auth_middleware.go 4.2 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187
  1. package middleware
  2. import (
  3. "eta/eta_mini_ht_api/common/component/cache"
  4. logger "eta/eta_mini_ht_api/common/component/log"
  5. "eta/eta_mini_ht_api/common/exception"
  6. "eta/eta_mini_ht_api/common/utils/jwt"
  7. "eta/eta_mini_ht_api/common/utils/redis"
  8. stringUtils "eta/eta_mini_ht_api/common/utils/string"
  9. "eta/eta_mini_ht_api/controllers"
  10. "eta/eta_mini_ht_api/service/user"
  11. "fmt"
  12. "github.com/beego/beego/v2/server/web"
  13. "github.com/beego/beego/v2/server/web/context"
  14. "strings"
  15. )
  16. var (
  17. rdCache *cache.RedisCache
  18. )
  19. const (
  20. ILLEGALUSER = "用户信息异常"
  21. UNAUTHORIZED = "请重新登录"
  22. TOKENEXPIRED = "token过期"
  23. FORBIDDEN = "禁止访问"
  24. NOTFOUND = "未找到"
  25. authorization = "Authorization"
  26. baseUrl = "/htapi"
  27. Bearer = "Bearer"
  28. )
  29. func rd() *cache.RedisCache {
  30. if rdCache == nil {
  31. rdCache = cache.GetInstance()
  32. }
  33. return rdCache
  34. }
  35. var publicRoutes = []string{
  36. "/auth/areaCodes",
  37. "/auth/wxAppid",
  38. "/auth/notice",
  39. "/auth/disclaimer",
  40. "/auth/refreshToken",
  41. "/auth/sendCode",
  42. "/user/bind_gzh",
  43. "/user/wx/notify",
  44. "/webhook/*",
  45. }
  46. var privateRoutes = []string{
  47. "/user/profile",
  48. "/user/followAnalyst",
  49. "/user/followAnalysts",
  50. "/user/followingAnalystList",
  51. "/user/readMessages",
  52. "/user/readMessage",
  53. "/user/feedback",
  54. "/user/checkFollowStatus",
  55. "/user/followingAnalysts",
  56. "/user/message",
  57. "/analyst/analystDetail",
  58. "/analyst/list",
  59. "/media/count",
  60. "/report/count",
  61. }
  62. func AuthMiddleware() web.FilterFunc {
  63. return func(ctx *context.Context) {
  64. path := ctx.Input.URL()
  65. logger.Info("请求路径:%v", path)
  66. if !allowed(path) {
  67. rep := unAuthorized()
  68. auth := ctx.Input.Header(authorization)
  69. if auth == "" {
  70. logger.Error("token信息不存在")
  71. _ = ctx.JSONResp(rep)
  72. return
  73. }
  74. parts := strings.Split(auth, " ")
  75. if len(parts) != 2 || parts[0] != Bearer {
  76. logger.Error("token参数不符合格式" + auth)
  77. _ = ctx.JSONResp(rep)
  78. return
  79. }
  80. info, err := jwt.CheckToken(parts[1])
  81. if err != nil {
  82. logger.Error("token无效:%v", err)
  83. _ = ctx.JSONResp(rep)
  84. return
  85. }
  86. //校验redis中是否合法
  87. redisToken := rd().GetString(redis.GenerateTokenKey(info.OpenId))
  88. if redisToken != parts[1] {
  89. logger.Error("token无效:用户token已刷新")
  90. _ = ctx.JSONResp(tokenExpired())
  91. return
  92. }
  93. //组装用户信息
  94. var userInfo user.User
  95. userInfo, err = user.GetUserByOpenId(info.OpenId)
  96. if err != nil {
  97. logger.Error("获取用户信息失败:%v", err)
  98. _ = ctx.JSONResp(illegalUser())
  99. return
  100. }
  101. if needCheckLoginStatus(path) {
  102. if info.TokenType != jwt.AccessToken || info.Mobile == "-" || info.Mobile == "" {
  103. logger.Error("token信息异常,当前token类型为:%v", jwt.GuestToken)
  104. _ = ctx.JSONResp(illegalUser())
  105. return
  106. }
  107. }
  108. //if userInfo.Mobile == "-" && path != baseUrl+"/auth/login" {
  109. // logger.Error("用户手机号为空:%v", err)
  110. // _ = ctx.JSONResp(illegalUser())
  111. // return
  112. //}
  113. ctx.Input.SetData("user", userInfo)
  114. return
  115. }
  116. return
  117. }
  118. }
  119. func unAuthorized() controllers.BaseResponse {
  120. return controllers.BaseResponse{
  121. Ret: 401,
  122. Msg: UNAUTHORIZED,
  123. ErrMsg: exception.GetMsg(exception.Unauthorized),
  124. }
  125. }
  126. func tokenExpired() controllers.BaseResponse {
  127. return controllers.BaseResponse{
  128. Ret: 408,
  129. Msg: TOKENEXPIRED,
  130. ErrMsg: exception.GetMsg(exception.Unauthorized),
  131. }
  132. }
  133. func illegalUser() controllers.BaseResponse {
  134. return controllers.BaseResponse{
  135. Ret: 401,
  136. Msg: ILLEGALUSER,
  137. ErrMsg: exception.GetMsg(exception.Unauthorized),
  138. }
  139. }
  140. func allowed(path string) bool {
  141. for _, p := range publicRoutes {
  142. if stringUtils.IsBlank(p) {
  143. continue
  144. }
  145. src := baseUrl + p
  146. if strings.HasSuffix(p, "*") {
  147. target := src[:len(src)-1]
  148. fmt.Println("target:" + target)
  149. if strings.HasPrefix(path, target) {
  150. return true
  151. }
  152. } else {
  153. if src == path {
  154. return true
  155. }
  156. }
  157. }
  158. return false
  159. }
  160. func needCheckLoginStatus(path string) bool {
  161. for _, p := range privateRoutes {
  162. if stringUtils.IsBlank(p) {
  163. continue
  164. }
  165. src := baseUrl + p
  166. if strings.HasSuffix(p, "*") {
  167. target := src[:len(src)-1]
  168. if strings.HasPrefix(path, target) {
  169. return true
  170. }
  171. } else {
  172. if src == path {
  173. return true
  174. }
  175. }
  176. }
  177. return false
  178. }