auth.go 6.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208
  1. package auth
  2. import (
  3. "git.sxidc.com/go-framework/baize/convenient/domain/auth/jwt_tools"
  4. "git.sxidc.com/go-framework/baize/convenient/domain/auth/permission"
  5. "git.sxidc.com/go-framework/baize/convenient/domain/auth/permission_group"
  6. "git.sxidc.com/go-framework/baize/convenient/domain/auth/relations"
  7. "git.sxidc.com/go-framework/baize/convenient/domain/auth/role"
  8. "git.sxidc.com/go-framework/baize/convenient/domain/auth/user"
  9. "git.sxidc.com/go-framework/baize/framework/binding"
  10. "git.sxidc.com/go-framework/baize/framework/core/api"
  11. "git.sxidc.com/go-framework/baize/framework/core/api/request"
  12. "git.sxidc.com/go-framework/baize/framework/core/api/response"
  13. "git.sxidc.com/go-framework/baize/framework/core/domain"
  14. "git.sxidc.com/go-framework/baize/framework/core/domain/entity"
  15. "git.sxidc.com/go-framework/baize/framework/core/infrastructure"
  16. "git.sxidc.com/go-framework/baize/framework/core/infrastructure/database"
  17. "git.sxidc.com/go-framework/baize/framework/core/infrastructure/database/sql"
  18. "git.sxidc.com/go-tools/utils/encoding"
  19. "github.com/pkg/errors"
  20. )
  21. // Simple Bind参数
  22. type Simple struct {
  23. // schema
  24. Schema string
  25. // AES加密用到的Key
  26. AESKey string
  27. // JWT的Key
  28. JWTSecretKey string
  29. // JWT到期时间
  30. JWTExpiredSec int64
  31. // 鉴权中间件
  32. AuthMiddleware binding.Middleware
  33. }
  34. func (simple *Simple) bind(binder *binding.Binder) {
  35. (&permission.Simple{Schema: simple.Schema, AuthMiddleware: simple.AuthMiddleware}).Bind(binder)
  36. (&permission_group.Simple{Schema: simple.Schema, AuthMiddleware: simple.AuthMiddleware}).Bind(binder)
  37. (&role.Simple{Schema: simple.Schema, AuthMiddleware: simple.AuthMiddleware}).Bind(binder)
  38. (&user.Simple{Schema: simple.Schema, AESKey: simple.AESKey, AuthMiddleware: simple.AuthMiddleware}).Bind(binder)
  39. (&relations.Simple{Schema: simple.Schema, AuthMiddleware: simple.AuthMiddleware}).Bind(binder)
  40. // 登录
  41. binding.PostBind(binder, &binding.SimpleBindItem[map[string]any]{
  42. Path: "/login",
  43. SendResponseFunc: response.SendMapResponse,
  44. RequestParams: &LoginJsonBody{},
  45. ServiceFunc: func(c *api.Context, params request.Params, objects []domain.Object, i *infrastructure.Infrastructure) (map[string]any, error) {
  46. errResponse := map[string]any{
  47. "token": "",
  48. }
  49. jsonBody, err := request.ToConcrete[*LoginJsonBody](params)
  50. if err != nil {
  51. return errResponse, err
  52. }
  53. encryptedPassword, err := encoding.AESEncrypt(jsonBody.Password, simple.AESKey)
  54. if err != nil {
  55. return errResponse, errors.New(err.Error())
  56. }
  57. userTableName := domain.TableName(simple.Schema, &user.Entity{})
  58. dbExecutor := i.DBExecutor()
  59. result, err := database.QueryOne(dbExecutor, &sql.QueryOneExecuteParams{
  60. TableName: userTableName,
  61. Conditions: sql.NewConditions().
  62. Equal(user.ColumnUserName, jsonBody.UserName).
  63. Equal(user.ColumnPassword, encryptedPassword),
  64. })
  65. if err != nil {
  66. if database.IsErrorDBRecordNotExist(err) {
  67. return errResponse, errors.New("用户名或密码错误")
  68. }
  69. return errResponse, errors.New(err.Error())
  70. }
  71. existUser := new(user.Entity)
  72. err = sql.ParseSqlResult(result, existUser)
  73. if err != nil {
  74. return errResponse, err
  75. }
  76. token, err := jwt_tools.NewJWT(simple.JWTSecretKey, existUser.ID, simple.JWTExpiredSec)
  77. if err != nil {
  78. return errResponse, errors.New(err.Error())
  79. }
  80. err = database.Update(dbExecutor, &sql.UpdateExecuteParams{
  81. TableName: userTableName,
  82. TableRow: sql.NewTableRow().Add(user.ColumnToken, token),
  83. Conditions: sql.NewConditions().Equal(entity.ColumnID, existUser.ID),
  84. })
  85. if err != nil {
  86. return errResponse, errors.New(err.Error())
  87. }
  88. return map[string]any{
  89. "token": token,
  90. }, nil
  91. },
  92. })
  93. // 注销
  94. binding.PostBind(binder, &binding.SimpleBindItem[any]{
  95. Path: "/logout",
  96. SendResponseFunc: response.SendMsgResponse,
  97. ServiceFunc: func(c *api.Context, params request.Params, objects []domain.Object, i *infrastructure.Infrastructure) (any, error) {
  98. userInfo := c.GetUserInfo()
  99. userTableName := domain.TableName(simple.Schema, &user.Entity{})
  100. dbExecutor := i.DBExecutor()
  101. err := database.Update(dbExecutor, &sql.UpdateExecuteParams{
  102. TableName: userTableName,
  103. TableRow: sql.NewTableRow().Add(user.ColumnToken, ""),
  104. Conditions: sql.NewConditions().Equal(entity.ColumnID, userInfo.GetID()),
  105. })
  106. if err != nil {
  107. return nil, errors.New(err.Error())
  108. }
  109. return nil, nil
  110. },
  111. }, simple.AuthMiddleware)
  112. // Challenge
  113. binding.PostBind(binder, &binding.SimpleBindItem[UserWithRoleInfo]{
  114. Path: "/challenge",
  115. SendResponseFunc: response.SendInfoResponse[UserWithRoleInfo],
  116. ServiceFunc: func(c *api.Context, params request.Params, objects []domain.Object, i *infrastructure.Infrastructure) (UserWithRoleInfo, error) {
  117. errInfo := UserWithRoleInfo{
  118. RoleInfos: make([]role.Info, 0),
  119. }
  120. userInfo := c.GetUserInfo()
  121. userAndRoleTableName := domain.RelationTableName(simple.Schema, &user.Entity{}, &role.Entity{})
  122. roleTableName := domain.TableName(simple.Schema, &role.Entity{})
  123. dbExecutor := i.DBExecutor()
  124. roleIDResults, totalCount, err := database.Query(dbExecutor, &sql.QueryExecuteParams{
  125. TableName: userAndRoleTableName,
  126. SelectColumns: []string{domain.RelationColumnName(&role.Entity{})},
  127. Conditions: sql.NewConditions().Equal(domain.RelationColumnName(&user.Entity{}), userInfo.GetID()),
  128. PageNo: 0,
  129. PageSize: 0,
  130. })
  131. if err != nil {
  132. return errInfo, errors.New(err.Error())
  133. }
  134. if totalCount == 0 {
  135. return UserWithRoleInfo{
  136. UserInfo: *(userInfo.(*user.Info)),
  137. RoleInfos: make([]role.Info, 0),
  138. }, nil
  139. }
  140. roleIDs := make([]string, len(roleIDResults))
  141. for index, roleIDResult := range roleIDResults {
  142. roleIDs[index] = roleIDResult.ColumnValueString(domain.RelationColumnName(&role.Entity{}))
  143. }
  144. roleResults, totalCount, err := database.Query(dbExecutor, &sql.QueryExecuteParams{
  145. TableName: roleTableName,
  146. Conditions: sql.NewConditions().In(entity.ColumnID, roleIDs),
  147. PageNo: 0,
  148. PageSize: 0,
  149. })
  150. if err != nil {
  151. return errInfo, errors.New(err.Error())
  152. }
  153. if totalCount == 0 {
  154. return UserWithRoleInfo{
  155. UserInfo: *(userInfo.(*user.Info)),
  156. RoleInfos: make([]role.Info, 0),
  157. }, nil
  158. }
  159. roleInfos := make([]role.Info, 0)
  160. err = sql.ParseSqlResult(roleResults, &roleInfos)
  161. if err != nil {
  162. return errInfo, errors.New(err.Error())
  163. }
  164. return UserWithRoleInfo{
  165. UserInfo: *(userInfo.(*user.Info)),
  166. RoleInfos: roleInfos,
  167. }, nil
  168. },
  169. }, simple.AuthMiddleware)
  170. }
  171. func BindAuth(binder *binding.Binder, simple *Simple) {
  172. simple.bind(binder)
  173. }