LoginController.cs 40 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722
  1. using Azure.Cosmos;
  2. using DingTalk.Api;
  3. using DingTalk.Api.Request;
  4. using DingTalk.Api.Response;
  5. using Microsoft.AspNetCore.Http;
  6. using Microsoft.AspNetCore.Mvc;
  7. using Microsoft.Extensions.Configuration;
  8. using System;
  9. using System.Collections.Generic;
  10. using System.Linq;
  11. using System.Text.Json;
  12. using System.Threading.Tasks;
  13. using TEAMModelOS.SDK.DI;
  14. using TEAMModelOS.SDK.Models;
  15. using HTEXLib.COMM.Helpers;
  16. using TEAMModelOS.Models;
  17. using Microsoft.Extensions.Options;
  18. using TEAMModelOS.SDK.Extension;
  19. using TEAMModelOS.SDK.Models.Service;
  20. using Microsoft.AspNetCore.Authorization;
  21. using Azure.Storage.Blobs.Models;
  22. using System.IdentityModel.Tokens.Jwt;
  23. using System.Net.Http;
  24. using System.Text;
  25. using System.Net;
  26. using Newtonsoft.Json;
  27. using System.Collections;
  28. using Newtonsoft.Json.Linq;
  29. using TEAMModelOS.SDK.Models.Cosmos.BI;
  30. using Azure.Storage.Sas;
  31. using System.Net.Http.Json;
  32. using TEAMModelBI.Filter;
  33. using TEAMModelBI.Models.Extension;
  34. using TEAMModelOS.SDK;
  35. //using static DingTalk.Api.Response.OapiV2UserGetResponse;
  36. namespace TEAMModelBI.Controllers
  37. {
  38. [ProducesResponseType(StatusCodes.Status200OK)]
  39. [ProducesResponseType(StatusCodes.Status400BadRequest)]
  40. [Route("common/login")]
  41. [ApiController]
  42. public class LoginController : ControllerBase
  43. {
  44. private readonly IConfiguration _configuration;
  45. //数据容器
  46. private readonly AzureCosmosFactory _azureCosmos;
  47. //文件容器
  48. private readonly AzureStorageFactory _azureStorage;
  49. //钉钉提示信息
  50. private readonly DingDing _dingDing;
  51. private readonly Option _option;
  52. //隐式登录
  53. private readonly CoreAPIHttpService _aoreAPIHttpService;
  54. private readonly IHttpClientFactory _http;
  55. string type = "ddteammodel";
  56. public LoginController(IConfiguration configuration, AzureCosmosFactory azureCosmos, AzureStorageFactory azureStorage, DingDing dingDing, IOptionsSnapshot<Option> option, CoreAPIHttpService aoreAPIHttpService, IHttpClientFactory http)
  57. {
  58. _configuration = configuration;
  59. _azureCosmos = azureCosmos;
  60. _azureStorage = azureStorage;
  61. _dingDing = dingDing;
  62. _option = option?.Value;
  63. _aoreAPIHttpService = aoreAPIHttpService;
  64. _http = http;
  65. }
  66. /// <summary>
  67. /// 钉钉扫码登录
  68. /// 先获取是否在钉钉架构中
  69. /// 获取数据库是否有该人员
  70. /// </summary>
  71. /// <param name="jsonElement"></param>
  72. /// <returns>Json结果</returns>
  73. [ProducesDefaultResponseType]
  74. [HttpPost("DingLogin")]
  75. [AllowAnonymous]
  76. public async Task<IActionResult> DingLogin(JsonElement jsonElement)
  77. {
  78. //state 是前端传入的,钉钉并不会修改,比如有多种登录方式的时候,一个登录方法判断登录方式可以进行不同的处理。
  79. try
  80. {
  81. string str_appKey = _configuration["DingDingAuth:appKey"];
  82. string str_appSecret = _configuration["DingDingAuth:appSecret"];
  83. if (string.IsNullOrWhiteSpace(str_appKey) || string.IsNullOrWhiteSpace(str_appSecret))
  84. {
  85. return Ok(new { state = 0, message = "扫码登录失败" });
  86. }
  87. //自己传的code
  88. if (!jsonElement.TryGetProperty("code", out JsonElement LoginTempCode)) return BadRequest();
  89. //获取企业内部应用的accessToken
  90. DefaultDingTalkClient Iclient = new DefaultDingTalkClient("https://oapi.dingtalk.com/gettoken");
  91. OapiGettokenRequest request = new OapiGettokenRequest();
  92. request.Appkey = str_appKey;
  93. request.Appsecret = str_appSecret;
  94. request.SetHttpMethod("GET");
  95. OapiGettokenResponse tokenResponse = Iclient.Execute(request);
  96. if (tokenResponse.IsError)
  97. {
  98. return Ok(new { state = 0, message = "扫码登录失败" });
  99. }
  100. string access_token = tokenResponse.AccessToken;
  101. //获取临时授权码 获取授权用户的个人信息
  102. DefaultDingTalkClient clientinfo = new DefaultDingTalkClient("https://oapi.dingtalk.com/sns/getuserinfo_bycode");
  103. OapiSnsGetuserinfoBycodeRequest req = new OapiSnsGetuserinfoBycodeRequest() { TmpAuthCode = $"{LoginTempCode}" }; //通过扫描二维码,跳转到指定的Url后,向Url中追加Code临时授权码
  104. OapiSnsGetuserinfoBycodeResponse response = clientinfo.Execute(req, str_appKey, str_appSecret);
  105. if (response.IsError)
  106. {
  107. return Ok(new { state = 0, message = "扫码登录失败" });
  108. }
  109. string unionid = response.UserInfo.Unionid;
  110. IDingTalkClient client2 = new DefaultDingTalkClient("https://oapi.dingtalk.com/topapi/user/getbyunionid"); //userid地址
  111. OapiUserGetbyunionidRequest byunionidRequest = new OapiUserGetbyunionidRequest() { Unionid = unionid };
  112. OapiUserGetbyunionidResponse byunionidResponse = client2.Execute(byunionidRequest, access_token);
  113. if (byunionidResponse.IsError)
  114. {
  115. return Ok(new { state = 0, message = "扫码登录失败" });
  116. }
  117. // 根据userId获取用户信息
  118. string userid = byunionidResponse.Result.Userid;
  119. IDingTalkClient client3 = new DefaultDingTalkClient("https://oapi.dingtalk.com/topapi/v2/user/get");
  120. OapiV2UserGetRequest v2GetRequest = new OapiV2UserGetRequest()
  121. {
  122. Userid = userid,
  123. Language = "zh_CN"
  124. };
  125. v2GetRequest.SetHttpMethod("POST");
  126. OapiV2UserGetResponse v2GetResponse = client3.Execute(v2GetRequest, access_token);
  127. if (v2GetResponse.IsError)
  128. {
  129. return Ok(new { state = 0, message = "扫码登录失败" });
  130. }
  131. var DDbind = v2GetResponse.Result;
  132. DingDingbinds dingDingBind = new DingDingbinds
  133. {
  134. type = type,
  135. deptIdList = DDbind.DeptIdList,
  136. title = DDbind.Title,
  137. name = DDbind.Name,
  138. unionid = DDbind.Unionid,
  139. userid = DDbind.Userid,
  140. };
  141. Teacher teacher = null;
  142. string sql = $"select distinct value(c) from c join A1 in c.ddbinds where A1.userid='{dingDingBind.userid}' AND A1.unionid ='{dingDingBind.unionid}'";
  143. await foreach (var item in _azureCosmos.GetCosmosClient().GetContainer(Constant.TEAMModelOS, "Teacher").GetItemQueryIterator<Teacher>(queryText: sql, requestOptions: new QueryRequestOptions() { PartitionKey = new PartitionKey($"Base") }))
  144. {
  145. teacher = item;
  146. break;
  147. }
  148. if (teacher == null)
  149. {
  150. return Ok(new { state = 1, dingDingBind });
  151. }
  152. else
  153. {
  154. var clientID = _configuration.GetValue<string>("HaBookAuth:CoreService:clientID");
  155. var location = _option.Location;
  156. TmdidImplicit implicit_token = await _aoreAPIHttpService.Implicit(
  157. new Dictionary<string, string>()
  158. {
  159. { "grant_type", "implicit" },
  160. { "client_id",clientID },
  161. { "account",teacher.id },
  162. { "nonce",Guid.NewGuid().ToString()}
  163. }, location, _configuration);
  164. Dictionary<string, object> dic = new Dictionary<string, object> { { "PartitionKey", "authority-bi" } };//设置只访问BI的权限
  165. var table = _azureStorage.GetCloudTableClient().GetTableReference("SchoolSetting");
  166. List<Authority> authorityBIList = await table.FindListByDict<Authority>(dic); //获取权限列表
  167. if (implicit_token!=null)
  168. {
  169. var ddbind = teacher.ddbinds.Find(x => x.userid.Equals($"{dingDingBind.userid}") && x.unionid.Equals($"{dingDingBind.unionid}"));
  170. if (ddbind != null)
  171. {
  172. List<string> roles = new List<string>();//角色列表
  173. List<string> permissions = new List<string>();//权限列表
  174. List<string> depts = new List<string>(); //部门id
  175. School school_base = new School();
  176. string school_code = null;
  177. if (teacher.defaultSchool != null)
  178. {
  179. var schoolRoles = await _azureCosmos.GetCosmosClient().GetContainer(Constant.TEAMModelOS, "School").ReadItemStreamAsync(teacher.id, new PartitionKey($"Teacher-{teacher.defaultSchool}"));
  180. if (schoolRoles.Status == 200)
  181. {
  182. using var json = await JsonDocument.ParseAsync(schoolRoles.ContentStream);
  183. if (json.RootElement.TryGetProperty("roles", out JsonElement _roles) && _roles.ValueKind != JsonValueKind.Null)
  184. {
  185. foreach (var obj in _roles.EnumerateArray())
  186. {
  187. if (obj.GetString().Equals("assist"))
  188. {
  189. roles.Add(obj.GetString());
  190. }
  191. }
  192. }
  193. if (json.RootElement.TryGetProperty("permissions", out JsonElement _permissions) && _permissions.ValueKind != JsonValueKind.Null)
  194. {
  195. foreach (var obj in _permissions.EnumerateArray())
  196. {
  197. foreach (var item in authorityBIList)
  198. {
  199. if (item.RowKey.Equals(obj.GetString()))
  200. {
  201. permissions.Add(obj.GetString());
  202. }
  203. }
  204. }
  205. }
  206. }
  207. school_base = await _azureCosmos.GetCosmosClient().GetContainer(Constant.TEAMModelOS, "School").ReadItemAsync<School>($"{teacher.defaultSchool}", new PartitionKey("Base"));
  208. //foreach (var period in school_base.period)
  209. //{
  210. // try
  211. // {
  212. // await _azureCosmos.GetCosmosClient().GetContainer(Constant.TEAMModelOS, "School").ReadItemAsync<ItemCond>($"{period.id}", new PartitionKey($"ItemCond-{teacher.defaultSchool}"));
  213. // }
  214. // catch (CosmosException)
  215. // {
  216. // ItemCond itemCond = new ItemCond
  217. // {
  218. // id = period.id,
  219. // pk = "ItemCond",
  220. // code = $"ItemCond-{teacher.defaultSchool}",
  221. // ttl = -1,
  222. // };
  223. // await _azureCosmos.GetCosmosClient().GetContainer(Constant.TEAMModelOS, "School").CreateItemAsync<ItemCond>(itemCond, new PartitionKey($"ItemCond-{teacher.defaultSchool}"));
  224. // }
  225. //}
  226. school_code = teacher.defaultSchool;
  227. }
  228. foreach (var temp in ddbind.deptIdList)
  229. {
  230. depts.Add(temp.ToString());
  231. }
  232. var auth_token = JwtAuthExtension.CreateAuthToken(_option.HostName, teacher.id,teacher.name?.ToString(),teacher.picture?.ToString(),_option.JwtSecretKey, scope: Constant.ScopeTeacher, Website: "BI", schoolID: school_code?.ToString(), standard: school_base.standard, roles:roles.ToArray(),permissions:permissions.ToArray(),ddDepts: depts.ToArray(),ddsub:ddbind.userid);
  233. return Ok(new { state = 200, auth_token = auth_token, teacher = teacher, id_token = implicit_token.id_token, access_token = implicit_token.access_token, expires_in = implicit_token.expires_in, token_type = implicit_token.token_type });
  234. }
  235. }
  236. return Ok(new { state = 1, dingdinginfo = dingDingBind });
  237. }
  238. }
  239. catch (Exception e)
  240. {
  241. return Ok(new { state = 1, message = "code失效" });
  242. }
  243. }
  244. /// <summary>
  245. /// 依据id_Ttoken获取教师信息
  246. /// </summary>
  247. /// <param name="jsonElement"></param>
  248. /// <returns></returns>
  249. [ProducesDefaultResponseType]
  250. [HttpPost("get-teacherinfo")]
  251. public async Task<IActionResult> GetTeacherInfo(JsonElement jsonElement)
  252. {
  253. try
  254. {
  255. if (!jsonElement.TryGetProperty("id_token", out JsonElement id_token)) return BadRequest();
  256. var jwt = new JwtSecurityToken(id_token.GetString());
  257. //TODO 此驗證IdToken先簡單檢查,後面需向Core ID新API,驗證Token
  258. //if (!jwt.Payload.Iss.Equals("account.teammodel", StringComparison.OrdinalIgnoreCase)) return BadRequest();
  259. var id = jwt.Payload.Sub;
  260. jwt.Payload.TryGetValue("name", out object name);
  261. jwt.Payload.TryGetValue("picture", out object picture);
  262. Teacher teacher = null;
  263. //检查是否有绑定信息
  264. var client = _azureCosmos.GetCosmosClient();
  265. teacher = await client.GetContainer(Constant.TEAMModelOS, "Teacher").ReadItemAsync<Teacher>($"{id}", new PartitionKey("Base"));
  266. var auth_token = "";
  267. var clientID = _configuration.GetValue<string>("HaBookAuth:CoreService:clientID");
  268. var location = _option.Location;
  269. TmdidImplicit implicit_token = await _aoreAPIHttpService.Implicit(
  270. new Dictionary<string, string>()
  271. {
  272. { "grant_type", "implicit" },
  273. { "client_id",clientID },
  274. { "account",teacher.id },
  275. { "nonce",Guid.NewGuid().ToString()}
  276. }, location, _configuration);
  277. Dictionary<string, object> dic = new Dictionary<string, object> { { "PartitionKey", "authority-bi" } };//设置只访问BI的权限
  278. var table = _azureStorage.GetCloudTableClient().GetTableReference("SchoolSetting");
  279. List<Authority> authorityBIList = await table.FindListByDict<Authority>(dic); //获取权限列表
  280. List<string> roles = new List<string>();//角色列表
  281. List<string> permissions = new List<string>();//权限列表
  282. List<string> depts = new List<string>(); //部门id
  283. School school_base = new School();
  284. string school_code = null;
  285. if (implicit_token!=null)
  286. {
  287. if (teacher.defaultSchool != null)
  288. {
  289. var schoolRoles = await _azureCosmos.GetCosmosClient().GetContainer(Constant.TEAMModelOS, "School").ReadItemStreamAsync(teacher.id, new PartitionKey($"Teacher-{teacher.defaultSchool}"));
  290. if (schoolRoles.Status == 200)
  291. {
  292. using var json = await JsonDocument.ParseAsync(schoolRoles.ContentStream);
  293. if (json.RootElement.TryGetProperty("roles", out JsonElement _roles) && _roles.ValueKind != JsonValueKind.Null)
  294. {
  295. foreach (var obj in _roles.EnumerateArray())
  296. {
  297. //初始定义顾问的assistant 更改为assist
  298. if (obj.GetString().Equals($"assist"))
  299. {
  300. roles.Add(obj.GetString());
  301. }
  302. }
  303. }
  304. if (json.RootElement.TryGetProperty("permissions", out JsonElement _permissions) && _permissions.ValueKind != JsonValueKind.Null)
  305. {
  306. foreach (var obj in _permissions.EnumerateArray())
  307. {
  308. //限制只显示BI权限
  309. foreach (var aut in authorityBIList)
  310. {
  311. if (aut.RowKey.Equals(obj.GetString()))
  312. {
  313. permissions.Add(obj.GetString());
  314. }
  315. }
  316. }
  317. }
  318. }
  319. school_base = await _azureCosmos.GetCosmosClient().GetContainer(Constant.TEAMModelOS, "School").ReadItemAsync<School>($"{teacher.defaultSchool}", new PartitionKey("Base"));
  320. //foreach (var period in school_base.period)
  321. //{
  322. // try
  323. // {
  324. // await _azureCosmos.GetCosmosClient().GetContainer(Constant.TEAMModelOS, "School").ReadItemAsync<ItemCond>($"{period.id}", new PartitionKey($"ItemCond-{teacher.defaultSchool}"));
  325. // }
  326. // catch (CosmosException)
  327. // {
  328. // ItemCond itemCond = new ItemCond
  329. // {
  330. // id = period.id,
  331. // pk = "ItemCond",
  332. // code = $"ItemCond-{teacher.defaultSchool}",
  333. // ttl = -1,
  334. // };
  335. // await _azureCosmos.GetCosmosClient().GetContainer(Constant.TEAMModelOS, "School").CreateItemAsync<ItemCond>(itemCond, new PartitionKey($"ItemCond-{teacher.defaultSchool}"));
  336. // }
  337. //}
  338. school_code = teacher.defaultSchool;
  339. }
  340. List<Teacher.DingDingBind> ddbinds = teacher.ddbinds;
  341. Teacher.DingDingBind ddbind = new Teacher.DingDingBind();
  342. if (teacher.ddbinds.Count > 0)
  343. {
  344. if (ddbinds != null)
  345. {
  346. foreach (var temp in ddbinds)
  347. {
  348. ddbind.userid = temp.userid;
  349. ddbind.deptIdList = temp.deptIdList;
  350. }
  351. }
  352. foreach (var temp in ddbind.deptIdList)
  353. {
  354. depts.Add(temp.ToString());
  355. }
  356. }
  357. else return Ok(new { state = 1, message = "该账户未绑定钉钉信息!请扫码绑定信息!" });
  358. auth_token = JwtAuthExtension.CreateAuthToken(_option.HostName, teacher.id, teacher.name?.ToString(), teacher.picture?.ToString(), _option.JwtSecretKey, scope: Constant.ScopeTeacher, Website: "BI", schoolID: school_code.ToString(), standard: school_base.standard, roles: roles.ToArray(), permissions: permissions.ToArray(), ddDepts: depts.ToArray(), ddsub: ddbind.userid);
  359. }
  360. var (osblob_uri, osblob_sas) = roles.Contains("area") ? _azureStorage.GetBlobContainerSAS("teammodelos", BlobContainerSasPermissions.Write | BlobContainerSasPermissions.Read | BlobContainerSasPermissions.List | BlobContainerSasPermissions.Delete) : _azureStorage.GetBlobContainerSAS("teammodelos", BlobContainerSasPermissions.Read | BlobContainerSasPermissions.List);
  361. return Ok(new { state = 200, auth_token = auth_token, teacher = teacher, id_token = implicit_token.id_token, access_token = implicit_token.access_token, expires_in = implicit_token.expires_in, token_type = implicit_token.token_type, osblob_uri, osblob_sas });
  362. }
  363. catch (Exception ex)
  364. {
  365. await _dingDing.SendBotMsg($"BI,{_option.Location}, /common/login/get-teacherinfo \n{ex.Message}{ex.StackTrace}", GroupNames.成都开发測試群組);
  366. return BadRequest();
  367. }
  368. }
  369. /// <summary>
  370. /// 钉钉扫码登录获取扫码信息
  371. /// </summary>
  372. /// <param name="jsonElement"></param>
  373. /// <returns></returns>
  374. [ProducesDefaultResponseType]
  375. [HttpPost("get-ddscancode")]
  376. public async Task<IActionResult> GetDingDingScanCode(JsonElement jsonElement)
  377. {
  378. try
  379. {
  380. string appKey = _configuration["DingDingAuth:appKey"];
  381. string appSecret = _configuration["DingDingAuth:appSecret"];
  382. string divide = _configuration["CustomParam:SiteScope"];
  383. if (string.IsNullOrWhiteSpace(appKey) || string.IsNullOrWhiteSpace(appSecret))
  384. {
  385. return Ok(new { state = 0, message = "请检查配置钉钉的信息" });
  386. }
  387. //自己传的code
  388. if (!jsonElement.TryGetProperty("code", out JsonElement LoginTempCode)) return BadRequest();
  389. //获取access_token
  390. IDingTalkClient tokenClient = new DefaultDingTalkClient("https://oapi.dingtalk.com/gettoken");
  391. OapiGettokenRequest tokenRequest = new() { Appkey = appKey, Appsecret = appSecret };
  392. tokenRequest.SetHttpMethod("Get");
  393. OapiGettokenResponse tokenRespone = tokenClient.Execute(tokenRequest);
  394. if (tokenRespone.IsError) return BadRequest();
  395. string access_token = tokenRespone.AccessToken;
  396. //获取临时授权码 获取授权用户的个人信息
  397. DefaultDingTalkClient clientinfo = new("https://oapi.dingtalk.com/sns/getuserinfo_bycode");
  398. OapiSnsGetuserinfoBycodeRequest req = new() { TmpAuthCode = $"{LoginTempCode}" }; //通过扫描二维码,跳转到指定的Url后,向Url中追加Code临时授权码
  399. OapiSnsGetuserinfoBycodeResponse response = clientinfo.Execute(req, appKey, appSecret);
  400. if (response.Errcode.Equals(40078))
  401. {
  402. return Ok(new { state = 0, message = $"state:{response.Errcode};Err{response.Errmsg}/临时授权码过期请重新扫码" });
  403. }
  404. string unionid = response.UserInfo.Unionid;
  405. IDingTalkClient client2 = new DefaultDingTalkClient("https://oapi.dingtalk.com/topapi/user/getbyunionid"); //userid地址
  406. OapiUserGetbyunionidRequest byunionidRequest = new() { Unionid = unionid };
  407. OapiUserGetbyunionidResponse byunionidResponse = client2.Execute(byunionidRequest, access_token);
  408. if (byunionidResponse.IsError|| byunionidResponse.Errcode == 60121)
  409. {
  410. return Ok(new { state = 0, message = byunionidResponse.Errmsg });
  411. }
  412. // 根据userId获取用户信息
  413. string userid = byunionidResponse.Result.Userid;
  414. IDingTalkClient client3 = new DefaultDingTalkClient("https://oapi.dingtalk.com/topapi/v2/user/get");
  415. OapiV2UserGetRequest v2GetRequest = new()
  416. {
  417. Userid = userid,
  418. Language = "zh_CN"
  419. };
  420. v2GetRequest.SetHttpMethod("POST");
  421. OapiV2UserGetResponse v2GetResponse = client3.Execute(v2GetRequest, access_token);
  422. if (v2GetResponse.IsError)
  423. {
  424. return Ok(new { state = 0, message = "扫码登录失败" });
  425. }
  426. var table = _azureStorage.GetCloudTableClient().GetTableReference("BIDDUserInfo");
  427. List<DingDingUserInfo> ddusers = await table.FindListByDict<DingDingUserInfo>(new Dictionary<string, object>() { { "RowKey", $"{v2GetResponse.Result.Userid}" }, { "unionId", $"{v2GetResponse.Result.Unionid}" } });
  428. if (ddusers.Count > 0)
  429. {
  430. List<DingDingUserInfo> ddUserInfos = new List<DingDingUserInfo>();
  431. var id_token = "";
  432. string osblob_uri = null, osblob_sas = null;
  433. List<string> roles = new();//角色列表
  434. List<string> permissions = new List<string>();//权限列表
  435. foreach (var item in ddusers)
  436. {
  437. ddUserInfos.Add(item);
  438. }
  439. foreach (var item in ddUserInfos)
  440. {
  441. if (!string.IsNullOrEmpty(item.tmdId))
  442. {
  443. roles = !string.IsNullOrEmpty($"{item.roles}") ? new List<string>(item.roles.Split(",")) : new List<string>();
  444. permissions = !string.IsNullOrEmpty($"{item.permissions}") ? new List<string>(item.permissions.Split(",")) : new List<string>();
  445. ///在IES5 添加
  446. //id_token = JwtAuthExtension.CreateAuthToken(_option.HostName, item.tmdId?.ToString(), item.tmdName?.ToString(), item.picture?.ToString(), _option.JwtSecretKey, Website: "BI", scope: $"assist", roles: roles?.ToArray(), permissions: permissions?.ToArray(), ddsub: item.RowKey?.ToString());
  447. //自己写的
  448. id_token = JwtAuth.CreateAuthTokenBI(_option.HostName, item.tmdId?.ToString(), item.tmdName?.ToString(), item.picture?.ToString(), item.RowKey?.ToString(), item.name?.ToString(), item.avatar?.ToString(), _option.JwtSecretKey, scope: "assist", Website: "BI", roles: roles?.ToArray(), permissions: permissions?.ToArray(), expire:3);
  449. (osblob_uri, osblob_sas) = roles.Contains("assist") ? _azureStorage.GetBlobContainerSAS("teammodelos", BlobContainerSasPermissions.Write | BlobContainerSasPermissions.Read | BlobContainerSasPermissions.List | BlobContainerSasPermissions.Delete) : _azureStorage.GetBlobContainerSAS("teammodelos", BlobContainerSasPermissions.Read | BlobContainerSasPermissions.List);
  450. }
  451. else
  452. {
  453. return Ok(new { state = 201, ddUserInfos });
  454. }
  455. }
  456. return Ok(new { state = 200, ddUserInfos, id_token, roles, permissions, osblob_uri, osblob_sas });
  457. }
  458. else
  459. {
  460. DingDingUserInfo dingDingUserInfo = new ()
  461. {
  462. PartitionKey = divide,
  463. RowKey = v2GetResponse.Result.Userid,
  464. unionId = v2GetResponse.Result.Unionid,
  465. name = v2GetResponse.Result.Name,
  466. title = v2GetResponse.Result.Title,
  467. mobile = v2GetResponse.Result.Mobile,
  468. jobNumber = v2GetResponse.Result.JobNumber,
  469. pid = 0,
  470. deptId = 0,
  471. deptName = null,
  472. depts = string.Join(",", v2GetResponse.Result.DeptIdList.ToArray()),
  473. avatar = v2GetResponse.Result.Avatar,
  474. isAdmin = v2GetResponse.Result.Admin,
  475. tmdId = "",
  476. tmdName = "",
  477. tmdMobile = "",
  478. mail = "",
  479. picture = "",
  480. roles = "",
  481. permissions = "",
  482. };
  483. await table.Save<DingDingUserInfo>(dingDingUserInfo);
  484. return Ok(new { state = 400, ddUserId = dingDingUserInfo });
  485. }
  486. }
  487. catch (Exception ex)
  488. {
  489. await _dingDing.SendBotMsg($"BI, {_option.Location} /common/login/get-ddscancode \n {ex.Message}{ex.StackTrace}", GroupNames.成都开发測試群組);
  490. return BadRequest();
  491. }
  492. }
  493. /// <summary>
  494. /// 钉钉绑定醍摩豆
  495. /// </summary>
  496. /// <returns></returns>
  497. [ProducesDefaultResponseType]
  498. [AuthToken(Roles = "assist")]
  499. [HttpPost("binguser")]
  500. public async Task<IActionResult> BindUser(JsonElement jsonElement)
  501. {
  502. try
  503. {
  504. if (!jsonElement.TryGetProperty("mobile", out JsonElement moile)) return BadRequest();
  505. if (!jsonElement.TryGetProperty("partitionKey", out JsonElement partitionKey)) return BadRequest();
  506. if (!jsonElement.TryGetProperty("rowKey", out JsonElement userId)) return BadRequest();
  507. HttpClient httpClient = _http.CreateClient();
  508. string url = _configuration.GetValue<string>("HaBookAuth:CoreId:userinfo");
  509. HttpResponseMessage responseMessage = await httpClient.PostAsJsonAsync(url, moile);
  510. if (responseMessage.StatusCode == HttpStatusCode.OK)
  511. {
  512. var table = _azureStorage.GetCloudTableClient().GetTableReference("BIDDUserInfo");
  513. var temp = await responseMessage.Content.ReadAsStringAsync();
  514. if (temp.Length > 0)
  515. {
  516. List<DingDingUserInfo> ddUserInfos = new();
  517. List<JsonElement> itemjson = temp.ToObject<List<JsonElement>>();
  518. var tempUser = await table.FindListByDict<DingDingUserInfo>(new Dictionary<string, object> { { "PartitionKey", $"{partitionKey}" }, { "RowKey", $"{userId}" } });
  519. foreach (var item in itemjson)
  520. {
  521. foreach (var itemUser in tempUser)
  522. {
  523. var tmdId = item.GetProperty("id").ToString();
  524. var tmdName = item.GetProperty("name").ToString();
  525. itemUser.tmdId = tmdId;
  526. itemUser.tmdName = tmdName;
  527. itemUser.tmdMobile = item.GetProperty("mobile").ToString();
  528. itemUser.picture = item.GetProperty("picture").ToString();
  529. itemUser.mail = item.GetProperty("mail").ToString();
  530. //保存操作记录
  531. await _azureStorage.SaveLog("tabledd-update", $"{tmdName}【{tmdId}】醍摩豆账号和{itemUser.name}【{itemUser.RowKey}】钉钉账户绑定成功", _dingDing, httpContext: HttpContext);
  532. ddUserInfos.Add(itemUser);
  533. }
  534. }
  535. var dingDingUserInfos = await table.UpdateAll(ddUserInfos);
  536. return Ok(new { state = 200, ddUsers = dingDingUserInfos });
  537. }
  538. else return Ok(new { state = 400, message = "该手机没有注册提莫信息" });
  539. }
  540. else return Ok(new { state = responseMessage.StatusCode });
  541. }
  542. catch (Exception ex)
  543. {
  544. await _dingDing.SendBotMsg($"BI, {_option.Location} /common/login/binguser \n {ex.Message}{ex.StackTrace}", GroupNames.成都开发測試群組);
  545. return BadRequest();
  546. }
  547. }
  548. /// <summary>
  549. /// 获取钉钉信息详情绑定醍摩豆和钉钉信息 二合一
  550. /// </summary>
  551. /// <param name="jsonElement"></param>
  552. /// <returns></returns>
  553. [ProducesDefaultResponseType]
  554. [HttpPost("get-ddinfo")]
  555. public async Task<IActionResult> GetDingDingInfo(JsonElement jsonElement)
  556. {
  557. try
  558. {
  559. if (!jsonElement.TryGetProperty("mobile", out JsonElement moile)) return BadRequest();
  560. if (!jsonElement.TryGetProperty("partitionKey", out JsonElement partitionKey)) return BadRequest();
  561. if (!jsonElement.TryGetProperty("rowKey", out JsonElement userId)) return BadRequest();
  562. var table = _azureStorage.GetCloudTableClient().GetTableReference("BIDDUserInfo");
  563. var tempUser = await table.FindListByDict<DingDingUserInfo>(new Dictionary<string, object> { { "PartitionKey", $"{partitionKey}" }, { "RowKey", $"{userId}" } });
  564. List<string> roles = new();//角色列表
  565. List<string> permissions = new();//权限列表
  566. List<DingDingUserInfo> ddUserInfos = new();
  567. var id_token = "";
  568. foreach (var itemUser in tempUser)
  569. {
  570. if (!string.IsNullOrEmpty($"{itemUser.tmdId}") && !string.IsNullOrEmpty($"{itemUser.tmdName}"))
  571. {
  572. //roles = new List<string>(itemUser.roles.Split(new string[] { "," }, StringSplitOptions.RemoveEmptyEntries));
  573. roles = !string.IsNullOrEmpty($"{itemUser.roles}") ? new List<string>(itemUser.roles.Split(",")) : new List<string>();
  574. permissions = !string.IsNullOrEmpty($"{itemUser.permissions}") ? new List<string>(itemUser.permissions.Split(",")) : new List<string>();
  575. ddUserInfos.Add(itemUser);
  576. }
  577. else
  578. {
  579. HttpClient httpClient = _http.CreateClient();
  580. string url = _configuration.GetValue<string>("HaBookAuth:CoreId:userinfo");
  581. HttpResponseMessage responseMessage = await httpClient.PostAsJsonAsync(url, moile);
  582. if (responseMessage.StatusCode == HttpStatusCode.OK)
  583. {
  584. var temp = await responseMessage.Content.ReadAsStringAsync();
  585. if (temp.Length > 0)
  586. {
  587. List<JsonElement> itemjson = temp.ToObject<List<JsonElement>>();
  588. string tmdId = null;
  589. string tmdName = null;
  590. foreach (var item in itemjson)
  591. {
  592. tmdId = item.GetProperty("id").ToString();
  593. tmdName = item.GetProperty("name").ToString();
  594. itemUser.tmdId = tmdId?.ToString();
  595. itemUser.tmdName = tmdName?.ToString();
  596. itemUser.tmdMobile = item.GetProperty("mobile").ToString();
  597. itemUser.picture = item.GetProperty("picture").ToString();
  598. itemUser.mail = item.GetProperty("mail").ToString();
  599. roles = !string.IsNullOrEmpty($"{itemUser.roles}") ? new List<string>(itemUser.roles.Split(",")) : new List<string>();
  600. permissions = !string.IsNullOrEmpty($"{itemUser.permissions}") ? new List<string>(itemUser.permissions.Split(",")) : new List<string>();
  601. ddUserInfos.Add(itemUser);
  602. }
  603. ddUserInfos = await table.UpdateAll<DingDingUserInfo>(ddUserInfos);
  604. //保存操作记录
  605. await _azureStorage.SaveLog("tabledd-update", $"{tmdName}【{tmdId}】醍摩豆账号和{itemUser.name}【{itemUser.RowKey}】钉钉账户绑定成功", _dingDing, httpContext: HttpContext);
  606. }
  607. else return Ok(new { state = 400, message = "该手机没有注册醍摩豆账号信息" });
  608. }
  609. else return Ok(new { state = responseMessage.StatusCode });
  610. }
  611. ////在IES5 的基础上增加参数
  612. //id_token = JwtAuthExtension.CreateAuthToken(_option.HostName, itemUser.tmdId?.ToString(), itemUser.tmdName?.ToString(), itemUser.picture?.ToString(), _option.JwtSecretKey,Website: "BI", scope: $"assist", roles: roles?.ToArray(), permissions: permissions?.ToArray(), ddsub: itemUser.RowKey?.ToString());
  613. //自己写的
  614. id_token = JwtAuth.CreateAuthTokenBI(_option.HostName, itemUser.tmdId?.ToString(), itemUser.tmdName?.ToString(), itemUser.picture?.ToString(), itemUser.RowKey?.ToString(), itemUser.name?.ToString(), itemUser.avatar?.ToString(), _option.JwtSecretKey, scope: "assist", Website: "BI", roles: roles?.ToArray(), permissions: permissions?.ToArray(), expire: 3);
  615. }
  616. var (osblob_uri, osblob_sas) = roles.Contains("assist") ? _azureStorage.GetBlobContainerSAS("teammodelos", BlobContainerSasPermissions.Write | BlobContainerSasPermissions.Read | BlobContainerSasPermissions.List | BlobContainerSasPermissions.Delete) : _azureStorage.GetBlobContainerSAS("teammodelos", BlobContainerSasPermissions.Read | BlobContainerSasPermissions.List);
  617. return Ok(new { state = 200, ddUserInfos, id_token, roles, permissions, osblob_uri, osblob_sas });
  618. }
  619. catch (Exception ex)
  620. {
  621. await _dingDing.SendBotMsg($"BI,{_option.Location} /common/login/get-ddinfo \n {ex.Message}{ex.StackTrace}", GroupNames.成都开发測試群組);
  622. return BadRequest();
  623. }
  624. }
  625. public record DingDingbinds
  626. {
  627. public string type { get; set; }
  628. /// <summary>
  629. /// 所属部门id列表
  630. /// </summary>
  631. public List<long> deptIdList { get; set; }
  632. /// <summary>
  633. /// 职位名称
  634. /// </summary>
  635. public string title { get; set; }
  636. /// <summary>
  637. /// 钉钉用户名
  638. /// </summary>
  639. public string name { get; set; }
  640. /// <summary>
  641. /// 钉钉unionid
  642. /// </summary>
  643. public string unionid { get; set; }
  644. /// <summary>
  645. /// 钉钉ID
  646. /// </summary>
  647. public string userid { get; set; }
  648. }
  649. }
  650. }