using Bootstrap.Security; using Bootstrap.Security.DataAccess; using Longbow; using Longbow.Data; using Longbow.Security.Cryptography; using System; using System.Collections.Generic; using System.Data; using System.Data.Common; using System.Data.SqlClient; using System.Linq; namespace Bootstrap.DataAccess { /// /// 用户表实体类 /// public class User : BootstrapUser { /// /// 获得/设置 用户主键ID /// public string Id { get; set; } /// /// 获取/设置 密码 /// public string Password { get; set; } /// /// 获取/设置 密码盐 /// public string PassSalt { get; set; } /// /// 获取/设置 角色用户关联状态 checked 标示已经关联 '' 标示未关联 /// public string Checked { get; set; } /// /// 获得/设置 用户注册时间 /// public DateTime RegisterTime { get; set; } /// /// 获得/设置 用户被批复时间 /// public DateTime ApprovedTime { get; set; } /// /// 获得/设置 用户批复人 /// public string ApprovedBy { get; set; } /// /// 获得/设置 用户的申请理由 /// public string Description { get; set; } /// /// 获得/设置 用户当前状态 0 表示管理员注册用户 1 表示用户注册 2 表示更改密码 3 表示更改个人皮肤 4 表示更改显示名称 5 批复新用户注册操作 /// public UserStates UserStatus { get; set; } /// /// 获得/设置 通知描述 2分钟内为刚刚 /// public string Period { get; set; } /// /// 获得/设置 新密码 /// public string NewPassword { get; set; } /// /// 验证用户登陆账号与密码正确 /// /// /// /// public virtual bool Authenticate(string userName, string password) { if (string.IsNullOrEmpty(userName) && string.IsNullOrEmpty(password)) return false; string oldPassword = null; string passwordSalt = null; string sql = "select Password, PassSalt from Users where ApprovedTime is not null and UserName = @UserName"; var db = DbAccessManager.DBAccess; using (DbCommand cmd = db.CreateCommand(CommandType.Text, sql)) { cmd.Parameters.Add(db.CreateParameter("@UserName", userName)); using (DbDataReader reader = db.ExecuteReader(cmd)) { if (reader.Read()) { oldPassword = (string)reader[0]; passwordSalt = (string)reader[1]; } } } return !string.IsNullOrEmpty(passwordSalt) && oldPassword == LgbCryptography.ComputeHash(password, passwordSalt); } /// /// /// /// /// /// /// public virtual bool ChangePassword(string userName, string password, string newPass) { bool ret = false; if (Authenticate(userName, password)) { string sql = "Update Users set Password = @Password, PassSalt = @PassSalt where UserName = @userName"; var passSalt = LgbCryptography.GenerateSalt(); var newPassword = LgbCryptography.ComputeHash(newPass, passSalt); using (DbCommand cmd = DbAccessManager.DBAccess.CreateCommand(CommandType.Text, sql)) { cmd.Parameters.Add(DbAccessManager.DBAccess.CreateParameter("@Password", newPassword)); cmd.Parameters.Add(DbAccessManager.DBAccess.CreateParameter("@PassSalt", passSalt)); cmd.Parameters.Add(DbAccessManager.DBAccess.CreateParameter("@userName", userName)); ret = DbAccessManager.DBAccess.ExecuteNonQuery(cmd) == 1; } } return ret; } /// /// 查询所有用户 /// /// /// public virtual IEnumerable RetrieveUsers() { List users = new List(); DbCommand cmd = DbAccessManager.DBAccess.CreateCommand(CommandType.Text, "select ID, UserName, DisplayName, RegisterTime, ApprovedTime, ApprovedBy, Description from Users Where ApprovedTime is not null"); using (DbDataReader reader = DbAccessManager.DBAccess.ExecuteReader(cmd)) { while (reader.Read()) { users.Add(new User() { Id = reader[0].ToString(), UserName = (string)reader[1], DisplayName = (string)reader[2], RegisterTime = LgbConvert.ReadValue(reader[3], DateTime.MinValue), ApprovedTime = LgbConvert.ReadValue(reader[4], DateTime.MinValue), ApprovedBy = reader.IsDBNull(5) ? string.Empty : (string)reader[5], Description = (string)reader[6] }); } } return users; } /// /// 查询所有的新注册用户 /// /// public virtual IEnumerable RetrieveNewUsers() { string sql = "select ID, UserName, DisplayName, RegisterTime, Description from Users Where ApprovedTime is null order by RegisterTime desc"; List users = new List(); DbCommand cmd = DbAccessManager.DBAccess.CreateCommand(CommandType.Text, sql); using (DbDataReader reader = DbAccessManager.DBAccess.ExecuteReader(cmd)) { while (reader.Read()) { users.Add(new User() { Id = reader[0].ToString(), UserName = (string)reader[1], DisplayName = (string)reader[2], RegisterTime = LgbConvert.ReadValue(reader[3], DateTime.MinValue), Description = (string)reader[4] }); } } return users; } /// /// 删除用户 /// /// public virtual bool DeleteUser(IEnumerable value) { bool ret = false; var ids = string.Join(",", value); using (TransactionPackage transaction = DbAccessManager.DBAccess.BeginTransaction()) { try { using (DbCommand cmd = DbAccessManager.DBAccess.CreateCommand(CommandType.Text, $"Delete from UserRole where UserID in ({ids})")) { DbAccessManager.DBAccess.ExecuteNonQuery(cmd, transaction); cmd.CommandText = $"delete from UserGroup where UserID in ({ids})"; DbAccessManager.DBAccess.ExecuteNonQuery(cmd, transaction); cmd.CommandText = $"delete from Users where ID in ({ids})"; DbAccessManager.DBAccess.ExecuteNonQuery(cmd, transaction); transaction.CommitTransaction(); ret = true; } } catch (Exception ex) { transaction.RollbackTransaction(); throw ex; } } return ret; } /// /// 新建前台User View调用/注册用户调用 /// /// /// public virtual bool SaveUser(User p) { var ret = false; if (string.IsNullOrEmpty(p.Id) && p.Description.Length > 500) p.Description = p.Description.Substring(0, 500); if (p.UserName.Length > 50) p.UserName = p.UserName.Substring(0, 50); p.PassSalt = LgbCryptography.GenerateSalt(); p.Password = LgbCryptography.ComputeHash(p.Password, p.PassSalt); using (TransactionPackage transaction = DbAccessManager.DBAccess.BeginTransaction()) { try { using (DbCommand cmd = DbAccessManager.DBAccess.CreateCommand(CommandType.Text, "select UserName from Users Where UserName = @userName")) { cmd.Parameters.Add(DbAccessManager.DBAccess.CreateParameter("@userName", p.UserName)); var un = DbAccessManager.DBAccess.ExecuteScalar(cmd, transaction); if (DbAdapterManager.ToObjectValue(un) == null) { cmd.CommandText = "Insert Into Users (UserName, Password, PassSalt, DisplayName, RegisterTime, ApprovedBy, ApprovedTime, Description) values (@userName, @password, @passSalt, @displayName, datetime('now', 'localtime'), @approvedBy, now(), @description)"; cmd.Parameters.Add(DbAccessManager.DBAccess.CreateParameter("@password", p.Password)); cmd.Parameters.Add(DbAccessManager.DBAccess.CreateParameter("@passSalt", p.PassSalt)); cmd.Parameters.Add(DbAccessManager.DBAccess.CreateParameter("@displayName", p.DisplayName)); cmd.Parameters.Add(DbAccessManager.DBAccess.CreateParameter("@approvedBy", DbAdapterManager.ToDBValue(p.ApprovedBy))); cmd.Parameters.Add(DbAccessManager.DBAccess.CreateParameter("@description", p.Description)); DbAccessManager.DBAccess.ExecuteNonQuery(cmd, transaction); cmd.CommandText = $"insert into UserRole (UserID, RoleID) select ID, (select ID from Roles where RoleName = 'Default') RoleId from Users where UserName = '{p.UserName}'"; cmd.Parameters.Clear(); DbAccessManager.DBAccess.ExecuteNonQuery(cmd, transaction); transaction.CommitTransaction(); ret = true; } } } catch (Exception ex) { transaction.RollbackTransaction(); throw ex; } } return ret; } /// /// User List 视图保存按钮调用 /// /// /// /// /// public virtual bool UpdateUser(string id, string password, string displayName) { bool ret = false; string sql = "Update Users set Password = @Password, PassSalt = @PassSalt, DisplayName = @DisplayName where ID = @id"; var passSalt = LgbCryptography.GenerateSalt(); var newPassword = LgbCryptography.ComputeHash(password, passSalt); using (DbCommand cmd = DbAccessManager.DBAccess.CreateCommand(CommandType.Text, sql)) { cmd.Parameters.Add(DbAccessManager.DBAccess.CreateParameter("@id", id)); cmd.Parameters.Add(DbAccessManager.DBAccess.CreateParameter("@DisplayName", displayName)); cmd.Parameters.Add(DbAccessManager.DBAccess.CreateParameter("@Password", newPassword)); cmd.Parameters.Add(DbAccessManager.DBAccess.CreateParameter("@PassSalt", passSalt)); ret = DbAccessManager.DBAccess.ExecuteNonQuery(cmd) == 1; } return ret; } /// /// /// /// /// /// public virtual bool ApproveUser(string id, string approvedBy) { var ret = false; var sql = "update Users set ApprovedTime = @ApproveTime, ApprovedBy = @approvedBy where ID = @id"; using (DbCommand cmd = DbAccessManager.DBAccess.CreateCommand(CommandType.Text, sql)) { cmd.Parameters.Add(DbAccessManager.DBAccess.CreateParameter("@id", id)); cmd.Parameters.Add(DbAccessManager.DBAccess.CreateParameter("@ApproveTime", DateTime.Now, DbType.DateTime)); cmd.Parameters.Add(DbAccessManager.DBAccess.CreateParameter("@approvedBy", approvedBy)); ret = DbAccessManager.DBAccess.ExecuteNonQuery(cmd) == 1; } return ret; } /// /// /// /// /// /// public virtual bool RejectUser(string id, string rejectBy) { var ret = false; using (TransactionPackage transaction = DbAccessManager.DBAccess.BeginTransaction()) { try { using (DbCommand cmd = DbAccessManager.DBAccess.CreateCommand(CommandType.Text, $"insert into RejectUsers (UserName, DisplayName, RegisterTime, RejectedBy, RejectedTime, RejectedReason) select UserName, DisplayName, Registertime, '{rejectBy}', @RejectTime, '未填写' from Users where ID = {id}")) { cmd.Parameters.Add(DbAccessManager.DBAccess.CreateParameter("@RejectTime", DateTime.Now, DbType.DateTime)); DbAccessManager.DBAccess.ExecuteNonQuery(cmd, transaction); cmd.Parameters.Clear(); cmd.CommandText = $"delete from UserRole where UserId = {id}"; DbAccessManager.DBAccess.ExecuteNonQuery(cmd, transaction); cmd.CommandText = $"delete from UserGroup where UserId = {id}"; DbAccessManager.DBAccess.ExecuteNonQuery(cmd, transaction); cmd.CommandText = $"delete from users where ID = {id}"; DbAccessManager.DBAccess.ExecuteNonQuery(cmd, transaction); transaction.CommitTransaction(); ret = true; } } catch (Exception ex) { transaction.RollbackTransaction(); throw ex; } } return ret; } /// /// 通过roleId获取所有用户 /// /// /// public virtual IEnumerable RetrieveUsersByRoleId(string roleId) { List users = new List(); string sql = "select u.ID, u.UserName, u.DisplayName, case ur.UserID when u.ID then 'checked' else '' end status from Users u left join UserRole ur on u.ID = ur.UserID and RoleID = @RoleID where u.ApprovedTime is not null"; DbCommand cmd = DbAccessManager.DBAccess.CreateCommand(CommandType.Text, sql); cmd.Parameters.Add(DbAccessManager.DBAccess.CreateParameter("@RoleID", roleId)); using (DbDataReader reader = DbAccessManager.DBAccess.ExecuteReader(cmd)) { while (reader.Read()) { users.Add(new User() { Id = reader[0].ToString(), UserName = (string)reader[1], DisplayName = (string)reader[2], Checked = (string)reader[3] }); } } return users; } /// /// 通过角色ID保存当前授权用户(插入) /// /// 角色ID /// 用户ID数组 /// public virtual bool SaveUsersByRoleId(string roleId, IEnumerable userIds) { bool ret = false; DataTable dt = new DataTable(); dt.Columns.Add("RoleID", typeof(int)); dt.Columns.Add("UserID", typeof(int)); userIds.ToList().ForEach(userId => dt.Rows.Add(roleId, userId)); using (TransactionPackage transaction = DbAccessManager.DBAccess.BeginTransaction()) { try { //删除用户角色表该角色所有的用户 string sql = $"delete from UserRole where RoleID = {roleId}"; using (DbCommand cmd = DbAccessManager.DBAccess.CreateCommand(CommandType.Text, sql)) { DbAccessManager.DBAccess.ExecuteNonQuery(cmd, transaction); //批插入用户角色表 using (SqlBulkCopy bulk = new SqlBulkCopy((SqlConnection)transaction.Transaction.Connection, SqlBulkCopyOptions.Default, (SqlTransaction)transaction.Transaction)) { bulk.DestinationTableName = "UserRole"; bulk.ColumnMappings.Add("RoleID", "RoleID"); bulk.ColumnMappings.Add("UserID", "UserID"); bulk.WriteToServer(dt); transaction.CommitTransaction(); } } ret = true; } catch (Exception ex) { transaction.RollbackTransaction(); throw ex; } } return ret; } /// /// 通过groupId获取所有用户 /// /// /// public virtual IEnumerable RetrieveUsersByGroupId(string groupId) { List users = new List(); string sql = "select u.ID, u.UserName, u.DisplayName, case ur.UserID when u.ID then 'checked' else '' end status from Users u left join UserGroup ur on u.ID = ur.UserID and GroupID =@groupId where u.ApprovedTime is not null"; DbCommand cmd = DbAccessManager.DBAccess.CreateCommand(CommandType.Text, sql); cmd.Parameters.Add(DbAccessManager.DBAccess.CreateParameter("@GroupID", groupId)); using (DbDataReader reader = DbAccessManager.DBAccess.ExecuteReader(cmd)) { while (reader.Read()) { users.Add(new User() { Id = reader[0].ToString(), UserName = (string)reader[1], DisplayName = (string)reader[2], Checked = (string)reader[3] }); } } return users; } /// /// 通过部门ID保存当前授权用户(插入) /// /// GroupID /// 用户ID数组 /// public virtual bool SaveUsersByGroupId(string groupId, IEnumerable userIds) { bool ret = false; DataTable dt = new DataTable(); dt.Columns.Add("UserID", typeof(int)); dt.Columns.Add("GroupID", typeof(int)); userIds.ToList().ForEach(userId => dt.Rows.Add(userId, groupId)); using (TransactionPackage transaction = DbAccessManager.DBAccess.BeginTransaction()) { try { //删除用户角色表该角色所有的用户 string sql = "delete from UserGroup where GroupID = @GroupID"; using (DbCommand cmd = DbAccessManager.DBAccess.CreateCommand(CommandType.Text, sql)) { cmd.Parameters.Add(DbAccessManager.DBAccess.CreateParameter("@GroupID", groupId)); DbAccessManager.DBAccess.ExecuteNonQuery(cmd, transaction); //批插入用户角色表 using (SqlBulkCopy bulk = new SqlBulkCopy((SqlConnection)transaction.Transaction.Connection, SqlBulkCopyOptions.Default, (SqlTransaction)transaction.Transaction)) { bulk.DestinationTableName = "UserGroup"; bulk.ColumnMappings.Add("UserID", "UserID"); bulk.ColumnMappings.Add("GroupID", "GroupID"); bulk.WriteToServer(dt); transaction.CommitTransaction(); } } ret = true; } catch (Exception ex) { transaction.RollbackTransaction(); throw ex; } } return ret; } /// /// 根据用户名修改用户头像 /// /// /// /// public virtual bool SaveUserIconByName(string userName, string iconName) { bool ret = false; string sql = "Update Users set Icon = @iconName where UserName = @userName"; using (DbCommand cmd = DbAccessManager.DBAccess.CreateCommand(CommandType.Text, sql)) { cmd.Parameters.Add(DbAccessManager.DBAccess.CreateParameter("@iconName", iconName)); cmd.Parameters.Add(DbAccessManager.DBAccess.CreateParameter("@userName", userName)); ret = DbAccessManager.DBAccess.ExecuteNonQuery(cmd) == 1; } return ret; } /// /// /// /// /// /// public virtual bool SaveDisplayName(string userName, string displayName) { bool ret = false; string sql = "Update Users set DisplayName = @DisplayName where UserName = @userName"; using (DbCommand cmd = DbAccessManager.DBAccess.CreateCommand(CommandType.Text, sql)) { cmd.Parameters.Add(DbAccessManager.DBAccess.CreateParameter("@DisplayName", displayName)); cmd.Parameters.Add(DbAccessManager.DBAccess.CreateParameter("@userName", userName)); ret = DbAccessManager.DBAccess.ExecuteNonQuery(cmd) == 1; } return ret; } /// /// 根据用户名更改用户皮肤 /// /// /// /// public virtual bool SaveUserCssByName(string userName, string cssName) { bool ret = false; string sql = "Update Users set Css = @cssName where UserName = @userName"; using (DbCommand cmd = DbAccessManager.DBAccess.CreateCommand(CommandType.Text, sql)) { cmd.Parameters.Add(DbAccessManager.DBAccess.CreateParameter("@cssName", DbAdapterManager.ToDBValue(cssName))); cmd.Parameters.Add(DbAccessManager.DBAccess.CreateParameter("@userName", userName)); ret = DbAccessManager.DBAccess.ExecuteNonQuery(cmd) == 1; } return ret; } /// /// /// /// /// public virtual BootstrapUser RetrieveUserByUserName(string userName) => DbHelper.RetrieveUserByUserName(userName); /// /// /// /// public override string ToString() { return string.Format("{0} ({1})", UserName, DisplayName); } } /// /// /// public enum UserStates { /// /// /// ChangePassword, /// /// /// ChangeTheme, /// /// /// ChangeDisplayName, /// /// /// ApproveUser, /// /// /// RejectUser } }