Auth.php 16 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613
  1. <?php
  2. namespace app\common\library;
  3. use app\common\model\User;
  4. use app\common\model\UserRule;
  5. use fast\Random;
  6. use think\Config;
  7. use think\Db;
  8. use think\Hook;
  9. use think\Request;
  10. use think\Validate;
  11. class Auth
  12. {
  13. protected static $instance = null;
  14. protected $_error = '';
  15. protected $_logined = FALSE;
  16. protected $_user = NULL;
  17. protected $_token = '';
  18. //Token默认有效时长
  19. protected $keeptime = 2592000;
  20. protected $requestUri = '';
  21. protected $rules = [];
  22. //默认配置
  23. protected $config = [];
  24. protected $options = [];
  25. protected $allowFields = ['id', 'username', 'nickname', 'mobile', 'avatar', 'score','money','city','gender'];
  26. public function __construct($options = [])
  27. {
  28. if ($config = Config::get('user'))
  29. {
  30. $this->config = array_merge($this->config, $config);
  31. }
  32. $this->options = array_merge($this->config, $options);
  33. }
  34. /**
  35. *
  36. * @param array $options 参数
  37. * @return Auth
  38. */
  39. public static function instance($options = [])
  40. {
  41. if (is_null(self::$instance))
  42. {
  43. self::$instance = new static($options);
  44. }
  45. return self::$instance;
  46. }
  47. /**
  48. * 获取User模型
  49. * @return User
  50. */
  51. public function getUser()
  52. {
  53. return $this->_user;
  54. }
  55. /**
  56. * 兼容调用user模型的属性
  57. *
  58. * @param string $name
  59. * @return mixed
  60. */
  61. public function __get($name)
  62. {
  63. return $this->_user ? $this->_user->$name : NULL;
  64. }
  65. /**
  66. * 根据Token初始化
  67. *
  68. * @param string $token Token
  69. * @return boolean
  70. */
  71. public function init($token)
  72. {
  73. if ($this->_logined)
  74. {
  75. return TRUE;
  76. }
  77. if ($this->_error)
  78. return FALSE;
  79. $data = Token::get($token);
  80. if (!$data)
  81. {
  82. return FALSE;
  83. }
  84. $user_id = intval($data['user_id']);
  85. if ($user_id > 0)
  86. {
  87. $user = User::get($user_id);
  88. if (!$user)
  89. {
  90. $this->setError('Account not exist');
  91. return FALSE;
  92. }
  93. if ($user['status'] != 'normal')
  94. {
  95. $this->setError('Account is locked');
  96. return FALSE;
  97. }
  98. $this->_user = $user;
  99. $this->_logined = TRUE;
  100. $this->_token = $token;
  101. //初始化成功的事件
  102. Hook::listen("user_init_successed", $this->_user);
  103. return TRUE;
  104. }
  105. else
  106. {
  107. $this->setError('You are not logged in');
  108. return FALSE;
  109. }
  110. }
  111. /**
  112. * 注册用户
  113. *
  114. * @param string $username 用户名
  115. * @param string $password 密码
  116. * @param string $email 邮箱
  117. * @param string $mobile 手机号
  118. * @param array $extend 扩展参数
  119. * @return boolean
  120. */
  121. public function register($username, $password, $email = '', $mobile = '', $extend = [])
  122. {
  123. // 检测用户名或邮箱、手机号是否存在
  124. if (User::getByUsername($username))
  125. {
  126. $this->setError('Username already exist');
  127. return FALSE;
  128. }
  129. if ($email && User::getByEmail($email))
  130. {
  131. $this->setError('Email already exist');
  132. return FALSE;
  133. }
  134. //if ($mobile && User::getByMobile($mobile))
  135. //{
  136. // $this->setError('Mobile already exist');
  137. // return FALSE;
  138. //}
  139. $ip = request()->ip();
  140. $time = time();
  141. $data = [
  142. 'username' => $username,
  143. 'password' => $password,
  144. 'email' => $email,
  145. 'mobile' => $mobile,
  146. 'level' => 1,
  147. 'score' => 0,
  148. 'avatar' => '',
  149. ];
  150. $params = array_merge($data, [
  151. 'nickname' => $username,
  152. 'salt' => Random::alnum(),
  153. 'jointime' => $time,
  154. 'joinip' => $ip,
  155. 'logintime' => $time,
  156. 'loginip' => $ip,
  157. 'prevtime' => $time,
  158. 'status' => 'normal'
  159. ]);
  160. $params['password'] = $this->getEncryptPassword($password, $params['salt']);
  161. $params = array_merge($params, $extend);
  162. //账号注册时需要开启事务,避免出现垃圾数据
  163. Db::startTrans();
  164. try
  165. {
  166. $user = User::create($params);
  167. Db::commit();
  168. // 此时的Model中只包含部分数据
  169. $this->_user = User::get($user->id);
  170. //设置Token
  171. $this->_token = Random::uuid();
  172. Token::set($this->_token, $user->id, $this->keeptime);
  173. //注册成功的事件
  174. Hook::listen("user_register_successed", $this->_user);
  175. return TRUE;
  176. }
  177. catch (Exception $e)
  178. {
  179. $this->setError($e->getMessage());
  180. Db::rollback();
  181. return FALSE;
  182. }
  183. }
  184. /**
  185. * 用户登录
  186. *
  187. * @param string $account 账号,用户名、邮箱、手机号
  188. * @param string $password 密码
  189. * @return boolean
  190. */
  191. public function login($account, $password)
  192. {
  193. $field = Validate::is($account, 'email') ? 'email' : (Validate::regex($account, '/^1\d{10}$/') ? 'mobile' : 'username');
  194. $user = User::get([$field => $account]);
  195. if (!$user)
  196. {
  197. $this->setError('Account is incorrect');
  198. return FALSE;
  199. }
  200. if (!empty($user->email_chkcode))
  201. {
  202. $this->setError('请验证邮箱后登陆');
  203. return FALSE;
  204. }
  205. if ($user->status != 'normal')
  206. {
  207. $this->setError('Account is locked');
  208. return FALSE;
  209. }
  210. if ($user->password != $this->getEncryptPassword($password, $user->salt))
  211. {
  212. $this->setError('Password is incorrect');
  213. return FALSE;
  214. }
  215. //直接登录会员
  216. $this->direct($user->id);
  217. return TRUE;
  218. }
  219. /**
  220. * 注销
  221. *
  222. * @return boolean
  223. */
  224. public function logout()
  225. {
  226. if (!$this->_logined)
  227. {
  228. $this->setError('You are not logged in');
  229. return false;
  230. }
  231. //设置登录标识
  232. $this->_logined = FALSE;
  233. //删除Token
  234. Token::delete($this->_token);
  235. //注销成功的事件
  236. Hook::listen("user_logout_successed", $this->_user);
  237. return TRUE;
  238. }
  239. /**
  240. * 修改密码
  241. * @param string $newpassword 新密码
  242. * @param string $oldpassword 旧密码
  243. * @param bool $ignoreoldpassword 忽略旧密码
  244. * @return boolean
  245. */
  246. public function changepwd($newpassword, $oldpassword = '', $ignoreoldpassword = false)
  247. {
  248. if (!$this->_logined)
  249. {
  250. $this->setError('You are not logged in');
  251. return false;
  252. }
  253. //判断旧密码是否正确
  254. if ($this->_user->password == $this->getEncryptPassword($oldpassword, $this->_user->salt) || $ignoreoldpassword)
  255. {
  256. $salt = Random::alnum();
  257. $newpassword = $this->getEncryptPassword($newpassword, $salt);
  258. $this->_user->save(['password' => $newpassword, 'salt' => $salt]);
  259. Token::delete($this->_token);
  260. //修改密码成功的事件
  261. Hook::listen("user_changepwd_successed", $this->_user);
  262. return true;
  263. }
  264. else
  265. {
  266. $this->setError('Password is incorrect');
  267. return false;
  268. }
  269. }
  270. /**
  271. * 直接登录账号
  272. * @param int $user_id
  273. * @return boolean
  274. */
  275. public function direct($user_id)
  276. {
  277. $user = User::get($user_id);
  278. if ($user)
  279. {
  280. ////////////////同步到Ucenter////////////////
  281. if (defined('UC_STATUS') && UC_STATUS)
  282. {
  283. $uc = new \addons\ucenter\library\client\Client();
  284. $re = $uc->uc_user_login($this->user->id, $this->user->password . '#split#' . $this->user->salt, 3);
  285. // 如果小于0则说明发生错误
  286. if ($re <= 0)
  287. {
  288. $this->setError('Username or password is incorrect');
  289. return FALSE;
  290. }
  291. }
  292. $ip = request()->ip();
  293. $time = time();
  294. //判断连续登录和最大连续登录
  295. if ($user->logintime < \fast\Date::unixtime('day'))
  296. {
  297. $user->successions = $user->logintime < \fast\Date::unixtime('day', -1) ? 1 : $user->successions + 1;
  298. $user->maxsuccessions = max($user->successions, $user->maxsuccessions);
  299. }
  300. $user->prevtime = $user->logintime;
  301. //记录本次登录的IP和时间
  302. $user->loginip = $ip;
  303. $user->logintime = $time;
  304. $user->save();
  305. $this->_user = $user;
  306. $this->_token = Random::uuid();
  307. Token::set($this->_token, $user->id, $this->keeptime);
  308. $this->_logined = TRUE;
  309. //登录成功的事件
  310. Hook::listen("user_login_successed", $this->_user);
  311. return TRUE;
  312. }
  313. else
  314. {
  315. return FALSE;
  316. }
  317. }
  318. /**
  319. * 检测是否是否有对应权限
  320. * @param string $path 控制器/方法
  321. * @param string $module 模块 默认为当前模块
  322. * @return boolean
  323. */
  324. public function check($path = NULL, $module = NULL)
  325. {
  326. if (!$this->_logined)
  327. return false;
  328. $ruleList = $this->getRuleList();
  329. $rules = [];
  330. foreach ($ruleList as $k => $v)
  331. {
  332. $rules[] = $v['name'];
  333. }
  334. $url = ($module ? $module : request()->module()) . '/' . (is_null($path) ? $this->getRequestUri() : $path);
  335. $url = strtolower(str_replace('.', '/', $url));
  336. return in_array($url, $rules) ? TRUE : FALSE;
  337. }
  338. /**
  339. * 判断是否登录
  340. * @return boolean
  341. */
  342. public function isLogin()
  343. {
  344. if ($this->_logined)
  345. {
  346. return true;
  347. }
  348. return false;
  349. }
  350. /**
  351. * 获取当前Token
  352. * @return string
  353. */
  354. public function getToken()
  355. {
  356. return $this->_token;
  357. }
  358. /**
  359. * 获取会员基本信息
  360. */
  361. public function getUserinfo()
  362. {
  363. $data = $this->_user->toArray();
  364. $allowFields = $this->getAllowFields();
  365. $userinfo = array_intersect_key($data, array_flip($allowFields));
  366. $userinfo = array_merge($userinfo, Token::get($this->_token));
  367. return $userinfo;
  368. }
  369. /**
  370. * 获取会员组别规则列表
  371. * @return array
  372. */
  373. public function getRuleList()
  374. {
  375. if ($this->rules)
  376. return $this->rules;
  377. $group = $this->_user->group;
  378. if (!$group)
  379. {
  380. return [];
  381. }
  382. $rules = explode(',', $group->rules);
  383. $this->rules = UserRule::where('status', 'normal')->where('id', 'in', $rules)->field('id,pid,name,title,ismenu')->select();
  384. return $this->rules;
  385. }
  386. /**
  387. * 获取当前请求的URI
  388. * @return string
  389. */
  390. public function getRequestUri()
  391. {
  392. return $this->requestUri;
  393. }
  394. /**
  395. * 设置当前请求的URI
  396. * @param string $uri
  397. */
  398. public function setRequestUri($uri)
  399. {
  400. $this->requestUri = $uri;
  401. }
  402. /**
  403. * 获取允许输出的字段
  404. * @return array
  405. */
  406. public function getAllowFields()
  407. {
  408. return $this->allowFields;
  409. }
  410. /**
  411. * 设置允许输出的字段
  412. * @param array $fields
  413. */
  414. public function setAllowFields($fields)
  415. {
  416. $this->allowFields = $fields;
  417. }
  418. /**
  419. * 删除一个指定会员
  420. * @param int $user_id 会员ID
  421. * @return boolean
  422. */
  423. public function delete($user_id)
  424. {
  425. $user = User::get($user_id);
  426. if (!$user)
  427. {
  428. return FALSE;
  429. }
  430. ////////////////同步到Ucenter////////////////
  431. if (defined('UC_STATUS') && UC_STATUS)
  432. {
  433. $uc = new \addons\ucenter\library\client\Client();
  434. $re = $uc->uc_user_delete($user['id']);
  435. // 如果小于0则说明发生错误
  436. if ($re <= 0)
  437. {
  438. $this->setError('Account is locked');
  439. return FALSE;
  440. }
  441. }
  442. // 调用事务删除账号
  443. $result = Db::transaction(function($db) use($user_id) {
  444. // 删除会员
  445. User::destroy($user_id);
  446. // 删除会员指定的所有Token
  447. Token::clear($user_id);
  448. return TRUE;
  449. });
  450. if ($result)
  451. {
  452. Hook::listen("user_delete_successed", $user);
  453. }
  454. return $result ? TRUE : FALSE;
  455. }
  456. /**
  457. * 获取密码加密后的字符串
  458. * @param string $password 密码
  459. * @param string $salt 密码盐
  460. * @return string
  461. */
  462. public function getEncryptPassword($password, $salt = '')
  463. {
  464. return md5(md5($password) . $salt);
  465. }
  466. /**
  467. * 检测当前控制器和方法是否匹配传递的数组
  468. *
  469. * @param array $arr 需要验证权限的数组
  470. * @return boolean
  471. */
  472. public function match($arr = [])
  473. {
  474. $request = Request::instance();
  475. $arr = is_array($arr) ? $arr : explode(',', $arr);
  476. if (!$arr)
  477. {
  478. return FALSE;
  479. }
  480. $arr = array_map('strtolower', $arr);
  481. // 是否存在
  482. if (in_array(strtolower($request->action()), $arr) || in_array('*', $arr))
  483. {
  484. return TRUE;
  485. }
  486. // 没找到匹配
  487. return FALSE;
  488. }
  489. /**
  490. * 设置会话有效时间
  491. * @param int $keeptime 默认为永久
  492. */
  493. public function keeptime($keeptime = 0)
  494. {
  495. $this->keeptime = $keeptime;
  496. }
  497. /**
  498. * 渲染用户数据
  499. * @param array $datalist 二维数组
  500. * @param mixed $fields 加载的字段列表
  501. * @param string $fieldkey 渲染的字段
  502. * @param string $renderkey 结果字段
  503. * @return array
  504. */
  505. public function render(&$datalist, $fields = [], $fieldkey = 'user_id', $renderkey = 'userinfo')
  506. {
  507. $fields = !$fields ? ['id', 'nickname', 'level', 'avatar'] : (is_array($fields) ? $fields : explode(',', $fields));
  508. $ids = [];
  509. foreach ($datalist as $k => $v)
  510. {
  511. if (!isset($v[$fieldkey]))
  512. continue;
  513. $ids[] = $v[$fieldkey];
  514. }
  515. $list = [];
  516. if ($ids)
  517. {
  518. if (!in_array('id', $fields))
  519. {
  520. $fields[] = 'id';
  521. }
  522. $ids = array_unique($ids);
  523. $selectlist = User::where('id', 'in', $ids)->column($fields);
  524. foreach ($selectlist as $k => $v)
  525. {
  526. $list[$v['id']] = $v;
  527. }
  528. }
  529. foreach ($datalist as $k => &$v)
  530. {
  531. $v[$renderkey] = isset($list[$v[$fieldkey]]) ? $list[$v[$fieldkey]] : NULL;
  532. }
  533. unset($v);
  534. return $datalist;
  535. }
  536. /**
  537. * 设置错误信息
  538. *
  539. * @param $error 错误信息
  540. * @return Auth
  541. */
  542. public function setError($error)
  543. {
  544. $this->_error = $error;
  545. return $this;
  546. }
  547. /**
  548. * 获取错误信息
  549. * @return string
  550. */
  551. public function getError()
  552. {
  553. return $this->_error ? __($this->_error) : '';
  554. }
  555. }