User.php 38 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005
  1. <?php
  2. namespace app\common\model;
  3. use think\Db;
  4. use think\View;
  5. use app\common\validate\User as UserValidate;
  6. class User extends Base
  7. {
  8. // 设置数据表(不含前缀)
  9. protected $name = 'user';
  10. // 定义时间戳字段名
  11. protected $createTime = '';
  12. protected $updateTime = '';
  13. // 自动完成
  14. protected $auto = [];
  15. protected $insert = [];
  16. protected $update = [];
  17. public $_guest_group = 1;
  18. public $_def_group = 2;
  19. public function countData($where)
  20. {
  21. $total = $this->where($where)->count();
  22. return $total;
  23. }
  24. public function listData($where, $order, $page = 1, $limit = 20, $start = 0)
  25. {
  26. $page = $page > 0 ? (int)$page : 1;
  27. $limit = $limit ? (int)$limit : 20;
  28. $start = $start ? (int)$start : 0;
  29. $total = $this->where($where)->count();
  30. $list = Db::name('User')->where($where)->order($order)->page($page)->limit($limit)->select();
  31. return ['code' => 1, 'msg' => lang('data_list'), 'page' => $page, 'pagecount' => ceil($total / $limit), 'limit' => $limit, 'total' => $total, 'list' => $list];
  32. }
  33. public function infoData($where, $field='*')
  34. {
  35. if (empty($where) || !is_array($where)) {
  36. return ['code' => 1001, 'msg'=>lang('param_err')];
  37. }
  38. $info = $this->field($field)->where($where)->find();
  39. if (empty($info)) {
  40. return ['code' => 1002, 'msg' => lang('obtain_err')];
  41. }
  42. $info = $info->toArray();
  43. //用户组
  44. $group_list = model('Group')->getCache('group_list');
  45. $group_ids = explode(',', $info['group_id']);
  46. $info['group'] = $group_list[$group_ids[0]];
  47. $info['groups'] = [];
  48. foreach($group_ids as $gid){
  49. if(isset($group_list[$gid])){
  50. $info['groups'][] = $group_list[$gid];
  51. }
  52. }
  53. $info['user_pwd'] = '';
  54. return ['code' => 1, 'msg' =>lang('obtain_ok'), 'info' => $info];
  55. }
  56. public function saveData($data)
  57. {
  58. $validate = \think\Loader::validate('User');
  59. if (isset($data['user_start_time']) && !is_numeric($data['user_start_time'])) {
  60. $data['user_start_time'] = strtotime($data['user_start_time']);
  61. }
  62. if (isset($data['user_end_time']) && !is_numeric($data['user_end_time'])) {
  63. $data['user_end_time'] = strtotime($data['user_end_time']);
  64. }
  65. if (!empty($data['user_id'])) {
  66. if (!$validate->scene('edit')->check($data)) {
  67. return ['code' => 1001, 'msg' => lang('param_err').':' . $validate->getError()];
  68. }
  69. if (empty($data['user_pwd'])) {
  70. unset($data['user_pwd']);
  71. } else {
  72. $data['user_pwd'] = md5($data['user_pwd']);
  73. }
  74. $where = [];
  75. $where['user_id'] = ['eq', $data['user_id']];
  76. $res = $this->where($where)->update($data);
  77. } else {
  78. if (!$validate->scene('edit')->check($data)) {
  79. return ['code' => 1002, 'msg' => lang('param_err').':' . $validate->getError()];
  80. }
  81. $data['user_pwd'] = md5($data['user_pwd']);
  82. $res = $this->insert($data);
  83. }
  84. if (false === $res) {
  85. return ['code' => 1003, 'msg' => '' . $this->getError()];
  86. }
  87. return ['code' => 1, 'msg' =>lang('save_ok')];
  88. }
  89. public function delData($where)
  90. {
  91. $res = $this->where($where)->delete();
  92. if ($res === false) {
  93. return ['code' => 1001, 'msg' => lang('del_err').':' . $this->getError()];
  94. }
  95. return ['code' => 1, 'msg'=>lang('del_ok')];
  96. }
  97. public function fieldData($where, $col, $val)
  98. {
  99. if (!isset($col) || !isset($val)) {
  100. return ['code' => 1001, 'msg'=>lang('param_err')];
  101. }
  102. $data = [];
  103. $data[$col] = $val;
  104. $res = $this->where($where)->update($data);
  105. if ($res === false) {
  106. return ['code' => 1002, 'msg' => lang('set_err').':' . $this->getError()];
  107. }
  108. return ['code' => 1, 'msg' =>lang('set_ok')];
  109. }
  110. public function register($param)
  111. {
  112. $config = config('maccms');
  113. $data = [];
  114. $password_raw = trim($param['user_pwd']);
  115. $data['user_name'] = htmlspecialchars(urldecode(trim($param['user_name'])));
  116. $data['user_pwd'] = htmlspecialchars(urldecode(trim($param['user_pwd'])));
  117. $data['user_pwd2'] = htmlspecialchars(urldecode(trim($param['user_pwd2'])));
  118. $data['verify'] = $param['verify'];
  119. $uid = $param['uid'];
  120. $is_from_3rdparty = !empty($param['user_openid_qq']) || !empty($param['user_openid_weixin']);
  121. if ($config['user']['status'] == 0 || $config['user']['reg_open'] == 0) {
  122. return ['code' => 1001, 'msg' => lang('model/user/not_open_reg')];
  123. }
  124. if (empty($data['user_name']) || empty($data['user_pwd']) || empty($data['user_pwd2'])) {
  125. return ['code' => 1002, 'msg' => lang('model/user/input_require')];
  126. }
  127. if (!$is_from_3rdparty && !captcha_check($data['verify']) && $config['user']['reg_verify'] == 1) {
  128. return ['code' => 1003, 'msg' => lang('verify_err')];
  129. }
  130. if ($data['user_pwd'] != $data['user_pwd2']) {
  131. return ['code' => 1004, 'msg' => lang('model/user/pass_not_pass2')];
  132. }
  133. $row = $this->where('user_name', $data['user_name'])->find();
  134. if (!empty($row)) {
  135. return ['code' => 1005, 'msg' => lang('model/user/haved_reg')];
  136. }
  137. if (!preg_match("/^[a-zA-Z\d]*$/i", $data['user_name'])) {
  138. return ['code' => 1006, 'msg' => lang('model/user/name_contain')];
  139. }
  140. $validate = \think\Loader::validate('User');
  141. if (!$validate->scene('add')->check($data)) {
  142. return ['code' => 1007, 'msg' => lang('param_err').':' . $validate->getError()];
  143. }
  144. $filter = $GLOBALS['config']['user']['filter_words'];
  145. if(!empty($filter)) {
  146. $filter_arr = explode(',', $filter);
  147. $f_name = str_replace($filter_arr, '', $data['user_name']);
  148. if ($f_name != $data['user_name']) {
  149. return ['code' => 1008, 'msg' =>lang('model/user/name_filter',[$filter])];
  150. }
  151. }
  152. $ip = mac_get_ip_long();
  153. if( $GLOBALS['config']['user']['reg_num'] > 0){
  154. $where2=[];
  155. $where2['user_reg_ip'] = ['eq', $ip];
  156. $where2['user_reg_time'] = ['gt', strtotime('today')];
  157. $cc = $this->where($where2)->count();
  158. if($cc >= $GLOBALS['config']['user']['reg_num']){
  159. return ['code' => 1009, 'msg' => lang('model/user/ip_limit',[$GLOBALS['config']['user']['reg_num']])];
  160. }
  161. }
  162. $fields = [];
  163. $fields['user_name'] = $data['user_name'];
  164. $fields['user_pwd'] = md5($password_raw);
  165. $fields['group_id'] = $this->_def_group;
  166. $fields['user_points'] = intval($config['user']['reg_points']);
  167. $fields['user_status'] = intval($config['user']['reg_status']);
  168. $fields['user_reg_time'] = time();
  169. $fields['user_reg_ip'] = $ip;
  170. $fields['user_openid_qq'] = (string)$param['user_openid_qq'];
  171. $fields['user_openid_weixin'] = (string)$param['user_openid_weixin'];
  172. if (!$is_from_3rdparty) {
  173. // https://github.com/magicblack/maccms10/issues/418
  174. if($config['user']['reg_phone_sms'] == '1'){
  175. $param['type'] = 3;
  176. $res = $this->check_msg($param);
  177. if($res['code'] >1){
  178. return $res;
  179. }
  180. $fields['user_phone'] = $param['to'];
  181. $update=[];
  182. $update['user_phone'] = '';
  183. $where2=[];
  184. $where2['user_phone'] = $param['to'];
  185. $row = $this->where($where2)->find();
  186. if (!empty($row)) {
  187. return ['code' => 1011, 'msg' =>lang('model/user/phone_haved')];
  188. }
  189. //$this->where($where2)->update($update);
  190. }
  191. elseif($config['user']['reg_email_sms'] == '1'){
  192. $param['type'] = 3;
  193. $res = $this->check_msg($param);
  194. if($res['code'] >1){
  195. return $res;
  196. }
  197. $fields['user_email'] = $param['to'];
  198. $update=[];
  199. $update['user_email'] = '';
  200. $where2=[];
  201. $where2['user_email'] = $param['to'];
  202. $row = $this->where($where2)->find();
  203. if (!empty($row)) {
  204. return ['code' => 1012, 'msg' => lang('model/user/email_haved')];
  205. }
  206. //$this->where($where2)->update($update);
  207. }
  208. }
  209. $res = $this->insert($fields);
  210. if ($res === false) {
  211. return ['code' => 1010, 'msg' => lang('model/user/reg_err')];
  212. }
  213. $nid = $this->getLastInsID();
  214. $uid = intval($uid);
  215. if($uid > 0) {
  216. $where2 = [];
  217. $where2['user_id'] = $uid;
  218. $invite = $this->where($where2)->find();
  219. if ($invite) {
  220. $where=[];
  221. $where['user_id'] = $nid;
  222. $update=[];
  223. $update['user_pid'] = $invite['user_id'];
  224. $update['user_pid_2'] = $invite['user_pid'];
  225. $update['user_pid_3'] = $invite['user_pid_2'];
  226. $r1 = $this->where($where)->update($update);
  227. $r2 = false;
  228. $config['user']['invite_reg_num'] = intval($config['user']['invite_reg_num']);
  229. if($config['user']['invite_reg_points']>0){
  230. $r2 = $this->where($where2)->setInc('user_points', $config['user']['invite_reg_points']);
  231. }
  232. if($r2!==false) {
  233. //积分日志
  234. $data = [];
  235. $data['user_id'] = $uid;
  236. $data['plog_type'] = 2;
  237. $data['plog_points'] = $config['user']['invite_reg_points'];
  238. model('Plog')->saveData($data);
  239. }
  240. }
  241. }
  242. return ['code' => 1, 'msg' => lang('model/user/reg_ok')];
  243. }
  244. public function regcheck($t, $str)
  245. {
  246. $where = [];
  247. if ($t == 'user_name') {
  248. $where['user_name'] = $str;
  249. $row = $this->where($where)->find();
  250. if (!empty($row)) {
  251. return ['code' => 1001, 'msg' => lang('registered')];
  252. }
  253. } elseif ($t == 'user_email') {
  254. $where['user_email'] = $str;
  255. $row = $this->where($where)->find();
  256. if (!empty($row)) {
  257. return ['code' => 1001, 'msg' => lang('registered')];
  258. }
  259. } elseif ($t == 'verify') {
  260. if (!captcha_check($str)) {
  261. return ['code' => 1002, 'msg' => lang('verify_err')];
  262. }
  263. }
  264. return ['code' => 1, 'msg' => 'ok'];
  265. }
  266. public function info($param)
  267. {
  268. if (empty($param['user_pwd'])) {
  269. return ['code' => 1001, 'msg' => lang('model/user/input_old_pass')];
  270. }
  271. $password_raw = trim($param['user_pwd']);
  272. $password_formatted = htmlspecialchars(urldecode(trim($param['user_pwd'])));
  273. if (!in_array($GLOBALS['user']['user_pwd'], [md5($password_raw), md5($password_formatted)])) {
  274. return ['code' => 1002, 'msg' => lang('model/user/old_pass_err')];
  275. }
  276. if ($param['user_pwd1'] != $param['user_pwd2']) {
  277. return ['code' => 1003, 'msg' => lang('model/user/pass_not_same_pass2')];
  278. }
  279. $data = [];
  280. $data['user_id'] = $GLOBALS['user']['user_id'];
  281. $data['user_name'] = $GLOBALS['user']['user_name'];
  282. if(!empty($param['user_nick_name'])){
  283. $data['user_nick_name'] = htmlspecialchars(urldecode(trim($param['user_nick_name'])));
  284. }
  285. $data['user_qq'] = htmlspecialchars(urldecode(trim($param['user_qq'])));
  286. $data['user_question'] = htmlspecialchars(urldecode(trim($param['user_question'])));
  287. $data['user_answer'] = htmlspecialchars(urldecode(trim($param['user_answer'])));
  288. if (!empty($param['user_pwd2'])) {
  289. $data['user_pwd'] = trim($param['user_pwd2']);
  290. }
  291. return $this->saveData($data);
  292. }
  293. public function login($param)
  294. {
  295. $data = [];
  296. $password_raw = trim($param['user_pwd']);
  297. $data['user_name'] = htmlspecialchars(urldecode(trim($param['user_name'])));
  298. $data['user_pwd'] = htmlspecialchars(urldecode(trim($param['user_pwd'])));
  299. $data['verify'] = $param['verify'];
  300. $data['openid'] = htmlspecialchars(urldecode(trim($param['openid'])));
  301. $data['col'] = htmlspecialchars(urldecode(trim($param['col'])));
  302. if (empty($data['openid'])) {
  303. if (empty($data['user_name']) || empty($data['user_pwd'])) {
  304. return ['code' => 1001, 'msg' => lang('model/user/input_require')];
  305. }
  306. if ($GLOBALS['config']['user']['login_verify'] ==1 && !captcha_check($data['verify'])) {
  307. return ['code' => 1002, 'msg' => lang('verify_err')];
  308. }
  309. $where = [];
  310. $pattern = '/\w+([-+.]\w+)*@\w+([-.]\w+)*\.\w+([-.]\w+)*/';
  311. if (!preg_match($pattern, $data['user_name'])) {
  312. $where['user_name'] = ['eq', $data['user_name']];
  313. } else {
  314. $where['user_email'] = ['eq', $data['user_name']];
  315. }
  316. // https://github.com/magicblack/maccms10/issues/781 兼容密码
  317. $where['user_pwd'] = [['eq', md5($password_raw)], ['eq', $data['user_pwd']], 'or'];
  318. } else {
  319. if (empty($data['openid']) || empty($data['col'])) {
  320. return ['code' => 1001, 'msg' => lang('model/user/input_require')];
  321. }
  322. if (!in_array($data['col'], ['user_openid_qq', 'user_openid_weixin'])) {
  323. return ['code' => 1002, 'msg' => lang('param_err') . ': col'];
  324. }
  325. $where[$data['col']] = $data['openid'];
  326. }
  327. $where['user_status'] = ['eq', 1];
  328. $row = $this->where($where)->find();
  329. if(empty($row)) {
  330. return ['code' => 1003, 'msg' => lang('model/user/not_found')];
  331. }
  332. $login_group_ids = explode(',', $row['group_id']);
  333. if(max($login_group_ids) > 2 && $row['user_end_time'] < time()) {
  334. $row['group_id'] = 2;
  335. $update['group_id'] = 2;
  336. }
  337. $random = md5(rand(10000000, 99999999));
  338. $update['user_random'] = $random;
  339. $update['user_login_ip'] = mac_get_ip_long();
  340. $update['user_login_time'] = time();
  341. $update['user_login_num'] = $row['user_login_num'] + 1;
  342. $update['user_last_login_time'] = $row['user_login_time'];
  343. $update['user_last_login_ip'] = $row['user_login_ip'];
  344. $res = $this->where($where)->update($update);
  345. if ($res === false) {
  346. return ['code' => 1004, 'msg' => lang('model/user/update_login_err')];
  347. }
  348. //用户组
  349. $group_list = model('Group')->getCache('group_list');
  350. $group_ids = explode(',', $row['group_id']);
  351. $group = [];
  352. foreach($group_ids as $gid){
  353. if(isset($group_list[$gid])){
  354. $group[] = $group_list[$gid];
  355. }
  356. }
  357. cookie('user_id', $row['user_id'],['expire'=>2592000] );
  358. cookie('user_name', $row['user_name'],['expire'=>2592000] );
  359. cookie('group_id', $group[0]['group_id'],['expire'=>2592000] );
  360. cookie('group_name', $group[0]['group_name'],['expire'=>2592000] );
  361. cookie('user_check', md5($random . '-' .$row['user_name'] . '-' . $row['user_id'] .'-' ),['expire'=>2592000] );
  362. cookie('user_portrait', mac_get_user_portrait($row['user_id']),['expire'=>2592000] );
  363. return ['code' => 1, 'msg' => lang('model/user/login_ok')];
  364. }
  365. public function expire()
  366. {
  367. $where=[];
  368. $where['user_end_time'] = ['elt',time()];
  369. $update=[];
  370. $update['group_id'] = '2';
  371. $res = $this->where($where)->update($update);
  372. if ($res === false) {
  373. return ['code' => 101, 'msg' => lang('model/user/update_expire_err')];
  374. }
  375. return ['code' => 1, 'msg' => lang('model/user/update_expire_ok')];
  376. }
  377. public function logout()
  378. {
  379. cookie('user_id', null);
  380. cookie('user_name', null);
  381. cookie('group_id', null);
  382. cookie('group_name', null);
  383. cookie('user_check', null);
  384. cookie('user_portrait', null);
  385. return ['code' => 1, 'msg' =>lang('model/user/logout_ok')];
  386. }
  387. public function checkLogin()
  388. {
  389. $user_id = cookie('user_id');
  390. $user_name = cookie('user_name');
  391. $user_check = cookie('user_check');
  392. $user_id = htmlspecialchars(urldecode(trim($user_id)));
  393. $user_name = htmlspecialchars(urldecode(trim($user_name)));
  394. $user_check = htmlspecialchars(urldecode(trim($user_check)));
  395. if (empty($user_id) || empty($user_name) || empty($user_check)) {
  396. return ['code' => 1001, 'msg' => lang('model/user/not_login')];
  397. }
  398. $where = [];
  399. $where['user_id'] = $user_id;
  400. $where['user_name'] = $user_name;
  401. $where['user_status'] = 1;
  402. $info = $this->field('*')->where($where)->find();
  403. if(empty($info)) {
  404. return ['code' => 1002, 'msg' => lang('model/user/not_login')];
  405. }
  406. $info = $info->toArray();
  407. $login_check = md5($info['user_random'] . '-' . $info['user_name']. '-' . $info['user_id'] .'-' );
  408. if($login_check != $user_check) {
  409. return ['code' => 1003, 'msg' => lang('model/user/not_login')];
  410. }
  411. $group_list = model('Group')->getCache('group_list');
  412. $group_ids = explode(',', $info['group_id']);
  413. $user_groups = [];
  414. $user_group_types = [];
  415. foreach($group_ids as $gid){
  416. if(isset($group_list[$gid])){
  417. $user_groups[] = $group_list[$gid];
  418. if (!empty($group_list[$gid]['group_type'])) {
  419. $user_group_types = array_merge($user_group_types, explode(',', $group_list[$gid]['group_type']));
  420. }
  421. }
  422. }
  423. if (!empty($user_groups)) {
  424. $info['group'] = $user_groups[0];
  425. $info['group']['group_type'] = implode(',', array_unique(array_filter($user_group_types)));
  426. $info['groups'] = $user_groups;
  427. $all_names = [];
  428. foreach($user_groups as $g){
  429. $all_names[] = $g['group_name'];
  430. }
  431. $info['group']['group_name'] = implode(',', $all_names);
  432. } else {
  433. $info['group'] = $group_list[1];
  434. }
  435. //会员截止日期
  436. if (max($group_ids) > 2 && $info['user_end_time'] < time()) {
  437. //用户组
  438. $info['group'] = $group_list[2];
  439. $update = [];
  440. $update['group_id'] = 2;
  441. $res = $this->where($where)->update($update);
  442. if($res === false){
  443. return ['code' => 1004, 'msg' => lang('model/user/update_expire_err')];
  444. }
  445. $info['group_id'] = 2;
  446. $info['groups'] = [$group_list[2]];
  447. cookie('group_id', $info['group']['group_id'], ['expire'=>2592000] );
  448. cookie('group_name', $info['group']['group_name'],['expire'=>2592000] );
  449. }
  450. return ['code' => 1, 'msg' => lang('model/user/haved_login'), 'info' => $info];
  451. }
  452. public function resetPwd()
  453. {
  454. }
  455. public function findpass($param)
  456. {
  457. $data = [];
  458. $password_raw = trim($param['user_pwd']);
  459. $data['user_name'] = htmlspecialchars(urldecode(trim($param['user_name'])));
  460. $data['user_question'] = htmlspecialchars(urldecode(trim($param['user_question'])));
  461. $data['user_answer'] = htmlspecialchars(urldecode(trim($param['user_answer'])));
  462. $data['user_pwd'] = htmlspecialchars(urldecode(trim($param['user_pwd'])));
  463. $data['user_pwd2'] = htmlspecialchars(urldecode(trim($param['user_pwd2'])));
  464. $data['verify'] = $param['verify'];
  465. if (empty($data['user_name']) || empty($data['user_question']) || empty($data['user_answer']) || empty($data['user_pwd']) || empty($data['user_pwd2']) || empty($data['verify'])) {
  466. return ['code' => 1001, 'msg' => lang('param_err')];
  467. }
  468. if (!captcha_check($data['verify'])) {
  469. return ['code' => 1002, 'msg' => lang('verify_err')];
  470. }
  471. if ($data['user_pwd'] != $data['user_pwd2']) {
  472. return ['code' => 1003, 'msg' => lang('model/user/pass_not_same_pass2')];
  473. }
  474. $where = [];
  475. $where['user_name'] = $data['user_name'];
  476. $where['user_question'] = $data['user_question'];
  477. $where['user_answer'] = $data['user_answer'];
  478. $info = $this->where($where)->find();
  479. if (empty($info)) {
  480. return ['code' => 1004, 'msg' => lang('model/user/findpass_not_found')];
  481. }
  482. $update = [];
  483. $update['user_pwd'] = md5($password_raw);
  484. $where = [];
  485. $where['user_id'] = $info['user_id'];
  486. $res = $this->where($where)->update($update);
  487. if (false === $res) {
  488. return ['code' => 1005, 'msg' => '' . $this->getError()];
  489. }
  490. return ['code' => 1, 'msg' => lang('model/user/findpass_ok')];
  491. }
  492. public function popedom($type_id, $popedom, $group_ids = 1)
  493. {
  494. $group_list = model('Group')->getCache();
  495. $group_ids = explode(',', $group_ids);
  496. foreach($group_ids as $group_id) {
  497. if(!isset($group_list[$group_id])) {
  498. continue;
  499. }
  500. $group_info = $group_list[$group_id];
  501. if (strpos(',' . $group_info['group_type'], ',' . $type_id . ',') !== false && !empty($group_info['group_popedom'][$type_id][$popedom]) !== false) {
  502. return true;
  503. }
  504. }
  505. return false;
  506. }
  507. public function upgrade($param)
  508. {
  509. $group_id = intval($param['group_id']);
  510. $long = $param['long'];
  511. $points_long = ['day'=>86400,'week'=>86400*7,'month'=>86400*30,'year'=>86400*365];
  512. if (!array_key_exists($long, $points_long)) {
  513. return ['code'=>1001,'msg'=>'非法操作'];
  514. }
  515. if($group_id <3){
  516. return ['code'=>1002,'msg'=>lang('model/user/select_diy_group_err')];
  517. }
  518. $group_list = model('Group')->getCache();
  519. $group_info = $group_list[$group_id];
  520. if(empty($group_info)){
  521. return ['code'=>1003,'msg'=>lang('model/user/group_not_found')];
  522. }
  523. if($group_info['group_status'] == 0){
  524. return ['code'=>1004,'msg'=>lang('model/user/group_is_close')];
  525. }
  526. $point = $group_info['group_points_'.$long];
  527. if($GLOBALS['user']['user_points'] < $point){
  528. return ['code'=>1005,'msg'=>lang('model/user/potins_not_enough')];
  529. }
  530. $sj = $points_long[$long];
  531. $end_time = time() + $sj;
  532. if($GLOBALS['user']['user_end_time'] > time() ){
  533. $end_time = $GLOBALS['user']['user_end_time'] + $sj;
  534. }
  535. $where = [];
  536. $where['user_id'] = $GLOBALS['user']['user_id'];
  537. $old_group_ids = explode(',', $GLOBALS['user']['group_id']);
  538. if(!in_array($group_id, $old_group_ids)){
  539. $old_group_ids[] = $group_id;
  540. }
  541. $data = [];
  542. $data['user_points'] = $GLOBALS['user']['user_points'] - $point;
  543. $data['user_end_time'] = $end_time;
  544. $data['group_id'] = implode(',', array_unique($old_group_ids));
  545. $res = $this->where($where)->update($data);
  546. if($res===false){
  547. return ['code'=>1009,'msg'=>lang('model/user/update_group_err')];
  548. }
  549. //积分日志
  550. $data = [];
  551. $data['user_id'] = $GLOBALS['user']['user_id'];
  552. $data['plog_type'] = 7;
  553. $data['plog_points'] = $point;
  554. model('Plog')->saveData($data);
  555. //分销日志
  556. $this->reward($point);
  557. cookie('group_id', $group_info['group_id'],['expire'=>2592000] );
  558. cookie('group_name', $group_info['group_name'],['expire'=>2592000] );
  559. return ['code'=>1,'msg'=>lang('model/user/update_group_ok')];
  560. }
  561. public function check_msg($param)
  562. {
  563. $param['to'] = htmlspecialchars(urldecode(trim($param['to'])));
  564. $param['code'] = htmlspecialchars(urldecode(trim($param['code'])));
  565. if(!in_array($param['ac'],['email','phone']) || empty($param['to']) || empty($param['code']) || empty($param['type'])){
  566. return ['code'=>9001,'msg'=>lang('param_err')];
  567. }
  568. // https://github.com/magicblack/maccms10/issues/792 邮箱增加黑白名单校验
  569. if ($param['ac'] == 'email' && in_array($param['type'], [1, 3])) {
  570. $result = UserValidate::validateEmail($param['to']);
  571. if ($result['code'] > 1) {
  572. return $result;
  573. }
  574. }
  575. //msg_type 1绑定2找回3注册
  576. $stime = strtotime('-5 min');
  577. if($param['ac']=='email' && intval($GLOBALS['config']['email']['time'])>0){
  578. $stime = strtotime('-'.$GLOBALS['config']['email']['time'].' min');
  579. }
  580. $where=[];
  581. $where['user_id'] = intval($GLOBALS['user']['user_id']);
  582. $where['msg_time'] = ['gt',$stime];
  583. $where['msg_code'] = ['eq',$param['code']];
  584. $where['msg_type'] = ['eq', $param['type'] ];
  585. $res = model('msg')->infoData($where);
  586. if($res['code'] >1){
  587. return ['code'=>9002,'msg'=>lang('model/user/msg_not_found')];
  588. }
  589. return ['code'=>1,'msg'=>'ok'];
  590. }
  591. public function send_msg($param)
  592. {
  593. $param['to'] = htmlspecialchars(urldecode(trim($param['to'])));
  594. $param['code'] = htmlspecialchars(urldecode(trim($param['code'])));
  595. $type_arr = [
  596. 1=>['des'=>lang('bind'),'flag'=>'bind'],
  597. 2=>['des'=>lang('findpass'),'flag'=>'findpass'],
  598. 3=>['des'=>lang('register'),'flag'=>'reg'],
  599. ];
  600. if(!in_array($param['ac'],['email','phone']) || !isset($type_arr[$param['type']]) || empty($param['to']) || empty($param['type'])){
  601. return ['code'=>9001,'msg'=>lang('param_err')];
  602. }
  603. // https://github.com/magicblack/maccms10/issues/792 邮箱增加黑白名单校验
  604. if ($param['ac'] == 'email' && in_array($param['type'], [1, 3])) {
  605. $result = UserValidate::validateEmail($param['to']);
  606. if ($result['code'] > 1) {
  607. return $result;
  608. }
  609. }
  610. $type_des = $type_arr[$param['type']]['des'];
  611. $type_flag = $type_arr[$param['type']]['flag'];
  612. $to = $param['to'];
  613. $code = mac_get_rndstr(6,'num');
  614. $r=0;
  615. $stime = strtotime('-5 min');
  616. if($param['ac']=='email' && intval($GLOBALS['config']['email']['time'])>0){
  617. $stime = strtotime('-'.$GLOBALS['config']['email']['time'].' min');
  618. }
  619. $where=[];
  620. $where['user_id'] = intval($GLOBALS['user']['user_id']);
  621. $where['msg_time'] = ['gt',$stime];
  622. $where['msg_type'] = ['eq', $param['type'] ];
  623. $where['msg_to'] = ['eq', $param['to'] ];
  624. $res = model('msg')->infoData($where);
  625. if($res['code'] ==1){
  626. return ['code'=>9002,'msg'=>lang('model/user/do_not_send_frequently')];
  627. }
  628. $res_msg= ','.lang('please_try_again');
  629. if($param['ac']=='email'){
  630. $title = $GLOBALS['config']['email']['tpl']['user_'.$type_flag.'_title'];
  631. $msg = $GLOBALS['config']['email']['tpl']['user_'.$type_flag.'_body'];
  632. View::instance()->assign(['code'=>$code,'time'=>$GLOBALS['config']['email']['time']]);
  633. $title = View::instance()->display($title);
  634. $msg = View::instance()->display($msg);
  635. $msg = htmlspecialchars_decode($msg);
  636. $res_send = mac_send_mail($to, $title, $msg);
  637. $res_code = $res_send['code'];
  638. $res_msg = $res_send['msg'];
  639. }
  640. else{
  641. $msg = $GLOBALS['config']['sms']['content'];
  642. $msg = str_replace(['[用户]','[类型]','[时长]','[验证码]'],[$GLOBALS['user']['user_name'],$type_des,'5',$code],$msg);
  643. $res_send = mac_send_sms($to,$code,$type_flag,$type_des,$msg);
  644. $res_code = $res_send['code'];
  645. $res_msg = $res_send['msg'];
  646. }
  647. if($res_code==1){
  648. $data=[];
  649. $data['user_id'] = intval($GLOBALS['user']['user_id']);
  650. $data['msg_type'] = $param['type'];
  651. $data['msg_status'] = 0;
  652. $data['msg_to'] = $to;
  653. $data['msg_code'] = $code;
  654. $data['msg_content'] = $msg;
  655. $data['msg_time'] = time();
  656. $res = model('msg')->saveData($data);
  657. return ['code'=>1,'msg'=>lang('model/user/msg_send_ok')];
  658. }
  659. else{
  660. return ['code'=>9009,'msg'=>lang('model/user/msg_send_err').':'.$res_msg];
  661. }
  662. }
  663. public function bind($param)
  664. {
  665. $param['type'] = 1;
  666. $res = $this->check_msg($param);
  667. if($res['code'] >1){
  668. return ['code'=>$res['code'],'msg'=>$res['msg']];
  669. }
  670. $update=[];
  671. $update2=[];
  672. $where2=[];
  673. if($param['ac']=='email') {
  674. $update['user_email'] = $param['to'];
  675. $update2['user_email'] = '';
  676. $where2['user_email'] = $param['to'];
  677. }
  678. else{
  679. $update['user_phone'] = $param['to'];
  680. $update2['user_phone'] = '';
  681. $where2['user_phone'] = $param['to'];
  682. }
  683. $this->where($where2)->update($update2);
  684. $where=[];
  685. $where['user_id'] = $GLOBALS['user']['user_id'];
  686. $res = $this->where($where)->update($update);
  687. if($res===false){
  688. return ['code'=>2003,'msg'=>lang('model/user/update_bind_err')];
  689. }
  690. return ['code'=>1,'msg'=>lang('model/user/update_bind_ok')];
  691. }
  692. public function unbind($param)
  693. {
  694. if(!in_array($param['ac'],['email','phone']) ){
  695. return ['code'=>2001,'msg'=>lang('param_err')];
  696. }
  697. $col = 'user_email';
  698. if($param['ac']=='phone'){
  699. $col = 'user_phone';
  700. }
  701. $update=[];
  702. $update[$col] = '';
  703. $where=[];
  704. $where['user_id'] = $GLOBALS['user']['user_id'];
  705. $res = $this->where($where)->update($update);
  706. if($res===false){
  707. return ['code'=>2002,'msg'=>lang('model/user/update_bind_err')];
  708. }
  709. return ['code'=>1,'msg'=>lang('model/user/update_unbind_ok')];
  710. }
  711. public function bindmsg($param)
  712. {
  713. $param['type'] = 1;
  714. return $this->send_msg($param);
  715. }
  716. public function findpass_msg($param)
  717. {
  718. $param['type'] = 2;
  719. return $this->send_msg($param);
  720. }
  721. public function reg_msg($param)
  722. {
  723. $param['type'] = 3;
  724. return $this->send_msg($param);
  725. }
  726. public function findpass_reset($param)
  727. {
  728. $to = htmlspecialchars(urldecode(trim($param['user_email'])));
  729. if(empty($to)){
  730. $to = htmlspecialchars(urldecode(trim($param['to'])));
  731. }
  732. $password_raw = trim($param['user_pwd']);
  733. $param['code'] = htmlspecialchars(urldecode(trim($param['code'])));
  734. $param['user_pwd'] = htmlspecialchars(urldecode(trim($param['user_pwd'])));
  735. $param['user_pwd2'] = htmlspecialchars(urldecode(trim($param['user_pwd2'])));
  736. if (strlen($param['user_pwd']) < 6) {
  737. return ['code' => 2002, 'msg' => lang('model/user/pass_length_err')];
  738. }
  739. if ($param['user_pwd'] != $param['user_pwd2']) {
  740. return ['code' => 2003, 'msg' => lang('model/user/pass_not_same_pass2')];
  741. }
  742. $param['type'] = 2;
  743. $res = $this->check_msg($param);
  744. if($res['code'] >1){
  745. return ['code'=>$res['code'],'msg'=>$res['msg']];
  746. }
  747. if($param['ac']=='email') {
  748. $pattern = '/\w+([-+.]\w+)*@\w+([-.]\w+)*\.\w+([-.]\w+)*/';
  749. if(!preg_match( $pattern, $to)){
  750. return ['code'=>2005,'msg'=>lang('model/user/email_format_err')];
  751. }
  752. $where = [];
  753. $where['user_email'] = $to;
  754. $user = $this->where($where)->find();
  755. if (!$user) {
  756. return ['code' => 2006, 'msg' => lang('model/user/email_err')];
  757. }
  758. }
  759. else{
  760. $pattern = "/^1{1}\d{10}$/";
  761. if(!preg_match($pattern,$to)){
  762. return ['code'=>2007,'msg'=>lang('model/user/phone_format_err')];
  763. }
  764. $where = [];
  765. $where['user_phone'] = $to;
  766. $user = $this->where($where)->find();
  767. if (!$user) {
  768. return ['code' => 2008, 'msg' =>lang('model/user/phone_err')];
  769. }
  770. }
  771. $update = [];
  772. $update['user_pwd'] = md5($password_raw);
  773. $res = $this->where($where)->update($update);
  774. if($res===false){
  775. return ['code'=>2009,'msg'=>lang('model/user/pass_reset_err')];
  776. }
  777. return ['code'=>1,'msg'=>lang('model/user/pass_reset_ok')];
  778. }
  779. public function visit($param)
  780. {
  781. $param['uid'] = abs(intval($param['uid']));
  782. if ($param['uid'] == 0) {
  783. return ['code' => 101, 'msg' =>lang('model/user/id_err')];
  784. }
  785. $ip = mac_get_ip_long();
  786. $max_cc = $GLOBALS['config']['user']['invite_visit_num'];
  787. if(empty($max_cc)){
  788. $max_cc=1;
  789. }
  790. $todayunix = strtotime("today");
  791. $where = [];
  792. $where['user_id'] = $param['uid'];
  793. $where['visit_ip'] = $ip;
  794. $where['visit_time'] = ['gt', $todayunix];
  795. $cc = model('visit')->where($where)->count();
  796. if ($cc>= $max_cc){
  797. return ['code' => 102, 'msg' => lang('model/user/visit_tip')];
  798. }
  799. $data = [];
  800. $data['user_id'] = $param['uid'];
  801. $data['visit_ip'] = $ip;
  802. $data['visit_time'] = time();
  803. $data['visit_ly'] = htmlspecialchars(mac_get_refer());
  804. $res = model('visit')->saveData($data);
  805. if ($res['code'] > 1) {
  806. return ['code' => 103, 'msg' => lang('model/user/visit_err')];
  807. }
  808. $res = $this->where('user_id', $param['uid'])->setInc('user_points', intval($GLOBALS['config']['user']['invite_visit_points']));
  809. if($res) {
  810. //积分日志
  811. $data = [];
  812. $data['user_id'] = $param['uid'];
  813. $data['plog_type'] = 3;
  814. $data['plog_points'] = intval($GLOBALS['config']['user']['invite_visit_points']);
  815. model('Plog')->saveData($data);
  816. }
  817. return ['code'=>1,'msg'=>lang('model/user/visit_ok')];
  818. }
  819. public function reward($fee_points=0)
  820. {
  821. //三级分销
  822. if($fee_points>0 && $GLOBALS['config']['user']['reward_status'] == '1'){
  823. if(!empty($GLOBALS['config']['user']['reward_ratio']) && !empty($GLOBALS['user']['user_pid'])){
  824. $points = floor($fee_points / 100 * $GLOBALS['config']['user']['reward_ratio']);
  825. if($points>0){
  826. $where=[];
  827. $where['user_id'] = $GLOBALS['user']['user_pid'];
  828. $r = model('User')->where($where)->setInc('user_points',$points);
  829. if($r){
  830. $data = [];
  831. $data['user_id'] = $GLOBALS['user']['user_pid'];
  832. $data['plog_type'] = 4;
  833. $data['plog_points'] = $points;
  834. $data['plog_remarks'] = lang('model/user/reward_tip',[$GLOBALS['user']['user_id'],$GLOBALS['user']['user_name'],$fee_points,$points]);
  835. model('Plog')->saveData($data);
  836. }
  837. }
  838. }
  839. if(!empty($GLOBALS['config']['user']['reward_ratio_2']) && !empty($GLOBALS['user']['user_pid_2'])){
  840. $points = floor($fee_points / 100 * $GLOBALS['config']['user']['reward_ratio_2']);
  841. if($points>0){
  842. $where=[];
  843. $where['user_id'] = $GLOBALS['user']['user_pid_2'];
  844. $r = model('User')->where($where)->setInc('user_points',$points);
  845. if($r){
  846. $data = [];
  847. $data['user_id'] = $GLOBALS['user']['user_pid_2'];
  848. $data['plog_type'] = 5;
  849. $data['plog_points'] = $points;
  850. $data['plog_remarks'] =lang('model/user/reward_tip',[$GLOBALS['user']['user_id'],$GLOBALS['user']['user_name'],$fee_points,$points]);
  851. model('Plog')->saveData($data);
  852. }
  853. }
  854. }
  855. if(!empty($GLOBALS['config']['user']['reward_ratio_3']) && !empty($GLOBALS['user']['user_pid_3'])){
  856. $points = floor($fee_points / 100 * $GLOBALS['config']['user']['reward_ratio_3']);
  857. if($points>0){
  858. $where=[];
  859. $where['user_id'] = $GLOBALS['user']['user_pid_3'];
  860. $r = model('User')->where($where)->setInc('user_points',$points);
  861. if($r){
  862. $data = [];
  863. $data['user_id'] = $GLOBALS['user']['user_pid_3'];
  864. $data['plog_type'] = 6;
  865. $data['plog_points'] = $points;
  866. $data['plog_remarks'] = lang('model/user/reward_tip',[$GLOBALS['user']['user_id'],$GLOBALS['user']['user_name'],$fee_points,$points]);
  867. model('Plog')->saveData($data);
  868. }
  869. }
  870. }
  871. }
  872. return ['code'=>1,'msg'=>lang('model/user/reward_ok')];
  873. }
  874. }