refreshTokenLogic.go 3.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116
  1. package pub
  2. import (
  3. "context"
  4. "fmt"
  5. "strings"
  6. "time"
  7. "perms-system-server/internal/consts"
  8. authHelper "perms-system-server/internal/logic/auth"
  9. "perms-system-server/internal/response"
  10. "perms-system-server/internal/svc"
  11. "perms-system-server/internal/types"
  12. "github.com/zeromicro/go-zero/core/limit"
  13. "github.com/zeromicro/go-zero/core/logx"
  14. )
  15. type RefreshTokenLogic struct {
  16. logx.Logger
  17. ctx context.Context
  18. svcCtx *svc.ServiceContext
  19. }
  20. func NewRefreshTokenLogic(ctx context.Context, svcCtx *svc.ServiceContext) *RefreshTokenLogic {
  21. return &RefreshTokenLogic{
  22. Logger: logx.WithContext(ctx),
  23. ctx: ctx,
  24. svcCtx: svcCtx,
  25. }
  26. }
  27. // RefreshToken 刷新令牌。使用有效的 refreshToken 换取新的 accessToken/refreshToken 令牌对,旧令牌即时失效(单会话轮转)。
  28. func (l *RefreshTokenLogic) RefreshToken(req *types.RefreshTokenReq) (resp *types.LoginResp, err error) {
  29. tokenStr := strings.TrimPrefix(req.Authorization, "Bearer ")
  30. if tokenStr == "" || tokenStr == req.Authorization {
  31. return nil, response.ErrUnauthorized("refreshToken格式错误")
  32. }
  33. claims, err := authHelper.ParseRefreshToken(tokenStr, l.svcCtx.Config.Auth.RefreshSecret)
  34. if err != nil {
  35. return nil, response.ErrUnauthorized("refreshToken无效或已过期")
  36. }
  37. productCode := claims.ProductCode
  38. if req.ProductCode != "" && req.ProductCode != productCode {
  39. return nil, response.ErrBadRequest("刷新令牌不允许切换产品")
  40. }
  41. ud := l.svcCtx.UserDetailsLoader.Load(l.ctx, claims.UserId, productCode)
  42. if ud.Status != consts.StatusEnabled {
  43. return nil, response.ErrForbidden("账号已被冻结")
  44. }
  45. if productCode != "" && ud.ProductStatus != consts.StatusEnabled {
  46. return nil, response.ErrForbidden("该产品已被禁用")
  47. }
  48. if productCode != "" && !ud.IsSuperAdmin && ud.MemberType == "" {
  49. return nil, response.ErrForbidden("您已不是该产品的成员")
  50. }
  51. if claims.TokenVersion != ud.TokenVersion {
  52. return nil, response.ErrUnauthorized("登录状态已失效,请重新登录")
  53. }
  54. if l.svcCtx.TokenOpLimiter != nil {
  55. code, _ := l.svcCtx.TokenOpLimiter.Take(fmt.Sprintf("refresh:%d", claims.UserId))
  56. if code == limit.OverQuota {
  57. return nil, response.ErrTooManyRequests("刷新操作过于频繁,请稍后再试")
  58. }
  59. }
  60. newVersion, err := l.svcCtx.SysUserModel.IncrementTokenVersion(l.ctx, claims.UserId)
  61. if err != nil {
  62. return nil, err
  63. }
  64. l.svcCtx.UserDetailsLoader.Clean(l.ctx, claims.UserId)
  65. accessToken, err := authHelper.GenerateAccessToken(
  66. l.svcCtx.Config.Auth.AccessSecret,
  67. l.svcCtx.Config.Auth.AccessExpire,
  68. ud.UserId, ud.Username, ud.ProductCode, ud.MemberType, newVersion,
  69. )
  70. if err != nil {
  71. return nil, err
  72. }
  73. newRefreshToken, err := authHelper.GenerateRefreshTokenWithExpiry(
  74. l.svcCtx.Config.Auth.RefreshSecret,
  75. claims.ExpiresAt.Time,
  76. ud.UserId, ud.ProductCode, newVersion,
  77. )
  78. if err != nil {
  79. return nil, response.ErrUnauthorized("refreshToken已过期,请重新登录")
  80. }
  81. return &types.LoginResp{
  82. AccessToken: accessToken,
  83. RefreshToken: newRefreshToken,
  84. Expires: time.Now().Unix() + l.svcCtx.Config.Auth.AccessExpire,
  85. UserInfo: types.UserInfo{
  86. UserId: ud.UserId,
  87. Username: ud.Username,
  88. Nickname: ud.Nickname,
  89. Avatar: ud.Avatar,
  90. Email: ud.Email,
  91. Phone: ud.Phone,
  92. IsSuperAdmin: ud.IsSuperAdminRaw,
  93. MustChangePassword: ud.MustChangePwdRaw,
  94. MemberType: ud.MemberType,
  95. Perms: ud.Perms,
  96. },
  97. }, nil
  98. }