'require|in:' . AdminTerminalEnum::PC . ',' . AdminTerminalEnum::MOBILE, 'account' => 'require', 'password' => 'require|password', ]; protected $message = [ 'account.require' => '请输入账号', 'password.require' => '请输入密码' ]; /** * @notes @notes 密码验证 * @param $password * @param $other * @param $data * @return bool|string * @throws \think\db\exception\DataNotFoundException * @throws \think\db\exception\DbException * @throws \think\db\exception\ModelNotFoundException * @author 令狐冲 * @date 2021/7/2 14:00 */ public function password($password, $other, $data) { // 登录限制 $config = [ 'login_restrictions' => ConfigService::get('admin_login', 'login_restrictions'), 'password_error_times' => ConfigService::get('admin_login', 'password_error_times'), 'limit_login_time' => ConfigService::get('admin_login', 'limit_login_time'), 'google_auth' => ConfigService::get('website', 'agent_google_auth'), ]; $adminAccountSafeCache = new AdminAccountSafeCache(); if ($config['login_restrictions'] == 1) { $adminAccountSafeCache->count = $config['password_error_times']; $adminAccountSafeCache->minute = $config['limit_login_time']; } //后台账号安全机制,连续输错后锁定,防止账号密码暴力破解 if ($config['login_restrictions'] == 1 && !$adminAccountSafeCache->isSafe()) { return '密码连续' . $adminAccountSafeCache->count . '次输入错误,请' . $adminAccountSafeCache->minute . '分钟后重试'; } $where = []; $login_way = $data['login_way'];//0邮箱1手机号 if($login_way == 1){ $where = ['country_code' => $data['country_code']]; } $userInfo = User::where($where) ->where(['account|mobile' => $data['account'],'is_agent' => 1]) ->field(['id,password,is_disable,is_open,agent_id']) ->findOrEmpty(); if ($userInfo->isEmpty()) { return '用户不存在';//用户不存在 } if ($userInfo['is_open'] === YesNoEnum::NO) { return '用户未启用';//用户未启用 } if ($userInfo['is_disable'] === YesNoEnum::YES) { return '用户已禁用';//用户已禁用 } $user_info = UserInfo::where(['user_id' => $userInfo['id']])->findOrEmpty(); if($config['google_auth'] == 1){ if(!$user_info->isEmpty() && $user_info['google_key']){ if(!$data['code']){ $adminAccountSafeCache->record(); return '请输入谷歌验证码'; } $valid = UtilsService::get_google_verify($user_info['google_key'],$data['code']); if(!$valid) { $adminAccountSafeCache->record(); return '验证码错误'; } }else{ $adminAccountSafeCache->record(); return '验证码错误'; } } $passwordSalt = Config::get('project.unique_identification'); if ($userInfo['password'] !== create_password($password, $passwordSalt)) { $adminAccountSafeCache->record(); return '密码错误';//密码错误 } $adminInfo = Admin::where('id', '=', $userInfo['agent_id']) ->where(['is_agent' => 1]) ->findOrEmpty(); if ($adminInfo->isEmpty()) { return '参数异常';//参数异常 } $adminAccountSafeCache->relieve(); return true; } }