You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

106 lines
3.6 KiB

4 weeks ago
<?php
namespace App\Http\Controllers\Api;
use App\Http\Controllers\Controller;
1 week ago
use App\Models\AuditLog;
4 weeks ago
use App\Models\User;
use Illuminate\Http\JsonResponse;
use Illuminate\Http\Request;
use Illuminate\Support\Facades\Hash;
class AuthController extends Controller
{
public function login(Request $request): JsonResponse
{
$data = $request->validate([
'username' => ['required', 'string'],
'password' => ['required', 'string'],
]);
$user = User::with('venues:id,name')->where('username', $data['username'])->first();
1 week ago
if (! $user || ! $user->is_active || ! Hash::check($data['password'], $user->password)) {
$this->recordLoginAudit(
$request,
null,
422,
'登录失败(账号或密码错误)',
['username' => $data['username']]
);
4 weeks ago
return response()->json(['message' => '账号或密码错误'], 422);
}
// 移动端核销登录:签发更长有效期的 tokenSanctum 仍会在 expires_at 到期后失效)
$isH5Verify = $request->input('client') === 'h5_verify';
1 week ago
if ($isH5Verify && ! $user->isSuperAdmin()) {
$this->recordLoginAudit(
$request,
$user,
403,
'登录失败(核销端仅限超级管理员账号)',
['username' => $data['username'], 'client' => 'h5_verify']
);
return response()->json(['message' => '场馆管理员请使用活动专用核销链接与账号登录'], 403);
}
4 weeks ago
$expiresAt = $isH5Verify ? now()->addMonths(6) : null;
$tokenName = $isH5Verify ? 'h5-verify' : 'admin-token';
$token = $user->createToken($tokenName, ['*'], $expiresAt)->plainTextToken;
1 week ago
$this->recordLoginAudit(
$request,
$user,
200,
'登录('.$user->username.'',
[
'username' => $data['username'],
'client' => $request->input('client'),
]
);
4 weeks ago
return response()->json([
'token' => $token,
'user' => [
'id' => $user->id,
'username' => $user->username,
'name' => $user->name,
'role' => $user->role,
'venues' => $user->venues,
1 week ago
'full_admin_access' => $user->isSuperAdmin(),
4 weeks ago
],
]);
}
public function logout(Request $request): JsonResponse
{
$request->user()?->currentAccessToken()?->delete();
1 week ago
4 weeks ago
return response()->json(['message' => '已退出登录']);
}
1 week ago
/**
* @param array<string, mixed> $payload
*/
private function recordLoginAudit(Request $request, ?User $user, int $statusCode, string $operationSummary, array $payload = []): void
{
try {
AuditLog::create([
'user_id' => $user?->id,
'username' => $user?->username ?? (isset($payload['username']) ? (string) $payload['username'] : null),
'role' => $user?->role,
'method' => 'POST',
'path' => '/'.ltrim($request->path(), '/'),
'action' => 'POST '.$request->path(),
'operation_summary' => $operationSummary,
'status_code' => $statusCode,
'ip' => $request->ip(),
'user_agent' => substr((string) $request->userAgent(), 0, 500),
'request_payload' => $payload,
]);
} catch (\Throwable) {
}
}
4 weeks ago
}