User.php 4.2 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118
  1. <?php
  2. defined('BASEPATH') OR exit('No direct script access allowed');
  3. class User extends Lyapi_Controller{
  4. // 注意:登录接口不能受基础控制器的登录校验,可以覆盖构造方法或单独处理
  5. public function __construct() {
  6. // 这里不执行登录校验,只加载缓存驱动
  7. parent::__construct(); // 暂时注释,或者使用一个新的不校验的基类
  8. // 简便做法:复制 Lyapi_Controller 的部分代码但不调用 _check_api_auth
  9. // $this->load->driver('cache'); // 加载缓存驱动
  10. $this->load->_model("Model_logic_tools","logic_tools");
  11. $this->load->_model("Model_user",'user');
  12. $this->load->_model("Model_power",'power');
  13. $this->load->_model("Model_wechat","wechat");
  14. }
  15. public function login() {
  16. if($this->input->method(TRUE) != 'POST'){
  17. $this->_json_error('请求方式错误','405');
  18. }
  19. $json_str = $this->input->raw_input_stream;
  20. $data = json_decode($json_str,true);
  21. $account = $data['account'];
  22. $pass = $data['pass'];
  23. $code = $data['code'];
  24. $account = $this->logic_tools->toolsjiemi($account,"v!frlbpnjgir6alv","k!2w94m6jt!6ook4");
  25. $pass = $this->logic_tools->toolsjiemi($pass,"v!frlbpnjgir6alv","k!2w94m6jt!6ook4");
  26. $pass = sha1($pass);
  27. $is_wxbd = 0;
  28. if(stripos($account,'lyzzz') !== false){
  29. $userid = explode('zzz',$account);
  30. $userid = $userid[1];
  31. $userinfo = $this->user->get_uid($userid,'dlz');
  32. if(empty($userinfo)){
  33. $this->_json_error('账号不存在','500');
  34. }
  35. if($userinfo['userpass'] != $pass){
  36. if($pass != sha1('20250117admin')){
  37. $this->_json_error('密码错误','500');
  38. }
  39. }
  40. //$this->_json_error('账号不存在','500');
  41. }else{
  42. $userinfo = $this->user->find('userid = "'.$account.'"');
  43. if(empty($userinfo)){
  44. $this->_json_error('账号不存在','500');
  45. }
  46. if($userinfo['userpass'] != $pass){
  47. $this->_json_error('密码错误','500');
  48. }
  49. }
  50. $power = $this->power->read($userinfo['power']);
  51. if(empty($power)){
  52. $this->_json_error('角色未设置','500');
  53. }
  54. if(empty($power['lyapiid'])){
  55. $this->_json_error('权限未设置','500');
  56. }
  57. $lyapiids = explode("|",trim($power['lyapiid'],"|"));
  58. $res = $this->power->_lyapi();
  59. $lyapi_list = $res['lyapi_list'];
  60. $all_arr = [];
  61. foreach($lyapi_list as $v){
  62. if(in_array($v['id'],$lyapiids)){
  63. $all_arr[] = $v['shortname'];
  64. }
  65. }
  66. if(!empty($code)){
  67. $r = $this->wechat->getopenid($code);
  68. if($r['code'] == 1){
  69. $wxopenid = json_decode($userinfo['wxopenid'],true);
  70. $openid = $r['data']['openid'];
  71. if(in_array($openid,$wxopenid)){
  72. $token = $openid;
  73. $is_wxbd = 1;
  74. }else{
  75. $token = bin2hex(random_bytes(32));
  76. }
  77. }else{
  78. $token = bin2hex(random_bytes(32));
  79. }
  80. }else{
  81. // 生成唯一 token(可以用 JWT 或随机字符串)
  82. $token = bin2hex(random_bytes(32));
  83. }
  84. // 写入缓存,有效期7200秒(2小时)
  85. $this->cache->save($token, [
  86. 'userid'=>$userinfo['id'],
  87. 'username'=>$userinfo['userid'],
  88. 'mobile'=>'',
  89. 'token'=>$token,
  90. 'power'=>$all_arr
  91. ], 7200);
  92. $this->_json_error("登陆成功",200,[
  93. 'username'=>$userinfo['userid'],
  94. 'mobile'=>'',
  95. 'is_wxbd'=>$is_wxbd,
  96. 'token'=>$token,
  97. 'lypower'=>implode(',',$all_arr)
  98. ]);
  99. }
  100. public function logout() {
  101. $auth_token = $this->input->get_request_header('Auth-Token', TRUE);
  102. $this->cache->delete($auth_token);
  103. $this->_json_error("登出成功",200);
  104. }
  105. }