UserController.java
2.9 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
package com.bsth.controller.sys;
import javax.servlet.http.HttpServletRequest;
import javax.servlet.http.HttpSession;
import org.springframework.beans.factory.annotation.Autowired;
import org.springframework.security.authentication.BadCredentialsException;
import org.springframework.security.crypto.bcrypt.BCryptPasswordEncoder;
import org.springframework.security.web.authentication.session.SessionAuthenticationException;
import org.springframework.web.bind.annotation.RequestMapping;
import org.springframework.web.bind.annotation.RequestParam;
import org.springframework.web.bind.annotation.RestController;
import com.bsth.controller.BaseController;
import com.bsth.entity.sys.SysUser;
import com.bsth.security.util.SecurityUtils;
import com.bsth.service.sys.SysUserService;
@RestController
@RequestMapping("user")
public class UserController extends BaseController<SysUser, Integer>{
@Autowired
SysUserService sysUserService;
/**
*
* @Title: loginFailure
* @Description: TODO(查询登录失败的详细信息)
* @param @param request
* @return String 返回类型
* @throws
*/
@RequestMapping("/loginFailure")
public String loginFailure(HttpServletRequest request){
String msg = "";
HttpSession session = request.getSession();
Object obj = session.getAttribute("SPRING_SECURITY_LAST_EXCEPTION");
if(obj instanceof BadCredentialsException)
msg = "登录失败,用户名或密码错误.";
else if(obj instanceof SessionAuthenticationException)
msg = "登录失败,当前策略不允许重复登录.";
session.removeAttribute("SPRING_SECURITY_LAST_EXCEPTION");
return msg;
}
@RequestMapping("/currentUser")
public SysUser currentUser(){
return SecurityUtils.getCurrentUser();
}
/**
* @Title changeEnabled
* @Description: TODO(改变用户状态)
* @param id 用户ID
* @param enabled 状态
* @return
*/
@RequestMapping("/changeEnabled")
public int changeEnabled(@RequestParam int id,@RequestParam int enabled){
return sysUserService.changeEnabled(id,enabled);
}
/**
* @Title changePWD
* @Description: TODO(修改密码)
* @param oldPWD 原始密码
* @param newwPWD 新密码
* @param cnewPWD 确认新密码
* @return
*/
@RequestMapping("/changePWD")
public String changePWD(@RequestParam String oldPWD,@RequestParam String newPWD,@RequestParam String cnewPWD){
SysUser sysUser = SecurityUtils.getCurrentUser();
String msg = "";
if(new BCryptPasswordEncoder(4).matches(oldPWD, sysUser.getPassword())){
if(oldPWD.equals(newPWD)){
msg = "新密码不能跟原始密码一样!";
}else{
if(newPWD.equals(cnewPWD)){
sysUserService.changePWD(sysUser.getId(),newPWD);
msg = "修改成功!";
}else{
msg= "新密码两次输入不一致!";
}
}
}else{
msg = "原始密码错误!";
}
return msg;
}
}