AuthorizationsController.php 12 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384
  1. <?php
  2. namespace App\Http\Controllers\Api;
  3. use App\Exceptions\SmsException;
  4. use App\Models\AdminRole;
  5. use App\Models\User;
  6. use App\Models\UserInfoModel;
  7. use App\Models\UserInviteLog;
  8. use App\Services\SmsService;
  9. use App\Services\TencentImAccountService;
  10. use App\Transformers\UserTransformer;
  11. use Carbon\Carbon;
  12. use Illuminate\Http\Request;
  13. use Illuminate\Support\Facades\Auth;
  14. use Illuminate\Support\Facades\DB;
  15. use Illuminate\Support\Facades\Hash;
  16. use Illuminate\Support\Facades\Validator;
  17. use PHPUnit\Util\Exception;
  18. class AuthorizationsController extends Controller
  19. {
  20. protected $tencentImAccountService;
  21. public function __construct(TencentImAccountService $tencentImAccountService)
  22. {
  23. $this->tencentImAccountService = $tencentImAccountService;
  24. }
  25. /**
  26. * 手机号登录
  27. * @param Request $request
  28. * @return \Illuminate\Http\JsonResponse
  29. */
  30. public function login_by_mobile(Request $request)
  31. {
  32. $validator = Validator::make($request->all(), [
  33. 'mobile' => ['required', 'regex:/^1[3456789]\d{9}$/'],
  34. 'verifyKey' => 'bail|required|string',
  35. 'smsCode' => 'bail|required',
  36. ], [
  37. 'mobile.required'=>"手机号码必须",
  38. 'mobile.regex'=>"手机号码格式错误",
  39. 'verifyKey.required'=>"验证码必须",
  40. 'smsCode.required'=>"短信验证码必须",
  41. ]);
  42. if ($validator->fails()) {
  43. return $this->response()->errorForbidden($validator->messages()->first());
  44. }
  45. try {
  46. //验证短信验证码
  47. SmsService::checkSmsCodeByVerifyKey($request->verifyKey, $request->smsCode);
  48. } catch (SmsException $e) {
  49. abort(403, $e->getMessage());
  50. } catch (\Exception $e) {
  51. abort(403, '短信校验失败');
  52. }
  53. User::firstOrCreate([
  54. 'mobile' => $request->input('mobile'),
  55. ]);
  56. $user = User::query()->where(['mobile'=>$request->input('mobile')])->first();
  57. if (!$user->ycode) {
  58. $user->ycode = $this->create_code();
  59. }
  60. if(!UserInfoModel::query()->where('user_id',$user->id)->first()){
  61. UserInfoModel::query()->firstOrCreate(['user_id'=>$user->id]);
  62. }
  63. if (!$user->tencent_im_user_id) {
  64. $user->tencent_im_user_id = $this->tencentImAccountService->accountImport($user);
  65. }
  66. if($user->status!=1){
  67. return $this->response->errorForbidden("用户已被禁用,请联系管理员");
  68. }
  69. $user->save();
  70. $token = Auth::guard('api')->fromUser($user);
  71. self::updateLastLogin($user, $token);
  72. $resdata['token'] = "Bearer ".$token;
  73. $resdata['sex'] = $user->sex;
  74. $resdata['password'] = $user->password?1:0;
  75. $resdata['tencent_im_user_id'] =$user->tencent_im_user_id;
  76. $resdata['mobile'] =$user->mobile;
  77. $resdata['lock_pass'] =$user->lock_pass?$user->lock_pass:false;
  78. $resdata['status'] =$user->status;
  79. $resdata['is_auth'] =$user->is_auth;
  80. $resdata['ycode'] =$user->ycode;
  81. $resdata['online'] =$user->online;
  82. $resdata['notice_status'] =$user->notice_status;
  83. return response()->json($resdata);
  84. }
  85. public function captcha(){
  86. return response(captcha_src());
  87. }
  88. /**
  89. * 根据用户ID生成唯一邀请码
  90. * @param $user_id
  91. * @return string
  92. */
  93. public function create_code() {
  94. $code = create_invite_code();
  95. if(User::where(['ycode'=>$code])->first()){
  96. $code = create_invite_code();
  97. }
  98. return $code;
  99. }
  100. /**
  101. * 用户账号密码登录
  102. * @param Request $request
  103. * @return \Illuminate\Http\JsonResponse|void
  104. */
  105. public function login_by_account_password(Request $request)
  106. {
  107. $validator = Validator::make($request->all(), [
  108. 'mobile' => ['required', 'regex:/^1[3456789]\d{9}$/'],
  109. 'password' => 'required|string',
  110. ],[
  111. 'mobile.required'=>"手机号码必须",
  112. 'mobile.regex'=>"手机号码格式错误",
  113. 'password.required'=>"密码必须",
  114. ]);
  115. if ($validator->fails()) {
  116. return $this->response()->errorForbidden($validator->messages()->first());
  117. }
  118. if (!$user=User::where(['mobile' => $request->mobile])->first()) {
  119. return $this->response->errorForbidden('用户不存在!');
  120. }
  121. $credentials = $request->only('mobile', 'password');
  122. if (!$token = auth('api')->attempt($credentials)) {
  123. return $this->response->errorForbidden ('用户名或密码错误');
  124. }
  125. if($user->status!=1){
  126. return $this->response->errorForbidden("用户已被禁用,请联系管理员");
  127. }
  128. if(!UserInfoModel::query()->where('user_id',$user->id)->first()){
  129. UserInfoModel::query()->firstOrCreate(['user_id'=>$user->id]);
  130. }
  131. if (!$user->ycode) {
  132. $user->ycode = $this->create_code();
  133. }
  134. if (!$user->tencent_im_user_id) {
  135. $user->tencent_im_user_id = $this->tencentImAccountService->accountImport($user);
  136. }
  137. $user->save();
  138. self::updateLastLogin($user, $token);
  139. $resdata['token'] = "Bearer ".$token;
  140. $resdata['sex'] = $user->sex;
  141. $resdata['password'] = $user->password?1:0;
  142. $resdata['tencent_im_user_id'] =$user->tencent_im_user_id;
  143. $resdata['mobile'] =$user->mobile;
  144. $resdata['lock_pass'] =$user->lock_pass?$user->lock_pass:false;
  145. $resdata['status'] =$user->status;
  146. $resdata['is_auth'] =$user->is_auth;
  147. $resdata['ycode'] =$user->ycode;
  148. $resdata['online'] =$user->online;
  149. $resdata['notice_status'] =$user->notice_status;
  150. return response()->json($resdata);
  151. }
  152. /**
  153. * 注册账号
  154. */
  155. public function register(Request $request){
  156. $validator = Validator::make($request->all(), [
  157. 'mobile' => ['required', 'regex:/^1[3456789]\d{9}$/'],
  158. 'password' => 'bail|required',
  159. ],[
  160. 'mobile.required'=>"手机号码必须",
  161. 'mobile.regex'=>"手机号码格式错误",
  162. 'password.required'=>"密码必须",
  163. ]);
  164. if ($validator->fails()){
  165. return $this->response()->errorForbidden($validator->messages()->first());
  166. }
  167. if(User::where(['mobile'=>$request->mobile])->first()){
  168. return $this->response->errorForbidden("该手机号码已使用");
  169. }
  170. $ins = array();
  171. $ins['mobile'] = $request->mobile;
  172. $ins['password'] = $request->password;
  173. if(User::create($ins)){
  174. return response()->json(['message'=>"注册成功"]);
  175. }else{
  176. return $this->response->errorForbidden("注册失败");
  177. }
  178. }
  179. public function reg_h5(Request $request){
  180. $validator = Validator::make($request->all(), [
  181. 'mobile' => ['required', 'regex:/^1[3456789]\d{9}$/'],
  182. 'password' => 'bail|required',
  183. 'smsCode' => 'bail|required',
  184. ],[
  185. 'mobile.required'=>"手机号码必须",
  186. 'mobile.regex'=>"手机号码格式错误",
  187. 'password.required'=>"密码必须",
  188. 'smsCode.required'=>"短信验证码必须",
  189. ]);
  190. if ($validator->fails()){
  191. return response()->json([
  192. 'code'=>0,
  193. 'message'=>$validator->messages()->first()
  194. ]);
  195. }
  196. DB::beginTransaction();
  197. try {
  198. //验证短信验证码
  199. SmsService::checkSmsCodeByVerifyKey($request->verifyKey, $request->smsCode);
  200. if(User::where(['mobile'=>$request->mobile])->first()){
  201. throw new Exception("该手机号码已使用");
  202. }
  203. //邀请码设置
  204. $pid = 0;
  205. if(isset($request->ycode) && $request->ycode!=""){
  206. if(!$puser = User::where(['ycode'=>$request->ycode])->first()){
  207. throw new Exception("邀请码不存在");
  208. }
  209. $pid = $puser->id;
  210. }
  211. $ins = array();
  212. $ins['mobile'] = $request->mobile;
  213. $ins['password'] = $request->password;
  214. $ins['pid'] = $pid;
  215. $ins['created_at'] = date('Y-m-d H:i:s');
  216. $ins['updated_at'] = date('Y-m-d H:i:s');
  217. $insid = User::query()->insertGetId($ins);
  218. //赠送会员天数
  219. UserInviteLog::query()->create([
  220. 'user_id'=>$pid,
  221. 'invite_id'=>$insid,
  222. 'day'=>1,
  223. 'status'=>0,
  224. ]);
  225. DB::commit();
  226. } catch (SmsException $e) {
  227. DB::rollBack();
  228. return response()->json([
  229. 'code'=>0,
  230. 'message'=>$e->getMessage()
  231. ]);
  232. } catch (\Exception $e) {
  233. DB::rollBack();
  234. return response()->json([
  235. 'code'=>0,
  236. 'message'=>'短信校验失败'
  237. ]);
  238. }
  239. return response()->json([
  240. 'code'=>1,
  241. 'message'=>'注册成功'
  242. ]);
  243. }
  244. /**
  245. * 忘记密码
  246. */
  247. public function forget_password(Request $request){
  248. $validator = Validator::make($request->all(), [
  249. 'mobile' => ['required', 'regex:/^1[3456789]\d{9}$/'],
  250. 'verifyKey' => 'bail|required|string',
  251. 'smsCode' => 'bail|required',
  252. 'password' => 'bail|required',
  253. ],[
  254. 'mobile.required'=>"手机号码必须",
  255. 'mobile.regex'=>"手机号码格式错误",
  256. 'verifyKey.required'=>"验证码必须",
  257. 'smsCode.required'=>"短信验证码必须",
  258. 'password.required'=>"密码必须",
  259. ]);
  260. if ($validator->fails()) {
  261. return $this->response()->errorForbidden($validator->messages()->first());
  262. }
  263. try {
  264. //验证短信验证码
  265. SmsService::checkSmsCodeByVerifyKey($request->verifyKey, $request->smsCode);
  266. } catch (SmsException $e) {
  267. abort(403, $e->getMessage());
  268. } catch (\Exception $e) {
  269. abort(403, '短信校验失败');
  270. }
  271. $user = User::where(['mobile'=>$request->mobile])->first();
  272. $user->password =$request->password;// Hash::make($request->password);
  273. if($user->save()){
  274. return $this->response->noContent();
  275. }
  276. }
  277. /**
  278. * 用户协议
  279. */
  280. public function xieyi(Request $request){
  281. if(isset($request->cont) && $request->cont==1){
  282. $data = DB::table("document")->where(['id'=>$request->id])->first();
  283. return response()->json(['data'=>$data]);
  284. }else{
  285. $url = "https://".$_SERVER['HTTP_HOST']."/xieyi/content.html?id=1";
  286. $url2 = "https://".$_SERVER['HTTP_HOST']."/xieyi/content.html?id=2";
  287. return response()->json(['url1'=>$url,'url2'=>$url2]);
  288. }
  289. }
  290. /**
  291. * Get the authenticated User.
  292. *
  293. * @return \Illuminate\Http\JsonResponse
  294. */
  295. public function me()
  296. {
  297. $user = auth('api')->user();
  298. return $this->response->item($user, new UserTransformer());
  299. }
  300. /**
  301. * Log the user out (Invalidate the token).
  302. *
  303. * @return \Illuminate\Http\JsonResponse
  304. */
  305. public function logout()
  306. {
  307. auth('api')->logout();
  308. return response()->json(['message' => '退出成功!']);
  309. }
  310. /**
  311. * Refresh a token.
  312. * 刷新token,如果开启黑名单,以前的token便会失效。
  313. * 值得注意的是用上面的getToken再获取一次Token并不算做刷新,两次获得的Token是并行的,即两个都可用。
  314. * @return \Illuminate\Http\JsonResponse
  315. */
  316. public function refresh()
  317. {
  318. return $this->respondWithToken(Auth::guard('api')->refresh());
  319. }
  320. static public function updateLastLogin(User $user, string $jwtToken)
  321. {
  322. $user->remember_token = $jwtToken;
  323. $user->last_login_time = Carbon::now();
  324. $user->last_login_ip = request()->ip();
  325. $user->save();
  326. }
  327. /**
  328. * Get the token array structure.
  329. *
  330. * @param string $token
  331. *
  332. * @return \Illuminate\Http\JsonResponse
  333. */
  334. protected function respondWithToken($token)
  335. {
  336. return response()->json([
  337. 'access_token' => $token,
  338. 'token_type' => 'Bearer',
  339. 'expires_in' => Auth::guard('api')->factory()->getTTL() * 60
  340. ]);
  341. }
  342. }