auth_middleware.go 5.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241
  1. package middleware
  2. import (
  3. "eta/eta_mini_ht_api/common/component/cache"
  4. logger "eta/eta_mini_ht_api/common/component/log"
  5. "eta/eta_mini_ht_api/common/exception"
  6. "eta/eta_mini_ht_api/common/utils/jwt"
  7. "eta/eta_mini_ht_api/common/utils/redis"
  8. stringUtils "eta/eta_mini_ht_api/common/utils/string"
  9. "eta/eta_mini_ht_api/controllers"
  10. userService "eta/eta_mini_ht_api/domian/user"
  11. "eta/eta_mini_ht_api/service/user"
  12. "fmt"
  13. "github.com/beego/beego/v2/server/web"
  14. "github.com/beego/beego/v2/server/web/context"
  15. "strings"
  16. )
  17. var (
  18. rdCache *cache.RedisCache
  19. )
  20. const (
  21. ILLEGALUSER = "用户信息异常"
  22. UNAUTHORIZED = "请重新登录"
  23. TOKENEXPIRED = "token过期"
  24. LOGINREQURED = "重新登录"
  25. FORBIDDEN = "禁止访问"
  26. NOTFOUND = "未找到"
  27. authorization = "Authorization"
  28. baseUrl = "/htapi"
  29. Bearer = "Bearer"
  30. )
  31. func rd() *cache.RedisCache {
  32. if rdCache == nil {
  33. rdCache = cache.GetInstance()
  34. }
  35. return rdCache
  36. }
  37. var detailRoutes = []string{
  38. "/media/media",
  39. "/report/report",
  40. "/media/list",
  41. "/media/search",
  42. }
  43. var publicRoutes = []string{
  44. "/auth/areaCodes",
  45. "/auth/wxAppid",
  46. "/auth/notice",
  47. "/auth/disclaimer",
  48. "/auth/refreshToken",
  49. "/auth/sendCode",
  50. "/user/bind_gzh",
  51. "/user/wx/notify",
  52. "/webhook/*",
  53. }
  54. var privateRoutes = []string{
  55. "/user/profile",
  56. "/user/followAnalyst",
  57. "/user/followAnalysts",
  58. "/user/followingAnalystList",
  59. "/user/readMessages",
  60. "/user/readMessage",
  61. "/user/feedback",
  62. "/user/checkFollowStatus",
  63. "/user/followingAnalysts",
  64. "/user/message",
  65. "/analyst/analystDetail",
  66. "/analyst/list",
  67. "/media/count",
  68. "/report/count",
  69. }
  70. func AuthMiddleware() web.FilterFunc {
  71. return func(ctx *context.Context) {
  72. path := ctx.Input.URL()
  73. logger.Info("请求路径:%v", path)
  74. if !allowed(path) {
  75. rep := unAuthorized()
  76. auth := ctx.Input.Header(authorization)
  77. if auth == "" {
  78. logger.Error("token信息不存在")
  79. _ = ctx.JSONResp(rep)
  80. return
  81. }
  82. parts := strings.Split(auth, " ")
  83. if len(parts) != 2 || parts[0] != Bearer {
  84. logger.Error("token参数不符合格式" + auth)
  85. _ = ctx.JSONResp(rep)
  86. return
  87. }
  88. info, err := jwt.CheckToken(parts[1])
  89. if err != nil {
  90. logger.Error("token无效:%v", err)
  91. _ = ctx.JSONResp(rep)
  92. return
  93. }
  94. //组装用户信息
  95. var userInfo user.User
  96. userInfo, err = user.GetUserByOpenId(info.OpenId)
  97. if err != nil {
  98. logger.Error("获取用户信息失败:%v", err)
  99. _ = ctx.JSONResp(illegalUser())
  100. return
  101. }
  102. //校验redis中是否合法
  103. redisToken := rd().GetString(redis.GenerateTokenKey(info.OpenId))
  104. if redisToken == "" {
  105. logger.Error("token无效:token已失效,自动退出登录")
  106. //重置用户状态为登出
  107. err = userService.UserLogout(userInfo.Id)
  108. if err != nil {
  109. logger.Error("重置用户状态失败:%v", err)
  110. }
  111. _ = ctx.JSONResp(LoginRequired())
  112. return
  113. }
  114. if redisToken != parts[1] {
  115. logger.Error("token无效:用户token已刷新")
  116. _ = ctx.JSONResp(tokenExpired())
  117. return
  118. }
  119. if needCheckLoginStatus(path) {
  120. if info.TokenType != jwt.AccessToken || info.Mobile == "-" || info.Mobile == "" {
  121. logger.Error("token信息异常,当前token类型为:%v", jwt.GuestToken)
  122. _ = ctx.JSONResp(LoginRequired())
  123. return
  124. }
  125. }
  126. //详情信息需要登录token才能看到全部
  127. if detail(path) {
  128. if info.TokenType != jwt.AccessToken || info.Mobile == "-" || info.Mobile == "" {
  129. ctx.Input.SetData("detailType", "logout")
  130. } else {
  131. ctx.Input.SetData("detailType", "login")
  132. }
  133. }
  134. //if userInfo.Mobile == "-" && path != baseUrl+"/auth/login" {
  135. // logger.Error("用户手机号为空:%v", err)
  136. // _ = ctx.JSONResp(illegalUser())
  137. // return
  138. //}
  139. ctx.Input.SetData("user", userInfo)
  140. return
  141. }
  142. return
  143. }
  144. }
  145. func unAuthorized() controllers.BaseResponse {
  146. return controllers.BaseResponse{
  147. Ret: 401,
  148. Msg: UNAUTHORIZED,
  149. ErrMsg: exception.GetMsg(exception.Unauthorized),
  150. }
  151. }
  152. func tokenExpired() controllers.BaseResponse {
  153. return controllers.BaseResponse{
  154. Ret: 408,
  155. Msg: TOKENEXPIRED,
  156. ErrMsg: exception.GetMsg(exception.Unauthorized),
  157. }
  158. }
  159. func LoginRequired() controllers.BaseResponse {
  160. return controllers.BaseResponse{
  161. Ret: 408,
  162. Msg: LOGINREQURED,
  163. ErrMsg: exception.GetMsg(exception.Unauthorized),
  164. }
  165. }
  166. func illegalUser() controllers.BaseResponse {
  167. return controllers.BaseResponse{
  168. Ret: 401,
  169. Msg: ILLEGALUSER,
  170. ErrMsg: exception.GetMsg(exception.Unauthorized),
  171. }
  172. }
  173. func allowed(path string) bool {
  174. for _, p := range publicRoutes {
  175. if stringUtils.IsBlank(p) {
  176. continue
  177. }
  178. src := baseUrl + p
  179. if strings.HasSuffix(p, "*") {
  180. target := src[:len(src)-1]
  181. fmt.Println("target:" + target)
  182. if strings.HasPrefix(path, target) {
  183. return true
  184. }
  185. } else {
  186. if src == path {
  187. return true
  188. }
  189. }
  190. }
  191. return false
  192. }
  193. func detail(path string) bool {
  194. for _, p := range detailRoutes {
  195. if stringUtils.IsBlank(p) {
  196. continue
  197. }
  198. src := baseUrl + p
  199. if strings.HasSuffix(p, "*") {
  200. target := src[:len(src)-1]
  201. if strings.HasPrefix(path, target) {
  202. return true
  203. }
  204. } else {
  205. if src == path {
  206. return true
  207. }
  208. }
  209. }
  210. return false
  211. }
  212. func needCheckLoginStatus(path string) bool {
  213. for _, p := range privateRoutes {
  214. if stringUtils.IsBlank(p) {
  215. continue
  216. }
  217. src := baseUrl + p
  218. if strings.HasSuffix(p, "*") {
  219. target := src[:len(src)-1]
  220. if strings.HasPrefix(path, target) {
  221. return true
  222. }
  223. } else {
  224. if src == path {
  225. return true
  226. }
  227. }
  228. }
  229. return false
  230. }