Login.php 13 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333
  1. <?php
  2. namespace App\Http\Controllers\Manager;
  3. use App\Models\Manager\AdminUser;
  4. use App\Http\Requests\Manager\Login as Request;
  5. use App\Models\Manager\AuthRule;
  6. use App\Facades\Servers\Encrypts\AccessToken;
  7. use App\Models\Manager\Personnel\Employee as EmployeeModel;
  8. use App\Facades\Servers\Sms\VerifyCode as Sms;
  9. use App\Models\Manager\Personnel\EmployeeOpenid as EmployeeOpenidModel;
  10. use App\Servers\Wechat\WeChatWebApp;
  11. use App\Models\Manager\Personnel\RolesAuthRule as RolesAuthRuleModel;
  12. /**
  13. * 管理后台登录控制器
  14. * @author 唐远望
  15. * @version 1.0
  16. * @date 2025-12-02
  17. *
  18. * */
  19. class Login extends Manager
  20. {
  21. /**
  22. * 登录方法 /manager/login/index
  23. * @author 唐远望
  24. * @version 1.0
  25. * @date 2025-12-02
  26. * @param string username 登录账号
  27. * @param string password 登录密码
  28. *
  29. * */
  30. public function index(Request $Request, AdminUser $AdminUser, AuthRule $AuthRule, EmployeeModel $EmployeeModel,RolesAuthRuleModel $RolesAuthRuleModel)
  31. {
  32. // 验证规则
  33. $Request->scene('login')->validate();
  34. // 接收数据
  35. $username = $Request->input('username', '');
  36. // 接收数据
  37. $password = $Request->input('password', '');
  38. if (strtolower($username) == 'admin') {
  39. // 查询用户
  40. $admin = $AdminUser->orWhere('username', $username)->first(['uid', 'username', 'phone', 'status', 'password', 'insert_time', 'update_time']);
  41. // 用户不存在
  42. if (!$admin) return json_send(['code' => 'error', 'msg' => '密码错误或账号不存在']);
  43. // 用户不存在
  44. if ($admin['status']) return json_send(['code' => 'error', 'msg' => '该账号已停用']);
  45. // 转数组
  46. $admin = $admin->toArray();
  47. // 比对密码
  48. if (md5($password) != $admin['password']) return json_send(['code' => 'error', 'msg' => '密码错误或账号不存在']);
  49. // 登录
  50. $accessToken = $AdminUser->Login($admin['uid'], 'manager');
  51. // 比对密码
  52. if (isset($accessToken['error'])) return json_send(['code' => 'error', 'msg' => '登录失败', 'data' => $accessToken['data']]);
  53. // 获取权限列表
  54. $accessToken['username'] = $admin['username'];
  55. // 获取权限列表
  56. $accessToken['auth_rules'] = $AuthRule->getAuthList($admin['uid'], '1', 'manager');
  57. } else {
  58. $admin = $EmployeeModel->where('employee_code', $username)->first(['id as uid', 'name as username', 'mobile as phone', 'status', 'password', 'insert_time', 'update_time']);
  59. // 用户不存在
  60. if (!$admin) return json_send(['code' => 'error', 'msg' => '密码错误或账号不存在']);
  61. // 用户不存在
  62. if ($admin['status']) return json_send(['code' => 'error', 'msg' => '该账号已停用']);
  63. // 转数组
  64. $admin = $admin->toArray();
  65. // 比对密码
  66. if (md5($password) != $admin['password']) return json_send(['code' => 'error', 'msg' => '密码错误或账号不存在']);
  67. // 登录
  68. $accessToken = $EmployeeModel->Login($admin['uid'], 'manager');
  69. // 比对密码
  70. if (isset($accessToken['error'])) return json_send(['code' => 'error', 'msg' => '登录失败', 'data' => $accessToken['data']]);
  71. // 获取权限列表
  72. $accessToken['username'] = $admin['username'];
  73. $accessToken['auth_rules'] = $RolesAuthRuleModel->getAuthList($admin['uid'], '0', 'manager');
  74. }
  75. // 表单令牌
  76. return json_send(['code' => 'success', 'msg' => '登录成功', 'data' => $accessToken]);
  77. }
  78. /**
  79. * 登录方法 /manager/login/out
  80. * @author 唐远望
  81. * @version 1.0
  82. * @date 2025-12-02
  83. * @param string username 登录账号
  84. * @param string password 登录密码
  85. *
  86. * */
  87. public function out(Request $Request, AdminUser $AdminUser, EmployeeModel $EmployeeModel)
  88. {
  89. $token = $Request->input('access_token_manager', '');
  90. // 解码
  91. $userInfo = AccessToken::decode($token);
  92. // 验证规则
  93. $uid = $userInfo['uid'];
  94. $is_admin = $userInfo['is_admin'];
  95. if ($is_admin == '1') {
  96. // 退出登录
  97. $AdminUser->LoginOut($uid, 'manager');
  98. } else {
  99. $EmployeeModel->LoginOut($uid, 'manager');
  100. }
  101. // 表单令牌
  102. return json_send(['code' => 'success', 'msg' => '退出成功', 'data' => '']);
  103. }
  104. /**
  105. * 手机号码登录 /manager/login/mobile
  106. * @author 唐远望
  107. * @version 1.0
  108. * @date 2025-12-04
  109. * @param string mobile 手机号码
  110. * @param string password 登录密码
  111. *
  112. */
  113. public function mobile(Request $Request, AuthRule $AuthRule, EmployeeModel $EmployeeModel)
  114. {
  115. // 验证规则
  116. $Request->scene('mobile')->validate();
  117. // 接收数据
  118. $phone = $Request->input('phone', '');
  119. // 接收数据
  120. $password = $Request->input('password', '');
  121. // 查询用户
  122. $admin = $EmployeeModel->where('mobile', $phone)->first(['id as uid', 'name as username', 'mobile as phone', 'status', 'password', 'insert_time', 'update_time']);
  123. // 用户不存在
  124. if (!$admin) return json_send(['code' => 'error', 'msg' => '密码错误或账号不存在']);
  125. // 用户不存在
  126. if ($admin['status']) return json_send(['code' => 'error', 'msg' => '该账号已停用']);
  127. // 转数组
  128. $admin = $admin->toArray();
  129. // 比对密码
  130. if (md5($password) != $admin['password']) return json_send(['code' => 'error', 'msg' => '密码错误或账号不存在']);
  131. // 登录
  132. $accessToken = $EmployeeModel->Login($admin['uid'], 'manager');
  133. // 比对密码
  134. if (isset($accessToken['error'])) return json_send(['code' => 'error', 'msg' => '登录失败', 'data' => $accessToken['data']]);
  135. // 获取权限列表
  136. $accessToken['username'] = $admin['username'];
  137. // 获取权限列表
  138. $accessToken['auth_rules'] = $AuthRule->getAuthList($admin['uid'], 'manager');;
  139. // 表单令牌
  140. return json_send(['code' => 'success', 'msg' => '登录成功', 'data' => $accessToken]);
  141. }
  142. /**
  143. * 发送验证码
  144. * @author 唐远望
  145. * @version 1.0
  146. * @date 2026-01-15
  147. * @param string phone 手机号码
  148. *
  149. */
  150. public function send_code(Request $Request, EmployeeModel $EmployeeModel)
  151. {
  152. // 验证规则
  153. $Request->scene('send_code')->validate();
  154. // 接收数据
  155. $mobile = request('phone', '');
  156. if (!$mobile) return json_send(['code' => 'error', 'msg' => '请先填写手机号']);
  157. // 获取数据
  158. $session = session('loginSmsCode');
  159. // 如果有数据,并且验证码创建的时间在一分钟之内
  160. if ($session && time() - $session['create_time'] < 60) return json_send(['code' => 'error', 'msg' => '请稍后再试']);
  161. // 查询用户
  162. $admin = $EmployeeModel->query()->where('mobile', $mobile)->first(['status']);
  163. if ($admin && $admin['status']) return json_send(['code' => 'error', 'msg' => '用户已被停用']);
  164. $code = strval(rand(100000, 999999));
  165. $result = Sms::sendCode($mobile, $code);
  166. if (isset($result['error'])) return json_send(['code' => 'error', 'msg' => $result['error']]);
  167. $session = ['code' => $code, 'mobile' => $mobile, 'create_time' => time()];
  168. session(['loginSmsCode' => $session]);
  169. return json_send(['code' => 'success', 'msg' => '发送成功', 'data' => $code]);
  170. }
  171. /**
  172. * 邮箱登录 /manager/login/email
  173. * @author 唐远望
  174. * @version 1.0
  175. * @date 2025-12-04
  176. * @param string email 邮箱号码
  177. * @param string password 登录密码
  178. *
  179. */
  180. public function email(Request $Request, AuthRule $AuthRule, EmployeeModel $EmployeeModel)
  181. {
  182. // 验证规则
  183. $Request->scene('email')->validate();
  184. // 接收数据
  185. $email = $Request->input('email', '');
  186. // 接收数据
  187. $password = $Request->input('password', '');
  188. // 查询用户
  189. $admin = $EmployeeModel->where('email', $email)->first(['id as uid', 'name as username', 'mobile as phone', 'status', 'password', 'insert_time', 'update_time']);
  190. // 用户不存在
  191. if (!$admin) return json_send(['code' => 'error', 'msg' => '密码错误或账号不存在']);
  192. // 用户不存在
  193. if ($admin['status']) return json_send(['code' => 'error', 'msg' => '该账号已停用']);
  194. // 转数组
  195. $admin = $admin->toArray();
  196. // 比对密码
  197. if (md5($password) != $admin['password']) return json_send(['code' => 'error', 'msg' => '密码错误或账号不存在']);
  198. // 登录
  199. $accessToken = $EmployeeModel->Login($admin['uid'], 'manager');
  200. // 比对密码
  201. if (isset($accessToken['error'])) return json_send(['code' => 'error', 'msg' => '登录失败', 'data' => $accessToken['data']]);
  202. // 获取权限列表
  203. $accessToken['username'] = $admin['username'];
  204. // 获取权限列表
  205. $accessToken['auth_rules'] = $AuthRule->getAuthList($admin['uid'], 'manager');;
  206. // 表单令牌
  207. return json_send(['code' => 'success', 'msg' => '登录成功', 'data' => $accessToken]);
  208. }
  209. /**
  210. * 手机验证码登录 /manager/login/mobile_code
  211. * @author 唐远望
  212. * @version 1.0
  213. * @date 2026-01-15
  214. * @param string mobile 手机号码
  215. * @param string code 验证码
  216. *
  217. */
  218. public function mobile_code(Request $Request, AuthRule $AuthRule, EmployeeModel $EmployeeModel)
  219. {
  220. // 验证规则
  221. $Request->scene('mobile_code')->validate();
  222. // 接收数据
  223. $phone = $Request->input('phone', '');
  224. // 接收数据
  225. $code = $Request->input('code', '');
  226. // 获取数据
  227. $session = session('loginSmsCode');
  228. if (!$session) return json_send(['code' => 'error', 'msg' => '请先获取手机号验证码']);
  229. if ($session['code'] != $code || $session['phone'] != $phone) return json_send(['code' => 'error', 'msg' => '验证码错误']);
  230. // 查询用户
  231. $admin = $EmployeeModel->where('mobile', $phone)->first(['id as uid', 'name as username', 'mobile as phone', 'status', 'password', 'insert_time', 'update_time']);
  232. // 用户不存在
  233. if (!$admin) return json_send(['code' => 'error', 'msg' => '账号不存在']);
  234. // 用户不存在
  235. if ($admin['status']) return json_send(['code' => 'error', 'msg' => '该账号已停用']);
  236. // 转数组
  237. $admin = $admin->toArray();
  238. // 登录
  239. $accessToken = $EmployeeModel->Login($admin['uid'], 'manager');
  240. // 比对密码
  241. if (isset($accessToken['error'])) return json_send(['code' => 'error', 'msg' => '登录失败', 'data' => $accessToken['data']]);
  242. // 获取权限列表
  243. $accessToken['username'] = $admin['username'];
  244. // 获取权限列表
  245. $accessToken['auth_rules'] = $AuthRule->getAuthList($admin['uid'], 'manager');;
  246. // 表单令牌
  247. return json_send(['code' => 'success', 'msg' => '登录成功', 'data' => $accessToken]);
  248. }
  249. /**
  250. * 微信扫码登录 /manager/login/wechat
  251. * @author 唐远望
  252. * @version 1.0
  253. * @date 2026-01-19
  254. * @param string open_code 微信扫码登录的code
  255. *
  256. */
  257. public function wechat(Request $Request, AuthRule $AuthRule, EmployeeModel $EmployeeModel, EmployeeOpenidModel $EmployeeOpenidModel)
  258. {
  259. // 验证规则
  260. $Request->scene('wechat')->validate();
  261. // 接收数据
  262. $open_code = $Request->input('open_code', '');
  263. $wechatApp = new WeChatWebApp();
  264. $tokenData = $wechatApp->getAccessTokenByCode($open_code);
  265. if (!$tokenData) return json_send(['code' => 'error', 'msg' => '获取微信用户信息失败']);
  266. $user_open_data = $EmployeeOpenidModel->where(['openid' => $tokenData['openid']])->first();
  267. if (!$user_open_data) return json_send(['code' => 'error', 'msg' => '未绑定账号,请登录后在绑定']);
  268. // 查询用户
  269. $admin = $EmployeeModel->where('id', $user_open_data->employee_id)->first(['id as uid', 'name as username', 'mobile as phone', 'status', 'password', 'insert_time', 'update_time']);
  270. // 用户不存在
  271. if (!$admin) return json_send(['code' => 'error', 'msg' => '账号不存在']);
  272. // 用户不存在
  273. if ($admin['status']) return json_send(['code' => 'error', 'msg' => '该账号已停用']);
  274. // 转数组
  275. $admin = $admin->toArray();
  276. // 登录
  277. $accessToken = $EmployeeModel->Login($admin['uid'], 'manager');
  278. // 比对密码
  279. if (isset($accessToken['error'])) return json_send(['code' => 'error', 'msg' => '登录失败', 'data' => $accessToken['data']]);
  280. // 获取权限列表
  281. $accessToken['username'] = $admin['username'];
  282. // 获取权限列表
  283. $accessToken['auth_rules'] = $AuthRule->getAuthList($admin['uid'], 'manager');;
  284. // 表单令牌
  285. return json_send(['code' => 'success', 'msg' => '登录成功', 'data' => $accessToken]);
  286. }
  287. /**
  288. * 微信扫码授权绑定 /manager/login/wechat_bind
  289. * @author 唐远望
  290. * @version 1.0
  291. * @date 2026-01-19
  292. * @param string open_code 微信扫码登录的code
  293. *
  294. */
  295. public function wechat_bind(Request $Request,EmployeeOpenidModel $EmployeeOpenidModel)
  296. {
  297. // 验证规则
  298. $Request->scene('wechat_bind')->validate();
  299. $uid = request('access_token.uid', 0);
  300. // 接收数据
  301. $open_code = $Request->input('open_code', '');
  302. $wechatApp = new WeChatWebApp();
  303. $tokenData = $wechatApp->getAccessTokenByCode($open_code);
  304. if (!$tokenData) return json_send(['code' => 'error', 'msg' => '获取微信用户信息失败']);
  305. $user_open_data = $EmployeeOpenidModel->where(['openid' => $tokenData['openid'],'employee_id'=> $uid])->first();
  306. if ($user_open_data) return json_send(['code' => 'error', 'msg' => '微信已绑定,无需重复绑定']);
  307. //新增绑定记录
  308. $EmployeeOpenidModel->create([
  309. 'openid' => $tokenData['openid'],
  310. 'unionid' => isset($tokenData['unionid']) ? $tokenData['unionid'] : '',
  311. 'employee_id' => $uid,
  312. 'insert_time' => time(),
  313. ]);
  314. return json_send(['code' => 'success', 'msg' => '绑定成功','data'=>'']);
  315. }
  316. }