TokenController.java 8.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239
  1. package org.dromara.auth.controller;
  2. import cn.dev33.satoken.exception.NotLoginException;
  3. import cn.hutool.core.codec.Base64;
  4. import cn.hutool.core.collection.CollUtil;
  5. import cn.hutool.core.util.ObjectUtil;
  6. import jakarta.servlet.http.HttpServletRequest;
  7. import lombok.RequiredArgsConstructor;
  8. import lombok.extern.slf4j.Slf4j;
  9. import me.zhyd.oauth.model.AuthResponse;
  10. import me.zhyd.oauth.model.AuthUser;
  11. import me.zhyd.oauth.request.AuthRequest;
  12. import me.zhyd.oauth.utils.AuthStateUtils;
  13. import org.apache.dubbo.config.annotation.DubboReference;
  14. import org.dromara.auth.domain.vo.LoginTenantVo;
  15. import org.dromara.auth.domain.vo.LoginVo;
  16. import org.dromara.auth.domain.vo.TenantListVo;
  17. import org.dromara.auth.form.RegisterBody;
  18. import org.dromara.auth.form.SocialLoginBody;
  19. import org.dromara.auth.service.IAuthStrategy;
  20. import org.dromara.auth.service.SysLoginService;
  21. import org.dromara.common.core.constant.SystemConstants;
  22. import org.dromara.common.core.domain.R;
  23. import org.dromara.common.core.domain.model.LoginBody;
  24. import org.dromara.common.core.utils.*;
  25. import org.dromara.common.encrypt.annotation.ApiEncrypt;
  26. import org.dromara.common.json.utils.JsonUtils;
  27. import org.dromara.common.ratelimiter.annotation.RateLimiter;
  28. import org.dromara.common.ratelimiter.enums.LimitType;
  29. import org.dromara.common.satoken.utils.LoginHelper;
  30. import org.dromara.common.social.config.properties.SocialLoginConfigProperties;
  31. import org.dromara.common.social.config.properties.SocialProperties;
  32. import org.dromara.common.social.utils.SocialUtils;
  33. import org.dromara.common.tenant.helper.TenantHelper;
  34. import org.dromara.resource.api.RemoteMessageService;
  35. import org.dromara.system.api.RemoteClientService;
  36. import org.dromara.system.api.RemoteConfigService;
  37. import org.dromara.system.api.RemoteSocialService;
  38. import org.dromara.system.api.RemoteTenantService;
  39. import org.dromara.system.api.domain.vo.RemoteClientVo;
  40. import org.dromara.system.api.domain.vo.RemoteTenantVo;
  41. import org.springframework.web.bind.annotation.*;
  42. import java.net.URL;
  43. import java.nio.charset.StandardCharsets;
  44. import java.util.Date;
  45. import java.util.HashMap;
  46. import java.util.List;
  47. import java.util.Map;
  48. import java.util.concurrent.ScheduledExecutorService;
  49. import java.util.concurrent.TimeUnit;
  50. /**
  51. * token 控制
  52. *
  53. * @author Lion Li
  54. */
  55. @Slf4j
  56. @RequiredArgsConstructor
  57. @RestController
  58. public class TokenController {
  59. private final SocialProperties socialProperties;
  60. private final SysLoginService sysLoginService;
  61. private final ScheduledExecutorService scheduledExecutorService;
  62. @DubboReference
  63. private final RemoteConfigService remoteConfigService;
  64. @DubboReference
  65. private final RemoteTenantService remoteTenantService;
  66. @DubboReference
  67. private final RemoteClientService remoteClientService;
  68. @DubboReference
  69. private final RemoteSocialService remoteSocialService;
  70. @DubboReference(stub = "true")
  71. private final RemoteMessageService remoteMessageService;
  72. /**
  73. * 登录方法
  74. *
  75. * @param body 登录信息
  76. * @return 结果
  77. */
  78. /**
  79. * FIXME 修改不通过租户进行隔离
  80. * @Author: Huanyi
  81. */
  82. @ApiEncrypt
  83. @PostMapping("/login")
  84. public R<LoginVo> login(@RequestBody String body) {
  85. LoginBody loginBody = JsonUtils.parseObject(body, LoginBody.class);
  86. ValidatorUtils.validate(loginBody);
  87. // 授权类型和客户端id
  88. String clientId = loginBody.getClientId();
  89. String grantType = loginBody.getGrantType();
  90. RemoteClientVo clientVo = remoteClientService.queryByClientId(clientId);
  91. // 查询不到 client 或 client 内不包含 grantType
  92. if (ObjectUtil.isNull(clientVo) || !StringUtils.contains(clientVo.getGrantType(), grantType)) {
  93. log.info("客户端id: {} 认证类型:{} 异常!.", clientId, grantType);
  94. return R.fail(MessageUtils.message("auth.grant.type.error"));
  95. } else if (!SystemConstants.NORMAL.equals(clientVo.getStatus())) {
  96. return R.fail(MessageUtils.message("auth.grant.type.blocked"));
  97. }
  98. // 校验租户
  99. sysLoginService.checkTenant(loginBody.getTenantId());
  100. // 登录
  101. LoginVo loginVo = IAuthStrategy.login(body, clientVo, grantType);
  102. Long userId = LoginHelper.getUserId();
  103. scheduledExecutorService.schedule(() -> {
  104. remoteMessageService.publishMessage(List.of(userId), DateUtils.getTodayHour(new Date()) + "好,欢迎登录 一站护萌 后台管理系统");
  105. }, 5, TimeUnit.SECONDS);
  106. return R.ok(loginVo);
  107. }
  108. /**
  109. * 第三方登录请求
  110. *
  111. * @param source 登录来源
  112. * @return 结果
  113. */
  114. @GetMapping("/binding/{source}")
  115. public R<String> authBinding(@PathVariable("source") String source,
  116. @RequestParam String tenantId, @RequestParam String domain) {
  117. SocialLoginConfigProperties obj = socialProperties.getType().get(source);
  118. if (ObjectUtil.isNull(obj)) {
  119. return R.fail(source + "平台账号暂不支持");
  120. }
  121. AuthRequest authRequest = SocialUtils.getAuthRequest(source, socialProperties);
  122. Map<String, String> map = new HashMap<>();
  123. map.put("tenantId", tenantId);
  124. map.put("domain", domain);
  125. map.put("state", AuthStateUtils.createState());
  126. String authorizeUrl = authRequest.authorize(Base64.encode(JsonUtils.toJsonString(map), StandardCharsets.UTF_8));
  127. return R.ok("操作成功", authorizeUrl);
  128. }
  129. /**
  130. * 第三方登录回调业务处理 绑定授权
  131. *
  132. * @param loginBody 请求体
  133. * @return 结果
  134. */
  135. @PostMapping("/social/callback")
  136. public R<Void> socialCallback(@RequestBody SocialLoginBody loginBody) {
  137. // 获取第三方登录信息
  138. AuthResponse<AuthUser> response = SocialUtils.loginAuth(
  139. loginBody.getSource(), loginBody.getSocialCode(),
  140. loginBody.getSocialState(), socialProperties);
  141. AuthUser authUserData = response.getData();
  142. // 判断授权响应是否成功
  143. if (!response.ok()) {
  144. return R.fail(response.getMsg());
  145. }
  146. sysLoginService.socialRegister(authUserData);
  147. return R.ok();
  148. }
  149. /**
  150. * 取消授权
  151. *
  152. * @param socialId socialId
  153. */
  154. @DeleteMapping(value = "/unlock/{socialId}")
  155. public R<Void> unlockSocial(@PathVariable Long socialId) {
  156. Boolean rows = remoteSocialService.deleteWithValidById(socialId);
  157. return rows ? R.ok() : R.fail("取消授权失败");
  158. }
  159. /**
  160. * 登出方法
  161. */
  162. @PostMapping("logout")
  163. public R<Void> logout() {
  164. sysLoginService.logout();
  165. return R.ok();
  166. }
  167. /**
  168. * 用户注册
  169. */
  170. @ApiEncrypt
  171. @PostMapping("register")
  172. public R<Void> register(@RequestBody RegisterBody registerBody) {
  173. if (!remoteConfigService.selectRegisterEnabled(registerBody.getTenantId())) {
  174. return R.fail("当前系统没有开启注册功能!");
  175. }
  176. // 用户注册
  177. sysLoginService.register(registerBody);
  178. return R.ok();
  179. }
  180. /**
  181. * 登录页面租户下拉框
  182. *
  183. * @return 租户列表
  184. */
  185. @RateLimiter(time = 60, count = 20, limitType = LimitType.IP)
  186. @GetMapping("/tenant/list")
  187. public R<LoginTenantVo> tenantList(HttpServletRequest request) throws Exception {
  188. // 返回对象
  189. LoginTenantVo result = new LoginTenantVo();
  190. boolean enable = TenantHelper.isEnable();
  191. result.setTenantEnabled(enable);
  192. // 如果未开启租户这直接返回
  193. if (!enable) {
  194. return R.ok(result);
  195. }
  196. List<RemoteTenantVo> tenantList = remoteTenantService.queryList();
  197. List<TenantListVo> voList = MapstructUtils.convert(tenantList, TenantListVo.class);
  198. try {
  199. // 如果只超管返回所有租户
  200. if (LoginHelper.isSuperAdmin()) {
  201. result.setVoList(voList);
  202. return R.ok(result);
  203. }
  204. } catch (NotLoginException ignored) {
  205. }
  206. // 获取域名
  207. String host;
  208. String referer = request.getHeader("referer");
  209. if (StringUtils.isNotBlank(referer)) {
  210. // 这里从referer中取值是为了本地使用hosts添加虚拟域名,方便本地环境调试
  211. host = referer.split("//")[1].split("/")[0];
  212. } else {
  213. host = new URL(request.getRequestURL().toString()).getHost();
  214. }
  215. // 根据域名进行筛选
  216. List<TenantListVo> list = StreamUtils.filter(voList, vo ->
  217. StringUtils.equalsIgnoreCase(vo.getDomain(), host));
  218. result.setVoList(CollUtil.isNotEmpty(list) ? list : voList);
  219. return R.ok(result);
  220. }
  221. }