package com.zy.asrs.wms.system.controller; import com.baomidou.mybatisplus.core.conditions.query.LambdaQueryWrapper; import com.zy.asrs.framework.common.Cools; import com.zy.asrs.framework.common.R; import com.zy.asrs.wms.common.annotation.OperationLog; import com.zy.asrs.wms.common.config.ConfigProperties; import com.zy.asrs.wms.common.security.JwtSubject; import com.zy.asrs.wms.system.controller.param.LoginParam; import com.zy.asrs.wms.system.controller.param.UpdatePasswordParam; import com.zy.asrs.wms.system.controller.result.LoginResult; import com.zy.asrs.wms.system.entity.*; import com.zy.asrs.wms.system.service.*; import com.zy.asrs.wms.utils.JwtUtil; import com.zy.asrs.wms.utils.Utils; import org.springframework.security.access.prepost.PreAuthorize; import org.springframework.web.bind.annotation.*; import javax.annotation.Resource; import javax.servlet.http.HttpServletRequest; import java.util.ArrayList; import java.util.List; /** * 认证控制器 * * Created by vincent on 1/30/2024 */ @RestController @RequestMapping("/api") public class AuthController extends BaseController { @Resource private ConfigProperties configProperties; @Resource private UserService userService; @Resource private UserLoginService userLoginService; @Resource private RoleMenuService roleMenuService; @Resource private HostService hostService; @Resource private UserRoleService userRoleService; @Resource private MenuService menuService; @PostMapping("/login") public R login(@RequestBody LoginParam param, HttpServletRequest request) { String username = param.getUsername(); Long hostId = param.getHostId(); User user = userService.getByUsername(username, hostId); if (user == null) { return R.error("账号不存在"); } if (!user.getStatus().equals(1)) { return R.error("账号被冻结"); } if (!userService.comparePassword(user.getPassword(), param.getPassword())) { return R.error("密码错误"); } String accessToken = JwtUtil.buildToken(new JwtSubject(username, user.getHostId()), configProperties.getTokenExpireTime(), configProperties.getTokenKey()); userLoginService.saveAsync(user.getId(), accessToken, UserLogin.TYPE_LOGIN, hostId, null, request); return R.ok("登录成功").add(new LoginResult(accessToken, user)); } @GetMapping("/auth/user") public R userInfo() { return R.ok(userService.getByIdRel(getLoginUserId())); } @GetMapping("/auth/menu") public R userMenu() { List