login.go 8.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329
  1. package admin
  2. import (
  3. "fmt"
  4. "github.com/gin-gonic/gin"
  5. "github.com/lejianwen/rustdesk-api/global"
  6. "github.com/lejianwen/rustdesk-api/http/controller/api"
  7. "github.com/lejianwen/rustdesk-api/http/request/admin"
  8. apiReq "github.com/lejianwen/rustdesk-api/http/request/api"
  9. "github.com/lejianwen/rustdesk-api/http/response"
  10. adResp "github.com/lejianwen/rustdesk-api/http/response/admin"
  11. "github.com/lejianwen/rustdesk-api/model"
  12. "github.com/lejianwen/rustdesk-api/service"
  13. "github.com/mojocn/base64Captcha"
  14. "sync"
  15. "time"
  16. )
  17. type Login struct {
  18. }
  19. // Captcha 验证码结构
  20. type Captcha struct {
  21. Id string `json:"id"` // 验证码 ID
  22. B64 string `json:"b64"` // base64 验证码
  23. Code string `json:"-"` // 验证码内容
  24. ExpiresAt time.Time `json:"-"` // 过期时间
  25. }
  26. type LoginLimiter struct {
  27. mu sync.RWMutex
  28. failCount map[string]int // 记录每个 IP 的失败次数
  29. timestamp map[string]time.Time // 记录每个 IP 的最后失败时间
  30. captchas map[string]Captcha // 每个 IP 的验证码
  31. threshold int // 失败阈值
  32. expiry time.Duration // 失败记录过期时间
  33. }
  34. func NewLoginLimiter(threshold int, expiry time.Duration) *LoginLimiter {
  35. return &LoginLimiter{
  36. failCount: make(map[string]int),
  37. timestamp: make(map[string]time.Time),
  38. captchas: make(map[string]Captcha),
  39. threshold: threshold,
  40. expiry: expiry,
  41. }
  42. }
  43. // RecordFailure 记录登录失败
  44. func (l *LoginLimiter) RecordFailure(ip string) {
  45. l.mu.Lock()
  46. defer l.mu.Unlock()
  47. // 如果该 IP 的记录已经过期,重置计数
  48. if lastTime, exists := l.timestamp[ip]; exists && time.Since(lastTime) > l.expiry {
  49. l.failCount[ip] = 0
  50. }
  51. // 更新失败次数和时间戳
  52. l.failCount[ip]++
  53. l.timestamp[ip] = time.Now()
  54. }
  55. // NeedsCaptcha 检查是否需要验证码
  56. func (l *LoginLimiter) NeedsCaptcha(ip string) bool {
  57. l.mu.RLock()
  58. defer l.mu.RUnlock()
  59. // 检查记录是否存在且未过期
  60. if lastTime, exists := l.timestamp[ip]; exists && time.Since(lastTime) <= l.expiry {
  61. return l.failCount[ip] >= l.threshold
  62. }
  63. return false
  64. }
  65. // GenerateCaptcha 为指定 IP 生成验证码
  66. func (l *LoginLimiter) GenerateCaptcha(ip string) Captcha {
  67. l.mu.Lock()
  68. defer l.mu.Unlock()
  69. capd := base64Captcha.NewDriverString(50, 150, 5, 10, 4, "1234567890abcdefghijklmnopqrstuvwxyz", nil, nil, nil)
  70. b64cap := base64Captcha.NewCaptcha(capd, base64Captcha.DefaultMemStore)
  71. id, b64s, answer, err := b64cap.Generate()
  72. if err != nil {
  73. global.Logger.Error("Generate captcha failed: " + err.Error())
  74. return Captcha{}
  75. }
  76. // 保存验证码到对应 IP
  77. l.captchas[ip] = Captcha{
  78. Id: id,
  79. B64: b64s,
  80. Code: answer,
  81. ExpiresAt: time.Now().Add(5 * time.Minute),
  82. }
  83. return l.captchas[ip]
  84. }
  85. // VerifyCaptcha 验证指定 IP 的验证码
  86. func (l *LoginLimiter) VerifyCaptcha(ip, code string) bool {
  87. l.mu.RLock()
  88. defer l.mu.RUnlock()
  89. // 检查验证码是否存在且未过期
  90. if captcha, exists := l.captchas[ip]; exists && time.Now().Before(captcha.ExpiresAt) {
  91. return captcha.Code == code
  92. }
  93. return false
  94. }
  95. // RemoveCaptcha 移除指定 IP 的验证码
  96. func (l *LoginLimiter) RemoveCaptcha(ip string) {
  97. l.mu.Lock()
  98. defer l.mu.Unlock()
  99. delete(l.captchas, ip)
  100. }
  101. // CleanupExpired 清理过期的记录
  102. func (l *LoginLimiter) CleanupExpired() {
  103. l.mu.Lock()
  104. defer l.mu.Unlock()
  105. now := time.Now()
  106. for ip, lastTime := range l.timestamp {
  107. if now.Sub(lastTime) > l.expiry {
  108. delete(l.failCount, ip)
  109. delete(l.timestamp, ip)
  110. delete(l.captchas, ip)
  111. }
  112. }
  113. }
  114. func (l *LoginLimiter) RemoveRecord(ip string) {
  115. l.mu.Lock()
  116. defer l.mu.Unlock()
  117. delete(l.failCount, ip)
  118. delete(l.timestamp, ip)
  119. delete(l.captchas, ip)
  120. }
  121. var loginLimiter = NewLoginLimiter(3, 5*time.Minute)
  122. // Login 登录
  123. // @Tags 登录
  124. // @Summary 登录
  125. // @Description 登录
  126. // @Accept json
  127. // @Produce json
  128. // @Param body body admin.Login true "登录信息"
  129. // @Success 200 {object} response.Response{data=adResp.LoginPayload}
  130. // @Failure 500 {object} response.Response
  131. // @Router /admin/login [post]
  132. // @Security token
  133. func (ct *Login) Login(c *gin.Context) {
  134. f := &admin.Login{}
  135. err := c.ShouldBindJSON(f)
  136. clientIp := c.ClientIP()
  137. if err != nil {
  138. global.Logger.Warn(fmt.Sprintf("Login Fail: %s %s %s", "ParamsError", c.RemoteIP(), clientIp))
  139. response.Fail(c, 101, response.TranslateMsg(c, "ParamsError")+err.Error())
  140. return
  141. }
  142. errList := global.Validator.ValidStruct(c, f)
  143. if len(errList) > 0 {
  144. global.Logger.Warn(fmt.Sprintf("Login Fail: %s %s %s", "ParamsError", c.RemoteIP(), clientIp))
  145. response.Fail(c, 101, errList[0])
  146. return
  147. }
  148. // 检查是否需要验证码
  149. if loginLimiter.NeedsCaptcha(clientIp) {
  150. if f.Captcha == "" || !loginLimiter.VerifyCaptcha(clientIp, f.Captcha) {
  151. response.Fail(c, 101, response.TranslateMsg(c, "CaptchaError"))
  152. return
  153. }
  154. }
  155. u := service.AllService.UserService.InfoByUsernamePassword(f.Username, f.Password)
  156. if u.Id == 0 {
  157. global.Logger.Warn(fmt.Sprintf("Login Fail: %s %s %s", "UsernameOrPasswordError", c.RemoteIP(), clientIp))
  158. loginLimiter.RecordFailure(clientIp)
  159. if loginLimiter.NeedsCaptcha(clientIp) {
  160. loginLimiter.RemoveCaptcha(clientIp)
  161. }
  162. response.Fail(c, 101, response.TranslateMsg(c, "UsernameOrPasswordError"))
  163. return
  164. }
  165. if !service.AllService.UserService.CheckUserEnable(u) {
  166. if loginLimiter.NeedsCaptcha(clientIp) {
  167. loginLimiter.RemoveCaptcha(clientIp)
  168. }
  169. response.Fail(c, 101, response.TranslateMsg(c, "UserDisabled"))
  170. return
  171. }
  172. ut := service.AllService.UserService.Login(u, &model.LoginLog{
  173. UserId: u.Id,
  174. Client: model.LoginLogClientWebAdmin,
  175. Uuid: "", //must be empty
  176. Ip: clientIp,
  177. Type: model.LoginLogTypeAccount,
  178. Platform: f.Platform,
  179. })
  180. // 成功后清除记录
  181. loginLimiter.RemoveRecord(clientIp)
  182. // 清理过期记录
  183. go loginLimiter.CleanupExpired()
  184. responseLoginSuccess(c, u, ut.Token)
  185. }
  186. func (ct *Login) Captcha(c *gin.Context) {
  187. clientIp := c.ClientIP()
  188. if !loginLimiter.NeedsCaptcha(clientIp) {
  189. response.Fail(c, 101, response.TranslateMsg(c, "NoCaptchaRequired"))
  190. return
  191. }
  192. captcha := loginLimiter.GenerateCaptcha(clientIp)
  193. response.Success(c, gin.H{
  194. "captcha": captcha,
  195. })
  196. }
  197. // Logout 登出
  198. // @Tags 登录
  199. // @Summary 登出
  200. // @Description 登出
  201. // @Accept json
  202. // @Produce json
  203. // @Success 200 {object} response.Response
  204. // @Failure 500 {object} response.Response
  205. // @Router /admin/logout [post]
  206. func (ct *Login) Logout(c *gin.Context) {
  207. u := service.AllService.UserService.CurUser(c)
  208. token, ok := c.Get("token")
  209. if ok {
  210. service.AllService.UserService.Logout(u, token.(string))
  211. }
  212. response.Success(c, nil)
  213. }
  214. // LoginOptions
  215. // @Tags 登录
  216. // @Summary 登录选项
  217. // @Description 登录选项
  218. // @Accept json
  219. // @Produce json
  220. // @Success 200 {object} []string
  221. // @Failure 500 {object} response.ErrorResponse
  222. // @Router /admin/login-options [post]
  223. func (ct *Login) LoginOptions(c *gin.Context) {
  224. ip := c.ClientIP()
  225. ops := service.AllService.OauthService.GetOauthProviders()
  226. response.Success(c, gin.H{
  227. "ops": ops,
  228. "register": global.Config.App.Register,
  229. "need_captcha": loginLimiter.NeedsCaptcha(ip),
  230. })
  231. }
  232. // OidcAuth
  233. // @Tags Oauth
  234. // @Summary OidcAuth
  235. // @Description OidcAuth
  236. // @Accept json
  237. // @Produce json
  238. // @Router /admin/oidc/auth [post]
  239. func (ct *Login) OidcAuth(c *gin.Context) {
  240. // o := &api.Oauth{}
  241. // o.OidcAuth(c)
  242. f := &apiReq.OidcAuthRequest{}
  243. err := c.ShouldBindJSON(f)
  244. if err != nil {
  245. response.Fail(c, 101, response.TranslateMsg(c, "ParamsError")+err.Error())
  246. return
  247. }
  248. err, code, url := service.AllService.OauthService.BeginAuth(f.Op)
  249. if err != nil {
  250. response.Error(c, response.TranslateMsg(c, err.Error()))
  251. return
  252. }
  253. service.AllService.OauthService.SetOauthCache(code, &service.OauthCacheItem{
  254. Action: service.OauthActionTypeLogin,
  255. Op: f.Op,
  256. Id: f.Id,
  257. DeviceType: "webadmin",
  258. // DeviceOs: ct.Platform(c),
  259. DeviceOs: f.DeviceInfo.Os,
  260. Uuid: f.Uuid,
  261. }, 5*60)
  262. response.Success(c, gin.H{
  263. "code": code,
  264. "url": url,
  265. })
  266. }
  267. // OidcAuthQuery
  268. // @Tags Oauth
  269. // @Summary OidcAuthQuery
  270. // @Description OidcAuthQuery
  271. // @Accept json
  272. // @Produce json
  273. // @Success 200 {object} response.Response{data=adResp.LoginPayload}
  274. // @Failure 500 {object} response.Response
  275. // @Router /admin/oidc/auth-query [get]
  276. func (ct *Login) OidcAuthQuery(c *gin.Context) {
  277. o := &api.Oauth{}
  278. u, ut := o.OidcAuthQueryPre(c)
  279. if ut == nil {
  280. return
  281. }
  282. responseLoginSuccess(c, u, ut.Token)
  283. }
  284. func responseLoginSuccess(c *gin.Context, u *model.User, token string) {
  285. lp := &adResp.LoginPayload{}
  286. lp.FromUser(u)
  287. lp.Token = token
  288. lp.RouteNames = service.AllService.UserService.RouteNames(u)
  289. response.Success(c, lp)
  290. }