|
@ -86,127 +86,7 @@ public class GateWayInterceptor extends BaseInterceptor {
|
|
|
return false;
|
|
|
}
|
|
|
//********************************判断accesstoken********************************
|
|
|
//********************************判断登陆的token**************************************
|
|
|
try {
|
|
|
request.setCharacterEncoding("UTF-8");
|
|
|
request.setAttribute("log-start", new Date().getTime());
|
|
|
response.setCharacterEncoding("UTF-8");
|
|
|
org.json.JSONObject json = getAgent(request);
|
|
|
|
|
|
if (json == null) {
|
|
|
// 未登录
|
|
|
response.getOutputStream().write(error(SystemConf.NOT_LOGIN, "请登录后再操作!").getBytes());
|
|
|
return false;
|
|
|
}
|
|
|
|
|
|
if (json.has("uid") && json.has("admin_token") && StringUtils.isNotEmpty(json.getString("admin_token"))) {
|
|
|
String adminToken = SystemConf.getInstance().getSystemProperties().getProperty("admin_token");
|
|
|
String adminUid = SystemConf.getInstance().getSystemProperties().getProperty("admin_uid");
|
|
|
if (json.getString("uid").equals(adminUid) && json.getString("admin_token").equals(adminToken)) {
|
|
|
return true;
|
|
|
}
|
|
|
}
|
|
|
|
|
|
String tokenStr = json.has("token") ? json.getString("token") : "";
|
|
|
String uid = json.has("uid") ? json.getString("uid") : "";
|
|
|
String imei = json.has("imei") ? json.getString("imei") : "";
|
|
|
String observer = json.has("observer") ? json.getString("observer") : "";
|
|
|
Integer platform = json.has("platform") ? json.getInt("platform") : 4;
|
|
|
logger.debug("tokenStr:" + tokenStr);
|
|
|
logger.debug("uid:" + uid);
|
|
|
logger.debug("imei:" + imei);
|
|
|
logger.debug("observer:" + observer);
|
|
|
logger.debug("platform:" + platform);
|
|
|
|
|
|
//如果是观察者直接返回true
|
|
|
if (!org.springframework.util.StringUtils.isEmpty(observer) && observer.equals("1")) {
|
|
|
Class cls = ((HandlerMethod) handler).getBeanType();
|
|
|
RequestMapping clsRm = (RequestMapping) cls.getAnnotation(RequestMapping.class);
|
|
|
Method method = ((HandlerMethod) handler).getMethod();
|
|
|
RequestMapping mthRm = method.getAnnotation(RequestMapping.class);
|
|
|
String url = "";
|
|
|
String urlCls = "";
|
|
|
String urlMth = "";
|
|
|
if (clsRm.value() != null && clsRm.value().length > 0) {
|
|
|
urlCls = clsRm.value()[0];
|
|
|
}
|
|
|
if (mthRm.value() != null && mthRm.value().length > 0) {
|
|
|
urlMth = mthRm.value()[0];
|
|
|
}
|
|
|
if (StringUtils.isNotEmpty(urlCls)) {
|
|
|
url += urlCls.startsWith("/") ? urlCls : ("/" + urlCls);
|
|
|
}
|
|
|
if (StringUtils.isNotEmpty(urlMth)) {
|
|
|
url += urlMth.startsWith("/") ? urlMth : ("/" + urlMth);
|
|
|
}
|
|
|
url = url.replace("\\", "/").replace("//", "/");
|
|
|
CudUrl cudUrl = cudUrlDao.findByUrl(url);
|
|
|
|
|
|
if (url.equals("/doctor/consult/readed")) {
|
|
|
response.getOutputStream().write(write(200, "操作成功").getBytes());
|
|
|
return false;
|
|
|
}
|
|
|
|
|
|
if (cudUrl != null) {
|
|
|
if (StringUtils.isNotEmpty(cudUrl.getMethod()) &&
|
|
|
request.getMethod().toUpperCase().compareTo(cudUrl.getMethod()) != 0) {
|
|
|
return true;
|
|
|
} else {
|
|
|
response.getOutputStream().write(error(403, "该操作没有权限").getBytes());
|
|
|
return false;
|
|
|
}
|
|
|
}
|
|
|
|
|
|
return true;
|
|
|
}
|
|
|
if (StringUtils.isEmpty(tokenStr) || StringUtils.isEmpty(imei) || StringUtils.isEmpty(uid)) {
|
|
|
response.getOutputStream().write(error(SystemConf.NOT_LOGIN, "请登录后再操作!").getBytes());
|
|
|
return false;
|
|
|
}
|
|
|
|
|
|
Token token = null;
|
|
|
Map<String, Token> tempMap = null;
|
|
|
if (platform == 4) {
|
|
|
tempMap = SystemData.doctorPCTokens;
|
|
|
}
|
|
|
token = tempMap.get(uid);
|
|
|
if (token == null) {
|
|
|
token = tokenDao.findByPatient(uid, platform);
|
|
|
if (token != null) {
|
|
|
// 加入缓存
|
|
|
tempMap.put(uid, token);
|
|
|
}
|
|
|
}
|
|
|
// 2、医生端app,3、微信公众号wechat,4、医生端pc,或者 PC端取药系统 或者对外系统
|
|
|
if (token == null || (token.getPlatform() != 4)) {
|
|
|
// 未登录
|
|
|
response.getOutputStream().write(error(SystemConf.NOT_LOGIN, "请登录后再操作!").getBytes());
|
|
|
flag = false;
|
|
|
} else {
|
|
|
if (token.getTimeout().getTime() < new Date().getTime()) {
|
|
|
// 登录超时
|
|
|
response.getOutputStream().write(error(SystemConf.LOGIN_TIMEOUT, "登录超时,请重新登录").getBytes());
|
|
|
flag = false;
|
|
|
} else if (!StringUtils.equals(tokenStr, token.getToken()) || !StringUtils.equals(uid, token.getUser()) || !StringUtils.equals(imei, token.getImei())) {
|
|
|
// 别处登录
|
|
|
response.getOutputStream().write(error(SystemConf.LOGIN_OTHER, "帐号在别处登录,请重新登录").getBytes());
|
|
|
flag = false;
|
|
|
} else {
|
|
|
// 一天只更新一次
|
|
|
if (DateUtil.getDays(token.getCzrq(), DateUtil.getNowDateShort()) != 0) {
|
|
|
// 今天未更新,则更新缓存
|
|
|
token.setCzrq(new Date());
|
|
|
// 更新内存
|
|
|
tempMap.put(uid, token);
|
|
|
// 更新数据库
|
|
|
tokenDao.save(token);
|
|
|
}
|
|
|
}
|
|
|
}
|
|
|
} catch (Exception e) {
|
|
|
e.printStackTrace();
|
|
|
}
|
|
|
//********************************判断登陆的token**************************************
|
|
|
return flag;
|
|
|
}
|
|
|
|