ModPasswordExcutor.cs 3.9 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113
  1. using System;
  2. using System.Collections.Generic;
  3. using System.Data.SqlClient;
  4. using System.Linq;
  5. using System.Text;
  6. using JLHHJSvr.BLL;
  7. using JLHHJSvr.Com;
  8. using JLHHJSvr.Com.Model;
  9. using JLHHJSvr.DBA.DBModle;
  10. using LJLib.DAL.SQL;
  11. using LJLib.Net.SPI.Server;
  12. using LJLib.Tools.DEncrypt;
  13. namespace JLHHJSvr.Excutor
  14. {
  15. internal sealed class ModPasswordExcutor : ExcutorBase<ModPasswordRequest, ModPasswordResponse>
  16. {
  17. protected override void ExcuteInternal(ModPasswordRequest request, object state, ModPasswordResponse rslt)
  18. {
  19. TokenData tokendata = null;
  20. if (string.IsNullOrEmpty(request.usercode))
  21. {
  22. rslt.ErrMsg = "未填写用户名";
  23. return;
  24. }
  25. if (request.oldpsw == null)
  26. {
  27. rslt.ErrMsg = "入参异常,旧密码为空";
  28. return;
  29. }
  30. if (request.newpsw == null)
  31. {
  32. //重置
  33. tokendata = BllHelper.GetToken(request.token);
  34. if (tokendata == null)
  35. {
  36. rslt.ErrMsg = "会话已经中断,请重新登录";
  37. return;
  38. }
  39. }
  40. else if (request.newpsw.Equals(""))
  41. {
  42. rslt.ErrMsg = "新密码不能为空";
  43. return;
  44. }
  45. using (var con = new SqlConnection(GlobalVar.ConnectionString))
  46. using (var cmd = con.CreateCommand())
  47. {
  48. con.Open();
  49. var user = new st_user(){usercode = request.usercode};
  50. cmd.CommandText = "SELECT userid, psw FROM st_user WHERE usercode = @usercode";
  51. cmd.Parameters.Clear();
  52. cmd.Parameters.AddWithValue("@usercode", user.usercode);
  53. using (var reader = cmd.ExecuteReader())
  54. {
  55. if (reader.Read())
  56. {
  57. user.userid = Convert.ToInt32(reader["userid"]);
  58. user.psw = Convert.ToString(reader["psw"]);
  59. }
  60. else
  61. {
  62. rslt.ErrMsg = string.Format("没有用户名为[{0}]的用户");
  63. return;
  64. }
  65. }
  66. using (cmd.Transaction = con.BeginTransaction())
  67. {
  68. try
  69. {
  70. if (request.newpsw == null)
  71. {
  72. //重置
  73. var havePower = new Power().CheckPower(cmd, tokendata.userid, 26);
  74. if (!havePower)
  75. {
  76. rslt.ErrMsg = "您没有恢复密码的权限";
  77. return;
  78. }
  79. //重置后密码与用户名一样
  80. user.psw = DESEncrypt.Encrypt(request.usercode, "BC493812B6664BECBF44C21C3BB043C4");
  81. }
  82. else
  83. {
  84. //修改
  85. if (DESEncrypt.Encrypt(request.oldpsw, "BC493812B6664BECBF44C21C3BB043C4") != user.psw)
  86. {
  87. rslt.ErrMsg = "密码错误";
  88. return;
  89. }
  90. user.psw = DESEncrypt.Encrypt(request.newpsw, "BC493812B6664BECBF44C21C3BB043C4");
  91. }
  92. DbSqlHelper.Update(cmd, user, "psw");
  93. cmd.Transaction.Commit();
  94. }
  95. catch (Exception e)
  96. {
  97. cmd.Transaction.Rollback();
  98. rslt.ErrMsg = e.ToString();
  99. }
  100. }
  101. }
  102. }
  103. }
  104. }