Login.php 8.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220
  1. <?php
  2. namespace App\Http\Controllers\Api;
  3. use App\Models\Api\Personnel\Employee as EmployeeModel;
  4. use App\Http\Requests\Api\Login as Request;
  5. use App\Facades\Servers\Sms\VerifyCode as Sms;
  6. /**
  7. * API登录控制器
  8. * @author 唐远望
  9. * @version 1.0
  10. * @date 2025-12-09
  11. *
  12. */
  13. class Login extends Api
  14. {
  15. /**
  16. * 登录方法 /manager/login/index
  17. * @author 唐远望
  18. * @version 1.0
  19. * @date 2025-12-09
  20. * @param string employee_code 登录账号
  21. * @param string password 登录密码
  22. *
  23. * */
  24. public function index(Request $Request, EmployeeModel $EmployeeModel)
  25. {
  26. // 验证规则
  27. $Request->scene('login')->validate();
  28. // 接收数据
  29. $employee_code = $Request->input('employee_code', '');
  30. // 接收数据
  31. $password = $Request->input('password', '');
  32. // 查询用户
  33. $admin = $EmployeeModel->Where('employee_code', $employee_code)->first(['id', 'name', 'mobile', 'status', 'password', 'insert_time', 'update_time']);
  34. // 用户不存在
  35. if (!$admin || $admin['status']) return json_send(['code' => 'error', 'msg' => '密码错误或账号不存在']);
  36. // 用户不存在
  37. if ($admin['status']) return json_send(['code' => 'error', 'msg' => '该账号已停用']);
  38. // 转数组
  39. $admin = $admin->toArray();
  40. // 比对密码
  41. if (md5($password) != $admin['password']) return json_send(['code' => 'error', 'msg' => '密码错误或账号不存在']);
  42. // 登录
  43. $accessToken = $EmployeeModel->Login($admin['id'], 'api');
  44. // 比对密码
  45. if (isset($accessToken['error'])) return json_send(['code' => 'error', 'msg' => '登录失败', 'data' => $accessToken['data']]);
  46. // 获取权限列表
  47. $accessToken['username'] = $admin['name'];
  48. // 表单令牌
  49. return json_send(['code' => 'success', 'msg' => '登录成功', 'data' => $accessToken]);
  50. }
  51. /**
  52. * 退出方法 /manager/login/out
  53. * @author 唐远望
  54. * @version 1.0
  55. * @date 2025-12-09
  56. * @param string authcode 用户令牌
  57. *
  58. */
  59. public function out(EmployeeModel $EmployeeModel)
  60. {
  61. $user_info = $this->checkLogin();
  62. // 验证规则
  63. $uid =$user_info['uid'];
  64. // 退出登录
  65. $EmployeeModel->LoginOut($uid, 'api');
  66. // 表单令牌
  67. return json_send(['code' => 'success', 'msg' => '退出成功', 'data' => '']);
  68. }
  69. /**
  70. * 手机号码登录 /manager/login/mobile
  71. * @author 唐远望
  72. * @version 1.0
  73. * @date 2025-12-04
  74. * @param string mobile 手机号码
  75. * @param string password 登录密码
  76. *
  77. */
  78. public function mobile(Request $Request, EmployeeModel $EmployeeModel)
  79. {
  80. // 验证规则
  81. $Request->scene('mobile')->validate();
  82. // 接收数据
  83. $phone = $Request->input('phone', '');
  84. // 接收数据
  85. $password = $Request->input('password', '');
  86. // 查询用户
  87. $user_info = $EmployeeModel->where('mobile', $phone)->first(['id', 'name', 'mobile', 'status', 'password', 'insert_time', 'update_time']);
  88. // 用户不存在
  89. if (!$user_info || $user_info['status']) return json_send(['code' => 'error', 'msg' => '密码错误或账号不存在']);
  90. // 用户不存在
  91. if ($user_info['status']) return json_send(['code' => 'error', 'msg' => '该账号已停用']);
  92. // 转数组
  93. $user_info = $user_info->toArray();
  94. // 比对密码
  95. if (md5($password) != $user_info['password']) return json_send(['code' => 'error', 'msg' => '密码错误或账号不存在']);
  96. // 登录
  97. $accessToken = $EmployeeModel->Login($user_info['id'], 'api');
  98. // 比对密码
  99. if (isset($accessToken['error'])) return json_send(['code' => 'error', 'msg' => '登录失败', 'data' => $accessToken['data']]);
  100. // 获取权限列表
  101. $accessToken['username'] = $user_info['name'];
  102. // 表单令牌
  103. return json_send(['code' => 'success', 'msg' => '登录成功', 'data' => $accessToken]);
  104. }
  105. /**
  106. * 发送验证码
  107. * @author 唐远望
  108. * @version 1.0
  109. * @date 2026-01-16
  110. * @param string phone 手机号码
  111. *
  112. */
  113. public function send_code(Request $Request, EmployeeModel $EmployeeModel)
  114. {
  115. // 验证规则
  116. $Request->scene('send_code')->validate();
  117. // 接收数据
  118. $mobile = request('phone', '');
  119. if (!$mobile) return json_send(['code' => 'error', 'msg' => '请先填写手机号']);
  120. // 获取数据
  121. $session = session('loginSmsCode');
  122. // 如果有数据,并且验证码创建的时间在一分钟之内
  123. if ($session && time() - $session['create_time'] < 60) return json_send(['code' => 'error', 'msg' => '请稍后再试']);
  124. // 查询用户
  125. $admin = $EmployeeModel->query()->where('mobile', $mobile)->first(['status']);
  126. if ($admin && $admin['status']) return json_send(['code' => 'error', 'msg' => '用户已被停用']);
  127. $code = strval(rand(100000, 999999));
  128. $result = Sms::sendCode($mobile, $code);
  129. if (isset($result['error'])) return json_send(['code' => 'error', 'msg' => $result['error']]);
  130. $session = ['code' => $code, 'mobile' => $mobile, 'create_time' => time()];
  131. session(['loginSmsCode' => $session]);
  132. return json_send(['code' => 'success', 'msg' => '发送成功', 'data' => $code]);
  133. }
  134. /**
  135. * 邮箱登录 /manager/login/email
  136. * @author 唐远望
  137. * @version 1.0
  138. * @date 2026-01-16
  139. * @param string email 邮箱号码
  140. * @param string password 登录密码
  141. *
  142. */
  143. public function email(Request $Request,EmployeeModel $EmployeeModel)
  144. {
  145. // 验证规则
  146. $Request->scene('email')->validate();
  147. // 接收数据
  148. $email = $Request->input('email', '');
  149. // 接收数据
  150. $password = $Request->input('password', '');
  151. // 查询用户
  152. $admin = $EmployeeModel->where('email', $email)->first(['id', 'name', 'mobile', 'status', 'password', 'insert_time', 'update_time']);
  153. // 用户不存在
  154. if (!$admin) return json_send(['code' => 'error', 'msg' => '密码错误或账号不存在']);
  155. // 用户不存在
  156. if ($admin['status']) return json_send(['code' => 'error', 'msg' => '该账号已停用']);
  157. // 转数组
  158. $admin = $admin->toArray();
  159. // 比对密码
  160. if (md5($password) != $admin['password']) return json_send(['code' => 'error', 'msg' => '密码错误或账号不存在']);
  161. // 登录
  162. $accessToken = $EmployeeModel->Login($admin['uid'], 'api');
  163. // 比对密码
  164. if (isset($accessToken['error'])) return json_send(['code' => 'error', 'msg' => '登录失败', 'data' => $accessToken['data']]);
  165. // 获取权限列表
  166. $accessToken['username'] = $admin['name'];
  167. // 表单令牌
  168. return json_send(['code' => 'success', 'msg' => '登录成功', 'data' => $accessToken]);
  169. }
  170. /**
  171. * 手机验证码登录 /manager/login/mobile_code
  172. * @author 唐远望
  173. * @version 1.0
  174. * @date 2026-01-16
  175. * @param string mobile 手机号码
  176. * @param string code 验证码
  177. *
  178. */
  179. public function mobile_code(Request $Request,EmployeeModel $EmployeeModel)
  180. {
  181. // 验证规则
  182. $Request->scene('mobile_code')->validate();
  183. // 接收数据
  184. $phone = $Request->input('phone', '');
  185. // 接收数据
  186. $code = $Request->input('code', '');
  187. // 获取数据
  188. $session = session('loginSmsCode');
  189. if (!$session) return json_send(['code' => 'error', 'msg' => '请先获取手机号验证码']);
  190. if ($session['code'] != $code || $session['phone'] != $phone) return json_send(['code' => 'error', 'msg' => '验证码错误']);
  191. // 查询用户
  192. $admin = $EmployeeModel->where('mobile', $phone)->first(['id', 'name', 'mobile', 'status', 'password', 'insert_time', 'update_time']);
  193. // 用户不存在
  194. if (!$admin) return json_send(['code' => 'error', 'msg' => '账号不存在']);
  195. // 用户不存在
  196. if ($admin['status']) return json_send(['code' => 'error', 'msg' => '该账号已停用']);
  197. // 转数组
  198. $admin = $admin->toArray();
  199. // 登录
  200. $accessToken = $EmployeeModel->Login($admin['uid'],'api');
  201. // 比对密码
  202. if (isset($accessToken['error'])) return json_send(['code' => 'error', 'msg' => '登录失败', 'data' => $accessToken['data']]);
  203. // 获取权限列表
  204. $accessToken['username'] = $admin['name'];
  205. // 表单令牌
  206. return json_send(['code' => 'success', 'msg' => '登录成功', 'data' => $accessToken]);
  207. }
  208. }