), nil
  187. }
  188. returnData := *user
  189. //更新登陆时间及ip
  190. user.LastLoginTime = gconv.Int(gtime.Timestamp())
  191. user.LastLoginIp = utils.GetClientIp(r)
  192. user.Update()
  193. return nil, &returnData
  194. }
  195. //登录日志记录
  196. func loginLog(status int, username, ip, userAgent, msg string) {
  197. var log sys_login_log.Entity
  198. log.LoginName = username
  199. log.Ipaddr = ip
  200. log.LoginLocation = utils.GetCityByIp(log.Ipaddr)
  201. ua := user_agent.New(userAgent)
  202. log.Browser, _ = ua.Browser()
  203. log.Os = ua.OS()
  204. log.Status = status
  205. log.Msg = msg
  206. log.LoginTime = gtime.Timestamp()
  207. log.Save()
  208. }