AuthController.java 6.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189
  1. package org.dromara.web.controller;
  2. import cn.dev33.satoken.annotation.SaIgnore;
  3. import cn.hutool.core.collection.CollUtil;
  4. import cn.hutool.core.util.ObjectUtil;
  5. import jakarta.servlet.http.HttpServletRequest;
  6. import lombok.RequiredArgsConstructor;
  7. import lombok.extern.slf4j.Slf4j;
  8. import me.zhyd.oauth.model.AuthResponse;
  9. import me.zhyd.oauth.model.AuthUser;
  10. import me.zhyd.oauth.request.AuthRequest;
  11. import me.zhyd.oauth.utils.AuthStateUtils;
  12. import org.dromara.common.core.constant.UserConstants;
  13. import org.dromara.common.core.domain.R;
  14. import org.dromara.common.core.domain.model.LoginBody;
  15. import org.dromara.common.core.domain.model.RegisterBody;
  16. import org.dromara.common.core.utils.MapstructUtils;
  17. import org.dromara.common.core.utils.MessageUtils;
  18. import org.dromara.common.core.utils.StreamUtils;
  19. import org.dromara.common.core.utils.StringUtils;
  20. import org.dromara.common.social.config.properties.SocialLoginConfigProperties;
  21. import org.dromara.common.social.config.properties.SocialProperties;
  22. import org.dromara.common.social.utils.SocialUtils;
  23. import org.dromara.common.tenant.helper.TenantHelper;
  24. import org.dromara.system.domain.SysClient;
  25. import org.dromara.system.domain.bo.SysTenantBo;
  26. import org.dromara.system.domain.vo.SysTenantVo;
  27. import org.dromara.system.service.ISysClientService;
  28. import org.dromara.system.service.ISysConfigService;
  29. import org.dromara.system.service.ISysSocialService;
  30. import org.dromara.system.service.ISysTenantService;
  31. import org.dromara.web.domain.vo.LoginTenantVo;
  32. import org.dromara.web.domain.vo.LoginVo;
  33. import org.dromara.web.domain.vo.TenantListVo;
  34. import org.dromara.web.service.IAuthStrategy;
  35. import org.dromara.web.service.SysLoginService;
  36. import org.dromara.web.service.SysRegisterService;
  37. import org.springframework.validation.annotation.Validated;
  38. import org.springframework.web.bind.annotation.*;
  39. import java.net.URL;
  40. import java.util.List;
  41. /**
  42. * 认证
  43. *
  44. * @author Lion Li
  45. */
  46. @Slf4j
  47. @SaIgnore
  48. @Validated
  49. @RequiredArgsConstructor
  50. @RestController
  51. @RequestMapping("/auth")
  52. public class AuthController {
  53. private final SocialProperties socialProperties;
  54. private final SysLoginService loginService;
  55. private final SysRegisterService registerService;
  56. private final ISysConfigService configService;
  57. private final ISysTenantService tenantService;
  58. private final ISysSocialService socialUserService;
  59. private final ISysClientService clientService;
  60. /**
  61. * 登录方法
  62. *
  63. * @param loginBody 登录信息
  64. * @return 结果
  65. */
  66. @PostMapping("/login")
  67. public R<LoginVo> login(@Validated @RequestBody LoginBody loginBody) {
  68. // 授权类型和客户端id
  69. String clientId = loginBody.getClientId();
  70. String grantType = loginBody.getGrantType();
  71. SysClient client = clientService.queryByClientId(clientId);
  72. // 查询不到 client 或 client 内不包含 grantType
  73. if (ObjectUtil.isNull(client) || !StringUtils.contains(client.getGrantType(), grantType)) {
  74. log.info("客户端id: {} 认证类型:{} 异常!.", clientId, grantType);
  75. return R.fail(MessageUtils.message("auth.grant.type.error"));
  76. } else if (!UserConstants.NORMAL.equals(client.getStatus())) {
  77. return R.fail(MessageUtils.message("auth.grant.type.stop"));
  78. }
  79. // 校验租户
  80. loginService.checkTenant(loginBody.getTenantId());
  81. // 登录
  82. return R.ok(IAuthStrategy.login(loginBody, client));
  83. }
  84. /**
  85. * 第三方登录请求
  86. *
  87. * @param source 登录来源
  88. * @return 结果
  89. */
  90. @GetMapping("/binding/{source}")
  91. public R<String> authBinding(@PathVariable("source") String source) {
  92. SocialLoginConfigProperties obj = socialProperties.getType().get(source);
  93. if (ObjectUtil.isNull(obj)) {
  94. return R.fail(source + "平台账号暂不支持");
  95. }
  96. AuthRequest authRequest = SocialUtils.getAuthRequest(source, socialProperties);
  97. String authorizeUrl = authRequest.authorize(AuthStateUtils.createState());
  98. return R.ok("操作成功", authorizeUrl);
  99. }
  100. /**
  101. * 第三方登录回调业务处理 绑定授权
  102. *
  103. * @param loginBody 请求体
  104. * @return 结果
  105. */
  106. @PostMapping("/social/callback")
  107. public R<Void> socialCallback(@RequestBody LoginBody loginBody) {
  108. // 获取第三方登录信息
  109. AuthResponse<AuthUser> response = SocialUtils.loginAuth(loginBody, socialProperties);
  110. AuthUser authUserData = response.getData();
  111. // 判断授权响应是否成功
  112. if (!response.ok()) {
  113. return R.fail(response.getMsg());
  114. }
  115. loginService.socialRegister(authUserData);
  116. return R.ok();
  117. }
  118. /**
  119. * 取消授权
  120. *
  121. * @param socialId socialId
  122. */
  123. @DeleteMapping(value = "/unlock/{socialId}")
  124. public R<Void> unlockSocial(@PathVariable Long socialId) {
  125. Boolean rows = socialUserService.deleteWithValidById(socialId);
  126. return rows ? R.ok() : R.fail("取消授权失败");
  127. }
  128. /**
  129. * 退出登录
  130. */
  131. @PostMapping("/logout")
  132. public R<Void> logout() {
  133. loginService.logout();
  134. return R.ok("退出成功");
  135. }
  136. /**
  137. * 用户注册
  138. */
  139. @PostMapping("/register")
  140. public R<Void> register(@Validated @RequestBody RegisterBody user) {
  141. if (!configService.selectRegisterEnabled(user.getTenantId())) {
  142. return R.fail("当前系统没有开启注册功能!");
  143. }
  144. registerService.register(user);
  145. return R.ok();
  146. }
  147. /**
  148. * 登录页面租户下拉框
  149. *
  150. * @return 租户列表
  151. */
  152. @GetMapping("/tenant/list")
  153. public R<LoginTenantVo> tenantList(HttpServletRequest request) throws Exception {
  154. List<SysTenantVo> tenantList = tenantService.queryList(new SysTenantBo());
  155. List<TenantListVo> voList = MapstructUtils.convert(tenantList, TenantListVo.class);
  156. // 获取域名
  157. String host;
  158. String referer = request.getHeader("referer");
  159. if (StringUtils.isNotBlank(referer)) {
  160. // 这里从referer中取值是为了本地使用hosts添加虚拟域名,方便本地环境调试
  161. host = referer.split("//")[1].split("/")[0];
  162. } else {
  163. host = new URL(request.getRequestURL().toString()).getHost();
  164. }
  165. // 根据域名进行筛选
  166. List<TenantListVo> list = StreamUtils.filter(voList, vo ->
  167. StringUtils.equals(vo.getDomain(), host));
  168. // 返回对象
  169. LoginTenantVo vo = new LoginTenantVo();
  170. vo.setVoList(CollUtil.isNotEmpty(list) ? list : voList);
  171. vo.setTenantEnabled(TenantHelper.isEnable());
  172. return R.ok(vo);
  173. }
  174. }