AccountController.go 32 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010101110121013101410151016101710181019102010211022102310241025102610271028102910301031103210331034103510361037103810391040104110421043104410451046104710481049105010511052105310541055
  1. package controllers
  2. import (
  3. "encoding/json"
  4. "fmt"
  5. "html/template"
  6. "math/rand"
  7. "net/url"
  8. "reflect"
  9. "regexp"
  10. "strconv"
  11. "strings"
  12. "time"
  13. "github.com/beego/beego/v2/client/orm"
  14. "github.com/beego/beego/v2/core/logs"
  15. "github.com/beego/beego/v2/server/web"
  16. "github.com/beego/i18n"
  17. "github.com/lifei6671/gocaptcha"
  18. "github.com/mindoc-org/mindoc/conf"
  19. "github.com/mindoc-org/mindoc/mail"
  20. "github.com/mindoc-org/mindoc/models"
  21. "github.com/mindoc-org/mindoc/utils"
  22. "github.com/mindoc-org/mindoc/utils/dingtalk"
  23. "github.com/mindoc-org/mindoc/utils/workweixin"
  24. )
  25. const (
  26. WorkWeixin_AuthorizeUrlBase = "https://open.weixin.qq.com/connect/oauth2/authorize"
  27. WorkWeixin_QRConnectUrlBase = "https://open.work.weixin.qq.com/wwopen/sso/qrConnect"
  28. SessionUserInfoKey = "session-user-info-key"
  29. )
  30. var src = rand.New(rand.NewSource(time.Now().UnixNano()))
  31. // AccountController 用户登录与注册
  32. type AccountController struct {
  33. BaseController
  34. }
  35. func (c *AccountController) referer() string {
  36. u, _ := url.PathUnescape(c.GetString("url"))
  37. if u == "" {
  38. u = conf.URLFor("HomeController.Index")
  39. }
  40. return u
  41. }
  42. func (c *AccountController) IsInWorkWeixin() (is_in_workweixin bool) {
  43. ua := c.Ctx.Input.UserAgent()
  44. var wechatRule = regexp.MustCompile(`\bMicroMessenger\/\d+(\.\d+)*\b`)
  45. var wxworkRule = regexp.MustCompile(`\bwxwork\/\d+(\.\d+)*\b`)
  46. return wechatRule.MatchString(ua) && wxworkRule.MatchString(ua)
  47. }
  48. func (c *AccountController) Prepare() {
  49. c.BaseController.Prepare()
  50. c.EnableXSRF = web.AppConfig.DefaultBool("enablexsrf", true)
  51. c.Data["xsrfdata"] = template.HTML(c.XSRFFormHTML())
  52. c.Data["CanLoginWorkWeixin"] = len(web.AppConfig.DefaultString("workweixin_corpid", "")) > 0
  53. c.Data["corpID"], _ = web.AppConfig.String("dingtalk_corpid")
  54. c.Data["CanLoginDingTalk"] = len(web.AppConfig.DefaultString("dingtalk_corpid", "")) > 0
  55. if reflect.ValueOf(c.Data["CanLoginDingTalk"]).Bool() {
  56. c.Data["ENABLE_QR_DINGTALK"] = true
  57. }
  58. c.Data["dingtalk_qr_key"], _ = web.AppConfig.String("dingtalk_qr_key")
  59. if !c.EnableXSRF {
  60. return
  61. }
  62. if c.Ctx.Input.IsPost() {
  63. token := c.Ctx.Input.Query("_xsrf")
  64. if token == "" {
  65. token = c.Ctx.Request.Header.Get("X-Xsrftoken")
  66. }
  67. if token == "" {
  68. token = c.Ctx.Request.Header.Get("X-Csrftoken")
  69. }
  70. if token == "" {
  71. if c.IsAjax() {
  72. c.JsonResult(403, i18n.Tr(c.Lang, "message.illegal_request"))
  73. } else {
  74. c.ShowErrorPage(403, i18n.Tr(c.Lang, "message.illegal_request"))
  75. }
  76. }
  77. xsrfToken := c.XSRFToken()
  78. if xsrfToken != token {
  79. if c.IsAjax() {
  80. c.JsonResult(403, i18n.Tr(c.Lang, "message.illegal_request"))
  81. } else {
  82. c.ShowErrorPage(403, i18n.Tr(c.Lang, "message.illegal_request"))
  83. }
  84. }
  85. }
  86. }
  87. // Login 用户登录
  88. func (c *AccountController) Login() {
  89. c.TplName = "account/login.tpl"
  90. if member, ok := c.GetSession(conf.LoginSessionName).(models.Member); ok && member.MemberId > 0 {
  91. u := c.GetString("url")
  92. if u == "" {
  93. u = c.Ctx.Request.Header.Get("Referer")
  94. }
  95. if u == "" {
  96. u = conf.URLFor("HomeController.Index")
  97. }
  98. c.Redirect(u, 302)
  99. }
  100. var remember CookieRemember
  101. // 如果 Cookie 中存在登录信息
  102. if cookie, ok := c.GetSecureCookie(conf.GetAppKey(), "login"); ok {
  103. if err := utils.Decode(cookie, &remember); err == nil {
  104. if member, err := models.NewMember().Find(remember.MemberId); err == nil {
  105. c.SetMember(*member)
  106. c.LoggedIn(false)
  107. c.StopRun()
  108. }
  109. }
  110. }
  111. if c.Ctx.Input.IsPost() {
  112. account := c.GetString("account")
  113. password := c.GetString("password")
  114. captcha := c.GetString("code")
  115. isRemember := c.GetString("is_remember")
  116. // 如果开启了验证码
  117. if v, ok := c.Option["ENABLED_CAPTCHA"]; ok && strings.EqualFold(v, "true") {
  118. v, ok := c.GetSession(conf.CaptchaSessionName).(string)
  119. if !ok || !strings.EqualFold(v, captcha) {
  120. c.JsonResult(6001, i18n.Tr(c.Lang, "message.captcha_wrong"))
  121. }
  122. }
  123. if account == "" || password == "" {
  124. c.JsonResult(6002, i18n.Tr(c.Lang, "message.account_or_password_empty"))
  125. }
  126. member, err := models.NewMember().Login(account, password)
  127. if err == nil {
  128. member.LastLoginTime = time.Now()
  129. _ = member.Update("last_login_time")
  130. c.SetMember(*member)
  131. if strings.EqualFold(isRemember, "yes") {
  132. remember.MemberId = member.MemberId
  133. remember.Account = member.Account
  134. remember.Time = time.Now()
  135. v, err := utils.Encode(remember)
  136. if err == nil {
  137. c.SetSecureCookie(conf.GetAppKey(), "login", v, time.Now().Add(time.Hour*24*30).Unix())
  138. }
  139. }
  140. c.JsonResult(0, "ok", c.referer())
  141. } else {
  142. logs.Error("用户登录 ->", err)
  143. c.JsonResult(500, i18n.Tr(c.Lang, "message.wrong_account_password"), nil)
  144. }
  145. } else {
  146. // 默认登录方式
  147. login_method := "AccountController.Login"
  148. var redirect_uri string
  149. // 企业微信登录检查
  150. canLoginWorkWeixin := reflect.ValueOf(c.Data["CanLoginWorkWeixin"]).Bool()
  151. referer := c.referer()
  152. if canLoginWorkWeixin {
  153. // 企业微信登录方式
  154. login_method = "AccountController.WorkWeixinLogin"
  155. u := c.GetString("url")
  156. if u == "" {
  157. u = referer
  158. if u == "" {
  159. u = conf.BaseUrl
  160. }
  161. } else {
  162. var schemaRule = regexp.MustCompile(`^https?\:\/\/`)
  163. if !schemaRule.MatchString(u) {
  164. u = conf.BaseUrl + u
  165. }
  166. }
  167. redirect_uri = conf.URLFor(login_method, "url", url.PathEscape(u))
  168. // 是否在企业微信内部打开
  169. isInWorkWeixin := c.IsInWorkWeixin()
  170. c.Data["IsInWorkWeixin"] = isInWorkWeixin
  171. if isInWorkWeixin {
  172. // 客户端拥有微信标识和企业微信标识
  173. c.Redirect(redirect_uri, 302)
  174. return
  175. } else {
  176. c.Data["workweixin_login_url"] = redirect_uri
  177. }
  178. }
  179. c.Data["url"] = referer
  180. }
  181. }
  182. // 钉钉登录
  183. func (c *AccountController) DingTalkLogin() {
  184. code := c.GetString("dingtalk_code")
  185. if code == "" {
  186. c.JsonResult(500, i18n.Tr(c.Lang, "message.failed_obtain_user_info"), nil)
  187. }
  188. appKey, _ := web.AppConfig.String("dingtalk_app_key")
  189. appSecret, _ := web.AppConfig.String("dingtalk_app_secret")
  190. tmpReader, _ := web.AppConfig.String("dingtalk_tmp_reader")
  191. if appKey == "" || appSecret == "" || tmpReader == "" {
  192. c.JsonResult(500, i18n.Tr(c.Lang, "message.dingtalk_auto_login_not_enable"), nil)
  193. c.StopRun()
  194. }
  195. dingtalkAgent := dingtalk.NewDingTalkAgent(appSecret, appKey)
  196. err := dingtalkAgent.GetAccesstoken()
  197. if err != nil {
  198. logs.Warn("获取钉钉临时Token失败 ->", err)
  199. c.JsonResult(500, i18n.Tr(c.Lang, "message.failed_auto_login"), nil)
  200. c.StopRun()
  201. }
  202. userid, err := dingtalkAgent.GetUserIDByCode(code)
  203. if err != nil {
  204. logs.Warn("获取钉钉用户ID失败 ->", err)
  205. c.JsonResult(500, i18n.Tr(c.Lang, "message.failed_auto_login"), nil)
  206. c.StopRun()
  207. }
  208. username, avatar, err := dingtalkAgent.GetUserNameAndAvatarByUserID(userid)
  209. if err != nil {
  210. logs.Warn("获取钉钉用户信息失败 ->", err)
  211. c.JsonResult(500, i18n.Tr(c.Lang, "message.failed_auto_login"), nil)
  212. c.StopRun()
  213. }
  214. member, err := models.NewMember().TmpLogin(tmpReader)
  215. if err == nil {
  216. member.LastLoginTime = time.Now()
  217. _ = member.Update("last_login_time")
  218. member.Account = username
  219. if avatar != "" {
  220. member.Avatar = avatar
  221. }
  222. c.SetMember(*member)
  223. }
  224. c.JsonResult(0, "ok", username)
  225. }
  226. // WorkWeixinLogin 用户企业微信登录
  227. func (c *AccountController) WorkWeixinLogin() {
  228. logs.Info("UserAgent: ", c.Ctx.Input.UserAgent()) // debug
  229. if member, ok := c.GetSession(conf.LoginSessionName).(models.Member); ok && member.MemberId > 0 {
  230. u := c.GetString("url")
  231. if u == "" {
  232. u = c.Ctx.Request.Header.Get("Referer")
  233. if u == "" {
  234. u = conf.URLFor("HomeController.Index")
  235. }
  236. }
  237. // session自动登录时刷新session内容
  238. member, err := models.NewMember().Find(member.MemberId)
  239. if err != nil {
  240. c.DelSession(conf.LoginSessionName)
  241. c.SetMember(models.Member{})
  242. c.SetSecureCookie(conf.GetAppKey(), "login", "", -3600)
  243. } else {
  244. c.SetMember(*member)
  245. }
  246. c.Redirect(u, 302)
  247. }
  248. var remember CookieRemember
  249. // 如果 Cookie 中存在登录信息
  250. if cookie, ok := c.GetSecureCookie(conf.GetAppKey(), "login"); ok {
  251. if err := utils.Decode(cookie, &remember); err == nil {
  252. if member, err := models.NewMember().Find(remember.MemberId); err == nil {
  253. c.SetMember(*member)
  254. c.LoggedIn(false)
  255. c.StopRun()
  256. }
  257. }
  258. }
  259. if c.Ctx.Input.IsPost() {
  260. // account := c.GetString("account")
  261. // password := c.GetString("password")
  262. // captcha := c.GetString("code")
  263. // isRemember := c.GetString("is_remember")
  264. c.JsonResult(400, "request method not allowed", nil)
  265. } else {
  266. var callback_u string
  267. u := c.GetString("url")
  268. if u == "" {
  269. u = c.referer()
  270. }
  271. if u != "" {
  272. var schemaRule = regexp.MustCompile(`^https?\:\/\/`)
  273. if !schemaRule.MatchString(u) {
  274. u = strings.TrimRight(conf.BaseUrl, "/") + strings.TrimLeft(u, "/")
  275. }
  276. }
  277. if u == "" {
  278. callback_u = conf.URLFor("AccountController.WorkWeixinLoginCallback")
  279. } else {
  280. callback_u = conf.URLFor("AccountController.WorkWeixinLoginCallback", "url", url.PathEscape(u))
  281. }
  282. logs.Info("callback_u: ", callback_u) // debug
  283. state := "mindoc"
  284. workweixinConf := conf.GetWorkWeixinConfig()
  285. appid := workweixinConf.CorpId
  286. agentid := workweixinConf.AgentId
  287. var redirect_uri string
  288. isInWorkWeixin := c.IsInWorkWeixin()
  289. c.Data["IsInWorkWeixin"] = isInWorkWeixin
  290. if isInWorkWeixin {
  291. // 企业微信内-网页授权登录
  292. urlFmt := "%s?appid=%s&redirect_uri=%s&response_type=code&scope=snsapi_base&state=%s#wechat_redirect"
  293. redirect_uri = fmt.Sprintf(urlFmt, WorkWeixin_AuthorizeUrlBase, appid, url.PathEscape(callback_u), state)
  294. } else {
  295. // 浏览器内-扫码授权登录
  296. urlFmt := "%s?appid=%s&agentid=%s&redirect_uri=%s&state=%s"
  297. redirect_uri = fmt.Sprintf(urlFmt, WorkWeixin_QRConnectUrlBase, appid, agentid, url.PathEscape(callback_u), state)
  298. }
  299. logs.Info("redirect_uri: ", redirect_uri) // debug
  300. c.Redirect(redirect_uri, 302)
  301. }
  302. }
  303. /*
  304. 思路:
  305. 1. 浏览器打开
  306. 用户名+密码 登录 与企业微信没有交集
  307. 手机企业微信登录->扫码页面->扫码后获取用户信息, 判断是否绑定了企业微信
  308. 已绑定,则读取用户信息,直接登录
  309. 未绑定,则弹窗提示[未绑定企业微信,请先在企业微信中打开,完成绑定]
  310. 2. 企业微信打开->自动登录->判断是否绑定了企业微信
  311. 已绑定,则读取用户信息,直接登录
  312. 未绑定,则弹窗提示
  313. 是否已有账户(用户名+密码方式)
  314. 有: 弹窗输入[用户名+密码+验证码]校验
  315. 无: 直接以企业UserId作为用户名(小写),创建随机密码
  316. */
  317. // WorkWeixinLoginCallback 用户企业微信登录-回调
  318. func (c *AccountController) WorkWeixinLoginCallback() {
  319. c.TplName = "account/workweixin-login-callback.tpl"
  320. if member, ok := c.GetSession(conf.LoginSessionName).(models.Member); ok && member.MemberId > 0 {
  321. u := c.GetString("url")
  322. if u == "" {
  323. u = c.Ctx.Request.Header.Get("Referer")
  324. }
  325. if u == "" {
  326. u = conf.URLFor("HomeController.Index")
  327. }
  328. member, err := models.NewMember().Find(member.MemberId)
  329. if err != nil {
  330. c.DelSession(conf.LoginSessionName)
  331. c.SetMember(models.Member{})
  332. c.SetSecureCookie(conf.GetAppKey(), "login", "", -3600)
  333. } else {
  334. c.SetMember(*member)
  335. }
  336. c.Redirect(u, 302)
  337. }
  338. var remember CookieRemember
  339. // 如果 Cookie 中存在登录信息
  340. if cookie, ok := c.GetSecureCookie(conf.GetAppKey(), "login"); ok {
  341. if err := utils.Decode(cookie, &remember); err == nil {
  342. if member, err := models.NewMember().Find(remember.MemberId); err == nil {
  343. c.SetMember(*member)
  344. c.LoggedIn(false)
  345. c.StopRun()
  346. }
  347. }
  348. }
  349. // 请求参数获取
  350. req_code := c.GetString("code")
  351. logs.Warning("req_code: ", req_code)
  352. req_state := c.GetString("state")
  353. logs.Warning("req_state: ", req_state)
  354. var user_info_json string
  355. var error_msg string
  356. var bind_existed string
  357. if len(req_code) > 0 && req_state == "mindoc" {
  358. // 获取当前应用的access_token
  359. access_token, ok := workweixin.GetAccessToken(false)
  360. if ok {
  361. logs.Warning("access_token: ", access_token)
  362. // 获取当前请求的userid
  363. user_id, ok := workweixin.RequestUserId(access_token, req_code)
  364. if ok {
  365. logs.Warning("user_id: ", user_id)
  366. // 获取通讯录应用的access_token
  367. contact_access_token, ok := workweixin.GetAccessToken(true)
  368. if ok {
  369. logs.Warning("contact_access_token: ", contact_access_token)
  370. // 获取用户信息
  371. //user_info, err_msg, ok := workweixin.RequestUserInfo(contact_access_token, user_id)
  372. // 获取用户id 列表
  373. user_info, err_msg, ok := workweixin.GetUserListId(contact_access_token, user_id)
  374. if ok {
  375. // [-------所有字段-Debug----------
  376. // user_info.UserId
  377. // user_info.Name
  378. // user_info.HideMobile
  379. // user_info.Mobile
  380. // user_info.Department
  381. // user_info.Email
  382. // user_info.IsLeaderInDept
  383. // user_info.IsLeader
  384. // user_info.Avatar
  385. // user_info.Alias
  386. // user_info.Status
  387. // user_info.MainDepartment
  388. // -----------------------------]
  389. // logs.Debug("user_info.UserId: ", user_info.UserId)
  390. // logs.Debug("user_info.Name: ", user_info.Name)
  391. json_info, _ := json.Marshal(user_info)
  392. user_info_json = string(json_info)
  393. // 查询系统现有数据,是否绑定了当前请求用户的企业微信
  394. member, err := models.NewWorkWeixinAccount().ExistedMember(user_info.UserId)
  395. if err == nil {
  396. member.LastLoginTime = time.Now()
  397. _ = member.Update("last_login_time")
  398. c.SetMember(*member)
  399. var remember CookieRemember
  400. remember.MemberId = member.MemberId
  401. remember.Account = member.Account
  402. remember.Time = time.Now()
  403. v, err := utils.Encode(remember)
  404. if err == nil {
  405. c.SetSecureCookie(conf.GetAppKey(), "login", v, time.Now().Add(time.Hour*24*30*5).Unix())
  406. }
  407. bind_existed = "true"
  408. error_msg = ""
  409. u := c.GetString("url")
  410. if u == "" {
  411. u = conf.URLFor("HomeController.Index")
  412. }
  413. c.Redirect(u, 302)
  414. } else {
  415. if err == orm.ErrNoRows {
  416. c.SetSession(SessionUserInfoKey, user_info)
  417. bind_existed = "false"
  418. error_msg = ""
  419. } else {
  420. logs.Error("Error: ", err)
  421. error_msg = "数据库错误: " + err.Error()
  422. }
  423. }
  424. //
  425. } else {
  426. error_msg = "获取用户信息失败: " + err_msg
  427. }
  428. } else {
  429. error_msg = "通讯录访问凭据获取失败: " + contact_access_token
  430. }
  431. } else {
  432. error_msg = "获取用户Id失败: " + user_id
  433. }
  434. } else {
  435. error_msg = "应用凭据获取失败: " + access_token
  436. }
  437. } else {
  438. error_msg = "参数错误"
  439. }
  440. if user_info_json == "" {
  441. user_info_json = "{}"
  442. }
  443. if bind_existed == "" {
  444. bind_existed = "null"
  445. }
  446. // refer & doc:
  447. // - https://golang.org/pkg/html/template/#HTML
  448. // - https://stackoverflow.com/questions/24411880/go-html-templates-can-i-stop-the-templates-package-inserting-quotes-around-stri
  449. // - https://stackoverflow.com/questions/38035176/insert-javascript-snippet-inside-template-with-beego-golang
  450. c.Data["bind_existed"] = template.JS(bind_existed)
  451. logs.Debug("bind_existed: ", bind_existed)
  452. c.Data["error_msg"] = template.JS(error_msg)
  453. c.Data["user_info_json"] = template.JS(user_info_json)
  454. /*
  455. // 调试: 显示源码
  456. result, err := c.RenderString()
  457. if err != nil {
  458. logs.Error(err)
  459. } else {
  460. logs.Warning(result)
  461. }
  462. */
  463. }
  464. // WorkWeixinLoginBind 用户企业微信登录-绑定
  465. func (c *AccountController) WorkWeixinLoginBind() {
  466. if user_info, ok := c.GetSession(SessionUserInfoKey).(workweixin.WorkWeixinDeptUserInfo); ok && len(user_info.UserId) > 0 {
  467. req_account := c.GetString("account")
  468. req_password := c.GetString("password")
  469. if req_account == "" || req_password == "" {
  470. c.JsonResult(400, "账号或密码不能为空")
  471. } else {
  472. member, err := models.NewMember().Login(req_account, req_password)
  473. if err == nil {
  474. account := models.NewWorkWeixinAccount()
  475. account.MemberId = member.MemberId
  476. account.WorkWeixin_UserId = user_info.UserId
  477. member.CreateAt = 0
  478. ormer := orm.NewOrm()
  479. o, err := ormer.Begin()
  480. if err != nil {
  481. logs.Error("开启事务时出错 -> ", err)
  482. c.JsonResult(500, "开启事务时出错: ", err.Error())
  483. }
  484. if err := account.AddBind(ormer); err != nil {
  485. o.Rollback()
  486. c.JsonResult(500, "绑定失败,数据库错误: "+err.Error())
  487. } else {
  488. // 绑定成功之后修改用户信息
  489. member.LastLoginTime = time.Now()
  490. //member.RealName = user_info.Name
  491. //member.Avatar = user_info.Avatar
  492. if len(member.Avatar) < 1 {
  493. member.Avatar = conf.GetDefaultAvatar()
  494. }
  495. //member.Email = user_info.Email
  496. //member.Phone = user_info.Mobile
  497. if _, err := ormer.Update(member, "last_login_time", "real_name", "avatar", "email", "phone"); err != nil {
  498. o.Rollback()
  499. logs.Error("保存用户信息失败=>", err)
  500. c.JsonResult(500, "绑定失败,现有账户信息更新失败: "+err.Error())
  501. } else {
  502. if err := o.Commit(); err != nil {
  503. logs.Error("开启事务时出错 -> ", err)
  504. c.JsonResult(500, "开启事务时出错: ", err.Error())
  505. } else {
  506. c.DelSession(SessionUserInfoKey)
  507. c.SetMember(*member)
  508. var remember CookieRemember
  509. remember.MemberId = member.MemberId
  510. remember.Account = member.Account
  511. remember.Time = time.Now()
  512. v, err := utils.Encode(remember)
  513. if err == nil {
  514. c.SetSecureCookie(conf.GetAppKey(), "login", v, time.Now().Add(time.Hour*24*30*5).Unix())
  515. c.JsonResult(0, "绑定成功", nil)
  516. } else {
  517. c.JsonResult(500, "绑定成功, 但自动登录失败, 请返回首页重新登录", nil)
  518. }
  519. }
  520. }
  521. }
  522. } else {
  523. logs.Error("用户登录 ->", err)
  524. c.JsonResult(500, "账号或密码错误", nil)
  525. }
  526. c.JsonResult(500, "TODO: 绑定以后账号功能开发中")
  527. }
  528. } else {
  529. if ok {
  530. c.DelSession(SessionUserInfoKey)
  531. }
  532. c.JsonResult(400, "请求错误, 请从首页重新登录")
  533. }
  534. }
  535. // WorkWeixinLoginIgnore 用户企业微信登录-忽略
  536. func (c *AccountController) WorkWeixinLoginIgnore() {
  537. if user_info, ok := c.GetSession(SessionUserInfoKey).(workweixin.WorkWeixinUserInfo); ok && len(user_info.UserId) > 0 {
  538. c.DelSession(SessionUserInfoKey)
  539. member := models.NewMember()
  540. if _, err := member.FindByAccount(user_info.UserId); err == nil && member.MemberId > 0 {
  541. c.JsonResult(400, "账号已存在")
  542. }
  543. ormer := orm.NewOrm()
  544. o, err := ormer.Begin()
  545. if err != nil {
  546. logs.Error("开启事务时出错 -> ", err)
  547. c.JsonResult(500, "开启事务时出错: ", err.Error())
  548. }
  549. member.Account = user_info.UserId
  550. member.RealName = user_info.Name
  551. var rnd = rand.New(src)
  552. // fmt.Sprintf("%x", rnd.Uint64())
  553. // strconv.FormatUint(rnd.Uint64(), 16)
  554. member.Password = user_info.UserId + strconv.FormatUint(rnd.Uint64(), 16)
  555. member.Password = "pathea.2020" // 强制设置默认密码,不然无法修改密码(因为目前修改密码需要知道当前密码)
  556. hash, err := utils.PasswordHash(member.Password)
  557. if err != nil {
  558. logs.Error("加密用户密码失败 =>", err)
  559. c.JsonResult(500, "加密用户密码失败"+err.Error())
  560. } else {
  561. logs.Error("member.Password: ", member.Password)
  562. logs.Error("hash: ", hash)
  563. member.Password = hash
  564. }
  565. member.Role = conf.MemberGeneralRole
  566. member.Avatar = user_info.Avatar
  567. if len(member.Avatar) < 1 {
  568. member.Avatar = conf.GetDefaultAvatar()
  569. }
  570. member.CreateAt = 0
  571. member.Email = user_info.Email
  572. member.Phone = user_info.Mobile
  573. member.Status = 0
  574. if _, err = ormer.Insert(member); err != nil {
  575. o.Rollback()
  576. c.JsonResult(500, "注册失败,数据库错误: "+err.Error())
  577. } else {
  578. account := models.NewWorkWeixinAccount()
  579. account.MemberId = member.MemberId
  580. account.WorkWeixin_UserId = user_info.UserId
  581. member.CreateAt = 0
  582. if err := account.AddBind(ormer); err != nil {
  583. o.Rollback()
  584. c.JsonResult(500, "注册失败,数据库错误: "+err.Error())
  585. } else {
  586. if err := o.Commit(); err != nil {
  587. logs.Error("提交事务时出错 -> ", err)
  588. c.JsonResult(500, "提交事务时出错: ", err.Error())
  589. } else {
  590. member.LastLoginTime = time.Now()
  591. _ = member.Update("last_login_time")
  592. c.SetMember(*member)
  593. var remember CookieRemember
  594. remember.MemberId = member.MemberId
  595. remember.Account = member.Account
  596. remember.Time = time.Now()
  597. v, err := utils.Encode(remember)
  598. if err == nil {
  599. c.SetSecureCookie(conf.GetAppKey(), "login", v, time.Now().Add(time.Hour*24*30*5).Unix())
  600. c.JsonResult(0, "绑定成功", nil)
  601. } else {
  602. c.JsonResult(500, "绑定成功, 但自动登录失败, 请返回首页重新登录", nil)
  603. }
  604. }
  605. }
  606. }
  607. } else {
  608. if ok {
  609. c.DelSession(SessionUserInfoKey)
  610. }
  611. c.JsonResult(400, "请求错误, 请从首页重新登录")
  612. }
  613. }
  614. // QR二维码登录
  615. func (c *AccountController) QRLogin() {
  616. appName := c.Ctx.Input.Param(":app")
  617. switch appName {
  618. // 钉钉扫码登录
  619. case "dingtalk":
  620. code := c.GetString("code")
  621. state := c.GetString("state")
  622. if state != "1" || code == "" {
  623. c.Redirect(conf.URLFor("AccountController.Login"), 302)
  624. c.StopRun()
  625. }
  626. appKey, _ := web.AppConfig.String("dingtalk_qr_key")
  627. appSecret, _ := web.AppConfig.String("dingtalk_qr_secret")
  628. qrDingtalk := dingtalk.NewDingtalkQRLogin(appSecret, appKey)
  629. unionID, err := qrDingtalk.GetUnionIDByCode(code)
  630. if err != nil {
  631. logs.Warn("获取钉钉临时UnionID失败 ->", err)
  632. c.Redirect(conf.URLFor("AccountController.Login"), 302)
  633. c.StopRun()
  634. }
  635. appKey, _ = web.AppConfig.String("dingtalk_app_key")
  636. appSecret, _ = web.AppConfig.String("dingtalk_app_secret")
  637. tmpReader, _ := web.AppConfig.String("dingtalk_tmp_reader")
  638. dingtalkAgent := dingtalk.NewDingTalkAgent(appSecret, appKey)
  639. err = dingtalkAgent.GetAccesstoken()
  640. if err != nil {
  641. logs.Warn("获取钉钉临时Token失败 ->", err)
  642. c.Redirect(conf.URLFor("AccountController.Login"), 302)
  643. c.StopRun()
  644. }
  645. userid, err := dingtalkAgent.GetUserIDByUnionID(unionID)
  646. if err != nil {
  647. logs.Warn("获取钉钉用户ID失败 ->", err)
  648. c.Redirect(conf.URLFor("AccountController.Login"), 302)
  649. c.StopRun()
  650. }
  651. username, avatar, err := dingtalkAgent.GetUserNameAndAvatarByUserID(userid)
  652. if err != nil {
  653. logs.Warn("获取钉钉用户信息失败 ->", err)
  654. c.Redirect(conf.URLFor("AccountController.Login"), 302)
  655. c.StopRun()
  656. }
  657. member, err := models.NewMember().TmpLogin(tmpReader)
  658. if err == nil {
  659. member.LastLoginTime = time.Now()
  660. _ = member.Update("last_login_time")
  661. member.Account = username
  662. if avatar != "" {
  663. member.Avatar = avatar
  664. }
  665. c.SetMember(*member)
  666. c.LoggedIn(false)
  667. c.StopRun()
  668. }
  669. c.Redirect(conf.URLFor("AccountController.Login"), 302)
  670. // 企业微信扫码登录
  671. case "workweixin":
  672. //
  673. default:
  674. c.Redirect(conf.URLFor("AccountController.Login"), 302)
  675. c.StopRun()
  676. }
  677. }
  678. // 登录成功后的操作,如重定向到原始请求页面
  679. func (c *AccountController) LoggedIn(isPost bool) interface{} {
  680. turl := c.referer()
  681. if !isPost {
  682. c.Redirect(turl, 302)
  683. return nil
  684. } else {
  685. var data struct {
  686. TURL string `json:"url"`
  687. }
  688. data.TURL = turl
  689. return data
  690. }
  691. }
  692. // 用户注册
  693. func (c *AccountController) Register() {
  694. c.TplName = "account/register.tpl"
  695. //如果用户登录了,则跳转到网站首页
  696. if member, ok := c.GetSession(conf.LoginSessionName).(models.Member); ok && member.MemberId > 0 {
  697. c.Redirect(conf.URLFor("HomeController.Index"), 302)
  698. }
  699. // 如果没有开启用户注册
  700. if v, ok := c.Option["ENABLED_REGISTER"]; ok && !strings.EqualFold(v, "true") {
  701. c.Abort("404")
  702. }
  703. if c.Ctx.Input.IsPost() {
  704. account := c.GetString("account")
  705. password1 := c.GetString("password1")
  706. password2 := c.GetString("password2")
  707. email := c.GetString("email")
  708. captcha := c.GetString("code")
  709. if ok, err := regexp.MatchString(conf.RegexpAccount, account); account == "" || !ok || err != nil {
  710. c.JsonResult(6001, i18n.Tr(c.Lang, "message.username_invalid_format"))
  711. }
  712. if l := strings.Count(password1, ""); password1 == "" || l > 50 || l < 6 {
  713. c.JsonResult(6002, i18n.Tr(c.Lang, "message.password_length_invalid"))
  714. }
  715. if password1 != password2 {
  716. c.JsonResult(6003, i18n.Tr(c.Lang, "message.incorrect_confirm_password"))
  717. }
  718. if ok, err := regexp.MatchString(conf.RegexpEmail, email); !ok || err != nil || email == "" {
  719. c.JsonResult(6004, i18n.Tr(c.Lang, "message.email_invalid_format"))
  720. }
  721. // 如果开启了验证码
  722. if v, ok := c.Option["ENABLED_CAPTCHA"]; ok && strings.EqualFold(v, "true") {
  723. v, ok := c.GetSession(conf.CaptchaSessionName).(string)
  724. if !ok || !strings.EqualFold(v, captcha) {
  725. c.JsonResult(6001, i18n.Tr(c.Lang, "message.captcha_wrong"))
  726. }
  727. }
  728. member := models.NewMember()
  729. if _, err := member.FindByAccount(account); err == nil && member.MemberId > 0 {
  730. c.JsonResult(6005, i18n.Tr(c.Lang, "message.account_existed"))
  731. }
  732. member.Account = account
  733. member.Password = password1
  734. member.Role = conf.MemberGeneralRole
  735. member.Avatar = conf.GetDefaultAvatar()
  736. member.CreateAt = 0
  737. member.Email = email
  738. member.Status = 0
  739. if err := member.Add(); err != nil {
  740. c.JsonResult(6006, i18n.Tr(c.Lang, "message.failed_register"))
  741. }
  742. c.JsonResult(0, "ok", member)
  743. }
  744. }
  745. // 找回密码
  746. func (c *AccountController) FindPassword() {
  747. c.TplName = "account/find_password_setp1.tpl"
  748. mailConf := conf.GetMailConfig()
  749. if c.Ctx.Input.IsPost() {
  750. email := c.GetString("email")
  751. captcha := c.GetString("code")
  752. if email == "" {
  753. c.JsonResult(6005, i18n.Tr(c.Lang, "message.email_empty"))
  754. }
  755. if !mailConf.EnableMail {
  756. c.JsonResult(6004, i18n.Tr(c.Lang, "message.mail_service_not_enable"))
  757. }
  758. // 如果开启了验证码
  759. if v, ok := c.Option["ENABLED_CAPTCHA"]; ok && strings.EqualFold(v, "true") {
  760. v, ok := c.GetSession(conf.CaptchaSessionName).(string)
  761. if !ok || !strings.EqualFold(v, captcha) {
  762. c.JsonResult(6001, i18n.Tr(c.Lang, "message.captcha_wrong"))
  763. }
  764. }
  765. member, err := models.NewMember().FindByFieldFirst("email", email)
  766. if err != nil {
  767. c.JsonResult(6006, i18n.Tr(c.Lang, "message.email_not_exist"))
  768. }
  769. if member == nil || member.Status != 0 {
  770. c.JsonResult(6007, i18n.Tr(c.Lang, "message.account_disable"))
  771. }
  772. if member == nil || member.AuthMethod == conf.AuthMethodLDAP {
  773. c.JsonResult(6011, i18n.Tr(c.Lang, "message.account_not_support_retrieval"))
  774. }
  775. count, err := models.NewMemberToken().FindSendCount(email, time.Now().Add(-1*time.Hour), time.Now())
  776. if err != nil {
  777. logs.Error(err)
  778. c.JsonResult(6008, i18n.Tr(c.Lang, "message.failed_send_mail"))
  779. }
  780. if count > mailConf.MailNumber {
  781. c.JsonResult(6008, i18n.Tr(c.Lang, "message.sent_too_many_times"))
  782. }
  783. memberToken := models.NewMemberToken()
  784. memberToken.Token = string(utils.Krand(32, utils.KC_RAND_KIND_ALL))
  785. memberToken.Email = email
  786. memberToken.MemberId = member.MemberId
  787. memberToken.IsValid = false
  788. if _, err := memberToken.InsertOrUpdate(); err != nil {
  789. c.JsonResult(6009, i18n.Tr(c.Lang, "message.failed_send_mail"))
  790. }
  791. data := map[string]interface{}{
  792. "SITE_NAME": c.Option["SITE_NAME"],
  793. "url": conf.URLFor("AccountController.FindPassword", "token", memberToken.Token, "mail", email),
  794. "BaseUrl": c.BaseUrl(),
  795. }
  796. body, err := c.ExecuteViewPathTemplate("account/mail_template.tpl", data)
  797. if err != nil {
  798. logs.Error(err)
  799. c.JsonResult(6003, i18n.Tr(c.Lang, "message.failed_send_mail"))
  800. }
  801. go func(mailConf *conf.SmtpConf, email string, body string) {
  802. mailConfig := &mail.SMTPConfig{
  803. Username: mailConf.SmtpUserName,
  804. Password: mailConf.SmtpPassword,
  805. Host: mailConf.SmtpHost,
  806. Port: mailConf.SmtpPort,
  807. Secure: mailConf.Secure,
  808. Identity: "",
  809. }
  810. logs.Info(mailConfig)
  811. c := mail.NewSMTPClient(mailConfig)
  812. m := mail.NewMail()
  813. m.AddFrom(mailConf.FormUserName)
  814. m.AddFromName(mailConf.FormUserName)
  815. m.AddSubject("找回密码")
  816. m.AddHTML(body)
  817. m.AddTo(email)
  818. if e := c.Send(m); e != nil {
  819. logs.Error("发送邮件失败:" + e.Error())
  820. } else {
  821. logs.Info("邮件发送成功:" + email)
  822. }
  823. //auth := smtp.PlainAuth(
  824. // "",
  825. // mail_conf.SmtpUserName,
  826. // mail_conf.SmtpPassword,
  827. // mail_conf.SmtpHost,
  828. //)
  829. //
  830. //mime := "MIME-version: 1.0;\nContent-Type: text/html; charset=\"UTF-8\";\n\n"
  831. //subject := "Subject: 找回密码!\n"
  832. //
  833. //err = smtp.SendMail(
  834. // mail_conf.SmtpHost+":"+strconv.Itoa(mail_conf.SmtpPort),
  835. // auth,
  836. // mail_conf.FormUserName,
  837. // []string{email},
  838. // []byte(subject+mime+"\n"+body),
  839. //)
  840. //if err != nil {
  841. // logs.Error("邮件发送失败 => ", email, err)
  842. //}
  843. }(mailConf, email, body)
  844. c.JsonResult(0, "ok", conf.URLFor("AccountController.Login"))
  845. }
  846. token := c.GetString("token")
  847. email := c.GetString("mail")
  848. if token != "" && email != "" {
  849. memberToken, err := models.NewMemberToken().FindByFieldFirst("token", token)
  850. if err != nil {
  851. logs.Error(err)
  852. c.Data["ErrorMessage"] = i18n.Tr(c.Lang, "message.mail_expired")
  853. c.TplName = "errors/error.tpl"
  854. return
  855. }
  856. subTime := time.Until(memberToken.SendTime)
  857. if !strings.EqualFold(memberToken.Email, email) || subTime.Minutes() > float64(mailConf.MailExpired) || !memberToken.ValidTime.IsZero() {
  858. c.Data["ErrorMessage"] = i18n.Tr(c.Lang, "message.captcha_expired")
  859. c.TplName = "errors/error.tpl"
  860. return
  861. }
  862. c.Data["Email"] = memberToken.Email
  863. c.Data["Token"] = memberToken.Token
  864. c.TplName = "account/find_password_setp2.tpl"
  865. }
  866. }
  867. // 校验邮件并修改密码
  868. func (c *AccountController) ValidEmail() {
  869. password1 := c.GetString("password1")
  870. password2 := c.GetString("password2")
  871. captcha := c.GetString("code")
  872. token := c.GetString("token")
  873. email := c.GetString("mail")
  874. if password1 == "" {
  875. c.JsonResult(6001, i18n.Tr(c.Lang, "message.password_empty"))
  876. }
  877. if l := strings.Count(password1, ""); l < 6 || l > 50 {
  878. c.JsonResult(6001, i18n.Tr(c.Lang, "message.password_length_invalid"))
  879. }
  880. if password2 == "" {
  881. c.JsonResult(6002, i18n.Tr(c.Lang, "message.confirm_password_empty"))
  882. }
  883. if password1 != password2 {
  884. c.JsonResult(6003, i18n.Tr(c.Lang, "message.incorrect_confirm_password"))
  885. }
  886. if captcha == "" {
  887. c.JsonResult(6004, i18n.Tr(c.Lang, "message.captcha_empty"))
  888. }
  889. v, ok := c.GetSession(conf.CaptchaSessionName).(string)
  890. if !ok || !strings.EqualFold(v, captcha) {
  891. c.JsonResult(6001, i18n.Tr(c.Lang, "message.captcha_wrong"))
  892. }
  893. mailConf := conf.GetMailConfig()
  894. memberToken, err := models.NewMemberToken().FindByFieldFirst("token", token)
  895. if err != nil {
  896. logs.Error(err)
  897. c.JsonResult(6007, i18n.Tr(c.Lang, "message.mail_expired"))
  898. }
  899. subTime := time.Until(memberToken.SendTime)
  900. if !strings.EqualFold(memberToken.Email, email) || subTime.Minutes() > float64(mailConf.MailExpired) || !memberToken.ValidTime.IsZero() {
  901. c.JsonResult(6008, i18n.Tr(c.Lang, "message.captcha_expired"))
  902. }
  903. member, err := models.NewMember().Find(memberToken.MemberId)
  904. if err != nil {
  905. logs.Error(err)
  906. c.JsonResult(6005, i18n.Tr(c.Lang, "message.user_not_existed"))
  907. }
  908. hash, err := utils.PasswordHash(password1)
  909. if err != nil {
  910. logs.Error(err)
  911. c.JsonResult(6006, i18n.Tr(c.Lang, "message.failed_save_password"))
  912. }
  913. member.Password = hash
  914. err = member.Update("password")
  915. memberToken.ValidTime = time.Now()
  916. memberToken.IsValid = true
  917. memberToken.InsertOrUpdate()
  918. if err != nil {
  919. logs.Error(err)
  920. c.JsonResult(6006, i18n.Tr(c.Lang, "message.failed_save_password"))
  921. }
  922. c.JsonResult(0, "ok", conf.URLFor("AccountController.Login"))
  923. }
  924. // Logout 退出登录
  925. func (c *AccountController) Logout() {
  926. c.SetMember(models.Member{})
  927. c.SetSecureCookie(conf.GetAppKey(), "login", "", -3600)
  928. u := c.Ctx.Request.Header.Get("Referer")
  929. c.Redirect(conf.URLFor("AccountController.Login", "url", u), 302)
  930. }
  931. // 验证码
  932. func (c *AccountController) Captcha() {
  933. captchaImage := gocaptcha.NewCaptchaImage(140, 40, gocaptcha.RandLightColor())
  934. captchaImage.DrawNoise(gocaptcha.CaptchaComplexLower)
  935. // captchaImage.DrawTextNoise(gocaptcha.CaptchaComplexHigh)
  936. txt := gocaptcha.RandText(4)
  937. c.SetSession(conf.CaptchaSessionName, txt)
  938. captchaImage.DrawText(txt)
  939. // captchaImage.Drawline(3);
  940. captchaImage.DrawBorder(gocaptcha.ColorToRGB(0x17A7A7A))
  941. // captchaImage.DrawHollowLine()
  942. captchaImage.SaveImage(c.Ctx.ResponseWriter, gocaptcha.ImageFormatJpeg)
  943. c.StopRun()
  944. }