File size: 10,920 Bytes
dd2231b
 
 
089917b
08adc84
b47ad38
 
 
dd2231b
d674f7c
b47ad38
 
d674f7c
d44aea5
 
 
dd2231b
 
d44aea5
dd2231b
 
 
 
 
d44aea5
dd2231b
 
 
 
d44aea5
033f13b
dd2231b
 
 
 
 
 
 
 
 
 
 
 
 
599ee8f
dd2231b
d674f7c
d44aea5
d674f7c
 
dd2231b
 
 
 
 
d674f7c
dd2231b
 
 
033f13b
d44aea5
dd2231b
 
033f13b
b47ad38
089917b
 
d674f7c
dd2231b
 
089917b
 
dd2231b
 
 
 
 
b47ad38
 
 
 
d674f7c
 
d44aea5
d674f7c
 
dd2231b
 
 
d674f7c
 
dd2231b
 
599ee8f
dd2231b
 
 
599ee8f
d674f7c
b47ad38
 
 
 
 
 
 
 
 
d674f7c
 
d44aea5
 
 
b47ad38
 
 
 
089917b
d44aea5
599ee8f
d44aea5
 
 
 
 
b47ad38
 
 
 
 
599ee8f
d44aea5
 
089917b
 
 
 
b47ad38
 
 
 
 
089917b
 
 
 
599ee8f
089917b
b47ad38
089917b
599ee8f
089917b
ec5b9cf
08adc84
599ee8f
ec5b9cf
 
08adc84
599ee8f
b47ad38
089917b
 
 
599ee8f
089917b
 
 
 
 
b47ad38
 
 
 
 
 
 
 
089917b
599ee8f
b47ad38
089917b
 
 
599ee8f
089917b
 
 
599ee8f
089917b
599ee8f
089917b
 
b47ad38
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
089917b
 
 
 
 
 
 
 
 
 
 
 
 
 
ec5b9cf
089917b
 
 
08adc84
 
089917b
 
ec5b9cf
089917b
 
 
08adc84
 
089917b
 
 
 
 
 
 
 
 
ec5b9cf
089917b
 
 
 
 
08adc84
 
 
089917b
 
 
 
 
 
 
 
 
ec5b9cf
 
 
 
 
 
 
 
 
 
 
 
 
 
08adc84
 
 
 
 
 
 
 
 
 
 
 
 
089917b
b47ad38
 
089917b
 
 
 
 
b47ad38
 
089917b
 
 
 
 
 
 
 
 
 
d674f7c
 
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
import json
import random
import string
import uuid
import time
import jwt
import datetime
from flask import Flask, request, jsonify, Request
from redis import Redis

SECERT_KEY = "8U2LL1"

app = Flask(__name__)
redis = Redis(host='192.168.3.229', port=6379, password='lizhen-redis')
# redis = Redis(host='10.254.13.87', port=6379)
# redis = Redis(host='localhost', port=6379)


# 生成验证码
def generate_verification_code():
    code = ''.join(random.choices(string.digits, k=6))
    return code


# 发送验证码到用户邮箱(这里只是模拟发送过程)
def send_verification_code(email, code):
    print(f'Sending verification code {code} to {email}...')


# 用户请求发送验证码
@app.route('/sendRegisterEmailCode', methods=['POST'])
def send_verification_code_endpoint():
    # 从请求中获取邮箱地址
    email = request.json.get('email')

    # 生成验证码
    verification_code = generate_verification_code()

    # 发送验证码到用户邮箱
    send_verification_code(email, verification_code)

    # 保存验证码到Redis,并设置过期时间(例如,5分钟)
    redis.setex(email, 300, verification_code)

    return jsonify({'code': 0, 'message': 'Verification code sent'})


# 用户注册
@app.route('/register', methods=['POST'])
def register():
    # 从请求中获取注册信息
    email = request.json.get('email')
    username = request.json.get('username')
    password = request.json.get('password')
    verification_code = request.json.get('verification_code')

    # 检查验证码是否匹配
    stored_code = redis.get(email)
    if stored_code is None or verification_code != stored_code.decode('utf-8'):
        return jsonify({'code': 400, 'message': 'Invalid verification code'})

    # 检查用户名是否已被注册
    if redis.hexists('users', username):
        return jsonify({'code': 400, 'message': 'Username already exists'})

    # 生成唯一的用户ID
    user_id = str(uuid.uuid4())

    # 保存用户信息到Redis
    user_data = {
        'user_id': user_id,
        'username': username,
        'email': email,
        'password': password
    }
    redis.hset('users', username, json.dumps(user_data))

    return jsonify({
        'code': 0,
        'message': 'Registration successful'
    })


# 用户登录
@app.route('/login', methods=['POST'])
def login():
    # 从请求中获取登录信息
    username = request.json.get('username')
    password = request.json.get('password')

    # 检查用户名和密码是否匹配
    user_data = redis.hget('users', username)
    if not user_data:
        return jsonify({'code': 400, 'message': 'Invalid username'})

    user_data = user_data.decode('utf-8')
    if password != eval(user_data)['password']:
        return jsonify({'code': 400, 'message': 'Invalid password'})

    # 生成令牌
    token = generate_token(eval(user_data)['user_id'], username)
    return jsonify({
        'code': 0,
        'message': 'Login successful',
        'data': {
            'token': token
        }
    })


# 需要验证登录状态的接口
@app.route('/protected', methods=['GET'])
def protected():
    token = parse_token(request)
    # 验证令牌
    if not validate_token(token):
        return jsonify({'code': 401, 'message': 'Invalid token'}), 200

    # 如果用户未登录,则返回未授权的响应
    return jsonify({'code': 401, 'message': 'Unauthorized'})


# 用户注销
@app.route('/logout', methods=['POST'])
def logout():
    token = parse_token(request)
    # 验证令牌
    if not validate_token(token):
        # 将令牌添加到 Redis 黑名单
        redis.set(token, 'revoked')
    return jsonify({'code': 0, 'message': 'Logout successful'})


# 购买支付套餐
@app.route('/purchase', methods=['POST'])
def purchase():
    package_id = request.json.get('package_id')
    token = parse_token(request)

    # 验证令牌
    if not validate_token(token):
        return jsonify({'code': 401, 'message': 'Invalid token'})

    # 根据套餐ID获取套餐信息
    package = get_package_by_id(package_id)
    if not package:
        return jsonify({'code': 400, 'message': 'Invalid package ID'})

    user_id = get_user_id_from_token(token)
    if not user_id:
        return jsonify({'code': 400, 'message': 'User not found'})

    # 检查用户是否已经支付过当前套餐
    if not is_package_expired(user_id) and has_purchased_package(user_id, package_id):
        return jsonify({'code': 400, 'message': 'Package already purchased'})

    # 检查如果用户已经支付了高级套餐,则不能支付比高级套餐更低级的基础套餐
    if not is_package_expired(user_id) and has_purchased_advanced_package(user_id) and package_id == '1':
        return jsonify({'code': 400, 'message': 'Cannot purchase lower level package'})

    # 存储用户套餐信息到Redis
    store_user_package(user_id, package)

    return jsonify({'code': 0, 'message': 'Purchase successful'})


# 验证用户聊天次数
@app.route('/validate', methods=['POST'])
def validate():
    token = parse_token(request)

    # 验证令牌
    if not validate_token(token):
        return jsonify({'code': 401, 'message': 'Invalid token'})

    user_id = get_user_id_from_token(token)

    if not user_id:
        return jsonify({'code': 400, 'message': 'User not found'})

    # 获取用户套餐信息
    package = get_user_package(user_id)
    if not package:
        return jsonify({'code': 400, 'message': 'User has not purchased any package'})

    # 检查用户聊天次数是否超过限制
    if exceeded_chat_limit(user_id, package):
        return jsonify({'code': 400, 'message': 'Chat limit exceeded'})

    return jsonify({'code': 0, 'message': 'Chat limit not exceeded'})


def parse_token(request: Request):
    token_with_bearer = request.headers.get('Authorization')

    if token_with_bearer is not None and token_with_bearer.startswith('Bearer '):
        token = token_with_bearer.split(' ')[1]
    else:
        # 处理未包含 "Bearer" 前缀的情况
        token = token_with_bearer
    return token


# 生成令牌
def generate_token(user_id, username):
    # 构造包含用户信息的负载
    payload = {
        'user_id': user_id,
        'username': username,
        'exp': datetime.datetime.utcnow() + datetime.timedelta(hours=1)
        }

    # 在这里,您可以使用您的密钥(secret key)来签署令牌
    # 选择适当的签名算法,并设置适当的过期时间等参数
    # 仅使用 HS256 算法和过期时间为1小时
    token = jwt.encode(payload, SECERT_KEY, algorithm='HS256')
    return token


# 验证令牌
def validate_token(token):
    try:
        print(token)
        # 使用密钥进行解码
        payload = jwt.decode(token, SECERT_KEY, algorithms=['HS256'])
        print(payload)

        # 检查令牌的过期时间
        if 'exp' in payload and datetime.datetime.utcnow() > datetime.datetime.fromtimestamp(payload['exp']):
            return False

        return True
    except (jwt.DecodeError, jwt.InvalidTokenError):
        return False


def get_user_id_from_token(token):
    try:
        decoded_token = jwt.decode(
            token, SECERT_KEY, algorithms=['HS256'])
        user_id = decoded_token.get('user_id')
        return user_id
    except jwt.ExpiredSignatureError:
        # 处理过期的令牌
        return None
    except (jwt.DecodeError, jwt.InvalidTokenError):
        # 处理解码或无效的令牌
        return None


# 获取用户ID通过用户名
def get_user_id_by_username(username):
    user_data = redis.hget('users', username)
    if user_data:
        user_data = json.loads(user_data.decode('utf-8'))
        user_id = user_data.get('user_id')
        return user_id
    return None


# 根据套餐ID获取套餐信息
def get_package_by_id(package_id):
    packages = {
        '1': {
            'package_id': '1',
            'name': 'Package 1',
            'basic_chat_limit': 10,
            'advanced_chat_limit': 10,
            'price': 10,
            'expiration': 30 * 24 * 60 * 60  # 过期时间为30天(以秒为单位)
        },
        '2': {
            'package_id': '2',
            'name': 'Package 2',
            'basic_chat_limit': -1,  # -1 表示无限次
            'advanced_chat_limit': -1,
            'price': 100,
            'expiration': 30 * 24 * 60 * 60  # 过期时间为30天(以秒为单位)
        }
    }

    return packages.get(package_id)


# 存储用户套餐信息到Redis
def store_user_package(user_id, package):
    user_package_key = f'user:{user_id}:package'
    redis.hset(user_package_key, 'package_id', package['package_id'])
    redis.hset(user_package_key, 'name', package['name'])
    redis.hset(user_package_key, 'basic_chat_limit',
               package['basic_chat_limit'])
    redis.hset(user_package_key, 'advanced_chat_limit',
               package['advanced_chat_limit'])
    # 设置套餐过期时间
    expiration = int(time.time()) + package['expiration']
    redis.expireat(user_package_key, expiration)


# 获取用户套餐信息
def get_user_package(user_id):
    user_package_key = f'user:{user_id}:package'
    package = redis.hgetall(user_package_key)
    return package


# 检查用户是否已经支付过指定套餐
def has_purchased_package(user_id, package_id):
    user_package_key = f'user:{user_id}:package'
    purchased_package_id = redis.hget(user_package_key, 'package_id')
    return purchased_package_id.decode('utf-8') == str(package_id)


# 检查用户是否已经支付了高级套餐
def has_purchased_advanced_package(user_id):
    user_package_key = f'user:{user_id}:package'
    purchased_package_id = redis.hget(user_package_key, 'package_id')
    return purchased_package_id.decode('utf-8') == '2'


# 检查套餐是否过期
def is_package_expired(user_id):
    user_package_key = f'user:{user_id}:package'
    expiration = redis.ttl(user_package_key)
    return expiration <= 0


# 获取套餐有效期
def get_package_expiration(user_id):
    user_package_key = f'user:{user_id}:package'
    expiration = redis.ttl(user_package_key)
    return expiration

# 检查用户聊天次数是否超过限制


def exceeded_chat_limit(user_id, package):
    user_basic_chat_key = f'user:{user_id}:basic_chat'
    user_advanced_chat_key = f'user:{user_id}:advanced_chat'

    basic_chat_limit = int(package.get(b'basic_chat_limit', 0).decode('utf-8'))
    advanced_chat_limit = int(package.get(
        b'advanced_chat_limit', 0).decode('utf-8'))

    if basic_chat_limit >= 0 and int(redis.get(user_basic_chat_key) or 0) >= basic_chat_limit:
        return True

    if advanced_chat_limit >= 0 and int(redis.get(user_advanced_chat_key) or 0) >= advanced_chat_limit:
        return True

    return False


if __name__ == '__main__':
    app.run(debug=True)