login_controller.js 17 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411
  1. /**
  2. * 登录相关控制器
  3. *
  4. * @author CaiAoLin
  5. * @date 2017/6/8
  6. * @version
  7. */
  8. const UserModel = require("../models/user_model");
  9. const SettingModel = require("../models/setting_model");
  10. const CompilationModel = require("../models/compilation_model");
  11. const LogModel = require("../models/log_model");
  12. const LogType = require("../../common/const/log_type_const");
  13. const SMS = require('../models/sms');
  14. const moment = require('moment');
  15. // 验证码
  16. const Captcha = require("../models/captcha");
  17. let mongoose = require("mongoose");
  18. let systemSettingModel = mongoose.model("system_setting");
  19. const uuidV1 = require('uuid/v1');
  20. let config = require("../../../config/config.js");
  21. let title = config[process.env.NODE_ENV].title?config[process.env.NODE_ENV].title:"纵横公路养护云造价";
  22. class LoginController {
  23. /**
  24. * 登录页面
  25. *
  26. * @param {object} request
  27. * @param {object} response
  28. * @return {void}
  29. */
  30. async index(request, response) {
  31. // 判断是否有带token和ssoID参数
  32. if (request.query.ssoID !== undefined && request.query.token !== undefined) {
  33. let ssoID = request.query.ssoID;
  34. let token = request.query.token;
  35. let preferenceSetting = {};
  36. let compilationList = [];
  37. try {
  38. let userModel = new UserModel();
  39. // 调用接口验证登录信息
  40. let responseData = await userModel.getInfoFromSSO2(ssoID, token);
  41. // 先判断返回值是否为未激活状态
  42. if ( responseData === '-3') {
  43. throw '因邮箱未完成认证,账号未激活;去<a href="https://sso.smartcost.com.cn" target="_blank">激活</a>。';
  44. }
  45. if ( responseData === '-2') {
  46. throw 'token已过期,请重新登录Z+获取';
  47. }
  48. responseData = JSON.parse(responseData);
  49. if (typeof responseData !== 'object') {
  50. throw 'ssoId错误或token过期';
  51. }
  52. if (responseData.length <= 0) {
  53. throw '接口返回数据错误';
  54. }
  55. let userData = responseData[0];
  56. // 判断用户是否开启了只使用短信登录
  57. const userInfo = await userModel.findDataByAccount(userData.mobile);
  58. if (userInfo !== undefined && userInfo !== null && userInfo.isSmsLogin === 1) {
  59. let renderData = {
  60. mobile: userData.mobile,
  61. title:title
  62. };
  63. response.render('users/html/login-sms', renderData);
  64. return;
  65. }
  66. let sessionUser = {
  67. ssoId: userData.id,
  68. username: userData.username,
  69. email: userData.useremail,
  70. mobile: userData.mobile,
  71. qq: userData.qq,
  72. isUserActive: userData.isUserActive,
  73. token: uuidV1(),
  74. };
  75. request.session.sessionUser = sessionUser;
  76. // 记录用户数据到数据库
  77. let result = await userModel.markUser(sessionUser, request);
  78. // 获取偏好设置
  79. let settingModel = new SettingModel();
  80. preferenceSetting = await settingModel.getPreferenceSetting(request.session.sessionUser.id);
  81. if (!result) {
  82. throw '标记用户信息失败!';
  83. }
  84. let compilationModel = new CompilationModel();
  85. if (preferenceSetting.login_ask === 1 || preferenceSetting.select_version === ''){
  86. preferenceSetting.login_ask = 1;
  87. compilationList = await compilationModel.getList();
  88. } else {
  89. compilationList = [];
  90. }
  91. // 获取编办信息
  92. let sessionCompilation = request.session.sessionCompilation;
  93. if (preferenceSetting.login_ask === 0 && !sessionCompilation &&
  94. preferenceSetting.select_version !== '') {
  95. let compilationData = await compilationModel.getCompilationById(preferenceSetting.select_version);
  96. // 判断当前用户的是使用免费版还是专业版
  97. let compilationVersion = await userModel.getVersionFromUpgrade(sessionUser.ssoId, preferenceSetting.select_version);
  98. request.session.compilationVersion = compilationVersion.version;
  99. request.session.sessionUser.compilationLock = compilationVersion.lock;
  100. request.session.sessionCompilation = compilationData;
  101. if(request.session.sessionUser.latest_used !== preferenceSetting.select_version) await userModel.updateLatestUsed(request.session.sessionUser.id,preferenceSetting.select_version);
  102. }
  103. let systemSetting = await systemSettingModel.findOne({}).lean();
  104. request.session.systemSetting = systemSetting;
  105. request.session.online_start_time = +new Date();
  106. console.log(`${request.session.sessionUser.real_name}--id:${request.session.sessionUser.id}--登录了系统`);
  107. if (preferenceSetting.login_ask === 1 || preferenceSetting.select_version === '') {
  108. let renderData = {
  109. versionData: compilationList,
  110. title:title
  111. };
  112. response.render('users/html/login-ver', renderData);
  113. } else {
  114. return response.redirect("/pm");
  115. }
  116. } catch (error) {
  117. console.log(error)
  118. return response.redirect("/login");
  119. }
  120. } else {
  121. let sessionUser = request.session.sessionUser;
  122. if (sessionUser !== undefined && sessionUser.ssoId >= 0) {
  123. return response.redirect("/pm");
  124. } else {
  125. response.render('users/html/login', {title:title});
  126. }
  127. }
  128. }
  129. /**
  130. * 登录操作
  131. *
  132. * @param {object} request
  133. * @param {object} response
  134. * @return {string}
  135. */
  136. async login(request, response) {
  137. let preferenceSetting = {};
  138. let compilationList = [];
  139. try {
  140. let userModel = new UserModel();
  141. let responseData = '';
  142. if (request.body.account === undefined) {
  143. let mobile = request.body.mobile;
  144. let codeMsg = request.session.code;
  145. if (codeMsg !== undefined && request.body.code !== '') {
  146. console.log(codeMsg);
  147. const validMobile = codeMsg.split('_')[0];
  148. const code = codeMsg.split('_')[1];
  149. const time = codeMsg.split('_')[2];
  150. if (validMobile !== mobile) {
  151. throw '短信验证码错误';
  152. }
  153. if (Date.parse(new Date())/1000 > time+60*5 || request.body.code !== code) {
  154. throw '短信验证码错误或已过期';
  155. } else {
  156. delete request.session.code;
  157. }
  158. } else {
  159. throw '短信验证码错误或已过期。';
  160. }
  161. responseData = await userModel.getInfoFromSSOMobile(mobile);
  162. } else {
  163. let account = request.body.account;
  164. let password = request.body.pw;
  165. // 调用接口验证登录信息
  166. responseData = await userModel.getInfoFromSSO(account, password);
  167. }
  168. // 先判断返回值是否为未激活状态
  169. if ( responseData === '-3') {
  170. throw '因邮箱未完成认证,账号未激活;去<a href="https://sso.smartcost.com.cn" target="_blank">激活</a>。';
  171. }
  172. responseData = JSON.parse(responseData);
  173. if (typeof responseData !== 'object') {
  174. throw '邮箱/手机 或 密码错误';
  175. }
  176. if (responseData.length <= 0) {
  177. throw '接口返回数据错误';
  178. }
  179. // 正确登录后 存入session
  180. let userData = responseData[0];
  181. if (userData.mobile === '') {
  182. return response.json({error: 2,ssoId: userData.id});
  183. }
  184. //还要判断account是否是专业版用户
  185. // let isPro = true;
  186. // const userInfo = await userModel.findDataByAccount(account);
  187. //
  188. // if (userInfo && userInfo.upgrade_list !== undefined) {
  189. // for (const ul of userInfo.upgrade_list) {
  190. // if (ul.isUpgrade === true) {
  191. // isPro = true;
  192. // break;
  193. // }
  194. // }
  195. // }
  196. // 专业版短信验证码验证
  197. // if (isPro) {
  198. // const codeMsg = request.session.code;
  199. // if (codeMsg !== undefined && request.body.code !== '') {
  200. // const code = codeMsg.split('_')[0];
  201. // const time = codeMsg.split('_')[1];
  202. // console.log(code);
  203. // console.log(request.body.code);
  204. // if (Date.parse(new Date())/1000 > time+60*5 || request.body.code !== code) {
  205. // return response.json({error: 3, msg: '验证码错误。'});
  206. // } else {
  207. // delete request.session.code;
  208. // }
  209. // } else {
  210. // return response.json({error: 3, msg: '验证码错误。'});
  211. // }
  212. // }
  213. // 判断极验验证码是否通过
  214. // 先不使用,出现验证慢的情况
  215. // const captcha = new Captcha();
  216. // const captchResult = await captcha.validate(request);
  217. // if (!captchResult) {
  218. // throw '极验验证码错误';
  219. // }
  220. // 判断用户是否开启了只使用短信登录
  221. const userInfo = await userModel.findDataByAccount(userData.mobile);
  222. if (request.body.mobile === undefined && request.body.code === undefined && userInfo !== undefined && userInfo !== null && userInfo.isSmsLogin === 1) {
  223. return response.json({error: 3, msg: '只能手机短信登录。', data: userData.mobile});
  224. }
  225. let sessionUser = {
  226. ssoId: userData.id,
  227. company: userInfo.company,
  228. username: userData.username,
  229. email: userData.useremail,
  230. mobile: userData.mobile,
  231. qq: userData.qq,
  232. isUserActive: userData.isUserActive,
  233. newLogin:true,
  234. token: uuidV1(),
  235. };
  236. request.session.sessionUser = sessionUser;
  237. // 记录用户数据到数据库
  238. let result = await userModel.markUser(sessionUser, request);
  239. // 获取偏好设置
  240. let settingModel = new SettingModel();
  241. preferenceSetting = await settingModel.getPreferenceSetting(request.session.sessionUser.id);
  242. if (!result) {
  243. throw '标记用户信息失败!';
  244. }
  245. let compilationModel = new CompilationModel();
  246. if(preferenceSetting.login_ask === 1 || preferenceSetting.select_version === ''){
  247. preferenceSetting.login_ask = 1;
  248. compilationList = await compilationModel.getList(request.headers.host);
  249. }
  250. else{
  251. compilationList = [];
  252. }
  253. // 获取编办信息
  254. let sessionCompilation = request.session.sessionCompilation;
  255. if (preferenceSetting.login_ask === 0 && !sessionCompilation &&
  256. preferenceSetting.select_version !== '') {
  257. let compilationData = await compilationModel.getCompilationById(preferenceSetting.select_version);
  258. // 判断当前用户的是使用免费版还是专业版
  259. let compilationVersion = await userModel.getVersionFromUpgrade(sessionUser.ssoId, preferenceSetting.select_version);
  260. request.session.compilationVersion = compilationVersion.version;
  261. request.session.sessionUser.compilationLock = compilationVersion.lock;
  262. request.session.sessionCompilation = compilationData;
  263. if(request.session.sessionUser.latest_used !== preferenceSetting.select_version) await userModel.updateLatestUsed(request.session.sessionUser.id,preferenceSetting.select_version);
  264. }
  265. // 登录异常短信提醒功能
  266. const userinfo2 = await userModel.findDataByAccount(userData.mobile);
  267. if (userinfo2.isLoginValid === 1) {
  268. // 获取本次访问ip
  269. let ip = request.headers["x-real-ip"]? request.headers["x-real-ip"]:"";
  270. let logModel = new LogModel();
  271. let logCount = await logModel.count();
  272. logCount = logCount > 30 ? 30 : logCount;
  273. let page = 1;
  274. const loginList = await logModel.getLog(request.session.sessionUser.id, LogType.LOGIN_LOG, page, logCount);
  275. let messageFlag = true;
  276. for (const [index,log] of loginList.entries()) {
  277. if (log.message.ip === ip && index !== 0) {
  278. messageFlag = false;
  279. break;
  280. }
  281. }
  282. messageFlag = true;
  283. if (messageFlag) {
  284. // 发送短信
  285. const Sms = new SMS();
  286. const logInfo = loginList[0];
  287. await Sms.sendLoginMsg(userData.mobile, request.session.sessionUser.real_name, moment(logInfo.create_time).format('YYYY-MM-DD'), moment(logInfo.create_time).format('HH:mm:ss'), logInfo.message.ip_info, logInfo.message.ip);
  288. }
  289. }
  290. } catch (error) {
  291. console.log(error);
  292. return response.json({error: 1, msg: error});
  293. }
  294. let systemSetting = await systemSettingModel.findOne({}).lean();
  295. request.session.systemSetting = systemSetting;
  296. request.session.online_start_time = +new Date();
  297. console.log(`${request.session.sessionUser.real_name}--id:${request.session.sessionUser.id}--登录了系统`);
  298. response.json({
  299. error: 0,
  300. msg: '',
  301. login_ask: preferenceSetting.login_ask,
  302. compilation_list: JSON.stringify(compilationList),
  303. last_page: request.session.lastPage
  304. });
  305. }
  306. /**
  307. * 验证码注册
  308. *
  309. * @param {object} request
  310. * @param {object} response
  311. * @return {string}
  312. */
  313. async captcha(request, response) {
  314. const captcha = new Captcha();
  315. const res = await captcha.register(request);
  316. response.json(res);
  317. }
  318. /**
  319. * 判断用户是否是专业版用户
  320. * @param request
  321. * @param response
  322. * @returns {Promise<void>}
  323. */
  324. // async accountIsPro(request, response) {
  325. // let res = {
  326. // error: 0,
  327. // msg: '',
  328. // result: false,
  329. // };
  330. // try{
  331. // const account = request.body.account;
  332. // const password = request.body.pw;
  333. //
  334. // // 根据邮箱或手机号获取账号信息
  335. // let userModel = new UserModel();
  336. // // 调用接口验证登录信息
  337. // let responseData = await userModel.getInfoFromSSO(account, password);
  338. // console.log(responseData);
  339. // // 先判断返回值是否为未激活状态
  340. // if ( responseData === '-3') {
  341. // throw '因邮箱未完成认证,账号未激活;去<a href="https://sso.smartcost.com.cn" target="_blank">激活</a>。';
  342. // }
  343. // responseData = JSON.parse(responseData);
  344. // if (typeof responseData !== 'object') {
  345. // throw '邮箱/手机 或 密码错误';
  346. // }
  347. //
  348. // if (responseData.length <= 0) {
  349. // throw '接口返回数据错误';
  350. // }
  351. //
  352. // // 正确登录后 存入session
  353. // let userData = responseData[0];
  354. //
  355. // if (userData.mobile === '') {
  356. // return response.json({error: 2,ssoId: userData.id});
  357. // }
  358. //
  359. // // const userInfo = await userModel.findDataByAccount(account);
  360. // // if (userInfo && userInfo.upgrade_list !== undefined) {
  361. // // for (const ul of userInfo.upgrade_list) {
  362. // // if (ul.isUpgrade === true) {
  363. // // res.result = true;
  364. // // res.data = userInfo.mobile;
  365. // // break;
  366. // // }
  367. // // }
  368. // // } else {
  369. // // res.msg = '当前未存在此用户';
  370. // // }
  371. // res.result = true;
  372. // // if (userInfo) {
  373. // // res.data = userInfo.mobile;
  374. // // } else {
  375. // res.data = userData.mobile;
  376. // // }
  377. // } catch (err) {
  378. // res.error = 1;
  379. // res.msg = err;
  380. // }
  381. //
  382. // response.json(res);
  383. // }
  384. }
  385. module.exports = LoginController;