1
0

AuthController.cs 7.1 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233
  1. using Admin.Core.Attributes;
  2. using Admin.Core.Common.Auth;
  3. using Admin.Core.Common.Consts;
  4. using Admin.Core.Common.Extensions;
  5. using Admin.Core.Common.Helpers;
  6. using Admin.Core.Common.Output;
  7. using Admin.Core.Service.Admin.Auth;
  8. using Admin.Core.Service.Admin.Auth.Input;
  9. using Admin.Core.Service.Admin.Auth.Output;
  10. using Admin.Core.Service.Admin.LoginLog;
  11. using Admin.Core.Service.Admin.LoginLog.Input;
  12. using Admin.Core.Service.Admin.User;
  13. using Admin.Tools.Captcha;
  14. using Microsoft.AspNetCore.Authorization;
  15. using Microsoft.AspNetCore.Cors;
  16. using Microsoft.AspNetCore.Mvc;
  17. using Microsoft.AspNetCore.Mvc.ModelBinding;
  18. using System;
  19. using System.Diagnostics;
  20. using System.Linq;
  21. using System.Security.Claims;
  22. using System.Threading.Tasks;
  23. namespace Admin.Core.Controllers.Admin
  24. {
  25. /// <summary>
  26. /// 授权管理
  27. /// </summary>
  28. public class AuthController : AreaController
  29. {
  30. private readonly IUserToken _userToken;
  31. private readonly IAuthService _authService;
  32. private readonly IUserService _userService;
  33. private readonly ILoginLogService _loginLogService;
  34. private readonly ICaptcha _captcha;
  35. public AuthController(
  36. IUserToken userToken,
  37. IAuthService authService,
  38. IUserService userService,
  39. ILoginLogService loginLogService,
  40. ICaptcha captcha
  41. )
  42. {
  43. _userToken = userToken;
  44. _authService = authService;
  45. _userService = userService;
  46. _loginLogService = loginLogService;
  47. _captcha = captcha;
  48. }
  49. /// <summary>
  50. /// 获得token
  51. /// </summary>
  52. /// <param name="output"></param>
  53. /// <returns></returns>
  54. private IResponseOutput GetToken(ResponseOutput<AuthLoginOutput> output)
  55. {
  56. if (!output.Success)
  57. {
  58. return ResponseOutput.NotOk(output.Msg);
  59. }
  60. var user = output.Data;
  61. if (user == null)
  62. {
  63. return ResponseOutput.NotOk();
  64. }
  65. var token = _userToken.Create(new[]
  66. {
  67. new Claim(ClaimAttributes.UserId, user.Id.ToString()),
  68. new Claim(ClaimAttributes.UserName, user.UserName),
  69. new Claim(ClaimAttributes.UserNickName, user.NickName),
  70. new Claim(ClaimAttributes.TenantId, user.TenantId.ToString()),
  71. new Claim(ClaimAttributes.TenantType, user.TenantType.ToString()),
  72. new Claim(ClaimAttributes.DataIsolationType, user.DataIsolationType.ToString())
  73. });
  74. return ResponseOutput.Ok(new { token });
  75. }
  76. /// <summary>
  77. /// 获取验证码
  78. /// </summary>
  79. /// <param name="lastKey">上次验证码键</param>
  80. /// <returns></returns>
  81. [HttpGet]
  82. [AllowAnonymous]
  83. [NoOprationLog]
  84. public async Task<IResponseOutput> GetVerifyCode(string lastKey)
  85. {
  86. return await _authService.GetVerifyCodeAsync(lastKey);
  87. }
  88. /// <summary>
  89. /// 获取验证数据
  90. /// </summary>
  91. /// <returns></returns>
  92. [HttpGet]
  93. [AllowAnonymous]
  94. [NoOprationLog]
  95. [EnableCors(AdminConsts.AllowAnyPolicyName)]
  96. public async Task<IResponseOutput> GetCaptcha()
  97. {
  98. var data = await _captcha.GetAsync();
  99. return ResponseOutput.Ok(data);
  100. }
  101. /// <summary>
  102. /// 检查验证数据
  103. /// </summary>
  104. /// <returns></returns>
  105. [HttpGet]
  106. [AllowAnonymous]
  107. [NoOprationLog]
  108. [EnableCors(AdminConsts.AllowAnyPolicyName)]
  109. public async Task<IResponseOutput> CheckCaptcha([FromQuery] CaptchaInput input)
  110. {
  111. var result = await _captcha.CheckAsync(input);
  112. return ResponseOutput.Result(result);
  113. }
  114. /// <summary>
  115. /// 获取密钥
  116. /// </summary>
  117. /// <returns></returns>
  118. [HttpGet]
  119. [AllowAnonymous]
  120. [NoOprationLog]
  121. public async Task<IResponseOutput> GetPassWordEncryptKey()
  122. {
  123. return await _authService.GetPassWordEncryptKeyAsync();
  124. }
  125. /// <summary>
  126. /// 查询用户信息
  127. /// </summary>
  128. /// <returns></returns>
  129. [HttpGet]
  130. [Login]
  131. public async Task<IResponseOutput> GetUserInfo()
  132. {
  133. return await _authService.GetUserInfoAsync();
  134. }
  135. /// <summary>
  136. /// 用户登录
  137. /// 根据登录信息生成Token
  138. /// </summary>
  139. /// <param name="input">登录信息</param>
  140. /// <returns></returns>
  141. [HttpPost]
  142. [AllowAnonymous]
  143. [NoOprationLog]
  144. public async Task<IResponseOutput> Login(AuthLoginInput input)
  145. {
  146. var sw = new Stopwatch();
  147. sw.Start();
  148. var res = await _authService.LoginAsync(input);
  149. sw.Stop();
  150. #region 添加登录日志
  151. var loginLogAddInput = new LoginLogAddInput()
  152. {
  153. CreatedUserName = input.UserName,
  154. ElapsedMilliseconds = sw.ElapsedMilliseconds,
  155. Status = res.Success,
  156. Msg = res.Msg
  157. };
  158. ResponseOutput<AuthLoginOutput> output = null;
  159. if (res.Success)
  160. {
  161. output = (res as ResponseOutput<AuthLoginOutput>);
  162. var user = output.Data;
  163. loginLogAddInput.CreatedUserId = user.Id;
  164. loginLogAddInput.NickName = user.NickName;
  165. loginLogAddInput.TenantId = user.TenantId;
  166. }
  167. await _loginLogService.AddAsync(loginLogAddInput);
  168. #endregion 添加登录日志
  169. if (!res.Success)
  170. {
  171. return res;
  172. }
  173. return GetToken(output);
  174. }
  175. /// <summary>
  176. /// 刷新Token
  177. /// 以旧换新
  178. /// </summary>
  179. /// <param name="token"></param>
  180. /// <returns></returns>
  181. [HttpGet]
  182. [AllowAnonymous]
  183. public async Task<IResponseOutput> Refresh([BindRequired] string token)
  184. {
  185. var userClaims = _userToken.Decode(token);
  186. if (userClaims == null || userClaims.Length == 0)
  187. {
  188. return ResponseOutput.NotOk();
  189. }
  190. var refreshExpires = userClaims.FirstOrDefault(a => a.Type == ClaimAttributes.RefreshExpires)?.Value;
  191. if (refreshExpires.IsNull())
  192. {
  193. return ResponseOutput.NotOk();
  194. }
  195. if (refreshExpires.ToLong() <= DateTime.Now.ToTimestamp())
  196. {
  197. return ResponseOutput.NotOk("登录信息已过期");
  198. }
  199. var userId = userClaims.FirstOrDefault(a => a.Type == ClaimAttributes.UserId)?.Value;
  200. if (userId.IsNull())
  201. {
  202. return ResponseOutput.NotOk("登录信息已失效");
  203. }
  204. var output = await _userService.GetLoginUserAsync(userId.ToLong());
  205. return GetToken(output);
  206. }
  207. }
  208. }