AuthorizationsController.php 13 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404
  1. <?php
  2. namespace App\Http\Controllers\Api;
  3. use App\Exceptions\SmsException;
  4. use App\Models\AdminRole;
  5. use App\Models\User;
  6. use App\Models\UserInfoModel;
  7. use App\Models\UserInviteLog;
  8. use App\Models\UserVipLimit;
  9. use App\Services\JPushService;
  10. use App\Services\SmsService;
  11. use App\Services\TencentImAccountService;
  12. use App\Transformers\UserTransformer;
  13. use Carbon\Carbon;
  14. use http\Env\Response;
  15. use Illuminate\Http\Request;
  16. use Illuminate\Support\Facades\Auth;
  17. use Illuminate\Support\Facades\DB;
  18. use Illuminate\Support\Facades\Hash;
  19. use Illuminate\Support\Facades\Validator;
  20. use PHPUnit\Util\Exception;
  21. class AuthorizationsController extends Controller
  22. {
  23. protected $tencentImAccountService;
  24. public function __construct(TencentImAccountService $tencentImAccountService)
  25. {
  26. $this->tencentImAccountService = $tencentImAccountService;
  27. }
  28. /**
  29. * 极光认证一键登录
  30. */
  31. public function auth_login(Request $request){
  32. try {
  33. if(empty($request->loginToken)){
  34. throw new Exception("参数错误");
  35. }
  36. $loginToken = $request->loginToken;
  37. $exID = $request->post('exID','800');
  38. $ret = JPushService::jgLoginTokenVerify($loginToken,$exID);
  39. $mobile = JPushService::jgOpensslPrivateDecrypt($ret['phone']);
  40. $res = $this->do_login($mobile);
  41. }catch (\Exception $exception){
  42. return $this->response->errorForbidden($exception->getMessage());
  43. }
  44. return response()->json($res);
  45. }
  46. /**
  47. * 手机号登录
  48. * @param Request $request
  49. * @return \Illuminate\Http\JsonResponse
  50. */
  51. public function login_by_mobile(Request $request)
  52. {
  53. try {
  54. $validator = Validator::make($request->all(), [
  55. 'mobile' => ['required', 'regex:/^1[3456789]\d{9}$/'],
  56. 'verifyKey' => 'bail|required|string',
  57. 'smsCode' => 'bail|required',
  58. ], [
  59. 'mobile.required'=>"手机号码必须",
  60. 'mobile.regex'=>"手机号码格式错误",
  61. 'verifyKey.required'=>"验证码必须",
  62. 'smsCode.required'=>"短信验证码必须",
  63. ]);
  64. if ($validator->fails()) {
  65. return $this->response()->errorForbidden($validator->messages()->first());
  66. }
  67. //验证短信验证码
  68. SmsService::checkSmsCodeByVerifyKey($request->verifyKey, $request->smsCode);
  69. $res = $this->do_login($request->mobile);
  70. }catch (\Exception $exception){
  71. return $this->response->errorForbidden($exception->getMessage());
  72. } catch (SmsException $e) {
  73. return $this->response->errorForbidden($e->getMessage());
  74. }
  75. return response()->json($res);
  76. }
  77. /**
  78. * 用户账号密码登录
  79. * @param Request $request
  80. * @return \Illuminate\Http\JsonResponse|void
  81. */
  82. public function login_by_account_password(Request $request)
  83. {
  84. try {
  85. $validator = Validator::make($request->all(), [
  86. 'mobile' => ['required', 'regex:/^1[3456789]\d{9}$/'],
  87. 'password' => 'required|string',
  88. ],[
  89. 'mobile.required'=>"手机号码必须",
  90. 'mobile.regex'=>"手机号码格式错误",
  91. 'password.required'=>"密码必须",
  92. ]);
  93. if ($validator->fails()) {
  94. throw new Exception($validator->messages()->first());
  95. }
  96. $res = $this->do_login($request->mobile,$request->password);
  97. }catch (\Exception $exception){
  98. return $this->response->errorForbidden($exception->getMessage());
  99. }
  100. return response()->json($res);
  101. }
  102. //登录操作
  103. public function do_login($mobile,$password=null){
  104. if(!empty($password)){
  105. if (!$user=User::query()->where(['mobile' => $mobile])->whereNull('deleted_at')->first()) {
  106. throw new Exception("用户不存在");
  107. }
  108. $credentials = ['mobile'=>$mobile,'password'=>$password];
  109. if (!auth('api')->attempt($credentials)) {
  110. throw new Exception("用户名或密码错误");
  111. }
  112. }else{
  113. User::firstOrCreate([
  114. 'mobile' => $mobile,
  115. ]);
  116. $user = User::query()->where(['mobile'=>$mobile])->whereNull('deleted_at')->first();
  117. }
  118. if (!$user->ycode) {
  119. $user->ycode = $this->create_code();
  120. }
  121. if(!UserInfoModel::query()->where('user_id',$user->id)->first()){
  122. UserInfoModel::query()->firstOrCreate([
  123. 'user_id'=>$user->id,
  124. 'avatar'=>"https://zhengda.oss-cn-chengdu.aliyuncs.com/chengluApp/default.jpg",
  125. 'nickname'=>"用户".$user->mobile,
  126. 'birthday'=>"1990-01-01"
  127. ]);
  128. }
  129. if(!UserVipLimit::query()->where('user_id',$user->id)->first()){
  130. UserVipLimit::query()->create([
  131. 'user_id'=>$user->id,
  132. ]);
  133. }
  134. if (!$user->tencent_im_user_id) {
  135. $user->tencent_im_user_id = $this->tencentImAccountService->accountImport($user);
  136. }
  137. if($user->status!=1){
  138. throw new Exception("用户已被禁用,请联系管理员");
  139. }
  140. $token = Auth::guard('api')->fromUser($user);
  141. $user->remember_token = $token;
  142. $user->last_login_time = Carbon::now();
  143. $user->last_login_ip = request()->ip();
  144. $user->save();
  145. $resdata['token'] = "Bearer ".$token;
  146. $resdata['sex'] = $user->sex;
  147. $resdata['password'] = $user->password?1:0;
  148. $resdata['tencent_im_user_id'] =$user->tencent_im_user_id;
  149. $resdata['mobile'] =$user->mobile;
  150. $resdata['lock_pass'] =$user->lock_pass?$user->lock_pass:false;
  151. $resdata['status'] =$user->status;
  152. $resdata['is_auth'] =$user->is_auth;
  153. $resdata['ycode'] =$user->ycode;
  154. $resdata['online'] =$user->online;
  155. $resdata['notice_status'] =$user->notice_status;
  156. return $resdata;
  157. }
  158. public function captcha(){
  159. return response(captcha_src());
  160. }
  161. /**
  162. * 根据用户ID生成唯一邀请码
  163. * @param $user_id
  164. * @return string
  165. */
  166. public function create_code() {
  167. $code = create_invite_code();
  168. if(User::where(['ycode'=>$code])->first()){
  169. $code = create_invite_code();
  170. }
  171. return $code;
  172. }
  173. /**
  174. * 注册账号
  175. */
  176. public function register(Request $request){
  177. $validator = Validator::make($request->all(), [
  178. 'mobile' => ['required', 'regex:/^1[3456789]\d{9}$/'],
  179. 'password' => 'bail|required',
  180. ],[
  181. 'mobile.required'=>"手机号码必须",
  182. 'mobile.regex'=>"手机号码格式错误",
  183. 'password.required'=>"密码必须",
  184. ]);
  185. if ($validator->fails()){
  186. return $this->response()->errorForbidden($validator->messages()->first());
  187. }
  188. if(User::where(['mobile'=>$request->mobile])->first()){
  189. return $this->response->errorForbidden("该手机号码已使用");
  190. }
  191. $ins = array();
  192. $ins['mobile'] = $request->mobile;
  193. $ins['password'] = $request->password;
  194. if(User::create($ins)){
  195. return response()->json(['message'=>"注册成功"]);
  196. }else{
  197. return $this->response->errorForbidden("注册失败");
  198. }
  199. }
  200. public function reg_h5(Request $request){
  201. $validator = Validator::make($request->all(), [
  202. 'mobile' => ['required', 'regex:/^1[3456789]\d{9}$/'],
  203. 'password' => 'bail|required',
  204. 'smsCode' => 'bail|required',
  205. ],[
  206. 'mobile.required'=>"手机号码必须",
  207. 'mobile.regex'=>"手机号码格式错误",
  208. 'password.required'=>"密码必须",
  209. 'smsCode.required'=>"短信验证码必须",
  210. ]);
  211. if ($validator->fails()){
  212. return response()->json([
  213. 'code'=>0,
  214. 'message'=>$validator->messages()->first()
  215. ]);
  216. }
  217. DB::beginTransaction();
  218. try {
  219. //验证短信验证码
  220. SmsService::checkSmsCodeByVerifyKey($request->verifyKey, $request->smsCode);
  221. if(User::where(['mobile'=>$request->mobile])->first()){
  222. throw new Exception("该手机号码已使用");
  223. }
  224. //邀请码设置
  225. $pid = 0;
  226. if(isset($request->ycode) && $request->ycode!=""){
  227. if(!$puser = User::where(['ycode'=>$request->ycode])->first()){
  228. throw new Exception("邀请码不存在");
  229. }
  230. $pid = $puser->id;
  231. }
  232. $ins = array();
  233. $ins['mobile'] = $request->mobile;
  234. $ins['password'] = $request->password;
  235. $ins['pid'] = $pid;
  236. $ins['created_at'] = date('Y-m-d H:i:s');
  237. $ins['updated_at'] = date('Y-m-d H:i:s');
  238. $insid = User::query()->insertGetId($ins);
  239. //赠送会员天数
  240. UserInviteLog::query()->create([
  241. 'user_id'=>$pid,
  242. 'invite_id'=>$insid,
  243. 'day'=>1,
  244. 'status'=>0,
  245. ]);
  246. DB::commit();
  247. } catch (SmsException $e) {
  248. DB::rollBack();
  249. return response()->json([
  250. 'code'=>0,
  251. 'message'=>$e->getMessage()
  252. ]);
  253. } catch (\Exception $e) {
  254. DB::rollBack();
  255. return response()->json([
  256. 'code'=>0,
  257. 'message'=>'短信校验失败'
  258. ]);
  259. }
  260. return response()->json([
  261. 'code'=>1,
  262. 'message'=>'注册成功'
  263. ]);
  264. }
  265. /**
  266. * 忘记密码
  267. */
  268. public function forget_password(Request $request){
  269. try {
  270. $validator = Validator::make($request->all(), [
  271. 'mobile' => ['required', 'regex:/^1[3456789]\d{9}$/'],
  272. 'verifyKey' => 'bail|required|string',
  273. 'smsCode' => 'bail|required',
  274. 'password' => 'bail|required',
  275. ],[
  276. 'mobile.required'=>"手机号码必须",
  277. 'mobile.regex'=>"手机号码格式错误",
  278. 'verifyKey.required'=>"验证码必须",
  279. 'smsCode.required'=>"短信验证码必须",
  280. 'password.required'=>"密码必须",
  281. ]);
  282. if ($validator->fails()) {
  283. throw new Exception($validator->messages()->first());
  284. }
  285. //验证短信验证码
  286. SmsService::checkSmsCodeByVerifyKey($request->verifyKey, $request->smsCode);
  287. $user = User::where(['mobile'=>$request->mobile])->first();
  288. $user->password =$request->password;// Hash::make($request->password);
  289. if(!$user->save()){
  290. throw new Exception("设置失败");
  291. }
  292. $res = $this->do_login($request->mobile,$request->password);
  293. }catch (\Exception $exception){
  294. return $this->response->errorForbidden($exception->getMessage());
  295. } catch (SmsException $e) {
  296. return $this->response->errorForbidden($e->getMessage());
  297. }
  298. return response()->json($res);
  299. }
  300. /**
  301. * 用户协议
  302. */
  303. public function xieyi(Request $request){
  304. if(isset($request->cont) && $request->cont==1){
  305. $data = DB::table("document")->where(['id'=>$request->id])->first();
  306. return response()->json(['data'=>$data]);
  307. }else{
  308. $url = "https://".$_SERVER['HTTP_HOST']."/xieyi/content.html?id=1";
  309. $url2 = "https://".$_SERVER['HTTP_HOST']."/xieyi/content.html?id=2";
  310. return response()->json(['url1'=>$url,'url2'=>$url2]);
  311. }
  312. }
  313. /**
  314. * Get the authenticated User.
  315. *
  316. * @return \Illuminate\Http\JsonResponse
  317. */
  318. public function me()
  319. {
  320. $user = auth('api')->user();
  321. return $this->response->item($user, new UserTransformer());
  322. }
  323. /**
  324. * Log the user out (Invalidate the token).
  325. *
  326. * @return \Illuminate\Http\JsonResponse
  327. */
  328. public function logout()
  329. {
  330. auth('api')->logout();
  331. return response()->json(['message' => '退出成功!']);
  332. }
  333. /**
  334. * Refresh a token.
  335. * 刷新token,如果开启黑名单,以前的token便会失效。
  336. * 值得注意的是用上面的getToken再获取一次Token并不算做刷新,两次获得的Token是并行的,即两个都可用。
  337. * @return \Illuminate\Http\JsonResponse
  338. */
  339. public function refresh()
  340. {
  341. return $this->respondWithToken(Auth::guard('api')->refresh());
  342. }
  343. static public function updateLastLogin(User $user, string $jwtToken)
  344. {
  345. $user->remember_token = $jwtToken;
  346. $user->last_login_time = Carbon::now();
  347. $user->last_login_ip = request()->ip();
  348. $user->save();
  349. }
  350. /**
  351. * Get the token array structure.
  352. *
  353. * @param string $token
  354. *
  355. * @return \Illuminate\Http\JsonResponse
  356. */
  357. protected function respondWithToken($token)
  358. {
  359. return response()->json([
  360. 'access_token' => $token,
  361. 'token_type' => 'Bearer',
  362. 'expires_in' => Auth::guard('api')->factory()->getTTL() * 60
  363. ]);
  364. }
  365. }