SysController.java 15 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336
  1. package com.qmth.distributed.print.api;
  2. import com.baomidou.mybatisplus.core.conditions.query.QueryWrapper;
  3. import com.qmth.boot.api.annotation.Aac;
  4. import com.qmth.boot.api.annotation.BOOL;
  5. import com.qmth.boot.api.constant.ApiConstant;
  6. import com.qmth.boot.api.exception.ApiException;
  7. import com.qmth.boot.core.enums.Platform;
  8. import com.qmth.boot.tools.signature.SignatureType;
  9. import com.qmth.distributed.print.business.bean.auth.AuthBean;
  10. import com.qmth.distributed.print.business.bean.auth.ExpireTimeBean;
  11. import com.qmth.distributed.print.business.bean.dto.MenuDto;
  12. import com.qmth.distributed.print.business.bean.params.LoginParam;
  13. import com.qmth.distributed.print.business.bean.result.EditResult;
  14. import com.qmth.distributed.print.business.bean.result.LoginResult;
  15. import com.qmth.distributed.print.business.config.DictionaryConfig;
  16. import com.qmth.distributed.print.business.entity.*;
  17. import com.qmth.distributed.print.business.enums.DownloadFileEnum;
  18. import com.qmth.distributed.print.business.enums.RoleTypeEnum;
  19. import com.qmth.distributed.print.business.enums.UploadFileEnum;
  20. import com.qmth.distributed.print.business.service.*;
  21. import com.qmth.distributed.print.business.util.AuthUtil;
  22. import com.qmth.distributed.print.business.util.RedisUtil;
  23. import com.qmth.distributed.print.business.util.ServletUtil;
  24. import com.qmth.distributed.print.business.util.security.Md5Utils;
  25. import com.qmth.distributed.print.common.SignatureEntityTest;
  26. import com.qmth.distributed.print.common.contant.SystemConstant;
  27. import com.qmth.distributed.print.common.enums.ExceptionResultEnum;
  28. import com.qmth.distributed.print.common.util.Result;
  29. import com.qmth.distributed.print.common.util.ResultUtil;
  30. import com.qmth.distributed.print.common.util.SessionUtil;
  31. import io.swagger.annotations.*;
  32. import org.slf4j.Logger;
  33. import org.slf4j.LoggerFactory;
  34. import org.springframework.beans.factory.annotation.Autowired;
  35. import org.springframework.transaction.annotation.Transactional;
  36. import org.springframework.validation.BindingResult;
  37. import org.springframework.web.bind.annotation.*;
  38. import org.springframework.web.multipart.MultipartFile;
  39. import javax.annotation.Resource;
  40. import javax.validation.Valid;
  41. import java.security.NoSuchAlgorithmException;
  42. import java.util.*;
  43. import java.util.stream.Collectors;
  44. /**
  45. * @Date: 2021/3/30.
  46. */
  47. @Api(tags = "系统Controller")
  48. @RestController
  49. @RequestMapping(ApiConstant.DEFAULT_URI_PREFIX + "/${prefix.url.common}")
  50. @Aac(strict = BOOL.TRUE, platform = Platform.WEB)
  51. public class SysController {
  52. private final static Logger log = LoggerFactory.getLogger(SysController.class);
  53. @Autowired
  54. private SysUserService sysUserService;
  55. @Autowired
  56. private BasicVerifyCodeService basicVerifyCodeService;
  57. @Autowired
  58. private DictionaryConfig dictionaryConfig;
  59. @Resource
  60. CacheService cacheService;
  61. @Resource
  62. TBSessionService tbSessionService;
  63. @Resource
  64. RedisUtil redisUtil;
  65. @Resource
  66. CommonService commonService;
  67. @Resource
  68. TBTaskService tbTaskService;
  69. @Resource
  70. BasicAttachmentService basicAttachmentService;
  71. @Autowired
  72. private SysConfigService sysConfigService;
  73. @Autowired
  74. private SysUserRoleService sysUserRoleService;
  75. /**
  76. * 登录
  77. *
  78. * @param login
  79. * @return
  80. */
  81. @ApiOperation(value = "登录")
  82. @RequestMapping(value = "/login", method = RequestMethod.POST)
  83. @ApiResponses({@ApiResponse(code = 200, message = "用户信息", response = LoginResult.class)})
  84. @Aac(auth = BOOL.FALSE)
  85. public Result login(@ApiParam(value = "用户信息", required = true) @Valid @RequestBody LoginParam login, BindingResult bindingResult) throws NoSuchAlgorithmException {
  86. if (bindingResult.hasErrors()) {
  87. return ResultUtil.error(bindingResult.getAllErrors().get(0).getDefaultMessage());
  88. }
  89. BasicSchool basicSchool = null;
  90. if (!Objects.equals(login.getSchoolCode().toUpperCase(), RoleTypeEnum.ADMIN.name())) {
  91. basicSchool = cacheService.schoolCache(login.getSchoolCode());
  92. if (Objects.isNull(basicSchool)) {
  93. throw ExceptionResultEnum.SCHOOL_NO_DATA.exception();
  94. }
  95. if (Objects.nonNull(basicSchool.getEnable()) && !basicSchool.getEnable()) {
  96. throw ExceptionResultEnum.SCHOOL_ENABLE.exception();
  97. }
  98. }
  99. QueryWrapper<SysUser> wrapper = new QueryWrapper<>();
  100. wrapper.lambda().eq(SysUser::getLoginName, login.getLoginName());
  101. if (!Objects.equals(login.getSchoolCode().toUpperCase(), RoleTypeEnum.ADMIN.name())) {
  102. wrapper.lambda().eq(SysUser::getSchoolId, basicSchool.getId());
  103. }
  104. List<SysUser> userList = sysUserService.list(wrapper);
  105. //用户不存在
  106. if (Objects.isNull(userList) || userList.size() == 0) {
  107. throw ExceptionResultEnum.USER_NO_DATA.exception();
  108. }
  109. if (Objects.equals(login.getSchoolCode().toUpperCase(), RoleTypeEnum.ADMIN.name())) {
  110. userList.forEach(o -> {
  111. AuthBean authBean = commonService.getUserAuth(o.getId());
  112. if (Objects.nonNull(authBean) && Objects.nonNull(authBean.getRoleList()) && authBean.getRoleList().size() > 0) {
  113. Set<RoleTypeEnum> roleType = authBean.getRoleList().stream().map(s -> s.getType()).collect(Collectors.toSet());
  114. if (!roleType.contains(RoleTypeEnum.ADMIN) && !roleType.contains(RoleTypeEnum.CUSTOMER)) {
  115. throw ExceptionResultEnum.ERROR.exception("学校代码为admin只允许超级管理员登录");
  116. }
  117. }
  118. });
  119. }
  120. if (userList.size() > 1) {
  121. throw ExceptionResultEnum.ERROR.exception("查询的用户有多条");
  122. }
  123. SysUser sysUser = userList.get(0);
  124. if (Objects.nonNull(sysUser.getSchoolId()) && sysUser.getSchoolId().longValue() != basicSchool.getId().longValue()) {
  125. throw ExceptionResultEnum.ERROR.exception("用户学校不匹配");
  126. }
  127. //密码不正确
  128. if (!Objects.equals(login.getPassword(), sysUser.getPassword())) {
  129. throw ExceptionResultEnum.PASSWORD_ERROR.exception();
  130. }
  131. //停用
  132. if (!sysUser.getEnable()) {
  133. throw ExceptionResultEnum.USER_ENABLE.exception();
  134. }
  135. // 校验验证码
  136. SysConfig value = sysConfigService.getByKey("sys.code.enable");
  137. if (Objects.nonNull(value) && value.getConfigValue().equals("true")) {
  138. String code = login.getCode();
  139. if (Objects.isNull(code)) {
  140. throw ExceptionResultEnum.ERROR.exception("验证码为空");
  141. }
  142. if (!dictionaryConfig.smsDomain().getSmsNormalCode().equals(code)) {
  143. QueryWrapper<BasicVerifyCode> codeWrapper = new QueryWrapper<>();
  144. codeWrapper.lambda().eq(BasicVerifyCode::getMobileNumber, sysUser.getMobileNumber()).eq(BasicVerifyCode::getUserId, sysUser.getId());
  145. BasicVerifyCode accessControl = basicVerifyCodeService.getOne(codeWrapper);
  146. if (accessControl == null || (accessControl != null && !accessControl.getVerifyCode().equals(code))) {
  147. throw ExceptionResultEnum.ERROR.exception("短信验证码错误,请仔细核对后再次输入");
  148. }
  149. if (new Date(accessControl.getExpireTime()).before(new Date())) {
  150. throw ExceptionResultEnum.ERROR.exception("短信验证码已过期");
  151. }
  152. }
  153. }
  154. Platform platform = ServletUtil.getRequestPlatform();
  155. String deviceId = ServletUtil.getRequestDeviceId();
  156. //添加用户鉴权缓存
  157. AuthBean authBean = cacheService.userAuthCache(sysUser.getId());
  158. if (Objects.isNull(authBean)) {
  159. throw ExceptionResultEnum.ROLE_ENABLE_AUTHORIZATION.exception();
  160. }
  161. //生成token
  162. String token = SystemConstant.getUuid();
  163. cacheService.userCache(sysUser.getId());
  164. //添加用户会话缓存
  165. Set<RoleTypeEnum> roleType = authBean.getRoleList().stream().map(s -> s.getType()).collect(Collectors.toSet());
  166. String sessionId = SessionUtil.digest(sysUser.getId(), Math.abs(roleType.toString().hashCode()), platform.name());
  167. //TODO 测试用
  168. String test = SignatureEntityTest.build(SignatureType.TOKEN, sessionId, token);
  169. ExpireTimeBean expireTime = AuthUtil.getExpireTime(platform);
  170. TBSession tbSession = new TBSession(sessionId, String.valueOf(sysUser.getId()), roleType.toString(),
  171. platform.name(), platform.name(), deviceId, ServletUtil.getRequest().getLocalAddr(), token,
  172. expireTime.getDate().getTime());
  173. tbSessionService.saveOrUpdate(tbSession);
  174. redisUtil.setUserSession(sessionId, tbSession, expireTime.getExpireSeconds());
  175. LoginResult loginResult = new LoginResult(sysUser, sessionId, test, roleType);
  176. loginResult.setSchoolInfo(Objects.nonNull(authBean.getSchool()) ? loginResult.new SchoolNativeBean(authBean.getSchool()) : null);
  177. loginResult.setOrgInfo(Objects.nonNull(authBean.getOrg()) ? loginResult.new OrgNativeBean(authBean.getOrg()) : null);
  178. return ResultUtil.ok(loginResult);
  179. }
  180. /**
  181. * 登出
  182. *
  183. * @return
  184. */
  185. @ApiOperation(value = "登出")
  186. @RequestMapping(value = "/logout", method = RequestMethod.POST)
  187. @ApiResponses({@ApiResponse(code = 200, message = "返回信息", response = EditResult.class)})
  188. public Result logout() {
  189. SysUser sysUser = (SysUser) ServletUtil.getRequestUser();
  190. TBSession tbSession = (TBSession) ServletUtil.getRequestSession();
  191. AuthBean authBean = cacheService.userAuthCache(sysUser.getId());
  192. if (Objects.isNull(authBean)) {
  193. throw ExceptionResultEnum.NOT_LOGIN.exception();
  194. }
  195. tbSessionService.removeById(tbSession.getId());
  196. redisUtil.deleteUserSession(tbSession.getId());
  197. cacheService.removeUserCache(sysUser.getId());
  198. cacheService.removeUserAuthCache(sysUser.getId());
  199. return ResultUtil.ok(new EditResult(sysUser.getId()));
  200. }
  201. /**
  202. * 发送验证码
  203. *
  204. * @param loginParam
  205. * @return
  206. */
  207. @ApiOperation(value = "发送验证码")
  208. @RequestMapping(value = "/getVerifyCode", method = RequestMethod.POST)
  209. public Object getverifyCode(@RequestBody LoginParam loginParam) {
  210. String loginName = loginParam.getLoginName();
  211. QueryWrapper<SysUser> wrapper = new QueryWrapper<>();
  212. wrapper.lambda().eq(SysUser::getLoginName, loginName);
  213. SysUser user = sysUserService.getOne(wrapper);
  214. //用户不存在
  215. if (Objects.isNull(user)) {
  216. throw ExceptionResultEnum.ERROR.exception("用户不存在");
  217. }
  218. String password = Md5Utils.toMd5Hex(loginParam.getPassword());
  219. if (password.equals(user.getPassword())) {
  220. throw ExceptionResultEnum.ERROR.exception("密码错误");
  221. }
  222. String mobileNumber = user.getMobileNumber();
  223. if (Objects.isNull(mobileNumber)) {
  224. throw ExceptionResultEnum.ERROR.exception("用户未绑定手机号码");
  225. }
  226. basicVerifyCodeService.sendVeirfyCode(mobileNumber, user.getId());
  227. return ResultUtil.ok(true);
  228. }
  229. @ApiOperation(value = "根据机构代码查询机构信息接口")
  230. @RequestMapping(value = "/school/query_by_school_code", method = RequestMethod.POST)
  231. @ApiResponses({@ApiResponse(code = 200, message = "学校信息", response = EditResult.class)})
  232. @Aac(auth = BOOL.FALSE)
  233. public Result queryBySchoolCode(@ApiParam(value = "机构code", required = true) @RequestParam String code) {
  234. if (!Objects.equals(code.toUpperCase(), RoleTypeEnum.ADMIN.name())) {
  235. BasicSchool basicSchool = cacheService.schoolCache(code);
  236. if (Objects.isNull(basicSchool)) {
  237. throw ExceptionResultEnum.SCHOOL_NO_DATA.exception();
  238. }
  239. return ResultUtil.ok(Collections.singletonMap(SystemConstant.LOGO, basicSchool.getLogo()));
  240. } else {
  241. return ResultUtil.ok(Collections.singletonMap(SystemConstant.LOGO, dictionaryConfig.sysDomain().getAdminLogoUrl()));
  242. }
  243. }
  244. @ApiOperation(value = "文件上传接口")
  245. @RequestMapping(value = "/file/upload", method = RequestMethod.POST)
  246. @Transactional
  247. @ApiResponses({@ApiResponse(code = 200, message = "返回信息", response = EditResult.class)})
  248. public Result fileUpload(@ApiParam(value = "上传文件", required = true) @RequestParam MultipartFile file,
  249. @ApiParam(value = "上传文件类型", required = true) @RequestParam UploadFileEnum type) {
  250. BasicAttachment basicAttachment = null;
  251. try {
  252. basicAttachment = basicAttachmentService.saveAttachment(file, ServletUtil.getRequestMd5(), type);
  253. if (Objects.isNull(basicAttachment)) {
  254. throw ExceptionResultEnum.ATTACHMENT_ERROR.exception();
  255. }
  256. } catch (Exception e) {
  257. log.error("请求出错", e);
  258. if (Objects.nonNull(basicAttachment)) {
  259. basicAttachmentService.deleteAttachment(basicAttachment);
  260. }
  261. if (e instanceof ApiException) {
  262. ResultUtil.error((ApiException) e, e.getMessage());
  263. } else {
  264. ResultUtil.error(e.getMessage());
  265. }
  266. }
  267. return ResultUtil.ok(new EditResult(basicAttachment.getId(), commonService.filePreview(basicAttachment.getPath()), basicAttachment.getPages()));
  268. }
  269. @ApiOperation(value = "文件下载接口")
  270. @RequestMapping(value = "/file/download", method = RequestMethod.POST)
  271. @ApiResponses({@ApiResponse(code = 200, message = "返回信息", response = EditResult.class)})
  272. public Result fileDownload(@ApiParam(value = "任务id", required = true) @RequestParam String id,
  273. @ApiParam(value = "下载文件类型", required = true) @RequestParam DownloadFileEnum type) {
  274. TBTask tbTask = tbTaskService.getById(Long.parseLong(id));
  275. if (Objects.isNull(tbTask)) {
  276. throw ExceptionResultEnum.TASK_NO_DATA.exception();
  277. }
  278. String path = null;
  279. switch (type.ordinal()) {
  280. case 0:
  281. path = tbTask.getImportFilePath();
  282. break;
  283. case 1:
  284. path = tbTask.getReportFilePath();
  285. break;
  286. default:
  287. path = tbTask.getResultFilePath();
  288. break;
  289. }
  290. if (Objects.isNull(path)) {
  291. throw ExceptionResultEnum.PATH_NO_DATA.exception();
  292. }
  293. return ResultUtil.ok(new EditResult(commonService.filePreview(path)));
  294. }
  295. @ApiOperation(value = "文件预览接口")
  296. @RequestMapping(value = "/file/preview", method = RequestMethod.POST)
  297. @ApiResponses({@ApiResponse(code = 200, message = "返回信息", response = EditResult.class)})
  298. public Result filePreview(@ApiParam(value = "附件id", required = true) @RequestParam String id) {
  299. BasicAttachment basicAttachment = basicAttachmentService.getById(Long.parseLong(id));
  300. return ResultUtil.ok(new EditResult(commonService.filePreview(basicAttachment.getPath())));
  301. }
  302. @ApiOperation(value = "查询用户权限")
  303. @RequestMapping(value = "/get_menu", method = RequestMethod.POST)
  304. public Result getMenu() {
  305. List<MenuDto> list = sysUserRoleService.listByUserId();
  306. return ResultUtil.ok(list);
  307. }
  308. }