auth.php 4.1 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150
  1. <?php
  2. session_start(); // starts new or resumes existing session
  3. session_regenerate_id(true); // regenerates SESSIONID to prevent hijacking
  4. Doo::loadModel('users');
  5. Doo::loadModel('usession');
  6. Doo::loadModelAt('ausers', 'admin');
  7. Doo::loadClass('user');
  8. Doo::loadModel('uprofile');
  9. class Auth {
  10. private $users, $usession, $user, $uinfo, $ausers, $profile;
  11. public function __construct() {
  12. $this->users = new Users();
  13. $this->usession = new Usession();
  14. $this->user = new User();
  15. $this->ausers = new AUsers();
  16. $this->profile = new Uprofile();
  17. }
  18. private function __setcookie($key, $value) {
  19. setcookie($this->cookiePre . $key, $value, 0, '/', $this->siteUrl, 0);
  20. }
  21. public function login($uname, $upasswd) {
  22. $uinfo = $this->checkLogin($uname, $upasswd);
  23. if (isset($uinfo['uid'])) {
  24. $this->uinfo = $uinfo;
  25. return TRUE;
  26. } else {
  27. return FALSE;
  28. }
  29. }
  30. public function getUinfo() {
  31. return $this->uinfo;
  32. }
  33. public function getUid() {
  34. if (isset($_SESSION['uid']) && $_SESSION['uid']) {
  35. return $_SESSION['uid'];
  36. } else {
  37. return FALSE;
  38. }
  39. }
  40. public function getUemail() {
  41. if (isset($_SESSION['uemail']) && $_SESSION['uemail']) {
  42. return $_SESSION['uemail'];
  43. } else {
  44. return 0;
  45. }
  46. }
  47. public function setUid($uid) {
  48. return $_SESSION['uid'] = $uid;
  49. }
  50. public function setUemail($uemail) {
  51. return $_SESSION['uemail'] = $uemail;
  52. }
  53. public function getAvatar($uid) {
  54. // $dir1 = ceil($uid / 10000);
  55. // $dir2 = ceil($uid % 10000 / 1000);
  56. // $url = 'http://sso.smartcost.com.cn/' . 'data/avatar/' . $dir1 . '/' . $dir2 . '/' . $uid . '/';
  57. // $avatar = array('180' => $url . '180x180.jpg', '90' => $url . '90x90.jpg', '45' => $url . '45x45.jpg', '30' => $url . '30x30.jpg');
  58. // return $avatar;
  59. $valArray = $this->profile->getOne(array('where' => 'userid=?', 'param' => array($uid), 'asArray' => TRUE));
  60. return Doo::conf()->APP_URL . $valArray['avatar'];
  61. }
  62. public function checkLogin($uemail, $upasswd) {
  63. return $this->user->login($uemail, $upasswd);
  64. }
  65. public function logout() {
  66. session_destroy();
  67. setcookie('token', '-1', 0, '/', 'jl.local', FALSE, TRUE);
  68. }
  69. public function checkauth() {
  70. //TODO 启用SESSION变量避免重复查询数据库
  71. if (isset($_COOKIE['M0s5Yi_yn_k']) && isset($_COOKIE['M0s5Yi_yn_v'])) {
  72. $uname = $this->decryptCookie($_COOKIE['M0s5Yi_yn_k']);
  73. $passwd = $this->decryptCookie($_COOKIE['M0s5Yi_yn_v']);
  74. if ($uname && $passwd) {
  75. return TRUE;
  76. } else {
  77. return FALSE;
  78. }
  79. } else {
  80. return FALSE;
  81. }
  82. }
  83. function isLoggedIn() {
  84. if (isset($_SESSION['token']) && isset($_COOKIE['token'])) {
  85. if ($_SESSION['token'] != $_COOKIE['token']) {
  86. return TRUE;
  87. }
  88. }
  89. return FALSE;
  90. }
  91. public function getUname() {
  92. //TODO 启用SESSION变量避免重复查询数据库
  93. if (isset($_COOKIE['M0s5Yi_yn_k']) && isset($_COOKIE['M0s5Yi_yn_v'])) {
  94. $uname = $this->decryptCookie($_COOKIE['M0s5Yi_yn_k']);
  95. $passwd = $this->decryptCookie($_COOKIE['M0s5Yi_yn_v']);
  96. if ($uname && $passwd) {
  97. return $uname;
  98. } else {
  99. return FALSE;
  100. }
  101. } else {
  102. return FALSE;
  103. }
  104. }
  105. private function encryptCookie($value) {
  106. if (!$value) {
  107. return false;
  108. }
  109. $key = '290234lk23jk23djLHSWCs92s';
  110. $text = $value;
  111. $iv_size = mcrypt_get_iv_size(MCRYPT_RIJNDAEL_256, MCRYPT_MODE_ECB);
  112. $iv = mcrypt_create_iv($iv_size, MCRYPT_RAND);
  113. $crypttext = mcrypt_encrypt(MCRYPT_RIJNDAEL_256, $key, $text, MCRYPT_MODE_ECB, $iv);
  114. return trim(base64_encode($crypttext)); //encode for cookie
  115. }
  116. private function decryptCookie($value) {
  117. if (!$value) {
  118. return false;
  119. }
  120. $key = '290234lk23jk23djLHSWCs92s';
  121. $crypttext = base64_decode($value); //decode cookie
  122. $iv_size = mcrypt_get_iv_size(MCRYPT_RIJNDAEL_256, MCRYPT_MODE_ECB);
  123. $iv = mcrypt_create_iv($iv_size, MCRYPT_RAND);
  124. $decrypttext = mcrypt_decrypt(MCRYPT_RIJNDAEL_256, $key, $crypttext, MCRYPT_MODE_ECB, $iv);
  125. return trim($decrypttext);
  126. }
  127. }
  128. ?>