AuthorizationsController.php 12 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374
  1. <?php
  2. namespace App\Http\Controllers\Api;
  3. use App\Exceptions\SmsException;
  4. use App\Models\AdminRole;
  5. use App\Models\User;
  6. use App\Services\SmsService;
  7. use App\Services\TencentImAccountService;
  8. use App\Transformers\UserTransformer;
  9. use Carbon\Carbon;
  10. use Illuminate\Http\Request;
  11. use Illuminate\Support\Facades\Auth;
  12. use Illuminate\Support\Facades\DB;
  13. use Illuminate\Support\Facades\Hash;
  14. use Illuminate\Support\Facades\Validator;
  15. class AuthorizationsController extends Controller
  16. {
  17. protected $tencentImAccountService;
  18. public function __construct(TencentImAccountService $tencentImAccountService)
  19. {
  20. $this->tencentImAccountService = $tencentImAccountService;
  21. }
  22. /**
  23. * 手机号登录
  24. * @param Request $request
  25. * @return \Illuminate\Http\JsonResponse
  26. */
  27. public function login_by_mobile(Request $request)
  28. {
  29. $validator = Validator::make($request->all(), [
  30. 'mobile' => ['required', 'regex:/^1[3456789]\d{9}$/'],
  31. 'verifyKey' => 'bail|required|string',
  32. 'smsCode' => 'bail|required',
  33. ], [
  34. 'mobile.required'=>"手机号码必须",
  35. 'mobile.regex'=>"手机号码格式错误",
  36. 'verifyKey.required'=>"验证码必须",
  37. 'smsCode.required'=>"短信验证码必须",
  38. ]);
  39. if ($validator->fails()) {
  40. return $this->response()->errorForbidden($validator->messages()->first());
  41. }
  42. // try {
  43. // //验证短信验证码
  44. // SmsService::checkSmsCodeByVerifyKey($request->verifyKey, $request->smsCode);
  45. // } catch (SmsException $e) {
  46. // abort(403, $e->getMessage());
  47. // } catch (\Exception $e) {
  48. // abort(403, '短信校验失败');
  49. // }
  50. User::firstOrCreate([
  51. 'mobile' => $request->input('mobile'),
  52. ]);
  53. $user = User::query()->where(['mobile'=>$request->input('mobile')])->first();
  54. if (!$user->ycode) {
  55. $user->ycode = $this->create_code();
  56. }
  57. if (!$user->tencent_im_user_id) {
  58. $user->tencent_im_user_id = $this->tencentImAccountService->accountImport($user);
  59. }
  60. if($user->status!=1){
  61. return $this->response->errorForbidden("用户已被禁用,请联系管理员");
  62. }
  63. $user->save();
  64. $token = Auth::guard('api')->fromUser($user);
  65. self::updateLastLogin($user, $token);
  66. $resdata['token'] = "Bearer ".$token;
  67. $resdata['sex'] = $user->sex;
  68. $resdata['password'] = $user->password?1:0;
  69. $resdata['tencent_im_user_id'] =$user->tencent_im_user_id;
  70. $resdata['mobile'] =$user->mobile;
  71. $resdata['lock_pass'] =$user->lock_pass?$user->lock_pass:false;
  72. $resdata['status'] =$user->status;
  73. $resdata['is_auth'] =$user->is_auth;
  74. $resdata['ycode'] =$user->ycode;
  75. $resdata['online'] =$user->online;
  76. $resdata['notice_status'] =$user->notice_status;
  77. return response()->json($resdata);
  78. }
  79. public function captcha(){
  80. return response(captcha_src());
  81. }
  82. /**
  83. * 根据用户ID生成唯一邀请码
  84. * @param $user_id
  85. * @return string
  86. */
  87. public function create_code() {
  88. $code = create_invite_code();
  89. if(User::where(['ycode'=>$code])->first()){
  90. $code = create_invite_code();
  91. }
  92. return $code;
  93. }
  94. /**
  95. * 用户账号密码登录
  96. * @param Request $request
  97. * @return \Illuminate\Http\JsonResponse|void
  98. */
  99. public function login_by_account_password(Request $request)
  100. {
  101. $validator = Validator::make($request->all(), [
  102. 'mobile' => ['required', 'regex:/^1[3456789]\d{9}$/'],
  103. 'password' => 'required|string',
  104. ],[
  105. 'mobile.required'=>"手机号码必须",
  106. 'mobile.regex'=>"手机号码格式错误",
  107. 'password.required'=>"密码必须",
  108. ]);
  109. if ($validator->fails()) {
  110. return $this->response()->errorForbidden($validator->messages()->first());
  111. }
  112. if (!$user=User::where(['mobile' => $request->mobile])->first()) {
  113. return $this->response->errorForbidden('用户不存在!');
  114. }
  115. $credentials = $request->only('mobile', 'password');
  116. if (!$token = auth('api')->attempt($credentials)) {
  117. return $this->response->errorForbidden ('用户名或密码错误');
  118. }
  119. if($user->status!=1){
  120. return $this->response->errorForbidden("用户已被禁用,请联系管理员");
  121. }
  122. if (!$user->ycode) {
  123. $user->ycode = $this->create_code();
  124. }
  125. if (!$user->tencent_im_user_id) {
  126. $user->tencent_im_user_id = $this->tencentImAccountService->accountImport($user);
  127. }
  128. $user->save();
  129. self::updateLastLogin($user, $token);
  130. $resdata['token'] = "Bearer ".$token;
  131. $resdata['sex'] = $user->sex;
  132. $resdata['password'] = $user->password?1:0;
  133. $resdata['tencent_im_user_id'] =$user->tencent_im_user_id;
  134. $resdata['mobile'] =$user->mobile;
  135. $resdata['lock_pass'] =$user->lock_pass?$user->lock_pass:false;
  136. $resdata['status'] =$user->status;
  137. $resdata['is_auth'] =$user->is_auth;
  138. $resdata['ycode'] =$user->ycode;
  139. $resdata['online'] =$user->online;
  140. $resdata['notice_status'] =$user->notice_status;
  141. return response()->json($resdata);
  142. }
  143. /**
  144. * 注册账号
  145. */
  146. public function register(Request $request){
  147. $validator = Validator::make($request->all(), [
  148. 'mobile' => ['required', 'regex:/^1[3456789]\d{9}$/'],
  149. 'password' => 'bail|required',
  150. ],[
  151. 'mobile.required'=>"手机号码必须",
  152. 'mobile.regex'=>"手机号码格式错误",
  153. 'password.required'=>"密码必须",
  154. ]);
  155. if ($validator->fails()){
  156. return $this->response()->errorForbidden($validator->messages()->first());
  157. }
  158. if(User::where(['mobile'=>$request->mobile])->first()){
  159. return $this->response->errorForbidden("该手机号码已使用");
  160. }
  161. $ins = array();
  162. $ins['mobile'] = $request->mobile;
  163. $ins['password'] = $request->password;
  164. if(User::create($ins)){
  165. return response()->json(['message'=>"注册成功"]);
  166. }else{
  167. return $this->response->errorForbidden("注册失败");
  168. }
  169. }
  170. public function reg_h5(Request $request){
  171. $validator = Validator::make($request->all(), [
  172. 'mobile' => ['required', 'regex:/^1[3456789]\d{9}$/'],
  173. 'password' => 'bail|required',
  174. 'smsCode' => 'bail|required',
  175. ],[
  176. 'mobile.required'=>"手机号码必须",
  177. 'mobile.regex'=>"手机号码格式错误",
  178. 'password.required'=>"密码必须",
  179. 'smsCode.required'=>"短信验证码必须",
  180. ]);
  181. if ($validator->fails()){
  182. return response()->json([
  183. 'code'=>0,
  184. 'message'=>$validator->messages()->first()
  185. ]);
  186. }
  187. // try {
  188. // //验证短信验证码
  189. // SmsService::checkSmsCodeByVerifyKey($request->verifyKey, $request->smsCode);
  190. // } catch (SmsException $e) {
  191. // return response()->json([
  192. // 'code'=>0,
  193. // 'message'=>$e->getMessage()
  194. // ]);
  195. // } catch (\Exception $e) {
  196. // return response()->json([
  197. // 'code'=>0,
  198. // 'message'=>'短信校验失败'
  199. // ]);
  200. // }
  201. if(User::where(['mobile'=>$request->mobile])->first()){
  202. return response()->json([
  203. 'code'=>0,
  204. 'message'=>'该手机号码已使用'
  205. ]);
  206. }
  207. //邀请码设置
  208. $pid = 0;
  209. if(isset($request->ycode) && $request->ycode!=""){
  210. if(!$puser = User::where(['ycode'=>$request->ycode])->first()){
  211. return response()->json([
  212. 'code'=>0,
  213. 'message'=>'邀请码不存在'
  214. ]);
  215. }
  216. $pid = $puser->id;
  217. }
  218. $ins = array();
  219. $ins['mobile'] = $request->mobile;
  220. $ins['password'] = $request->password;
  221. $ins['pid'] = $pid;
  222. if(User::create($ins)){
  223. return response()->json([
  224. 'code'=>1,
  225. 'message'=>'注册成功'
  226. ]);
  227. }else{
  228. return response()->json([
  229. 'code'=>0,
  230. 'message'=>'注册失败'
  231. ]);
  232. }
  233. }
  234. /**
  235. * 忘记密码
  236. */
  237. public function forget_password(Request $request){
  238. $validator = Validator::make($request->all(), [
  239. 'mobile' => ['required', 'regex:/^1[3456789]\d{9}$/'],
  240. 'verifyKey' => 'bail|required|string',
  241. 'smsCode' => 'bail|required',
  242. 'password' => 'bail|required',
  243. ],[
  244. 'mobile.required'=>"手机号码必须",
  245. 'mobile.regex'=>"手机号码格式错误",
  246. 'verifyKey.required'=>"验证码必须",
  247. 'smsCode.required'=>"短信验证码必须",
  248. 'password.required'=>"密码必须",
  249. ]);
  250. if ($validator->fails()) {
  251. return $this->response()->errorForbidden($validator->messages()->first());
  252. }
  253. try {
  254. //验证短信验证码
  255. SmsService::checkSmsCodeByVerifyKey($request->verifyKey, $request->smsCode);
  256. } catch (SmsException $e) {
  257. abort(403, $e->getMessage());
  258. } catch (\Exception $e) {
  259. abort(403, '短信校验失败');
  260. }
  261. $user = User::where(['mobile'=>$request->mobile])->first();
  262. $user->password =$request->password;// Hash::make($request->password);
  263. if($user->save()){
  264. return $this->response->noContent();
  265. }
  266. }
  267. /**
  268. * 用户协议
  269. */
  270. public function xieyi(Request $request){
  271. if(isset($request->cont) && $request->cont==1){
  272. $data = DB::table("document")->where(['id'=>$request->id])->first();
  273. return response()->json(['data'=>$data]);
  274. }else{
  275. $url = "https://".$_SERVER['HTTP_HOST']."/xieyi/content.html?id=1";
  276. $url2 = "https://".$_SERVER['HTTP_HOST']."/xieyi/content.html?id=2";
  277. return response()->json(['url1'=>$url,'url2'=>$url2]);
  278. }
  279. }
  280. /**
  281. * Get the authenticated User.
  282. *
  283. * @return \Illuminate\Http\JsonResponse
  284. */
  285. public function me()
  286. {
  287. $user = auth('api')->user();
  288. return $this->response->item($user, new UserTransformer());
  289. }
  290. /**
  291. * Log the user out (Invalidate the token).
  292. *
  293. * @return \Illuminate\Http\JsonResponse
  294. */
  295. public function logout()
  296. {
  297. auth('api')->logout();
  298. return response()->json(['message' => '退出成功!']);
  299. }
  300. /**
  301. * Refresh a token.
  302. * 刷新token,如果开启黑名单,以前的token便会失效。
  303. * 值得注意的是用上面的getToken再获取一次Token并不算做刷新,两次获得的Token是并行的,即两个都可用。
  304. * @return \Illuminate\Http\JsonResponse
  305. */
  306. public function refresh()
  307. {
  308. return $this->respondWithToken(Auth::guard('api')->refresh());
  309. }
  310. static public function updateLastLogin(User $user, string $jwtToken)
  311. {
  312. $user->remember_token = $jwtToken;
  313. $user->last_login_time = Carbon::now();
  314. $user->last_login_ip = request()->ip();
  315. $user->save();
  316. }
  317. /**
  318. * Get the token array structure.
  319. *
  320. * @param string $token
  321. *
  322. * @return \Illuminate\Http\JsonResponse
  323. */
  324. protected function respondWithToken($token)
  325. {
  326. return response()->json([
  327. 'access_token' => $token,
  328. 'token_type' => 'Bearer',
  329. 'expires_in' => Auth::guard('api')->factory()->getTTL() * 60
  330. ]);
  331. }
  332. }