package middleware

import (
	"encoding/json"
	"fmt"
	"log"
	"net/http"

	"git.apinb.com/bsm-sdk/core/cache/redis"
	"git.apinb.com/bsm-sdk/core/crypto/encipher"
	"git.apinb.com/bsm-sdk/core/errcode"
	"git.apinb.com/bsm-sdk/core/types"
	"github.com/gin-gonic/gin"
)

func JwtAuth(redis *redis.RedisClient) gin.HandlerFunc {
	return func(c *gin.Context) {
		// 从请求头中获取 Authorization
		authHeader := c.GetHeader("Authorization")
		if authHeader == "" {
			log.Println("获取token异常:", "Authorization header is required")
			c.JSON(http.StatusUnauthorized, gin.H{"error": "Authorization header is required"})
			c.Abort()
			return
		}
		// 提取Token
		claims, err := encipher.ParseTokenAes(authHeader)
		if err != nil || claims == nil {
			log.Println("提取token异常:", "Token is required")
			c.JSON(http.StatusUnauthorized, gin.H{"error": "Token is required"})
			c.Abort()
			return
		}

		// 从redis 获取token,判断当前redis 是否为空
		tokenKey := fmt.Sprintf("%d-%s-%s", claims.ID, claims.Role, "token")
		redisToken := redis.Client.Get(redis.Ctx, tokenKey)
		if redisToken.Val() == "" {
			log.Println("redis异常", "Token status unauthorized")
			c.JSON(http.StatusUnauthorized, gin.H{"error": "Token status unauthorized"})
			c.Abort()
			return
		}

		// 将解析后的 Token 存储到上下文中
		c.Set("Auth", claims)
		// 如果 Token 有效,继续处理请求
		c.Next()
	}
}

// 获取上下文用户登录信息
func ParseAuth(c *gin.Context) (*types.JwtClaims, error) {
	claims, ok := c.Get("Auth")
	if !ok {
		log.Printf("获取登录信息异常: %v", errcode.ErrJWTAuthNotFound)
		return nil, errcode.ErrJWTAuthNotFound
	}

	json_claims, err := json.Marshal(claims)
	if err != nil {
		log.Printf("解析json异常: %v", err)
		return nil, errcode.ErrJsonMarshal
	}

	var auth *types.JwtClaims
	if err := json.Unmarshal(json_claims, &auth); err != nil {
		log.Printf("解析json异常: %v", err)
		return nil, errcode.ErrJsonUnmarshal
	}

	return auth, nil
}