SysController.java 15 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338
  1. package com.qmth.distributed.print.api;
  2. import cn.hutool.core.codec.Base64Encoder;
  3. import com.baomidou.mybatisplus.core.conditions.query.QueryWrapper;
  4. import com.qmth.boot.api.annotation.Aac;
  5. import com.qmth.boot.api.annotation.BOOL;
  6. import com.qmth.boot.api.constant.ApiConstant;
  7. import com.qmth.boot.api.exception.ApiException;
  8. import com.qmth.boot.core.enums.Platform;
  9. import com.qmth.boot.tools.signature.SignatureType;
  10. import com.qmth.distributed.print.business.bean.auth.AuthBean;
  11. import com.qmth.distributed.print.business.bean.auth.ExpireTimeBean;
  12. import com.qmth.distributed.print.business.bean.dto.MenuDto;
  13. import com.qmth.distributed.print.business.bean.params.LoginParam;
  14. import com.qmth.distributed.print.business.bean.result.EditResult;
  15. import com.qmth.distributed.print.business.bean.result.LoginResult;
  16. import com.qmth.distributed.print.business.config.DictionaryConfig;
  17. import com.qmth.distributed.print.business.entity.*;
  18. import com.qmth.distributed.print.business.enums.DownloadFileEnum;
  19. import com.qmth.distributed.print.business.enums.RoleTypeEnum;
  20. import com.qmth.distributed.print.business.enums.UploadFileEnum;
  21. import com.qmth.distributed.print.business.service.*;
  22. import com.qmth.distributed.print.business.util.AuthUtil;
  23. import com.qmth.distributed.print.business.util.RedisUtil;
  24. import com.qmth.distributed.print.business.util.ServletUtil;
  25. import com.qmth.distributed.print.business.util.security.Md5Utils;
  26. import com.qmth.distributed.print.common.SignatureEntityTest;
  27. import com.qmth.distributed.print.common.contant.SystemConstant;
  28. import com.qmth.distributed.print.common.enums.ExceptionResultEnum;
  29. import com.qmth.distributed.print.common.util.Result;
  30. import com.qmth.distributed.print.common.util.ResultUtil;
  31. import com.qmth.distributed.print.common.util.SessionUtil;
  32. import io.swagger.annotations.*;
  33. import org.slf4j.Logger;
  34. import org.slf4j.LoggerFactory;
  35. import org.springframework.beans.factory.annotation.Autowired;
  36. import org.springframework.transaction.annotation.Transactional;
  37. import org.springframework.validation.BindingResult;
  38. import org.springframework.web.bind.annotation.*;
  39. import org.springframework.web.multipart.MultipartFile;
  40. import sun.misc.BASE64Encoder;
  41. import javax.annotation.Resource;
  42. import javax.validation.Valid;
  43. import java.security.NoSuchAlgorithmException;
  44. import java.util.*;
  45. import java.util.stream.Collectors;
  46. /**
  47. * @Date: 2021/3/30.
  48. */
  49. @Api(tags = "系统Controller")
  50. @RestController
  51. @RequestMapping(ApiConstant.DEFAULT_URI_PREFIX + "/${prefix.url.common}")
  52. @Aac(strict = BOOL.TRUE, platform = Platform.WEB)
  53. public class SysController {
  54. private final static Logger log = LoggerFactory.getLogger(SysController.class);
  55. @Autowired
  56. private SysUserService sysUserService;
  57. @Autowired
  58. private BasicVerifyCodeService basicVerifyCodeService;
  59. @Autowired
  60. private DictionaryConfig dictionaryConfig;
  61. @Resource
  62. CacheService cacheService;
  63. @Resource
  64. TBSessionService tbSessionService;
  65. @Resource
  66. RedisUtil redisUtil;
  67. @Resource
  68. CommonService commonService;
  69. @Resource
  70. TBTaskService tbTaskService;
  71. @Resource
  72. BasicAttachmentService basicAttachmentService;
  73. @Autowired
  74. private SysConfigService sysConfigService;
  75. @Autowired
  76. private SysUserRoleService sysUserRoleService;
  77. /**
  78. * 登录
  79. *
  80. * @param login
  81. * @return
  82. */
  83. @ApiOperation(value = "登录")
  84. @RequestMapping(value = "/login", method = RequestMethod.POST)
  85. @ApiResponses({@ApiResponse(code = 200, message = "用户信息", response = LoginResult.class)})
  86. @Aac(auth = BOOL.FALSE)
  87. public Result login(@ApiParam(value = "用户信息", required = true) @Valid @RequestBody LoginParam login, BindingResult bindingResult) throws NoSuchAlgorithmException {
  88. if (bindingResult.hasErrors()) {
  89. return ResultUtil.error(bindingResult.getAllErrors().get(0).getDefaultMessage());
  90. }
  91. BasicSchool basicSchool = null;
  92. if (!Objects.equals(login.getSchoolCode().toUpperCase(), RoleTypeEnum.ADMIN.name())) {
  93. basicSchool = cacheService.schoolCache(login.getSchoolCode());
  94. if (Objects.isNull(basicSchool)) {
  95. throw ExceptionResultEnum.SCHOOL_NO_DATA.exception();
  96. }
  97. if (Objects.nonNull(basicSchool.getEnable()) && !basicSchool.getEnable()) {
  98. throw ExceptionResultEnum.SCHOOL_ENABLE.exception();
  99. }
  100. }
  101. QueryWrapper<SysUser> wrapper = new QueryWrapper<>();
  102. wrapper.lambda().eq(SysUser::getLoginName, login.getLoginName());
  103. if (!Objects.equals(login.getSchoolCode().toUpperCase(), RoleTypeEnum.ADMIN.name())) {
  104. wrapper.lambda().eq(SysUser::getSchoolId, basicSchool.getId());
  105. }
  106. List<SysUser> userList = sysUserService.list(wrapper);
  107. //用户不存在
  108. if (Objects.isNull(userList) || userList.size() == 0) {
  109. throw ExceptionResultEnum.USER_NO_DATA.exception();
  110. }
  111. if (Objects.equals(login.getSchoolCode().toUpperCase(), RoleTypeEnum.ADMIN.name())) {
  112. userList.forEach(o -> {
  113. AuthBean authBean = commonService.getUserAuth(o.getId());
  114. if (Objects.nonNull(authBean) && Objects.nonNull(authBean.getRoleList()) && authBean.getRoleList().size() > 0) {
  115. Set<RoleTypeEnum> roleType = authBean.getRoleList().stream().map(s -> s.getType()).collect(Collectors.toSet());
  116. if (!roleType.contains(RoleTypeEnum.ADMIN) && !roleType.contains(RoleTypeEnum.CUSTOMER)) {
  117. throw ExceptionResultEnum.ERROR.exception("学校代码为admin只允许超级管理员登录");
  118. }
  119. }
  120. });
  121. }
  122. if (userList.size() > 1) {
  123. throw ExceptionResultEnum.ERROR.exception("查询的用户有多条");
  124. }
  125. SysUser sysUser = userList.get(0);
  126. if (Objects.nonNull(sysUser.getSchoolId()) && sysUser.getSchoolId().longValue() != basicSchool.getId().longValue()) {
  127. throw ExceptionResultEnum.ERROR.exception("用户学校不匹配");
  128. }
  129. //密码不正确
  130. if (!Objects.equals(login.getPassword(), sysUser.getPassword())) {
  131. throw ExceptionResultEnum.PASSWORD_ERROR.exception();
  132. }
  133. //停用
  134. if (!sysUser.getEnable()) {
  135. throw ExceptionResultEnum.USER_ENABLE.exception();
  136. }
  137. // 校验验证码
  138. SysConfig value = sysConfigService.getByKey("sys.code.enable");
  139. if (Objects.nonNull(value) && value.getConfigValue().equals("true")) {
  140. String code = login.getCode();
  141. if (Objects.isNull(code)) {
  142. throw ExceptionResultEnum.ERROR.exception("验证码为空");
  143. }
  144. if (!dictionaryConfig.smsDomain().getSmsNormalCode().equals(code)) {
  145. QueryWrapper<BasicVerifyCode> codeWrapper = new QueryWrapper<>();
  146. codeWrapper.lambda().eq(BasicVerifyCode::getMobileNumber, sysUser.getMobileNumber()).eq(BasicVerifyCode::getUserId, sysUser.getId());
  147. BasicVerifyCode accessControl = basicVerifyCodeService.getOne(codeWrapper);
  148. if (accessControl == null || (accessControl != null && !accessControl.getVerifyCode().equals(code))) {
  149. throw ExceptionResultEnum.ERROR.exception("短信验证码错误,请仔细核对后再次输入");
  150. }
  151. if (new Date(accessControl.getExpireTime()).before(new Date())) {
  152. throw ExceptionResultEnum.ERROR.exception("短信验证码已过期");
  153. }
  154. }
  155. }
  156. Platform platform = ServletUtil.getRequestPlatform();
  157. String deviceId = ServletUtil.getRequestDeviceId();
  158. //添加用户鉴权缓存
  159. AuthBean authBean = cacheService.userAuthCache(sysUser.getId());
  160. if (Objects.isNull(authBean)) {
  161. throw ExceptionResultEnum.ROLE_ENABLE_AUTHORIZATION.exception();
  162. }
  163. //生成token
  164. String token = SystemConstant.getUuid();
  165. cacheService.userCache(sysUser.getId());
  166. //添加用户会话缓存
  167. Set<RoleTypeEnum> roleType = authBean.getRoleList().stream().map(s -> s.getType()).collect(Collectors.toSet());
  168. String sessionId = SessionUtil.digest(sysUser.getId(), Math.abs(roleType.toString().hashCode()), platform.name());
  169. //TODO 测试用
  170. String test = SignatureEntityTest.build(SignatureType.TOKEN, sessionId, token);
  171. ExpireTimeBean expireTime = AuthUtil.getExpireTime(platform);
  172. TBSession tbSession = new TBSession(sessionId, String.valueOf(sysUser.getId()), roleType.toString(),
  173. platform.name(), platform.name(), deviceId, ServletUtil.getRequest().getLocalAddr(), token,
  174. expireTime.getDate().getTime());
  175. tbSessionService.saveOrUpdate(tbSession);
  176. redisUtil.setUserSession(sessionId, tbSession, expireTime.getExpireSeconds());
  177. LoginResult loginResult = new LoginResult(sysUser, sessionId, test, roleType);
  178. loginResult.setSchoolInfo(Objects.nonNull(authBean.getSchool()) ? loginResult.new SchoolNativeBean(authBean.getSchool()) : null);
  179. loginResult.setOrgInfo(Objects.nonNull(authBean.getOrg()) ? loginResult.new OrgNativeBean(authBean.getOrg()) : null);
  180. return ResultUtil.ok(loginResult);
  181. }
  182. /**
  183. * 登出
  184. *
  185. * @return
  186. */
  187. @ApiOperation(value = "登出")
  188. @RequestMapping(value = "/logout", method = RequestMethod.POST)
  189. @ApiResponses({@ApiResponse(code = 200, message = "返回信息", response = EditResult.class)})
  190. public Result logout() {
  191. SysUser sysUser = (SysUser) ServletUtil.getRequestUser();
  192. TBSession tbSession = (TBSession) ServletUtil.getRequestSession();
  193. AuthBean authBean = cacheService.userAuthCache(sysUser.getId());
  194. if (Objects.isNull(authBean)) {
  195. throw ExceptionResultEnum.NOT_LOGIN.exception();
  196. }
  197. tbSessionService.removeById(tbSession.getId());
  198. redisUtil.deleteUserSession(tbSession.getId());
  199. cacheService.removeUserCache(sysUser.getId());
  200. cacheService.removeUserAuthCache(sysUser.getId());
  201. return ResultUtil.ok(new EditResult(sysUser.getId()));
  202. }
  203. /**
  204. * 发送验证码
  205. *
  206. * @param loginParam
  207. * @return
  208. */
  209. @ApiOperation(value = "发送验证码")
  210. @RequestMapping(value = "/getVerifyCode", method = RequestMethod.POST)
  211. public Object getverifyCode(@RequestBody LoginParam loginParam) {
  212. String loginName = loginParam.getLoginName();
  213. QueryWrapper<SysUser> wrapper = new QueryWrapper<>();
  214. wrapper.lambda().eq(SysUser::getLoginName, loginName);
  215. SysUser user = sysUserService.getOne(wrapper);
  216. //用户不存在
  217. if (Objects.isNull(user)) {
  218. throw ExceptionResultEnum.ERROR.exception("用户不存在");
  219. }
  220. String password = Md5Utils.toMd5Hex(loginParam.getPassword());
  221. if (password.equals(user.getPassword())) {
  222. throw ExceptionResultEnum.ERROR.exception("密码错误");
  223. }
  224. String mobileNumber = user.getMobileNumber();
  225. if (Objects.isNull(mobileNumber)) {
  226. throw ExceptionResultEnum.ERROR.exception("用户未绑定手机号码");
  227. }
  228. basicVerifyCodeService.sendVeirfyCode(mobileNumber, user.getId());
  229. return ResultUtil.ok(true);
  230. }
  231. @ApiOperation(value = "根据机构代码查询机构信息接口")
  232. @RequestMapping(value = "/school/query_by_school_code", method = RequestMethod.POST)
  233. @ApiResponses({@ApiResponse(code = 200, message = "学校信息", response = EditResult.class)})
  234. @Aac(auth = BOOL.FALSE)
  235. public Result queryBySchoolCode(@ApiParam(value = "机构code", required = true) @RequestParam String code) {
  236. if (!Objects.equals(code.toUpperCase(), RoleTypeEnum.ADMIN.name())) {
  237. BasicSchool basicSchool = cacheService.schoolCache(code);
  238. if (Objects.isNull(basicSchool)) {
  239. throw ExceptionResultEnum.SCHOOL_NO_DATA.exception();
  240. }
  241. return ResultUtil.ok(Collections.singletonMap(SystemConstant.LOGO, basicSchool.getLogo()));
  242. } else {
  243. return ResultUtil.ok(Collections.singletonMap(SystemConstant.LOGO, dictionaryConfig.sysDomain().getAdminLogoUrl()));
  244. }
  245. }
  246. @ApiOperation(value = "文件上传接口")
  247. @RequestMapping(value = "/file/upload", method = RequestMethod.POST)
  248. @Transactional
  249. @ApiResponses({@ApiResponse(code = 200, message = "返回信息", response = EditResult.class)})
  250. public Result fileUpload(@ApiParam(value = "上传文件", required = true) @RequestParam MultipartFile file,
  251. @ApiParam(value = "上传文件类型", required = true) @RequestParam UploadFileEnum type) {
  252. BasicAttachment basicAttachment = null;
  253. try {
  254. basicAttachment = basicAttachmentService.saveAttachment(file, ServletUtil.getRequestMd5(), type);
  255. if (Objects.isNull(basicAttachment)) {
  256. throw ExceptionResultEnum.ATTACHMENT_ERROR.exception();
  257. }
  258. } catch (Exception e) {
  259. log.error("请求出错", e);
  260. if (Objects.nonNull(basicAttachment)) {
  261. basicAttachmentService.deleteAttachment(basicAttachment);
  262. }
  263. if (e instanceof ApiException) {
  264. ResultUtil.error((ApiException) e, e.getMessage());
  265. } else {
  266. ResultUtil.error(e.getMessage());
  267. }
  268. }
  269. return ResultUtil.ok(new EditResult(basicAttachment.getId(), commonService.filePreview(basicAttachment.getPath()), basicAttachment.getPages()));
  270. }
  271. @ApiOperation(value = "文件下载接口")
  272. @RequestMapping(value = "/file/download", method = RequestMethod.POST)
  273. @ApiResponses({@ApiResponse(code = 200, message = "返回信息", response = EditResult.class)})
  274. public Result fileDownload(@ApiParam(value = "任务id", required = true) @RequestParam String id,
  275. @ApiParam(value = "下载文件类型", required = true) @RequestParam DownloadFileEnum type) {
  276. TBTask tbTask = tbTaskService.getById(Long.parseLong(id));
  277. if (Objects.isNull(tbTask)) {
  278. throw ExceptionResultEnum.TASK_NO_DATA.exception();
  279. }
  280. String path = null;
  281. switch (type.ordinal()) {
  282. case 0:
  283. path = tbTask.getImportFilePath();
  284. break;
  285. case 1:
  286. path = tbTask.getReportFilePath();
  287. break;
  288. default:
  289. path = tbTask.getResultFilePath();
  290. break;
  291. }
  292. if (Objects.isNull(path)) {
  293. throw ExceptionResultEnum.PATH_NO_DATA.exception();
  294. }
  295. return ResultUtil.ok(new EditResult(commonService.filePreview(path)));
  296. }
  297. @ApiOperation(value = "文件预览接口")
  298. @RequestMapping(value = "/file/preview", method = RequestMethod.POST)
  299. @ApiResponses({@ApiResponse(code = 200, message = "返回信息", response = EditResult.class)})
  300. public Result filePreview(@ApiParam(value = "附件id", required = true) @RequestParam String id) {
  301. BasicAttachment basicAttachment = basicAttachmentService.getById(Long.parseLong(id));
  302. return ResultUtil.ok(new EditResult(commonService.filePreview(basicAttachment.getPath())));
  303. }
  304. @ApiOperation(value = "查询用户权限")
  305. @RequestMapping(value = "/get_menu", method = RequestMethod.POST)
  306. public Result getMenu() {
  307. List<MenuDto> list = sysUserRoleService.listByUserId();
  308. return ResultUtil.ok(list);
  309. }
  310. }