light_auth.go 4.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153
  1. package auth
  2. import (
  3. "fmt"
  4. "git.qianqiusoft.com/qianqiusoft/light-apiengine/entitys"
  5. sysmodel "git.qianqiusoft.com/qianqiusoft/light-apiengine/models"
  6. sysutils "git.qianqiusoft.com/qianqiusoft/light-apiengine/utils"
  7. "github.com/xormplus/xorm"
  8. "net"
  9. "net/http"
  10. "strings"
  11. )
  12. type LightAuth struct {
  13. }
  14. var session *xorm.Engine
  15. func init() {
  16. lightAuth := &LightAuth{}
  17. RegisterAuth("qianqiusoft.com", lightAuth)
  18. }
  19. func (la *LightAuth) Init() {
  20. }
  21. func (la *LightAuth) Login(c *entitys.CtrlContext) {
  22. var logininfo sysmodel.LoginInfo
  23. c.Ctx.BindJSON(&logininfo)
  24. //fmt.Println(logininfo)
  25. var user sysmodel.SysUser
  26. ret, err := c.PlatformDbEngine.SQL(sysmodel.SqlUserLogin, logininfo.Account).Get(&user)
  27. if ret && err == nil {
  28. //TODO check password
  29. md5Pwd := sysutils.HashPassword(logininfo.Password, "")
  30. //密码错误
  31. if !strings.EqualFold(user.Password, md5Pwd) {
  32. c.Ctx.JSON(200, sysmodel.SysReturn{400, "password incorrect!", nil})
  33. return
  34. }
  35. //token := &entitys.Token{}
  36. //timestamp_str := strconv.FormatUint(timestamp, 10)
  37. //sec_tooken := sysutils.GenerateToken(logininfo.Account + timestamp_str)
  38. //if v := sysutils.GetGlobalTokenStore().Get(sec_tooken); v == nil {
  39. // token.AccessToken = sec_tooken
  40. // token.RefreshToken = sec_tooken
  41. // token.LoginID = logininfo.Account
  42. // token.UserId = user.Id
  43. // token.Result = 200
  44. // //token.Password = pwd
  45. // token.ServerIp = ""
  46. // token.Domain = user.Domain
  47. // sysutils.GetGlobalTokenStore().Set(sec_tooken, token)
  48. // //sysutils.GetGlobalTokenStore().Set(token.LoginID+user.Domain, token)
  49. //} else {
  50. // token = v
  51. //}
  52. //// 查找Business对应的用户信息
  53. //var businessUser sysmodel.SysUser
  54. //_, err = c.App.GetBusinessDb(user.Domain).Table(new(sysmodel.SysUser)).ID(user.Id).Get(&businessUser)
  55. //if err != nil {
  56. // c.Ctx.JSON(200, sysmodel.SysReturn{400, "business db con't found user!", nil})
  57. // return
  58. //}
  59. //
  60. //data := sysmodel.LoginReturnInfo{}
  61. //data.Id = user.Id
  62. //data.LoginId = user.LoginId
  63. //data.Token = token.AccessToken
  64. //data.Type = user.Type
  65. //data.Domain = user.Domain
  66. //data.OrgId = businessUser.OrgId
  67. //data.Name = businessUser.Name
  68. //data.Mobile = businessUser.Mobile
  69. //data.Email = businessUser.Email
  70. //
  71. //// 查找用户对应角色
  72. //var roles []sysmodel.SysRole
  73. //c.App.GetBusinessDb(user.Domain).SQL("select sys_role.* from sys_user_role, sys_role where sys_user_role.role_id = sys_role.id and sys_role.del_flag = 0 and sys_user_role.user_id = ? order by sys_role.priority asc", user.Id).Find(&roles)
  74. //data.Roles = roles
  75. data, err := AddToGlobalTokenStore(c, &user)
  76. if err != nil {
  77. c.Ctx.JSON(200, sysmodel.SysReturn{400, err.Error(), nil})
  78. return
  79. }
  80. //登录日志
  81. if session != nil {
  82. ip := RemoteIp(c.Ctx.Request)
  83. sql := "insert into log_sys_login (user_id,account,ip_addr,login_time,del_flag,login_type,user_name) values (?, ?,?,?,?,?,?)"
  84. _, err = session.Exec(sql, user.Id, user.LoginId, ip, sysmodel.NowLocal().Value(), 0, 0, user.Name)
  85. if err != nil {
  86. c.Ctx.JSON(200, sysmodel.SysReturn{400, err.Error(), nil})
  87. return
  88. }
  89. }
  90. //
  91. c.Ctx.JSON(200, sysmodel.SysReturn{200, "", data})
  92. } else {
  93. //fmt.Println(err.Error())
  94. c.Ctx.JSON(200, sysmodel.SysReturn{400, "username or password incorrect!", nil})
  95. }
  96. }
  97. func (la *LightAuth) Logout(c *entitys.CtrlContext) {
  98. token := c.Ctx.GetHeader("token")
  99. fmt.Println("delete token: ", token)
  100. sysutils.GetGlobalTokenStore().Remove(token)
  101. //登录日志
  102. tokenStore := sysutils.GetGlobalTokenStore()
  103. tokenInfo := tokenStore.Get(token)
  104. user := new(sysmodel.SysUser)
  105. if session != nil && tokenInfo != nil {
  106. _, err := c.PlatformDbEngine.Table(user.TableName()).Where("login_id = ?", tokenInfo.LoginID).Get(user)
  107. if err != nil {
  108. c.Ctx.JSON(200, sysmodel.SysReturn{400, err.Error(), nil})
  109. return
  110. }
  111. ip := RemoteIp(c.Ctx.Request)
  112. sql := "insert into log_sys_login (user_id,account,ip_addr,login_time,del_flag,login_type,user_name) values (?, ?,?,?,?,?,?)"
  113. _, err = session.Exec(sql, user.Id, user.LoginId, ip, sysmodel.NowLocal().Value(), 0, 1, user.Name)
  114. if err != nil {
  115. c.Ctx.JSON(200, sysmodel.SysReturn{400, err.Error(), nil})
  116. return
  117. }
  118. }
  119. //
  120. c.Ctx.JSON(200, sysmodel.SysReturn{200, "", nil})
  121. }
  122. const (
  123. XForwardedFor = "X-Forwarded-For"
  124. XRealIP = "X-Real-IP"
  125. )
  126. // RemoteIp 返回远程客户端的 IP,如 192.168.1.1
  127. func RemoteIp(req *http.Request) string {
  128. remoteAddr := req.RemoteAddr
  129. if ip := req.Header.Get(XRealIP); ip != "" {
  130. remoteAddr = ip
  131. } else if ip = req.Header.Get(XForwardedFor); ip != "" {
  132. remoteAddr = ip
  133. } else {
  134. remoteAddr, _, _ = net.SplitHostPort(remoteAddr)
  135. }
  136. if remoteAddr == "::1" {
  137. remoteAddr = "127.0.0.1"
  138. }
  139. return remoteAddr
  140. }