auth.go 5.2 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176
  1. package auth
  2. import (
  3. "git.sxidc.com/go-framework/baize/convenient/domain/auth/permission"
  4. "git.sxidc.com/go-framework/baize/convenient/domain/auth/permission_group"
  5. "git.sxidc.com/go-framework/baize/convenient/domain/auth/relations"
  6. "git.sxidc.com/go-framework/baize/convenient/domain/auth/role"
  7. "git.sxidc.com/go-framework/baize/convenient/domain/auth/user"
  8. "git.sxidc.com/go-framework/baize/framework/binding"
  9. "git.sxidc.com/go-framework/baize/framework/core/api"
  10. "git.sxidc.com/go-framework/baize/framework/core/api/request"
  11. "git.sxidc.com/go-framework/baize/framework/core/api/response"
  12. "git.sxidc.com/go-framework/baize/framework/core/domain"
  13. "git.sxidc.com/go-framework/baize/framework/core/domain/entity"
  14. "git.sxidc.com/go-framework/baize/framework/core/infrastructure"
  15. "git.sxidc.com/go-framework/baize/framework/core/infrastructure/database"
  16. "git.sxidc.com/go-framework/baize/framework/core/infrastructure/database/sql"
  17. "git.sxidc.com/go-tools/utils/encoding"
  18. "github.com/pkg/errors"
  19. )
  20. // Simple Bind参数
  21. type Simple struct {
  22. // schema
  23. Schema string
  24. // AES加密用到的Key
  25. AESKey string
  26. // JWT的Key
  27. JWTSecretKey string
  28. // JWT到期时间
  29. JWTExpiredSec int64
  30. }
  31. func (simple *Simple) bind(binder *binding.Binder) {
  32. (&permission.Simple{Schema: simple.Schema}).Bind(binder)
  33. (&permission_group.Simple{Schema: simple.Schema}).Bind(binder)
  34. (&role.Simple{Schema: simple.Schema}).Bind(binder)
  35. (&user.Simple{Schema: simple.Schema, AESKey: simple.AESKey}).Bind(binder)
  36. (&relations.Simple{Schema: simple.Schema}).Bind(binder)
  37. // 登录
  38. binding.PostBind(binder, &binding.SimpleBindItem[map[string]any]{
  39. Path: "/login",
  40. SendResponseFunc: response.SendMapResponse,
  41. RequestParams: &LoginJsonBody{},
  42. ServiceFunc: func(c *api.Context, params request.Params, objects []domain.Object, i *infrastructure.Infrastructure) (map[string]any, error) {
  43. errResponse := map[string]any{
  44. "token": "",
  45. }
  46. jsonBody, err := request.ToConcrete[*LoginJsonBody](params)
  47. if err != nil {
  48. return errResponse, err
  49. }
  50. encryptedPassword, err := encoding.AESEncrypt(jsonBody.Password, simple.AESKey)
  51. if err != nil {
  52. return errResponse, errors.New(err.Error())
  53. }
  54. userTableName := domain.TableName(simple.Schema, &user.Entity{})
  55. dbExecutor := i.DBExecutor()
  56. result, err := database.QueryOne(dbExecutor, &sql.QueryOneExecuteParams{
  57. TableName: userTableName,
  58. Conditions: sql.NewConditions().
  59. Equal(user.ColumnUserName, jsonBody.UserName).
  60. Equal(user.ColumnPassword, encryptedPassword),
  61. })
  62. if err != nil {
  63. if database.IsErrorDBRecordNotExist(err) {
  64. return errResponse, errors.New("用户名或密码错误")
  65. }
  66. return errResponse, errors.New(err.Error())
  67. }
  68. existUser := new(user.Entity)
  69. err = sql.ParseSqlResult(result, existUser)
  70. if err != nil {
  71. return errResponse, err
  72. }
  73. token, err := newJWT(simple.JWTSecretKey, existUser.ID, simple.JWTExpiredSec)
  74. if err != nil {
  75. return errResponse, errors.New(err.Error())
  76. }
  77. err = database.Update(dbExecutor, &sql.UpdateExecuteParams{
  78. TableName: userTableName,
  79. TableRow: sql.NewTableRow().Add(user.ColumnToken, token),
  80. Conditions: sql.NewConditions().Equal(entity.ColumnID, existUser.ID),
  81. })
  82. if err != nil {
  83. return errResponse, errors.New(err.Error())
  84. }
  85. return map[string]any{
  86. "token": token,
  87. }, nil
  88. },
  89. }, Authentication())
  90. // 注销
  91. binding.PostBind(binder, &binding.SimpleBindItem[any]{
  92. Path: "/logout",
  93. SendResponseFunc: response.SendMsgResponse,
  94. ServiceFunc: func(c *api.Context, params request.Params, objects []domain.Object, i *infrastructure.Infrastructure) (any, error) {
  95. errResponse := map[string]any{
  96. "token": "",
  97. }
  98. jsonBody, err := request.ToConcrete[*LoginJsonBody](params)
  99. if err != nil {
  100. return errResponse, err
  101. }
  102. encryptedPassword, err := encoding.AESEncrypt(jsonBody.Password, simple.AESKey)
  103. if err != nil {
  104. return errResponse, errors.New(err.Error())
  105. }
  106. userTableName := domain.TableName(simple.Schema, &user.Entity{})
  107. dbExecutor := i.DBExecutor()
  108. result, err := database.QueryOne(dbExecutor, &sql.QueryOneExecuteParams{
  109. TableName: userTableName,
  110. Conditions: sql.NewConditions().
  111. Equal(user.ColumnUserName, jsonBody.UserName).
  112. Equal(user.ColumnPassword, encryptedPassword),
  113. })
  114. if err != nil {
  115. if database.IsErrorDBRecordNotExist(err) {
  116. return errResponse, errors.New("用户名或密码错误")
  117. }
  118. return errResponse, errors.New(err.Error())
  119. }
  120. existUser := new(user.Entity)
  121. err = sql.ParseSqlResult(result, existUser)
  122. if err != nil {
  123. return errResponse, err
  124. }
  125. token, err := newJWT(simple.JWTSecretKey, existUser.ID, simple.JWTExpiredSec)
  126. if err != nil {
  127. return errResponse, errors.New(err.Error())
  128. }
  129. err = database.Update(dbExecutor, &sql.UpdateExecuteParams{
  130. TableName: userTableName,
  131. TableRow: sql.NewTableRow().Add(user.ColumnToken, token),
  132. Conditions: sql.NewConditions().Equal(entity.ColumnID, existUser.ID),
  133. })
  134. if err != nil {
  135. return errResponse, errors.New(err.Error())
  136. }
  137. return map[string]any{
  138. "token": token,
  139. }, nil
  140. },
  141. })
  142. // TODO Challenge
  143. }
  144. func BindAuth(binder *binding.Binder, simple *Simple) {
  145. simple.bind(binder)
  146. }