SysAuthServiceImpl.java 17 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401
  1. package com.backendsys.modules.system.service.impl;
  2. import cn.hutool.core.convert.Convert;
  3. import cn.hutool.core.date.DateUnit;
  4. import cn.hutool.core.date.DateUtil;
  5. import cn.hutool.core.util.NumberUtil;
  6. import cn.hutool.json.JSONUtil;
  7. import com.backendsys.exception.CustException;
  8. import com.backendsys.modules.common.config.redis.utils.RedisUtil;
  9. import com.backendsys.modules.common.config.security.entity.SecurityUserInfo;
  10. import com.backendsys.modules.common.config.security.utils.*;
  11. import com.backendsys.modules.system.dao.SysMobileAreaDao;
  12. import com.backendsys.modules.system.dao.SysUserDao;
  13. import com.backendsys.modules.system.dao.SysUserInfoDao;
  14. import com.backendsys.modules.system.entity.*;
  15. import com.backendsys.modules.system.service.SysAuthService;
  16. import com.backendsys.modules.system.service.SysCommonService;
  17. import com.backendsys.modules.system.service.SysUserIntegralService;
  18. import com.backendsys.modules.system.service.SysUserService;
  19. import com.backendsys.utils.response.ResultEnum;
  20. import com.baomidou.mybatisplus.core.conditions.query.LambdaQueryWrapper;
  21. import com.google.code.kaptcha.Producer;
  22. import jakarta.servlet.ServletOutputStream;
  23. import jakarta.servlet.http.HttpServletResponse;
  24. import org.springframework.beans.factory.annotation.Autowired;
  25. import org.springframework.beans.factory.annotation.Value;
  26. import org.springframework.security.crypto.bcrypt.BCryptPasswordEncoder;
  27. import org.springframework.stereotype.Service;
  28. import org.springframework.transaction.annotation.Transactional;
  29. import javax.imageio.ImageIO;
  30. import java.awt.image.BufferedImage;
  31. import java.io.ByteArrayOutputStream;
  32. import java.io.IOException;
  33. import java.util.*;
  34. import java.util.concurrent.TimeUnit;
  35. @Service
  36. public class SysAuthServiceImpl implements SysAuthService {
  37. @Autowired
  38. private JwtUtil jwtUtil;
  39. @Autowired
  40. private RedisUtil redisUtil;
  41. @Autowired
  42. private TokenUtil tokenUtil;
  43. @Autowired
  44. private HttpRequestUtil httpRequestUtil;
  45. @Autowired
  46. private CountUtilV2 countUtilV2;
  47. @Autowired
  48. private CaptchaUtil captchaUtil;
  49. @Autowired
  50. private Producer captchaProducer;
  51. @Autowired
  52. private SysUserDao sysUserDao;
  53. @Autowired
  54. private SysUserInfoDao sysUserInfoDao;
  55. @Autowired
  56. private SysUserService sysUserService;
  57. @Autowired
  58. private SysMobileAreaDao sysMobileAreaDao;
  59. @Autowired
  60. private SysUserIntegralService sysUserIntegralService;
  61. @Autowired
  62. private SysCommonService sysCommonService;
  63. @Value("${tencent.sms.debug}")
  64. private String SMS_DEBUG;
  65. @Value("${CAPTCHA_DURATION}")
  66. private Integer CAPTCHA_DURATION;
  67. @Value("${REDIS_LOGIN_TOKEN_PREFIX}")
  68. private String REDIS_LOGIN_TOKEN_PREFIX;
  69. @Value("${REDIS_LOGIN_PERMISSION_PREFIX}")
  70. private String REDIS_LOGIN_PERMISSION_PREFIX;
  71. @Value("${spring.application.name}")
  72. private String APPLICATION_NAME;
  73. private String redisKeyOfLogin = APPLICATION_NAME + "-sms-login";
  74. private String redisKeyOfRegister = APPLICATION_NAME + "-sms-register";
  75. private String redisKeyOfLoginFail = APPLICATION_NAME + "-login-error";
  76. private String redisKeyOfRegisterFail = APPLICATION_NAME + "-register-error";
  77. @Override
  78. public void renderCaptcha(HttpServletResponse response) throws IOException {
  79. byte[] captchaChallengeAsJpeg;
  80. ByteArrayOutputStream jpegOutputStream = new ByteArrayOutputStream();
  81. try {
  82. String createText = captchaProducer.createText();
  83. // 获得当前 (UA + IP) 生成的 Key
  84. String captchaRedisKey = httpRequestUtil.getKaptchaKey();
  85. // 保存 验证码字符串 到 redis 中
  86. redisUtil.setCacheObject(captchaRedisKey, createText, this.CAPTCHA_DURATION, TimeUnit.MILLISECONDS);
  87. // 返回 BufferedImage 对象并转为 byte 写入到 byte 数组中
  88. BufferedImage challenge = captchaProducer.createImage(createText);
  89. ImageIO.write(challenge, "jpg", jpegOutputStream);
  90. } catch (Exception e) {
  91. response.sendError(HttpServletResponse.SC_NOT_FOUND);
  92. }
  93. // 定义response输出类型为image/jpeg类型,使用response输出流输出图片的byte数组
  94. captchaChallengeAsJpeg = jpegOutputStream.toByteArray();
  95. response.setHeader("Cache-Control", "no-store");
  96. response.setHeader("Pragma", "no-cache");
  97. response.setDateHeader("Expires", 0);
  98. response.setContentType("image/jpeg");
  99. ServletOutputStream responseOutputStream = response.getOutputStream();
  100. responseOutputStream.write(captchaChallengeAsJpeg);
  101. responseOutputStream.flush();
  102. responseOutputStream.close();
  103. }
  104. @Override
  105. public List<SysMobileArea> getMobileAreaList(SysMobileArea sysMobileArea) {
  106. return sysMobileAreaDao.selectMobileAreaList(sysMobileArea);
  107. }
  108. // [方法] 登录失败 (errMsg: 错误提示文本, username: 用户名, intercept: 是否拦截)
  109. private void loginFail(String errMsg, String username, Boolean isIntercept) {
  110. // 删除图形验证码
  111. redisUtil.delete(httpRequestUtil.getKaptchaKey());
  112. // 添加登录错误的冻结标记
  113. if (isIntercept) countUtilV2.setErrorCount(redisKeyOfLoginFail, username);
  114. throw new CustException(errMsg, ResultEnum.INVALID_CREDENTIALS.getCode());
  115. }
  116. // [方法] 登录成功
  117. private SysUserInfo loginSuccess(Long user_id, Integer is_remember) {
  118. // [查询] 登录的用户信息
  119. SysUserInfo sysUserInfo = sysUserService.selectUserInfo(user_id);
  120. // 删除图形验证码缓存
  121. redisUtil.delete(httpRequestUtil.getKaptchaKey());
  122. // 删除旧的登录缓存
  123. tokenUtil.deleteRedisLoginToken(sysUserInfo.getLast_login_uuid());
  124. // 判断用户是否审核
  125. Integer audit_status = sysUserInfo.getAudit_status();
  126. if (audit_status != null && audit_status.equals(1)) throw new CustException("请等待管理员审核");
  127. if (audit_status != null && audit_status.equals(-1)) throw new CustException("审核未通过,请与客服联系");
  128. // 判断用户是否启用
  129. Integer status = sysUserInfo.getStatus();
  130. if (status != null && status.equals(-1)) throw new CustException("该用户已被禁用,请与客服联系");
  131. // 判断用户是否已删除
  132. Integer del_flag = sysUserInfo.getDel_flag();
  133. if (del_flag != null && del_flag.equals(1)) throw new CustException("用户处于预删除状态,请与客服联系");
  134. // 设置 最后一次的登录信息 (uuid, ip, 登录时间)
  135. String uuid = String.valueOf(UUID.randomUUID());
  136. sysUserInfo.setLast_login_uuid(uuid);
  137. sysUserInfo.setLast_login_ip(httpRequestUtil.getIpAddr());
  138. sysUserInfo.setLast_login_time(DateUtil.format(new Date(), "yyyy-MM-dd HH:mm:ss"));
  139. sysUserInfoDao.updateById(sysUserInfo);
  140. // [系统配置] 系统用户默认登录过期时间(小时)
  141. Integer SYSTEM_USER_LOGIN_DURATION_DEFAULT = Convert.toInt(sysCommonService.getCommonByTag("SYSTEM_USER_LOGIN_DURATION_DEFAULT"));
  142. // 将小时转换为毫秒
  143. Long DEFAULT_MILLISECONDS = SYSTEM_USER_LOGIN_DURATION_DEFAULT * DateUnit.HOUR.getMillis();
  144. // 7天 (转毫秒)
  145. Long SEVEN_DAY_MILLISECONDS = 7L * 24 * 60 * 60 * 1000;
  146. Long token_duration_milliseconds = (is_remember != null && is_remember.equals(1)) ? SEVEN_DAY_MILLISECONDS : DEFAULT_MILLISECONDS;
  147. Integer token_duration_hours = Convert.toInt(token_duration_milliseconds / 3600000L);
  148. Date token_expiration = new Date((new Date()).getTime() + token_duration_milliseconds);
  149. sysUserInfo.setToken_expiration(DateUtil.format(token_expiration, "yyyy-MM-dd HH:mm:ss"));
  150. // 生成 Token
  151. SecurityUserInfo securityUserInfo = JSONUtil.toBean(JSONUtil.parseObj(sysUserInfo), SecurityUserInfo.class);
  152. String token = jwtUtil.createSystemJwtToken(securityUserInfo);
  153. String token_redis_key = REDIS_LOGIN_TOKEN_PREFIX + uuid;
  154. sysUserInfo.setToken(token);
  155. // [Redis] 将 Token 存入缓存
  156. redisUtil.setCacheObject(token_redis_key, token, token_duration_hours, TimeUnit.HOURS);
  157. // [Redis] 将 Permission 存入缓存
  158. List<String> permission_ids_list = sysUserInfo.getPermission_ids();
  159. String permission_ids = String.join(",", permission_ids_list);
  160. String permission_redis_key = REDIS_LOGIN_PERMISSION_PREFIX + uuid;
  161. redisUtil.setCacheObject(permission_redis_key, permission_ids, token_duration_hours, TimeUnit.HOURS);
  162. return sysUserInfo;
  163. }
  164. /**
  165. * 登录 (用户名)
  166. */
  167. @Override
  168. @Transactional
  169. public SysUserInfo login(SysAuth sysAuth) {
  170. String username = sysAuth.getUsername();
  171. String password = sysAuth.getPassword();
  172. String captcha = sysAuth.getCaptcha();
  173. // 判断是否处于登录错误的冻结状态 (2分钟内错误5次,则出现冻结提示)
  174. countUtilV2.checkErrorStatus(redisKeyOfLoginFail, username);
  175. // 判断图形验证码是否正确
  176. if (!captchaUtil.isCaptchaValid(captcha, httpRequestUtil.getKaptchaKey())) {
  177. loginFail("验证码错误", username, false);
  178. return null;
  179. }
  180. // [Method] 判断 用户 是否存在 && 密码是否正确
  181. SysUser sysUser = sysUserDao.selectOne(new LambdaQueryWrapper<SysUser>().eq(SysUser::getUsername, username));
  182. if (sysUser == null) {
  183. // [登录失败] 用户不存在
  184. loginFail("用户名或密码错误", username, true);
  185. return null;
  186. } else {
  187. // [登录失败] 密码不正确
  188. BCryptPasswordEncoder encoder = new BCryptPasswordEncoder();
  189. if (!encoder.matches(password, sysUser.getPassword())) {
  190. loginFail("用户名或密码错误", username, true);
  191. }
  192. // [登录成功]
  193. return loginSuccess(sysUser.getId(), sysAuth.getIs_remember());
  194. }
  195. }
  196. /**
  197. * 登录 (手机号码)
  198. */
  199. @Override
  200. @Transactional
  201. public SysUserInfo loginWithPhone(SysAuthPhone sysAuthPhone) {
  202. String phone = sysAuthPhone.getPhone();
  203. Integer phoneAreaCode = sysAuthPhone.getPhone_area_code();
  204. Integer phoneValidCode = sysAuthPhone.getPhone_valid_code();
  205. // 判断是否处于登录错误的冻结状态 (2分钟内错误5次,则出现冻结提示)
  206. countUtilV2.checkErrorStatus(redisKeyOfLoginFail, phone);
  207. // 判断短信验证码是否正确
  208. String redisKey = redisKeyOfLogin + "-" + phone;
  209. Integer smsCode = redisUtil.getCacheObject(redisKey);
  210. // 判断是否发送验证码
  211. if ("false".equals(SMS_DEBUG) && smsCode == null) throw new CustException("请先发送验证码");
  212. // 判断短信验证码是否错误
  213. if ("false".equals(SMS_DEBUG) && !smsCode.equals(phoneValidCode)) loginFail("短信验证码错误", phone, true);
  214. // 判断手机号是否存在
  215. LambdaQueryWrapper<SysUser> queryWrapper = new LambdaQueryWrapper<>();
  216. queryWrapper.eq(SysUser::getPhone, phone).eq(SysUser::getPhone_area_code, phoneAreaCode);
  217. SysUser sysUser = sysUserDao.selectOne(queryWrapper);
  218. if (sysUser == null) {
  219. // [登录失败] 用户不存在 (并不会销毁短信验证码)
  220. loginFail("手机号码不存在", phone, true);
  221. return null;
  222. } else {
  223. // 登录成功,销毁短信验证码
  224. redisUtil.delete(redisKey);
  225. // [登录成功]
  226. return loginSuccess(sysUser.getId(), sysAuthPhone.getIs_remember());
  227. }
  228. }
  229. @Override
  230. @Transactional
  231. public Map<String, Object> register(SysUserDTO sysUserDTO) {
  232. // 判断是否允许注册
  233. // [系统配置] 是否允许系统用户注册
  234. Boolean SYSTEM_USER_ALLOW_REGISTER = Convert.toBool(sysCommonService.getCommonByTag("SYSTEM_USER_ALLOW_REGISTER"));
  235. if (!SYSTEM_USER_ALLOW_REGISTER) throw new CustException("系统已禁止注册");
  236. // -- 参数校验 --------------------------------------------------------------
  237. String username = sysUserDTO.getUsername();
  238. String password = sysUserDTO.getPassword();
  239. String captcha = sysUserDTO.getCaptcha();
  240. String phone = sysUserDTO.getPhone();
  241. Integer phoneAreaCode = sysUserDTO.getPhone_area_code();
  242. Integer phoneValidCode = sysUserDTO.getPhone_valid_code();
  243. // 判断是否处于登录错误的冻结状态 (2分钟内错误5次,则出现冻结提示)
  244. countUtilV2.checkErrorStatus(redisKeyOfRegisterFail, username);
  245. countUtilV2.checkErrorStatus(redisKeyOfRegisterFail, phone);
  246. // 判断图形验证码是否正确
  247. if (!captchaUtil.isCaptchaValid(captcha, httpRequestUtil.getKaptchaKey())) {
  248. loginFail("验证码错误", username, false);
  249. return null;
  250. }
  251. // [查询] 判断用户名是否存在
  252. SysUser sysUser1 = sysUserDao.selectOne(new LambdaQueryWrapper<SysUser>().eq(SysUser::getUsername, username));
  253. if (sysUser1 != null) throw new CustException("用户名 (" + username + ") 已被注册");
  254. // 判断短信验证码是否正确
  255. String redisKey = redisKeyOfLogin + "-" + phone;
  256. Integer smsCode = redisUtil.getCacheObject(redisKey);
  257. // 判断是否发送验证码
  258. if ("false".equals(SMS_DEBUG) && smsCode == null) throw new CustException("请先发送验证码");
  259. // 判断短信验证码是否错误
  260. if ("false".equals(SMS_DEBUG) && !smsCode.equals(phoneValidCode)) loginFail("短信验证码错误", phone, true);
  261. // [查询] 判断手机号是否存在
  262. LambdaQueryWrapper<SysUser> queryWrapper = new LambdaQueryWrapper<>();
  263. queryWrapper.eq(SysUser::getPhone, phone).eq(SysUser::getPhone_area_code, phoneAreaCode);
  264. SysUser sysUser2 = sysUserDao.selectOne(queryWrapper);
  265. if (sysUser2 != null) throw new CustException("手机号码 (+" + phoneAreaCode + " " + phone + ") 已被注册");
  266. // -- 通过校验 --------------------------------------------------------------
  267. // 密码二次加密
  268. BCryptPasswordEncoder encoder = new BCryptPasswordEncoder();
  269. String encodedPassword = encoder.encode(password);
  270. sysUserDTO.setPassword(encodedPassword);
  271. // 注册
  272. SysUserDTO registerEntity = new SysUserDTO();
  273. registerEntity.setUsername(sysUserDTO.getUsername());
  274. registerEntity.setPhone(sysUserDTO.getPhone());
  275. registerEntity.setPhone_area_code(sysUserDTO.getPhone_area_code());
  276. registerEntity.setPassword(sysUserDTO.getPassword());
  277. // 注册时,默认使用 游客 2L 权限
  278. registerEntity.setRole_id(Arrays.asList(2L));
  279. registerEntity.setInvite_code(sysUserDTO.getInvite_code());
  280. // 注册时,状态为禁用
  281. registerEntity.setStatus(-1);
  282. // 创建用户
  283. sysUserDao.insertUser(registerEntity);
  284. // 初始化用户积分
  285. sysUserIntegralService.init(registerEntity.getId());
  286. return Map.of("user_id", registerEntity.getId());
  287. }
  288. /**
  289. * 忘记密码/重置密码
  290. */
  291. @Override
  292. public Map<String, Object> forgotPassword(SysUserDTO sysUserDTO) {
  293. String phone = sysUserDTO.getPhone();
  294. Integer phoneAreaCode = sysUserDTO.getPhone_area_code();
  295. Integer phoneValidCode = sysUserDTO.getPhone_valid_code();
  296. // 判断短信验证码是否正确
  297. String redisKey = "sms-forgotPassword-" + sysUserDTO.getPhone();
  298. Integer smsCode = redisUtil.getCacheObject(redisKey);
  299. if ("false".equals(SMS_DEBUG) && (smsCode == null || !smsCode.equals(phoneValidCode))) {
  300. throw new CustException("短信验证码错误");
  301. }
  302. // [查询] 判断手机号是否存在
  303. LambdaQueryWrapper<SysUser> queryWrapper = new LambdaQueryWrapper<>();
  304. queryWrapper.eq(SysUser::getPhone, phone).eq(SysUser::getPhone_area_code, phoneAreaCode);
  305. SysUser sysUser = sysUserDao.selectOne(queryWrapper);
  306. if (sysUser == null) throw new CustException("手机号码不存在");
  307. // 密码二次加密
  308. String password = sysUserDTO.getPassword();
  309. BCryptPasswordEncoder encoder = new BCryptPasswordEncoder();
  310. String encodedPassword = encoder.encode(password);
  311. sysUser.setPassword(encodedPassword);
  312. // 编辑密码
  313. sysUserDao.updateById(sysUser);
  314. // 更改成功,销毁短信验证码
  315. redisUtil.delete(redisKey);
  316. return Map.of("user_id", sysUser.getId());
  317. }
  318. /**
  319. * 退出登录
  320. */
  321. public Map<String, Object> logout() {
  322. Long user_id = httpRequestUtil.getUserId();
  323. if (user_id != null) {
  324. tokenUtil.deleteRedisLoginToken(null);
  325. }
  326. return Map.of("user_id", user_id);
  327. }
  328. }