From 38f0f601c507fa9a7a27754e9f1a1bd10f913899 Mon Sep 17 00:00:00 2001
From: ludc
Date: 星期日, 03 十二月 2023 23:07:12 +0800
Subject: [PATCH] Merge remote-tracking branch 'origin/master'
---
Source/UBCS/ubcs-service/ubcs-code/src/main/java/com/vci/ubcs/code/service/impl/PasswordFreeLoginServiceImpl.java | 130 +++++++++++++++++++++++++++++++-----------
1 files changed, 95 insertions(+), 35 deletions(-)
diff --git a/Source/UBCS/ubcs-service/ubcs-code/src/main/java/com/vci/ubcs/code/service/impl/PasswordFreeLoginServiceImpl.java b/Source/UBCS/ubcs-service/ubcs-code/src/main/java/com/vci/ubcs/code/service/impl/PasswordFreeLoginServiceImpl.java
index fbedf76..3b4a571 100644
--- a/Source/UBCS/ubcs-service/ubcs-code/src/main/java/com/vci/ubcs/code/service/impl/PasswordFreeLoginServiceImpl.java
+++ b/Source/UBCS/ubcs-service/ubcs-code/src/main/java/com/vci/ubcs/code/service/impl/PasswordFreeLoginServiceImpl.java
@@ -3,8 +3,10 @@
import com.alibaba.fastjson.JSON;
import com.vci.ubcs.code.entity.TokenUserObject;
import com.vci.ubcs.code.service.IPasswordFreeLoginService;
-import com.vci.ubcs.code.util.HttpUtils;
+import com.vci.ubcs.starter.util.HttpUtils;
+import com.vci.ubcs.system.cache.NacosConfigCache;
import io.jsonwebtoken.Claims;
+import lombok.extern.slf4j.Slf4j;
import org.apache.http.auth.AuthenticationException;
import org.springblade.core.jwt.JwtUtil;
import org.springblade.core.jwt.props.JwtProperties;
@@ -30,7 +32,10 @@
import javax.servlet.http.HttpServletRequest;
import java.util.List;
import java.util.Map;
+import java.util.logging.Logger;
+import static com.vci.ubcs.starter.util.AESUtils.aesDecrypt;
+import static com.vci.ubcs.starter.util.AESUtils.aesEncrypt;
import static org.springblade.core.secure.utils.AuthUtil.parseJWT;
/**
@@ -39,15 +44,33 @@
* @date 2023/9/11 15:45
*/
@Service
+@Slf4j
public class PasswordFreeLoginServiceImpl implements IPasswordFreeLoginService {
// 閫氳繃鏈嶅姟娉ㄥ唽涓績鑾峰彇缃戝叧鐨勭鍙e彿
@Autowired
private DiscoveryClient discoveryClient;
- @Value("${user-info.pwd-free-tenant-id}")
+
+ // 閰嶇疆鐨勫厤瀵嗙櫥褰曠殑璐﹀彿鎵�灞炵殑绉熸埛id
+ @Value("${password-free.pwd-free-tenant-id:000000}")
private String pwdFreeTenantId;
+
+ // 閰嶇疆鐨則oken鍦╮edis涓殑鐢熷瓨鏃堕棿
+ @Value("${password-free.token-redis-expire:36000}")
+ private Long tokenRedisExpire;
+
+ @Value("${password-free.pwd-free-addr:localhost}")
+ private String pwdFreeAddr;
+
+ @Value("${password-free.client-id:a104c4fd2f0e4958}")
+ private String clientId;//搴旂敤ID
+
+ @Value("${password-free.secret-key:9fbd170bd83eb869}")
+ private String secretKey;//搴旂敤绉橀挜
+
@Autowired
private BladeRedis bladeRedis;
+
// 缂撳瓨鍚�
public static final String PWD_FREE_LOGIN_TOKEN = "pwdFreeLogin:Token:";
private static JwtProperties jwtProperties;
@@ -68,40 +91,25 @@
/**
* 鍏嶅瘑鐧诲綍锛屾敼鍙樺綋鍓峸ebservice璇锋眰鐨刪eader
- * @param username 璐﹀彿
- * @return
+ * @param userName 璐﹀彿
+ * @param servletRequest
+ * @return boolean
+ * @throws AuthenticationException
*/
@Override
- public boolean passwordFreeLogin(String username, ServletRequest servletRequest) throws AuthenticationException {
+ public boolean pwdFreeLoginByBoolean(String userName, ServletRequest servletRequest) throws AuthenticationException {
//杩涙潵鍏堝垽鏂紦瀛樹腑鏄惁瀛樺湪token
// 璇锋眰鏉ヨ嚜宸卞摢涓猧p鍦板潃
HttpServletRequest request = (HttpServletRequest) servletRequest;
String ipAddr = request.getRemoteAddr();
// 鍏堝皾璇曚粠缂撳瓨褰撲腑鍙栵紝瀛樺湪灏辩洿鎺ヤ粠缂撳瓨涓幏鍙�
- String authToken = bladeRedis.get(PWD_FREE_LOGIN_TOKEN+ipAddr);
- BladeUser user = null;
+ String authToken = bladeRedis.get(PWD_FREE_LOGIN_TOKEN+ipAddr+":"+userName);
+ // 瑙f瀽token瀛樻斁杩沘ttr涓�
+ String token2 = JwtUtil.getToken(authToken);
+ BladeUser user = this.getUser(token2);
//涓嶅瓨鍦ㄥ氨璇锋眰
- if(Func.isEmpty(authToken)){
- // 鍏嶅瘑鐧诲綍鎺ュ彛鍦板潃
- String loginUrl = "http://localhost:"+this.getGatewayPort("ubcs-gateway")+"/ubcs-auth/oauth/token";
- // 璇锋眰ubcs-auth鏈嶅姟鑾峰彇token锛屽厛璁剧疆璇锋眰澶�
- HttpHeaders headers = new HttpHeaders();
- headers.setContentType(MediaType.APPLICATION_FORM_URLENCODED);
- headers.set("Authorization", "Basic c3dvcmQ6c3dvcmRfc2VjcmV0");
- headers.set("Tenant-Id", pwdFreeTenantId);
- //璁剧疆璇锋眰浣撳弬鏁�
- MultiValueMap<String,String> parameters = new LinkedMultiValueMap<String,String>();
- parameters.add("username",username);
- parameters.add("grant_type", "passwordfree");
- parameters.add("scope", "all");
- parameters.add("type", "account");
- String responseBody = null;
- try {
- // 鍙戦�丳OST璇锋眰
- responseBody = HttpUtils.post(loginUrl, parameters,headers);
- }catch (Exception e){
- throw new AuthenticationException("璋冪敤閴存潈鏈嶅姟ubcs-auth澶辫触锛屽師鍥狅細"+e.getMessage());
- }
+ if(Func.isEmpty(authToken) || Func.isEmpty(user) || !user.getTenantId().equals(NacosConfigCache.getAdminUserInfo().getTenantId())){
+ String responseBody = this.passwordFreeLogin(userName);
//鎷垮埌鍝嶅簲浣撳叾涓寘鍚玹oken,鐢╮equest涓殑ip鍦板潃浣滀负閿�硷紝灏唗oken瀛樺叆缂撳瓨
TokenUserObject tokenUserObject = null;
try {
@@ -112,14 +120,69 @@
// 鎷兼帴token鏍煎紡
authToken = "bearer " + tokenUserObject.getAccess_token();
// 灏唗oken瀛樺叆缂撳瓨褰撲腑,杩囨湡鏃堕棿涓�24灏忔椂
- bladeRedis.setEx(PWD_FREE_LOGIN_TOKEN+ipAddr,"bearer "+tokenUserObject.getAccess_token(),60*60*60*24L);
+ bladeRedis.setEx(PWD_FREE_LOGIN_TOKEN+ipAddr+":"+userName,"bearer "+tokenUserObject.getAccess_token(),tokenRedisExpire);
+ token2 = JwtUtil.getToken(authToken);
+ user = this.getUser(token2);
}
- // 瑙f瀽token瀛樻斁杩沘ttr涓�
- String token2 = JwtUtil.getToken(authToken);
- user = this.getUser(token2);
//request.setAttribute("Blade-Auth",token);
request.setAttribute("_BLADE_USER_REQUEST_ATTR_",user);
return true;
+ }
+
+ /**
+ * 鍏嶅瘑鐧诲綍璇锋眰鍙戦��
+ * @param userName 璐﹀彿
+ * @return 杩斿洖token
+ * @throws AuthenticationException
+ */
+ @Override
+ public String passwordFreeLogin(String userName) throws AuthenticationException {
+ // 鍏嶅瘑鐧诲綍鎺ュ彛鍦板潃
+ String loginUrl = "http://"+pwdFreeAddr+":"+this.getGatewayPort("ubcs-gateway")+"/ubcs-auth/oauth/token";
+ log.debug("褰撳墠鍏嶅瘑鐧诲綍璋冪敤鍦板潃锛�"+loginUrl);
+ // 璇锋眰ubcs-auth鏈嶅姟鑾峰彇token锛屽厛璁剧疆璇锋眰澶�
+ HttpHeaders headers = new HttpHeaders();
+ headers.setContentType(MediaType.APPLICATION_FORM_URLENCODED);
+ headers.set("Authorization", "Basic c3dvcmQ6c3dvcmRfc2VjcmV0");
+ headers.set("Tenant-Id", pwdFreeTenantId);
+ //璁剧疆璇锋眰浣撳弬鏁�
+ MultiValueMap<String,String> parameters = new LinkedMultiValueMap<String,String>();
+ parameters.add("username",userName);
+ parameters.add("grant_type", "passwordfree");
+ parameters.add("scope", "all");
+ parameters.add("type", "account");
+ String responseBody = null;
+ try {
+ // 鍙戦�丳OST璇锋眰
+ responseBody = HttpUtils.post(loginUrl, parameters,headers);
+ }catch (Exception e){
+ throw new AuthenticationException("璋冪敤閴存潈鏈嶅姟ubcs-auth澶辫触锛屽師鍥狅細"+e.getMessage());
+ }
+ return responseBody;
+ }
+
+ /**
+ * 鍗曠偣鐧诲綍
+ * @param empCode
+ * @return
+ * @throws Exception
+ */
+ @Override
+ public String ssoFreeLogin(String empCode) throws Exception {
+ if(Func.isBlank(empCode)){
+ throw new ServiceException("鏈幏鍙栧埌empCode鍙傛暟");
+ }
+ String enStr2;
+ try {
+ String enStr1 = aesDecrypt(empCode, secretKey);
+ enStr2 = aesDecrypt(enStr1, clientId);
+ }catch (Exception e){
+ throw new ServiceException("empCode鍙傛暟瑙e瘑澶辫触锛佸師鍥�:"+e.getMessage());
+ }
+ // 瑙e瘑
+ log.debug("鍗曠偣鐧诲綍鍙傛暟瑙e瘑鍚庯細"+enStr2);
+ String token = this.passwordFreeLogin(enStr2);
+ return token;
}
/**
@@ -181,11 +244,9 @@
if (StringUtil.isNotBlank(authToken)) {
token = JwtUtil.getToken(authToken);
}
-
if (StringUtil.isNotBlank(token)) {
claims = parseJWT(token);
}
-
if (ObjectUtil.isNotEmpty(claims) && getJwtProperties().getState()) {
tenantId = Func.toStr(claims.get("tenant_id"));
String userId = Func.toStr(claims.get("user_id"));
@@ -205,6 +266,5 @@
return jwtProperties;
}
-
}
--
Gitblit v1.9.3