admin 发表于 2024-5-26 13:03:31

微擎手机端开发掉用系统验证码

//引入验证码类
<?php
defined('IN_IA') and defined('IN_MOBILE') or exit('Access Denied');
global $_W, $_GPC;
load()->model('user');
load()->model('message');
load()->classs('oauth2/oauth2client');
load()->model('setting');

$settings = $this->module['config'];
/*if ($_SESSION['admin']){
echo $_SESSION['admin'];
}*/

               
      //message($_SESSION['admin']."欢迎回来,{$admin['name']}。", $this->createMobileUrl('login', array('p' => 'admin')));

$cgc_kanjia_zhuli_shop = new common_model("cgc_kanjia_zhuli_shop");
//      message('hkl'.$settings['version_desc']);
/*if (!empty($_GPC['id']) && !empty($_GPC['code'])) {
      $admin = $cgc_kanjia_zhuli_shop->getOne($_GPC['id']);      
      if (empty($admin)) {
                message('请登录', $this->createMobileUrl('login', array('p' => 'admin')), 'SUCCESS');
      }
      
      $code = md5($admin['loginname'] . $admin['password']);
      if ($code == $_GPC['code']) {               
                $_SESSION['admin'] = $admin;
                message('', $this->createMobileUrl('goods', array('p' => 'admin', 'op' => 'info')), 'SUCCESS');
               
      } else {
                message('请登录', $this->createMobileUrl('login', array('p' => 'admin')), 'SUCCESS');
      }
}
*/
if (checksubmit('login')) {
      $loginname = trim($_GPC['loginname']);
      
      $verify = trim($_GPC['verify']);
      if (empty($verify)) {
                message('请输入验证码', '', 'error');
      }
      $result = checkAdminCaptcha($verify, $this->modulename);
      if (empty($result)) {
                message('验证码错误了,可重新换一张验证码图片在输入.', '', 'error');
      }
      if (empty($loginname)) {
                message('请输入要登录的用户名', '', 'error');
      }
      $password = $_GPC['password'];
      
      if (empty($password)) {
                message('请输入密码', '', 'error');
      }
      $con = " loginname = '{$loginname}'";

      $admin = $cgc_kanjia_zhuli_shop->getByCon($con);
      
      if (empty($admin)) {
                message('登录失败,请检查您输入的用户名和密码1!');
      }
      
      if (md5($password) == $admin['password']) {
                if ($admin['status'] != 1) {
                        message('您的账号已被禁用!', '', 'error');
                }
               
                if(!empty($admin['validity_date'])&&$admin['validity_date']<=time()){
                        message('您的账号已过期!','','error');
                }
               
                //$_SESSION['cgc_kanjia_zhuli_admin'] = $admin;
                $_SESSION['admin'] = $admin['id'];
               
               
               
                if(!empty($settings['login_user'])&& !empty($settings['login_password']) && empty($_GPC['__session'])){
                        $_GPC['username'] = $settings['login_user'];
                        $_GPC['password'] = $settings['login_password'];         
                        _login(array('username'=>$_GPC['username'],'password'=>$_GPC['password']),$this->createMobileUrl('goods', array('p' => 'admin')));
                     
                }
               
                header("location:".$this->createMobileUrl('goods', array('p' => 'admin')));               
                //message("欢迎回来,{$admin['name']}。", $this->createMobileUrl('login', array('p' => 'admin')));
      } else {
                message('登录失败,请检查您输入的用户名和密码!', '', 'error');
      }
      
}


if ($_GPC['userkey']){
   getUserKey();
}
if ($settings['template_mode'] == 1) {
      include $this->template("login1");
      exit();
}
include $this->template("login1");
exit();

if ($_GPC['op'] == 'loginout') {
unset($_SESSION['admin']);
unset($_SESSION['cgc_kanjia_zhuli_admin']);
//if $cookie['hash']
/*isetcookie('__session', '', -10000);
isetcookie('__switch', '', -10000);*/

message('已退出登录', $this->createMobileUrl('login', array('p' => 'admin')), 'SUCCESS');
}


function checkAdminCaptcha($code, $modulename) {
      global $_W, $_GPC;
      session_start();
      $codehash = md5(strtolower($code));
      if (!empty($_GPC[$modulename . '_admin_code']) && $codehash == $_SESSION[$modulename . '_admin_code']) {
                $return = true;
      } else {
               
                $return = false;
      }
      $_SESSION[$modulename . '_admin_code'] = '';
      isetcookie($modulename . '_admin_code', '');
      return $return;
}


function _login($member,$forward = '') {
      global $_GPC, $_W;
      if (empty($_GPC['login_type'])) {
                $_GPC['login_type'] = 'system';
      }
      
      if (empty($_GPC['handle_type'])) {
                $_GPC['handle_type'] = 'login';
      }
      
/*      if ($_GPC['handle_type'] == 'login') {
                $zz=OAuth2Client::create($_GPC['login_type'], $_W['setting']['thirdlogin'][$_GPC['login_type']]['appid'], $_W['setting']['thirdlogin'][$_GPC['login_type']]['appsecret']);
                print_r(get_class($zz));
      exit("dd");
                $member = OAuth2Client::create($_GPC['login_type'], $_W['setting']['thirdlogin'][$_GPC['login_type']]['appid'], $_W['setting']['thirdlogin'][$_GPC['login_type']]['appsecret'])->login();
      } else {
               
                //$member = OAuth2Client::create($_GPC['login_type'], $_W['setting']['thirdlogin'][$_GPC['login_type']]['appid'], $_W['setting']['thirdlogin'][$_GPC['login_type']]['appsecret'])->bind();
      }*/


      $record = user_single($member);
      if (!empty($record)) {      
                $_W['uid'] = $record['uid'];
                $_W['user'] = $record;
                $cookie = array();
                $cookie['uid'] = $record['uid'];
                $cookie['lastvisit'] = $record['lastvisit'];
                $cookie['lastip'] = $record['lastip'];
                $cookie['hash'] = md5($record['password'] . $record['salt']);
                $session = authcode(json_encode($cookie), 'encode');
                isetcookie('__session', $session, !empty($_GPC['rember']) ? 7 * 86400 : 0, true);
                $status = array();
                /*$status['uid'] = $record['uid'];
                $status['lastvisit'] = TIMESTAMP;
                $status['lastip'] = CLIENT_IP;
                user_update($status);*/
            //$_SESSION['user_destroy'] = $true;
      

                message("欢迎回来。",$forward);
      } else {
      
                //message('登录失败,账号和密码', '', '');
      }
}
自定义验证码验证函数
function checkAdminCaptcha($code, $modulename) {
      global $_W, $_GPC;
      session_start();
      $codehash = md5(strtolower($code));
      if (!empty($_GPC[$modulename . '_admin_code']) && $codehash == $_SESSION[$modulename . '_admin_code']) {
                $return = true;
      } else {
               
                $return = false;
      }
      $_SESSION[$modulename . '_admin_code'] = '';
      isetcookie($modulename . '_admin_code', '');
      return $return;
}引自百川砍价

页: [1]
查看完整版本: 微擎手机端开发掉用系统验证码