shish 1 miesiąc temu
rodzic
commit
751d46b396
1 zmienionych plików z 183 dodań i 0 usunięć
  1. 183 0
      app-ghs/controllers/AuthController.php

+ 183 - 0
app-ghs/controllers/AuthController.php

@@ -15,6 +15,7 @@ use common\components\httpUtil;
 use common\components\imgUtil;
 use common\components\jwt;
 use common\components\noticeUtil;
+use common\components\sms;
 use common\components\util;
 use Yii;
 use common\components\stringUtil;
@@ -805,4 +806,186 @@ class AuthController extends PublicController
         util::success(['html' => $html]);
     }
 
+    /**
+     * 【用途】发送登录短信验证码
+     * 【为什么】供短信登录功能获取验证码,并包含防刷安全限制(单手机号60秒锁、每日上限5条)
+     */
+    public function actionSendLoginSms()
+    {
+        $getParams = Yii::$app->request->get();
+        $postParams = Yii::$app->request->post();
+        $allParams = array_merge($getParams, $postParams);
+        $mobile = $allParams['mobile'] ?? '';
+
+        if (!stringUtil::isMobile($mobile)) {
+            util::fail('请填写正确手机号');
+        }
+
+        // 1. 安全检查:单手机号 60 秒防刷
+        $lockKey = 'LOGIN_SMS_LOCK_' . $mobile;
+        if (Yii::$app->redis->executeCommand('GET', [$lockKey])) {
+            util::fail('发送过于频繁,请稍后再试');
+        }
+
+        // 2. 安全检查:单手机号每日上限 5 条
+        $dayKey = 'LOGIN_SMS_COUNT_' . date('Ymd') . '_' . $mobile;
+        $sendCount = (int)Yii::$app->redis->executeCommand('GET', [$dayKey]);
+        if ($sendCount >= 5) {
+            util::fail('该手机号今日获取验证码已达上限');
+        }
+
+        // 3. 生成 6 位随机验证码并保存至 Redis(有效期 5 分钟)
+        $code = (string)rand(100000, 999999);
+        $codeCacheKey = 'LOGIN_SMS_CODE_' . $mobile;
+        Yii::$app->redis->executeCommand('SETEX', [$codeCacheKey, 300, $code]);
+
+        // 4. 调用系统自带的限流发送组件 (内置了 IP 60秒锁和每日15条限制)
+        $minute = 5;
+        sms::send($mobile . ',' . $code . ',' . $minute, '登录验证码:{$var},{$var}分钟内有效');
+
+        // 5. 写入单手机号限制锁
+        Yii::$app->redis->executeCommand('SETEX', [$lockKey, 60, '1']);
+        Yii::$app->redis->executeCommand('SETEX', [$dayKey, 86400, $sendCount + 1]);
+
+        util::complete('验证码发送成功');
+    }
+
+    /**
+     * 【用途】短信验证码登录
+     * 【为什么】提供免密码快捷登录方式,验证通过后自动签发 JWT Token 并返回商家后台所需的所有初始化数据
+     */
+    public function actionSmsLogin()
+    {
+        $getParams = Yii::$app->request->get();
+        $postParams = Yii::$app->request->post();
+        $allParams = array_merge($getParams, $postParams);
+        $mobile = $allParams['mobile'] ?? '';
+        $code = $allParams['code'] ?? '';
+
+        if (empty($mobile) || empty($code)) {
+            util::fail('手机号和验证码不能为空');
+        }
+
+        if (!stringUtil::isMobile($mobile)) {
+            util::fail('请填写正确手机号');
+        }
+
+        // 1. 校验验证码
+        $codeCacheKey = 'LOGIN_SMS_CODE_' . $mobile;
+        $savedCode = Yii::$app->redis->executeCommand('GET', [$codeCacheKey]);
+
+        if (empty($savedCode) || $savedCode !== $code) {
+            util::fail('验证码错误或已过期');
+        }
+
+        // 2. 验证通过,立即销毁验证码以确保一次性使用
+        Yii::$app->redis->executeCommand('DEL', [$codeCacheKey]);
+
+        // 3. 查找用户并执行登录
+        $admin = AdminService::getByCondition(['mobile' => $mobile], true);
+        if (empty($admin)) {
+            util::fail('请先注册哦...');
+        }
+
+        $openShop = $admin->openGhsShop ?? 1;
+        $currentShopId = $admin->currentGhsShopId ?? 0;
+        if (empty($currentShopId)) {
+            if ($openShop == 2) {
+                util::fail('审核中');
+            }
+            util::fail('请先注册');
+        }
+        $currentShop = \bizGhs\shop\classes\ShopClass::getById($currentShopId, true);
+        if (empty($currentShop)) {
+            util::fail('没有找到门店71');
+        }
+        $mainId = $currentShop->mainId ?? 0;
+        $adminId = $admin->id;
+        $shopAdmin = ShopAdminService::getByCondition(['mainId' => $mainId, 'adminId' => $adminId], true);
+        if (empty($shopAdmin)) {
+            util::fail('您没有权限');
+        }
+        if ($shopAdmin->delStatus == 1) {
+            util::fail('您没有权限哦');
+        }
+        if ($shopAdmin->status == 0) {
+            util::fail("您的账号已被冻结");
+        }
+        $token = jwt::getNewToken($adminId);
+        $shopAdminId = $shopAdmin->id ?? 0;
+        //是否有切换门店的权限
+        $switchShop = \biz\shop\classes\ShopAdminClass::hasSwitchShopRight($shopAdmin);
+        //1没有开店 2已申请待审核 3已开店
+        $openShop = $admin['openGhsShop'] ?? 1;
+        $showDemo = 1;
+        $shop = ShopClass::getById($currentShopId, true);
+        $skCustomId = $shop->skCustomId ?? 0;
+        $apiHost = Yii::$app->params['ghsHost'];
+        $imgUploadApi = $apiHost . '/upload/save-file';
+        //使用手册
+        $cacheKey = 'close_book_' . $shopAdminId;
+        $hasClose = Yii::$app->redis->executeCommand('GET', [$cacheKey]);
+        $showBook = !empty($hasClose) ? 0 : 1;
+
+        $cacheKey = 'has_hit_navigate_' . $shopAdminId;
+        $hasHit = Yii::$app->redis->executeCommand('GET', [$cacheKey]);
+        $hasHitNavigate = !empty($hasHit) ? 1 : 0;
+
+        $ghsUpgrading = getenv('GHS_UPGRADING') == false ? 0 : getenv('GHS_UPGRADING');
+        if ($ghsUpgrading == 1) {
+            $allowShopAdminIdsStr = getenv('GHS_UPGRADE_ALLOW_SHOP_ADMIN_IDS') ?: '';
+            $allowShopAdminIds = !empty($allowShopAdminIdsStr) ? explode(',', $allowShopAdminIdsStr) : [];
+            if (!in_array($shopAdminId, $allowShopAdminIds)) {
+                util::fail('系统升级中,稍后再试');
+            }
+        }
+
+        $lookAllShop = 0;
+        if (getenv('YII_ENV') == 'production') {
+            $couldLookAllShop = dict::getDict('couldLookAllShop');
+            if (in_array($adminId, $couldLookAllShop)) {
+                $lookAllShop = 1;
+            }
+        } else {
+            $lookAllShop = 1;
+        }
+
+        //惠雅鲜花员工不能看收入情况
+        if (in_array($adminId, [2366, 2812, 4004])) {
+            $shopAdmin->super = 0;
+        }
+
+        $labelList = LabelClass::getMyUnUseLabelList($mainId);
+
+        //把设备状态更新为登录
+        if (isset($allParams['deviceId']) && $allParams['deviceId'] != '') {
+            $device =  \bizGhs\device\classes\GhsDeviceClass::getByCondition(['shopId'=>$currentShopId, 'deviceId'=>$allParams['deviceId']], true);
+            if ($device) {
+                $device->status = 1;
+                $device->save();
+            }
+        }
+
+        //注意这里的输出内容有多个地方一样,要修改需要同步修改,请搜索关键词loginOK!!!!!!!!
+        util::success([
+            'token' => $token,
+            'admin' => $admin,
+            'shopAdminId' => $shopAdminId,
+            'shopId' => $currentShopId,
+            'switchShop' => $switchShop,
+            'openShop' => $openShop,
+            'showDemo' => $showDemo,
+            //有小程序新版本提示更新
+            'update' => 0,
+            'skCustomId' => $skCustomId,
+            'apiHost' => $apiHost,
+            'imgUploadApi' => $imgUploadApi,
+            'showBook' => $showBook,
+            'hasHitNavigate' => $hasHitNavigate,
+            'staff' => $shopAdmin,
+            'lookAllShop' => $lookAllShop,
+            'labelList' => $labelList,
+        ]);
+    }
+
 }