Login.php 10 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260
  1. <?php
  2. namespace App\Http\Controllers\Manager;
  3. use App\Models\Manager\AdminUser;
  4. use App\Http\Requests\Manager\Login as Request;
  5. use App\Models\Manager\AuthRule;
  6. use App\Facades\Servers\Encrypts\AccessToken;
  7. use App\Models\Manager\Personnel\Employee as EmployeeModel;
  8. use App\Facades\Servers\Sms\VerifyCode as Sms;
  9. /**
  10. * 管理后台登录控制器
  11. * @author 唐远望
  12. * @version 1.0
  13. * @date 2025-12-02
  14. *
  15. * */
  16. class Login extends Manager
  17. {
  18. /**
  19. * 登录方法 /manager/login/index
  20. * @author 唐远望
  21. * @version 1.0
  22. * @date 2025-12-02
  23. * @param string username 登录账号
  24. * @param string password 登录密码
  25. *
  26. * */
  27. public function index(Request $Request, AdminUser $AdminUser, AuthRule $AuthRule, EmployeeModel $EmployeeModel)
  28. {
  29. // 验证规则
  30. $Request->scene('login')->validate();
  31. // 接收数据
  32. $username = $Request->input('username', '');
  33. // 接收数据
  34. $password = $Request->input('password', '');
  35. if (strtolower($username) == 'admin') {
  36. // 查询用户
  37. $admin = $AdminUser->orWhere('username', $username)->first(['uid', 'username', 'phone', 'status', 'password', 'insert_time', 'update_time']);
  38. // 用户不存在
  39. if (!$admin) return json_send(['code' => 'error', 'msg' => '密码错误或账号不存在']);
  40. // 用户不存在
  41. if ($admin['status']) return json_send(['code' => 'error', 'msg' => '该账号已停用']);
  42. // 转数组
  43. $admin = $admin->toArray();
  44. // 比对密码
  45. if (md5($password) != $admin['password']) return json_send(['code' => 'error', 'msg' => '密码错误或账号不存在']);
  46. // 登录
  47. $accessToken = $AdminUser->Login($admin['uid'], 'manager');
  48. // 比对密码
  49. if (isset($accessToken['error'])) return json_send(['code' => 'error', 'msg' => '登录失败', 'data' => $accessToken['data']]);
  50. // 获取权限列表
  51. $accessToken['username'] = $admin['username'];
  52. // 获取权限列表
  53. $accessToken['auth_rules'] = $AuthRule->getAuthList($admin['uid'], '1', 'manager');
  54. } else {
  55. $admin = $EmployeeModel->where('employee_code', $username)->first(['id as uid', 'name as username', 'mobile as phone', 'status', 'password', 'insert_time', 'update_time']);
  56. // 用户不存在
  57. if (!$admin) return json_send(['code' => 'error', 'msg' => '密码错误或账号不存在']);
  58. // 用户不存在
  59. if ($admin['status']) return json_send(['code' => 'error', 'msg' => '该账号已停用']);
  60. // 转数组
  61. $admin = $admin->toArray();
  62. // 比对密码
  63. if (md5($password) != $admin['password']) return json_send(['code' => 'error', 'msg' => '密码错误或账号不存在']);
  64. // 登录
  65. $accessToken = $EmployeeModel->Login($admin['uid'], 'manager');
  66. // 比对密码
  67. if (isset($accessToken['error'])) return json_send(['code' => 'error', 'msg' => '登录失败', 'data' => $accessToken['data']]);
  68. // 获取权限列表
  69. $accessToken['username'] = $admin['username'];
  70. $accessToken['auth_rules'] = $AuthRule->getAuthList($admin['uid'], '0', 'manager');
  71. }
  72. // 表单令牌
  73. return json_send(['code' => 'success', 'msg' => '登录成功', 'data' => $accessToken]);
  74. }
  75. /**
  76. * 登录方法 /manager/login/out
  77. * @author 唐远望
  78. * @version 1.0
  79. * @date 2025-12-02
  80. * @param string username 登录账号
  81. * @param string password 登录密码
  82. *
  83. * */
  84. public function out(Request $Request, AdminUser $AdminUser, EmployeeModel $EmployeeModel)
  85. {
  86. $token = $Request->input('access_token_manager', '');
  87. // 解码
  88. $userInfo = AccessToken::decode($token);
  89. // 验证规则
  90. $uid = $userInfo['uid'];
  91. $is_admin = $userInfo['is_admin'];
  92. if ($is_admin == '1') {
  93. // 退出登录
  94. $AdminUser->LoginOut($uid, 'manager');
  95. } else {
  96. $EmployeeModel->LoginOut($uid, 'manager');
  97. }
  98. // 表单令牌
  99. return json_send(['code' => 'success', 'msg' => '退出成功', 'data' => '']);
  100. }
  101. /**
  102. * 手机号码登录 /manager/login/mobile
  103. * @author 唐远望
  104. * @version 1.0
  105. * @date 2025-12-04
  106. * @param string mobile 手机号码
  107. * @param string password 登录密码
  108. *
  109. */
  110. public function mobile(Request $Request, AuthRule $AuthRule, EmployeeModel $EmployeeModel)
  111. {
  112. // 验证规则
  113. $Request->scene('mobile')->validate();
  114. // 接收数据
  115. $phone = $Request->input('phone', '');
  116. // 接收数据
  117. $password = $Request->input('password', '');
  118. // 查询用户
  119. $admin = $EmployeeModel->where('mobile', $phone)->first(['id as uid', 'name as username', 'mobile as phone', 'status', 'password', 'insert_time', 'update_time']);
  120. // 用户不存在
  121. if (!$admin) return json_send(['code' => 'error', 'msg' => '密码错误或账号不存在']);
  122. // 用户不存在
  123. if ($admin['status']) return json_send(['code' => 'error', 'msg' => '该账号已停用']);
  124. // 转数组
  125. $admin = $admin->toArray();
  126. // 比对密码
  127. if (md5($password) != $admin['password']) return json_send(['code' => 'error', 'msg' => '密码错误或账号不存在']);
  128. // 登录
  129. $accessToken = $EmployeeModel->Login($admin['uid'], 'manager');
  130. // 比对密码
  131. if (isset($accessToken['error'])) return json_send(['code' => 'error', 'msg' => '登录失败', 'data' => $accessToken['data']]);
  132. // 获取权限列表
  133. $accessToken['username'] = $admin['username'];
  134. // 获取权限列表
  135. $accessToken['auth_rules'] = $AuthRule->getAuthList($admin['uid'], 'manager');;
  136. // 表单令牌
  137. return json_send(['code' => 'success', 'msg' => '登录成功', 'data' => $accessToken]);
  138. }
  139. /**
  140. * 发送验证码
  141. * @author 唐远望
  142. * @version 1.0
  143. * @date 2026-01-15
  144. * @param string phone 手机号码
  145. *
  146. */
  147. public function send_code(Request $Request, EmployeeModel $EmployeeModel)
  148. {
  149. // 验证规则
  150. $Request->scene('send_code')->validate();
  151. // 接收数据
  152. $mobile = request('phone', '');
  153. if (!$mobile) return json_send(['code' => 'error', 'msg' => '请先填写手机号']);
  154. // 获取数据
  155. $session = session('loginSmsCode');
  156. // 如果有数据,并且验证码创建的时间在一分钟之内
  157. if ($session && time() - $session['create_time'] < 60) return json_send(['code' => 'error', 'msg' => '请稍后再试']);
  158. // 查询用户
  159. $admin = $EmployeeModel->query()->where('mobile', $mobile)->first(['status']);
  160. if ($admin && $admin['status']) return json_send(['code' => 'error', 'msg' => '用户已被停用']);
  161. $code = strval(rand(100000, 999999));
  162. $result = Sms::sendCode($mobile, $code);
  163. if (isset($result['error'])) return json_send(['code' => 'error', 'msg' => $result['error']]);
  164. $session = ['code' => $code, 'mobile' => $mobile, 'create_time' => time()];
  165. session(['loginSmsCode' => $session]);
  166. return json_send(['code' => 'success', 'msg' => '发送成功', 'data' => $code]);
  167. }
  168. /**
  169. * 邮箱登录 /manager/login/email
  170. * @author 唐远望
  171. * @version 1.0
  172. * @date 2025-12-04
  173. * @param string email 邮箱号码
  174. * @param string password 登录密码
  175. *
  176. */
  177. public function email(Request $Request, AuthRule $AuthRule, EmployeeModel $EmployeeModel)
  178. {
  179. // 验证规则
  180. $Request->scene('email')->validate();
  181. // 接收数据
  182. $email = $Request->input('email', '');
  183. // 接收数据
  184. $password = $Request->input('password', '');
  185. // 查询用户
  186. $admin = $EmployeeModel->where('email', $email)->first(['id as uid', 'name as username', 'mobile as phone', 'status', 'password', 'insert_time', 'update_time']);
  187. // 用户不存在
  188. if (!$admin) return json_send(['code' => 'error', 'msg' => '密码错误或账号不存在']);
  189. // 用户不存在
  190. if ($admin['status']) return json_send(['code' => 'error', 'msg' => '该账号已停用']);
  191. // 转数组
  192. $admin = $admin->toArray();
  193. // 比对密码
  194. if (md5($password) != $admin['password']) return json_send(['code' => 'error', 'msg' => '密码错误或账号不存在']);
  195. // 登录
  196. $accessToken = $EmployeeModel->Login($admin['uid'], 'manager');
  197. // 比对密码
  198. if (isset($accessToken['error'])) return json_send(['code' => 'error', 'msg' => '登录失败', 'data' => $accessToken['data']]);
  199. // 获取权限列表
  200. $accessToken['username'] = $admin['username'];
  201. // 获取权限列表
  202. $accessToken['auth_rules'] = $AuthRule->getAuthList($admin['uid'], 'manager');;
  203. // 表单令牌
  204. return json_send(['code' => 'success', 'msg' => '登录成功', 'data' => $accessToken]);
  205. }
  206. /**
  207. * 手机验证码登录 /manager/login/mobile_code
  208. * @author 唐远望
  209. * @version 1.0
  210. * @date 2026-01-15
  211. * @param string mobile 手机号码
  212. * @param string code 验证码
  213. *
  214. */
  215. public function mobile_code(Request $Request, AuthRule $AuthRule, EmployeeModel $EmployeeModel)
  216. {
  217. // 验证规则
  218. $Request->scene('mobile_code')->validate();
  219. // 接收数据
  220. $phone = $Request->input('phone', '');
  221. // 接收数据
  222. $code = $Request->input('code', '');
  223. // 获取数据
  224. $session = session('loginSmsCode');
  225. if (!$session) return json_send(['code' => 'error', 'msg' => '请先获取手机号验证码']);
  226. if ($session['code'] != $code || $session['phone'] != $phone) return json_send(['code' => 'error', 'msg' => '验证码错误']);
  227. // 查询用户
  228. $admin = $EmployeeModel->where('mobile', $phone)->first(['id as uid', 'name as username', 'mobile as phone', 'status', 'password', 'insert_time', 'update_time']);
  229. // 用户不存在
  230. if (!$admin) return json_send(['code' => 'error', 'msg' => '账号不存在']);
  231. // 用户不存在
  232. if ($admin['status']) return json_send(['code' => 'error', 'msg' => '该账号已停用']);
  233. // 转数组
  234. $admin = $admin->toArray();
  235. // 登录
  236. $accessToken = $EmployeeModel->Login($admin['uid'], 'manager');
  237. // 比对密码
  238. if (isset($accessToken['error'])) return json_send(['code' => 'error', 'msg' => '登录失败', 'data' => $accessToken['data']]);
  239. // 获取权限列表
  240. $accessToken['username'] = $admin['username'];
  241. // 获取权限列表
  242. $accessToken['auth_rules'] = $AuthRule->getAuthList($admin['uid'], 'manager');;
  243. // 表单令牌
  244. return json_send(['code' => 'success', 'msg' => '登录成功', 'data' => $accessToken]);
  245. }
  246. }