login.go 8.3 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324
  1. package admin
  2. import (
  3. "Gwen/global"
  4. "Gwen/http/controller/api"
  5. "Gwen/http/request/admin"
  6. apiReq "Gwen/http/request/api"
  7. "Gwen/http/response"
  8. adResp "Gwen/http/response/admin"
  9. "Gwen/model"
  10. "Gwen/service"
  11. "fmt"
  12. "github.com/gin-gonic/gin"
  13. "github.com/mojocn/base64Captcha"
  14. "sync"
  15. "time"
  16. )
  17. type Login struct {
  18. }
  19. // Captcha 验证码结构
  20. type Captcha struct {
  21. Id string `json:"id"` // 验证码 ID
  22. B64 string `json:"b64"` // base64 验证码
  23. Code string `json:"-"` // 验证码内容
  24. ExpiresAt time.Time `json:"-"` // 过期时间
  25. }
  26. type LoginLimiter struct {
  27. mu sync.RWMutex
  28. failCount map[string]int // 记录每个 IP 的失败次数
  29. timestamp map[string]time.Time // 记录每个 IP 的最后失败时间
  30. captchas map[string]Captcha // 每个 IP 的验证码
  31. threshold int // 失败阈值
  32. expiry time.Duration // 失败记录过期时间
  33. }
  34. func NewLoginLimiter(threshold int, expiry time.Duration) *LoginLimiter {
  35. return &LoginLimiter{
  36. failCount: make(map[string]int),
  37. timestamp: make(map[string]time.Time),
  38. captchas: make(map[string]Captcha),
  39. threshold: threshold,
  40. expiry: expiry,
  41. }
  42. }
  43. // RecordFailure 记录登录失败
  44. func (l *LoginLimiter) RecordFailure(ip string) {
  45. l.mu.Lock()
  46. defer l.mu.Unlock()
  47. // 如果该 IP 的记录已经过期,重置计数
  48. if lastTime, exists := l.timestamp[ip]; exists && time.Since(lastTime) > l.expiry {
  49. l.failCount[ip] = 0
  50. }
  51. // 更新失败次数和时间戳
  52. l.failCount[ip]++
  53. l.timestamp[ip] = time.Now()
  54. }
  55. // NeedsCaptcha 检查是否需要验证码
  56. func (l *LoginLimiter) NeedsCaptcha(ip string) bool {
  57. l.mu.RLock()
  58. defer l.mu.RUnlock()
  59. // 检查记录是否存在且未过期
  60. if lastTime, exists := l.timestamp[ip]; exists && time.Since(lastTime) <= l.expiry {
  61. return l.failCount[ip] >= l.threshold
  62. }
  63. return false
  64. }
  65. // GenerateCaptcha 为指定 IP 生成验证码
  66. func (l *LoginLimiter) GenerateCaptcha(ip string) Captcha {
  67. l.mu.Lock()
  68. defer l.mu.Unlock()
  69. capd := base64Captcha.NewDriverString(50, 150, 5, 10, 4, "1234567890abcdefghijklmnopqrstuvwxyz", nil, nil, nil)
  70. b64cap := base64Captcha.NewCaptcha(capd, base64Captcha.DefaultMemStore)
  71. id, b64s, answer, err := b64cap.Generate()
  72. if err != nil {
  73. global.Logger.Error("Generate captcha failed: " + err.Error())
  74. return Captcha{}
  75. }
  76. // 保存验证码到对应 IP
  77. l.captchas[ip] = Captcha{
  78. Id: id,
  79. B64: b64s,
  80. Code: answer,
  81. ExpiresAt: time.Now().Add(5 * time.Minute),
  82. }
  83. return l.captchas[ip]
  84. }
  85. // VerifyCaptcha 验证指定 IP 的验证码
  86. func (l *LoginLimiter) VerifyCaptcha(ip, code string) bool {
  87. l.mu.RLock()
  88. defer l.mu.RUnlock()
  89. // 检查验证码是否存在且未过期
  90. if captcha, exists := l.captchas[ip]; exists && time.Now().Before(captcha.ExpiresAt) {
  91. return captcha.Code == code
  92. }
  93. return false
  94. }
  95. // RemoveCaptcha 移除指定 IP 的验证码
  96. func (l *LoginLimiter) RemoveCaptcha(ip string) {
  97. l.mu.Lock()
  98. defer l.mu.Unlock()
  99. delete(l.captchas, ip)
  100. }
  101. // CleanupExpired 清理过期的记录
  102. func (l *LoginLimiter) CleanupExpired() {
  103. l.mu.Lock()
  104. defer l.mu.Unlock()
  105. now := time.Now()
  106. for ip, lastTime := range l.timestamp {
  107. if now.Sub(lastTime) > l.expiry {
  108. delete(l.failCount, ip)
  109. delete(l.timestamp, ip)
  110. delete(l.captchas, ip)
  111. }
  112. }
  113. }
  114. func (l *LoginLimiter) RemoveRecord(ip string) {
  115. l.mu.Lock()
  116. defer l.mu.Unlock()
  117. delete(l.failCount, ip)
  118. delete(l.timestamp, ip)
  119. delete(l.captchas, ip)
  120. }
  121. var loginLimiter = NewLoginLimiter(3, 5*time.Minute)
  122. // Login 登录
  123. // @Tags 登录
  124. // @Summary 登录
  125. // @Description 登录
  126. // @Accept json
  127. // @Produce json
  128. // @Param body body admin.Login true "登录信息"
  129. // @Success 200 {object} response.Response{data=adResp.LoginPayload}
  130. // @Failure 500 {object} response.Response
  131. // @Router /admin/login [post]
  132. // @Security token
  133. func (ct *Login) Login(c *gin.Context) {
  134. f := &admin.Login{}
  135. err := c.ShouldBindJSON(f)
  136. clientIp := c.ClientIP()
  137. if err != nil {
  138. global.Logger.Warn(fmt.Sprintf("Login Fail: %s %s %s", "ParamsError", c.RemoteIP(), clientIp))
  139. response.Fail(c, 101, response.TranslateMsg(c, "ParamsError")+err.Error())
  140. return
  141. }
  142. errList := global.Validator.ValidStruct(c, f)
  143. if len(errList) > 0 {
  144. global.Logger.Warn(fmt.Sprintf("Login Fail: %s %s %s", "ParamsError", c.RemoteIP(), clientIp))
  145. response.Fail(c, 101, errList[0])
  146. return
  147. }
  148. // 检查是否需要验证码
  149. if loginLimiter.NeedsCaptcha(clientIp) {
  150. if f.Captcha == "" || !loginLimiter.VerifyCaptcha(clientIp, f.Captcha) {
  151. response.Fail(c, 101, response.TranslateMsg(c, "CaptchaError"))
  152. return
  153. }
  154. }
  155. u := service.AllService.UserService.InfoByUsernamePassword(f.Username, f.Password)
  156. if u.Id == 0 {
  157. global.Logger.Warn(fmt.Sprintf("Login Fail: %s %s %s", "UsernameOrPasswordError", c.RemoteIP(), clientIp))
  158. loginLimiter.RecordFailure(clientIp)
  159. if loginLimiter.NeedsCaptcha(clientIp) {
  160. // 移除原验证码,重新生成
  161. loginLimiter.RemoveCaptcha(clientIp)
  162. response.Fail(c, 110, response.TranslateMsg(c, "UsernameOrPasswordError"))
  163. return
  164. }
  165. response.Fail(c, 101, response.TranslateMsg(c, "UsernameOrPasswordError"))
  166. return
  167. }
  168. ut := service.AllService.UserService.Login(u, &model.LoginLog{
  169. UserId: u.Id,
  170. Client: model.LoginLogClientWebAdmin,
  171. Uuid: "", //must be empty
  172. Ip: clientIp,
  173. Type: model.LoginLogTypeAccount,
  174. Platform: f.Platform,
  175. })
  176. // 成功后清除记录
  177. loginLimiter.RemoveRecord(clientIp)
  178. // 清理过期记录
  179. go loginLimiter.CleanupExpired()
  180. responseLoginSuccess(c, u, ut.Token)
  181. }
  182. func (ct *Login) Captcha(c *gin.Context) {
  183. clientIp := c.ClientIP()
  184. if !loginLimiter.NeedsCaptcha(clientIp) {
  185. response.Fail(c, 101, response.TranslateMsg(c, "NoCaptchaRequired"))
  186. return
  187. }
  188. captcha := loginLimiter.GenerateCaptcha(clientIp)
  189. response.Success(c, gin.H{
  190. "captcha": captcha,
  191. })
  192. }
  193. // Logout 登出
  194. // @Tags 登录
  195. // @Summary 登出
  196. // @Description 登出
  197. // @Accept json
  198. // @Produce json
  199. // @Success 200 {object} response.Response
  200. // @Failure 500 {object} response.Response
  201. // @Router /admin/logout [post]
  202. func (ct *Login) Logout(c *gin.Context) {
  203. u := service.AllService.UserService.CurUser(c)
  204. token, ok := c.Get("token")
  205. if ok {
  206. service.AllService.UserService.Logout(u, token.(string))
  207. }
  208. response.Success(c, nil)
  209. }
  210. // LoginOptions
  211. // @Tags 登录
  212. // @Summary 登录选项
  213. // @Description 登录选项
  214. // @Accept json
  215. // @Produce json
  216. // @Success 200 {object} []string
  217. // @Failure 500 {object} response.ErrorResponse
  218. // @Router /admin/login-options [post]
  219. func (ct *Login) LoginOptions(c *gin.Context) {
  220. ip := c.ClientIP()
  221. ops := service.AllService.OauthService.GetOauthProviders()
  222. response.Success(c, gin.H{
  223. "ops": ops,
  224. "register": global.Config.App.Register,
  225. "need_captcha": loginLimiter.NeedsCaptcha(ip),
  226. })
  227. }
  228. // OidcAuth
  229. // @Tags Oauth
  230. // @Summary OidcAuth
  231. // @Description OidcAuth
  232. // @Accept json
  233. // @Produce json
  234. // @Router /admin/oidc/auth [post]
  235. func (ct *Login) OidcAuth(c *gin.Context) {
  236. // o := &api.Oauth{}
  237. // o.OidcAuth(c)
  238. f := &apiReq.OidcAuthRequest{}
  239. err := c.ShouldBindJSON(f)
  240. if err != nil {
  241. response.Fail(c, 101, response.TranslateMsg(c, "ParamsError")+err.Error())
  242. return
  243. }
  244. err, code, url := service.AllService.OauthService.BeginAuth(f.Op)
  245. if err != nil {
  246. response.Error(c, response.TranslateMsg(c, err.Error()))
  247. return
  248. }
  249. service.AllService.OauthService.SetOauthCache(code, &service.OauthCacheItem{
  250. Action: service.OauthActionTypeLogin,
  251. Op: f.Op,
  252. Id: f.Id,
  253. DeviceType: "webadmin",
  254. // DeviceOs: ct.Platform(c),
  255. DeviceOs: f.DeviceInfo.Os,
  256. Uuid: f.Uuid,
  257. }, 5*60)
  258. response.Success(c, gin.H{
  259. "code": code,
  260. "url": url,
  261. })
  262. }
  263. // OidcAuthQuery
  264. // @Tags Oauth
  265. // @Summary OidcAuthQuery
  266. // @Description OidcAuthQuery
  267. // @Accept json
  268. // @Produce json
  269. // @Success 200 {object} response.Response{data=adResp.LoginPayload}
  270. // @Failure 500 {object} response.Response
  271. // @Router /admin/oidc/auth-query [get]
  272. func (ct *Login) OidcAuthQuery(c *gin.Context) {
  273. o := &api.Oauth{}
  274. u, ut := o.OidcAuthQueryPre(c)
  275. if ut == nil {
  276. return
  277. }
  278. responseLoginSuccess(c, u, ut.Token)
  279. }
  280. func responseLoginSuccess(c *gin.Context, u *model.User, token string) {
  281. lp := &adResp.LoginPayload{}
  282. lp.FromUser(u)
  283. lp.Token = token
  284. lp.RouteNames = service.AllService.UserService.RouteNames(u)
  285. response.Success(c, lp)
  286. }