OpenApiController.java 12 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227
  1. package com.qmth.xjtu.api;
  2. import com.alibaba.fastjson.JSON;
  3. import com.alibaba.fastjson.JSONArray;
  4. import com.alibaba.fastjson.JSONObject;
  5. import com.baomidou.mybatisplus.core.conditions.query.QueryWrapper;
  6. import com.qmth.boot.api.annotation.Aac;
  7. import com.qmth.boot.api.annotation.BOOL;
  8. import com.qmth.boot.api.constant.ApiConstant;
  9. import com.qmth.boot.tools.signature.SignatureEntity;
  10. import com.qmth.boot.tools.signature.SignatureType;
  11. import com.qmth.teachcloud.exchange.common.bean.params.OpenParams;
  12. import com.qmth.teachcloud.exchange.common.contant.SystemConstant;
  13. import com.qmth.teachcloud.exchange.common.entity.BasicSchool;
  14. import com.qmth.teachcloud.exchange.common.enums.ExceptionResultEnum;
  15. import com.qmth.teachcloud.exchange.common.service.AuthInfoService;
  16. import com.qmth.teachcloud.exchange.common.service.BasicSchoolService;
  17. import com.qmth.teachcloud.exchange.common.service.CommonService;
  18. import com.qmth.teachcloud.exchange.common.util.HttpUtil;
  19. import com.qmth.teachcloud.exchange.common.util.JacksonUtil;
  20. import com.qmth.teachcloud.exchange.common.util.Result;
  21. import com.qmth.teachcloud.exchange.common.util.ServletUtil;
  22. import io.swagger.annotations.*;
  23. import org.apache.commons.lang3.StringUtils;
  24. import org.slf4j.Logger;
  25. import org.slf4j.LoggerFactory;
  26. import org.springframework.beans.factory.annotation.Value;
  27. import org.springframework.http.HttpStatus;
  28. import org.springframework.util.CollectionUtils;
  29. import org.springframework.validation.annotation.Validated;
  30. import org.springframework.web.bind.annotation.RequestMapping;
  31. import org.springframework.web.bind.annotation.RequestMethod;
  32. import org.springframework.web.bind.annotation.RequestParam;
  33. import org.springframework.web.bind.annotation.RestController;
  34. import javax.annotation.Resource;
  35. import javax.servlet.http.HttpServletResponse;
  36. import java.io.IOException;
  37. import java.util.*;
  38. /**
  39. * <p>
  40. * 西安交通大学开放接口前端控制器
  41. * </p>
  42. *
  43. * @author wangliang
  44. * @since 2022-04-26
  45. */
  46. @Api(tags = "西安交通大学开放接口Controller")
  47. @RestController
  48. @RequestMapping(ApiConstant.DEFAULT_URI_PREFIX + "/${prefix.url.open}")
  49. @Validated
  50. public class OpenApiController {
  51. private static final Logger log = LoggerFactory.getLogger(OpenApiController.class);
  52. private static final String ACCESS_TOKEN_URL = "http://org.xjtu.edu.cn/openplatform/oauth/getAccessToken";
  53. private static final String USER_INFO_URL = "http://org.xjtu.edu.cn/openplatform/oauth/open/getUserInfo";
  54. private static final String LOGOUT_URL = "http://org.xjtu.edu.cn/openplatform/oauth/logout";
  55. private static final String SCHOOL_CODE = "xjtu";//测试学校code,正式改成xjtu
  56. private static final String LOGIN_BEFORE_XJU_LOGIC_API = "/api/admin/print/open/login_before_xju_logic";//西交大登录之前逻辑
  57. @Resource
  58. CommonService commonService;
  59. @Resource
  60. AuthInfoService authInfoService;
  61. @Value("${cas.config.logoutUrl}")
  62. String logoutUrl;
  63. @Value("${cas.config.returnUrl}")
  64. String returnUrl;
  65. @Value("${cas.config.teachcloudPrintLoginUrl}")
  66. String teachcloudLoginUrl;
  67. @Resource
  68. BasicSchoolService basicSchoolService;
  69. @ApiOperation(value = "西安交通大学cas鉴权接口")
  70. @ApiResponses({@ApiResponse(code = 200, message = "返回消息", response = Result.class)})
  71. @RequestMapping(value = "/authentication", method = RequestMethod.GET)
  72. @Aac(auth = BOOL.FALSE)
  73. public void authentication(@ApiParam(value = "工号") @RequestParam(required = false) String code,
  74. @ApiParam(value = "系统参数") @RequestParam(required = false) String state,
  75. @ApiParam(value = "用户类型") @RequestParam(required = false) String userType,
  76. @ApiParam(value = "员工工号") @RequestParam(required = false) String employeeNo,
  77. @ApiParam(value = "返回url") @RequestParam(required = false) String returnUrl) throws IOException {
  78. if ((Objects.isNull(code) || Objects.equals(code, ""))
  79. || (Objects.isNull(employeeNo) || Objects.equals(employeeNo, ""))) {
  80. throw ExceptionResultEnum.ERROR.exception("请先通过学校地址登录");
  81. }
  82. authInfoService.appHasExpired(SCHOOL_CODE);
  83. //2022-12-06加入登录之前逻辑
  84. if (Objects.isNull(teachcloudLoginUrl) || Objects.equals(teachcloudLoginUrl, "")) {
  85. throw ExceptionResultEnum.PARAMS_ERROR.exception("知学登录跳转地址不存在");
  86. }
  87. String[] strs = teachcloudLoginUrl.split(SystemConstant.PATH_SUBSTR);
  88. if (strs[0].contains(SystemConstant.PATH_MATCH)) {
  89. strs[0] = strs[0].replace(SystemConstant.PATH_MATCH, SCHOOL_CODE);
  90. }
  91. QueryWrapper<BasicSchool> basicSchoolQueryWrapper = new QueryWrapper<>();
  92. basicSchoolQueryWrapper.lambda().eq(BasicSchool::getCode, SCHOOL_CODE);
  93. BasicSchool basicSchool = basicSchoolService.getOne(basicSchoolQueryWrapper);
  94. Optional.ofNullable(basicSchool).orElseThrow(() -> ExceptionResultEnum.PARAMS_ERROR.exception("学校信息不存在"));
  95. Long timestamp = System.currentTimeMillis();
  96. String signature = SignatureEntity.build(SignatureType.SECRET, SystemConstant.METHOD, LOGIN_BEFORE_XJU_LOGIC_API, timestamp, basicSchool.getAccessKey(), basicSchool.getAccessSecret());
  97. String callResult = HttpUtil.postJson(strs[0] + LOGIN_BEFORE_XJU_LOGIC_API, JacksonUtil.parseJson(employeeNo), signature, timestamp);
  98. String schoolCode = null;
  99. if (!StringUtils.isBlank(callResult)) {
  100. log.info("callbackResult:{}", JacksonUtil.parseJson(callResult));
  101. Result result = JSON.parseObject(callResult, Result.class);
  102. if (result.getCode() == HttpStatus.OK.value()) {
  103. Object data = result.getData();
  104. List<Map> sysuserList = JSONObject.parseArray(JSON.toJSONString(data), Map.class);
  105. if (CollectionUtils.isEmpty(sysuserList)) {
  106. throw ExceptionResultEnum.ERROR.exception("未查到此用户");
  107. }
  108. if (sysuserList.size() >= 2) {
  109. throw ExceptionResultEnum.ERROR.exception("查询到有多个用户");
  110. }
  111. Long schoolId = Long.parseLong(String.valueOf(sysuserList.get(0).get("schoolId")));
  112. Optional.ofNullable(schoolId).orElseThrow(() -> ExceptionResultEnum.ERROR.exception("学校id为空"));
  113. basicSchool = basicSchoolService.getById(schoolId);
  114. Optional.ofNullable(basicSchool).orElseThrow(() -> ExceptionResultEnum.ERROR.exception("学校id:" + schoolId + ",学校不存在"));
  115. schoolCode = basicSchool.getCode();
  116. } else {
  117. throw ExceptionResultEnum.ERROR.exception("调用知学知考西交大登录前查找账号接口失败");
  118. }
  119. }
  120. Map<String, Object> accessTokenParams = new LinkedHashMap<>();
  121. accessTokenParams.put("code", code);
  122. String accessTokenResult = HttpUtil.post(ACCESS_TOKEN_URL, accessTokenParams, null);
  123. String accessToken = null, gsessionId = null;
  124. //获取accessToken
  125. if (Objects.nonNull(accessTokenResult)) {
  126. log.info("accessTokenResult:{}", JacksonUtil.parseJson(accessTokenResult));
  127. JSONObject jsonObject = JSONObject.parseObject(accessTokenResult);
  128. JSONObject object = jsonObject.getJSONObject("data");
  129. String message = jsonObject.getString("message");
  130. if (Objects.nonNull(object) && Objects.nonNull(message) && Objects.equals(message, "成功")) {
  131. accessToken = object.getString("accessToken");
  132. gsessionId = object.getString("gsessionId");
  133. } else {
  134. throw ExceptionResultEnum.ERROR.exception(message);
  135. }
  136. }
  137. OpenParams openParams = null;
  138. //获取用户信息
  139. if (Objects.nonNull(accessToken)) {
  140. String userInfoResult = HttpUtil.post(USER_INFO_URL, null, accessToken);
  141. if (Objects.nonNull(userInfoResult)) {
  142. log.info("userInfoResult:{}", JacksonUtil.parseJson(userInfoResult));
  143. openParams = new OpenParams();
  144. // openParams.setResult(JacksonUtil.parseJson(userInfoResult));
  145. JSONObject jsonObject = JSONObject.parseObject(userInfoResult);
  146. JSONObject object = jsonObject.getJSONObject("data");
  147. String message = jsonObject.getString("message");
  148. JSONArray userTypeJsonArray = object.getJSONArray("userTypes");
  149. JSONArray deptInfoJsonArray = object.getJSONArray("deptInfos");
  150. if (Objects.nonNull(object) && Objects.nonNull(message) && Objects.equals(message, "成功")) {
  151. openParams.setOrgName(object.getString("orgName"));
  152. if (Objects.nonNull(userTypeJsonArray) && userTypeJsonArray.size() > 0) {
  153. JSONObject userTypeJsonObject = userTypeJsonArray.getJSONObject(0);
  154. openParams.setName(userTypeJsonObject.getString("memberName"));
  155. Integer userTypeRole = userTypeJsonObject.getInteger("userType");
  156. if (Objects.nonNull(userTypeRole) && userTypeRole.intValue() == 1) {
  157. openParams.setRoleName("学生");
  158. } else if (Objects.nonNull(userTypeRole) && userTypeRole.intValue() == 2) {
  159. openParams.setRoleName("教职工");
  160. }
  161. }
  162. if (Objects.nonNull(deptInfoJsonArray) && deptInfoJsonArray.size() > 0) {
  163. JSONObject deptInfoJsonArrayJsonObject = deptInfoJsonArray.getJSONObject(0);
  164. openParams.setDeptName(deptInfoJsonArrayJsonObject.getString("deptName"));
  165. }
  166. } else {
  167. throw ExceptionResultEnum.ERROR.exception(message);
  168. }
  169. }
  170. }
  171. //登出
  172. if (Objects.nonNull(gsessionId)) {
  173. StringJoiner stringJoiner = new StringJoiner("");
  174. stringJoiner.add(logoutUrl).add(SystemConstant.GET_UNKNOWN).add("gSessionId")
  175. .add(SystemConstant.GET_EQUAL).add(gsessionId);
  176. returnUrl = stringJoiner.toString();
  177. } else {
  178. throw ExceptionResultEnum.ERROR.exception("gSessionId为空");
  179. }
  180. commonService.redirectLogic(employeeNo, schoolCode, returnUrl, Objects.nonNull(openParams) ? JacksonUtil.parseJson(openParams) : null);
  181. }
  182. @ApiOperation(value = "西安交通大学cas鉴权退出接口")
  183. @RequestMapping(value = "/authentication/logout", method = RequestMethod.GET)
  184. @ApiResponses({@ApiResponse(code = 200, message = "返回消息", response = Result.class)})
  185. @Aac(auth = BOOL.FALSE)
  186. public void logout(@ApiParam(value = "sessionId", required = true) @RequestParam String gSessionId) throws IOException {
  187. if (Objects.isNull(logoutUrl) || Objects.equals(logoutUrl, "")) {
  188. throw ExceptionResultEnum.PARAMS_ERROR.exception("鉴权退出地址不存在");
  189. }
  190. if (Objects.isNull(gSessionId) || Objects.equals(gSessionId, "")) {
  191. throw ExceptionResultEnum.PARAMS_ERROR.exception("sessionId为空");
  192. }
  193. authInfoService.appHasExpired(SCHOOL_CODE);
  194. Map<String, Object> logoutParams = new LinkedHashMap<>();
  195. logoutParams.put("gSessionId", gSessionId);
  196. String logoutResult = HttpUtil.post(LOGOUT_URL, logoutParams, null);
  197. if (Objects.nonNull(logoutResult)) {
  198. log.info("logoutResult:{}", JacksonUtil.parseJson(logoutResult));
  199. JSONObject jsonObject = JSONObject.parseObject(logoutResult);
  200. String message = jsonObject.getString("message");
  201. if (Objects.nonNull(message) && Objects.equals(message, "成功")) {
  202. HttpServletResponse response = ServletUtil.getResponse();
  203. response.setHeader("Access-Control-Allow-Origin", SystemConstant.PATH_MATCH);
  204. response.sendRedirect(returnUrl);
  205. }
  206. }
  207. }
  208. }