ludc
2024-10-15 aecacfb404d19749260189ab1d4ee90efc92ae24
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
package com.vci.web.controller;
 
import com.vci.starter.web.annotation.controller.VciUnCheckRight;
import com.vci.starter.web.annotation.log.VciBusinessLog;
import com.vci.starter.web.constant.TokenKeyConstant;
import com.vci.starter.web.pagemodel.BaseResult;
import com.vci.starter.web.pagemodel.RequestClientInfo;
import com.vci.starter.web.pagemodel.SessionInfo;
import com.vci.starter.web.util.LangBaseUtil;
import com.vci.starter.web.util.MessageUtils;
import com.vci.starter.web.util.VciBaseUtil;
import com.vci.starter.web.util.WebThreadLocalUtil;
import com.vci.bo.LoginResultBO;
import com.vci.dto.LoginUserDTO;
import com.vci.web.service.LoginServiceI;
import eu.bitwalker.useragentutils.*;
import org.apache.commons.lang3.StringUtils;
import org.slf4j.Logger;
import org.slf4j.LoggerFactory;
import org.springframework.beans.factory.annotation.Autowired;
import org.springframework.stereotype.Controller;
import org.springframework.web.bind.annotation.PostMapping;
import org.springframework.web.bind.annotation.RequestMapping;
import org.springframework.web.bind.annotation.ResponseBody;
import org.springframework.web.servlet.ModelAndView;
 
import javax.servlet.http.Cookie;
import javax.servlet.http.HttpServletRequest;
import javax.servlet.http.HttpServletResponse;
import java.security.Principal;
import java.util.Enumeration;
import java.util.HashMap;
import java.util.Locale;
import java.util.Map;
 
/**
 * 登录控制器
 * @author weidy
 * @date 2021-1-28
 */
@Controller
@RequestMapping("/framework/loginController")
@VciBusinessLog(modelName="登录服务")
public class LoginController{
 
    /**
     * 登录服务
     */
    @Autowired
    private LoginServiceI loginService;
 
    /**
     * 日志
     */
    private Logger logger = LoggerFactory.getLogger(getClass());
 
    /**
     * 登录,这个地方主要是为了登录后单独的业务
     * @param userDTO 用户的对象
     * @param request 请求对象
     * @param clientInfo 客户端的信息
     * @return 执行结果
     */
    @VciBusinessLog(operateName="登录")
    @PostMapping(value = "/login")
    @ResponseBody
    @VciUnCheckRight()
    public BaseResult login(LoginUserDTO userDTO, HttpServletRequest request, RequestClientInfo clientInfo){
        VciBaseUtil.alertNotNull(userDTO,"用户对象",clientInfo,"请求客户端信息");
        try {
            wrapperBrowserInfo(clientInfo,request);
            LoginResultBO loginResultBO = loginService.login(userDTO,clientInfo);
            if(loginResultBO.isSuccess()){
                return BaseResult.success(loginResultBO);
            }else{
                BaseResult result = BaseResult.fail(loginResultBO.getFailMsg());
                if(StringUtils.isBlank(loginResultBO.getFailMsg())){
                    result.setMsg(MessageUtils.get(loginResultBO.getFailCode(),loginResultBO.getFailMsgArray()));
                }
                result.setObj(loginResultBO);
                return result;
            }
        }catch (Exception e){
            e.printStackTrace();
            String msg = "调用登录方法时出现错误,原因:"+VciBaseUtil.getExceptionMessage(e);
            logger.error(msg);
            return BaseResult.fail(msg);
        }
    }
    
    /**
     *  CAS的单点登录
     *  1. cas单点登录,则从userPrincipal里获取
     *  2. 在头里面加iv-user
     *  3. 在request里面放用户
     * @param request 请求的对象
     * @param response 响应对象
     * @return html的名字的前缀,具体是Jsp还是html,是spring-mvc里配置的
     */
    @VciBusinessLog(operateName="单点登录")
    @RequestMapping("/singleLoginCas")
    @VciUnCheckRight()
    public ModelAndView singleLoginCas(HttpServletRequest request,HttpServletResponse response){
        return doSingleLogin(request,response,"");
    }
 
    /**
     * 执行单点登录
     * @param request 请求的信息
     * @param userParam 用户的参数名字
     * @return 返回main.html
     */
    private ModelAndView doSingleLogin(HttpServletRequest request, HttpServletResponse response,String userParam){
        String msg = "";
        String token = "";
        if(request.getSession() == null){
            msg = "session已经过期或不存在,你可能需要重新执行单点登录";
        }else {
            String username = "";
            Principal principal = request.getUserPrincipal();
            if(principal!=null){
                Object ivUser = principal.getName();
                if (ivUser != null ) {
                    username = ivUser.toString();
                }
            }
            //用户的参数
            if(StringUtils.isBlank(userParam)){
                userParam = request.getParameter("userParam");
            }
            userParam = StringUtils.isBlank(userParam)?"iv-user":userParam;
            if(StringUtils.isBlank(username)){
                //不是cas的方式,而是头的方式
                username = request.getHeader(userParam);
            }
            if(StringUtils.isBlank(username)){
                //看看是不参数
                username = request.getParameter(userParam);
            }
            if(StringUtils.isBlank(username)){
                msg = "没有获取到用户的信息";
            }else{
                RequestClientInfo clientInfo =new RequestClientInfo();
                wrapperBrowserInfo(clientInfo,request);
                LoginUserDTO userDTO = new LoginUserDTO();
                userDTO.setUserId(username);
                try {
                    LoginResultBO loginResultBO = loginService.singleLogin(userDTO, clientInfo);
                    if(!loginResultBO.isSuccess()){
                        msg = loginResultBO.getFailMsg();
                    }else {
                        token = loginResultBO.getTokenVO().getAccessToken();
                    }
                }catch (Throwable e){
                    msg = LangBaseUtil.getErrorMsg(e);
                }
            }
        }
        Enumeration<?> parameterNames = request.getParameterNames();
        Map<String,String> paramMap = new HashMap<>();
        while (parameterNames.hasMoreElements()){
            String paramName = (String)parameterNames.nextElement();
            String value  = request.getParameter(paramName);
            if(!userParam.equalsIgnoreCase(paramName)) {
                paramMap.put(paramName, value);
            }
            //sb.append("&" + paramName + "=" + value);
        }
        String html = request.getParameter("html");
        if(StringUtils.isBlank(html)){
            html = "main";
        }
        ModelAndView view = new ModelAndView();
        Cookie cookie = new Cookie("msg", msg);
        cookie.setPath("/");
        response.addCookie(cookie);
        Cookie cookie1 = new Cookie(TokenKeyConstant.USER_TOKEN_KEY, token);
        cookie1.setPath("/");
        response.addCookie(cookie1);
        view.addAllObjects(paramMap);
        view.setViewName("redirect:/" + html + ".html");
 
        return view;
        //特别注意,单点登录一定在运行环境里调试,开发环境没有这个文件
    }
 
    /**
     * 执行单点登录,根据username
     * @param request 请求的信息
     * @param username 用户的参数名字
     * @return 返回main.html
     */
    public BaseResult doSingleLoginByUsername(HttpServletRequest request, HttpServletResponse response,String username){
        String msg = "";
        String token = "";
        if(request.getSession() == null){
            msg = "session已经过期或不存在,你可能需要重新执行单点登录";
            return BaseResult.fail(msg);
        }else {
 
            if(StringUtils.isBlank(username)){
                msg = "没有获取到用户的信息";
                return BaseResult.fail(msg);
            }else{
                RequestClientInfo clientInfo =new RequestClientInfo();
                wrapperBrowserInfo(clientInfo,request);
                LoginUserDTO userDTO = new LoginUserDTO();
                userDTO.setUserId(username);
                try {
                    LoginResultBO loginResultBO = loginService.singleLogin(userDTO, clientInfo);
                    if(!loginResultBO.isSuccess()){
                        msg = loginResultBO.getFailMsg();
                        return BaseResult.fail(msg);
                    }else {
                        token = loginResultBO.getTokenVO().getAccessToken();
                        msg="登录成功!";
                    }
                }catch (Throwable e){
                    msg = LangBaseUtil.getErrorMsg(e);
                }
            }
        }
 
 
        return BaseResult.success(msg);
        //特别注意,单点登录一定在运行环境里调试,开发环境没有这个文件
    }
 
    /**
     * 使用用户名来执行单点登录
     * @param request 请求对象
     * @param response 响应对象
     * @return main.html
     */
    @RequestMapping("/singleLoginByUsername")
    @VciUnCheckRight
    @VciBusinessLog(operateName="单点登录")
    public ModelAndView singleLoginByUsername(HttpServletRequest request,HttpServletResponse response){
        return doSingleLogin(request,response,"username");
    }
 
 
 
    /**
     * 获取客户端请求信息,为了隔绝在server层使用request
     * @param request 请求对象
     * @param clientInfo 客户端信息
     */
    private void wrapperBrowserInfo(RequestClientInfo clientInfo,HttpServletRequest request) {
        UserAgent userAgent = UserAgent.parseUserAgentString(request.getHeader("User-Agent"));
        if(StringUtils.isBlank(clientInfo.getIpaddress())){
            //找IP地址
            clientInfo.setIpaddress(getIpAddressFromRequest(request));
        }
        if(userAgent !=null) {
            Browser browser = userAgent.getBrowser();
            OperatingSystem os = userAgent.getOperatingSystem();
 
            clientInfo.setOsversion(os != null ? os.getName() : "");
            clientInfo.setBrowser(browser != null ? browser.getName() : "IE");
            String version = "";
            if (browser != null) {
                Version version1 = browser.getVersion(request.getHeader("User-Agent"));
                if (version1 != null) {
                    version = version1.getVersion();
                }
            }
            clientInfo.setBrowserversion(version);
            if (os != null) {
                clientInfo.setRequestType(os.getDeviceType().getName());
                if (DeviceType.COMPUTER.getName().equals(clientInfo.getRequestType())) {
                    clientInfo.setRequestType("browser");
                }
            }
 
            Locale loc = Locale.getDefault();
            clientInfo.setCountry(loc.getCountry());
            clientInfo.setLanguage(loc.toLanguageTag());
 
            Map<String,String> map = System.getenv();
            clientInfo.setMachine(map.get("COMPUTERNAME"));
            clientInfo.setOsUser(map.get("USERNAME"));
        }
    }
 
    /**
     * 从请求中获取ip地址,为了隔绝在server层使用request
     * @param request 请求对象
     * @return ip地址,没有找到默认为127.0.0.1
     */
    private String getIpAddressFromRequest(HttpServletRequest request){
        String ip = request.getHeader("X-Forwarded-For");
        if (ip == null || ip.length() == 0 || "unknown".equalsIgnoreCase(ip)) {
            ip = request.getHeader("Proxy-Client-IP");
        }
        if (ip == null || ip.length() == 0 || "unknown".equalsIgnoreCase(ip)) {
            ip = request.getHeader("WL-Proxy-Client-IP");
        }
        if (ip == null || ip.length() == 0 || "unknown".equalsIgnoreCase(ip)) {
            ip = request.getHeader("HTTP_CLIENT_IP");
        }
        if (ip == null || ip.length() == 0 || "unknown".equalsIgnoreCase(ip)) {
            ip = request.getHeader("HTTP_X_FORWARDED_FOR");
        }
        if (ip == null || ip.length() == 0 || "unknown".equalsIgnoreCase(ip)) {
            ip = request.getRemoteAddr();
        }
        if (ip == null || ip.length() == 0 || ip.indexOf("0:0:0:0:0:0:0:1") >-1) {
            //0:0:0:0:0:0:0:1是本机在访问
            ip = "127.0.0.1";
        }
        return ip;
    }
 
    /**
     * 获取用户的会话信息
     * @return success为true表示获取成功,否则msg是错误信息,obj属性是获取的会话对象信息
     */
    @VciUnCheckRight
    @PostMapping("/getSessionInfo")
    @ResponseBody
    public BaseResult getSessionInfo(){
        BaseResult<SessionInfo> json = new BaseResult<>();
        SessionInfo sessionInfo = WebThreadLocalUtil.getCurrentUserSessionInfoInThread();
        if(sessionInfo != null){
            json = json.success(sessionInfo);
        }
        return json;
    }
 
    /**
     * 执行退出
     * @param request 请求对象
     * @return success为true表示退出成功,前端不需要判断结果
     */
    @VciUnCheckRight
    @PostMapping("/logout")
    @ResponseBody
    public BaseResult logout(HttpServletRequest request){
        String userToken = request.getHeader(TokenKeyConstant.USER_TOKEN_KEY);
        loginService.logout(userToken);
        return BaseResult.success();
    }
}