SysAuthServiceImpl.java 19 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433
  1. package com.backendsys.modules.system.service.impl;
  2. import cn.hutool.core.convert.Convert;
  3. import cn.hutool.core.date.DateUnit;
  4. import cn.hutool.core.date.DateUtil;
  5. import cn.hutool.core.util.StrUtil;
  6. import cn.hutool.json.JSONUtil;
  7. import com.backendsys.exception.CustException;
  8. import com.backendsys.modules.common.config.redis.utils.RedisUtil;
  9. import com.backendsys.modules.common.config.security.entity.SecurityUserInfo;
  10. import com.backendsys.modules.common.config.security.utils.*;
  11. import com.backendsys.modules.system.dao.SysMobileAreaDao;
  12. import com.backendsys.modules.system.dao.SysUserDao;
  13. import com.backendsys.modules.system.dao.SysUserInfoDao;
  14. import com.backendsys.modules.system.entity.*;
  15. import com.backendsys.modules.system.service.SysAuthService;
  16. import com.backendsys.modules.system.service.SysCommonService;
  17. import com.backendsys.modules.system.service.SysUserIntegralService;
  18. import com.backendsys.modules.system.service.SysUserService;
  19. import com.backendsys.utils.response.ResultEnum;
  20. import com.baomidou.mybatisplus.core.conditions.query.LambdaQueryWrapper;
  21. import com.google.code.kaptcha.Producer;
  22. import jakarta.servlet.ServletOutputStream;
  23. import jakarta.servlet.http.HttpServletResponse;
  24. import org.springframework.beans.factory.annotation.Autowired;
  25. import org.springframework.beans.factory.annotation.Value;
  26. import org.springframework.security.crypto.bcrypt.BCryptPasswordEncoder;
  27. import org.springframework.stereotype.Service;
  28. import org.springframework.transaction.annotation.Transactional;
  29. import javax.imageio.ImageIO;
  30. import java.awt.image.BufferedImage;
  31. import java.io.ByteArrayOutputStream;
  32. import java.io.IOException;
  33. import java.util.*;
  34. import java.util.concurrent.TimeUnit;
  35. @Service
  36. public class SysAuthServiceImpl implements SysAuthService {
  37. @Autowired
  38. private JwtUtil jwtUtil;
  39. @Autowired
  40. private RedisUtil redisUtil;
  41. @Autowired
  42. private TokenUtil tokenUtil;
  43. @Autowired
  44. private HttpRequestUtil httpRequestUtil;
  45. @Autowired
  46. private LockStatusUtil lockStatusUtil;
  47. @Autowired
  48. private CaptchaUtil captchaUtil;
  49. @Autowired
  50. private Producer captchaProducer;
  51. @Autowired
  52. private SysUserDao sysUserDao;
  53. @Autowired
  54. private SysUserInfoDao sysUserInfoDao;
  55. @Autowired
  56. private SysUserService sysUserService;
  57. @Autowired
  58. private SysMobileAreaDao sysMobileAreaDao;
  59. @Autowired
  60. private SysUserIntegralService sysUserIntegralService;
  61. @Autowired
  62. private SysCommonService sysCommonService;
  63. @Value("${tencent.sms.debug}")
  64. private String SMS_DEBUG;
  65. @Value("${CAPTCHA_DURATION}")
  66. private Integer CAPTCHA_DURATION;
  67. @Value("${REDIS_LOGIN_TOKEN_PREFIX}")
  68. private String REDIS_LOGIN_TOKEN_PREFIX;
  69. @Value("${spring.application.name}")
  70. private String APPLICATION_NAME;
  71. @Override
  72. public void renderCaptcha(HttpServletResponse response) throws IOException {
  73. byte[] captchaChallengeAsJpeg;
  74. ByteArrayOutputStream jpegOutputStream = new ByteArrayOutputStream();
  75. try {
  76. String createText = captchaProducer.createText();
  77. // 获得当前 (UA + IP) 生成的 Key
  78. String captchaRedisKey = httpRequestUtil.getKaptchaKey();
  79. // 保存 验证码字符串 到 redis 中
  80. redisUtil.setCacheObject(captchaRedisKey, createText, this.CAPTCHA_DURATION, TimeUnit.MILLISECONDS);
  81. // 返回 BufferedImage 对象并转为 byte 写入到 byte 数组中
  82. BufferedImage challenge = captchaProducer.createImage(createText);
  83. ImageIO.write(challenge, "jpg", jpegOutputStream);
  84. } catch (Exception e) {
  85. response.sendError(HttpServletResponse.SC_NOT_FOUND);
  86. }
  87. // 定义response输出类型为image/jpeg类型,使用response输出流输出图片的byte数组
  88. captchaChallengeAsJpeg = jpegOutputStream.toByteArray();
  89. response.setHeader("Cache-Control", "no-store");
  90. response.setHeader("Pragma", "no-cache");
  91. response.setDateHeader("Expires", 0);
  92. response.setContentType("image/jpeg");
  93. ServletOutputStream responseOutputStream = response.getOutputStream();
  94. responseOutputStream.write(captchaChallengeAsJpeg);
  95. responseOutputStream.flush();
  96. responseOutputStream.close();
  97. }
  98. // 判断是否需验证码登录状态
  99. @Override
  100. public Map<String, Object> checkCaptchaRequired(String username) {
  101. if (StrUtil.isEmpty(username)) throw new CustException("username 不能为空");
  102. Boolean currentCaptchaRequired = captchaUtil.isCaptchaRequired(APPLICATION_NAME + "-login-required-captcha-" + username, 3);
  103. return Map.of("is_captcha_required", currentCaptchaRequired);
  104. }
  105. @Override
  106. public List<SysMobileArea> getMobileAreaList(SysMobileArea sysMobileArea) {
  107. return sysMobileAreaDao.selectMobileAreaList(sysMobileArea);
  108. }
  109. // [方法] 登录失败 (通用) (errMsg: 错误提示文本, username: 用户名, intercept: 是否拦截)
  110. private void loginFail(String errMsg, String username, Boolean isIntercept) {
  111. // 验证码是否必填
  112. Boolean currentCaptchaRequired = captchaUtil.isCaptchaRequired(APPLICATION_NAME + "-login-required-captcha-" + username, 3);
  113. System.out.println("(loginFailByUsername) currentCaptchaRequired = " + currentCaptchaRequired);
  114. // 删除图形验证码
  115. redisUtil.delete(httpRequestUtil.getKaptchaKey());
  116. // 添加登录错误的冻结标记
  117. if (isIntercept) lockStatusUtil.setLockStatus(APPLICATION_NAME + "-login-error", username);
  118. if (currentCaptchaRequired) {
  119. throw new CustException(errMsg, ResultEnum.INVALID_CREDENTIALS.getCode(), Map.of("is_captcha_required", true));
  120. } else {
  121. throw new CustException(errMsg, ResultEnum.INVALID_CREDENTIALS.getCode());
  122. }
  123. }
  124. // [方法] 登录成功
  125. private SysUserInfo loginSuccess(Long user_id, Integer is_remember) {
  126. // [查询] 登录的用户信息
  127. SysUserInfo sysUserInfo = sysUserService.selectUserInfo(user_id);
  128. // 删除图形验证码缓存
  129. redisUtil.delete(httpRequestUtil.getKaptchaKey());
  130. // 删除旧的登录缓存
  131. tokenUtil.deleteRedisLoginToken(sysUserInfo.getLast_login_uuid());
  132. // 判断用户是否审核
  133. Integer audit_status = sysUserInfo.getAudit_status();
  134. if (audit_status != null && audit_status.equals(1)) throw new CustException("用户审核中");
  135. if (audit_status != null && audit_status.equals(-1)) throw new CustException("用户审核未通过,请与客服联系");
  136. // 判断用户是否启用
  137. Integer status = sysUserInfo.getStatus();
  138. if (status != null && status.equals(-1)) throw new CustException("该用户已被禁用,请与客服联系");
  139. // 判断用户是否已删除
  140. Integer del_flag = sysUserInfo.getDel_flag();
  141. if (del_flag != null && del_flag.equals(1)) throw new CustException("当前用户不可用,请与客服联系");
  142. // 设置 最后一次的登录信息 (uuid, ip, 登录时间)
  143. String uuid = Convert.toStr(UUID.randomUUID());
  144. sysUserInfo.setLast_login_uuid(uuid);
  145. sysUserInfo.setLast_login_ip(httpRequestUtil.getIpAddr());
  146. sysUserInfo.setLast_login_time(DateUtil.format(new Date(), "yyyy-MM-dd HH:mm:ss"));
  147. sysUserInfoDao.updateById(sysUserInfo);
  148. // [系统配置] 系统用户默认登录过期时间(小时)
  149. Integer SYSTEM_USER_LOGIN_DURATION_DEFAULT = Convert.toInt(sysCommonService.getCommonByTag("SYSTEM_USER_LOGIN_DURATION_DEFAULT"));
  150. // 将小时转换为毫秒
  151. Long DEFAULT_MILLISECONDS = SYSTEM_USER_LOGIN_DURATION_DEFAULT * DateUnit.HOUR.getMillis();
  152. // 7天 (转毫秒)
  153. Long SEVEN_DAY_MILLISECONDS = 7L * 24 * 60 * 60 * 1000;
  154. Long token_duration_milliseconds = (is_remember != null && is_remember.equals(1)) ? SEVEN_DAY_MILLISECONDS : DEFAULT_MILLISECONDS;
  155. Integer token_duration_hours = Convert.toInt(token_duration_milliseconds / 3600000L);
  156. Date token_expiration = new Date((new Date()).getTime() + token_duration_milliseconds);
  157. sysUserInfo.setToken_expiration(DateUtil.format(token_expiration, "yyyy-MM-dd HH:mm:ss"));
  158. // 生成 Token
  159. SecurityUserInfo securityUserInfo = JSONUtil.toBean(JSONUtil.parseObj(sysUserInfo), SecurityUserInfo.class);
  160. String token = jwtUtil.createSystemJwtToken(securityUserInfo);
  161. String token_redis_key = REDIS_LOGIN_TOKEN_PREFIX + uuid;
  162. sysUserInfo.setToken(token);
  163. // 生成 PerMissionIds
  164. List<String> permission_ids_list = sysUserInfo.getPermission_ids();
  165. // [Redis] 将 Token 与 Permission 存入缓存
  166. TokenCatch tokenCatch = new TokenCatch(token, permission_ids_list);
  167. redisUtil.setCacheObject(token_redis_key, JSONUtil.toJsonStr(tokenCatch), token_duration_hours, TimeUnit.HOURS);
  168. return sysUserInfo;
  169. }
  170. private void setLoginRequired(String key) {
  171. Object captchaValue = redisUtil.getCacheObject(APPLICATION_NAME + "-login-required-captcha-" + key);
  172. Integer currentErrCount = (captchaValue == null) ? 1 : (Convert.toInt(captchaValue) + 1);
  173. redisUtil.setCacheObject(APPLICATION_NAME + "-login-required-captcha-" + key, currentErrCount, 1, TimeUnit.MINUTES);
  174. System.out.println("currentErrCount: " + currentErrCount);
  175. }
  176. private void cleanLoginRequired(String key) {
  177. redisUtil.delete(APPLICATION_NAME + "-login-required-captcha-" + key);
  178. }
  179. /**
  180. * 登录 (用户名)
  181. */
  182. @Override
  183. @Transactional(rollbackFor = Exception.class)
  184. public SysUserInfo login(SysAuth sysAuth) {
  185. String username = sysAuth.getUsername();
  186. String password = sysAuth.getPassword();
  187. String captcha = sysAuth.getCaptcha();
  188. // 判断是否处于登录错误的冻结状态 (2分钟内错误5次,则出现冻结提示)
  189. lockStatusUtil.checkLockStatus(APPLICATION_NAME + "-login-error", username);
  190. // -- 判断是否需要输入验证码 ----------------------------------------------------
  191. // - 当输错 3 次密码时,需要输入验证码
  192. // - 当输错后 1 分钟后重置
  193. Boolean isCaptchaRequired = captchaUtil.isCaptchaRequired(APPLICATION_NAME + "-login-required-captcha-" + username, 3);
  194. if (isCaptchaRequired) {
  195. Boolean isCaptchaEmpty = StrUtil.isEmpty(captcha);
  196. Boolean isCpatchaValid = (captchaUtil.isCaptchaValid(captcha, httpRequestUtil.getKaptchaKey()));
  197. if (isCaptchaEmpty) { loginFail("验证码不能为空", username, false); return null; }
  198. if (!isCpatchaValid) { loginFail("验证码错误", username, false); return null; }
  199. }
  200. // --------------------------------------------------------------------------
  201. // [Method] 判断 用户 是否存在 && 密码是否正确
  202. SysUser sysUser = sysUserDao.selectOne(new LambdaQueryWrapper<SysUser>().eq(SysUser::getUsername, username));
  203. if (sysUser == null) {
  204. // 输入错误时,计数器叠加,并且设置重置时间 (会一直叠加,直到重置 或 登录成功)
  205. setLoginRequired(username);
  206. // [登录失败] 用户不存在
  207. loginFail("用户名或密码错误", username, true);
  208. return null;
  209. } else {
  210. BCryptPasswordEncoder encoder = new BCryptPasswordEncoder();
  211. if (!encoder.matches(password, sysUser.getPassword())) {
  212. // 输入错误时,计数器叠加,并且设置重置时间 (会一直叠加,直到重置 或 登录成功)
  213. setLoginRequired(username);
  214. // [登录失败] 密码不正确
  215. loginFail("用户名或密码错误", username, true);
  216. }
  217. // [登录成功]
  218. cleanLoginRequired(username);
  219. return loginSuccess(sysUser.getId(), sysAuth.getIs_remember());
  220. }
  221. }
  222. /**
  223. * 登录 (手机号码)
  224. */
  225. @Override
  226. @Transactional(rollbackFor = Exception.class)
  227. public SysUserInfo loginWithPhone(SysAuthPhone sysAuthPhone) {
  228. String phone = sysAuthPhone.getPhone();
  229. Integer phoneAreaCode = sysAuthPhone.getPhone_area_code();
  230. Integer phoneValidCode = sysAuthPhone.getPhone_valid_code();
  231. // 判断是否处于登录错误的冻结状态 (2分钟内错误5次,则出现冻结提示)
  232. lockStatusUtil.checkLockStatus(APPLICATION_NAME + "-login-error", phone);
  233. // 判断短信验证码是否正确
  234. String redisKey = APPLICATION_NAME + "-sms-login" + "-" + phone;
  235. Integer smsCode = redisUtil.getCacheObject(redisKey);
  236. // 判断是否发送验证码
  237. if ("false".equals(SMS_DEBUG) && smsCode == null) throw new CustException("请先发送短信验证码");
  238. // 判断短信验证码是否错误
  239. if ("false".equals(SMS_DEBUG) && !smsCode.equals(phoneValidCode)) loginFail("短信验证码错误", phone, true);
  240. // 判断手机号是否存在
  241. LambdaQueryWrapper<SysUser> queryWrapper = new LambdaQueryWrapper<>();
  242. queryWrapper.eq(SysUser::getPhone, phone).eq(SysUser::getPhone_area_code, phoneAreaCode);
  243. SysUser sysUser = sysUserDao.selectOne(queryWrapper);
  244. if (sysUser == null) {
  245. // [登录失败] 用户不存在 (并不会销毁短信验证码)
  246. loginFail("手机号码未注册,请先注册", phone, true);
  247. return null;
  248. } else {
  249. // 登录成功,销毁短信验证码
  250. redisUtil.delete(redisKey);
  251. // [登录成功]
  252. return loginSuccess(sysUser.getId(), sysAuthPhone.getIs_remember());
  253. }
  254. }
  255. @Override
  256. @Transactional(rollbackFor = Exception.class)
  257. public Map<String, Object> register(SysUserDTO sysUserDTO) {
  258. // 判断是否允许注册
  259. // [系统配置] 是否允许系统用户注册
  260. Boolean SYSTEM_USER_ALLOW_REGISTER = Convert.toBool(sysCommonService.getCommonByTag("SYSTEM_USER_ALLOW_REGISTER"));
  261. if (!SYSTEM_USER_ALLOW_REGISTER) throw new CustException("系统已禁止注册");
  262. // -- 参数校验 --------------------------------------------------------------
  263. String username = sysUserDTO.getUsername();
  264. String password = sysUserDTO.getPassword();
  265. String captcha = sysUserDTO.getCaptcha();
  266. String phone = sysUserDTO.getPhone();
  267. Integer phoneAreaCode = sysUserDTO.getPhone_area_code();
  268. Integer phoneValidCode = sysUserDTO.getPhone_valid_code();
  269. // 判断是否处于登录错误的冻结状态 (2分钟内错误5次,则出现冻结提示)
  270. lockStatusUtil.checkLockStatus(APPLICATION_NAME + "-register-error", username);
  271. lockStatusUtil.checkLockStatus(APPLICATION_NAME + "-register-error", phone);
  272. // 判断图形验证码是否正确
  273. if (!captchaUtil.isCaptchaValid(captcha, httpRequestUtil.getKaptchaKey())) {
  274. loginFail("验证码错误", username, false);
  275. return null;
  276. }
  277. // [查询] 判断用户名是否存在
  278. SysUser sysUser1 = sysUserDao.selectOne(new LambdaQueryWrapper<SysUser>().eq(SysUser::getUsername, username));
  279. if (sysUser1 != null) throw new CustException("用户名 (" + username + ") 已被注册");
  280. // 判断短信验证码是否正确
  281. String redisKey = APPLICATION_NAME + "-sms-register" + "-" + phone;
  282. Integer smsCode = redisUtil.getCacheObject(redisKey);
  283. // 判断是否发送验证码
  284. if ("false".equals(SMS_DEBUG) && smsCode == null) throw new CustException("请先发送短信验证码");
  285. // 判断短信验证码是否错误
  286. if ("false".equals(SMS_DEBUG) && !smsCode.equals(phoneValidCode)) loginFail("短信验证码错误", phone, true);
  287. // [查询] 判断手机号是否存在
  288. LambdaQueryWrapper<SysUser> queryWrapper = new LambdaQueryWrapper<>();
  289. queryWrapper.eq(SysUser::getPhone, phone).eq(SysUser::getPhone_area_code, phoneAreaCode);
  290. SysUser sysUser2 = sysUserDao.selectOne(queryWrapper);
  291. if (sysUser2 != null) throw new CustException("手机号码 (+" + phoneAreaCode + " " + phone + ") 已被注册");
  292. // -- 通过校验 --------------------------------------------------------------
  293. // 密码二次加密
  294. BCryptPasswordEncoder encoder = new BCryptPasswordEncoder();
  295. String encodedPassword = encoder.encode(password);
  296. sysUserDTO.setPassword(encodedPassword);
  297. // 注册
  298. SysUserDTO registerEntity = new SysUserDTO();
  299. registerEntity.setUsername(sysUserDTO.getUsername());
  300. registerEntity.setPhone(sysUserDTO.getPhone());
  301. registerEntity.setPhone_area_code(sysUserDTO.getPhone_area_code());
  302. registerEntity.setPassword(sysUserDTO.getPassword());
  303. // 做成后台可控制?
  304. // 注册时,默认使用 权限
  305. registerEntity.setRole_id(Arrays.asList(3L));
  306. registerEntity.setInvite_code(sysUserDTO.getInvite_code());
  307. // 注册时,状态为禁用
  308. registerEntity.setStatus(-1);
  309. // 创建用户
  310. sysUserDao.insertUser(registerEntity);
  311. // 初始化用户积分
  312. sysUserIntegralService.init(registerEntity.getId());
  313. return Map.of("user_id", registerEntity.getId());
  314. }
  315. /**
  316. * 忘记密码/重置密码
  317. */
  318. @Override
  319. public Map<String, Object> forgotPassword(SysUserDTO sysUserDTO) {
  320. String phone = sysUserDTO.getPhone();
  321. Integer phoneAreaCode = sysUserDTO.getPhone_area_code();
  322. Integer phoneValidCode = sysUserDTO.getPhone_valid_code();
  323. // 判断短信验证码是否正确
  324. String redisKey = APPLICATION_NAME + "-sms-forgotPassword-" + sysUserDTO.getPhone();
  325. Integer smsCode = redisUtil.getCacheObject(redisKey);
  326. if ("false".equals(SMS_DEBUG) && (smsCode == null || !smsCode.equals(phoneValidCode))) {
  327. throw new CustException("短信验证码错误");
  328. }
  329. // [查询] 判断手机号是否存在
  330. LambdaQueryWrapper<SysUser> queryWrapper = new LambdaQueryWrapper<>();
  331. queryWrapper.eq(SysUser::getPhone, phone).eq(SysUser::getPhone_area_code, phoneAreaCode);
  332. SysUser sysUser = sysUserDao.selectOne(queryWrapper);
  333. if (sysUser == null) throw new CustException("手机号码不存在");
  334. // 密码二次加密
  335. String password = sysUserDTO.getPassword();
  336. BCryptPasswordEncoder encoder = new BCryptPasswordEncoder();
  337. String encodedPassword = encoder.encode(password);
  338. sysUser.setPassword(encodedPassword);
  339. // 编辑密码
  340. sysUserDao.updateById(sysUser);
  341. // 更改成功,销毁短信验证码
  342. redisUtil.delete(redisKey);
  343. return Map.of("user_id", sysUser.getId());
  344. }
  345. /**
  346. * 退出登录
  347. */
  348. public Map<String, Object> logout() {
  349. Long user_id = httpRequestUtil.getUserId();
  350. if (user_id != null) {
  351. tokenUtil.deleteRedisLoginToken(null);
  352. }
  353. return Map.of("user_id", user_id);
  354. }
  355. }