BsSysUserController.java 10 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242
  1. package com.zhongzheng.controller.system;
  2. import cn.hutool.core.bean.BeanUtil;
  3. import cn.hutool.core.lang.Validator;
  4. import com.github.xiaoymin.knife4j.annotations.ApiOperationSupport;
  5. import com.zhongzheng.common.annotation.Log;
  6. import com.zhongzheng.common.constant.UserConstants;
  7. import com.zhongzheng.common.core.bo.SysUserEditBo;
  8. import com.zhongzheng.common.core.controller.BaseController;
  9. import com.zhongzheng.common.core.domain.AjaxResult;
  10. import com.zhongzheng.common.core.domain.entity.SysRole;
  11. import com.zhongzheng.common.core.domain.entity.SysUser;
  12. import com.zhongzheng.common.core.domain.model.LoginUser;
  13. import com.zhongzheng.common.core.page.TableDataInfo;
  14. import com.zhongzheng.common.enums.BusinessType;
  15. import com.zhongzheng.common.exception.CustomException;
  16. import com.zhongzheng.common.utils.DateUtils;
  17. import com.zhongzheng.common.utils.SecurityUtils;
  18. import com.zhongzheng.common.utils.ServletUtils;
  19. import com.zhongzheng.common.utils.ToolsUtils;
  20. import com.zhongzheng.common.utils.poi.ExcelUtil;
  21. import com.zhongzheng.framework.web.service.BsTokenService;
  22. import com.zhongzheng.framework.web.service.TokenService;
  23. import com.zhongzheng.modules.bs.company.entity.ClientBsLoginUser;
  24. import com.zhongzheng.modules.bs.system.domain.BsSysRole;
  25. import com.zhongzheng.modules.bs.system.domain.BsSysUser;
  26. import com.zhongzheng.modules.bs.system.service.IBsSysPostService;
  27. import com.zhongzheng.modules.bs.system.service.IBsSysRoleService;
  28. import com.zhongzheng.modules.bs.system.service.IBsSysUserService;
  29. import com.zhongzheng.modules.course.bo.CourseBusinessQueryBo;
  30. import com.zhongzheng.modules.system.service.ISysPostService;
  31. import com.zhongzheng.modules.system.service.ISysRoleService;
  32. import com.zhongzheng.modules.system.service.ISysUserService;
  33. import io.swagger.annotations.Api;
  34. import io.swagger.annotations.ApiImplicitParam;
  35. import io.swagger.annotations.ApiOperation;
  36. import org.springframework.beans.factory.annotation.Autowired;
  37. import org.springframework.security.access.prepost.PreAuthorize;
  38. import org.springframework.security.authentication.AuthenticationManager;
  39. import org.springframework.security.authentication.UsernamePasswordAuthenticationToken;
  40. import org.springframework.security.core.Authentication;
  41. import org.springframework.validation.annotation.Validated;
  42. import org.springframework.web.HttpRequestHandler;
  43. import org.springframework.web.bind.annotation.*;
  44. import javax.annotation.Resource;
  45. import javax.servlet.http.HttpServletRequest;
  46. import java.util.List;
  47. import java.util.stream.Collectors;
  48. /**
  49. * 用户信息
  50. *
  51. * @author zhongzheng
  52. */
  53. @Api(tags ="用户信息管理")
  54. @RestController
  55. @RequestMapping("/bs/system/user")
  56. public class BsSysUserController extends BaseController
  57. {
  58. @Autowired
  59. private IBsSysUserService userService;
  60. @Autowired
  61. private IBsSysRoleService roleService;
  62. @Autowired
  63. private BsTokenService bsTokenService;
  64. @Resource
  65. private AuthenticationManager authenticationManager;
  66. /**
  67. * 获取用户列表
  68. */
  69. @ApiOperation("获取用户列表")
  70. @PreAuthorize("@ss.hasPermi('system:user:list')")
  71. @GetMapping("/list")
  72. public TableDataInfo list(BsSysUser user)
  73. {
  74. startPage();
  75. List<BsSysUser> list = userService.selectUserList(user);
  76. return getDataTable(list);
  77. }
  78. /**
  79. * 根据用户编号获取详细信息
  80. */
  81. @ApiOperation("获取用户详细")
  82. @PreAuthorize("@ss.hasPermi('system:user:query')")
  83. @GetMapping(value = { "/getInfo" })
  84. public AjaxResult getInfo( Long userId)
  85. {
  86. AjaxResult ajax = AjaxResult.success();
  87. List<BsSysRole> roles = roleService.selectRoleAll();
  88. BsSysUser sysUser = userService.selectUserById(userId);
  89. if (!sysUser.isAdmin()){
  90. roles=roles.stream().filter(r -> !r.isAdmin()).collect(Collectors.toList());
  91. }
  92. if (Validator.isNotNull(userId))
  93. {
  94. BsSysUser bsSysUser = userService.selectUserById(userId);
  95. bsSysUser.setRoles(roles);
  96. ajax.put(AjaxResult.DATA_TAG, bsSysUser);
  97. ajax.put("roleIds", roleService.selectRoleListByUserId(userId));
  98. }
  99. return ajax;
  100. }
  101. /**
  102. * 新增用户
  103. */
  104. @ApiOperation("新增用户")
  105. @ApiOperationSupport(ignoreParameters = {"id","orderDate.id"})
  106. @PreAuthorize("@ss.hasPermi('system:user:add')")
  107. @Log(title = "用户管理", businessType = BusinessType.INSERT)
  108. @PostMapping
  109. public AjaxResult add(@Validated @RequestBody BsSysUser user)
  110. {
  111. if (UserConstants.NOT_UNIQUE.equals(userService.checkUserNameUnique(user.getUserName())))
  112. {
  113. return AjaxResult.error("新增用户'" + user.getUserName() + "'失败,登录账号已存在");
  114. }
  115. else if (Validator.isNotEmpty(user.getPhonenumber())
  116. && UserConstants.NOT_UNIQUE.equals(userService.checkPhoneUnique(user)))
  117. {
  118. return AjaxResult.error("新增用户'" + user.getUserName() + "'失败,手机号码已存在");
  119. }
  120. else if (Validator.isNotEmpty(user.getEmail())
  121. && UserConstants.NOT_UNIQUE.equals(userService.checkEmailUnique(user)))
  122. {
  123. return AjaxResult.error("新增用户'" + user.getUserName() + "'失败,邮箱账号已存在");
  124. }
  125. user.setCreateBy(bsTokenService.getLoginUser(ServletUtils.getRequest()).getUsername());
  126. if(!ToolsUtils.verifEasyPwd(user.getPassword())){
  127. throw new CustomException("密码应由8-16位数字、大小写字母、符号组成");
  128. }
  129. user.setCompanyId(bsTokenService.getLoginUser(ServletUtils.getRequest()).getUser().getCompanyId());
  130. user.setPassword(SecurityUtils.encryptPassword(user.getPassword()));
  131. user.setCreateTime(DateUtils.getNowTime());
  132. user.setUpdateTime(DateUtils.getNowTime());
  133. return toAjax(userService.insertUser(user));
  134. }
  135. /**
  136. * 修改用户
  137. */
  138. @ApiOperation("更新用户")
  139. @PreAuthorize("@ss.hasPermi('system:user:edit')")
  140. @Log(title = "用户管理", businessType = BusinessType.UPDATE)
  141. @PostMapping("/edit")
  142. public AjaxResult edit(@Validated @RequestBody SysUserEditBo bo)
  143. {
  144. if (Validator.isNotEmpty(bo.getStatus())&&bo.getStatus().equals(-1)){
  145. BsSysUser user = BeanUtil.toBean(bo, BsSysUser.class);
  146. int result = userService.updateUser(user);
  147. return toAjax(result);
  148. }
  149. BsSysUser user = BeanUtil.toBean(bo, BsSysUser.class);
  150. userService.checkUserAllowed(user);
  151. ClientBsLoginUser loginUser = bsTokenService.getLoginUser(ServletUtils.getRequest());
  152. if(!loginUser.getUser().isAdmin()&&loginUser.getUser().getUserId()!=user.getUserId()){
  153. return AjaxResult.error("您无权限修改本信息");
  154. }
  155. if (Validator.isNotEmpty(user.getPhonenumber())
  156. && UserConstants.NOT_UNIQUE.equals(userService.checkPhoneUnique(user)))
  157. {
  158. return AjaxResult.error("修改用户'" + user.getUserName() + "'失败,手机号码已存在");
  159. }
  160. else if (Validator.isNotEmpty(user.getEmail())
  161. && UserConstants.NOT_UNIQUE.equals(userService.checkEmailUnique(user)))
  162. {
  163. return AjaxResult.error("修改用户'" + user.getUserName() + "'失败,邮箱账号已存在");
  164. }
  165. if(Validator.isNotEmpty(user.getPassword())){
  166. //重置密码
  167. if(!loginUser.getUser().isAdmin()){
  168. //普通用户需传入旧密码修改
  169. // 旧密码用户验证
  170. Authentication authentication = null;
  171. try
  172. {
  173. // 该方法会去调用UserDetailsServiceImpl.loadUserByUsername
  174. authentication = authenticationManager
  175. .authenticate(new UsernamePasswordAuthenticationToken(loginUser.getUser().getUserName(), bo.getOldPassword()));
  176. }
  177. catch (Exception e)
  178. {
  179. return AjaxResult.error("旧密码错误");
  180. }
  181. }
  182. if(!ToolsUtils.verifEasyPwd(user.getPassword())){
  183. throw new CustomException("密码应由8-16位数字、大小写字母、符号组成");
  184. }
  185. user.setPassword(SecurityUtils.encryptPassword(user.getPassword()));
  186. user.setPwdTime(DateUtils.getNowTime());
  187. }
  188. user.setUpdateBy(bsTokenService.getLoginUser(ServletUtils.getRequest()).getUsername());
  189. int result = userService.updateUser(user);
  190. if(result>0){
  191. BsSysUser bsSysUser = userService.selectUserByUserName(loginUser.getUser().getUserName());
  192. //同个用户ID则更新用户信息,admin操作其他用户则不更新
  193. if(bsSysUser.getUserId()==loginUser.getUser().getUserId()){
  194. // 更新缓存用户
  195. loginUser.setUser(bsSysUser);
  196. }
  197. bsTokenService.setLoginUser(loginUser);
  198. }
  199. return toAjax(result);
  200. }
  201. /**
  202. * 状态修改
  203. */
  204. @PreAuthorize("@ss.hasPermi('system:user:edit')")
  205. @Log(title = "用户管理", businessType = BusinessType.UPDATE)
  206. @PostMapping("/changeStatus")
  207. public AjaxResult changeStatus(@RequestBody BsSysUser user)
  208. {
  209. userService.checkUserAllowed(user);
  210. user.setUpdateBy(bsTokenService.getLoginUser(ServletUtils.getRequest()).getUsername());
  211. user.setUpdateTime(DateUtils.getNowTime());
  212. return toAjax(userService.updateUserStatus(user));
  213. }
  214. // @ApiOperation("检查密码修改时间")
  215. // @PreAuthorize("@ss.hasPermi('system:user:list')")
  216. // @GetMapping("/checkPwdTime")
  217. // public AjaxResult<Boolean> checkPwdTime()
  218. // {
  219. // ClientBsLoginUser loginUser = bsTokenService.getLoginUser(ServletUtils.getRequest());
  220. // BsSysUser user = userService.selectUserById(loginUser.getUser().getUserId());
  221. // boolean needUpdate = false;
  222. // if(Validator.isNotEmpty(user.getPwdTime())&&(DateUtils.getNowTime().longValue()-user.getPwdTime().longValue())>90*24*3600){
  223. // needUpdate = true;
  224. // }
  225. // return AjaxResult.success(needUpdate);
  226. // }
  227. }