Auth.php 18 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538
  1. <?php
  2. namespace app\admin\library;
  3. use app\admin\model\Admin;
  4. use fast\Random;
  5. use fast\Tree;
  6. use think\Config;
  7. use think\Cookie;
  8. use think\Hook;
  9. use think\Request;
  10. use think\Session;
  11. class Auth extends \fast\Auth
  12. {
  13. protected $_error = '';
  14. protected $requestUri = '';
  15. protected $breadcrumb = [];
  16. protected $logined = false; //登录状态
  17. public function __construct()
  18. {
  19. parent::__construct();
  20. }
  21. public function __get($name)
  22. {
  23. return Session::get('admin.' . $name);
  24. }
  25. /**
  26. * 管理员登录
  27. *
  28. * @param string $username 用户名
  29. * @param string $password 密码
  30. * @param int $keeptime 有效时长
  31. * @return boolean
  32. */
  33. public function login($username, $password, $keeptime = 0, $is_sms = false)
  34. {
  35. $admin = Admin::get(['username' => $username]);
  36. $tel = Admin::get(['mobile'=>$username]);
  37. //手机号登录
  38. if(!$admin){
  39. $admin = $tel;
  40. }
  41. if (!$admin) {
  42. $this->setError('Username is incorrect');
  43. return false;
  44. }
  45. if ($admin['status'] == 'hidden') {
  46. $this->setError('Admin is forbidden');
  47. return false;
  48. }
  49. if (Config::get('fastadmin.login_failure_retry') && $admin->loginfailure >= 10 && time() - $admin->updatetime < 86400) {
  50. $this->setError('Please try again after 1 day');
  51. return false;
  52. }
  53. //验证码登录,无需验证密码
  54. if(!$is_sms) {
  55. if ($admin->password != md5(md5($password) . $admin->salt)) {
  56. $admin->loginfailure++;
  57. $admin->save();
  58. $this->setError('Password is incorrect');
  59. return false;
  60. }
  61. }
  62. $admin->loginfailure = 0;
  63. $admin->logintime = time();
  64. $admin->loginip = request()->ip();
  65. $admin->token = Random::uuid();
  66. $admin->save();
  67. Session::set("admin", $admin->toArray());
  68. $this->keeplogin($keeptime);
  69. return true;
  70. }
  71. /**
  72. * 退出登录
  73. */
  74. public function logout()
  75. {
  76. $admin = Admin::get(intval($this->id));
  77. if ($admin) {
  78. $admin->token = '';
  79. $admin->save();
  80. }
  81. $this->logined = false; //重置登录状态
  82. Session::delete("admin");
  83. Cookie::delete("keeplogin");
  84. return true;
  85. }
  86. /**
  87. * 自动登录
  88. * @return boolean
  89. */
  90. public function autologin()
  91. {
  92. $keeplogin = Cookie::get('keeplogin');
  93. if (!$keeplogin) {
  94. return false;
  95. }
  96. list($id, $keeptime, $expiretime, $key) = explode('|', $keeplogin);
  97. if ($id && $keeptime && $expiretime && $key && $expiretime > time()) {
  98. $admin = Admin::get($id);
  99. if (!$admin || !$admin->token) {
  100. return false;
  101. }
  102. //token有变更
  103. if ($key != md5(md5($id) . md5($keeptime) . md5($expiretime) . $admin->token . config('token.key'))) {
  104. return false;
  105. }
  106. $ip = request()->ip();
  107. //IP有变动
  108. if ($admin->loginip != $ip) {
  109. return false;
  110. }
  111. Session::set("admin", $admin->toArray());
  112. //刷新自动登录的时效
  113. $this->keeplogin($keeptime);
  114. return true;
  115. } else {
  116. return false;
  117. }
  118. }
  119. /**
  120. * 刷新保持登录的Cookie
  121. *
  122. * @param int $keeptime
  123. * @return boolean
  124. */
  125. protected function keeplogin($keeptime = 0)
  126. {
  127. if ($keeptime) {
  128. $expiretime = time() + $keeptime;
  129. $key = md5(md5($this->id) . md5($keeptime) . md5($expiretime) . $this->token . config('token.key'));
  130. $data = [$this->id, $keeptime, $expiretime, $key];
  131. Cookie::set('keeplogin', implode('|', $data), 86400 * 7);
  132. return true;
  133. }
  134. return false;
  135. }
  136. public function check($name, $uid = '', $relation = 'or', $mode = 'url')
  137. {
  138. $uid = $uid ? $uid : $this->id;
  139. return parent::check($name, $uid, $relation, $mode);
  140. }
  141. /**
  142. * 检测当前控制器和方法是否匹配传递的数组
  143. *
  144. * @param array $arr 需要验证权限的数组
  145. * @return bool
  146. */
  147. public function match($arr = [])
  148. {
  149. $request = Request::instance();
  150. $arr = is_array($arr) ? $arr : explode(',', $arr);
  151. if (!$arr) {
  152. return false;
  153. }
  154. $arr = array_map('strtolower', $arr);
  155. // 是否存在
  156. if (in_array(strtolower($request->action()), $arr) || in_array('*', $arr)) {
  157. return true;
  158. }
  159. // 没找到匹配
  160. return false;
  161. }
  162. /**
  163. * 检测是否登录
  164. *
  165. * @return boolean
  166. */
  167. public function isLogin()
  168. {
  169. if ($this->logined) {
  170. return true;
  171. }
  172. $admin = Session::get('admin');
  173. if (!$admin) {
  174. return false;
  175. }
  176. //判断是否同一时间同一账号只能在一个地方登录
  177. if (Config::get('fastadmin.login_unique')) {
  178. $my = Admin::get($admin['id']);
  179. if (!$my || $my['token'] != $admin['token']) {
  180. $this->logined = false; //重置登录状态
  181. Session::delete("admin");
  182. Cookie::delete("keeplogin");
  183. return false;
  184. }
  185. }
  186. //判断管理员IP是否变动
  187. if (Config::get('fastadmin.loginip_check')) {
  188. if (!isset($admin['loginip']) || $admin['loginip'] != request()->ip()) {
  189. $this->logout();
  190. return false;
  191. }
  192. }
  193. $this->logined = true;
  194. return true;
  195. }
  196. /**
  197. * 获取当前请求的URI
  198. * @return string
  199. */
  200. public function getRequestUri()
  201. {
  202. return $this->requestUri;
  203. }
  204. /**
  205. * 设置当前请求的URI
  206. * @param string $uri
  207. */
  208. public function setRequestUri($uri)
  209. {
  210. $this->requestUri = $uri;
  211. }
  212. public function getGroups($uid = null)
  213. {
  214. $uid = is_null($uid) ? $this->id : $uid;
  215. return parent::getGroups($uid);
  216. }
  217. public function getRuleList($uid = null)
  218. {
  219. $uid = is_null($uid) ? $this->id : $uid;
  220. return parent::getRuleList($uid);
  221. }
  222. public function getUserInfo($uid = null)
  223. {
  224. $uid = is_null($uid) ? $this->id : $uid;
  225. return $uid != $this->id ? Admin::get(intval($uid)) : Session::get('admin');
  226. }
  227. public function getRuleIds($uid = null)
  228. {
  229. $uid = is_null($uid) ? $this->id : $uid;
  230. return parent::getRuleIds($uid);
  231. }
  232. public function isSuperAdmin()
  233. {
  234. return in_array('*', $this->getRuleIds()) ? true : false;
  235. }
  236. /**
  237. * 获取管理员所属于的分组ID
  238. * @param int $uid
  239. * @return array
  240. */
  241. public function getGroupIds($uid = null)
  242. {
  243. $groups = $this->getGroups($uid);
  244. $groupIds = [];
  245. foreach ($groups as $K => $v) {
  246. $groupIds[] = (int)$v['group_id'];
  247. }
  248. return $groupIds;
  249. }
  250. /**
  251. * 取出当前管理员所拥有权限的分组
  252. * @param boolean $withself 是否包含当前所在的分组
  253. * @return array
  254. */
  255. public function getChildrenGroupIds($withself = false)
  256. {
  257. //取出当前管理员所有的分组
  258. $groups = $this->getGroups();
  259. $groupIds = [];
  260. foreach ($groups as $k => $v) {
  261. $groupIds[] = $v['id'];
  262. }
  263. $originGroupIds = $groupIds;
  264. foreach ($groups as $k => $v) {
  265. if (in_array($v['pid'], $originGroupIds)) {
  266. $groupIds = array_diff($groupIds, [$v['id']]);
  267. unset($groups[$k]);
  268. }
  269. }
  270. // 取出所有分组
  271. $groupList = \app\admin\model\AuthGroup::where(['status' => 'normal'])->select();
  272. $objList = [];
  273. foreach ($groups as $k => $v) {
  274. if ($v['rules'] === '*') {
  275. $objList = $groupList;
  276. break;
  277. }
  278. // 取出包含自己的所有子节点
  279. $childrenList = Tree::instance()->init($groupList, 'pid')->getChildren($v['id'], true);
  280. $obj = Tree::instance()->init($childrenList, 'pid')->getTreeArray($v['pid']);
  281. $objList = array_merge($objList, Tree::instance()->getTreeList($obj));
  282. }
  283. $childrenGroupIds = [];
  284. foreach ($objList as $k => $v) {
  285. $childrenGroupIds[] = $v['id'];
  286. }
  287. if (!$withself) {
  288. $childrenGroupIds = array_diff($childrenGroupIds, $groupIds);
  289. }
  290. return $childrenGroupIds;
  291. }
  292. /**
  293. * 取出当前管理员所拥有权限的管理员
  294. * @param boolean $withself 是否包含自身
  295. * @return array
  296. */
  297. public function getChildrenAdminIds($withself = false)
  298. {
  299. $childrenAdminIds = [];
  300. if (!$this->isSuperAdmin()) {
  301. $groupIds = $this->getChildrenGroupIds(false);
  302. $authGroupList = \app\admin\model\AuthGroupAccess::
  303. field('uid,group_id')
  304. ->where('group_id', 'in', $groupIds)
  305. ->select();
  306. foreach ($authGroupList as $k => $v) {
  307. $childrenAdminIds[] = $v['uid'];
  308. }
  309. } else {
  310. //超级管理员拥有所有人的权限
  311. $childrenAdminIds = Admin::column('id');
  312. }
  313. if ($withself) {
  314. if (!in_array($this->id, $childrenAdminIds)) {
  315. $childrenAdminIds[] = $this->id;
  316. }
  317. } else {
  318. $childrenAdminIds = array_diff($childrenAdminIds, [$this->id]);
  319. }
  320. return $childrenAdminIds;
  321. }
  322. /**
  323. * 获得面包屑导航
  324. * @param string $path
  325. * @return array
  326. */
  327. public function getBreadCrumb($path = '')
  328. {
  329. if ($this->breadcrumb || !$path) {
  330. return $this->breadcrumb;
  331. }
  332. $titleArr = [];
  333. $menuArr = [];
  334. $urlArr = explode('/', $path);
  335. foreach ($urlArr as $index => $item) {
  336. $pathArr[implode('/', array_slice($urlArr, 0, $index + 1))] = $index;
  337. }
  338. if (!$this->rules && $this->id) {
  339. $this->getRuleList();
  340. }
  341. foreach ($this->rules as $rule) {
  342. if (isset($pathArr[$rule['name']])) {
  343. $rule['title'] = __($rule['title']);
  344. $rule['url'] = url($rule['name']);
  345. $titleArr[$pathArr[$rule['name']]] = $rule['title'];
  346. $menuArr[$pathArr[$rule['name']]] = $rule;
  347. }
  348. }
  349. ksort($menuArr);
  350. $this->breadcrumb = $menuArr;
  351. return $this->breadcrumb;
  352. }
  353. /**
  354. * 获取左侧和顶部菜单栏
  355. *
  356. * @param array $params URL对应的badge数据
  357. * @param string $fixedPage 默认页
  358. * @return array
  359. */
  360. public function getSidebar($params = [], $fixedPage = 'dashboard')
  361. {
  362. // 边栏开始
  363. Hook::listen("admin_sidebar_begin", $params);
  364. $colorArr = ['red', 'green', 'yellow', 'blue', 'teal', 'orange', 'purple'];
  365. $colorNums = count($colorArr);
  366. $badgeList = [];
  367. $module = request()->module();
  368. // 生成菜单的badge
  369. foreach ($params as $k => $v) {
  370. $url = $k;
  371. if (is_array($v)) {
  372. $nums = isset($v[0]) ? $v[0] : 0;
  373. $color = isset($v[1]) ? $v[1] : $colorArr[(is_numeric($nums) ? $nums : strlen($nums)) % $colorNums];
  374. $class = isset($v[2]) ? $v[2] : 'label';
  375. } else {
  376. $nums = $v;
  377. $color = $colorArr[(is_numeric($nums) ? $nums : strlen($nums)) % $colorNums];
  378. $class = 'label';
  379. }
  380. //必须nums大于0才显示
  381. if ($nums) {
  382. $badgeList[$url] = '<small class="' . $class . ' pull-right bg-' . $color . '">' . $nums . '</small>';
  383. }
  384. }
  385. // 读取管理员当前拥有的权限节点
  386. $userRule = $this->getRuleList();
  387. $selected = $referer = [];
  388. $refererUrl = Session::get('referer');
  389. // 必须将结果集转换为数组
  390. $ruleList = collection(\app\admin\model\AuthRule::where('status', 'normal')
  391. ->where('ismenu', 1)
  392. ->order('weigh', 'desc')
  393. ->cache("__menu__")
  394. ->select())->toArray();
  395. $indexRuleList = \app\admin\model\AuthRule::where('status', 'normal')
  396. ->where('ismenu', 0)
  397. ->where('name', 'like', '%/index')
  398. ->column('name,pid');
  399. $pidArr = array_unique(array_filter(array_column($ruleList, 'pid')));
  400. foreach ($ruleList as $k => &$v) {
  401. if (!in_array($v['name'], $userRule)) {
  402. unset($ruleList[$k]);
  403. continue;
  404. }
  405. $indexRuleName = $v['name'] . '/index';
  406. if (isset($indexRuleList[$indexRuleName]) && !in_array($indexRuleName, $userRule)) {
  407. unset($ruleList[$k]);
  408. continue;
  409. }
  410. $v['icon'] = $v['icon'] . ' fa-fw';
  411. $v['url'] = isset($v['url']) && $v['url'] ? $v['url'] : '/' . $module . '/' . $v['name'];
  412. $v['badge'] = isset($badgeList[$v['name']]) ? $badgeList[$v['name']] : '';
  413. $v['title'] = __($v['title']);
  414. $v['url'] = preg_match("/^((?:[a-z]+:)?\/\/|data:image\/)(.*)/i", $v['url']) ? $v['url'] : url($v['url']);
  415. $v['menuclass'] = in_array($v['menutype'], ['dialog', 'ajax']) ? 'btn-' . $v['menutype'] : '';
  416. $v['menutabs'] = !$v['menutype'] || in_array($v['menutype'], ['default', 'addtabs']) ? 'addtabs="' . $v['id'] . '"' : '';
  417. $selected = $v['name'] == $fixedPage ? $v : $selected;
  418. $referer = $v['url'] == $refererUrl ? $v : $referer;
  419. }
  420. $lastArr = array_unique(array_filter(array_column($ruleList, 'pid')));
  421. $pidDiffArr = array_diff($pidArr, $lastArr);
  422. foreach ($ruleList as $index => $item) {
  423. if (in_array($item['id'], $pidDiffArr)) {
  424. unset($ruleList[$index]);
  425. }
  426. }
  427. if ($selected == $referer) {
  428. $referer = [];
  429. }
  430. $select_id = $referer ? $referer['id'] : ($selected ? $selected['id'] : 0);
  431. $menu = $nav = '';
  432. $showSubmenu = config('fastadmin.show_submenu');
  433. if (Config::get('fastadmin.multiplenav')) {
  434. $topList = [];
  435. foreach ($ruleList as $index => $item) {
  436. if (!$item['pid']) {
  437. $topList[] = $item;
  438. }
  439. }
  440. $selectParentIds = [];
  441. $tree = Tree::instance();
  442. $tree->init($ruleList);
  443. if ($select_id) {
  444. $selectParentIds = $tree->getParentsIds($select_id, true);
  445. }
  446. foreach ($topList as $index => $item) {
  447. $childList = Tree::instance()->getTreeMenu(
  448. $item['id'],
  449. '<li class="@class" pid="@pid"><a @extend href="@url@addtabs" addtabs="@id" class="@menuclass" url="@url" py="@py" pinyin="@pinyin"><i class="@icon"></i> <span>@title</span> <span class="pull-right-container">@caret @badge</span></a> @childlist</li>',
  450. $select_id,
  451. '',
  452. 'ul',
  453. 'class="treeview-menu' . ($showSubmenu ? ' menu-open' : '') . '"'
  454. );
  455. $current = in_array($item['id'], $selectParentIds);
  456. $url = $childList ? 'javascript:;' : $item['url'];
  457. $addtabs = $childList || !$url ? "" : (stripos($url, "?") !== false ? "&" : "?") . "ref=" . ($item['menutype'] ? $item['menutype'] : 'addtabs');
  458. $childList = str_replace(
  459. '" pid="' . $item['id'] . '"',
  460. ' ' . ($current ? '' : 'hidden') . '" pid="' . $item['id'] . '"',
  461. $childList
  462. );
  463. $nav .= '<li class="' . ($current ? 'active' : '') . '"><a ' . $item['extend'] . ' href="' . $url . $addtabs . '" ' . $item['menutabs'] . ' class="' . $item['menuclass'] . '" url="' . $url . '" title="' . $item['title'] . '"><i class="' . $item['icon'] . '"></i> <span>' . $item['title'] . '</span> <span class="pull-right-container"> </span></a> </li>';
  464. $menu .= $childList;
  465. }
  466. } else {
  467. // 构造菜单数据
  468. Tree::instance()->init($ruleList);
  469. $menu = Tree::instance()->getTreeMenu(
  470. 0,
  471. '<li class="@class"><a @extend href="@url@addtabs" @menutabs class="@menuclass" url="@url" py="@py" pinyin="@pinyin"><i class="@icon"></i> <span>@title</span> <span class="pull-right-container">@caret @badge</span></a> @childlist</li>',
  472. $select_id,
  473. '',
  474. 'ul',
  475. 'class="treeview-menu' . ($showSubmenu ? ' menu-open' : '') . '"'
  476. );
  477. if ($selected) {
  478. $nav .= '<li role="presentation" id="tab_' . $selected['id'] . '" class="' . ($referer ? '' : 'active') . '"><a href="#con_' . $selected['id'] . '" node-id="' . $selected['id'] . '" aria-controls="' . $selected['id'] . '" role="tab" data-toggle="tab"><i class="' . $selected['icon'] . ' fa-fw"></i> <span>' . $selected['title'] . '</span> </a></li>';
  479. }
  480. if ($referer) {
  481. $nav .= '<li role="presentation" id="tab_' . $referer['id'] . '" class="active"><a href="#con_' . $referer['id'] . '" node-id="' . $referer['id'] . '" aria-controls="' . $referer['id'] . '" role="tab" data-toggle="tab"><i class="' . $referer['icon'] . ' fa-fw"></i> <span>' . $referer['title'] . '</span> </a> <i class="close-tab fa fa-remove"></i></li>';
  482. }
  483. }
  484. return [$menu, $nav, $selected, $referer];
  485. }
  486. /**
  487. * 设置错误信息
  488. *
  489. * @param string $error 错误信息
  490. * @return Auth
  491. */
  492. public function setError($error)
  493. {
  494. $this->_error = $error;
  495. return $this;
  496. }
  497. /**
  498. * 获取错误信息
  499. * @return string
  500. */
  501. public function getError()
  502. {
  503. return $this->_error ? __($this->_error) : '';
  504. }
  505. }