LoginController.java 6.8 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161
  1. package com.lemon.lifecenter.controller;
  2. import java.util.HashMap;
  3. import javax.servlet.http.HttpServletRequest;
  4. import javax.servlet.http.HttpServletResponse;
  5. import org.json.JSONObject;
  6. import org.slf4j.Logger;
  7. import org.slf4j.LoggerFactory;
  8. import org.springframework.beans.factory.annotation.Autowired;
  9. import org.springframework.stereotype.Controller;
  10. import org.springframework.web.bind.annotation.ModelAttribute;
  11. import org.springframework.web.bind.annotation.RequestMapping;
  12. import org.springframework.web.bind.annotation.RequestMethod;
  13. import org.springframework.web.bind.annotation.ResponseBody;
  14. import org.springframework.web.servlet.ModelAndView;
  15. import com.lemon.lifecenter.common.LifeCenterConfigVO;
  16. import com.lemon.lifecenter.common.LifeCenterController;
  17. import com.lemon.lifecenter.common.LifeCenterFunction;
  18. import com.lemon.lifecenter.common.LifeCenterSessionController;
  19. import com.lemon.lifecenter.dto.LoginDTO;
  20. import com.lemon.lifecenter.service.LoginService;
  21. @Controller
  22. @RequestMapping("/login")
  23. public class LoginController extends LifeCenterController {
  24. private final Logger logger = LoggerFactory.getLogger(this.getClass());
  25. @Autowired
  26. LifeCenterConfigVO config;
  27. @Autowired
  28. LoginService loginService;
  29. @RequestMapping("/admin")
  30. public ModelAndView adminLogin() {
  31. ModelAndView mv = setMV("login/admin");
  32. return mv;
  33. }
  34. @RequestMapping("/staff")
  35. public ModelAndView staffLogin() {
  36. ModelAndView mv = setMV("login/staff");
  37. return mv;
  38. }
  39. @RequestMapping( value="/check", method = RequestMethod.POST )
  40. @ResponseBody
  41. public String staffLoginCheck(
  42. @ModelAttribute("dto") final LoginDTO dto,
  43. HttpServletRequest request, HttpServletResponse response ) throws Exception {
  44. String remoteIp = LifeCenterFunction.getRemoteAddr( request );
  45. String resultCode = "";
  46. String message = "";
  47. String url = "";
  48. HashMap<String, String> accessMap = new HashMap<String, String>();
  49. JSONObject json = new JSONObject();
  50. // dto.setPassword( LifeCenterFunction.aesEncrypt( config.aesKey, config.IV, dto.getPassword() ) );
  51. dto.setPassword( LifeCenterFunction.sha256Encrypt(dto.getPassword()) );
  52. int total = loginService.selectMemberCount( dto );
  53. if( total == 0 ) { //로그인실패시 log 남긴 후 failCount 처리
  54. resultCode = "01";
  55. message = "아이디 또는 비밀번호를 다시 확인하세요.<br/>등록되지 않은 사용자이거나, 잘못된 비밀번호입니다.";
  56. logger.error( "[LOGIN FAILED] RemoteIP : " + remoteIp + " ID : " + dto.getId() + "MESSAGE : " + LifeCenterFunction.removeTag( message ) );
  57. if( loginService.selectMemberIdCount( dto ) == 1 ) { //존재하는사용자일경우
  58. dto.setFailCount( loginService.selectMemberFailCount( dto ) + 1 ); //해당아이디의 failCount + 1
  59. dto.setResultCode( resultCode );
  60. accessMap.put( "id" , dto.getId() );
  61. accessMap.put( "ip" , remoteIp );
  62. accessMap.put( "successYn", "N" );
  63. accessMap.put( "logMessage" , LifeCenterFunction.removeTag( message ) );
  64. loginService.updateMemberLoginData( dto ); //해당 아이디의 failCount
  65. loginService.insertAccessHistory( accessMap );
  66. }
  67. } else { // 로그인 성공시 ( id, password 일치 )
  68. LoginDTO memberData = loginService.selectMemberData( dto );
  69. accessMap.put( "id" , dto.getId() );
  70. accessMap.put( "ip" , remoteIp );
  71. if( memberData.getUseYn().toUpperCase().equals( "N" ) ) { // 사용이 중지된 계정
  72. logger.error( "[LOGIN FAILED] RemoteIP : " + remoteIp + " ID : " + dto.getId() );
  73. resultCode = "02";
  74. message = "사용이 중지된 계정입니다. 관리자에게 문의하세요.";
  75. accessMap.put( "successYn", "N" );
  76. accessMap.put( "logMessage" , message );
  77. logger.error( "[LOGIN FAILED] RemoteIP : " + remoteIp + " ID : " + dto.getId() + "MESSAGE : " + message );
  78. loginService.insertAccessHistory( accessMap );
  79. } else {
  80. // 로그인 성공
  81. // failCount 0 초기화
  82. // last login time NOW() update
  83. resultCode = "00";
  84. message = "로그인 성공";
  85. dto.setFailCount( 0 );
  86. dto.setResultCode( resultCode );
  87. accessMap.put( "successYn", "Y" );
  88. accessMap.put( "logMessage" , message );
  89. logger.info( "[LOGIN SUCCESS] RemoteIP : " + remoteIp + " ID : " + dto.getId() + "MESSAGE : " + message );
  90. loginService.updateMemberLoginData( dto ); //failCount -> 0, lastLoginTime -> NOW()
  91. loginService.insertAccessHistory( accessMap ); //insert AccessHistory
  92. LifeCenterSessionController.sessionInvalidate( request );
  93. LifeCenterSessionController.setSession( request, "sesId", memberData.getId() );
  94. LifeCenterSessionController.setSession( request, "sesName", memberData.getName() );
  95. LifeCenterSessionController.setSession( request, "sesCenterCode", memberData.getCenterCode() );
  96. LifeCenterSessionController.setSession( request, "sesCenterName", memberData.getCenterName() );
  97. LifeCenterSessionController.setSession( request, "sesGroupIdx", String.valueOf( memberData.getGroupIdx() ) );
  98. url = "/patient/list";
  99. if( memberData.getGroupIdx() == 1 ) {
  100. url = "/center/list";
  101. }
  102. }
  103. }
  104. json.put( "code", resultCode );
  105. json.put( "message", message );
  106. json.put( "url", url );
  107. System.out.println( "JSON : " + json );
  108. return json.toString();
  109. }
  110. @RequestMapping("/logout")
  111. public String staffLogout( HttpServletRequest request, HttpServletResponse response ) {
  112. String remoteIp = LifeCenterFunction.getRemoteAddr( request );
  113. String sesId = LifeCenterSessionController.getSession( request, "sesId" );
  114. LifeCenterSessionController.sessionInvalidate( request );
  115. logger.error( "[LOGOUT] RemoteIP : " + remoteIp + " UserId : " + sesId );
  116. return "redirect:/login/staff";
  117. }
  118. }