AuthController.php 16 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411
  1. <?php
  2. namespace App\Http\Controllers\Api\V1;
  3. use App\Helper\AttachmentHelper;
  4. use App\Helper\SmsHelper;
  5. use Illuminate\Foundation\Auth\AuthenticatesUsers;
  6. use App\Models\UserInfoModel;
  7. use Illuminate\Http\Request;
  8. use App\Services\Base\ErrorCode;
  9. use Validator, Auth, Cache;
  10. class AuthController extends Controller
  11. {
  12. use SmsHelper,AuthenticatesUsers,AttachmentHelper;
  13. private $expireTime = 1;
  14. private $keySmsCode = 'auth:sms:';
  15. private $keySmsCodeExist = 'auth:sms:exist';
  16. private $expireTimeExist = 24*60;
  17. public function test(){
  18. // return $this->error(ErrorCode::SAVE_USER_FAILED);
  19. return $this->api(['test' => 'test']);
  20. }
  21. /**
  22. * @api {post} /api/auth/login 登陆(login)
  23. * @apiDescription 登陆(login)
  24. * @apiGroup Auth
  25. * @apiPermission none
  26. * @apiVersion 0.1.0
  27. * @apiParam {string} phone 手机号码
  28. * @apiParam {String} verify_code 手机验证码
  29. * @apiSuccessExample {json} Success-Response:
  30. * HTTP/1.1 200 OK
  31. * {
  32. * "state": true,
  33. * "code": 0,
  34. * "message": "",
  35. * "data": {
  36. * "token": "eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIsImp0aSI6IjdjYWUyYzFmYTUwMTIyZDI0ZTRiYTZhZGZhNmQxYmZlOWNiMzIxMTBmYWJlZjNjYzIyNmViZjRmNGExNWM3NjllNmU2ZTNiYWE5OGNhOWUzIn0.eyJhdWQiOiIxIiwianRpIjoiN2NhZTJjMWZhNTAxMjJkMjRlNGJhNmFkZmE2ZDFiZmU5Y2IzMjExMGZhYmVmM2NjMjI2ZWJmNGY0YTE1Yzc2OWU2ZTZlM2JhYTk4Y2E5ZTMiLCJpYXQiOjE0NzU0MTE1NTgsIm5iZiI6MTQ3NTQxMTU1OCwiZXhwIjo0NjMxMDg1MTU4LCJzdWIiOiIxIiwic2NvcGVzIjpbXX0.E9YGEzuRUOk02aV1EiWLJ_pD0hKoCyW0k_sGy63hM3u5X8K_HI1kVhaU6JNLqLZeszIAroTEDB8XMgZKAqTLlwtL8PLCJcuDoxfk1BRHbfjhDheTsahBysKGalvNEpzRCrGlao0mS0Cg9qDpEsndtypPFS8sfaflToOzbJjiSK2DvQiHSH8xZI3zHJTezgZMz-pB_hPTxp8ajdv0ve1gWtWjs3vERr0Y91X4hngO8X7LuXtAYtfxGZRIye12YE7TuLBMYzj8CCfiRt7Smhyf4palNW5mzKlZpa2l87n6NQ14Iy4oMzQ2PON1j_swrosuE2yZohGOn6fDdSCBRdJ6dLD_emjBdQCQOoB63R7BbhFZgvFX25TjzFJ7r9AdVMiGmebuRKEVSZV_JCGu1C71OIbQk-UK35s00gSr2fmJGBbN2cZTXBRTJpfuMZ_ihFYEZrvVq_Ih2X0xkd36JUuxaUld1BXRgPZvH-9jBuhe0YW2OOlgwpdm6ZB8BMcuS4ftLoi6FipgzFqfIuy-0ZqPMDnJaG7Gycrdpxza00mgOFxYxJtqwZNsUWFRZEVU881l6VC_cy294YXSPQxUwEoyKg-G5Pm8AEB9bqv5z4EU4B8-XTd3zKNqtNba_snHbc711i4EytCiZfYSjNB1hwenq45YYOAhPTwOpFI0kxyRazc",
  37. * "user": {
  38. * "id": 1,
  39. * "name": "15888888888",
  40. * "email": "abcdefg@gmail.com",
  41. * "type": 2,
  42. * "phone": "15888888888",
  43. * "avatar": null,
  44. * "last_ip": null,
  45. * "created_at": "2016-09-30 00:45:13",
  46. * "updated_at": "2016-09-29 16:43:36"
  47. * }
  48. * }
  49. * }
  50. * @apiErrorExample {json} Error-Response:
  51. * HTTP/1.1 400 Bad Request
  52. * {
  53. * "state": false,
  54. * "code": 1000,
  55. * "message": "传入参数不正确",
  56. * "data": null or []
  57. * }
  58. * 可能出现的错误代码:
  59. * 1000 CLIENT_WRONG_PARAMS 传入参数不正确
  60. * 1103 VERIFY_CODE_TOO_MUCH 验证码大于5次
  61. * 1610 SERVICE_CODE_FAILED 验证码错误
  62. *
  63. */
  64. public function login(Request $request,$openid_webo=null,$type=null) {
  65. $validator = Validator::make($request->all(),
  66. [
  67. 'phone' => 'required|regex:/^1[34578]\d{9}$/',
  68. 'verify_code' => 'required',
  69. ],
  70. [
  71. 'phone.required' => '请输入手机号码',
  72. 'phone.regex' => '手机号码格式不正确',
  73. 'verify_code.required' => '短信验证码必填',
  74. ]
  75. );
  76. if ($validator->fails())
  77. return $this->validatorError($validator->messages()->all(),ErrorCode::CLIENT_WRONG_PARAMS);
  78. $phone = $request->phone;
  79. $key = $this->keySmsCode . $phone;
  80. $code = Cache::store('file')->get($key);
  81. $password = 123456;
  82. if ($request->verify_code != $code) return $this->error(ErrorCode::SERVICE_CODE_FAILED);
  83. $user = UserInfoModel::where('phone',$phone)->first();
  84. if (empty($user)) {
  85. $user = UserInfoModel::create(['phone'=>$phone,'password'=>bcrypt(123456)]);
  86. $user->status=1;
  87. }
  88. $status =empty($user) ? 0 : $user->status;
  89. if ($status == 0) return $this->error(ErrorCode::LOCK_USER);
  90. if (Auth::attempt(['phone'=>$phone,'password'=>$password])) {
  91. $user = Auth::user();
  92. if (!empty($openid_webo)) {
  93. if ($type == 'wechat') {
  94. $user->wechat =$openid_webo;
  95. }
  96. if ($type == 'webo') {
  97. $user->webo =$openid_webo;
  98. }
  99. $user->save();
  100. }
  101. \Log::info($user);
  102. $token = $user->createToken($user->phone)->accessToken;
  103. return $this->api(compact( 'user', 'code','token'));
  104. }else{
  105. return $this->error(ErrorCode::INCORRECT_USER_OR_PASS);
  106. }
  107. }
  108. // 第三方登录 微信、微博
  109. /**
  110. * @api {post} /api/auth/wechat_login 微信登陆(login)
  111. * @apiDescription 微信登陆(login)
  112. * @apiGroup Auth
  113. * @apiPermission none
  114. * @apiVersion 0.1.0
  115. * @apiParam {string} wechat 微信id
  116. * @apiSuccessExample {json} Success-Response:
  117. * HTTP/1.1 200 OK
  118. * {
  119. * "state": true,
  120. * "code": 0,
  121. * "message": "",
  122. * "data": {
  123. * "token": "eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIsImp0aSI6IjdjYWUyYzFmYTUwMTIyZDI0ZTRiYTZhZGZhNmQxYmZlOWNiMzIxMTBmYWJlZjNjYzIyNmViZjRmNGExNWM3NjllNmU2ZTNiYWE5OGNhOWUzIn0.eyJhdWQiOiIxIiwianRpIjoiN2NhZTJjMWZhNTAxMjJkMjRlNGJhNmFkZmE2ZDFiZmU5Y2IzMjExMGZhYmVmM2NjMjI2ZWJmNGY0YTE1Yzc2OWU2ZTZlM2JhYTk4Y2E5ZTMiLCJpYXQiOjE0NzU0MTE1NTgsIm5iZiI6MTQ3NTQxMTU1OCwiZXhwIjo0NjMxMDg1MTU4LCJzdWIiOiIxIiwic2NvcGVzIjpbXX0.E9YGEzuRUOk02aV1EiWLJ_pD0hKoCyW0k_sGy63hM3u5X8K_HI1kVhaU6JNLqLZeszIAroTEDB8XMgZKAqTLlwtL8PLCJcuDoxfk1BRHbfjhDheTsahBysKGalvNEpzRCrGlao0mS0Cg9qDpEsndtypPFS8sfaflToOzbJjiSK2DvQiHSH8xZI3zHJTezgZMz-pB_hPTxp8ajdv0ve1gWtWjs3vERr0Y91X4hngO8X7LuXtAYtfxGZRIye12YE7TuLBMYzj8CCfiRt7Smhyf4palNW5mzKlZpa2l87n6NQ14Iy4oMzQ2PON1j_swrosuE2yZohGOn6fDdSCBRdJ6dLD_emjBdQCQOoB63R7BbhFZgvFX25TjzFJ7r9AdVMiGmebuRKEVSZV_JCGu1C71OIbQk-UK35s00gSr2fmJGBbN2cZTXBRTJpfuMZ_ihFYEZrvVq_Ih2X0xkd36JUuxaUld1BXRgPZvH-9jBuhe0YW2OOlgwpdm6ZB8BMcuS4ftLoi6FipgzFqfIuy-0ZqPMDnJaG7Gycrdpxza00mgOFxYxJtqwZNsUWFRZEVU881l6VC_cy294YXSPQxUwEoyKg-G5Pm8AEB9bqv5z4EU4B8-XTd3zKNqtNba_snHbc711i4EytCiZfYSjNB1hwenq45YYOAhPTwOpFI0kxyRazc",
  124. * "user": {
  125. * "id": 1,
  126. * "name": "15888888888",
  127. * "email": "abcdefg@gmail.com",
  128. * "type": 2,
  129. * "phone": "15888888888",
  130. * "avatar": null,
  131. * "last_ip": null,
  132. * "created_at": "2016-09-30 00:45:13",
  133. * "updated_at": "2016-09-29 16:43:36"
  134. * }
  135. * }
  136. * }
  137. * @apiErrorExample {json} Error-Response:
  138. * HTTP/1.1 400 Bad Request
  139. */
  140. public function wechatLogin(Request $request) {
  141. $validator = Validator::make($request->all(),
  142. [
  143. 'wechat' => 'required',
  144. ],
  145. [
  146. 'wechat.required' => '微信id不存在',
  147. ]
  148. );
  149. if ($validator->fails())
  150. return $this->validatorError($validator->messages()->all(),ErrorCode::CLIENT_WRONG_PARAMS);
  151. $user = UserInfoModel::where('wechat',$request->wechat)->first();
  152. if (empty($user)) {
  153. $this->login($request,$request->wechat,'wechat');
  154. }else{
  155. $token = $user->createToken($user->phone)->accessToken;
  156. return $this->api(compact( 'user', 'code','token'));
  157. }
  158. }
  159. /**
  160. * @api {post} /api/auth/webo_login 微博登录
  161. * @apiDescription 微博登录
  162. * @apiGroup Auth
  163. * @apiPermission none
  164. * @apiVersion 0.1.0
  165. * @apiParam {string} webo 微博id
  166. * @apiSuccessExample {json} Success-Response:
  167. * HTTP/1.1 200 OK
  168. * {
  169. * "state": true,
  170. * "code": 0,
  171. * "message": "",
  172. * "data": {
  173. * "token": "eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIsImp0aSI6IjdjYWUyYzFmYTUwMTIyZDI0ZTRiYTZhZGZhNmQxYmZlOWNiMzIxMTBmYWJlZjNjYzIyNmViZjRmNGExNWM3NjllNmU2ZTNiYWE5OGNhOWUzIn0.eyJhdWQiOiIxIiwianRpIjoiN2NhZTJjMWZhNTAxMjJkMjRlNGJhNmFkZmE2ZDFiZmU5Y2IzMjExMGZhYmVmM2NjMjI2ZWJmNGY0YTE1Yzc2OWU2ZTZlM2JhYTk4Y2E5ZTMiLCJpYXQiOjE0NzU0MTE1NTgsIm5iZiI6MTQ3NTQxMTU1OCwiZXhwIjo0NjMxMDg1MTU4LCJzdWIiOiIxIiwic2NvcGVzIjpbXX0.E9YGEzuRUOk02aV1EiWLJ_pD0hKoCyW0k_sGy63hM3u5X8K_HI1kVhaU6JNLqLZeszIAroTEDB8XMgZKAqTLlwtL8PLCJcuDoxfk1BRHbfjhDheTsahBysKGalvNEpzRCrGlao0mS0Cg9qDpEsndtypPFS8sfaflToOzbJjiSK2DvQiHSH8xZI3zHJTezgZMz-pB_hPTxp8ajdv0ve1gWtWjs3vERr0Y91X4hngO8X7LuXtAYtfxGZRIye12YE7TuLBMYzj8CCfiRt7Smhyf4palNW5mzKlZpa2l87n6NQ14Iy4oMzQ2PON1j_swrosuE2yZohGOn6fDdSCBRdJ6dLD_emjBdQCQOoB63R7BbhFZgvFX25TjzFJ7r9AdVMiGmebuRKEVSZV_JCGu1C71OIbQk-UK35s00gSr2fmJGBbN2cZTXBRTJpfuMZ_ihFYEZrvVq_Ih2X0xkd36JUuxaUld1BXRgPZvH-9jBuhe0YW2OOlgwpdm6ZB8BMcuS4ftLoi6FipgzFqfIuy-0ZqPMDnJaG7Gycrdpxza00mgOFxYxJtqwZNsUWFRZEVU881l6VC_cy294YXSPQxUwEoyKg-G5Pm8AEB9bqv5z4EU4B8-XTd3zKNqtNba_snHbc711i4EytCiZfYSjNB1hwenq45YYOAhPTwOpFI0kxyRazc",
  174. * "user": {
  175. * "id": 1,
  176. * "name": "15888888888",
  177. * "email": "abcdefg@gmail.com",
  178. * "type": 2,
  179. * "phone": "15888888888",
  180. * "avatar": null,
  181. * "last_ip": null,
  182. * "created_at": "2016-09-30 00:45:13",
  183. * "updated_at": "2016-09-29 16:43:36"
  184. * }
  185. * }
  186. * }
  187. * @apiErrorExample {json} Error-Response:
  188. * HTTP/1.1 400 Bad Request
  189. */
  190. public function weboLogin(Request $request) {
  191. $validator = Validator::make($request->all(),
  192. [
  193. 'webo' => 'required',
  194. ],
  195. [
  196. 'webo.required' => '微博id不存在',
  197. ]
  198. );
  199. if ($validator->fails())
  200. return $this->validatorError($validator->messages()->all(),ErrorCode::CLIENT_WRONG_PARAMS);
  201. $user = UserInfoModel::where('webo',$request->webo)->first();
  202. if (empty($user)) {
  203. $this->login($request,$request->webo,'webo');
  204. }else{
  205. $token = $user->createToken($user->phone)->accessToken;
  206. return $this->api(compact( 'user', 'code','token'));
  207. }
  208. }
  209. /**
  210. * @api {get} /api/auth/logout 退出(logout)
  211. * @apiDescription 退出(logout)
  212. * @apiGroup Auth
  213. * @apiPermission Passport
  214. * @apiVersion 0.1.0
  215. * @apiSuccessExample {json} Success-Response:
  216. * HTTP/1.1 200 OK
  217. * {
  218. * "state": true,
  219. * "code": 0,
  220. * "message": "",
  221. * "data": {
  222. * "result": true/false
  223. * }
  224. * }
  225. * @apiErrorExample {json} Error-Response:
  226. * HTTP/1.1 400 Bad Request
  227. * {
  228. * "state": false,
  229. * "code": 1104,
  230. * "message": "退出失败",
  231. * "data": null
  232. * }
  233. * 可能出现的错误代码:
  234. * 1104 LOGOUT_FAILED 退出失败
  235. */
  236. public function logout() {
  237. $user = Auth::guard('api')->user();
  238. if ($user->token()->delete()) {
  239. return $this->api(['result' => true]);
  240. }
  241. return $this->error(ErrorCode::LOGOUT_FAILED);
  242. }
  243. /**
  244. * @api {post} /api/auth/code 获取验证码(get code)
  245. * @apiDescription 获取验证码(get code),验证码有效期暂定为15分钟
  246. * @apiGroup Auth
  247. * @apiPermission none
  248. * @apiVersion 0.1.0
  249. * @apiParam {string} phone 手机
  250. * @apiSuccessExample {json} Success-Response:
  251. * HTTP/1.1 200 OK
  252. * {
  253. * "state": true,
  254. * "code": 0,
  255. * "message": "",
  256. * "data": {
  257. * "verify_code": "1234"//该值调试时使用,sms调通后取消
  258. * }
  259. * }
  260. * @apiErrorExample {json} Error-Response:
  261. * HTTP/1.1 400 Bad Request
  262. * {
  263. * "state": false,
  264. * "code": 1000,
  265. * "message": "传入参数不正确",
  266. * "data": null or []
  267. * }
  268. * 可能出现的错误代码:
  269. * 1000 CLIENT_WRONG_PARAMS 传入参数不正确
  270. */
  271. public function getCode(Request $request)
  272. {
  273. $validator = Validator::make($request->all(),
  274. [
  275. 'phone' => 'required|regex:/^1[34578]\d{9}$/',
  276. ],
  277. [
  278. 'phone.required' => '手机号码必填',
  279. 'phone.regex' => '手机号码格式不正确',
  280. ]
  281. );
  282. if ($validator->fails())
  283. return $this->validatorError($validator->messages()->all(),ErrorCode::CLIENT_WRONG_PARAMS);
  284. $phone = $request->phone;
  285. $keyexist = $this->keySmsCodeExist . $phone;
  286. $times = Cache::store('file')->get($keyexist);
  287. if($times>20) {
  288. return $this->error(ErrorCode::VERIFY_CODE_TOO_MUCH);
  289. }else{
  290. $times++;
  291. Cache::store('file')->put($keyexist, $times, $this->expireTimeExist);
  292. }
  293. $verify_code = (string) mt_rand(1000, 9999);
  294. \Log::info('verify_code:'.$verify_code);
  295. $key = $this->keySmsCode . $phone;
  296. Cache::store('file')->put($key, $verify_code, $this->expireTime);
  297. $msg = '【喵喵】您的验证码是:' . $verify_code;
  298. /*
  299. $result = $this->sendSms($msg, $phone);
  300. if (!$result)
  301. $this->logger->Error("Send sms failed.");
  302. */
  303. return $this->api(['verify_code' => $verify_code]);
  304. }
  305. public function refreshToken() {
  306. $token = '';//TODO
  307. return $this->api([
  308. 'token' => $token,
  309. ]);
  310. }
  311. public function isLogin()
  312. {
  313. $user = Auth::user();
  314. $res = true;
  315. if(!$user) $res = false;
  316. return $this->api([
  317. 'result' => $res,
  318. ]);
  319. }
  320. /**
  321. * @api {post} /api/auth/avatar 上传头像(avatar)
  322. * @apiDescription 上传头像(reset)
  323. * @apiGroup Auth
  324. * @apiPermission Passport
  325. * @apiVersion 0.1.0
  326. * @apiParam {File} avatar 头像图片
  327. * @apiSuccessExample {json} Success-Response:
  328. * HTTP/1.1 200 OK
  329. * {
  330. * "state": true,
  331. * "code": 0,
  332. * "message": "",
  333. * "data": {
  334. * "md5": "fdf8dd78eb383b8acf6d94d4752c1424",
  335. * }
  336. * }
  337. * @apiErrorExample {json} Error-Response:
  338. * HTTP/1.1 400 Bad Request
  339. * {
  340. * "state": false,
  341. * "code": 1000,
  342. * "message": "传入参数不正确",
  343. * "data": null or []
  344. * }
  345. * 可能出现的错误代码:
  346. * 200 SAVE_USER_FAILED 保存用户数据失败
  347. * 201 ATTACHMENT_MKDIR_FAILED 创建附件目录失败
  348. * 202 ATTACHMENT_UPLOAD_INVALID 上传附件文件无效
  349. * 203 ATTACHMENT_SAVE_FAILED 保存附件失败
  350. * 204 ATTACHMENT_MOVE_FAILED 移动附件失败
  351. * 205 ATTACHMENT_DELETE_FAILED 删除附件文件失败
  352. * 206 ATTACHMENT_RECORD_DELETE_FAILED 删除附件记录失败
  353. * 1000 CLIENT_WRONG_PARAMS 传入参数不正确
  354. * 1101 INCORRECT_VERIFY_CODE 输入验证码错误
  355. * 1105 USER_DOES_NOT_EXIST 用户不存在
  356. * 1200 ATTACHMENT_UPLOAD_FAILED 附件上传失败
  357. * 1201 ATTACHMENT_SIZE_EXCEEDED 附件大小超过限制
  358. * 1202 ATTACHMENT_MIME_NOT_ALLOWED 附件类型不允许
  359. * 1203 ATTACHMENT_NOT_EXIST 附件不存在
  360. */
  361. public function avatar(Request $request) {
  362. // $user = Auth::user();
  363. $user = $this->getUser();
  364. $old_avatar = $user->avatar;
  365. $result = $this->uploadAttachment($request, 'avatar', 'avatar', 4 * 1024 * 1024, [
  366. 'image/jpeg',
  367. 'image/png',
  368. 'image/gif',
  369. ]);
  370. if (is_array($result)) {
  371. $result = array_shift($result);
  372. }
  373. if (is_string($result)) {
  374. $user->avatar = config('app.url')."api/attachment/download/".$result;
  375. if (!$user->save()) {
  376. return $this->error(ErrorCode::SAVE_USER_FAILED);
  377. }
  378. $this->deleteAttachment($old_avatar);
  379. return $this->api(['file' => $result]);
  380. }
  381. return $this->error($result);
  382. }
  383. }