AuthController.java 12 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310
  1. package org.dromara.web.controller;
  2. import cn.dev33.satoken.annotation.SaIgnore;
  3. import cn.hutool.core.collection.CollUtil;
  4. import cn.hutool.core.util.ObjectUtil;
  5. import jakarta.servlet.http.HttpServletRequest;
  6. import lombok.RequiredArgsConstructor;
  7. import lombok.extern.slf4j.Slf4j;
  8. import me.zhyd.oauth.model.AuthResponse;
  9. import me.zhyd.oauth.model.AuthUser;
  10. import me.zhyd.oauth.request.AuthRequest;
  11. import me.zhyd.oauth.utils.AuthStateUtils;
  12. import org.dromara.common.core.domain.AjaxResult;
  13. import org.dromara.common.core.domain.R;
  14. import org.dromara.common.core.domain.model.LoginBody;
  15. import org.dromara.common.core.domain.model.LoginUser;
  16. import org.dromara.common.core.domain.model.RegisterBody;
  17. import org.dromara.common.core.utils.MapstructUtils;
  18. import org.dromara.common.core.utils.MessageUtils;
  19. import org.dromara.common.core.utils.StreamUtils;
  20. import org.dromara.common.core.utils.StringUtils;
  21. import org.dromara.common.redis.utils.RedisUtils;
  22. import org.dromara.common.satoken.utils.LoginHelper;
  23. import org.dromara.common.social.config.properties.SocialLoginConfigProperties;
  24. import org.dromara.common.social.config.properties.SocialProperties;
  25. import org.dromara.common.social.utils.SocialUtils;
  26. import org.dromara.common.tenant.helper.TenantHelper;
  27. import org.dromara.system.domain.SysClient;
  28. import org.dromara.system.domain.app.AppletLoginForm;
  29. import org.dromara.system.domain.bo.SysTenantBo;
  30. import org.dromara.system.domain.school.bo.SysSchoolNameBo;
  31. import org.dromara.system.domain.school.vo.SysSchoolNameVo;
  32. import org.dromara.system.domain.vo.SysRoleVo;
  33. import org.dromara.system.domain.vo.SysTenantVo;
  34. import org.dromara.system.domain.vo.SysUserVo;
  35. import org.dromara.system.mapper.SysRoleMapper;
  36. import org.dromara.system.mapper.SysUserMapper;
  37. import org.dromara.system.service.*;
  38. import org.dromara.system.service.school.ISysSchoolNameService;
  39. import org.dromara.web.domain.vo.LoginTenantVo;
  40. import org.dromara.web.domain.vo.LoginVo;
  41. import org.dromara.web.domain.vo.TenantListVo;
  42. import org.dromara.web.service.IAuthStrategy;
  43. import org.dromara.web.service.SysLoginService;
  44. import org.dromara.web.service.SysRegisterService;
  45. import org.springframework.validation.annotation.Validated;
  46. import org.springframework.web.bind.annotation.*;
  47. import java.net.URL;
  48. import java.util.ArrayList;
  49. import java.util.List;
  50. import java.util.Map;
  51. import java.util.stream.Collectors;
  52. /**
  53. * 认证
  54. *
  55. * @author Lion Li
  56. */
  57. @Slf4j
  58. @SaIgnore
  59. @Validated
  60. @RequiredArgsConstructor
  61. @RestController
  62. @RequestMapping("/auth")
  63. public class AuthController {
  64. private final SocialProperties socialProperties;
  65. private final SysLoginService loginService;
  66. private final SysRegisterService registerService;
  67. private final ISysConfigService configService;
  68. private final ISysTenantService tenantService;
  69. private final ISysSocialService socialUserService;
  70. private final ISysClientService clientService;
  71. private final ISysSchoolNameService sysSchoolNameService;
  72. private final SysUserMapper sysUserMapper;
  73. private final SysRoleMapper sysRoleMapper;
  74. /**
  75. * 登录方法
  76. *
  77. * @param loginBody 登录信息
  78. * @return 结果
  79. */
  80. @PostMapping("/login")
  81. public R<LoginVo> login(@Validated @RequestBody LoginBody loginBody) {
  82. // 授权类型和客户端id
  83. String clientId = loginBody.getClientId();
  84. String grantType = loginBody.getGrantType();
  85. SysClient client = clientService.queryByClientId(clientId);
  86. // 查询不到 client 或 client 内不包含 grantType
  87. if (ObjectUtil.isNull(client) || !StringUtils.contains(client.getGrantType(), grantType)) {
  88. log.info("客户端id: {} 认证类型:{} 异常!.", clientId, grantType);
  89. return R.fail(MessageUtils.message("auth.grant.type.error"));
  90. }
  91. //去redis中查询当前账号登录租户id = loginBody.get
  92. Object tenantId = RedisUtils.getCacheObject(loginBody.getUsername() + ":login");
  93. if (ObjectUtil.isEmpty(tenantId)) {
  94. tenantId = "000000";
  95. //如果是空,则去查询
  96. List<SysUserVo> sysUserVo = sysUserMapper.selectUserByUserNameList(loginBody.getUsername());
  97. if (sysUserVo != null && sysUserVo.size() > 0) {
  98. boolean flag = true;
  99. for (SysUserVo userVo : sysUserVo) {
  100. if (!"000000".equals(userVo.getTenantId()) && flag){
  101. tenantId = userVo.getTenantId();
  102. }
  103. Long userId = userVo.getUserId();
  104. List<SysRoleVo> sysRoleVo = sysRoleMapper.selectRolePermissionByUserId(userId);
  105. for (SysRoleVo roleVo : sysRoleVo) {
  106. if ("teacher".equals(roleVo.getRoleKey())) {
  107. tenantId = userVo.getTenantId();
  108. flag = false;
  109. break;
  110. }
  111. }
  112. }
  113. }
  114. }
  115. loginBody.setTenantId(tenantId.toString());
  116. // 校验租户
  117. loginService.checkTenant(loginBody.getTenantId());
  118. // 登录
  119. return R.ok(IAuthStrategy.login(loginBody, client));
  120. }
  121. /**
  122. * 微信登录方法
  123. *
  124. * @param form 登录信息
  125. * @return 结果
  126. */
  127. @SaIgnore
  128. @PostMapping("/weChatLogin")
  129. public R<LoginVo> weChatLogin(@Validated @RequestBody AppletLoginForm form) {
  130. LoginBody loginBody = new LoginBody();
  131. String clientId = "428a8310cd442757ae699df5d894f051";
  132. String grantType = "password";
  133. loginBody.setClientId(clientId);
  134. loginBody.setGrantType(grantType);
  135. SysClient client = clientService.queryByClientId(clientId);
  136. // 查询不到 client 或 client 内不包含 grantType
  137. if (ObjectUtil.isNull(client) || !StringUtils.contains(client.getGrantType(), grantType)) {
  138. log.info("客户端id: {} 认证类型:{} 异常!.", clientId, grantType);
  139. return R.fail(MessageUtils.message("auth.grant.type.error"));
  140. }
  141. LoginVo loginVo = IAuthStrategy.weChatLogin(form, loginBody, client);
  142. //去redis中查询当前账号登录租户id = loginBody.get
  143. Object tenantId = RedisUtils.getCacheObject(loginBody.getUsername() + ":login");
  144. if (ObjectUtil.isEmpty(tenantId)) {
  145. //如果是空,则去查询
  146. SysUserVo sysUserVo = sysUserMapper.selectUserByUserName(loginBody.getUsername());
  147. tenantId = sysUserVo.getTenantId();
  148. }
  149. loginBody.setTenantId(tenantId.toString());
  150. // 校验租户
  151. loginService.checkTenant(loginBody.getTenantId());
  152. return R.ok(loginVo);
  153. }
  154. /**
  155. * 第三方登录请求
  156. *
  157. * @param source 登录来源
  158. * @return 结果
  159. */
  160. @GetMapping("/binding/{source}")
  161. public R<String> authBinding(@PathVariable("source") String source) {
  162. SocialLoginConfigProperties obj = socialProperties.getType().get(source);
  163. if (ObjectUtil.isNull(obj)) {
  164. return R.fail(source + "平台账号暂不支持");
  165. }
  166. AuthRequest authRequest = SocialUtils.getAuthRequest(source, socialProperties);
  167. String authorizeUrl = authRequest.authorize(AuthStateUtils.createState());
  168. return R.ok("操作成功", authorizeUrl);
  169. }
  170. /**
  171. * 第三方登录回调业务处理 绑定授权
  172. *
  173. * @param loginBody 请求体
  174. * @return 结果
  175. */
  176. @PostMapping("/social/callback")
  177. public R<Void> socialCallback(@RequestBody LoginBody loginBody) {
  178. // 获取第三方登录信息
  179. AuthResponse<AuthUser> response = SocialUtils.loginAuth(loginBody, socialProperties);
  180. AuthUser authUserData = response.getData();
  181. // 判断授权响应是否成功
  182. if (!response.ok()) {
  183. return R.fail(response.getMsg());
  184. }
  185. loginService.socialRegister(authUserData);
  186. return R.ok();
  187. }
  188. /**
  189. * 取消授权
  190. *
  191. * @param socialId socialId
  192. */
  193. @DeleteMapping(value = "/unlock/{socialId}")
  194. public R<Void> unlockSocial(@PathVariable Long socialId) {
  195. Boolean rows = socialUserService.deleteWithValidById(socialId);
  196. return rows ? R.ok() : R.fail("取消授权失败");
  197. }
  198. /**
  199. * 退出登录
  200. */
  201. @PostMapping("/logout")
  202. public R<Void> logout() {
  203. loginService.logout();
  204. return R.ok("退出成功");
  205. }
  206. /**
  207. * 用户注册
  208. */
  209. @PostMapping("/register")
  210. public R<Void> register(@Validated @RequestBody RegisterBody user) {
  211. if (!configService.selectRegisterEnabled(user.getTenantId())) {
  212. return R.fail("当前系统没有开启注册功能!");
  213. }
  214. registerService.register(user);
  215. return R.ok();
  216. }
  217. /**
  218. * 登录页面租户下拉框
  219. *
  220. * @return 租户列表
  221. */
  222. @GetMapping("/tenant/list")
  223. public R<LoginTenantVo> tenantList(HttpServletRequest request) throws Exception {
  224. List<SysTenantVo> tenantList = tenantService.queryList(new SysTenantBo());
  225. List<TenantListVo> voList = MapstructUtils.convert(tenantList, TenantListVo.class);
  226. // 获取域名
  227. String host;
  228. String referer = request.getHeader("referer");
  229. if (StringUtils.isNotBlank(referer)) {
  230. // 这里从referer中取值是为了本地使用hosts添加虚拟域名,方便本地环境调试
  231. host = referer.split("//")[1].split("/")[0];
  232. } else {
  233. host = new URL(request.getRequestURL().toString()).getHost();
  234. }
  235. // 根据域名进行筛选
  236. List<TenantListVo> list = StreamUtils.filter(voList, vo ->
  237. StringUtils.equals(vo.getDomain(), host));
  238. // 返回对象
  239. LoginTenantVo vo = new LoginTenantVo();
  240. vo.setVoList(CollUtil.isNotEmpty(list) ? list : voList);
  241. vo.setTenantEnabled(TenantHelper.isEnable());
  242. return R.ok(vo);
  243. }
  244. /**
  245. * 返回家长所在班级
  246. *
  247. * @return 租户列表
  248. */
  249. @GetMapping("/parents/tenant/list")
  250. public R<LoginTenantVo> parentsTenantList(HttpServletRequest request) throws Exception {
  251. //查询账号的租户id
  252. LoginUser user = LoginHelper.getLoginUser();
  253. List<SysUserVo> userList = sysUserMapper.selectUserListByUserName(user.getUsername());
  254. List<String> tList = new ArrayList<>();
  255. for (SysUserVo sysUserVo : userList) {
  256. boolean bl = false;
  257. for (SysRoleVo role : sysUserVo.getRoles()) {
  258. if ("parents".equals(role.getRoleKey())) {
  259. bl = true;
  260. break;
  261. }
  262. }
  263. if (bl) {
  264. tList.add(sysUserVo.getTenantId());
  265. }
  266. }
  267. SysTenantBo tenantBo = new SysTenantBo();
  268. tenantBo.setTenantList(tList);
  269. List<SysTenantVo> tenantList = tenantService.queryList(tenantBo);
  270. List<TenantListVo> voList = MapstructUtils.convert(tenantList, TenantListVo.class);
  271. // 返回对象
  272. LoginTenantVo vo = new LoginTenantVo();
  273. vo.setVoList(voList);
  274. vo.setTenantEnabled(TenantHelper.isEnable());
  275. return R.ok(vo);
  276. }
  277. /**
  278. * 注册页获取学校下拉框
  279. *
  280. * @return 租户列表
  281. */
  282. @GetMapping("/school/list")
  283. public AjaxResult schoolList() {
  284. List<SysSchoolNameVo> sysSchoolNameVos = sysSchoolNameService.queryList(new SysSchoolNameBo());
  285. Map<String, List<SysSchoolNameVo>> collect = sysSchoolNameVos.parallelStream().collect(Collectors.groupingBy(SysSchoolNameVo::getInitial));
  286. return AjaxResult.success(collect);
  287. }
  288. }