User.php 11 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358
  1. <?php
  2. declare (strict_types = 1);
  3. namespace app\controller;
  4. use app\BaseController;
  5. use think\facade\Cookie;
  6. use think\facade\Request;
  7. use think\facade\Config;
  8. use app\model\UserModel;
  9. use app\model\UserRoleModel;
  10. use app\validate\UserValidate;
  11. class User extends BaseController
  12. {
  13. protected $message = [
  14. 'logout' => '退出成功',
  15. 'login' => '登录成功',
  16. 'error' => '账号或密码错误',
  17. 'param' => '参数错误',
  18. 'duplicate' => '用户账号已存在',
  19. 'create_suc' => '创建用户成功',
  20. 'empty' => '用户不存在',
  21. 'suc' => '操作成功',
  22. 'res' => '获取成功'
  23. ];
  24. /**
  25. * 登录
  26. */
  27. public function login()
  28. {
  29. // 获取输入数据
  30. $userName = trim(Request::post('user_name'));
  31. $password = trim(Request::post('password'));
  32. // 验证输入数据
  33. $checkMessage = $this->validateInput([
  34. 'user_name' => $userName,
  35. 'password' => $password,
  36. ], 'login');
  37. if(!empty($checkMessage)) {
  38. return json_error([], $checkMessage);
  39. }
  40. // 查询用户
  41. $user = UserModel::where('user_name', $userName)->find();
  42. if ($user && password_verify($password, $user->password)) {
  43. $token = generateToken([
  44. 'user_id' => $user->user_id,
  45. 'merchant_id' => $user->merchant_id,
  46. 'user_role' => $user->user_role
  47. ]);
  48. Cookie::set('auth_token', $token, ['expire' => $GLOBALS['cookieExpire'], 'httponly' => true]);
  49. // 更新登录时间
  50. $user->login_time = time();
  51. $user->save();
  52. return json_success([
  53. 'user_name' => $user->user_name,
  54. 'nick_name' => $user->nick_name,
  55. 'user_role' => $user->user_role,
  56. 'login_time' => $user->login_time,
  57. 'token' => $token
  58. ], $this->message['login']);
  59. } else {
  60. return json_error([], $this->message['error']);
  61. }
  62. }
  63. /**
  64. * 用户注销
  65. */
  66. public function logout()
  67. {
  68. Cookie::delete('auth_token');
  69. return json_success([], '退出成功');
  70. }
  71. /**
  72. * 创建用户
  73. */
  74. public function createUser()
  75. {
  76. // 获取当前登录用户信息
  77. $loginInfo = checkUserLogin();
  78. if (!$loginInfo) {
  79. return json_error([], '请先登录');
  80. }
  81. // 检查是否有创建用户权限
  82. if (!checkPermission($loginInfo, 'user', 'create')) {
  83. return json_error([], '没有创建用户的权限');
  84. }
  85. // 获取输入数据
  86. $data = Request::only([
  87. 'user_name', 'nick_name', 'password', 'phone',
  88. 'user_role', 'white_list_ip'
  89. ]);
  90. $data['merchant_id'] = $loginInfo['merchant_id'];
  91. try {
  92. // 验证数据
  93. $this->validate($data, UserValidate::class . '.create');
  94. } catch (\think\exception\ValidateException $e) {
  95. return json_error($e->getError());
  96. }
  97. // 验证角色是否存在
  98. if ($data['user_role'] > 0) {
  99. $role = UserRoleModel::getRoleById($data['user_role'], $loginInfo['merchant_id']);
  100. if (!$role) {
  101. return json_error([], '选择的角色不存在');
  102. }
  103. }
  104. // 检查用户名是否已存在
  105. if (UserModel::where('user_name', $data['user_name'])->find()) {
  106. return json_error($this->message['duplicate']);
  107. }
  108. // 创建新用户
  109. $data['password'] = password_hash($data['password'], PASSWORD_DEFAULT);
  110. try {
  111. $user = UserModel::create($data);
  112. return json_success(['user_id' => $user->user_id], $this->message['create_suc']);
  113. } catch (\Exception $e) {
  114. return json_error([], '创建用户失败:' . $e->getMessage());
  115. }
  116. }
  117. /**
  118. * 获取用户列表
  119. */
  120. public function list()
  121. {
  122. $loginInfo = checkUserLogin();
  123. if (!$loginInfo) {
  124. return json_error([], '请先登录');
  125. }
  126. if (!checkPermission($loginInfo, 'user', 'list')) {
  127. return json_error([], '没有查看用户列表的权限');
  128. }
  129. $page = Request::get('page', 1, 'intval');
  130. $limit = Request::get('limit', 10, 'intval');
  131. $userName = Request::get('user_name', '', 'trim');
  132. $nickName = Request::get('nick_name', '', 'trim');
  133. $userRole = Request::get('user_role', 0, 'intval');
  134. $where = [
  135. ['merchant_id', '=', $loginInfo['merchant_id']]
  136. ];
  137. if ($userName) {
  138. $where[] = ['user_name', 'like', '%' . $userName . '%'];
  139. }
  140. if ($nickName) {
  141. $where[] = ['nick_name', 'like', '%' . $nickName . '%'];
  142. }
  143. if ($userRole > 0) {
  144. $where[] = ['user_role', '=', $userRole];
  145. }
  146. $total = UserModel::where($where)->count();
  147. $list = UserModel::where($where)
  148. ->field('user_id, user_name, nick_name, phone, user_role, merchant_id, white_list_ip, create_time, login_time, update_time')
  149. ->order('user_id', 'desc')
  150. ->page($page, $limit)
  151. ->select();
  152. // 获取角色信息
  153. $roleIds = array_unique(array_column($list->toArray(), 'user_role'));
  154. $roles = [];
  155. if ($roleIds) {
  156. $roleList = UserRoleModel::whereIn('id', $roleIds)->select();
  157. foreach ($roleList as $role) {
  158. $roles[$role->id] = $role->role_name;
  159. }
  160. }
  161. // 添加角色名称
  162. foreach ($list as $user) {
  163. $user->role_name = $roles[$user->user_role] ?? '未分配角色';
  164. }
  165. return json_success([
  166. 'list' => $list,
  167. 'total' => $total,
  168. 'page' => $page,
  169. 'limit' => $limit
  170. ]);
  171. }
  172. /**
  173. * 获取用户详情
  174. */
  175. public function detail()
  176. {
  177. $loginInfo = checkUserLogin();
  178. if (!$loginInfo) {
  179. return json_error([], '请先登录');
  180. }
  181. if (!checkPermission($loginInfo, 'user', 'detail')) {
  182. return json_error([], '没有查看用户详情的权限');
  183. }
  184. $userId = Request::param('user_id', 0, 'intval');
  185. if (!$userId) {
  186. return json_error([], '用户ID不能为空');
  187. }
  188. $user = UserModel::where('user_id', $userId)
  189. ->where('merchant_id', $loginInfo['merchant_id'])
  190. ->field('user_id, user_name, nick_name, phone, user_role, merchant_id, white_list_ip, create_time, login_time, update_time')
  191. ->find();
  192. if (!$user) {
  193. return json_error($this->message['empty']);
  194. }
  195. // 获取角色信息
  196. if ($user->user_role > 0) {
  197. $role = UserRoleModel::getRoleById($user->user_role, $loginInfo['merchant_id']);
  198. $user->role_name = $role ? $role->role_name : '未分配角色';
  199. $user->role_privileges = $role ? $role->privileges : [];
  200. } else {
  201. $user->role_name = '未分配角色';
  202. $user->role_privileges = [];
  203. }
  204. return json_success($user);
  205. }
  206. /**
  207. * 更新用户
  208. */
  209. public function update()
  210. {
  211. $loginInfo = checkUserLogin();
  212. if (!$loginInfo) {
  213. return json_error([], '请先登录');
  214. }
  215. if (!checkPermission($loginInfo, 'user', 'update')) {
  216. return json_error([], '没有编辑用户的权限');
  217. }
  218. $userId = Request::post('user_id', 0, 'intval');
  219. if (!$userId) {
  220. return json_error([], '用户ID不能为空');
  221. }
  222. $user = UserModel::where('user_id', $userId)
  223. ->where('merchant_id', $loginInfo['merchant_id'])
  224. ->find();
  225. if (!$user) {
  226. return json_error($this->message['empty']);
  227. }
  228. // 获取更新数据
  229. $data = Request::only([
  230. 'nick_name', 'phone', 'password', 'user_role', 'white_list_ip'
  231. ]);
  232. // 过滤空值
  233. $data = array_filter($data, function($value, $key) {
  234. return $key !== 'password' || !empty($value);
  235. }, ARRAY_FILTER_USE_BOTH);
  236. if (empty($data)) {
  237. return json_error([], '没有要更新的数据');
  238. }
  239. // 验证角色是否存在
  240. if (isset($data['user_role']) && $data['user_role'] > 0) {
  241. $role = UserRoleModel::getRoleById($data['user_role'], $loginInfo['merchant_id']);
  242. if (!$role) {
  243. return json_error([], '选择的角色不存在');
  244. }
  245. }
  246. // 密码加密
  247. if (isset($data['password'])) {
  248. $data['password'] = password_hash($data['password'], PASSWORD_DEFAULT);
  249. }
  250. try {
  251. $user->save($data);
  252. return json_success([], $this->message['suc']);
  253. } catch (\Exception $e) {
  254. return json_error([], '更新失败:' . $e->getMessage());
  255. }
  256. }
  257. /**
  258. * 删除用户
  259. */
  260. public function delete()
  261. {
  262. $loginInfo = checkUserLogin();
  263. if (!$loginInfo) {
  264. return json_error([], '请先登录');
  265. }
  266. if (!checkPermission($loginInfo, 'user', 'delete')) {
  267. return json_error([], '没有删除用户的权限');
  268. }
  269. $userId = Request::post('user_id', 0, 'intval');
  270. if (!$userId) {
  271. return json_error([], '用户ID不能为空');
  272. }
  273. if ($userId == $loginInfo['user_id']) {
  274. return json_error([], '不能删除自己');
  275. }
  276. $user = UserModel::where('user_id', $userId)
  277. ->where('merchant_id', $loginInfo['merchant_id'])
  278. ->find();
  279. if (!$user) {
  280. return json_error($this->message['empty']);
  281. }
  282. try {
  283. $user->delete();
  284. return json_success([], '删除成功');
  285. } catch (\Exception $e) {
  286. return json_error([], '删除失败:' . $e->getMessage());
  287. }
  288. }
  289. /**
  290. * 验证输入数据
  291. */
  292. protected function validateInput(array $data, $scene = '')
  293. {
  294. $validate = new UserValidate();
  295. // 执行场景验证
  296. if (!$validate->scene($scene)->check($data)) {
  297. return $validate->getError();
  298. }
  299. return "";
  300. }
  301. }