Captcha.php 20 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442
  1. <?php
  2. // +----------------------------------------------------------------------
  3. // | ThinkPHP [ WE CAN DO IT JUST THINK ]
  4. // +----------------------------------------------------------------------
  5. // | Copyright (c) 2006-2015 http://thinkphp.cn All rights reserved.
  6. // +----------------------------------------------------------------------
  7. // | Licensed ( http://www.apache.org/licenses/LICENSE-2.0 )
  8. // +----------------------------------------------------------------------
  9. // | Author: yunwuxin <448901948@qq.com>
  10. // +----------------------------------------------------------------------
  11. // | 妙码生花在 2022-2-26 进行修订,通过Mysql保存验证码而不是Session以更好的支持API访问
  12. // | 使用Cache不能清理过期验证码,且一旦执行清理缓存操作,验证码将失效
  13. // +----------------------------------------------------------------------
  14. namespace ba;
  15. use GdImage;
  16. use Throwable;
  17. use think\Response;
  18. use think\facade\Db;
  19. /**
  20. * 验证码类(图形验证码、继续流程验证码)
  21. * @property string $seKey 验证码加密密钥
  22. * @property string $codeSet 验证码字符集合
  23. * @property int $expire 验证码过期时间(s)
  24. * @property bool $useZh 使用中文验证码
  25. * @property string $zhSet 中文验证码字符串
  26. * @property bool $useImgBg 使用背景图片
  27. * @property int $fontSize 验证码字体大小(px)
  28. * @property bool $useCurve 是否画混淆曲线
  29. * @property bool $useNoise 是否添加杂点
  30. * @property int $imageH 验证码图片高度
  31. * @property int $imageW 验证码图片宽度
  32. * @property int $length 验证码位数
  33. * @property string $fontTtf 验证码字体,不设置随机获取
  34. * @property array $bg 背景颜色
  35. * @property bool $reset 验证成功后是否重置
  36. */
  37. class Captcha
  38. {
  39. protected array $config = [
  40. // 验证码加密密钥
  41. 'seKey' => 'BuildAdmin',
  42. // 验证码字符集合
  43. 'codeSet' => '2345678abcdefhijkmnpqrstuvwxyzABCDEFGHJKLMNPQRTUVWXY',
  44. // 验证码过期时间(s)
  45. 'expire' => 600,
  46. // 使用中文验证码
  47. 'useZh' => false,
  48. // 中文验证码字符串
  49. 'zhSet' => '们以我到他会作时要动国产的一是工就年阶义发成部民可出能方进在了不和有大这主中人上为来分生对于学下级地个用同行面说种过命度革而多子后自社加小机也经力线本电高量长党得实家定深法表着水理化争现所二起政三好十战无农使性前等反体合斗路图把结第里正新开论之物从当两些还天资事队批点育重其思与间内去因件日利相由压员气业代全组数果期导平各基或月毛然如应形想制心样干都向变关问比展那它最及外没看治提五解系林者米群头意只明四道马认次文通但条较克又公孔领军流入接席位情运器并飞原油放立题质指建区验活众很教决特此常石强极土少已根共直团统式转别造切九你取西持总料连任志观调七么山程百报更见必真保热委手改管处己将修支识病象几先老光专什六型具示复安带每东增则完风回南广劳轮科北打积车计给节做务被整联步类集号列温装即毫知轴研单色坚据速防史拉世设达尔场织历花受求传口断况采精金界品判参层止边清至万确究书术状厂须离再目海交权且儿青才证低越际八试规斯近注办布门铁需走议县兵固除般引齿千胜细影济白格效置推空配刀叶率述今选养德话查差半敌始片施响收华觉备名红续均药标记难存测士身紧液派准斤角降维板许破述技消底床田势端感往神便贺村构照容非搞亚磨族火段算适讲按值美态黄易彪服早班麦削信排台声该击素张密害侯草何树肥继右属市严径螺检左页抗苏显苦英快称坏移约巴材省黑武培著河帝仅针怎植京助升王眼她抓含苗副杂普谈围食射源例致酸旧却充足短划剂宣环落首尺波承粉践府鱼随考刻靠够满夫失包住促枝局菌杆周护岩师举曲春元超负砂封换太模贫减阳扬江析亩木言球朝医校古呢稻宋听唯输滑站另卫字鼓刚写刘微略范供阿块某功套友限项余倒卷创律雨让骨远帮初皮播优占死毒圈伟季训控激找叫云互跟裂粮粒母练塞钢顶策双留误础吸阻故寸盾晚丝女散焊功株亲院冷彻弹错散商视艺灭版烈零室轻血倍缺厘泵察绝富城冲喷壤简否柱李望盘磁雄似困巩益洲脱投送奴侧润盖挥距触星松送获兴独官混纪依未突架宽冬章湿偏纹吃执阀矿寨责熟稳夺硬价努翻奇甲预职评读背协损棉侵灰虽矛厚罗泥辟告卵箱掌氧恩爱停曾溶营终纲孟钱待尽俄缩沙退陈讨奋械载胞幼哪剥迫旋征槽倒握担仍呀鲜吧卡粗介钻逐弱脚怕盐末阴丰雾冠丙街莱贝辐肠付吉渗瑞惊顿挤秒悬姆烂森糖圣凹陶词迟蚕亿矩康遵牧遭幅园腔订香肉弟屋敏恢忘编印蜂急拿扩伤飞露核缘游振操央伍域甚迅辉异序免纸夜乡久隶缸夹念兰映沟乙吗儒杀汽磷艰晶插埃燃欢铁补咱芽永瓦倾阵碳演威附牙芽永瓦斜灌欧献顺猪洋腐请透司危括脉宜笑若尾束壮暴企菜穗楚汉愈绿拖牛份染既秋遍锻玉夏疗尖殖井费州访吹荣铜沿替滚客召旱悟刺脑措贯藏敢令隙炉壳硫煤迎铸粘探临薄旬善福纵择礼愿伏残雷延烟句纯渐耕跑泽慢栽鲁赤繁境潮横掉锥希池败船假亮谓托伙哲怀割摆贡呈劲财仪沉炼麻罪祖息车穿货销齐鼠抽画饲龙库守筑房歌寒喜哥洗蚀废纳腹乎录镜妇恶脂庄擦险赞钟摇典柄辩竹谷卖乱虚桥奥伯赶垂途额壁网截野遗静谋弄挂课镇妄盛耐援扎虑键归符庆聚绕摩忙舞遇索顾胶羊湖钉仁音迹碎伸灯避泛亡答勇频皇柳哈揭甘诺概宪浓岛袭谁洪谢炮浇斑讯懂灵蛋闭孩释乳巨徒私银伊景坦累匀霉杜乐勒隔弯绩招绍胡呼痛峰零柴簧午跳居尚丁秦稍追梁折耗碱殊岗挖氏刃剧堆赫荷胸衡勤膜篇登驻案刊秧缓凸役剪川雪链渔啦脸户洛孢勃盟买杨宗焦赛旗滤硅炭股坐蒸凝竟陷枪黎救冒暗洞犯筒您宋弧爆谬涂味津臂障褐陆啊健尊豆拔莫抵桑坡缝警挑污冰柬嘴啥饭塑寄赵喊垫丹渡耳刨虎笔稀昆浪萨茶滴浅拥穴覆伦娘吨浸袖珠雌妈紫戏塔锤震岁貌洁剖牢锋疑霸闪埔猛诉刷狠忽灾闹乔唐漏闻沈熔氯荒茎男凡抢像浆旁玻亦忠唱蒙予纷捕锁尤乘乌智淡允叛畜俘摸锈扫毕璃宝芯爷鉴秘净蒋钙肩腾枯抛轨堂拌爸循诱祝励肯酒绳穷塘燥泡袋朗喂铝软渠颗惯贸粪综墙趋彼届墨碍启逆卸航衣孙龄岭骗休借',
  50. // 使用背景图片
  51. 'useImgBg' => false,
  52. // 验证码字体大小(px)
  53. 'fontSize' => 25,
  54. // 是否画混淆曲线
  55. 'useCurve' => true,
  56. // 是否添加杂点
  57. 'useNoise' => true,
  58. // 验证码图片高度
  59. 'imageH' => 0,
  60. // 验证码图片宽度
  61. 'imageW' => 0,
  62. // 验证码位数
  63. 'length' => 4,
  64. // 验证码字体,不设置随机获取
  65. 'fontTtf' => '',
  66. // 背景颜色
  67. 'bg' => [243, 251, 254],
  68. // 验证成功后是否重置
  69. 'reset' => true,
  70. ];
  71. /**
  72. * 验证码图片实例
  73. * @var GdImage|resource|null
  74. */
  75. private $image = null;
  76. /**
  77. * 验证码字体颜色
  78. * @var bool|int|null
  79. */
  80. private bool|int|null $color = null;
  81. /**
  82. * 架构方法 设置参数
  83. * @param array $config 配置参数
  84. * @throws Throwable
  85. */
  86. public function __construct(array $config = [])
  87. {
  88. $this->config = array_merge($this->config, $config);
  89. // 清理过期的验证码
  90. Db::name('captcha')
  91. ->where('expire_time', '<', time())
  92. ->delete();
  93. }
  94. /**
  95. * 使用 $this->name 获取配置
  96. * @param string $name 配置名称
  97. * @return mixed 配置值
  98. */
  99. public function __get(string $name): mixed
  100. {
  101. return $this->config[$name];
  102. }
  103. /**
  104. * 设置验证码配置
  105. * @param string $name 配置名称
  106. * @param mixed $value 配置值
  107. * @return void
  108. */
  109. public function __set(string $name, mixed $value): void
  110. {
  111. if (isset($this->config[$name])) {
  112. $this->config[$name] = $value;
  113. }
  114. }
  115. /**
  116. * 检查配置
  117. * @param string $name 配置名称
  118. * @return bool
  119. */
  120. public function __isset(string $name): bool
  121. {
  122. return isset($this->config[$name]);
  123. }
  124. /**
  125. * 验证验证码是否正确
  126. * @param string $code 用户验证码
  127. * @param string $id 验证码标识
  128. * @return bool 用户验证码是否正确
  129. * @throws Throwable
  130. */
  131. public function check(string $code, string $id): bool
  132. {
  133. $key = $this->authCode($this->seKey, $id);
  134. $seCode = Db::name('captcha')->where('key', $key)->find();
  135. // 验证码为空
  136. if (empty($code) || empty($seCode)) {
  137. return false;
  138. }
  139. // 验证码过期
  140. if (time() > $seCode['expire_time']) {
  141. Db::name('captcha')->where('key', $key)->delete();
  142. return false;
  143. }
  144. if ($this->authCode(strtoupper($code), $id) == $seCode['code']) {
  145. $this->reset && Db::name('captcha')->where('key', $key)->delete();
  146. return true;
  147. }
  148. return false;
  149. }
  150. /**
  151. * 创建一个逻辑验证码可供后续验证(非图形)
  152. * @param string $id 验证码标识
  153. * @param string|bool $captcha 验证码,不传递则自动生成
  154. * @return string 生成的验证码,发送出去或做它用...
  155. * @throws Throwable
  156. */
  157. public function create(string $id, string|bool $captcha = false): string
  158. {
  159. $nowTime = time();
  160. $key = $this->authCode($this->seKey, $id);
  161. $captchaTemp = Db::name('captcha')->where('key', $key)->find();
  162. if ($captchaTemp) {
  163. // 重复的为同一标识创建验证码
  164. Db::name('captcha')->where('key', $key)->delete();
  165. }
  166. $captcha = $this->generate($captcha);
  167. $code = $this->authCode($captcha, $id);
  168. Db::name('captcha')
  169. ->insert([
  170. 'key' => $key,
  171. 'code' => $code,
  172. 'captcha' => $captcha,
  173. 'create_time' => date('Y-m-d H:i:s',$nowTime),
  174. 'expire_time' => $nowTime + $this->expire
  175. ]);
  176. return $captcha;
  177. }
  178. /**
  179. * 获取验证码数据
  180. * @param string $id 验证码标识
  181. * @return array
  182. * @throws Throwable
  183. */
  184. public function getCaptchaData(string $id): array
  185. {
  186. $key = $this->authCode($this->seKey, $id);
  187. $seCode = Db::name('captcha')->where('key', $key)->find();
  188. return $seCode ?: [];
  189. }
  190. /**
  191. * 输出图形验证码并把验证码的值保存的Mysql中
  192. * @param string $id 要生成验证码的标识
  193. * @return Response
  194. * @throws Throwable
  195. */
  196. public function entry(string $id): Response
  197. {
  198. $nowTime = time();
  199. // 图片宽(px)
  200. $this->imageW || $this->imageW = $this->length * $this->fontSize * 1.5 + $this->length * $this->fontSize / 2;
  201. // 图片高(px)
  202. $this->imageH || $this->imageH = $this->fontSize * 2.5;
  203. // 建立一幅 $this->imageW x $this->imageH 的图像
  204. $this->image = imagecreate($this->imageW, $this->imageH);
  205. // 设置背景
  206. imagecolorallocate($this->image, $this->bg[0], $this->bg[1], $this->bg[2]);
  207. // 验证码字体随机颜色
  208. $this->color = imagecolorallocate($this->image, mt_rand(1, 150), mt_rand(1, 150), mt_rand(1, 150));
  209. // 验证码使用随机字体
  210. $ttfPath = public_path() . 'static' . DIRECTORY_SEPARATOR . 'fonts' . DIRECTORY_SEPARATOR . ($this->useZh ? 'zhttfs' : 'ttfs') . DIRECTORY_SEPARATOR;
  211. if (empty($this->fontTtf)) {
  212. $dir = dir($ttfPath);
  213. $ttfFiles = [];
  214. while (false !== ($file = $dir->read())) {
  215. if ('.' != $file[0] && str_ends_with($file, '.ttf')) {
  216. $ttfFiles[] = $file;
  217. }
  218. }
  219. $dir->close();
  220. $this->fontTtf = $ttfFiles[array_rand($ttfFiles)];
  221. }
  222. $this->fontTtf = $ttfPath . $this->fontTtf;
  223. if ($this->useImgBg) {
  224. $this->background();
  225. }
  226. if ($this->useNoise) {
  227. // 绘杂点
  228. $this->writeNoise();
  229. }
  230. if ($this->useCurve) {
  231. // 绘干扰线
  232. $this->writeCurve();
  233. }
  234. $key = $this->authCode($this->seKey, $id);
  235. $captcha = Db::name('captcha')->where('key', $key)->find();
  236. // 绘验证码
  237. if ($captcha && $nowTime <= $captcha['expire_time']) {
  238. $this->writeText($captcha['captcha']);
  239. } else {
  240. $captcha = $this->writeText();
  241. // 保存验证码
  242. $code = $this->authCode(strtoupper(implode('', $captcha)), $id);
  243. Db::name('captcha')->insert([
  244. 'key' => $key,
  245. 'code' => $code,
  246. 'captcha' => strtoupper(implode('', $captcha)),
  247. 'create_time' => date('Y-m-d H:i:s',$nowTime),
  248. 'expire_time' => $nowTime + $this->expire
  249. ]);
  250. }
  251. ob_start();
  252. // 输出图像
  253. imagepng($this->image);
  254. $content = ob_get_clean();
  255. imagedestroy($this->image);
  256. return response($content, 200, ['Content-Length' => strlen($content)])->contentType('image/png');
  257. }
  258. /**
  259. * 绘验证码
  260. * @param string $captcha 验证码
  261. * @return array|string 验证码
  262. */
  263. private function writeText(string $captcha = ''): array|string
  264. {
  265. $code = []; // 验证码
  266. $codeNX = 0; // 验证码第N个字符的左边距
  267. if ($this->useZh) {
  268. // 中文验证码
  269. for ($i = 0; $i < $this->length; $i++) {
  270. $code[$i] = $captcha ? $captcha[$i] : iconv_substr($this->zhSet, floor(mt_rand(0, mb_strlen($this->zhSet, 'utf-8') - 1)), 1, 'utf-8');
  271. imagettftext($this->image, $this->fontSize, mt_rand(-40, 40), $this->fontSize * ($i + 1) * 1.5, $this->fontSize + mt_rand(10, 20), (int)$this->color, $this->fontTtf, $code[$i]);
  272. }
  273. } else {
  274. for ($i = 0; $i < $this->length; $i++) {
  275. $code[$i] = $captcha ? $captcha[$i] : $this->codeSet[mt_rand(0, strlen($this->codeSet) - 1)];
  276. $codeNX += mt_rand((int)($this->fontSize * 1.2), (int)($this->fontSize * 1.6));
  277. imagettftext($this->image, $this->fontSize, mt_rand(-40, 40), $codeNX, (int)($this->fontSize * 1.6), (int)$this->color, $this->fontTtf, $code[$i]);
  278. }
  279. }
  280. return $captcha ?: $code;
  281. }
  282. /**
  283. * 画一条由两条连在一起构成的随机正弦函数曲线作干扰线(你可以改成更帅的曲线函数)
  284. * 正弦型函数解析式:y=Asin(ωx+φ)+b
  285. * 各常数值对函数图像的影响:
  286. * A:决定峰值(即纵向拉伸压缩的倍数)
  287. * b:表示波形在Y轴的位置关系或纵向移动距离(上加下减)
  288. * φ:决定波形与X轴位置关系或横向移动距离(左加右减)
  289. * ω:决定周期(最小正周期T=2π/∣ω∣)
  290. */
  291. private function writeCurve(): void
  292. {
  293. $py = 0;
  294. // 曲线前部分
  295. $A = mt_rand(1, $this->imageH / 2); // 振幅
  296. $b = mt_rand(-$this->imageH / 4, $this->imageH / 4); // Y轴方向偏移量
  297. $f = mt_rand(-$this->imageH / 4, $this->imageH / 4); // X轴方向偏移量
  298. $T = mt_rand($this->imageH, $this->imageW * 2); // 周期
  299. $w = (2 * M_PI) / $T;
  300. $px1 = 0; // 曲线横坐标起始位置
  301. $px2 = mt_rand($this->imageW / 2, $this->imageW * 0.8); // 曲线横坐标结束位置
  302. for ($px = $px1; $px <= $px2; $px = $px + 1) {
  303. if (0 != $w) {
  304. $py = $A * sin($w * $px + $f) + $b + $this->imageH / 2; // y = Asin(ωx+φ) + b
  305. $i = (int)($this->fontSize / 5);
  306. while ($i > 0) {
  307. imagesetpixel($this->image, $px + $i, $py + $i, (int)$this->color); // 这里(while)循环画像素点比imagettftext和imagestring用字体大小一次画出(不用这while循环)性能要好很多
  308. $i--;
  309. }
  310. }
  311. }
  312. // 曲线后部分
  313. $A = mt_rand(1, $this->imageH / 2); // 振幅
  314. $f = mt_rand(-$this->imageH / 4, $this->imageH / 4); // X轴方向偏移量
  315. $T = mt_rand($this->imageH, $this->imageW * 2); // 周期
  316. $w = (2 * M_PI) / $T;
  317. $b = $py - $A * sin($w * $px + $f) - $this->imageH / 2;
  318. $px1 = $px2;
  319. $px2 = $this->imageW;
  320. for ($px = $px1; $px <= $px2; $px = $px + 1) {
  321. if (0 != $w) {
  322. $py = $A * sin($w * $px + $f) + $b + $this->imageH / 2; // y = Asin(ωx+φ) + b
  323. $i = (int)($this->fontSize / 5);
  324. while ($i > 0) {
  325. imagesetpixel($this->image, $px + $i, $py + $i, (int)$this->color);
  326. $i--;
  327. }
  328. }
  329. }
  330. }
  331. /**
  332. * 绘杂点,往图片上写不同颜色的字母或数字
  333. */
  334. private function writeNoise(): void
  335. {
  336. $codeSet = '2345678abcdefhijkmnpqrstuvwxyz';
  337. for ($i = 0; $i < 10; $i++) {
  338. //杂点颜色
  339. $noiseColor = imagecolorallocate($this->image, mt_rand(150, 225), mt_rand(150, 225), mt_rand(150, 225));
  340. for ($j = 0; $j < 5; $j++) {
  341. // 绘制
  342. imagestring($this->image, 5, mt_rand(-10, $this->imageW), mt_rand(-10, $this->imageH), $codeSet[mt_rand(0, 29)], $noiseColor);
  343. }
  344. }
  345. }
  346. /**
  347. * 绘制背景图片
  348. *
  349. * 注:如果验证码输出图片比较大,将占用比较多的系统资源
  350. */
  351. private function background(): void
  352. {
  353. $path = Filesystem::fsFit(public_path() . 'static/images/captcha/image/');
  354. $dir = dir($path);
  355. $bgs = [];
  356. while (false !== ($file = $dir->read())) {
  357. if ('.' != $file[0] && str_ends_with($file, '.jpg')) {
  358. $bgs[] = $path . $file;
  359. }
  360. }
  361. $dir->close();
  362. $gb = $bgs[array_rand($bgs)];
  363. list($width, $height) = @getimagesize($gb);
  364. // Resample
  365. $bgImage = @imagecreatefromjpeg($gb);
  366. @imagecopyresampled($this->image, $bgImage, 0, 0, 0, 0, $this->imageW, $this->imageH, $width, $height);
  367. @imagedestroy($bgImage);
  368. }
  369. /**
  370. * 加密验证码
  371. * @param string $str 验证码字符串
  372. * @param string $id 验证码标识
  373. */
  374. private function authCode(string $str, string $id): string
  375. {
  376. $key = substr(md5($this->seKey), 5, 8);
  377. $str = substr(md5($str), 8, 10);
  378. return md5($key . $str . $id);
  379. }
  380. /**
  381. * 生成验证码随机字符
  382. * @param bool|string $captcha
  383. * @return string
  384. */
  385. private function generate(bool|string $captcha = false): string
  386. {
  387. $code = []; // 验证码
  388. if ($this->useZh) {
  389. // 中文验证码
  390. for ($i = 0; $i < $this->length; $i++) {
  391. $code[$i] = $captcha ? $captcha[$i] : iconv_substr($this->zhSet, floor(mt_rand(0, mb_strlen($this->zhSet, 'utf-8') - 1)), 1, 'utf-8');
  392. }
  393. } else {
  394. for ($i = 0; $i < $this->length; $i++) {
  395. $code[$i] = $captcha ? $captcha[$i] : $this->codeSet[mt_rand(0, strlen($this->codeSet) - 1)];
  396. }
  397. }
  398. return $captcha ?: strtoupper(implode('', $code));
  399. }
  400. }