AuthController.java 9.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274
  1. package org.jk.web.controller;
  2. import cn.dev33.satoken.annotation.SaIgnore;
  3. import cn.dev33.satoken.exception.NotLoginException;
  4. import cn.dev33.satoken.stp.StpUtil;
  5. import cn.hutool.core.codec.Base64;
  6. import cn.hutool.core.collection.CollUtil;
  7. import cn.hutool.core.util.ObjectUtil;
  8. import jakarta.servlet.http.HttpServletRequest;
  9. import lombok.RequiredArgsConstructor;
  10. import lombok.extern.slf4j.Slf4j;
  11. import me.zhyd.oauth.model.AuthResponse;
  12. import me.zhyd.oauth.model.AuthUser;
  13. import me.zhyd.oauth.request.AuthRequest;
  14. import me.zhyd.oauth.utils.AuthStateUtils;
  15. import org.jk.common.core.constant.SystemConstants;
  16. import org.jk.common.core.domain.R;
  17. import org.jk.common.core.domain.model.LoginBody;
  18. import org.jk.common.core.domain.model.LoginUser;
  19. import org.jk.common.core.domain.model.RegisterBody;
  20. import org.jk.common.core.domain.model.SocialLoginBody;
  21. import org.jk.common.core.utils.*;
  22. import org.jk.common.core.utils.*;
  23. import org.jk.common.encrypt.annotation.ApiEncrypt;
  24. import org.jk.common.json.utils.JsonUtils;
  25. import org.jk.common.ratelimiter.annotation.RateLimiter;
  26. import org.jk.common.ratelimiter.enums.LimitType;
  27. import org.jk.common.satoken.utils.LoginHelper;
  28. import org.jk.common.social.config.properties.SocialLoginConfigProperties;
  29. import org.jk.common.social.config.properties.SocialProperties;
  30. import org.jk.common.social.utils.SocialUtils;
  31. import org.jk.common.sse.dto.SseMessageDto;
  32. import org.jk.common.sse.utils.SseMessageUtils;
  33. import org.jk.common.tenant.helper.TenantHelper;
  34. import org.jk.system.domain.bo.SysTenantBo;
  35. import org.jk.system.domain.vo.SysClientVo;
  36. import org.jk.system.domain.vo.SysTenantVo;
  37. import org.jk.system.service.*;
  38. import org.jk.web.domain.vo.LoginTenantVo;
  39. import org.jk.web.domain.vo.LoginVo;
  40. import org.jk.web.domain.vo.TenantListVo;
  41. import org.jk.web.service.IAuthStrategy;
  42. //import org.jk.web.service.JkLoginService;
  43. import org.jk.web.service.SysLoginService;
  44. import org.jk.web.service.SysRegisterService;
  45. import org.springframework.validation.annotation.Validated;
  46. import org.springframework.web.bind.annotation.*;
  47. import java.io.IOException;
  48. import java.net.URL;
  49. import java.nio.charset.StandardCharsets;
  50. import java.util.HashMap;
  51. import java.util.List;
  52. import java.util.Map;
  53. import java.util.Set;
  54. import java.util.concurrent.ScheduledExecutorService;
  55. import java.util.concurrent.TimeUnit;
  56. /**
  57. * 认证
  58. *
  59. * @author jk
  60. */
  61. @Slf4j
  62. @SaIgnore
  63. @RequiredArgsConstructor
  64. @RestController
  65. @RequestMapping("/auth")
  66. public class AuthController {
  67. private final SocialProperties socialProperties;
  68. private final SysLoginService loginService;
  69. private final SysRegisterService registerService;
  70. private final ISysConfigService configService;
  71. private final ISysTenantService tenantService;
  72. private final ISysSocialService socialUserService;
  73. private final ISysClientService clientService;
  74. private final ISysUserService userService;
  75. private final ScheduledExecutorService scheduledExecutorService;
  76. //private final JkLoginService jkLoginService;
  77. /**
  78. * 登录方法
  79. *
  80. * @param body 登录信息
  81. * @return 结果
  82. */
  83. @ApiEncrypt
  84. @PostMapping("/login")
  85. public R<LoginVo> login(@RequestBody String body) {
  86. LoginBody loginBody = JsonUtils.parseObject(body, LoginBody.class);
  87. ValidatorUtils.validate(loginBody);
  88. // 授权类型和客户端id
  89. String clientId = loginBody.getClientId();
  90. String grantType = loginBody.getGrantType();
  91. SysClientVo client = clientService.queryByClientId(clientId);
  92. // 查询不到 client 或 client 内不包含 grantType
  93. if (ObjectUtil.isNull(client) || !StringUtils.contains(client.getGrantType(), grantType)) {
  94. log.info("客户端id: {} 认证类型:{} 异常!.", clientId, grantType);
  95. return R.fail(MessageUtils.message("auth.grant.type.error"));
  96. } else if (!SystemConstants.NORMAL.equals(client.getStatus())) {
  97. return R.fail(MessageUtils.message("auth.grant.type.blocked"));
  98. }
  99. // 校验租户
  100. //loginService.checkTenant(loginBody.getTenantId());
  101. // 登录
  102. LoginVo loginVo = IAuthStrategy.login(body, client, grantType);
  103. Long userId = LoginHelper.getUserId();
  104. scheduledExecutorService.schedule(() -> {
  105. SseMessageDto dto = new SseMessageDto();
  106. dto.setMessage("欢迎登录建科RAG后台管理系统");
  107. dto.setUserIds(List.of(userId));
  108. SseMessageUtils.publishMessage(dto);
  109. }, 5, TimeUnit.SECONDS);
  110. return R.ok(loginVo);
  111. }
  112. /**
  113. * 获取跳转URL
  114. *
  115. * @param source 登录来源
  116. * @return 结果
  117. */
  118. @GetMapping("/binding/{source}")
  119. public R<String> authBinding(@PathVariable("source") String source,
  120. @RequestParam String tenantId, @RequestParam String domain) {
  121. SocialLoginConfigProperties obj = socialProperties.getType().get(source);
  122. if (ObjectUtil.isNull(obj)) {
  123. return R.fail(source + "平台账号暂不支持");
  124. }
  125. AuthRequest authRequest = SocialUtils.getAuthRequest(source, socialProperties);
  126. Map<String, String> map = new HashMap<>();
  127. map.put("tenantId", tenantId);
  128. map.put("domain", domain);
  129. map.put("state", AuthStateUtils.createState());
  130. String authorizeUrl = authRequest.authorize(Base64.encode(JsonUtils.toJsonString(map), StandardCharsets.UTF_8));
  131. return R.ok("操作成功", authorizeUrl);
  132. }
  133. /**
  134. * 前端回调绑定授权(需要token)
  135. *
  136. * @param loginBody 请求体
  137. * @return 结果
  138. */
  139. @PostMapping("/social/callback")
  140. public R<Void> socialCallback(@RequestBody SocialLoginBody loginBody) {
  141. // 校验token
  142. StpUtil.checkLogin();
  143. // 获取第三方登录信息
  144. AuthResponse<AuthUser> response = SocialUtils.loginAuth(
  145. loginBody.getSource(), loginBody.getSocialCode(),
  146. loginBody.getSocialState(), socialProperties);
  147. AuthUser authUserData = response.getData();
  148. // 判断授权响应是否成功
  149. if (!response.ok()) {
  150. return R.fail(response.getMsg());
  151. }
  152. loginService.socialRegister(authUserData);
  153. return R.ok();
  154. }
  155. /**
  156. * 取消授权(需要token)
  157. *
  158. * @param socialId socialId
  159. */
  160. @DeleteMapping(value = "/unlock/{socialId}")
  161. public R<Void> unlockSocial(@PathVariable Long socialId) {
  162. // 校验token
  163. StpUtil.checkLogin();
  164. Boolean rows = socialUserService.deleteWithValidById(socialId);
  165. return rows ? R.ok() : R.fail("取消授权失败");
  166. }
  167. /**
  168. * 退出登录
  169. */
  170. @PostMapping("/logout")
  171. public R<Void> logout() {
  172. loginService.logout();
  173. return R.ok("退出成功");
  174. }
  175. /**
  176. * 用户注册
  177. */
  178. @ApiEncrypt
  179. @PostMapping("/register")
  180. public R<Void> register(@Validated @RequestBody RegisterBody user) {
  181. if (!configService.selectRegisterEnabled(user.getTenantId())) {
  182. return R.fail("当前系统没有开启注册功能!");
  183. }
  184. registerService.register(user);
  185. return R.ok();
  186. }
  187. /**
  188. * 登录页面租户下拉框
  189. *
  190. * @return 租户列表
  191. */
  192. @RateLimiter(time = 60, count = 20, limitType = LimitType.IP)
  193. @GetMapping("/tenant/list")
  194. public R<LoginTenantVo> tenantList(HttpServletRequest request) throws Exception {
  195. // 返回对象
  196. LoginTenantVo result = new LoginTenantVo();
  197. boolean enable = TenantHelper.isEnable();
  198. result.setTenantEnabled(enable);
  199. // 如果未开启租户这直接返回
  200. if (!enable) {
  201. return R.ok(result);
  202. }
  203. List<SysTenantVo> tenantList = tenantService.queryList(new SysTenantBo());
  204. List<TenantListVo> voList = MapstructUtils.convert(tenantList, TenantListVo.class);
  205. try {
  206. // 如果只超管返回所有租户
  207. if (LoginHelper.isSuperAdmin()) {
  208. result.setVoList(voList);
  209. return R.ok(result);
  210. }
  211. } catch (NotLoginException ignored) {
  212. }
  213. // 获取域名
  214. String host;
  215. String referer = request.getHeader("referer");
  216. if (StringUtils.isNotBlank(referer)) {
  217. // 这里从referer中取值是为了本地使用hosts添加虚拟域名,方便本地环境调试
  218. host = referer.split("//")[1].split("/")[0];
  219. } else {
  220. host = new URL(request.getRequestURL().toString()).getHost();
  221. }
  222. // 根据域名进行筛选
  223. List<TenantListVo> list = StreamUtils.filter(voList, vo ->
  224. StringUtils.equalsIgnoreCase(vo.getDomain(), host));
  225. result.setVoList(CollUtil.isNotEmpty(list) ? list : voList);
  226. return R.ok(result);
  227. }
  228. /**
  229. * token校验
  230. * @param token
  231. * @return
  232. */
  233. @GetMapping("/checkToken/{token}")
  234. public R<LoginUser> checkToken(@PathVariable("token") String token){
  235. StpUtil.setTokenValue(token);
  236. StpUtil.checkLogin();
  237. LoginUser loginUser = LoginHelper.getLoginUser(token);
  238. log.info("checkToken:loginUser"+loginUser);
  239. return R.ok(loginUser);
  240. }
  241. /**
  242. * 建科用户登录方法
  243. *
  244. * @param loginBody 登录信息
  245. * @return 结果
  246. */
  247. // @PostMapping("/jk_code_login")
  248. // public R<LoginVo> jkLogin(@RequestBody LoginBody loginBody) throws IOException {
  249. // LoginVo loginVo = jkLoginService.login(loginBody.getCode(),loginBody.getRedirectUrl());
  250. // return R.ok(loginVo);
  251. // }
  252. }