Login.php 14 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347
  1. <?php
  2. namespace App\Http\Controllers\Manager;
  3. use App\Models\Manager\AdminUser;
  4. use App\Http\Requests\Manager\Login as Request;
  5. use App\Models\Manager\AuthRule;
  6. use App\Facades\Servers\Encrypts\AccessToken;
  7. use App\Models\Manager\Personnel\Employee as EmployeeModel;
  8. use App\Facades\Servers\Sms\VerifyCode as Sms;
  9. use App\Models\Manager\Personnel\EmployeeOpenid as EmployeeOpenidModel;
  10. use App\Servers\Wechat\WeChatWebApp;
  11. use App\Models\Manager\Personnel\RolesAuthRule as RolesAuthRuleModel;
  12. use Illuminate\Support\Facades\Cache;
  13. /**
  14. * 管理后台登录控制器
  15. * @author 唐远望
  16. * @version 1.0
  17. * @date 2025-12-02
  18. *
  19. * */
  20. class Login extends Manager
  21. {
  22. /**
  23. * 登录方法 /manager/login/index
  24. * @author 唐远望
  25. * @version 1.0
  26. * @date 2025-12-02
  27. * @param string username 登录账号
  28. * @param string password 登录密码
  29. *
  30. * */
  31. public function index(Request $Request, AdminUser $AdminUser, AuthRule $AuthRule, EmployeeModel $EmployeeModel,RolesAuthRuleModel $RolesAuthRuleModel)
  32. {
  33. // 验证规则
  34. $Request->scene('login')->validate();
  35. // 接收数据
  36. $username = $Request->input('username', '');
  37. // 接收数据
  38. $password = $Request->input('password', '');
  39. if (strtolower($username) == 'admin') {
  40. // 查询用户
  41. $admin = $AdminUser->orWhere('username', $username)->first(['uid', 'username', 'phone', 'status', 'password', 'insert_time', 'update_time']);
  42. // 用户不存在
  43. if (!$admin) return json_send(['code' => 'error', 'msg' => '密码错误或账号不存在']);
  44. // 用户不存在
  45. if ($admin['status']) return json_send(['code' => 'error', 'msg' => '该账号已停用']);
  46. // 转数组
  47. $admin = $admin->toArray();
  48. // 比对密码
  49. if (md5($password) != $admin['password']) return json_send(['code' => 'error', 'msg' => '密码错误或账号不存在']);
  50. // 登录
  51. $accessToken = $AdminUser->Login($admin['uid'], 'manager');
  52. // 比对密码
  53. if (isset($accessToken['error'])) return json_send(['code' => 'error', 'msg' => '登录失败', 'data' => $accessToken['data']]);
  54. // 获取权限列表
  55. $accessToken['username'] = $admin['username'];
  56. // 获取权限列表
  57. } else {
  58. $admin = $EmployeeModel->where('employee_code', $username)->first(['company_id','company_id','id as uid', 'name as username', 'mobile as phone', 'status', 'password', 'insert_time', 'update_time']);
  59. // 用户不存在
  60. if (!$admin) return json_send(['code' => 'error', 'msg' => '密码错误或账号不存在']);
  61. // 用户不存在
  62. if ($admin['status']) return json_send(['code' => 'error', 'msg' => '该账号已停用']);
  63. // 转数组
  64. $admin = $admin->toArray();
  65. // 比对密码
  66. if (md5($password) != $admin['password']) return json_send(['code' => 'error', 'msg' => '密码错误或账号不存在']);
  67. // 登录
  68. $accessToken = $EmployeeModel->Login($admin['uid'],$admin['company_id'], 'manager');
  69. // 比对密码
  70. if (isset($accessToken['error'])) return json_send(['code' => 'error', 'msg' => '登录失败', 'data' => $accessToken['data']]);
  71. // 获取权限列表
  72. $accessToken['username'] = $admin['username'];
  73. }
  74. // 表单令牌
  75. return json_send(['code' => 'success', 'msg' => '登录成功', 'data' => $accessToken]);
  76. }
  77. /**
  78. * 获取用户页面权限 /manager/login/auth_rules'
  79. * @author 唐远望
  80. * @version 1.0
  81. * @date 2026-01-30
  82. * @param string username 登录账号
  83. * @param string password 登录密码
  84. *
  85. */
  86. public function auth_rules(Request $Request, AuthRule $AuthRule, RolesAuthRuleModel $RolesAuthRuleModel)
  87. {
  88. $access_token = $Request->input('access_token', '');
  89. if (!isset($access_token)) return json_send(['code' => 'error', 'msg' => '缺少参数']);
  90. $auth_rules = [];
  91. if ($access_token['is_admin'] == 0) {
  92. $auth_rules = $RolesAuthRuleModel->getAuthList($access_token['uid'], '0', 'manager');
  93. } else {
  94. $auth_rules = $AuthRule->getAuthList($access_token['uid'], '1', 'manager');
  95. }
  96. return json_send(['code' => 'success', 'msg' => '获取成功', 'data' => $auth_rules]);
  97. }
  98. /**
  99. * 登录方法 /manager/login/out
  100. * @author 唐远望
  101. * @version 1.0
  102. * @date 2025-12-02
  103. * @param string username 登录账号
  104. * @param string password 登录密码
  105. *
  106. * */
  107. public function out(Request $Request, AdminUser $AdminUser, EmployeeModel $EmployeeModel)
  108. {
  109. $token = $Request->input('access_token_manager', '');
  110. // 解码
  111. $userInfo = AccessToken::decode($token);
  112. // 验证规则
  113. $uid = $userInfo['uid'];
  114. $is_admin = $userInfo['is_admin'];
  115. if ($is_admin == '1') {
  116. // 退出登录
  117. $AdminUser->LoginOut($uid, 'manager');
  118. } else {
  119. $EmployeeModel->LoginOut($uid, 'manager');
  120. }
  121. // 表单令牌
  122. return json_send(['code' => 'success', 'msg' => '退出成功', 'data' => '']);
  123. }
  124. /**
  125. * 手机号码登录 /manager/login/mobile
  126. * @author 唐远望
  127. * @version 1.0
  128. * @date 2025-12-04
  129. * @param string mobile 手机号码
  130. * @param string password 登录密码
  131. *
  132. */
  133. public function mobile(Request $Request, AuthRule $AuthRule, EmployeeModel $EmployeeModel)
  134. {
  135. // 验证规则
  136. $Request->scene('mobile')->validate();
  137. // 接收数据
  138. $phone = $Request->input('phone', '');
  139. // 接收数据
  140. $password = $Request->input('password', '');
  141. // 查询用户
  142. $admin = $EmployeeModel->where('mobile', $phone)->first(['company_id','id as uid', 'name as username', 'mobile as phone', 'status', 'password', 'insert_time', 'update_time']);
  143. // 用户不存在
  144. if (!$admin) return json_send(['code' => 'error', 'msg' => '密码错误或账号不存在']);
  145. // 用户不存在
  146. if ($admin['status']) return json_send(['code' => 'error', 'msg' => '该账号已停用']);
  147. // 转数组
  148. $admin = $admin->toArray();
  149. // 比对密码
  150. if (md5($password) != $admin['password']) return json_send(['code' => 'error', 'msg' => '密码错误或账号不存在']);
  151. // 登录
  152. $accessToken = $EmployeeModel->Login($admin['uid'],$admin['company_id'], 'manager');
  153. // 比对密码
  154. if (isset($accessToken['error'])) return json_send(['code' => 'error', 'msg' => '登录失败', 'data' => $accessToken['data']]);
  155. // 获取权限列表
  156. $accessToken['username'] = $admin['username'];
  157. // 表单令牌
  158. return json_send(['code' => 'success', 'msg' => '登录成功', 'data' => $accessToken]);
  159. }
  160. /**
  161. * 发送验证码
  162. * @author 唐远望
  163. * @version 1.0
  164. * @date 2026-01-15
  165. * @param string phone 手机号码
  166. *
  167. */
  168. public function send_code(Request $Request, EmployeeModel $EmployeeModel)
  169. {
  170. // 验证规则
  171. $Request->scene('send_code')->validate();
  172. // 接收数据
  173. $mobile = request('phone', '');
  174. if (!$mobile) return json_send(['code' => 'error', 'msg' => '请先填写手机号']);
  175. // 获取数据
  176. $session = Cache::get('loginSmsCode_' . $mobile);
  177. // 如果有数据,并且验证码创建的时间在一分钟之内
  178. if ($session && time() - $session['create_time'] < 60) return json_send(['code' => 'error', 'msg' => '请稍后再试']);
  179. // 查询用户
  180. $admin = $EmployeeModel->query()->where('mobile', $mobile)->first(['status']);
  181. if ($admin && $admin['status']) return json_send(['code' => 'error', 'msg' => '用户已被停用']);
  182. $code = strval(rand(100000, 999999));
  183. $result = Sms::sendCode($mobile, $code);
  184. if (isset($result['error'])) return json_send(['code' => 'error', 'msg' => $result['error']]);
  185. $session = ['code' => $code, 'mobile' => $mobile, 'create_time' => time()];
  186. Cache::put('loginSmsCode_' . $mobile, $session, 60);
  187. return json_send(['code' => 'success', 'msg' => '发送成功', 'data' => $code]);
  188. }
  189. /**
  190. * 邮箱登录 /manager/login/email
  191. * @author 唐远望
  192. * @version 1.0
  193. * @date 2025-12-04
  194. * @param string email 邮箱号码
  195. * @param string password 登录密码
  196. *
  197. */
  198. public function email(Request $Request, AuthRule $AuthRule, EmployeeModel $EmployeeModel)
  199. {
  200. // 验证规则
  201. $Request->scene('email')->validate();
  202. // 接收数据
  203. $email = $Request->input('email', '');
  204. // 接收数据
  205. $password = $Request->input('password', '');
  206. // 查询用户
  207. $admin = $EmployeeModel->where('email', $email)->first(['company_id','company_id','id as uid', 'name as username', 'mobile as phone', 'status', 'password', 'insert_time', 'update_time']);
  208. // 用户不存在
  209. if (!$admin) return json_send(['code' => 'error', 'msg' => '密码错误或账号不存在']);
  210. // 用户不存在
  211. if ($admin['status']) return json_send(['code' => 'error', 'msg' => '该账号已停用']);
  212. // 转数组
  213. $admin = $admin->toArray();
  214. // 比对密码
  215. if (md5($password) != $admin['password']) return json_send(['code' => 'error', 'msg' => '密码错误或账号不存在']);
  216. // 登录
  217. $accessToken = $EmployeeModel->Login($admin['uid'],$admin['company_id'], 'manager');
  218. // 比对密码
  219. if (isset($accessToken['error'])) return json_send(['code' => 'error', 'msg' => '登录失败', 'data' => $accessToken['data']]);
  220. // 获取权限列表
  221. $accessToken['username'] = $admin['username'];
  222. // 表单令牌
  223. return json_send(['code' => 'success', 'msg' => '登录成功', 'data' => $accessToken]);
  224. }
  225. /**
  226. * 手机验证码登录 /manager/login/mobile_code
  227. * @author 唐远望
  228. * @version 1.0
  229. * @date 2026-01-15
  230. * @param string mobile 手机号码
  231. * @param string code 验证码
  232. *
  233. */
  234. public function mobile_code(Request $Request, AuthRule $AuthRule, EmployeeModel $EmployeeModel)
  235. {
  236. // 验证规则
  237. $Request->scene('mobile_code')->validate();
  238. // 接收数据
  239. $phone = $Request->input('phone', '');
  240. // 接收数据
  241. $code = $Request->input('code', '');
  242. // 获取数据
  243. $session = Cache::get('loginSmsCode_' . $phone);
  244. if (!$session) return json_send(['code' => 'error', 'msg' => '请先获取手机号验证码']);
  245. if ($session['code'] != $code || $session['phone'] != $phone) return json_send(['code' => 'error', 'msg' => '验证码错误']);
  246. // 查询用户
  247. $admin = $EmployeeModel->where('mobile', $phone)->first(['company_id','id as uid', 'name as username', 'mobile as phone', 'status', 'password', 'insert_time', 'update_time']);
  248. // 用户不存在
  249. if (!$admin) return json_send(['code' => 'error', 'msg' => '账号不存在']);
  250. // 用户不存在
  251. if ($admin['status']) return json_send(['code' => 'error', 'msg' => '该账号已停用']);
  252. // 转数组
  253. $admin = $admin->toArray();
  254. // 登录
  255. $accessToken = $EmployeeModel->Login($admin['uid'],$admin['company_id'], 'manager');
  256. // 比对密码
  257. if (isset($accessToken['error'])) return json_send(['code' => 'error', 'msg' => '登录失败', 'data' => $accessToken['data']]);
  258. // 获取权限列表
  259. $accessToken['username'] = $admin['username'];
  260. // 表单令牌
  261. return json_send(['code' => 'success', 'msg' => '登录成功', 'data' => $accessToken]);
  262. }
  263. /**
  264. * 微信扫码登录 /manager/login/wechat
  265. * @author 唐远望
  266. * @version 1.0
  267. * @date 2026-01-19
  268. * @param string open_code 微信扫码登录的code
  269. *
  270. */
  271. public function wechat(Request $Request, AuthRule $AuthRule, EmployeeModel $EmployeeModel, EmployeeOpenidModel $EmployeeOpenidModel)
  272. {
  273. // 验证规则
  274. $Request->scene('wechat')->validate();
  275. // 接收数据
  276. $open_code = $Request->input('open_code', '');
  277. $wechatApp = new WeChatWebApp();
  278. $tokenData = $wechatApp->getAccessTokenByCode($open_code);
  279. if (!$tokenData) return json_send(['code' => 'error', 'msg' => '获取微信用户信息失败']);
  280. $user_open_data = $EmployeeOpenidModel->where(['openid' => $tokenData['openid']])->first();
  281. if (!$user_open_data) return json_send(['code' => 'error', 'msg' => '未绑定账号,请登录后在绑定']);
  282. // 查询用户
  283. $admin = $EmployeeModel->where('id', $user_open_data->employee_id)->first(['company_id','company_id','id as uid', 'name as username', 'mobile as phone', 'status', 'password', 'insert_time', 'update_time']);
  284. // 用户不存在
  285. if (!$admin) return json_send(['code' => 'error', 'msg' => '账号不存在']);
  286. // 用户不存在
  287. if ($admin['status']) return json_send(['code' => 'error', 'msg' => '该账号已停用']);
  288. // 转数组
  289. $admin = $admin->toArray();
  290. // 登录
  291. $accessToken = $EmployeeModel->Login($admin['uid'],$admin['company_id'], 'manager');
  292. // 比对密码
  293. if (isset($accessToken['error'])) return json_send(['code' => 'error', 'msg' => '登录失败', 'data' => $accessToken['data']]);
  294. // 获取权限列表
  295. $accessToken['username'] = $admin['username'];
  296. // 表单令牌
  297. return json_send(['code' => 'success', 'msg' => '登录成功', 'data' => $accessToken]);
  298. }
  299. /**
  300. * 微信扫码授权绑定 /manager/login/wechat_bind
  301. * @author 唐远望
  302. * @version 1.0
  303. * @date 2026-01-19
  304. * @param string open_code 微信扫码登录的code
  305. *
  306. */
  307. public function wechat_bind(Request $Request,EmployeeOpenidModel $EmployeeOpenidModel)
  308. {
  309. // 验证规则
  310. $Request->scene('wechat_bind')->validate();
  311. $uid = request('access_token.uid', 0);
  312. // 接收数据
  313. $open_code = $Request->input('open_code', '');
  314. $wechatApp = new WeChatWebApp();
  315. $tokenData = $wechatApp->getAccessTokenByCode($open_code);
  316. if (!$tokenData) return json_send(['code' => 'error', 'msg' => '获取微信用户信息失败']);
  317. $user_open_data = $EmployeeOpenidModel->where(['openid' => $tokenData['openid'],'employee_id'=> $uid])->first();
  318. if ($user_open_data) return json_send(['code' => 'error', 'msg' => '微信已绑定,无需重复绑定']);
  319. //新增绑定记录
  320. $EmployeeOpenidModel->create([
  321. 'openid' => $tokenData['openid'],
  322. 'unionid' => isset($tokenData['unionid']) ? $tokenData['unionid'] : '',
  323. 'employee_id' => $uid,
  324. 'insert_time' => time(),
  325. ]);
  326. return json_send(['code' => 'success', 'msg' => '绑定成功','data'=>'']);
  327. }
  328. }