SysLoginController.java 9.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241
  1. package com.ruoyi.project.system.controller;
  2. import java.nio.charset.StandardCharsets;
  3. import java.security.*;
  4. import java.security.cert.Certificate;
  5. import java.security.cert.CertificateException;
  6. import java.security.cert.CertificateFactory;
  7. import java.security.interfaces.RSAPublicKey;
  8. import java.security.spec.InvalidKeySpecException;
  9. import java.security.spec.X509EncodedKeySpec;
  10. import java.util.*;
  11. import com.alibaba.fastjson.JSON;
  12. import com.alibaba.fastjson.JSONObject;
  13. import com.ruoyi.common.utils.MessageUtils;
  14. import com.ruoyi.common.utils.SecurityUtils;
  15. import com.ruoyi.framework.manager.AsyncManager;
  16. import com.ruoyi.framework.manager.factory.AsyncFactory;
  17. import com.ruoyi.framework.web.controller.BaseController;
  18. import com.ruoyi.project.system.service.ISysUserService;
  19. import io.jsonwebtoken.*;
  20. import lombok.extern.flogger.Flogger;
  21. import org.springframework.beans.factory.annotation.Autowired;
  22. import org.springframework.core.ParameterizedTypeReference;
  23. import org.springframework.http.*;
  24. import org.springframework.util.Assert;
  25. import org.springframework.util.LinkedMultiValueMap;
  26. import org.springframework.util.MultiValueMap;
  27. import org.springframework.web.bind.annotation.GetMapping;
  28. import org.springframework.web.bind.annotation.PostMapping;
  29. import org.springframework.web.bind.annotation.RequestBody;
  30. import org.springframework.web.bind.annotation.RestController;
  31. import com.ruoyi.common.constant.Constants;
  32. import com.ruoyi.common.utils.ServletUtils;
  33. import com.ruoyi.framework.security.LoginBody;
  34. import com.ruoyi.framework.security.LoginUser;
  35. import com.ruoyi.framework.security.service.SysLoginService;
  36. import com.ruoyi.framework.security.service.SysPermissionService;
  37. import com.ruoyi.framework.security.service.TokenService;
  38. import com.ruoyi.framework.web.domain.AjaxResult;
  39. import com.ruoyi.project.system.domain.SysMenu;
  40. import com.ruoyi.project.system.domain.SysUser;
  41. import com.ruoyi.project.system.service.ISysMenuService;
  42. import org.springframework.web.client.RestTemplate;
  43. import static sun.security.x509.X509CertImpl.PUBLIC_KEY;
  44. /**
  45. * 登录验证
  46. *
  47. * @author ruoyi
  48. */
  49. @RestController
  50. public class SysLoginController extends BaseController {
  51. @Autowired
  52. private SysLoginService loginService;
  53. @Autowired
  54. private ISysMenuService menuService;
  55. @Autowired
  56. private SysPermissionService permissionService;
  57. @Autowired
  58. private TokenService tokenService;
  59. // @Resource // 可优化,注册一个 RestTemplate Bean,然后注入
  60. private final RestTemplate restTemplate = new RestTemplate();
  61. @Autowired
  62. private ISysUserService userService;
  63. /**
  64. * 登录方法
  65. *
  66. * @param loginBody 登录信息
  67. * @return 结果
  68. */
  69. @PostMapping("/login")
  70. public AjaxResult login(@RequestBody LoginBody loginBody) {
  71. AjaxResult ajax = AjaxResult.success();
  72. // 生成令牌
  73. String token = loginService.login(loginBody.getUsername(), loginBody.getPassword(), loginBody.getCode(),
  74. loginBody.getUuid());
  75. ajax.put(Constants.TOKEN, token);
  76. return ajax;
  77. }
  78. /**
  79. * 获取用户信息
  80. *
  81. * @return 用户信息
  82. */
  83. @GetMapping("getInfo")
  84. public AjaxResult getInfo() {
  85. LoginUser loginUser = tokenService.getLoginUser(ServletUtils.getRequest());
  86. SysUser user = loginUser.getUser();
  87. // 角色集合
  88. Set<String> roles = permissionService.getRolePermission(user);
  89. // 权限集合
  90. Set<String> permissions = permissionService.getMenuPermission(user);
  91. AjaxResult ajax = AjaxResult.success();
  92. ajax.put("user", user);
  93. ajax.put("roles", roles);
  94. ajax.put("permissions", permissions);
  95. return ajax;
  96. }
  97. /**
  98. * 获取路由信息
  99. *
  100. * @return 路由信息
  101. */
  102. @GetMapping("getRouters")
  103. public AjaxResult getRouters() {
  104. LoginUser loginUser = tokenService.getLoginUser(ServletUtils.getRequest());
  105. // 用户信息
  106. SysUser user = loginUser.getUser();
  107. List<SysMenu> menus = menuService.selectMenuTreeByUserId(user.getUserId());
  108. return AjaxResult.success(menuService.buildMenus(menus));
  109. }
  110. /**
  111. * Azure登录方法
  112. *
  113. * @param loginBody 登录信息
  114. * @return 结果
  115. */
  116. @PostMapping("/getAccessToken")
  117. public AjaxResult getAccessToken(@RequestBody LoginBody loginBody) {
  118. AjaxResult ajax = AjaxResult.success();
  119. // 生成令牌
  120. String code = loginBody.getCode();
  121. // 1.1 构建请求头
  122. HttpHeaders headers = new HttpHeaders();
  123. headers.setContentType(MediaType.APPLICATION_JSON);
  124. headers.add("Authorization", "Bearer ");
  125. // 1.2 构建请求参数
  126. Map<String, String> body = new HashMap<>();
  127. body.put("code", code);
  128. body.put("grant_type", "authorization_code");
  129. body.put("client_secret", "12102a6a3290fd2cf3aedf631d771d48ccc474501bea71d47627fe985c34aa8c");
  130. body.put("client_id", "e7faeabf239846288ee07e6c40066cbd0dcc46cb1c1dea37c602c29a2368c6b8");
  131. body.put("redirect_uri", "http://localhost/cpms/index.html#/socialLogin");
  132. // 2. 执行请求
  133. ResponseEntity<AjaxResult> exchange = restTemplate.exchange(
  134. "https://gitee.com/oauth/token",
  135. HttpMethod.POST,
  136. new HttpEntity<>(body, headers),
  137. new ParameterizedTypeReference<AjaxResult>() {
  138. }); // 解决 CommonResult 的泛型丢失
  139. Assert.isTrue(exchange.getStatusCode().is2xxSuccessful(), "响应必须是 200 成功");
  140. ajax = exchange.getBody();
  141. System.out.println(ajax.toString());
  142. ajax.get("access_token");
  143. //进行jwt解析
  144. //系统登录 获取系统token
  145. return ajax;
  146. }
  147. /**
  148. * Azure登录方法
  149. *
  150. * @param loginBody 登录信息
  151. * @return 结果
  152. */
  153. @PostMapping("/getAzureAccessToken")
  154. public AjaxResult getAzureAccessToken(@RequestBody LoginBody loginBody) {
  155. AjaxResult ajax = AjaxResult.success();
  156. // 授权码
  157. String code = loginBody.getCode();
  158. logger.info("code:" + code);
  159. // 1.1 构建请求头
  160. HttpHeaders headers = new HttpHeaders();
  161. headers.setContentType(MediaType.APPLICATION_FORM_URLENCODED);
  162. headers.add("Authorization", "Bearer ");
  163. // 1.2 构建请求参数
  164. MultiValueMap<String, String> body = new LinkedMultiValueMap<>();
  165. body.put("code", new LinkedList<String>(){{ add(code); }});
  166. body.put("grant_type", new LinkedList<String>(){{ add("authorization_code"); }});
  167. // body.put("client_secret", new LinkedList<String>(){{ add("FdR8Q~hmMJsJtJzPhDntTMwRv2WKD6dEhpSKraqk"); }});
  168. body.put("client_secret", new LinkedList<String>(){{ add("DzS8Q~EKILR6BpDTYLqKzkJ0oDtzSpptMY~uBcY."); }});
  169. // body.put("client_id", new LinkedList<String>(){{ add("3db6f125-db4d-456b-a76e-a6d03182e845"); }});
  170. body.put("client_id", new LinkedList<String>(){{ add("13848745-b09e-4105-a48b-180c0c9d13fd"); }});
  171. // body.put("redirect_uri", new LinkedList<String>(){{ add("http://localhost/cpms/index.html"); }});
  172. body.put("redirect_uri", new LinkedList<String>(){{ add("https://cpms.basf-ypc.net.cn/cpms/index.html"); }});
  173. // body.put("scope", new LinkedList<String>(){{ add("api://3db6f125-db4d-456b-a76e-a6d03182e845/User.Read"); }});
  174. body.put("scope", new LinkedList<String>(){{ add("openid profile"); }});
  175. // 2. 执行请求
  176. ResponseEntity<AjaxResult> exchange = restTemplate.exchange(
  177. // token请求链接
  178. // "https://login.microsoftonline.com/7503e40a-97ec-4eb9-bf6d-2836e57e882d/oauth2/v2.0/token",
  179. "https://login.microsoftonline.com/ecaa386b-c8df-4ce0-ad01-740cbdb5ba55/oauth2/v2.0/token",
  180. HttpMethod.POST,
  181. new HttpEntity<>(body, headers),
  182. new ParameterizedTypeReference<AjaxResult>() {}); // 解决 CommonResult 的泛型丢失
  183. logger.info(JSON.toJSONString(exchange));
  184. if (!exchange.getStatusCode().is2xxSuccessful()) {
  185. return AjaxResult.error("登录失败");
  186. }
  187. ajax = exchange.getBody();
  188. try {
  189. // 3. 进行jwt解析
  190. String idToken = ajax.get("id_token").toString();
  191. idToken = idToken.substring(idToken.indexOf(".") + 1, idToken.lastIndexOf("."));
  192. byte[] decodeBytes = java.util.Base64.getDecoder().decode(idToken);
  193. String decodeStr = new String(decodeBytes,StandardCharsets.UTF_8);
  194. JSONObject jsonObject = JSONObject.parseObject(decodeStr);
  195. // 4. 系统登录 获取系统token
  196. // 获取preferred_username字段,对应cpms.sysuser.username
  197. String preferredUsername = jsonObject.get("preferred_username").toString();
  198. String userName = preferredUsername.substring(0, preferredUsername.indexOf("@"));
  199. // 根据username,获取系统用户对象
  200. SysUser sysUser = userService.selectUserByUserName(userName);
  201. if (sysUser == null) {
  202. return AjaxResult.error("用户不存在");
  203. }
  204. AsyncManager.me().execute(AsyncFactory.recordLogininfor(userName, Constants.LOGIN_SUCCESS, MessageUtils.message("user.login.success")));
  205. LoginUser loginUser = new LoginUser(sysUser, permissionService.getMenuPermission(sysUser));
  206. String token = tokenService.createToken(loginUser);
  207. ajax.put(Constants.TOKEN, token);
  208. } catch (Exception e) {
  209. e.printStackTrace();
  210. ajax = AjaxResult.error("登录失败");
  211. }
  212. return ajax;
  213. }
  214. }