UserManageController.py 22 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522
  1. #!/usr/bin/env python3
  2. # -*- coding: utf-8 -*-
  3. """
  4. @Copyright (C) ansjer cop Video Technology Co.,Ltd.All rights reserved.
  5. @AUTHOR: ASJRD018
  6. @NAME: AnsjerFormal
  7. @software: PyCharm
  8. @DATE: 2018/9/11 15:08
  9. @Version: python3.6
  10. @MODIFY DECORD:ansjer dev
  11. @file: UserController.py
  12. @Contact: chanjunkai@163.com
  13. """
  14. import datetime
  15. import traceback
  16. import time
  17. import logging
  18. import jwt
  19. import oss2
  20. import simplejson
  21. import simplejson as json
  22. import requests
  23. from django.contrib.auth.hashers import make_password, check_password # 对密码加密模块
  24. from django.db.models import Q
  25. from django.http import HttpResponseRedirect
  26. from django.utils.decorators import method_decorator
  27. from django.utils.timezone import utc
  28. from django.views.decorators.csrf import csrf_exempt
  29. from django.views.generic import TemplateView
  30. from jwt.algorithms import RSAAlgorithm
  31. from ratelimit.decorators import ratelimit
  32. from Ansjer.config import AuthCode_Expire, SERVER_DOMAIN, APNS_CONFIG, JPUSH_CONFIG, FCM_CONFIG, TUTK_PUSH_DOMAIN, \
  33. OSS_STS_ACCESS_KEY, OSS_STS_ACCESS_SECRET
  34. from Controller.CheckUserData import DataValid, date_handler, RandomStr
  35. from Model.models import Device_User, Role, UidPushModel, UserOauth2Model, UserExModel, Device_Info, UidSetModel, \
  36. UserAppFrequencyModel, CountryIPModel, CountryModel, UidChannelSetModel, MenuModel, FeedBackModel, StatResModel
  37. from Object.AWS.SesClassObject import SesClassObject
  38. from Object.AliSmsObject import AliSmsObject
  39. from Object.RedisObject import RedisObject
  40. from Object.ResponseObject import ResponseObject
  41. from Object.TokenObject import TokenObject
  42. from Service.CommonService import CommonService
  43. from Service.ModelService import ModelService
  44. from Service.TemplateService import TemplateService
  45. from django.views.generic import View
  46. import base64
  47. import random
  48. from io import BytesIO
  49. from PIL import Image, ImageDraw, ImageFont
  50. from django.shortcuts import HttpResponse
  51. from Ansjer.config import BASE_DIR
  52. # 登录
  53. class LoginView(TemplateView):
  54. @method_decorator(csrf_exempt) # @csrf_exempt
  55. def dispatch(self, *args, **kwargs):
  56. return super(LoginView, self).dispatch(*args, **kwargs)
  57. def post(self, request, *args, **kwargs):
  58. request.encoding = 'utf-8'
  59. request_dict = request.POST
  60. language = request_dict.get('language', 'en')
  61. response = ResponseObject(language,'pc')
  62. return self.validates(request_dict, response)
  63. def validates(self, request_dict, response):
  64. username = request_dict.get('username', None)
  65. password = request_dict.get('password', None)
  66. if not username or not password:
  67. return response.json(111)
  68. username = username.strip()
  69. password = password.strip()
  70. data_valid = DataValid()
  71. if data_valid.email_validate(username):
  72. return self.do_email_login(username, password, response)
  73. elif data_valid.mobile_validate(username):
  74. return self.do_phone_login(username, password, response)
  75. elif data_valid.name_validate(username):
  76. return self.do_name_login(username, password, response)
  77. else:
  78. return response.json(107)
  79. def do_email_login(self, email, password, response):
  80. user_qs = Device_User.objects.filter(Q(username=email) | Q(userEmail=email))
  81. return self.valid_login(user_qs, password, response)
  82. def do_phone_login(self, phone, password, response):
  83. user_qs = Device_User.objects.filter(Q(phone=phone) | Q(username=phone), is_active=True, user_isValid=True)
  84. return self.valid_login(user_qs, password, response)
  85. def do_name_login(self, username, password, response):
  86. user_qs = Device_User.objects.filter(Q(username=username) | Q(phone=username) | Q(userEmail=username),
  87. is_active=True, user_isValid=True)
  88. return self.valid_login(user_qs, password, response)
  89. def valid_login(self, user_qs, password, response):
  90. if not user_qs.exists():
  91. return response.json(104)
  92. # users = user_qs.values('role__rid', 'role__roleName', 'userID', 'role', 'NickName', 'username', 'userEmail',
  93. # 'phone', 'password', 'userIconPath', 'user_isValid', 'is_active')[0]
  94. users = user_qs.values('role__rid', 'role__roleName', 'userID', 'NickName', 'username', 'userEmail',
  95. 'phone', 'password', 'userIconPath')[0]
  96. if not check_password(password, users['password']):
  97. return response.json(111)
  98. userID = users['userID']
  99. tko = TokenObject(returntpye='pc')
  100. res = tko.generate(
  101. data={'userID': userID, 'lang': response.lang, 'user': users['username'], 'm_code': '123413243214'})
  102. if tko.code == 0:
  103. now_time = datetime.datetime.utcnow().replace(tzinfo=utc).astimezone(utc)
  104. user_qs.update(last_login=now_time, language=response.lang)
  105. res['rid'] = users['role__rid']
  106. res['roleName'] = users['role__roleName']
  107. res['permList'] = ModelService.own_permission(userID)
  108. res['userID'] = userID
  109. # 昵称,邮箱,电话,刷新,头像
  110. userIconPath = str(users['userIconPath'])
  111. if userIconPath and userIconPath.find('static/') != -1:
  112. userIconPath = userIconPath.replace('static/', '').replace('\\', '/')
  113. res['userIconUrl'] = SERVER_DOMAIN + 'account/getAvatar/' + userIconPath
  114. else:
  115. res['userIconUrl'] = ''
  116. res['NickName'] = users['NickName'] if users['NickName'] is not None else ''
  117. res['username'] = users['username'] if users['username'] is not None else ''
  118. res['userEmail'] = users['userEmail'] if users['userEmail'] is not None else ''
  119. res['phone'] = users['phone'] if users['phone'] is not None else ''
  120. return response.json(0, res)
  121. else:
  122. return response.json(tko.code)
  123. # 获取登录权限
  124. class GetPermissions(TemplateView):
  125. @method_decorator(csrf_exempt) # @csrf_exempt
  126. def dispatch(self, *args, **kwargs):
  127. return super(GetPermissions, self).dispatch(*args, **kwargs)
  128. def get(self, request, *args, **kwargs):
  129. token = request.META.get('HTTP_AUTHORIZATION')
  130. request.encoding = 'utf-8'
  131. request_dict = request.GET
  132. language = request_dict.get('language', 'en')
  133. response = ResponseObject(language, 'pc')
  134. return self.validates(request_dict,token, response)
  135. def validates(self, request_dict,token, response):
  136. tko = TokenObject(token,returntpye='pc')
  137. response.lang = tko.lang
  138. if tko.code != 0:
  139. return response.json(tko.code)
  140. userID = tko.userID
  141. user_qs = Device_User.objects.filter(userID=userID)
  142. if not user_qs.exists():
  143. return response.json(104)
  144. #待补充逻辑
  145. username = user_qs[0].username
  146. userIconPath = user_qs[0].userIconPath.url
  147. if userIconPath:
  148. if userIconPath.find('static/') != -1:
  149. userIconPath = userIconPath.replace('static/', '').replace('\\', '/')
  150. userIconUrl = SERVER_DOMAIN + 'account/getAvatar/' + userIconPath
  151. role_qs = Role.objects.filter(device_user=userID)
  152. menu_qs = MenuModel.objects.filter(role__in=role_qs,menutype=2);
  153. perms = []
  154. for menu in menu_qs:
  155. perms.append(menu.menu_code)
  156. res={
  157. "code": 200,
  158. "msg": "success",
  159. "data": {
  160. "roles": ["admin"], # 一个用户可包含多个角色如["admin","editor","XXXX"],必须返回,如小项目用不到角色权限请返回 ["admin"]
  161. "ability": ["READ", "WRITE", "DELETE"], # 如果用不到rabc精细化权限可以不返回,建议返回
  162. "username": username, # 用户名,必须返回
  163. "avatar": userIconUrl,# 头像,必须返回
  164. "perms": perms
  165. }
  166. }
  167. return response.json(0, res)
  168. # 获取菜单
  169. class GetList(TemplateView):
  170. @method_decorator(csrf_exempt) # @csrf_exempt
  171. def dispatch(self, *args, **kwargs):
  172. return super(GetList, self).dispatch(*args, **kwargs)
  173. def get(self, request, *args, **kwargs):
  174. token = request.META.get('HTTP_AUTHORIZATION')
  175. request.encoding = 'utf-8'
  176. request_dict = request.GET
  177. language = request_dict.get('language', 'en')
  178. response = ResponseObject(language, 'pc')
  179. return self.validates(request_dict,token, response)
  180. def validates(self, request_dict,token, response):
  181. tko = TokenObject(token,returntpye='pc')
  182. response.lang = tko.lang
  183. if tko.code != 0:
  184. return response.json(tko.code)
  185. userID = tko.userID
  186. role_qs =Role.objects.filter(device_user=userID)
  187. menu_qs = MenuModel.objects.filter(parentId=0,role__in=role_qs,menutype=1);
  188. list = []
  189. for menu in menu_qs:
  190. list.append(
  191. {
  192. 'id': menu.id,
  193. 'parentId': menu.parentId,
  194. 'path': menu.path,
  195. 'name': menu.name,
  196. 'component': menu.component,
  197. 'meta': {
  198. 'hidden': menu.hidden,
  199. 'levelHidden': menu.levelHidden,
  200. 'title': menu.title,
  201. 'icon': menu.icon,
  202. 'isCustomSvg':menu.isCustomSvg,
  203. 'noKeepAlive': menu.noKeepAlive,
  204. 'noClosable':menu.noClosable,
  205. 'badge': menu.badge,
  206. 'tabHidden': menu.tabHidden,
  207. 'activeMenu': menu.activeMenu,
  208. 'dot':menu.dot,
  209. 'dynamicNewTab': menu.dynamicNewTab,
  210. 'sort': menu.sort
  211. }
  212. }
  213. )
  214. menu_qs = MenuModel.objects.filter(role__in=role_qs,menutype=1)
  215. menulist = []
  216. for objlist in list:
  217. menulist.append(self.menulist(menu_qs, objlist))
  218. return response.json(0, {'list': menulist})
  219. def menulist(self, menu_qs, objlist):
  220. if objlist is None:
  221. return
  222. for menu in menu_qs:
  223. if objlist['id'] == menu.parentId:
  224. if 'children' not in objlist:
  225. objlist['children'] = []
  226. obj = {
  227. 'id': menu.id,
  228. 'parentId': menu.parentId,
  229. 'path': menu.path,
  230. 'name': menu.name,
  231. 'component': menu.component,
  232. 'menutype': menu.menutype,
  233. 'menu_code': menu.menu_code,
  234. 'meta': {
  235. 'hidden': menu.hidden,
  236. 'levelHidden': menu.levelHidden,
  237. 'title': menu.title,
  238. 'icon': menu.icon,
  239. 'isCustomSvg': menu.isCustomSvg,
  240. 'noKeepAlive': menu.noKeepAlive,
  241. 'noClosable': menu.noClosable,
  242. 'badge': menu.badge,
  243. 'tabHidden': menu.tabHidden,
  244. 'activeMenu': menu.activeMenu,
  245. 'dot': menu.dot,
  246. 'dynamicNewTab': menu.dynamicNewTab,
  247. 'sort': menu.sort
  248. }
  249. }
  250. objlist['children'].append(
  251. obj
  252. )
  253. self.menulist(menu_qs, obj)
  254. return objlist
  255. class UserManagement(View):
  256. def get(self, request, *args, **kwargs):
  257. request.encoding = 'utf-8'
  258. operation = kwargs.get('operation')
  259. return self.validation(request.GET, request, operation)
  260. def post(self, request, *args, **kwargs):
  261. request.encoding = 'utf-8'
  262. operation = kwargs.get('operation')
  263. return self.validation(request.POST, request, operation)
  264. def validation(self, request_dict, request, operation):
  265. language = request_dict.get('language', 'en')
  266. response = ResponseObject(language, 'pc')
  267. if operation == '??':
  268. return 0
  269. else:
  270. tko = TokenObject(request.META.get('HTTP_AUTHORIZATION'), returntpye='pc')
  271. if tko.code != 0:
  272. return response.json(tko.code)
  273. response.lang = tko.lang
  274. userID = tko.userID
  275. if operation == 'getUserInfo':
  276. return self.getUserInfo(userID, request_dict, response)
  277. elif operation == 'AddOrEditAccount':
  278. return self.AddOrEditAccount(userID, request_dict, response)
  279. elif operation == 'doDelete':
  280. return self.doDelete(userID, request_dict, response)
  281. elif operation == 'resetPassword':
  282. return self.resetPassword(request_dict, response)
  283. elif operation == 'getFeedbackList':
  284. return self.getFeedbackList(request_dict, response)
  285. else:
  286. return response.json(404)
  287. def getUserInfo(self, userID, request_dict, response):
  288. print('request_dict: ', request_dict)
  289. username = request_dict.get('username', '').strip() # 移除字符串头尾的空格
  290. NickName = request_dict.get('NickName', '').strip()
  291. phone = request_dict.get('phone', '').strip()
  292. userEmail = request_dict.get('userEmail', '').strip()
  293. pageNo = request_dict.get('pageNo', None)
  294. pageSize = request_dict.get('pageSize', None)
  295. if not all([pageNo, pageSize]):
  296. return response.json(444)
  297. page = int(pageNo)
  298. line = int(pageSize)
  299. try:
  300. if username or NickName or phone or userEmail:
  301. # 条件查询
  302. if username:
  303. device_user_qs = Device_User.objects.filter(username__contains=username)
  304. if NickName:
  305. device_user_qs = Device_User.objects.filter(NickName__contains=NickName)
  306. if phone:
  307. device_user_qs = Device_User.objects.filter(phone__contains=phone)
  308. if userEmail:
  309. device_user_qs = Device_User.objects.filter(userEmail__contains=userEmail)
  310. if not device_user_qs.exists():
  311. return response.json(0)
  312. total = len(device_user_qs)
  313. device_users = device_user_qs[(page - 1) * line:page * line]
  314. else:
  315. total = Device_User.objects.filter().count()
  316. device_users = Device_User.objects.filter()[(page - 1) * line:page * line]
  317. user_list = []
  318. for device_user in device_users:
  319. role = device_user.role.first()
  320. rid = role.rid if role else 1 # 不存在角色默认分配为'Users'
  321. user_list.append({
  322. 'userID': device_user.userID,
  323. 'username': device_user.username,
  324. 'NickName': device_user.NickName,
  325. 'role': Role.objects.get(rid=rid).roleName,
  326. 'phone': device_user.phone,
  327. 'userEmail': device_user.userEmail,
  328. 'data_joined': device_user.data_joined.strftime("%Y-%m-%d %H:%M:%S"),
  329. 'last_login': device_user.last_login.strftime("%Y-%m-%d %H:%M:%S"),
  330. 'online': device_user.online,
  331. })
  332. print('user_list: ', user_list)
  333. return response.json(0, {'list': user_list, 'total': total})
  334. except Exception as e:
  335. print(e)
  336. return response.json(500, repr(e))
  337. def AddOrEditAccount(self, userID, request_dict, response):
  338. # 添加/编辑用户
  339. print('request_dict: ', request_dict)
  340. username = request_dict.get('username', '').strip() # 移除字符串头尾的空格
  341. userEmail = request_dict.get('userEmail', '').strip()
  342. roleName = request_dict.get('role', None)
  343. password = request_dict.get('password', None)
  344. isEdit = request_dict.get('isEdit', None)
  345. # 校验用户名,邮箱,密码是否符合规则
  346. dataValid = DataValid()
  347. if not username or not dataValid.name_validate(username):
  348. return response.json(444, {'Parameter error': 'username'})
  349. if userEmail and not dataValid.email_validate(userEmail):
  350. return response.json(444, {'Parameter error': 'userEmail'})
  351. if not isEdit: # 添加用户需要输入密码
  352. if not password or not dataValid.password_validate(password):
  353. return response.json(444, {'Parameter error': 'password'})
  354. try:
  355. if isEdit: # 编辑用户信息
  356. userID = request_dict.get('userID')
  357. user_data = {
  358. "username": username,
  359. "NickName": username,
  360. "userEmail": userEmail,
  361. "password": make_password(password),
  362. }
  363. device_user_qs = Device_User.objects.filter(userID=userID)
  364. device_user_qs.update(**user_data)
  365. # 如果角色改变,修改用户角色
  366. device_user_role = device_user_qs[0].role
  367. user_role = device_user_role.first()
  368. if not user_role or roleName != user_role.roleName:
  369. device_user_role.clear()
  370. role_qs = Role.objects.filter(roleName=roleName) # 账号角色
  371. device_user_qs[0].role.set(role_qs)
  372. else: # 添加用户
  373. # 查询邮箱是否已注册
  374. if Device_User.objects.filter(userEmail=userEmail).exists():
  375. return response.json(103)
  376. role_qs = Role.objects.filter(roleName=roleName) # 账号角色
  377. # 创建用户
  378. user_data = {
  379. "username": username,
  380. "NickName": username,
  381. "userEmail": userEmail,
  382. "password": make_password(password),
  383. "userID": CommonService.getUserID(μs=False, setOTAID=True),
  384. "is_active": True,
  385. "user_isValid": True,
  386. }
  387. Device_User.objects.create(**user_data).role.set(role_qs)
  388. return response.json(0)
  389. except Exception as e:
  390. print(e)
  391. return response.json(500, repr(e))
  392. def doDelete(self, userID, request_dict, response):
  393. userID = request_dict.get('userID', '')
  394. Device_User.objects.filter(userID=userID).delete()
  395. return response.json(0)
  396. def resetPassword(self, request_dict, response):
  397. userID = request_dict.get('userID', None)
  398. if not userID:
  399. return response.json(444)
  400. try:
  401. password = '123456'
  402. is_update = Device_User.objects.filter(userID=userID).update(password=make_password(password))
  403. if is_update:
  404. return response.json(0)
  405. else:
  406. return response.json(177)
  407. except Exception as e:
  408. print(e)
  409. return response.json(500, repr(e))
  410. def getFeedbackList(self, request_dict, response):
  411. status = request_dict.get('status', 0)
  412. username = request_dict.get('username', None)
  413. pageNo = request_dict.get('pageNo', None)
  414. pageSize = request_dict.get('pageSize', None)
  415. if not all([pageNo, pageSize]):
  416. return response.json(444)
  417. page = int(pageNo)
  418. line = int(pageSize)
  419. try:
  420. filter_data = {}
  421. if status or username:
  422. if status:
  423. filter_data['status'] = int(status)
  424. if username:
  425. filter_data['userID_id'] = ModelService.get_userID_byname(username)
  426. feed_back_qs = FeedBackModel.objects.filter()
  427. if filter_data:
  428. feed_back_qs = feed_back_qs.filter(**filter_data)
  429. total = feed_back_qs.count()
  430. feed_backs = feed_back_qs[(page - 1) * line:page * line]. values(
  431. 'id',
  432. 'userID__username',
  433. 'userID__phone',
  434. 'userID__userEmail',
  435. 'content',
  436. 'addTime',
  437. 'status',
  438. 'type',
  439. 'app',
  440. 'app_version',
  441. 'phone_model',
  442. 'os_version',
  443. 'uid',
  444. 'appBundleId',
  445. 'score')
  446. feed_back_id_list = [feed_back['id'] for feed_back in feed_backs]
  447. stat_res_qs = StatResModel.objects.filter(
  448. feedbackmodel__id__in=feed_back_id_list).values(
  449. 'name', 'feedbackmodel__id')
  450. auth = oss2.Auth(OSS_STS_ACCESS_KEY, OSS_STS_ACCESS_SECRET)
  451. bucket = oss2.Bucket(
  452. auth, 'oss-cn-hongkong.aliyuncs.com', 'statres')
  453. feed_back_list = []
  454. for feed_back in feed_backs:
  455. feed_back['img_url'] = []
  456. for stat_res in stat_res_qs:
  457. if stat_res['feedbackmodel__id'] == feed_back['id']:
  458. obj = 'feedback/' + stat_res['name']
  459. img_url = bucket.sign_url('GET', obj, 3600)
  460. feed_back['img_url'].append(img_url)
  461. if not feed_back['userID__username']:
  462. feed_back['userID__username'] = feed_back['userID__userEmail'] if feed_back[
  463. 'userID__userEmail'] else feed_back['userID__phone']
  464. feed_back_list.append(feed_back)
  465. return response.json(0, {'list': feed_back_list, 'total': total})
  466. except Exception as e:
  467. print(e)
  468. return response.json(500, repr(e))