auth_middleware.go 4.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195
  1. package middleware
  2. import (
  3. "eta/eta_mini_ht_api/common/component/cache"
  4. logger "eta/eta_mini_ht_api/common/component/log"
  5. "eta/eta_mini_ht_api/common/exception"
  6. "eta/eta_mini_ht_api/common/utils/jwt"
  7. "eta/eta_mini_ht_api/common/utils/redis"
  8. stringUtils "eta/eta_mini_ht_api/common/utils/string"
  9. "eta/eta_mini_ht_api/controllers"
  10. userService "eta/eta_mini_ht_api/domian/user"
  11. "eta/eta_mini_ht_api/service/user"
  12. "fmt"
  13. "github.com/beego/beego/v2/server/web"
  14. "github.com/beego/beego/v2/server/web/context"
  15. "strings"
  16. )
  17. var (
  18. rdCache *cache.RedisCache
  19. )
  20. const (
  21. ILLEGALUSER = "用户信息异常"
  22. UNAUTHORIZED = "请重新登录"
  23. TOKENEXPIRED = "token过期"
  24. FORBIDDEN = "禁止访问"
  25. NOTFOUND = "未找到"
  26. authorization = "Authorization"
  27. baseUrl = "/htapi"
  28. Bearer = "Bearer"
  29. )
  30. func rd() *cache.RedisCache {
  31. if rdCache == nil {
  32. rdCache = cache.GetInstance()
  33. }
  34. return rdCache
  35. }
  36. var publicRoutes = []string{
  37. "/auth/areaCodes",
  38. "/auth/wxAppid",
  39. "/auth/notice",
  40. "/auth/disclaimer",
  41. "/auth/refreshToken",
  42. "/auth/sendCode",
  43. "/user/bind_gzh",
  44. "/user/wx/notify",
  45. "/webhook/*",
  46. }
  47. var privateRoutes = []string{
  48. "/user/profile",
  49. "/user/followAnalyst",
  50. "/user/followAnalysts",
  51. "/user/followingAnalystList",
  52. "/user/readMessages",
  53. "/user/readMessage",
  54. "/user/feedback",
  55. "/user/checkFollowStatus",
  56. "/user/followingAnalysts",
  57. "/user/message",
  58. "/analyst/analystDetail",
  59. "/analyst/list",
  60. "/media/count",
  61. "/report/count",
  62. }
  63. func AuthMiddleware() web.FilterFunc {
  64. return func(ctx *context.Context) {
  65. path := ctx.Input.URL()
  66. logger.Info("请求路径:%v", path)
  67. if !allowed(path) {
  68. rep := unAuthorized()
  69. auth := ctx.Input.Header(authorization)
  70. if auth == "" {
  71. logger.Error("token信息不存在")
  72. _ = ctx.JSONResp(rep)
  73. return
  74. }
  75. parts := strings.Split(auth, " ")
  76. if len(parts) != 2 || parts[0] != Bearer {
  77. logger.Error("token参数不符合格式" + auth)
  78. _ = ctx.JSONResp(rep)
  79. return
  80. }
  81. info, err := jwt.CheckToken(parts[1])
  82. if err != nil {
  83. logger.Error("token无效:%v", err)
  84. _ = ctx.JSONResp(rep)
  85. return
  86. }
  87. //组装用户信息
  88. var userInfo user.User
  89. userInfo, err = user.GetUserByOpenId(info.OpenId)
  90. if err != nil {
  91. logger.Error("获取用户信息失败:%v", err)
  92. _ = ctx.JSONResp(illegalUser())
  93. return
  94. }
  95. //校验redis中是否合法
  96. redisToken := rd().GetString(redis.GenerateTokenKey(info.OpenId))
  97. if redisToken == "" {
  98. logger.Error("token无效:token已失效,自动退出登录")
  99. //重置用户状态为登出
  100. _ = userService.UserLogout(userInfo.Id)
  101. _ = ctx.JSONResp(tokenExpired())
  102. return
  103. }
  104. if redisToken != parts[1] {
  105. logger.Error("token无效:用户token已刷新")
  106. _ = ctx.JSONResp(tokenExpired())
  107. return
  108. }
  109. if needCheckLoginStatus(path) {
  110. if info.TokenType != jwt.AccessToken || info.Mobile == "-" || info.Mobile == "" {
  111. logger.Error("token信息异常,当前token类型为:%v", jwt.GuestToken)
  112. _ = ctx.JSONResp(illegalUser())
  113. return
  114. }
  115. }
  116. //if userInfo.Mobile == "-" && path != baseUrl+"/auth/login" {
  117. // logger.Error("用户手机号为空:%v", err)
  118. // _ = ctx.JSONResp(illegalUser())
  119. // return
  120. //}
  121. ctx.Input.SetData("user", userInfo)
  122. return
  123. }
  124. return
  125. }
  126. }
  127. func unAuthorized() controllers.BaseResponse {
  128. return controllers.BaseResponse{
  129. Ret: 401,
  130. Msg: UNAUTHORIZED,
  131. ErrMsg: exception.GetMsg(exception.Unauthorized),
  132. }
  133. }
  134. func tokenExpired() controllers.BaseResponse {
  135. return controllers.BaseResponse{
  136. Ret: 408,
  137. Msg: TOKENEXPIRED,
  138. ErrMsg: exception.GetMsg(exception.Unauthorized),
  139. }
  140. }
  141. func illegalUser() controllers.BaseResponse {
  142. return controllers.BaseResponse{
  143. Ret: 401,
  144. Msg: ILLEGALUSER,
  145. ErrMsg: exception.GetMsg(exception.Unauthorized),
  146. }
  147. }
  148. func allowed(path string) bool {
  149. for _, p := range publicRoutes {
  150. if stringUtils.IsBlank(p) {
  151. continue
  152. }
  153. src := baseUrl + p
  154. if strings.HasSuffix(p, "*") {
  155. target := src[:len(src)-1]
  156. fmt.Println("target:" + target)
  157. if strings.HasPrefix(path, target) {
  158. return true
  159. }
  160. } else {
  161. if src == path {
  162. return true
  163. }
  164. }
  165. }
  166. return false
  167. }
  168. func needCheckLoginStatus(path string) bool {
  169. for _, p := range privateRoutes {
  170. if stringUtils.IsBlank(p) {
  171. continue
  172. }
  173. src := baseUrl + p
  174. if strings.HasSuffix(p, "*") {
  175. target := src[:len(src)-1]
  176. if strings.HasPrefix(path, target) {
  177. return true
  178. }
  179. } else {
  180. if src == path {
  181. return true
  182. }
  183. }
  184. }
  185. return false
  186. }