add 企业端手机号登录,修改密码
This commit is contained in:
+71
-15
@@ -61,9 +61,9 @@ public class CompanyLoginController {
|
||||
@PostMapping(value = "/login")
|
||||
public Result<JSONObject> login(@RequestBody SysLoginModel sysLoginModel) {
|
||||
Result<JSONObject> result = new Result<>();
|
||||
String username = PasswordUtil.encrypt(sysLoginModel.getUsername());
|
||||
String phone = sysLoginModel.getUsername();
|
||||
String password = sysLoginModel.getPassword();
|
||||
/*String rsaPublicKey = sysLoginModel.getRsaPublicKey();
|
||||
String rsaPublicKey = sysLoginModel.getRsaPublicKey();
|
||||
String rsaPrivateKey = String.valueOf(redisUtil.get(rsaPublicKey));
|
||||
//update-begin--Author:scott Date:20190805 for:暂时注释掉密码加密逻辑,有点问题
|
||||
//前端密码加密,后端进行密码解密
|
||||
@@ -88,14 +88,14 @@ public class CompanyLoginController {
|
||||
try {
|
||||
//解密获取密码和用户名
|
||||
password = CommonUtils.decryptBtRsaPriKey(password, rsaPrivateKey);
|
||||
username = CommonUtils.decryptBtRsaPriKey(username, rsaPrivateKey);
|
||||
phone = CommonUtils.decryptBtRsaPriKey(phone, rsaPrivateKey);
|
||||
} catch (Exception e) {
|
||||
e.printStackTrace();
|
||||
}*/
|
||||
}
|
||||
//1. 校验用户是否有效
|
||||
//update-begin-author:wangshuai date:20200601 for: 登录代码验证用户是否注销bug,if条件永远为false
|
||||
LambdaQueryWrapper<PayContactsManagement> queryWrapper = new LambdaQueryWrapper<>();
|
||||
queryWrapper.eq(PayContactsManagement::getPhone, username);
|
||||
queryWrapper.eq(PayContactsManagement::getPhone, PasswordUtil.encrypt(phone));
|
||||
PayContactsManagement contactsManagement = payContactsManagementService.getOne(queryWrapper);
|
||||
//update-end-author:wangshuai date:20200601 for: 登录代码验证用户是否注销bug,if条件永远为false
|
||||
if (Objects.isNull(contactsManagement)) {
|
||||
@@ -104,37 +104,88 @@ public class CompanyLoginController {
|
||||
|
||||
// 若用户名有效,则查询该账号的登陆失败次数是否符合等保要求
|
||||
int retryCount = 0;
|
||||
if (redisUtil.get(RETRY_LOGIN_PREFIX + username) != null) {
|
||||
retryCount = (int) redisUtil.get(RETRY_LOGIN_PREFIX + username);
|
||||
if (redisUtil.get(RETRY_LOGIN_PREFIX + phone) != null) {
|
||||
retryCount = (int) redisUtil.get(RETRY_LOGIN_PREFIX + phone);
|
||||
}
|
||||
if (retryCount >= RETRY_LOGIN_MAX_COUNT) {
|
||||
result.error500("密码错误次数过多,请稍后重试");
|
||||
return result;
|
||||
}
|
||||
//2. 校验用户名或密码是否正确
|
||||
String userpassword = PasswordUtil.encrypt(username, password, contactsManagement.getSalt());
|
||||
String userpassword = PasswordUtil.encrypt(phone, password, contactsManagement.getSalt());
|
||||
String syspassword = contactsManagement.getPassword();
|
||||
if (!syspassword.equals(userpassword)) {
|
||||
// 重试登录次数加一
|
||||
retryCount++;
|
||||
if (retryCount == 1) {
|
||||
redisUtil.set(RETRY_LOGIN_PREFIX + username, retryCount, 60 * 30);
|
||||
redisUtil.set(RETRY_LOGIN_PREFIX + phone, retryCount, 60 * 30);
|
||||
} else {
|
||||
redisUtil.set(RETRY_LOGIN_PREFIX + username, retryCount, redisUtil.getExpire(RETRY_LOGIN_PREFIX + username));
|
||||
redisUtil.set(RETRY_LOGIN_PREFIX + phone, retryCount, redisUtil.getExpire(RETRY_LOGIN_PREFIX + phone));
|
||||
}
|
||||
String msg = retryCount == RETRY_LOGIN_MAX_COUNT ? "密码错误次数过多,请稍后重试" : "用户名或密码错误,剩余可登录次数:" + (RETRY_LOGIN_MAX_COUNT - retryCount);
|
||||
result.error500(msg);
|
||||
return result;
|
||||
}
|
||||
//登录成功,清除错误登录次数
|
||||
redisUtil.del(RETRY_LOGIN_PREFIX + username);
|
||||
redisUtil.del(RETRY_LOGIN_PREFIX + phone);
|
||||
|
||||
//用户登录信息
|
||||
userInfo(contactsManagement, result);
|
||||
//update-begin--Author:wangshuai Date:20200714 for:登录日志没有记录人员
|
||||
LoginUser loginUser = new LoginUser();
|
||||
BeanUtils.copyProperties(contactsManagement, loginUser);
|
||||
baseCommonService.addLog("用户名: " + username + ",登录成功!", CommonConstant.LOG_TYPE_1, null, loginUser);
|
||||
baseCommonService.addLog("用户名: " + phone + ",登录成功!", CommonConstant.LOG_TYPE_1, null, loginUser);
|
||||
//update-end--Author:wangshuai Date:20200714 for:登录日志没有记录人员
|
||||
return result;
|
||||
}
|
||||
|
||||
@ApiOperation("短信登录接口")
|
||||
@PostMapping(value = "/smsLogin")
|
||||
public Result<JSONObject> smsLogin(@RequestBody SysLoginModel sysLoginModel) {
|
||||
Result<JSONObject> result = new Result<>();
|
||||
String phone = sysLoginModel.getUsername();
|
||||
String rsaPublicKey = sysLoginModel.getRsaPublicKey();
|
||||
String rsaPrivateKey = String.valueOf(redisUtil.get(rsaPublicKey));
|
||||
//update-begin--Author:scott Date:20190805 for:暂时注释掉密码加密逻辑,有点问题
|
||||
//前端密码加密,后端进行密码解密
|
||||
//password = AesEncryptUtil.desEncrypt(sysLoginModel.getPassword().replaceAll("%2B", "\\+")).trim();//密码解密
|
||||
//update-begin--Author:scott Date:20190805 for:暂时注释掉密码加密逻辑,有点问题
|
||||
//update-begin-author:taoyan date:20190828 for:校验验证码
|
||||
try {
|
||||
//解密获取密码和用户名
|
||||
phone = CommonUtils.decryptBtRsaPriKey(phone, rsaPrivateKey);
|
||||
} catch (Exception e) {
|
||||
e.printStackTrace();
|
||||
}
|
||||
String captcha = sysLoginModel.getCaptcha();
|
||||
if (captcha == null) {
|
||||
result.error500("验证码无效");
|
||||
return result;
|
||||
}
|
||||
Object checkCode = redisUtil.get("_verification:_phone:" + phone);
|
||||
if (checkCode == null) {
|
||||
result.error500("验证码错误");
|
||||
return result;
|
||||
} else {
|
||||
redisUtil.del("_verification:_phone:" + phone);
|
||||
}
|
||||
|
||||
//1. 校验用户是否有效
|
||||
//update-begin-author:wangshuai date:20200601 for: 登录代码验证用户是否注销bug,if条件永远为false
|
||||
LambdaQueryWrapper<PayContactsManagement> queryWrapper = new LambdaQueryWrapper<>();
|
||||
queryWrapper.eq(PayContactsManagement::getPhone, phone);
|
||||
PayContactsManagement contactsManagement = payContactsManagementService.getOne(queryWrapper);
|
||||
//update-end-author:wangshuai date:20200601 for: 登录代码验证用户是否注销bug,if条件永远为false
|
||||
if (Objects.isNull(contactsManagement)) {
|
||||
throw new JeroBootException("手机号不存在");
|
||||
}
|
||||
|
||||
//用户登录信息
|
||||
userInfo(contactsManagement, result);
|
||||
//update-begin--Author:wangshuai Date:20200714 for:登录日志没有记录人员
|
||||
LoginUser loginUser = new LoginUser();
|
||||
BeanUtils.copyProperties(contactsManagement, loginUser);
|
||||
baseCommonService.addLog("用户名: " + phone + ",登录成功!", CommonConstant.LOG_TYPE_1, null, loginUser);
|
||||
//update-end--Author:wangshuai Date:20200714 for:登录日志没有记录人员
|
||||
return result;
|
||||
}
|
||||
@@ -207,9 +258,6 @@ public class CompanyLoginController {
|
||||
throw new JeroBootException("手机号不是企业联系人");
|
||||
}
|
||||
sysBaseAPI.sendVerificationCode(phone,"2",null,null);
|
||||
if (StringUtils.isBlank(contactsManagement.getPassword())){
|
||||
return Result.error("updatePassword");
|
||||
}
|
||||
String string = redisUtil.get("_verification:_phone:" + PasswordUtil.decrypt(phone)).toString();
|
||||
return Result.OK(string);
|
||||
}
|
||||
@@ -221,4 +269,12 @@ public class CompanyLoginController {
|
||||
return Result.OK("修改密码成功");
|
||||
}
|
||||
|
||||
@ApiOperation(value = "修改密码")
|
||||
@PostMapping(value = "/changePassword")
|
||||
public Result<?> changePassword(@RequestBody CompanyLoginVO companyLoginVO) {
|
||||
payContactsManagementService.changePassword(companyLoginVO);
|
||||
|
||||
return Result.OK("修改密码成功");
|
||||
}
|
||||
|
||||
}
|
||||
|
||||
+2
@@ -50,4 +50,6 @@ public interface IPayContactsManagementService extends IService<PayContactsManag
|
||||
List<PayContactsManagement> listPayContactsManagement(List<String> phoneList);
|
||||
|
||||
void verificationChangePassword(CompanyLoginVO companyLoginVO);
|
||||
|
||||
void changePassword(CompanyLoginVO companyLoginVO);
|
||||
}
|
||||
|
||||
+25
-4
@@ -5,16 +5,17 @@ import com.baomidou.mybatisplus.core.conditions.query.LambdaQueryWrapper;
|
||||
import com.baomidou.mybatisplus.core.metadata.IPage;
|
||||
import com.baomidou.mybatisplus.extension.plugins.pagination.Page;
|
||||
import com.baomidou.mybatisplus.extension.service.impl.ServiceImpl;
|
||||
import com.jero.common.api.vo.Result;
|
||||
import com.jero.common.exception.JeroBootException;
|
||||
import com.jero.common.util.CommonUtils;
|
||||
import com.jero.common.util.PasswordUtil;
|
||||
import com.jero.common.util.RedisUtil;
|
||||
import com.jero.common.util.ValidUtil;
|
||||
import com.jero.common.system.vo.LoginUser;
|
||||
import com.jero.common.util.*;
|
||||
import com.jero.company.entity.PayContactsManagement;
|
||||
import com.jero.company.mapper.PayContactsManagementMapper;
|
||||
import com.jero.company.service.IPayContactsManagementService;
|
||||
import com.jero.company.vo.CompanyLoginVO;
|
||||
import com.jero.modules.system.entity.SysUser;
|
||||
import org.apache.commons.collections.CollectionUtils;
|
||||
import org.apache.shiro.SecurityUtils;
|
||||
import org.springframework.beans.factory.annotation.Autowired;
|
||||
import org.springframework.stereotype.Service;
|
||||
import org.springframework.transaction.annotation.Transactional;
|
||||
@@ -107,4 +108,24 @@ public class PayContactsManagementServiceImpl extends ServiceImpl<PayContactsMan
|
||||
payContactsManagementMapper.forgetPassword(companyLoginVO);
|
||||
redisUtil.del("_verification:_phone:" + phone);
|
||||
}
|
||||
|
||||
@Override
|
||||
public void changePassword(CompanyLoginVO companyLoginVO) {
|
||||
LoginUser loginUser = (LoginUser) SecurityUtils.getSubject().getPrincipal();
|
||||
String newPassword = companyLoginVO.getNewPassword();
|
||||
String verifyPassword = companyLoginVO.getVerifyPassword();
|
||||
String phone = loginUser.getPhone();
|
||||
LambdaQueryWrapper<PayContactsManagement> queryWrapper = new LambdaQueryWrapper<>();
|
||||
queryWrapper.eq(PayContactsManagement::getPhone, PasswordUtil.encrypt(phone));
|
||||
PayContactsManagement contactsManagement = this.getOne(queryWrapper);
|
||||
|
||||
if (oConvertUtils.isEmpty(newPassword)) {
|
||||
throw new JeroBootException("新密码不允许为空!");
|
||||
}
|
||||
if (!newPassword.equals(verifyPassword)) {
|
||||
throw new JeroBootException("两次输入密码不一致!");
|
||||
}
|
||||
String password = PasswordUtil.encrypt(phone, newPassword, contactsManagement.getSalt());
|
||||
this.update(new PayContactsManagement().setPassword(password), new LambdaQueryWrapper<PayContactsManagement>().eq(PayContactsManagement::getPhone, phone));
|
||||
}
|
||||
}
|
||||
|
||||
@@ -25,15 +25,16 @@ public class CompanyLoginVO {
|
||||
/**
|
||||
* 密码
|
||||
*/
|
||||
@JsonProperty(access = JsonProperty.Access.WRITE_ONLY)
|
||||
@ApiModelProperty(value = "密码")
|
||||
@NotEmpty(message = "密码不能为空!")
|
||||
private String password;
|
||||
|
||||
@ApiModelProperty(value = "新密码")
|
||||
private String newPassword;
|
||||
|
||||
/**
|
||||
* 确认密码
|
||||
*/
|
||||
@JsonProperty(access = JsonProperty.Access.WRITE_ONLY)
|
||||
@ApiModelProperty(value = "确认密码")
|
||||
@NotEmpty(message = "确认密码不能为空!")
|
||||
private String verifyPassword;
|
||||
|
||||
Reference in New Issue
Block a user