OpenApiController.java 12 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230
  1. package com.qmth.xjtu.api;
  2. import com.alibaba.fastjson.JSON;
  3. import com.alibaba.fastjson.JSONArray;
  4. import com.alibaba.fastjson.JSONObject;
  5. import com.baomidou.mybatisplus.core.conditions.query.QueryWrapper;
  6. import com.qmth.boot.api.annotation.Aac;
  7. import com.qmth.boot.api.annotation.BOOL;
  8. import com.qmth.boot.api.constant.ApiConstant;
  9. import com.qmth.boot.tools.signature.SignatureEntity;
  10. import com.qmth.boot.tools.signature.SignatureType;
  11. import com.qmth.teachcloud.exchange.common.bean.params.OpenParams;
  12. import com.qmth.teachcloud.exchange.common.contant.SystemConstant;
  13. import com.qmth.teachcloud.exchange.common.entity.BasicSchool;
  14. import com.qmth.teachcloud.exchange.common.enums.ExceptionResultEnum;
  15. import com.qmth.teachcloud.exchange.common.service.AuthInfoService;
  16. import com.qmth.teachcloud.exchange.common.service.BasicSchoolService;
  17. import com.qmth.teachcloud.exchange.common.service.CommonService;
  18. import com.qmth.teachcloud.exchange.common.util.HttpUtil;
  19. import com.qmth.teachcloud.exchange.common.util.JacksonUtil;
  20. import com.qmth.teachcloud.exchange.common.util.Result;
  21. import com.qmth.teachcloud.exchange.common.util.ServletUtil;
  22. import io.swagger.annotations.*;
  23. import org.apache.commons.lang3.StringUtils;
  24. import org.slf4j.Logger;
  25. import org.slf4j.LoggerFactory;
  26. import org.springframework.beans.factory.annotation.Value;
  27. import org.springframework.http.HttpStatus;
  28. import org.springframework.util.CollectionUtils;
  29. import org.springframework.validation.annotation.Validated;
  30. import org.springframework.web.bind.annotation.RequestMapping;
  31. import org.springframework.web.bind.annotation.RequestMethod;
  32. import org.springframework.web.bind.annotation.RequestParam;
  33. import org.springframework.web.bind.annotation.RestController;
  34. import javax.annotation.Resource;
  35. import javax.servlet.http.HttpServletResponse;
  36. import java.io.IOException;
  37. import java.util.*;
  38. /**
  39. * <p>
  40. * 西安交通大学开放接口前端控制器
  41. * </p>
  42. *
  43. * @author wangliang
  44. * @since 2022-04-26
  45. */
  46. @Api(tags = "西安交通大学开放接口Controller")
  47. @RestController
  48. @RequestMapping(ApiConstant.DEFAULT_URI_PREFIX + SystemConstant.PREFIX_URL_OPEN)
  49. @Validated
  50. public class OpenApiController {
  51. private static final Logger log = LoggerFactory.getLogger(OpenApiController.class);
  52. private static final String ACCESS_TOKEN_URL = "http://org.xjtu.edu.cn/openplatform/oauth/getAccessToken";
  53. private static final String USER_INFO_URL = "http://org.xjtu.edu.cn/openplatform/oauth/open/getUserInfo";
  54. private static final String LOGOUT_URL = "http://org.xjtu.edu.cn/openplatform/oauth/logout";
  55. private static final String SCHOOL_CODE = "xjtu";//测试学校code,正式改成xjtu
  56. private static final String LOGIN_BEFORE_XJU_LOGIC_API = "/api/admin/print/open/login_before_xju_logic";//西交大登录之前逻辑
  57. private static final String VERSION = "1.0.1.1";
  58. @Resource
  59. CommonService commonService;
  60. @Resource
  61. AuthInfoService authInfoService;
  62. @Value("${cas.config.logoutUrl}")
  63. String logoutUrl;
  64. @Value("${cas.config.returnUrl}")
  65. String returnUrl;
  66. @Value("${cas.config.teachcloudPrintLoginUrl}")
  67. String teachcloudLoginUrl;
  68. @Resource
  69. BasicSchoolService basicSchoolService;
  70. @ApiOperation(value = "西安交通大学cas鉴权接口")
  71. @ApiResponses({@ApiResponse(code = 200, message = "返回消息", response = Result.class)})
  72. @RequestMapping(value = "/authentication", method = RequestMethod.GET)
  73. @Aac(auth = BOOL.FALSE)
  74. public void authentication(@ApiParam(value = "工号") @RequestParam(required = false) String code,
  75. @ApiParam(value = "系统参数") @RequestParam(required = false) String state,
  76. @ApiParam(value = "用户类型") @RequestParam(required = false) String userType,
  77. @ApiParam(value = "员工工号") @RequestParam(required = false) String employeeNo,
  78. @ApiParam(value = "返回url") @RequestParam(required = false) String returnUrl) throws IOException {
  79. log.info("version:{}", VERSION);
  80. if ((Objects.isNull(code) || Objects.equals(code, ""))
  81. || (Objects.isNull(employeeNo) || Objects.equals(employeeNo, ""))) {
  82. throw ExceptionResultEnum.ERROR.exception("请先通过学校地址登录");
  83. }
  84. authInfoService.appHasExpired(SCHOOL_CODE);
  85. //2022-12-06加入登录之前逻辑
  86. if (Objects.isNull(teachcloudLoginUrl) || Objects.equals(teachcloudLoginUrl, "")) {
  87. throw ExceptionResultEnum.PARAMS_ERROR.exception("知学登录跳转地址不存在");
  88. }
  89. String[] strs = teachcloudLoginUrl.split(SystemConstant.PATH_SUBSTR);
  90. if (strs[0].contains(SystemConstant.PATH_MATCH)) {
  91. strs[0] = strs[0].replace(SystemConstant.PATH_MATCH, SCHOOL_CODE);
  92. }
  93. QueryWrapper<BasicSchool> basicSchoolQueryWrapper = new QueryWrapper<>();
  94. basicSchoolQueryWrapper.lambda().eq(BasicSchool::getCode, SCHOOL_CODE);
  95. BasicSchool basicSchool = basicSchoolService.getOne(basicSchoolQueryWrapper);
  96. Optional.ofNullable(basicSchool).orElseThrow(() -> ExceptionResultEnum.PARAMS_ERROR.exception("学校信息不存在"));
  97. Long timestamp = System.currentTimeMillis();
  98. String signature = SignatureEntity.build(SignatureType.SECRET, SystemConstant.METHOD, LOGIN_BEFORE_XJU_LOGIC_API, timestamp, basicSchool.getAccessKey(), basicSchool.getAccessSecret());
  99. String callResult = HttpUtil.postJson(strs[0] + LOGIN_BEFORE_XJU_LOGIC_API, JacksonUtil.parseJson(employeeNo), signature, timestamp);
  100. // String schoolCodeParam = null;
  101. if (!StringUtils.isBlank(callResult)) {
  102. log.info("callbackResult:{}", JacksonUtil.parseJson(callResult));
  103. Result result = JSON.parseObject(callResult, Result.class);
  104. if (result.getCode() == HttpStatus.OK.value()) {
  105. Object data = result.getData();
  106. List<Map> sysuserList = JSONObject.parseArray(JSON.toJSONString(data), Map.class);
  107. if (CollectionUtils.isEmpty(sysuserList)) {
  108. throw ExceptionResultEnum.ERROR.exception("未查到此用户");
  109. }
  110. // if (sysuserList.size() >= 2) {
  111. // throw ExceptionResultEnum.ERROR.exception("查询到有多个用户");
  112. // }
  113. // String schoolId = String.valueOf(sysuserList.get(0).get("schoolId"));
  114. // Optional.ofNullable(schoolId).orElseThrow(() -> ExceptionResultEnum.ERROR.exception("学校id为空"));
  115. // BasicSchool basicSchoolMap = (BasicSchool) cacheService.get(SystemConstant.SCHOOL_CACHE, schoolId);
  116. // Optional.ofNullable(basicSchoolMap).orElseThrow(() -> ExceptionResultEnum.ERROR.exception("学校id:" + schoolId + ",学校不存在"));
  117. // schoolCodeParam = basicSchoolMap.getCode();
  118. } else {
  119. throw ExceptionResultEnum.ERROR.exception("调用知学知考西交大登录前查找账号接口失败");
  120. }
  121. }
  122. Map<String, Object> accessTokenParams = new LinkedHashMap<>();
  123. accessTokenParams.put("code", code);
  124. String accessTokenResult = HttpUtil.post(ACCESS_TOKEN_URL, accessTokenParams, null);
  125. String accessToken = null, gsessionId = null;
  126. //获取accessToken
  127. if (Objects.nonNull(accessTokenResult)) {
  128. log.info("accessTokenResult:{}", JacksonUtil.parseJson(accessTokenResult));
  129. JSONObject jsonObject = JSONObject.parseObject(accessTokenResult);
  130. JSONObject object = jsonObject.getJSONObject("data");
  131. String message = jsonObject.getString("message");
  132. if (Objects.nonNull(object) && Objects.nonNull(message) && Objects.equals(message, "成功")) {
  133. accessToken = object.getString("accessToken");
  134. gsessionId = object.getString("gsessionId");
  135. } else {
  136. throw ExceptionResultEnum.ERROR.exception(message);
  137. }
  138. }
  139. OpenParams openParams = null;
  140. //获取用户信息
  141. if (Objects.nonNull(accessToken)) {
  142. String userInfoResult = HttpUtil.post(USER_INFO_URL, null, accessToken);
  143. if (Objects.nonNull(userInfoResult)) {
  144. log.info("userInfoResult:{}", JacksonUtil.parseJson(userInfoResult));
  145. openParams = new OpenParams();
  146. // openParams.setResult(JacksonUtil.parseJson(userInfoResult));
  147. JSONObject jsonObject = JSONObject.parseObject(userInfoResult);
  148. JSONObject object = jsonObject.getJSONObject("data");
  149. String message = jsonObject.getString("message");
  150. JSONArray userTypeJsonArray = object.getJSONArray("userTypes");
  151. JSONArray deptInfoJsonArray = object.getJSONArray("deptInfos");
  152. if (Objects.nonNull(object) && Objects.nonNull(message) && Objects.equals(message, "成功")) {
  153. openParams.setOrgName(object.getString("orgName"));
  154. if (Objects.nonNull(userTypeJsonArray) && userTypeJsonArray.size() > 0) {
  155. JSONObject userTypeJsonObject = userTypeJsonArray.getJSONObject(0);
  156. openParams.setName(userTypeJsonObject.getString("memberName"));
  157. Integer userTypeRole = userTypeJsonObject.getInteger("userType");
  158. if (Objects.nonNull(userTypeRole) && userTypeRole.intValue() == 1) {
  159. openParams.setRoleName("学生");
  160. } else if (Objects.nonNull(userTypeRole) && userTypeRole.intValue() == 2) {
  161. openParams.setRoleName("教职工");
  162. }
  163. }
  164. if (Objects.nonNull(deptInfoJsonArray) && deptInfoJsonArray.size() > 0) {
  165. JSONObject deptInfoJsonArrayJsonObject = deptInfoJsonArray.getJSONObject(0);
  166. openParams.setDeptName(deptInfoJsonArrayJsonObject.getString("deptName"));
  167. }
  168. } else {
  169. throw ExceptionResultEnum.ERROR.exception(message);
  170. }
  171. }
  172. }
  173. //登出
  174. if (Objects.nonNull(gsessionId)) {
  175. StringJoiner stringJoiner = new StringJoiner("");
  176. stringJoiner.add(logoutUrl).add(SystemConstant.GET_UNKNOWN).add("gSessionId")
  177. .add(SystemConstant.GET_EQUAL).add(gsessionId);
  178. returnUrl = stringJoiner.toString();
  179. } else {
  180. throw ExceptionResultEnum.ERROR.exception("gSessionId为空");
  181. }
  182. commonService.redirectLogic(employeeNo, SCHOOL_CODE, returnUrl, Objects.nonNull(openParams) ? JacksonUtil.parseJson(openParams) : null);
  183. }
  184. @ApiOperation(value = "西安交通大学cas鉴权退出接口")
  185. @RequestMapping(value = "/authentication/logout", method = RequestMethod.GET)
  186. @ApiResponses({@ApiResponse(code = 200, message = "返回消息", response = Result.class)})
  187. @Aac(auth = BOOL.FALSE)
  188. public void logout(@ApiParam(value = "sessionId", required = true) @RequestParam String gSessionId) throws IOException {
  189. if (Objects.isNull(logoutUrl) || Objects.equals(logoutUrl, "")) {
  190. throw ExceptionResultEnum.PARAMS_ERROR.exception("鉴权退出地址不存在");
  191. }
  192. if (Objects.isNull(gSessionId) || Objects.equals(gSessionId, "")) {
  193. throw ExceptionResultEnum.PARAMS_ERROR.exception("sessionId为空");
  194. }
  195. authInfoService.appHasExpired(SCHOOL_CODE);
  196. Map<String, Object> logoutParams = new LinkedHashMap<>();
  197. logoutParams.put("gSessionId", gSessionId);
  198. String logoutResult = HttpUtil.post(LOGOUT_URL, logoutParams, null);
  199. if (Objects.nonNull(logoutResult)) {
  200. log.info("logoutResult:{}", JacksonUtil.parseJson(logoutResult));
  201. JSONObject jsonObject = JSONObject.parseObject(logoutResult);
  202. String message = jsonObject.getString("message");
  203. if (Objects.nonNull(message) && Objects.equals(message, "成功")) {
  204. HttpServletResponse response = ServletUtil.getResponse();
  205. response.setHeader("Access-Control-Allow-Origin", SystemConstant.PATH_MATCH);
  206. response.sendRedirect(returnUrl);
  207. }
  208. }
  209. }
  210. }