loginService.go 2.8 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101
  1. package pub
  2. import (
  3. "context"
  4. "errors"
  5. "perms-system-server/internal/consts"
  6. "perms-system-server/internal/loaders"
  7. authHelper "perms-system-server/internal/logic/auth"
  8. "perms-system-server/internal/model/user"
  9. "perms-system-server/internal/svc"
  10. "github.com/zeromicro/go-zero/core/limit"
  11. "golang.org/x/crypto/bcrypt"
  12. )
  13. type LoginResult struct {
  14. UserDetails *loaders.UserDetails
  15. AccessToken string
  16. RefreshToken string
  17. }
  18. type LoginError struct {
  19. Code int
  20. Message string
  21. }
  22. func (e *LoginError) Error() string {
  23. return e.Message
  24. }
  25. func ValidateProductLogin(ctx context.Context, svcCtx *svc.ServiceContext, username, password, productCode string) (*LoginResult, error) {
  26. if svcCtx.UsernameLoginLimit != nil {
  27. code, _ := svcCtx.UsernameLoginLimit.Take(username)
  28. if code == limit.OverQuota {
  29. return nil, &LoginError{Code: 429, Message: "该账号登录尝试过于频繁,请5分钟后再试"}
  30. }
  31. }
  32. u, err := svcCtx.SysUserModel.FindOneByUsername(ctx, username)
  33. if err != nil {
  34. if errors.Is(err, user.ErrNotFound) {
  35. return nil, &LoginError{Code: 401, Message: "用户名或密码错误"}
  36. }
  37. return nil, err
  38. }
  39. if u.Status != consts.StatusEnabled {
  40. return nil, &LoginError{Code: 403, Message: "账号已被冻结"}
  41. }
  42. if err := bcrypt.CompareHashAndPassword([]byte(u.Password), []byte(password)); err != nil {
  43. return nil, &LoginError{Code: 401, Message: "用户名或密码错误"}
  44. }
  45. if u.IsSuperAdmin == consts.IsSuperAdminYes {
  46. return nil, &LoginError{Code: 403, Message: "超级管理员不允许通过产品端登录,请使用管理后台"}
  47. }
  48. product, err := svcCtx.SysProductModel.FindOneByCode(ctx, productCode)
  49. if err != nil {
  50. return nil, &LoginError{Code: 400, Message: "产品不存在"}
  51. }
  52. if product.Status != consts.StatusEnabled {
  53. return nil, &LoginError{Code: 403, Message: "该产品已被禁用"}
  54. }
  55. member, memberErr := svcCtx.SysProductMemberModel.FindOneByProductCodeUserId(ctx, productCode, u.Id)
  56. if memberErr != nil {
  57. return nil, &LoginError{Code: 403, Message: "您不是该产品的成员"}
  58. }
  59. if member.Status != consts.StatusEnabled {
  60. return nil, &LoginError{Code: 403, Message: "您在该产品下的成员资格已被禁用"}
  61. }
  62. ud := svcCtx.UserDetailsLoader.Load(ctx, u.Id, productCode)
  63. accessToken, err := authHelper.GenerateAccessToken(
  64. svcCtx.Config.Auth.AccessSecret,
  65. svcCtx.Config.Auth.AccessExpire,
  66. ud.UserId, ud.Username, ud.ProductCode, ud.MemberType, ud.TokenVersion,
  67. )
  68. if err != nil {
  69. return nil, err
  70. }
  71. refreshToken, err := authHelper.GenerateRefreshToken(
  72. svcCtx.Config.Auth.RefreshSecret,
  73. svcCtx.Config.Auth.RefreshExpire,
  74. ud.UserId, ud.ProductCode, ud.TokenVersion,
  75. )
  76. if err != nil {
  77. return nil, err
  78. }
  79. return &LoginResult{
  80. UserDetails: ud,
  81. AccessToken: accessToken,
  82. RefreshToken: refreshToken,
  83. }, nil
  84. }