AuthenticationController.java 5.0 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120
  1. package com.izouma.nineth.web;
  2. import com.izouma.nineth.domain.User;
  3. import com.izouma.nineth.enums.AuthorityName;
  4. import com.izouma.nineth.exception.AuthenticationException;
  5. import com.izouma.nineth.exception.BusinessException;
  6. import com.izouma.nineth.security.JwtTokenUtil;
  7. import com.izouma.nineth.security.JwtUser;
  8. import com.izouma.nineth.security.JwtUserFactory;
  9. import com.izouma.nineth.service.CaptchaService;
  10. import com.izouma.nineth.service.UserService;
  11. import io.swagger.annotations.ApiOperation;
  12. import lombok.AllArgsConstructor;
  13. import lombok.extern.slf4j.Slf4j;
  14. import org.springframework.security.authentication.AuthenticationManager;
  15. import org.springframework.security.authentication.BadCredentialsException;
  16. import org.springframework.security.authentication.DisabledException;
  17. import org.springframework.security.authentication.UsernamePasswordAuthenticationToken;
  18. import org.springframework.security.core.Authentication;
  19. import org.springframework.security.core.authority.SimpleGrantedAuthority;
  20. import org.springframework.web.bind.annotation.PostMapping;
  21. import org.springframework.web.bind.annotation.RequestMapping;
  22. import org.springframework.web.bind.annotation.RestController;
  23. import java.util.Objects;
  24. @Slf4j
  25. @AllArgsConstructor
  26. @RestController
  27. @RequestMapping("/auth")
  28. public class AuthenticationController {
  29. private final AuthenticationManager authenticationManager;
  30. private final JwtTokenUtil jwtTokenUtil;
  31. private final UserService userService;
  32. private final CaptchaService captchaService;
  33. @PostMapping("/login")
  34. public String loginByUserPwd(String username, String password, Integer expiration) {
  35. Authentication authentication = authenticate(username, password);
  36. JwtUser jwtUser = (JwtUser) authentication.getPrincipal();
  37. return jwtTokenUtil.generateToken(jwtUser);
  38. }
  39. @PostMapping("/loginAdmin")
  40. public String loginByUserPwdAdmin(String username, String password, Integer expiration) {
  41. Authentication authentication = authenticate(username, password);
  42. if (!authentication.getAuthorities().contains(new SimpleGrantedAuthority(AuthorityName.ROLE_ADMIN.name()))) {
  43. throw new AuthenticationException("禁止登录", null);
  44. }
  45. JwtUser jwtUser = (JwtUser) authentication.getPrincipal();
  46. return jwtTokenUtil.generateToken(jwtUser);
  47. }
  48. @PostMapping("/phoneLogin")
  49. @ApiOperation(value = "手机号验证码登录")
  50. public String phoneLogin(String phone, String code) {
  51. User user = userService.loginByPhone(phone, code);
  52. return jwtTokenUtil.generateToken(JwtUserFactory.create(user));
  53. }
  54. @PostMapping("/phonePwdLogin")
  55. @ApiOperation(value = "手机号密码登录")
  56. public String phonePwdLogin(String phone, String password) {
  57. User user = userService.loginByPhonePwd(phone, password);
  58. return jwtTokenUtil.generateToken(JwtUserFactory.create(user));
  59. }
  60. @PostMapping("/phoneRegister")
  61. @ApiOperation(value = "手机号密码注册")
  62. public String phonePwdLogin(String phone, String code, String password, String inviteCode, Long invitor,
  63. String captcha, String captchaKey) {
  64. boolean verify = captchaService.verify(captcha, captchaKey);
  65. if (!verify){
  66. throw new BusinessException("验证码错误");
  67. }
  68. User user = userService.phoneRegister(phone, code, password, inviteCode, invitor);
  69. return jwtTokenUtil.generateToken(JwtUserFactory.create(user));
  70. }
  71. @PostMapping("/mpLogin")
  72. @ApiOperation(value = "公众号登录")
  73. public String mpLogin(String code) {
  74. try {
  75. User user = userService.loginMp(code);
  76. return jwtTokenUtil.generateToken(JwtUserFactory.create(user));
  77. } catch (Exception e) {
  78. log.error("loginByCode", e);
  79. throw new AuthenticationException("登陆错误", e);
  80. }
  81. }
  82. @PostMapping("/maLogin")
  83. @ApiOperation(value = "小程序登录")
  84. public String maLogin(String code) {
  85. try {
  86. User user = userService.loginMa(code);
  87. return jwtTokenUtil.generateToken(JwtUserFactory.create(user));
  88. } catch (Exception e) {
  89. log.error("loginByCode", e);
  90. throw new AuthenticationException("登陆错误", e);
  91. }
  92. }
  93. /**
  94. * Authenticates the user. If something is wrong, an {@link AuthenticationException} will be thrown
  95. *
  96. * @return Authentication
  97. */
  98. private Authentication authenticate(String username, String password) {
  99. Objects.requireNonNull(username);
  100. Objects.requireNonNull(password);
  101. try {
  102. return authenticationManager.authenticate(new UsernamePasswordAuthenticationToken(username, password));
  103. } catch (DisabledException e) {
  104. throw new AuthenticationException("禁止登录", e);
  105. } catch (BadCredentialsException e) {
  106. throw new AuthenticationException("用户名或密码错误", e);
  107. }
  108. }
  109. }