login_controller.js 17 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410
  1. /**
  2. * 登录相关控制器
  3. *
  4. * @author CaiAoLin
  5. * @date 2017/6/8
  6. * @version
  7. */
  8. import UserModel from "../models/user_model";
  9. import SettingModel from "../models/setting_model";
  10. import CompilationModel from "../models/compilation_model";
  11. import LogModel from "../models/log_model";
  12. import LogType from "../../common/const/log_type_const";
  13. const SMS = require('../models/sms');
  14. const moment = require('moment');
  15. // 验证码
  16. const Captcha = require("../models/captcha");
  17. let mongoose = require("mongoose");
  18. let systemSettingModel = mongoose.model("system_setting");
  19. const uuidV1 = require('uuid/v1');
  20. class LoginController {
  21. /**
  22. * 登录页面
  23. *
  24. * @param {object} request
  25. * @param {object} response
  26. * @return {void}
  27. */
  28. async index(request, response) {
  29. // 判断是否有带token和ssoID参数
  30. if (request.query.ssoID !== undefined && request.query.token !== undefined) {
  31. let ssoID = request.query.ssoID;
  32. let token = request.query.token;
  33. let preferenceSetting = {};
  34. let compilationList = [];
  35. try {
  36. let userModel = new UserModel();
  37. // 调用接口验证登录信息
  38. let responseData = await userModel.getInfoFromSSO2(ssoID, token);
  39. // 先判断返回值是否为未激活状态
  40. if ( responseData === '-3') {
  41. throw '因邮箱未完成认证,账号未激活;去<a href="https://sso.smartcost.com.cn" target="_blank">激活</a>。';
  42. }
  43. if ( responseData === '-2') {
  44. throw 'token已过期,请重新登录Z+获取';
  45. }
  46. responseData = JSON.parse(responseData);
  47. if (typeof responseData !== 'object') {
  48. throw 'ssoId错误或token过期';
  49. }
  50. if (responseData.length <= 0) {
  51. throw '接口返回数据错误';
  52. }
  53. let userData = responseData[0];
  54. // 判断用户是否开启了只使用短信登录
  55. const userInfo = await userModel.findDataByAccount(userData.mobile);
  56. if (userInfo !== undefined && userInfo !== null && userInfo.isSmsLogin === 1) {
  57. let renderData = {
  58. mobile: userData.mobile,
  59. };
  60. response.render('users/html/login-sms', renderData);
  61. return;
  62. }
  63. let sessionUser = {
  64. ssoId: userData.id,
  65. username: userData.username,
  66. email: userData.useremail,
  67. mobile: userData.mobile,
  68. qq: userData.qq,
  69. isUserActive: userData.isUserActive,
  70. token: uuidV1(),
  71. };
  72. request.session.sessionUser = sessionUser;
  73. // 记录用户数据到数据库
  74. let result = await userModel.markUser(sessionUser, request);
  75. // 获取偏好设置
  76. let settingModel = new SettingModel();
  77. preferenceSetting = await settingModel.getPreferenceSetting(request.session.sessionUser.id);
  78. if (!result) {
  79. throw '标记用户信息失败!';
  80. }
  81. let compilationModel = new CompilationModel();
  82. if (preferenceSetting.login_ask === 1 || preferenceSetting.select_version === ''){
  83. preferenceSetting.login_ask = 1;
  84. compilationList = await compilationModel.getList();
  85. } else {
  86. compilationList = [];
  87. }
  88. // 获取编办信息
  89. let sessionCompilation = request.session.sessionCompilation;
  90. if (preferenceSetting.login_ask === 0 && !sessionCompilation &&
  91. preferenceSetting.select_version !== '') {
  92. let compilationData = await compilationModel.getCompilationById(preferenceSetting.select_version);
  93. // 判断当前用户的是使用免费版还是专业版
  94. let compilationVersion = await userModel.getVersionFromUpgrade(sessionUser.ssoId, preferenceSetting.select_version);
  95. request.session.compilationVersion = compilationVersion.version;
  96. request.session.sessionUser.compilationDeadline = compilationVersion.deadline;
  97. request.session.sessionCompilation = compilationData;
  98. if(request.session.sessionUser.latest_used !== preferenceSetting.select_version) await userModel.updateLatestUsed(request.session.sessionUser.id,preferenceSetting.select_version);
  99. }
  100. let systemSetting = await systemSettingModel.findOne({}).lean();
  101. request.session.systemSetting = systemSetting;
  102. request.session.online_start_time = +new Date();
  103. console.log(`${request.session.sessionUser.real_name}--id:${request.session.sessionUser.id}--登录了系统`);
  104. if (preferenceSetting.login_ask === 1 || preferenceSetting.select_version === '') {
  105. let renderData = {
  106. versionData: compilationList,
  107. };
  108. response.render('users/html/login-ver', renderData);
  109. } else {
  110. return response.redirect("/pm");
  111. }
  112. } catch (error) {
  113. console.log(error)
  114. return response.redirect("/login");
  115. }
  116. } else {
  117. let sessionUser = request.session.sessionUser;
  118. if (sessionUser !== undefined && sessionUser.ssoId >= 0) {
  119. return response.redirect("/pm");
  120. } else {
  121. response.render('users/html/login', {});
  122. }
  123. }
  124. }
  125. /**
  126. * 登录操作
  127. *
  128. * @param {object} request
  129. * @param {object} response
  130. * @return {string}
  131. */
  132. async login(request, response) {
  133. let preferenceSetting = {};
  134. let compilationList = [];
  135. try {
  136. let userModel = new UserModel();
  137. let responseData = '';
  138. if (request.body.account === undefined) {
  139. let mobile = request.body.mobile;
  140. let codeMsg = request.session.code;
  141. if (codeMsg !== undefined && request.body.code !== '') {
  142. console.log(codeMsg);
  143. const validMobile = codeMsg.split('_')[0];
  144. const code = codeMsg.split('_')[1];
  145. const time = codeMsg.split('_')[2];
  146. if (validMobile !== mobile) {
  147. throw '短信验证码错误';
  148. }
  149. if (Date.parse(new Date())/1000 > time+60*5 || request.body.code !== code) {
  150. throw '短信验证码错误或已过期';
  151. } else {
  152. delete request.session.code;
  153. }
  154. } else {
  155. throw '短信验证码错误或已过期。';
  156. }
  157. responseData = await userModel.getInfoFromSSOMobile(mobile);
  158. } else {
  159. let account = request.body.account;
  160. let password = request.body.pw;
  161. // 调用接口验证登录信息
  162. responseData = await userModel.getInfoFromSSO(account, password);
  163. }
  164. // 先判断返回值是否为未激活状态
  165. if ( responseData === '-3') {
  166. throw '因邮箱未完成认证,账号未激活;去<a href="https://sso.smartcost.com.cn" target="_blank">激活</a>。';
  167. }
  168. responseData = JSON.parse(responseData);
  169. if (typeof responseData !== 'object') {
  170. throw '邮箱/手机 或 密码错误';
  171. }
  172. if (responseData.length <= 0) {
  173. throw '接口返回数据错误';
  174. }
  175. // 正确登录后 存入session
  176. let userData = responseData[0];
  177. if (userData.mobile === '') {
  178. return response.json({error: 2,ssoId: userData.id});
  179. }
  180. //还要判断account是否是专业版用户
  181. // let isPro = true;
  182. // const userInfo = await userModel.findDataByAccount(account);
  183. //
  184. // if (userInfo && userInfo.upgrade_list !== undefined) {
  185. // for (const ul of userInfo.upgrade_list) {
  186. // if (ul.isUpgrade === true) {
  187. // isPro = true;
  188. // break;
  189. // }
  190. // }
  191. // }
  192. // 专业版短信验证码验证
  193. // if (isPro) {
  194. // const codeMsg = request.session.code;
  195. // if (codeMsg !== undefined && request.body.code !== '') {
  196. // const code = codeMsg.split('_')[0];
  197. // const time = codeMsg.split('_')[1];
  198. // console.log(code);
  199. // console.log(request.body.code);
  200. // if (Date.parse(new Date())/1000 > time+60*5 || request.body.code !== code) {
  201. // return response.json({error: 3, msg: '验证码错误。'});
  202. // } else {
  203. // delete request.session.code;
  204. // }
  205. // } else {
  206. // return response.json({error: 3, msg: '验证码错误。'});
  207. // }
  208. // }
  209. // 判断极验验证码是否通过
  210. // 先不使用,出现验证慢的情况
  211. // const captcha = new Captcha();
  212. // const captchResult = await captcha.validate(request);
  213. // if (!captchResult) {
  214. // throw '极验验证码错误';
  215. // }
  216. // 判断用户是否开启了只使用短信登录
  217. const userInfo = await userModel.findDataByAccount(userData.mobile);
  218. if (request.body.mobile === undefined && request.body.code === undefined && userInfo !== undefined && userInfo !== null && userInfo.isSmsLogin === 1) {
  219. return response.json({error: 3, msg: '只能手机短信登录。', data: userData.mobile});
  220. }
  221. let sessionUser = {
  222. ssoId: userData.id,
  223. company: userInfo.company,
  224. username: userData.username,
  225. email: userData.useremail,
  226. mobile: userData.mobile,
  227. qq: userData.qq,
  228. isUserActive: userData.isUserActive,
  229. newLogin:true,
  230. token: uuidV1(),
  231. };
  232. request.session.sessionUser = sessionUser;
  233. // 记录用户数据到数据库
  234. let result = await userModel.markUser(sessionUser, request);
  235. // 获取偏好设置
  236. let settingModel = new SettingModel();
  237. preferenceSetting = await settingModel.getPreferenceSetting(request.session.sessionUser.id);
  238. if (!result) {
  239. throw '标记用户信息失败!';
  240. }
  241. let compilationModel = new CompilationModel();
  242. if(preferenceSetting.login_ask === 1 || preferenceSetting.select_version === ''){
  243. preferenceSetting.login_ask = 1;
  244. compilationList = await compilationModel.getList();
  245. }
  246. else{
  247. compilationList = [];
  248. }
  249. // 获取编办信息
  250. let sessionCompilation = request.session.sessionCompilation;
  251. if (preferenceSetting.login_ask === 0 && !sessionCompilation &&
  252. preferenceSetting.select_version !== '') {
  253. let compilationData = await compilationModel.getCompilationById(preferenceSetting.select_version);
  254. // 判断当前用户的是使用免费版还是专业版
  255. let compilationVersion = await userModel.getVersionFromUpgrade(sessionUser.ssoId, preferenceSetting.select_version);
  256. request.session.compilationVersion = compilationVersion.version;
  257. request.session.sessionUser.compilationDeadline = compilationVersion.deadline;
  258. request.session.sessionCompilation = compilationData;
  259. if(request.session.sessionUser.latest_used !== preferenceSetting.select_version) await userModel.updateLatestUsed(request.session.sessionUser.id,preferenceSetting.select_version);
  260. }
  261. // 登录异常短信提醒功能
  262. const userinfo2 = await userModel.findDataByAccount(userData.mobile);
  263. if (userinfo2.isLoginValid === 1) {
  264. // 获取本次访问ip
  265. let ip = request.connection.remoteAddress;
  266. ip = ip.split(':');
  267. ip = ip[3] === undefined ? '' : ip[3];
  268. let logModel = new LogModel();
  269. let logCount = await logModel.count();
  270. logCount = logCount > 30 ? 30 : logCount;
  271. let page = 1;
  272. const loginList = await logModel.getLog(request.session.sessionUser.id, LogType.LOGIN_LOG, page, logCount);
  273. let messageFlag = true;
  274. for (const [index,log] of loginList.entries()) {
  275. if (log.message.ip === ip && index !== 0) {
  276. messageFlag = false;
  277. break;
  278. }
  279. }
  280. messageFlag = true;
  281. if (messageFlag) {
  282. // 发送短信
  283. const Sms = new SMS();
  284. const logInfo = loginList[0];
  285. await Sms.sendLoginMsg(userData.mobile, request.session.sessionUser.real_name, moment(logInfo.create_time).format('YYYY-MM-DD'), moment(logInfo.create_time).format('HH:mm:ss'), logInfo.message.ip_info, logInfo.message.ip);
  286. }
  287. }
  288. } catch (error) {
  289. console.log(error);
  290. return response.json({error: 1, msg: error});
  291. }
  292. let systemSetting = await systemSettingModel.findOne({}).lean();
  293. request.session.systemSetting = systemSetting;
  294. request.session.online_start_time = +new Date();
  295. console.log(`${request.session.sessionUser.real_name}--id:${request.session.sessionUser.id}--登录了系统`);
  296. response.json({
  297. error: 0,
  298. msg: '',
  299. login_ask: preferenceSetting.login_ask,
  300. compilation_list: JSON.stringify(compilationList),
  301. last_page: request.session.lastPage
  302. });
  303. }
  304. /**
  305. * 验证码注册
  306. *
  307. * @param {object} request
  308. * @param {object} response
  309. * @return {string}
  310. */
  311. async captcha(request, response) {
  312. const captcha = new Captcha();
  313. const res = await captcha.register(request);
  314. response.json(res);
  315. }
  316. /**
  317. * 判断用户是否是专业版用户
  318. * @param request
  319. * @param response
  320. * @returns {Promise<void>}
  321. */
  322. // async accountIsPro(request, response) {
  323. // let res = {
  324. // error: 0,
  325. // msg: '',
  326. // result: false,
  327. // };
  328. // try{
  329. // const account = request.body.account;
  330. // const password = request.body.pw;
  331. //
  332. // // 根据邮箱或手机号获取账号信息
  333. // let userModel = new UserModel();
  334. // // 调用接口验证登录信息
  335. // let responseData = await userModel.getInfoFromSSO(account, password);
  336. // console.log(responseData);
  337. // // 先判断返回值是否为未激活状态
  338. // if ( responseData === '-3') {
  339. // throw '因邮箱未完成认证,账号未激活;去<a href="https://sso.smartcost.com.cn" target="_blank">激活</a>。';
  340. // }
  341. // responseData = JSON.parse(responseData);
  342. // if (typeof responseData !== 'object') {
  343. // throw '邮箱/手机 或 密码错误';
  344. // }
  345. //
  346. // if (responseData.length <= 0) {
  347. // throw '接口返回数据错误';
  348. // }
  349. //
  350. // // 正确登录后 存入session
  351. // let userData = responseData[0];
  352. //
  353. // if (userData.mobile === '') {
  354. // return response.json({error: 2,ssoId: userData.id});
  355. // }
  356. //
  357. // // const userInfo = await userModel.findDataByAccount(account);
  358. // // if (userInfo && userInfo.upgrade_list !== undefined) {
  359. // // for (const ul of userInfo.upgrade_list) {
  360. // // if (ul.isUpgrade === true) {
  361. // // res.result = true;
  362. // // res.data = userInfo.mobile;
  363. // // break;
  364. // // }
  365. // // }
  366. // // } else {
  367. // // res.msg = '当前未存在此用户';
  368. // // }
  369. // res.result = true;
  370. // // if (userInfo) {
  371. // // res.data = userInfo.mobile;
  372. // // } else {
  373. // res.data = userData.mobile;
  374. // // }
  375. // } catch (err) {
  376. // res.error = 1;
  377. // res.msg = err;
  378. // }
  379. //
  380. // response.json(res);
  381. // }
  382. }
  383. export default LoginController;