LoginController.cs 44 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747
  1. using Azure.Cosmos;
  2. using DingTalk.Api;
  3. using DingTalk.Api.Request;
  4. using DingTalk.Api.Response;
  5. using Microsoft.AspNetCore.Http;
  6. using Microsoft.AspNetCore.Mvc;
  7. using Microsoft.Extensions.Configuration;
  8. using System;
  9. using System.Collections.Generic;
  10. using System.Linq;
  11. using System.Text.Json;
  12. using System.Threading.Tasks;
  13. using TEAMModelOS.SDK.DI;
  14. using TEAMModelOS.SDK.Models;
  15. using HTEXLib.COMM.Helpers;
  16. using TEAMModelOS.Models;
  17. using Microsoft.Extensions.Options;
  18. using TEAMModelOS.SDK.Extension;
  19. using TEAMModelOS.SDK.Models.Service;
  20. using Microsoft.AspNetCore.Authorization;
  21. using Azure.Storage.Blobs.Models;
  22. using System.IdentityModel.Tokens.Jwt;
  23. using System.Net.Http;
  24. using System.Text;
  25. using System.Net;
  26. using Newtonsoft.Json;
  27. using System.Collections;
  28. using Newtonsoft.Json.Linq;
  29. using TEAMModelOS.SDK.Models.Cosmos.BI;
  30. using Azure.Storage.Sas;
  31. using System.Net.Http.Json;
  32. using TEAMModelBI.Filter;
  33. using TEAMModelBI.Models.Extension;
  34. using TEAMModelOS.SDK;
  35. using Microsoft.AspNetCore.Hosting;
  36. using TEAMModelBI.Tool;
  37. using TEAMModelBI.DI.BIAzureStorage;
  38. using TEAMModelBI.Tool.Context;
  39. using TEAMModelOS.SDK.Models.Table;
  40. using TEAMModelOS.SDK.Context.Constant;
  41. //using static DingTalk.Api.Response.OapiV2UserGetResponse;
  42. namespace TEAMModelBI.Controllers
  43. {
  44. [ProducesResponseType(StatusCodes.Status200OK)]
  45. [ProducesResponseType(StatusCodes.Status400BadRequest)]
  46. [Route("common/login")]
  47. [ApiController]
  48. public class LoginController : ControllerBase
  49. {
  50. private readonly IConfiguration _configuration;
  51. //数据容器
  52. private readonly AzureCosmosFactory _azureCosmos;
  53. //文件容器
  54. private readonly AzureStorageFactory _azureStorage;
  55. //钉钉提示信息
  56. private readonly DingDing _dingDing;
  57. private readonly Option _option;
  58. //隐式登录
  59. private readonly CoreAPIHttpService _coreAPIHttpService;
  60. private readonly IHttpClientFactory _http;
  61. private readonly IWebHostEnvironment _environment; //读取文件
  62. public LoginController(IConfiguration configuration, AzureCosmosFactory azureCosmos, AzureStorageFactory azureStorage, DingDing dingDing, IOptionsSnapshot<Option> option, CoreAPIHttpService coreAPIHttpService, IHttpClientFactory http, IWebHostEnvironment environment)
  63. {
  64. _configuration = configuration;
  65. _azureCosmos = azureCosmos;
  66. _azureStorage = azureStorage;
  67. _dingDing = dingDing;
  68. _option = option?.Value;
  69. _coreAPIHttpService = coreAPIHttpService;
  70. _http = http;
  71. _environment = environment;
  72. }
  73. /// <summary>
  74. /// 钉钉扫码登录获取扫码信息
  75. /// </summary>
  76. /// <param name="jsonElement"></param>
  77. /// <returns></returns>
  78. [ProducesDefaultResponseType]
  79. [HttpPost("get-ddscancode")]
  80. public async Task<IActionResult> GetDingDingScanCode(JsonElement jsonElement)
  81. {
  82. try
  83. {
  84. string appKey = _configuration["DingDingAuth:appKey"];
  85. string appSecret = _configuration["DingDingAuth:appSecret"];
  86. string proDeptId = _configuration["CustomParam:proDeptId"];
  87. //string divide = _configuration["CustomParam:SiteScope"];
  88. string divide = _option.Location;
  89. var cosmosClient = _azureCosmos.GetCosmosClient();
  90. string Website = "China";
  91. if (string.IsNullOrWhiteSpace(appKey) || string.IsNullOrWhiteSpace(appSecret))
  92. {
  93. return Ok(new { state = 0, msg = "请检查配置钉钉的信息" });
  94. }
  95. //自己传的code
  96. if (!jsonElement.TryGetProperty("code", out JsonElement LoginTempCode)) return BadRequest();
  97. jsonElement.TryGetProperty("site", out JsonElement site);
  98. var tableClient = _azureStorage.GetCloudTableClient();
  99. var blobClient = _azureStorage.GetBlobContainerClient(containerName: "0-public");
  100. if ($"{site}".Equals(BIConst.Global))
  101. {
  102. tableClient = _azureStorage.GetCloudTableClient(BIConst.Global);
  103. blobClient = _azureStorage.GetBlobContainerClient(containerName: "0-public", BIConst.Global);
  104. Website = BIConst.Global;
  105. }
  106. //获取access_token
  107. IDingTalkClient tokenClient = new DefaultDingTalkClient("https://oapi.dingtalk.com/gettoken");
  108. OapiGettokenRequest tokenRequest = new() { Appkey = appKey, Appsecret = appSecret };
  109. tokenRequest.SetHttpMethod("Get");
  110. OapiGettokenResponse tokenRespone = tokenClient.Execute(tokenRequest);
  111. if (tokenRespone.IsError) return BadRequest();
  112. string access_token = tokenRespone.AccessToken;
  113. //获取临时授权码 获取授权用户的个人信息
  114. DefaultDingTalkClient clientinfo = new("https://oapi.dingtalk.com/sns/getuserinfo_bycode");
  115. OapiSnsGetuserinfoBycodeRequest req = new() { TmpAuthCode = $"{LoginTempCode}" }; //通过扫描二维码,跳转到指定的Url后,向Url中追加Code临时授权码
  116. OapiSnsGetuserinfoBycodeResponse response = clientinfo.Execute(req, appKey, appSecret);
  117. if (response.Errcode.Equals(40078))
  118. {
  119. return Ok(new { state = 0, msg = $"state:{response.Errcode};Err{response.Errmsg}/临时授权码过期请重新扫码" });
  120. }
  121. string unionid = response.UserInfo.Unionid;
  122. IDingTalkClient client2 = new DefaultDingTalkClient("https://oapi.dingtalk.com/topapi/user/getbyunionid"); //userid地址
  123. OapiUserGetbyunionidRequest byunionidRequest = new() { Unionid = unionid };
  124. OapiUserGetbyunionidResponse byunionidResponse = client2.Execute(byunionidRequest, access_token);
  125. if (byunionidResponse.IsError || byunionidResponse.Errcode == 60121)
  126. {
  127. return Ok(new { state = 0, msg = byunionidResponse.Errmsg });
  128. }
  129. // 根据userId获取用户信息
  130. string userid = byunionidResponse.Result.Userid;
  131. IDingTalkClient client3 = new DefaultDingTalkClient("https://oapi.dingtalk.com/topapi/v2/user/get");
  132. OapiV2UserGetRequest v2GetRequest = new()
  133. {
  134. Userid = userid,
  135. Language = "zh_CN"
  136. };
  137. v2GetRequest.SetHttpMethod("POST");
  138. OapiV2UserGetResponse v2GetResponse = client3.Execute(v2GetRequest, access_token);
  139. if (v2GetResponse.IsError)
  140. {
  141. return Ok(new { state = 0, msg = "扫码登录失败" });
  142. }
  143. var table = _azureStorage.GetCloudTableClient().GetTableReference("BIDDUserInfo");
  144. var id_token = "";
  145. string osblob_uri = null, osblob_sas = null;
  146. List<string> roles = new();//角色列表
  147. List<string> permissions = new();//权限列表
  148. bool isExploit = false;
  149. List<DingDingUserInfo> ddusers = await table.FindListByDict<DingDingUserInfo>(new Dictionary<string, object>() { { "PartitionKey", $"{divide}"},{ "userId", $"{v2GetResponse.Result.Userid}" }, { "unionId", $"{v2GetResponse.Result.Unionid}" } });
  150. if (ddusers.Count > 0)
  151. {
  152. List<DingDingUserInfo> saveInfo = new();
  153. StringBuilder strMsg = new();
  154. foreach (var item in ddusers)
  155. {
  156. if (string.IsNullOrEmpty(item.tmdId))
  157. {
  158. var coreUser = await _coreAPIHttpService.GetUserInfo(new Dictionary<string, string> { { "key", $"{item.mobile}" } }, _option.Location, _configuration);
  159. if (coreUser != null && coreUser.id != null)
  160. {
  161. item.tmdId = coreUser.id;
  162. item.tmdName = coreUser.name;
  163. item.tmdMobile = coreUser.mobile;
  164. item.picture = coreUser.picture;
  165. item.mail = coreUser.mail;
  166. }
  167. else return Ok(new { state = 404, msg = "依据钉钉手机号未找到醍摩豆账号!" });
  168. //List<string> mobiles = new() { $"{ item.mobile}" };
  169. //var content = new StringContent(mobiles.ToJsonString(), Encoding.UTF8, "application/json");
  170. //string json = await _coreAPIHttpService.GetUserInfos(content);
  171. //if (!string.IsNullOrEmpty(json))
  172. //{
  173. // List<JsonElement> json_id = json.ToObject<List<JsonElement>>();
  174. // foreach (var tmd in json_id)
  175. // {
  176. // item.tmdId = tmd.GetProperty("id").ToString();
  177. // item.tmdName = tmd.GetProperty("name").ToString();
  178. // item.tmdMobile = tmd.GetProperty("mobile").ToString();
  179. // item.picture = tmd.GetProperty("picture").ToString();
  180. // item.mail = tmd.GetProperty("mail").ToString();
  181. // }
  182. //}
  183. //else return Ok(new { state = 404, msg = "依据钉钉手机号未找到醍摩豆账号!" });
  184. strMsg.Append($"{item.tmdName}【{item.tmdId}】醍摩豆账号和{item.name}【{item.userId}】钉钉账户绑定成功");
  185. //保存操作记录
  186. //await _azureStorage.SaveBILog("tabledd-update", strMsg?.ToString(), _dingDing, httpContext: HttpContext, twebsite: Website, tid: item.tmdId, tname: item.tmdName);
  187. await AzureStorageBlobExtensions.SaveBILog(blobClient, tableClient, "tabledd-update", strMsg?.ToString(), _dingDing, httpContext: HttpContext, twebsite: Website, tid: item.tmdId, tname: item.tmdName);
  188. saveInfo.Add(item);
  189. }
  190. List<string> schoolIds = await CommonFind.FindSchoolIds(cosmosClient, item.tmdId);
  191. if (schoolIds.Count > 0)
  192. {
  193. item.schoolIds = string.Join("|", schoolIds);
  194. await table.SaveOrUpdate<DingDingUserInfo>(item);
  195. }
  196. roles = !string.IsNullOrEmpty($"{item.roles}") ? new List<string>(item.roles.Split(",")) : new List<string>();
  197. permissions = !string.IsNullOrEmpty($"{item.permissions}") ? new List<string>(item.permissions.Split(",")) : new List<string>();
  198. if (item.depts.Contains($"{proDeptId}")) isExploit = true;
  199. if (item.deptId == long.Parse($"{proDeptId}")) isExploit = true;
  200. if (item.pid == long.Parse($"{proDeptId}")) isExploit = true;
  201. //自己写的
  202. id_token = JwtAuth.CreateAuthTokenBI(_option.HostName, item.tmdId?.ToString(), item.tmdName?.ToString(), item.picture?.ToString(), _option.JwtSecretKey, scope: "assist", webSite: Website, isex: isExploit, item.userId?.ToString(), item.name?.ToString(), item.avatar?.ToString(), roles: roles?.ToArray(), permissions: permissions?.ToArray(), expire: 3);
  203. }
  204. if (saveInfo.Count > 0)
  205. {
  206. ddusers = await table.UpdateAll<DingDingUserInfo>(saveInfo);
  207. }
  208. }
  209. else
  210. {
  211. DingDingUserInfo ddUserInfo = new()
  212. {
  213. PartitionKey = divide,
  214. RowKey = DateTimeOffset.UtcNow.ToUnixTimeMilliseconds().ToString(),
  215. userId = v2GetResponse.Result.Userid,
  216. unionId = v2GetResponse.Result.Unionid,
  217. name = v2GetResponse.Result.Name,
  218. title = v2GetResponse.Result.Title,
  219. mobile = v2GetResponse.Result.Mobile,
  220. jobNumber = v2GetResponse.Result.JobNumber,
  221. pid = 0,
  222. deptId = 0,
  223. deptName = null,
  224. depts = string.Join(",", v2GetResponse.Result.DeptIdList.ToArray()),
  225. avatar = v2GetResponse.Result.Avatar,
  226. isAdmin = v2GetResponse.Result.Admin,
  227. roles = "assist",
  228. permissions = "abilitystandard-read,batcharea-read,batchschool-read,orgusers-read"
  229. };
  230. if (!string.IsNullOrEmpty($"{ddUserInfo.mobile}"))
  231. {
  232. var coreUser = await _coreAPIHttpService.GetUserInfo(new Dictionary<string, string> { { "key", $"{ddUserInfo.mobile}" } }, _option.Location, _configuration);
  233. if (coreUser != null && coreUser.id != null) {
  234. ddUserInfo.tmdId = coreUser.id;
  235. ddUserInfo.tmdName = coreUser.name;
  236. ddUserInfo.tmdMobile = coreUser.mobile;
  237. ddUserInfo.picture = coreUser.mobile;
  238. ddUserInfo.mail = coreUser.mail;
  239. }
  240. else return Ok(new { state = 404, msg = "依据钉钉手机号未找到醍摩豆账号!" });
  241. //HttpClient httpClient = _http.CreateClient();
  242. //string url = _configuration.GetValue<string>("HaBookAuth:CoreId:userinfo");
  243. //List<string> mobiles = new() { $"{ ddUserInfo.mobile}" };
  244. //HttpResponseMessage responseMessage = await httpClient.PostAsJsonAsync(url, mobiles);
  245. //if (responseMessage.StatusCode == HttpStatusCode.OK)
  246. //{
  247. // string temp = responseMessage.Content.ReadAsStringAsync().Result;
  248. // List<JsonElement> json_id = temp.ToObject<List<JsonElement>>();
  249. // if (json_id.Count > 0)
  250. // {
  251. // foreach (var tmd in json_id)
  252. // {
  253. // ddUserInfo.tmdId = tmd.GetProperty("id").ToString();
  254. // ddUserInfo.tmdName = tmd.GetProperty("name").ToString();
  255. // ddUserInfo.tmdMobile = tmd.GetProperty("mobile").ToString();
  256. // ddUserInfo.picture = tmd.GetProperty("picture").ToString();
  257. // ddUserInfo.mail = tmd.GetProperty("mail").ToString();
  258. // }
  259. // }
  260. // else return Ok(new { state = 404, msg = "依据钉钉手机号未找到醍摩豆账号!" });
  261. //}
  262. }
  263. else return Ok(new { state = 404, msg = "钉钉手机号为空" });
  264. List<string> schoolIds = await CommonFind.FindSchoolIds(cosmosClient, ddUserInfo.tmdId);
  265. if (schoolIds.Count > 0)
  266. {
  267. ddUserInfo.schoolIds = string.Join("|", schoolIds);
  268. }
  269. ddUserInfo = await table.Save<DingDingUserInfo>(ddUserInfo);
  270. //保存操作记录
  271. //await _azureStorage.SaveBILog("tabledd-update", $"{ddUserInfo.tmdName}【{ddUserInfo.tmdId}】醍摩豆账号和{ddUserInfo.name}【{ddUserInfo.RowKey}】钉钉账户绑定成功", _dingDing, httpContext: HttpContext, tid: ddUserInfo.tmdId, tname: ddUserInfo.tmdName, twebsite: Website);
  272. await AzureStorageBlobExtensions.SaveBILog(blobClient, tableClient, "tabledd-update", $"{ddUserInfo.tmdName}【{ddUserInfo.tmdId}】醍摩豆账号和{ddUserInfo.name}【{ddUserInfo.RowKey}】钉钉账户绑定成功", _dingDing, httpContext: HttpContext, tid: ddUserInfo.tmdId, tname: ddUserInfo.tmdName, twebsite: Website);
  273. roles = !string.IsNullOrEmpty($"{ddUserInfo.roles}") ? new List<string>(ddUserInfo.roles.Split(",")) : new List<string>();
  274. permissions = !string.IsNullOrEmpty($"{ddUserInfo.permissions}") ? new List<string>(ddUserInfo.permissions.Split(",")) : new List<string>();
  275. if (ddUserInfo.depts.Contains($"{proDeptId}")) isExploit = true;
  276. if (ddUserInfo.deptId == long.Parse($"{proDeptId}")) isExploit = true;
  277. if (ddUserInfo.pid == long.Parse($"{proDeptId}")) isExploit = true;
  278. //自己写的
  279. id_token = JwtAuth.CreateAuthTokenBI(_option.HostName, ddUserInfo.tmdId?.ToString(), ddUserInfo.tmdName?.ToString(), ddUserInfo.picture?.ToString(), _option.JwtSecretKey, scope: "assist", webSite: Website, isex: isExploit, ddUserInfo.userId?.ToString(), ddUserInfo.name?.ToString(), ddUserInfo.avatar?.ToString(), roles: roles?.ToArray(), permissions: permissions?.ToArray(), expire: 3);
  280. }
  281. if (Website.Equals(BIConst.Global))
  282. {
  283. (osblob_uri, osblob_sas) = _azureStorage.GetBlobContainerSAS("teammodelos", BlobContainerSasPermissions.Write | BlobContainerSasPermissions.Read | BlobContainerSasPermissions.List | BlobContainerSasPermissions.Delete, BIConst.Global);
  284. }
  285. else
  286. {
  287. (osblob_uri, osblob_sas) = _azureStorage.GetBlobContainerSAS("teammodelos", BlobContainerSasPermissions.Write | BlobContainerSasPermissions.Read | BlobContainerSasPermissions.List | BlobContainerSasPermissions.Delete);
  288. }
  289. //(osblob_uri, osblob_sas) = roles.Contains("assist") ? _azureStorage.GetBlobContainerSAS("teammodelos", BlobContainerSasPermissions.Write | BlobContainerSasPermissions.Read | BlobContainerSasPermissions.List | BlobContainerSasPermissions.Delete) : _azureStorage.GetBlobContainerSAS("teammodelos", BlobContainerSasPermissions.Write | BlobContainerSasPermissions.Read | BlobContainerSasPermissions.List, BIConst.Global);
  290. return Ok(new { state = 200, ddUserInfos = ddusers, id_token, roles, permissions, osblob_uri, osblob_sas });
  291. }
  292. catch (Exception ex)
  293. {
  294. await _dingDing.SendBotMsg($"BI, {_option.Location} /common/login/get-ddscancode \n {ex.Message}\n{ex.StackTrace}", GroupNames.成都开发測試群組);
  295. return BadRequest();
  296. }
  297. }
  298. /// <summary>
  299. /// 钉钉绑定醍摩豆
  300. /// </summary>
  301. /// <returns></returns>
  302. [ProducesDefaultResponseType]
  303. [HttpPost("set-bind")]
  304. public async Task<IActionResult> BindUser(JsonElement jsonElement)
  305. {
  306. try
  307. {
  308. if (!jsonElement.TryGetProperty("partitionKey", out JsonElement partitionKey)) return BadRequest();
  309. if (!jsonElement.TryGetProperty("rowKey", out JsonElement userId)) return BadRequest();
  310. jsonElement.TryGetProperty("id_token", out JsonElement idtoken);
  311. jsonElement.TryGetProperty("mobile", out JsonElement mobile);
  312. jsonElement.TryGetProperty("site", out JsonElement site);
  313. string Website = "China";
  314. var tableClient = _azureStorage.GetCloudTableClient();
  315. var blobClient = _azureStorage.GetBlobContainerClient(containerName: "0-public");
  316. if ($"{site}".Equals(BIConst.Global))
  317. {
  318. tableClient = _azureStorage.GetCloudTableClient(BIConst.Global);
  319. blobClient = _azureStorage.GetBlobContainerClient(containerName: "0-public", BIConst.Global);
  320. Website = BIConst.Global;
  321. }
  322. HttpClient httpClient = _http.CreateClient();
  323. var table = _azureStorage.GetCloudTableClient().GetTableReference("BIDDUserInfo");
  324. var tempUser = await table.FindListByDict<DingDingUserInfo>(new Dictionary<string, object> { { "PartitionKey", $"{partitionKey}" }, { "userId", $"{userId}" } });
  325. var id_token = "";
  326. var auth_token = "";
  327. List<DingDingUserInfo> ddUserInfos = new();
  328. List<string> roles = new();//角色列表
  329. List<string> permissions = new();//权限列表
  330. foreach (var itemUser in tempUser)
  331. {
  332. if (!string.IsNullOrEmpty($"{idtoken}"))
  333. {
  334. JwtSecurityToken jwt = new JwtSecurityToken($"{idtoken}");
  335. var tmdId = jwt.Payload.Sub;
  336. jwt.Payload.TryGetValue("name", out object tmdName);
  337. jwt.Payload.TryGetValue("picture", out object picture);
  338. itemUser.tmdId = tmdId;
  339. itemUser.tmdName = $"{tmdName}";
  340. itemUser.tmdMobile = itemUser.mobile;
  341. itemUser.picture = $"{picture}";
  342. }
  343. if (!string.IsNullOrEmpty($"{mobile}"))
  344. {
  345. var coreUser = await _coreAPIHttpService.GetUserInfo(new Dictionary<string, string> { { "key", $"{mobile}" } }, _option.Location, _configuration);
  346. if (coreUser != null && coreUser.id != null)
  347. {
  348. itemUser.tmdId = coreUser.id;
  349. itemUser.tmdName = coreUser.name;
  350. itemUser.tmdMobile = coreUser.mobile;
  351. itemUser.picture = coreUser.mobile;
  352. itemUser.mail = coreUser.mail;
  353. }
  354. else return Ok(new { state = 404, msg = "手机号未找到醍摩豆账户" });
  355. //string url = _configuration.GetValue<string>("HaBookAuth:CoreId:userinfo");
  356. //List<string> mobiles = new() { $"{mobile}" };
  357. //HttpResponseMessage responseMessage = await httpClient.PostAsJsonAsync(url, mobiles);
  358. //if (responseMessage.StatusCode == HttpStatusCode.OK)
  359. //{
  360. // var temp = await responseMessage.Content.ReadAsStringAsync();
  361. // if (temp.Length > 0)
  362. // {
  363. // List<JsonElement> itemjson = temp.ToObject<List<JsonElement>>();
  364. // foreach (var item in itemjson)
  365. // {
  366. // itemUser.tmdId = item.GetProperty("id").ToString();
  367. // itemUser.tmdName = item.GetProperty("name").ToString();
  368. // itemUser.tmdMobile = item.GetProperty("mobile").ToString();
  369. // itemUser.picture = item.GetProperty("picture").ToString();
  370. // itemUser.mail = item.GetProperty("mail").ToString();
  371. // }
  372. // }
  373. //}
  374. //else return Ok(new { state = 404, msg = "手机号未找到醍摩豆账户" });
  375. }
  376. if (string.IsNullOrEmpty($"{mobile}") && string.IsNullOrEmpty($"{idtoken}"))
  377. return Ok(new { state = 400, msg = "mobile、idtoken参数错误" });
  378. else
  379. {
  380. ddUserInfos.Add(itemUser);
  381. roles = !string.IsNullOrEmpty($"{itemUser.roles}") ? new List<string>(itemUser.roles.Split(",")) : new List<string>();
  382. //保存操作记录
  383. //await _azureStorage.SaveBILog("tabledd-update", $"{itemUser.tmdName}【{itemUser.tmdId}】醍摩豆账号和{itemUser.name}【{itemUser.userId}】钉钉账户绑定成功", _dingDing, tid: itemUser.tmdId, tname: itemUser.name, twebsite: Website, httpContext: HttpContext);
  384. await AzureStorageBlobExtensions.SaveBILog(blobClient, tableClient, "tabledd-update", $"{itemUser.tmdName}【{itemUser.tmdId}】醍摩豆账号和{itemUser.name}【{itemUser.userId}】钉钉账户绑定成功", _dingDing, tid: itemUser.tmdId, tname: itemUser.name, twebsite: Website, httpContext: HttpContext);
  385. id_token = JwtAuth.CreateAuthTokenBI(_option.HostName, itemUser.tmdId?.ToString(), itemUser.tmdName?.ToString(), itemUser.picture?.ToString(), _option.JwtSecretKey, scope: "assist", webSite: Website, isex: false, itemUser.userId?.ToString(), itemUser.name?.ToString(), itemUser.avatar?.ToString(), roles: roles?.ToArray(), permissions: permissions?.ToArray(), expire: 3);
  386. }
  387. }
  388. ddUserInfos = await table.UpdateAll(ddUserInfos);
  389. string osblob_uri = null, osblob_sas = null;
  390. if (Website.Equals(BIConst.Global))
  391. {
  392. (osblob_uri, osblob_sas) = _azureStorage.GetBlobContainerSAS("teammodelos", BlobContainerSasPermissions.Write | BlobContainerSasPermissions.Read | BlobContainerSasPermissions.List | BlobContainerSasPermissions.Delete, BIConst.Global);
  393. }
  394. else
  395. {
  396. (osblob_uri, osblob_sas) = _azureStorage.GetBlobContainerSAS("teammodelos", BlobContainerSasPermissions.Write | BlobContainerSasPermissions.Read | BlobContainerSasPermissions.List | BlobContainerSasPermissions.Delete);
  397. }
  398. //blob 访问权限
  399. //var (osblob_uri, osblob_sas) = roles.Contains("assist") ? _azureStorage.GetBlobContainerSAS("teammodelos", BlobContainerSasPermissions.Write | BlobContainerSasPermissions.Read | BlobContainerSasPermissions.List | BlobContainerSasPermissions.Delete) : _azureStorage.GetBlobContainerSAS("teammodelos", BlobContainerSasPermissions.Read | BlobContainerSasPermissions.List);
  400. return Ok(new { state = 200, ddUserInfos, id_token, roles, osblob_uri, osblob_sas });
  401. }
  402. catch (Exception ex)
  403. {
  404. await _dingDing.SendBotMsg($"BI, {_option.Location} /common/login/set-bind \n {ex.Message}\n{ex.StackTrace}", GroupNames.成都开发測試群組);
  405. return BadRequest();
  406. }
  407. }
  408. /// <summary>
  409. /// 获取钉钉信息详情绑定醍摩豆和钉钉信息 二合一
  410. /// </summary>
  411. /// <param name="jsonElement"></param>
  412. /// <returns></returns>
  413. [ProducesDefaultResponseType]
  414. [HttpPost("get-ddinfo")]
  415. public async Task<IActionResult> GetDingDingInfo(JsonElement jsonElement)
  416. {
  417. try
  418. {
  419. if (!jsonElement.TryGetProperty("mobile", out JsonElement moile)) return BadRequest();
  420. if (!jsonElement.TryGetProperty("partitionKey", out JsonElement partitionKey)) return BadRequest();
  421. if (!jsonElement.TryGetProperty("rowKey", out JsonElement userId)) return BadRequest();
  422. jsonElement.TryGetProperty("site", out JsonElement site);
  423. string Website = "China";
  424. var tableClient = _azureStorage.GetCloudTableClient();
  425. var blobClient = _azureStorage.GetBlobContainerClient(containerName: "0-public");
  426. if ($"{site}".Equals(BIConst.Global))
  427. {
  428. tableClient = _azureStorage.GetCloudTableClient(BIConst.Global);
  429. blobClient = _azureStorage.GetBlobContainerClient(containerName: "0-public", BIConst.Global);
  430. Website = BIConst.Global;
  431. }
  432. var table = tableClient.GetTableReference("BIDDUserInfo");
  433. var tempUser = await table.FindListByDict<DingDingUserInfo>(new Dictionary<string, object> { { "PartitionKey", $"{partitionKey}" }, { "userId", $"{userId}" } });
  434. List<string> roles = new();//角色列表
  435. List<string> permissions = new();//权限列表
  436. List<DingDingUserInfo> ddUserInfos = new();
  437. var id_token = "";
  438. foreach (var itemUser in tempUser)
  439. {
  440. if (!string.IsNullOrEmpty($"{itemUser.tmdId}") && !string.IsNullOrEmpty($"{itemUser.tmdName}"))
  441. {
  442. //roles = new List<string>(itemUser.roles.Split(new string[] { "," }, StringSplitOptions.RemoveEmptyEntries));
  443. roles = !string.IsNullOrEmpty($"{itemUser.roles}") ? new List<string>(itemUser.roles.Split(",")) : new List<string>();
  444. permissions = !string.IsNullOrEmpty($"{itemUser.permissions}") ? new List<string>(itemUser.permissions.Split(",")) : new List<string>();
  445. ddUserInfos.Add(itemUser);
  446. }
  447. else
  448. {
  449. var coreUser = await _coreAPIHttpService.GetUserInfo(new Dictionary<string, string> { { "key", $"{moile}" } }, _option.Location, _configuration);
  450. if (coreUser != null && coreUser.id != null)
  451. {
  452. itemUser.tmdId = coreUser.id;
  453. itemUser.tmdName = coreUser.name;
  454. itemUser.tmdMobile = coreUser.mobile;
  455. itemUser.picture = coreUser.mobile;
  456. itemUser.mail = coreUser.mail;
  457. roles = !string.IsNullOrEmpty($"{itemUser.roles}") ? new List<string>(itemUser.roles.Split(",")) : new List<string>();
  458. permissions = !string.IsNullOrEmpty($"{itemUser.permissions}") ? new List<string>(itemUser.permissions.Split(",")) : new List<string>();
  459. ddUserInfos.Add(itemUser);
  460. await AzureStorageBlobExtensions.SaveBILog(blobClient, tableClient, "tabledd-update", $"{coreUser.name}【{coreUser.id}】醍摩豆账号和{itemUser.name}【{itemUser.userId}】钉钉账户绑定成功", _dingDing, tid: itemUser.tmdId, tname: itemUser.name, twebsite: Website, httpContext: HttpContext);
  461. }
  462. else return Ok(new { state = 400, message = "该手机没有注册醍摩豆账号信息" });
  463. //HttpClient httpClient = _http.CreateClient();
  464. //string url = _configuration.GetValue<string>("HaBookAuth:CoreId:userinfo");
  465. //HttpResponseMessage responseMessage = await httpClient.PostAsJsonAsync(url, moile);
  466. //if (responseMessage.StatusCode == HttpStatusCode.OK)
  467. //{
  468. // var temp = await responseMessage.Content.ReadAsStringAsync();
  469. // if (temp.Length > 0)
  470. // {
  471. // List<JsonElement> itemjson = temp.ToObject<List<JsonElement>>();
  472. // string tmdId = null;
  473. // string tmdName = null;
  474. // foreach (var item in itemjson)
  475. // {
  476. // tmdId = item.GetProperty("id").ToString();
  477. // tmdName = item.GetProperty("name").ToString();
  478. // itemUser.tmdId = tmdId?.ToString();
  479. // itemUser.tmdName = tmdName?.ToString();
  480. // itemUser.tmdMobile = item.GetProperty("mobile").ToString();
  481. // itemUser.picture = item.GetProperty("picture").ToString();
  482. // itemUser.mail = item.GetProperty("mail").ToString();
  483. // roles = !string.IsNullOrEmpty($"{itemUser.roles}") ? new List<string>(itemUser.roles.Split(",")) : new List<string>();
  484. // permissions = !string.IsNullOrEmpty($"{itemUser.permissions}") ? new List<string>(itemUser.permissions.Split(",")) : new List<string>();
  485. // ddUserInfos.Add(itemUser);
  486. // }
  487. // ddUserInfos = await table.UpdateAll<DingDingUserInfo>(ddUserInfos);
  488. // //保存操作记录
  489. // //await _azureStorage.SaveBILog("tabledd-update", $"{tmdName}【{tmdId}】醍摩豆账号和{itemUser.name}【{itemUser.userId}】钉钉账户绑定成功", _dingDing, tid: itemUser.tmdId, tname: itemUser.name, twebsite: Website, httpContext: HttpContext);
  490. // await AzureStorageBlobExtensions.SaveBILog(blobClient, tableClient, "tabledd-update", $"{tmdName}【{tmdId}】醍摩豆账号和{itemUser.name}【{itemUser.userId}】钉钉账户绑定成功", _dingDing, tid: itemUser.tmdId, tname: itemUser.name, twebsite: Website, httpContext: HttpContext);
  491. // }
  492. // else return Ok(new { state = 400, message = "该手机没有注册醍摩豆账号信息" });
  493. //}
  494. //else return Ok(new { state = responseMessage.StatusCode });
  495. }
  496. //自己写的
  497. id_token = JwtAuth.CreateAuthTokenBI(_option.HostName, itemUser.tmdId?.ToString(), itemUser.tmdName?.ToString(), itemUser.picture?.ToString(), _option.JwtSecretKey, scope: "assist", webSite: Website, isex: false, itemUser.userId?.ToString(), itemUser.name?.ToString(), itemUser.avatar?.ToString(), roles: roles?.ToArray(), permissions: permissions?.ToArray(), expire: 3);
  498. }
  499. await table.SaveOrUpdateAll<DingDingUserInfo>(ddUserInfos);
  500. string osblob_uri = null, osblob_sas = null;
  501. if (Website.Equals(BIConst.Global))
  502. {
  503. (osblob_uri, osblob_sas) = _azureStorage.GetBlobContainerSAS("teammodelos", BlobContainerSasPermissions.Write | BlobContainerSasPermissions.Read | BlobContainerSasPermissions.List | BlobContainerSasPermissions.Delete, BIConst.Global);
  504. }
  505. else
  506. {
  507. (osblob_uri, osblob_sas) = _azureStorage.GetBlobContainerSAS("teammodelos", BlobContainerSasPermissions.Write | BlobContainerSasPermissions.Read | BlobContainerSasPermissions.List | BlobContainerSasPermissions.Delete);
  508. }
  509. //var (osblob_uri, osblob_sas) = roles.Contains("assist") ? _azureStorage.GetBlobContainerSAS("teammodelos", BlobContainerSasPermissions.Write | BlobContainerSasPermissions.Read | BlobContainerSasPermissions.List | BlobContainerSasPermissions.Delete) : _azureStorage.GetBlobContainerSAS("teammodelos", BlobContainerSasPermissions.Read | BlobContainerSasPermissions.List);
  510. return Ok(new { state = 200, ddUserInfos, id_token, roles, permissions, osblob_uri, osblob_sas });
  511. }
  512. catch (Exception ex)
  513. {
  514. await _dingDing.SendBotMsg($"BI,{_option.Location} /common/login/get-ddinfo \n {ex.Message}\n{ex.StackTrace}", GroupNames.成都开发測試群組);
  515. return BadRequest();
  516. }
  517. }
  518. /// <summary>
  519. /// 企业登录
  520. /// </summary>
  521. /// <param name="jsonElement"></param>
  522. /// <returns></returns>
  523. [ProducesDefaultResponseType]
  524. [HttpPost("get-bizuserlogin")]
  525. public async Task<IActionResult> GetCommpanyLogin(JsonElement jsonElement)
  526. {
  527. jsonElement.TryGetProperty("mobile", out JsonElement mobile);
  528. jsonElement.TryGetProperty("tmdId", out JsonElement tmdId);
  529. jsonElement.TryGetProperty("mail", out JsonElement mail);
  530. if (!jsonElement.TryGetProperty("pwd", out JsonElement password)) return BadRequest();
  531. jsonElement.TryGetProperty("site", out JsonElement site);
  532. string Website = "China";
  533. var cosmosClient = _azureCosmos.GetCosmosClient();
  534. var tableClient = _azureStorage.GetCloudTableClient();
  535. var blobClient = _azureStorage.GetBlobContainerClient(containerName: "0-public");
  536. if ($"{site}".Equals(BIConst.Global))
  537. {
  538. cosmosClient = _azureCosmos.GetCosmosClient(name: BIConst.Global);
  539. tableClient = _azureStorage.GetCloudTableClient(BIConst.Global);
  540. blobClient = _azureStorage.GetBlobContainerClient(containerName: "0-public", BIConst.Global);
  541. Website = BIConst.Global;
  542. }
  543. Dictionary<string, object> tableDic = new();
  544. string tableSql = null;
  545. if (!string.IsNullOrEmpty($"{mail}"))
  546. {
  547. tableSql = $" PartitionKey eq 'BusinessUser' and mail eq '{mail}'";
  548. tableDic = new Dictionary<string, object>() { { "PartitionKey", "BizRelUser" }, { "mail", $"{mail}" } };
  549. }
  550. if (!string.IsNullOrEmpty($"{tmdId}"))
  551. {
  552. tableSql = $" PartitionKey eq 'BusinessUser' and tmdId eq '{tmdId}'";
  553. tableDic = new Dictionary<string, object>() { { "PartitionKey", "BizRelUser" }, { "tmdId", $"{tmdId}" } };
  554. }
  555. if (!string.IsNullOrEmpty($"{mobile}"))
  556. {
  557. tableSql = $" PartitionKey eq 'BusinessUser' and mobile eq '{mobile}'";
  558. tableDic = new Dictionary<string, object>() { { "PartitionKey", "BizRelUser" }, { "mobile", $"{mobile}" } };
  559. }
  560. if (!string.IsNullOrEmpty(tableSql))
  561. {
  562. var table = tableClient.GetTableReference("IESOpenApi");
  563. List<BusinessUser> findBizUsers = await table.QueryWhereString<BusinessUser>(tableSql);
  564. //List<BusinessUser> findBizUsers = await table.FindListByDict<BusinessUser>(tableDic);
  565. if (findBizUsers.Count > 0)
  566. {
  567. BusinessUser bizUser = new();
  568. foreach (var item in findBizUsers)
  569. {
  570. bizUser.PartitionKey = item.PartitionKey;
  571. bizUser.RowKey = item.RowKey;
  572. bizUser.name = item.name;
  573. bizUser.picture = item.picture;
  574. bizUser.tmdId = item.tmdId;
  575. bizUser.mobile = item.mobile;
  576. bizUser.mail = item.mail;
  577. bizUser.salt = item.salt;
  578. bizUser.pwd = item.pwd;
  579. }
  580. List<BizRelUser> bizRelUsers = new();
  581. if (bizUser != null)
  582. {
  583. bizRelUsers = await table.FindListByDict<BizRelUser>(new Dictionary<string, object>() { { "PartitionKey", "BizRelUser" }, { "bizUser", $"{bizUser.RowKey}" } });
  584. }
  585. var hashedPw = Utils.HashedPassword(password.ToString(), bizUser.salt.ToString());
  586. if (hashedPw.Equals(bizUser.pwd))
  587. {
  588. string id_token = JwtAuth.CreateAuthTokenBI(_option.HostName, bizUser.RowKey?.ToString(), bizUser.name?.ToString(), bizUser.picture?.ToString(), _option.JwtSecretKey, scope: "company", webSite: Website, expire: 3);
  589. await AzureStorageBlobExtensions.SaveBILog(blobClient, tableClient, "tabledd-update", $"{bizUser.name}【{bizUser.RowKey}】登录商务智能开放平台", _dingDing, tid: bizUser.RowKey, tname: bizUser.name, twebsite: Website?.ToString(), httpContext: HttpContext);
  590. return Ok(new { state = RespondCode.Ok, id_token, bizUser, bizRelUsers });
  591. }
  592. else return Ok(new { state = RespondCode.ForbiddenPwd, msg = "密码错误!" });
  593. }
  594. else return Ok(new { state = RespondCode.NotFound, msg = "该账户不存在" });
  595. }
  596. else return Ok(new { state = RespondCode.ParamsError, msg = "参数错误" });
  597. }
  598. /// <summary>
  599. /// 用户信息注册
  600. /// </summary>
  601. /// <param name="jsonElement"></param>
  602. /// <returns></returns>
  603. [HttpPost("set-ropen")]
  604. public async Task<IActionResult> SetRegistered(JsonElement jsonElement)
  605. {
  606. if (!jsonElement.TryGetProperty("name", out JsonElement name)) return BadRequest();
  607. if (!jsonElement.TryGetProperty("mobile", out JsonElement mobile)) return BadRequest();
  608. jsonElement.TryGetProperty("tmdId", out JsonElement tmdId);
  609. jsonElement.TryGetProperty("mail", out JsonElement mail);
  610. jsonElement.TryGetProperty("pwd", out JsonElement pwd);
  611. jsonElement.TryGetProperty("site", out JsonElement site);
  612. string Website = "China";
  613. var cosmosClient = _azureCosmos.GetCosmosClient();
  614. var tableClient = _azureStorage.GetCloudTableClient();
  615. var blobClient = _azureStorage.GetBlobContainerClient(containerName: "0-public");
  616. if ($"{site}".Equals(BIConst.Global))
  617. {
  618. cosmosClient = _azureCosmos.GetCosmosClient(name: BIConst.Global);
  619. tableClient = _azureStorage.GetCloudTableClient(BIConst.Global);
  620. blobClient = _azureStorage.GetBlobContainerClient(containerName: "0-public", BIConst.Global);
  621. Website = BIConst.Global;
  622. }
  623. var table = tableClient.GetTableReference("IESOpenApi");
  624. string salt = Utils.CreatSaltString(8);
  625. BusinessUser bizUser = null;
  626. List<BusinessUser> findBizUsers = await table.QueryWhereString<BusinessUser>($" PartitionKey eq 'BusinessUser' and mobile eq '{mobile}'");
  627. if (findBizUsers.Count <= 0)
  628. {
  629. var coreUser = await _coreAPIHttpService.GetUserInfo(new Dictionary<string, string> { { "key", $"{mobile}" } }, _option.Location, _configuration);
  630. if (coreUser != null)
  631. bizUser = new() { RowKey = Guid.NewGuid().ToString(), name = coreUser.name, tmdId = coreUser.id, mobile = coreUser.mobile, mail = coreUser.mail, salt = salt, pwd = string.IsNullOrEmpty($"{pwd}") ? Utils.HashedPassword($"{mobile}", salt) : Utils.HashedPassword($"{pwd}", salt) };
  632. else
  633. bizUser = new() { RowKey = Guid.NewGuid().ToString(), name = $"{name}", mobile = $"{mobile}", salt = salt, pwd = string.IsNullOrEmpty($"{pwd}") ? Utils.HashedPassword($"{mobile}", salt) : Utils.HashedPassword($"{pwd}", salt) };
  634. bizUser = await table.Save<BusinessUser>(bizUser);
  635. await AzureStorageBlobExtensions.SaveBILog(blobClient, tableClient, "bizUser-update", $"{bizUser.name}【{bizUser.RowKey}】注册开放平台用户", _dingDing, tid: bizUser.RowKey, tname: bizUser.name, twebsite: Website?.ToString(), httpContext: HttpContext);
  636. return Ok(new { state = RespondCode.Ok, bizUser });
  637. }
  638. else return Ok(new { state = RespondCode.Conflict, msg = "该手机号已注册开放平台,请直接登录" });
  639. }
  640. public record DingDingbinds
  641. {
  642. public string type { get; set; }
  643. /// <summary>
  644. /// 所属部门id列表
  645. /// </summary>
  646. public List<long> deptIdList { get; set; }
  647. /// <summary>
  648. /// 职位名称
  649. /// </summary>
  650. public string title { get; set; }
  651. /// <summary>
  652. /// 钉钉用户名
  653. /// </summary>
  654. public string name { get; set; }
  655. /// <summary>
  656. /// 钉钉unionid
  657. /// </summary>
  658. public string unionid { get; set; }
  659. /// <summary>
  660. /// 钉钉ID
  661. /// </summary>
  662. public string userid { get; set; }
  663. }
  664. }
  665. }