control.php 9.4 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312
  1. <?php
  2. /**
  3. * 系统后台公共方法
  4. *
  5. * 包括系统后台父类
  6. *
  7. ***/
  8. defined('InShopNC') or exit('Access Invalid!');
  9. class SystemControl
  10. {
  11. /**
  12. * 管理员资料 name id group
  13. */
  14. protected $admin_info;
  15. /**
  16. * 权限内容
  17. */
  18. protected $permission;
  19. protected function __construct()
  20. {
  21. Language::read('common,layout');
  22. /**
  23. * 验证用户是否登录
  24. * $admin_info 管理员资料 name id
  25. */
  26. $this->admin_info = $this->systemLogin();
  27. if ($this->admin_info['id'] != 1){
  28. // 验证权限
  29. $this->checkPermission();
  30. }
  31. //转码 防止GBK下用ajax调用时传汉字数据出现乱码
  32. if (($_GET['branch']!='' || $_GET['op']=='ajax') && strtoupper(CHARSET) == 'GBK'){
  33. $_GET = Language::getGBK($_GET);
  34. }
  35. }
  36. /**
  37. * 取得当前管理员信息
  38. *
  39. * @param
  40. * @return 数组类型的返回结果
  41. */
  42. protected final function getAdminInfo(){
  43. return $this->admin_info;
  44. }
  45. /**
  46. * 系统后台登录验证
  47. *
  48. * @param
  49. * @return array 数组类型的返回结果
  50. */
  51. protected final function systemLogin(){
  52. //取得cookie内容,解密,和系统匹配
  53. $user = unserialize(decrypt(cookie('sys_key'),MD5_KEY));
  54. if (!key_exists('gid',(array)$user) || !isset($user['sp']) || (empty($user['name']) || empty($user['id']))){
  55. @header('Location: index.php?act=login&op=login');exit;
  56. }else {
  57. $this->systemSetKey($user);
  58. }
  59. return $user;
  60. }
  61. /**
  62. * 系统后台 会员登录后 将会员验证内容写入对应cookie中
  63. *
  64. * @param string $name 用户名
  65. * @param int $id 用户ID
  66. * @return bool 布尔类型的返回结果
  67. */
  68. protected final function systemSetKey($user){
  69. setNcCookie('sys_key',encrypt(serialize($user),MD5_KEY),3600,'',null);
  70. }
  71. /**
  72. * 验证当前管理员权限是否可以进行操作
  73. *
  74. * @param string $link_nav
  75. * @return
  76. */
  77. protected final function checkPermission($link_nav = null){
  78. if ($this->admin_info['sp'] == 1) return true;
  79. $act = $_GET['act']?$_GET['act']:$_POST['act'];
  80. $op = $_GET['op']?$_GET['op']:$_POST['op'];
  81. if (empty($this->permission)){
  82. $gadmin = Model('gadmin')->getby_gid($this->admin_info['gid']);
  83. $permission = decrypt($gadmin['limits'],MD5_KEY.md5($gadmin['gname']));
  84. $this->permission = $permission = explode('|',$permission);
  85. }else{
  86. $permission = $this->permission;
  87. }
  88. //显示隐藏小导航,成功与否都直接返回
  89. if (is_array($link_nav)){
  90. if (!in_array("{$link_nav['act']}.{$link_nav['op']}",$permission) && !in_array($link_nav['act'],$permission)){
  91. return false;
  92. }else{
  93. return true;
  94. }
  95. }
  96. //以下几项不需要验证
  97. $tmp = array('index','dashboard','login','common','cms_base');
  98. if (in_array($act,$tmp)) return true;
  99. if (in_array($act,$permission) || in_array("$act.$op",$permission)){
  100. return true;
  101. }else{
  102. $extlimit = array('ajax','export_step1');
  103. if (in_array($op,$extlimit) && (in_array($act,$permission) || strpos(serialize($permission),'"'.$act.'.'))){
  104. return true;
  105. }
  106. //带前缀的都通过
  107. foreach ($permission as $v) {
  108. if (!empty($v) && strpos("$act.$op",$v.'_') !== false) {
  109. return true;break;
  110. }
  111. }
  112. }
  113. showMessage(Language::get('nc_assign_right'),'','html','succ',0);
  114. }
  115. /**
  116. * 取得后台菜单
  117. *
  118. * @param string $permission
  119. * @return
  120. */
  121. protected final function getNav($permission = '',&$top_nav,&$left_nav,&$map_nav){
  122. $act = $_GET['act']?$_GET['act']:$_POST['act'];
  123. $op = $_GET['op']?$_GET['op']:$_POST['op'];
  124. if ($this->admin_info['sp'] != 1 && empty($this->permission)){
  125. $gadmin = Model('gadmin')->getby_gid($this->admin_info['gid']);
  126. $permission = decrypt($gadmin['limits'],MD5_KEY.md5($gadmin['gname']));
  127. $this->permission = $permission = explode('|',$permission);
  128. }
  129. Language::read('common');
  130. $lang = Language::getLangContent();
  131. $array = require(BASE_PATH.'/include/menu.php');
  132. $array = $this->parseMenu($array);
  133. //管理地图
  134. $map_nav = $array['left'];
  135. unset($map_nav[0]);
  136. $model_nav = "<li><a class=\"link actived\" id=\"nav__nav_\" href=\"javascript:;\" onclick=\"openItem('_args_');\"><span>_text_</span></a></li>\n";
  137. $top_nav = '';
  138. //顶部菜单
  139. foreach ($array['top'] as $k=>$v) {
  140. $v['nav'] = $v['args'];
  141. $top_nav .= str_ireplace(array('_args_','_text_','_nav_'),$v,$model_nav);
  142. }
  143. $top_nav = str_ireplace("\n<li><a class=\"link actived\"","\n<li><a class=\"link\"",$top_nav);
  144. //左侧菜单
  145. $model_nav = "
  146. <ul id=\"sort__nav_\">
  147. <li>
  148. <dl>
  149. <dd>
  150. <ol>
  151. list_body
  152. </ol>
  153. </dd>
  154. </dl>
  155. </li>
  156. </ul>\n";
  157. $left_nav = '';
  158. foreach ($array['left'] as $k=>$v) {
  159. $left_nav .= str_ireplace(array('_nav_'),array($v['nav']),$model_nav);
  160. $model_list = "<li nc_type='_pkey_'><a href=\"JavaScript:void(0);\" name=\"item__opact_\" id=\"item__opact_\" onclick=\"openItem('_args_');\">_text_</a></li>";
  161. $tmp_list = '';
  162. $current_parent = '';//当前父级key
  163. foreach ($v['list'] as $key=>$value) {
  164. $model_list_parent = '';
  165. $args = explode(',',$value['args']);
  166. if (!empty($value['parent'])){
  167. if (empty($current_parent) || $current_parent != $value['parent']){
  168. $model_list_parent = "<li nc_type='parentli' dataparam='{$value['parent']}'><dt>{$value['parenttext']}</dt><dd style='display:block;'></dd></li>";
  169. }
  170. $current_parent = $value['parent'];
  171. }
  172. $value['op'] = $args[0];
  173. $value['act'] = $args[1];
  174. //$tmp_list .= str_ireplace(array('_args_','_text_','_op_'),$value,$model_list);
  175. $tmp_list .= str_ireplace(['_args_','_text_','_opact_','_pkey_'],
  176. [$value['args'],$value['text'],$value['op'],$value['act'],$value['parent']],
  177. $model_list_parent.$model_list);
  178. }
  179. $left_nav = str_replace('list_body',$tmp_list,$left_nav);
  180. }
  181. }
  182. /**
  183. * 过滤掉无权查看的菜单
  184. *
  185. * @param array $menu
  186. * @return array
  187. */
  188. private final function parseMenu($menu = array()){
  189. if ($this->admin_info['sp'] == 1) return $menu;
  190. foreach ($menu['left'] as $k=>$v) {
  191. foreach ($v['list'] as $xk=>$xv) {
  192. $tmp = explode(',',$xv['args']);
  193. //以下几项不需要验证
  194. $except = array('index','dashboard','login','common');
  195. if (in_array($tmp[1],$except)) continue;
  196. if (!in_array($tmp[1],$this->permission) && !in_array($tmp[1].'.'.$tmp[0],$this->permission)){
  197. unset($menu['left'][$k]['list'][$xk]);
  198. }
  199. }
  200. if (empty($menu['left'][$k]['list'])) {
  201. unset($menu['top'][$k]);unset($menu['left'][$k]);
  202. }
  203. }
  204. return $menu;
  205. }
  206. /**
  207. * 取得顶部小导航
  208. *
  209. * @param array $links
  210. * @param 当前页 $actived
  211. */
  212. protected final function sublink($links = array(), $actived = '', $file='index.php'){
  213. $linkstr = '';
  214. foreach ($links as $k=>$v) {
  215. parse_str($v['url'],$array);
  216. if (!$this->checkPermission($array)) continue;
  217. $href = ($array['op'] == $actived ? null : "href=\"{$file}?{$v['url']}\"");
  218. $class = ($array['op'] == $actived ? "class=\"current\"" : null);
  219. $lang = L($v['lang']);
  220. $linkstr .= sprintf('<li><a %s %s><span>%s</span></a></li>',$href,$class,$lang);
  221. }
  222. return "<ul class=\"tab-base\">{$linkstr}</ul>";
  223. }
  224. /**
  225. * 记录系统日志
  226. *
  227. * @param $lang 日志语言包
  228. * @param $state 1成功0失败null不出现成功失败提示
  229. * @param $admin_name
  230. * @param $admin_id
  231. */
  232. protected final function log($lang = '', $state = 1, $admin_name = '', $admin_id = 0){
  233. if (!C('sys_log') || !is_string($lang)) return;
  234. if ($admin_name == ''){
  235. $admin = unserialize(decrypt(cookie('sys_key'),MD5_KEY));
  236. $admin_name = $admin['name'];
  237. $admin_id = $admin['id'];
  238. }
  239. $data = array();
  240. if (is_null($state)){
  241. $state = null;
  242. }else{
  243. // $state = $state ? L('nc_succ') : L('nc_fail');
  244. $state = $state ? '' : L('nc_fail');
  245. }
  246. $data['content'] = $lang.$state;
  247. $data['admin_name'] = $admin_name;
  248. $data['createtime'] = time();
  249. $data['admin_id'] = $admin_id;
  250. $data['ip'] = getIp();
  251. $data['url'] = $_REQUEST['act'].'&'.$_REQUEST['op'];
  252. return Model('admin_log')->insert($data);
  253. }
  254. /**
  255. * 添加到任务队列
  256. *
  257. * @param array $goods_array
  258. * @param boolean $ifdel 是否删除以原记录
  259. */
  260. protected function addcron($data = array(), $ifdel = false) {
  261. $model_cron = Model('cron');
  262. if (isset($data[0])) { // 批量插入
  263. $where = array();
  264. foreach ($data as $k => $v) {
  265. if (isset($v['content'])) {
  266. $data[$k]['content'] = serialize($v['content']);
  267. }
  268. // 删除原纪录条件
  269. if ($ifdel) {
  270. $where[] = '(type = ' . $data['type'] . ' and exeid = ' . $data['exeid'] . ')';
  271. }
  272. }
  273. // 删除原纪录
  274. if ($ifdel) {
  275. $model_cron->delCron(implode(',', $where));
  276. }
  277. $model_cron->addCronAll($data);
  278. } else { // 单条插入
  279. if (isset($data['content'])) {
  280. $data['content'] = serialize($data['content']);
  281. }
  282. // 删除原纪录
  283. if ($ifdel) {
  284. $model_cron->delCron(array('type' => $data['type'], 'exeid' => $data['exeid']));
  285. }
  286. $model_cron->addCron($data);
  287. }
  288. }
  289. }