From 7e48d847402d2ea4da85af582529de676f30dc38 Mon Sep 17 00:00:00 2001
From: 648540858 <648540858@qq.com>
Date: 星期一, 08 五月 2023 17:56:56 +0800
Subject: [PATCH] Merge pull request #844 from xiaoQQya/wvp-28181-2.0

---
 src/main/java/com/genersoft/iot/vmp/vmanager/user/UserController.java |  211 +++++++++++++++++++++++++++++++++++++++++++++++-----
 1 files changed, 189 insertions(+), 22 deletions(-)

diff --git a/src/main/java/com/genersoft/iot/vmp/vmanager/user/UserController.java b/src/main/java/com/genersoft/iot/vmp/vmanager/user/UserController.java
index cf781c0..5ffb02c 100644
--- a/src/main/java/com/genersoft/iot/vmp/vmanager/user/UserController.java
+++ b/src/main/java/com/genersoft/iot/vmp/vmanager/user/UserController.java
@@ -1,41 +1,208 @@
 package com.genersoft.iot.vmp.vmanager.user;
 
+import com.genersoft.iot.vmp.conf.exception.ControllerException;
+import com.genersoft.iot.vmp.conf.security.JwtUtils;
+import com.genersoft.iot.vmp.conf.security.SecurityUtils;
+import com.genersoft.iot.vmp.conf.security.dto.LoginUser;
+import com.genersoft.iot.vmp.service.IRoleService;
 import com.genersoft.iot.vmp.service.IUserService;
+import com.genersoft.iot.vmp.storager.dao.dto.Role;
 import com.genersoft.iot.vmp.storager.dao.dto.User;
-import io.swagger.annotations.Api;
-import io.swagger.annotations.ApiImplicitParam;
-import io.swagger.annotations.ApiImplicitParams;
-import io.swagger.annotations.ApiOperation;
+import com.genersoft.iot.vmp.utils.DateUtil;
+import com.genersoft.iot.vmp.vmanager.bean.ErrorCode;
+import com.genersoft.iot.vmp.vmanager.bean.WVPResult;
+import com.github.pagehelper.PageInfo;
+import io.swagger.v3.oas.annotations.Operation;
+import io.swagger.v3.oas.annotations.Parameter;
+import io.swagger.v3.oas.annotations.tags.Tag;
 import org.springframework.beans.factory.annotation.Autowired;
-import org.springframework.beans.factory.annotation.Value;
-import org.springframework.util.StringUtils;
-import org.springframework.web.bind.annotation.CrossOrigin;
-import org.springframework.web.bind.annotation.GetMapping;
-import org.springframework.web.bind.annotation.RequestMapping;
-import org.springframework.web.bind.annotation.RestController;
+import org.springframework.security.authentication.AuthenticationManager;
+import org.springframework.util.DigestUtils;
+import org.springframework.util.ObjectUtils;
+import org.springframework.web.bind.annotation.*;
 
-@Api(tags = "鐢ㄦ埛绠$悊")
-@CrossOrigin
+import javax.security.sasl.AuthenticationException;
+import javax.servlet.http.HttpServletRequest;
+import javax.servlet.http.HttpServletResponse;
+import java.util.List;
+
+@Tag(name  = "鐢ㄦ埛绠$悊")
 @RestController
 @RequestMapping("/api/user")
 public class UserController {
 
     @Autowired
+    private AuthenticationManager authenticationManager;
+
+    @Autowired
     private IUserService userService;
 
+    @Autowired
+    private IRoleService roleService;
 
-    @ApiOperation("鐧诲綍")
-    @ApiImplicitParams({
-            @ApiImplicitParam(name = "username", value = "鐢ㄦ埛鍚�", dataTypeClass = String.class),
-            @ApiImplicitParam(name = "password", value = "瀵嗙爜锛�32鏈猰d5鍔犲瘑锛�", dataTypeClass = String.class),
-    })
     @GetMapping("/login")
-    public String login(String username, String password){
-        User user = userService.getUser(username, password);
-        if (user != null) {
-            return "success";
+    @PostMapping("/login")
+    @Operation(summary = "鐧诲綍", description = "鐧诲綍鎴愬姛鍚庤繑鍥濧ccessToken锛� 鍙互浠庤繑鍥炲�艰幏鍙栧埌涔熷彲浠ヤ粠鍝嶅簲澶翠腑鑾峰彇鍒帮紝" +
+            "鍚庣画鐨勮姹傞渶瑕佹坊鍔犺姹傚ご 'access-token'鎴栬�呮斁鍦ㄥ弬鏁伴噷")
+
+    @Parameter(name = "username", description = "鐢ㄦ埛鍚�", required = true)
+    @Parameter(name = "password", description = "瀵嗙爜锛�32浣峬d5鍔犲瘑锛�", required = true)
+    public LoginUser login(HttpServletRequest request, HttpServletResponse response, @RequestParam String username, @RequestParam String password){
+        LoginUser user;
+        try {
+            user = SecurityUtils.login(username, password, authenticationManager);
+        } catch (AuthenticationException e) {
+            throw new ControllerException(ErrorCode.ERROR100.getCode(), e.getMessage());
+        }
+        if (user == null) {
+            throw new ControllerException(ErrorCode.ERROR100.getCode(), "鐢ㄦ埛鍚嶆垨瀵嗙爜閿欒");
         }else {
-            return "fail";
+            String jwt = JwtUtils.createToken(username, password, user.getRole().getId());
+            response.setHeader(JwtUtils.getHeader(), jwt);
+            user.setAccessToken(jwt);
+        }
+        return user;
+    }
+
+
+    @PostMapping("/changePassword")
+    @Operation(summary = "淇敼瀵嗙爜")
+    @Parameter(name = "username", description = "鐢ㄦ埛鍚�", required = true)
+    @Parameter(name = "oldpassword", description = "鏃у瘑鐮侊紙宸瞞d5鍔犲瘑鐨勫瘑鐮侊級", required = true)
+    @Parameter(name = "password", description = "鏂板瘑鐮侊紙鏈猰d5鍔犲瘑鐨勫瘑鐮侊級", required = true)
+    public void changePassword(@RequestParam String oldPassword, @RequestParam String password){
+        // 鑾峰彇褰撳墠鐧诲綍鐢ㄦ埛id
+        LoginUser userInfo = SecurityUtils.getUserInfo();
+        if (userInfo== null) {
+            throw new ControllerException(ErrorCode.ERROR100);
+        }
+        String username = userInfo.getUsername();
+        LoginUser user = null;
+        try {
+            user = SecurityUtils.login(username, oldPassword, authenticationManager);
+            if (user == null) {
+                throw new ControllerException(ErrorCode.ERROR100);
+            }
+            //int userId = SecurityUtils.getUserId();
+            boolean result = userService.changePassword(user.getId(), DigestUtils.md5DigestAsHex(password.getBytes()));
+            if (!result) {
+                throw new ControllerException(ErrorCode.ERROR100);
+            }
+        } catch (AuthenticationException e) {
+            throw new ControllerException(ErrorCode.ERROR100.getCode(), e.getMessage());
+        }
+    }
+
+
+    @PostMapping("/add")
+    @Operation(summary = "娣诲姞鐢ㄦ埛")
+    @Parameter(name = "username", description = "鐢ㄦ埛鍚�", required = true)
+    @Parameter(name = "password", description = "瀵嗙爜锛堟湭md5鍔犲瘑鐨勫瘑鐮侊級", required = true)
+    @Parameter(name = "roleId", description = "瑙掕壊ID", required = true)
+    public void add(@RequestParam String username,
+                                                 @RequestParam String password,
+                                                 @RequestParam Integer roleId){
+        if (ObjectUtils.isEmpty(username) || ObjectUtils.isEmpty(password) || roleId == null) {
+            throw new ControllerException(ErrorCode.ERROR400.getCode(), "鍙傛暟涓嶅彲涓虹┖");
+        }
+        // 鑾峰彇褰撳墠鐧诲綍鐢ㄦ埛id
+        int currenRoleId = SecurityUtils.getUserInfo().getRole().getId();
+        if (currenRoleId != 1) {
+            // 鍙敤瑙掕壊id涓�1鎵嶅彲浠ュ垹闄ゅ拰娣诲姞鐢ㄦ埛
+            throw new ControllerException(ErrorCode.ERROR400.getCode(), "鐢ㄦ埛鏃犳潈闄�");
+        }
+        User user = new User();
+        user.setUsername(username);
+        user.setPassword(DigestUtils.md5DigestAsHex(password.getBytes()));
+        //鏂板鐢ㄦ埛鐨刾ushKey鐨勭敓鎴愯鍒欎负md5(鏃堕棿鎴�+鐢ㄦ埛鍚�)
+        user.setPushKey(DigestUtils.md5DigestAsHex((System.currentTimeMillis()+password).getBytes()));
+        Role role = roleService.getRoleById(roleId);
+
+        if (role == null) {
+            throw new ControllerException(ErrorCode.ERROR400.getCode(), "瑙掕壊涓嶅瓨鍦�");
+        }
+        user.setRole(role);
+        user.setCreateTime(DateUtil.getNow());
+        user.setUpdateTime(DateUtil.getNow());
+        int addResult = userService.addUser(user);
+        if (addResult <= 0) {
+            throw new ControllerException(ErrorCode.ERROR100);
+        }
+    }
+
+    @DeleteMapping("/delete")
+    @Operation(summary = "鍒犻櫎鐢ㄦ埛")
+    @Parameter(name = "id", description = "鐢ㄦ埛Id", required = true)
+    public void delete(@RequestParam Integer id){
+        // 鑾峰彇褰撳墠鐧诲綍鐢ㄦ埛id
+        int currenRoleId = SecurityUtils.getUserInfo().getRole().getId();
+        if (currenRoleId != 1) {
+            // 鍙敤瑙掕壊id涓�0鎵嶅彲浠ュ垹闄ゅ拰娣诲姞鐢ㄦ埛
+            throw new ControllerException(ErrorCode.ERROR400.getCode(), "鐢ㄦ埛鏃犳潈闄�");
+        }
+        int deleteResult = userService.deleteUser(id);
+        if (deleteResult <= 0) {
+            throw new ControllerException(ErrorCode.ERROR100);
+        }
+    }
+
+    @GetMapping("/all")
+    @Operation(summary = "鏌ヨ鐢ㄦ埛")
+    public List<User> all(){
+        // 鑾峰彇褰撳墠鐧诲綍鐢ㄦ埛id
+        return userService.getAllUsers();
+    }
+
+    /**
+     * 鍒嗛〉鏌ヨ鐢ㄦ埛
+     *
+     * @param page  褰撳墠椤�
+     * @param count 姣忛〉鏌ヨ鏁伴噺
+     * @return 鍒嗛〉鐢ㄦ埛鍒楄〃
+     */
+    @GetMapping("/users")
+    @Operation(summary = "鍒嗛〉鏌ヨ鐢ㄦ埛")
+    @Parameter(name = "page", description = "褰撳墠椤�", required = true)
+    @Parameter(name = "count", description = "姣忛〉鏌ヨ鏁伴噺", required = true)
+    public PageInfo<User> users(int page, int count) {
+        return userService.getUsers(page, count);
+    }
+
+    @RequestMapping("/changePushKey")
+    @Operation(summary = "淇敼pushkey")
+    @Parameter(name = "userId", description = "鐢ㄦ埛Id", required = true)
+    @Parameter(name = "pushKey", description = "鏂扮殑pushKey", required = true)
+    public void changePushKey(@RequestParam Integer userId,@RequestParam String pushKey) {
+        // 鑾峰彇褰撳墠鐧诲綍鐢ㄦ埛id
+        int currenRoleId = SecurityUtils.getUserInfo().getRole().getId();
+        WVPResult<String> result = new WVPResult<>();
+        if (currenRoleId != 1) {
+            // 鍙敤瑙掕壊id涓�0鎵嶅彲浠ュ垹闄ゅ拰娣诲姞鐢ㄦ埛
+            throw new ControllerException(ErrorCode.ERROR400.getCode(), "鐢ㄦ埛鏃犳潈闄�");
+        }
+        int resetPushKeyResult = userService.changePushKey(userId,pushKey);
+        if (resetPushKeyResult <= 0) {
+            throw new ControllerException(ErrorCode.ERROR100);
+        }
+    }
+
+    @PostMapping("/changePasswordForAdmin")
+    @Operation(summary = "绠$悊鍛樹慨鏀规櫘閫氱敤鎴峰瘑鐮�")
+    @Parameter(name = "adminId", description = "绠$悊鍛榠d", required = true)
+    @Parameter(name = "userId", description = "鐢ㄦ埛id", required = true)
+    @Parameter(name = "password", description = "鏂板瘑鐮侊紙鏈猰d5鍔犲瘑鐨勫瘑鐮侊級", required = true)
+    public void changePasswordForAdmin(@RequestParam int userId, @RequestParam String password) {
+        // 鑾峰彇褰撳墠鐧诲綍鐢ㄦ埛id
+        LoginUser userInfo = SecurityUtils.getUserInfo();
+        if (userInfo == null) {
+            throw new ControllerException(ErrorCode.ERROR100);
+        }
+        Role role = userInfo.getRole();
+        if (role != null && role.getId() == 1) {
+            boolean result = userService.changePassword(userId, DigestUtils.md5DigestAsHex(password.getBytes()));
+            if (!result) {
+                throw new ControllerException(ErrorCode.ERROR100);
+            }
         }
     }
 }

--
Gitblit v1.8.0