login_controller.js 16 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394
  1. /**
  2. * 登录相关控制器
  3. *
  4. * @author CaiAoLin
  5. * @date 2017/6/8
  6. * @version
  7. */
  8. import UserModel from "../models/user_model";
  9. import SettingModel from "../models/setting_model";
  10. import CompilationModel from "../models/compilation_model";
  11. import LogModel from "../models/log_model";
  12. import LogType from "../../common/const/log_type_const";
  13. const SMS = require('../models/sms');
  14. const moment = require('moment');
  15. // 验证码
  16. const Captcha = require("../models/captcha");
  17. class LoginController {
  18. /**
  19. * 登录页面
  20. *
  21. * @param {object} request
  22. * @param {object} response
  23. * @return {void}
  24. */
  25. async index(request, response) {
  26. // 判断是否有带token和ssoID参数
  27. if (request.query.ssoID !== undefined && request.query.token !== undefined) {
  28. let ssoID = request.query.ssoID;
  29. let token = request.query.token;
  30. let preferenceSetting = {};
  31. let compilationList = [];
  32. try {
  33. let userModel = new UserModel();
  34. // 调用接口验证登录信息
  35. let responseData = await userModel.getInfoFromSSO2(ssoID, token);
  36. // 先判断返回值是否为未激活状态
  37. if ( responseData === '-3') {
  38. throw '因邮箱未完成认证,账号未激活;去<a href="https://sso.smartcost.com.cn" target="_blank">激活</a>。';
  39. }
  40. if ( responseData === '-2') {
  41. throw 'token已过期,请重新登录Z+获取';
  42. }
  43. responseData = JSON.parse(responseData);
  44. if (typeof responseData !== 'object') {
  45. throw 'ssoId错误或token过期';
  46. }
  47. if (responseData.length <= 0) {
  48. throw '接口返回数据错误';
  49. }
  50. let userData = responseData[0];
  51. // 判断用户是否开启了只使用短信登录
  52. const userInfo = await userModel.findDataByAccount(userData.mobile);
  53. if (userInfo !== undefined && userInfo !== null && userInfo.isSmsLogin === 1) {
  54. let renderData = {
  55. mobile: userData.mobile,
  56. };
  57. response.render('users/html/login-sms', renderData);
  58. return;
  59. }
  60. let sessionUser = {
  61. ssoId: userData.id,
  62. username: userData.username,
  63. email: userData.useremail,
  64. mobile: userData.mobile,
  65. isUserActive: userData.isUserActive,
  66. };
  67. request.session.sessionUser = sessionUser;
  68. // 记录用户数据到数据库
  69. let result = await userModel.markUser(sessionUser, request);
  70. // 获取偏好设置
  71. let settingModel = new SettingModel();
  72. preferenceSetting = await settingModel.getPreferenceSetting(request.session.sessionUser.id);
  73. if (!result) {
  74. throw '标记用户信息失败!';
  75. }
  76. let compilationModel = new CompilationModel();
  77. if (preferenceSetting.login_ask === 1 || preferenceSetting.select_version === ''){
  78. preferenceSetting.login_ask = 1;
  79. compilationList = await compilationModel.getList();
  80. } else {
  81. compilationList = [];
  82. }
  83. // 获取编办信息
  84. let sessionCompilation = request.session.sessionCompilation;
  85. if (preferenceSetting.login_ask === 0 && !sessionCompilation &&
  86. preferenceSetting.select_version !== '') {
  87. let compilationData = await compilationModel.getCompilationById(preferenceSetting.select_version);
  88. // 判断当前用户的是使用免费版还是专业版
  89. let compilationVersion = await userModel.getVersionFromUpgrade(sessionUser.ssoId, preferenceSetting.select_version);
  90. request.session.compilationVersion = compilationVersion;
  91. request.session.sessionCompilation = compilationData;
  92. if(request.session.sessionUser.latest_used !== preferenceSetting.select_version) await userModel.updateLatestUsed(request.session.sessionUser.id,preferenceSetting.select_version);
  93. }
  94. request.session.online_start_time = +new Date();
  95. console.log(`${request.session.sessionUser.real_name}--id:${request.session.sessionUser.id}--登录了系统`);
  96. if (preferenceSetting.login_ask === 1 || preferenceSetting.select_version === '') {
  97. let renderData = {
  98. versionData: compilationList,
  99. };
  100. response.render('users/html/login-ver', renderData);
  101. } else {
  102. return response.redirect("/pm");
  103. }
  104. } catch (error) {
  105. console.log(error)
  106. return response.redirect("/login");
  107. }
  108. } else {
  109. let sessionUser = request.session.sessionUser;
  110. if (sessionUser !== undefined && sessionUser.ssoId >= 0) {
  111. return response.redirect("/pm");
  112. } else {
  113. response.render('users/html/login', {});
  114. }
  115. }
  116. }
  117. /**
  118. * 登录操作
  119. *
  120. * @param {object} request
  121. * @param {object} response
  122. * @return {string}
  123. */
  124. async login(request, response) {
  125. let preferenceSetting = {};
  126. let compilationList = [];
  127. try {
  128. let userModel = new UserModel();
  129. let responseData = '';
  130. if (request.body.account === undefined) {
  131. let mobile = request.body.mobile;
  132. let codeMsg = request.session.code;
  133. if (codeMsg !== undefined && request.body.code !== '') {
  134. console.log(codeMsg);
  135. const validMobile = codeMsg.split('_')[0];
  136. const code = codeMsg.split('_')[1];
  137. const time = codeMsg.split('_')[2];
  138. if (validMobile !== mobile) {
  139. throw '短信验证码错误';
  140. }
  141. if (Date.parse(new Date())/1000 > time+60*5 || request.body.code !== code) {
  142. throw '短信验证码错误或已过期';
  143. } else {
  144. delete request.session.code;
  145. }
  146. } else {
  147. throw '短信验证码错误或已过期。';
  148. }
  149. responseData = await userModel.getInfoFromSSOMobile(mobile);
  150. } else {
  151. let account = request.body.account;
  152. let password = request.body.pw;
  153. // 调用接口验证登录信息
  154. responseData = await userModel.getInfoFromSSO(account, password);
  155. }
  156. // 先判断返回值是否为未激活状态
  157. if ( responseData === '-3') {
  158. throw '因邮箱未完成认证,账号未激活;去<a href="https://sso.smartcost.com.cn" target="_blank">激活</a>。';
  159. }
  160. responseData = JSON.parse(responseData);
  161. if (typeof responseData !== 'object') {
  162. throw '邮箱/手机 或 密码错误';
  163. }
  164. if (responseData.length <= 0) {
  165. throw '接口返回数据错误';
  166. }
  167. // 正确登录后 存入session
  168. let userData = responseData[0];
  169. if (userData.mobile === '') {
  170. return response.json({error: 2,ssoId: userData.id});
  171. }
  172. //还要判断account是否是专业版用户
  173. // let isPro = true;
  174. // const userInfo = await userModel.findDataByAccount(account);
  175. //
  176. // if (userInfo && userInfo.upgrade_list !== undefined) {
  177. // for (const ul of userInfo.upgrade_list) {
  178. // if (ul.isUpgrade === true) {
  179. // isPro = true;
  180. // break;
  181. // }
  182. // }
  183. // }
  184. // 专业版短信验证码验证
  185. // if (isPro) {
  186. // const codeMsg = request.session.code;
  187. // if (codeMsg !== undefined && request.body.code !== '') {
  188. // const code = codeMsg.split('_')[0];
  189. // const time = codeMsg.split('_')[1];
  190. // console.log(code);
  191. // console.log(request.body.code);
  192. // if (Date.parse(new Date())/1000 > time+60*5 || request.body.code !== code) {
  193. // return response.json({error: 3, msg: '验证码错误。'});
  194. // } else {
  195. // delete request.session.code;
  196. // }
  197. // } else {
  198. // return response.json({error: 3, msg: '验证码错误。'});
  199. // }
  200. // }
  201. // 判断极验验证码是否通过
  202. const captcha = new Captcha();
  203. const captchResult = await captcha.validate(request);
  204. if (!captchResult) {
  205. throw '极验验证码错误';
  206. }
  207. // 判断用户是否开启了只使用短信登录
  208. const userInfo = await userModel.findDataByAccount(userData.mobile);
  209. if (request.body.mobile === undefined && request.body.code === undefined && userInfo !== undefined && userInfo !== null && userInfo.isSmsLogin === 1) {
  210. return response.json({error: 3, msg: '只能手机短信登录。', data: userData.mobile});
  211. }
  212. let sessionUser = {
  213. ssoId: userData.id,
  214. username: userData.username,
  215. email: userData.useremail,
  216. mobile: userData.mobile,
  217. isUserActive: userData.isUserActive,
  218. };
  219. request.session.sessionUser = sessionUser;
  220. // 记录用户数据到数据库
  221. let result = await userModel.markUser(sessionUser, request);
  222. // 获取偏好设置
  223. let settingModel = new SettingModel();
  224. preferenceSetting = await settingModel.getPreferenceSetting(request.session.sessionUser.id);
  225. if (!result) {
  226. throw '标记用户信息失败!';
  227. }
  228. let compilationModel = new CompilationModel();
  229. if(preferenceSetting.login_ask === 1 || preferenceSetting.select_version === ''){
  230. preferenceSetting.login_ask = 1;
  231. compilationList = await compilationModel.getList();
  232. }
  233. else{
  234. compilationList = [];
  235. }
  236. // 获取编办信息
  237. let sessionCompilation = request.session.sessionCompilation;
  238. if (preferenceSetting.login_ask === 0 && !sessionCompilation &&
  239. preferenceSetting.select_version !== '') {
  240. let compilationData = await compilationModel.getCompilationById(preferenceSetting.select_version);
  241. // 判断当前用户的是使用免费版还是专业版
  242. let compilationVersion = await userModel.getVersionFromUpgrade(sessionUser.ssoId, preferenceSetting.select_version);
  243. request.session.compilationVersion = compilationVersion;
  244. request.session.sessionCompilation = compilationData;
  245. if(request.session.sessionUser.latest_used !== preferenceSetting.select_version) await userModel.updateLatestUsed(request.session.sessionUser.id,preferenceSetting.select_version);
  246. }
  247. // 登录异常短信提醒功能
  248. const userinfo2 = await userModel.findDataByAccount(userData.mobile);
  249. if (userinfo2.isLoginValid === 1) {
  250. // 获取本次访问ip
  251. let ip = request.connection.remoteAddress;
  252. ip = ip.split(':');
  253. ip = ip[3] === undefined ? '' : ip[3];
  254. let logModel = new LogModel();
  255. let logCount = await logModel.count();
  256. logCount = logCount > 30 ? 30 : logCount;
  257. let page = 1;
  258. const loginList = await logModel.getLog(request.session.sessionUser.id, LogType.LOGIN_LOG, page, logCount);
  259. let messageFlag = true;
  260. for (const [index,log] of loginList.entries()) {
  261. if (log.message.ip === ip && index !== 0) {
  262. messageFlag = false;
  263. break;
  264. }
  265. }
  266. messageFlag = true;
  267. if (messageFlag) {
  268. // 发送短信
  269. const Sms = new SMS();
  270. const logInfo = loginList[0];
  271. await Sms.sendLoginMsg(userData.mobile, request.session.sessionUser.real_name, moment(logInfo.create_time).format('YYYY-MM-DD'), moment(logInfo.create_time).format('HH:mm:ss'), logInfo.message.ip_info, logInfo.message.ip);
  272. }
  273. }
  274. } catch (error) {
  275. console.log(error);
  276. return response.json({error: 1, msg: error});
  277. }
  278. request.session.online_start_time = +new Date();
  279. console.log(`${request.session.sessionUser.real_name}--id:${request.session.sessionUser.id}--登录了系统`);
  280. response.json({
  281. error: 0,
  282. msg: '',
  283. login_ask: preferenceSetting.login_ask,
  284. compilation_list: JSON.stringify(compilationList),
  285. last_page: request.session.lastPage
  286. });
  287. }
  288. /**
  289. * 验证码注册
  290. *
  291. * @param {object} request
  292. * @param {object} response
  293. * @return {string}
  294. */
  295. async captcha(request, response) {
  296. const captcha = new Captcha();
  297. const res = await captcha.register(request);
  298. response.json(res);
  299. }
  300. /**
  301. * 判断用户是否是专业版用户
  302. * @param request
  303. * @param response
  304. * @returns {Promise<void>}
  305. */
  306. // async accountIsPro(request, response) {
  307. // let res = {
  308. // error: 0,
  309. // msg: '',
  310. // result: false,
  311. // };
  312. // try{
  313. // const account = request.body.account;
  314. // const password = request.body.pw;
  315. //
  316. // // 根据邮箱或手机号获取账号信息
  317. // let userModel = new UserModel();
  318. // // 调用接口验证登录信息
  319. // let responseData = await userModel.getInfoFromSSO(account, password);
  320. // console.log(responseData);
  321. // // 先判断返回值是否为未激活状态
  322. // if ( responseData === '-3') {
  323. // throw '因邮箱未完成认证,账号未激活;去<a href="https://sso.smartcost.com.cn" target="_blank">激活</a>。';
  324. // }
  325. // responseData = JSON.parse(responseData);
  326. // if (typeof responseData !== 'object') {
  327. // throw '邮箱/手机 或 密码错误';
  328. // }
  329. //
  330. // if (responseData.length <= 0) {
  331. // throw '接口返回数据错误';
  332. // }
  333. //
  334. // // 正确登录后 存入session
  335. // let userData = responseData[0];
  336. //
  337. // if (userData.mobile === '') {
  338. // return response.json({error: 2,ssoId: userData.id});
  339. // }
  340. //
  341. // // const userInfo = await userModel.findDataByAccount(account);
  342. // // if (userInfo && userInfo.upgrade_list !== undefined) {
  343. // // for (const ul of userInfo.upgrade_list) {
  344. // // if (ul.isUpgrade === true) {
  345. // // res.result = true;
  346. // // res.data = userInfo.mobile;
  347. // // break;
  348. // // }
  349. // // }
  350. // // } else {
  351. // // res.msg = '当前未存在此用户';
  352. // // }
  353. // res.result = true;
  354. // // if (userInfo) {
  355. // // res.data = userInfo.mobile;
  356. // // } else {
  357. // res.data = userData.mobile;
  358. // // }
  359. // } catch (err) {
  360. // res.error = 1;
  361. // res.msg = err;
  362. // }
  363. //
  364. // response.json(res);
  365. // }
  366. }
  367. export default LoginController;