login_auth.go 4.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178
  1. package service
  2. import (
  3. "context"
  4. "encoding/json"
  5. "errors"
  6. "fmt"
  7. "strconv"
  8. "strings"
  9. "time"
  10. "youngee_b_api/consts"
  11. "youngee_b_api/db"
  12. "youngee_b_api/model/redis_model"
  13. "youngee_b_api/model/system_model"
  14. "youngee_b_api/redis"
  15. "youngee_b_api/util"
  16. "github.com/sirupsen/logrus"
  17. )
  18. var LoginAuth *loginAuth
  19. func LoginAuthInit(config *system_model.Session) {
  20. auth := new(loginAuth)
  21. auth.sessionTTL = time.Duration(config.TTL) * time.Minute
  22. LoginAuth = auth
  23. }
  24. type loginAuth struct {
  25. sessionTTL time.Duration
  26. }
  27. func (l *loginAuth) AuthToken(ctx context.Context, token string) (*redis_model.Auth, error) {
  28. phone, err := l.parseToken(ctx, token)
  29. if err != nil {
  30. logrus.Debug("token格式错误:%+v", token)
  31. return nil, err
  32. }
  33. auth, err := l.getSession(ctx, phone)
  34. if err != nil {
  35. logrus.Debug("获取session redis错误: token:%+v,err:%+v", token, err)
  36. return nil, err
  37. }
  38. if auth.Token != token {
  39. logrus.Debug("获取session time过期错误: token:%+v", token)
  40. return nil, errors.New("auth failed")
  41. }
  42. return auth, nil
  43. }
  44. func (l *loginAuth) AuthMSG(ctx context.Context, phone string, vcode string) (string, error) {
  45. // 验证是否存在
  46. user, err := db.GetUserByPhone(ctx, phone)
  47. if err != nil {
  48. return "", err
  49. }
  50. code, err := l.getSessionCode(ctx, phone)
  51. if err != nil {
  52. return "", err
  53. }
  54. if user == nil {
  55. fmt.Printf("user == nil\n")
  56. }
  57. if string(user.Role) != consts.BRole {
  58. fmt.Printf("%+v\n", string(user.Role))
  59. }
  60. if *code != vcode {
  61. fmt.Printf("code:%+v, vcode:%+v\n", *code, vcode)
  62. }
  63. if user == nil || string(user.Role) != consts.BRole || *code != vcode { // 登录失败
  64. logrus.Debugf("[AuthPassword] auth fail,phone:%+v", phone)
  65. return "", errors.New("auth fail")
  66. }
  67. token := l.getToken(ctx, phone)
  68. auth := &redis_model.Auth{
  69. Phone: phone,
  70. ID: user.ID,
  71. User: user.User,
  72. Username: user.Username,
  73. RealName: user.RealName,
  74. Role: user.Role,
  75. Email: user.Email,
  76. Token: token,
  77. }
  78. if err := l.setSession(ctx, phone, auth); err != nil {
  79. fmt.Printf("setSession error\n")
  80. return "", err
  81. }
  82. return token, nil
  83. }
  84. func (l *loginAuth) AuthPassword(ctx context.Context, phone string, password string) (string, error) {
  85. // 验证是否存在
  86. user, err := db.GetUserByPhone(ctx, phone)
  87. if err != nil {
  88. return "", err
  89. }
  90. // 验证正确性
  91. if user == nil || user.Role != consts.BRole || user.Password != l.encryptPassword(password) {
  92. // 登录失败
  93. logrus.Debugf("[AuthPassword] auth fail,phone:%+v", phone)
  94. return "", errors.New("auth fail")
  95. }
  96. token := l.getToken(ctx, phone)
  97. auth := &redis_model.Auth{
  98. Phone: phone,
  99. ID: user.ID,
  100. User: user.User,
  101. Username: user.Username,
  102. RealName: user.RealName,
  103. Role: user.Role,
  104. Email: user.Email,
  105. Token: token,
  106. }
  107. if err := l.setSession(ctx, phone, auth); err != nil {
  108. return "", err
  109. }
  110. return token, nil
  111. }
  112. func (l *loginAuth) setSession(ctx context.Context, phone string, auth *redis_model.Auth) error {
  113. if authJson, err := json.Marshal(auth); err == nil {
  114. err = redis.Set(ctx, l.getRedisKey(phone), string(authJson), l.sessionTTL)
  115. if err == nil {
  116. return err
  117. }
  118. }
  119. return nil
  120. }
  121. func (l *loginAuth) getSessionCode(ctx context.Context, phone string) (*string, error) {
  122. value, err := redis.Get(ctx, l.getRedisKey(phone))
  123. if err != nil {
  124. if err == consts.RedisNil {
  125. return nil, fmt.Errorf("not found in redis,phone:%+v", phone)
  126. }
  127. return nil, err
  128. }
  129. return &value, nil
  130. }
  131. func (l *loginAuth) getSession(ctx context.Context, phone string) (*redis_model.Auth, error) {
  132. value, err := redis.Get(ctx, l.getRedisKey(phone))
  133. if err != nil {
  134. if err == consts.RedisNil {
  135. return nil, fmt.Errorf("not found in redis,phone:%+v", phone)
  136. }
  137. return nil, err
  138. }
  139. auth := new(redis_model.Auth)
  140. if err = json.Unmarshal([]byte(value), auth); err != nil {
  141. return nil, err
  142. }
  143. return auth, nil
  144. }
  145. func (l *loginAuth) getToken(ctx context.Context, phone string) string {
  146. timeSeed := strconv.FormatInt(time.Now().Unix(), 10)
  147. token := phone + "." + timeSeed + "." + util.MD5(phone, timeSeed, consts.AuthSalt)
  148. return token
  149. }
  150. func (l *loginAuth) parseToken(ctx context.Context, token string) (string, error) {
  151. parts := strings.Split(token, ".")
  152. if len(parts) == 3 {
  153. phone := parts[0]
  154. timeSeed := parts[1]
  155. if parts[2] == util.MD5(phone, timeSeed, consts.AuthSalt) {
  156. return phone, nil
  157. }
  158. }
  159. return "", errors.New("token invalid")
  160. }
  161. func (l *loginAuth) encryptPassword(password string) string {
  162. return util.MD5(password)
  163. }
  164. func (l *loginAuth) getRedisKey(key string) string {
  165. return fmt.Sprintf("%s%s", consts.SessionRedisPrefix, key)
  166. }