164 lines
4.4 KiB
Go
Raw Normal View History

2023-06-04 22:54:54 +08:00
package service
import (
2024-02-21 12:04:40 +08:00
"context"
2023-06-04 22:54:54 +08:00
"crypto/sha256"
"encoding/hex"
"errors"
"github.com/google/uuid"
"github.com/labstack/echo/v4"
2024-04-29 19:35:18 +08:00
"golang.org/x/time/rate"
2024-09-29 14:08:55 +08:00
"mylomen_server/common/constant"
"mylomen_server/common/dto"
"mylomen_server/common/email"
"mylomen_server/common/logs"
"mylomen_server/common/utils"
2024-09-30 22:49:21 +08:00
"mylomen_server/common/xjwt"
2024-09-29 21:12:57 +08:00
"mylomen_server/infrastructure/convert"
2024-09-29 14:08:55 +08:00
"mylomen_server/infrastructure/redis"
"mylomen_server/infrastructure/repository"
2023-06-04 22:54:54 +08:00
"strings"
"time"
)
2024-09-30 22:49:21 +08:00
type user struct {
2023-06-04 22:54:54 +08:00
}
2024-09-30 22:49:21 +08:00
var UserBiz user
2023-06-04 22:54:54 +08:00
2024-04-29 19:35:18 +08:00
// 令牌桶大小为 100, 以每秒 10 个 Token 的速率向桶中放置 Token
var limiter = rate.NewLimiter(10, 10)
// Register 注册
2024-09-30 22:49:21 +08:00
func (l user) Register(ctx context.Context, req dto.RegisterReq) error {
2024-09-29 21:12:57 +08:00
acUser := repository.GUser.FindByReq(ctx, req.LoginReq)
2024-09-30 15:41:00 +08:00
if acUser != nil && acUser.Deleted == false {
2024-04-29 19:35:18 +08:00
return errors.New("user exist")
}
2024-09-30 22:49:21 +08:00
//fill data
2024-09-29 21:12:57 +08:00
userDO := convert.UserReq2DO(req)
2024-10-01 02:13:07 +08:00
userDO.Sn = utils.GetTrueRandomCode(8)
2024-09-30 22:49:21 +08:00
userDO.Deleted = false
userDO.UpdateTime = time.Now()
userDO.NickName = req.NickName
userDO.Avatar = req.Avatar
2024-04-29 19:35:18 +08:00
//密码加密
h := sha256.Sum256([]byte(req.Password))
passHash := hex.EncodeToString(h[:])
2024-09-29 21:12:57 +08:00
userDO.Pwd = &passHash
2024-04-29 19:35:18 +08:00
2024-09-29 21:12:57 +08:00
return repository.GUser.Create(ctx, &userDO)
2024-04-29 19:35:18 +08:00
}
2024-09-30 22:49:21 +08:00
func (l user) Login(ctx context.Context, req dto.LoginReq) (*dto.UserVO, error) {
2024-08-18 18:24:26 +08:00
start := time.Now().UnixMilli()
2023-06-04 22:54:54 +08:00
2024-09-29 21:12:57 +08:00
//1. 查询用户
acUser := repository.GUser.FindByReq(ctx, req)
2024-09-30 15:41:00 +08:00
if acUser == nil || acUser.Deleted == true {
2024-09-29 21:12:57 +08:00
return nil, errors.New("user not exist")
2023-06-04 22:54:54 +08:00
}
2024-09-29 21:12:57 +08:00
//2. email 和 手机号登录 和account 需要验证密码。其他情况不需要验证密码
if req.Account != nil || req.Email != nil || req.Phone != nil {
if acUser.Pwd == nil {
return nil, errors.New("password not set")
}
// 验证账号密码
h := sha256.Sum256([]byte(req.Password))
passHash := hex.EncodeToString(h[:])
if acUser.Pwd == nil || passHash != *acUser.Pwd {
return nil, errors.New("password is error")
}
2023-06-04 22:54:54 +08:00
}
2024-09-29 21:12:57 +08:00
//3. 组装数据
result := convert.UserDO2VO(*acUser)
2024-09-30 22:49:21 +08:00
result.Platform = req.Platform
2023-06-04 22:54:54 +08:00
2024-09-30 22:49:21 +08:00
//生成token
token := strings.ReplaceAll(uuid.New().String(), "-", "")
claims := dto.LoginTokenVo{Sn: result.Sn, Token: token}
//设置超时时间
claims.SetExtByPlatform(req.Platform)
result.Token = xjwt.GenJwtToken(claims)
2024-08-18 18:24:26 +08:00
diff := time.Now().UnixMilli() - start
logs.NewLog("").Infof("Login cost: %d", diff)
2024-09-29 21:12:57 +08:00
return &result, nil
2024-04-29 19:35:18 +08:00
}
2024-09-30 22:49:21 +08:00
func (l user) SendResetPwdCode(ctx context.Context, emailP string) error {
2024-04-29 19:35:18 +08:00
//1. 验证账号
2024-09-30 22:49:21 +08:00
acUser := repository.GUser.FindByEmail(ctx, emailP)
2024-09-30 15:41:00 +08:00
if acUser == nil || acUser.Deleted == true {
2024-04-29 19:35:18 +08:00
return errors.New("user not exist")
}
//2. 生成code & 发送
code := utils.GetPseudoRandomCode(6)
//3. save into redis
2024-09-30 22:49:21 +08:00
if err := redis.Set(constant.G_RESET_PWD_CODE+emailP, code, time.Duration(30)*time.Minute); err != nil {
2024-04-29 19:35:18 +08:00
return errors.New("cache illegal")
}
//频控
if !limiter.Allow() {
return errors.New("rate limit, please try again later")
}
//4. send code
2024-09-30 22:49:21 +08:00
if err := email.SendEmailVerifyCodeByEmail(code, emailP); err != nil {
2024-04-29 19:35:18 +08:00
return errors.New("send email code illegal")
}
return nil
}
// ResetPwd 重置密码
2024-09-30 22:49:21 +08:00
func (l user) ResetPwd(ctx context.Context, req dto.ResetPwdReq) error {
2024-04-29 19:35:18 +08:00
//1. 验证code
redisStr, err := redis.Get(constant.G_RESET_PWD_CODE + req.Account)
if err != nil && redisStr != req.Code {
return errors.New("code is error")
}
//2. 查询用户
acUser := repository.GUser.FindByAccount(ctx, req.Account)
2024-09-30 15:41:00 +08:00
if acUser == nil || acUser.Deleted == true {
2024-04-29 19:35:18 +08:00
return errors.New("user not exist")
}
//3. 重置密码
h := sha256.Sum256([]byte(req.Password))
passHash := hex.EncodeToString(h[:])
2024-09-29 21:12:57 +08:00
acUser.Pwd = &passHash
2024-09-30 22:49:21 +08:00
if updateErr := repository.GUser.UpdateById(ctx, acUser); updateErr != nil {
logs.NewLog("").Errorf("update user password req:%+v error: %+v", req, updateErr)
return errors.New("system error")
}
2024-04-29 19:35:18 +08:00
return nil
2023-06-04 22:54:54 +08:00
}
2024-09-30 22:49:21 +08:00
func (l user) GetLoginResult(ctx context.Context, c *echo.Context) (*dto.UserVO, error) {
2023-06-04 22:54:54 +08:00
accessToken := utils.GetAccessToken(c)
2024-09-30 22:49:21 +08:00
loginVo, err := xjwt.ParseJwtToken(accessToken)
if err != nil || loginVo.Sn == "" {
return nil, errors.New("token illegal")
2023-06-04 22:54:54 +08:00
}
2024-09-30 22:49:21 +08:00
//查询数据库
userDO := repository.GUser.FindBySn(ctx, loginVo.Sn)
if err != nil || userDO == nil {
return nil, errors.New("user not exist")
2023-06-04 22:54:54 +08:00
}
2024-09-30 22:49:21 +08:00
result := convert.UserDO2VO(*userDO)
result.Token = accessToken
result.Platform = loginVo.Platform
return utils.ToPtr(result), nil
2023-06-04 22:54:54 +08:00
}