mock平台

base.js 7.9KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315
  1. const yapi = require('../yapi.js');
  2. const projectModel = require('../models/project.js');
  3. const userModel = require('../models/user.js');
  4. const interfaceModel = require('../models/interface.js');
  5. const groupModel = require('../models/group.js');
  6. const tokenModel = require('../models/token.js');
  7. const _ = require('underscore');
  8. const jwt = require('jsonwebtoken');
  9. const {parseToken} = require('../utils/token')
  10. class baseController {
  11. constructor(ctx) {
  12. this.ctx = ctx;
  13. //网站上线后,role对象key是不能修改的,value可以修改
  14. this.roles = {
  15. admin: 'Admin',
  16. member: '网站会员'
  17. };
  18. }
  19. async init(ctx) {
  20. this.$user = null;
  21. this.tokenModel = yapi.getInst(tokenModel);
  22. this.projectModel = yapi.getInst(projectModel);
  23. let ignoreRouter = [
  24. '/api/user/login_by_token',
  25. '/api/user/login',
  26. '/api/user/reg',
  27. '/api/user/status',
  28. '/api/user/logout',
  29. '/api/user/avatar',
  30. '/api/user/login_by_ldap'
  31. ];
  32. if (ignoreRouter.indexOf(ctx.path) > -1) {
  33. this.$auth = true;
  34. } else {
  35. await this.checkLogin(ctx);
  36. }
  37. let openApiRouter = [
  38. '/api/open/run_auto_test',
  39. '/api/open/import_data',
  40. '/api/interface/add',
  41. '/api/interface/save',
  42. '/api/interface/up',
  43. '/api/interface/get',
  44. '/api/interface/list',
  45. '/api/interface/list_menu',
  46. '/api/interface/add_cat',
  47. '/api/interface/getCatMenu',
  48. '/api/interface/list_cat',
  49. '/api/project/get',
  50. '/api/plugin/export'
  51. ];
  52. let params = Object.assign({}, ctx.query, ctx.request.body);
  53. let token = params.token;
  54. // 如果前缀是 /api/open,执行 parse token 逻辑
  55. if (token && (openApiRouter.indexOf(ctx.path) > -1 || ctx.path.indexOf('/api/open/') === 0 )) {
  56. let tokens = parseToken(token)
  57. const oldTokenUid = '999999'
  58. let tokenUid = oldTokenUid;
  59. if(!tokens){
  60. let checkId = await this.getProjectIdByToken(token);
  61. if(!checkId)return;
  62. }else{
  63. token = tokens.projectToken;
  64. tokenUid = tokens.uid;
  65. }
  66. // if (this.$auth) {
  67. // ctx.params.project_id = await this.getProjectIdByToken(token);
  68. // if (!ctx.params.project_id) {
  69. // return (this.$tokenAuth = false);
  70. // }
  71. // return (this.$tokenAuth = true);
  72. // }
  73. let checkId = await this.getProjectIdByToken(token);
  74. if(!checkId){
  75. ctx.body = yapi.commons.resReturn(null, 42014, 'token 无效');
  76. }
  77. let projectData = await this.projectModel.get(checkId);
  78. if (projectData) {
  79. ctx.query.pid = checkId; // 兼容:/api/plugin/export
  80. ctx.params.project_id = checkId;
  81. this.$tokenAuth = true;
  82. this.$uid = tokenUid;
  83. let result;
  84. if(tokenUid === oldTokenUid){
  85. result = {
  86. _id: tokenUid,
  87. role: 'member',
  88. username: 'system'
  89. }
  90. }else{
  91. let userInst = yapi.getInst(userModel); //创建user实体
  92. result = await userInst.findById(tokenUid);
  93. }
  94. this.$user = result;
  95. this.$auth = true;
  96. }
  97. }
  98. }
  99. async getProjectIdByToken(token) {
  100. let projectId = await this.tokenModel.findId(token);
  101. if (projectId) {
  102. return projectId.toObject().project_id;
  103. }
  104. }
  105. getUid() {
  106. return parseInt(this.$uid, 10);
  107. }
  108. async checkLogin(ctx) {
  109. let token = ctx.cookies.get('_yapi_token');
  110. let uid = ctx.cookies.get('_yapi_uid');
  111. try {
  112. if (!token || !uid) {
  113. return false;
  114. }
  115. let userInst = yapi.getInst(userModel); //创建user实体
  116. let result = await userInst.findById(uid);
  117. if (!result) {
  118. return false;
  119. }
  120. let decoded;
  121. try {
  122. decoded = jwt.verify(token, result.passsalt);
  123. } catch (err) {
  124. return false;
  125. }
  126. if (decoded.uid == uid) {
  127. this.$uid = uid;
  128. this.$auth = true;
  129. this.$user = result;
  130. return true;
  131. }
  132. return false;
  133. } catch (e) {
  134. yapi.commons.log(e, 'error');
  135. return false;
  136. }
  137. }
  138. async checkRegister() {
  139. // console.log('config', yapi.WEBCONFIG);
  140. if (yapi.WEBCONFIG.closeRegister) {
  141. return false;
  142. } else {
  143. return true;
  144. }
  145. }
  146. async checkLDAP() {
  147. // console.log('config', yapi.WEBCONFIG);
  148. if (!yapi.WEBCONFIG.ldapLogin) {
  149. return false;
  150. } else {
  151. return yapi.WEBCONFIG.ldapLogin.enable || false;
  152. }
  153. }
  154. /**
  155. *
  156. * @param {*} ctx
  157. */
  158. async getLoginStatus(ctx) {
  159. let body;
  160. if ((await this.checkLogin(ctx)) === true) {
  161. let result = yapi.commons.fieldSelect(this.$user, [
  162. '_id',
  163. 'username',
  164. 'email',
  165. 'up_time',
  166. 'add_time',
  167. 'role',
  168. 'type',
  169. 'study'
  170. ]);
  171. body = yapi.commons.resReturn(result);
  172. } else {
  173. body = yapi.commons.resReturn(null, 40011, '请登录...');
  174. }
  175. body.ladp = await this.checkLDAP();
  176. body.canRegister = await this.checkRegister();
  177. ctx.body = body;
  178. }
  179. getRole() {
  180. return this.$user.role;
  181. }
  182. getUsername() {
  183. return this.$user.username;
  184. }
  185. getEmail() {
  186. return this.$user.email;
  187. }
  188. async getProjectRole(id, type) {
  189. let result = {};
  190. try {
  191. if (this.getRole() === 'admin') {
  192. return 'admin';
  193. }
  194. if (type === 'interface') {
  195. let interfaceInst = yapi.getInst(interfaceModel);
  196. let interfaceData = await interfaceInst.get(id);
  197. result.interfaceData = interfaceData;
  198. // 项目创建者相当于 owner
  199. if (interfaceData.uid === this.getUid()) {
  200. return 'owner';
  201. }
  202. type = 'project';
  203. id = interfaceData.project_id;
  204. }
  205. if (type === 'project') {
  206. let projectInst = yapi.getInst(projectModel);
  207. let projectData = await projectInst.get(id);
  208. if (projectData.uid === this.getUid()) {
  209. // 建立项目的人
  210. return 'owner';
  211. }
  212. let memberData = _.find(projectData.members, m => {
  213. if (m && m.uid === this.getUid()) {
  214. return true;
  215. }
  216. });
  217. if (memberData && memberData.role) {
  218. if (memberData.role === 'owner') {
  219. return 'owner';
  220. } else if (memberData.role === 'dev') {
  221. return 'dev';
  222. } else {
  223. return 'guest';
  224. }
  225. }
  226. type = 'group';
  227. id = projectData.group_id;
  228. }
  229. if (type === 'group') {
  230. let groupInst = yapi.getInst(groupModel);
  231. let groupData = await groupInst.get(id);
  232. // 建立分组的人
  233. if (groupData.uid === this.getUid()) {
  234. return 'owner';
  235. }
  236. let groupMemberData = _.find(groupData.members, m => {
  237. if (m.uid === this.getUid()) {
  238. return true;
  239. }
  240. });
  241. if (groupMemberData && groupMemberData.role) {
  242. if (groupMemberData.role === 'owner') {
  243. return 'owner';
  244. } else if (groupMemberData.role === 'dev') {
  245. return 'dev';
  246. } else {
  247. return 'guest';
  248. }
  249. }
  250. }
  251. return 'member';
  252. } catch (e) {
  253. yapi.commons.log(e, 'error');
  254. return false;
  255. }
  256. }
  257. /**
  258. * 身份验证
  259. * @param {*} id type对应的id
  260. * @param {*} type enum[interface, project, group]
  261. * @param {*} action enum[ danger, edit, view ] danger只有owner或管理员才能操作,edit只要是dev或以上就能执行
  262. */
  263. async checkAuth(id, type, action) {
  264. let role = await this.getProjectRole(id, type);
  265. if (action === 'danger') {
  266. if (role === 'admin' || role === 'owner') {
  267. return true;
  268. }
  269. } else if (action === 'edit') {
  270. if (role === 'admin' || role === 'owner' || role === 'dev') {
  271. return true;
  272. }
  273. } else if (action === 'view') {
  274. if (role === 'admin' || role === 'owner' || role === 'dev' || role === 'guest') {
  275. return true;
  276. }
  277. }
  278. return false;
  279. }
  280. }
  281. module.exports = baseController;