package cn.gistack.auth.granter;
|
|
import cn.gistack.auth.utils.TokenUtil;
|
import cn.gistack.common.cache.CacheNames;
|
import org.springblade.core.redis.cache.BladeRedis;
|
import org.springblade.core.tool.utils.StringUtil;
|
import org.springframework.security.authentication.*;
|
import org.springframework.security.core.Authentication;
|
import org.springframework.security.oauth2.common.exceptions.InvalidGrantException;
|
import org.springframework.security.oauth2.common.exceptions.UserDeniedAuthorizationException;
|
import org.springframework.security.oauth2.provider.*;
|
import org.springframework.security.oauth2.provider.token.AbstractTokenGranter;
|
import org.springframework.security.oauth2.provider.token.AuthorizationServerTokenServices;
|
|
import java.util.LinkedHashMap;
|
import java.util.Map;
|
|
/**
|
* 验证码TokenGranter
|
*
|
* @author Chill
|
*/
|
public class AccountPhoneTokenGranter extends AbstractTokenGranter {
|
|
private static final String GRANT_TYPE = "accountPhone";
|
|
private final AuthenticationManager authenticationManager;
|
|
private BladeRedis bladeRedis;
|
|
public AccountPhoneTokenGranter(AuthenticationManager authenticationManager,
|
AuthorizationServerTokenServices tokenServices, ClientDetailsService clientDetailsService, OAuth2RequestFactory requestFactory, BladeRedis bladeRedis) {
|
this(authenticationManager, tokenServices, clientDetailsService, requestFactory, GRANT_TYPE);
|
this.bladeRedis = bladeRedis;
|
}
|
|
protected AccountPhoneTokenGranter(AuthenticationManager authenticationManager, AuthorizationServerTokenServices tokenServices,
|
ClientDetailsService clientDetailsService, OAuth2RequestFactory requestFactory, String grantType) {
|
super(tokenServices, clientDetailsService, requestFactory, grantType);
|
this.authenticationManager = authenticationManager;
|
}
|
|
@Override
|
protected OAuth2Authentication getOAuth2Authentication(ClientDetails client, TokenRequest tokenRequest) {
|
Map<String, String> parameters = new LinkedHashMap<String, String>(tokenRequest.getRequestParameters());
|
String phone = parameters.get("username");
|
String password = parameters.get("password");
|
String code = parameters.get("code");
|
// 获取验证码
|
String redisCode = bladeRedis.get(CacheNames.PHONE_KEY + phone);
|
// 判断验证码
|
if (code == null || !StringUtil.equalsIgnoreCase(redisCode, code)) {
|
throw new UserDeniedAuthorizationException(TokenUtil.CAPTCHA_NOT_CORRECT);
|
}
|
// 通过手机号查询用户
|
Authentication userAuth = new UsernamePasswordAuthenticationToken(phone, "CUSTOM_LOGIN_SMS");
|
((AbstractAuthenticationToken) userAuth).setDetails(parameters);
|
try {
|
userAuth = authenticationManager.authenticate(userAuth);
|
}
|
catch (AccountStatusException | BadCredentialsException ase) {
|
//covers expired, locked, disabled cases (mentioned in section 5.2, draft 31)
|
throw new InvalidGrantException(ase.getMessage());
|
}
|
// If the username/password are wrong the spec says we should send 400/invalid grant
|
|
if (userAuth == null || !userAuth.isAuthenticated()) {
|
throw new InvalidGrantException("Could not authenticate user: " + phone);
|
}
|
|
OAuth2Request storedOAuth2Request = getRequestFactory().createOAuth2Request(client, tokenRequest);
|
return new OAuth2Authentication(storedOAuth2Request, userAuth);
|
}
|
}
|