SysLoginController.java 9.4 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237
  1. package com.ruoyi.project.system.controller;
  2. import java.nio.charset.StandardCharsets;
  3. import java.security.*;
  4. import java.security.cert.Certificate;
  5. import java.security.cert.CertificateException;
  6. import java.security.cert.CertificateFactory;
  7. import java.security.interfaces.RSAPublicKey;
  8. import java.security.spec.InvalidKeySpecException;
  9. import java.security.spec.X509EncodedKeySpec;
  10. import java.util.*;
  11. import com.alibaba.fastjson.JSONObject;
  12. import com.ruoyi.common.utils.MessageUtils;
  13. import com.ruoyi.common.utils.SecurityUtils;
  14. import com.ruoyi.framework.manager.AsyncManager;
  15. import com.ruoyi.framework.manager.factory.AsyncFactory;
  16. import com.ruoyi.project.system.service.ISysUserService;
  17. import io.jsonwebtoken.*;
  18. import org.springframework.beans.factory.annotation.Autowired;
  19. import org.springframework.core.ParameterizedTypeReference;
  20. import org.springframework.http.*;
  21. import org.springframework.util.Assert;
  22. import org.springframework.util.LinkedMultiValueMap;
  23. import org.springframework.util.MultiValueMap;
  24. import org.springframework.web.bind.annotation.GetMapping;
  25. import org.springframework.web.bind.annotation.PostMapping;
  26. import org.springframework.web.bind.annotation.RequestBody;
  27. import org.springframework.web.bind.annotation.RestController;
  28. import com.ruoyi.common.constant.Constants;
  29. import com.ruoyi.common.utils.ServletUtils;
  30. import com.ruoyi.framework.security.LoginBody;
  31. import com.ruoyi.framework.security.LoginUser;
  32. import com.ruoyi.framework.security.service.SysLoginService;
  33. import com.ruoyi.framework.security.service.SysPermissionService;
  34. import com.ruoyi.framework.security.service.TokenService;
  35. import com.ruoyi.framework.web.domain.AjaxResult;
  36. import com.ruoyi.project.system.domain.SysMenu;
  37. import com.ruoyi.project.system.domain.SysUser;
  38. import com.ruoyi.project.system.service.ISysMenuService;
  39. import org.springframework.web.client.RestTemplate;
  40. import static sun.security.x509.X509CertImpl.PUBLIC_KEY;
  41. /**
  42. * 登录验证
  43. *
  44. * @author ruoyi
  45. */
  46. @RestController
  47. public class SysLoginController {
  48. @Autowired
  49. private SysLoginService loginService;
  50. @Autowired
  51. private ISysMenuService menuService;
  52. @Autowired
  53. private SysPermissionService permissionService;
  54. @Autowired
  55. private TokenService tokenService;
  56. // @Resource // 可优化,注册一个 RestTemplate Bean,然后注入
  57. private final RestTemplate restTemplate = new RestTemplate();
  58. @Autowired
  59. private ISysUserService userService;
  60. /**
  61. * 登录方法
  62. *
  63. * @param loginBody 登录信息
  64. * @return 结果
  65. */
  66. @PostMapping("/login")
  67. public AjaxResult login(@RequestBody LoginBody loginBody) {
  68. AjaxResult ajax = AjaxResult.success();
  69. // 生成令牌
  70. String token = loginService.login(loginBody.getUsername(), loginBody.getPassword(), loginBody.getCode(),
  71. loginBody.getUuid());
  72. ajax.put(Constants.TOKEN, token);
  73. return ajax;
  74. }
  75. /**
  76. * 获取用户信息
  77. *
  78. * @return 用户信息
  79. */
  80. @GetMapping("getInfo")
  81. public AjaxResult getInfo() {
  82. LoginUser loginUser = tokenService.getLoginUser(ServletUtils.getRequest());
  83. SysUser user = loginUser.getUser();
  84. // 角色集合
  85. Set<String> roles = permissionService.getRolePermission(user);
  86. // 权限集合
  87. Set<String> permissions = permissionService.getMenuPermission(user);
  88. AjaxResult ajax = AjaxResult.success();
  89. ajax.put("user", user);
  90. ajax.put("roles", roles);
  91. ajax.put("permissions", permissions);
  92. return ajax;
  93. }
  94. /**
  95. * 获取路由信息
  96. *
  97. * @return 路由信息
  98. */
  99. @GetMapping("getRouters")
  100. public AjaxResult getRouters() {
  101. LoginUser loginUser = tokenService.getLoginUser(ServletUtils.getRequest());
  102. // 用户信息
  103. SysUser user = loginUser.getUser();
  104. List<SysMenu> menus = menuService.selectMenuTreeByUserId(user.getUserId());
  105. return AjaxResult.success(menuService.buildMenus(menus));
  106. }
  107. /**
  108. * Azure登录方法
  109. *
  110. * @param loginBody 登录信息
  111. * @return 结果
  112. */
  113. @PostMapping("/getAccessToken")
  114. public AjaxResult getAccessToken(@RequestBody LoginBody loginBody) {
  115. AjaxResult ajax = AjaxResult.success();
  116. // 生成令牌
  117. String code = loginBody.getCode();
  118. // 1.1 构建请求头
  119. HttpHeaders headers = new HttpHeaders();
  120. headers.setContentType(MediaType.APPLICATION_JSON);
  121. headers.add("Authorization", "Bearer ");
  122. // 1.2 构建请求参数
  123. Map<String, String> body = new HashMap<>();
  124. body.put("code", code);
  125. body.put("grant_type", "authorization_code");
  126. body.put("client_secret", "12102a6a3290fd2cf3aedf631d771d48ccc474501bea71d47627fe985c34aa8c");
  127. body.put("client_id", "e7faeabf239846288ee07e6c40066cbd0dcc46cb1c1dea37c602c29a2368c6b8");
  128. body.put("redirect_uri", "http://localhost/cpms/index.html#/socialLogin");
  129. // 2. 执行请求
  130. ResponseEntity<AjaxResult> exchange = restTemplate.exchange(
  131. "https://gitee.com/oauth/token",
  132. HttpMethod.POST,
  133. new HttpEntity<>(body, headers),
  134. new ParameterizedTypeReference<AjaxResult>() {
  135. }); // 解决 CommonResult 的泛型丢失
  136. Assert.isTrue(exchange.getStatusCode().is2xxSuccessful(), "响应必须是 200 成功");
  137. ajax = exchange.getBody();
  138. System.out.println(ajax.toString());
  139. ajax.get("access_token");
  140. //进行jwt解析
  141. //系统登录 获取系统token
  142. return ajax;
  143. }
  144. /**
  145. * Azure登录方法
  146. *
  147. * @param loginBody 登录信息
  148. * @return 结果
  149. */
  150. @PostMapping("/getAzureAccessToken")
  151. public AjaxResult getAzureAccessToken(@RequestBody LoginBody loginBody) {
  152. AjaxResult ajax = AjaxResult.success();
  153. // 授权码
  154. String code = loginBody.getCode();
  155. // 1.1 构建请求头
  156. HttpHeaders headers = new HttpHeaders();
  157. headers.setContentType(MediaType.APPLICATION_FORM_URLENCODED);
  158. headers.add("Authorization", "Bearer ");
  159. // 1.2 构建请求参数
  160. MultiValueMap<String, String> body = new LinkedMultiValueMap<>();
  161. body.put("code", new LinkedList<String>(){{ add(code); }});
  162. body.put("grant_type", new LinkedList<String>(){{ add("authorization_code"); }});
  163. // body.put("client_secret", new LinkedList<String>(){{ add("FdR8Q~hmMJsJtJzPhDntTMwRv2WKD6dEhpSKraqk"); }});
  164. body.put("client_secret", new LinkedList<String>(){{ add("Ntg8Q~n3Ky7BnMo.xWW5BITBrTHjjDupZV5LSadW"); }});
  165. // body.put("client_id", new LinkedList<String>(){{ add("3db6f125-db4d-456b-a76e-a6d03182e845"); }});
  166. body.put("client_id", new LinkedList<String>(){{ add("13848745-b09e-4105-a48b-180c0c9d13fd"); }});
  167. // body.put("redirect_uri", new LinkedList<String>(){{ add("http://localhost/cpms/index.html"); }});
  168. body.put("redirect_uri", new LinkedList<String>(){{ add("https://cpms.basf-ypc.net.cn/cpms/index.html"); }});
  169. // body.put("scope", new LinkedList<String>(){{ add("api://3db6f125-db4d-456b-a76e-a6d03182e845/User.Read"); }});
  170. body.put("scope", new LinkedList<String>(){{ add("openid profile"); }});
  171. // 2. 执行请求
  172. ResponseEntity<AjaxResult> exchange = restTemplate.exchange(
  173. // token请求链接
  174. // "https://login.microsoftonline.com/7503e40a-97ec-4eb9-bf6d-2836e57e882d/oauth2/v2.0/token",
  175. "https://login.microsoftonline.com/ecaa386b-c8df-4ce0-ad01-740cbdb5ba55/oauth2/v2.0/token",
  176. HttpMethod.POST,
  177. new HttpEntity<>(body, headers),
  178. new ParameterizedTypeReference<AjaxResult>() {}); // 解决 CommonResult 的泛型丢失
  179. if (!exchange.getStatusCode().is2xxSuccessful()) {
  180. return AjaxResult.error("登录失败");
  181. }
  182. ajax = exchange.getBody();
  183. try {
  184. // 3. 进行jwt解析
  185. String idToken = ajax.get("id_token").toString();
  186. idToken = idToken.substring(idToken.indexOf(".") + 1, idToken.lastIndexOf("."));
  187. byte[] decodeBytes = java.util.Base64.getDecoder().decode(idToken);
  188. String decodeStr = new String(decodeBytes,StandardCharsets.UTF_8);
  189. JSONObject jsonObject = JSONObject.parseObject(decodeStr);
  190. // 4. 系统登录 获取系统token
  191. // 获取preferred_username字段,对应cpms.sysuser.username
  192. String preferredUsername = jsonObject.get("preferred_username").toString();
  193. String userName = preferredUsername.substring(0, preferredUsername.indexOf("@"));
  194. // 根据username,获取系统用户对象
  195. SysUser sysUser = userService.selectUserByUserName(userName);
  196. if (sysUser == null) {
  197. return AjaxResult.error("用户不存在");
  198. }
  199. AsyncManager.me().execute(AsyncFactory.recordLogininfor(userName, Constants.LOGIN_SUCCESS, MessageUtils.message("user.login.success")));
  200. LoginUser loginUser = new LoginUser(sysUser, permissionService.getMenuPermission(sysUser));
  201. String token = tokenService.createToken(loginUser);
  202. ajax.put(Constants.TOKEN, token);
  203. } catch (Exception e) {
  204. e.printStackTrace();
  205. ajax = AjaxResult.error("登录失败");
  206. }
  207. return ajax;
  208. }
  209. }