User.php 3.0 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485
  1. <?php
  2. defined('BASEPATH') OR exit('No direct script access allowed');
  3. class User extends Lyapi_Controller{
  4. // 注意:登录接口不能受基础控制器的登录校验,可以覆盖构造方法或单独处理
  5. public function __construct() {
  6. // 这里不执行登录校验,只加载缓存驱动
  7. parent::__construct(); // 暂时注释,或者使用一个新的不校验的基类
  8. // 简便做法:复制 Lyapi_Controller 的部分代码但不调用 _check_api_auth
  9. // $this->load->driver('cache'); // 加载缓存驱动
  10. $this->load->_model("Model_logic_tools","logic_tools");
  11. $this->load->_model("Model_user",'user');
  12. $this->load->_model("Model_power",'power');
  13. }
  14. public function login() {
  15. if($this->input->method(TRUE) != 'POST'){
  16. $this->_json_error('请求方式错误','405');
  17. }
  18. $json_str = $this->input->raw_input_stream;
  19. $data = json_decode($json_str,true);
  20. $account = $data['account'];
  21. $pass = $data['pass'];
  22. $account = $this->logic_tools->toolsjiemi($account,"v!frlbpnjgir6alv","k!2w94m6jt!6ook4");
  23. $pass = $this->logic_tools->toolsjiemi($pass,"v!frlbpnjgir6alv","k!2w94m6jt!6ook4");
  24. $pass = sha1($pass);
  25. if(stripos($account,'lyzzz') !== false){
  26. $userid = explode('zzz',$account);
  27. $userid = $userid[1];
  28. $userinfo = $this->user->get_uid($userid,'dlz');
  29. if(empty($userinfo)){
  30. $this->_json_error('账号不存在','500');
  31. }
  32. }else{
  33. $userinfo = $this->user->find('userid = "'.$account.'"');
  34. if(empty($userinfo)){
  35. $this->_json_error('账号不存在','500');
  36. }
  37. if($userinfo['userpass'] != $pass){
  38. $this->_json_error('密码错误','500');
  39. }
  40. $power = $this->power->read($userinfo['power']);
  41. if(empty($power)){
  42. $this->_json_error('角色未设置','500');
  43. }
  44. if(empty($power['lyapiid'])){
  45. $this->_json_error('权限未设置','500');
  46. }
  47. }
  48. $lyapiids = explode("|",trim($power['lyapiid'],"|"));
  49. $res = $this->power->_lyapi();
  50. $lyapi_list = $res['lyapi_list'];
  51. $all_arr = [];
  52. foreach($lyapi_list as $v){
  53. if(in_array($v['id'],$lyapiids)){
  54. $all_arr[] = $v['shortname'];
  55. }
  56. }
  57. // 生成唯一 token(可以用 JWT 或随机字符串)
  58. $token = bin2hex(random_bytes(32));
  59. // 写入缓存,有效期7200秒(2小时)
  60. $this->cache->save($token, [
  61. 'username'=>$userinfo['userid'],
  62. 'mobile'=>'',
  63. 'token'=>$token,
  64. 'power'=>$all_arr
  65. ], 7200);
  66. $this->_json_error("登陆成功",200,[
  67. 'username'=>$userinfo['userid'],
  68. 'mobile'=>'',
  69. 'token'=>$token,
  70. 'lypower'=>implode(',',$all_arr)
  71. ]);
  72. }
  73. }