AuthorizationsController.php 14 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414
  1. <?php
  2. namespace App\Http\Controllers\Api;
  3. use App\Exceptions\SmsException;
  4. use App\Models\AdminRole;
  5. use App\Models\User;
  6. use App\Models\UserInfoModel;
  7. use App\Models\UserInviteLog;
  8. use App\Models\UserVipLimit;
  9. use App\Services\JPushService;
  10. use App\Services\SmsService;
  11. use App\Services\TencentImAccountService;
  12. use App\Transformers\UserTransformer;
  13. use Carbon\Carbon;
  14. use http\Env\Response;
  15. use Illuminate\Http\Request;
  16. use Illuminate\Support\Facades\Auth;
  17. use Illuminate\Support\Facades\DB;
  18. use Illuminate\Support\Facades\Hash;
  19. use Illuminate\Support\Facades\Validator;
  20. use PHPUnit\Util\Exception;
  21. class AuthorizationsController extends Controller
  22. {
  23. protected $tencentImAccountService;
  24. public function __construct(TencentImAccountService $tencentImAccountService)
  25. {
  26. $this->tencentImAccountService = $tencentImAccountService;
  27. }
  28. /**
  29. * 极光认证一键登录
  30. */
  31. public function auth_login(Request $request){
  32. file_put_contents("login_data.log",var_export($request->all(),true).PHP_EOL,FILE_APPEND);
  33. try {
  34. if(empty($request->loginToken)){
  35. throw new Exception("参数错误");
  36. }
  37. $loginToken = $request->loginToken;
  38. $exID = $request->post('exID','800');
  39. $ret = JPushService::jgLoginTokenVerify($loginToken,$exID);
  40. $mobile = JPushService::jgOpensslPrivateDecrypt($ret['phone']);
  41. $res = $this->do_login($mobile);
  42. }catch (\Exception $exception){
  43. return $this->response->errorForbidden($exception->getMessage());
  44. }
  45. return response()->json($res);
  46. }
  47. /**
  48. * 手机号登录
  49. * @param Request $request
  50. * @return \Illuminate\Http\JsonResponse
  51. */
  52. public function login_by_mobile(Request $request)
  53. {
  54. file_put_contents("login_data.log",var_export($request->all(),true).PHP_EOL,FILE_APPEND);
  55. try {
  56. $validator = Validator::make($request->all(), [
  57. 'mobile' => ['required', 'regex:/^1[3456789]\d{9}$/'],
  58. 'verifyKey' => 'bail|required|string',
  59. 'smsCode' => 'bail|required',
  60. ], [
  61. 'mobile.required'=>"手机号码必须",
  62. 'mobile.regex'=>"手机号码格式错误",
  63. 'verifyKey.required'=>"验证码必须",
  64. 'smsCode.required'=>"短信验证码必须",
  65. ]);
  66. if ($validator->fails()) {
  67. return $this->response()->errorForbidden($validator->messages()->first());
  68. }
  69. //验证短信验证码
  70. SmsService::checkSmsCodeByVerifyKey($request->verifyKey, $request->smsCode);
  71. $res = $this->do_login($request->mobile,null,$request->registrationId,$request->phoneModel);
  72. }catch (\Exception $exception){
  73. return $this->response->errorForbidden($exception->getMessage());
  74. } catch (SmsException $e) {
  75. return $this->response->errorForbidden($e->getMessage());
  76. }
  77. return response()->json($res);
  78. }
  79. /**
  80. * 用户账号密码登录
  81. * @param Request $request
  82. * @return \Illuminate\Http\JsonResponse|void
  83. */
  84. public function login_by_account_password(Request $request)
  85. {
  86. file_put_contents("login_data.log",var_export($request->all(),true).PHP_EOL,FILE_APPEND);
  87. try {
  88. $validator = Validator::make($request->all(), [
  89. 'mobile' => ['required', 'regex:/^1[3456789]\d{9}$/'],
  90. 'password' => 'required|string',
  91. ],[
  92. 'mobile.required'=>"手机号码必须",
  93. 'mobile.regex'=>"手机号码格式错误",
  94. 'password.required'=>"密码必须",
  95. ]);
  96. if ($validator->fails()) {
  97. throw new Exception($validator->messages()->first());
  98. }
  99. $res = $this->do_login($request->mobile,$request->password,$request->registrationId,$request->phoneModel);
  100. }catch (\Exception $exception){
  101. return $this->response->errorForbidden($exception->getMessage());
  102. }
  103. return response()->json($res);
  104. }
  105. //登录操作
  106. public function do_login($mobile,$password=null,$registrationId=null,$phoneModel=null){
  107. if(!empty($password)){
  108. if (!$user=User::query()->where(['mobile' => $mobile,'is_distory'=>0])->whereNull('deleted_at')->first()) {
  109. throw new Exception("用户不存在");
  110. }
  111. $credentials = ['mobile'=>$mobile,'password'=>$password];
  112. if (!auth('api')->attempt($credentials)) {
  113. throw new Exception("用户名或密码错误");
  114. }
  115. }else{
  116. if(!User::query()->where(['mobile'=>$mobile,'is_distory'=>0])->first()){
  117. User::query()->create([
  118. 'mobile' => $mobile,
  119. ]);
  120. }
  121. $user = User::query()->where(['mobile'=>$mobile,'is_distory'=>0])->whereNull('deleted_at')->first();
  122. }
  123. if (!$user->ycode) {
  124. $user->ycode = $this->create_code();
  125. }
  126. if(!UserInfoModel::query()->where('user_id',$user->id)->first()){
  127. UserInfoModel::query()->create([
  128. 'user_id'=>$user->id,
  129. 'avatar'=>"https://zhengda.oss-cn-chengdu.aliyuncs.com/chengluApp/default.jpg",
  130. 'nickname'=>"用户".$user->mobile,
  131. 'birthday'=>"1990-01-01"
  132. ]);
  133. }
  134. if(!UserVipLimit::query()->where('user_id',$user->id)->first()){
  135. UserVipLimit::query()->create([
  136. 'user_id'=>$user->id,
  137. ]);
  138. }
  139. if (!$user->tencent_im_user_id) {
  140. $user->tencent_im_user_id = $this->tencentImAccountService->accountImport($user);
  141. }
  142. if($user->status!=1){
  143. throw new Exception("用户已被禁用,请联系管理员");
  144. }
  145. $token = Auth::guard('api')->fromUser($user);
  146. $user->remember_token = $token;
  147. $user->last_login_time = Carbon::now();
  148. $user->last_login_ip = request()->ip();
  149. if(!empty($registrationId)){
  150. $user->registrationId = $registrationId;
  151. $user->phoneModel = $phoneModel;
  152. }
  153. $user->save();
  154. $resdata['token'] = "Bearer ".$token;
  155. $resdata['sex'] = $user->sex;
  156. $resdata['password'] = $user->password?1:0;
  157. $resdata['tencent_im_user_id'] =$user->tencent_im_user_id;
  158. $resdata['mobile'] =$user->mobile;
  159. $resdata['lock_pass'] =$user->lock_pass?$user->lock_pass:false;
  160. $resdata['status'] =$user->status;
  161. $resdata['is_auth'] =$user->is_auth;
  162. $resdata['ycode'] =$user->ycode;
  163. $resdata['online'] =$user->online;
  164. $resdata['notice_status'] =$user->notice_status;
  165. return $resdata;
  166. }
  167. public function captcha(){
  168. return response(captcha_src());
  169. }
  170. /**
  171. * 根据用户ID生成唯一邀请码
  172. * @param $user_id
  173. * @return string
  174. */
  175. public function create_code() {
  176. $code = create_invite_code();
  177. if(User::where(['ycode'=>$code])->first()){
  178. $code = create_invite_code();
  179. }
  180. return $code;
  181. }
  182. /**
  183. * 注册账号
  184. */
  185. public function register(Request $request){
  186. $validator = Validator::make($request->all(), [
  187. 'mobile' => ['required', 'regex:/^1[3456789]\d{9}$/'],
  188. 'password' => 'bail|required',
  189. ],[
  190. 'mobile.required'=>"手机号码必须",
  191. 'mobile.regex'=>"手机号码格式错误",
  192. 'password.required'=>"密码必须",
  193. ]);
  194. if ($validator->fails()){
  195. return $this->response()->errorForbidden($validator->messages()->first());
  196. }
  197. if(User::where(['mobile'=>$request->mobile,'is_distory'=>0])->first()){
  198. return $this->response->errorForbidden("该手机号码已使用");
  199. }
  200. $ins = array();
  201. $ins['mobile'] = $request->mobile;
  202. $ins['password'] = $request->password;
  203. if(User::create($ins)){
  204. return response()->json(['message'=>"注册成功"]);
  205. }else{
  206. return $this->response->errorForbidden("注册失败");
  207. }
  208. }
  209. public function reg_h5(Request $request){
  210. $validator = Validator::make($request->all(), [
  211. 'mobile' => ['required', 'regex:/^1[3456789]\d{9}$/'],
  212. 'password' => 'bail|required',
  213. 'smsCode' => 'bail|required',
  214. ],[
  215. 'mobile.required'=>"手机号码必须",
  216. 'mobile.regex'=>"手机号码格式错误",
  217. 'password.required'=>"密码必须",
  218. 'smsCode.required'=>"短信验证码必须",
  219. ]);
  220. if ($validator->fails()){
  221. return response()->json([
  222. 'code'=>0,
  223. 'message'=>$validator->messages()->first()
  224. ]);
  225. }
  226. DB::beginTransaction();
  227. try {
  228. //验证短信验证码
  229. SmsService::checkSmsCodeByVerifyKey($request->verifyKey, $request->smsCode);
  230. if(User::where(['mobile'=>$request->mobile,'is_distory'=>0])->first()){
  231. throw new Exception("该手机号码已使用");
  232. }
  233. //邀请码设置
  234. $pid = 0;
  235. if(isset($request->ycode) && $request->ycode!=""){
  236. if(!$puser = User::where(['ycode'=>$request->ycode])->first()){
  237. throw new Exception("邀请码不存在");
  238. }
  239. $pid = $puser->id;
  240. }
  241. $ins = array();
  242. $ins['mobile'] = $request->mobile;
  243. $ins['password'] = $request->password;
  244. $ins['pid'] = $pid;
  245. $ins['created_at'] = date('Y-m-d H:i:s');
  246. $ins['updated_at'] = date('Y-m-d H:i:s');
  247. $insid = User::query()->insertGetId($ins);
  248. //赠送会员天数
  249. UserInviteLog::query()->create([
  250. 'user_id'=>$pid,
  251. 'invite_id'=>$insid,
  252. 'day'=>1,
  253. 'status'=>0,
  254. ]);
  255. DB::commit();
  256. } catch (SmsException $e) {
  257. DB::rollBack();
  258. return response()->json([
  259. 'code'=>0,
  260. 'message'=>$e->getMessage()
  261. ]);
  262. } catch (\Exception $e) {
  263. DB::rollBack();
  264. return response()->json([
  265. 'code'=>0,
  266. 'message'=>'短信校验失败'
  267. ]);
  268. }
  269. return response()->json([
  270. 'code'=>1,
  271. 'message'=>'注册成功'
  272. ]);
  273. }
  274. /**
  275. * 忘记密码
  276. */
  277. public function forget_password(Request $request){
  278. try {
  279. $validator = Validator::make($request->all(), [
  280. 'mobile' => ['required', 'regex:/^1[3456789]\d{9}$/'],
  281. 'verifyKey' => 'bail|required|string',
  282. 'smsCode' => 'bail|required',
  283. 'password' => 'bail|required',
  284. ],[
  285. 'mobile.required'=>"手机号码必须",
  286. 'mobile.regex'=>"手机号码格式错误",
  287. 'verifyKey.required'=>"验证码必须",
  288. 'smsCode.required'=>"短信验证码必须",
  289. 'password.required'=>"密码必须",
  290. ]);
  291. if ($validator->fails()) {
  292. throw new Exception($validator->messages()->first());
  293. }
  294. //验证短信验证码
  295. //SmsService::checkSmsCodeByVerifyKey($request->verifyKey, $request->smsCode);
  296. $user = User::where(['mobile'=>$request->mobile])->first();
  297. $user->password =$request->password;// Hash::make($request->password);
  298. if(!$user->save()){
  299. throw new Exception("设置失败");
  300. }
  301. $res = $this->do_login($request->mobile,$request->password);
  302. }catch (\Exception $exception){
  303. return $this->response->errorForbidden($exception->getMessage());
  304. } catch (SmsException $e) {
  305. return $this->response->errorForbidden($e->getMessage());
  306. }
  307. return response()->json($res);
  308. }
  309. /**
  310. * 用户协议
  311. */
  312. public function xieyi(Request $request){
  313. if(isset($request->cont) && $request->cont==1){
  314. $data = DB::table("document")->where(['id'=>$request->id])->first();
  315. return response()->json(['data'=>$data]);
  316. }else{
  317. $url = "https://".$_SERVER['HTTP_HOST']."/xieyi/content.html?id=1";
  318. $url2 = "https://".$_SERVER['HTTP_HOST']."/xieyi/content.html?id=2";
  319. return response()->json(['url1'=>$url,'url2'=>$url2]);
  320. }
  321. }
  322. /**
  323. * Get the authenticated User.
  324. *
  325. * @return \Illuminate\Http\JsonResponse
  326. */
  327. public function me()
  328. {
  329. $user = auth('api')->user();
  330. return $this->response->item($user, new UserTransformer());
  331. }
  332. /**
  333. * Log the user out (Invalidate the token).
  334. *
  335. * @return \Illuminate\Http\JsonResponse
  336. */
  337. public function logout()
  338. {
  339. auth('api')->logout();
  340. return response()->json(['message' => '退出成功!']);
  341. }
  342. /**
  343. * Refresh a token.
  344. * 刷新token,如果开启黑名单,以前的token便会失效。
  345. * 值得注意的是用上面的getToken再获取一次Token并不算做刷新,两次获得的Token是并行的,即两个都可用。
  346. * @return \Illuminate\Http\JsonResponse
  347. */
  348. public function refresh()
  349. {
  350. return $this->respondWithToken(Auth::guard('api')->refresh());
  351. }
  352. static public function updateLastLogin(User $user, string $jwtToken)
  353. {
  354. $user->remember_token = $jwtToken;
  355. $user->last_login_time = Carbon::now();
  356. $user->last_login_ip = request()->ip();
  357. $user->save();
  358. }
  359. /**
  360. * Get the token array structure.
  361. *
  362. * @param string $token
  363. *
  364. * @return \Illuminate\Http\JsonResponse
  365. */
  366. protected function respondWithToken($token)
  367. {
  368. return response()->json([
  369. 'access_token' => $token,
  370. 'token_type' => 'Bearer',
  371. 'expires_in' => Auth::guard('api')->factory()->getTTL() * 60
  372. ]);
  373. }
  374. }