Auth.php 7.0 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273
  1. <?php
  2. namespace app\admin\library;
  3. use app\admin\model\Admin;
  4. use fast\Random;
  5. use fast\Tree;
  6. use think\Cookie;
  7. use think\Request;
  8. use think\Session;
  9. class Auth extends \fast\Auth
  10. {
  11. protected $requestUri = '';
  12. public function __construct()
  13. {
  14. parent::__construct();
  15. }
  16. public function __get($name)
  17. {
  18. return Session::get('admin.' . $name);
  19. }
  20. public function login($username, $password, $keeptime = 0)
  21. {
  22. $admin = Admin::get(['username' => $username]);
  23. if (!$admin)
  24. {
  25. return false;
  26. }
  27. if ($admin->password != md5(md5($password) . $admin->salt))
  28. {
  29. $admin->loginfailure++;
  30. $admin->save();
  31. return false;
  32. }
  33. $admin->loginfailure = 0;
  34. $admin->logintime = time();
  35. $admin->token = Random::uuid();
  36. $admin->save();
  37. Session::set("admin", $admin);
  38. $this->keeplogin($keeptime);
  39. return true;
  40. }
  41. /**
  42. * 注销登录
  43. */
  44. public function logout()
  45. {
  46. $admin = Admin::get(intval($this->id));
  47. if (!$admin)
  48. {
  49. return true;
  50. }
  51. $admin->token = '';
  52. $admin->save();
  53. Session::delete("admin");
  54. Cookie::delete("keeplogin");
  55. return true;
  56. }
  57. /**
  58. * 自动登录
  59. * @return boolean
  60. */
  61. public function autologin()
  62. {
  63. $keeplogin = Cookie::get('keeplogin');
  64. if (!$keeplogin)
  65. {
  66. return false;
  67. }
  68. list($id, $keeptime, $expiretime, $key) = explode('|', $keeplogin);
  69. if ($id && $keeptime && $expiretime && $key && $expiretime > time())
  70. {
  71. $admin = Admin::get($id);
  72. if (!$admin)
  73. {
  74. return false;
  75. }
  76. //token有变更
  77. if ($key != md5(md5($id) . md5($keeptime) . md5($expiretime) . $admin->token))
  78. {
  79. return false;
  80. }
  81. Session::set("admin", $admin);
  82. //刷新自动登录的时效
  83. $this->keeplogin($keeptime);
  84. return true;
  85. }
  86. else
  87. {
  88. return false;
  89. }
  90. }
  91. /**
  92. * 刷新保持登录的Cookie
  93. * @param int $keeptime
  94. * @return boolean
  95. */
  96. protected function keeplogin($keeptime = 0)
  97. {
  98. if ($keeptime)
  99. {
  100. $expiretime = time() + $keeptime;
  101. $key = md5(md5($this->id) . md5($keeptime) . md5($expiretime) . $this->token);
  102. $data = [$this->id, $keeptime, $expiretime, $key];
  103. Cookie::set('keeplogin', implode('|', $data));
  104. return true;
  105. }
  106. return false;
  107. }
  108. public function check($name, $uid = '', $relation = 'or', $mode = 'url')
  109. {
  110. return parent::check($name, $this->id, $relation, $mode);
  111. }
  112. /**
  113. * 检测当前控制器和方法是否匹配传递的数组
  114. *
  115. * @param array $arr 需要验证权限的数组
  116. */
  117. public function match($arr = [])
  118. {
  119. $request = Request::instance();
  120. $arr = is_array($arr) ? $arr : explode(',', $arr);
  121. if (!$arr)
  122. {
  123. return FALSE;
  124. }
  125. // 是否存在
  126. if (in_array(strtolower($request->action()), $arr) || in_array('*', $arr))
  127. {
  128. return TRUE;
  129. }
  130. // 没找到匹配
  131. return FALSE;
  132. }
  133. /**
  134. * 检测是否登录
  135. *
  136. * @return boolean
  137. */
  138. public function isLogin()
  139. {
  140. return Session::get('admin') ? true : false;
  141. }
  142. /**
  143. * 获取当前请求的URI
  144. * @return string
  145. */
  146. public function getRequestUri()
  147. {
  148. return $this->requestUri;
  149. }
  150. /**
  151. * 设置当前请求的URI
  152. * @param string $uri
  153. */
  154. public function setRequestUri($uri)
  155. {
  156. $this->requestUri = $uri;
  157. }
  158. public function getGroups($uid = null)
  159. {
  160. $uid = is_null($uid) ? $this->id : $uid;
  161. return parent::getGroups($uid);
  162. }
  163. public function getRuleList($uid = null)
  164. {
  165. $uid = is_null($uid) ? $this->id : $uid;
  166. return parent::getRuleList($uid);
  167. }
  168. public function getUserInfo($uid = null)
  169. {
  170. $uid = is_null($uid) ? $this->id : $uid;
  171. return $uid != $this->id ? Admin::get(intval($uid)) : Session::get('admin');
  172. }
  173. public function getRuleIds($uid = null)
  174. {
  175. $uid = is_null($uid) ? $this->id : $uid;
  176. return parent::getRuleIds($uid);
  177. }
  178. public function isSuperAdmin()
  179. {
  180. return in_array('*', $this->getRuleIds()) ? TRUE : FALSE;
  181. }
  182. /**
  183. * 获取左侧菜单栏
  184. *
  185. * @param array $params URL对应的badge数据
  186. * @return string
  187. */
  188. public function getSidebar($params = [])
  189. {
  190. $colorArr = ['red', 'green', 'yellow', 'blue', 'teal', 'orange', 'purple'];
  191. $colorNums = count($colorArr);
  192. $badgeList = [];
  193. $module = request()->module();
  194. // 生成菜单的badge
  195. foreach ($params as $k => $v)
  196. {
  197. if (stripos($k, '/') === false)
  198. {
  199. $url = '/' . $module . '/' . $k;
  200. }
  201. else
  202. {
  203. $url = url($k);
  204. }
  205. if (is_array($v))
  206. {
  207. $nums = isset($v[0]) ? $v[0] : 0;
  208. $color = isset($v[1]) ? $v[1] : $colorArr[(is_numeric($nums) ? $nums : strlen($nums)) % $colorNums];
  209. $class = isset($v[2]) ? $v[2] : 'label';
  210. }
  211. else
  212. {
  213. $nums = $v;
  214. $color = $colorArr[(is_numeric($nums) ? $nums : strlen($nums)) % $colorNums];
  215. $class = 'label';
  216. }
  217. //必须nums大于0才显示
  218. if ($nums)
  219. {
  220. $badgeList[$url] = '<small class="' . $class . ' pull-right bg-' . $color . '">' . $nums . '</small>';
  221. }
  222. }
  223. // 读取管理员当前拥有的权限节点
  224. $userRule = $this->getRuleList();
  225. $select_id = 0;
  226. $dashboard = '/' . $module . '/dashboard';
  227. // 必须将结果集转换为数组
  228. $ruleList = collection(model('AuthRule')->where('ismenu', 1)->order('weigh', 'desc')->cache("__menu__")->select())->toArray();
  229. foreach ($ruleList as $k => &$v)
  230. {
  231. if (!in_array($v['name'], $userRule))
  232. {
  233. unset($ruleList[$k]);
  234. continue;
  235. }
  236. $select_id = $v['name'] == $dashboard ? $v['id'] : $select_id;
  237. $v['url'] = $v['name'];
  238. $v['badge'] = isset($badgeList[$v['name']]) ? $badgeList[$v['name']] : '';
  239. }
  240. // 构造菜单数据
  241. Tree::instance()->init($ruleList);
  242. $menu = Tree::instance()->getTreeMenu(0, '<li class="@class"><a href="@url" addtabs="@id" url="@url"><i class="@icon"></i> <span>@title</span> <span class="pull-right-container">@caret @badge</span></a> @childlist</li>', $select_id, '', 'ul', 'class="treeview-menu"');
  243. return $menu;
  244. }
  245. }