mysql.ts 7.3 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287
  1. import * as mysql from "mysql2"
  2. import secret from "../../config"
  3. import * as jwt from "jsonwebtoken"
  4. import { createHash } from "crypto"
  5. import Logger from "../../loaders/logger"
  6. import { Request, Response } from "express"
  7. import { createMathExpr } from "svg-captcha"
  8. import getFormatDate from "../../utils/date"
  9. import { connection } from "../../utils/initMysql"
  10. export interface dataModel {
  11. length: number
  12. }
  13. // 保存验证码
  14. let generateVerify: number
  15. /**
  16. * @typedef Error
  17. * @property {string} code.required
  18. */
  19. /**
  20. * @typedef Response
  21. * @property {[integer]} code
  22. */
  23. /**
  24. * @typedef Login
  25. * @property {string} username.required - 用户名 - eg: admin
  26. * @property {string} password.required - 密码 - eg: 123456
  27. * @property {integer} verify.required - 验证码
  28. */
  29. /**
  30. * 登录
  31. * @route POST /login
  32. * @param {Login.model} point.body.required - the new point
  33. * @produces application/json application/xml
  34. * @consumes application/json application/xml
  35. * @summary 登录
  36. * @group 用户登录、注册相关
  37. * @returns {Response.model} 200
  38. * @returns {Array.<Login>} Login
  39. * @headers {integer} 200.X-Rate-Limit
  40. * @headers {string} 200.X-Expires-After
  41. * @security JWT
  42. */
  43. const login = async (req: Request, res: Response) => {
  44. const { username, password, verify } = req.body
  45. if (generateVerify !== verify) return res.json({
  46. code: -1,
  47. info: "请输入正确的验证码"
  48. })
  49. let sql: string = 'select * from users where username=' + "'" + username + "'"
  50. connection.query(sql, async function (err, data: dataModel) {
  51. if (data.length == 0) {
  52. await res.json({
  53. code: -1,
  54. info: "账号尚未被注册"
  55. })
  56. } else {
  57. if (createHash('md5').update(password).digest('hex') == data[0].password) {
  58. const accessToken = jwt.sign({
  59. accountId: data[0].id
  60. }, secret.jwtSecret, { expiresIn: 3600 })
  61. await res.json({
  62. code: 0,
  63. info: "登录成功",
  64. accessToken
  65. })
  66. } else {
  67. await res.json({
  68. code: -1,
  69. info: "密码错误"
  70. })
  71. }
  72. }
  73. })
  74. }
  75. /**
  76. * @typedef Register
  77. * @property {string} username.required - 用户名 - eg: admin
  78. * @property {string} password.required - 密码 - eg: 123456
  79. * @property {integer} verify.required - 验证码
  80. */
  81. /**
  82. * 注册
  83. * @route POST /register
  84. * @param {Register.model} point.body.required - the new point
  85. * @produces application/json application/xml
  86. * @consumes application/json application/xml
  87. * @summary 注册
  88. * @group 用户登录、注册相关
  89. * @returns {Response.model} 200
  90. * @returns {Array.<Register>} Register
  91. * @headers {integer} 200.X-Rate-Limit
  92. * @headers {string} 200.X-Expires-After
  93. * @security JWT
  94. */
  95. const register = async (req: Request, res: Response) => {
  96. const { username, password, verify } = req.body
  97. if (generateVerify !== verify) return res.json({
  98. code: -1,
  99. info: "请输入正确的验证码"
  100. })
  101. if (password.length < 6) return res.json({
  102. code: -1,
  103. info: "密码长度不能小于6位"
  104. })
  105. let sql: string = 'select * from users where username=' + "'" + username + "'"
  106. connection.query(sql, async (err, data: dataModel) => {
  107. if (data.length > 0) {
  108. await res.json({
  109. code: -1,
  110. info: "账号已被注册"
  111. })
  112. } else {
  113. let time = await getFormatDate()
  114. let sql: string = 'insert into users (username,password,time) value(' + "'" + username + "'" + ',' + "'" + createHash('md5').update(password).digest('hex') +
  115. "'" + ',' + "'" + time + "'" + ')'
  116. connection.query(sql, async function (err) {
  117. if (err) {
  118. Logger.error(err)
  119. } else {
  120. await res.json({
  121. code: 0,
  122. info: "账号注册成功"
  123. })
  124. }
  125. })
  126. }
  127. })
  128. }
  129. /**
  130. * 列表更新
  131. * @route GET /updateList
  132. * @summary 列表更新
  133. * @group 用户管理相关
  134. * @returns {object} 200
  135. * @security JWT
  136. */
  137. const updateList = async (req: Request, res: Response) => {
  138. res.json({ code: 1, msg: "成功" })
  139. }
  140. /**
  141. * 列表删除
  142. * @route GET /deleteList
  143. * @summary 列表删除
  144. * @group 用户管理相关
  145. * @returns {object} 200
  146. * @security JWT
  147. */
  148. const deleteList = async (req: Request, res: Response) => {
  149. res.json({ code: 1, msg: "成功" })
  150. }
  151. /**
  152. * @typedef SearchPage
  153. * @property {integer} page.required - 第几页 - eg: 1
  154. * @property {integer} size.required - 数据量(条)- eg: 5
  155. */
  156. /**
  157. * 分页查询
  158. * @route POST /searchPage
  159. * @param {SearchPage.model} point.body.required - the new point
  160. * @produces application/json application/xml
  161. * @consumes application/json application/xml
  162. * @summary 分页查询
  163. * @group 用户管理相关
  164. * @returns {Response.model} 200
  165. * @returns {Array.<SearchPage>} SearchPage
  166. * @headers {integer} 200.X-Rate-Limit
  167. * @headers {string} 200.X-Expires-After
  168. * @security JWT
  169. */
  170. const searchPage = async (req: Request, res: Response) => {
  171. const { page, size } = req.body
  172. let payload = null
  173. try {
  174. const authorizationHeader = req.get("Authorization")
  175. const accessToken = authorizationHeader.substr("Bearer ".length)
  176. payload = jwt.verify(accessToken, secret.jwtSecret)
  177. } catch (error) {
  178. return res.status(401).end()
  179. }
  180. let sql = 'select * from users limit ' + size + ' offset ' + size * (page - 1)
  181. connection.query(sql, async function (err, data) {
  182. if (err) {
  183. Logger.error(err)
  184. } else {
  185. await res.json({
  186. code: 0,
  187. info: data
  188. })
  189. }
  190. })
  191. }
  192. /**
  193. * @typedef SearchVague
  194. * @property {string} username.required - 用户名 - eg: admin
  195. */
  196. /**
  197. * 模糊查询(根据用户名)
  198. * @route POST /searchVague
  199. * @param {SearchVague.model} point.body.required - the new point
  200. * @produces application/json application/xml
  201. * @consumes application/json application/xml
  202. * @summary 模糊查询
  203. * @group 用户管理相关
  204. * @returns {Response.model} 200
  205. * @returns {Array.<SearchVague>} SearchVague
  206. * @headers {integer} 200.X-Rate-Limit
  207. * @headers {string} 200.X-Expires-After
  208. * @security JWT
  209. */
  210. const searchVague = async (req: Request, res: Response) => {
  211. const { username } = req.body
  212. let payload = null
  213. try {
  214. const authorizationHeader = req.get("Authorization")
  215. const accessToken = authorizationHeader.substr("Bearer ".length)
  216. payload = jwt.verify(accessToken, secret.jwtSecret)
  217. } catch (error) {
  218. return res.status(401).end()
  219. }
  220. if (username === "" || username === null) return res.json({
  221. code: -1,
  222. info: "搜索信息不能为空"
  223. })
  224. let sql = 'select * from users'
  225. sql += " WHERE username LIKE " + mysql.escape("%" + username + "%")
  226. connection.query(sql, function (err, data) {
  227. connection.query(sql, async function (err) {
  228. if (err) {
  229. Logger.error(err)
  230. } else {
  231. await res.json({
  232. code: 0,
  233. info: data
  234. })
  235. }
  236. })
  237. })
  238. }
  239. /**
  240. * 图形验证码
  241. * @route GET /captcha
  242. * @summary 图形验证码
  243. * @group captcha - 图形验证码
  244. * @returns {object} 200
  245. * @security JWT
  246. */
  247. const captcha = async (req: Request, res: Response) => {
  248. const create = createMathExpr({
  249. mathMin: 1,
  250. mathMax: 4,
  251. mathOperator: "+"
  252. })
  253. generateVerify = Number(create.text)
  254. res.type('svg') // 响应的类型
  255. res.json({ code: 1, msg: create.text, svg: create.data })
  256. }
  257. export {
  258. login,
  259. register,
  260. updateList,
  261. deleteList,
  262. searchPage,
  263. searchVague,
  264. captcha,
  265. }