SysAuthServiceImpl.java 20 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465
  1. package com.backendsys.modules.system.service.impl;
  2. import cn.hutool.core.convert.Convert;
  3. import cn.hutool.core.date.DateUnit;
  4. import cn.hutool.core.date.DateUtil;
  5. import cn.hutool.core.util.RandomUtil;
  6. import cn.hutool.core.util.StrUtil;
  7. import cn.hutool.json.JSONUtil;
  8. import com.backendsys.exception.CustException;
  9. import com.backendsys.modules.common.config.redis.utils.RedisUtil;
  10. import com.backendsys.modules.common.config.security.entity.SecurityUserInfo;
  11. import com.backendsys.modules.common.config.security.utils.*;
  12. import com.backendsys.modules.system.dao.SysMobileAreaDao;
  13. import com.backendsys.modules.system.dao.SysUserDao;
  14. import com.backendsys.modules.system.dao.SysUserInfoDao;
  15. import com.backendsys.modules.system.dao.SysUserRoleDao;
  16. import com.backendsys.modules.system.entity.*;
  17. import com.backendsys.modules.system.service.SysAuthService;
  18. import com.backendsys.modules.system.service.SysCommonService;
  19. import com.backendsys.modules.system.service.SysUserIntegralService;
  20. import com.backendsys.modules.system.service.SysUserService;
  21. import com.backendsys.utils.response.ResultEnum;
  22. import com.baomidou.mybatisplus.core.conditions.query.LambdaQueryWrapper;
  23. import com.google.code.kaptcha.Producer;
  24. import jakarta.servlet.ServletOutputStream;
  25. import jakarta.servlet.http.HttpServletResponse;
  26. import org.springframework.beans.factory.annotation.Autowired;
  27. import org.springframework.beans.factory.annotation.Value;
  28. import org.springframework.cache.annotation.Cacheable;
  29. import org.springframework.core.env.Environment;
  30. import org.springframework.security.crypto.bcrypt.BCryptPasswordEncoder;
  31. import org.springframework.stereotype.Service;
  32. import org.springframework.transaction.annotation.Transactional;
  33. import javax.imageio.ImageIO;
  34. import java.awt.image.BufferedImage;
  35. import java.io.ByteArrayOutputStream;
  36. import java.io.IOException;
  37. import java.time.LocalDateTime;
  38. import java.time.ZoneOffset;
  39. import java.util.*;
  40. import java.util.concurrent.TimeUnit;
  41. @Service
  42. public class SysAuthServiceImpl implements SysAuthService {
  43. @Autowired
  44. private Environment env;
  45. @Autowired
  46. private JwtUtil jwtUtil;
  47. @Autowired
  48. private RedisUtil redisUtil;
  49. @Autowired
  50. private TokenUtil tokenUtil;
  51. @Autowired
  52. private HttpRequestUtil httpRequestUtil;
  53. @Autowired
  54. private LockStatusUtil lockStatusUtil;
  55. @Autowired
  56. private CaptchaUtil captchaUtil;
  57. @Autowired
  58. private Producer captchaProducer;
  59. @Autowired
  60. private SysUserDao sysUserDao;
  61. @Autowired
  62. private SysUserRoleDao sysUserRoleDao;
  63. @Autowired
  64. private SysUserInfoDao sysUserInfoDao;
  65. @Autowired
  66. private SysUserService sysUserService;
  67. @Autowired
  68. private SysMobileAreaDao sysMobileAreaDao;
  69. @Autowired
  70. private SysUserIntegralService sysUserIntegralService;
  71. @Autowired
  72. private SysCommonService sysCommonService;
  73. @Value("${tencent.sms.debug}")
  74. private String SMS_DEBUG;
  75. @Value("${CAPTCHA_DURATION}")
  76. private Integer CAPTCHA_DURATION;
  77. @Value("${REDIS_LOGIN_TOKEN_PREFIX}")
  78. private String REDIS_LOGIN_TOKEN_PREFIX;
  79. @Value("${spring.application.name}")
  80. private String APPLICATION_NAME;
  81. @Override
  82. public void renderCaptcha(HttpServletResponse response) throws IOException {
  83. byte[] captchaChallengeAsJpeg;
  84. ByteArrayOutputStream jpegOutputStream = new ByteArrayOutputStream();
  85. try {
  86. String createText = captchaProducer.createText();
  87. // 获得当前 (UA + IP) 生成的 Key
  88. String captchaRedisKey = httpRequestUtil.getKaptchaKey();
  89. // 保存 验证码字符串 到 redis 中
  90. redisUtil.setCacheObject(captchaRedisKey, createText, this.CAPTCHA_DURATION, TimeUnit.MILLISECONDS);
  91. // 返回 BufferedImage 对象并转为 byte 写入到 byte 数组中
  92. BufferedImage challenge = captchaProducer.createImage(createText);
  93. ImageIO.write(challenge, "jpg", jpegOutputStream);
  94. } catch (Exception e) {
  95. response.sendError(HttpServletResponse.SC_NOT_FOUND);
  96. }
  97. // 定义response输出类型为image/jpeg类型,使用response输出流输出图片的byte数组
  98. captchaChallengeAsJpeg = jpegOutputStream.toByteArray();
  99. response.setHeader("Cache-Control", "no-store");
  100. response.setHeader("Pragma", "no-cache");
  101. response.setDateHeader("Expires", 0);
  102. response.setContentType("image/jpeg");
  103. ServletOutputStream responseOutputStream = response.getOutputStream();
  104. responseOutputStream.write(captchaChallengeAsJpeg);
  105. responseOutputStream.flush();
  106. responseOutputStream.close();
  107. }
  108. // 判断是否需验证码登录状态
  109. @Override
  110. public Map<String, Object> checkCaptchaRequired(String username) {
  111. if (StrUtil.isEmpty(username)) throw new CustException("username 不能为空");
  112. Boolean currentCaptchaRequired = captchaUtil.isCaptchaRequired(APPLICATION_NAME + "-login-required-captcha-" + username, 3);
  113. return Map.of("is_captcha_required", currentCaptchaRequired);
  114. }
  115. @Override
  116. @Cacheable(value = "catch::mobile-area", key = "'list'", unless = "#result == null")
  117. public List<SysMobileArea> getMobileAreaList(SysMobileArea sysMobileArea) {
  118. return sysMobileAreaDao.selectMobileAreaList(sysMobileArea);
  119. }
  120. // [方法] 登录失败 (通用) (errMsg: 错误提示文本, username: 用户名, intercept: 是否拦截)
  121. public void loginFail(String errMsg, String username, Boolean isIntercept) {
  122. // 验证码是否必填
  123. Boolean currentCaptchaRequired = captchaUtil.isCaptchaRequired(APPLICATION_NAME + "-login-required-captcha-" + username, 3);
  124. System.out.println("(loginFailByUsername) currentCaptchaRequired = " + currentCaptchaRequired);
  125. // 删除图形验证码
  126. redisUtil.delete(httpRequestUtil.getKaptchaKey());
  127. // 添加登录错误的冻结标记
  128. if (isIntercept) lockStatusUtil.setLockStatus(APPLICATION_NAME + "-login-error", username);
  129. if (currentCaptchaRequired) {
  130. throw new CustException(errMsg, ResultEnum.INVALID_CREDENTIALS.getCode(), Map.of("is_captcha_required", true));
  131. } else {
  132. throw new CustException(errMsg, ResultEnum.INVALID_CREDENTIALS.getCode());
  133. }
  134. }
  135. // [方法] 登录成功
  136. public SysUserInfo loginSuccess(Long user_id, Integer is_remember) {
  137. // [查询] 登录的用户信息
  138. SysUserInfo sysUserInfo = sysUserService.selectUserInfo(user_id);
  139. // 删除图形验证码缓存
  140. redisUtil.delete(httpRequestUtil.getKaptchaKey());
  141. // 删除旧的登录缓存
  142. tokenUtil.deleteRedisLoginToken(sysUserInfo.getLast_login_uuid());
  143. // 判断用户是否审核
  144. Integer audit_status = sysUserInfo.getAudit_status();
  145. if (audit_status != null && audit_status.equals(1)) throw new CustException("用户正在审核中");
  146. if (audit_status != null && audit_status.equals(-1)) throw new CustException("用户审核未通过,请与客服联系");
  147. // 判断用户是否启用
  148. Integer status = sysUserInfo.getStatus();
  149. if (status != null && status.equals(-1)) throw new CustException("该用户已被禁用,请与客服联系");
  150. // 判断用户是否已删除
  151. Integer del_flag = sysUserInfo.getDel_flag();
  152. if (del_flag != null && del_flag.equals(1)) throw new CustException("当前用户不可用,请与客服联系");
  153. // 设置 最后一次的登录信息 (uuid, ip, 登录时间)
  154. String uuid = Convert.toStr(UUID.randomUUID());
  155. sysUserInfo.setLast_login_uuid(uuid);
  156. sysUserInfo.setLast_login_ip(httpRequestUtil.getIpAddr());
  157. // sysUserInfo.setLast_login_time(DateUtil.format(new Date(), "yyyy-MM-dd HH:mm:ss"));
  158. sysUserInfo.setLast_login_time(LocalDateTime.now(ZoneOffset.UTC));
  159. sysUserInfoDao.updateById(sysUserInfo);
  160. // [系统配置] 系统用户默认登录过期时间(小时)
  161. Integer SYSTEM_USER_LOGIN_DURATION_DEFAULT = Convert.toInt(sysCommonService.getCommonByTag("SYSTEM_USER_LOGIN_DURATION_DEFAULT"));
  162. // 将小时转换为毫秒
  163. Long DEFAULT_MILLISECONDS = SYSTEM_USER_LOGIN_DURATION_DEFAULT * DateUnit.HOUR.getMillis();
  164. // 7天 (转毫秒)
  165. Long SEVEN_DAY_MILLISECONDS = 7L * 24 * 60 * 60 * 1000;
  166. Long token_duration_milliseconds = (is_remember != null && is_remember.equals(1)) ? SEVEN_DAY_MILLISECONDS : DEFAULT_MILLISECONDS;
  167. Integer token_duration_hours = Convert.toInt(token_duration_milliseconds / 3600000L);
  168. Date token_expiration = new Date((new Date()).getTime() + token_duration_milliseconds);
  169. sysUserInfo.setToken_expiration(DateUtil.format(token_expiration, "yyyy-MM-dd HH:mm:ss"));
  170. // 生成 Token
  171. SecurityUserInfo securityUserInfo = JSONUtil.toBean(JSONUtil.parseObj(sysUserInfo), SecurityUserInfo.class);
  172. String token = jwtUtil.createSystemJwtToken(securityUserInfo);
  173. String token_redis_key = REDIS_LOGIN_TOKEN_PREFIX + uuid;
  174. sysUserInfo.setToken(token);
  175. // 生成 PerMissionIds
  176. List<String> permission_ids_list = sysUserInfo.getPermission_ids();
  177. // [Redis] 将 Token 与 Permission 存入缓存
  178. TokenCatch tokenCatch = new TokenCatch(token, permission_ids_list);
  179. redisUtil.setCacheObject(token_redis_key, JSONUtil.toJsonStr(tokenCatch), token_duration_hours, TimeUnit.HOURS);
  180. return sysUserInfo;
  181. }
  182. private void setLoginRequired(String key) {
  183. Object captchaValue = redisUtil.getCacheObject(APPLICATION_NAME + "-login-required-captcha-" + key);
  184. Integer currentErrCount = (captchaValue == null) ? 1 : (Convert.toInt(captchaValue) + 1);
  185. redisUtil.setCacheObject(APPLICATION_NAME + "-login-required-captcha-" + key, currentErrCount, 1, TimeUnit.MINUTES);
  186. System.out.println("currentErrCount: " + currentErrCount);
  187. }
  188. public void cleanLoginRequired(String key) {
  189. redisUtil.delete(APPLICATION_NAME + "-login-required-captcha-" + key);
  190. }
  191. /**
  192. * 登录 (用户名)
  193. */
  194. @Override
  195. @Transactional(rollbackFor = Exception.class)
  196. public SysUserInfo login(SysAuth sysAuth) {
  197. String username = sysAuth.getUsername();
  198. String password = sysAuth.getPassword();
  199. String captcha = sysAuth.getCaptcha();
  200. // 判断是否处于登录错误的冻结状态 (2分钟内错误5次,则出现冻结提示)
  201. lockStatusUtil.checkLockStatus(APPLICATION_NAME + "-login-error", username);
  202. // -- 判断是否需要输入验证码 ----------------------------------------------------
  203. // - 当输错 3 次密码时,需要输入验证码
  204. // - 当输错后 1 分钟后重置
  205. Boolean isCaptchaRequired = captchaUtil.isCaptchaRequired(APPLICATION_NAME + "-login-required-captcha-" + username, 3);
  206. if (isCaptchaRequired) {
  207. Boolean isCaptchaEmpty = StrUtil.isEmpty(captcha);
  208. Boolean isCpatchaValid = (captchaUtil.isCaptchaValid(captcha, httpRequestUtil.getKaptchaKey()));
  209. if (isCaptchaEmpty) { loginFail("验证码不能为空", username, false); return null; }
  210. if (!isCpatchaValid) { loginFail("验证码错误", username, false); return null; }
  211. }
  212. // --------------------------------------------------------------------------
  213. // [Method] 判断 用户 是否存在 && 密码是否正确
  214. SysUser sysUser = sysUserDao.selectOne(new LambdaQueryWrapper<SysUser>().eq(SysUser::getUsername, username));
  215. if (sysUser == null) {
  216. // 输入错误时,计数器叠加,并且设置重置时间 (会一直叠加,直到重置 或 登录成功)
  217. setLoginRequired(username);
  218. // [登录失败] 用户不存在
  219. loginFail("用户名或密码错误", username, true);
  220. return null;
  221. } else {
  222. BCryptPasswordEncoder encoder = new BCryptPasswordEncoder();
  223. if (!encoder.matches(password, sysUser.getPassword())) {
  224. // 输入错误时,计数器叠加,并且设置重置时间 (会一直叠加,直到重置 或 登录成功)
  225. setLoginRequired(username);
  226. // [登录失败] 密码不正确
  227. loginFail("用户名或密码错误", username, true);
  228. }
  229. // [登录成功]
  230. cleanLoginRequired(username);
  231. return loginSuccess(sysUser.getId(), sysAuth.getIs_remember());
  232. }
  233. }
  234. /**
  235. * 登录 (手机号码)
  236. */
  237. @Override
  238. @Transactional(rollbackFor = Exception.class)
  239. public SysUserInfo loginWithPhone(SysAuthPhone sysAuthPhone) {
  240. String phone = sysAuthPhone.getPhone();
  241. Integer phoneAreaCode = sysAuthPhone.getPhone_area_code();
  242. Integer phoneValidCode = sysAuthPhone.getPhone_valid_code();
  243. // 判断是否处于登录错误的冻结状态 (2分钟内错误5次,则出现冻结提示)
  244. lockStatusUtil.checkLockStatus(APPLICATION_NAME + "-login-error", phone);
  245. // 判断短信验证码是否正确
  246. String redisKey = APPLICATION_NAME + "-sms-login" + "-" + phone;
  247. Integer smsCode = redisUtil.getCacheObject(redisKey);
  248. // 判断是否发送验证码
  249. if ("false".equals(SMS_DEBUG) && smsCode == null) throw new CustException("请先发送短信验证码");
  250. // 判断短信验证码是否错误
  251. if ("false".equals(SMS_DEBUG) && !smsCode.equals(phoneValidCode)) loginFail("短信验证码错误", phone, true);
  252. // 判断手机号是否存在
  253. LambdaQueryWrapper<SysUser> queryWrapper = new LambdaQueryWrapper<>();
  254. queryWrapper.eq(SysUser::getPhone, phone).eq(SysUser::getPhone_area_code, phoneAreaCode);
  255. SysUser sysUser = sysUserDao.selectOne(queryWrapper);
  256. if (sysUser == null) {
  257. // [登录失败] 用户不存在 (并不会销毁短信验证码)
  258. loginFail("手机号码未注册,请先注册", phone, true);
  259. return null;
  260. } else {
  261. // 登录成功,销毁短信验证码
  262. redisUtil.delete(redisKey);
  263. // [登录成功]
  264. return loginSuccess(sysUser.getId(), sysAuthPhone.getIs_remember());
  265. }
  266. }
  267. @Override
  268. @Transactional(rollbackFor = Exception.class)
  269. public Map<String, Object> register(SysUserDTO sysUserDTO) {
  270. // 判断是否允许注册
  271. // [系统配置] 是否允许系统用户注册
  272. Boolean SYSTEM_USER_ALLOW_REGISTER = Convert.toBool(sysCommonService.getCommonByTag("SYSTEM_USER_ALLOW_REGISTER"));
  273. if (!SYSTEM_USER_ALLOW_REGISTER) throw new CustException("系统已禁止注册");
  274. // -- 参数校验 --------------------------------------------------------------
  275. String username = sysUserDTO.getUsername();
  276. String password = sysUserDTO.getPassword();
  277. String captcha = sysUserDTO.getCaptcha();
  278. String phone = sysUserDTO.getPhone();
  279. Integer phoneAreaCode = sysUserDTO.getPhone_area_code();
  280. Integer phoneValidCode = sysUserDTO.getPhone_valid_code();
  281. String activeProfile = env.getActiveProfiles()[0];
  282. if (!"local".equals(activeProfile)) {
  283. // 判断是否处于登录错误的冻结状态 (2分钟内错误5次,则出现冻结提示)
  284. lockStatusUtil.checkLockStatus(APPLICATION_NAME + "-register-error", username);
  285. lockStatusUtil.checkLockStatus(APPLICATION_NAME + "-register-error", phone);
  286. // 判断图形验证码是否正确
  287. if (!captchaUtil.isCaptchaValid(captcha, httpRequestUtil.getKaptchaKey())) {
  288. loginFail("验证码错误", username, false);
  289. return null;
  290. }
  291. }
  292. // [查询] 判断用户名是否存在
  293. SysUser sysUser1 = sysUserDao.selectOne(new LambdaQueryWrapper<SysUser>().eq(SysUser::getUsername, username));
  294. if (sysUser1 != null) throw new CustException("用户名 (" + username + ") 已被注册");
  295. // 判断短信验证码是否正确
  296. if (!"local".equals(activeProfile)) {
  297. String redisKey = APPLICATION_NAME + "-sms-register" + "-" + phone;
  298. Integer smsCode = redisUtil.getCacheObject(redisKey);
  299. // 判断是否发送验证码
  300. if ("false".equals(SMS_DEBUG) && smsCode == null) throw new CustException("请先发送短信验证码");
  301. // 判断短信验证码是否错误
  302. if ("false".equals(SMS_DEBUG) && !smsCode.equals(phoneValidCode)) loginFail("短信验证码错误", phone, true);
  303. }
  304. // [查询] 判断手机号是否存在
  305. LambdaQueryWrapper<SysUser> queryWrapper = new LambdaQueryWrapper<>();
  306. queryWrapper.eq(SysUser::getPhone, phone).eq(SysUser::getPhone_area_code, phoneAreaCode);
  307. SysUser sysUser2 = sysUserDao.selectOne(queryWrapper);
  308. if (sysUser2 != null) throw new CustException("手机号码 (+" + phoneAreaCode + " " + phone + ") 已被注册");
  309. // -- 通过校验 --------------------------------------------------------------
  310. // 密码二次加密
  311. BCryptPasswordEncoder encoder = new BCryptPasswordEncoder();
  312. String encodedPassword = encoder.encode(password);
  313. sysUserDTO.setPassword(encodedPassword);
  314. // 注册
  315. SysUserDTO registerEntity = new SysUserDTO();
  316. registerEntity.setUsername(sysUserDTO.getUsername());
  317. registerEntity.setPhone(sysUserDTO.getPhone());
  318. registerEntity.setPhone_area_code(sysUserDTO.getPhone_area_code());
  319. registerEntity.setPassword(sysUserDTO.getPassword());
  320. // 做成后台可控制?
  321. // 邀请码
  322. registerEntity.setInvite_code(sysUserDTO.getInvite_code());
  323. // 注册时,默认使用 权限 (DEFAULT)
  324. String role_sign = "DEFAULT";
  325. // 如果邀请码是 (Material),则注册成为 [素材游客]
  326. if ("Material".equals(sysUserDTO.getInvite_code())) role_sign = "MATERIAL_GUEST";
  327. LambdaQueryWrapper<SysUserRole> wrapperRole = new LambdaQueryWrapper<>();
  328. wrapperRole.eq(SysUserRole::getRole_sign, role_sign);
  329. SysUserRole roleDetail = sysUserRoleDao.selectOne(wrapperRole);
  330. registerEntity.setRole_id(Arrays.asList(roleDetail.getRole_id()));
  331. // 注册时,审核状态为 待审核 (-1拒绝, 1待审核, 2审核通过)
  332. registerEntity.setAudit_status(1);
  333. // 注册时,状态为 禁用
  334. // registerEntity.setStatus(-1);
  335. // 随机昵称 (6位)
  336. registerEntity.setNickname("用户" + RandomUtil.randomStringUpper(6));
  337. // 创建用户
  338. sysUserDao.insertUser(registerEntity);
  339. // 初始化用户积分
  340. sysUserIntegralService.init(registerEntity.getId());
  341. return Map.of("user_id", registerEntity.getId());
  342. }
  343. /**
  344. * 忘记密码/重置密码
  345. */
  346. @Override
  347. public Map<String, Object> forgotPassword(SysUserDTO sysUserDTO) {
  348. String phone = sysUserDTO.getPhone();
  349. Integer phoneAreaCode = sysUserDTO.getPhone_area_code();
  350. Integer phoneValidCode = sysUserDTO.getPhone_valid_code();
  351. // 判断短信验证码是否正确
  352. String redisKey = APPLICATION_NAME + "-sms-forgotPassword-" + sysUserDTO.getPhone();
  353. Integer smsCode = redisUtil.getCacheObject(redisKey);
  354. if ("false".equals(SMS_DEBUG) && (smsCode == null || !smsCode.equals(phoneValidCode))) {
  355. throw new CustException("短信验证码错误");
  356. }
  357. // [查询] 判断手机号是否存在
  358. LambdaQueryWrapper<SysUser> queryWrapper = new LambdaQueryWrapper<>();
  359. queryWrapper.eq(SysUser::getPhone, phone).eq(SysUser::getPhone_area_code, phoneAreaCode);
  360. SysUser sysUser = sysUserDao.selectOne(queryWrapper);
  361. if (sysUser == null) throw new CustException("手机号码不存在");
  362. // 密码二次加密
  363. String password = sysUserDTO.getPassword();
  364. BCryptPasswordEncoder encoder = new BCryptPasswordEncoder();
  365. String encodedPassword = encoder.encode(password);
  366. sysUser.setPassword(encodedPassword);
  367. // 编辑密码
  368. sysUserDao.updateById(sysUser);
  369. // 更改成功,销毁短信验证码
  370. redisUtil.delete(redisKey);
  371. return Map.of("user_id", sysUser.getId());
  372. }
  373. /**
  374. * 退出登录
  375. */
  376. public Map<String, Object> logout() {
  377. Long user_id = httpRequestUtil.getUserId();
  378. if (user_id != null) {
  379. tokenUtil.deleteRedisLoginToken(null);
  380. }
  381. return Map.of("user_id", user_id);
  382. }
  383. }