From 86df207c37502cce1b2043e1c7c0486459eef1d6 Mon Sep 17 00:00:00 2001 From: mitao <2763622819@qq.com> Date: 星期四, 13 三月 2025 19:58:45 +0800 Subject: [PATCH] 党员、诉求评论基础代码 --- springcloud_k8s_panzhihuazhihuishequ/auth/src/main/java/com/panzhihua/auth/handel/UserAuthenticationProvider.java | 134 +++++++++++++++++++++++++++++++------------- 1 files changed, 93 insertions(+), 41 deletions(-) diff --git a/springcloud_k8s_panzhihuazhihuishequ/auth/src/main/java/com/panzhihua/auth/handel/UserAuthenticationProvider.java b/springcloud_k8s_panzhihuazhihuishequ/auth/src/main/java/com/panzhihua/auth/handel/UserAuthenticationProvider.java index 947e5f2..20a5bd8 100644 --- a/springcloud_k8s_panzhihuazhihuishequ/auth/src/main/java/com/panzhihua/auth/handel/UserAuthenticationProvider.java +++ b/springcloud_k8s_panzhihuazhihuishequ/auth/src/main/java/com/panzhihua/auth/handel/UserAuthenticationProvider.java @@ -13,7 +13,9 @@ import javax.crypto.NoSuchPaddingException; import com.panzhihua.auth.config.MyAESUtil; +import com.panzhihua.common.constants.Constants; import com.panzhihua.common.model.helper.AESUtil; +import com.panzhihua.common.service.community.CommunityService; import com.panzhihua.common.utlis.AES; import org.springframework.beans.factory.annotation.Value; import org.springframework.data.redis.core.RedisTemplate; @@ -34,6 +36,8 @@ import com.panzhihua.common.model.vos.R; import com.panzhihua.common.service.user.UserService; +import static java.util.Objects.nonNull; + /** * @program: springcloud_k8s_panzhihuazhihuishequ * @description: 登录认证 @@ -46,6 +50,8 @@ private UserService userService; @Resource private RedisTemplate redisTemplate; + @Resource + private CommunityService communityService; private static String LOGIN_FAIL="LOGIN_FAIL_"; @@ -54,49 +60,95 @@ // 获取表单输入中返回的用户名 String userName = (String)authentication.getPrincipal(); String password =(String)authentication.getCredentials(); - try { - password = MyAESUtil.Decrypt((String)authentication.getCredentials(),"Ryo7M3n8loC5Abcd"); - } catch (Exception e) { - e.printStackTrace(); + if(!userName.contains("_1")&&!userName.contains("_6")){ + try { + password = MyAESUtil.Decrypt((String)authentication.getCredentials(),"Ryo7M3n8loC5Abcd"); + } catch (Exception e) { + e.printStackTrace(); + } + boolean flag= redisTemplate.hasKey(LOGIN_FAIL+userName); + if(flag){ + Integer time= (Integer) redisTemplate.opsForValue().get(LOGIN_FAIL+userName); + if(time>=5){ + redisTemplate.opsForValue().set(LOGIN_FAIL+userName,5); + throw new LockedException("账号或密码错误,登录错误超过限制"); + } + } + // 查询用户是否存在 + R<LoginUserInfoVO> r = userService.getUserInfo(userName); + if (r.getCode() != 200) { + lockLogin(flag,userName); + throw new UsernameNotFoundException("账号或密码错误"); + } + LoginUserInfoVO loginUserInfoVO = r.getData(); + List<GrantedAuthority> grantedAuthorityList = new ArrayList<>(); + Set<String> roles = loginUserInfoVO.getRoles(); + if (!ObjectUtils.isEmpty(roles)) { + roles.forEach(s -> { + grantedAuthorityList.add(new SimpleGrantedAuthority(s)); + }); + } + if (ObjectUtils.isEmpty(loginUserInfoVO.getAccount())||ObjectUtils.isEmpty(password)) { + lockLogin(flag,userName); + throw new UsernameNotFoundException("账号或密码错误"); + } + // 我们还要判断密码是否正确,这里我们的密码使用BCryptPasswordEncoder进行加密的 + if (!new BCryptPasswordEncoder().matches(password, loginUserInfoVO.getPassword())) { + lockLogin(flag,userName); + throw new BadCredentialsException("账号或密码错误"); + } + // 还可以加一些其他信息的判断,比如用户账号已停用等判断 + if (loginUserInfoVO.getStatus().intValue() == 2) { + throw new LockedException("该用户已被禁用"); + } + // 维护最后登录时间 + userService.putUserLastLoginTime(loginUserInfoVO.getUserId()); + //是否为专家登陆 + if (nonNull(loginUserInfoVO.getPhone())){ + R r1 = communityService.isExpert(loginUserInfoVO.getPhone()); + if (r1.getCode()== Constants.SUCCESS){ + loginUserInfoVO.setType(13); + } + } + return new UsernamePasswordAuthenticationToken(loginUserInfoVO, password, grantedAuthorityList); } - boolean flag= redisTemplate.hasKey(LOGIN_FAIL+userName); - if(flag){ - Integer time= (Integer) redisTemplate.opsForValue().get(LOGIN_FAIL+userName); - if(time>=5){ - redisTemplate.opsForValue().set(LOGIN_FAIL+userName,5, Duration.ofMinutes(5)); - throw new LockedException("登录错误超过限制,请五分钟后重试"); - } + else { + // 查询用户是否存在 + R<LoginUserInfoVO> r = userService.getUserInfo(userName); + if (r.getCode() != 200) { + throw new UsernameNotFoundException("账号或密码错误"); + } + LoginUserInfoVO loginUserInfoVO = r.getData(); + List<GrantedAuthority> grantedAuthorityList = new ArrayList<>(); + Set<String> roles = loginUserInfoVO.getRoles(); + if (!ObjectUtils.isEmpty(roles)) { + roles.forEach(s -> { + grantedAuthorityList.add(new SimpleGrantedAuthority(s)); + }); + } + if (ObjectUtils.isEmpty(loginUserInfoVO.getAccount())) { + throw new UsernameNotFoundException("账号或密码错误"); + } + // 我们还要判断密码是否正确,这里我们的密码使用BCryptPasswordEncoder进行加密的 + if (!new BCryptPasswordEncoder().matches(password, loginUserInfoVO.getPassword())) { + throw new BadCredentialsException("账号或密码错误"); + } + // 还可以加一些其他信息的判断,比如用户账号已停用等判断 + if (loginUserInfoVO.getStatus().intValue() == 2) { + throw new LockedException("该用户已被禁用"); + } + // 维护最后登录时间 + userService.putUserLastLoginTime(loginUserInfoVO.getUserId()); + //是否为专家登陆 + if (nonNull(loginUserInfoVO.getPhone())){ + R r1 = communityService.isExpert(loginUserInfoVO.getPhone()); + if (r1.getCode() == Constants.SUCCESS){ + loginUserInfoVO.setType(13); + } + } + return new UsernamePasswordAuthenticationToken(loginUserInfoVO, password, grantedAuthorityList); + } - // 查询用户是否存在 - R<LoginUserInfoVO> r = userService.getUserInfo(userName); - if (r.getCode() != 200) { - lockLogin(flag,userName); - throw new UsernameNotFoundException("账号或密码错误"); - } - LoginUserInfoVO loginUserInfoVO = r.getData(); - List<GrantedAuthority> grantedAuthorityList = new ArrayList<>(); - Set<String> roles = loginUserInfoVO.getRoles(); - if (!ObjectUtils.isEmpty(roles)) { - roles.forEach(s -> { - grantedAuthorityList.add(new SimpleGrantedAuthority(s)); - }); - } - if (ObjectUtils.isEmpty(loginUserInfoVO.getAccount())||ObjectUtils.isEmpty(password)) { - lockLogin(flag,userName); - throw new UsernameNotFoundException("账号或密码错误"); - } - // 我们还要判断密码是否正确,这里我们的密码使用BCryptPasswordEncoder进行加密的 - if (!new BCryptPasswordEncoder().matches(password, loginUserInfoVO.getPassword())) { - lockLogin(flag,userName); - throw new BadCredentialsException("密码不正确"); - } - // 还可以加一些其他信息的判断,比如用户账号已停用等判断 - if (loginUserInfoVO.getStatus().intValue() == 2) { - throw new LockedException("该用户已被禁用"); - } - // 维护最后登录时间 - userService.putUserLastLoginTime(loginUserInfoVO.getUserId()); - return new UsernamePasswordAuthenticationToken(loginUserInfoVO, password, grantedAuthorityList); } @Override -- Gitblit v1.7.1