User.php 37 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002
  1. <?php
  2. namespace app\common\model;
  3. use think\Db;
  4. use think\View;
  5. use app\common\validate\User as UserValidate;
  6. class User extends Base
  7. {
  8. // 设置数据表(不含前缀)
  9. protected $name = 'user';
  10. // 定义时间戳字段名
  11. protected $createTime = '';
  12. protected $updateTime = '';
  13. // 自动完成
  14. protected $auto = [];
  15. protected $insert = [];
  16. protected $update = [];
  17. public $_guest_group = 1;
  18. public $_def_group = 2;
  19. public function countData($where)
  20. {
  21. $total = $this->where($where)->count();
  22. return $total;
  23. }
  24. public function listData($where, $order, $page = 1, $limit = 20, $start = 0)
  25. {
  26. $page = $page > 0 ? (int)$page : 1;
  27. $limit = $limit ? (int)$limit : 20;
  28. $start = $start ? (int)$start : 0;
  29. $total = $this->where($where)->count();
  30. $list = Db::name('User')->where($where)->order($order)->page($page)->limit($limit)->select();
  31. return ['code' => 1, 'msg' => lang('data_list'), 'page' => $page, 'pagecount' => ceil($total / $limit), 'limit' => $limit, 'total' => $total, 'list' => $list];
  32. }
  33. public function infoData($where, $field='*')
  34. {
  35. if (empty($where) || !is_array($where)) {
  36. return ['code' => 1001, 'msg'=>lang('param_err')];
  37. }
  38. $info = $this->field($field)->where($where)->find();
  39. if (empty($info)) {
  40. return ['code' => 1002, 'msg' => lang('obtain_err')];
  41. }
  42. $info = $info->toArray();
  43. //用户组
  44. $group_list = model('Group')->getCache('group_list');
  45. $group_ids = explode(',', $info['group_id']);
  46. $info['group'] = $group_list[$group_ids[0]];
  47. $info['groups'] = [];
  48. foreach($group_ids as $gid){
  49. if(isset($group_list[$gid])){
  50. $info['groups'][] = $group_list[$gid];
  51. }
  52. }
  53. $info['user_pwd'] = '';
  54. return ['code' => 1, 'msg' =>lang('obtain_ok'), 'info' => $info];
  55. }
  56. public function saveData($data)
  57. {
  58. $validate = \think\Loader::validate('User');
  59. if (isset($data['user_start_time']) && !is_numeric($data['user_start_time'])) {
  60. $data['user_start_time'] = strtotime($data['user_start_time']);
  61. }
  62. if (isset($data['user_end_time']) && !is_numeric($data['user_end_time'])) {
  63. $data['user_end_time'] = strtotime($data['user_end_time']);
  64. }
  65. if (!empty($data['user_id'])) {
  66. if (!$validate->scene('edit')->check($data)) {
  67. return ['code' => 1001, 'msg' => lang('param_err').':' . $validate->getError()];
  68. }
  69. if (empty($data['user_pwd'])) {
  70. unset($data['user_pwd']);
  71. } else {
  72. $data['user_pwd'] = md5($data['user_pwd']);
  73. }
  74. $where = [];
  75. $where['user_id'] = ['eq', $data['user_id']];
  76. $res = $this->where($where)->update($data);
  77. } else {
  78. if (!$validate->scene('edit')->check($data)) {
  79. return ['code' => 1002, 'msg' => lang('param_err').':' . $validate->getError()];
  80. }
  81. $data['user_pwd'] = md5($data['user_pwd']);
  82. $res = $this->insert($data);
  83. }
  84. if (false === $res) {
  85. return ['code' => 1003, 'msg' => '' . $this->getError()];
  86. }
  87. return ['code' => 1, 'msg' =>lang('save_ok')];
  88. }
  89. public function delData($where)
  90. {
  91. $res = $this->where($where)->delete();
  92. if ($res === false) {
  93. return ['code' => 1001, 'msg' => lang('del_err').':' . $this->getError()];
  94. }
  95. return ['code' => 1, 'msg'=>lang('del_ok')];
  96. }
  97. public function fieldData($where, $col, $val)
  98. {
  99. if (!isset($col) || !isset($val)) {
  100. return ['code' => 1001, 'msg'=>lang('param_err')];
  101. }
  102. $data = [];
  103. $data[$col] = $val;
  104. $res = $this->where($where)->update($data);
  105. if ($res === false) {
  106. return ['code' => 1002, 'msg' => lang('set_err').':' . $this->getError()];
  107. }
  108. return ['code' => 1, 'msg' =>lang('set_ok')];
  109. }
  110. public function register($param)
  111. {
  112. $config = config('maccms');
  113. $data = [];
  114. $password_raw = trim($param['user_pwd']);
  115. $data['user_name'] = htmlspecialchars(urldecode(trim($param['user_name'])));
  116. $data['user_pwd'] = htmlspecialchars(urldecode(trim($param['user_pwd'])));
  117. $data['user_pwd2'] = htmlspecialchars(urldecode(trim($param['user_pwd2'])));
  118. $data['verify'] = $param['verify'];
  119. $uid = $param['uid'];
  120. $is_from_3rdparty = !empty($param['user_openid_qq']) || !empty($param['user_openid_weixin']);
  121. if ($config['user']['status'] == 0 || $config['user']['reg_open'] == 0) {
  122. return ['code' => 1001, 'msg' => lang('model/user/not_open_reg')];
  123. }
  124. if (empty($data['user_name']) || empty($data['user_pwd']) || empty($data['user_pwd2'])) {
  125. return ['code' => 1002, 'msg' => lang('model/user/input_require')];
  126. }
  127. if (!$is_from_3rdparty && !captcha_check($data['verify']) && $config['user']['reg_verify'] == 1) {
  128. return ['code' => 1003, 'msg' => lang('verify_err')];
  129. }
  130. if ($data['user_pwd'] != $data['user_pwd2']) {
  131. return ['code' => 1004, 'msg' => lang('model/user/pass_not_pass2')];
  132. }
  133. $row = $this->where('user_name', $data['user_name'])->find();
  134. if (!empty($row)) {
  135. return ['code' => 1005, 'msg' => lang('model/user/haved_reg')];
  136. }
  137. if (!preg_match("/^[a-zA-Z\d]*$/i", $data['user_name'])) {
  138. return ['code' => 1006, 'msg' => lang('model/user/name_contain')];
  139. }
  140. $validate = \think\Loader::validate('User');
  141. if (!$validate->scene('add')->check($data)) {
  142. return ['code' => 1007, 'msg' => lang('param_err').':' . $validate->getError()];
  143. }
  144. $filter = $GLOBALS['config']['user']['filter_words'];
  145. if(!empty($filter)) {
  146. $filter_arr = explode(',', $filter);
  147. $f_name = str_replace($filter_arr, '', $data['user_name']);
  148. if ($f_name != $data['user_name']) {
  149. return ['code' => 1008, 'msg' =>lang('model/user/name_filter',[$filter])];
  150. }
  151. }
  152. $ip = mac_get_ip_long();
  153. if( $GLOBALS['config']['user']['reg_num'] > 0){
  154. $where2=[];
  155. $where2['user_reg_ip'] = ['eq', $ip];
  156. $where2['user_reg_time'] = ['gt', strtotime('today')];
  157. $cc = $this->where($where2)->count();
  158. if($cc >= $GLOBALS['config']['user']['reg_num']){
  159. return ['code' => 1009, 'msg' => lang('model/user/ip_limit',[$GLOBALS['config']['user']['reg_num']])];
  160. }
  161. }
  162. $fields = [];
  163. $fields['user_name'] = $data['user_name'];
  164. $fields['user_pwd'] = md5($password_raw);
  165. $fields['group_id'] = $this->_def_group;
  166. $fields['user_points'] = intval($config['user']['reg_points']);
  167. $fields['user_status'] = intval($config['user']['reg_status']);
  168. $fields['user_reg_time'] = time();
  169. $fields['user_reg_ip'] = $ip;
  170. $fields['user_openid_qq'] = (string)$param['user_openid_qq'];
  171. $fields['user_openid_weixin'] = (string)$param['user_openid_weixin'];
  172. if (!$is_from_3rdparty) {
  173. // https://github.com/magicblack/maccms10/issues/418
  174. if($config['user']['reg_phone_sms'] == '1'){
  175. $param['type'] = 3;
  176. $res = $this->check_msg($param);
  177. if($res['code'] >1){
  178. return $res;
  179. }
  180. $fields['user_phone'] = $param['to'];
  181. $update=[];
  182. $update['user_phone'] = '';
  183. $where2=[];
  184. $where2['user_phone'] = $param['to'];
  185. $row = $this->where($where2)->find();
  186. if (!empty($row)) {
  187. return ['code' => 1011, 'msg' =>lang('model/user/phone_haved')];
  188. }
  189. //$this->where($where2)->update($update);
  190. }
  191. elseif($config['user']['reg_email_sms'] == '1'){
  192. $param['type'] = 3;
  193. $res = $this->check_msg($param);
  194. if($res['code'] >1){
  195. return $res;
  196. }
  197. $fields['user_email'] = $param['to'];
  198. $update=[];
  199. $update['user_email'] = '';
  200. $where2=[];
  201. $where2['user_email'] = $param['to'];
  202. $row = $this->where($where2)->find();
  203. if (!empty($row)) {
  204. return ['code' => 1012, 'msg' => lang('model/user/email_haved')];
  205. }
  206. //$this->where($where2)->update($update);
  207. }
  208. }
  209. $res = $this->insert($fields);
  210. if ($res === false) {
  211. return ['code' => 1010, 'msg' => lang('model/user/reg_err')];
  212. }
  213. $nid = $this->getLastInsID();
  214. $uid = intval($uid);
  215. if($uid > 0) {
  216. $where2 = [];
  217. $where2['user_id'] = $uid;
  218. $invite = $this->where($where2)->find();
  219. if ($invite) {
  220. $where=[];
  221. $where['user_id'] = $nid;
  222. $update=[];
  223. $update['user_pid'] = $invite['user_id'];
  224. $update['user_pid_2'] = $invite['user_pid'];
  225. $update['user_pid_3'] = $invite['user_pid_2'];
  226. $r1 = $this->where($where)->update($update);
  227. $r2 = false;
  228. $config['user']['invite_reg_num'] = intval($config['user']['invite_reg_num']);
  229. if($config['user']['invite_reg_points']>0){
  230. $r2 = $this->where($where2)->setInc('user_points', $config['user']['invite_reg_points']);
  231. }
  232. if($r2!==false) {
  233. //积分日志
  234. $data = [];
  235. $data['user_id'] = $uid;
  236. $data['plog_type'] = 2;
  237. $data['plog_points'] = $config['user']['invite_reg_points'];
  238. model('Plog')->saveData($data);
  239. }
  240. }
  241. }
  242. return ['code' => 1, 'msg' => lang('model/user/reg_ok')];
  243. }
  244. public function regcheck($t, $str)
  245. {
  246. $where = [];
  247. if ($t == 'user_name') {
  248. $where['user_name'] = $str;
  249. $row = $this->where($where)->find();
  250. if (!empty($row)) {
  251. return ['code' => 1001, 'msg' => lang('registered')];
  252. }
  253. } elseif ($t == 'user_email') {
  254. $where['user_email'] = $str;
  255. $row = $this->where($where)->find();
  256. if (!empty($row)) {
  257. return ['code' => 1001, 'msg' => lang('registered')];
  258. }
  259. } elseif ($t == 'verify') {
  260. if (!captcha_check($str)) {
  261. return ['code' => 1002, 'msg' => lang('verify_err')];
  262. }
  263. }
  264. return ['code' => 1, 'msg' => 'ok'];
  265. }
  266. public function info($param)
  267. {
  268. if (empty($param['user_pwd'])) {
  269. return ['code' => 1001, 'msg' => lang('model/user/input_old_pass')];
  270. }
  271. $password_raw = trim($param['user_pwd']);
  272. $password_formatted = htmlspecialchars(urldecode(trim($param['user_pwd'])));
  273. if (!in_array($GLOBALS['user']['user_pwd'], [md5($password_raw), md5($password_formatted)])) {
  274. return ['code' => 1002, 'msg' => lang('model/user/old_pass_err')];
  275. }
  276. if ($param['user_pwd1'] != $param['user_pwd2']) {
  277. return ['code' => 1003, 'msg' => lang('model/user/pass_not_same_pass2')];
  278. }
  279. $data = [];
  280. $data['user_id'] = $GLOBALS['user']['user_id'];
  281. $data['user_name'] = $GLOBALS['user']['user_name'];
  282. if(!empty($param['user_nick_name'])){
  283. $data['user_nick_name'] = htmlspecialchars(urldecode(trim($param['user_nick_name'])));
  284. }
  285. $data['user_qq'] = htmlspecialchars(urldecode(trim($param['user_qq'])));
  286. $data['user_question'] = htmlspecialchars(urldecode(trim($param['user_question'])));
  287. $data['user_answer'] = htmlspecialchars(urldecode(trim($param['user_answer'])));
  288. if (!empty($param['user_pwd2'])) {
  289. $data['user_pwd'] = trim($param['user_pwd2']);
  290. }
  291. return $this->saveData($data);
  292. }
  293. public function login($param)
  294. {
  295. $data = [];
  296. $password_raw = trim($param['user_pwd']);
  297. $data['user_name'] = htmlspecialchars(urldecode(trim($param['user_name'])));
  298. $data['user_pwd'] = htmlspecialchars(urldecode(trim($param['user_pwd'])));
  299. $data['verify'] = $param['verify'];
  300. $data['openid'] = htmlspecialchars(urldecode(trim($param['openid'])));
  301. $data['col'] = htmlspecialchars(urldecode(trim($param['col'])));
  302. if (empty($data['openid'])) {
  303. if (empty($data['user_name']) || empty($data['user_pwd'])) {
  304. return ['code' => 1001, 'msg' => lang('model/user/input_require')];
  305. }
  306. if ($GLOBALS['config']['user']['login_verify'] ==1 && !captcha_check($data['verify'])) {
  307. return ['code' => 1002, 'msg' => lang('verify_err')];
  308. }
  309. $where = [];
  310. $pattern = '/\w+([-+.]\w+)*@\w+([-.]\w+)*\.\w+([-.]\w+)*/';
  311. if (!preg_match($pattern, $data['user_name'])) {
  312. $where['user_name'] = ['eq', $data['user_name']];
  313. } else {
  314. $where['user_email'] = ['eq', $data['user_name']];
  315. }
  316. // https://github.com/magicblack/maccms10/issues/781 兼容密码
  317. $where['user_pwd'] = [['eq', md5($password_raw)], ['eq', $data['user_pwd']], 'or'];
  318. } else {
  319. if (empty($data['openid']) || empty($data['col'])) {
  320. return ['code' => 1001, 'msg' => lang('model/user/input_require')];
  321. }
  322. if (!in_array($data['col'], ['user_openid_qq', 'user_openid_weixin'])) {
  323. return ['code' => 1002, 'msg' => lang('param_err') . ': col'];
  324. }
  325. $where[$data['col']] = $data['openid'];
  326. }
  327. $where['user_status'] = ['eq', 1];
  328. $row = $this->where($where)->find();
  329. if(empty($row)) {
  330. return ['code' => 1003, 'msg' => lang('model/user/not_found')];
  331. }
  332. $login_group_ids = explode(',', $row['group_id']);
  333. if(max($login_group_ids) > 2 && $row['user_end_time'] < time()) {
  334. $row['group_id'] = 2;
  335. $update['group_id'] = 2;
  336. }
  337. $random = md5(rand(10000000, 99999999));
  338. $update['user_random'] = $random;
  339. $update['user_login_ip'] = mac_get_ip_long();
  340. $update['user_login_time'] = time();
  341. $update['user_login_num'] = $row['user_login_num'] + 1;
  342. $update['user_last_login_time'] = $row['user_login_time'];
  343. $update['user_last_login_ip'] = $row['user_login_ip'];
  344. $res = $this->where($where)->update($update);
  345. if ($res === false) {
  346. return ['code' => 1004, 'msg' => lang('model/user/update_login_err')];
  347. }
  348. //用户组
  349. $group_list = model('Group')->getCache('group_list');
  350. $group_ids = explode(',', $row['group_id']);
  351. $group = [];
  352. foreach($group_ids as $gid){
  353. if(isset($group_list[$gid])){
  354. $group[] = $group_list[$gid];
  355. }
  356. }
  357. cookie('user_id', $row['user_id'],['expire'=>2592000] );
  358. cookie('user_name', $row['user_name'],['expire'=>2592000] );
  359. cookie('group_id', $group[0]['group_id'],['expire'=>2592000] );
  360. cookie('group_name', $group[0]['group_name'],['expire'=>2592000] );
  361. cookie('user_check', md5($random . '-' .$row['user_name'] . '-' . $row['user_id'] .'-' ),['expire'=>2592000] );
  362. cookie('user_portrait', mac_get_user_portrait($row['user_id']),['expire'=>2592000] );
  363. return ['code' => 1, 'msg' => lang('model/user/login_ok')];
  364. }
  365. public function expire()
  366. {
  367. $where=[];
  368. $where['user_end_time'] = ['elt',time()];
  369. $update=[];
  370. $update['group_id'] = '2';
  371. $res = $this->where($where)->update($update);
  372. if ($res === false) {
  373. return ['code' => 101, 'msg' => lang('model/user/update_expire_err')];
  374. }
  375. return ['code' => 1, 'msg' => lang('model/user/update_expire_ok')];
  376. }
  377. public function logout()
  378. {
  379. cookie('user_id', null);
  380. cookie('user_name', null);
  381. cookie('group_id', null);
  382. cookie('group_name', null);
  383. cookie('user_check', null);
  384. cookie('user_portrait', null);
  385. return ['code' => 1, 'msg' =>lang('model/user/logout_ok')];
  386. }
  387. public function checkLogin()
  388. {
  389. $user_id = cookie('user_id');
  390. $user_name = cookie('user_name');
  391. $user_check = cookie('user_check');
  392. $user_id = htmlspecialchars(urldecode(trim($user_id)));
  393. $user_name = htmlspecialchars(urldecode(trim($user_name)));
  394. $user_check = htmlspecialchars(urldecode(trim($user_check)));
  395. if (empty($user_id) || empty($user_name) || empty($user_check)) {
  396. return ['code' => 1001, 'msg' => lang('model/user/not_login')];
  397. }
  398. $where = [];
  399. $where['user_id'] = $user_id;
  400. $where['user_name'] = $user_name;
  401. $where['user_status'] = 1;
  402. $info = $this->field('*')->where($where)->find();
  403. if(empty($info)) {
  404. return ['code' => 1002, 'msg' => lang('model/user/not_login')];
  405. }
  406. $info = $info->toArray();
  407. $login_check = md5($info['user_random'] . '-' . $info['user_name']. '-' . $info['user_id'] .'-' );
  408. if($login_check != $user_check) {
  409. return ['code' => 1003, 'msg' => lang('model/user/not_login')];
  410. }
  411. $group_list = model('Group')->getCache('group_list');
  412. $group_ids = explode(',', $info['group_id']);
  413. $user_groups = [];
  414. $user_group_types = [];
  415. foreach($group_ids as $gid){
  416. if(isset($group_list[$gid])){
  417. $user_groups[] = $group_list[$gid];
  418. if (!empty($group_list[$gid]['group_type'])) {
  419. $user_group_types = array_merge($user_group_types, explode(',', $group_list[$gid]['group_type']));
  420. }
  421. }
  422. }
  423. if (!empty($user_groups)) {
  424. $info['group'] = $user_groups[0];
  425. $info['group']['group_type'] = implode(',', array_unique(array_filter($user_group_types)));
  426. $info['groups'] = $user_groups;
  427. $all_names = [];
  428. foreach($user_groups as $g){
  429. $all_names[] = $g['group_name'];
  430. }
  431. $info['group']['group_name'] = implode(',', $all_names);
  432. } else {
  433. $info['group'] = $group_list[1];
  434. }
  435. //会员截止日期
  436. if (max($group_ids) > 2 && $info['user_end_time'] < time()) {
  437. //用户组
  438. $info['group'] = $group_list[2];
  439. $update = [];
  440. $update['group_id'] = 2;
  441. $res = $this->where($where)->update($update);
  442. if($res === false){
  443. return ['code' => 1004, 'msg' => lang('model/user/update_expire_err')];
  444. }
  445. $info['group_id'] = 2;
  446. $info['groups'] = [$group_list[2]];
  447. cookie('group_id', $info['group']['group_id'], ['expire'=>2592000] );
  448. cookie('group_name', $info['group']['group_name'],['expire'=>2592000] );
  449. }
  450. return ['code' => 1, 'msg' => lang('model/user/haved_login'), 'info' => $info];
  451. }
  452. public function resetPwd()
  453. {
  454. }
  455. public function findpass($param)
  456. {
  457. $data = [];
  458. $password_raw = trim($param['user_pwd']);
  459. $data['user_name'] = htmlspecialchars(urldecode(trim($param['user_name'])));
  460. $data['user_question'] = htmlspecialchars(urldecode(trim($param['user_question'])));
  461. $data['user_answer'] = htmlspecialchars(urldecode(trim($param['user_answer'])));
  462. $data['user_pwd'] = htmlspecialchars(urldecode(trim($param['user_pwd'])));
  463. $data['user_pwd2'] = htmlspecialchars(urldecode(trim($param['user_pwd2'])));
  464. $data['verify'] = $param['verify'];
  465. if (empty($data['user_name']) || empty($data['user_question']) || empty($data['user_answer']) || empty($data['user_pwd']) || empty($data['user_pwd2']) || empty($data['verify'])) {
  466. return ['code' => 1001, 'msg' => lang('param_err')];
  467. }
  468. if (!captcha_check($data['verify'])) {
  469. return ['code' => 1002, 'msg' => lang('verify_err')];
  470. }
  471. if ($data['user_pwd'] != $data['user_pwd2']) {
  472. return ['code' => 1003, 'msg' => lang('model/user/pass_not_same_pass2')];
  473. }
  474. $where = [];
  475. $where['user_name'] = $data['user_name'];
  476. $where['user_question'] = $data['user_question'];
  477. $where['user_answer'] = $data['user_answer'];
  478. $info = $this->where($where)->find();
  479. if (empty($info)) {
  480. return ['code' => 1004, 'msg' => lang('model/user/findpass_not_found')];
  481. }
  482. $update = [];
  483. $update['user_pwd'] = md5($password_raw);
  484. $where = [];
  485. $where['user_id'] = $info['user_id'];
  486. $res = $this->where($where)->update($update);
  487. if (false === $res) {
  488. return ['code' => 1005, 'msg' => '' . $this->getError()];
  489. }
  490. return ['code' => 1, 'msg' => lang('model/user/findpass_ok')];
  491. }
  492. public function popedom($type_id, $popedom, $group_ids = 1)
  493. {
  494. $group_list = model('Group')->getCache();
  495. $group_ids = explode(',', $group_ids);
  496. foreach($group_ids as $group_id) {
  497. if(!isset($group_list[$group_id])) {
  498. continue;
  499. }
  500. $group_info = $group_list[$group_id];
  501. if (strpos(',' . $group_info['group_type'], ',' . $type_id . ',') !== false && !empty($group_info['group_popedom'][$type_id][$popedom]) !== false) {
  502. return true;
  503. }
  504. }
  505. return false;
  506. }
  507. public function upgrade($param)
  508. {
  509. $group_id = intval($param['group_id']);
  510. $long = $param['long'];
  511. $points_long = ['day'=>86400,'week'=>86400*7,'month'=>86400*30,'year'=>86400*365];
  512. if (!array_key_exists($long, $points_long)) {
  513. return ['code'=>1001,'msg'=>'非法操作'];
  514. }
  515. if($group_id <3){
  516. return ['code'=>1002,'msg'=>lang('model/user/select_diy_group_err')];
  517. }
  518. $group_list = model('Group')->getCache();
  519. $group_info = $group_list[$group_id];
  520. if(empty($group_info)){
  521. return ['code'=>1003,'msg'=>lang('model/user/group_not_found')];
  522. }
  523. if($group_info['group_status'] == 0){
  524. return ['code'=>1004,'msg'=>lang('model/user/group_is_close')];
  525. }
  526. $point = $group_info['group_points_'.$long];
  527. if($GLOBALS['user']['user_points'] < $point){
  528. return ['code'=>1005,'msg'=>lang('model/user/potins_not_enough')];
  529. }
  530. $sj = $points_long[$long];
  531. $end_time = time() + $sj;
  532. if($GLOBALS['user']['user_end_time'] > time() ){
  533. $end_time = $GLOBALS['user']['user_end_time'] + $sj;
  534. }
  535. $where = [];
  536. $where['user_id'] = $GLOBALS['user']['user_id'];
  537. $data = [];
  538. $data['user_points'] = $GLOBALS['user']['user_points'] - $point;
  539. $data['user_end_time'] = $end_time;
  540. $data['group_id'] = $group_id;
  541. $res = $this->where($where)->update($data);
  542. if($res===false){
  543. return ['code'=>1009,'msg'=>lang('model/user/update_group_err')];
  544. }
  545. //积分日志
  546. $data = [];
  547. $data['user_id'] = $GLOBALS['user']['user_id'];
  548. $data['plog_type'] = 7;
  549. $data['plog_points'] = $point;
  550. model('Plog')->saveData($data);
  551. //分销日志
  552. $this->reward($point);
  553. cookie('group_id', $group_info['group_id'],['expire'=>2592000] );
  554. cookie('group_name', $group_info['group_name'],['expire'=>2592000] );
  555. return ['code'=>1,'msg'=>lang('model/user/update_group_ok')];
  556. }
  557. public function check_msg($param)
  558. {
  559. $param['to'] = htmlspecialchars(urldecode(trim($param['to'])));
  560. $param['code'] = htmlspecialchars(urldecode(trim($param['code'])));
  561. if(!in_array($param['ac'],['email','phone']) || empty($param['to']) || empty($param['code']) || empty($param['type'])){
  562. return ['code'=>9001,'msg'=>lang('param_err')];
  563. }
  564. // https://github.com/magicblack/maccms10/issues/792 邮箱增加黑白名单校验
  565. if ($param['ac'] == 'email' && in_array($param['type'], [1, 3])) {
  566. $result = UserValidate::validateEmail($param['to']);
  567. if ($result['code'] > 1) {
  568. return $result;
  569. }
  570. }
  571. //msg_type 1绑定2找回3注册
  572. $stime = strtotime('-5 min');
  573. if($param['ac']=='email' && intval($GLOBALS['config']['email']['time'])>0){
  574. $stime = strtotime('-'.$GLOBALS['config']['email']['time'].' min');
  575. }
  576. $where=[];
  577. $where['user_id'] = intval($GLOBALS['user']['user_id']);
  578. $where['msg_time'] = ['gt',$stime];
  579. $where['msg_code'] = ['eq',$param['code']];
  580. $where['msg_type'] = ['eq', $param['type'] ];
  581. $res = model('msg')->infoData($where);
  582. if($res['code'] >1){
  583. return ['code'=>9002,'msg'=>lang('model/user/msg_not_found')];
  584. }
  585. return ['code'=>1,'msg'=>'ok'];
  586. }
  587. public function send_msg($param)
  588. {
  589. $param['to'] = htmlspecialchars(urldecode(trim($param['to'])));
  590. $param['code'] = htmlspecialchars(urldecode(trim($param['code'])));
  591. $type_arr = [
  592. 1=>['des'=>lang('bind'),'flag'=>'bind'],
  593. 2=>['des'=>lang('findpass'),'flag'=>'findpass'],
  594. 3=>['des'=>lang('register'),'flag'=>'reg'],
  595. ];
  596. if(!in_array($param['ac'],['email','phone']) || !isset($type_arr[$param['type']]) || empty($param['to']) || empty($param['type'])){
  597. return ['code'=>9001,'msg'=>lang('param_err')];
  598. }
  599. // https://github.com/magicblack/maccms10/issues/792 邮箱增加黑白名单校验
  600. if ($param['ac'] == 'email' && in_array($param['type'], [1, 3])) {
  601. $result = UserValidate::validateEmail($param['to']);
  602. if ($result['code'] > 1) {
  603. return $result;
  604. }
  605. }
  606. $type_des = $type_arr[$param['type']]['des'];
  607. $type_flag = $type_arr[$param['type']]['flag'];
  608. $to = $param['to'];
  609. $code = mac_get_rndstr(6,'num');
  610. $r=0;
  611. $stime = strtotime('-5 min');
  612. if($param['ac']=='email' && intval($GLOBALS['config']['email']['time'])>0){
  613. $stime = strtotime('-'.$GLOBALS['config']['email']['time'].' min');
  614. }
  615. $where=[];
  616. $where['user_id'] = intval($GLOBALS['user']['user_id']);
  617. $where['msg_time'] = ['gt',$stime];
  618. $where['msg_type'] = ['eq', $param['type'] ];
  619. $where['msg_to'] = ['eq', $param['to'] ];
  620. $res = model('msg')->infoData($where);
  621. if($res['code'] ==1){
  622. return ['code'=>9002,'msg'=>lang('model/user/do_not_send_frequently')];
  623. }
  624. $res_msg= ','.lang('please_try_again');
  625. if($param['ac']=='email'){
  626. $title = $GLOBALS['config']['email']['tpl']['user_'.$type_flag.'_title'];
  627. $msg = $GLOBALS['config']['email']['tpl']['user_'.$type_flag.'_body'];
  628. View::instance()->assign(['code'=>$code,'time'=>$GLOBALS['config']['email']['time']]);
  629. $title = View::instance()->display($title);
  630. $msg = View::instance()->display($msg);
  631. $msg = htmlspecialchars_decode($msg);
  632. $res_send = mac_send_mail($to, $title, $msg);
  633. $res_code = $res_send['code'];
  634. $res_msg = $res_send['msg'];
  635. }
  636. else{
  637. $msg = $GLOBALS['config']['sms']['content'];
  638. $msg = str_replace(['[用户]','[类型]','[时长]','[验证码]'],[$GLOBALS['user']['user_name'],$type_des,'5',$code],$msg);
  639. $res_send = mac_send_sms($to,$code,$type_flag,$type_des,$msg);
  640. $res_code = $res_send['code'];
  641. $res_msg = $res_send['msg'];
  642. }
  643. if($res_code==1){
  644. $data=[];
  645. $data['user_id'] = intval($GLOBALS['user']['user_id']);
  646. $data['msg_type'] = $param['type'];
  647. $data['msg_status'] = 0;
  648. $data['msg_to'] = $to;
  649. $data['msg_code'] = $code;
  650. $data['msg_content'] = $msg;
  651. $data['msg_time'] = time();
  652. $res = model('msg')->saveData($data);
  653. return ['code'=>1,'msg'=>lang('model/user/msg_send_ok')];
  654. }
  655. else{
  656. return ['code'=>9009,'msg'=>lang('model/user/msg_send_err').':'.$res_msg];
  657. }
  658. }
  659. public function bind($param)
  660. {
  661. $param['type'] = 1;
  662. $res = $this->check_msg($param);
  663. if($res['code'] >1){
  664. return ['code'=>$res['code'],'msg'=>$res['msg']];
  665. }
  666. $update=[];
  667. $update2=[];
  668. $where2=[];
  669. if($param['ac']=='email') {
  670. $update['user_email'] = $param['to'];
  671. $update2['user_email'] = '';
  672. $where2['user_email'] = $param['to'];
  673. }
  674. else{
  675. $update['user_phone'] = $param['to'];
  676. $update2['user_phone'] = '';
  677. $where2['user_phone'] = $param['to'];
  678. }
  679. $this->where($where2)->update($update2);
  680. $where=[];
  681. $where['user_id'] = $GLOBALS['user']['user_id'];
  682. $res = $this->where($where)->update($update);
  683. if($res===false){
  684. return ['code'=>2003,'msg'=>lang('model/user/update_bind_err')];
  685. }
  686. return ['code'=>1,'msg'=>lang('model/user/update_bind_ok')];
  687. }
  688. public function unbind($param)
  689. {
  690. if(!in_array($param['ac'],['email','phone']) ){
  691. return ['code'=>2001,'msg'=>lang('param_err')];
  692. }
  693. $col = 'user_email';
  694. if($param['ac']=='phone'){
  695. $col = 'user_phone';
  696. }
  697. $update=[];
  698. $update[$col] = '';
  699. $where=[];
  700. $where['user_id'] = $GLOBALS['user']['user_id'];
  701. $res = $this->where($where)->update($update);
  702. if($res===false){
  703. return ['code'=>2002,'msg'=>lang('model/user/update_bind_err')];
  704. }
  705. return ['code'=>1,'msg'=>lang('model/user/update_unbind_ok')];
  706. }
  707. public function bindmsg($param)
  708. {
  709. $param['type'] = 1;
  710. return $this->send_msg($param);
  711. }
  712. public function findpass_msg($param)
  713. {
  714. $param['type'] = 2;
  715. return $this->send_msg($param);
  716. }
  717. public function reg_msg($param)
  718. {
  719. $param['type'] = 3;
  720. return $this->send_msg($param);
  721. }
  722. public function findpass_reset($param)
  723. {
  724. $to = htmlspecialchars(urldecode(trim($param['user_email'])));
  725. if(empty($to)){
  726. $to = htmlspecialchars(urldecode(trim($param['to'])));
  727. }
  728. $password_raw = trim($param['user_pwd']);
  729. $param['code'] = htmlspecialchars(urldecode(trim($param['code'])));
  730. $param['user_pwd'] = htmlspecialchars(urldecode(trim($param['user_pwd'])));
  731. $param['user_pwd2'] = htmlspecialchars(urldecode(trim($param['user_pwd2'])));
  732. if (strlen($param['user_pwd']) < 6) {
  733. return ['code' => 2002, 'msg' => lang('model/user/pass_length_err')];
  734. }
  735. if ($param['user_pwd'] != $param['user_pwd2']) {
  736. return ['code' => 2003, 'msg' => lang('model/user/pass_not_same_pass2')];
  737. }
  738. $param['type'] = 2;
  739. $res = $this->check_msg($param);
  740. if($res['code'] >1){
  741. return ['code'=>$res['code'],'msg'=>$res['msg']];
  742. }
  743. if($param['ac']=='email') {
  744. $pattern = '/\w+([-+.]\w+)*@\w+([-.]\w+)*\.\w+([-.]\w+)*/';
  745. if(!preg_match( $pattern, $to)){
  746. return ['code'=>2005,'msg'=>lang('model/user/email_format_err')];
  747. }
  748. $where = [];
  749. $where['user_email'] = $to;
  750. $user = $this->where($where)->find();
  751. if (!$user) {
  752. return ['code' => 2006, 'msg' => lang('model/user/email_err')];
  753. }
  754. }
  755. else{
  756. $pattern = "/^1{1}\d{10}$/";
  757. if(!preg_match($pattern,$to)){
  758. return ['code'=>2007,'msg'=>lang('model/user/phone_format_err')];
  759. }
  760. $where = [];
  761. $where['user_phone'] = $to;
  762. $user = $this->where($where)->find();
  763. if (!$user) {
  764. return ['code' => 2008, 'msg' =>lang('model/user/phone_err')];
  765. }
  766. }
  767. $update = [];
  768. $update['user_pwd'] = md5($password_raw);
  769. $res = $this->where($where)->update($update);
  770. if($res===false){
  771. return ['code'=>2009,'msg'=>lang('model/user/pass_reset_err')];
  772. }
  773. return ['code'=>1,'msg'=>lang('model/user/pass_reset_ok')];
  774. }
  775. public function visit($param)
  776. {
  777. $param['uid'] = abs(intval($param['uid']));
  778. if ($param['uid'] == 0) {
  779. return ['code' => 101, 'msg' =>lang('model/user/id_err')];
  780. }
  781. $ip = mac_get_ip_long();
  782. $max_cc = $GLOBALS['config']['user']['invite_visit_num'];
  783. if(empty($max_cc)){
  784. $max_cc=1;
  785. }
  786. $todayunix = strtotime("today");
  787. $where = [];
  788. $where['user_id'] = $param['uid'];
  789. $where['visit_ip'] = $ip;
  790. $where['visit_time'] = ['gt', $todayunix];
  791. $cc = model('visit')->where($where)->count();
  792. if ($cc>= $max_cc){
  793. return ['code' => 102, 'msg' => lang('model/user/visit_tip')];
  794. }
  795. $data = [];
  796. $data['user_id'] = $param['uid'];
  797. $data['visit_ip'] = $ip;
  798. $data['visit_time'] = time();
  799. $data['visit_ly'] = htmlspecialchars(mac_get_refer());
  800. $res = model('visit')->saveData($data);
  801. if ($res['code'] > 1) {
  802. return ['code' => 103, 'msg' => lang('model/user/visit_err')];
  803. }
  804. $res = $this->where('user_id', $param['uid'])->setInc('user_points', intval($GLOBALS['config']['user']['invite_visit_points']));
  805. if($res) {
  806. //积分日志
  807. $data = [];
  808. $data['user_id'] = $param['uid'];
  809. $data['plog_type'] = 3;
  810. $data['plog_points'] = intval($GLOBALS['config']['user']['invite_visit_points']);
  811. model('Plog')->saveData($data);
  812. }
  813. return ['code'=>1,'msg'=>lang('model/user/visit_ok')];
  814. }
  815. public function reward($fee_points=0)
  816. {
  817. //三级分销
  818. if($fee_points>0 && $GLOBALS['config']['user']['reward_status'] == '1'){
  819. if(!empty($GLOBALS['config']['user']['reward_ratio']) && !empty($GLOBALS['user']['user_pid'])){
  820. $points = floor($fee_points / 100 * $GLOBALS['config']['user']['reward_ratio']);
  821. if($points>0){
  822. $where=[];
  823. $where['user_id'] = $GLOBALS['user']['user_pid'];
  824. $r = model('User')->where($where)->setInc('user_points',$points);
  825. if($r){
  826. $data = [];
  827. $data['user_id'] = $GLOBALS['user']['user_pid'];
  828. $data['plog_type'] = 4;
  829. $data['plog_points'] = $points;
  830. $data['plog_remarks'] = lang('model/user/reward_tip',[$GLOBALS['user']['user_id'],$GLOBALS['user']['user_name'],$fee_points,$points]);
  831. model('Plog')->saveData($data);
  832. }
  833. }
  834. }
  835. if(!empty($GLOBALS['config']['user']['reward_ratio_2']) && !empty($GLOBALS['user']['user_pid_2'])){
  836. $points = floor($fee_points / 100 * $GLOBALS['config']['user']['reward_ratio_2']);
  837. if($points>0){
  838. $where=[];
  839. $where['user_id'] = $GLOBALS['user']['user_pid_2'];
  840. $r = model('User')->where($where)->setInc('user_points',$points);
  841. if($r){
  842. $data = [];
  843. $data['user_id'] = $GLOBALS['user']['user_pid_2'];
  844. $data['plog_type'] = 5;
  845. $data['plog_points'] = $points;
  846. $data['plog_remarks'] =lang('model/user/reward_tip',[$GLOBALS['user']['user_id'],$GLOBALS['user']['user_name'],$fee_points,$points]);
  847. model('Plog')->saveData($data);
  848. }
  849. }
  850. }
  851. if(!empty($GLOBALS['config']['user']['reward_ratio_3']) && !empty($GLOBALS['user']['user_pid_3'])){
  852. $points = floor($fee_points / 100 * $GLOBALS['config']['user']['reward_ratio_3']);
  853. if($points>0){
  854. $where=[];
  855. $where['user_id'] = $GLOBALS['user']['user_pid_3'];
  856. $r = model('User')->where($where)->setInc('user_points',$points);
  857. if($r){
  858. $data = [];
  859. $data['user_id'] = $GLOBALS['user']['user_pid_3'];
  860. $data['plog_type'] = 6;
  861. $data['plog_points'] = $points;
  862. $data['plog_remarks'] = lang('model/user/reward_tip',[$GLOBALS['user']['user_id'],$GLOBALS['user']['user_name'],$fee_points,$points]);
  863. model('Plog')->saveData($data);
  864. }
  865. }
  866. }
  867. }
  868. return ['code'=>1,'msg'=>lang('model/user/reward_ok')];
  869. }
  870. }