AuthCodeController.java 16 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347
  1. package com.zhentao.controller;
  2. import com.baomidou.mybatisplus.core.conditions.query.LambdaQueryWrapper;
  3. import com.zhentao.common.Result;
  4. import com.zhentao.dto.*;
  5. import com.zhentao.pojo.Users;
  6. import com.zhentao.service.SmsService;
  7. import com.zhentao.service.UsersService;
  8. import com.zhentao.service.WeChatService;
  9. import com.zhentao.util.AvatarUploadUtil;
  10. import com.zhentao.util.JwtUtil;
  11. import org.springframework.beans.factory.annotation.Autowired;
  12. import org.springframework.boot.autoconfigure.condition.ConditionalOnProperty;
  13. import org.springframework.security.crypto.bcrypt.BCryptPasswordEncoder;
  14. import org.springframework.web.bind.annotation.PostMapping;
  15. import org.springframework.web.bind.annotation.RequestBody;
  16. import org.springframework.web.bind.annotation.RequestMapping;
  17. import org.springframework.web.bind.annotation.RestController;
  18. import java.util.Date;
  19. import java.util.HashMap;
  20. import java.util.Map;
  21. @RestController
  22. @RequestMapping("/api/login")
  23. //@CrossOrigin
  24. // 在 Redis 启用时加载该控制器;不依赖数据库
  25. @ConditionalOnProperty(prefix = "redis", name = "enabled", havingValue = "true", matchIfMissing = true)
  26. public class AuthCodeController {
  27. // @Autowired
  28. // private SmsService smsService;
  29. @Autowired
  30. private JwtUtil jwtUtil;
  31. @Autowired
  32. private WeChatService weChatService;
  33. @Autowired
  34. private UsersService usersService;
  35. @Autowired
  36. private AvatarUploadUtil avatarUploadUtil;
  37. private final BCryptPasswordEncoder passwordEncoder = new BCryptPasswordEncoder();
  38. // /**
  39. // * 发送登录验证码(不依赖数据库)
  40. // */
  41. // @PostMapping("/send-code")
  42. // public Result<Void> sendCode(@RequestBody SmsSendRequest req) {
  43. // if (req == null || req.getPhone() == null || req.getPhone().trim().isEmpty()) {
  44. // return Result.error(400, "手机号不能为空");
  45. // }
  46. // boolean ok = smsService.sendLoginCode(req.getPhone().trim());
  47. // if (!ok) {
  48. // return Result.error(500, "验证码发送失败");
  49. // }
  50. // return Result.success();
  51. // }
  52. //
  53. // /**
  54. // * 验证码登录:校验通过后查询或创建用户,签发JWT
  55. // */
  56. // @PostMapping("/sms-login")
  57. // public Result<LoginResponse> smsLogin(@RequestBody SmsLoginRequest req) {
  58. // System.out.println("=== 验证码登录请求 ===");
  59. // if (req == null || req.getPhone() == null || req.getCode() == null) {
  60. // return Result.error(400, "手机号或验证码不能为空");
  61. // }
  62. //
  63. // System.out.println("手机号: " + req.getPhone());
  64. // boolean passed = smsService.verifyLoginCode(req.getPhone().trim(), req.getCode().trim());
  65. // if (!passed) {
  66. // System.out.println("❌ 验证码验证失败");
  67. // return Result.error(401, "验证码错误或已过期");
  68. // }
  69. //
  70. // System.out.println("✅ 验证码验证成功");
  71. //
  72. // // 查询数据库中的用户
  73. // Users user = usersService.getOne(new LambdaQueryWrapper<Users>()
  74. // .eq(Users::getPhone, req.getPhone().trim())
  75. // .eq(Users::getStatus, 1), false);
  76. //
  77. // // 如果用户不存在,创建新用户
  78. // if (user == null) {
  79. // System.out.println("⚠️ 用户不存在,创建新用户");
  80. // user = new Users();
  81. // user.setPhone(req.getPhone().trim());
  82. // user.setNickname("用户" + req.getPhone().substring(Math.max(0, req.getPhone().length() - 4)));
  83. // user.setStatus(1);
  84. // user.setPassword(null);
  85. // user.setCreatedAt(new Date());
  86. // user.setUpdatedAt(new Date());
  87. // user.setSourceChannel("sms");
  88. //
  89. // // 保存到数据库,自动生成userId
  90. // usersService.save(user);
  91. // System.out.println("✅ 创建新用户成功,ID: " + user.getUserId());
  92. // } else {
  93. // System.out.println("✅ 找到现有用户,ID: " + user.getUserId());
  94. // // 更新最后登录时间
  95. // user.setLastLoginAt(new Date());
  96. // usersService.updateById(user);
  97. // }
  98. //
  99. // // 生成JWT令牌
  100. // Map<String, Object> claims = new HashMap<>();
  101. // claims.put("userId", user.getUserId());
  102. // claims.put("nickname", user.getNickname());
  103. // claims.put("phone", user.getPhone());
  104. // String token = jwtUtil.generateToken(claims);
  105. //
  106. // System.out.println("✅ JWT token生成成功");
  107. //
  108. // // 构造响应,避免泄露密码
  109. // user.setPassword(null);
  110. // LoginResponse resp = new LoginResponse();
  111. // resp.setToken(token);
  112. // resp.setUser(user);
  113. //
  114. // System.out.println("✅ 验证码登录成功,返回用户信息");
  115. // System.out.println("返回的用户ID: " + user.getUserId() + " (类型: " + user.getUserId().getClass().getSimpleName() + ")");
  116. // return Result.success(resp);
  117. // }
  118. /**
  119. * 微信授权登录:传入 wx.login 的临时 code,后端调用 jscode2session,查询或创建用户并返回 JWT
  120. */
  121. @PostMapping("/wechat/login")
  122. public Result<LoginResponse> wechatLogin(@RequestBody WechatLoginRequest req) {
  123. System.out.println("=== 微信登录请求 ===");
  124. if (req == null || req.getCode() == null || req.getCode().trim().isEmpty()) {
  125. return Result.error(400, "code 不能为空");
  126. }
  127. Map<String, Object> wx = weChatService.code2Session(req.getCode().trim());
  128. if (wx == null || (wx.containsKey("errcode") && ((Number) wx.get("errcode")).intValue() != 0)) {
  129. String msg = wx != null && wx.get("errmsg") != null ? String.valueOf(wx.get("errmsg")) : "微信接口错误";
  130. System.out.println("❌ 微信接口调用失败: " + msg);
  131. return Result.error(502, msg);
  132. }
  133. String openid = String.valueOf(wx.get("openid"));
  134. String unionid = wx.get("unionid") != null ? String.valueOf(wx.get("unionid")) : null;
  135. System.out.println("✅ 获取到微信openid: " + openid);
  136. // 根据openid查询用户
  137. Users user = usersService.getOne(new LambdaQueryWrapper<Users>()
  138. .eq(Users::getWechatOpenid, openid)
  139. .eq(Users::getStatus, 1), false);
  140. // 如果用户不存在,创建新用户
  141. if (user == null) {
  142. System.out.println("⚠️ 微信用户不存在,创建新用户");
  143. user = new Users();
  144. // ✅ 生成默认昵称
  145. String defaultNickname = "微信用户";
  146. if (req.getNickname() != null && !req.getNickname().trim().isEmpty()) {
  147. user.setNickname(req.getNickname().trim());
  148. } else if (user.getPhone() != null && !user.getPhone().trim().isEmpty()) {
  149. // 如果有手机号,使用"用户+手机号后四位"
  150. String phone = user.getPhone().trim();
  151. defaultNickname = "用户" + phone.substring(Math.max(0, phone.length() - 4));
  152. user.setNickname(defaultNickname);
  153. } else {
  154. // 随机生成4位数字作为后缀
  155. int randomNum = (int) (Math.random() * 9000) + 1000;
  156. defaultNickname = "微信用户" + randomNum;
  157. user.setNickname(defaultNickname);
  158. }
  159. System.out.println("设置用户昵称: " + user.getNickname());
  160. // ✅ 上传头像到MinIO
  161. if (req.getAvatarUrl() != null && !req.getAvatarUrl().trim().isEmpty()) {
  162. try {
  163. System.out.println("开始上传头像到MinIO...");
  164. String avatarUrl = avatarUploadUtil.uploadBase64Avatar(req.getAvatarUrl().trim(), 0); // 临时使用0,保存后会有真实ID
  165. if (avatarUrl != null) {
  166. user.setAvatarUrl(avatarUrl);
  167. System.out.println("✅ 头像上传成功: " + avatarUrl);
  168. } else {
  169. System.out.println("⚠️ 头像上传失败,使用默认头像");
  170. // 这里可以设置一个默认头像URL
  171. user.setAvatarUrl("https://via.placeholder.com/150");
  172. }
  173. } catch (Exception e) {
  174. System.err.println("⚠️ 头像上传异常: " + e.getMessage());
  175. // 这里可以设置一个默认头像URL
  176. user.setAvatarUrl("https://via.placeholder.com/150");
  177. }
  178. } else {
  179. System.out.println("⚠️ 未提供头像,使用默认头像");
  180. // 这里可以设置一个默认头像URL
  181. user.setAvatarUrl("https://via.placeholder.com/150");
  182. }
  183. user.setStatus(1);
  184. // ✅ 设置加密后的默认密码
  185. user.setPassword(passwordEncoder.encode("123456"));
  186. user.setSourceChannel("wechat");
  187. user.setHasWechatLogin(1);
  188. user.setWechatOpenid(openid);
  189. if (unionid != null) {
  190. user.setWechatUnionid(unionid);
  191. }
  192. user.setCreatedAt(new Date());
  193. user.setUpdatedAt(new Date());
  194. // ✅ 如果提供了手机号code,尝试获取手机号(先获取手机号,以便生成昵称)
  195. if (req.getPhoneCode() != null && !req.getPhoneCode().trim().isEmpty()) {
  196. try {
  197. System.out.println("尝试获取手机号,code: " + req.getPhoneCode());
  198. String phone = weChatService.getUserPhoneByCode(req.getPhoneCode().trim());
  199. if (phone != null && !phone.isEmpty()) {
  200. user.setPhone(phone);
  201. System.out.println("✅ 成功获取手机号: " + phone);
  202. } else {
  203. System.out.println("⚠️ 手机号为空");
  204. }
  205. } catch (Exception e) {
  206. System.err.println("⚠️ 获取手机号失败: " + e.getMessage());
  207. }
  208. } else {
  209. System.out.println("⚠️ 未提供手机号code");
  210. }
  211. // ✅ 重新生成昵称(确保使用最新的手机号信息)
  212. if (req.getNickname() == null || req.getNickname().trim().isEmpty()) {
  213. // String defaultNickname = "微信用户";
  214. if (user.getPhone() != null && !user.getPhone().trim().isEmpty()) {
  215. // 如果有手机号,使用"用户+手机号后四位"
  216. String phone = user.getPhone().trim();
  217. defaultNickname = "用户" + phone.substring(Math.max(0, phone.length() - 4));
  218. user.setNickname(defaultNickname);
  219. System.out.println("更新昵称使用手机号后四位: " + defaultNickname);
  220. }
  221. }
  222. // 保存到数据库,自动生成userId
  223. usersService.save(user);
  224. System.out.println("✅ 创建微信新用户成功,ID: " + user.getUserId() + ", 昵称: " + user.getNickname());
  225. } else {
  226. System.out.println("✅ 找到微信用户,ID: " + user.getUserId());
  227. // ✅ 如果是已存在用户,也更新昵称和头像(如果前端提供了新值)
  228. boolean needUpdate = false;
  229. if (req.getNickname() != null && !req.getNickname().trim().isEmpty()
  230. && !req.getNickname().equals(user.getNickname())) {
  231. System.out.println("更新昵称: " + user.getNickname() + " -> " + req.getNickname());
  232. user.setNickname(req.getNickname().trim());
  233. needUpdate = true;
  234. }
  235. // ✅ 更新头像(上传到MinIO)
  236. if (req.getAvatarUrl() != null && !req.getAvatarUrl().trim().isEmpty()) {
  237. try {
  238. System.out.println("用户更新头像,上传到MinIO...");
  239. String avatarUrl = avatarUploadUtil.uploadBase64Avatar(req.getAvatarUrl().trim(), user.getUserId());
  240. if (avatarUrl != null && !avatarUrl.equals(user.getAvatarUrl())) {
  241. System.out.println("更新头像: " + avatarUrl);
  242. user.setAvatarUrl(avatarUrl);
  243. needUpdate = true;
  244. }
  245. } catch (Exception e) {
  246. System.err.println("⚠️ 更新头像失败: " + e.getMessage());
  247. }
  248. }
  249. // ✅ 如果提供了手机号code且当前用户没有手机号,尝试获取
  250. if ((user.getPhone() == null || user.getPhone().isEmpty())
  251. && req.getPhoneCode() != null && !req.getPhoneCode().trim().isEmpty()) {
  252. try {
  253. System.out.println("用户无手机号,尝试获取,code: " + req.getPhoneCode());
  254. String phone = weChatService.getUserPhoneByCode(req.getPhoneCode().trim());
  255. if (phone != null && !phone.isEmpty()) {
  256. user.setPhone(phone);
  257. System.out.println("✅ 成功获取手机号: " + phone);
  258. needUpdate = true;
  259. }
  260. } catch (Exception e) {
  261. System.err.println("⚠️ 获取手机号失败: " + e.getMessage());
  262. }
  263. }
  264. // 更新最后登录时间
  265. user.setLastLoginAt(new Date());
  266. needUpdate = true;
  267. if (needUpdate) {
  268. user.setUpdatedAt(new Date());
  269. usersService.updateById(user);
  270. System.out.println("✅ 更新用户信息成功");
  271. }
  272. }
  273. // 生成JWT令牌
  274. Map<String, Object> claims = new HashMap<>();
  275. claims.put("userId", user.getUserId());
  276. claims.put("nickname", user.getNickname());
  277. claims.put("openid", openid);
  278. if (unionid != null) claims.put("unionid", unionid);
  279. String token = jwtUtil.generateToken(claims);
  280. System.out.println("✅ JWT token生成成功");
  281. // 构造响应,避免泄露密码
  282. user.setPassword(null);
  283. LoginResponse resp = new LoginResponse();
  284. resp.setToken(token);
  285. resp.setUser(user);
  286. System.out.println("✅ 微信登录成功,返回用户信息");
  287. System.out.println("返回的用户ID: " + user.getUserId() + " (类型: " + user.getUserId().getClass().getSimpleName() + ")");
  288. return Result.success(resp);
  289. }
  290. /**
  291. * 微信手机号获取(兼容旧版 iv/加密数据;推荐前端走新版 getPhoneNumber 并直接上传手机号)
  292. */
  293. @PostMapping("/wechat/phone")
  294. public Result<Map<String, Object>> wechatPhone(@RequestBody WechatPhoneRequest req) {
  295. Map<String, Object> data = new HashMap<>();
  296. data.put("phone", null);
  297. if (req != null && req.getCode() != null && !req.getCode().trim().isEmpty()) {
  298. String phone = weChatService.getUserPhoneByCode(req.getCode().trim());
  299. if (phone != null) {
  300. data.put("phone", phone);
  301. return Result.success(data);
  302. }
  303. return Result.error(502, "微信返回空手机号或接口错误");
  304. }
  305. // 兼容旧版:若提供 iv/encryptedData + 需要 sessionKey(从前面的 /wechat/login 返回中获取并传入)
  306. if (req != null && req.getIv() != null && req.getEncryptedData() != null && req.getSessionKey() != null) {
  307. String phone = weChatService.decryptPhone(req.getSessionKey(), req.getIv(), req.getEncryptedData());
  308. if (phone != null) {
  309. data.put("phone", phone);
  310. return Result.success(data);
  311. }
  312. return Result.error(501, "暂不支持解密或数据不完整");
  313. }
  314. return Result.error(400, "缺少 code 或 iv/encryptedData+sessionKey");
  315. }
  316. }