TokenUtil.java 6.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164
  1. /*
  2. * Copyright (c) 2018-2028, Chill Zhuang All rights reserved.
  3. *
  4. * Redistribution and use in source and binary forms, with or without
  5. * modification, are permitted provided that the following conditions are met:
  6. *
  7. * Redistributions of source code must retain the above copyright notice,
  8. * this list of conditions and the following disclaimer.
  9. * Redistributions in binary form must reproduce the above copyright
  10. * notice, this list of conditions and the following disclaimer in the
  11. * documentation and/or other materials provided with the distribution.
  12. * Neither the name of the dreamlu.net developer nor the names of its
  13. * contributors may be used to endorse or promote products derived from
  14. * this software without specific prior written permission.
  15. * Author: Chill 庄骞 (smallchill@163.com)
  16. */
  17. package org.springblade.modules.auth.utils;
  18. import org.springblade.common.constant.TenantConstant;
  19. import org.springblade.core.launch.constant.TokenConstant;
  20. import org.springblade.core.log.exception.ServiceException;
  21. import org.springblade.core.secure.TokenInfo;
  22. import org.springblade.core.secure.utils.SecureUtil;
  23. import org.springblade.core.tenant.BladeTenantProperties;
  24. import org.springblade.core.tool.constant.BladeConstant;
  25. import org.springblade.core.tool.jackson.JsonUtil;
  26. import org.springblade.core.tool.support.Kv;
  27. import org.springblade.core.tool.utils.*;
  28. import org.springblade.modules.system.entity.Tenant;
  29. import org.springblade.modules.system.entity.User;
  30. import org.springblade.modules.system.entity.UserInfo;
  31. import javax.servlet.http.HttpServletResponse;
  32. import java.util.Date;
  33. import java.util.HashMap;
  34. import java.util.Map;
  35. /**
  36. * 认证工具类
  37. *
  38. * @author Chill
  39. */
  40. public class TokenUtil {
  41. public final static String CAPTCHA_HEADER_KEY = "Captcha-Key";
  42. public final static String CAPTCHA_HEADER_CODE = "Captcha-Code";
  43. public final static String CAPTCHA_NOT_CORRECT = "验证码不正确";
  44. public final static String TENANT_HEADER_KEY = "Tenant-Id";
  45. public final static String DEFAULT_TENANT_ID = "000000";
  46. public final static String USER_TYPE_HEADER_KEY = "User-Type";
  47. public final static String DEFAULT_USER_TYPE = "web";
  48. public final static String USER_NOT_FOUND = "用户名或密码错误";
  49. public final static String USER_HAS_NO_ROLE = "未获得用户的角色信息";
  50. public final static String USER_HAS_NO_TENANT = "未获得用户的租户信息";
  51. public final static String USER_HAS_NO_TENANT_PERMISSION = "租户授权已过期,请联系管理员";
  52. public final static String USER_HAS_TOO_MANY_FAILS = "登录错误次数过多,请稍后再试";
  53. public final static String HEADER_KEY = "Authorization";
  54. public final static String HEADER_PREFIX = "Basic ";
  55. public final static String DEFAULT_AVATAR = "https://gw.alipayobjects.com/zos/rmsportal/BiazfanxmamNRoxxVxka.png";
  56. private static BladeTenantProperties tenantProperties;
  57. /**
  58. * 获取租户配置
  59. *
  60. * @return tenantProperties
  61. */
  62. private static BladeTenantProperties getTenantProperties() {
  63. if (tenantProperties == null) {
  64. tenantProperties = SpringUtil.getBean(BladeTenantProperties.class);
  65. }
  66. return tenantProperties;
  67. }
  68. /**
  69. * 创建认证token
  70. *
  71. * @param userInfo 用户信息
  72. * @return token
  73. */
  74. public static Kv createAuthInfo(UserInfo userInfo) {
  75. Kv authInfo = Kv.create();
  76. User user = userInfo.getUser();
  77. //设置jwt参数
  78. Map<String, Object> param = new HashMap<>(16);
  79. param.put(TokenConstant.TOKEN_TYPE, TokenConstant.ACCESS_TOKEN);
  80. param.put(TokenConstant.TENANT_ID, user.getTenantId());
  81. param.put(TokenConstant.USER_ID, Func.toStr(user.getId()));
  82. param.put(TokenConstant.DEPT_ID, user.getDeptId());
  83. param.put(TokenConstant.POST_ID, user.getPostId());
  84. param.put(TokenConstant.ROLE_ID, user.getRoleId());
  85. param.put(TokenConstant.OAUTH_ID, userInfo.getOauthId());
  86. param.put(TokenConstant.ACCOUNT, user.getAccount());
  87. param.put(TokenConstant.USER_NAME, user.getAccount());
  88. param.put(TokenConstant.NICK_NAME, user.getRealName());
  89. param.put(TokenConstant.ROLE_NAME, Func.join(userInfo.getRoles()));
  90. param.put(TokenConstant.DETAIL, userInfo.getDetail());
  91. //拼装accessToken
  92. try {
  93. TokenInfo accessToken = SecureUtil.createJWT(param, "audience", "issuser", TokenConstant.ACCESS_TOKEN);
  94. //返回accessToken
  95. return authInfo.set(TokenConstant.TENANT_ID, user.getTenantId())
  96. .set(TokenConstant.USER_ID, Func.toStr(user.getId()))
  97. .set(TokenConstant.DEPT_ID, user.getDeptId())
  98. .set(TokenConstant.POST_ID, user.getPostId())
  99. .set(TokenConstant.ROLE_ID, user.getRoleId())
  100. .set(TokenConstant.OAUTH_ID, userInfo.getOauthId())
  101. .set(TokenConstant.ACCOUNT, user.getAccount())
  102. .set(TokenConstant.USER_NAME, user.getAccount())
  103. .set(TokenConstant.NICK_NAME, user.getRealName())
  104. .set(TokenConstant.ROLE_NAME, Func.join(userInfo.getRoles()))
  105. .set(TokenConstant.AVATAR, Func.toStr(user.getAvatar(), TokenConstant.DEFAULT_AVATAR))
  106. .set(TokenConstant.ACCESS_TOKEN, accessToken.getToken())
  107. .set(TokenConstant.REFRESH_TOKEN, createRefreshToken(userInfo).getToken())
  108. .set(TokenConstant.TOKEN_TYPE, TokenConstant.BEARER)
  109. .set(TokenConstant.EXPIRES_IN, accessToken.getExpire())
  110. .set(TokenConstant.DETAIL, userInfo.getDetail())
  111. .set(TokenConstant.LICENSE, TokenConstant.LICENSE_NAME);
  112. } catch (Exception ex) {
  113. return authInfo.set("error_code", HttpServletResponse.SC_UNAUTHORIZED).set("error_description", ex.getMessage());
  114. }
  115. }
  116. /**
  117. * 创建refreshToken
  118. *
  119. * @param userInfo 用户信息
  120. * @return refreshToken
  121. */
  122. private static TokenInfo createRefreshToken(UserInfo userInfo) {
  123. User user = userInfo.getUser();
  124. Map<String, Object> param = new HashMap<>(16);
  125. param.put(TokenConstant.TOKEN_TYPE, TokenConstant.REFRESH_TOKEN);
  126. param.put(TokenConstant.USER_ID, Func.toStr(user.getId()));
  127. return SecureUtil.createJWT(param, "audience", "issuser", TokenConstant.REFRESH_TOKEN);
  128. }
  129. /**
  130. * 判断租户权限
  131. *
  132. * @param tenant 租户信息
  133. * @return boolean
  134. */
  135. public static boolean judgeTenant(Tenant tenant) {
  136. if (tenant == null) {
  137. throw new ServiceException(TokenUtil.USER_HAS_NO_TENANT);
  138. }
  139. if (StringUtil.equalsIgnoreCase(tenant.getTenantId(), BladeConstant.ADMIN_TENANT_ID)) {
  140. return false;
  141. }
  142. Date expireTime = tenant.getExpireTime();
  143. if (getTenantProperties().getLicense()) {
  144. String licenseKey = tenant.getLicenseKey();
  145. String decrypt = DesUtil.decryptFormHex(licenseKey, TenantConstant.DES_KEY);
  146. expireTime = JsonUtil.parse(decrypt, Tenant.class).getExpireTime();
  147. }
  148. if (expireTime != null && expireTime.before(DateUtil.now())) {
  149. throw new ServiceException(TokenUtil.USER_HAS_NO_TENANT_PERMISSION);
  150. }
  151. return false;
  152. }
  153. }