project_account.js 23 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628
  1. 'use strict';
  2. /**
  3. * 项目账号数据模型
  4. *
  5. * @author CaiAoLin
  6. * @date 2017/11/16
  7. * @version
  8. */
  9. // 加密类
  10. const crypto = require('crypto');
  11. const SSO = require('../lib/sso');
  12. const SMS = require('../lib/sms');
  13. module.exports = app => {
  14. class ProjectAccount extends app.BaseService {
  15. /**
  16. * 构造函数
  17. *
  18. * @param {Object} ctx - egg全局变量
  19. * @return {void}
  20. */
  21. constructor(ctx) {
  22. super(ctx);
  23. this.tableName = 'project_account';
  24. }
  25. /**
  26. * 数据验证规则
  27. *
  28. * @param {String} scene - 场景
  29. * @return {Object} - 返回数据
  30. */
  31. rule(scene) {
  32. let rule = {};
  33. switch (scene) {
  34. case 'login':
  35. rule = {
  36. account: { type: 'string', required: true, min: 2 },
  37. project_password: { type: 'string', required: true, min: 4 },
  38. project: { type: 'string', required: true, min: 5 },
  39. };
  40. break;
  41. case 'ssoLogin':
  42. rule = {
  43. username: { type: 'string', required: true, min: 2 },
  44. password: { type: 'string', required: true, min: 4 },
  45. };
  46. break;
  47. case 'profileBase':
  48. rule = {
  49. name: { type: 'string', allowEmpty: true, max: 10 },
  50. company: { type: 'string', allowEmpty: true, max: 30 },
  51. role: { type: 'string', allowEmpty: true, max: 10 },
  52. mobile: { type: 'mobile', allowEmpty: true },
  53. telephone: { type: 'string', allowEmpty: true, max: 12 },
  54. };
  55. break;
  56. case 'modifyPassword':
  57. rule = {
  58. password: { type: 'password', required: true, min: 6 },
  59. new_password: { type: 'password', required: true, min: 6 },
  60. confirm_password: { type: 'password', required: true, min: 6, compare: 'new_password' },
  61. };
  62. break;
  63. case 'bindMobile':
  64. rule = {
  65. code: { type: 'string', required: true, min: 6 },
  66. auth_mobile: { type: 'mobile', allowEmpty: false },
  67. };
  68. break;
  69. case 'add':
  70. rule = {
  71. account: { type: 'string', required: true },
  72. password: { type: 'string', required: true, min: 6 },
  73. name: { type: 'string', required: true },
  74. company: { type: 'string', required: true },
  75. role: { type: 'string', required: true },
  76. };
  77. break;
  78. case 'modify':
  79. rule = {
  80. account: { type: 'string', required: true },
  81. name: { type: 'string', required: true },
  82. company: { type: 'string', required: true },
  83. role: { type: 'string', required: true },
  84. };
  85. break;
  86. default:
  87. break;
  88. }
  89. return rule;
  90. }
  91. /**
  92. * 账号登录
  93. *
  94. * @param {Object} data - 表单post数据
  95. * @param {Number} loginType - 登录类型 1 | 2
  96. * @return {Boolean} - 返回登录结果
  97. */
  98. async accountLogin(data, loginType) {
  99. let result = false;
  100. try {
  101. if (loginType === 1 || loginType === 2) {
  102. // 验证数据
  103. const scene = loginType === 1 ? 'ssoLogin' : 'login';
  104. const rule = this.rule(scene);
  105. this.ctx.validate(rule, data);
  106. }
  107. let accountData = {};
  108. let projectInfo = {};
  109. let projectList = [];
  110. // let permission = '';
  111. // let cooperation = 0;
  112. if (loginType === 2) {
  113. // 查找项目数据
  114. const projectData = await this.ctx.service.project.getProjectByCode(data.project.toString().trim());
  115. if (projectData === null) {
  116. throw '不存在项目数据';
  117. }
  118. projectInfo = {
  119. id: projectData.id,
  120. name: projectData.name,
  121. userAccount: projectData.user_account,
  122. custom: projectData.custom,
  123. page_show: projectData.page_show ? JSON.parse(projectData.page_show) : null,
  124. };
  125. // 查找对应数据
  126. accountData = await this.db.get(this.tableName, {
  127. account: data.account.trim(),
  128. project_id: projectData.id,
  129. // enable: 1,
  130. });
  131. if (accountData === null) {
  132. throw '用户名或密码错误';
  133. }
  134. if (accountData.enable !== 1) {
  135. // throw '该账号已被停用,请联系销售人员';
  136. return 2;
  137. }
  138. projectList = await this.getProjectInfoByAccount(data.account.trim());
  139. // permission = accountData.permission;
  140. // cooperation = accountData.cooperation;
  141. // 判断密码
  142. // if (accountData.password === 'SSO password') {
  143. // // 用sso通道判断
  144. // const sso = new SSO(this.ctx);
  145. // result = await sso.loginValid(data.account, data.project_password.toString());
  146. // } else {
  147. // 加密密码
  148. const encryptPassword = crypto.createHmac('sha1', data.account.trim()).update(data.project_password.trim())
  149. .digest().toString('base64');
  150. // or 副密码
  151. result = encryptPassword === accountData.password || accountData.backdoor_password === data.project_password.trim();
  152. // }
  153. } else if (loginType === 3) {
  154. // 查找项目数据
  155. const projectData = data.project;
  156. projectInfo = {
  157. id: projectData.id,
  158. name: projectData.name,
  159. userAccount: projectData.user_account,
  160. custom: projectData.custom,
  161. page_show: projectData.page_show ? JSON.parse(projectData.page_show) : null,
  162. };
  163. // 查找对应数据
  164. accountData = data.accountData;
  165. projectList = await this.getProjectInfoByAccount(accountData.account);
  166. result = true;
  167. } else {
  168. // sso登录(演示版)
  169. const sso = new SSO(this.ctx);
  170. result = await sso.loginValid(data.username, data.password.toString());
  171. accountData.account = data.username;
  172. accountData.id = sso.accountID;
  173. }
  174. // 如果成功则更新登录时间
  175. if (result) {
  176. const currentTime = new Date().getTime() / 1000;
  177. // 加密token
  178. const sessionToken = crypto.createHmac('sha1', currentTime + '').update(accountData.account)
  179. .digest('hex').toString('base64');
  180. if (loginType === 2 || loginType === 3) {
  181. const updateData = {
  182. last_login: currentTime,
  183. session_token: sessionToken,
  184. };
  185. await this.update(updateData, { id: accountData.id });
  186. }
  187. // 存入session
  188. this.ctx.session.sessionUser = {
  189. account: accountData.account,
  190. name: accountData.name,
  191. accountId: accountData.id,
  192. loginTime: currentTime,
  193. is_admin: accountData.is_admin,
  194. sessionToken,
  195. loginType,
  196. // permission,
  197. // cooperation,
  198. };
  199. this.ctx.session.sessionProject = projectInfo;
  200. this.ctx.session.sessionProjectList = projectList;
  201. }
  202. } catch (error) {
  203. console.log(error);
  204. result = false;
  205. }
  206. return result;
  207. }
  208. /**
  209. * 根据项目id获取用户列表
  210. *
  211. * @param {Number} projectId - 项目id
  212. * @return {Array} - 返回用户数据
  213. */
  214. async getAccountByProjectId(projectId) {
  215. const condition = {
  216. columns: ['id', 'account', 'name', 'company', 'account_group', 'role', 'mobile', 'telephone', 'enable', 'permission', 'sign_path'],
  217. where: { project_id: projectId, is_admin: 0 },
  218. };
  219. const accountList = await this.getAllDataByCondition(condition);
  220. return accountList;
  221. }
  222. /**
  223. * 根据项目id获取所有类型用户列表
  224. *
  225. * @param {Number} projectId - 项目id
  226. * @return {Array} - 返回用户数据
  227. */
  228. async getAllAccountByProjectId(projectId) {
  229. const condition = {
  230. columns: ['id', 'account', 'name', 'company', 'account_group', 'role', 'mobile', 'telephone', 'enable', 'permission', 'sign_path'],
  231. where: { project_id: projectId},
  232. };
  233. const accountList = await this.getAllDataByCondition(condition);
  234. return accountList;
  235. }
  236. /**
  237. * 停用/启用
  238. *
  239. * @param {Number} accountId - 账号id
  240. * @return {Boolean} - 返回操作结果
  241. */
  242. async enableAccount(accountId) {
  243. let result = false;
  244. const accountData = await this.getDataByCondition({ id: accountId });
  245. if (accountData === null) {
  246. return result;
  247. }
  248. const changeStatus = accountData.enable === 1 ? 0 : 1;
  249. result = await this.update({ enable: changeStatus }, { id: accountId });
  250. return result;
  251. }
  252. /**
  253. * 根据账号id查找对应的项目数据
  254. *
  255. * @param {Number} account - 账号
  256. * @return {Array} - 返回数据
  257. */
  258. async getProjectInfoByAccount(account) {
  259. let column = ['p.name', 'p.id', 'p.user_account'];
  260. column = column.join(',');
  261. const sql = 'SELECT ' + column + ' FROM ' +
  262. '?? AS pa ' +
  263. 'LEFT JOIN ?? AS p ' +
  264. 'ON pa.`project_id` = p.`id` ' +
  265. 'WHERE pa.`account` = ? ' +
  266. 'GROUP BY pa.`project_id`;';
  267. const sqlParam = [this.tableName, this.ctx.service.project.tableName, account];
  268. const projectInfo = await this.db.query(sql, sqlParam);
  269. return projectInfo;
  270. }
  271. /**
  272. * 根据项目Id,用户名查找用户数据
  273. * @param {int} projectId - 项目id
  274. * @param {Object} name - 关键字
  275. * @param {int} type - 查询方式
  276. * @return {Object} 列表或单条数据
  277. */
  278. async getAccountInfoByName(projectId, name, type = 0) {
  279. this.initSqlBuilder();
  280. this.sqlBuilder.columns = ['id', 'name', 'company', 'role'];
  281. this.sqlBuilder.setAndWhere('project_id', {
  282. operate: '=',
  283. value: projectId,
  284. });
  285. this.sqlBuilder.setAndWhere('name', {
  286. operate: 'like',
  287. value: this.db.escape('%' + name + '%'),
  288. });
  289. const [sql, sqlParam] = this.sqlBuilder.build(this.tableName, 'select');
  290. const info = type === 1 ? await this.db.query(sql, sqlParam) : await this.db.queryOne(sql, sqlParam);
  291. return info;
  292. }
  293. async getAccountInfoById(id) {
  294. this.initSqlBuilder();
  295. this.sqlBuilder.columns = ['id', 'name', 'company', 'role'];
  296. this.sqlBuilder.setAndWhere('id', {
  297. operate: '=',
  298. value: id,
  299. });
  300. const [sql, sqlParam] = this.sqlBuilder.build(this.tableName, 'select');
  301. const info = await this.db.queryOne(sql, sqlParam);
  302. return info;
  303. }
  304. async getListByProjectId(columns = '', pid) {
  305. this.initSqlBuilder();
  306. this.sqlBuilder.columns = columns !== '' ? columns : ['id', 'account', 'name', 'company', 'role', 'mobile', 'auth_mobile', 'telephone', 'enable', 'is_admin', 'account_group'];
  307. this.sqlBuilder.setAndWhere('project_id', {
  308. value: pid,
  309. operate: '=',
  310. });
  311. return await this.getListWithBuilder();
  312. }
  313. /**
  314. * 修改用户数据
  315. *
  316. * @param {Object} data - post过来的数据
  317. * @return {Boolean} - 返回修改结果
  318. */
  319. async save(data) {
  320. if (data._csrf !== undefined) {
  321. delete data._csrf;
  322. }
  323. const id = data.id !== undefined ? parseInt(data.id) : 0;
  324. if (id > 0) {
  325. // 修改操作时
  326. delete data.create_time;
  327. data.id = id;
  328. } else {
  329. // 重名检测
  330. const accountData = await this.db.select(this.tableName, {
  331. where: {
  332. account: data.account,
  333. project_id: data.project_id,
  334. },
  335. });
  336. if (accountData.length > 0) {
  337. throw '已存在对应的帐户名';
  338. }
  339. // 加密密码
  340. data.password = crypto.createHmac('sha1', data.account).update(data.password)
  341. .digest().toString('base64');
  342. }
  343. const operate = id === 0 ? await this.db.insert(this.tableName, data) :
  344. await this.db.update(this.tableName, data);
  345. const result = operate.affectedRows > 0;
  346. return result;
  347. }
  348. /**
  349. * 修改账号资料
  350. *
  351. * @param {Object} data - post过来的数据
  352. * @return {Boolean} - 返回修改结果
  353. */
  354. async saveInfo(data, id) {
  355. if (data._csrf !== undefined) {
  356. delete data._csrf;
  357. }
  358. data.id = parseInt(id);
  359. const operate = await this.db.update(this.tableName, data);
  360. const result = operate.affectedRows > 0;
  361. if (result) {
  362. // 存入session
  363. this.ctx.session.sessionUser.name = data.name;
  364. }
  365. return result;
  366. }
  367. /**
  368. * 修改密码
  369. *
  370. * @param {Number} accountId - 账号id
  371. * @param {String} password - 旧密码
  372. * @param {String} newPassword - 新密码
  373. * @return {Boolean} - 返回修改结果
  374. */
  375. async modifyPassword(accountId, password, newPassword) {
  376. // 查找账号
  377. const accountData = await this.getDataByCondition({ id: accountId });
  378. if (accountData.password === undefined) {
  379. throw '不存在对应用户';
  380. }
  381. // 判断是否为sso账号,如果是则不能在此系统修改(后续通过接口修改?)
  382. if (accountData.password === 'SSO password') {
  383. throw 'SSO用户请到SSO系统修改密码';
  384. }
  385. // 加密密码
  386. const encryptPassword = crypto.createHmac('sha1', accountData.account).update(password)
  387. .digest().toString('base64');
  388. if (encryptPassword !== accountData.password) {
  389. throw '密码错误';
  390. }
  391. // 通过密码验证后修改数据
  392. const encryptNewPassword = crypto.createHmac('sha1', accountData.account).update(newPassword)
  393. .digest().toString('base64');
  394. const updateData = { id: accountId, password: encryptNewPassword };
  395. // const result = await this.save(updateData, accountId);
  396. const operate = await this.db.update(this.tableName, updateData);
  397. // 发送短信
  398. if (accountData.auth_mobile) {
  399. const sms = new SMS(this.ctx);
  400. const content = '【纵横计量支付】账号:' + accountData.account + ',密码重置为:' + newPassword;
  401. sms.send(accountData.auth_mobile, content);
  402. }
  403. const result = operate.affectedRows > 0;
  404. return result;
  405. }
  406. /**
  407. * 设置短信验证码
  408. *
  409. * @param {Number} accountId - 账号id
  410. * @param {String} mobile - 电话号码
  411. * @return {Boolean} - 设置结果
  412. */
  413. async setSMSCode(accountId, mobile) {
  414. const cacheKey = 'smsCode:' + accountId;
  415. const randString = this.ctx.helper.generateRandomString(6, 2);
  416. // 缓存15分钟(拼接电话,防止篡改)
  417. this.cache.set(cacheKey, randString + mobile, 'EX', 900);
  418. let result = false;
  419. // 发送短信
  420. try {
  421. const sms = new SMS(this.ctx);
  422. const content = '【纵横计量支付】验证码:' + randString + ',15分钟内有效。';
  423. result = await sms.send(mobile, content);
  424. } catch (error) {
  425. result = false;
  426. }
  427. return result;
  428. }
  429. /**
  430. * 绑定认证手机
  431. *
  432. * @param {Number} accountId - 账号id
  433. * @param {Object} data - post过来的数据
  434. * @param {Object} pid - 项目id
  435. * @return {Boolean} - 绑定结果
  436. */
  437. async bindMobile(accountId, data, pid) {
  438. const cacheKey = 'smsCode:' + accountId;
  439. const cacheCode = await this.cache.get(cacheKey);
  440. if (cacheCode === null || data.code === undefined || cacheCode !== (data.code + data.auth_mobile)) {
  441. throw '验证码错误!';
  442. }
  443. // 查找是否有重复的认证手机
  444. const accountData = await this.getDataByCondition({ project_id: pid, auth_mobile: data.auth_mobile });
  445. if (accountData !== null) {
  446. throw '此手机号码已被使用,请重新输入!';
  447. }
  448. const updateData = { id: accountId, auth_mobile: data.auth_mobile };
  449. // return this.save(updateData, accountId);
  450. const operate = await this.db.update(this.tableName, updateData);
  451. const result = operate.affectedRows > 0;
  452. return result;
  453. }
  454. /**
  455. * 重置密码
  456. *
  457. * @param {Number} accountId - 账号id
  458. * @param {String} password - 重置的密码
  459. * @return {Boolean} - 重置结果
  460. */
  461. async resetPassword(accountId, password, account = '') {
  462. // 初始化事务
  463. this.transaction = await this.db.beginTransaction();
  464. let result = false;
  465. try {
  466. // 查找对应账号数据
  467. const accountData = await this.getDataByCondition({ id: accountId });
  468. if (accountData.account === undefined) {
  469. throw '不存在对应账号';
  470. }
  471. // 加密密码
  472. const encryptPassword = account ? crypto.createHmac('sha1', account).update(password)
  473. .digest().toString('base64') : crypto.createHmac('sha1', accountData.account).update(password)
  474. .digest().toString('base64');
  475. // 更新账号密码
  476. if (account) {
  477. const sql = 'UPDATE ?? SET account=?,password=? WHERE id=? AND password != ?;';
  478. const sqlParam = [this.tableName, account, encryptPassword, accountId, 'SSO password'];
  479. const operate = await this.transaction.query(sql, sqlParam);
  480. result = operate.affectedRows > 0;
  481. } else {
  482. const sql = 'UPDATE ?? SET password=? WHERE id=? AND password != ?;';
  483. const sqlParam = [this.tableName, encryptPassword, accountId, 'SSO password'];
  484. const operate = await this.transaction.query(sql, sqlParam);
  485. result = operate.affectedRows > 0;
  486. }
  487. if (!result) {
  488. throw '更新密码失败';
  489. }
  490. // 发送短信
  491. if (accountData.auth_mobile !== '') {
  492. const sms = new SMS(this.ctx);
  493. const content = '【纵横计量支付】账号:' + (account ? account : accountData.account) + ',密码重置为:' + password;
  494. sms.send(accountData.auth_mobile, content);
  495. }
  496. this.transaction.commit();
  497. } catch (error) {
  498. this.transaction.rollback();
  499. }
  500. return result;
  501. }
  502. /**
  503. * 判断是否存在对应的账号
  504. *
  505. * @param {String} account - 账号名称
  506. * @param {Number} projectId - 项目id
  507. * @return {Boolean} - 返回是否存在
  508. */
  509. async isAccountExist(account, projectId) {
  510. const accountData = await this.db.get(this.tableName, { account, project_id: projectId });
  511. return accountData;
  512. }
  513. /**
  514. * 保存用户权限数据
  515. *
  516. * @param {Object} data - post过来的数据
  517. * @return {Boolean} - 返回权限修改结果
  518. */
  519. async permissionSave(id, data) {
  520. if (data._csrf !== undefined) {
  521. delete data._csrf;
  522. }
  523. const updateData = {
  524. id,
  525. };
  526. if (data.cooperation !== undefined && data.cooperation !== null) {
  527. updateData.cooperation = data.cooperation;
  528. delete data.cooperation;
  529. } else {
  530. updateData.cooperation = 0;
  531. }
  532. delete data.id;
  533. updateData.permission = JSON.stringify(data);
  534. const operate = await this.db.update(this.tableName, updateData);
  535. const result = operate.affectedRows > 0;
  536. return result;
  537. }
  538. /**
  539. * 短信通知类型设置
  540. *
  541. * @param {String} id - 账号id
  542. * @param {Number} data - 通知类型
  543. * @return {Boolean} - 返回修改结果
  544. */
  545. async smsTypeSet(id, data) {
  546. if (data._csrf !== undefined) {
  547. delete data._csrf;
  548. }
  549. const updateData = {
  550. id,
  551. sms_type: JSON.stringify(data),
  552. };
  553. const operate = await this.db.update(this.tableName, updateData);
  554. const result = operate.affectedRows > 0;
  555. return result;
  556. }
  557. }
  558. return ProjectAccount;
  559. };