asp.net webapi使用过滤器/filter实现用户禁用登录控制

/// <summary>
    /// 锁定账户的检查
    /// </summary>
    public class LockAccountAttribute : ActionFilterAttribute
    {
        public override void OnActionExecuting(HttpActionContext actionContext)
        {
            Base_UsersDTO userinfo = null;
            string actionName = actionContext.ActionDescriptor.ActionName;
            if (actionName.ToLower() == "login")
            {
                var args = actionContext.ActionArguments;
                var userLoginDTO = args["userlogin"] as UserLoginDTO;
                if (userLoginDTO != null)
                {
                    userinfo = new Base_UsersBLL().GetUserInfo(userLoginDTO.UserAccount).ToDto<Base_Users, Base_UsersDTO>();
                }
            }
            else
            {
                IEnumerable<string> tokenlist;
                if (actionContext.Request.Headers.TryGetValues("x-token", out tokenlist))
                {
                    Object obj = actionContext.Request.Content.ReadAsStreamAsync();
                    string token = tokenlist.FirstOrDefault();
                    var token_obj = CacheHelper.Get(token);
                    userinfo = JsonConvert.DeserializeObject<Base_UsersDTO>(token_obj.ToString());
                }
            }

            if (userinfo != null)
            {
                var user_LockBLL = new User_LockBLL();
                string memberID = userinfo.UserID;

                if (userinfo.UserType == SettleAccountType.merchant.GetStringValue())//如果是商家或者服务商,会有全组织下禁用
                {
                    memberID = userinfo.MerchantID;
                }
                else if (userinfo.UserType == SettleAccountType.isv.GetStringValue())
                {
                    memberID = userinfo.OrganizationID;
                }

                var lockSettleAccountInfo = user_LockBLL.IsLock(userinfo.UserType.ToEnum<SettleAccountType>(), memberID, LockEvent.Account);
                if (lockSettleAccountInfo.Status == true)
                {
                    actionContext.Response = new HttpResponseMessage
                    {
                        Content = new StringContent(JsonConvert.SerializeObject(new
                        {
                            statusCode = 0,
                            message = "账户已禁用",
                        }), System.Text.Encoding.GetEncoding("UTF-8"), "application/json"),
                        StatusCode = HttpStatusCode.OK
                    };
                }

                if (userinfo.UserType == SettleAccountType.merchant.GetStringValue() || userinfo.UserType == SettleAccountType.isv.GetStringValue())//如果是商家或者服务商,可以独立禁用员工
                {
                    var lockUserInfo = user_LockBLL.IsLock(userinfo.UserType.ToEnum<SettleAccountType>(), userinfo.UserID, LockEvent.Account);
                    if (lockUserInfo.Status == true)
                    {
                        actionContext.Response = new HttpResponseMessage
                        {
                            Content = new StringContent(JsonConvert.SerializeObject(new
                            {
                                statusCode = 0,
                                message = "账户已禁用",
                            }), System.Text.Encoding.GetEncoding("UTF-8"), "application/json"),
                            StatusCode = HttpStatusCode.OK
                        };
                    }
                }
            }
            else
            {
                actionContext.Response = new HttpResponseMessage
                {
                    Content = new StringContent(JsonConvert.SerializeObject(new
                    {
                        statusCode = 0,
                        message = "未找到用户信息",
                    }), System.Text.Encoding.GetEncoding("UTF-8"), "application/json"),
                    StatusCode = HttpStatusCode.OK
                };
            }

        }
    }

 

评论 2
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值