createProductLogic.go 5.0 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161
  1. package product
  2. import (
  3. "context"
  4. "crypto/rand"
  5. "encoding/hex"
  6. "fmt"
  7. "regexp"
  8. "time"
  9. "perms-system-server/internal/consts"
  10. authHelper "perms-system-server/internal/logic/auth"
  11. productModel "perms-system-server/internal/model/product"
  12. "perms-system-server/internal/model/productmember"
  13. userModel "perms-system-server/internal/model/user"
  14. "perms-system-server/internal/response"
  15. "perms-system-server/internal/svc"
  16. "perms-system-server/internal/types"
  17. "perms-system-server/internal/util"
  18. "github.com/zeromicro/go-zero/core/logx"
  19. "github.com/zeromicro/go-zero/core/stores/sqlx"
  20. "golang.org/x/crypto/bcrypt"
  21. )
  22. var productCodeRegexp = regexp.MustCompile(`^[a-zA-Z][a-zA-Z0-9_-]{1,63}$`)
  23. type CreateProductLogic struct {
  24. logx.Logger
  25. ctx context.Context
  26. svcCtx *svc.ServiceContext
  27. }
  28. func NewCreateProductLogic(ctx context.Context, svcCtx *svc.ServiceContext) *CreateProductLogic {
  29. return &CreateProductLogic{
  30. Logger: logx.WithContext(ctx),
  31. ctx: ctx,
  32. svcCtx: svcCtx,
  33. }
  34. }
  35. // CreateProduct 创建产品。仅超管可调用,自动生成 appKey/appSecret 和产品专属管理员账号,用于接入新的业务产品。
  36. func (l *CreateProductLogic) CreateProduct(req *types.CreateProductReq) (resp *types.CreateProductResp, err error) {
  37. if err := authHelper.RequireSuperAdmin(l.ctx); err != nil {
  38. return nil, err
  39. }
  40. if !productCodeRegexp.MatchString(req.Code) {
  41. return nil, response.ErrBadRequest("产品编码只能包含字母、数字、下划线和中划线,须以字母开头,长度2-64")
  42. }
  43. if len(req.Name) > 64 {
  44. return nil, response.ErrBadRequest("产品名称长度不能超过64个字符")
  45. }
  46. if len(req.Remark) > 255 {
  47. return nil, response.ErrBadRequest("备注长度不能超过255个字符")
  48. }
  49. _, findErr := l.svcCtx.SysProductModel.FindOneByCode(l.ctx, req.Code)
  50. if findErr == nil {
  51. return nil, response.ErrConflict("产品编码已存在")
  52. }
  53. appKey, err := generateRandomHex(16)
  54. if err != nil {
  55. return nil, err
  56. }
  57. rawAppSecret, err := generateRandomHex(32)
  58. if err != nil {
  59. return nil, err
  60. }
  61. appSecretHash, err := bcrypt.GenerateFromPassword([]byte(rawAppSecret), bcrypt.DefaultCost)
  62. if err != nil {
  63. return nil, err
  64. }
  65. now := time.Now().Unix()
  66. adminUsername := fmt.Sprintf("admin_%s", req.Code)
  67. if _, err := l.svcCtx.SysUserModel.FindOneByUsername(l.ctx, adminUsername); err == nil {
  68. return nil, response.ErrConflict(fmt.Sprintf("用户名 %s 已存在,无法自动创建管理员账号", adminUsername))
  69. }
  70. adminPassword, err := generateRandomHex(12)
  71. if err != nil {
  72. return nil, err
  73. }
  74. hashedPwd, err := bcrypt.GenerateFromPassword([]byte(adminPassword), bcrypt.DefaultCost)
  75. if err != nil {
  76. return nil, err
  77. }
  78. var productId int64
  79. err = l.svcCtx.SysProductModel.TransactCtx(l.ctx, func(ctx context.Context, session sqlx.Session) error {
  80. result, err := l.svcCtx.SysProductModel.InsertWithTx(ctx, session, &productModel.SysProduct{
  81. Code: req.Code,
  82. Name: req.Name,
  83. AppKey: appKey,
  84. AppSecret: string(appSecretHash),
  85. Remark: req.Remark,
  86. Status: consts.StatusEnabled,
  87. CreateTime: now,
  88. UpdateTime: now,
  89. })
  90. if err != nil {
  91. return err
  92. }
  93. productId, _ = result.LastInsertId()
  94. userResult, err := l.svcCtx.SysUserModel.InsertWithTx(ctx, session, &userModel.SysUser{
  95. Username: adminUsername,
  96. Password: string(hashedPwd),
  97. Nickname: fmt.Sprintf("%s管理员", req.Name),
  98. IsSuperAdmin: consts.IsSuperAdminNo,
  99. MustChangePassword: consts.MustChangePasswordYes,
  100. Status: consts.StatusEnabled,
  101. CreateTime: now,
  102. UpdateTime: now,
  103. })
  104. if err != nil {
  105. return err
  106. }
  107. userId, _ := userResult.LastInsertId()
  108. _, err = l.svcCtx.SysProductMemberModel.InsertWithTx(ctx, session, &productmember.SysProductMember{
  109. ProductCode: req.Code,
  110. UserId: userId,
  111. MemberType: consts.MemberTypeAdmin,
  112. Status: consts.StatusEnabled,
  113. CreateTime: now,
  114. UpdateTime: now,
  115. })
  116. return err
  117. })
  118. if err != nil {
  119. // 前置的 FindOneByCode / FindOneByUsername 已经在大多数合法请求里把"产品码/用户名已存在"
  120. // 分辨清楚并返回具体文案。落到这里的 1062 基本都是同秒并发创建的稀有竞态,按审计 M-5 的
  121. // 建议不再用 strings.Contains 匹配 MySQL 错误消息中的索引名(不同版本的文案不稳定,
  122. // 改索引名会导致静默降级成通用冲突);直接统一回通用冲突让前端重试,由 pre-check 负责语义。
  123. if util.IsDuplicateEntryErr(err) {
  124. return nil, response.ErrConflict("数据冲突,请稍后重试")
  125. }
  126. return nil, err
  127. }
  128. return &types.CreateProductResp{
  129. Id: productId,
  130. Code: req.Code,
  131. AppKey: appKey,
  132. AppSecret: rawAppSecret,
  133. AdminUser: adminUsername,
  134. AdminPassword: adminPassword,
  135. }, nil
  136. }
  137. func generateRandomHex(byteLen int) (string, error) {
  138. b := make([]byte, byteLen)
  139. if _, err := rand.Read(b); err != nil {
  140. return "", fmt.Errorf("generate random bytes failed: %w", err)
  141. }
  142. return hex.EncodeToString(b), nil
  143. }