AuthController.java 8.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234
  1. package org.dromara.web.controller;
  2. import cn.dev33.satoken.annotation.SaIgnore;
  3. import cn.dev33.satoken.exception.NotLoginException;
  4. import cn.hutool.core.codec.Base64;
  5. import cn.hutool.core.collection.CollUtil;
  6. import cn.hutool.core.util.ObjectUtil;
  7. import jakarta.servlet.http.HttpServletRequest;
  8. import lombok.RequiredArgsConstructor;
  9. import lombok.extern.slf4j.Slf4j;
  10. import me.zhyd.oauth.model.AuthResponse;
  11. import me.zhyd.oauth.model.AuthUser;
  12. import me.zhyd.oauth.request.AuthRequest;
  13. import me.zhyd.oauth.utils.AuthStateUtils;
  14. import org.dromara.common.core.constant.UserConstants;
  15. import org.dromara.common.core.domain.R;
  16. import org.dromara.common.core.domain.model.LoginBody;
  17. import org.dromara.common.core.domain.model.RegisterBody;
  18. import org.dromara.common.core.domain.model.SocialLoginBody;
  19. import org.dromara.common.core.utils.*;
  20. import org.dromara.common.encrypt.annotation.ApiEncrypt;
  21. import org.dromara.common.json.utils.JsonUtils;
  22. import org.dromara.common.satoken.utils.LoginHelper;
  23. import org.dromara.common.social.config.properties.SocialLoginConfigProperties;
  24. import org.dromara.common.social.config.properties.SocialProperties;
  25. import org.dromara.common.social.utils.SocialUtils;
  26. import org.dromara.common.tenant.helper.TenantHelper;
  27. import org.dromara.common.websocket.dto.WebSocketMessageDto;
  28. import org.dromara.common.websocket.utils.WebSocketUtils;
  29. import org.dromara.system.domain.bo.SysTenantBo;
  30. import org.dromara.system.domain.vo.SysClientVo;
  31. import org.dromara.system.domain.vo.SysTenantVo;
  32. import org.dromara.system.service.ISysClientService;
  33. import org.dromara.system.service.ISysConfigService;
  34. import org.dromara.system.service.ISysSocialService;
  35. import org.dromara.system.service.ISysTenantService;
  36. import org.dromara.web.domain.vo.LoginTenantVo;
  37. import org.dromara.web.domain.vo.LoginVo;
  38. import org.dromara.web.domain.vo.TenantListVo;
  39. import org.dromara.web.service.IAuthStrategy;
  40. import org.dromara.web.service.SysLoginService;
  41. import org.dromara.web.service.SysRegisterService;
  42. import org.springframework.validation.annotation.Validated;
  43. import org.springframework.web.bind.annotation.*;
  44. import java.net.URL;
  45. import java.nio.charset.StandardCharsets;
  46. import java.util.HashMap;
  47. import java.util.List;
  48. import java.util.Map;
  49. import java.util.concurrent.ScheduledExecutorService;
  50. import java.util.concurrent.TimeUnit;
  51. /**
  52. * 认证
  53. *
  54. * @author Lion Li
  55. */
  56. @Slf4j
  57. @SaIgnore
  58. @RequiredArgsConstructor
  59. @RestController
  60. @RequestMapping("/auth")
  61. public class AuthController {
  62. private final SocialProperties socialProperties;
  63. private final SysLoginService loginService;
  64. private final SysRegisterService registerService;
  65. private final ISysConfigService configService;
  66. private final ISysTenantService tenantService;
  67. private final ISysSocialService socialUserService;
  68. private final ISysClientService clientService;
  69. private final ScheduledExecutorService scheduledExecutorService;
  70. /**
  71. * 登录方法
  72. *
  73. * @param body 登录信息
  74. * @return 结果
  75. */
  76. @ApiEncrypt
  77. @PostMapping("/login")
  78. public R<LoginVo> login(@RequestBody String body) {
  79. LoginBody loginBody = JsonUtils.parseObject(body, LoginBody.class);
  80. ValidatorUtils.validate(loginBody);
  81. // 授权类型和客户端id
  82. String clientId = loginBody.getClientId();
  83. String grantType = loginBody.getGrantType();
  84. SysClientVo client = clientService.queryByClientId(clientId);
  85. // 查询不到 client 或 client 内不包含 grantType
  86. if (ObjectUtil.isNull(client) || !StringUtils.contains(client.getGrantType(), grantType)) {
  87. log.info("客户端id: {} 认证类型:{} 异常!.", clientId, grantType);
  88. return R.fail(MessageUtils.message("auth.grant.type.error"));
  89. } else if (!UserConstants.NORMAL.equals(client.getStatus())) {
  90. return R.fail(MessageUtils.message("auth.grant.type.blocked"));
  91. }
  92. // 校验租户
  93. loginService.checkTenant(loginBody.getTenantId());
  94. // 登录
  95. LoginVo loginVo = IAuthStrategy.login(body, client, grantType);
  96. Long userId = LoginHelper.getUserId();
  97. scheduledExecutorService.schedule(() -> {
  98. WebSocketMessageDto dto = new WebSocketMessageDto();
  99. dto.setMessage("欢迎登录RuoYi-Vue-Plus后台管理系统");
  100. dto.setSessionKeys(List.of(userId));
  101. WebSocketUtils.publishMessage(dto);
  102. }, 3, TimeUnit.SECONDS);
  103. return R.ok(loginVo);
  104. }
  105. /**
  106. * 第三方登录请求
  107. *
  108. * @param source 登录来源
  109. * @return 结果
  110. */
  111. @GetMapping("/binding/{source}")
  112. public R<String> authBinding(@PathVariable("source") String source,
  113. @RequestParam String tenantId, @RequestParam String domain) {
  114. SocialLoginConfigProperties obj = socialProperties.getType().get(source);
  115. if (ObjectUtil.isNull(obj)) {
  116. return R.fail(source + "平台账号暂不支持");
  117. }
  118. AuthRequest authRequest = SocialUtils.getAuthRequest(source, socialProperties);
  119. Map<String, String> map = new HashMap<>();
  120. map.put("tenantId", tenantId);
  121. map.put("domain", domain);
  122. map.put("state", AuthStateUtils.createState());
  123. String authorizeUrl = authRequest.authorize(Base64.encode(JsonUtils.toJsonString(map), StandardCharsets.UTF_8));
  124. return R.ok("操作成功", authorizeUrl);
  125. }
  126. /**
  127. * 第三方登录回调业务处理 绑定授权
  128. *
  129. * @param loginBody 请求体
  130. * @return 结果
  131. */
  132. @PostMapping("/social/callback")
  133. public R<Void> socialCallback(@RequestBody SocialLoginBody loginBody) {
  134. // 获取第三方登录信息
  135. AuthResponse<AuthUser> response = SocialUtils.loginAuth(
  136. loginBody.getSource(), loginBody.getSocialCode(),
  137. loginBody.getSocialState(), socialProperties);
  138. AuthUser authUserData = response.getData();
  139. // 判断授权响应是否成功
  140. if (!response.ok()) {
  141. return R.fail(response.getMsg());
  142. }
  143. loginService.socialRegister(authUserData);
  144. return R.ok();
  145. }
  146. /**
  147. * 取消授权
  148. *
  149. * @param socialId socialId
  150. */
  151. @DeleteMapping(value = "/unlock/{socialId}")
  152. public R<Void> unlockSocial(@PathVariable Long socialId) {
  153. Boolean rows = socialUserService.deleteWithValidById(socialId);
  154. return rows ? R.ok() : R.fail("取消授权失败");
  155. }
  156. /**
  157. * 退出登录
  158. */
  159. @PostMapping("/logout")
  160. public R<Void> logout() {
  161. loginService.logout();
  162. return R.ok("退出成功");
  163. }
  164. /**
  165. * 用户注册
  166. */
  167. @ApiEncrypt
  168. @PostMapping("/register")
  169. public R<Void> register(@Validated @RequestBody RegisterBody user) {
  170. if (!configService.selectRegisterEnabled(user.getTenantId())) {
  171. return R.fail("当前系统没有开启注册功能!");
  172. }
  173. registerService.register(user);
  174. return R.ok();
  175. }
  176. /**
  177. * 登录页面租户下拉框
  178. *
  179. * @return 租户列表
  180. */
  181. @GetMapping("/tenant/list")
  182. public R<LoginTenantVo> tenantList(HttpServletRequest request) throws Exception {
  183. // 返回对象
  184. LoginTenantVo result = new LoginTenantVo();
  185. boolean enable = TenantHelper.isEnable();
  186. result.setTenantEnabled(enable);
  187. // 如果未开启租户这直接返回
  188. if (!enable) {
  189. return R.ok(result);
  190. }
  191. List<SysTenantVo> tenantList = tenantService.queryList(new SysTenantBo());
  192. List<TenantListVo> voList = MapstructUtils.convert(tenantList, TenantListVo.class);
  193. try {
  194. // 如果只超管返回所有租户
  195. if (LoginHelper.isSuperAdmin()) {
  196. result.setVoList(voList);
  197. return R.ok(result);
  198. }
  199. } catch (NotLoginException ignored) {
  200. }
  201. // 获取域名
  202. String host;
  203. String referer = request.getHeader("referer");
  204. if (StringUtils.isNotBlank(referer)) {
  205. // 这里从referer中取值是为了本地使用hosts添加虚拟域名,方便本地环境调试
  206. host = referer.split("//")[1].split("/")[0];
  207. } else {
  208. host = new URL(request.getRequestURL().toString()).getHost();
  209. }
  210. // 根据域名进行筛选
  211. List<TenantListVo> list = StreamUtils.filter(voList, vo ->
  212. StringUtils.equals(vo.getDomain(), host));
  213. result.setVoList(CollUtil.isNotEmpty(list) ? list : voList);
  214. return R.ok(result);
  215. }
  216. }