Login.php 13 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332
  1. <?php
  2. namespace App\Http\Controllers\Manager;
  3. use App\Models\Manager\AdminUser;
  4. use App\Http\Requests\Manager\Login as Request;
  5. use App\Models\Manager\AuthRule;
  6. use App\Facades\Servers\Encrypts\AccessToken;
  7. use App\Models\Manager\Personnel\Employee as EmployeeModel;
  8. use App\Facades\Servers\Sms\VerifyCode as Sms;
  9. use App\Models\Manager\Personnel\EmployeeOpenid as EmployeeOpenidModel;
  10. use App\Servers\Wechat\WeChatWebApp;
  11. /**
  12. * 管理后台登录控制器
  13. * @author 唐远望
  14. * @version 1.0
  15. * @date 2025-12-02
  16. *
  17. * */
  18. class Login extends Manager
  19. {
  20. /**
  21. * 登录方法 /manager/login/index
  22. * @author 唐远望
  23. * @version 1.0
  24. * @date 2025-12-02
  25. * @param string username 登录账号
  26. * @param string password 登录密码
  27. *
  28. * */
  29. public function index(Request $Request, AdminUser $AdminUser, AuthRule $AuthRule, EmployeeModel $EmployeeModel)
  30. {
  31. // 验证规则
  32. $Request->scene('login')->validate();
  33. // 接收数据
  34. $username = $Request->input('username', '');
  35. // 接收数据
  36. $password = $Request->input('password', '');
  37. if (strtolower($username) == 'admin') {
  38. // 查询用户
  39. $admin = $AdminUser->orWhere('username', $username)->first(['uid', 'username', 'phone', 'status', 'password', 'insert_time', 'update_time']);
  40. // 用户不存在
  41. if (!$admin) return json_send(['code' => 'error', 'msg' => '密码错误或账号不存在']);
  42. // 用户不存在
  43. if ($admin['status']) return json_send(['code' => 'error', 'msg' => '该账号已停用']);
  44. // 转数组
  45. $admin = $admin->toArray();
  46. // 比对密码
  47. if (md5($password) != $admin['password']) return json_send(['code' => 'error', 'msg' => '密码错误或账号不存在']);
  48. // 登录
  49. $accessToken = $AdminUser->Login($admin['uid'], 'manager');
  50. // 比对密码
  51. if (isset($accessToken['error'])) return json_send(['code' => 'error', 'msg' => '登录失败', 'data' => $accessToken['data']]);
  52. // 获取权限列表
  53. $accessToken['username'] = $admin['username'];
  54. // 获取权限列表
  55. $accessToken['auth_rules'] = $AuthRule->getAuthList($admin['uid'], '1', 'manager');
  56. } else {
  57. $admin = $EmployeeModel->where('employee_code', $username)->first(['id as uid', 'name as username', 'mobile as phone', 'status', 'password', 'insert_time', 'update_time']);
  58. // 用户不存在
  59. if (!$admin) return json_send(['code' => 'error', 'msg' => '密码错误或账号不存在']);
  60. // 用户不存在
  61. if ($admin['status']) return json_send(['code' => 'error', 'msg' => '该账号已停用']);
  62. // 转数组
  63. $admin = $admin->toArray();
  64. // 比对密码
  65. if (md5($password) != $admin['password']) return json_send(['code' => 'error', 'msg' => '密码错误或账号不存在']);
  66. // 登录
  67. $accessToken = $EmployeeModel->Login($admin['uid'], 'manager');
  68. // 比对密码
  69. if (isset($accessToken['error'])) return json_send(['code' => 'error', 'msg' => '登录失败', 'data' => $accessToken['data']]);
  70. // 获取权限列表
  71. $accessToken['username'] = $admin['username'];
  72. $accessToken['auth_rules'] = $AuthRule->getAuthList($admin['uid'], '0', 'manager');
  73. }
  74. // 表单令牌
  75. return json_send(['code' => 'success', 'msg' => '登录成功', 'data' => $accessToken]);
  76. }
  77. /**
  78. * 登录方法 /manager/login/out
  79. * @author 唐远望
  80. * @version 1.0
  81. * @date 2025-12-02
  82. * @param string username 登录账号
  83. * @param string password 登录密码
  84. *
  85. * */
  86. public function out(Request $Request, AdminUser $AdminUser, EmployeeModel $EmployeeModel)
  87. {
  88. $token = $Request->input('access_token_manager', '');
  89. // 解码
  90. $userInfo = AccessToken::decode($token);
  91. // 验证规则
  92. $uid = $userInfo['uid'];
  93. $is_admin = $userInfo['is_admin'];
  94. if ($is_admin == '1') {
  95. // 退出登录
  96. $AdminUser->LoginOut($uid, 'manager');
  97. } else {
  98. $EmployeeModel->LoginOut($uid, 'manager');
  99. }
  100. // 表单令牌
  101. return json_send(['code' => 'success', 'msg' => '退出成功', 'data' => '']);
  102. }
  103. /**
  104. * 手机号码登录 /manager/login/mobile
  105. * @author 唐远望
  106. * @version 1.0
  107. * @date 2025-12-04
  108. * @param string mobile 手机号码
  109. * @param string password 登录密码
  110. *
  111. */
  112. public function mobile(Request $Request, AuthRule $AuthRule, EmployeeModel $EmployeeModel)
  113. {
  114. // 验证规则
  115. $Request->scene('mobile')->validate();
  116. // 接收数据
  117. $phone = $Request->input('phone', '');
  118. // 接收数据
  119. $password = $Request->input('password', '');
  120. // 查询用户
  121. $admin = $EmployeeModel->where('mobile', $phone)->first(['id as uid', 'name as username', 'mobile as phone', 'status', 'password', 'insert_time', 'update_time']);
  122. // 用户不存在
  123. if (!$admin) return json_send(['code' => 'error', 'msg' => '密码错误或账号不存在']);
  124. // 用户不存在
  125. if ($admin['status']) return json_send(['code' => 'error', 'msg' => '该账号已停用']);
  126. // 转数组
  127. $admin = $admin->toArray();
  128. // 比对密码
  129. if (md5($password) != $admin['password']) return json_send(['code' => 'error', 'msg' => '密码错误或账号不存在']);
  130. // 登录
  131. $accessToken = $EmployeeModel->Login($admin['uid'], 'manager');
  132. // 比对密码
  133. if (isset($accessToken['error'])) return json_send(['code' => 'error', 'msg' => '登录失败', 'data' => $accessToken['data']]);
  134. // 获取权限列表
  135. $accessToken['username'] = $admin['username'];
  136. // 获取权限列表
  137. $accessToken['auth_rules'] = $AuthRule->getAuthList($admin['uid'], 'manager');;
  138. // 表单令牌
  139. return json_send(['code' => 'success', 'msg' => '登录成功', 'data' => $accessToken]);
  140. }
  141. /**
  142. * 发送验证码
  143. * @author 唐远望
  144. * @version 1.0
  145. * @date 2026-01-15
  146. * @param string phone 手机号码
  147. *
  148. */
  149. public function send_code(Request $Request, EmployeeModel $EmployeeModel)
  150. {
  151. // 验证规则
  152. $Request->scene('send_code')->validate();
  153. // 接收数据
  154. $mobile = request('phone', '');
  155. if (!$mobile) return json_send(['code' => 'error', 'msg' => '请先填写手机号']);
  156. // 获取数据
  157. $session = session('loginSmsCode');
  158. // 如果有数据,并且验证码创建的时间在一分钟之内
  159. if ($session && time() - $session['create_time'] < 60) return json_send(['code' => 'error', 'msg' => '请稍后再试']);
  160. // 查询用户
  161. $admin = $EmployeeModel->query()->where('mobile', $mobile)->first(['status']);
  162. if ($admin && $admin['status']) return json_send(['code' => 'error', 'msg' => '用户已被停用']);
  163. $code = strval(rand(100000, 999999));
  164. $result = Sms::sendCode($mobile, $code);
  165. if (isset($result['error'])) return json_send(['code' => 'error', 'msg' => $result['error']]);
  166. $session = ['code' => $code, 'mobile' => $mobile, 'create_time' => time()];
  167. session(['loginSmsCode' => $session]);
  168. return json_send(['code' => 'success', 'msg' => '发送成功', 'data' => $code]);
  169. }
  170. /**
  171. * 邮箱登录 /manager/login/email
  172. * @author 唐远望
  173. * @version 1.0
  174. * @date 2025-12-04
  175. * @param string email 邮箱号码
  176. * @param string password 登录密码
  177. *
  178. */
  179. public function email(Request $Request, AuthRule $AuthRule, EmployeeModel $EmployeeModel)
  180. {
  181. // 验证规则
  182. $Request->scene('email')->validate();
  183. // 接收数据
  184. $email = $Request->input('email', '');
  185. // 接收数据
  186. $password = $Request->input('password', '');
  187. // 查询用户
  188. $admin = $EmployeeModel->where('email', $email)->first(['id as uid', 'name as username', 'mobile as phone', 'status', 'password', 'insert_time', 'update_time']);
  189. // 用户不存在
  190. if (!$admin) return json_send(['code' => 'error', 'msg' => '密码错误或账号不存在']);
  191. // 用户不存在
  192. if ($admin['status']) return json_send(['code' => 'error', 'msg' => '该账号已停用']);
  193. // 转数组
  194. $admin = $admin->toArray();
  195. // 比对密码
  196. if (md5($password) != $admin['password']) return json_send(['code' => 'error', 'msg' => '密码错误或账号不存在']);
  197. // 登录
  198. $accessToken = $EmployeeModel->Login($admin['uid'], 'manager');
  199. // 比对密码
  200. if (isset($accessToken['error'])) return json_send(['code' => 'error', 'msg' => '登录失败', 'data' => $accessToken['data']]);
  201. // 获取权限列表
  202. $accessToken['username'] = $admin['username'];
  203. // 获取权限列表
  204. $accessToken['auth_rules'] = $AuthRule->getAuthList($admin['uid'], 'manager');;
  205. // 表单令牌
  206. return json_send(['code' => 'success', 'msg' => '登录成功', 'data' => $accessToken]);
  207. }
  208. /**
  209. * 手机验证码登录 /manager/login/mobile_code
  210. * @author 唐远望
  211. * @version 1.0
  212. * @date 2026-01-15
  213. * @param string mobile 手机号码
  214. * @param string code 验证码
  215. *
  216. */
  217. public function mobile_code(Request $Request, AuthRule $AuthRule, EmployeeModel $EmployeeModel)
  218. {
  219. // 验证规则
  220. $Request->scene('mobile_code')->validate();
  221. // 接收数据
  222. $phone = $Request->input('phone', '');
  223. // 接收数据
  224. $code = $Request->input('code', '');
  225. // 获取数据
  226. $session = session('loginSmsCode');
  227. if (!$session) return json_send(['code' => 'error', 'msg' => '请先获取手机号验证码']);
  228. if ($session['code'] != $code || $session['phone'] != $phone) return json_send(['code' => 'error', 'msg' => '验证码错误']);
  229. // 查询用户
  230. $admin = $EmployeeModel->where('mobile', $phone)->first(['id as uid', 'name as username', 'mobile as phone', 'status', 'password', 'insert_time', 'update_time']);
  231. // 用户不存在
  232. if (!$admin) return json_send(['code' => 'error', 'msg' => '账号不存在']);
  233. // 用户不存在
  234. if ($admin['status']) return json_send(['code' => 'error', 'msg' => '该账号已停用']);
  235. // 转数组
  236. $admin = $admin->toArray();
  237. // 登录
  238. $accessToken = $EmployeeModel->Login($admin['uid'], 'manager');
  239. // 比对密码
  240. if (isset($accessToken['error'])) return json_send(['code' => 'error', 'msg' => '登录失败', 'data' => $accessToken['data']]);
  241. // 获取权限列表
  242. $accessToken['username'] = $admin['username'];
  243. // 获取权限列表
  244. $accessToken['auth_rules'] = $AuthRule->getAuthList($admin['uid'], 'manager');;
  245. // 表单令牌
  246. return json_send(['code' => 'success', 'msg' => '登录成功', 'data' => $accessToken]);
  247. }
  248. /**
  249. * 微信扫码登录 /manager/login/wechat
  250. * @author 唐远望
  251. * @version 1.0
  252. * @date 2026-01-19
  253. * @param string open_code 微信扫码登录的code
  254. *
  255. */
  256. public function wechat(Request $Request, AuthRule $AuthRule, EmployeeModel $EmployeeModel, EmployeeOpenidModel $EmployeeOpenidModel)
  257. {
  258. // 验证规则
  259. $Request->scene('wechat')->validate();
  260. // 接收数据
  261. $open_code = $Request->input('open_code', '');
  262. $wechatApp = new WeChatWebApp();
  263. $tokenData = $wechatApp->getAccessTokenByCode($open_code);
  264. if (!$tokenData) return json_send(['code' => 'error', 'msg' => '获取微信用户信息失败']);
  265. $user_open_data = $EmployeeOpenidModel->where(['openid' => $tokenData['openid']])->first();
  266. if (!$user_open_data) return json_send(['code' => 'error', 'msg' => '未绑定账号,请登录后在绑定']);
  267. // 查询用户
  268. $admin = $EmployeeModel->where('id', $user_open_data->employee_id)->first(['id as uid', 'name as username', 'mobile as phone', 'status', 'password', 'insert_time', 'update_time']);
  269. // 用户不存在
  270. if (!$admin) return json_send(['code' => 'error', 'msg' => '账号不存在']);
  271. // 用户不存在
  272. if ($admin['status']) return json_send(['code' => 'error', 'msg' => '该账号已停用']);
  273. // 转数组
  274. $admin = $admin->toArray();
  275. // 登录
  276. $accessToken = $EmployeeModel->Login($admin['uid'], 'manager');
  277. // 比对密码
  278. if (isset($accessToken['error'])) return json_send(['code' => 'error', 'msg' => '登录失败', 'data' => $accessToken['data']]);
  279. // 获取权限列表
  280. $accessToken['username'] = $admin['username'];
  281. // 获取权限列表
  282. $accessToken['auth_rules'] = $AuthRule->getAuthList($admin['uid'], 'manager');;
  283. // 表单令牌
  284. return json_send(['code' => 'success', 'msg' => '登录成功', 'data' => $accessToken]);
  285. }
  286. /**
  287. * 微信扫码授权绑定 /manager/login/wechat_bind
  288. * @author 唐远望
  289. * @version 1.0
  290. * @date 2026-01-19
  291. * @param string open_code 微信扫码登录的code
  292. *
  293. */
  294. public function wechat_bind(Request $Request,EmployeeOpenidModel $EmployeeOpenidModel)
  295. {
  296. // 验证规则
  297. $Request->scene('wechat_bind')->validate();
  298. $uid = request('access_token.uid', 0);
  299. // 接收数据
  300. $open_code = $Request->input('open_code', '');
  301. $wechatApp = new WeChatWebApp();
  302. $tokenData = $wechatApp->getAccessTokenByCode($open_code);
  303. if (!$tokenData) return json_send(['code' => 'error', 'msg' => '获取微信用户信息失败']);
  304. $user_open_data = $EmployeeOpenidModel->where(['openid' => $tokenData['openid'],'employee_id'=> $uid])->first();
  305. if ($user_open_data) return json_send(['code' => 'error', 'msg' => '微信已绑定,无需重复绑定']);
  306. //新增绑定记录
  307. $EmployeeOpenidModel->create([
  308. 'openid' => $tokenData['openid'],
  309. 'unionid' => isset($tokenData['unionid']) ? $tokenData['unionid'] : '',
  310. 'employee_id' => $uid,
  311. 'insert_time' => time(),
  312. ]);
  313. return json_send(['code' => 'success', 'msg' => '绑定成功','data'=>'']);
  314. }
  315. }