User.php 14 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467
  1. <?php
  2. declare (strict_types = 1);
  3. namespace app\controller;
  4. use app\BaseController;
  5. use think\facade\Cookie;
  6. use think\facade\Request;
  7. use think\facade\Config;
  8. use app\model\UserModel;
  9. use app\model\UserRoleModel;
  10. use app\validate\UserValidate;
  11. use app\service\IpWhiteListService;
  12. class User extends BaseController
  13. {
  14. protected $message = [
  15. 'logout' => '退出成功',
  16. 'login' => '登录成功',
  17. 'error' => '账号或密码错误',
  18. 'param' => '参数错误',
  19. 'duplicate' => '用户账号已存在',
  20. 'create_suc' => '创建用户成功',
  21. 'empty' => '用户不存在',
  22. 'suc' => '操作成功',
  23. 'res' => '获取成功',
  24. 'ip_denied' => 'IP地址不在白名单中,禁止登录'
  25. ];
  26. /**
  27. * 登录
  28. */
  29. public function login()
  30. {
  31. // 获取输入数据
  32. $userName = trim(Request::post('user_name'));
  33. $password = trim(Request::post('password'));
  34. // 验证输入数据
  35. $checkMessage = $this->validateInput([
  36. 'user_name' => $userName,
  37. 'password' => $password,
  38. ], 'login');
  39. if(!empty($checkMessage)) {
  40. return json_error([], $checkMessage);
  41. }
  42. // 查询用户
  43. $user = UserModel::where('user_name', $userName)->find();
  44. if ($user && password_verify($password, $user->password)) {
  45. // 检查IP白名单
  46. $clientIp = IpWhiteListService::getRealIp();
  47. if (!IpWhiteListService::checkIpWhiteList($clientIp, $user->white_list_ip)) {
  48. // 记录IP限制登录日志
  49. trace("用户 {$userName} 尝试从IP {$clientIp} 登录,但不在白名单 {$user->white_list_ip} 中", 'info');
  50. return json_error([
  51. 'client_ip' => $clientIp,
  52. 'white_list_ip' => $user->white_list_ip
  53. ], $this->message['ip_denied']);
  54. }
  55. $token = generateToken([
  56. 'user_id' => $user->user_id,
  57. 'merchant_id' => $user->merchant_id,
  58. 'user_role' => $user->user_role
  59. ]);
  60. Cookie::set('auth_token', $token, ['expire' => $GLOBALS['cookieExpire'], 'httponly' => true]);
  61. // 更新登录时间
  62. $user->login_time = time();
  63. $user->save();
  64. // 记录成功登录日志
  65. trace("用户 {$userName} 从IP {$clientIp} 登录成功", 'info');
  66. return json_success([
  67. 'user_name' => $user->user_name,
  68. 'nick_name' => $user->nick_name,
  69. 'user_role' => $user->user_role,
  70. 'login_time' => $user->login_time,
  71. 'token' => $token,
  72. 'client_ip' => $clientIp
  73. ], $this->message['login']);
  74. } else {
  75. return json_error([], $this->message['error']);
  76. }
  77. }
  78. /**
  79. * 用户注销
  80. */
  81. public function logout()
  82. {
  83. Cookie::delete('auth_token');
  84. return json_success([], '退出成功');
  85. }
  86. /**
  87. * 创建用户
  88. */
  89. public function createUser()
  90. {
  91. // 获取当前登录用户信息
  92. $loginInfo = checkUserLogin();
  93. if (!$loginInfo) {
  94. return json_error([], '请先登录');
  95. }
  96. // 检查是否有创建用户权限
  97. if (!checkPermission($loginInfo, 'user', 'create')) {
  98. return json_error([], '没有创建用户的权限');
  99. }
  100. // 获取输入数据
  101. $data = Request::only([
  102. 'user_name', 'nick_name', 'password', 'phone',
  103. 'user_role', 'white_list_ip'
  104. ]);
  105. $data['merchant_id'] = $loginInfo['merchant_id'];
  106. try {
  107. // 验证数据
  108. $this->validate($data, UserValidate::class . '.create');
  109. } catch (\think\exception\ValidateException $e) {
  110. return json_error($e->getError());
  111. }
  112. // 验证角色是否存在
  113. if ($data['user_role'] > 0) {
  114. $role = UserRoleModel::getRoleById($data['user_role'], $loginInfo['merchant_id']);
  115. if (!$role) {
  116. return json_error([], '选择的角色不存在');
  117. }
  118. }
  119. // 检查用户名是否已存在
  120. if (UserModel::where('user_name', $data['user_name'])->find()) {
  121. return json_error($this->message['duplicate']);
  122. }
  123. // 创建新用户
  124. $data['password'] = password_hash($data['password'], PASSWORD_DEFAULT);
  125. try {
  126. $user = UserModel::create($data);
  127. return json_success(['user_id' => $user->user_id], $this->message['create_suc']);
  128. } catch (\Exception $e) {
  129. return json_error([], '创建用户失败:' . $e->getMessage());
  130. }
  131. }
  132. /**
  133. * 获取用户列表
  134. */
  135. public function list()
  136. {
  137. $loginInfo = checkUserLogin();
  138. if (!$loginInfo) {
  139. return json_error([], '请先登录');
  140. }
  141. if (!checkPermission($loginInfo, 'user', 'list')) {
  142. return json_error([], '没有查看用户列表的权限');
  143. }
  144. $page = Request::get('page', 1, 'intval');
  145. $limit = Request::get('limit', 10, 'intval');
  146. $userName = Request::get('user_name', '', 'trim');
  147. $nickName = Request::get('nick_name', '', 'trim');
  148. $userRole = Request::get('user_role', 0, 'intval');
  149. $where = [
  150. ['merchant_id', '=', $loginInfo['merchant_id']]
  151. ];
  152. if ($userName) {
  153. $where[] = ['user_name', 'like', '%' . $userName . '%'];
  154. }
  155. if ($nickName) {
  156. $where[] = ['nick_name', 'like', '%' . $nickName . '%'];
  157. }
  158. if ($userRole > 0) {
  159. $where[] = ['user_role', '=', $userRole];
  160. }
  161. $total = UserModel::where($where)->count();
  162. $list = UserModel::where($where)
  163. ->field('user_id, user_name, nick_name, phone, user_role, merchant_id, white_list_ip, create_time, login_time, update_time')
  164. ->order('user_id', 'desc')
  165. ->page($page, $limit)
  166. ->select();
  167. // 获取角色信息
  168. $roleIds = array_unique(array_column($list->toArray(), 'user_role'));
  169. $roles = [];
  170. if ($roleIds) {
  171. $roleList = UserRoleModel::whereIn('id', $roleIds)->select();
  172. foreach ($roleList as $role) {
  173. $roles[$role->id] = $role->role_name;
  174. }
  175. }
  176. // 添加角色名称
  177. foreach ($list as $user) {
  178. $user->role_name = $roles[$user->user_role] ?? '未分配角色';
  179. }
  180. return json_success([
  181. 'list' => $list,
  182. 'total' => $total,
  183. 'page' => $page,
  184. 'limit' => $limit
  185. ]);
  186. }
  187. /**
  188. * 获取用户详情
  189. */
  190. public function detail()
  191. {
  192. $loginInfo = checkUserLogin();
  193. if (!$loginInfo) {
  194. return json_error([], '请先登录');
  195. }
  196. if (!checkPermission($loginInfo, 'user', 'detail')) {
  197. return json_error([], '没有查看用户详情的权限');
  198. }
  199. $userId = Request::param('user_id', 0, 'intval');
  200. if (!$userId) {
  201. return json_error([], '用户ID不能为空');
  202. }
  203. $user = UserModel::where('user_id', $userId)
  204. ->where('merchant_id', $loginInfo['merchant_id'])
  205. ->field('user_id, user_name, nick_name, phone, user_role, merchant_id, white_list_ip, create_time, login_time, update_time')
  206. ->find();
  207. if (!$user) {
  208. return json_error($this->message['empty']);
  209. }
  210. // 获取角色信息
  211. if ($user->user_role > 0) {
  212. $role = UserRoleModel::getRoleById($user->user_role, $loginInfo['merchant_id']);
  213. $user->role_name = $role ? $role->role_name : '未分配角色';
  214. $user->role_privileges = $role ? $role->privileges : [];
  215. } else {
  216. $user->role_name = '未分配角色';
  217. $user->role_privileges = [];
  218. }
  219. return json_success($user);
  220. }
  221. /**
  222. * 更新用户
  223. */
  224. public function update()
  225. {
  226. $loginInfo = checkUserLogin();
  227. if (!$loginInfo) {
  228. return json_error([], '请先登录');
  229. }
  230. if (!checkPermission($loginInfo, 'user', 'update')) {
  231. return json_error([], '没有编辑用户的权限');
  232. }
  233. $userId = Request::post('user_id', 0, 'intval');
  234. if (!$userId) {
  235. return json_error([], '用户ID不能为空');
  236. }
  237. $user = UserModel::where('user_id', $userId)
  238. ->where('merchant_id', $loginInfo['merchant_id'])
  239. ->find();
  240. if (!$user) {
  241. return json_error($this->message['empty']);
  242. }
  243. // 获取更新数据
  244. $data = Request::only([
  245. 'nick_name', 'phone', 'password', 'user_role', 'white_list_ip'
  246. ]);
  247. // 过滤空值
  248. $data = array_filter($data, function($value, $key) {
  249. return $key !== 'password' || !empty($value);
  250. }, ARRAY_FILTER_USE_BOTH);
  251. if (empty($data)) {
  252. return json_error([], '没有要更新的数据');
  253. }
  254. // 验证角色是否存在
  255. if (isset($data['user_role']) && $data['user_role'] > 0) {
  256. $role = UserRoleModel::getRoleById($data['user_role'], $loginInfo['merchant_id']);
  257. if (!$role) {
  258. return json_error([], '选择的角色不存在');
  259. }
  260. }
  261. // 密码加密
  262. if (isset($data['password'])) {
  263. $data['password'] = password_hash($data['password'], PASSWORD_DEFAULT);
  264. }
  265. try {
  266. $user->save($data);
  267. return json_success([], $this->message['suc']);
  268. } catch (\Exception $e) {
  269. return json_error([], '更新失败:' . $e->getMessage());
  270. }
  271. }
  272. /**
  273. * 删除用户
  274. */
  275. public function delete()
  276. {
  277. $loginInfo = checkUserLogin();
  278. if (!$loginInfo) {
  279. return json_error([], '请先登录');
  280. }
  281. if (!checkPermission($loginInfo, 'user', 'delete')) {
  282. return json_error([], '没有删除用户的权限');
  283. }
  284. $userId = Request::post('user_id', 0, 'intval');
  285. if (!$userId) {
  286. return json_error([], '用户ID不能为空');
  287. }
  288. if ($userId == $loginInfo['user_id']) {
  289. return json_error([], '不能删除自己');
  290. }
  291. $user = UserModel::where('user_id', $userId)
  292. ->where('merchant_id', $loginInfo['merchant_id'])
  293. ->find();
  294. if (!$user) {
  295. return json_error($this->message['empty']);
  296. }
  297. try {
  298. $user->delete();
  299. return json_success([], '删除成功');
  300. } catch (\Exception $e) {
  301. return json_error([], '删除失败:' . $e->getMessage());
  302. }
  303. }
  304. /**
  305. * 验证IP白名单格式
  306. */
  307. public function validateIpWhiteList()
  308. {
  309. $loginInfo = checkUserLogin();
  310. if (!$loginInfo) {
  311. return json_error([], '请先登录');
  312. }
  313. $whiteListIp = Request::post('white_list_ip', '', 'trim');
  314. try {
  315. list($isValid, $message, $parsedList) = IpWhiteListService::validateWhiteListFormat($whiteListIp);
  316. return json_success([
  317. 'valid' => $isValid,
  318. 'message' => $message,
  319. 'parsed_list' => $parsedList,
  320. 'current_ip' => IpWhiteListService::getRealIp()
  321. ], '验证完成');
  322. } catch (\Exception $e) {
  323. return json_error([], '验证失败:' . $e->getMessage());
  324. }
  325. }
  326. /**
  327. * 获取当前访问IP信息
  328. */
  329. public function getCurrentIp()
  330. {
  331. $loginInfo = checkUserLogin();
  332. if (!$loginInfo) {
  333. return json_error([], '请先登录');
  334. }
  335. try {
  336. $currentIp = IpWhiteListService::getRealIp();
  337. $ipInfo = IpWhiteListService::getIpInfo($currentIp);
  338. return json_success([
  339. 'current_ip' => $currentIp,
  340. 'ip_info' => $ipInfo,
  341. 'timestamp' => time(),
  342. 'datetime' => date('Y-m-d H:i:s')
  343. ], '获取当前IP成功');
  344. } catch (\Exception $e) {
  345. return json_error([], '获取IP信息失败:' . $e->getMessage());
  346. }
  347. }
  348. /**
  349. * 检查IP是否在用户白名单中
  350. */
  351. public function checkIpWhiteList()
  352. {
  353. $loginInfo = checkUserLogin();
  354. if (!$loginInfo) {
  355. return json_error([], '请先登录');
  356. }
  357. $userId = Request::get('user_id', $loginInfo['user_id'], 'intval');
  358. $testIp = Request::get('test_ip', '', 'trim');
  359. // 获取用户信息
  360. $user = UserModel::where('user_id', $userId)
  361. ->where('merchant_id', $loginInfo['merchant_id'])
  362. ->find();
  363. if (!$user) {
  364. return json_error([], '用户不存在');
  365. }
  366. $currentIp = IpWhiteListService::getRealIp();
  367. $checkIp = !empty($testIp) ? $testIp : $currentIp;
  368. try {
  369. $isAllowed = IpWhiteListService::checkIpWhiteList($checkIp, $user->white_list_ip);
  370. return json_success([
  371. 'user_id' => $userId,
  372. 'user_name' => $user->user_name,
  373. 'check_ip' => $checkIp,
  374. 'white_list_ip' => $user->white_list_ip,
  375. 'is_allowed' => $isAllowed,
  376. 'current_ip' => $currentIp,
  377. 'is_current_ip' => $checkIp === $currentIp
  378. ], $isAllowed ? 'IP在白名单中' : 'IP不在白名单中');
  379. } catch (\Exception $e) {
  380. return json_error([], '检查IP白名单失败:' . $e->getMessage());
  381. }
  382. }
  383. /**
  384. * 验证输入数据
  385. */
  386. protected function validateInput(array $data, $scene = '')
  387. {
  388. $validate = new UserValidate();
  389. // 执行场景验证
  390. if (!$validate->scene($scene)->check($data)) {
  391. return $validate->getError();
  392. }
  393. return "";
  394. }
  395. }