AccountController.go 32 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010101110121013101410151016101710181019102010211022102310241025102610271028102910301031103210331034103510361037103810391040104110421043104410451046104710481049105010511052105310541055105610571058105910601061106210631064
  1. package controllers
  2. import (
  3. "encoding/json"
  4. "fmt"
  5. "html/template"
  6. "math/rand"
  7. "net/url"
  8. "reflect"
  9. "regexp"
  10. "strconv"
  11. "strings"
  12. "time"
  13. "github.com/beego/beego/v2/client/orm"
  14. "github.com/beego/beego/v2/core/logs"
  15. "github.com/beego/beego/v2/server/web"
  16. "github.com/beego/i18n"
  17. "github.com/lifei6671/gocaptcha"
  18. "github.com/mindoc-org/mindoc/conf"
  19. "github.com/mindoc-org/mindoc/mail"
  20. "github.com/mindoc-org/mindoc/models"
  21. "github.com/mindoc-org/mindoc/utils"
  22. "github.com/mindoc-org/mindoc/utils/dingtalk"
  23. "github.com/mindoc-org/mindoc/utils/workweixin"
  24. )
  25. const (
  26. WorkWeixin_AuthorizeUrlBase = "https://open.weixin.qq.com/connect/oauth2/authorize"
  27. WorkWeixin_QRConnectUrlBase = "https://open.work.weixin.qq.com/wwopen/sso/qrConnect"
  28. SessionUserInfoKey = "session-user-info-key"
  29. )
  30. var src = rand.New(rand.NewSource(time.Now().UnixNano()))
  31. // AccountController 用户登录与注册
  32. type AccountController struct {
  33. BaseController
  34. }
  35. func (c *AccountController) referer() string {
  36. u, _ := url.PathUnescape(c.GetString("url"))
  37. if u == "" {
  38. u = conf.URLFor("HomeController.Index")
  39. }
  40. return u
  41. }
  42. func (c *AccountController) IsInWorkWeixin() (is_in_workweixin bool) {
  43. ua := c.Ctx.Input.UserAgent()
  44. var wechatRule = regexp.MustCompile(`\bMicroMessenger\/\d+(\.\d+)*\b`)
  45. var wxworkRule = regexp.MustCompile(`\bwxwork\/\d+(\.\d+)*\b`)
  46. return wechatRule.MatchString(ua) && wxworkRule.MatchString(ua)
  47. }
  48. func (c *AccountController) Prepare() {
  49. c.BaseController.Prepare()
  50. c.EnableXSRF = web.AppConfig.DefaultBool("enablexsrf", true)
  51. c.Data["xsrfdata"] = template.HTML(c.XSRFFormHTML())
  52. c.Data["CanLoginWorkWeixin"] = len(web.AppConfig.DefaultString("workweixin_corpid", "")) > 0
  53. c.Data["corpID"], _ = web.AppConfig.String("dingtalk_corpid")
  54. c.Data["CanLoginDingTalk"] = len(web.AppConfig.DefaultString("dingtalk_corpid", "")) > 0
  55. if reflect.ValueOf(c.Data["CanLoginDingTalk"]).Bool() {
  56. c.Data["ENABLE_QR_DINGTALK"] = true
  57. }
  58. c.Data["dingtalk_qr_key"], _ = web.AppConfig.String("dingtalk_qr_key")
  59. if !c.EnableXSRF {
  60. return
  61. }
  62. if c.Ctx.Input.IsPost() {
  63. token := c.Ctx.Input.Query("_xsrf")
  64. if token == "" {
  65. token = c.Ctx.Request.Header.Get("X-Xsrftoken")
  66. }
  67. if token == "" {
  68. token = c.Ctx.Request.Header.Get("X-Csrftoken")
  69. }
  70. if token == "" {
  71. if c.IsAjax() {
  72. c.JsonResult(403, i18n.Tr(c.Lang, "message.illegal_request"))
  73. } else {
  74. c.ShowErrorPage(403, i18n.Tr(c.Lang, "message.illegal_request"))
  75. }
  76. }
  77. xsrfToken := c.XSRFToken()
  78. if xsrfToken != token {
  79. if c.IsAjax() {
  80. c.JsonResult(403, i18n.Tr(c.Lang, "message.illegal_request"))
  81. } else {
  82. c.ShowErrorPage(403, i18n.Tr(c.Lang, "message.illegal_request"))
  83. }
  84. }
  85. }
  86. }
  87. // Login 用户登录
  88. func (c *AccountController) Login() {
  89. c.Prepare()
  90. c.TplName = "account/login.tpl"
  91. if member, ok := c.GetSession(conf.LoginSessionName).(models.Member); ok && member.MemberId > 0 {
  92. u := c.GetString("url")
  93. if u == "" {
  94. u = c.Ctx.Request.Header.Get("Referer")
  95. }
  96. if u == "" {
  97. u = conf.URLFor("HomeController.Index")
  98. }
  99. c.Redirect(u, 302)
  100. }
  101. var remember CookieRemember
  102. // 如果 Cookie 中存在登录信息
  103. if cookie, ok := c.GetSecureCookie(conf.GetAppKey(), "login"); ok {
  104. if err := utils.Decode(cookie, &remember); err == nil {
  105. if member, err := models.NewMember().Find(remember.MemberId); err == nil {
  106. c.SetMember(*member)
  107. c.LoggedIn(false)
  108. c.StopRun()
  109. }
  110. }
  111. }
  112. if c.Ctx.Input.IsPost() {
  113. account := c.GetString("account")
  114. password := c.GetString("password")
  115. captcha := c.GetString("code")
  116. isRemember := c.GetString("is_remember")
  117. // 如果开启了验证码
  118. if v, ok := c.Option["ENABLED_CAPTCHA"]; ok && strings.EqualFold(v, "true") {
  119. v, ok := c.GetSession(conf.CaptchaSessionName).(string)
  120. if !ok || !strings.EqualFold(v, captcha) {
  121. c.JsonResult(6001, i18n.Tr(c.Lang, "message.captcha_wrong"))
  122. }
  123. }
  124. if account == "" || password == "" {
  125. c.JsonResult(6002, i18n.Tr(c.Lang, "message.account_or_password_empty"))
  126. }
  127. member, err := models.NewMember().Login(account, password)
  128. if err == nil {
  129. member.LastLoginTime = time.Now()
  130. _ = member.Update("last_login_time")
  131. c.SetMember(*member)
  132. if strings.EqualFold(isRemember, "yes") {
  133. remember.MemberId = member.MemberId
  134. remember.Account = member.Account
  135. remember.Time = time.Now()
  136. v, err := utils.Encode(remember)
  137. if err == nil {
  138. c.SetSecureCookie(conf.GetAppKey(), "login", v, time.Now().Add(time.Hour*24*30).Unix())
  139. }
  140. }
  141. c.JsonResult(0, "ok", c.referer())
  142. } else {
  143. logs.Error("用户登录 ->", err)
  144. c.JsonResult(500, i18n.Tr(c.Lang, "message.wrong_account_password"), nil)
  145. }
  146. } else {
  147. // 默认登录方式
  148. login_method := "AccountController.Login"
  149. var redirect_uri string
  150. // 企业微信登录检查
  151. canLoginWorkWeixin := reflect.ValueOf(c.Data["CanLoginWorkWeixin"]).Bool()
  152. referer := c.referer()
  153. if canLoginWorkWeixin {
  154. // 企业微信登录方式
  155. login_method = "AccountController.WorkWeixinLogin"
  156. u := c.GetString("url")
  157. if u == "" {
  158. u = referer
  159. if u == "" {
  160. u = conf.BaseUrl
  161. }
  162. } else {
  163. var schemaRule = regexp.MustCompile(`^https?\:\/\/`)
  164. if !schemaRule.MatchString(u) {
  165. u = conf.BaseUrl + u
  166. }
  167. }
  168. redirect_uri = conf.URLFor(login_method, "url", url.PathEscape(u))
  169. // 是否在企业微信内部打开
  170. isInWorkWeixin := c.IsInWorkWeixin()
  171. c.Data["IsInWorkWeixin"] = isInWorkWeixin
  172. if isInWorkWeixin {
  173. // 客户端拥有微信标识和企业微信标识
  174. c.Redirect(redirect_uri, 302)
  175. return
  176. } else {
  177. c.Data["workweixin_login_url"] = redirect_uri
  178. }
  179. }
  180. c.Data["url"] = referer
  181. }
  182. }
  183. // 钉钉登录
  184. func (c *AccountController) DingTalkLogin() {
  185. c.Prepare()
  186. code := c.GetString("dingtalk_code")
  187. if code == "" {
  188. c.JsonResult(500, i18n.Tr(c.Lang, "message.failed_obtain_user_info"), nil)
  189. }
  190. appKey, _ := web.AppConfig.String("dingtalk_app_key")
  191. appSecret, _ := web.AppConfig.String("dingtalk_app_secret")
  192. tmpReader, _ := web.AppConfig.String("dingtalk_tmp_reader")
  193. if appKey == "" || appSecret == "" || tmpReader == "" {
  194. c.JsonResult(500, i18n.Tr(c.Lang, "message.dingtalk_auto_login_not_enable"), nil)
  195. c.StopRun()
  196. }
  197. dingtalkAgent := dingtalk.NewDingTalkAgent(appSecret, appKey)
  198. err := dingtalkAgent.GetAccesstoken()
  199. if err != nil {
  200. logs.Warn("获取钉钉临时Token失败 ->", err)
  201. c.JsonResult(500, i18n.Tr(c.Lang, "message.failed_auto_login"), nil)
  202. c.StopRun()
  203. }
  204. userid, err := dingtalkAgent.GetUserIDByCode(code)
  205. if err != nil {
  206. logs.Warn("获取钉钉用户ID失败 ->", err)
  207. c.JsonResult(500, i18n.Tr(c.Lang, "message.failed_auto_login"), nil)
  208. c.StopRun()
  209. }
  210. username, avatar, err := dingtalkAgent.GetUserNameAndAvatarByUserID(userid)
  211. if err != nil {
  212. logs.Warn("获取钉钉用户信息失败 ->", err)
  213. c.JsonResult(500, i18n.Tr(c.Lang, "message.failed_auto_login"), nil)
  214. c.StopRun()
  215. }
  216. member, err := models.NewMember().TmpLogin(tmpReader)
  217. if err == nil {
  218. member.LastLoginTime = time.Now()
  219. _ = member.Update("last_login_time")
  220. member.Account = username
  221. if avatar != "" {
  222. member.Avatar = avatar
  223. }
  224. c.SetMember(*member)
  225. }
  226. c.JsonResult(0, "ok", username)
  227. }
  228. // WorkWeixinLogin 用户企业微信登录
  229. func (c *AccountController) WorkWeixinLogin() {
  230. c.Prepare()
  231. logs.Info("UserAgent: ", c.Ctx.Input.UserAgent()) // debug
  232. if member, ok := c.GetSession(conf.LoginSessionName).(models.Member); ok && member.MemberId > 0 {
  233. u := c.GetString("url")
  234. if u == "" {
  235. u = c.Ctx.Request.Header.Get("Referer")
  236. if u == "" {
  237. u = conf.URLFor("HomeController.Index")
  238. }
  239. }
  240. // session自动登录时刷新session内容
  241. member, err := models.NewMember().Find(member.MemberId)
  242. if err != nil {
  243. c.DelSession(conf.LoginSessionName)
  244. c.SetMember(models.Member{})
  245. c.SetSecureCookie(conf.GetAppKey(), "login", "", -3600)
  246. } else {
  247. c.SetMember(*member)
  248. }
  249. c.Redirect(u, 302)
  250. }
  251. var remember CookieRemember
  252. // 如果 Cookie 中存在登录信息
  253. if cookie, ok := c.GetSecureCookie(conf.GetAppKey(), "login"); ok {
  254. if err := utils.Decode(cookie, &remember); err == nil {
  255. if member, err := models.NewMember().Find(remember.MemberId); err == nil {
  256. c.SetMember(*member)
  257. c.LoggedIn(false)
  258. c.StopRun()
  259. }
  260. }
  261. }
  262. if c.Ctx.Input.IsPost() {
  263. // account := c.GetString("account")
  264. // password := c.GetString("password")
  265. // captcha := c.GetString("code")
  266. // isRemember := c.GetString("is_remember")
  267. c.JsonResult(400, "request method not allowed", nil)
  268. } else {
  269. var callback_u string
  270. u := c.GetString("url")
  271. if u == "" {
  272. u = c.referer()
  273. }
  274. if u != "" {
  275. var schemaRule = regexp.MustCompile(`^https?\:\/\/`)
  276. if !schemaRule.MatchString(u) {
  277. u = strings.TrimRight(conf.BaseUrl, "/") + strings.TrimLeft(u, "/")
  278. }
  279. }
  280. if u == "" {
  281. callback_u = conf.URLFor("AccountController.WorkWeixinLoginCallback")
  282. } else {
  283. callback_u = conf.URLFor("AccountController.WorkWeixinLoginCallback", "url", url.PathEscape(u))
  284. }
  285. logs.Info("callback_u: ", callback_u) // debug
  286. state := "mindoc"
  287. workweixinConf := conf.GetWorkWeixinConfig()
  288. appid := workweixinConf.CorpId
  289. agentid := workweixinConf.AgentId
  290. var redirect_uri string
  291. isInWorkWeixin := c.IsInWorkWeixin()
  292. c.Data["IsInWorkWeixin"] = isInWorkWeixin
  293. if isInWorkWeixin {
  294. // 企业微信内-网页授权登录
  295. urlFmt := "%s?appid=%s&redirect_uri=%s&response_type=code&scope=snsapi_base&state=%s#wechat_redirect"
  296. redirect_uri = fmt.Sprintf(urlFmt, WorkWeixin_AuthorizeUrlBase, appid, url.PathEscape(callback_u), state)
  297. } else {
  298. // 浏览器内-扫码授权登录
  299. urlFmt := "%s?appid=%s&agentid=%s&redirect_uri=%s&state=%s"
  300. redirect_uri = fmt.Sprintf(urlFmt, WorkWeixin_QRConnectUrlBase, appid, agentid, url.PathEscape(callback_u), state)
  301. }
  302. logs.Info("redirect_uri: ", redirect_uri) // debug
  303. c.Redirect(redirect_uri, 302)
  304. }
  305. }
  306. /*
  307. 思路:
  308. 1. 浏览器打开
  309. 用户名+密码 登录 与企业微信没有交集
  310. 手机企业微信登录->扫码页面->扫码后获取用户信息, 判断是否绑定了企业微信
  311. 已绑定,则读取用户信息,直接登录
  312. 未绑定,则弹窗提示[未绑定企业微信,请先在企业微信中打开,完成绑定]
  313. 2. 企业微信打开->自动登录->判断是否绑定了企业微信
  314. 已绑定,则读取用户信息,直接登录
  315. 未绑定,则弹窗提示
  316. 是否已有账户(用户名+密码方式)
  317. 有: 弹窗输入[用户名+密码+验证码]校验
  318. 无: 直接以企业UserId作为用户名(小写),创建随机密码
  319. */
  320. // WorkWeixinLoginCallback 用户企业微信登录-回调
  321. func (c *AccountController) WorkWeixinLoginCallback() {
  322. c.TplName = "account/workweixin-login-callback.tpl"
  323. if member, ok := c.GetSession(conf.LoginSessionName).(models.Member); ok && member.MemberId > 0 {
  324. u := c.GetString("url")
  325. if u == "" {
  326. u = c.Ctx.Request.Header.Get("Referer")
  327. }
  328. if u == "" {
  329. u = conf.URLFor("HomeController.Index")
  330. }
  331. member, err := models.NewMember().Find(member.MemberId)
  332. if err != nil {
  333. c.DelSession(conf.LoginSessionName)
  334. c.SetMember(models.Member{})
  335. c.SetSecureCookie(conf.GetAppKey(), "login", "", -3600)
  336. } else {
  337. c.SetMember(*member)
  338. }
  339. c.Redirect(u, 302)
  340. }
  341. var remember CookieRemember
  342. // 如果 Cookie 中存在登录信息
  343. if cookie, ok := c.GetSecureCookie(conf.GetAppKey(), "login"); ok {
  344. if err := utils.Decode(cookie, &remember); err == nil {
  345. if member, err := models.NewMember().Find(remember.MemberId); err == nil {
  346. c.SetMember(*member)
  347. c.LoggedIn(false)
  348. c.StopRun()
  349. }
  350. }
  351. }
  352. // 请求参数获取
  353. req_code := c.GetString("code")
  354. logs.Warning("req_code: ", req_code)
  355. req_state := c.GetString("state")
  356. logs.Warning("req_state: ", req_state)
  357. var user_info_json string
  358. var error_msg string
  359. var bind_existed string
  360. if len(req_code) > 0 && req_state == "mindoc" {
  361. // 获取当前应用的access_token
  362. access_token, ok := workweixin.GetAccessToken(false)
  363. if ok {
  364. logs.Warning("access_token: ", access_token)
  365. // 获取当前请求的userid
  366. user_id, ok := workweixin.RequestUserId(access_token, req_code)
  367. if ok {
  368. logs.Warning("user_id: ", user_id)
  369. // 获取通讯录应用的access_token
  370. contact_access_token, ok := workweixin.GetAccessToken(true)
  371. if ok {
  372. logs.Warning("contact_access_token: ", contact_access_token)
  373. user_info, err_msg, ok := workweixin.RequestUserInfo(contact_access_token, user_id)
  374. if ok {
  375. // [-------所有字段-Debug----------
  376. // user_info.UserId
  377. // user_info.Name
  378. // user_info.HideMobile
  379. // user_info.Mobile
  380. // user_info.Department
  381. // user_info.Email
  382. // user_info.IsLeaderInDept
  383. // user_info.IsLeader
  384. // user_info.Avatar
  385. // user_info.Alias
  386. // user_info.Status
  387. // user_info.MainDepartment
  388. // -----------------------------]
  389. // logs.Debug("user_info.UserId: ", user_info.UserId)
  390. // logs.Debug("user_info.Name: ", user_info.Name)
  391. json_info, _ := json.Marshal(user_info)
  392. user_info_json = string(json_info)
  393. // 查询系统现有数据,是否绑定了当前请求用户的企业微信
  394. member, err := models.NewWorkWeixinAccount().ExistedMember(user_info.UserId)
  395. if err == nil {
  396. member.LastLoginTime = time.Now()
  397. _ = member.Update("last_login_time")
  398. c.SetMember(*member)
  399. var remember CookieRemember
  400. remember.MemberId = member.MemberId
  401. remember.Account = member.Account
  402. remember.Time = time.Now()
  403. v, err := utils.Encode(remember)
  404. if err == nil {
  405. c.SetSecureCookie(conf.GetAppKey(), "login", v, time.Now().Add(time.Hour*24*30*5).Unix())
  406. }
  407. bind_existed = "true"
  408. error_msg = ""
  409. u := c.GetString("url")
  410. if u == "" {
  411. u = conf.URLFor("HomeController.Index")
  412. }
  413. c.Redirect(u, 302)
  414. } else {
  415. if err == orm.ErrNoRows {
  416. c.SetSession(SessionUserInfoKey, user_info)
  417. bind_existed = "false"
  418. error_msg = ""
  419. } else {
  420. logs.Error("Error: ", err)
  421. error_msg = "数据库错误: " + err.Error()
  422. }
  423. }
  424. //
  425. } else {
  426. error_msg = "获取用户信息失败: " + err_msg
  427. }
  428. } else {
  429. error_msg = "通讯录访问凭据获取失败: " + contact_access_token
  430. }
  431. } else {
  432. error_msg = "获取用户Id失败: " + user_id
  433. }
  434. } else {
  435. error_msg = "应用凭据获取失败: " + access_token
  436. }
  437. } else {
  438. error_msg = "参数错误"
  439. }
  440. if user_info_json == "" {
  441. user_info_json = "{}"
  442. }
  443. if bind_existed == "" {
  444. bind_existed = "null"
  445. }
  446. // refer & doc:
  447. // - https://golang.org/pkg/html/template/#HTML
  448. // - https://stackoverflow.com/questions/24411880/go-html-templates-can-i-stop-the-templates-package-inserting-quotes-around-stri
  449. // - https://stackoverflow.com/questions/38035176/insert-javascript-snippet-inside-template-with-beego-golang
  450. c.Data["bind_existed"] = template.JS(bind_existed)
  451. logs.Debug("bind_existed: ", bind_existed)
  452. c.Data["error_msg"] = template.JS(error_msg)
  453. c.Data["user_info_json"] = template.JS(user_info_json)
  454. /*
  455. // 调试: 显示源码
  456. result, err := c.RenderString()
  457. if err != nil {
  458. logs.Error(err)
  459. } else {
  460. logs.Warning(result)
  461. }
  462. */
  463. }
  464. // WorkWeixinLoginBind 用户企业微信登录-绑定
  465. func (c *AccountController) WorkWeixinLoginBind() {
  466. c.Prepare()
  467. if user_info, ok := c.GetSession(SessionUserInfoKey).(workweixin.WorkWeixinUserInfo); ok && len(user_info.UserId) > 0 {
  468. req_account := c.GetString("account")
  469. req_password := c.GetString("password")
  470. if req_account == "" || req_password == "" {
  471. c.JsonResult(400, "账号或密码不能为空")
  472. } else {
  473. member, err := models.NewMember().Login(req_account, req_password)
  474. if err == nil {
  475. account := models.NewWorkWeixinAccount()
  476. account.MemberId = member.MemberId
  477. account.WorkWeixin_UserId = user_info.UserId
  478. member.CreateAt = 0
  479. ormer := orm.NewOrm()
  480. o, err := ormer.Begin()
  481. if err != nil {
  482. logs.Error("开启事物时出错 -> ", err)
  483. c.JsonResult(500, "开启事物时出错: ", err.Error())
  484. }
  485. if err := account.AddBind(ormer); err != nil {
  486. o.Rollback()
  487. c.JsonResult(500, "绑定失败,数据库错误: "+err.Error())
  488. } else {
  489. member.LastLoginTime = time.Now()
  490. member.RealName = user_info.Name
  491. member.Avatar = user_info.Avatar
  492. if len(member.Avatar) < 1 {
  493. member.Avatar = conf.GetDefaultAvatar()
  494. }
  495. member.Email = user_info.Email
  496. member.Phone = user_info.Mobile
  497. if _, err := ormer.Update(member, "last_login_time", "real_name", "avatar", "email", "phone"); err != nil {
  498. o.Rollback()
  499. logs.Error("保存用户信息失败=>", err)
  500. c.JsonResult(500, "绑定失败,现有账户信息更新失败: "+err.Error())
  501. } else {
  502. if err := o.Commit(); err != nil {
  503. logs.Error("提交事物时出错 -> ", err)
  504. c.JsonResult(500, "提交事物时出错: ", err.Error())
  505. } else {
  506. c.DelSession(SessionUserInfoKey)
  507. c.SetMember(*member)
  508. var remember CookieRemember
  509. remember.MemberId = member.MemberId
  510. remember.Account = member.Account
  511. remember.Time = time.Now()
  512. v, err := utils.Encode(remember)
  513. if err == nil {
  514. c.SetSecureCookie(conf.GetAppKey(), "login", v, time.Now().Add(time.Hour*24*30*5).Unix())
  515. c.JsonResult(0, "绑定成功", nil)
  516. } else {
  517. c.JsonResult(500, "绑定成功, 但自动登录失败, 请返回首页重新登录", nil)
  518. }
  519. }
  520. }
  521. }
  522. } else {
  523. logs.Error("用户登录 ->", err)
  524. c.JsonResult(500, "账号或密码错误", nil)
  525. }
  526. c.JsonResult(500, "TODO: 绑定以后账号功能开发中")
  527. }
  528. } else {
  529. if ok {
  530. c.DelSession(SessionUserInfoKey)
  531. }
  532. c.JsonResult(400, "请求错误, 请从首页重新登录")
  533. }
  534. }
  535. // WorkWeixinLoginIgnore 用户企业微信登录-忽略
  536. func (c *AccountController) WorkWeixinLoginIgnore() {
  537. if user_info, ok := c.GetSession(SessionUserInfoKey).(workweixin.WorkWeixinUserInfo); ok && len(user_info.UserId) > 0 {
  538. c.DelSession(SessionUserInfoKey)
  539. member := models.NewMember()
  540. if _, err := member.FindByAccount(user_info.UserId); err == nil && member.MemberId > 0 {
  541. c.JsonResult(400, "账号已存在")
  542. }
  543. ormer := orm.NewOrm()
  544. o, err := ormer.Begin()
  545. if err != nil {
  546. logs.Error("开启事物时出错 -> ", err)
  547. c.JsonResult(500, "开启事物时出错: ", err.Error())
  548. }
  549. member.Account = user_info.UserId
  550. member.RealName = user_info.Name
  551. var rnd = rand.New(src)
  552. // fmt.Sprintf("%x", rnd.Uint64())
  553. // strconv.FormatUint(rnd.Uint64(), 16)
  554. member.Password = user_info.UserId + strconv.FormatUint(rnd.Uint64(), 16)
  555. member.Password = "pathea.2020" // 强制设置默认密码,不然无法修改密码(因为目前修改密码需要知道当前密码)
  556. hash, err := utils.PasswordHash(member.Password)
  557. if err != nil {
  558. logs.Error("加密用户密码失败 =>", err)
  559. c.JsonResult(500, "加密用户密码失败"+err.Error())
  560. } else {
  561. logs.Error("member.Password: ", member.Password)
  562. logs.Error("hash: ", hash)
  563. member.Password = hash
  564. }
  565. member.Role = conf.MemberGeneralRole
  566. member.Avatar = user_info.Avatar
  567. if len(member.Avatar) < 1 {
  568. member.Avatar = conf.GetDefaultAvatar()
  569. }
  570. member.CreateAt = 0
  571. member.Email = user_info.Email
  572. member.Phone = user_info.Mobile
  573. member.Status = 0
  574. if _, err = ormer.Insert(member); err != nil {
  575. o.Rollback()
  576. c.JsonResult(500, "注册失败,数据库错误: "+err.Error())
  577. } else {
  578. account := models.NewWorkWeixinAccount()
  579. account.MemberId = member.MemberId
  580. account.WorkWeixin_UserId = user_info.UserId
  581. member.CreateAt = 0
  582. if err := account.AddBind(ormer); err != nil {
  583. o.Rollback()
  584. c.JsonResult(500, "注册失败,数据库错误: "+err.Error())
  585. } else {
  586. if err := o.Commit(); err != nil {
  587. logs.Error("提交事物时出错 -> ", err)
  588. c.JsonResult(500, "提交事物时出错: ", err.Error())
  589. } else {
  590. member.LastLoginTime = time.Now()
  591. _ = member.Update("last_login_time")
  592. c.SetMember(*member)
  593. var remember CookieRemember
  594. remember.MemberId = member.MemberId
  595. remember.Account = member.Account
  596. remember.Time = time.Now()
  597. v, err := utils.Encode(remember)
  598. if err == nil {
  599. c.SetSecureCookie(conf.GetAppKey(), "login", v, time.Now().Add(time.Hour*24*30*5).Unix())
  600. c.JsonResult(0, "绑定成功", nil)
  601. } else {
  602. c.JsonResult(500, "绑定成功, 但自动登录失败, 请返回首页重新登录", nil)
  603. }
  604. }
  605. }
  606. }
  607. } else {
  608. if ok {
  609. c.DelSession(SessionUserInfoKey)
  610. }
  611. c.JsonResult(400, "请求错误, 请从首页重新登录")
  612. }
  613. }
  614. // QR二维码登录
  615. func (c *AccountController) QRLogin() {
  616. c.Prepare()
  617. appName := c.Ctx.Input.Param(":app")
  618. switch appName {
  619. // 钉钉扫码登录
  620. case "dingtalk":
  621. code := c.GetString("code")
  622. state := c.GetString("state")
  623. if state != "1" || code == "" {
  624. c.Redirect(conf.URLFor("AccountController.Login"), 302)
  625. c.StopRun()
  626. }
  627. appKey, _ := web.AppConfig.String("dingtalk_qr_key")
  628. appSecret, _ := web.AppConfig.String("dingtalk_qr_secret")
  629. qrDingtalk := dingtalk.NewDingtalkQRLogin(appSecret, appKey)
  630. unionID, err := qrDingtalk.GetUnionIDByCode(code)
  631. if err != nil {
  632. logs.Warn("获取钉钉临时UnionID失败 ->", err)
  633. c.Redirect(conf.URLFor("AccountController.Login"), 302)
  634. c.StopRun()
  635. }
  636. appKey, _ = web.AppConfig.String("dingtalk_app_key")
  637. appSecret, _ = web.AppConfig.String("dingtalk_app_secret")
  638. tmpReader, _ := web.AppConfig.String("dingtalk_tmp_reader")
  639. dingtalkAgent := dingtalk.NewDingTalkAgent(appSecret, appKey)
  640. err = dingtalkAgent.GetAccesstoken()
  641. if err != nil {
  642. logs.Warn("获取钉钉临时Token失败 ->", err)
  643. c.Redirect(conf.URLFor("AccountController.Login"), 302)
  644. c.StopRun()
  645. }
  646. userid, err := dingtalkAgent.GetUserIDByUnionID(unionID)
  647. if err != nil {
  648. logs.Warn("获取钉钉用户ID失败 ->", err)
  649. c.Redirect(conf.URLFor("AccountController.Login"), 302)
  650. c.StopRun()
  651. }
  652. username, avatar, err := dingtalkAgent.GetUserNameAndAvatarByUserID(userid)
  653. if err != nil {
  654. logs.Warn("获取钉钉用户信息失败 ->", err)
  655. c.Redirect(conf.URLFor("AccountController.Login"), 302)
  656. c.StopRun()
  657. }
  658. member, err := models.NewMember().TmpLogin(tmpReader)
  659. if err == nil {
  660. member.LastLoginTime = time.Now()
  661. _ = member.Update("last_login_time")
  662. member.Account = username
  663. if avatar != "" {
  664. member.Avatar = avatar
  665. }
  666. c.SetMember(*member)
  667. c.LoggedIn(false)
  668. c.StopRun()
  669. }
  670. c.Redirect(conf.URLFor("AccountController.Login"), 302)
  671. // 企业微信扫码登录
  672. case "workweixin":
  673. //
  674. default:
  675. c.Redirect(conf.URLFor("AccountController.Login"), 302)
  676. c.StopRun()
  677. }
  678. }
  679. // 登录成功后的操作,如重定向到原始请求页面
  680. func (c *AccountController) LoggedIn(isPost bool) interface{} {
  681. turl := c.referer()
  682. if !isPost {
  683. c.Redirect(turl, 302)
  684. return nil
  685. } else {
  686. var data struct {
  687. TURL string `json:"url"`
  688. }
  689. data.TURL = turl
  690. return data
  691. }
  692. }
  693. // 用户注册
  694. func (c *AccountController) Register() {
  695. c.TplName = "account/register.tpl"
  696. //如果用户登录了,则跳转到网站首页
  697. if member, ok := c.GetSession(conf.LoginSessionName).(models.Member); ok && member.MemberId > 0 {
  698. c.Redirect(conf.URLFor("HomeController.Index"), 302)
  699. }
  700. // 如果没有开启用户注册
  701. if v, ok := c.Option["ENABLED_REGISTER"]; ok && !strings.EqualFold(v, "true") {
  702. c.Abort("404")
  703. }
  704. if c.Ctx.Input.IsPost() {
  705. account := c.GetString("account")
  706. password1 := c.GetString("password1")
  707. password2 := c.GetString("password2")
  708. email := c.GetString("email")
  709. captcha := c.GetString("code")
  710. if ok, err := regexp.MatchString(conf.RegexpAccount, account); account == "" || !ok || err != nil {
  711. c.JsonResult(6001, i18n.Tr(c.Lang, "message.username_invalid_format"))
  712. }
  713. if l := strings.Count(password1, ""); password1 == "" || l > 50 || l < 6 {
  714. c.JsonResult(6002, i18n.Tr(c.Lang, "message.password_length_invalid"))
  715. }
  716. if password1 != password2 {
  717. c.JsonResult(6003, i18n.Tr(c.Lang, "message.incorrect_confirm_password"))
  718. }
  719. if ok, err := regexp.MatchString(conf.RegexpEmail, email); !ok || err != nil || email == "" {
  720. c.JsonResult(6004, i18n.Tr(c.Lang, "message.email_invalid_format"))
  721. }
  722. // 如果开启了验证码
  723. if v, ok := c.Option["ENABLED_CAPTCHA"]; ok && strings.EqualFold(v, "true") {
  724. v, ok := c.GetSession(conf.CaptchaSessionName).(string)
  725. if !ok || !strings.EqualFold(v, captcha) {
  726. c.JsonResult(6001, i18n.Tr(c.Lang, "message.captcha_wrong"))
  727. }
  728. }
  729. member := models.NewMember()
  730. if _, err := member.FindByAccount(account); err == nil && member.MemberId > 0 {
  731. c.JsonResult(6005, i18n.Tr(c.Lang, "message.account_existed"))
  732. }
  733. member.Account = account
  734. member.Password = password1
  735. member.Role = conf.MemberGeneralRole
  736. member.Avatar = conf.GetDefaultAvatar()
  737. member.CreateAt = 0
  738. member.Email = email
  739. member.Status = 0
  740. if err := member.Add(); err != nil {
  741. c.JsonResult(6006, i18n.Tr(c.Lang, "message.failed_register"))
  742. }
  743. c.JsonResult(0, "ok", member)
  744. }
  745. }
  746. // 找回密码
  747. func (c *AccountController) FindPassword() {
  748. c.TplName = "account/find_password_setp1.tpl"
  749. mailConf := conf.GetMailConfig()
  750. if c.Ctx.Input.IsPost() {
  751. email := c.GetString("email")
  752. captcha := c.GetString("code")
  753. if email == "" {
  754. c.JsonResult(6005, i18n.Tr(c.Lang, "message.email_empty"))
  755. }
  756. if !mailConf.EnableMail {
  757. c.JsonResult(6004, i18n.Tr(c.Lang, "message.mail_service_not_enable"))
  758. }
  759. // 如果开启了验证码
  760. if v, ok := c.Option["ENABLED_CAPTCHA"]; ok && strings.EqualFold(v, "true") {
  761. v, ok := c.GetSession(conf.CaptchaSessionName).(string)
  762. if !ok || !strings.EqualFold(v, captcha) {
  763. c.JsonResult(6001, i18n.Tr(c.Lang, "message.captcha_wrong"))
  764. }
  765. }
  766. member, err := models.NewMember().FindByFieldFirst("email", email)
  767. if err != nil {
  768. c.JsonResult(6006, i18n.Tr(c.Lang, "message.email_not_exist"))
  769. }
  770. if member == nil || member.Status != 0 {
  771. c.JsonResult(6007, i18n.Tr(c.Lang, "message.account_disable"))
  772. }
  773. if member == nil || member.AuthMethod == conf.AuthMethodLDAP {
  774. c.JsonResult(6011, i18n.Tr(c.Lang, "message.account_not_support_retrieval"))
  775. }
  776. count, err := models.NewMemberToken().FindSendCount(email, time.Now().Add(-1*time.Hour), time.Now())
  777. if err != nil {
  778. logs.Error(err)
  779. c.JsonResult(6008, i18n.Tr(c.Lang, "message.failed_send_mail"))
  780. }
  781. if count > mailConf.MailNumber {
  782. c.JsonResult(6008, i18n.Tr(c.Lang, "message.sent_too_many_times"))
  783. }
  784. memberToken := models.NewMemberToken()
  785. memberToken.Token = string(utils.Krand(32, utils.KC_RAND_KIND_ALL))
  786. memberToken.Email = email
  787. memberToken.MemberId = member.MemberId
  788. memberToken.IsValid = false
  789. if _, err := memberToken.InsertOrUpdate(); err != nil {
  790. c.JsonResult(6009, i18n.Tr(c.Lang, "message.failed_send_mail"))
  791. }
  792. data := map[string]interface{}{
  793. "SITE_NAME": c.Option["SITE_NAME"],
  794. "url": conf.URLFor("AccountController.FindPassword", "token", memberToken.Token, "mail", email),
  795. "BaseUrl": c.BaseUrl(),
  796. }
  797. body, err := c.ExecuteViewPathTemplate("account/mail_template.tpl", data)
  798. if err != nil {
  799. logs.Error(err)
  800. c.JsonResult(6003, i18n.Tr(c.Lang, "message.failed_send_mail"))
  801. }
  802. go func(mailConf *conf.SmtpConf, email string, body string) {
  803. mailConfig := &mail.SMTPConfig{
  804. Username: mailConf.SmtpUserName,
  805. Password: mailConf.SmtpPassword,
  806. Host: mailConf.SmtpHost,
  807. Port: mailConf.SmtpPort,
  808. Secure: mailConf.Secure,
  809. Identity: "",
  810. }
  811. logs.Info(mailConfig)
  812. c := mail.NewSMTPClient(mailConfig)
  813. m := mail.NewMail()
  814. m.AddFrom(mailConf.FormUserName)
  815. m.AddFromName(mailConf.FormUserName)
  816. m.AddSubject("找回密码")
  817. m.AddHTML(body)
  818. m.AddTo(email)
  819. if e := c.Send(m); e != nil {
  820. logs.Error("发送邮件失败:" + e.Error())
  821. } else {
  822. logs.Info("邮件发送成功:" + email)
  823. }
  824. //auth := smtp.PlainAuth(
  825. // "",
  826. // mail_conf.SmtpUserName,
  827. // mail_conf.SmtpPassword,
  828. // mail_conf.SmtpHost,
  829. //)
  830. //
  831. //mime := "MIME-version: 1.0;\nContent-Type: text/html; charset=\"UTF-8\";\n\n"
  832. //subject := "Subject: 找回密码!\n"
  833. //
  834. //err = smtp.SendMail(
  835. // mail_conf.SmtpHost+":"+strconv.Itoa(mail_conf.SmtpPort),
  836. // auth,
  837. // mail_conf.FormUserName,
  838. // []string{email},
  839. // []byte(subject+mime+"\n"+body),
  840. //)
  841. //if err != nil {
  842. // logs.Error("邮件发送失败 => ", email, err)
  843. //}
  844. }(mailConf, email, body)
  845. c.JsonResult(0, "ok", conf.URLFor("AccountController.Login"))
  846. }
  847. token := c.GetString("token")
  848. email := c.GetString("mail")
  849. if token != "" && email != "" {
  850. memberToken, err := models.NewMemberToken().FindByFieldFirst("token", token)
  851. if err != nil {
  852. logs.Error(err)
  853. c.Data["ErrorMessage"] = i18n.Tr(c.Lang, "message.mail_expired")
  854. c.TplName = "errors/error.tpl"
  855. return
  856. }
  857. subTime := time.Until(memberToken.SendTime)
  858. if !strings.EqualFold(memberToken.Email, email) || subTime.Minutes() > float64(mailConf.MailExpired) || !memberToken.ValidTime.IsZero() {
  859. c.Data["ErrorMessage"] = i18n.Tr(c.Lang, "message.captcha_expired")
  860. c.TplName = "errors/error.tpl"
  861. return
  862. }
  863. c.Data["Email"] = memberToken.Email
  864. c.Data["Token"] = memberToken.Token
  865. c.TplName = "account/find_password_setp2.tpl"
  866. }
  867. }
  868. // 校验邮件并修改密码
  869. func (c *AccountController) ValidEmail() {
  870. c.Prepare()
  871. password1 := c.GetString("password1")
  872. password2 := c.GetString("password2")
  873. captcha := c.GetString("code")
  874. token := c.GetString("token")
  875. email := c.GetString("mail")
  876. if password1 == "" {
  877. c.JsonResult(6001, i18n.Tr(c.Lang, "message.password_empty"))
  878. }
  879. if l := strings.Count(password1, ""); l < 6 || l > 50 {
  880. c.JsonResult(6001, i18n.Tr(c.Lang, "message.password_length_invalid"))
  881. }
  882. if password2 == "" {
  883. c.JsonResult(6002, i18n.Tr(c.Lang, "message.confirm_password_empty"))
  884. }
  885. if password1 != password2 {
  886. c.JsonResult(6003, i18n.Tr(c.Lang, "message.incorrect_confirm_password"))
  887. }
  888. if captcha == "" {
  889. c.JsonResult(6004, i18n.Tr(c.Lang, "message.captcha_empty"))
  890. }
  891. v, ok := c.GetSession(conf.CaptchaSessionName).(string)
  892. if !ok || !strings.EqualFold(v, captcha) {
  893. c.JsonResult(6001, i18n.Tr(c.Lang, "message.captcha_wrong"))
  894. }
  895. mailConf := conf.GetMailConfig()
  896. memberToken, err := models.NewMemberToken().FindByFieldFirst("token", token)
  897. if err != nil {
  898. logs.Error(err)
  899. c.JsonResult(6007, i18n.Tr(c.Lang, "message.mail_expired"))
  900. }
  901. subTime := time.Until(memberToken.SendTime)
  902. if !strings.EqualFold(memberToken.Email, email) || subTime.Minutes() > float64(mailConf.MailExpired) || !memberToken.ValidTime.IsZero() {
  903. c.JsonResult(6008, i18n.Tr(c.Lang, "message.captcha_expired"))
  904. }
  905. member, err := models.NewMember().Find(memberToken.MemberId)
  906. if err != nil {
  907. logs.Error(err)
  908. c.JsonResult(6005, i18n.Tr(c.Lang, "message.user_not_existed"))
  909. }
  910. hash, err := utils.PasswordHash(password1)
  911. if err != nil {
  912. logs.Error(err)
  913. c.JsonResult(6006, i18n.Tr(c.Lang, "message.failed_save_password"))
  914. }
  915. member.Password = hash
  916. err = member.Update("password")
  917. memberToken.ValidTime = time.Now()
  918. memberToken.IsValid = true
  919. memberToken.InsertOrUpdate()
  920. if err != nil {
  921. logs.Error(err)
  922. c.JsonResult(6006, i18n.Tr(c.Lang, "message.failed_save_password"))
  923. }
  924. c.JsonResult(0, "ok", conf.URLFor("AccountController.Login"))
  925. }
  926. // Logout 退出登录
  927. func (c *AccountController) Logout() {
  928. c.SetMember(models.Member{})
  929. c.SetSecureCookie(conf.GetAppKey(), "login", "", -3600)
  930. u := c.Ctx.Request.Header.Get("Referer")
  931. c.Redirect(conf.URLFor("AccountController.Login", "url", u), 302)
  932. }
  933. // 验证码
  934. func (c *AccountController) Captcha() {
  935. c.Prepare()
  936. captchaImage := gocaptcha.NewCaptchaImage(140, 40, gocaptcha.RandLightColor())
  937. captchaImage.DrawNoise(gocaptcha.CaptchaComplexLower)
  938. // captchaImage.DrawTextNoise(gocaptcha.CaptchaComplexHigh)
  939. txt := gocaptcha.RandText(4)
  940. c.SetSession(conf.CaptchaSessionName, txt)
  941. captchaImage.DrawText(txt)
  942. // captchaImage.Drawline(3);
  943. captchaImage.DrawBorder(gocaptcha.ColorToRGB(0x17A7A7A))
  944. // captchaImage.DrawHollowLine()
  945. captchaImage.SaveImage(c.Ctx.ResponseWriter, gocaptcha.ImageFormatJpeg)
  946. c.StopRun()
  947. }