| 123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120 |
- 'use strict';
- // 加密类
- const crypto = require('crypto');
- const messageType = require('../const/message_type');
- module.exports = options => {
- /**
- * session判断中间件
- *
- * @param {function} next - 中间件继续执行的方法
- * @return {void}
- */
- return function* sessionAuth(next) {
- try {
- const share = this.query.share;
- if (share && this.request.url.indexOf('/tender') === 0) {
- const tender = yield this.service.tender.getDataByCondition({ id: this.params.id });
- if (tender.share_token !== share) {
- throw '分享码不正确';
- }
- if (tender.share_expiration < new Date()) {
- throw '分享码已过期';
- }
- const currentTime = new Date().getTime() / 1000;
- this.session.sessionUser = {
- account: '游客',
- name: '游客',
- accountId: 0,
- loginTime: currentTime,
- is_admin: false,
- loginType: 4,
- loginStatus: 0,
- dskAccountData: null,
- permission: null,
- };
- this.session.sessionUser.sessionToken = crypto.createHmac('sha1', currentTime + '')
- .update(this.session.sessionUser.account).digest('hex').toString('base64');
- const projectData = yield this.service.project.getDataByCondition({ id: tender.project_id });
- this.session.sessionProject = {
- id: projectData.id,
- code: projectData.code,
- name: projectData.name,
- userAccount: projectData.user_account,
- custom: projectData.custom,
- };
- }
- // 判断session
- const sessionUser = this.session.sessionUser;
- if (sessionUser === undefined) {
- throw '不存在session';
- }
- // 校验session
- if (sessionUser.account === undefined || sessionUser.loginTime === undefined) {
- throw '用户数据不完整';
- }
- // 校验session
- const sessionToken = crypto.createHmac('sha1', sessionUser.loginTime + '')
- .update(sessionUser.account).digest('hex').toString('base64');
- if (sessionToken !== sessionUser.sessionToken) {
- throw 'session数据错误';
- }
- // 获取用户新建标段权利
- if (sessionUser.loginType !== 4) {
- const accountInfo = yield this.service.projectAccount.getDataById(this.session.sessionUser.accountId);
- this.session.sessionUser.permission = accountInfo !== undefined && accountInfo.permission !== '' ? JSON.parse(accountInfo.permission) : null;
- }
- const projectData = yield this.service.project.getDataById(this.session.sessionProject.id);
- this.session.sessionProject.page_show = yield this.service.projectAccount.getPageShow(projectData.page_show);
- this.session.sessionProject.custom = projectData.custom;
- this.session.sessionProject.customType = projectData.customType;
- this.session.sessionProject.funSet = projectData.fun_set ? JSON.parse(projectData.fun_set) : null;
- // 同步消息
- yield this.service.notify.syncNotifyData();
- // 同步系统维护信息
- yield this.service.maintain.syncMaintainData();
- if (this.session === null) {
- throw '系统维护中~';
- }
- // 对sub_menu项目默认打开页进行配置
- const path = yield this.service.settingShow.getDefaultPath(this.session.sessionProject.id);
- path && (this.curListUrl = path);
- // 针对非wap重定向,去掉wap
- if (this.method === 'GET' && this.url.match(/\/wap\//) && !this.helper.isMobile(this.request.header['user-agent'])) {
- const returnUrl = this.url.replace(/\/wap/g, '');
- this.redirect(returnUrl);
- }
- } catch (error) {
- this.log(error);
- if (this.helper.isAjax(this.request)) {
- return this.body = {
- err: 2,
- msg: '登录信息异常,请重新登录',
- data: '',
- };
- } else if (this.session === null) {
- if (this.helper.isWap(this.request)) {
- this.session.wapTenderID = this.params.id ? this.params.id : null;
- return this.redirect('/wap/login?referer=' + this.url);
- }
- return this.redirect('/login?referer=' + this.url);
- }
- if (this.helper.isWap(this.request)) {
- this.session.wapTenderID = this.params.id ? this.params.id : null;
- return this.redirect('/wap/login?referer=' + this.url);
- }
- this.session.message = {
- type: messageType.ERROR,
- icon: 'exclamation-circle',
- message: '登录信息异常,请重新登录',
- };
- return this.redirect('/login?referer=' + this.url);
- }
- yield next;
- };
- };
|