Auth.php 17 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533
  1. <?php
  2. namespace app\cmgadm\library;
  3. use app\cmgadm\model\Admin;
  4. use fast\Random;
  5. use fast\Tree;
  6. use think\Config;
  7. use think\Cookie;
  8. use think\Hook;
  9. use think\Request;
  10. use think\Session;
  11. class Auth extends \fast\Auth
  12. {
  13. protected $_error = '';
  14. protected $requestUri = '';
  15. protected $breadcrumb = [];
  16. protected $logined = false; //登录状态
  17. public function __construct()
  18. {
  19. parent::__construct();
  20. }
  21. public function __get($name)
  22. {
  23. return Session::get('admin.' . $name);
  24. }
  25. /**
  26. * 管理员登录
  27. *
  28. * @param string $username 用户名
  29. * @param string $password 密码
  30. * @param int $keeptime 有效时长
  31. * @return boolean
  32. */
  33. public function login($username, $password, $keeptime = 0)
  34. {
  35. $admin = Admin::get(['username' => $username]);
  36. if (!$admin) {
  37. $this->setError('Username is incorrect');
  38. return false;
  39. }
  40. if ($admin['status'] == 'hidden') {
  41. $this->setError('Admin is forbidden');
  42. return false;
  43. }
  44. if (Config::get('fastadmin.login_failure_retry') && $admin->loginfailure >= 10 && time() - $admin->updatetime < 86400) {
  45. $this->setError('Please try again after 1 day');
  46. return false;
  47. }
  48. //var_dump(md5($password . $admin->salt.Config::get('fastadmin.salt')));
  49. if ($admin->password != md5($password . $admin->salt.Config::get('fastadmin.salt'))) {
  50. $admin->loginfailure++;
  51. $admin->save();
  52. $this->setError('Password is incorrect');
  53. return false;
  54. }
  55. $admin->loginfailure = 0;
  56. $admin->logintime = time();
  57. $admin->loginip = request()->ip(0, false);
  58. $admin->token = Random::uuid();
  59. $admin->save();
  60. Session::set("admin", $admin->toArray());
  61. $this->keeplogin($keeptime);
  62. return true;
  63. }
  64. /**
  65. * 注销登录
  66. */
  67. public function logout()
  68. {
  69. $admin = Admin::get(intval($this->id));
  70. if (!$admin) {
  71. $admin->token = '';
  72. $admin->save();
  73. }
  74. $this->logined = false; //重置登录状态
  75. Session::delete("admin");
  76. Cookie::delete("keeplogin");
  77. return true;
  78. }
  79. /**
  80. * 自动登录
  81. * @return boolean
  82. */
  83. public function autologin()
  84. {
  85. $keeplogin = Cookie::get('keeplogin');
  86. if (!$keeplogin) {
  87. return false;
  88. }
  89. list($id, $keeptime, $expiretime, $key) = explode('|', $keeplogin);
  90. if ($id && $keeptime && $expiretime && $key && $expiretime > time()) {
  91. $admin = Admin::get($id);
  92. if (!$admin || !$admin->token) {
  93. return false;
  94. }
  95. //token有变更
  96. if ($key != md5(md5($id) . md5($keeptime) . md5($expiretime) . $admin->token)) {
  97. return false;
  98. }
  99. $ip = request()->ip(0, false);
  100. //IP有变动
  101. if ($admin->loginip != $ip) {
  102. return false;
  103. }
  104. Session::set("admin", $admin->toArray());
  105. //刷新自动登录的时效
  106. $this->keeplogin($keeptime);
  107. return true;
  108. } else {
  109. return false;
  110. }
  111. }
  112. /**
  113. * 刷新保持登录的Cookie
  114. *
  115. * @param int $keeptime
  116. * @return boolean
  117. */
  118. protected function keeplogin($keeptime = 0)
  119. {
  120. if ($keeptime) {
  121. $expiretime = time() + $keeptime;
  122. $key = md5(md5($this->id) . md5($keeptime) . md5($expiretime) . $this->token);
  123. $data = [$this->id, $keeptime, $expiretime, $key];
  124. Cookie::set('keeplogin', implode('|', $data), 86400 * 30);
  125. return true;
  126. }
  127. return false;
  128. }
  129. public function check($name, $uid = '', $relation = 'or', $mode = 'url')
  130. {
  131. return parent::check($name, $this->id, $relation, $mode);
  132. }
  133. /**
  134. * 检测当前控制器和方法是否匹配传递的数组
  135. *
  136. * @param array $arr 需要验证权限的数组
  137. * @return bool
  138. */
  139. public function match($arr = [])
  140. {
  141. $request = Request::instance();
  142. $arr = is_array($arr) ? $arr : explode(',', $arr);
  143. if (!$arr) {
  144. return false;
  145. }
  146. $arr = array_map('strtolower', $arr);
  147. // 是否存在
  148. if (in_array(strtolower($request->action()), $arr) || in_array('*', $arr)) {
  149. return true;
  150. }
  151. // 没找到匹配
  152. return false;
  153. }
  154. /**
  155. * 检测是否登录
  156. *
  157. * @return boolean
  158. */
  159. public function isLogin()
  160. {
  161. if ($this->logined) {
  162. return true;
  163. }
  164. $admin = Session::get('admin');
  165. if (!$admin) {
  166. return false;
  167. }
  168. //判断是否同一时间同一账号只能在一个地方登录
  169. if (Config::get('fastadmin.login_unique')) {
  170. $my = Admin::get($admin['id']);
  171. if (!$my || $my['token'] != $admin['token']) {
  172. return false;
  173. }
  174. }
  175. if (!isset($admin['loginip']) || $admin['loginip'] != request()->ip(0, false)) {
  176. return false;
  177. }
  178. $this->logined = true;
  179. return true;
  180. }
  181. /**
  182. * 获取当前请求的URI
  183. * @return string
  184. */
  185. public function getRequestUri()
  186. {
  187. return $this->requestUri;
  188. }
  189. /**
  190. * 设置当前请求的URI
  191. * @param string $uri
  192. */
  193. public function setRequestUri($uri)
  194. {
  195. $this->requestUri = $uri;
  196. }
  197. public function getGroups($uid = null)
  198. {
  199. $uid = is_null($uid) ? $this->id : $uid;
  200. return parent::getGroups($uid);
  201. }
  202. public function getRuleList($uid = null)
  203. {
  204. $uid = is_null($uid) ? $this->id : $uid;
  205. return parent::getRuleList($uid);
  206. }
  207. public function getUserInfo($uid = null)
  208. {
  209. $uid = is_null($uid) ? $this->id : $uid;
  210. return $uid != $this->id ? Admin::get(intval($uid)) : Session::get('admin');
  211. }
  212. public function getRuleIds($uid = null)
  213. {
  214. $uid = is_null($uid) ? $this->id : $uid;
  215. return parent::getRuleIds($uid);
  216. }
  217. public function isSuperAdmin()
  218. {
  219. return in_array('*', $this->getRuleIds()) ? true : false;
  220. }
  221. /**
  222. * 获取管理员所属于的分组ID
  223. * @param int $uid
  224. * @return array
  225. */
  226. public function getGroupIds($uid = null)
  227. {
  228. $groups = $this->getGroups($uid);
  229. $groupIds = [];
  230. foreach ($groups as $K => $v) {
  231. $groupIds[] = (int)$v['group_id'];
  232. }
  233. return $groupIds;
  234. }
  235. /**
  236. * 取出当前管理员所拥有权限的分组
  237. * @param boolean $withself 是否包含当前所在的分组
  238. * @return array
  239. */
  240. public function getChildrenGroupIds($withself = false)
  241. {
  242. //取出当前管理员所有的分组
  243. $groups = $this->getGroups();
  244. $groupIds = [];
  245. foreach ($groups as $k => $v) {
  246. $groupIds[] = $v['id'];
  247. }
  248. $originGroupIds = $groupIds;
  249. foreach ($groups as $k => $v) {
  250. if (in_array($v['pid'], $originGroupIds)) {
  251. $groupIds = array_diff($groupIds, [$v['id']]);
  252. unset($groups[$k]);
  253. }
  254. }
  255. // 取出所有分组
  256. $groupList = \app\cmgadm\model\AuthGroup::where(['status' => 'normal'])->select();
  257. $objList = [];
  258. foreach ($groups as $k => $v) {
  259. if ($v['rules'] === '*') {
  260. $objList = $groupList;
  261. break;
  262. }
  263. // 取出包含自己的所有子节点
  264. $childrenList = Tree::instance()->init($groupList)->getChildren($v['id'], true);
  265. $obj = Tree::instance()->init($childrenList)->getTreeArray($v['pid']);
  266. $objList = array_merge($objList, Tree::instance()->getTreeList($obj));
  267. }
  268. $childrenGroupIds = [];
  269. foreach ($objList as $k => $v) {
  270. $childrenGroupIds[] = $v['id'];
  271. }
  272. if (!$withself) {
  273. $childrenGroupIds = array_diff($childrenGroupIds, $groupIds);
  274. }
  275. return $childrenGroupIds;
  276. }
  277. /**
  278. * 取出当前管理员所拥有权限的管理员
  279. * @param boolean $withself 是否包含自身
  280. * @return array
  281. */
  282. public function getChildrenAdminIds($withself = false)
  283. {
  284. $childrenAdminIds = [];
  285. if (!$this->isSuperAdmin()) {
  286. $groupIds = $this->getChildrenGroupIds(false);
  287. $authGroupList = \app\cmgadm\model\AuthGroupAccess::
  288. field('uid,group_id')
  289. ->where('group_id', 'in', $groupIds)
  290. ->select();
  291. foreach ($authGroupList as $k => $v) {
  292. $childrenAdminIds[] = $v['uid'];
  293. }
  294. } else {
  295. //超级管理员拥有所有人的权限
  296. $childrenAdminIds = Admin::column('id');
  297. }
  298. if ($withself) {
  299. if (!in_array($this->id, $childrenAdminIds)) {
  300. $childrenAdminIds[] = $this->id;
  301. }
  302. } else {
  303. $childrenAdminIds = array_diff($childrenAdminIds, [$this->id]);
  304. }
  305. return $childrenAdminIds;
  306. }
  307. /**
  308. * 获得面包屑导航
  309. * @param string $path
  310. * @return array
  311. */
  312. public function getBreadCrumb($path = '')
  313. {
  314. if ($this->breadcrumb || !$path) {
  315. return $this->breadcrumb;
  316. }
  317. $path_rule_id = 0;
  318. foreach ($this->rules as $rule) {
  319. $path_rule_id = $rule['name'] == $path ? $rule['id'] : $path_rule_id;
  320. }
  321. if ($path_rule_id) {
  322. $this->breadcrumb = Tree::instance()->init($this->rules)->getParents($path_rule_id, true);
  323. foreach ($this->breadcrumb as $k => &$v) {
  324. $v['url'] = url($v['name']);
  325. $v['title'] = __($v['title']);
  326. }
  327. }
  328. return $this->breadcrumb;
  329. }
  330. /**
  331. * 获取左侧和顶部菜单栏
  332. *
  333. * @param array $params URL对应的badge数据
  334. * @param string $fixedPage 默认页
  335. * @return array
  336. */
  337. public function getSidebar($params = [], $fixedPage = 'dashboard')
  338. {
  339. // 边栏开始
  340. Hook::listen("admin_sidebar_begin", $params);
  341. $colorArr = ['red', 'green', 'yellow', 'blue', 'teal', 'orange', 'purple'];
  342. $colorNums = count($colorArr);
  343. $badgeList = [];
  344. $module = request()->module();
  345. // 生成菜单的badge
  346. foreach ($params as $k => $v) {
  347. $url = $k;
  348. if (is_array($v)) {
  349. $nums = isset($v[0]) ? $v[0] : 0;
  350. $color = isset($v[1]) ? $v[1] : $colorArr[(is_numeric($nums) ? $nums : strlen($nums)) % $colorNums];
  351. $class = isset($v[2]) ? $v[2] : 'label';
  352. } else {
  353. $nums = $v;
  354. $color = $colorArr[(is_numeric($nums) ? $nums : strlen($nums)) % $colorNums];
  355. $class = 'label';
  356. }
  357. //必须nums大于0才显示
  358. if ($nums) {
  359. $badgeList[$url] = '<small class="' . $class . ' pull-right bg-' . $color . '">' . $nums . '</small>';
  360. }
  361. }
  362. // 读取管理员当前拥有的权限节点
  363. $userRule = $this->getRuleList();
  364. $selected = $referer = [];
  365. $refererUrl = Session::get('referer');
  366. $pinyin = new \Overtrue\Pinyin\Pinyin('Overtrue\Pinyin\MemoryFileDictLoader');
  367. // 必须将结果集转换为数组
  368. if(config('develop_mode') != 1)
  369. {
  370. $ruleList = collection(\app\cmgadm\model\AuthRule::where('status', 'normal')
  371. ->where('ismenu', 1)
  372. ->where('dev', 0)
  373. ->order('weigh', 'desc')
  374. ->select())->toArray();
  375. $indexRuleList = \app\cmgadm\model\AuthRule::where('status', 'normal')
  376. ->where('ismenu', 0)
  377. ->where('dev', 0)
  378. ->where('name', 'like', '%/index')
  379. ->column('name,pid');
  380. }else{
  381. $ruleList = collection(\app\cmgadm\model\AuthRule::where('status', 'normal')
  382. ->where('ismenu', 1)
  383. ->order('weigh', 'desc')
  384. ->select())->toArray();
  385. $indexRuleList = \app\cmgadm\model\AuthRule::where('status', 'normal')
  386. ->where('ismenu', 0)
  387. ->where('name', 'like', '%/index')
  388. ->column('name,pid');
  389. }
  390. $pidArr = array_filter(array_unique(array_map(function ($item) {
  391. return $item['pid'];
  392. }, $ruleList)));
  393. foreach ($ruleList as $k => &$v) {
  394. if (!in_array($v['name'], $userRule)) {
  395. unset($ruleList[$k]);
  396. continue;
  397. }
  398. $indexRuleName = $v['name'] . '/index';
  399. if (isset($indexRuleList[$indexRuleName]) && !in_array($indexRuleName, $userRule)) {
  400. unset($ruleList[$k]);
  401. continue;
  402. }
  403. $v['icon'] = $v['icon'] . ' fa-fw';
  404. $v['url'] = '/' . $module . '/' . $v['name'];
  405. $v['badge'] = isset($badgeList[$v['name']]) ? $badgeList[$v['name']] : '';
  406. $v['py'] = $pinyin->abbr($v['title'], '');
  407. $v['pinyin'] = $pinyin->permalink($v['title'], '');
  408. $v['title'] = __($v['title']);
  409. $selected = $v['name'] == $fixedPage ? $v : $selected;
  410. $referer = url($v['url']) == $refererUrl ? $v : $referer;
  411. }
  412. $lastArr = array_diff($pidArr, array_filter(array_unique(array_map(function ($item) {
  413. return $item['pid'];
  414. }, $ruleList))));
  415. foreach ($ruleList as $index => $item) {
  416. if (in_array($item['id'], $lastArr)) {
  417. unset($ruleList[$index]);
  418. }
  419. }
  420. if ($selected == $referer) {
  421. $referer = [];
  422. }
  423. $selected && $selected['url'] = url($selected['url']);
  424. $referer && $referer['url'] = url($referer['url']);
  425. $select_id = $selected ? $selected['id'] : 0;
  426. $menu = $nav = '';
  427. if (Config::get('fastadmin.multiplenav')) {
  428. $topList = [];
  429. foreach ($ruleList as $index => $item) {
  430. if (!$item['pid']) {
  431. $topList[] = $item;
  432. }
  433. }
  434. $selectParentIds = [];
  435. $tree = Tree::instance();
  436. $tree->init($ruleList);
  437. if ($select_id) {
  438. $selectParentIds = $tree->getParentsIds($select_id, true);
  439. }
  440. foreach ($topList as $index => $item) {
  441. $childList = Tree::instance()->getTreeMenu(
  442. $item['id'],
  443. '<li class="@class" pid="@pid"><a href="@url@addtabs" addtabs="@id" url="@url" py="@py" pinyin="@pinyin"><i class="@icon"></i> <span>@title</span> <span class="pull-right-container">@caret @badge</span></a> @childlist</li>',
  444. $select_id,
  445. '',
  446. 'ul',
  447. 'class="treeview-menu"'
  448. );
  449. $current = in_array($item['id'], $selectParentIds);
  450. $url = $childList ? 'javascript:;' : url($item['url']);
  451. $addtabs = $childList || !$url ? "" : (stripos($url, "?") !== false ? "&" : "?") . "ref=addtabs";
  452. $childList = str_replace(
  453. '" pid="' . $item['id'] . '"',
  454. ' treeview ' . ($current ? '' : 'hidden') . '" pid="' . $item['id'] . '"',
  455. $childList
  456. );
  457. $nav .= '<li class="' . ($current ? 'active' : '') . '"><a href="' . $url . $addtabs . '" addtabs="' . $item['id'] . '" url="' . $url . '"><i class="' . $item['icon'] . '"></i> <span>' . $item['title'] . '</span> <span class="pull-right-container"> </span></a> </li>';
  458. $menu .= $childList;
  459. }
  460. } else {
  461. // 构造菜单数据
  462. Tree::instance()->init($ruleList);
  463. $menu = Tree::instance()->getTreeMenu(
  464. 0,
  465. '<li class="@class"><a href="@url@addtabs" addtabs="@id" url="@url" py="@py" pinyin="@pinyin"><i class="@icon"></i> <span>@title</span> <span class="pull-right-container">@caret @badge</span></a> @childlist</li>',
  466. $select_id,
  467. '',
  468. 'ul',
  469. 'class="treeview-menu"'
  470. );
  471. if ($selected) {
  472. $nav .= '<li role="presentation" id="tab_' . $selected['id'] . '" class="' . ($referer ? '' : 'active') . '"><a href="#con_' . $selected['id'] . '" node-id="' . $selected['id'] . '" aria-controls="' . $selected['id'] . '" role="tab" data-toggle="tab"><i class="' . $selected['icon'] . ' fa-fw"></i> <span>' . $selected['title'] . '</span> </a></li>';
  473. }
  474. if ($referer) {
  475. $nav .= '<li role="presentation" id="tab_' . $referer['id'] . '" class="active"><a href="#con_' . $referer['id'] . '" node-id="' . $referer['id'] . '" aria-controls="' . $referer['id'] . '" role="tab" data-toggle="tab"><i class="' . $referer['icon'] . ' fa-fw"></i> <span>' . $referer['title'] . '</span> </a> <i class="close-tab fa fa-remove"></i></li>';
  476. }
  477. }
  478. return [$menu, $nav, $selected, $referer];
  479. }
  480. /**
  481. * 设置错误信息
  482. *
  483. * @param string $error 错误信息
  484. * @return Auth
  485. */
  486. public function setError($error)
  487. {
  488. $this->_error = $error;
  489. return $this;
  490. }
  491. /**
  492. * 获取错误信息
  493. * @return string
  494. */
  495. public function getError()
  496. {
  497. return $this->_error ? __($this->_error) : '';
  498. }
  499. }