Auth.php 4.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206
  1. <?php
  2. namespace app\admin\library;
  3. use app\admin\model\Admin;
  4. use fast\Random;
  5. use think\Cookie;
  6. use think\Request;
  7. use think\Session;
  8. class Auth extends \fast\Auth
  9. {
  10. protected $requestUri = '';
  11. public function __construct()
  12. {
  13. parent::__construct();
  14. }
  15. public function __get($name)
  16. {
  17. return Session::get('admin.' . $name);
  18. }
  19. public function login($username, $password, $keeptime = 0)
  20. {
  21. $admin = Admin::get(['username' => $username]);
  22. if (!$admin)
  23. {
  24. return false;
  25. }
  26. if ($admin->password != md5(md5($password) . $admin->salt))
  27. {
  28. $admin->loginfailure++;
  29. $admin->save();
  30. return false;
  31. }
  32. $admin->loginfailure = 0;
  33. $admin->logintime = time();
  34. $admin->token = Random::uuid();
  35. $admin->save();
  36. Session::set("admin", $admin);
  37. $this->keeplogin($keeptime);
  38. return true;
  39. }
  40. /**
  41. * 注销登录
  42. */
  43. public function logout()
  44. {
  45. $admin = Admin::get(intval($this->id));
  46. if (!$admin)
  47. {
  48. return true;
  49. }
  50. $admin->token = '';
  51. $admin->save();
  52. Session::delete("admin");
  53. Cookie::delete("keeplogin");
  54. return true;
  55. }
  56. /**
  57. * 自动登录
  58. * @return boolean
  59. */
  60. public function autologin()
  61. {
  62. $keeplogin = Cookie::get('keeplogin');
  63. if (!$keeplogin)
  64. {
  65. return false;
  66. }
  67. list($id, $keeptime, $expiretime, $key) = explode('|', $keeplogin);
  68. if ($id && $keeptime && $expiretime && $key && $expiretime > time())
  69. {
  70. $admin = Admin::get($id);
  71. if (!$admin)
  72. {
  73. return false;
  74. }
  75. //token有变更
  76. if ($key != md5(md5($id) . md5($keeptime) . md5($expiretime) . $admin->token))
  77. {
  78. return false;
  79. }
  80. Session::set("admin", $admin);
  81. //刷新自动登录的时效
  82. $this->keeplogin($keeptime);
  83. return true;
  84. }
  85. else
  86. {
  87. return false;
  88. }
  89. }
  90. /**
  91. * 刷新保持登录的Cookie
  92. * @param int $keeptime
  93. * @return boolean
  94. */
  95. protected function keeplogin($keeptime = 0)
  96. {
  97. if ($keeptime)
  98. {
  99. $expiretime = time() + $keeptime;
  100. $key = md5(md5($this->id) . md5($keeptime) . md5($expiretime) . $this->token);
  101. $data = [$this->id, $keeptime, $expiretime, $key];
  102. Cookie::set('keeplogin', implode('|', $data));
  103. return true;
  104. }
  105. return false;
  106. }
  107. public function check($name, $uid = '', $relation = 'or', $mode = 'url')
  108. {
  109. return parent::check($name, $this->id, $relation, $mode);
  110. }
  111. /**
  112. * 检测当前控制器和方法是否匹配传递的数组
  113. *
  114. * @param array $arr 需要验证权限的数组
  115. */
  116. public function match($arr = [])
  117. {
  118. $request = Request::instance();
  119. $arr = is_array($arr) ? $arr : explode(',', $arr);
  120. if (!$arr)
  121. {
  122. return FALSE;
  123. }
  124. // 是否存在
  125. if (in_array(strtolower($request->action()), $arr) || in_array('*', $arr))
  126. {
  127. return TRUE;
  128. }
  129. // 没找到匹配
  130. return FALSE;
  131. }
  132. /**
  133. * 检测是否登录
  134. *
  135. * @return boolean
  136. */
  137. public function isLogin()
  138. {
  139. return Session::get('admin') ? true : false;
  140. }
  141. /**
  142. * 获取当前请求的URI
  143. * @return string
  144. */
  145. public function getRequestUri()
  146. {
  147. return $this->requestUri;
  148. }
  149. /**
  150. * 设置当前请求的URI
  151. * @param string $uri
  152. */
  153. public function setRequestUri($uri)
  154. {
  155. $this->requestUri = $uri;
  156. }
  157. public function getGroups($uid = null)
  158. {
  159. $uid = is_null($uid) ? $this->id : $uid;
  160. return parent::getGroups($uid);
  161. }
  162. public function getRuleList($uid = null)
  163. {
  164. $uid = is_null($uid) ? $this->id : $uid;
  165. return parent::getRuleList($uid);
  166. }
  167. public function getUserInfo($uid = null)
  168. {
  169. $uid = is_null($uid) ? $this->id : $uid;
  170. return $uid != $this->id ? Admin::get(intval($uid)) : Session::get('admin');
  171. }
  172. public function getRuleIds($uid = null)
  173. {
  174. $uid = is_null($uid) ? $this->id : $uid;
  175. return parent::getRuleIds($uid);
  176. }
  177. public function isSuperAdmin()
  178. {
  179. return in_array('*', $this->getRuleIds()) ? TRUE : FALSE;
  180. }
  181. }