Auth.php 11 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415
  1. <?php
  2. namespace app\admin\library;
  3. use app\admin\model\Admin;
  4. use fast\Random;
  5. use fast\Tree;
  6. use think\Config;
  7. use think\Cookie;
  8. use think\Request;
  9. use think\Session;
  10. class Auth extends \fast\Auth
  11. {
  12. protected $requestUri = '';
  13. protected $breadcrumb = [];
  14. protected $logined = false; //登录状态
  15. public function __construct()
  16. {
  17. parent::__construct();
  18. }
  19. public function __get($name)
  20. {
  21. return Session::get('admin.' . $name);
  22. }
  23. public function login($username, $password, $keeptime = 0)
  24. {
  25. $admin = Admin::get(['username' => $username]);
  26. if (!$admin)
  27. {
  28. return false;
  29. }
  30. if ($admin->password != md5(md5($password) . $admin->salt))
  31. {
  32. $admin->loginfailure++;
  33. $admin->save();
  34. return false;
  35. }
  36. $admin->loginfailure = 0;
  37. $admin->logintime = time();
  38. $admin->token = Random::uuid();
  39. $admin->save();
  40. Session::set("admin", $admin);
  41. $this->keeplogin($keeptime);
  42. return true;
  43. }
  44. /**
  45. * 注销登录
  46. */
  47. public function logout()
  48. {
  49. $admin = Admin::get(intval($this->id));
  50. if (!$admin)
  51. {
  52. return true;
  53. }
  54. $admin->token = '';
  55. $admin->save();
  56. Session::delete("admin");
  57. Cookie::delete("keeplogin");
  58. return true;
  59. }
  60. /**
  61. * 自动登录
  62. * @return boolean
  63. */
  64. public function autologin()
  65. {
  66. $keeplogin = Cookie::get('keeplogin');
  67. if (!$keeplogin)
  68. {
  69. return false;
  70. }
  71. list($id, $keeptime, $expiretime, $key) = explode('|', $keeplogin);
  72. if ($id && $keeptime && $expiretime && $key && $expiretime > time())
  73. {
  74. $admin = Admin::get($id);
  75. if (!$admin || !$admin->token)
  76. {
  77. return false;
  78. }
  79. //token有变更
  80. if ($key != md5(md5($id) . md5($keeptime) . md5($expiretime) . $admin->token))
  81. {
  82. return false;
  83. }
  84. Session::set("admin", $admin->toArray());
  85. //刷新自动登录的时效
  86. $this->keeplogin($keeptime);
  87. return true;
  88. }
  89. else
  90. {
  91. return false;
  92. }
  93. }
  94. /**
  95. * 刷新保持登录的Cookie
  96. * @param int $keeptime
  97. * @return boolean
  98. */
  99. protected function keeplogin($keeptime = 0)
  100. {
  101. if ($keeptime)
  102. {
  103. $expiretime = time() + $keeptime;
  104. $key = md5(md5($this->id) . md5($keeptime) . md5($expiretime) . $this->token);
  105. $data = [$this->id, $keeptime, $expiretime, $key];
  106. Cookie::set('keeplogin', implode('|', $data));
  107. return true;
  108. }
  109. return false;
  110. }
  111. public function check($name, $uid = '', $relation = 'or', $mode = 'url')
  112. {
  113. return parent::check($name, $this->id, $relation, $mode);
  114. }
  115. /**
  116. * 检测当前控制器和方法是否匹配传递的数组
  117. *
  118. * @param array $arr 需要验证权限的数组
  119. */
  120. public function match($arr = [])
  121. {
  122. $request = Request::instance();
  123. $arr = is_array($arr) ? $arr : explode(',', $arr);
  124. if (!$arr)
  125. {
  126. return FALSE;
  127. }
  128. // 是否存在
  129. if (in_array(strtolower($request->action()), $arr) || in_array('*', $arr))
  130. {
  131. return TRUE;
  132. }
  133. // 没找到匹配
  134. return FALSE;
  135. }
  136. /**
  137. * 检测是否登录
  138. *
  139. * @return boolean
  140. */
  141. public function isLogin()
  142. {
  143. if ($this->logined)
  144. {
  145. return true;
  146. }
  147. $admin = Session::get('admin');
  148. if (!$admin)
  149. {
  150. return false;
  151. }
  152. //判断是否同一时间同一账号只能在一个地方登录
  153. if (Config::get('fastadmin.login_unique'))
  154. {
  155. $my = Admin::get($admin->id);
  156. if (!$my || $my->token != $admin->token)
  157. {
  158. return false;
  159. }
  160. }
  161. $this->logined = true;
  162. return true;
  163. }
  164. /**
  165. * 获取当前请求的URI
  166. * @return string
  167. */
  168. public function getRequestUri()
  169. {
  170. return $this->requestUri;
  171. }
  172. /**
  173. * 设置当前请求的URI
  174. * @param string $uri
  175. */
  176. public function setRequestUri($uri)
  177. {
  178. $this->requestUri = $uri;
  179. }
  180. public function getGroups($uid = null)
  181. {
  182. $uid = is_null($uid) ? $this->id : $uid;
  183. return parent::getGroups($uid);
  184. }
  185. public function getRuleList($uid = null)
  186. {
  187. $uid = is_null($uid) ? $this->id : $uid;
  188. return parent::getRuleList($uid);
  189. }
  190. public function getUserInfo($uid = null)
  191. {
  192. $uid = is_null($uid) ? $this->id : $uid;
  193. return $uid != $this->id ? Admin::get(intval($uid)) : Session::get('admin');
  194. }
  195. public function getRuleIds($uid = null)
  196. {
  197. $uid = is_null($uid) ? $this->id : $uid;
  198. return parent::getRuleIds($uid);
  199. }
  200. public function isSuperAdmin()
  201. {
  202. return in_array('*', $this->getRuleIds()) ? TRUE : FALSE;
  203. }
  204. /**
  205. * 获取管理员所属于的分组ID
  206. * @param int $uid
  207. * @return array
  208. */
  209. public function getGroupIds($uid = null)
  210. {
  211. $groups = $this->getGroups($uid);
  212. $groupIds = [];
  213. foreach ($groups as $K => $v)
  214. {
  215. $groupIds[] = (int) $v['group_id'];
  216. }
  217. return $groupIds;
  218. }
  219. /**
  220. * 取出当前管理员所拥有权限的分组
  221. * @param boolean $withself 是否包含当前所在的分组
  222. * @return array
  223. */
  224. public function getChildrenGroupIds($withself = false)
  225. {
  226. //取出当前管理员所有的分组
  227. $groups = $this->getGroups();
  228. $groupIds = [];
  229. foreach ($groups as $k => $v)
  230. {
  231. $groupIds[] = $v['id'];
  232. }
  233. // 取出所有分组
  234. $groupList = model('AuthGroup')->all(['status' => 'normal']);
  235. $objList = [];
  236. foreach ($groups as $K => $v)
  237. {
  238. if ($v['rules'] === '*')
  239. {
  240. $objList = $groupList;
  241. break;
  242. }
  243. // 取出包含自己的所有子节点
  244. $childrenList = Tree::instance()->init($groupList)->getChildren($v['id'], true);
  245. $obj = Tree::instance()->init($childrenList)->getTreeArray($v['pid']);
  246. $objList = array_merge($objList, Tree::instance()->getTreeList($obj));
  247. }
  248. $childrenGroupIds = [];
  249. foreach ($objList as $k => $v)
  250. {
  251. $childrenGroupIds[] = $v['id'];
  252. }
  253. if (!$withself)
  254. {
  255. $childrenGroupIds = array_diff($childrenGroupIds, $groupIds);
  256. }
  257. return $childrenGroupIds;
  258. }
  259. /**
  260. * 取出当前管理员所拥有权限的管理员
  261. * @param boolean $withself 是否包含自身
  262. * @return array
  263. */
  264. public function getChildrenAdminIds($withself = false)
  265. {
  266. $childrenAdminIds = [];
  267. if (!$this->isSuperAdmin())
  268. {
  269. $groupIds = $this->getChildrenGroupIds(false);
  270. $authGroupList = model('AuthGroupAccess')
  271. ->field('uid,group_id')
  272. ->where('group_id', 'in', $groupIds)
  273. ->select();
  274. foreach ($authGroupList as $k => $v)
  275. {
  276. $childrenAdminIds[] = $v['uid'];
  277. }
  278. }
  279. else
  280. {
  281. //超级管理员拥有所有人的权限
  282. $childrenAdminIds = Admin::column('id');
  283. }
  284. if ($withself)
  285. {
  286. if (!in_array($this->id, $childrenAdminIds))
  287. {
  288. $childrenAdminIds[] = $this->id;
  289. }
  290. }
  291. else
  292. {
  293. $childrenAdminIds = array_diff($childrenAdminIds, [$this->id]);
  294. }
  295. return $childrenAdminIds;
  296. }
  297. /**
  298. * 获得面包屑导航
  299. * @param string $path
  300. * @return array
  301. */
  302. public function getBreadCrumb($path = '')
  303. {
  304. if ($this->breadcrumb || !$path)
  305. return $this->breadcrumb;
  306. $path_rule_id = 0;
  307. foreach ($this->rules as $rule)
  308. {
  309. $path_rule_id = $rule['name'] == $path ? $rule['id'] : $path_rule_id;
  310. }
  311. if ($path_rule_id)
  312. {
  313. $this->breadcrumb = Tree::instance()->init($this->rules)->getParents($path_rule_id, true);
  314. foreach ($this->breadcrumb as $k => &$v)
  315. {
  316. $v['url'] = url($v['name']);
  317. $v['title'] = __($v['title']);
  318. }
  319. }
  320. return $this->breadcrumb;
  321. }
  322. /**
  323. * 获取左侧菜单栏
  324. *
  325. * @param array $params URL对应的badge数据
  326. * @return string
  327. */
  328. public function getSidebar($params = [], $fixedPage = 'dashboard')
  329. {
  330. $colorArr = ['red', 'green', 'yellow', 'blue', 'teal', 'orange', 'purple'];
  331. $colorNums = count($colorArr);
  332. $badgeList = [];
  333. $module = request()->module();
  334. // 生成菜单的badge
  335. foreach ($params as $k => $v)
  336. {
  337. $url = $k;
  338. if (is_array($v))
  339. {
  340. $nums = isset($v[0]) ? $v[0] : 0;
  341. $color = isset($v[1]) ? $v[1] : $colorArr[(is_numeric($nums) ? $nums : strlen($nums)) % $colorNums];
  342. $class = isset($v[2]) ? $v[2] : 'label';
  343. }
  344. else
  345. {
  346. $nums = $v;
  347. $color = $colorArr[(is_numeric($nums) ? $nums : strlen($nums)) % $colorNums];
  348. $class = 'label';
  349. }
  350. //必须nums大于0才显示
  351. if ($nums)
  352. {
  353. $badgeList[$url] = '<small class="' . $class . ' pull-right bg-' . $color . '">' . $nums . '</small>';
  354. }
  355. }
  356. // 读取管理员当前拥有的权限节点
  357. $userRule = $this->getRuleList();
  358. $select_id = 0;
  359. $pinyin = new \Overtrue\Pinyin\Pinyin('Overtrue\Pinyin\MemoryFileDictLoader');
  360. // 必须将结果集转换为数组
  361. $ruleList = collection(model('AuthRule')->where('ismenu', 1)->order('weigh', 'desc')->cache("__menu__")->select())->toArray();
  362. foreach ($ruleList as $k => &$v)
  363. {
  364. if (!in_array($v['name'], $userRule))
  365. {
  366. unset($ruleList[$k]);
  367. continue;
  368. }
  369. $select_id = $v['name'] == $fixedPage ? $v['id'] : $select_id;
  370. $v['url'] = '/' . $module . '/' . $v['name'];
  371. $v['badge'] = isset($badgeList[$v['name']]) ? $badgeList[$v['name']] : '';
  372. $v['py'] = $pinyin->abbr($v['title'], '');
  373. $v['pinyin'] = $pinyin->permalink($v['title'], '');
  374. $v['title'] = __($v['title']);
  375. }
  376. // 构造菜单数据
  377. Tree::instance()->init($ruleList);
  378. $menu = Tree::instance()->getTreeMenu(0, '<li class="@class"><a href="@url@addtabs" addtabs="@id" url="@url" py="@py" pinyin="@pinyin"><i class="@icon"></i> <span>@title</span> <span class="pull-right-container">@caret @badge</span></a> @childlist</li>', $select_id, '', 'ul', 'class="treeview-menu"');
  379. return $menu;
  380. }
  381. }