LoginController.cs 43 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741
  1. using Azure.Cosmos;
  2. using DingTalk.Api;
  3. using DingTalk.Api.Request;
  4. using DingTalk.Api.Response;
  5. using Microsoft.AspNetCore.Http;
  6. using Microsoft.AspNetCore.Mvc;
  7. using Microsoft.Extensions.Configuration;
  8. using System;
  9. using System.Collections.Generic;
  10. using System.Linq;
  11. using System.Text.Json;
  12. using System.Threading.Tasks;
  13. using TEAMModelOS.SDK.DI;
  14. using TEAMModelOS.SDK.Models;
  15. using HTEXLib.COMM.Helpers;
  16. using TEAMModelOS.Models;
  17. using Microsoft.Extensions.Options;
  18. using TEAMModelOS.SDK.Extension;
  19. using TEAMModelOS.SDK.Models.Service;
  20. using Microsoft.AspNetCore.Authorization;
  21. using Azure.Storage.Blobs.Models;
  22. using System.IdentityModel.Tokens.Jwt;
  23. using System.Net.Http;
  24. using System.Text;
  25. using System.Net;
  26. using Newtonsoft.Json;
  27. using System.Collections;
  28. using Newtonsoft.Json.Linq;
  29. using TEAMModelOS.SDK.Models.Cosmos.BI;
  30. using Azure.Storage.Sas;
  31. using System.Net.Http.Json;
  32. using TEAMModelBI.Filter;
  33. using TEAMModelBI.Models.Extension;
  34. using TEAMModelOS.SDK;
  35. using Microsoft.AspNetCore.Hosting;
  36. using TEAMModelBI.Tool;
  37. using TEAMModelBI.DI.BIAzureStorage;
  38. using TEAMModelBI.Tool.Context;
  39. //using static DingTalk.Api.Response.OapiV2UserGetResponse;
  40. namespace TEAMModelBI.Controllers
  41. {
  42. [ProducesResponseType(StatusCodes.Status200OK)]
  43. [ProducesResponseType(StatusCodes.Status400BadRequest)]
  44. [Route("common/login")]
  45. [ApiController]
  46. public class LoginController : ControllerBase
  47. {
  48. private readonly IConfiguration _configuration;
  49. //数据容器
  50. private readonly AzureCosmosFactory _azureCosmos;
  51. //文件容器
  52. private readonly AzureStorageFactory _azureStorage;
  53. //钉钉提示信息
  54. private readonly DingDing _dingDing;
  55. private readonly Option _option;
  56. //隐式登录
  57. private readonly CoreAPIHttpService _coreAPIHttpService;
  58. private readonly IHttpClientFactory _http;
  59. private readonly IWebHostEnvironment _environment; //读取文件
  60. public LoginController(IConfiguration configuration, AzureCosmosFactory azureCosmos, AzureStorageFactory azureStorage, DingDing dingDing, IOptionsSnapshot<Option> option, CoreAPIHttpService coreAPIHttpService, IHttpClientFactory http, IWebHostEnvironment environment)
  61. {
  62. _configuration = configuration;
  63. _azureCosmos = azureCosmos;
  64. _azureStorage = azureStorage;
  65. _dingDing = dingDing;
  66. _option = option?.Value;
  67. _coreAPIHttpService = coreAPIHttpService;
  68. _http = http;
  69. _environment = environment;
  70. }
  71. /// <summary>
  72. /// 钉钉扫码登录获取扫码信息
  73. /// </summary>
  74. /// <param name="jsonElement"></param>
  75. /// <returns></returns>
  76. [ProducesDefaultResponseType]
  77. [HttpPost("get-ddscancode")]
  78. public async Task<IActionResult> GetDingDingScanCode(JsonElement jsonElement)
  79. {
  80. try
  81. {
  82. string appKey = _configuration["DingDingAuth:appKey"];
  83. string appSecret = _configuration["DingDingAuth:appSecret"];
  84. string proDeptId = _configuration["CustomParam:proDeptId"];
  85. //string divide = _configuration["CustomParam:SiteScope"];
  86. string divide = _option.Location;
  87. var cosmosClient = _azureCosmos.GetCosmosClient();
  88. string Website = "China";
  89. if (string.IsNullOrWhiteSpace(appKey) || string.IsNullOrWhiteSpace(appSecret))
  90. {
  91. return Ok(new { state = 0, msg = "请检查配置钉钉的信息" });
  92. }
  93. //自己传的code
  94. if (!jsonElement.TryGetProperty("code", out JsonElement LoginTempCode)) return BadRequest();
  95. jsonElement.TryGetProperty("site", out JsonElement site);
  96. var tableClient = _azureStorage.GetCloudTableClient();
  97. var blobClient = _azureStorage.GetBlobContainerClient(containerName: "0-public");
  98. if ($"{site}".Equals(BIConst.GlobalSite))
  99. {
  100. tableClient = _azureStorage.GetCloudTableClient(BIConst.GlobalSite);
  101. blobClient = _azureStorage.GetBlobContainerClient(containerName: "0-public", BIConst.GlobalSite);
  102. Website = BIConst.GlobalSite;
  103. }
  104. //获取access_token
  105. IDingTalkClient tokenClient = new DefaultDingTalkClient("https://oapi.dingtalk.com/gettoken");
  106. OapiGettokenRequest tokenRequest = new() { Appkey = appKey, Appsecret = appSecret };
  107. tokenRequest.SetHttpMethod("Get");
  108. OapiGettokenResponse tokenRespone = tokenClient.Execute(tokenRequest);
  109. if (tokenRespone.IsError) return BadRequest();
  110. string access_token = tokenRespone.AccessToken;
  111. //获取临时授权码 获取授权用户的个人信息
  112. DefaultDingTalkClient clientinfo = new("https://oapi.dingtalk.com/sns/getuserinfo_bycode");
  113. OapiSnsGetuserinfoBycodeRequest req = new() { TmpAuthCode = $"{LoginTempCode}" }; //通过扫描二维码,跳转到指定的Url后,向Url中追加Code临时授权码
  114. OapiSnsGetuserinfoBycodeResponse response = clientinfo.Execute(req, appKey, appSecret);
  115. if (response.Errcode.Equals(40078))
  116. {
  117. return Ok(new { state = 0, msg = $"state:{response.Errcode};Err{response.Errmsg}/临时授权码过期请重新扫码" });
  118. }
  119. string unionid = response.UserInfo.Unionid;
  120. IDingTalkClient client2 = new DefaultDingTalkClient("https://oapi.dingtalk.com/topapi/user/getbyunionid"); //userid地址
  121. OapiUserGetbyunionidRequest byunionidRequest = new() { Unionid = unionid };
  122. OapiUserGetbyunionidResponse byunionidResponse = client2.Execute(byunionidRequest, access_token);
  123. if (byunionidResponse.IsError || byunionidResponse.Errcode == 60121)
  124. {
  125. return Ok(new { state = 0, msg = byunionidResponse.Errmsg });
  126. }
  127. // 根据userId获取用户信息
  128. string userid = byunionidResponse.Result.Userid;
  129. IDingTalkClient client3 = new DefaultDingTalkClient("https://oapi.dingtalk.com/topapi/v2/user/get");
  130. OapiV2UserGetRequest v2GetRequest = new()
  131. {
  132. Userid = userid,
  133. Language = "zh_CN"
  134. };
  135. v2GetRequest.SetHttpMethod("POST");
  136. OapiV2UserGetResponse v2GetResponse = client3.Execute(v2GetRequest, access_token);
  137. if (v2GetResponse.IsError)
  138. {
  139. return Ok(new { state = 0, msg = "扫码登录失败" });
  140. }
  141. var table = _azureStorage.GetCloudTableClient().GetTableReference("BIDDUserInfo");
  142. var id_token = "";
  143. string osblob_uri = null, osblob_sas = null;
  144. List<string> roles = new();//角色列表
  145. List<string> permissions = new();//权限列表
  146. bool isExploit = false;
  147. List<DingDingUserInfo> ddusers = await table.FindListByDict<DingDingUserInfo>(new Dictionary<string, object>() { { "PartitionKey", $"{divide}"},{ "userId", $"{v2GetResponse.Result.Userid}" }, { "unionId", $"{v2GetResponse.Result.Unionid}" } });
  148. if (ddusers.Count > 0)
  149. {
  150. List<DingDingUserInfo> saveInfo = new();
  151. StringBuilder strMsg = new();
  152. foreach (var item in ddusers)
  153. {
  154. if (string.IsNullOrEmpty(item.tmdId))
  155. {
  156. var coreUser = await _coreAPIHttpService.GetUserInfo(new Dictionary<string, string> { { "key", $"{item.mobile}" } }, _option.Location, _configuration);
  157. if (coreUser.id != null)
  158. {
  159. item.tmdId = coreUser.id;
  160. item.tmdName = coreUser.name;
  161. item.tmdMobile = coreUser.mobile;
  162. item.picture = coreUser.picture;
  163. item.mail = coreUser.mail;
  164. }
  165. else return Ok(new { state = 404, msg = "依据钉钉手机号未找到醍摩豆账号!" });
  166. //List<string> mobiles = new() { $"{ item.mobile}" };
  167. //var content = new StringContent(mobiles.ToJsonString(), Encoding.UTF8, "application/json");
  168. //string json = await _coreAPIHttpService.GetUserInfos(content);
  169. //if (!string.IsNullOrEmpty(json))
  170. //{
  171. // List<JsonElement> json_id = json.ToObject<List<JsonElement>>();
  172. // foreach (var tmd in json_id)
  173. // {
  174. // item.tmdId = tmd.GetProperty("id").ToString();
  175. // item.tmdName = tmd.GetProperty("name").ToString();
  176. // item.tmdMobile = tmd.GetProperty("mobile").ToString();
  177. // item.picture = tmd.GetProperty("picture").ToString();
  178. // item.mail = tmd.GetProperty("mail").ToString();
  179. // }
  180. //}
  181. //else return Ok(new { state = 404, msg = "依据钉钉手机号未找到醍摩豆账号!" });
  182. strMsg.Append($"{item.tmdName}【{item.tmdId}】醍摩豆账号和{item.name}【{item.userId}】钉钉账户绑定成功");
  183. //保存操作记录
  184. //await _azureStorage.SaveBILog("tabledd-update", strMsg?.ToString(), _dingDing, httpContext: HttpContext, twebsite: Website, tid: item.tmdId, tname: item.tmdName);
  185. await AzureStorageBlobExtensions.SaveBILog(blobClient, tableClient, "tabledd-update", strMsg?.ToString(), _dingDing, httpContext: HttpContext, twebsite: Website, tid: item.tmdId, tname: item.tmdName);
  186. saveInfo.Add(item);
  187. }
  188. List<string> schoolIds = await CommonFind.FindSchoolIds(cosmosClient, item.tmdId);
  189. if (schoolIds.Count > 0)
  190. {
  191. item.schoolIds = string.Join("|", schoolIds);
  192. await table.SaveOrUpdate<DingDingUserInfo>(item);
  193. }
  194. roles = !string.IsNullOrEmpty($"{item.roles}") ? new List<string>(item.roles.Split(",")) : new List<string>();
  195. permissions = !string.IsNullOrEmpty($"{item.permissions}") ? new List<string>(item.permissions.Split(",")) : new List<string>();
  196. if (item.depts.Contains($"{proDeptId}")) isExploit = true;
  197. if (item.deptId == long.Parse($"{proDeptId}")) isExploit = true;
  198. if (item.pid == long.Parse($"{proDeptId}")) isExploit = true;
  199. //自己写的
  200. id_token = JwtAuth.CreateAuthTokenBI(_option.HostName, item.tmdId?.ToString(), item.tmdName?.ToString(), item.picture?.ToString(), _option.JwtSecretKey, scope: "assist", webSite: Website, isex: isExploit, item.userId?.ToString(), item.name?.ToString(), item.avatar?.ToString(), roles: roles?.ToArray(), permissions: permissions?.ToArray(), expire: 3);
  201. }
  202. if (saveInfo.Count > 0)
  203. {
  204. ddusers = await table.UpdateAll<DingDingUserInfo>(saveInfo);
  205. }
  206. }
  207. else
  208. {
  209. DingDingUserInfo ddUserInfo = new()
  210. {
  211. PartitionKey = divide,
  212. RowKey = DateTimeOffset.UtcNow.ToUnixTimeMilliseconds().ToString(),
  213. userId = v2GetResponse.Result.Userid,
  214. unionId = v2GetResponse.Result.Unionid,
  215. name = v2GetResponse.Result.Name,
  216. title = v2GetResponse.Result.Title,
  217. mobile = v2GetResponse.Result.Mobile,
  218. jobNumber = v2GetResponse.Result.JobNumber,
  219. pid = 0,
  220. deptId = 0,
  221. deptName = null,
  222. depts = string.Join(",", v2GetResponse.Result.DeptIdList.ToArray()),
  223. avatar = v2GetResponse.Result.Avatar,
  224. isAdmin = v2GetResponse.Result.Admin,
  225. roles = "assist",
  226. permissions = "abilitystandard-read,batcharea-read,batchschool-read,orgusers-read"
  227. };
  228. if (!string.IsNullOrEmpty($"{ddUserInfo.mobile}"))
  229. {
  230. var coreUser = await _coreAPIHttpService.GetUserInfo(new Dictionary<string, string> { { "key", $"{ddUserInfo.mobile}" } }, _option.Location, _configuration);
  231. if (coreUser.id != null) {
  232. ddUserInfo.tmdId = coreUser.id;
  233. ddUserInfo.tmdName = coreUser.name;
  234. ddUserInfo.tmdMobile = coreUser.mobile;
  235. ddUserInfo.picture = coreUser.mobile;
  236. ddUserInfo.mail = coreUser.mail;
  237. }
  238. else return Ok(new { state = 404, msg = "依据钉钉手机号未找到醍摩豆账号!" });
  239. //HttpClient httpClient = _http.CreateClient();
  240. //string url = _configuration.GetValue<string>("HaBookAuth:CoreId:userinfo");
  241. //List<string> mobiles = new() { $"{ ddUserInfo.mobile}" };
  242. //HttpResponseMessage responseMessage = await httpClient.PostAsJsonAsync(url, mobiles);
  243. //if (responseMessage.StatusCode == HttpStatusCode.OK)
  244. //{
  245. // string temp = responseMessage.Content.ReadAsStringAsync().Result;
  246. // List<JsonElement> json_id = temp.ToObject<List<JsonElement>>();
  247. // if (json_id.Count > 0)
  248. // {
  249. // foreach (var tmd in json_id)
  250. // {
  251. // ddUserInfo.tmdId = tmd.GetProperty("id").ToString();
  252. // ddUserInfo.tmdName = tmd.GetProperty("name").ToString();
  253. // ddUserInfo.tmdMobile = tmd.GetProperty("mobile").ToString();
  254. // ddUserInfo.picture = tmd.GetProperty("picture").ToString();
  255. // ddUserInfo.mail = tmd.GetProperty("mail").ToString();
  256. // }
  257. // }
  258. // else return Ok(new { state = 404, msg = "依据钉钉手机号未找到醍摩豆账号!" });
  259. //}
  260. }
  261. else return Ok(new { state = 404, msg = "钉钉手机号为空" });
  262. List<string> schoolIds = await CommonFind.FindSchoolIds(cosmosClient, ddUserInfo.tmdId);
  263. if (schoolIds.Count > 0)
  264. {
  265. ddUserInfo.schoolIds = string.Join("|", schoolIds);
  266. }
  267. ddUserInfo = await table.Save<DingDingUserInfo>(ddUserInfo);
  268. //保存操作记录
  269. //await _azureStorage.SaveBILog("tabledd-update", $"{ddUserInfo.tmdName}【{ddUserInfo.tmdId}】醍摩豆账号和{ddUserInfo.name}【{ddUserInfo.RowKey}】钉钉账户绑定成功", _dingDing, httpContext: HttpContext, tid: ddUserInfo.tmdId, tname: ddUserInfo.tmdName, twebsite: Website);
  270. await AzureStorageBlobExtensions.SaveBILog(blobClient, tableClient, "tabledd-update", $"{ddUserInfo.tmdName}【{ddUserInfo.tmdId}】醍摩豆账号和{ddUserInfo.name}【{ddUserInfo.RowKey}】钉钉账户绑定成功", _dingDing, httpContext: HttpContext, tid: ddUserInfo.tmdId, tname: ddUserInfo.tmdName, twebsite: Website);
  271. roles = !string.IsNullOrEmpty($"{ddUserInfo.roles}") ? new List<string>(ddUserInfo.roles.Split(",")) : new List<string>();
  272. permissions = !string.IsNullOrEmpty($"{ddUserInfo.permissions}") ? new List<string>(ddUserInfo.permissions.Split(",")) : new List<string>();
  273. if (ddUserInfo.depts.Contains($"{proDeptId}")) isExploit = true;
  274. if (ddUserInfo.deptId == long.Parse($"{proDeptId}")) isExploit = true;
  275. if (ddUserInfo.pid == long.Parse($"{proDeptId}")) isExploit = true;
  276. //自己写的
  277. id_token = JwtAuth.CreateAuthTokenBI(_option.HostName, ddUserInfo.tmdId?.ToString(), ddUserInfo.tmdName?.ToString(), ddUserInfo.picture?.ToString(), _option.JwtSecretKey, scope: "assist", webSite: Website, isex: isExploit, ddUserInfo.userId?.ToString(), ddUserInfo.name?.ToString(), ddUserInfo.avatar?.ToString(), roles: roles?.ToArray(), permissions: permissions?.ToArray(), expire: 3);
  278. }
  279. if (Website.Equals(BIConst.GlobalSite))
  280. {
  281. (osblob_uri, osblob_sas) = _azureStorage.GetBlobContainerSAS("teammodelos", BlobContainerSasPermissions.Write | BlobContainerSasPermissions.Read | BlobContainerSasPermissions.List | BlobContainerSasPermissions.Delete, BIConst.GlobalSite);
  282. }
  283. else
  284. {
  285. (osblob_uri, osblob_sas) = _azureStorage.GetBlobContainerSAS("teammodelos", BlobContainerSasPermissions.Write | BlobContainerSasPermissions.Read | BlobContainerSasPermissions.List | BlobContainerSasPermissions.Delete);
  286. }
  287. //(osblob_uri, osblob_sas) = roles.Contains("assist") ? _azureStorage.GetBlobContainerSAS("teammodelos", BlobContainerSasPermissions.Write | BlobContainerSasPermissions.Read | BlobContainerSasPermissions.List | BlobContainerSasPermissions.Delete) : _azureStorage.GetBlobContainerSAS("teammodelos", BlobContainerSasPermissions.Write | BlobContainerSasPermissions.Read | BlobContainerSasPermissions.List, BIConst.GlobalSite);
  288. return Ok(new { state = 200, ddUserInfos = ddusers, id_token, roles, permissions, osblob_uri, osblob_sas });
  289. }
  290. catch (Exception ex)
  291. {
  292. await _dingDing.SendBotMsg($"BI, {_option.Location} /common/login/get-ddscancode \n {ex.Message}\n{ex.StackTrace}", GroupNames.成都开发測試群組);
  293. return BadRequest();
  294. }
  295. }
  296. /// <summary>
  297. /// 钉钉绑定醍摩豆
  298. /// </summary>
  299. /// <returns></returns>
  300. [ProducesDefaultResponseType]
  301. [HttpPost("set-bind")]
  302. public async Task<IActionResult> BindUser(JsonElement jsonElement)
  303. {
  304. try
  305. {
  306. if (!jsonElement.TryGetProperty("partitionKey", out JsonElement partitionKey)) return BadRequest();
  307. if (!jsonElement.TryGetProperty("rowKey", out JsonElement userId)) return BadRequest();
  308. jsonElement.TryGetProperty("id_token", out JsonElement idtoken);
  309. jsonElement.TryGetProperty("mobile", out JsonElement mobile);
  310. jsonElement.TryGetProperty("site", out JsonElement site);
  311. string Website = "China";
  312. var tableClient = _azureStorage.GetCloudTableClient();
  313. var blobClient = _azureStorage.GetBlobContainerClient(containerName: "0-public");
  314. if ($"{site}".Equals(BIConst.GlobalSite))
  315. {
  316. tableClient = _azureStorage.GetCloudTableClient(BIConst.GlobalSite);
  317. blobClient = _azureStorage.GetBlobContainerClient(containerName: "0-public", BIConst.GlobalSite);
  318. Website = BIConst.GlobalSite;
  319. }
  320. HttpClient httpClient = _http.CreateClient();
  321. var table = _azureStorage.GetCloudTableClient().GetTableReference("BIDDUserInfo");
  322. var tempUser = await table.FindListByDict<DingDingUserInfo>(new Dictionary<string, object> { { "PartitionKey", $"{partitionKey}" }, { "userId", $"{userId}" } });
  323. var id_token = "";
  324. var auth_token = "";
  325. List<DingDingUserInfo> ddUserInfos = new();
  326. List<string> roles = new();//角色列表
  327. List<string> permissions = new();//权限列表
  328. foreach (var itemUser in tempUser)
  329. {
  330. if (!string.IsNullOrEmpty($"{idtoken}"))
  331. {
  332. JwtSecurityToken jwt = new JwtSecurityToken($"{idtoken}");
  333. var tmdId = jwt.Payload.Sub;
  334. jwt.Payload.TryGetValue("name", out object tmdName);
  335. jwt.Payload.TryGetValue("picture", out object picture);
  336. itemUser.tmdId = tmdId;
  337. itemUser.tmdName = $"{tmdName}";
  338. itemUser.tmdMobile = itemUser.mobile;
  339. itemUser.picture = $"{picture}";
  340. }
  341. if (!string.IsNullOrEmpty($"{mobile}"))
  342. {
  343. var coreUser = await _coreAPIHttpService.GetUserInfo(new Dictionary<string, string> { { "key", $"{mobile}" } }, _option.Location, _configuration);
  344. if (coreUser.id != null)
  345. {
  346. itemUser.tmdId = coreUser.id;
  347. itemUser.tmdName = coreUser.name;
  348. itemUser.tmdMobile = coreUser.mobile;
  349. itemUser.picture = coreUser.mobile;
  350. itemUser.mail = coreUser.mail;
  351. }
  352. else return Ok(new { state = 404, msg = "手机号未找到醍摩豆账户" });
  353. //string url = _configuration.GetValue<string>("HaBookAuth:CoreId:userinfo");
  354. //List<string> mobiles = new() { $"{mobile}" };
  355. //HttpResponseMessage responseMessage = await httpClient.PostAsJsonAsync(url, mobiles);
  356. //if (responseMessage.StatusCode == HttpStatusCode.OK)
  357. //{
  358. // var temp = await responseMessage.Content.ReadAsStringAsync();
  359. // if (temp.Length > 0)
  360. // {
  361. // List<JsonElement> itemjson = temp.ToObject<List<JsonElement>>();
  362. // foreach (var item in itemjson)
  363. // {
  364. // itemUser.tmdId = item.GetProperty("id").ToString();
  365. // itemUser.tmdName = item.GetProperty("name").ToString();
  366. // itemUser.tmdMobile = item.GetProperty("mobile").ToString();
  367. // itemUser.picture = item.GetProperty("picture").ToString();
  368. // itemUser.mail = item.GetProperty("mail").ToString();
  369. // }
  370. // }
  371. //}
  372. //else return Ok(new { state = 404, msg = "手机号未找到醍摩豆账户" });
  373. }
  374. if (string.IsNullOrEmpty($"{mobile}") && string.IsNullOrEmpty($"{idtoken}"))
  375. return Ok(new { state = 400, msg = "mobile、idtoken参数错误" });
  376. else
  377. {
  378. ddUserInfos.Add(itemUser);
  379. roles = !string.IsNullOrEmpty($"{itemUser.roles}") ? new List<string>(itemUser.roles.Split(",")) : new List<string>();
  380. //保存操作记录
  381. //await _azureStorage.SaveBILog("tabledd-update", $"{itemUser.tmdName}【{itemUser.tmdId}】醍摩豆账号和{itemUser.name}【{itemUser.userId}】钉钉账户绑定成功", _dingDing, tid: itemUser.tmdId, tname: itemUser.name, twebsite: Website, httpContext: HttpContext);
  382. await AzureStorageBlobExtensions.SaveBILog(blobClient, tableClient, "tabledd-update", $"{itemUser.tmdName}【{itemUser.tmdId}】醍摩豆账号和{itemUser.name}【{itemUser.userId}】钉钉账户绑定成功", _dingDing, tid: itemUser.tmdId, tname: itemUser.name, twebsite: Website, httpContext: HttpContext);
  383. id_token = JwtAuth.CreateAuthTokenBI(_option.HostName, itemUser.tmdId?.ToString(), itemUser.tmdName?.ToString(), itemUser.picture?.ToString(), _option.JwtSecretKey, scope: "assist", webSite: Website, isex: false, itemUser.userId?.ToString(), itemUser.name?.ToString(), itemUser.avatar?.ToString(), roles: roles?.ToArray(), permissions: permissions?.ToArray(), expire: 3);
  384. }
  385. }
  386. ddUserInfos = await table.UpdateAll(ddUserInfos);
  387. string osblob_uri = null, osblob_sas = null;
  388. if (Website.Equals(BIConst.GlobalSite))
  389. {
  390. (osblob_uri, osblob_sas) = _azureStorage.GetBlobContainerSAS("teammodelos", BlobContainerSasPermissions.Write | BlobContainerSasPermissions.Read | BlobContainerSasPermissions.List | BlobContainerSasPermissions.Delete, BIConst.GlobalSite);
  391. }
  392. else
  393. {
  394. (osblob_uri, osblob_sas) = _azureStorage.GetBlobContainerSAS("teammodelos", BlobContainerSasPermissions.Write | BlobContainerSasPermissions.Read | BlobContainerSasPermissions.List | BlobContainerSasPermissions.Delete);
  395. }
  396. //blob 访问权限
  397. //var (osblob_uri, osblob_sas) = roles.Contains("assist") ? _azureStorage.GetBlobContainerSAS("teammodelos", BlobContainerSasPermissions.Write | BlobContainerSasPermissions.Read | BlobContainerSasPermissions.List | BlobContainerSasPermissions.Delete) : _azureStorage.GetBlobContainerSAS("teammodelos", BlobContainerSasPermissions.Read | BlobContainerSasPermissions.List);
  398. return Ok(new { state = 200, ddUserInfos, id_token, roles, osblob_uri, osblob_sas });
  399. }
  400. catch (Exception ex)
  401. {
  402. await _dingDing.SendBotMsg($"BI, {_option.Location} /common/login/set-bind \n {ex.Message}\n{ex.StackTrace}", GroupNames.成都开发測試群組);
  403. return BadRequest();
  404. }
  405. }
  406. /// <summary>
  407. /// 获取钉钉信息详情绑定醍摩豆和钉钉信息 二合一
  408. /// </summary>
  409. /// <param name="jsonElement"></param>
  410. /// <returns></returns>
  411. [ProducesDefaultResponseType]
  412. [HttpPost("get-ddinfo")]
  413. public async Task<IActionResult> GetDingDingInfo(JsonElement jsonElement)
  414. {
  415. try
  416. {
  417. if (!jsonElement.TryGetProperty("mobile", out JsonElement moile)) return BadRequest();
  418. if (!jsonElement.TryGetProperty("partitionKey", out JsonElement partitionKey)) return BadRequest();
  419. if (!jsonElement.TryGetProperty("rowKey", out JsonElement userId)) return BadRequest();
  420. jsonElement.TryGetProperty("site", out JsonElement site);
  421. string Website = "China";
  422. var tableClient = _azureStorage.GetCloudTableClient();
  423. var blobClient = _azureStorage.GetBlobContainerClient(containerName: "0-public");
  424. if ($"{site}".Equals(BIConst.GlobalSite))
  425. {
  426. tableClient = _azureStorage.GetCloudTableClient(BIConst.GlobalSite);
  427. blobClient = _azureStorage.GetBlobContainerClient(containerName: "0-public", BIConst.GlobalSite);
  428. Website = BIConst.GlobalSite;
  429. }
  430. var table = tableClient.GetTableReference("BIDDUserInfo");
  431. var tempUser = await table.FindListByDict<DingDingUserInfo>(new Dictionary<string, object> { { "PartitionKey", $"{partitionKey}" }, { "userId", $"{userId}" } });
  432. List<string> roles = new();//角色列表
  433. List<string> permissions = new();//权限列表
  434. List<DingDingUserInfo> ddUserInfos = new();
  435. var id_token = "";
  436. foreach (var itemUser in tempUser)
  437. {
  438. if (!string.IsNullOrEmpty($"{itemUser.tmdId}") && !string.IsNullOrEmpty($"{itemUser.tmdName}"))
  439. {
  440. //roles = new List<string>(itemUser.roles.Split(new string[] { "," }, StringSplitOptions.RemoveEmptyEntries));
  441. roles = !string.IsNullOrEmpty($"{itemUser.roles}") ? new List<string>(itemUser.roles.Split(",")) : new List<string>();
  442. permissions = !string.IsNullOrEmpty($"{itemUser.permissions}") ? new List<string>(itemUser.permissions.Split(",")) : new List<string>();
  443. ddUserInfos.Add(itemUser);
  444. }
  445. else
  446. {
  447. var coreUser = await _coreAPIHttpService.GetUserInfo(new Dictionary<string, string> { { "key", $"{moile}" } }, _option.Location, _configuration);
  448. if (coreUser.id != null)
  449. {
  450. itemUser.tmdId = coreUser.id;
  451. itemUser.tmdName = coreUser.name;
  452. itemUser.tmdMobile = coreUser.mobile;
  453. itemUser.picture = coreUser.mobile;
  454. itemUser.mail = coreUser.mail;
  455. roles = !string.IsNullOrEmpty($"{itemUser.roles}") ? new List<string>(itemUser.roles.Split(",")) : new List<string>();
  456. permissions = !string.IsNullOrEmpty($"{itemUser.permissions}") ? new List<string>(itemUser.permissions.Split(",")) : new List<string>();
  457. ddUserInfos.Add(itemUser);
  458. await AzureStorageBlobExtensions.SaveBILog(blobClient, tableClient, "tabledd-update", $"{coreUser.name}【{coreUser.id}】醍摩豆账号和{itemUser.name}【{itemUser.userId}】钉钉账户绑定成功", _dingDing, tid: itemUser.tmdId, tname: itemUser.name, twebsite: Website, httpContext: HttpContext);
  459. }
  460. else return Ok(new { state = 400, message = "该手机没有注册醍摩豆账号信息" });
  461. //HttpClient httpClient = _http.CreateClient();
  462. //string url = _configuration.GetValue<string>("HaBookAuth:CoreId:userinfo");
  463. //HttpResponseMessage responseMessage = await httpClient.PostAsJsonAsync(url, moile);
  464. //if (responseMessage.StatusCode == HttpStatusCode.OK)
  465. //{
  466. // var temp = await responseMessage.Content.ReadAsStringAsync();
  467. // if (temp.Length > 0)
  468. // {
  469. // List<JsonElement> itemjson = temp.ToObject<List<JsonElement>>();
  470. // string tmdId = null;
  471. // string tmdName = null;
  472. // foreach (var item in itemjson)
  473. // {
  474. // tmdId = item.GetProperty("id").ToString();
  475. // tmdName = item.GetProperty("name").ToString();
  476. // itemUser.tmdId = tmdId?.ToString();
  477. // itemUser.tmdName = tmdName?.ToString();
  478. // itemUser.tmdMobile = item.GetProperty("mobile").ToString();
  479. // itemUser.picture = item.GetProperty("picture").ToString();
  480. // itemUser.mail = item.GetProperty("mail").ToString();
  481. // roles = !string.IsNullOrEmpty($"{itemUser.roles}") ? new List<string>(itemUser.roles.Split(",")) : new List<string>();
  482. // permissions = !string.IsNullOrEmpty($"{itemUser.permissions}") ? new List<string>(itemUser.permissions.Split(",")) : new List<string>();
  483. // ddUserInfos.Add(itemUser);
  484. // }
  485. // ddUserInfos = await table.UpdateAll<DingDingUserInfo>(ddUserInfos);
  486. // //保存操作记录
  487. // //await _azureStorage.SaveBILog("tabledd-update", $"{tmdName}【{tmdId}】醍摩豆账号和{itemUser.name}【{itemUser.userId}】钉钉账户绑定成功", _dingDing, tid: itemUser.tmdId, tname: itemUser.name, twebsite: Website, httpContext: HttpContext);
  488. // await AzureStorageBlobExtensions.SaveBILog(blobClient, tableClient, "tabledd-update", $"{tmdName}【{tmdId}】醍摩豆账号和{itemUser.name}【{itemUser.userId}】钉钉账户绑定成功", _dingDing, tid: itemUser.tmdId, tname: itemUser.name, twebsite: Website, httpContext: HttpContext);
  489. // }
  490. // else return Ok(new { state = 400, message = "该手机没有注册醍摩豆账号信息" });
  491. //}
  492. //else return Ok(new { state = responseMessage.StatusCode });
  493. }
  494. //自己写的
  495. id_token = JwtAuth.CreateAuthTokenBI(_option.HostName, itemUser.tmdId?.ToString(), itemUser.tmdName?.ToString(), itemUser.picture?.ToString(), _option.JwtSecretKey, scope: "assist", webSite: Website, isex: false, itemUser.userId?.ToString(), itemUser.name?.ToString(), itemUser.avatar?.ToString(), roles: roles?.ToArray(), permissions: permissions?.ToArray(), expire: 3);
  496. }
  497. await table.SaveOrUpdateAll<DingDingUserInfo>(ddUserInfos);
  498. string osblob_uri = null, osblob_sas = null;
  499. if (Website.Equals(BIConst.GlobalSite))
  500. {
  501. (osblob_uri, osblob_sas) = _azureStorage.GetBlobContainerSAS("teammodelos", BlobContainerSasPermissions.Write | BlobContainerSasPermissions.Read | BlobContainerSasPermissions.List | BlobContainerSasPermissions.Delete, BIConst.GlobalSite);
  502. }
  503. else
  504. {
  505. (osblob_uri, osblob_sas) = _azureStorage.GetBlobContainerSAS("teammodelos", BlobContainerSasPermissions.Write | BlobContainerSasPermissions.Read | BlobContainerSasPermissions.List | BlobContainerSasPermissions.Delete);
  506. }
  507. //var (osblob_uri, osblob_sas) = roles.Contains("assist") ? _azureStorage.GetBlobContainerSAS("teammodelos", BlobContainerSasPermissions.Write | BlobContainerSasPermissions.Read | BlobContainerSasPermissions.List | BlobContainerSasPermissions.Delete) : _azureStorage.GetBlobContainerSAS("teammodelos", BlobContainerSasPermissions.Read | BlobContainerSasPermissions.List);
  508. return Ok(new { state = 200, ddUserInfos, id_token, roles, permissions, osblob_uri, osblob_sas });
  509. }
  510. catch (Exception ex)
  511. {
  512. await _dingDing.SendBotMsg($"BI,{_option.Location} /common/login/get-ddinfo \n {ex.Message}\n{ex.StackTrace}", GroupNames.成都开发測試群組);
  513. return BadRequest();
  514. }
  515. }
  516. /// <summary>
  517. /// 企业登录
  518. /// </summary>
  519. /// <param name="jsonElement"></param>
  520. /// <returns></returns>
  521. [ProducesDefaultResponseType]
  522. [HttpPost("get-commpany")]
  523. public async Task<IActionResult> GetCommpanyLogin(JsonElement jsonElement)
  524. {
  525. if (!jsonElement.TryGetProperty("account", out JsonElement accout)) return BadRequest();
  526. if (!jsonElement.TryGetProperty("password", out JsonElement password)) return BadRequest();
  527. jsonElement.TryGetProperty("site", out JsonElement site);
  528. string Website = "China";
  529. var cosmosClient = _azureCosmos.GetCosmosClient();
  530. var tableClient = _azureStorage.GetCloudTableClient();
  531. var blobClient = _azureStorage.GetBlobContainerClient(containerName: "0-public");
  532. if ($"{site}".Equals(BIConst.GlobalSite))
  533. {
  534. cosmosClient = _azureCosmos.GetCosmosClient(name: BIConst.GlobalSite);
  535. tableClient = _azureStorage.GetCloudTableClient(BIConst.GlobalSite);
  536. blobClient = _azureStorage.GetBlobContainerClient(containerName: "0-public", BIConst.GlobalSite);
  537. Website = BIConst.GlobalSite;
  538. }
  539. StringBuilder sqlTxt = new($"select value(c) from c");
  540. var temps = $"{accout}".Contains($"@");
  541. if (temps)
  542. sqlTxt.Append($" where c.emall='{accout}'");
  543. else
  544. sqlTxt.Append($" where c.mobile='{accout}'");
  545. Company company = new();
  546. List<Company> companies = new();
  547. string id_token = "";
  548. await foreach (var item in cosmosClient.GetContainer("TEAMModelOS", "Normal").GetItemQueryIterator<Company>(queryText: sqlTxt.ToString(), requestOptions: new QueryRequestOptions() { PartitionKey = new PartitionKey("Company") }))
  549. {
  550. companies.Add(item);
  551. }
  552. if (companies.Count > 0)
  553. {
  554. foreach (var item in companies)
  555. {
  556. var hashedPw = Utils.HashedPassword(password.ToString(), item.salt.ToString());
  557. if (hashedPw.Equals(item.password))
  558. {
  559. company = item;
  560. id_token = JwtAuth.CreateAuthTokenBI(_option.HostName, item.id?.ToString(), item.name?.ToString(), company.picture?.ToString(), _option.JwtSecretKey, scope: "company", webSite: Website, expire: 3);
  561. }
  562. }
  563. }
  564. else return Ok(new { state = 404 });
  565. //保存操作记录
  566. //await _azureStorage.SaveBILog("tabledd-update", $"{company.name}【{company.id}】登录商务智能开放平台", _dingDing, tid: company.id, tname: company.name, twebsite: "BI", httpContext: HttpContext);
  567. await AzureStorageBlobExtensions.SaveBILog(blobClient, tableClient, "tabledd-update", $"{company.name}【{company.id}】登录商务智能开放平台", _dingDing, tid: company.id, tname: company.name, twebsite: Website?.ToString(), httpContext: HttpContext);
  568. return Ok(new { error = 200, id_token, company });
  569. }
  570. /// <summary>
  571. /// 企业注册信息
  572. /// </summary>
  573. /// <param name="jsonElement"></param>
  574. /// <returns></returns>
  575. [HttpPost("set-registered")]
  576. public async Task<IActionResult> SetRegistered(JsonElement jsonElement)
  577. {
  578. if (!jsonElement.TryGetProperty("name", out JsonElement name)) return BadRequest();
  579. if (!jsonElement.TryGetProperty("credit", out JsonElement credit)) return BadRequest();
  580. if (!jsonElement.TryGetProperty("mobile", out JsonElement mobile)) return BadRequest();
  581. if (!jsonElement.TryGetProperty("password", out JsonElement password)) return BadRequest();
  582. jsonElement.TryGetProperty("site", out JsonElement site);
  583. string Website = "China";
  584. var cosmosClient = _azureCosmos.GetCosmosClient();
  585. var tableClient = _azureStorage.GetCloudTableClient();
  586. var blobClient = _azureStorage.GetBlobContainerClient(containerName: "0-public");
  587. if ($"{site}".Equals(BIConst.GlobalSite))
  588. {
  589. cosmosClient = _azureCosmos.GetCosmosClient(name: BIConst.GlobalSite);
  590. tableClient = _azureStorage.GetCloudTableClient(BIConst.GlobalSite);
  591. blobClient = _azureStorage.GetBlobContainerClient(containerName: "0-public", BIConst.GlobalSite);
  592. Website = BIConst.GlobalSite;
  593. }
  594. string salt = Utils.CreatSaltString(8);
  595. string sqltxt = $"select value(c) from c where c.mobile='{mobile}'";
  596. await foreach (var item in cosmosClient.GetContainer("TEAMModelOS", "Normal").GetItemQueryStreamIterator(queryText: sqltxt, requestOptions: new QueryRequestOptions() { PartitionKey = new PartitionKey("Company") }))
  597. {
  598. using var json = await JsonDocument.ParseAsync(item.ContentStream);
  599. if (json.RootElement.TryGetProperty("_count", out JsonElement count) && count.GetUInt16() > 0)
  600. {
  601. return Ok(new { state = 201, msg = "手机号已存在," });
  602. }
  603. }
  604. CreateSchoolInfo createCompanyCode = new CreateSchoolInfo()
  605. {
  606. province = "",
  607. id = "",
  608. name = $"{name}",
  609. city = "",
  610. aname = "",
  611. createCount = 0,
  612. };
  613. //生成企业ID
  614. bool tempStaus = true;
  615. do
  616. {
  617. createCompanyCode = await SchoolCode.GenerateSchoolCode(createCompanyCode, _dingDing, _environment);
  618. var companyState = await cosmosClient.GetContainer("TEAMModelOS", "Normal").ReadItemStreamAsync($"{createCompanyCode.id}", new PartitionKey("Company"));
  619. if (companyState.Status != 200) tempStaus = false;
  620. else createCompanyCode.createCount = createCompanyCode.createCount >= 3 ? createCompanyCode.createCount = 3 : createCompanyCode.createCount += 1;
  621. } while (tempStaus);
  622. Company company = new() { name = $"{name}", credit = $"{credit}", mobile = $"{mobile}", salt = salt, password = Utils.HashedPassword($"{password}", salt), pk = "Company", code = "Company", createTime = DateTimeOffset.UtcNow.ToUnixTimeMilliseconds() };
  623. company = await cosmosClient.GetContainer("TEAMModelOS", "Normal").CreateItemAsync<Company>(company, new PartitionKey("Company"));
  624. //保存操作记录
  625. //await _azureStorage.SaveBILog("tabledd-update", $"{company.name}【{company.id}】注册商务智能开放平台", _dingDing, tid: company.id, tname: company.name, twebsite: "BI", httpContext: HttpContext);
  626. await AzureStorageBlobExtensions.SaveBILog(blobClient, tableClient, "tabledd-update", $"{company.name}【{company.id}】注册商务智能开放平台", _dingDing, tid: company.id, tname: company.name, twebsite: Website?.ToString(), httpContext: HttpContext);
  627. return Ok(new { state = 200, company });
  628. }
  629. public record DingDingbinds
  630. {
  631. public string type { get; set; }
  632. /// <summary>
  633. /// 所属部门id列表
  634. /// </summary>
  635. public List<long> deptIdList { get; set; }
  636. /// <summary>
  637. /// 职位名称
  638. /// </summary>
  639. public string title { get; set; }
  640. /// <summary>
  641. /// 钉钉用户名
  642. /// </summary>
  643. public string name { get; set; }
  644. /// <summary>
  645. /// 钉钉unionid
  646. /// </summary>
  647. public string unionid { get; set; }
  648. /// <summary>
  649. /// 钉钉ID
  650. /// </summary>
  651. public string userid { get; set; }
  652. }
  653. }
  654. }