login_auth.go 7.0 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249
  1. package service
  2. import (
  3. "context"
  4. "encoding/json"
  5. "errors"
  6. "fmt"
  7. "strconv"
  8. "strings"
  9. "time"
  10. "youngee_b_api/consts"
  11. "youngee_b_api/db"
  12. "youngee_b_api/model/redis_model"
  13. "youngee_b_api/model/system_model"
  14. "youngee_b_api/redis"
  15. "youngee_b_api/util"
  16. "github.com/sirupsen/logrus"
  17. )
  18. var LoginAuth *loginAuth
  19. func LoginAuthInit(config *system_model.Session) {
  20. auth := new(loginAuth)
  21. auth.sessionTTL = time.Duration(config.TTL) * time.Minute
  22. LoginAuth = auth
  23. }
  24. type loginAuth struct {
  25. sessionTTL time.Duration
  26. }
  27. func (l *loginAuth) AuthToken(ctx context.Context, token string) (*redis_model.Auth, error) {
  28. phone, err := l.parseToken(ctx, token)
  29. if err != nil {
  30. logrus.Debug("token格式错误:%+v", token)
  31. return nil, err
  32. }
  33. auth, err := l.getSessionAuth(ctx, phone)
  34. if err != nil {
  35. logrus.Debug("获取session redis错误: token:%+v,err:%+v", token, err)
  36. return nil, err
  37. }
  38. if auth.Token != token {
  39. logrus.Debug("获取session time过期错误: token:%+v", token)
  40. return nil, errors.New("auth failed")
  41. }
  42. return auth, nil
  43. }
  44. // AuthCode 判断此手机号是否有账号存在 鉴定验证码 用户信息存入redis 并返回Token
  45. func (l *loginAuth) AuthCode(ctx context.Context, phone string, code string) (string, error) {
  46. user, err := db.GetUserByPhone(ctx, phone)
  47. fmt.Println("login_auth", user, err)
  48. if err != nil {
  49. // 数据库操作错误
  50. return "", err
  51. } else if user == nil {
  52. // 账号不存在,则注册账号
  53. _, err = Enterprise.CreateEnterprise(ctx, phone)
  54. if err != nil {
  55. return "账号创建失败", err
  56. }
  57. user, err = db.GetUserByPhone(ctx, phone)
  58. fmt.Println("login_auth", user, err)
  59. if err != nil {
  60. return "", err
  61. }
  62. } else if string(user.Role) != consts.BRole {
  63. // 账号权限有误
  64. logrus.Debugf("[AuthCode] auth fail,phone:%+v", phone)
  65. return "权限错误,请登录企业账号", errors.New("auth fail")
  66. }
  67. vcode, err := l.getSessionCode(ctx, phone)
  68. if err != nil {
  69. return "", err
  70. }
  71. fmt.Printf("缓存的验证码 vcode: %v,实际填入的 code:%v", vcode, code)
  72. if vcode != code {
  73. // 验证码错误
  74. logrus.Debugf("[AuthCode] auth fail,phone:%+v", phone)
  75. return "验证码有误", errors.New("auth fail")
  76. }
  77. token := l.getToken(ctx, phone)
  78. enterprise, err := db.GetEnterpriseByUID(ctx, user.ID)
  79. if err != nil {
  80. return "", err
  81. }
  82. auth := &redis_model.Auth{
  83. Phone: phone,
  84. ID: user.ID,
  85. User: user.User,
  86. Username: user.Username,
  87. RealName: user.RealName,
  88. Role: user.Role,
  89. Email: user.Email,
  90. Token: token,
  91. EnterpriseID: enterprise.EnterpriseID,
  92. }
  93. if err := l.setSession(ctx, phone, auth); err != nil {
  94. fmt.Printf("setSession error\n")
  95. return "", err
  96. }
  97. return token, nil
  98. }
  99. // func (l *loginAuth) AuthPassword(ctx context.Context, phone string, password string) (string, error) {
  100. // // 验证是否存在
  101. // user, err := db.GetUserByPhone(ctx, phone)
  102. // if err != nil {
  103. // return "", err
  104. // }
  105. // // 验证正确性
  106. // if user == nil || user.Role != consts.BRole || user.Password != l.encryptPassword(password) {
  107. // // 登录失败
  108. // logrus.Debugf("[AuthPassword] auth fail,phone:%+v", phone)
  109. // return "", errors.New("auth fail")
  110. // }
  111. // token := l.getToken(ctx, phone)
  112. // auth := &redis_model.Auth{
  113. // Phone: phone,
  114. // ID: user.ID,
  115. // User: user.User,
  116. // Username: user.Username,
  117. // RealName: user.RealName,
  118. // Role: user.Role,
  119. // Email: user.Email,
  120. // Token: token,
  121. // }
  122. // if err := l.setSession(ctx, phone, auth); err != nil {
  123. // return "", err
  124. // }
  125. // return token, nil
  126. // }
  127. func (l *loginAuth) setSession(ctx context.Context, phone string, auth *redis_model.Auth) error {
  128. if authJson, err := json.Marshal(auth); err == nil {
  129. err = redis.Set(ctx, l.getRedisKey(phone), string(authJson), l.sessionTTL)
  130. if err == nil {
  131. return err
  132. }
  133. }
  134. return nil
  135. }
  136. func (l *loginAuth) getSessionCode(ctx context.Context, phone string) (string, error) {
  137. value, err := redis.Get(ctx, l.getRedisKey(phone))
  138. if err != nil {
  139. if err == consts.RedisNil {
  140. return "", fmt.Errorf("not found in redis,phone:%+v", phone)
  141. }
  142. return "", err
  143. }
  144. return value, nil
  145. }
  146. func (l *loginAuth) getSessionAuth(ctx context.Context, phone string) (*redis_model.Auth, error) {
  147. value, err := redis.Get(ctx, l.getRedisKey(phone))
  148. if err != nil {
  149. if err == consts.RedisNil {
  150. return nil, fmt.Errorf("not found in redis,phone:%+v", phone)
  151. }
  152. return nil, err
  153. }
  154. auth := new(redis_model.Auth)
  155. if err = json.Unmarshal([]byte(value), auth); err != nil {
  156. return nil, err
  157. }
  158. return auth, nil
  159. }
  160. func (l *loginAuth) getToken(ctx context.Context, phone string) string {
  161. timeSeed := strconv.FormatInt(time.Now().Unix(), 10)
  162. token := phone + "." + timeSeed + "." + util.MD5(phone, timeSeed, consts.AuthSalt)
  163. return token
  164. }
  165. func (l *loginAuth) parseToken(ctx context.Context, token string) (string, error) {
  166. parts := strings.Split(token, ".")
  167. if len(parts) == 3 {
  168. phone := parts[0]
  169. timeSeed := parts[1]
  170. if parts[2] == util.MD5(phone, timeSeed, consts.AuthSalt) {
  171. return phone, nil
  172. }
  173. }
  174. return "", errors.New("token invalid")
  175. }
  176. func (l *loginAuth) encryptPassword(password string) string {
  177. return util.MD5(password)
  178. }
  179. func (l *loginAuth) getRedisKey(key string) string {
  180. return fmt.Sprintf("%s%s", consts.SessionRedisPrefix, key)
  181. }
  182. func (l *loginAuth) SubAccountAuthCode(ctx context.Context, phone string, code string) (string, error) {
  183. user, err := db.FindSubAccountByPhone(ctx, phone)
  184. phoneNumber := phone
  185. fmt.Println("login_auth", user, err)
  186. if err != nil {
  187. // 数据库错误
  188. return "数据库错误", err
  189. } else if user == nil {
  190. // 账号不存在,则判断此手机号码是否被商家主账号注册
  191. user, err := db.GetUserByPhone(ctx, phoneNumber)
  192. if err != nil {
  193. // 数据库操作错误
  194. return "", err
  195. } else if user == nil {
  196. // 没有被商家主账户注册,则可以注册
  197. vcode, err := l.getSessionCode(ctx, phoneNumber)
  198. if err != nil {
  199. return "session err", err
  200. }
  201. fmt.Printf("缓存的验证码 vcode: %v,实际填入的 code:%v", vcode, code)
  202. if vcode != code {
  203. // 验证码错误
  204. logrus.Debugf("[AuthCode] auth fail,phone:%+v", phone)
  205. return "验证码有误", errors.New("auth fail")
  206. }
  207. return "1", err
  208. } else if string(user.Role) != consts.BRole {
  209. if user.AuthStatus == 1 {
  210. // 被商家主账户注册,未认证,则可以注册
  211. vcode, err := l.getSessionCode(ctx, phoneNumber)
  212. if err != nil {
  213. return "session err", err
  214. }
  215. fmt.Printf("缓存的验证码 vcode: %v,实际填入的 code:%v", vcode, code)
  216. if vcode != code {
  217. // 验证码错误
  218. logrus.Debugf("[AuthCode] auth fail,phone:%+v", phone)
  219. return "验证码有误", errors.New("auth fail")
  220. }
  221. return "1", err
  222. } else {
  223. return "主账号存在", errors.New("auth fail")
  224. }
  225. }
  226. } else if user != nil {
  227. // 子账号存在,则无法注册
  228. logrus.Debugf("[AuthCode] auth fail,phone:%+v", phone)
  229. return "子账号存在", errors.New("auth fail")
  230. }
  231. return "", nil
  232. }