AuthController.php 17 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445
  1. <?php
  2. namespace App\Http\Controllers\Api\V1;
  3. use App\Helper\AttachmentHelper;
  4. use App\Helper\JpushHelper;
  5. use App\Helper\SmsHelper;
  6. use Illuminate\Foundation\Auth\AuthenticatesUsers;
  7. use App\Models\UserInfoModel;
  8. use Illuminate\Http\Request;
  9. use App\Models\BaseSettingsModel;
  10. use App\Services\Base\ErrorCode;
  11. use Validator, Auth, Cache;
  12. class AuthController extends Controller
  13. {
  14. use SmsHelper,AuthenticatesUsers,AttachmentHelper,JpushHelper;
  15. private $expireTime = 5;
  16. private $keySmsCode = 'auth:sms:';
  17. private $keySmsCodeExist = 'auth:sms:exist';
  18. private $expireTimeExist = 24*60;
  19. public function test(){
  20. //test
  21. $this->jPush("title",'141fe1da9e8a58e72fe',77,2,452);
  22. if(env("APP_DEBUG")){
  23. return $this->error(0);
  24. }else{
  25. //product
  26. return $this->api(1);
  27. }
  28. }
  29. public function info(Request $request){
  30. if($request->type==1){
  31. $data = BaseSettingsModel::where('category','miaomiao')->select('key','value')->first();
  32. return $this->api($data);
  33. }else if($request->type==2){
  34. $data = BaseSettingsModel::where('category','miaomiao')->select('key','value')->first();
  35. return $this->api($data);
  36. }else if($request->type==3){
  37. return $this->api('关于我们');
  38. }
  39. }
  40. /**
  41. * @api {post} /api/auth/login 登陆(login)
  42. * @apiDescription 登陆(login)
  43. * @apiGroup Auth
  44. * @apiPermission none
  45. * @apiVersion 0.1.0
  46. * @apiParam {string} phone 手机号码
  47. * @apiParam {string} [jpush]
  48. * @apiParam {string} wechat 微信openid
  49. * @apiParam {String} verify_code 手机验证码
  50. * @apiSuccessExample {json} Success-Response:
  51. * HTTP/1.1 200 OK
  52. * {
  53. * "state": true,
  54. * "code": 0,
  55. * "message": "",
  56. * "data": {
  57. * "token": "eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIsImp0aSI6IjdjYWUyYzFmYTUwMTIyZDI0ZTRiYTZhZGZhNmQxYmZlOWNiMzIxMTBmYWJlZjNjYzIyNmViZjRmNGExNWM3NjllNmU2ZTNiYWE5OGNhOWUzIn0.eyJhdWQiOiIxIiwianRpIjoiN2NhZTJjMWZhNTAxMjJkMjRlNGJhNmFkZmE2ZDFiZmU5Y2IzMjExMGZhYmVmM2NjMjI2ZWJmNGY0YTE1Yzc2OWU2ZTZlM2JhYTk4Y2E5ZTMiLCJpYXQiOjE0NzU0MTE1NTgsIm5iZiI6MTQ3NTQxMTU1OCwiZXhwIjo0NjMxMDg1MTU4LCJzdWIiOiIxIiwic2NvcGVzIjpbXX0.E9YGEzuRUOk02aV1EiWLJ_pD0hKoCyW0k_sGy63hM3u5X8K_HI1kVhaU6JNLqLZeszIAroTEDB8XMgZKAqTLlwtL8PLCJcuDoxfk1BRHbfjhDheTsahBysKGalvNEpzRCrGlao0mS0Cg9qDpEsndtypPFS8sfaflToOzbJjiSK2DvQiHSH8xZI3zHJTezgZMz-pB_hPTxp8ajdv0ve1gWtWjs3vERr0Y91X4hngO8X7LuXtAYtfxGZRIye12YE7TuLBMYzj8CCfiRt7Smhyf4palNW5mzKlZpa2l87n6NQ14Iy4oMzQ2PON1j_swrosuE2yZohGOn6fDdSCBRdJ6dLD_emjBdQCQOoB63R7BbhFZgvFX25TjzFJ7r9AdVMiGmebuRKEVSZV_JCGu1C71OIbQk-UK35s00gSr2fmJGBbN2cZTXBRTJpfuMZ_ihFYEZrvVq_Ih2X0xkd36JUuxaUld1BXRgPZvH-9jBuhe0YW2OOlgwpdm6ZB8BMcuS4ftLoi6FipgzFqfIuy-0ZqPMDnJaG7Gycrdpxza00mgOFxYxJtqwZNsUWFRZEVU881l6VC_cy294YXSPQxUwEoyKg-G5Pm8AEB9bqv5z4EU4B8-XTd3zKNqtNba_snHbc711i4EytCiZfYSjNB1hwenq45YYOAhPTwOpFI0kxyRazc",
  58. * "user": {
  59. * "id": 1,
  60. * "name": "15888888888",
  61. * "email": "abcdefg@gmail.com",
  62. * "type": 2,
  63. * "phone": "15888888888",
  64. * "avatar": null,
  65. * "step": 0, 新手引导默认0
  66. * "last_ip": null,
  67. * "created_at": "2016-09-30 00:45:13",
  68. * "updated_at": "2016-09-29 16:43:36"
  69. * }
  70. * }
  71. * }
  72. * @apiErrorExample {json} Error-Response:
  73. * HTTP/1.1 400 Bad Request
  74. * {
  75. * "state": false,
  76. * "code": 1000,
  77. * "message": "传入参数不正确",
  78. * "data": null or []
  79. * }
  80. * 可能出现的错误代码:
  81. * 1000 CLIENT_WRONG_PARAMS 传入参数不正确
  82. * 1103 VERIFY_CODE_TOO_MUCH 验证码大于5次
  83. * 1610 SERVICE_CODE_FAILED 验证码错误
  84. *
  85. */
  86. public function login(Request $request) {
  87. $validator = Validator::make($request->all(),
  88. [
  89. // 'wechat' => 'required',
  90. 'phone' => 'required|regex:/^1[34578]\d{9}$/',
  91. 'verify_code' => 'required',
  92. ],
  93. [
  94. // 'wechat.required' => '请先绑定微信',
  95. 'phone.required' => '请输入手机号码',
  96. 'phone.regex' => '手机号码格式不正确',
  97. 'verify_code.required' => '短信验证码必填',
  98. ]
  99. );
  100. if ($validator->fails())
  101. return $this->validatorError($validator->messages()->all(),ErrorCode::CLIENT_WRONG_PARAMS);
  102. $phone = $request->phone;
  103. $wechat = $request->wechat;
  104. // $url = "https://api.weixin.qq.com/sns/oauth2/access_token?appid=wxc5181c0d406023e6&secret=82d15bf4c5c5baaad1e5a521cfdcf96c&code=".$wechat."&grant_type=authorization_code";
  105. // $res = file_get_contents($url); //file_get_contents获取指定路由返回的数据
  106. // \Log::info($res);
  107. // $arr = json_decode($res, true);
  108. // $openid='';
  109. // if(!$arr['errcode'])$openid = $arr['openid'];
  110. \Log::info('openid: ' . $wechat);
  111. $user = UserInfoModel::where('wechat',$wechat)->first();
  112. $jpush = $request->jpush;
  113. $key = $this->keySmsCode . $phone;
  114. $code = Cache::store('file')->get($key);
  115. $password = 123456;
  116. if ($request->verify_code != $code) return $this->error(ErrorCode::SERVICE_CODE_FAILED);
  117. if(empty($user)){
  118. $user = UserInfoModel::where('phone',$phone)->first();
  119. }else{
  120. $phone_user = UserInfoModel::where('phone',$phone)->first();
  121. if(!empty($phone_user)){
  122. // return $this->error(ErrorCode::USER_DOES_EXIST);
  123. $user = $phone_user;
  124. $token = $user->createToken($user->phone)->accessToken;
  125. return $this->api(compact( 'user', 'code','token'));
  126. }
  127. }
  128. // 如果走到这里 就检查user_info.phone是否唯一 允许为空
  129. if (empty($user)) {
  130. $user = UserInfoModel::create([
  131. 'phone'=>$phone,
  132. 'wechat'=>$wechat,
  133. 'jpush'=>$jpush,
  134. 'nickname'=>'瞄喵'.rand(1000,9999),
  135. 'status'=>1,
  136. 'password'=>bcrypt(123456)
  137. ]);
  138. }else{
  139. //用户已经存在,重新绑定
  140. $user->wechat=$wechat;
  141. $user->phone=$phone;
  142. $user->password=bcrypt(123456);
  143. $user->save();
  144. }
  145. $status =empty($user) ? 0 : $user->status;
  146. if ($status == 0) return $this->error(ErrorCode::LOCK_USER);
  147. if (Auth::attempt(['phone'=>$phone,'password'=>$password])) {
  148. $user = Auth::guard('api')->user();
  149. /* if (!empty($wechat)) {
  150. $user->wechat =$wechat;
  151. $user->save();
  152. }*/
  153. \Log::info($user);
  154. $token = $user->createToken($user->phone)->accessToken;
  155. return $this->api(compact( 'user', 'code','token'));
  156. }else{
  157. return $this->error(ErrorCode::INCORRECT_USER_OR_PASS);
  158. }
  159. }
  160. // 第三方登录 微信
  161. /**
  162. * @api {get} /api/auth/wechat_login 微信登陆(login)
  163. * @apiDescription 微信登陆(login)
  164. * @apiGroup Auth
  165. * @apiPermission none
  166. * @apiVersion 0.1.0
  167. * @apiParam {string} wechat 微信id
  168. * @apiSuccessExample {json} Success-Response:
  169. * HTTP/1.1 200 OK
  170. * {
  171. * "state": true,
  172. * "code": 0,
  173. * "message": "",
  174. * "data": {
  175. * "token": "eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIsImp0aSI6IjdjYWUyYzFmYTUwMTIyZDI0ZTRiYTZhZGZhNmQxYmZlOWNiMzIxMTBmYWJlZjNjYzIyNmViZjRmNGExNWM3NjllNmU2ZTNiYWE5OGNhOWUzIn0.eyJhdWQiOiIxIiwianRpIjoiN2NhZTJjMWZhNTAxMjJkMjRlNGJhNmFkZmE2ZDFiZmU5Y2IzMjExMGZhYmVmM2NjMjI2ZWJmNGY0YTE1Yzc2OWU2ZTZlM2JhYTk4Y2E5ZTMiLCJpYXQiOjE0NzU0MTE1NTgsIm5iZiI6MTQ3NTQxMTU1OCwiZXhwIjo0NjMxMDg1MTU4LCJzdWIiOiIxIiwic2NvcGVzIjpbXX0.E9YGEzuRUOk02aV1EiWLJ_pD0hKoCyW0k_sGy63hM3u5X8K_HI1kVhaU6JNLqLZeszIAroTEDB8XMgZKAqTLlwtL8PLCJcuDoxfk1BRHbfjhDheTsahBysKGalvNEpzRCrGlao0mS0Cg9qDpEsndtypPFS8sfaflToOzbJjiSK2DvQiHSH8xZI3zHJTezgZMz-pB_hPTxp8ajdv0ve1gWtWjs3vERr0Y91X4hngO8X7LuXtAYtfxGZRIye12YE7TuLBMYzj8CCfiRt7Smhyf4palNW5mzKlZpa2l87n6NQ14Iy4oMzQ2PON1j_swrosuE2yZohGOn6fDdSCBRdJ6dLD_emjBdQCQOoB63R7BbhFZgvFX25TjzFJ7r9AdVMiGmebuRKEVSZV_JCGu1C71OIbQk-UK35s00gSr2fmJGBbN2cZTXBRTJpfuMZ_ihFYEZrvVq_Ih2X0xkd36JUuxaUld1BXRgPZvH-9jBuhe0YW2OOlgwpdm6ZB8BMcuS4ftLoi6FipgzFqfIuy-0ZqPMDnJaG7Gycrdpxza00mgOFxYxJtqwZNsUWFRZEVU881l6VC_cy294YXSPQxUwEoyKg-G5Pm8AEB9bqv5z4EU4B8-XTd3zKNqtNba_snHbc711i4EytCiZfYSjNB1hwenq45YYOAhPTwOpFI0kxyRazc",
  176. * "user": {
  177. * "id": 1,
  178. * "name": "15888888888",
  179. * "email": "abcdefg@gmail.com",
  180. * "type": 2,
  181. * "phone": "15888888888",
  182. * "avatar": null,
  183. * "last_ip": null,
  184. * "created_at": "2016-09-30 00:45:13",
  185. * "updated_at": "2016-09-29 16:43:36"
  186. * }
  187. * }
  188. * }
  189. * @apiErrorExample {json} Error-Response:
  190. * HTTP/1.1 400 Bad Request
  191. */
  192. public function wechatLogin(Request $request) {
  193. $validator = Validator::make($request->all(),
  194. [
  195. 'wechat' => 'required',
  196. ],
  197. [
  198. 'wechat.required' => '微信id不存在',
  199. ]
  200. );
  201. if ($validator->fails())
  202. return $this->validatorError($validator->messages()->all(),ErrorCode::CLIENT_WRONG_PARAMS);
  203. $url = "https://api.weixin.qq.com/sns/oauth2/access_token?appid=wxc5181c0d406023e6&secret=82d15bf4c5c5baaad1e5a521cfdcf96c&code=".$request->wechat."&grant_type=authorization_code";
  204. $res = file_get_contents($url); //file_get_contents获取指定路由返回的数据
  205. \Log::info($res);
  206. $arr = json_decode($res, true);
  207. $openid='';
  208. if(!isset($arr['errcode']))$openid = $arr['openid'];
  209. if(!empty($openid)){
  210. $url = "https://api.weixin.qq.com/sns/userinfo?access_token=".$arr['access_token']."&openid=".$openid."&lang=zh_CN";
  211. $userInfoJson = file_get_contents($url); //file_get_contents获取指定路由返回的数据
  212. $userInfo = json_decode($userInfoJson, true);
  213. \Log::info('userInfo: ' . $userInfoJson);
  214. }
  215. \Log::info('openid: ' . $openid);
  216. if($openid!='')$user = UserInfoModel::where('wechat',$openid)->first();
  217. \Log::info($user);
  218. if (empty($user)||$user->phone=='') {
  219. \Log::info('empty: ' . empty($user));
  220. if(empty($user)){
  221. UserInfoModel::create([
  222. 'wechat'=>$openid,
  223. 'nickname'=>$userInfo['nickname'],
  224. 'avatar'=>$userInfo['headimgurl'],
  225. 'status'=>1,
  226. 'password'=>bcrypt(123456)
  227. ]);
  228. }
  229. return $this->api(['openid' => $openid]);
  230. // return $this->api(['wechat' => $openid]);
  231. }else{
  232. $token = $user->createToken($user->phone)->accessToken;
  233. return $this->api(compact( 'user', 'openid','token'));
  234. }
  235. }
  236. /**
  237. * @api {get} /api/auth/logout 退出(logout)
  238. * @apiDescription 退出(logout)
  239. * @apiGroup Auth
  240. * @apiPermission Passport
  241. * @apiVersion 0.1.0
  242. * @apiSuccessExample {json} Success-Response:
  243. * HTTP/1.1 200 OK
  244. * {
  245. * "state": true,
  246. * "code": 0,
  247. * "message": "",
  248. * "data": {
  249. * "result": true/false
  250. * }
  251. * }
  252. * @apiErrorExample {json} Error-Response:
  253. * HTTP/1.1 400 Bad Request
  254. * {
  255. * "state": false,
  256. * "code": 1104,
  257. * "message": "退出失败",
  258. * "data": null
  259. * }
  260. * 可能出现的错误代码:
  261. * 1104 LOGOUT_FAILED 退出失败
  262. */
  263. public function logout() {
  264. $user = Auth::guard('api')->user();
  265. if ($user->token()->delete()) {
  266. return $this->api(['result' => true]);
  267. }
  268. return $this->error(ErrorCode::LOGOUT_FAILED);
  269. }
  270. /**
  271. * @api {post} /api/auth/code 获取验证码(get code)
  272. * @apiDescription 获取验证码(get code),验证码有效期暂定为15分钟
  273. * @apiGroup Auth
  274. * @apiPermission none
  275. * @apiVersion 0.1.0
  276. * @apiParam {string} phone 手机
  277. * @apiSuccessExample {json} Success-Response:
  278. * HTTP/1.1 200 OK
  279. * {
  280. * "state": true,
  281. * "code": 0,
  282. * "message": "",
  283. * "data": {
  284. * "verify_code": "1234"//该值调试时使用,sms调通后取消
  285. * }
  286. * }
  287. * @apiErrorExample {json} Error-Response:
  288. * HTTP/1.1 400 Bad Request
  289. * {
  290. * "state": false,
  291. * "code": 1000,
  292. * "message": "传入参数不正确",
  293. * "data": null or []
  294. * }
  295. * 可能出现的错误代码:
  296. * 1000 CLIENT_WRONG_PARAMS 传入参数不正确
  297. */
  298. public function getCode(Request $request)
  299. {
  300. $validator = Validator::make($request->all(),
  301. [
  302. 'phone' => 'required|regex:/^1[34578]\d{9}$/',
  303. ],
  304. [
  305. 'phone.required' => '手机号码必填',
  306. 'phone.regex' => '手机号码格式不正确',
  307. ]
  308. );
  309. if ($validator->fails())
  310. return $this->validatorError($validator->messages()->all(),ErrorCode::CLIENT_WRONG_PARAMS);
  311. $phone = $request->phone;
  312. $keyexist = $this->keySmsCodeExist . $phone;
  313. $times = Cache::store('file')->get($keyexist);
  314. if($times>60) {
  315. return $this->error(ErrorCode::VERIFY_CODE_TOO_MUCH);
  316. }else{
  317. $times++;
  318. Cache::store('file')->put($keyexist, $times, $this->expireTimeExist);
  319. }
  320. $verify_code = (string) mt_rand(1000, 9999);
  321. \Log::info('verify_code:'.$verify_code);
  322. $key = $this->keySmsCode . $phone;
  323. Cache::store('file')->put($key, $verify_code, $this->expireTime);
  324. $msg = '【喵喵】您的验证码是:(' . $verify_code.')。5分钟内有效请及时验证';
  325. if(env("APP_DEBUG")){
  326. return $this->api(['verify_code' => $verify_code]);
  327. }else{
  328. $result = $this->sendSms($msg, $phone);
  329. }
  330. if ($result!='success') {
  331. \Log::error("Send sms failed.".$result);
  332. }
  333. }
  334. public function refreshToken() {
  335. $token = '';//TODO
  336. return $this->api([
  337. 'token' => $token,
  338. ]);
  339. }
  340. public function isLogin()
  341. {
  342. $user = Auth::guard('api')->user();
  343. $res = true;
  344. if(!$user) $res = false;
  345. return $this->api([
  346. 'result' => $res,
  347. ]);
  348. }
  349. /**
  350. * @api {post} /api/auth/avatar 上传头像(avatar)
  351. * @apiDescription 上传头像(reset)
  352. * @apiGroup Auth
  353. * @apiPermission Passport
  354. * @apiVersion 0.1.0
  355. * @apiParam {File} avatar 头像图片
  356. * @apiSuccessExample {json} Success-Response:
  357. * HTTP/1.1 200 OK
  358. * {
  359. * "state": true,
  360. * "code": 0,
  361. * "message": "",
  362. * "data": {
  363. * "md5": "fdf8dd78eb383b8acf6d94d4752c1424",
  364. * }
  365. * }
  366. * @apiErrorExample {json} Error-Response:
  367. * HTTP/1.1 400 Bad Request
  368. * {
  369. * "state": false,
  370. * "code": 1000,
  371. * "message": "传入参数不正确",
  372. * "data": null or []
  373. * }
  374. * 可能出现的错误代码:
  375. * 200 SAVE_USER_FAILED 保存用户数据失败
  376. * 201 ATTACHMENT_MKDIR_FAILED 创建附件目录失败
  377. * 202 ATTACHMENT_UPLOAD_INVALID 上传附件文件无效
  378. * 203 ATTACHMENT_SAVE_FAILED 保存附件失败
  379. * 204 ATTACHMENT_MOVE_FAILED 移动附件失败
  380. * 205 ATTACHMENT_DELETE_FAILED 删除附件文件失败
  381. * 206 ATTACHMENT_RECORD_DELETE_FAILED 删除附件记录失败
  382. * 1000 CLIENT_WRONG_PARAMS 传入参数不正确
  383. * 1101 INCORRECT_VERIFY_CODE 输入验证码错误
  384. * 1105 USER_DOES_NOT_EXIST 用户不存在
  385. * 1200 ATTACHMENT_UPLOAD_FAILED 附件上传失败
  386. * 1201 ATTACHMENT_SIZE_EXCEEDED 附件大小超过限制
  387. * 1202 ATTACHMENT_MIME_NOT_ALLOWED 附件类型不允许
  388. * 1203 ATTACHMENT_NOT_EXIST 附件不存在
  389. */
  390. public function avatar(Request $request) {
  391. // $user = Auth::user();
  392. $user = $this->getUser();
  393. $old_avatar = $user->avatar;
  394. $result = $this->uploadAttachment($request, 'avatar', 'avatar', 4 * 1024 * 1024, [
  395. 'image/jpeg',
  396. 'image/png',
  397. 'image/gif',
  398. ]);
  399. if (is_array($result)) {
  400. $result = array_shift($result);
  401. }
  402. if (is_string($result)) {
  403. $user->avatar = config('app.url')."/attachment/".$result;
  404. if (!$user->save()) {
  405. return $this->error(ErrorCode::SAVE_USER_FAILED);
  406. }
  407. $this->deleteAttachment($old_avatar);
  408. return $this->api(['file' => $result]);
  409. }
  410. return $this->error($result);
  411. }
  412. }