index.php 13 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344
  1. <?php
  2. defined('IN_PHPCMS') or exit('No permission resources.');
  3. pc_base::load_app_class('admin','admin',0);
  4. class index extends admin {
  5. public function __construct() {
  6. parent::__construct();
  7. $this->db = pc_base::load_model('admin_model');
  8. $this->menu_db = pc_base::load_model('menu_model');
  9. $this->panel_db = pc_base::load_model('admin_panel_model');
  10. }
  11. public function init () {
  12. $userid = $_SESSION['userid'];
  13. $admin_username = param::get_cookie('admin_username');
  14. $roles = getcache('role','commons');
  15. $rolename = $roles[$_SESSION['roleid']];
  16. $site = pc_base::load_app_class('sites');
  17. $sitelist = $site->get_list($_SESSION['roleid']);
  18. $currentsite = $this->get_siteinfo(param::get_cookie('siteid'));
  19. /*管理员收藏栏*/
  20. $adminpanel = $this->panel_db->select(array('userid'=>$userid), "*",20 , 'datetime');
  21. $site_model = param::get_cookie('site_model');
  22. include $this->admin_tpl('index');
  23. }
  24. public function login() {
  25. if(isset($_GET['dosubmit'])) {
  26. //不为口令卡验证
  27. if (!isset($_GET['card'])) {
  28. $username = isset($_POST['username']) ? trim($_POST['username']) : showmessage(L('nameerror'),HTTP_REFERER);
  29. $code = isset($_POST['code']) && trim($_POST['code']) ? trim($_POST['code']) : showmessage(L('input_code'), HTTP_REFERER);
  30. if ($_SESSION['code'] != strtolower($code)) {
  31. $_SESSION['code'] = '';
  32. showmessage(L('code_error'), HTTP_REFERER);
  33. }
  34. $_SESSION['code'] = '';
  35. } else { //口令卡验证
  36. if (!isset($_SESSION['card_verif']) || $_SESSION['card_verif'] != 1) {
  37. showmessage(L('your_password_card_is_not_validate'), '?m=admin&c=index&a=public_card');
  38. }
  39. $username = $_SESSION['card_username'] ? $_SESSION['card_username'] : showmessage(L('nameerror'),HTTP_REFERER);
  40. }
  41. if(!is_username($username)){
  42. showmessage(L('username_illegal'), HTTP_REFERER);
  43. }
  44. //密码错误剩余重试次数
  45. $this->times_db = pc_base::load_model('times_model');
  46. $rtime = $this->times_db->get_one(array('username'=>$username,'isadmin'=>1));
  47. $maxloginfailedtimes = getcache('common','commons');
  48. $maxloginfailedtimes = (int)$maxloginfailedtimes['maxloginfailedtimes'];
  49. if($rtime['times'] >= $maxloginfailedtimes) {
  50. $minute = 60-floor((SYS_TIME-$rtime['logintime'])/60);
  51. if($minute>0) showmessage(L('wait_1_hour',array('minute'=>$minute)));
  52. }
  53. //查询帐号
  54. $r = $this->db->get_one(array('username'=>$username));
  55. if(!$r) showmessage(L('user_not_exist'),'?m=admin&c=index&a=login');
  56. $password = md5(md5(trim((!isset($_GET['card']) ? $_POST['password'] : $_SESSION['card_password']))).$r['encrypt']);
  57. if($r['password'] != $password) {
  58. $ip = ip();
  59. if($rtime && $rtime['times'] < $maxloginfailedtimes) {
  60. $times = $maxloginfailedtimes-intval($rtime['times']);
  61. $this->times_db->update(array('ip'=>$ip,'isadmin'=>1,'times'=>'+=1'),array('username'=>$username));
  62. } else {
  63. $this->times_db->delete(array('username'=>$username,'isadmin'=>1));
  64. $this->times_db->insert(array('username'=>$username,'ip'=>$ip,'isadmin'=>1,'logintime'=>SYS_TIME,'times'=>1));
  65. $times = $maxloginfailedtimes;
  66. }
  67. showmessage(L('password_error',array('times'=>$times)),'?m=admin&c=index&a=login',3000);
  68. }
  69. $this->times_db->delete(array('username'=>$username));
  70. //查看是否使用口令卡
  71. if (!isset($_GET['card']) && $r['card'] && pc_base::load_config('system', 'safe_card') == 1) {
  72. $_SESSION['card_username'] = $username;
  73. $_SESSION['card_password'] = $_POST['password'];
  74. header("location:?m=admin&c=index&a=public_card");
  75. exit;
  76. } elseif (isset($_GET['card']) && pc_base::load_config('system', 'safe_card') == 1 && $r['card']) {//对口令卡进行验证
  77. isset($_SESSION['card_username']) ? $_SESSION['card_username'] = '' : '';
  78. isset($_SESSION['card_password']) ? $_SESSION['card_password'] = '' : '';
  79. isset($_SESSION['card_password']) ? $_SESSION['card_verif'] = '' : '';
  80. }
  81. $this->db->update(array('lastloginip'=>ip(),'lastlogintime'=>SYS_TIME),array('userid'=>$r['userid']));
  82. $_SESSION['userid'] = $r['userid'];
  83. $_SESSION['roleid'] = $r['roleid'];
  84. $_SESSION['pc_hash'] = random(6,'abcdefghigklmnopqrstuvwxwyABCDEFGHIGKLMNOPQRSTUVWXWY0123456789');
  85. $_SESSION['lock_screen'] = 0;
  86. $default_siteid = self::return_siteid();
  87. $cookie_time = SYS_TIME+86400*30;
  88. if(!$r['lang']) $r['lang'] = 'zh-cn';
  89. param::set_cookie('admin_username',$username,$cookie_time);
  90. param::set_cookie('siteid', $default_siteid,$cookie_time);
  91. param::set_cookie('userid', $r['userid'],$cookie_time);
  92. param::set_cookie('admin_email', $r['email'],$cookie_time);
  93. param::set_cookie('sys_lang', $r['lang'],$cookie_time);
  94. showmessage(L('login_success'),'?m=admin&c=index');
  95. //同步登陆vms,先检查是否启用了vms
  96. $video_setting = getcache('video', 'video');
  97. if ($video_setting['sn'] && $video_setting['skey']) {
  98. $vmsapi = pc_base::load_app_class('ku6api', 'video');
  99. $vmsapi->member_login_vms();
  100. }
  101. } else {
  102. //modified by zhengtaiyou@qq.com 2016-07-24
  103. $sites = getcache('sitelist', 'commons');
  104. pc_base::load_sys_class('form', '', 0);
  105. include $this->admin_tpl('login');
  106. }
  107. }
  108. public function public_card() {
  109. $username = $_SESSION['card_username'] ? $_SESSION['card_username'] : showmessage(L('nameerror'),HTTP_REFERER);
  110. $r = $this->db->get_one(array('username'=>$username));
  111. if(!$r) showmessage(L('user_not_exist'),'?m=admin&c=index&a=login');
  112. if (isset($_GET['dosubmit'])) {
  113. pc_base::load_app_class('card', 'admin', 0);
  114. $result = card::verification($r['card'], $_POST['code'], $_POST['rand']);
  115. $_SESSION['card_verif'] = 1;
  116. header("location:?m=admin&c=index&a=login&dosubmit=1&card=1");
  117. exit;
  118. }
  119. pc_base::load_app_class('card', 'admin', 0);
  120. $rand = card::authe_rand($r['card']);
  121. include $this->admin_tpl('login_card');
  122. }
  123. public function public_logout() {
  124. $_SESSION['userid'] = 0;
  125. $_SESSION['roleid'] = 0;
  126. param::set_cookie('admin_username','');
  127. param::set_cookie('userid',0);
  128. //退出phpsso
  129. $phpsso_api_url = pc_base::load_config('system', 'phpsso_api_url');
  130. $phpsso_logout = '<script type="text/javascript" src="'.$phpsso_api_url.'/api.php?op=logout" reload="1"></script>';
  131. showmessage(L('logout_success').$phpsso_logout,'?m=admin&c=index&a=login');
  132. }
  133. //左侧菜单
  134. public function public_menu_left() {
  135. $menuid = intval($_GET['menuid']);
  136. $datas = admin::admin_menu($menuid);
  137. if (isset($_GET['parentid']) && $parentid = intval($_GET['parentid']) ? intval($_GET['parentid']) : 10) {
  138. foreach($datas as $_value) {
  139. if($parentid==$_value['id']) {
  140. echo '<li id="_M'.$_value['id'].'" class="on top_menu"><a href="javascript:_M('.$_value['id'].',\'?m='.$_value['m'].'&c='.$_value['c'].'&a='.$_value['a'].'\')" hidefocus="true" style="outline:none;">'.L($_value['name']).'</a></li>';
  141. } else {
  142. echo '<li id="_M'.$_value['id'].'" class="top_menu"><a href="javascript:_M('.$_value['id'].',\'?m='.$_value['m'].'&c='.$_value['c'].'&a='.$_value['a'].'\')" hidefocus="true" style="outline:none;">'.L($_value['name']).'</a></li>';
  143. }
  144. }
  145. } else {
  146. include $this->admin_tpl('left');
  147. }
  148. }
  149. //当前位置
  150. public function public_current_pos() {
  151. echo admin::current_pos($_GET['menuid']);
  152. exit;
  153. }
  154. /**
  155. * 设置站点ID COOKIE
  156. */
  157. public function public_set_siteid() {
  158. $siteid = isset($_GET['siteid']) && intval($_GET['siteid']) ? intval($_GET['siteid']) : exit('0');
  159. param::set_cookie('siteid', $siteid);
  160. exit('1');
  161. }
  162. public function public_ajax_add_panel() {
  163. $menuid = isset($_POST['menuid']) ? $_POST['menuid'] : exit('0');
  164. $menuarr = $this->menu_db->get_one(array('id'=>$menuid));
  165. $url = '?m='.$menuarr['m'].'&c='.$menuarr['c'].'&a='.$menuarr['a'].'&'.$menuarr['data'];
  166. $data = array('menuid'=>$menuid, 'userid'=>$_SESSION['userid'], 'name'=>$menuarr['name'], 'url'=>$url, 'datetime'=>SYS_TIME);
  167. $this->panel_db->insert($data, '', 1);
  168. $panelarr = $this->panel_db->listinfo(array('userid'=>$_SESSION['userid']), "datetime");
  169. foreach($panelarr as $v) {
  170. echo "<span><a onclick='paneladdclass(this);' target='right' href='".$v['url'].'&menuid='.$v['menuid']."&pc_hash=".$_SESSION['pc_hash']."'>".L($v['name'])."</a> <a class='panel-delete' href='javascript:delete_panel(".$v['menuid'].");'></a></span>";
  171. }
  172. exit;
  173. }
  174. public function public_ajax_delete_panel() {
  175. $menuid = isset($_POST['menuid']) ? $_POST['menuid'] : exit('0');
  176. $this->panel_db->delete(array('menuid'=>$menuid, 'userid'=>$_SESSION['userid']));
  177. $panelarr = $this->panel_db->listinfo(array('userid'=>$_SESSION['userid']), "datetime");
  178. foreach($panelarr as $v) {
  179. echo "<span><a onclick='paneladdclass(this);' target='right' href='".$v['url']."&pc_hash=".$_SESSION['pc_hash']."'>".L($v['name'])."</a> <a class='panel-delete' href='javascript:delete_panel(".$v['menuid'].");'></a></span>";
  180. }
  181. exit;
  182. }
  183. public function public_main() {
  184. pc_base::load_app_func('global');
  185. pc_base::load_app_func('admin');
  186. define('PC_VERSION', pc_base::load_config('version','pc_version'));
  187. define('PC_RELEASE', pc_base::load_config('version','pc_release'));
  188. $admin_username = param::get_cookie('admin_username');
  189. $roles = getcache('role','commons');
  190. $userid = $_SESSION['userid'];
  191. $rolename = $roles[$_SESSION['roleid']];
  192. $r = $this->db->get_one(array('userid'=>$userid));
  193. $logintime = $r['lastlogintime'];
  194. $loginip = $r['lastloginip'];
  195. $sysinfo = get_sysinfo();
  196. $sysinfo['mysqlv'] = $this->db->version();
  197. $show_header = $show_pc_hash = 1;
  198. /*检测框架目录可写性*/
  199. $pc_writeable = is_writable(PC_PATH.'base.php');
  200. $common_cache = getcache('common','commons');
  201. $logsize_warning = errorlog_size() > $common_cache['errorlog_size'] ? '1' : '0';
  202. $adminpanel = $this->panel_db->select(array('userid'=>$userid), '*',20 , 'datetime');
  203. $product_copyright = '酷溜网(北京)科技有限公司';
  204. $programmer = '马玉辉、张明雪、李天会、潘兆志';
  205. $designer = '张二强';
  206. ob_start();
  207. include $this->admin_tpl('main');
  208. $data = ob_get_contents();
  209. ob_end_clean();
  210. system_information($data);
  211. }
  212. /**
  213. * 维持 session 登陆状态
  214. */
  215. public function public_session_life() {
  216. $userid = $_SESSION['userid'];
  217. return true;
  218. }
  219. /**
  220. * 锁屏
  221. */
  222. public function public_lock_screen() {
  223. $_SESSION['lock_screen'] = 1;
  224. }
  225. public function public_login_screenlock() {
  226. if(empty($_GET['lock_password'])) showmessage(L('password_can_not_be_empty'));
  227. //密码错误剩余重试次数
  228. $this->times_db = pc_base::load_model('times_model');
  229. $username = param::get_cookie('admin_username');
  230. $maxloginfailedtimes = getcache('common','commons');
  231. $maxloginfailedtimes = (int)$maxloginfailedtimes['maxloginfailedtimes'];
  232. $rtime = $this->times_db->get_one(array('username'=>$username,'isadmin'=>1));
  233. if($rtime['times'] > $maxloginfailedtimes-1) {
  234. $minute = 60-floor((SYS_TIME-$rtime['logintime'])/60);
  235. exit('3');
  236. }
  237. //查询帐号
  238. $r = $this->db->get_one(array('userid'=>$_SESSION['userid']));
  239. $password = md5(md5($_GET['lock_password']).$r['encrypt']);
  240. if($r['password'] != $password) {
  241. $ip = ip();
  242. if($rtime && $rtime['times']<$maxloginfailedtimes) {
  243. $times = $maxloginfailedtimes-intval($rtime['times']);
  244. $this->times_db->update(array('ip'=>$ip,'isadmin'=>1,'times'=>'+=1'),array('username'=>$username));
  245. } else {
  246. $this->times_db->insert(array('username'=>$username,'ip'=>$ip,'isadmin'=>1,'logintime'=>SYS_TIME,'times'=>1));
  247. $times = $maxloginfailedtimes;
  248. }
  249. exit('2|'.$times);//密码错误
  250. }
  251. $this->times_db->delete(array('username'=>$username));
  252. $_SESSION['lock_screen'] = 0;
  253. exit('1');
  254. }
  255. //后台站点地图
  256. public function public_map() {
  257. $array = admin::admin_menu(0);
  258. $menu = array();
  259. foreach ($array as $k=>$v) {
  260. $menu[$v['id']] = $v;
  261. $menu[$v['id']]['childmenus'] = admin::admin_menu($v['id']);
  262. }
  263. $show_header = true;
  264. include $this->admin_tpl('map');
  265. }
  266. /**
  267. *
  268. * 读取盛大接扣获取appid和secretkey
  269. */
  270. public function public_snda_status() {
  271. //引入盛大接口
  272. if(!strstr(pc_base::load_config('snda','snda_status'), '|')) {
  273. $this->site_db = pc_base::load_model('site_model');
  274. $uuid_arr = $this->site_db->get_one(array('siteid'=>1), 'uuid');
  275. $uuid = $uuid_arr['uuid'];
  276. $snda_check_url = "http://open.sdo.com/phpcms?cmsid=".$uuid."&sitedomain=".$_SERVER['SERVER_NAME'];
  277. $snda_res_json = @file_get_contents($snda_check_url);
  278. $snda_res = json_decode($snda_res_json, 1);
  279. if(!isset($snda_res[err]) && !empty($snda_res['appid'])) {
  280. $appid = $snda_res['appid'];
  281. $secretkey = $snda_res['secretkey'];
  282. set_config(array('snda_status'=>$appid.'|'.$secretkey), 'snda');
  283. }
  284. }
  285. }
  286. /**
  287. * @设置网站模式 设置了模式后,后台仅出现在此模式中的菜单
  288. */
  289. public function public_set_model() {
  290. $model = $_GET['site_model'];
  291. if (!$model) {
  292. param::set_cookie('site_model','');
  293. } else {
  294. $models = pc_base::load_config('model_config');
  295. if (in_array($model, array_keys($models))) {
  296. param::set_cookie('site_model', $model);
  297. } else {
  298. param::set_cookie('site_model','');
  299. }
  300. }
  301. $menudb = pc_base::load_model('menu_model');
  302. $where = array('parentid'=>0,'display'=>1);
  303. if ($model) {
  304. $where[$model] = 1;
  305. }
  306. $result =$menudb->select($where,'id',1000,'listorder ASC');
  307. $menuids = array();
  308. if (is_array($result)) {
  309. foreach ($result as $r) {
  310. $menuids[] = $r['id'];
  311. }
  312. }
  313. exit(json_encode($menuids));
  314. }
  315. }
  316. ?>