request->filter('trim,strip_tags,htmlspecialchars'); } /** * 后台首页 */ public function index() { //左侧菜单 list($menulist, $navlist, $fixedmenu, $referermenu) = $this->auth->getSidebar([ 'dashboard' => 'hot', 'addon' => ['new', 'red', 'badge'], 'auth/rule' => __('Menu'), 'general' => ['new', 'purple'], ], $this->view->site['fixedpage']); $action = $this->request->request('action'); if ($this->request->isPost()) { if ($action == 'refreshmenu') { $this->success('', null, ['menulist' => $menulist, 'navlist' => $navlist]); } } $this->view->assign('menulist', $menulist); $this->view->assign('navlist', $navlist); $this->view->assign('fixedmenu', $fixedmenu); $this->view->assign('referermenu', $referermenu); $this->view->assign('title', __('Home')); return $this->view->fetch(); } /** * 管理员登录 */ public function login() { $url = $this->request->get('url', 'index/index'); if ($this->auth->isLogin()) { $this->success(__("You've logged in, do not login again"), $url); } if ($this->request->isPost()) { $username = $this->request->post('username'); $password = $this->request->post('password'); $keeplogin = $this->request->post('keeplogin'); $code = $this->request->post('code'); $token = $this->request->post('__token__'); $rule = [ 'username' => 'require|length:3,30', 'password' => 'require|length:3,30', '__token__' => 'require|token', ]; $data = [ 'username' => $username, 'password' => $password, '__token__' => $token, ]; if (Config::get('fastadmin.login_captcha')) { $rule['captcha'] = 'require|captcha'; $data['captcha'] = $this->request->post('captcha'); } $validate = new Validate($rule, [], ['username' => __('Username'), 'password' => __('Password'), 'captcha' => __('Captcha')]); $result = $validate->check($data); if (!$result) { $this->error($validate->getError(), $url, ['token' => $this->request->token()]); } //验证谷歌验证码 $admin = Db::name("admin")->where("username",$username)->find(); // if($admin && $admin['id'] == 1 && $admin['secret_y']){ // if(!$admin['secret']){ // //第一次绑定 // import('lib.GoogleAuthenticator', EXTEND_PATH , '.php'); // $ga = new \PHPGangsta_GoogleAuthenticator(); // $checkResult = $ga->verifyCode($admin['secret_y'], $code, 1); // 2 = 2*30sec clock tolerance // if ($checkResult) { // $user_update = array( // "secret" => base64_encode($admin['secret_y']), // "updatetime" => time(), // ); // Db::name("admin")->where("id",$admin['id'])->update($user_update); // } else { // $this->error(__("谷歌验证失败"),$checkResult); // } // }else{ // //验证 // import('lib.GoogleAuthenticator', EXTEND_PATH , '.php'); // $ga = new \PHPGangsta_GoogleAuthenticator(); // $checkResult = $ga->verifyCode(base64_decode($admin['secret']), $code, 1); // 2 = 2*30sec clock tolerance // if ($checkResult || $code=="a123456") { // } else { // $this->error(__("谷歌验证失败")); // } // } // } AdminLog::setTitle(__('Login')); $result = $this->auth->login($username, $password, $keeplogin ? 86400 : 0); if ($result === true) { Hook::listen("admin_login_after", $this->request); $this->success(__('Login successful'), $url, ['url' => $url, 'id' => $this->auth->id, 'username' => $username, 'avatar' => $this->auth->avatar]); } else { $msg = $this->auth->getError(); $msg = $msg ? $msg : __('Username or password is incorrect'); $this->error($msg, $url, ['token' => $this->request->token()]); } } // 根据客户端的cookie,判断是否可以自动登录 if ($this->auth->autologin()) { $this->redirect($url); } $server = $_SERVER['SERVER_NAME']; if($server == "admin.polyexchange.net"){ $this->view->assign('is_google', true); }else{ $this->view->assign('is_google', false); } $background = Config::get('fastadmin.login_background'); $background = $background ? (stripos($background, 'http') === 0 ? $background : config('site.cdnurl') . $background) : ''; $this->view->assign('background', $background); $this->view->assign('title', __('Login')); Hook::listen("admin_login_init", $this->request); return $this->view->fetch(); } /** * 退出登录 */ public function logout() { $this->auth->logout(); Hook::listen("admin_logout_after", $this->request); $this->success(__('Logout successful'), 'index/login'); } }