| 123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335 |
- <?php
- namespace App\Module\OpenAPI\Controllers;
- use App\Module\OpenAPI\Services\AuthService;
- use App\Module\OpenAPI\Services\OpenApiService;
- use App\Module\OpenAPI\Validators\AuthValidator;
- use Illuminate\Http\Request;
- use Illuminate\Http\JsonResponse;
- /**
- * 认证控制器
- */
- class AuthController
- {
- /**
- * @var AuthService
- */
- protected AuthService $authService;
- /**
- * @var OpenApiService
- */
- protected OpenApiService $openApiService;
- /**
- * @var AuthValidator
- */
- protected AuthValidator $authValidator;
- public function __construct(
- AuthService $authService,
- OpenApiService $openApiService,
- AuthValidator $authValidator
- ) {
- $this->authService = $authService;
- $this->openApiService = $openApiService;
- $this->authValidator = $authValidator;
- }
- /**
- * 获取访问令牌
- *
- * @param Request $request
- * @return JsonResponse
- */
- public function token(Request $request): JsonResponse
- {
- $startTime = microtime(true);
- // 初始化请求日志记录器
- $requestLogger = new \App\Module\System\Services\RequestLogger($request);
- $requestLogger->setRouter("openapi/auth/token");
- try {
- // 使用标准验证系统
- $validation = new \App\Module\OpenAPI\Validations\TokenRequestValidation($request->all());
- $validation->validate();
- if ($validation->isFail()) {
- // 记录验证失败和运行时间
- $requestLogger->setError('参数验证失败: ' . json_encode($validation->getErrors()));
- $requestLogger->setRunTime($startTime);
- return $this->errorResponse('参数验证失败', $validation->getErrors(), 400);
- }
- $data = $validation->getSafeData();
- $grantType = $data['grant_type'];
- // 根据授权类型处理
- $response = match ($grantType) {
- 'client_credentials' => $this->handleClientCredentials(
- $validation->app,
- $validation->scopes ?? []
- ),
- 'authorization_code' => $this->handleAuthorizationCode(
- $validation->app,
- $data['code'],
- $validation->scopes ?? []
- ),
- 'refresh_token' => $this->handleRefreshToken($data['refresh_token']),
- default => $this->errorResponse('不支持的授权类型', [], 400)
- };
- // 记录运行时间
- $requestLogger->setRunTime($startTime);
- return $response;
- } catch (\Exception $e) {
- // 记录错误信息和运行时间
- $requestLogger->setError($e->getMessage());
- $requestLogger->setRunTime($startTime);
- return $this->errorResponse('获取令牌失败', ['message' => $e->getMessage()], 500);
- }
- }
- /**
- * 处理客户端凭证授权
- *
- * @param \App\Module\OpenAPI\Models\OpenApiApp $app
- * @param array $scopes
- * @return JsonResponse
- */
- protected function handleClientCredentials(\App\Module\OpenAPI\Models\OpenApiApp $app, array $scopes): JsonResponse
- {
- // 生成访问令牌
- $tokenData = $this->authService->generateAccessToken($app, 0, $scopes);
- return $this->successResponse('令牌获取成功', $tokenData);
- }
- /**
- * 处理授权码授权
- *
- * @param \App\Module\OpenAPI\Models\OpenApiApp $app
- * @param string $code
- * @param array $scopes
- * @return JsonResponse
- */
- protected function handleAuthorizationCode(\App\Module\OpenAPI\Models\OpenApiApp $app, string $code, array $scopes): JsonResponse
- {
- // 验证授权码
- $codeData = $this->authService->validateAuthCode($code, $app->app_id);
- if (!$codeData) {
- return $this->errorResponse('授权码无效', [], 400);
- }
- // 生成访问令牌
- $tokenData = $this->authService->generateAccessToken(
- $app,
- $codeData['user_id'],
- $scopes
- );
- return $this->successResponse('令牌获取成功', $tokenData);
- }
- /**
- * 处理刷新令牌
- *
- * @param string $refreshToken
- * @return JsonResponse
- */
- protected function handleRefreshToken(string $refreshToken): JsonResponse
- {
- // 刷新访问令牌
- $tokenData = $this->authService->refreshAccessToken($refreshToken);
- if (!$tokenData) {
- return $this->errorResponse('刷新令牌无效', [], 400);
- }
- return $this->successResponse('令牌刷新成功', $tokenData);
- }
- /**
- * 刷新令牌
- *
- * @param Request $request
- * @return JsonResponse
- */
- public function refresh(Request $request): JsonResponse
- {
- $startTime = microtime(true);
- // 初始化请求日志记录器
- $requestLogger = new \App\Module\System\Services\RequestLogger($request);
- $requestLogger->setRouter("openapi/auth/refresh");
- try {
- $refreshToken = $request->input('refresh_token');
- if (!$refreshToken) {
- $requestLogger->setError('缺少刷新令牌');
- $requestLogger->setRunTime($startTime);
- return $this->errorResponse('缺少刷新令牌', [], 400);
- }
- $tokenData = $this->authService->refreshAccessToken($refreshToken);
- if (!$tokenData) {
- $requestLogger->setError('刷新令牌无效');
- $requestLogger->setRunTime($startTime);
- return $this->errorResponse('刷新令牌无效', [], 400);
- }
- // 记录运行时间
- $requestLogger->setRunTime($startTime);
- return $this->successResponse('令牌刷新成功', $tokenData);
- } catch (\Exception $e) {
- // 记录错误信息和运行时间
- $requestLogger->setError($e->getMessage());
- $requestLogger->setRunTime($startTime);
- return $this->errorResponse('刷新令牌失败', ['message' => $e->getMessage()], 500);
- }
- }
- /**
- * 撤销令牌
- *
- * @param Request $request
- * @return JsonResponse
- */
- public function revoke(Request $request): JsonResponse
- {
- try {
- $token = $request->input('token');
- if (!$token) {
- return $this->errorResponse('缺少令牌', [], 400);
- }
- // 这里可以实现令牌撤销逻辑
- // 暂时返回成功响应
- return $this->successResponse('令牌已撤销');
- } catch (\Exception $e) {
- return $this->errorResponse('撤销令牌失败', ['message' => $e->getMessage()], 500);
- }
- }
- /**
- * 生成JWT令牌
- *
- * @param Request $request
- * @return JsonResponse
- */
- public function jwt(Request $request): JsonResponse
- {
- $startTime = microtime(true);
- // 初始化请求日志记录器
- $requestLogger = new \App\Module\System\Services\RequestLogger($request);
- $requestLogger->setRouter("openapi/auth/jwt");
- try {
- $appId = $request->input('app_id');
- $appSecret = $request->input('app_secret');
- // 验证应用
- $app = $this->openApiService->validateApp($appId, $appSecret);
- if (!$app) {
- $requestLogger->setError('应用认证失败');
- $requestLogger->setRunTime($startTime);
- return $this->errorResponse('应用认证失败', [], 401);
- }
- // 生成JWT令牌
- $payload = [
- 'user_id' => $request->input('user_id', 0),
- 'scopes' => $app->scopes,
- ];
- $token = $this->authService->generateJwtToken($app, $payload);
- // 记录运行时间
- $requestLogger->setRunTime($startTime);
- return $this->successResponse('JWT令牌生成成功', [
- 'token' => $token,
- 'token_type' => 'Bearer',
- 'expires_in' => config('openapi.auth.jwt.expire', 3600),
- ]);
- } catch (\Exception $e) {
- // 记录错误信息和运行时间
- $requestLogger->setError($e->getMessage());
- $requestLogger->setRunTime($startTime);
- return $this->errorResponse('生成JWT令牌失败', ['message' => $e->getMessage()], 500);
- }
- }
- /**
- * 验证JWT令牌
- *
- * @param Request $request
- * @return JsonResponse
- */
- public function verifyJwt(Request $request): JsonResponse
- {
- try {
- $token = $request->input('token');
-
- if (!$token) {
- return $this->errorResponse('缺少令牌', [], 400);
- }
- $payload = $this->authService->validateJwtToken($token);
- if (!$payload) {
- return $this->errorResponse('令牌无效', [], 401);
- }
- return $this->successResponse('令牌验证成功', $payload);
- } catch (\Exception $e) {
- return $this->errorResponse('验证令牌失败', ['message' => $e->getMessage()], 500);
- }
- }
- /**
- * 返回成功响应
- *
- * @param string $message
- * @param array $data
- * @return JsonResponse
- */
- protected function successResponse(string $message, array $data = []): JsonResponse
- {
- return response()->json([
- 'success' => true,
- 'message' => $message,
- 'data' => $data,
- 'timestamp' => time(),
- ]);
- }
- /**
- * 返回错误响应
- *
- * @param string $message
- * @param array $errors
- * @param int $code
- * @return JsonResponse
- */
- protected function errorResponse(string $message, array $errors = [], int $code = 400): JsonResponse
- {
- return response()->json([
- 'success' => false,
- 'message' => $message,
- 'errors' => $errors,
- 'timestamp' => time(),
- ], $code);
- }
- }
|