SysUserController.java 12 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308
  1. package com.zhongzheng.controller.system;
  2. import cn.hutool.core.bean.BeanUtil;
  3. import cn.hutool.core.lang.Validator;
  4. import com.github.xiaoymin.knife4j.annotations.ApiOperationSupport;
  5. import com.github.xiaoymin.knife4j.annotations.DynamicParameter;
  6. import com.github.xiaoymin.knife4j.annotations.DynamicParameters;
  7. import com.zhongzheng.common.annotation.Log;
  8. import com.zhongzheng.common.constant.Constants;
  9. import com.zhongzheng.common.constant.UserConstants;
  10. import com.zhongzheng.common.core.bo.SysUserEditBo;
  11. import com.zhongzheng.common.core.controller.BaseController;
  12. import com.zhongzheng.common.core.domain.AjaxResult;
  13. import com.zhongzheng.common.core.domain.entity.SysRole;
  14. import com.zhongzheng.common.core.domain.entity.SysUser;
  15. import com.zhongzheng.common.core.domain.model.LoginUser;
  16. import com.zhongzheng.common.core.page.TableDataInfo;
  17. import com.zhongzheng.common.enums.BusinessType;
  18. import com.zhongzheng.common.exception.CustomException;
  19. import com.zhongzheng.common.exception.user.UserPasswordNotMatchException;
  20. import com.zhongzheng.common.utils.*;
  21. import com.zhongzheng.common.utils.poi.ExcelUtil;
  22. import com.zhongzheng.framework.manager.AsyncManager;
  23. import com.zhongzheng.framework.manager.factory.AsyncFactory;
  24. import com.zhongzheng.framework.web.service.TokenService;
  25. import com.zhongzheng.modules.course.bo.CourseBusinessQueryBo;
  26. import com.zhongzheng.modules.exam.domain.ExamConfig;
  27. import com.zhongzheng.modules.system.service.ISysPostService;
  28. import com.zhongzheng.modules.system.service.ISysRoleService;
  29. import com.zhongzheng.modules.system.service.ISysUserService;
  30. import io.swagger.annotations.Api;
  31. import io.swagger.annotations.ApiImplicitParam;
  32. import io.swagger.annotations.ApiOperation;
  33. import org.springframework.beans.factory.annotation.Autowired;
  34. import org.springframework.security.access.prepost.PreAuthorize;
  35. import org.springframework.security.authentication.AuthenticationManager;
  36. import org.springframework.security.authentication.BadCredentialsException;
  37. import org.springframework.security.authentication.UsernamePasswordAuthenticationToken;
  38. import org.springframework.security.core.Authentication;
  39. import org.springframework.validation.annotation.Validated;
  40. import org.springframework.web.bind.annotation.*;
  41. import org.springframework.web.multipart.MultipartFile;
  42. import javax.annotation.Resource;
  43. import java.util.List;
  44. import java.util.stream.Collectors;
  45. /**
  46. * 用户信息
  47. *
  48. * @author zhongzheng
  49. */
  50. @Api(tags ="用户信息管理")
  51. @RestController
  52. @RequestMapping("/system/user")
  53. public class SysUserController extends BaseController
  54. {
  55. @Autowired
  56. private ISysUserService userService;
  57. @Autowired
  58. private ISysRoleService roleService;
  59. @Autowired
  60. private ISysPostService postService;
  61. @Autowired
  62. private TokenService tokenService;
  63. @Resource
  64. private AuthenticationManager authenticationManager;
  65. /**
  66. * 获取用户列表
  67. */
  68. @ApiOperation("获取用户列表")
  69. @PreAuthorize("@ss.hasPermi('system:user:list')")
  70. @GetMapping("/list")
  71. public TableDataInfo list(SysUser user)
  72. {
  73. startPage();
  74. List<SysUser> list = userService.selectUserList(user);
  75. return getDataTable(list);
  76. }
  77. @Log(title = "用户管理", businessType = BusinessType.EXPORT)
  78. @PreAuthorize("@ss.hasPermi('system:user:export')")
  79. @GetMapping("/export")
  80. public AjaxResult export(SysUser user)
  81. {
  82. List<SysUser> list = userService.selectUserList(user);
  83. ExcelUtil<SysUser> util = new ExcelUtil<SysUser>(SysUser.class);
  84. return util.exportExcel(list, "用户数据");
  85. }
  86. @Log(title = "用户管理", businessType = BusinessType.IMPORT)
  87. @PreAuthorize("@ss.hasPermi('system:user:import')")
  88. @PostMapping("/importData")
  89. /* public AjaxResult importData(MultipartFile file, boolean updateSupport) throws Exception
  90. {
  91. ExcelUtil<SysUser> util = new ExcelUtil<SysUser>(SysUser.class);
  92. List<SysUser> userList = util.importExcel(file.getInputStream());
  93. LoginUser loginUser = tokenService.getLoginUser(ServletUtils.getRequest());
  94. String operName = loginUser.getUsername();
  95. String message = userService.importUser(userList, updateSupport, operName);
  96. return AjaxResult.success(message);
  97. }*/
  98. @GetMapping("/importTemplate")
  99. public AjaxResult importTemplate()
  100. {
  101. ExcelUtil<SysUser> util = new ExcelUtil<SysUser>(SysUser.class);
  102. return util.importTemplateExcel("用户数据");
  103. }
  104. /**
  105. * 根据用户编号获取详细信息
  106. */
  107. @ApiOperation("获取用户详细")
  108. @ApiImplicitParam(name = "userId", value = "用户ID", required = true, dataType = "int", paramType = "path")
  109. @PreAuthorize("@ss.hasPermi('system:user:query')")
  110. @GetMapping(value = { "/{userId}" })
  111. public AjaxResult getInfo(@PathVariable(value = "userId", required = false) Long userId)
  112. {
  113. AjaxResult ajax = AjaxResult.success();
  114. List<SysRole> roles = roleService.selectRoleAll();
  115. SysUser sysUser = userService.selectUserById(userId);
  116. ajax.put("roles", SysUser.isAdmin(sysUser.getUserName()) ? roles : roles.stream().filter(r -> !r.isAdmin()).collect(Collectors.toList()));
  117. ajax.put("posts", postService.selectPostAll());
  118. if (Validator.isNotNull(userId))
  119. {
  120. ajax.put(AjaxResult.DATA_TAG, userService.selectUserById(userId));
  121. ajax.put("postIds", postService.selectPostListByUserId(userId));
  122. ajax.put("roleIds", roleService.selectRoleListByUserId(userId));
  123. }
  124. return ajax;
  125. }
  126. /**
  127. * 新增用户
  128. */
  129. @ApiOperation("新增用户")
  130. @ApiOperationSupport(ignoreParameters = {"id","orderDate.id"})
  131. @PreAuthorize("@ss.hasPermi('system:user:add')")
  132. @Log(title = "用户管理", businessType = BusinessType.INSERT)
  133. @PostMapping
  134. public AjaxResult add(@Validated @RequestBody SysUser user)
  135. {
  136. if (UserConstants.NOT_UNIQUE.equals(userService.checkUserNameUnique(user.getUserName())))
  137. {
  138. return AjaxResult.error("新增用户'" + user.getUserName() + "'失败,登录账号已存在");
  139. }
  140. else if (Validator.isNotEmpty(user.getPhonenumber())
  141. && UserConstants.NOT_UNIQUE.equals(userService.checkPhoneUnique(user)))
  142. {
  143. return AjaxResult.error("新增用户'" + user.getUserName() + "'失败,手机号码已存在");
  144. }
  145. else if (Validator.isNotEmpty(user.getEmail())
  146. && UserConstants.NOT_UNIQUE.equals(userService.checkEmailUnique(user)))
  147. {
  148. return AjaxResult.error("新增用户'" + user.getUserName() + "'失败,邮箱账号已存在");
  149. }
  150. user.setCreateBy(SecurityUtils.getUsername());
  151. if(!ToolsUtils.verifPwd(user.getPassword())){
  152. throw new CustomException("密码应由8-16位数字、大小写字母、符号组成");
  153. }
  154. user.setPassword(SecurityUtils.encryptPassword(user.getPassword()));
  155. user.setPwdTime(DateUtils.getNowTime());
  156. return toAjax(userService.insertUser(user));
  157. }
  158. /**
  159. * 修改用户
  160. */
  161. @ApiOperation("更新用户")
  162. @PreAuthorize("@ss.hasPermi('system:user:edit')")
  163. @Log(title = "用户管理", businessType = BusinessType.UPDATE)
  164. @PostMapping("/edit")
  165. public AjaxResult edit(@Validated @RequestBody SysUserEditBo bo)
  166. {
  167. if (Validator.isNotEmpty(bo.getStatus())&&bo.getStatus().equals(-1)){
  168. SysUser user = BeanUtil.toBean(bo, SysUser.class);
  169. int result = userService.updateUser(user);
  170. return toAjax(result);
  171. }
  172. SysUser user = BeanUtil.toBean(bo, SysUser.class);
  173. userService.checkUserAllowed(user);
  174. LoginUser loginUser = tokenService.getLoginUser(ServletUtils.getRequest());
  175. if(!loginUser.getUser().isAdmin()&&loginUser.getUser().getUserId()!=user.getUserId()){
  176. return AjaxResult.error("您无权限修改本信息");
  177. }
  178. if (Validator.isNotEmpty(user.getPhonenumber())
  179. && UserConstants.NOT_UNIQUE.equals(userService.checkPhoneUnique(user)))
  180. {
  181. return AjaxResult.error("修改用户'" + user.getUserName() + "'失败,手机号码已存在");
  182. }
  183. else if (Validator.isNotEmpty(user.getEmail())
  184. && UserConstants.NOT_UNIQUE.equals(userService.checkEmailUnique(user)))
  185. {
  186. return AjaxResult.error("修改用户'" + user.getUserName() + "'失败,邮箱账号已存在");
  187. }
  188. if(Validator.isNotEmpty(user.getPassword())){
  189. //重置密码
  190. if(!loginUser.getUser().isAdmin()){
  191. //普通用户需传入旧密码修改
  192. // 旧密码用户验证
  193. Authentication authentication = null;
  194. try
  195. {
  196. // 该方法会去调用UserDetailsServiceImpl.loadUserByUsername
  197. authentication = authenticationManager
  198. .authenticate(new UsernamePasswordAuthenticationToken(loginUser.getUser().getUserName(), bo.getOldPassword()));
  199. }
  200. catch (Exception e)
  201. {
  202. return AjaxResult.error("旧密码错误");
  203. }
  204. }
  205. if(!ToolsUtils.verifPwd(user.getPassword())){
  206. throw new CustomException("密码应由8-16位数字、大小写字母、符号组成");
  207. }
  208. user.setPassword(SecurityUtils.encryptPassword(user.getPassword()));
  209. user.setPwdTime(DateUtils.getNowTime());
  210. }
  211. user.setUpdateBy(SecurityUtils.getUsername());
  212. int result = userService.updateUser(user);
  213. if(result>0){
  214. SysUser newUser = userService.selectUserByUserName(loginUser.getUser().getUserName());
  215. //同个用户ID则更新用户信息,admin操作其他用户则不更新
  216. if(newUser.getUserId()==loginUser.getUser().getUserId()){
  217. // 更新缓存用户
  218. loginUser.setUser(newUser);
  219. }
  220. tokenService.setLoginUser(loginUser);
  221. }
  222. return toAjax(result);
  223. }
  224. /**
  225. * 删除用户
  226. */
  227. /* @ApiOperation("删除用户信息")
  228. @ApiImplicitParam(name = "userId", value = "用户ID", required = true, dataType = "int", paramType = "path")
  229. @PreAuthorize("@ss.hasPermi('system:user:remove')")
  230. @Log(title = "用户管理", businessType = BusinessType.DELETE)
  231. @DeleteMapping("/{userIds}")
  232. public AjaxResult remove(@PathVariable Long[] userIds)
  233. {
  234. return toAjax(userService.deleteUserByIds(userIds));
  235. }*/
  236. /**
  237. * 重置密码
  238. */
  239. /* @PreAuthorize("@ss.hasPermi('system:user:resetPwd')")
  240. @Log(title = "用户管理", businessType = BusinessType.UPDATE)
  241. @PostMapping("/resetPwd")
  242. public AjaxResult resetPwd(@RequestBody SysUser user)
  243. {
  244. userService.checkUserAllowed(user);
  245. user.setPassword(SecurityUtils.encryptPassword(user.getPassword()));
  246. user.setUpdateBy(SecurityUtils.getUsername());
  247. return toAjax(userService.resetPwd(user));
  248. }*/
  249. /**
  250. * 状态修改
  251. */
  252. @PreAuthorize("@ss.hasPermi('system:user:edit')")
  253. @Log(title = "用户管理", businessType = BusinessType.UPDATE)
  254. @PutMapping("/changeStatus")
  255. public AjaxResult changeStatus(@RequestBody SysUser user)
  256. {
  257. userService.checkUserAllowed(user);
  258. user.setUpdateBy(SecurityUtils.getUsername());
  259. return toAjax(userService.updateUserStatus(user));
  260. }
  261. /**
  262. * 业务层次获取用户列表
  263. */
  264. @ApiOperation("业务层次获取用户列表")
  265. @PreAuthorize("@ss.hasPermi('system:user:list')")
  266. @GetMapping("/businessPeopleList")
  267. public TableDataInfo queryBusinessPeopleList(CourseBusinessQueryBo bo)
  268. {
  269. startPage();
  270. List<SysUser> list = userService.queryBusinessPeopleList(bo);
  271. return getDataTable(list);
  272. }
  273. @ApiOperation("检查密码修改时间")
  274. @PreAuthorize("@ss.hasPermi('system:user:list')")
  275. @GetMapping("/checkPwdTime")
  276. public AjaxResult<Boolean> checkPwdTime()
  277. {
  278. LoginUser loginUser = tokenService.getLoginUser(ServletUtils.getRequest());
  279. SysUser user = userService.selectUserById(loginUser.getUser().getUserId());
  280. boolean needUpdate = false;
  281. /* if(Validator.isNotEmpty(user.getPwdTime())&&(DateUtils.getNowTime().longValue()-user.getPwdTime().longValue())>90*24*3600){
  282. needUpdate = true;
  283. }*/
  284. return AjaxResult.success(needUpdate);
  285. }
  286. }