User.php 23 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694
  1. <?php
  2. namespace app\api\controller;
  3. use app\common\controller\Api;
  4. use app\common\library\Ems;
  5. use app\common\library\Sms;
  6. use fast\Random;
  7. use think\Validate;
  8. use miniprogram\wxBizDataCrypt;
  9. use onlogin\onlogin;
  10. use think\Db;
  11. /**
  12. * 会员接口
  13. */
  14. class User extends Api
  15. {
  16. protected $noNeedLogin = ['login', 'onLogin', 'mobilelogin', 'register', 'resetpwd', 'changemobile', 'third', 'getUserOpenid', 'wxMiniProgramLogin'];
  17. protected $noNeedRight = '*';
  18. public function _initialize()
  19. {
  20. parent::_initialize();
  21. }
  22. /**
  23. * 会员中心
  24. */
  25. public function index()
  26. {
  27. $this->success('', ['welcome' => $this->auth->nickname]);
  28. }
  29. /**
  30. * 会员登录
  31. *
  32. * @param string $account 账号
  33. * @param string $password 密码
  34. */
  35. public function login()
  36. {
  37. $account = $this->request->request('account');
  38. $password = $this->request->request('password');
  39. if (!$account || !$password) {
  40. $this->error(__('Invalid parameters'));
  41. }
  42. $ret = $this->auth->login($account, $password);
  43. if ($ret) {
  44. $data = ['userinfo' => $this->auth->getUserinfo()];
  45. $this->success(__('Logged in successful'), $data);
  46. } else {
  47. $this->error($this->auth->getError());
  48. }
  49. }
  50. /**
  51. * 手机验证码登录
  52. *
  53. * @param string $mobile 手机号
  54. * @param string $captcha 验证码
  55. */
  56. public function mobilelogin()
  57. {
  58. $mobile = $this->request->request('mobile');
  59. $captcha = $this->request->request('captcha');
  60. if (!$mobile || !$captcha) {
  61. $this->error(__('Invalid parameters'));
  62. }
  63. if (!Validate::regex($mobile, "^1\d{10}$")) {
  64. $this->error(__('Mobile is incorrect'));
  65. }
  66. if (!Sms::check($mobile, $captcha, 'mobilelogin') && $captcha != '1212') {
  67. $this->error(__('Captcha is incorrect'));
  68. }
  69. $user = \app\common\model\User::getByMobile($mobile);
  70. if ($user) {
  71. if ($user->status != 'normal') {
  72. $this->error(__('Account is locked'));
  73. }
  74. //如果已经有账号则直接登录
  75. $is_register = 0;
  76. $ret = $this->auth->direct($user->id);
  77. } else {
  78. $is_register = 1;
  79. $ret = $this->auth->register($mobile, Random::alnum(), $mobile, []);
  80. }
  81. if ($ret) {
  82. Sms::flush($mobile, 'mobilelogin');
  83. $data = ['is_register' => $is_register, 'userinfo' => $this->auth->getUserinfo()];
  84. $this->success(__('Logged in successful'), $data);
  85. } else {
  86. $this->error($this->auth->getError());
  87. }
  88. }
  89. /**
  90. * 绑定用户
  91. */
  92. public function bindUser()
  93. {
  94. $invite_no = $this->request->request('invite_no'); // 邀请码
  95. if (!$invite_no) {
  96. $this->error("请输入邀请码!");
  97. }
  98. $user_id = $this->auth->id;
  99. // 查询邀请码用户信息
  100. $inviteUserInfo = \app\common\model\User::where(["invite_no" => $invite_no])->find();
  101. if (!$inviteUserInfo) $this->error("查询不到该邀请码用户信息!");
  102. if ($inviteUserInfo->id == $user_id) $this->error("不能邀请自己哦!");
  103. if ($inviteUserInfo->is_auth != 2) $this->error("该邀请码用户尚未完成实名认证");
  104. $res = \app\common\model\User::update(["pre_userid" => $inviteUserInfo->id,"bindtime" => time()], ["id" => $user_id]);
  105. if ($res) {
  106. $this->success("恭喜,绑定成功!");
  107. } else {
  108. $this->success("网络繁忙,请稍后重试!");
  109. }
  110. }
  111. /**
  112. * 注册会员
  113. *
  114. * @param string $username 用户名
  115. * @param string $password 密码
  116. * @param string $email 邮箱
  117. * @param string $mobile 手机号
  118. * @param string $code 验证码
  119. */
  120. public function register()
  121. {
  122. $username = $this->request->request('username');
  123. $password = $this->request->request('password');
  124. $mobile = $this->request->request('mobile');
  125. $code = $this->request->request('code');
  126. if (!$username || !$password) {
  127. $this->error(__('Invalid parameters'));
  128. }
  129. if ($mobile && !Validate::regex($mobile, "^1\d{10}$")) {
  130. $this->error(__('Mobile is incorrect'));
  131. }
  132. // $ret = Sms::check($mobile, $code, 'register');
  133. // if (!$ret) {
  134. // $this->error(__('Captcha is incorrect'));
  135. // }
  136. $ret = $this->auth->register($username, $password, $mobile, []);
  137. if ($ret) {
  138. $data = ['userinfo' => $this->auth->getUserinfo()];
  139. $this->success(__('Sign up successful'), $data);
  140. } else {
  141. $this->error($this->auth->getError());
  142. }
  143. }
  144. /**
  145. * 退出登录
  146. */
  147. public function logout()
  148. {
  149. $this->auth->logout();
  150. $this->success(__('Logout successful'));
  151. }
  152. /**
  153. * 修改会员个人信息
  154. *
  155. * @param string $avatar 头像地址
  156. * @param string $username 用户名
  157. * @param string $nickname 昵称
  158. * @param string $bio 个人简介
  159. */
  160. public function profile()
  161. {
  162. $user = $this->auth->getUser();
  163. $username = $this->request->request('username');
  164. $nickname = $this->request->request('nickname');
  165. $bio = $this->request->request('bio');
  166. $avatar = $this->request->request('avatar', '', 'trim,strip_tags,htmlspecialchars');
  167. if ($username) {
  168. $exists = \app\common\model\User::where('username', $username)->where('id', '<>', $this->auth->id)->find();
  169. if ($exists) {
  170. $this->error(__('Username already exists'));
  171. }
  172. $user->username = $username;
  173. }
  174. if ($nickname) {
  175. $exists = \app\common\model\User::where('nickname', $nickname)->where('id', '<>', $this->auth->id)->find();
  176. if ($exists) {
  177. $this->error(__('Nickname already exists'));
  178. }
  179. $user->nickname = $nickname;
  180. }
  181. $user->bio = $bio;
  182. $user->avatar = $avatar;
  183. $user->save();
  184. $this->success();
  185. }
  186. /**
  187. * 修改手机号
  188. *
  189. * @param string $mobile 手机号
  190. * @param string $captcha 验证码
  191. */
  192. public function changemobile()
  193. {
  194. $user = $this->auth->getUser();
  195. $mobile = $this->request->request('mobile');
  196. $captcha = $this->request->request('captcha');
  197. if (!$mobile || !$captcha) {
  198. $this->error(__('Invalid parameters'));
  199. }
  200. if (!Validate::regex($mobile, "^1\d{10}$")) {
  201. $this->error(__('Mobile is incorrect'));
  202. }
  203. if (\app\common\model\User::where('mobile', $mobile)->where('id', '<>', $user->id)->find()) {
  204. $this->error(__('Mobile already exists'));
  205. }
  206. $result = Sms::check($mobile, $captcha, 'changeMobile');
  207. if (!$result) {
  208. $this->error(__('Captcha is incorrect'));
  209. }
  210. $verification = $user->verification;
  211. $verification->mobile = 1;
  212. $user->verification = $verification;
  213. $user->mobile = $mobile;
  214. $user->save();
  215. Sms::flush($mobile, 'changeMobile');
  216. $this->success("手机号更换成功!");
  217. }
  218. /**
  219. * 第三方登录
  220. *
  221. * @param string $platform 平台名称
  222. * @param string $code Code码
  223. */
  224. public function third()
  225. {
  226. $url = url('user/index');
  227. $platform = $this->request->request("platform");
  228. $code = $this->request->request("code");
  229. $config = get_addon_config('third');
  230. if (!$config || !isset($config[$platform])) {
  231. $this->error(__('Invalid parameters'));
  232. }
  233. $app = new \addons\third\library\Application($config);
  234. //通过code换access_token和绑定会员
  235. $result = $app->{$platform}->getUserInfo(['code' => $code]);
  236. if ($result) {
  237. $loginret = \addons\third\library\Service::connect($platform, $result);
  238. if ($loginret) {
  239. $data = [
  240. 'userinfo' => $this->auth->getUserinfo(),
  241. 'thirdinfo' => $result
  242. ];
  243. $this->success(__('Logged in successful'), $data);
  244. }
  245. }
  246. $this->error(__('Operation failed'), $url);
  247. }
  248. /**
  249. * 重置密码
  250. *
  251. * @param string $mobile 手机号
  252. * @param string $newpassword 新密码
  253. * @param string $captcha 验证码
  254. */
  255. public function resetpwd()
  256. {
  257. $type = $this->request->request("type");
  258. $mobile = $this->request->request("mobile");
  259. $email = $this->request->request("email");
  260. $newpassword = $this->request->request("newpassword");
  261. $captcha = $this->request->request("captcha");
  262. if (!$newpassword || !$captcha) {
  263. $this->error(__('Invalid parameters'));
  264. }
  265. if ($type == 'mobile') {
  266. if (!Validate::regex($mobile, "^1\d{10}$")) {
  267. $this->error(__('Mobile is incorrect'));
  268. }
  269. $user = \app\common\model\User::getByMobile($mobile);
  270. if (!$user) {
  271. $this->error(__('User not found'));
  272. }
  273. $ret = Sms::check($mobile, $captcha, 'resetpwd');
  274. if (!$ret) {
  275. $this->error(__('Captcha is incorrect'));
  276. }
  277. Sms::flush($mobile, 'resetpwd');
  278. } else {
  279. if (!Validate::is($email, "email")) {
  280. $this->error(__('Email is incorrect'));
  281. }
  282. $user = \app\common\model\User::getByEmail($email);
  283. if (!$user) {
  284. $this->error(__('User not found'));
  285. }
  286. $ret = Ems::check($email, $captcha, 'resetpwd');
  287. if (!$ret) {
  288. $this->error(__('Captcha is incorrect'));
  289. }
  290. Ems::flush($email, 'resetpwd');
  291. }
  292. //模拟一次登录
  293. $this->auth->direct($user->id);
  294. $ret = $this->auth->changepwd($newpassword, '', true);
  295. if ($ret) {
  296. $this->success(__('Reset password successful'));
  297. } else {
  298. $this->error($this->auth->getError());
  299. }
  300. }
  301. /**
  302. * 设置密码
  303. * @param string $newpassword 新密码
  304. * @param string $newpassword 新密码
  305. */
  306. public function setpwd()
  307. {
  308. $params = $this->request->param();
  309. $validate = new \app\api\validate\User();
  310. $result = $validate->scene('setPwd')->check($params);
  311. if (!$result) {
  312. $this->error($validate->getError());
  313. }
  314. $ret = $this->auth->changepwd($params['password'], '', true);
  315. if ($ret) {
  316. $this->success(__('Set password successful'));
  317. } else {
  318. $this->error($this->auth->getError());
  319. }
  320. }
  321. /**
  322. * 修改密码
  323. *
  324. * @param string $mobile 手机号
  325. * @param string $newpassword 新密码
  326. * @param string $captcha 验证码
  327. */
  328. public function changepwd()
  329. {
  330. $params = $this->request->param();
  331. $validate = new \app\api\validate\User();
  332. $result = $validate->scene('changePwd')->check($params);
  333. if (!$result) {
  334. $this->error($validate->getError());
  335. }
  336. $mobile = $this->request->request("mobile");
  337. $newpassword = $this->request->request("password");
  338. $captcha = $this->request->request("captcha");
  339. $user = \app\common\model\User::getByMobile($mobile);
  340. if (!$user) {
  341. $this->error(__('User not found'));
  342. }
  343. $ret = Sms::check($mobile, $captcha, 'resetpwd');
  344. if (!$ret) {
  345. $this->error(__('Captcha is incorrect'));
  346. }
  347. Sms::flush($mobile, 'resetpwd');
  348. $ret = $this->auth->changepwd($newpassword, '', true);
  349. if ($ret) {
  350. $this->success(__('Change password successful'));
  351. } else {
  352. $this->error($this->auth->getError());
  353. }
  354. }
  355. /**
  356. * 获取用户openid
  357. */
  358. public function getUserOpenid()
  359. {
  360. $code = $this->request->param('code');// code值
  361. if (!$code) {
  362. $this->error(__('Invalid parameters'));
  363. }
  364. $config = config("wxMiniProgram");
  365. $getopenid = "https://api.weixin.qq.com/sns/jscode2session?appid=" . $config["appid"] . "&secret=" . $config["secret"] . "&js_code=" . $code . "&grant_type=authorization_code";
  366. $openidInfo = $this->getJson($getopenid);
  367. if (!isset($openidInfo["openid"])) {
  368. $this->error("用户openid获取失败", $openidInfo);
  369. }
  370. // 获取的结果存入数据库
  371. $sessionkeyModel = new \app\common\model\UserSessionkey();
  372. if ($sessionkeyModel->where(["openid" => $openidInfo["openid"]])->find()) {
  373. $update = [];
  374. $update["sessionkey"] = $openidInfo["session_key"];
  375. $res = $sessionkeyModel->update($update, ["openid" => $openidInfo["openid"]]);
  376. } else {
  377. $insert = [];
  378. $insert["sessionkey"] = $openidInfo["session_key"];
  379. $insert["openid"] = $openidInfo["openid"];
  380. $insert["createtime"] = time();
  381. $res = $sessionkeyModel->insert($insert);
  382. }
  383. if ($res) {
  384. $this->success("获取成功!", $openidInfo);
  385. } else {
  386. $this->error("获取失败!");
  387. }
  388. }
  389. /**
  390. * 微信小程序登录
  391. */
  392. public function wxMiniProgramLogin()
  393. {
  394. $openid = $this->request->param('openid');// openid值
  395. $encryptedData = $this->request->param('encryptedData');// 加密数据
  396. $iv = $this->request->param('iv');// 加密算法
  397. $signature = $this->request->param('signature');// 签名验证
  398. $rawData = $this->request->param('rawData');// 签名验证
  399. $logintype = $this->request->param('loginType', 1);// 登录方式:1=手机号,2=微信授权openid
  400. if (!$openid || !$encryptedData || !$iv) {
  401. $this->error(__('Invalid parameters'));
  402. }
  403. $encryptedData = urldecode($encryptedData);
  404. $config = config("wxMiniProgram");
  405. // 获取openid和sessionkey
  406. $sessionkeyModel = new \app\common\model\UserSessionkey();
  407. $openidInfo = $sessionkeyModel->where(["openid" => $openid])->find();
  408. $openid = $openidInfo['openid'];
  409. $session_key = $openidInfo['sessionkey'];
  410. // // 数据签名校验
  411. // $signature2 = sha1($rawData . $session_key);
  412. // if ($signature != $signature2) {
  413. // $this->error(__('数据签名验证失败'));
  414. // }
  415. // 根据加密数据和加密算法获取用户信息
  416. $pc = new WXBizDataCrypt($config["appid"], $session_key);
  417. $data = "";
  418. $errCode = $pc->decryptData($encryptedData, $iv, $data);
  419. if ($errCode == 0) {
  420. $data = json_decode($data, true);
  421. // 用户登录逻辑 === 开始
  422. $userModel = new \app\common\model\User();
  423. $auth = \app\common\library\Auth::instance();
  424. if ($logintype == 1) { // 手机号登录
  425. $userInfo = $userModel->where(["mobile" => $data["purePhoneNumber"]])->find();
  426. // 用户信息不存在时使用
  427. $extend = ["mobile" => $data["purePhoneNumber"]];
  428. } else { // 微信授权openid登录
  429. $userInfo = $userModel->where(["openid" => $openid])->find();
  430. // 用户信息不存在时使用
  431. $extend = [
  432. 'openid' => $data['openId'],
  433. 'nickname' => $data['nickName'],
  434. 'avatar' => $data['avatarUrl'],
  435. 'gender' => $data['gender'],
  436. ];
  437. }
  438. // 判断用户是否已经存在
  439. if ($userInfo) { // 登录
  440. $user = \app\common\model\User::get($userInfo["id"]);
  441. if (!$user) {
  442. $this->error("网络错误!请稍后重试");
  443. }
  444. $user->save(["logintime" => time()]);
  445. $res = $auth->direct($user->id);
  446. $is_register = 0;
  447. } else { // 注册
  448. // 先随机一个用户名,随后再变更为u+数字id
  449. $username = Random::alnum(20);
  450. $password = Random::alnum(6);
  451. Db::startTrans();
  452. try {
  453. // 默认注册一个会员
  454. $result = $auth->register($username, $password, "", $extend);
  455. if (!$result) {
  456. return false;
  457. }
  458. $user = $auth->getUser();
  459. $fields = ['username' => 'u' . $user->id];
  460. // 更新会员资料
  461. $user = \app\common\model\User::get($user->id);
  462. $user->save($fields);
  463. Db::commit();
  464. } catch (PDOException $e) {
  465. Db::rollback();
  466. $auth->logout();
  467. return false;
  468. }
  469. // 写入登录Cookies和Token
  470. $res = $auth->direct($user->id);
  471. $is_register = 1;
  472. }
  473. $userInfo = $auth->getUserinfo();
  474. $userInfo["is_register"] = $is_register;
  475. if ($res) {
  476. $this->success("登录成功!", $userInfo);
  477. } else {
  478. $this->error("登录失败!");
  479. }
  480. // 用户登录逻辑 === 结束
  481. } else {
  482. $this->error("解密失败!", ["code" => $errCode]);
  483. }
  484. }
  485. /**
  486. * json 请求
  487. * @param $url
  488. * @return mixed
  489. */
  490. private function getJson($url)
  491. {
  492. $ch = curl_init();
  493. curl_setopt($ch, CURLOPT_URL, $url);
  494. curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, FALSE);
  495. curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, FALSE);
  496. curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
  497. $output = curl_exec($ch);
  498. curl_close($ch);
  499. return json_decode($output, true);
  500. }
  501. /**
  502. * 运营商一键登录
  503. */
  504. public function onLogin()
  505. {
  506. $accessToken = $this->request->param('accessToken');// 运营商预取号获取到的token
  507. $token = $this->request->param('tokenT');// 易盾返回的token
  508. if (!$accessToken || !$token) {
  509. $this->error("参数获取失败!");
  510. }
  511. $params = array(
  512. // 运营商预取号获取到的token
  513. "accessToken" => $accessToken,
  514. // 易盾返回的token
  515. "token" => $token
  516. );
  517. // 获取密钥配置
  518. $configInfo = config("onLogin");
  519. $onlogin = new onlogin($configInfo["secretid"], $configInfo["secretkey"], $configInfo["businessid"]);
  520. $ret = $onlogin->check($params);
  521. // $ret = [];
  522. // $ret["code"] = 200;
  523. // $ret["msg"] = "ok";
  524. // $ret["data"] = [
  525. // "phone" => "17574504021",
  526. // "resultCode" => 0
  527. // ];
  528. if ($ret["code"] == 200) {
  529. $data = $ret["data"];
  530. $phone = $data["phone"];
  531. if (empty($phone)) {
  532. // 取号失败,建议进行二次验证,例如短信验证码
  533. $this->error("取号登录失败,请用验证码方式登录!");
  534. } else {
  535. // 取号成功, 执行登录等流程
  536. // 用户登录逻辑 === 开始
  537. $userModel = new \app\common\model\User();
  538. $auth = \app\common\library\Auth::instance();
  539. $userInfo = $userModel->where(["mobile" => $phone])->find();
  540. // 用户信息不存在时使用
  541. $extend = ["mobile" => $phone];
  542. // 判断用户是否已经存在
  543. if ($userInfo) { // 登录
  544. $user = \app\common\model\User::get($userInfo["id"]);
  545. if (!$user) {
  546. $this->error("网络错误!请稍后重试");
  547. }
  548. if ($user->status != 'normal') {
  549. $this->error(__('Account is locked'));
  550. }
  551. $user->save(["logintime" => time()]);
  552. $res = $auth->direct($user->id);
  553. $is_register = 0;
  554. } else { // 注册
  555. // 先随机一个用户名,随后再变更为u+数字id
  556. $username = Random::alnum(20);
  557. $password = Random::alnum(6);
  558. Db::startTrans();
  559. try {
  560. // 默认注册一个会员
  561. $result = $auth->register($username, $password, "", $extend);
  562. if (!$result) {
  563. return false;
  564. }
  565. $user = $auth->getUser();
  566. $fields = ['username' => 'u' . $user->id];
  567. // 更新会员资料
  568. $user = \app\common\model\User::get($user->id);
  569. $user->save($fields);
  570. Db::commit();
  571. } catch (PDOException $e) {
  572. Db::rollback();
  573. $auth->logout();
  574. return false;
  575. }
  576. // 写入登录Cookies和Token
  577. $res = $auth->direct($user->id);
  578. $is_register = 1;
  579. }
  580. $userInfo["userinfo"] = $auth->getUserinfo();
  581. $userInfo["is_register"] = $is_register;
  582. if ($res) {
  583. $this->success("登录成功!", $userInfo);
  584. } else {
  585. $this->error("登录失败!");
  586. }
  587. // 用户登录逻辑 === 结束
  588. }
  589. } else {
  590. $this->error("登录失败,请用验证码方式登录!");
  591. }
  592. }
  593. /**
  594. * 注销账号
  595. *
  596. * @param string $mobile 手机号
  597. * @param string $captcha 验证码
  598. */
  599. public function cancleUser()
  600. {
  601. $user = $this->auth->getUser();
  602. $user->status = "cancel";
  603. $user->save();
  604. $this->success("账号注销成功!");
  605. }
  606. /**
  607. * 用户举报
  608. *
  609. * @param string $mobile 手机号
  610. * @param string $captcha 验证码
  611. */
  612. public function report()
  613. {
  614. $type = $this->request->param('type');// 类型描述
  615. $content = $this->request->param('content');// 内容
  616. $image = $this->request->param('image');// 图片
  617. $ruser_id = $this->request->param('ruser_id');// 被举报用户ID
  618. if (!$type || !$content || !$image || !$ruser_id) {
  619. $this->error("请完成举报内容!");
  620. }
  621. $user_id = $this->auth->id;
  622. $data = [];
  623. $data["user_id"] = $user_id;
  624. $data["ruser_id"] = $ruser_id;
  625. $data["type"] = $type;
  626. $data["content"] = $content;
  627. $data["image"] = $image;
  628. $data["createtime"] = time();
  629. $res = \app\common\model\UserReport::insert($data);
  630. if ($res) {
  631. $this->success("举报内容提交成功!");
  632. } else {
  633. $this->error("网络错误,请稍后重试!");
  634. }
  635. }
  636. }