SysAuthService.cs 13 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379
  1. // 麻省理工学院许可证
  2. //
  3. // 版权所有 (c) 2021-2023 zuohuaijun,大名科技(天津)有限公司 联系电话/微信:18020030720 QQ:515096995
  4. //
  5. // 特此免费授予获得本软件的任何人以处理本软件的权利,但须遵守以下条件:在所有副本或重要部分的软件中必须包括上述版权声明和本许可声明。
  6. //
  7. // 软件按“原样”提供,不提供任何形式的明示或暗示的保证,包括但不限于对适销性、适用性和非侵权的保证。
  8. // 在任何情况下,作者或版权持有人均不对任何索赔、损害或其他责任负责,无论是因合同、侵权或其他方式引起的,与软件或其使用或其他交易有关。
  9. using Furion.SpecificationDocument;
  10. using Lazy.Captcha.Core;
  11. namespace Admin.NET.Core.Service;
  12. /// <summary>
  13. /// 系统登录授权服务
  14. /// </summary>
  15. [ApiDescriptionSettings(Order = 500)]
  16. public class SysAuthService : IDynamicApiController, ITransient
  17. {
  18. private readonly UserManager _userManager;
  19. private readonly SqlSugarRepository<SysUser> _sysUserRep;
  20. private readonly IHttpContextAccessor _httpContextAccessor;
  21. private readonly SysMenuService _sysMenuService;
  22. private readonly SysOnlineUserService _sysOnlineUserService;
  23. private readonly SysConfigService _sysConfigService;
  24. private readonly ICaptcha _captcha;
  25. private readonly SysCacheService _sysCacheService;
  26. public SysAuthService(UserManager userManager,
  27. SqlSugarRepository<SysUser> sysUserRep,
  28. IHttpContextAccessor httpContextAccessor,
  29. SysMenuService sysMenuService,
  30. SysOnlineUserService sysOnlineUserService,
  31. SysConfigService sysConfigService,
  32. ICaptcha captcha,
  33. SysCacheService sysCacheService)
  34. {
  35. _userManager = userManager;
  36. _sysUserRep = sysUserRep;
  37. _httpContextAccessor = httpContextAccessor;
  38. _sysMenuService = sysMenuService;
  39. _sysOnlineUserService = sysOnlineUserService;
  40. _sysConfigService = sysConfigService;
  41. _captcha = captcha;
  42. _sysCacheService = sysCacheService;
  43. }
  44. /// <summary>
  45. /// 账号密码登录
  46. /// </summary>
  47. /// <param name="input"></param>
  48. /// <remarks>用户名/密码:superadmin/123456</remarks>
  49. /// <returns></returns>
  50. [AllowAnonymous]
  51. [DisplayName("账号密码登录")]
  52. public async Task<LoginOutput> Login([Required] LoginInput input)
  53. {
  54. //// 可以根据域名获取具体租户
  55. //var host = _httpContextAccessor.HttpContext.Request.Host;
  56. // 判断密码错误次数(默认5次,缓存30分钟)
  57. var keyErrorPasswordCount = $"{CacheConst.KeyErrorPasswordCount}{input.Account}";
  58. var errorPasswordCount = _sysCacheService.Get<int>(keyErrorPasswordCount);
  59. if (errorPasswordCount >= 5)
  60. throw Oops.Oh(ErrorCodeEnum.D1027);
  61. // 是否开启验证码
  62. if (await _sysConfigService.GetConfigValue<bool>(CommonConst.SysCaptcha))
  63. {
  64. // 判断验证码
  65. if (!_captcha.Validate(input.CodeId.ToString(), input.Code))
  66. throw Oops.Oh(ErrorCodeEnum.D0008);
  67. }
  68. // 账号是否存在
  69. var user = await _sysUserRep.AsQueryable().Includes(t => t.SysOrg).ClearFilter().FirstAsync(u => u.Account.Equals(input.Account));
  70. _ = user ?? throw Oops.Oh(ErrorCodeEnum.D0009);
  71. // 账号是否被冻结
  72. if (user.Status == StatusEnum.Disable)
  73. throw Oops.Oh(ErrorCodeEnum.D1017);
  74. // 租户是否被禁用
  75. var tenant = await _sysUserRep.ChangeRepository<SqlSugarRepository<SysTenant>>().GetFirstAsync(u => u.Id == user.TenantId);
  76. if (tenant != null && tenant.Status == StatusEnum.Disable)
  77. throw Oops.Oh(ErrorCodeEnum.Z1003);
  78. // 国密SM2解密(前端密码传输SM2加密后的)
  79. input.Password = CryptogramUtil.SM2Decrypt(input.Password);
  80. // 密码是否正确
  81. if (CryptogramUtil.CryptoType == CryptogramEnum.MD5.ToString())
  82. {
  83. if (!user.Password.Equals(MD5Encryption.Encrypt(input.Password)))
  84. {
  85. _sysCacheService.Set(keyErrorPasswordCount, ++errorPasswordCount, TimeSpan.FromMinutes(30));
  86. throw Oops.Oh(ErrorCodeEnum.D1000);
  87. }
  88. }
  89. else
  90. {
  91. if (!CryptogramUtil.Decrypt(user.Password).Equals(input.Password))
  92. {
  93. _sysCacheService.Set(keyErrorPasswordCount, ++errorPasswordCount, TimeSpan.FromMinutes(30));
  94. throw Oops.Oh(ErrorCodeEnum.D1000);
  95. }
  96. }
  97. // 登录成功则清空密码错误次数
  98. _sysCacheService.Remove(keyErrorPasswordCount);
  99. return await CreateToken(user);
  100. }
  101. /// <summary>
  102. /// 锁屏验证账号密码
  103. /// </summary>
  104. /// <param name="password"></param>
  105. /// <remarks>用户名/密码:superadmin/123456</remarks>
  106. /// <returns></returns>
  107. [DisplayName("锁屏验证账号密码")]
  108. public async Task<bool> Unlock([Required,FromQuery] string password)
  109. {
  110. // 判断密码错误次数(默认5次,缓存30分钟)
  111. var keyErrorPasswordCount = $"{CacheConst.KeyErrorPasswordCount}{_userManager.Account}";
  112. var errorPasswordCount = _sysCacheService.Get<int>(keyErrorPasswordCount);
  113. if (errorPasswordCount >= 5)
  114. throw Oops.Oh(ErrorCodeEnum.D1027);
  115. // 账号是否存在
  116. var user = await _sysUserRep.GetFirstAsync(u => u.Id == _userManager.UserId);
  117. _ = user ?? throw Oops.Oh(ErrorCodeEnum.D0009);
  118. // 账号是否被冻结
  119. if (user.Status == StatusEnum.Disable)
  120. throw Oops.Oh(ErrorCodeEnum.D1017);
  121. // 租户是否被禁用
  122. var tenant = await _sysUserRep.ChangeRepository<SqlSugarRepository<SysTenant>>().GetFirstAsync(u => u.Id == user.TenantId);
  123. if (tenant != null && tenant.Status == StatusEnum.Disable)
  124. throw Oops.Oh(ErrorCodeEnum.Z1003);
  125. // 国密SM2解密(前端密码传输SM2加密后的)
  126. password = CryptogramUtil.SM2Decrypt(password);
  127. // 密码是否正确
  128. if (CryptogramUtil.CryptoType == CryptogramEnum.MD5.ToString())
  129. {
  130. if (!user.Password.Equals(MD5Encryption.Encrypt(password)))
  131. {
  132. _sysCacheService.Set(keyErrorPasswordCount, ++errorPasswordCount, TimeSpan.FromMinutes(30));
  133. throw Oops.Oh(ErrorCodeEnum.D1000);
  134. }
  135. }
  136. else
  137. {
  138. if (!CryptogramUtil.Decrypt(user.Password).Equals(password))
  139. {
  140. _sysCacheService.Set(keyErrorPasswordCount, ++errorPasswordCount, TimeSpan.FromMinutes(30));
  141. throw Oops.Oh(ErrorCodeEnum.D1000);
  142. }
  143. }
  144. // 登录成功则清空密码错误次数
  145. _sysCacheService.Remove(keyErrorPasswordCount);
  146. return true;
  147. }
  148. /// <summary>
  149. /// 手机号登录
  150. /// </summary>
  151. /// <param name="input"></param>
  152. /// <returns></returns>
  153. [AllowAnonymous]
  154. [DisplayName("手机号登录")]
  155. public async Task<LoginOutput> LoginPhone([Required] LoginPhoneInput input)
  156. {
  157. var verifyCode = _sysCacheService.Get<string>($"{CacheConst.KeyPhoneVerCode}{input.Phone}");
  158. if (string.IsNullOrWhiteSpace(verifyCode))
  159. throw Oops.Oh("验证码不存在或已失效,请重新获取!");
  160. if (verifyCode != input.Code)
  161. throw Oops.Oh("验证码错误!");
  162. // 账号是否存在
  163. var user = await _sysUserRep.AsQueryable().Includes(t => t.SysOrg).ClearFilter().FirstAsync(u => u.Phone.Equals(input.Phone));
  164. _ = user ?? throw Oops.Oh(ErrorCodeEnum.D0009);
  165. return await CreateToken(user);
  166. }
  167. /// <summary>
  168. /// 生成Token令牌
  169. /// </summary>
  170. /// <param name="user"></param>
  171. /// <returns></returns>
  172. [NonAction]
  173. public async Task<LoginOutput> CreateToken(SysUser user)
  174. {
  175. // 单用户登录
  176. await _sysOnlineUserService.SingleLogin(user.Id);
  177. // 生成Token令牌
  178. var tokenExpire = await _sysConfigService.GetTokenExpire();
  179. var accessToken = JWTEncryption.Encrypt(new Dictionary<string, object>
  180. {
  181. { ClaimConst.UserId, user.Id },
  182. { ClaimConst.TenantId, user.TenantId },
  183. { ClaimConst.Account, user.Account },
  184. { ClaimConst.RealName, user.RealName },
  185. { ClaimConst.AccountType, user.AccountType },
  186. { ClaimConst.OrgId, user.OrgId },
  187. { ClaimConst.OrgName, user.SysOrg?.Name },
  188. { ClaimConst.OrgType, user.SysOrg?.Type },
  189. }, tokenExpire);
  190. // 生成刷新Token令牌
  191. var refreshTokenExpire = await _sysConfigService.GetRefreshTokenExpire();
  192. var refreshToken = JWTEncryption.GenerateRefreshToken(accessToken, refreshTokenExpire);
  193. // 设置响应报文头
  194. _httpContextAccessor.HttpContext.SetTokensOfResponseHeaders(accessToken, refreshToken);
  195. // Swagger Knife4UI-AfterScript登录脚本
  196. // ke.global.setAllHeader('Authorization', 'Bearer ' + ke.response.headers['access-token']);
  197. return new LoginOutput
  198. {
  199. AccessToken = accessToken,
  200. RefreshToken = refreshToken
  201. };
  202. }
  203. /// <summary>
  204. /// 获取登录账号
  205. /// </summary>
  206. /// <returns></returns>
  207. [DisplayName("获取登录账号")]
  208. public async Task<LoginUserOutput> GetUserInfo()
  209. {
  210. var user = await _sysUserRep.GetFirstAsync(u => u.Id == _userManager.UserId) ?? throw Oops.Oh(ErrorCodeEnum.D1011).StatusCode(401);
  211. // 获取机构
  212. var org = await _sysUserRep.ChangeRepository<SqlSugarRepository<SysOrg>>().GetFirstAsync(u => u.Id == user.OrgId);
  213. // 获取职位
  214. var pos = await _sysUserRep.ChangeRepository<SqlSugarRepository<SysPos>>().GetFirstAsync(u => u.Id == user.PosId);
  215. // 获取拥有按钮权限集合
  216. var buttons = await _sysMenuService.GetOwnBtnPermList();
  217. // 获取权限集合
  218. var roleIds = await _sysUserRep.ChangeRepository<SqlSugarRepository<SysUserRole>>().AsQueryable()
  219. .Where(u => u.UserId == user.Id).Select(u => u.RoleId).ToListAsync();
  220. return new LoginUserOutput
  221. {
  222. Id = user.Id,
  223. Account = user.Account,
  224. RealName = user.RealName,
  225. Phone = user.Phone,
  226. IdCardNum = user.IdCardNum,
  227. Email = user.Email,
  228. AccountType = user.AccountType,
  229. Avatar = user.Avatar,
  230. Address = user.Address,
  231. Signature = user.Signature,
  232. OrgId = user.OrgId,
  233. OrgName = org?.Name,
  234. OrgType = org?.Type,
  235. PosName = pos?.Name,
  236. Buttons = buttons,
  237. RoleIds = roleIds
  238. };
  239. }
  240. /// <summary>
  241. /// 获取刷新Token
  242. /// </summary>
  243. /// <param name="accessToken"></param>
  244. /// <returns></returns>
  245. [DisplayName("获取刷新Token")]
  246. public string GetRefreshToken([FromQuery] string accessToken)
  247. {
  248. var refreshTokenExpire = _sysConfigService.GetRefreshTokenExpire().GetAwaiter().GetResult();
  249. return JWTEncryption.GenerateRefreshToken(accessToken, refreshTokenExpire);
  250. }
  251. /// <summary>
  252. /// 退出系统
  253. /// </summary>
  254. [DisplayName("退出系统")]
  255. public void Logout()
  256. {
  257. if (string.IsNullOrWhiteSpace(_userManager.Account))
  258. throw Oops.Oh(ErrorCodeEnum.D1011);
  259. _httpContextAccessor.HttpContext.SignoutToSwagger();
  260. }
  261. /// <summary>
  262. /// 获取登录配置
  263. /// </summary>
  264. /// <returns></returns>
  265. [AllowAnonymous]
  266. [SuppressMonitor]
  267. [DisplayName("获取登录配置")]
  268. public async Task<dynamic> GetLoginConfig()
  269. {
  270. var secondVerEnabled = await _sysConfigService.GetConfigValue<bool>(CommonConst.SysSecondVer);
  271. var captchaEnabled = await _sysConfigService.GetConfigValue<bool>(CommonConst.SysCaptcha);
  272. return new { SecondVerEnabled = secondVerEnabled, CaptchaEnabled = captchaEnabled };
  273. }
  274. /// <summary>
  275. /// 获取水印配置
  276. /// </summary>
  277. /// <returns></returns>
  278. [SuppressMonitor]
  279. [DisplayName("获取水印配置")]
  280. public async Task<dynamic> GetWatermarkConfig()
  281. {
  282. var watermarkEnabled = await _sysConfigService.GetConfigValue<bool>(CommonConst.SysWatermark);
  283. return new { WatermarkEnabled = watermarkEnabled };
  284. }
  285. /// <summary>
  286. /// 获取验证码
  287. /// </summary>
  288. /// <returns></returns>
  289. [AllowAnonymous]
  290. [SuppressMonitor]
  291. [DisplayName("获取验证码")]
  292. public dynamic GetCaptcha()
  293. {
  294. var codeId = YitIdHelper.NextId().ToString();
  295. var captcha = _captcha.Generate(codeId);
  296. return new { Id = codeId, Img = captcha.Base64 };
  297. }
  298. /// <summary>
  299. /// Swagger登录检查
  300. /// </summary>
  301. /// <returns></returns>
  302. [AllowAnonymous]
  303. [HttpPost("/swagger/checkUrl"), NonUnify]
  304. [DisplayName("Swagger登录检查")]
  305. public int SwaggerCheckUrl()
  306. {
  307. return _httpContextAccessor.HttpContext.User.Identity.IsAuthenticated ? 200 : 401;
  308. }
  309. /// <summary>
  310. /// Swagger登录提交
  311. /// </summary>
  312. /// <param name="auth"></param>
  313. /// <returns></returns>
  314. [AllowAnonymous]
  315. [HttpPost("/swagger/submitUrl"), NonUnify]
  316. [DisplayName("Swagger登录提交")]
  317. public async Task<int> SwaggerSubmitUrl([FromForm] SpecificationAuth auth)
  318. {
  319. try
  320. {
  321. _sysCacheService.Set(CommonConst.SysCaptcha, false);
  322. await Login(new LoginInput
  323. {
  324. Account = auth.UserName,
  325. Password = CryptogramUtil.SM2Encrypt(auth.Password),
  326. });
  327. _sysCacheService.Remove(CommonConst.SysCaptcha);
  328. return 200;
  329. }
  330. catch (Exception)
  331. {
  332. return 401;
  333. }
  334. }
  335. }