AuthorizationsController.php 13 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388
  1. <?php
  2. namespace App\Http\Controllers\Api;
  3. use App\Exceptions\SmsException;
  4. use App\Models\AdminRole;
  5. use App\Models\User;
  6. use App\Models\UserInfoModel;
  7. use App\Models\UserInviteLog;
  8. use App\Services\JPushService;
  9. use App\Services\SmsService;
  10. use App\Services\TencentImAccountService;
  11. use App\Transformers\UserTransformer;
  12. use Carbon\Carbon;
  13. use Illuminate\Http\Request;
  14. use Illuminate\Support\Facades\Auth;
  15. use Illuminate\Support\Facades\DB;
  16. use Illuminate\Support\Facades\Hash;
  17. use Illuminate\Support\Facades\Validator;
  18. use PHPUnit\Util\Exception;
  19. class AuthorizationsController extends Controller
  20. {
  21. protected $tencentImAccountService;
  22. public function __construct(TencentImAccountService $tencentImAccountService)
  23. {
  24. $this->tencentImAccountService = $tencentImAccountService;
  25. }
  26. /**
  27. * 极光认证一键登录
  28. */
  29. public function auth_login(Request $request){
  30. try {
  31. if(empty($request->loginToken)){
  32. throw new Exception("参数错误");
  33. }
  34. $loginToken = $request->loginToken;
  35. $exID = $request->post('exID','800');
  36. $ret = JPushService::jgLoginTokenVerify($loginToken,$exID);
  37. $mobile = JPushService::jgOpensslPrivateDecrypt($ret['phone']);
  38. $res = $this->do_login($mobile);
  39. }catch (\Exception $exception){
  40. return $this->response->errorForbidden($exception->getMessage());
  41. }
  42. return response()->json($res);
  43. }
  44. /**
  45. * 手机号登录
  46. * @param Request $request
  47. * @return \Illuminate\Http\JsonResponse
  48. */
  49. public function login_by_mobile(Request $request)
  50. {
  51. try {
  52. $validator = Validator::make($request->all(), [
  53. 'mobile' => ['required', 'regex:/^1[3456789]\d{9}$/'],
  54. 'verifyKey' => 'bail|required|string',
  55. 'smsCode' => 'bail|required',
  56. ], [
  57. 'mobile.required'=>"手机号码必须",
  58. 'mobile.regex'=>"手机号码格式错误",
  59. 'verifyKey.required'=>"验证码必须",
  60. 'smsCode.required'=>"短信验证码必须",
  61. ]);
  62. if ($validator->fails()) {
  63. return $this->response()->errorForbidden($validator->messages()->first());
  64. }
  65. //验证短信验证码
  66. SmsService::checkSmsCodeByVerifyKey($request->verifyKey, $request->smsCode);
  67. $res = $this->do_login($request->mobile);
  68. }catch (\Exception $exception){
  69. return $this->response->errorForbidden($exception->getMessage());
  70. } catch (SmsException $e) {
  71. return $this->response->errorForbidden($e->getMessage());
  72. }
  73. return $res;
  74. }
  75. /**
  76. * 用户账号密码登录
  77. * @param Request $request
  78. * @return \Illuminate\Http\JsonResponse|void
  79. */
  80. public function login_by_account_password(Request $request)
  81. {
  82. try {
  83. $validator = Validator::make($request->all(), [
  84. 'mobile' => ['required', 'regex:/^1[3456789]\d{9}$/'],
  85. 'password' => 'required|string',
  86. ],[
  87. 'mobile.required'=>"手机号码必须",
  88. 'mobile.regex'=>"手机号码格式错误",
  89. 'password.required'=>"密码必须",
  90. ]);
  91. if ($validator->fails()) {
  92. throw new Exception($validator->messages()->first());
  93. }
  94. $res = $this->do_login($request->mobile,$request->password);
  95. }catch (\Exception $exception){
  96. return $this->response->errorForbidden($exception->getMessage());
  97. }
  98. return $res;
  99. }
  100. //登录操作
  101. public function do_login($mobile,$password=null){
  102. if(!empty($password)){
  103. if (!$user=User::where(['mobile' => $mobile])->first()) {
  104. throw new Exception("用户不存在");
  105. }
  106. $credentials = ['mobile'=>$mobile,'password'=>$password];
  107. if (!auth('api')->attempt($credentials)) {
  108. throw new Exception("用户名或密码错误");
  109. }
  110. }else{
  111. User::firstOrCreate([
  112. 'mobile' => $mobile,
  113. ]);
  114. $user = User::query()->where(['mobile'=>$mobile])->first();
  115. }
  116. if (!$user->ycode) {
  117. $user->ycode = $this->create_code();
  118. }
  119. if(!UserInfoModel::query()->where('user_id',$user->id)->first()){
  120. UserInfoModel::query()->firstOrCreate(['user_id'=>$user->id]);
  121. }
  122. if (!$user->tencent_im_user_id) {
  123. $user->tencent_im_user_id = $this->tencentImAccountService->accountImport($user);
  124. }
  125. if($user->status!=1){
  126. throw new Exception("用户已被禁用,请联系管理员");
  127. }
  128. $token = Auth::guard('api')->fromUser($user);
  129. $user->remember_token = $token;
  130. $user->last_login_time = Carbon::now();
  131. $user->last_login_ip = request()->ip();
  132. $user->save();
  133. $resdata['token'] = "Bearer ".$token;
  134. $resdata['sex'] = $user->sex;
  135. $resdata['password'] = $user->password?1:0;
  136. $resdata['tencent_im_user_id'] =$user->tencent_im_user_id;
  137. $resdata['mobile'] =$user->mobile;
  138. $resdata['lock_pass'] =$user->lock_pass?$user->lock_pass:false;
  139. $resdata['status'] =$user->status;
  140. $resdata['is_auth'] =$user->is_auth;
  141. $resdata['ycode'] =$user->ycode;
  142. $resdata['online'] =$user->online;
  143. $resdata['notice_status'] =$user->notice_status;
  144. return $resdata;
  145. }
  146. public function captcha(){
  147. return response(captcha_src());
  148. }
  149. /**
  150. * 根据用户ID生成唯一邀请码
  151. * @param $user_id
  152. * @return string
  153. */
  154. public function create_code() {
  155. $code = create_invite_code();
  156. if(User::where(['ycode'=>$code])->first()){
  157. $code = create_invite_code();
  158. }
  159. return $code;
  160. }
  161. /**
  162. * 注册账号
  163. */
  164. public function register(Request $request){
  165. $validator = Validator::make($request->all(), [
  166. 'mobile' => ['required', 'regex:/^1[3456789]\d{9}$/'],
  167. 'password' => 'bail|required',
  168. ],[
  169. 'mobile.required'=>"手机号码必须",
  170. 'mobile.regex'=>"手机号码格式错误",
  171. 'password.required'=>"密码必须",
  172. ]);
  173. if ($validator->fails()){
  174. return $this->response()->errorForbidden($validator->messages()->first());
  175. }
  176. if(User::where(['mobile'=>$request->mobile])->first()){
  177. return $this->response->errorForbidden("该手机号码已使用");
  178. }
  179. $ins = array();
  180. $ins['mobile'] = $request->mobile;
  181. $ins['password'] = $request->password;
  182. if(User::create($ins)){
  183. return response()->json(['message'=>"注册成功"]);
  184. }else{
  185. return $this->response->errorForbidden("注册失败");
  186. }
  187. }
  188. public function reg_h5(Request $request){
  189. $validator = Validator::make($request->all(), [
  190. 'mobile' => ['required', 'regex:/^1[3456789]\d{9}$/'],
  191. 'password' => 'bail|required',
  192. 'smsCode' => 'bail|required',
  193. ],[
  194. 'mobile.required'=>"手机号码必须",
  195. 'mobile.regex'=>"手机号码格式错误",
  196. 'password.required'=>"密码必须",
  197. 'smsCode.required'=>"短信验证码必须",
  198. ]);
  199. if ($validator->fails()){
  200. return response()->json([
  201. 'code'=>0,
  202. 'message'=>$validator->messages()->first()
  203. ]);
  204. }
  205. DB::beginTransaction();
  206. try {
  207. //验证短信验证码
  208. SmsService::checkSmsCodeByVerifyKey($request->verifyKey, $request->smsCode);
  209. if(User::where(['mobile'=>$request->mobile])->first()){
  210. throw new Exception("该手机号码已使用");
  211. }
  212. //邀请码设置
  213. $pid = 0;
  214. if(isset($request->ycode) && $request->ycode!=""){
  215. if(!$puser = User::where(['ycode'=>$request->ycode])->first()){
  216. throw new Exception("邀请码不存在");
  217. }
  218. $pid = $puser->id;
  219. }
  220. $ins = array();
  221. $ins['mobile'] = $request->mobile;
  222. $ins['password'] = $request->password;
  223. $ins['pid'] = $pid;
  224. $ins['created_at'] = date('Y-m-d H:i:s');
  225. $ins['updated_at'] = date('Y-m-d H:i:s');
  226. $insid = User::query()->insertGetId($ins);
  227. //赠送会员天数
  228. UserInviteLog::query()->create([
  229. 'user_id'=>$pid,
  230. 'invite_id'=>$insid,
  231. 'day'=>1,
  232. 'status'=>0,
  233. ]);
  234. DB::commit();
  235. } catch (SmsException $e) {
  236. DB::rollBack();
  237. return response()->json([
  238. 'code'=>0,
  239. 'message'=>$e->getMessage()
  240. ]);
  241. } catch (\Exception $e) {
  242. DB::rollBack();
  243. return response()->json([
  244. 'code'=>0,
  245. 'message'=>'短信校验失败'
  246. ]);
  247. }
  248. return response()->json([
  249. 'code'=>1,
  250. 'message'=>'注册成功'
  251. ]);
  252. }
  253. /**
  254. * 忘记密码
  255. */
  256. public function forget_password(Request $request){
  257. $validator = Validator::make($request->all(), [
  258. 'mobile' => ['required', 'regex:/^1[3456789]\d{9}$/'],
  259. 'verifyKey' => 'bail|required|string',
  260. 'smsCode' => 'bail|required',
  261. 'password' => 'bail|required',
  262. ],[
  263. 'mobile.required'=>"手机号码必须",
  264. 'mobile.regex'=>"手机号码格式错误",
  265. 'verifyKey.required'=>"验证码必须",
  266. 'smsCode.required'=>"短信验证码必须",
  267. 'password.required'=>"密码必须",
  268. ]);
  269. if ($validator->fails()) {
  270. return $this->response()->errorForbidden($validator->messages()->first());
  271. }
  272. try {
  273. //验证短信验证码
  274. SmsService::checkSmsCodeByVerifyKey($request->verifyKey, $request->smsCode);
  275. } catch (SmsException $e) {
  276. abort(403, $e->getMessage());
  277. } catch (\Exception $e) {
  278. abort(403, '短信校验失败');
  279. }
  280. $user = User::where(['mobile'=>$request->mobile])->first();
  281. $user->password =$request->password;// Hash::make($request->password);
  282. if($user->save()){
  283. return $this->response->noContent();
  284. }
  285. }
  286. /**
  287. * 用户协议
  288. */
  289. public function xieyi(Request $request){
  290. if(isset($request->cont) && $request->cont==1){
  291. $data = DB::table("document")->where(['id'=>$request->id])->first();
  292. return response()->json(['data'=>$data]);
  293. }else{
  294. $url = "https://".$_SERVER['HTTP_HOST']."/xieyi/content.html?id=1";
  295. $url2 = "https://".$_SERVER['HTTP_HOST']."/xieyi/content.html?id=2";
  296. return response()->json(['url1'=>$url,'url2'=>$url2]);
  297. }
  298. }
  299. /**
  300. * Get the authenticated User.
  301. *
  302. * @return \Illuminate\Http\JsonResponse
  303. */
  304. public function me()
  305. {
  306. $user = auth('api')->user();
  307. return $this->response->item($user, new UserTransformer());
  308. }
  309. /**
  310. * Log the user out (Invalidate the token).
  311. *
  312. * @return \Illuminate\Http\JsonResponse
  313. */
  314. public function logout()
  315. {
  316. auth('api')->logout();
  317. return response()->json(['message' => '退出成功!']);
  318. }
  319. /**
  320. * Refresh a token.
  321. * 刷新token,如果开启黑名单,以前的token便会失效。
  322. * 值得注意的是用上面的getToken再获取一次Token并不算做刷新,两次获得的Token是并行的,即两个都可用。
  323. * @return \Illuminate\Http\JsonResponse
  324. */
  325. public function refresh()
  326. {
  327. return $this->respondWithToken(Auth::guard('api')->refresh());
  328. }
  329. static public function updateLastLogin(User $user, string $jwtToken)
  330. {
  331. $user->remember_token = $jwtToken;
  332. $user->last_login_time = Carbon::now();
  333. $user->last_login_ip = request()->ip();
  334. $user->save();
  335. }
  336. /**
  337. * Get the token array structure.
  338. *
  339. * @param string $token
  340. *
  341. * @return \Illuminate\Http\JsonResponse
  342. */
  343. protected function respondWithToken($token)
  344. {
  345. return response()->json([
  346. 'access_token' => $token,
  347. 'token_type' => 'Bearer',
  348. 'expires_in' => Auth::guard('api')->factory()->getTTL() * 60
  349. ]);
  350. }
  351. }