SysAuthServiceImpl.java 17 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396
  1. package com.backendsys.modules.system.service.impl;
  2. import cn.hutool.core.convert.Convert;
  3. import cn.hutool.core.date.DateUnit;
  4. import cn.hutool.core.date.DateUtil;
  5. import cn.hutool.core.util.NumberUtil;
  6. import cn.hutool.json.JSONUtil;
  7. import com.backendsys.exception.CustException;
  8. import com.backendsys.modules.common.config.redis.utils.RedisUtil;
  9. import com.backendsys.modules.common.config.security.entity.SecurityUserInfo;
  10. import com.backendsys.modules.common.config.security.utils.*;
  11. import com.backendsys.modules.system.dao.SysMobileAreaDao;
  12. import com.backendsys.modules.system.dao.SysUserDao;
  13. import com.backendsys.modules.system.dao.SysUserInfoDao;
  14. import com.backendsys.modules.system.entity.*;
  15. import com.backendsys.modules.system.service.SysAuthService;
  16. import com.backendsys.modules.system.service.SysCommonService;
  17. import com.backendsys.modules.system.service.SysUserIntegralService;
  18. import com.backendsys.modules.system.service.SysUserService;
  19. import com.backendsys.utils.response.ResultEnum;
  20. import com.baomidou.mybatisplus.core.conditions.query.LambdaQueryWrapper;
  21. import com.google.code.kaptcha.Producer;
  22. import jakarta.servlet.ServletOutputStream;
  23. import jakarta.servlet.http.HttpServletResponse;
  24. import org.springframework.beans.factory.annotation.Autowired;
  25. import org.springframework.beans.factory.annotation.Value;
  26. import org.springframework.security.crypto.bcrypt.BCryptPasswordEncoder;
  27. import org.springframework.stereotype.Service;
  28. import org.springframework.transaction.annotation.Transactional;
  29. import javax.imageio.ImageIO;
  30. import java.awt.image.BufferedImage;
  31. import java.io.ByteArrayOutputStream;
  32. import java.io.IOException;
  33. import java.util.*;
  34. import java.util.concurrent.TimeUnit;
  35. @Service
  36. public class SysAuthServiceImpl implements SysAuthService {
  37. @Autowired
  38. private JwtUtil jwtUtil;
  39. @Autowired
  40. private RedisUtil redisUtil;
  41. @Autowired
  42. private TokenUtil tokenUtil;
  43. @Autowired
  44. private HttpRequestUtil httpRequestUtil;
  45. @Autowired
  46. private CountUtilV2 countUtilV2;
  47. @Autowired
  48. private CaptchaUtil captchaUtil;
  49. @Autowired
  50. private Producer captchaProducer;
  51. @Autowired
  52. private SysUserDao sysUserDao;
  53. @Autowired
  54. private SysUserInfoDao sysUserInfoDao;
  55. @Autowired
  56. private SysUserService sysUserService;
  57. @Autowired
  58. private SysMobileAreaDao sysMobileAreaDao;
  59. @Autowired
  60. private SysUserIntegralService sysUserIntegralService;
  61. @Autowired
  62. private SysCommonService sysCommonService;
  63. @Value("${tencent.sms.debug}")
  64. private String SMS_DEBUG;
  65. @Value("${CAPTCHA_DURATION}")
  66. private Integer CAPTCHA_DURATION;
  67. @Value("${REDIS_LOGIN_TOKEN_PREFIX}")
  68. private String REDIS_LOGIN_TOKEN_PREFIX;
  69. @Value("${spring.application.name}")
  70. private String APPLICATION_NAME;
  71. private String redisKeyOfLogin = APPLICATION_NAME + "-sms-login";
  72. private String redisKeyOfRegister = APPLICATION_NAME + "-sms-register";
  73. private String redisKeyOfLoginFail = APPLICATION_NAME + "-login-error";
  74. private String redisKeyOfRegisterFail = APPLICATION_NAME + "-register-error";
  75. @Override
  76. public void renderCaptcha(HttpServletResponse response) throws IOException {
  77. byte[] captchaChallengeAsJpeg;
  78. ByteArrayOutputStream jpegOutputStream = new ByteArrayOutputStream();
  79. try {
  80. String createText = captchaProducer.createText();
  81. // 获得当前 (UA + IP) 生成的 Key
  82. String captchaRedisKey = httpRequestUtil.getKaptchaKey();
  83. // 保存 验证码字符串 到 redis 中
  84. redisUtil.setCacheObject(captchaRedisKey, createText, this.CAPTCHA_DURATION, TimeUnit.MILLISECONDS);
  85. // 返回 BufferedImage 对象并转为 byte 写入到 byte 数组中
  86. BufferedImage challenge = captchaProducer.createImage(createText);
  87. ImageIO.write(challenge, "jpg", jpegOutputStream);
  88. } catch (Exception e) {
  89. response.sendError(HttpServletResponse.SC_NOT_FOUND);
  90. }
  91. // 定义response输出类型为image/jpeg类型,使用response输出流输出图片的byte数组
  92. captchaChallengeAsJpeg = jpegOutputStream.toByteArray();
  93. response.setHeader("Cache-Control", "no-store");
  94. response.setHeader("Pragma", "no-cache");
  95. response.setDateHeader("Expires", 0);
  96. response.setContentType("image/jpeg");
  97. ServletOutputStream responseOutputStream = response.getOutputStream();
  98. responseOutputStream.write(captchaChallengeAsJpeg);
  99. responseOutputStream.flush();
  100. responseOutputStream.close();
  101. }
  102. @Override
  103. public List<SysMobileArea> getMobileAreaList(SysMobileArea sysMobileArea) {
  104. return sysMobileAreaDao.selectMobileAreaList(sysMobileArea);
  105. }
  106. // [方法] 登录失败 (errMsg: 错误提示文本, username: 用户名, intercept: 是否拦截)
  107. private void loginFail(String errMsg, String username, Boolean isIntercept) {
  108. // 删除图形验证码
  109. redisUtil.delete(httpRequestUtil.getKaptchaKey());
  110. // 添加登录错误的冻结标记
  111. if (isIntercept) countUtilV2.setErrorCount(redisKeyOfLoginFail, username);
  112. throw new CustException(errMsg, ResultEnum.INVALID_CREDENTIALS.getCode());
  113. }
  114. // [方法] 登录成功
  115. private SysUserInfo loginSuccess(Long user_id, Integer is_remember) {
  116. // [查询] 登录的用户信息
  117. SysUserInfo sysUserInfo = sysUserService.selectUserInfo(user_id);
  118. // 删除图形验证码缓存
  119. redisUtil.delete(httpRequestUtil.getKaptchaKey());
  120. // 删除旧的登录缓存
  121. tokenUtil.deleteRedisLoginToken(sysUserInfo.getLast_login_uuid());
  122. // 判断用户是否审核
  123. Integer audit_status = sysUserInfo.getAudit_status();
  124. if (audit_status != null && audit_status.equals(1)) throw new CustException("用户审核中");
  125. if (audit_status != null && audit_status.equals(-1)) throw new CustException("用户审核未通过,请与客服联系");
  126. // 判断用户是否启用
  127. Integer status = sysUserInfo.getStatus();
  128. if (status != null && status.equals(-1)) throw new CustException("该用户已被禁用,请与客服联系");
  129. // 判断用户是否已删除
  130. Integer del_flag = sysUserInfo.getDel_flag();
  131. if (del_flag != null && del_flag.equals(1)) throw new CustException("用户处于预删除状态,请与客服联系");
  132. // 设置 最后一次的登录信息 (uuid, ip, 登录时间)
  133. String uuid = String.valueOf(UUID.randomUUID());
  134. sysUserInfo.setLast_login_uuid(uuid);
  135. sysUserInfo.setLast_login_ip(httpRequestUtil.getIpAddr());
  136. sysUserInfo.setLast_login_time(DateUtil.format(new Date(), "yyyy-MM-dd HH:mm:ss"));
  137. sysUserInfoDao.updateById(sysUserInfo);
  138. // [系统配置] 系统用户默认登录过期时间(小时)
  139. Integer SYSTEM_USER_LOGIN_DURATION_DEFAULT = Convert.toInt(sysCommonService.getCommonByTag("SYSTEM_USER_LOGIN_DURATION_DEFAULT"));
  140. // 将小时转换为毫秒
  141. Long DEFAULT_MILLISECONDS = SYSTEM_USER_LOGIN_DURATION_DEFAULT * DateUnit.HOUR.getMillis();
  142. // 7天 (转毫秒)
  143. Long SEVEN_DAY_MILLISECONDS = 7L * 24 * 60 * 60 * 1000;
  144. Long token_duration_milliseconds = (is_remember != null && is_remember.equals(1)) ? SEVEN_DAY_MILLISECONDS : DEFAULT_MILLISECONDS;
  145. Integer token_duration_hours = Convert.toInt(token_duration_milliseconds / 3600000L);
  146. Date token_expiration = new Date((new Date()).getTime() + token_duration_milliseconds);
  147. sysUserInfo.setToken_expiration(DateUtil.format(token_expiration, "yyyy-MM-dd HH:mm:ss"));
  148. // 生成 Token
  149. SecurityUserInfo securityUserInfo = JSONUtil.toBean(JSONUtil.parseObj(sysUserInfo), SecurityUserInfo.class);
  150. String token = jwtUtil.createSystemJwtToken(securityUserInfo);
  151. String token_redis_key = REDIS_LOGIN_TOKEN_PREFIX + uuid;
  152. sysUserInfo.setToken(token);
  153. // 生成 PerMissionIds
  154. List<String> permission_ids_list = sysUserInfo.getPermission_ids();
  155. // [Redis] 将 Token 与 Permission 存入缓存
  156. TokenCatch tokenCatch = new TokenCatch(token, permission_ids_list);
  157. redisUtil.setCacheObject(token_redis_key, JSONUtil.toJsonStr(tokenCatch), token_duration_hours, TimeUnit.HOURS);
  158. return sysUserInfo;
  159. }
  160. /**
  161. * 登录 (用户名)
  162. */
  163. @Override
  164. @Transactional
  165. public SysUserInfo login(SysAuth sysAuth) {
  166. String username = sysAuth.getUsername();
  167. String password = sysAuth.getPassword();
  168. String captcha = sysAuth.getCaptcha();
  169. // 判断是否处于登录错误的冻结状态 (2分钟内错误5次,则出现冻结提示)
  170. countUtilV2.checkErrorStatus(redisKeyOfLoginFail, username);
  171. // 判断图形验证码是否正确
  172. if (!captchaUtil.isCaptchaValid(captcha, httpRequestUtil.getKaptchaKey())) {
  173. loginFail("验证码错误", username, false);
  174. return null;
  175. }
  176. // [Method] 判断 用户 是否存在 && 密码是否正确
  177. SysUser sysUser = sysUserDao.selectOne(new LambdaQueryWrapper<SysUser>().eq(SysUser::getUsername, username));
  178. if (sysUser == null) {
  179. // [登录失败] 用户不存在
  180. loginFail("用户名或密码错误", username, true);
  181. return null;
  182. } else {
  183. // [登录失败] 密码不正确
  184. BCryptPasswordEncoder encoder = new BCryptPasswordEncoder();
  185. if (!encoder.matches(password, sysUser.getPassword())) {
  186. loginFail("用户名或密码错误", username, true);
  187. }
  188. // [登录成功]
  189. return loginSuccess(sysUser.getId(), sysAuth.getIs_remember());
  190. }
  191. }
  192. /**
  193. * 登录 (手机号码)
  194. */
  195. @Override
  196. @Transactional
  197. public SysUserInfo loginWithPhone(SysAuthPhone sysAuthPhone) {
  198. String phone = sysAuthPhone.getPhone();
  199. Integer phoneAreaCode = sysAuthPhone.getPhone_area_code();
  200. Integer phoneValidCode = sysAuthPhone.getPhone_valid_code();
  201. // 判断是否处于登录错误的冻结状态 (2分钟内错误5次,则出现冻结提示)
  202. countUtilV2.checkErrorStatus(redisKeyOfLoginFail, phone);
  203. // 判断短信验证码是否正确
  204. String redisKey = redisKeyOfLogin + "-" + phone;
  205. Integer smsCode = redisUtil.getCacheObject(redisKey);
  206. // 判断是否发送验证码
  207. if ("false".equals(SMS_DEBUG) && smsCode == null) throw new CustException("请先发送验证码");
  208. // 判断短信验证码是否错误
  209. if ("false".equals(SMS_DEBUG) && !smsCode.equals(phoneValidCode)) loginFail("短信验证码错误", phone, true);
  210. // 判断手机号是否存在
  211. LambdaQueryWrapper<SysUser> queryWrapper = new LambdaQueryWrapper<>();
  212. queryWrapper.eq(SysUser::getPhone, phone).eq(SysUser::getPhone_area_code, phoneAreaCode);
  213. SysUser sysUser = sysUserDao.selectOne(queryWrapper);
  214. if (sysUser == null) {
  215. // [登录失败] 用户不存在 (并不会销毁短信验证码)
  216. loginFail("手机号码不存在", phone, true);
  217. return null;
  218. } else {
  219. // 登录成功,销毁短信验证码
  220. redisUtil.delete(redisKey);
  221. // [登录成功]
  222. return loginSuccess(sysUser.getId(), sysAuthPhone.getIs_remember());
  223. }
  224. }
  225. @Override
  226. @Transactional
  227. public Map<String, Object> register(SysUserDTO sysUserDTO) {
  228. // 判断是否允许注册
  229. // [系统配置] 是否允许系统用户注册
  230. Boolean SYSTEM_USER_ALLOW_REGISTER = Convert.toBool(sysCommonService.getCommonByTag("SYSTEM_USER_ALLOW_REGISTER"));
  231. if (!SYSTEM_USER_ALLOW_REGISTER) throw new CustException("系统已禁止注册");
  232. // -- 参数校验 --------------------------------------------------------------
  233. String username = sysUserDTO.getUsername();
  234. String password = sysUserDTO.getPassword();
  235. String captcha = sysUserDTO.getCaptcha();
  236. String phone = sysUserDTO.getPhone();
  237. Integer phoneAreaCode = sysUserDTO.getPhone_area_code();
  238. Integer phoneValidCode = sysUserDTO.getPhone_valid_code();
  239. // 判断是否处于登录错误的冻结状态 (2分钟内错误5次,则出现冻结提示)
  240. countUtilV2.checkErrorStatus(redisKeyOfRegisterFail, username);
  241. countUtilV2.checkErrorStatus(redisKeyOfRegisterFail, phone);
  242. // 判断图形验证码是否正确
  243. if (!captchaUtil.isCaptchaValid(captcha, httpRequestUtil.getKaptchaKey())) {
  244. loginFail("验证码错误", username, false);
  245. return null;
  246. }
  247. // [查询] 判断用户名是否存在
  248. SysUser sysUser1 = sysUserDao.selectOne(new LambdaQueryWrapper<SysUser>().eq(SysUser::getUsername, username));
  249. if (sysUser1 != null) throw new CustException("用户名 (" + username + ") 已被注册");
  250. // 判断短信验证码是否正确
  251. String redisKey = redisKeyOfLogin + "-" + phone;
  252. Integer smsCode = redisUtil.getCacheObject(redisKey);
  253. // 判断是否发送验证码
  254. if ("false".equals(SMS_DEBUG) && smsCode == null) throw new CustException("请先发送验证码");
  255. // 判断短信验证码是否错误
  256. if ("false".equals(SMS_DEBUG) && !smsCode.equals(phoneValidCode)) loginFail("短信验证码错误", phone, true);
  257. // [查询] 判断手机号是否存在
  258. LambdaQueryWrapper<SysUser> queryWrapper = new LambdaQueryWrapper<>();
  259. queryWrapper.eq(SysUser::getPhone, phone).eq(SysUser::getPhone_area_code, phoneAreaCode);
  260. SysUser sysUser2 = sysUserDao.selectOne(queryWrapper);
  261. if (sysUser2 != null) throw new CustException("手机号码 (+" + phoneAreaCode + " " + phone + ") 已被注册");
  262. // -- 通过校验 --------------------------------------------------------------
  263. // 密码二次加密
  264. BCryptPasswordEncoder encoder = new BCryptPasswordEncoder();
  265. String encodedPassword = encoder.encode(password);
  266. sysUserDTO.setPassword(encodedPassword);
  267. // 注册
  268. SysUserDTO registerEntity = new SysUserDTO();
  269. registerEntity.setUsername(sysUserDTO.getUsername());
  270. registerEntity.setPhone(sysUserDTO.getPhone());
  271. registerEntity.setPhone_area_code(sysUserDTO.getPhone_area_code());
  272. registerEntity.setPassword(sysUserDTO.getPassword());
  273. // 注册时,默认使用 游客 2L 权限
  274. registerEntity.setRole_id(Arrays.asList(2L));
  275. registerEntity.setInvite_code(sysUserDTO.getInvite_code());
  276. // 注册时,状态为禁用
  277. registerEntity.setStatus(-1);
  278. // 创建用户
  279. sysUserDao.insertUser(registerEntity);
  280. // 初始化用户积分
  281. sysUserIntegralService.init(registerEntity.getId());
  282. return Map.of("user_id", registerEntity.getId());
  283. }
  284. /**
  285. * 忘记密码/重置密码
  286. */
  287. @Override
  288. public Map<String, Object> forgotPassword(SysUserDTO sysUserDTO) {
  289. String phone = sysUserDTO.getPhone();
  290. Integer phoneAreaCode = sysUserDTO.getPhone_area_code();
  291. Integer phoneValidCode = sysUserDTO.getPhone_valid_code();
  292. // 判断短信验证码是否正确
  293. String redisKey = "sms-forgotPassword-" + sysUserDTO.getPhone();
  294. Integer smsCode = redisUtil.getCacheObject(redisKey);
  295. if ("false".equals(SMS_DEBUG) && (smsCode == null || !smsCode.equals(phoneValidCode))) {
  296. throw new CustException("短信验证码错误");
  297. }
  298. // [查询] 判断手机号是否存在
  299. LambdaQueryWrapper<SysUser> queryWrapper = new LambdaQueryWrapper<>();
  300. queryWrapper.eq(SysUser::getPhone, phone).eq(SysUser::getPhone_area_code, phoneAreaCode);
  301. SysUser sysUser = sysUserDao.selectOne(queryWrapper);
  302. if (sysUser == null) throw new CustException("手机号码不存在");
  303. // 密码二次加密
  304. String password = sysUserDTO.getPassword();
  305. BCryptPasswordEncoder encoder = new BCryptPasswordEncoder();
  306. String encodedPassword = encoder.encode(password);
  307. sysUser.setPassword(encodedPassword);
  308. // 编辑密码
  309. sysUserDao.updateById(sysUser);
  310. // 更改成功,销毁短信验证码
  311. redisUtil.delete(redisKey);
  312. return Map.of("user_id", sysUser.getId());
  313. }
  314. /**
  315. * 退出登录
  316. */
  317. public Map<String, Object> logout() {
  318. Long user_id = httpRequestUtil.getUserId();
  319. if (user_id != null) {
  320. tokenUtil.deleteRedisLoginToken(null);
  321. }
  322. return Map.of("user_id", user_id);
  323. }
  324. }