|
@@ -1,20 +1,30 @@
|
|
|
package com.cyksj.service.user.impl;
|
|
package com.cyksj.service.user.impl;
|
|
|
|
|
|
|
|
import cn.hutool.extra.servlet.ServletUtil;
|
|
import cn.hutool.extra.servlet.ServletUtil;
|
|
|
|
|
+import cn.hutool.http.HttpUtil;
|
|
|
|
|
+import cn.hutool.json.JSONObject;
|
|
|
import com.cyksj.common.exception.BusinessRuntimeException;
|
|
import com.cyksj.common.exception.BusinessRuntimeException;
|
|
|
import com.cyksj.common.util.StringUtil;
|
|
import com.cyksj.common.util.StringUtil;
|
|
|
import com.cyksj.redis.RedisService;
|
|
import com.cyksj.redis.RedisService;
|
|
|
import com.cyksj.service.user.BadIntentionOpService;
|
|
import com.cyksj.service.user.BadIntentionOpService;
|
|
|
import lombok.RequiredArgsConstructor;
|
|
import lombok.RequiredArgsConstructor;
|
|
|
import lombok.extern.slf4j.Slf4j;
|
|
import lombok.extern.slf4j.Slf4j;
|
|
|
|
|
+import org.apache.commons.lang3.StringUtils;
|
|
|
|
|
+import org.springframework.beans.factory.annotation.Value;
|
|
|
import org.springframework.stereotype.Service;
|
|
import org.springframework.stereotype.Service;
|
|
|
|
|
|
|
|
import javax.servlet.http.HttpServletRequest;
|
|
import javax.servlet.http.HttpServletRequest;
|
|
|
|
|
+import java.util.HashMap;
|
|
|
|
|
+import java.util.Map;
|
|
|
|
|
|
|
|
@Service
|
|
@Service
|
|
|
@RequiredArgsConstructor
|
|
@RequiredArgsConstructor
|
|
|
@Slf4j
|
|
@Slf4j
|
|
|
public class BadIntentionOpServiceImpl implements BadIntentionOpService {
|
|
public class BadIntentionOpServiceImpl implements BadIntentionOpService {
|
|
|
|
|
+
|
|
|
|
|
+ @Value("${smsVerify.apiKey}")
|
|
|
|
|
+ String apiKey;
|
|
|
|
|
+
|
|
|
private final RedisService redisService;
|
|
private final RedisService redisService;
|
|
|
|
|
|
|
|
private static final int PHONE_CODE_GET_NUM_DAY_LIMIT = 30;
|
|
private static final int PHONE_CODE_GET_NUM_DAY_LIMIT = 30;
|
|
@@ -22,17 +32,28 @@ public class BadIntentionOpServiceImpl implements BadIntentionOpService {
|
|
|
|
|
|
|
|
private static final int PHONE_LOGIN_CODE_RETRY = 10;
|
|
private static final int PHONE_LOGIN_CODE_RETRY = 10;
|
|
|
|
|
|
|
|
|
|
+ private static final String VERIFY_URL = "https://captcha.luosimao.com/api/site_verify";
|
|
|
|
|
+
|
|
|
@Override
|
|
@Override
|
|
|
- public void checkHandleBadUserOp(HttpServletRequest request, String phone) {
|
|
|
|
|
|
|
+ public void checkHandleBadUserOp(String phone, String verifyCode) {
|
|
|
if ("13662979985".equals(phone)) {
|
|
if ("13662979985".equals(phone)) {
|
|
|
throw BusinessRuntimeException.getInstance("异常手机号");
|
|
throw BusinessRuntimeException.getInstance("异常手机号");
|
|
|
}
|
|
}
|
|
|
- String clientIP = ServletUtil.getClientIP(request);
|
|
|
|
|
- String ipAddress = StringUtil.getInternalAddressByIP(clientIP);
|
|
|
|
|
- log.info("--------------获取手机验证码------- ip:{} address:{}", clientIP, ipAddress);
|
|
|
|
|
|
|
+ if (StringUtils.isBlank(verifyCode)) {
|
|
|
|
|
+ throw BusinessRuntimeException.getInstance("人机校验不通过");
|
|
|
|
|
+ }else {
|
|
|
|
|
+ Map<String, Object> parmas = new HashMap<>();
|
|
|
|
|
+ parmas.put("api_key", apiKey);
|
|
|
|
|
+ parmas.put("response", verifyCode);
|
|
|
|
|
+ String post = HttpUtil.post(VERIFY_URL, parmas);
|
|
|
|
|
+ JSONObject res = new JSONObject(post);
|
|
|
|
|
+ if (!res.getStr("res").equals("success")) {
|
|
|
|
|
+ log.error("手机号:{}验证码校验不通过 res:{}", phone, res);
|
|
|
|
|
+ throw BusinessRuntimeException.getInstance("人机校验不通过");
|
|
|
|
|
+ }
|
|
|
|
|
+ }
|
|
|
String dayKey = RedisService.key.PHONE_CODE_USER_NUM_KEY_DAY.getName() + phone;
|
|
String dayKey = RedisService.key.PHONE_CODE_USER_NUM_KEY_DAY.getName() + phone;
|
|
|
if (redisService.hasKey(RedisService.key.PHONE_CODE_BALCK_KEY.getName() + phone)) {
|
|
if (redisService.hasKey(RedisService.key.PHONE_CODE_BALCK_KEY.getName() + phone)) {
|
|
|
- log.error("--------------黑名单 手机号------- ip:{} address:{}", clientIP, ipAddress);
|
|
|
|
|
throw BusinessRuntimeException.getInstance("异常手机号");
|
|
throw BusinessRuntimeException.getInstance("异常手机号");
|
|
|
}
|
|
}
|
|
|
if (redisService.hasKey(dayKey)) {
|
|
if (redisService.hasKey(dayKey)) {
|
|
@@ -49,14 +70,14 @@ public class BadIntentionOpServiceImpl implements BadIntentionOpService {
|
|
|
return;
|
|
return;
|
|
|
}
|
|
}
|
|
|
redisService.set(dayKey, 1, RedisService.key.PHONE_CODE_USER_NUM_KEY_DAY.getTimeout());
|
|
redisService.set(dayKey, 1, RedisService.key.PHONE_CODE_USER_NUM_KEY_DAY.getTimeout());
|
|
|
|
|
+
|
|
|
}
|
|
}
|
|
|
|
|
|
|
|
@Override
|
|
@Override
|
|
|
public void isBadOpLoginPhone(HttpServletRequest request, String phone) {
|
|
public void isBadOpLoginPhone(HttpServletRequest request, String phone) {
|
|
|
- String clientIP = ServletUtil.getClientIP(request);
|
|
|
|
|
- String ipAddress = StringUtil.getInternalAddressByIP(clientIP);
|
|
|
|
|
- log.info("--------------校验ip 是否黑名单------- ip:{} ipAddress:{}", clientIP, ipAddress);
|
|
|
|
|
- String blackIpKey = RedisService.key.BALCK_USER_IP_KEY + clientIP;
|
|
|
|
|
|
|
+ String ip = StringUtil.getInternalAddressByIP(ServletUtil.getClientIP(request));
|
|
|
|
|
+ log.info("--------------校验ip 是否黑名单------- ip:{}", ip);
|
|
|
|
|
+ String blackIpKey = RedisService.key.BALCK_USER_IP_KEY + ip;
|
|
|
if (redisService.hasKey(blackIpKey)) {
|
|
if (redisService.hasKey(blackIpKey)) {
|
|
|
throw BusinessRuntimeException.getInstance("检测到您操作异常,请联系客服");
|
|
throw BusinessRuntimeException.getInstance("检测到您操作异常,请联系客服");
|
|
|
}
|
|
}
|
|
@@ -65,7 +86,7 @@ public class BadIntentionOpServiceImpl implements BadIntentionOpService {
|
|
|
int i = Integer.parseInt(redisService.get(RetryTimeKey).toString());
|
|
int i = Integer.parseInt(redisService.get(RetryTimeKey).toString());
|
|
|
if (i >= PHONE_LOGIN_CODE_RETRY) {
|
|
if (i >= PHONE_LOGIN_CODE_RETRY) {
|
|
|
//锁住他的ip
|
|
//锁住他的ip
|
|
|
- redisService.setNx(blackIpKey, clientIP, RedisService.key.BALCK_USER_IP_KEY.getTimeout());
|
|
|
|
|
|
|
+ redisService.setNx(blackIpKey, ip, RedisService.key.BALCK_USER_IP_KEY.getTimeout());
|
|
|
throw BusinessRuntimeException.getInstance("检测到您操作异常,请联系客服");
|
|
throw BusinessRuntimeException.getInstance("检测到您操作异常,请联系客服");
|
|
|
} else {
|
|
} else {
|
|
|
redisService.incr(RetryTimeKey, 1l);
|
|
redisService.incr(RetryTimeKey, 1l);
|