|
|
|
@ -2,6 +2,8 @@ package com.manage.controller;
|
|
|
|
|
|
|
|
|
|
import com.alibaba.fastjson.JSON;
|
|
|
|
|
import com.alibaba.fastjson.JSONObject;
|
|
|
|
|
import com.google.code.kaptcha.Constants;
|
|
|
|
|
import com.google.code.kaptcha.Producer;
|
|
|
|
|
import com.manage.bean.LoginVoRedis;
|
|
|
|
|
import com.manage.dao.Power_Login_SetMapper;
|
|
|
|
|
import com.manage.encrypt.Base64;
|
|
|
|
@ -21,13 +23,20 @@ import org.springframework.stereotype.Controller;
|
|
|
|
|
import org.springframework.ui.Model;
|
|
|
|
|
import org.springframework.web.bind.annotation.RequestMapping;
|
|
|
|
|
import org.springframework.web.bind.annotation.RequestMethod;
|
|
|
|
|
import org.springframework.web.bind.annotation.RequestParam;
|
|
|
|
|
import org.springframework.web.bind.annotation.ResponseBody;
|
|
|
|
|
|
|
|
|
|
import org.springframework.web.servlet.ModelAndView;
|
|
|
|
|
import redis.clients.jedis.Jedis;
|
|
|
|
|
import sun.security.provider.MD5;
|
|
|
|
|
|
|
|
|
|
import javax.imageio.ImageIO;
|
|
|
|
|
import javax.servlet.ServletOutputStream;
|
|
|
|
|
import javax.servlet.http.HttpServletRequest;
|
|
|
|
|
import javax.servlet.http.HttpServletResponse;
|
|
|
|
|
import javax.servlet.http.HttpSession;
|
|
|
|
|
import java.awt.image.BufferedImage;
|
|
|
|
|
import java.io.IOException;
|
|
|
|
|
import java.text.DateFormat;
|
|
|
|
|
import java.text.ParseException;
|
|
|
|
|
import java.text.SimpleDateFormat;
|
|
|
|
@ -35,6 +44,9 @@ import java.util.*;
|
|
|
|
|
|
|
|
|
|
@Controller
|
|
|
|
|
public class LoginController {
|
|
|
|
|
@Autowired
|
|
|
|
|
private Producer captchaProducer;
|
|
|
|
|
|
|
|
|
|
@Value("${TOKEN_EXPIRE_TIME}")
|
|
|
|
|
private long TOKEN_EXPIRE_TIME;
|
|
|
|
|
@Value("${sysFlag}")
|
|
|
|
@ -62,9 +74,7 @@ public class LoginController {
|
|
|
|
|
|
|
|
|
|
@Value("${EMRMEDICALRECORD_PORT}")
|
|
|
|
|
private String port;
|
|
|
|
|
//
|
|
|
|
|
// @Autowired
|
|
|
|
|
// private JedisPool jedisPool;
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
@Value("${POWER_PORT}")
|
|
|
|
|
private String POWER_PORT;
|
|
|
|
@ -79,128 +89,126 @@ public class LoginController {
|
|
|
|
|
|
|
|
|
|
@RequestMapping(value = "login", method = RequestMethod.POST)
|
|
|
|
|
@ResponseBody
|
|
|
|
|
public Msg login(Power_User powerUser, HttpServletResponse response, HttpServletRequest request, Model model) {
|
|
|
|
|
public Msg login(Power_User powerUser, HttpServletResponse response, HttpServletRequest request, Model model,String code) {
|
|
|
|
|
//判断是否在可登录时间内
|
|
|
|
|
Power_Log unlockDate = logService.getUnlockDate(powerUser.getUserName());
|
|
|
|
|
//不等于空说明账号次数过多被锁定
|
|
|
|
|
if (unlockDate != null) {
|
|
|
|
|
return Msg.failUnlockUser(unlockDate.getUnlockDate());
|
|
|
|
|
}
|
|
|
|
|
//正确的验证码
|
|
|
|
|
String original =(String) request.getSession().getAttribute(Constants.KAPTCHA_SESSION_KEY);
|
|
|
|
|
String userName = powerUser.getUserName();
|
|
|
|
|
String userPwd = powerUser.getUserPwd();
|
|
|
|
|
if (!code.equalsIgnoreCase(original)) {
|
|
|
|
|
return Msg.codeUser();
|
|
|
|
|
}
|
|
|
|
|
if (!userName.equals("admin")) {
|
|
|
|
|
String s = "00" + userName;
|
|
|
|
|
powerUser.setUserName(s);
|
|
|
|
|
}
|
|
|
|
|
Jedis redis = JedisPoolUtil.getJedisPoolInstance().getResource();
|
|
|
|
|
String userInfo = redis.get(userName);
|
|
|
|
|
String errorPwsCount = "0";
|
|
|
|
|
if (userInfo == null) {
|
|
|
|
|
redis.set(userName, errorPwsCount);
|
|
|
|
|
}
|
|
|
|
|
int i = Integer.parseInt(redis.get(userName));
|
|
|
|
|
if (i < 5) {
|
|
|
|
|
try {
|
|
|
|
|
Power_UserVo user = powerUserService.findPowerUserByUserNameAndUserPwd(powerUser);
|
|
|
|
|
//添加进操作日志
|
|
|
|
|
Power_Log log = new Power_Log();
|
|
|
|
|
if (user != null) {
|
|
|
|
|
//存session密码置空
|
|
|
|
|
//是否记住密码功能
|
|
|
|
|
MyCookieUtil.remember(request, response);
|
|
|
|
|
//设置token缓存
|
|
|
|
|
String token = UUID.randomUUID().toString();
|
|
|
|
|
CacheManager.addExcCount("noExc");
|
|
|
|
|
List<Power_Menu> list = null;
|
|
|
|
|
List<User_Dept_Menu> menuList = new ArrayList<>();
|
|
|
|
|
Set<String> menus = new LinkedHashSet<>();
|
|
|
|
|
if (user.getRoleId().equals(0) || user.getRoleId().equals(-100)) {
|
|
|
|
|
list = powerMenuService.queryAllPowerMenu(null, user.getRoleId());
|
|
|
|
|
} else {
|
|
|
|
|
list = powerMenuService.selectUserAndRoleMenuListPower(user.getUserId(), null);
|
|
|
|
|
}
|
|
|
|
|
if (null != list && !list.isEmpty()) {
|
|
|
|
|
for (Power_Menu powerMenu : list) {
|
|
|
|
|
User_Dept_Menu deptMenu = new User_Dept_Menu();
|
|
|
|
|
String menuUrl = powerMenu.getMenuUrl();
|
|
|
|
|
if (StringUtils.isNotBlank(menuUrl)) {
|
|
|
|
|
BeanUtils.copyProperties(powerMenu, deptMenu);
|
|
|
|
|
deptMenu.setMethodParent(powerMenu.getParentId());
|
|
|
|
|
menuList.add(deptMenu);
|
|
|
|
|
}
|
|
|
|
|
if (StringUtils.isNotBlank(powerMenu.getMethod())) {
|
|
|
|
|
menus.add(powerMenu.getMenuUrl());
|
|
|
|
|
}
|
|
|
|
|
try {
|
|
|
|
|
Power_UserVo user = powerUserService.findPowerUserByUserNameAndUserPwd(powerUser);
|
|
|
|
|
//添加进操作日志
|
|
|
|
|
Power_Log log = new Power_Log();
|
|
|
|
|
if (user != null) {
|
|
|
|
|
//存session密码置空
|
|
|
|
|
//是否记住密码功能
|
|
|
|
|
MyCookieUtil.remember(request, response);
|
|
|
|
|
//设置token缓存
|
|
|
|
|
String token = UUID.randomUUID().toString();
|
|
|
|
|
CacheManager.addExcCount("noExc");
|
|
|
|
|
List<Power_Menu> list = null;
|
|
|
|
|
List<User_Dept_Menu> menuList = new ArrayList<>();
|
|
|
|
|
Set<String> menus = new LinkedHashSet<>();
|
|
|
|
|
if (user.getRoleId().equals(0) || user.getRoleId().equals(-100)) {
|
|
|
|
|
list = powerMenuService.queryAllPowerMenu(null, user.getRoleId());
|
|
|
|
|
} else {
|
|
|
|
|
list = powerMenuService.selectUserAndRoleMenuListPower(user.getUserId(), null);
|
|
|
|
|
}
|
|
|
|
|
if (null != list && !list.isEmpty()) {
|
|
|
|
|
for (Power_Menu powerMenu : list) {
|
|
|
|
|
User_Dept_Menu deptMenu = new User_Dept_Menu();
|
|
|
|
|
String menuUrl = powerMenu.getMenuUrl();
|
|
|
|
|
if (StringUtils.isNotBlank(menuUrl)) {
|
|
|
|
|
BeanUtils.copyProperties(powerMenu, deptMenu);
|
|
|
|
|
deptMenu.setMethodParent(powerMenu.getParentId());
|
|
|
|
|
menuList.add(deptMenu);
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
user.setMenuList(menuList);
|
|
|
|
|
user.setMenus(menus);
|
|
|
|
|
//设置科室
|
|
|
|
|
StringBuilder powerDepts = new StringBuilder();
|
|
|
|
|
List<Power_Dept> powerDeptsList = power_deptService.selectByPrimaryKeys(user.getDeptId());
|
|
|
|
|
for (int j = 0; j < powerDeptsList.size(); j++) {
|
|
|
|
|
if (j < powerDeptsList.size() - 1) {
|
|
|
|
|
powerDepts.append(powerDeptsList.get(j).getDeptName()).append(",");
|
|
|
|
|
} else {
|
|
|
|
|
powerDepts.append(powerDeptsList.get(j).getDeptName());
|
|
|
|
|
if (StringUtils.isNotBlank(powerMenu.getMethod())) {
|
|
|
|
|
menus.add(powerMenu.getMenuUrl());
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
Integer roleId = user.getRoleId();
|
|
|
|
|
if (null != roleId && roleId != 0 && roleId != -100) {
|
|
|
|
|
user.setRemark(powerDepts.toString());
|
|
|
|
|
}
|
|
|
|
|
//清除用户登录错误次数缓存
|
|
|
|
|
CacheManager.clearOnly(powerUser.getUserName());
|
|
|
|
|
//设置进缓存
|
|
|
|
|
CacheManager.putCache(token, new Cache(user, System.currentTimeMillis(), TOKEN_EXPIRE_TIME * 1000));
|
|
|
|
|
ActionScopeUtils.setSessionAttribute("token", token, Integer.valueOf(String.valueOf(TOKEN_EXPIRE_TIME)));
|
|
|
|
|
ActionScopeUtils.setSessionAttribute("CURRENT_USER", user, Integer.valueOf(String.valueOf(TOKEN_EXPIRE_TIME)));
|
|
|
|
|
//检测弱密码强制跳转修改密码
|
|
|
|
|
//大小写,中文,数据,特殊符号必须存在三种
|
|
|
|
|
String reg = "^(?![A-Za-z]+$)(?![A-Z\\d]+$)(?![A-Z\\W]+$)(?![a-z\\d]+$)(?![a-z\\W]+$)(?![\\d\\W]+$)\\S{8,20}$";
|
|
|
|
|
//判断是否为弱密码
|
|
|
|
|
boolean msg=userPwd.matches(reg);
|
|
|
|
|
redis.del(userName);
|
|
|
|
|
JedisPoolUtil.close(redis);
|
|
|
|
|
if (msg==false){
|
|
|
|
|
String url = "http://" + SERVER_IP + ":" + SERVER_PORT +"/power"+ "/font/updatePassword";
|
|
|
|
|
return Msg.success().add("url", url);
|
|
|
|
|
}
|
|
|
|
|
//单点登录跳转
|
|
|
|
|
String url = "";
|
|
|
|
|
if (sysFlag == 2) {
|
|
|
|
|
url = EMRMEDICALRECORD_URLHEAD + "/login?token=" + token + "&userName=" + user.getUserName() + "&flag=1";
|
|
|
|
|
}
|
|
|
|
|
user.setMenuList(menuList);
|
|
|
|
|
user.setMenus(menus);
|
|
|
|
|
//设置科室
|
|
|
|
|
StringBuilder powerDepts = new StringBuilder();
|
|
|
|
|
List<Power_Dept> powerDeptsList = power_deptService.selectByPrimaryKeys(user.getDeptId());
|
|
|
|
|
for (int j = 0; j < powerDeptsList.size(); j++) {
|
|
|
|
|
if (j < powerDeptsList.size() - 1) {
|
|
|
|
|
powerDepts.append(powerDeptsList.get(j).getDeptName()).append(",");
|
|
|
|
|
} else {
|
|
|
|
|
//获取本地端口
|
|
|
|
|
int POWER_PORT = request.getLocalPort();
|
|
|
|
|
url = "http://" + ip + ":" + POWER_PORT + "/power/gatewayPage";
|
|
|
|
|
powerDepts.append(powerDeptsList.get(j).getDeptName());
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
Integer roleId = user.getRoleId();
|
|
|
|
|
if (null != roleId && roleId != 0 && roleId != -100) {
|
|
|
|
|
user.setRemark(powerDepts.toString());
|
|
|
|
|
}
|
|
|
|
|
//清除用户登录错误次数缓存
|
|
|
|
|
CacheManager.clearOnly(powerUser.getUserName());
|
|
|
|
|
//设置进缓存
|
|
|
|
|
CacheManager.putCache(token, new Cache(user, System.currentTimeMillis(), TOKEN_EXPIRE_TIME * 1000));
|
|
|
|
|
ActionScopeUtils.setSessionAttribute("token", token, Integer.valueOf(String.valueOf(TOKEN_EXPIRE_TIME)));
|
|
|
|
|
ActionScopeUtils.setSessionAttribute("CURRENT_USER", user, Integer.valueOf(String.valueOf(TOKEN_EXPIRE_TIME)));
|
|
|
|
|
//检测弱密码强制跳转修改密码
|
|
|
|
|
//大小写,中文,数据,特殊符号必须存在三种
|
|
|
|
|
String reg = "^(?![A-Za-z]+$)(?![A-Z\\d]+$)(?![A-Z\\W]+$)(?![a-z\\d]+$)(?![a-z\\W]+$)(?![\\d\\W]+$)\\S{8,20}$";
|
|
|
|
|
//判断是否为弱密码
|
|
|
|
|
boolean msg = userPwd.matches(reg);
|
|
|
|
|
if (msg == false) {
|
|
|
|
|
String url = "http://" + SERVER_IP + ":" + SERVER_PORT + "/power" + "/font/updatePassword";
|
|
|
|
|
return Msg.success().add("url", url);
|
|
|
|
|
}
|
|
|
|
|
//单点登录跳转
|
|
|
|
|
String url = "";
|
|
|
|
|
if (sysFlag == 2) {
|
|
|
|
|
url = EMRMEDICALRECORD_URLHEAD + "/login?token=" + token + "&userName=" + user.getUserName() + "&flag=1";
|
|
|
|
|
} else {
|
|
|
|
|
//登录失败
|
|
|
|
|
Integer wrongNum = 1;
|
|
|
|
|
Cache cache = CacheManager.getCacheInfo(powerUser.getUserName());
|
|
|
|
|
if (cache != null) {
|
|
|
|
|
//缓存中错误次数
|
|
|
|
|
Integer currentNum = (Integer) cache.getValue();
|
|
|
|
|
//叠加1
|
|
|
|
|
wrongNum += currentNum;
|
|
|
|
|
}
|
|
|
|
|
//添加缓存
|
|
|
|
|
CacheManager.putCache(powerUser.getUserName(), new Cache(wrongNum));
|
|
|
|
|
log.setCreater(powerUser.getUserName());
|
|
|
|
|
log.setLogTitle("登录");
|
|
|
|
|
log.setLogContent("用户密码错误");
|
|
|
|
|
log.setRemark("已错误【" + wrongNum + "】次");
|
|
|
|
|
logService.insert(log);
|
|
|
|
|
request.setAttribute("msg", "用户名或密码不正确");
|
|
|
|
|
redis.incr(userName);
|
|
|
|
|
JedisPoolUtil.close(redis);
|
|
|
|
|
return Msg.failUser();
|
|
|
|
|
//获取本地端口
|
|
|
|
|
int POWER_PORT = request.getLocalPort();
|
|
|
|
|
url = "http://" + ip + ":" + POWER_PORT + "/power/gatewayPage";
|
|
|
|
|
}
|
|
|
|
|
return Msg.success().add("url", url);
|
|
|
|
|
} else {
|
|
|
|
|
//登录失败
|
|
|
|
|
Integer wrongNum = 1;
|
|
|
|
|
Cache cache = CacheManager.getCacheInfo(powerUser.getUserName());
|
|
|
|
|
if (cache != null) {
|
|
|
|
|
//缓存中错误次数
|
|
|
|
|
Integer currentNum = (Integer) cache.getValue();
|
|
|
|
|
//叠加1
|
|
|
|
|
wrongNum += currentNum;
|
|
|
|
|
}
|
|
|
|
|
} catch (Exception e) {
|
|
|
|
|
e.printStackTrace();
|
|
|
|
|
CacheManager.addExcCount("exc");
|
|
|
|
|
//添加缓存
|
|
|
|
|
CacheManager.putCache(powerUser.getUserName(), new Cache(wrongNum));
|
|
|
|
|
log.setCreater(powerUser.getUserName());
|
|
|
|
|
log.setLogTitle("登录");
|
|
|
|
|
log.setLogContent("用户密码错误");
|
|
|
|
|
log.setRemark("已错误【" + wrongNum + "】次");
|
|
|
|
|
//如果错误次数=5添加锁定时间
|
|
|
|
|
if (wrongNum == 5) {
|
|
|
|
|
SimpleDateFormat UnlockFmt = new SimpleDateFormat("yyyy-MM-dd HH:mm:ss");
|
|
|
|
|
log.setUnlockDate(UnlockFmt.format(new Date().getTime() + 15 * 60 * 1000));
|
|
|
|
|
}
|
|
|
|
|
logService.insert(log);
|
|
|
|
|
request.setAttribute("msg", "用户名或密码不正确");
|
|
|
|
|
return Msg.failUser();
|
|
|
|
|
}
|
|
|
|
|
} else {
|
|
|
|
|
//失败次数大于五时锁十五分钟
|
|
|
|
|
redis.setex(userName, 900, i + "");
|
|
|
|
|
JedisPoolUtil.close(redis);
|
|
|
|
|
return Msg.failUser2();
|
|
|
|
|
} catch (Exception e) {
|
|
|
|
|
e.printStackTrace();
|
|
|
|
|
CacheManager.addExcCount("exc");
|
|
|
|
|
}
|
|
|
|
|
return null;
|
|
|
|
|
}
|
|
|
|
@ -225,4 +233,45 @@ public class LoginController {
|
|
|
|
|
return null;
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
/**
|
|
|
|
|
* 生成带验证码的图片
|
|
|
|
|
*
|
|
|
|
|
* @param model
|
|
|
|
|
* @param request
|
|
|
|
|
* @param response
|
|
|
|
|
* @param timestamp
|
|
|
|
|
* @return
|
|
|
|
|
* @throws IOException
|
|
|
|
|
*/
|
|
|
|
|
@RequestMapping(value = "/getCaptchaImage", method = RequestMethod.GET)
|
|
|
|
|
public ModelAndView getCaptchaImage(Model model, HttpServletRequest request, HttpServletResponse response,
|
|
|
|
|
@RequestParam(value = "timestamp", required = false) String timestamp) throws IOException {
|
|
|
|
|
if (StringUtils.isEmpty(timestamp)) {
|
|
|
|
|
//System.out.println("没有时间戳\ttimestamp:" + timestamp);
|
|
|
|
|
model.addAttribute("timestamp", System.currentTimeMillis());
|
|
|
|
|
} else {
|
|
|
|
|
//System.out.println("有时间戳\ttimestamp:" + timestamp);
|
|
|
|
|
model.addAttribute("timestamp", timestamp);
|
|
|
|
|
}
|
|
|
|
|
response.setDateHeader("Expires", 0);
|
|
|
|
|
response.setHeader("Cache-Control", "no-store, no-cache, must-revalidate");
|
|
|
|
|
response.addHeader("Cache-Control", "post-check=0, pre-check=0");
|
|
|
|
|
response.setHeader("Pragma", "no-cache");
|
|
|
|
|
response.setContentType("image/jpeg");
|
|
|
|
|
String capText = captchaProducer.createText();
|
|
|
|
|
request.getSession().setAttribute(Constants.KAPTCHA_SESSION_KEY, capText);
|
|
|
|
|
BufferedImage bi = captchaProducer.createImage(capText);
|
|
|
|
|
ServletOutputStream out = response.getOutputStream();
|
|
|
|
|
ImageIO.write(bi, "jpg", out);
|
|
|
|
|
try {
|
|
|
|
|
out.flush();
|
|
|
|
|
} finally {
|
|
|
|
|
out.close();
|
|
|
|
|
}
|
|
|
|
|
return null;
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
}
|
|
|
|
|