Auth.php 11 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400
  1. <?php
  2. namespace app\admin\library;
  3. use app\admin\model\Admin;
  4. use fast\Random;
  5. use fast\Tree;
  6. use think\Cookie;
  7. use think\Request;
  8. use think\Session;
  9. class Auth extends \fast\Auth
  10. {
  11. protected $requestUri = '';
  12. protected $breadcrumb = [];
  13. protected $loginUnique = false; //是否同一账号同一时间只能在一个地方登录
  14. public function __construct()
  15. {
  16. parent::__construct();
  17. }
  18. public function __get($name)
  19. {
  20. return Session::get('admin.' . $name);
  21. }
  22. public function login($username, $password, $keeptime = 0)
  23. {
  24. $admin = Admin::get(['username' => $username]);
  25. if (!$admin)
  26. {
  27. return false;
  28. }
  29. if ($admin->password != md5(md5($password) . $admin->salt))
  30. {
  31. $admin->loginfailure++;
  32. $admin->save();
  33. return false;
  34. }
  35. $admin->loginfailure = 0;
  36. $admin->logintime = time();
  37. $admin->token = Random::uuid();
  38. $admin->save();
  39. Session::set("admin", $admin);
  40. $this->keeplogin($keeptime);
  41. return true;
  42. }
  43. /**
  44. * 注销登录
  45. */
  46. public function logout()
  47. {
  48. $admin = Admin::get(intval($this->id));
  49. if (!$admin)
  50. {
  51. return true;
  52. }
  53. $admin->token = '';
  54. $admin->save();
  55. Session::delete("admin");
  56. Cookie::delete("keeplogin");
  57. return true;
  58. }
  59. /**
  60. * 自动登录
  61. * @return boolean
  62. */
  63. public function autologin()
  64. {
  65. $keeplogin = Cookie::get('keeplogin');
  66. if (!$keeplogin)
  67. {
  68. return false;
  69. }
  70. list($id, $keeptime, $expiretime, $key) = explode('|', $keeplogin);
  71. if ($id && $keeptime && $expiretime && $key && $expiretime > time())
  72. {
  73. $admin = Admin::get($id);
  74. if (!$admin || !$admin->token)
  75. {
  76. return false;
  77. }
  78. //token有变更
  79. if ($key != md5(md5($id) . md5($keeptime) . md5($expiretime) . $admin->token))
  80. {
  81. return false;
  82. }
  83. Session::set("admin", $admin);
  84. //刷新自动登录的时效
  85. $this->keeplogin($keeptime);
  86. return true;
  87. }
  88. else
  89. {
  90. return false;
  91. }
  92. }
  93. /**
  94. * 刷新保持登录的Cookie
  95. * @param int $keeptime
  96. * @return boolean
  97. */
  98. protected function keeplogin($keeptime = 0)
  99. {
  100. if ($keeptime)
  101. {
  102. $expiretime = time() + $keeptime;
  103. $key = md5(md5($this->id) . md5($keeptime) . md5($expiretime) . $this->token);
  104. $data = [$this->id, $keeptime, $expiretime, $key];
  105. Cookie::set('keeplogin', implode('|', $data));
  106. return true;
  107. }
  108. return false;
  109. }
  110. public function check($name, $uid = '', $relation = 'or', $mode = 'url')
  111. {
  112. return parent::check($name, $this->id, $relation, $mode);
  113. }
  114. /**
  115. * 检测当前控制器和方法是否匹配传递的数组
  116. *
  117. * @param array $arr 需要验证权限的数组
  118. */
  119. public function match($arr = [])
  120. {
  121. $request = Request::instance();
  122. $arr = is_array($arr) ? $arr : explode(',', $arr);
  123. if (!$arr)
  124. {
  125. return FALSE;
  126. }
  127. // 是否存在
  128. if (in_array(strtolower($request->action()), $arr) || in_array('*', $arr))
  129. {
  130. return TRUE;
  131. }
  132. // 没找到匹配
  133. return FALSE;
  134. }
  135. /**
  136. * 检测是否登录
  137. *
  138. * @return boolean
  139. */
  140. public function isLogin()
  141. {
  142. $admin = Session::get('admin');
  143. if (!$admin)
  144. {
  145. return false;
  146. }
  147. //判断是否同一时间同一账号只能在一个地方登录
  148. if ($this->loginUnique)
  149. {
  150. $my = Admin::get($admin->id);
  151. if (!$my || $my->token != $admin->token)
  152. {
  153. return false;
  154. }
  155. }
  156. return true;
  157. }
  158. /**
  159. * 获取当前请求的URI
  160. * @return string
  161. */
  162. public function getRequestUri()
  163. {
  164. return $this->requestUri;
  165. }
  166. /**
  167. * 设置当前请求的URI
  168. * @param string $uri
  169. */
  170. public function setRequestUri($uri)
  171. {
  172. $this->requestUri = $uri;
  173. }
  174. public function getGroups($uid = null)
  175. {
  176. $uid = is_null($uid) ? $this->id : $uid;
  177. return parent::getGroups($uid);
  178. }
  179. public function getRuleList($uid = null)
  180. {
  181. $uid = is_null($uid) ? $this->id : $uid;
  182. return parent::getRuleList($uid);
  183. }
  184. public function getUserInfo($uid = null)
  185. {
  186. $uid = is_null($uid) ? $this->id : $uid;
  187. return $uid != $this->id ? Admin::get(intval($uid)) : Session::get('admin');
  188. }
  189. public function getRuleIds($uid = null)
  190. {
  191. $uid = is_null($uid) ? $this->id : $uid;
  192. return parent::getRuleIds($uid);
  193. }
  194. public function isSuperAdmin()
  195. {
  196. return in_array('*', $this->getRuleIds()) ? TRUE : FALSE;
  197. }
  198. /**
  199. * 获取管理员所属于的分组ID
  200. * @param int $uid
  201. * @return array
  202. */
  203. public function getGroupIds($uid = null)
  204. {
  205. $groups = $this->getGroups($uid);
  206. $groupIds = [];
  207. foreach ($groups as $K => $v)
  208. {
  209. $groupIds[] = (int) $v['group_id'];
  210. }
  211. return $groupIds;
  212. }
  213. /**
  214. * 取出当前管理员所拥有权限的分组
  215. * @param boolean $withself 是否包含当前所在的分组
  216. * @return array
  217. */
  218. public function getChildrenGroupIds($withself = false)
  219. {
  220. //取出当前管理员所有的分组
  221. $groups = $this->getGroups();
  222. $groupIds = [];
  223. foreach ($groups as $k => $v)
  224. {
  225. $groupIds[] = $v['id'];
  226. }
  227. // 取出所有分组
  228. $groupList = model('AuthGroup')->all(['status' => 'normal']);
  229. $objList = [];
  230. foreach ($groups as $K => $v)
  231. {
  232. if ($v['rules'] === '*')
  233. {
  234. $objList = $groupList;
  235. break;
  236. }
  237. // 取出包含自己的所有子节点
  238. $childrenList = Tree::instance()->init($groupList)->getChildren($v['id'], true);
  239. $obj = Tree::instance()->init($childrenList)->getTreeArray($v['pid']);
  240. $objList = array_merge($objList, Tree::instance()->getTreeList($obj));
  241. }
  242. $childrenGroupIds = [];
  243. foreach ($objList as $k => $v)
  244. {
  245. $childrenGroupIds[] = $v['id'];
  246. }
  247. if (!$withself)
  248. {
  249. $childrenGroupIds = array_diff($childrenGroupIds, $groupIds);
  250. }
  251. return $childrenGroupIds;
  252. }
  253. /**
  254. * 取出当前管理员所拥有权限的管理员
  255. * @param boolean $withself 是否包含自身
  256. * @return array
  257. */
  258. public function getChildrenAdminIds($withself = false)
  259. {
  260. $groupIds = $this->getChildrenGroupIds(false);
  261. $childrenAdminIds = [];
  262. $authGroupList = model('AuthGroupAccess')
  263. ->field('uid,group_id')
  264. ->where('group_id', 'in', $groupIds)
  265. ->select();
  266. foreach ($authGroupList as $k => $v)
  267. {
  268. $childrenAdminIds[] = $v['uid'];
  269. }
  270. if ($withself)
  271. {
  272. if (!in_array($this->id, $childrenAdminIds))
  273. {
  274. $childrenAdminIds[] = $this->id;
  275. }
  276. }
  277. else
  278. {
  279. $childrenAdminIds = array_diff($childrenAdminIds, [$this->id]);
  280. }
  281. return $childrenAdminIds;
  282. }
  283. /**
  284. * 获得面包屑导航
  285. * @param string $path
  286. * @return array
  287. */
  288. public function getBreadCrumb($path = '')
  289. {
  290. if ($this->breadcrumb || !$path)
  291. return $this->breadcrumb;
  292. $path_rule_id = 0;
  293. foreach ($this->rules as $rule)
  294. {
  295. $path_rule_id = $rule['name'] == $path ? $rule['id'] : $path_rule_id;
  296. }
  297. if ($path_rule_id)
  298. {
  299. $this->breadcrumb = Tree::instance()->init($this->rules)->getParents($path_rule_id, true);
  300. foreach ($this->breadcrumb as $k => &$v)
  301. {
  302. $v['url'] = url($v['name']);
  303. $v['title'] = __($v['title']);
  304. }
  305. }
  306. return $this->breadcrumb;
  307. }
  308. /**
  309. * 获取左侧菜单栏
  310. *
  311. * @param array $params URL对应的badge数据
  312. * @return string
  313. */
  314. public function getSidebar($params = [], $fixedPage = 'dashboard')
  315. {
  316. $colorArr = ['red', 'green', 'yellow', 'blue', 'teal', 'orange', 'purple'];
  317. $colorNums = count($colorArr);
  318. $badgeList = [];
  319. $module = request()->module();
  320. // 生成菜单的badge
  321. foreach ($params as $k => $v)
  322. {
  323. $url = $k;
  324. if (is_array($v))
  325. {
  326. $nums = isset($v[0]) ? $v[0] : 0;
  327. $color = isset($v[1]) ? $v[1] : $colorArr[(is_numeric($nums) ? $nums : strlen($nums)) % $colorNums];
  328. $class = isset($v[2]) ? $v[2] : 'label';
  329. }
  330. else
  331. {
  332. $nums = $v;
  333. $color = $colorArr[(is_numeric($nums) ? $nums : strlen($nums)) % $colorNums];
  334. $class = 'label';
  335. }
  336. //必须nums大于0才显示
  337. if ($nums)
  338. {
  339. $badgeList[$url] = '<small class="' . $class . ' pull-right bg-' . $color . '">' . $nums . '</small>';
  340. }
  341. }
  342. // 读取管理员当前拥有的权限节点
  343. $userRule = $this->getRuleList();
  344. $select_id = 0;
  345. $pinyin = new \Overtrue\Pinyin\Pinyin('Overtrue\Pinyin\MemoryFileDictLoader');
  346. // 必须将结果集转换为数组
  347. $ruleList = collection(model('AuthRule')->where('ismenu', 1)->order('weigh', 'desc')->cache("__menu__")->select())->toArray();
  348. foreach ($ruleList as $k => &$v)
  349. {
  350. if (!in_array($v['name'], $userRule))
  351. {
  352. unset($ruleList[$k]);
  353. continue;
  354. }
  355. $select_id = $v['name'] == $fixedPage ? $v['id'] : $select_id;
  356. $v['url'] = '/' . $module . '/' . $v['name'];
  357. $v['badge'] = isset($badgeList[$v['name']]) ? $badgeList[$v['name']] : '';
  358. $v['py'] = $pinyin->abbr($v['title'], '');
  359. $v['pinyin'] = $pinyin->permalink($v['title'], '');
  360. $v['title'] = __($v['title']);
  361. }
  362. // 构造菜单数据
  363. Tree::instance()->init($ruleList);
  364. $menu = Tree::instance()->getTreeMenu(0, '<li class="@class"><a href="@url@addtabs" addtabs="@id" url="@url" py="@py" pinyin="@pinyin"><i class="@icon"></i> <span>@title</span> <span class="pull-right-container">@caret @badge</span></a> @childlist</li>', $select_id, '', 'ul', 'class="treeview-menu"');
  365. return $menu;
  366. }
  367. }