AuthorizationsController.php 13 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397
  1. <?php
  2. namespace App\Http\Controllers\Api;
  3. use App\Exceptions\SmsException;
  4. use App\Models\AdminRole;
  5. use App\Models\User;
  6. use App\Models\UserInfoModel;
  7. use App\Models\UserInviteLog;
  8. use App\Services\JPushService;
  9. use App\Services\SmsService;
  10. use App\Services\TencentImAccountService;
  11. use App\Transformers\UserTransformer;
  12. use Carbon\Carbon;
  13. use http\Env\Response;
  14. use Illuminate\Http\Request;
  15. use Illuminate\Support\Facades\Auth;
  16. use Illuminate\Support\Facades\DB;
  17. use Illuminate\Support\Facades\Hash;
  18. use Illuminate\Support\Facades\Validator;
  19. use PHPUnit\Util\Exception;
  20. class AuthorizationsController extends Controller
  21. {
  22. protected $tencentImAccountService;
  23. public function __construct(TencentImAccountService $tencentImAccountService)
  24. {
  25. $this->tencentImAccountService = $tencentImAccountService;
  26. }
  27. /**
  28. * 极光认证一键登录
  29. */
  30. public function auth_login(Request $request){
  31. try {
  32. if(empty($request->loginToken)){
  33. throw new Exception("参数错误");
  34. }
  35. $loginToken = $request->loginToken;
  36. $exID = $request->post('exID','800');
  37. $ret = JPushService::jgLoginTokenVerify($loginToken,$exID);
  38. $mobile = JPushService::jgOpensslPrivateDecrypt($ret['phone']);
  39. $res = $this->do_login($mobile);
  40. }catch (\Exception $exception){
  41. return $this->response->errorForbidden($exception->getMessage());
  42. }
  43. return response()->json($res);
  44. }
  45. /**
  46. * 手机号登录
  47. * @param Request $request
  48. * @return \Illuminate\Http\JsonResponse
  49. */
  50. public function login_by_mobile(Request $request)
  51. {
  52. try {
  53. $validator = Validator::make($request->all(), [
  54. 'mobile' => ['required', 'regex:/^1[3456789]\d{9}$/'],
  55. 'verifyKey' => 'bail|required|string',
  56. 'smsCode' => 'bail|required',
  57. ], [
  58. 'mobile.required'=>"手机号码必须",
  59. 'mobile.regex'=>"手机号码格式错误",
  60. 'verifyKey.required'=>"验证码必须",
  61. 'smsCode.required'=>"短信验证码必须",
  62. ]);
  63. if ($validator->fails()) {
  64. return $this->response()->errorForbidden($validator->messages()->first());
  65. }
  66. //验证短信验证码
  67. SmsService::checkSmsCodeByVerifyKey($request->verifyKey, $request->smsCode);
  68. $res = $this->do_login($request->mobile);
  69. }catch (\Exception $exception){
  70. return $this->response->errorForbidden($exception->getMessage());
  71. } catch (SmsException $e) {
  72. return $this->response->errorForbidden($e->getMessage());
  73. }
  74. return response()->json($res);
  75. }
  76. /**
  77. * 用户账号密码登录
  78. * @param Request $request
  79. * @return \Illuminate\Http\JsonResponse|void
  80. */
  81. public function login_by_account_password(Request $request)
  82. {
  83. try {
  84. $validator = Validator::make($request->all(), [
  85. 'mobile' => ['required', 'regex:/^1[3456789]\d{9}$/'],
  86. 'password' => 'required|string',
  87. ],[
  88. 'mobile.required'=>"手机号码必须",
  89. 'mobile.regex'=>"手机号码格式错误",
  90. 'password.required'=>"密码必须",
  91. ]);
  92. if ($validator->fails()) {
  93. throw new Exception($validator->messages()->first());
  94. }
  95. $res = $this->do_login($request->mobile,$request->password);
  96. }catch (\Exception $exception){
  97. return $this->response->errorForbidden($exception->getMessage());
  98. }
  99. return response()->json($res);
  100. }
  101. //登录操作
  102. public function do_login($mobile,$password=null){
  103. if(!empty($password)){
  104. if (!$user=User::query()->where(['mobile' => $mobile])->whereNull('deleted_at')->first()) {
  105. throw new Exception("用户不存在");
  106. }
  107. $credentials = ['mobile'=>$mobile,'password'=>$password];
  108. if (!auth('api')->attempt($credentials)) {
  109. throw new Exception("用户名或密码错误");
  110. }
  111. }else{
  112. User::firstOrCreate([
  113. 'mobile' => $mobile,
  114. ]);
  115. $user = User::query()->where(['mobile'=>$mobile])->whereNull('deleted_at')->first();
  116. }
  117. if (!$user->ycode) {
  118. $user->ycode = $this->create_code();
  119. }
  120. if(!UserInfoModel::query()->where('user_id',$user->id)->first()){
  121. UserInfoModel::query()->firstOrCreate([
  122. 'user_id'=>$user->id,
  123. 'avatar'=>"https://zhengda.oss-cn-chengdu.aliyuncs.com/chengluApp/default.jpg",
  124. 'nickname'=>"用户".$user->mobile,
  125. 'birthday'=>"1990-01-01"
  126. ]);
  127. }
  128. if (!$user->tencent_im_user_id) {
  129. $user->tencent_im_user_id = $this->tencentImAccountService->accountImport($user);
  130. }
  131. if($user->status!=1){
  132. throw new Exception("用户已被禁用,请联系管理员");
  133. }
  134. $token = Auth::guard('api')->fromUser($user);
  135. $user->remember_token = $token;
  136. $user->last_login_time = Carbon::now();
  137. $user->last_login_ip = request()->ip();
  138. $user->save();
  139. $resdata['token'] = "Bearer ".$token;
  140. $resdata['sex'] = $user->sex;
  141. $resdata['password'] = $user->password?1:0;
  142. $resdata['tencent_im_user_id'] =$user->tencent_im_user_id;
  143. $resdata['mobile'] =$user->mobile;
  144. $resdata['lock_pass'] =$user->lock_pass?$user->lock_pass:false;
  145. $resdata['status'] =$user->status;
  146. $resdata['is_auth'] =$user->is_auth;
  147. $resdata['ycode'] =$user->ycode;
  148. $resdata['online'] =$user->online;
  149. $resdata['notice_status'] =$user->notice_status;
  150. return $resdata;
  151. }
  152. public function captcha(){
  153. return response(captcha_src());
  154. }
  155. /**
  156. * 根据用户ID生成唯一邀请码
  157. * @param $user_id
  158. * @return string
  159. */
  160. public function create_code() {
  161. $code = create_invite_code();
  162. if(User::where(['ycode'=>$code])->first()){
  163. $code = create_invite_code();
  164. }
  165. return $code;
  166. }
  167. /**
  168. * 注册账号
  169. */
  170. public function register(Request $request){
  171. $validator = Validator::make($request->all(), [
  172. 'mobile' => ['required', 'regex:/^1[3456789]\d{9}$/'],
  173. 'password' => 'bail|required',
  174. ],[
  175. 'mobile.required'=>"手机号码必须",
  176. 'mobile.regex'=>"手机号码格式错误",
  177. 'password.required'=>"密码必须",
  178. ]);
  179. if ($validator->fails()){
  180. return $this->response()->errorForbidden($validator->messages()->first());
  181. }
  182. if(User::where(['mobile'=>$request->mobile])->first()){
  183. return $this->response->errorForbidden("该手机号码已使用");
  184. }
  185. $ins = array();
  186. $ins['mobile'] = $request->mobile;
  187. $ins['password'] = $request->password;
  188. if(User::create($ins)){
  189. return response()->json(['message'=>"注册成功"]);
  190. }else{
  191. return $this->response->errorForbidden("注册失败");
  192. }
  193. }
  194. public function reg_h5(Request $request){
  195. $validator = Validator::make($request->all(), [
  196. 'mobile' => ['required', 'regex:/^1[3456789]\d{9}$/'],
  197. 'password' => 'bail|required',
  198. 'smsCode' => 'bail|required',
  199. ],[
  200. 'mobile.required'=>"手机号码必须",
  201. 'mobile.regex'=>"手机号码格式错误",
  202. 'password.required'=>"密码必须",
  203. 'smsCode.required'=>"短信验证码必须",
  204. ]);
  205. if ($validator->fails()){
  206. return response()->json([
  207. 'code'=>0,
  208. 'message'=>$validator->messages()->first()
  209. ]);
  210. }
  211. DB::beginTransaction();
  212. try {
  213. //验证短信验证码
  214. SmsService::checkSmsCodeByVerifyKey($request->verifyKey, $request->smsCode);
  215. if(User::where(['mobile'=>$request->mobile])->first()){
  216. throw new Exception("该手机号码已使用");
  217. }
  218. //邀请码设置
  219. $pid = 0;
  220. if(isset($request->ycode) && $request->ycode!=""){
  221. if(!$puser = User::where(['ycode'=>$request->ycode])->first()){
  222. throw new Exception("邀请码不存在");
  223. }
  224. $pid = $puser->id;
  225. }
  226. $ins = array();
  227. $ins['mobile'] = $request->mobile;
  228. $ins['password'] = $request->password;
  229. $ins['pid'] = $pid;
  230. $ins['created_at'] = date('Y-m-d H:i:s');
  231. $ins['updated_at'] = date('Y-m-d H:i:s');
  232. $insid = User::query()->insertGetId($ins);
  233. //赠送会员天数
  234. UserInviteLog::query()->create([
  235. 'user_id'=>$pid,
  236. 'invite_id'=>$insid,
  237. 'day'=>1,
  238. 'status'=>0,
  239. ]);
  240. DB::commit();
  241. } catch (SmsException $e) {
  242. DB::rollBack();
  243. return response()->json([
  244. 'code'=>0,
  245. 'message'=>$e->getMessage()
  246. ]);
  247. } catch (\Exception $e) {
  248. DB::rollBack();
  249. return response()->json([
  250. 'code'=>0,
  251. 'message'=>'短信校验失败'
  252. ]);
  253. }
  254. return response()->json([
  255. 'code'=>1,
  256. 'message'=>'注册成功'
  257. ]);
  258. }
  259. /**
  260. * 忘记密码
  261. */
  262. public function forget_password(Request $request){
  263. try {
  264. $validator = Validator::make($request->all(), [
  265. 'mobile' => ['required', 'regex:/^1[3456789]\d{9}$/'],
  266. 'verifyKey' => 'bail|required|string',
  267. 'smsCode' => 'bail|required',
  268. 'password' => 'bail|required',
  269. ],[
  270. 'mobile.required'=>"手机号码必须",
  271. 'mobile.regex'=>"手机号码格式错误",
  272. 'verifyKey.required'=>"验证码必须",
  273. 'smsCode.required'=>"短信验证码必须",
  274. 'password.required'=>"密码必须",
  275. ]);
  276. if ($validator->fails()) {
  277. throw new Exception($validator->messages()->first());
  278. }
  279. //验证短信验证码
  280. SmsService::checkSmsCodeByVerifyKey($request->verifyKey, $request->smsCode);
  281. $user = User::where(['mobile'=>$request->mobile])->first();
  282. $user->password =$request->password;// Hash::make($request->password);
  283. if(!$user->save()){
  284. throw new Exception("设置失败");
  285. }
  286. $res = $this->do_login($request->mobile,$request->password);
  287. }catch (\Exception $exception){
  288. return $this->response->errorForbidden($exception->getMessage());
  289. } catch (SmsException $e) {
  290. return $this->response->errorForbidden($e->getMessage());
  291. }
  292. return response()->json($res);
  293. }
  294. /**
  295. * 用户协议
  296. */
  297. public function xieyi(Request $request){
  298. if(isset($request->cont) && $request->cont==1){
  299. $data = DB::table("document")->where(['id'=>$request->id])->first();
  300. return response()->json(['data'=>$data]);
  301. }else{
  302. $url = "https://".$_SERVER['HTTP_HOST']."/xieyi/content.html?id=1";
  303. $url2 = "https://".$_SERVER['HTTP_HOST']."/xieyi/content.html?id=2";
  304. return response()->json(['url1'=>$url,'url2'=>$url2]);
  305. }
  306. }
  307. /**
  308. * Get the authenticated User.
  309. *
  310. * @return \Illuminate\Http\JsonResponse
  311. */
  312. public function me()
  313. {
  314. $user = auth('api')->user();
  315. return $this->response->item($user, new UserTransformer());
  316. }
  317. /**
  318. * Log the user out (Invalidate the token).
  319. *
  320. * @return \Illuminate\Http\JsonResponse
  321. */
  322. public function logout()
  323. {
  324. auth('api')->logout();
  325. return response()->json(['message' => '退出成功!']);
  326. }
  327. /**
  328. * Refresh a token.
  329. * 刷新token,如果开启黑名单,以前的token便会失效。
  330. * 值得注意的是用上面的getToken再获取一次Token并不算做刷新,两次获得的Token是并行的,即两个都可用。
  331. * @return \Illuminate\Http\JsonResponse
  332. */
  333. public function refresh()
  334. {
  335. return $this->respondWithToken(Auth::guard('api')->refresh());
  336. }
  337. static public function updateLastLogin(User $user, string $jwtToken)
  338. {
  339. $user->remember_token = $jwtToken;
  340. $user->last_login_time = Carbon::now();
  341. $user->last_login_ip = request()->ip();
  342. $user->save();
  343. }
  344. /**
  345. * Get the token array structure.
  346. *
  347. * @param string $token
  348. *
  349. * @return \Illuminate\Http\JsonResponse
  350. */
  351. protected function respondWithToken($token)
  352. {
  353. return response()->json([
  354. 'access_token' => $token,
  355. 'token_type' => 'Bearer',
  356. 'expires_in' => Auth::guard('api')->factory()->getTTL() * 60
  357. ]);
  358. }
  359. }