AuthenticationController.java 5.1 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124
  1. package com.izouma.nineth.web;
  2. import com.izouma.nineth.domain.User;
  3. import com.izouma.nineth.enums.AuthorityName;
  4. import com.izouma.nineth.exception.AuthenticationException;
  5. import com.izouma.nineth.security.JwtTokenUtil;
  6. import com.izouma.nineth.security.JwtUser;
  7. import com.izouma.nineth.security.JwtUserFactory;
  8. import com.izouma.nineth.service.CacheService;
  9. import com.izouma.nineth.service.CaptchaService;
  10. import com.izouma.nineth.service.UserService;
  11. import io.swagger.annotations.ApiOperation;
  12. import lombok.AllArgsConstructor;
  13. import lombok.extern.slf4j.Slf4j;
  14. import org.springframework.security.authentication.AuthenticationManager;
  15. import org.springframework.security.authentication.BadCredentialsException;
  16. import org.springframework.security.authentication.DisabledException;
  17. import org.springframework.security.authentication.UsernamePasswordAuthenticationToken;
  18. import org.springframework.security.core.Authentication;
  19. import org.springframework.security.core.authority.SimpleGrantedAuthority;
  20. import org.springframework.web.bind.annotation.GetMapping;
  21. import org.springframework.web.bind.annotation.PostMapping;
  22. import org.springframework.web.bind.annotation.RequestMapping;
  23. import org.springframework.web.bind.annotation.RestController;
  24. import java.util.Objects;
  25. @Slf4j
  26. @AllArgsConstructor
  27. @RestController
  28. @RequestMapping("/auth")
  29. public class AuthenticationController {
  30. private final AuthenticationManager authenticationManager;
  31. private final JwtTokenUtil jwtTokenUtil;
  32. private final UserService userService;
  33. private final CaptchaService captchaService;
  34. @PostMapping("/login")
  35. public String loginByUserPwd(String username, String password, Integer expiration) {
  36. Authentication authentication = authenticate(username, password);
  37. JwtUser jwtUser = (JwtUser) authentication.getPrincipal();
  38. return jwtTokenUtil.generateToken(jwtUser);
  39. }
  40. @PostMapping("/loginAdmin")
  41. public String loginByUserPwdAdmin(String username, String password, Integer expiration) {
  42. Authentication authentication = authenticate(username, password);
  43. if (!authentication.getAuthorities().contains(new SimpleGrantedAuthority(AuthorityName.ROLE_ADMIN.name()))) {
  44. throw new AuthenticationException("禁止登录", null);
  45. }
  46. JwtUser jwtUser = (JwtUser) authentication.getPrincipal();
  47. return jwtTokenUtil.generateToken(jwtUser);
  48. }
  49. @PostMapping("/phoneLogin")
  50. @ApiOperation(value = "手机号验证码登录")
  51. public String phoneLogin(String phone, String code) {
  52. User user = userService.loginByPhone(phone, code);
  53. return jwtTokenUtil.generateToken(JwtUserFactory.create(user));
  54. }
  55. @PostMapping("/phonePwdLogin")
  56. @ApiOperation(value = "手机号密码登录")
  57. public String phonePwdLogin(String phone, String password) {
  58. User user = userService.loginByPhonePwd(phone, password);
  59. return jwtTokenUtil.generateToken(JwtUserFactory.create(user));
  60. }
  61. @PostMapping("/phoneRegister")
  62. @ApiOperation(value = "手机号密码注册")
  63. public String phonePwdLogin(String phone, String code, String password, String inviteCode, Long invitor,
  64. Long collectionId, String captcha, String captchaKey) {
  65. captchaService.verify(captcha, captchaKey);
  66. User user = userService.phoneRegister(phone, code, password, inviteCode, invitor, collectionId);
  67. return jwtTokenUtil.generateToken(JwtUserFactory.create(user));
  68. }
  69. @PostMapping("/mpLogin")
  70. @ApiOperation(value = "公众号登录")
  71. public String mpLogin(String code) {
  72. try {
  73. User user = userService.loginMp(code);
  74. return jwtTokenUtil.generateToken(JwtUserFactory.create(user));
  75. } catch (Exception e) {
  76. log.error("loginByCode", e);
  77. throw new AuthenticationException("登陆错误", e);
  78. }
  79. }
  80. @PostMapping("/maLogin")
  81. @ApiOperation(value = "小程序登录")
  82. public String maLogin(String code) {
  83. try {
  84. User user = userService.loginMa(code);
  85. return jwtTokenUtil.generateToken(JwtUserFactory.create(user));
  86. } catch (Exception e) {
  87. log.error("loginByCode", e);
  88. throw new AuthenticationException("登陆错误", e);
  89. }
  90. }
  91. @GetMapping("/getTime")
  92. public Long getTime() {
  93. return System.currentTimeMillis();
  94. }
  95. /**
  96. * Authenticates the user. If something is wrong, an {@link AuthenticationException} will be thrown
  97. *
  98. * @return Authentication
  99. */
  100. private Authentication authenticate(String username, String password) {
  101. Objects.requireNonNull(username);
  102. Objects.requireNonNull(password);
  103. try {
  104. return authenticationManager.authenticate(new UsernamePasswordAuthenticationToken(username, password));
  105. } catch (DisabledException e) {
  106. throw new AuthenticationException("禁止登录", e);
  107. } catch (BadCredentialsException e) {
  108. throw new AuthenticationException("用户名或密码错误", e);
  109. }
  110. }
  111. }