Ajax.php 10 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287
  1. <?php
  2. namespace app\admin\controller;
  3. use app\common\controller\Backend;
  4. use fast\Random;
  5. use think\addons\Service;
  6. use think\Cache;
  7. use think\Config;
  8. use think\Db;
  9. use think\Lang;
  10. /**
  11. * Ajax异步请求接口
  12. * @internal
  13. */
  14. class Ajax extends Backend
  15. {
  16. protected $noNeedLogin = ['lang'];
  17. protected $noNeedRight = ['*'];
  18. protected $layout = '';
  19. public function _initialize()
  20. {
  21. parent::_initialize();
  22. //设置过滤方法
  23. $this->request->filter(['strip_tags', 'htmlspecialchars']);
  24. }
  25. /**
  26. * 加载语言包
  27. */
  28. public function lang()
  29. {
  30. header('Content-Type: application/javascript');
  31. $controllername = input("controllername");
  32. //默认只加载了控制器对应的语言名,你还根据控制器名来加载额外的语言包
  33. $this->loadlang($controllername);
  34. return jsonp(Lang::get(), 200, [], ['json_encode_param' => JSON_FORCE_OBJECT | JSON_UNESCAPED_UNICODE]);
  35. }
  36. /**
  37. * 上传文件
  38. */
  39. public function upload()
  40. {
  41. Config::set('default_return_type', 'json');
  42. $file = $this->request->file('file');
  43. if (empty($file)) {
  44. $this->error(__('No file upload or server upload limit exceeded'));
  45. }
  46. //判断是否已经存在附件
  47. $sha1 = $file->hash();
  48. $extparam = $this->request->post();
  49. $upload = Config::get('upload');
  50. preg_match('/(\d+)(\w+)/', $upload['maxsize'], $matches);
  51. $type = strtolower($matches[2]);
  52. $typeDict = ['b' => 0, 'k' => 1, 'kb' => 1, 'm' => 2, 'mb' => 2, 'gb' => 3, 'g' => 3];
  53. $size = (int)$upload['maxsize'] * pow(1024, isset($typeDict[$type]) ? $typeDict[$type] : 0);
  54. $fileInfo = $file->getInfo();
  55. $suffix = strtolower(pathinfo($fileInfo['name'], PATHINFO_EXTENSION));
  56. $suffix = $suffix && preg_match("/^[a-zA-Z0-9]+$/", $suffix) ? $suffix : 'file';
  57. var_dump($upload);
  58. $mimetypeArr = explode(',', strtolower($upload['mimetype']));
  59. $typeArr = explode('/', $fileInfo['type']);
  60. //禁止上传PHP和HTML文件
  61. if (in_array($fileInfo['type'], ['text/x-php', 'text/html']) || in_array($suffix, ['php', 'html', 'htm'])) {
  62. $this->error(__('Uploaded file format is limited'));
  63. }
  64. //验证文件后缀
  65. if ($upload['mimetype'] !== '*' &&
  66. (
  67. !in_array($suffix, $mimetypeArr)
  68. || (stripos($typeArr[0] . '/', $upload['mimetype']) !== false && (!in_array($fileInfo['type'], $mimetypeArr) && !in_array($typeArr[0] . '/*', $mimetypeArr)))
  69. )
  70. ) {
  71. $this->error(__('Uploaded file format is limited'));
  72. }
  73. //验证是否为图片文件
  74. $imagewidth = $imageheight = 0;
  75. if (in_array($fileInfo['type'], ['image/gif', 'image/jpg', 'image/jpeg', 'image/bmp', 'image/png', 'image/webp']) || in_array($suffix, ['gif', 'jpg', 'jpeg', 'bmp', 'png', 'webp','video','mp4'])) {
  76. $imgInfo = getimagesize($fileInfo['tmp_name']);
  77. if (!$imgInfo || !isset($imgInfo[0]) || !isset($imgInfo[1])) {
  78. $this->error(__('Uploaded file is not a valid image'));
  79. }
  80. $imagewidth = isset($imgInfo[0]) ? $imgInfo[0] : $imagewidth;
  81. $imageheight = isset($imgInfo[1]) ? $imgInfo[1] : $imageheight;
  82. }
  83. $replaceArr = [
  84. '{year}' => date("Y"),
  85. '{mon}' => date("m"),
  86. '{day}' => date("d"),
  87. '{hour}' => date("H"),
  88. '{min}' => date("i"),
  89. '{sec}' => date("s"),
  90. '{random}' => Random::alnum(16),
  91. '{random32}' => Random::alnum(32),
  92. '{filename}' => $suffix ? substr($fileInfo['name'], 0, strripos($fileInfo['name'], '.')) : $fileInfo['name'],
  93. '{suffix}' => $suffix,
  94. '{.suffix}' => $suffix ? '.' . $suffix : '',
  95. '{filemd5}' => md5_file($fileInfo['tmp_name']),
  96. ];
  97. $savekey = $upload['savekey'];
  98. $savekey = str_replace(array_keys($replaceArr), array_values($replaceArr), $savekey);
  99. $uploadDir = substr($savekey, 0, strripos($savekey, '/') + 1);
  100. $fileName = substr($savekey, strripos($savekey, '/') + 1);
  101. //
  102. $splInfo = $file->validate(['size' => $size])->move(ROOT_PATH . '/public' . $uploadDir, $fileName);
  103. if ($splInfo) {
  104. $params = array(
  105. 'admin_id' => (int)$this->auth->id,
  106. 'user_id' => 0,
  107. 'filesize' => $fileInfo['size'],
  108. 'imagewidth' => $imagewidth,
  109. 'imageheight' => $imageheight,
  110. 'imagetype' => $suffix,
  111. 'imageframes' => 0,
  112. 'mimetype' => $fileInfo['type'],
  113. 'url' => $uploadDir . $splInfo->getSaveName(),
  114. 'uploadtime' => time(),
  115. 'storage' => 'local',
  116. 'sha1' => $sha1,
  117. 'extparam' => json_encode($extparam),
  118. );
  119. $attachment = model("attachment");
  120. $attachment->data(array_filter($params));
  121. $attachment->save();
  122. \think\Hook::listen("upload_after", $attachment);
  123. $this->success(__('Upload successful'), null, [
  124. 'url' => $uploadDir . $splInfo->getSaveName()
  125. ]);
  126. } else {
  127. // 上传失败获取错误信息
  128. $this->error($file->getError());
  129. }
  130. }
  131. /**
  132. * 通用排序
  133. */
  134. public function weigh()
  135. {
  136. //排序的数组
  137. $ids = $this->request->post("ids");
  138. //拖动的记录ID
  139. $changeid = $this->request->post("changeid");
  140. //操作字段
  141. $field = $this->request->post("field");
  142. //操作的数据表
  143. $table = $this->request->post("table");
  144. //主键
  145. $pk = $this->request->post("pk");
  146. //排序的方式
  147. $orderway = $this->request->post("orderway", "", 'strtolower');
  148. $orderway = $orderway == 'asc' ? 'ASC' : 'DESC';
  149. $sour = $weighdata = [];
  150. $ids = explode(',', $ids);
  151. $prikey = $pk ? $pk : (Db::name($table)->getPk() ?: 'id');
  152. $pid = $this->request->post("pid");
  153. //限制更新的字段
  154. $field = in_array($field, ['weigh']) ? $field : 'weigh';
  155. // 如果设定了pid的值,此时只匹配满足条件的ID,其它忽略
  156. if ($pid !== '') {
  157. $hasids = [];
  158. $list = Db::name($table)->where($prikey, 'in', $ids)->where('pid', 'in', $pid)->field("{$prikey},pid")->select();
  159. foreach ($list as $k => $v) {
  160. $hasids[] = $v[$prikey];
  161. }
  162. $ids = array_values(array_intersect($ids, $hasids));
  163. }
  164. $list = Db::name($table)->field("$prikey,$field")->where($prikey, 'in', $ids)->order($field, $orderway)->select();
  165. foreach ($list as $k => $v) {
  166. $sour[] = $v[$prikey];
  167. $weighdata[$v[$prikey]] = $v[$field];
  168. }
  169. $position = array_search($changeid, $ids);
  170. $desc_id = $sour[$position]; //移动到目标的ID值,取出所处改变前位置的值
  171. $sour_id = $changeid;
  172. $weighids = array();
  173. $temp = array_values(array_diff_assoc($ids, $sour));
  174. foreach ($temp as $m => $n) {
  175. if ($n == $sour_id) {
  176. $offset = $desc_id;
  177. } else {
  178. if ($sour_id == $temp[0]) {
  179. $offset = isset($temp[$m + 1]) ? $temp[$m + 1] : $sour_id;
  180. } else {
  181. $offset = isset($temp[$m - 1]) ? $temp[$m - 1] : $sour_id;
  182. }
  183. }
  184. $weighids[$n] = $weighdata[$offset];
  185. Db::name($table)->where($prikey, $n)->update([$field => $weighdata[$offset]]);
  186. }
  187. $this->success();
  188. }
  189. /**
  190. * 清空系统缓存
  191. */
  192. public function wipecache()
  193. {
  194. $type = $this->request->request("type");
  195. switch ($type) {
  196. case 'all':
  197. case 'content':
  198. rmdirs(CACHE_PATH, false);
  199. Cache::clear();
  200. if ($type == 'content')
  201. break;
  202. case 'template':
  203. rmdirs(TEMP_PATH, false);
  204. if ($type == 'template')
  205. break;
  206. case 'addons':
  207. Service::refresh();
  208. if ($type == 'addons')
  209. break;
  210. }
  211. \think\Hook::listen("wipecache_after");
  212. $this->success();
  213. }
  214. /**
  215. * 读取分类数据,联动列表
  216. */
  217. public function category()
  218. {
  219. $type = $this->request->get('type');
  220. $pid = $this->request->get('pid');
  221. $where = ['status' => 'normal'];
  222. $categorylist = null;
  223. if ($pid !== '') {
  224. if ($type) {
  225. $where['type'] = $type;
  226. }
  227. if ($pid) {
  228. $where['pid'] = $pid;
  229. }
  230. $categorylist = Db::name('category')->where($where)->field('id as value,name')->order('weigh desc,id desc')->select();
  231. }
  232. $this->success('', null, $categorylist);
  233. }
  234. /**
  235. * 读取省市区数据,联动列表
  236. */
  237. public function area()
  238. {
  239. $params = $this->request->get("row/a");
  240. if (!empty($params)) {
  241. $province = isset($params['province']) ? $params['province'] : '';
  242. $city = isset($params['city']) ? $params['city'] : null;
  243. } else {
  244. $province = $this->request->get('province');
  245. $city = $this->request->get('city');
  246. }
  247. $where = ['pid' => 0, 'level' => 1];
  248. $provincelist = null;
  249. if ($province !== '') {
  250. if ($province) {
  251. $where['pid'] = $province;
  252. $where['level'] = 2;
  253. }
  254. if ($city !== '') {
  255. if ($city) {
  256. $where['pid'] = $city;
  257. $where['level'] = 3;
  258. }
  259. $provincelist = Db::name('area')->where($where)->field('id as value,name')->select();
  260. }
  261. }
  262. $this->success('', null, $provincelist);
  263. }
  264. }