login_controller.js 18 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415
  1. /**
  2. * 登录相关控制器
  3. *
  4. * @author CaiAoLin
  5. * @date 2017/6/8
  6. * @version
  7. */
  8. import UserModel from "../models/user_model";
  9. import SettingModel from "../models/setting_model";
  10. import CompilationModel from "../models/compilation_model";
  11. import LogModel from "../models/log_model";
  12. import LogType from "../../common/const/log_type_const";
  13. const SMS = require('../models/sms');
  14. const moment = require('moment');
  15. // 验证码
  16. const Captcha = require("../models/captcha");
  17. let mongoose = require("mongoose");
  18. let systemSettingModel = mongoose.model("system_setting");
  19. class LoginController {
  20. /**
  21. * 登录页面
  22. *
  23. * @param {object} request
  24. * @param {object} response
  25. * @return {void}
  26. */
  27. async index(request, response) {
  28. // 判断是否有带token和ssoID参数
  29. if (request.query.ssoID !== undefined && request.query.token !== undefined) {
  30. let ssoID = request.query.ssoID;
  31. let token = request.query.token;
  32. let preferenceSetting = {};
  33. let compilationList = [];
  34. try {
  35. let userModel = new UserModel();
  36. // 调用接口验证登录信息
  37. let responseData = await userModel.getInfoFromSSO2(ssoID, token);
  38. // 先判断返回值是否为未激活状态
  39. if ( responseData === '-3') {
  40. throw '因邮箱未完成认证,账号未激活;去<a href="https://sso.smartcost.com.cn" target="_blank">激活</a>。';
  41. }
  42. if ( responseData === '-2') {
  43. throw 'token已过期,请重新登录Z+获取';
  44. }
  45. responseData = JSON.parse(responseData);
  46. if (typeof responseData !== 'object') {
  47. throw 'ssoId错误或token过期';
  48. }
  49. if (responseData.length <= 0) {
  50. throw '接口返回数据错误';
  51. }
  52. let userData = responseData[0];
  53. // 判断用户是否开启了只使用短信登录
  54. const userInfo = await userModel.findDataByAccount(userData.mobile);
  55. if (userInfo !== undefined && userInfo !== null && userInfo.isSmsLogin === 1) {
  56. let renderData = {
  57. mobile: userData.mobile,
  58. };
  59. response.render('users/html/login-sms', renderData);
  60. return;
  61. }
  62. let sessionUser = {
  63. ssoId: userData.id,
  64. username: userData.username,
  65. email: userData.useremail,
  66. mobile: userData.mobile,
  67. isUserActive: userData.isUserActive,
  68. };
  69. request.session.sessionUser = sessionUser;
  70. // 记录用户数据到数据库
  71. let result = await userModel.markUser(sessionUser, request);
  72. // 获取偏好设置
  73. let settingModel = new SettingModel();
  74. preferenceSetting = await settingModel.getPreferenceSetting(request.session.sessionUser.id);
  75. if (!result) {
  76. throw '标记用户信息失败!';
  77. }
  78. let compilationModel = new CompilationModel();
  79. if (preferenceSetting.login_ask === 1 || preferenceSetting.select_version === ''){
  80. preferenceSetting.login_ask = 1;
  81. compilationList = await compilationModel.getList();
  82. } else {
  83. compilationList = [];
  84. }
  85. // 获取编办信息
  86. let sessionCompilation = request.session.sessionCompilation;
  87. if (preferenceSetting.login_ask === 0 && !sessionCompilation &&
  88. preferenceSetting.select_version !== '') {
  89. let compilationData = await compilationModel.getCompilationById(preferenceSetting.select_version);
  90. // 判断当前用户的是使用免费版还是专业版
  91. let compilationVersion = await userModel.getVersionFromUpgrade(sessionUser.ssoId, preferenceSetting.select_version);
  92. request.session.compilationVersion = compilationVersion;
  93. request.session.sessionCompilation = compilationData;
  94. if(request.session.sessionUser.latest_used !== preferenceSetting.select_version) await userModel.updateLatestUsed(request.session.sessionUser.id,preferenceSetting.select_version);
  95. }
  96. let systemSetting = await systemSettingModel.findOne({}).lean();
  97. request.session.systemSetting = systemSetting;
  98. request.session.online_start_time = +new Date();
  99. console.log(`${request.session.sessionUser.real_name}--id:${request.session.sessionUser.id}--登录了系统`);
  100. if (preferenceSetting.login_ask === 1 || preferenceSetting.select_version === '') {
  101. let renderData = {
  102. versionData: compilationList,
  103. };
  104. response.render('users/html/login-ver', renderData);
  105. } else {
  106. return response.redirect("/pm");
  107. }
  108. } catch (error) {
  109. console.log(error)
  110. return response.redirect("/login");
  111. }
  112. } else {
  113. let sessionUser = request.session.sessionUser;
  114. if (sessionUser !== undefined && sessionUser.ssoId >= 0) {
  115. return response.redirect("/pm");
  116. } else {
  117. response.render('users/html/login', {});
  118. }
  119. }
  120. }
  121. /**
  122. * 登录操作
  123. *
  124. * @param {object} request
  125. * @param {object} response
  126. * @return {string}
  127. */
  128. async login(request, response) {
  129. console.log("开始登录操作------------------");
  130. let preferenceSetting = {};
  131. let compilationList = [];
  132. try {
  133. let userModel = new UserModel();
  134. let responseData = '';
  135. if (request.body.account === undefined) {
  136. let mobile = request.body.mobile;
  137. let codeMsg = request.session.code;
  138. if (codeMsg !== undefined && request.body.code !== '') {
  139. console.log(codeMsg);
  140. const validMobile = codeMsg.split('_')[0];
  141. const code = codeMsg.split('_')[1];
  142. const time = codeMsg.split('_')[2];
  143. if (validMobile !== mobile) {
  144. throw '短信验证码错误';
  145. }
  146. if (Date.parse(new Date())/1000 > time+60*5 || request.body.code !== code) {
  147. throw '短信验证码错误或已过期';
  148. } else {
  149. delete request.session.code;
  150. }
  151. } else {
  152. throw '短信验证码错误或已过期。';
  153. }
  154. responseData = await userModel.getInfoFromSSOMobile(mobile);
  155. console.log("getInfoFromSSOMobile complete------------------");
  156. } else {
  157. let account = request.body.account;
  158. let password = request.body.pw;
  159. // 调用接口验证登录信息
  160. responseData = await userModel.getInfoFromSSO(account, password);
  161. console.log("getInfoFromSSO complete------------------");
  162. }
  163. // 先判断返回值是否为未激活状态
  164. if ( responseData === '-3') {
  165. throw '因邮箱未完成认证,账号未激活;去<a href="https://sso.smartcost.com.cn" target="_blank">激活</a>。';
  166. }
  167. responseData = JSON.parse(responseData);
  168. if (typeof responseData !== 'object') {
  169. throw '邮箱/手机 或 密码错误';
  170. }
  171. if (responseData.length <= 0) {
  172. throw '接口返回数据错误';
  173. }
  174. // 正确登录后 存入session
  175. let userData = responseData[0];
  176. if (userData.mobile === '') {
  177. return response.json({error: 2,ssoId: userData.id});
  178. }
  179. //还要判断account是否是专业版用户
  180. // let isPro = false;
  181. // const userInfo = await userModel.findDataByAccount(account);
  182. //
  183. // if (userInfo && userInfo.upgrade_list !== undefined) {
  184. // for (const ul of userInfo.upgrade_list) {
  185. // if (ul.isUpgrade === true) {
  186. // isPro = true;
  187. // break;
  188. // }
  189. // }
  190. // }
  191. // // 专业版短信验证码验证
  192. // if (isPro) {
  193. // const codeMsg = request.session.code;
  194. // if (codeMsg !== undefined && request.body.code !== '') {
  195. // const code = codeMsg.split('_')[0];
  196. // const time = codeMsg.split('_')[1];
  197. // console.log(code);
  198. // console.log(request.body.code);
  199. // if (Date.parse(new Date())/1000 > time+60*5 || request.body.code !== code) {
  200. // return response.json({error: 3, msg: '验证码错误。'});
  201. // } else {
  202. // delete request.session.code;
  203. // }
  204. // } else {
  205. // return response.json({error: 3, msg: '验证码错误。'});
  206. // }
  207. // }
  208. // 判断极验验证码是否通过
  209. // const captcha = new Captcha();
  210. // const captchResult = await captcha.validate(request);
  211. // console.log(captchResult);
  212. // if (!captchResult) {
  213. // throw '极验验证码错误';
  214. // }
  215. // 判断用户是否开启了只使用短信登录
  216. const userInfo = await userModel.findDataByAccount(userData.mobile);
  217. console.log("判断用户是否开启了只使用短信登录 完成------------------");
  218. if (request.body.mobile === undefined && request.body.code === undefined && userInfo !== undefined && userInfo !== null && userInfo.isSmsLogin === 1) {
  219. return response.json({error: 3, msg: '只能手机短信登录。', data: userData.mobile});
  220. }
  221. // for (const ul of userInfo.upgrade_list) {
  222. // if (ul.isUpgrade === true) {
  223. // isPro = true;
  224. // break;
  225. // }
  226. // }
  227. // }
  228. let sessionUser = {
  229. ssoId: userData.id,
  230. company: userInfo.company,
  231. username: userData.username,
  232. email: userData.useremail,
  233. mobile: userData.mobile,
  234. isUserActive: userData.isUserActive,
  235. };
  236. request.session.sessionUser = sessionUser;
  237. // 记录用户数据到数据库
  238. let result = await userModel.markUser(sessionUser, request);
  239. console.log("markUser 完成------------------");
  240. // 获取偏好设置
  241. let settingModel = new SettingModel();
  242. preferenceSetting = await settingModel.getPreferenceSetting(request.session.sessionUser.id);
  243. console.log("获取偏好设置 完成------------------");
  244. if (!result) {
  245. throw '标记用户信息失败!';
  246. }
  247. let compilationModel = new CompilationModel();
  248. if(preferenceSetting.login_ask === 1 || preferenceSetting.select_version === ''){
  249. preferenceSetting.login_ask = 1;
  250. compilationList = await compilationModel.getList();
  251. console.log("compilationList 完成------------------");
  252. }
  253. else{
  254. compilationList = [];
  255. }
  256. // 获取编办信息
  257. let sessionCompilation = request.session.sessionCompilation;
  258. if (preferenceSetting.login_ask === 0 && !sessionCompilation &&
  259. preferenceSetting.select_version !== '') {
  260. let compilationData = await compilationModel.getCompilationById(preferenceSetting.select_version);
  261. // 判断当前用户的是使用免费版还是专业版
  262. let compilationVersion = await userModel.getVersionFromUpgrade(sessionUser.ssoId, preferenceSetting.select_version);
  263. console.log("当前用户的是使用免费版还是专业版 完成------------------");
  264. request.session.compilationVersion = compilationVersion;
  265. request.session.sessionCompilation = compilationData;
  266. if(request.session.sessionUser.latest_used !== preferenceSetting.select_version) await userModel.updateLatestUsed(request.session.sessionUser.id,preferenceSetting.select_version);
  267. }
  268. // 登录异常短信提醒功能
  269. const userinfo2 = await userModel.findDataByAccount(userData.mobile);
  270. if (userinfo2.isLoginValid === 1) {
  271. // 获取本次访问ip
  272. let ip = request.connection.remoteAddress;
  273. ip = ip.split(':');
  274. ip = ip[3] === undefined ? '' : ip[3];
  275. let logModel = new LogModel();
  276. let logCount = await logModel.count();
  277. logCount = logCount > 30 ? 30 : logCount;
  278. let page = 1;
  279. const loginList = await logModel.getLog(request.session.sessionUser.id, LogType.LOGIN_LOG, page, logCount);
  280. let messageFlag = true;
  281. for (const [index,log] of loginList.entries()) {
  282. if (log.message.ip === ip && index !== 0) {
  283. messageFlag = false;
  284. break;
  285. }
  286. }
  287. messageFlag = true;
  288. if (messageFlag) {
  289. // 发送短信
  290. const Sms = new SMS();
  291. const logInfo = loginList[0];
  292. await Sms.sendLoginMsg(userData.mobile, request.session.sessionUser.real_name, moment(logInfo.create_time).format('YYYY-MM-DD'), moment(logInfo.create_time).format('HH:mm:ss'), logInfo.message.ip_info, logInfo.message.ip);
  293. console.log("sendLoginMsg 完成------------------");
  294. // const msg = '【纵横云计价】您的账号(账号昵称:'+ request.session.sessionUser.real_name +')于' + moment(logInfo.create_time).format('YYYY-MM-DD HH:mm:ss') + '在' + logInfo.message.ip_info + '(' + logInfo.message.ip + ')' + '登录成功。纵横云计价提醒您,如果怀疑此次登录行为有异常,请及时修改账号密码。';
  295. // console.log(msg);
  296. }
  297. }
  298. } catch (error) {
  299. console.log(error);
  300. return response.json({error: 1, msg: error});
  301. }
  302. let systemSetting = await systemSettingModel.findOne({}).lean();
  303. request.session.systemSetting = systemSetting;
  304. request.session.online_start_time = +new Date();
  305. console.log(`${request.session.sessionUser.real_name}--id:${request.session.sessionUser.id}--登录了系统`);
  306. response.json({
  307. error: 0,
  308. msg: '',
  309. login_ask: preferenceSetting.login_ask,
  310. compilation_list: JSON.stringify(compilationList),
  311. last_page: request.session.lastPage
  312. });
  313. }
  314. /**
  315. * 验证码注册
  316. *
  317. * @param {object} request
  318. * @param {object} response
  319. * @return {string}
  320. */
  321. async captcha(request, response) {
  322. const captcha = new Captcha();
  323. const res = await captcha.register(request);
  324. response.json(res);
  325. }
  326. /**
  327. * 判断用户是否是专业版用户
  328. * @param request
  329. * @param response
  330. * @returns {Promise<void>}
  331. */
  332. // async accountIsPro(request, response) {
  333. // let res = {
  334. // error: 0,
  335. // msg: '',
  336. // result: false,
  337. // };
  338. // try{
  339. // const account = request.body.account;
  340. // const password = request.body.pw;
  341. //
  342. // // 根据邮箱或手机号获取账号信息
  343. // let userModel = new UserModel();
  344. // // 调用接口验证登录信息
  345. // let responseData = await userModel.getInfoFromSSO(account, password);
  346. // // 先判断返回值是否为未激活状态
  347. // if ( responseData === '-3') {
  348. // throw '因邮箱未完成认证,账号未激活;去<a href="https://sso.smartcost.com.cn" target="_blank">激活</a>。';
  349. // }
  350. // responseData = JSON.parse(responseData);
  351. // if (typeof responseData !== 'object') {
  352. // throw '邮箱/手机 或 密码错误';
  353. // }
  354. //
  355. // if (responseData.length <= 0) {
  356. // throw '接口返回数据错误';
  357. // }
  358. //
  359. // // 正确登录后 存入session
  360. // let userData = responseData[0];
  361. //
  362. // if (userData.mobile === '') {
  363. // return response.json({error: 2,ssoId: userData.id});
  364. // }
  365. //
  366. // const userInfo = await userModel.findDataByAccount(account);
  367. // if (userInfo && userInfo.upgrade_list !== undefined) {
  368. // for (const ul of userInfo.upgrade_list) {
  369. // if (ul.isUpgrade === true) {
  370. // res.result = true;
  371. // res.data = userInfo.mobile;
  372. // break;
  373. // }
  374. // }
  375. // } else {
  376. // res.msg = '当前未存在此用户';
  377. // }
  378. // } catch (err) {
  379. // res.error = 1;
  380. // res.msg = err;
  381. // }
  382. //
  383. // response.json(res);
  384. // }
  385. }
  386. export default LoginController;