LoginUtil.jsp
11.7 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
<%@ page language="java" contentType="text/html; charset=UTF-8" %>
<%@ page import="net.sf.json.*"%>
<%@ page import="weaver.general.Util"%>
<%@ page import="java.util.Map"%>
<%@ page import="java.util.HashMap"%>
<%@ page import="weaver.hrm.settings.RemindSettings"%>
<%@ page import="weaver.hrm.settings.BirthdayReminder"%>
<%@ page import="weaver.conn.RecordSet"%>
<%@ page import="java.net.URLDecoder"%>
<%@ page import="weaver.login.CheckIpNetWork"%>
<%@ page import="weaver.login.VerifyLogin"%>
<%@ page import="weaver.hrm.settings.HrmSettingsComInfo"%>
<%@page import="weaver.general.GCONST"%>
<%@ page import="weaver.hrm.settings.ChgPasswdReminder" %>
<jsp:useBean id="LoginUtil" class="com.api.login.util.LoginUtil" scope="page" />
<%
response.setHeader("cache-control", "no-cache");
response.setHeader("pragma", "no-cache");
response.setHeader("expires", "Mon 1 Jan 1990 00:00:00 GMT");
Map<String,String> result = new HashMap<String,String>();
String requestMethod = Util.null2String(request.getMethod());
if(requestMethod.equalsIgnoreCase("GET")){
result.put("status","非法登录方式");
JSONObject jo = JSONObject.fromObject(result);
out.print(jo.toString());
return;
}
ChgPasswdReminder reminder = new ChgPasswdReminder();
RemindSettings settings=reminder.getRemindSettings();
if(settings==null){
BirthdayReminder birth_reminder = new BirthdayReminder();
settings=birth_reminder.getRemindSettings();
if(settings==null){
out.println("Cann't create connetion to database,please check your database.");
return;
}
application.setAttribute("hrmsettings",settings);
}
String type = Util.null2String(request.getParameter("type"));
if(type.equals("checklogin")){
String[] usercheck = LoginUtil.checkLogin(application,request,response);
RecordSet rs = new RecordSet();
String loginid = Util.null2String(request.getParameter("loginid"));
String sql = "select sumpasswordwrong from hrmresource where loginid='"+loginid+"'";
rs.executeSql(sql);
if(rs.next()){
usercheck[3]=""+Util.getIntValue(rs.getString(1));
}else{
usercheck[3]="0";
}
result.put("loginstatus",usercheck[0]);
result.put("msgcode",usercheck[1]);
result.put("msg",usercheck[2]);
result.put("sumpasswordwrong",usercheck[3]);
result.put("access_token",usercheck[4]);
JSONObject jo = JSONObject.fromObject(result);
out.println(jo.toString());
}else if(type.equals("logout")){
LoginUtil.checkLogout(application,request,response);
}else if(type.equals("hrmsetting")){
int needvalidate=settings.getNeedvalidate(); //启用验证码 1 :是 0:否
int numvalidatewrong=settings.getNumvalidatewrong(); //输入密码错误几次后出现验证码
int validatetype=settings.getValidatetype();
int showDynamicPwd = settings.getNeeddynapass(); //启用动态密码 1 :是 0:否
int isMulti = 0;
int enLanguage = GCONST.getENLANGUAGE();
int twLanguage = GCONST.getZHTWLANGUAGE();
if(enLanguage==0 && twLanguage==0) {
isMulti = 0;
} else {
isMulti = 1;
}
result.put("multilang",""+isMulti);
result.put("needvalidate",""+needvalidate);
result.put("numvalidatewrong",""+numvalidatewrong);
result.put("validatetype",""+validatetype);
result.put("showDynamicPwd",""+showDynamicPwd);
JSONObject jo = JSONObject.fromObject(result);
out.println(jo.toString());
}else if("checkTokenKey".equals(type)){
String loginid=URLDecoder.decode(request.getParameter("loginid"),"utf-8");
RecordSet recordSet = new RecordSet();
String sql = "select sumpasswordwrong from hrmresource where loginid='"+loginid+"'";
recordSet.executeSql(sql);
if(recordSet.next()){
result.put("sumpasswordwrong",""+Util.getIntValue(recordSet.getString(1)));
}else{
result.put("sumpasswordwrong","0");
}
String tableName = "hrmresource";
recordSet.executeSql("select id from HrmResourcemanager where loginid='"+loginid+"'");
if(recordSet.next()){
tableName = "HrmResourcemanager";
}
String sysNeedusb=Util.null2String(settings.getNeedusb());
String needusbHt=Util.null2String(settings.getNeedusbHt());
String needusbDt=Util.null2String(settings.getNeedusbDt());
sysNeedusb = (needusbHt.equals("1") || needusbDt.equals("1")) ? "1" : "0";
String usbType =Util.null2String(settings.getUsbType());
String userNeedusb="0";
String userUsbType="";
String tokenkey="";
String usbstate = "";
String id="0";
if("HrmResourcemanager".equals(tableName)){
recordSet.executeSql("select id,userUsbType,tokenkey,usbstate from HrmResourcemanager where loginid='"+loginid+"'");
if(recordSet.next()){
id=recordSet.getString("id");
userUsbType=recordSet.getString("userUsbType");
tokenkey=recordSet.getString("tokenkey");
usbstate = recordSet.getString("usbstate");
}
}else{
recordSet.executeSql("select id,needusb,userUsbType,tokenkey,usbstate from hrmresource where loginid='"+loginid+"'");
if(recordSet.next()){
id=recordSet.getString("id");
userNeedusb=recordSet.getString("needusb");
userUsbType=recordSet.getString("userUsbType");
tokenkey=recordSet.getString("tokenkey");
usbstate = recordSet.getString("usbstate");
}
}
if(userUsbType.equals(""))
userUsbType=usbType;
/**检测是否启用usb网段策略开始**/
CheckIpNetWork checkipnetwork = new CheckIpNetWork();
String clientIP = request.getRemoteAddr();
boolean checktmp = checkipnetwork.checkIpSeg(clientIP);//true表示在网段之外,false表示在网段之内
/**检测是否启用usb网段策略结束**/
if(sysNeedusb.equals("1")&&(userNeedusb.equals("1")||"HrmResourcemanager".equals(tableName)) && (usbstate.equals("0") || (usbstate.equals("2")&&checktmp))){
VerifyLogin verifylogin = new VerifyLogin();
boolean isNeedIp = true;
HrmSettingsComInfo sci = new HrmSettingsComInfo();
int forbidLogin = Util.getIntValue(sci.getForbidLogin(), 0);
if(forbidLogin == 0){
isNeedIp = false;
if(usbstate.equals("2")&&!checktmp) isNeedIp = true;
}else{
isNeedIp = verifylogin.checkIpSegByForbidLogin(request, loginid);
}
//动态令牌 网段策略-->网段内不需弹出
if(isNeedIp){
result.put("status","0");
JSONObject jo = JSONObject.fromObject(result);
out.print(jo.toString());
}else{
if(userUsbType.equals("3") ){
sql="select * from tokenJscx WHERE tokenKey='"+tokenkey+"'";
recordSet.execute(sql);
if(tokenkey.equals("")||!recordSet.next()){ //令牌未绑定或者未初始化
result.put("status","0");
JSONObject jo = JSONObject.fromObject(result);
out.print(jo.toString());
}else{
result.put("status",userUsbType);
JSONObject jo = JSONObject.fromObject(result);
out.print(jo.toString());
}
}else{
result.put("status",userUsbType);
JSONObject jo = JSONObject.fromObject(result);
out.print(jo.toString());
}
}
}else{
result.put("status","0");
JSONObject jo = JSONObject.fromObject(result);
out.print(jo.toString());
}
}else if("checkIsBind".equals(type)){
String userid=Util.null2String(request.getParameter("userid"));
String requestFrom=Util.null2String(request.getParameter("requestFrom"));
String loginid=Util.null2String(request.getParameter("loginid"));
String tokenKey=Util.null2String(request.getParameter("tokenKey"));
String sysNeedusb=Util.null2String(settings.getNeedusb());
String needusbHt=Util.null2String(settings.getNeedusbHt());
String needusbDt=Util.null2String(settings.getNeedusbDt());
sysNeedusb = (needusbHt.equals("1") || needusbDt.equals("1")) ? "1" : "0";
String usbType =Util.null2String(settings.getUsbType());
String userNeedusb="0";
String userUsbType="";
String tempUserid="0";
if(sysNeedusb.equals("1")){
RecordSet recordSet=new RecordSet();
if(!requestFrom.equals("system")){ //检查用户是否启用usbkey
recordSet.execute("select id,loginid,needusb,userUsbType from hrmresource WHERE loginid='"+loginid+"'");
if(recordSet.next()){
userNeedusb=Util.null2String(recordSet.getString("needusb"));
userUsbType=Util.null2String(recordSet.getString("userUsbType"));
}
}else{
userNeedusb="1";
userUsbType="3";
}
if(userNeedusb.equals("1")&&userUsbType.equals("3")){
//检查令牌是否已经绑定过
boolean isBind=false; //是否绑定过
String stauts=""; //被绑定人状态
String tempLoginid="";//被绑定人id
String sql="select * from tokenJscx WHERE tokenKey='"+tokenKey+"'";
recordSet.execute(sql);
if(recordSet.next()){
isBind=true;
//查询当前串号被绑定的用户
sql="select id,loginid,needusb,status from hrmresource where tokenKey='"+tokenKey+"'";
recordSet.execute(sql);
if(recordSet.next()){
tempUserid=recordSet.getString("id");
stauts=recordSet.getString("status");
tempLoginid=recordSet.getString("loginid");
}
}
if(requestFrom.equals("system"))
sql="select id,loginid,needusb,status,tokenKey from hrmresource WHERE id="+userid; //检查当前用户是否已经绑定过
else
sql="select id,loginid,needusb,status,tokenKey from hrmresource WHERE loginid='"+loginid; //检查当前用户是否已经绑定过
recordSet.execute(sql);
String bindTokenkey=Util.null2String(recordSet.getString("tokenKey"));
if(isBind){
if((!requestFrom.equals("system")&&loginid.equals(tempLoginid))||(requestFrom.equals("system")&&userid.equals(tempUserid))){
result.put("status","0");//被绑定人和当前用户是同一个人
JSONObject jo = JSONObject.fromObject(result);
out.print(jo.toString());
}else{
if(stauts.equals("0")||stauts.equals("1")||stauts.equals("2")||stauts.equals("3")){
result.put("status","1"); //被绑定的用户属于正常状态用户,不能再绑定给其他用户
JSONObject jo = JSONObject.fromObject(result);
out.print(jo.toString());
}else{
if(!bindTokenkey.equals("")){
result.put("status","5");//当前用户已经绑定过,但需要提醒用户确认令牌串号
JSONObject jo = JSONObject.fromObject(result);
out.print(jo.toString());
}else{
result.put("status","2");//令牌已经被激活,更改用户需要验证令牌口令
JSONObject jo = JSONObject.fromObject(result);
out.print(jo.toString());
}
}
}
}else{
if(bindTokenkey.equals(tokenKey)){
result.put("status","7"); //令牌已经绑定给用户但还未初始化
JSONObject jo = JSONObject.fromObject(result);
out.print(jo.toString());
}else if(bindTokenkey.equals("")){
result.put("status","3"); //当前令牌还未绑定过
JSONObject jo = JSONObject.fromObject(result);
out.print(jo.toString());
}else{
result.put("status","4"); //当前用户已经绑定过,但需要提醒用户确认令牌串号
JSONObject jo = JSONObject.fromObject(result);
out.print(jo.toString());
}
}
}else{
result.put("status","6"); //用户未启用usbkey验证,则不需要进行绑定
JSONObject jo = JSONObject.fromObject(result);
out.print(jo.toString());
}}else{
result.put("status","6"); //系统未启用usbkey验证,则不需要进行绑定
JSONObject jo = JSONObject.fromObject(result);
out.print(jo.toString());
}
}else if("checkIsUsed".equals(type)){ //检查令牌是否绑定给其他用户
String tokenKey=Util.null2String(request.getParameter("tokenKey"));
String userid=Util.null2String(request.getParameter("userid"));
String sql="select id,lastname from hrmresource where id <>+"+userid+" and tokenkey='"+tokenKey+"' and status in(0,1,2,3)";
RecordSet recordSet=new RecordSet();
recordSet.execute(sql);
if(recordSet.next()){ //令牌已经被使用
String lastname=recordSet.getString("lastname");
result.put("status","1");
result.put("lastname",lastname);
JSONObject jo = JSONObject.fromObject(result);
out.print(jo.toString());
}else{
result.put("status","0");
result.put("lastname","");
JSONObject jo = JSONObject.fromObject(result);
out.print(jo.toString());
}
}
%>