loginService.go 2.5 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192
  1. package pub
  2. import (
  3. "context"
  4. "perms-system-server/internal/consts"
  5. "perms-system-server/internal/loaders"
  6. authHelper "perms-system-server/internal/logic/auth"
  7. "perms-system-server/internal/model/user"
  8. "perms-system-server/internal/svc"
  9. "golang.org/x/crypto/bcrypt"
  10. )
  11. type LoginResult struct {
  12. UserDetails *loaders.UserDetails
  13. AccessToken string
  14. RefreshToken string
  15. }
  16. type LoginError struct {
  17. Code int
  18. Message string
  19. }
  20. func (e *LoginError) Error() string {
  21. return e.Message
  22. }
  23. func ValidateProductLogin(ctx context.Context, svcCtx *svc.ServiceContext, username, password, productCode string) (*LoginResult, error) {
  24. u, err := svcCtx.SysUserModel.FindOneByUsername(ctx, username)
  25. if err != nil {
  26. if err == user.ErrNotFound {
  27. return nil, &LoginError{Code: 401, Message: "用户名或密码错误"}
  28. }
  29. return nil, err
  30. }
  31. if u.Status != consts.StatusEnabled {
  32. return nil, &LoginError{Code: 403, Message: "账号已被冻结"}
  33. }
  34. if err := bcrypt.CompareHashAndPassword([]byte(u.Password), []byte(password)); err != nil {
  35. return nil, &LoginError{Code: 401, Message: "用户名或密码错误"}
  36. }
  37. if u.IsSuperAdmin == consts.IsSuperAdminYes {
  38. return nil, &LoginError{Code: 403, Message: "超级管理员不允许通过产品端登录,请使用管理后台"}
  39. }
  40. product, err := svcCtx.SysProductModel.FindOneByCode(ctx, productCode)
  41. if err != nil {
  42. return nil, &LoginError{Code: 400, Message: "产品不存在"}
  43. }
  44. if product.Status != consts.StatusEnabled {
  45. return nil, &LoginError{Code: 403, Message: "该产品已被禁用"}
  46. }
  47. member, memberErr := svcCtx.SysProductMemberModel.FindOneByProductCodeUserId(ctx, productCode, u.Id)
  48. if memberErr != nil {
  49. return nil, &LoginError{Code: 403, Message: "您不是该产品的成员"}
  50. }
  51. if member.Status != consts.StatusEnabled {
  52. return nil, &LoginError{Code: 403, Message: "您在该产品下的成员资格已被禁用"}
  53. }
  54. ud := svcCtx.UserDetailsLoader.Load(ctx, u.Id, productCode)
  55. accessToken, err := authHelper.GenerateAccessToken(
  56. svcCtx.Config.Auth.AccessSecret,
  57. svcCtx.Config.Auth.AccessExpire,
  58. ud.UserId, ud.Username, ud.ProductCode, ud.MemberType, ud.Perms,
  59. )
  60. if err != nil {
  61. return nil, err
  62. }
  63. refreshToken, err := authHelper.GenerateRefreshToken(
  64. svcCtx.Config.Auth.RefreshSecret,
  65. svcCtx.Config.Auth.RefreshExpire,
  66. ud.UserId, ud.ProductCode,
  67. )
  68. if err != nil {
  69. return nil, err
  70. }
  71. return &LoginResult{
  72. UserDetails: ud,
  73. AccessToken: accessToken,
  74. RefreshToken: refreshToken,
  75. }, nil
  76. }