add 用户登录判断是否为初始密码,增加忘记密码,发送验证码
This commit is contained in:
+16
-1
@@ -28,6 +28,7 @@ import com.jero.modules.system.service.ISysUserService;
|
||||
import com.jero.modules.system.util.RandImageUtil;
|
||||
import org.springframework.beans.BeanUtils;
|
||||
import org.springframework.beans.factory.annotation.Autowired;
|
||||
import org.springframework.beans.factory.annotation.Value;
|
||||
import org.springframework.web.bind.annotation.*;
|
||||
|
||||
import javax.annotation.Resource;
|
||||
@@ -74,6 +75,9 @@ public class LoginController {
|
||||
*/
|
||||
public static final int RETRY_LOGIN_MAX_COUNT = 5;
|
||||
|
||||
@Value("${defaultPassword}")
|
||||
private String defaultPassword;
|
||||
|
||||
@ApiOperation("登录接口")
|
||||
@RequestMapping(value = "/login", method = RequestMethod.POST)
|
||||
public Result<JSONObject> login(@RequestBody SysLoginModel sysLoginModel) {
|
||||
@@ -146,7 +150,11 @@ public class LoginController {
|
||||
}
|
||||
//登录成功,清除错误登录次数
|
||||
redisUtil.del(RETRY_LOGIN_PREFIX + username);
|
||||
|
||||
//如果用初始密码登录,前端就跳转到修改密码界面
|
||||
if(defaultPassword.equals(password)){
|
||||
result.error500("updatePassword");
|
||||
return result;
|
||||
}
|
||||
//用户登录信息
|
||||
userInfo(sysUser, result);
|
||||
//update-begin--Author:wangshuai Date:20200714 for:登录日志没有记录人员
|
||||
@@ -585,4 +593,11 @@ public class LoginController {
|
||||
public String getStandardsRSAPublicKey() {
|
||||
return authenticationUtils.getPublicKey();
|
||||
}
|
||||
|
||||
@ApiOperation(value = "忘记密码", notes = "忘记密码")
|
||||
@PostMapping(value = "/forgetPassword")
|
||||
public Result<?> forgetPassword(@RequestBody SysUser user) {
|
||||
sysUserService.forgetPassword(user);
|
||||
return Result.OK("修改密码成功");
|
||||
}
|
||||
}
|
||||
@@ -2,11 +2,13 @@ package com.jero.modules.system.entity;
|
||||
|
||||
import java.util.Date;
|
||||
|
||||
import com.baomidou.mybatisplus.annotation.TableField;
|
||||
import com.baomidou.mybatisplus.annotation.TableLogic;
|
||||
import com.fasterxml.jackson.annotation.JsonIgnore;
|
||||
import com.fasterxml.jackson.annotation.JsonProperty;
|
||||
import com.jero.common.aspect.annotation.Dict;
|
||||
import com.jero.modules.system.volid.group.CreateGroup;
|
||||
import io.swagger.annotations.ApiModelProperty;
|
||||
import org.jeecgframework.poi.excel.annotation.Excel;
|
||||
import org.springframework.format.annotation.DateTimeFormat;
|
||||
|
||||
@@ -187,4 +189,23 @@ public class SysUser implements Serializable {
|
||||
|
||||
/**设备id uniapp推送用*/
|
||||
private String clientId;
|
||||
|
||||
/**
|
||||
* 验证码
|
||||
*/
|
||||
@ApiModelProperty(value = "验证码")
|
||||
@TableField(exist = false)
|
||||
private String verifyCode;
|
||||
|
||||
@TableField(exist = false)
|
||||
@ApiModelProperty(value = "RSA公钥")
|
||||
private String rsapublickey;
|
||||
|
||||
/**
|
||||
* 确认密码
|
||||
*/
|
||||
@JsonProperty(access = JsonProperty.Access.WRITE_ONLY)
|
||||
@ApiModelProperty(value = "确认密码")
|
||||
@TableField(exist = false)
|
||||
private String verifyPassword;
|
||||
}
|
||||
|
||||
+3
@@ -165,4 +165,7 @@ public interface SysUserMapper extends BaseMapper<SysUser> {
|
||||
List<SysRole> getRoleNameByUserIds(@Param("userIds") List<String> userIds);
|
||||
|
||||
PayContactsManagement getPayContactsManagementByPhone(@Param("username") String username);
|
||||
|
||||
void forgetPassword(@Param("user") SysUser user);
|
||||
|
||||
}
|
||||
|
||||
+5
@@ -204,4 +204,9 @@
|
||||
select *
|
||||
from pay_contacts_management where phone = #{username};
|
||||
</select>
|
||||
|
||||
<update id="forgetPassword">
|
||||
update sys_user set password = #{user.password}
|
||||
where username = #{user.username}
|
||||
</update>
|
||||
</mapper>
|
||||
+2
@@ -240,4 +240,6 @@ public interface ISysUserService extends IService<SysUser> {
|
||||
Map<String, String> getRoleNameByUserIds(List<String> userIds);
|
||||
|
||||
String resetPassword(String username);
|
||||
|
||||
void forgetPassword(SysUser user);
|
||||
}
|
||||
|
||||
+8
@@ -9,6 +9,7 @@ import com.baomidou.mybatisplus.core.conditions.update.UpdateWrapper;
|
||||
import com.baomidou.mybatisplus.core.metadata.IPage;
|
||||
import com.baomidou.mybatisplus.extension.plugins.pagination.Page;
|
||||
import com.google.common.base.Joiner;
|
||||
import com.jero.common.util.HuaWeiSmsUtil;
|
||||
import com.jero.modules.oss.mapper.OSSFileMapper;
|
||||
import com.jero.modules.pay.company.entity.PayContactsManagement;
|
||||
import lombok.extern.slf4j.Slf4j;
|
||||
@@ -96,6 +97,8 @@ public class SysBaseApiImpl implements ISysBaseAPI {
|
||||
private SysPermissionMapper sysPermissionMapper;
|
||||
@Autowired
|
||||
private ISysPermissionDataRuleService sysPermissionDataRuleService;
|
||||
@Resource
|
||||
private HuaWeiSmsUtil huaWeiSmsUtil;
|
||||
@Override
|
||||
@Cacheable(cacheNames=CacheConstant.SYS_USERS_CACHE, key="#username")
|
||||
public LoginUser getUserByName(String username) {
|
||||
@@ -1021,6 +1024,11 @@ public class SysBaseApiImpl implements ISysBaseAPI {
|
||||
emailHandle.SendMsgAndFile(email, title, content,list);
|
||||
}
|
||||
|
||||
@Override
|
||||
public void sendVerificationCode(String phone, String codeType, String codeTime, String templateParas) {
|
||||
huaWeiSmsUtil.sendVerificationCode(phone, codeType, codeTime, templateParas);
|
||||
}
|
||||
|
||||
/**
|
||||
* 根据部门id查询部门所有的父级(不包含自己)
|
||||
* @author 马志朝
|
||||
|
||||
+78
-3
@@ -5,6 +5,8 @@ import com.baomidou.mybatisplus.core.conditions.query.QueryWrapper;
|
||||
import com.baomidou.mybatisplus.core.metadata.IPage;
|
||||
import com.baomidou.mybatisplus.extension.plugins.pagination.Page;
|
||||
import com.baomidou.mybatisplus.extension.service.impl.ServiceImpl;
|
||||
import com.jero.common.exception.JeroBootException;
|
||||
import com.jero.common.util.*;
|
||||
import com.jero.modules.system.vo.SysUserVo;
|
||||
import lombok.extern.slf4j.Slf4j;
|
||||
import com.jero.common.api.vo.Result;
|
||||
@@ -14,9 +16,6 @@ import com.jero.common.system.api.ISysBaseAPI;
|
||||
import com.jero.modules.base.service.BaseCommonService;
|
||||
import com.jero.common.system.vo.LoginUser;
|
||||
import com.jero.common.system.vo.SysUserCacheInfo;
|
||||
import com.jero.common.util.PasswordUtil;
|
||||
import com.jero.common.util.UUIDGenerator;
|
||||
import com.jero.common.util.oConvertUtils;
|
||||
import com.jero.modules.system.entity.*;
|
||||
import com.jero.modules.system.mapper.*;
|
||||
import com.jero.modules.system.model.SysUserSysDepartModel;
|
||||
@@ -27,6 +26,7 @@ import org.springframework.beans.factory.annotation.Value;
|
||||
import org.springframework.cache.annotation.CacheEvict;
|
||||
import org.springframework.stereotype.Service;
|
||||
import org.springframework.transaction.annotation.Transactional;
|
||||
import org.springframework.util.ObjectUtils;
|
||||
|
||||
import javax.annotation.Resource;
|
||||
import java.util.*;
|
||||
@@ -64,6 +64,8 @@ public class SysUserServiceImpl extends ServiceImpl<SysUserMapper, SysUser> impl
|
||||
private SysDepartRoleMapper sysDepartRoleMapper;
|
||||
@Resource
|
||||
private BaseCommonService baseCommonService;
|
||||
@Autowired
|
||||
private RedisUtil redisUtil;
|
||||
@Value("${defaultPassword}")
|
||||
private String defaultPassword;
|
||||
|
||||
@@ -472,4 +474,77 @@ public class SysUserServiceImpl extends ServiceImpl<SysUserMapper, SysUser> impl
|
||||
return "密码重置成功!,默认密码为:"+defaultPassword;
|
||||
}
|
||||
|
||||
@Override
|
||||
public void forgetPassword(SysUser user) {
|
||||
fPRuleCheck(user);
|
||||
//前端传入密码解密
|
||||
String username = user.getUsername();
|
||||
String password = user.getPassword();
|
||||
String verifyPassword = user.getVerifyPassword();
|
||||
String RSAPublicKey = user.getRsapublickey();
|
||||
String RSAPrivateKey = String.valueOf(redisUtil.get(RSAPublicKey));
|
||||
try {
|
||||
password = CommonUtils.decryptBtRsaPriKey(password, RSAPrivateKey);
|
||||
verifyPassword = CommonUtils.decryptBtRsaPriKey(verifyPassword, RSAPrivateKey);
|
||||
user.setPassword(password);
|
||||
user.setVerifyPassword(verifyPassword);
|
||||
} catch (Exception e) {
|
||||
e.printStackTrace();
|
||||
}
|
||||
|
||||
//处理手机获取验证码的逻辑
|
||||
Object obj = redisUtil.get("_verification:_phone:" + user.getPhone());
|
||||
if (obj == null) {
|
||||
throw new JeroBootException("验证码失效,请重新发送");
|
||||
}
|
||||
String code = obj.toString();
|
||||
if (!user.getVerifyCode().equals(code)) {
|
||||
throw new JeroBootException("验证码错误!");
|
||||
}
|
||||
|
||||
if (!password.equals(verifyPassword)) {
|
||||
throw new JeroBootException("新密码和确认密码不一致,请重新输入");
|
||||
}
|
||||
LambdaQueryWrapper<SysUser> wrapper = new LambdaQueryWrapper<>();
|
||||
wrapper.eq(SysUser::getUsername, username);
|
||||
SysUser sysUser = userMapper.selectOne(wrapper);
|
||||
if (ObjectUtils.isEmpty(sysUser)) {
|
||||
throw new JeroBootException("用户不存在");
|
||||
}
|
||||
String passwordEncode = PasswordUtil.encrypt(sysUser.getUsername(), password, sysUser.getSalt());
|
||||
user.setPassword(passwordEncode);
|
||||
userMapper.forgetPassword(user);
|
||||
redisUtil.del("_verification:_phone:" + user.getPhone());
|
||||
List<String> roles = sysBaseAPI.getRolesByUsername(sysUser.getUsername());
|
||||
//SysRole sysRole = sysRoleMapper.selectOne(new LambdaQueryWrapper<SysRole>().eq(SysRole::getRoleCode, roles.get(0)));
|
||||
}
|
||||
|
||||
/**
|
||||
* 忘记密码校验
|
||||
* @param user
|
||||
*/
|
||||
private void fPRuleCheck(SysUser user){
|
||||
if(ObjectUtils.isEmpty(user.getUsername())){
|
||||
throw new JeroBootException("用户名为必填");
|
||||
}else if(user.getUsername().length()>50){
|
||||
throw new JeroBootException("用户名长度不超过50个字符");
|
||||
}
|
||||
if(ObjectUtils.isEmpty(user.getPhone())){
|
||||
throw new JeroBootException("手机号为必填");
|
||||
}else if(!Assert.isTel(user.getPhone())){
|
||||
throw new JeroBootException("请输入正确的手机号");
|
||||
}
|
||||
if(ObjectUtils.isEmpty(user.getVerifyCode())){
|
||||
throw new JeroBootException("验证码为必填");
|
||||
}else if(user.getVerifyCode().length()>50){
|
||||
throw new JeroBootException("验证码长度不超过50个字符");
|
||||
}
|
||||
if(ObjectUtils.isEmpty(user.getPassword())){
|
||||
throw new JeroBootException("新密码为必填");
|
||||
}
|
||||
if(ObjectUtils.isEmpty(user.getVerifyPassword())){
|
||||
throw new JeroBootException("确认密码为必填");
|
||||
}
|
||||
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user