user.go 14 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489
  1. package service
  2. import (
  3. "Gwen/global"
  4. "Gwen/model"
  5. "Gwen/utils"
  6. "errors"
  7. "github.com/gin-gonic/gin"
  8. "gorm.io/gorm"
  9. "math/rand"
  10. "strconv"
  11. "strings"
  12. "time"
  13. )
  14. type UserService struct {
  15. }
  16. // InfoById 根据用户id取用户信息
  17. func (us *UserService) InfoById(id uint) *model.User {
  18. u := &model.User{}
  19. global.DB.Where("id = ?", id).First(u)
  20. return u
  21. }
  22. // InfoByUsername 根据用户名取用户信息
  23. func (us *UserService) InfoByUsername(un string) *model.User {
  24. u := &model.User{}
  25. global.DB.Where("username = ?", un).First(u)
  26. return u
  27. }
  28. // InfoByEmail 根据邮箱取用户信息
  29. func (us *UserService) InfoByEmail(email string) *model.User {
  30. u := &model.User{}
  31. global.DB.Where("email = ?", email).First(u)
  32. return u
  33. }
  34. // InfoByOpenid 根据openid取用户信息
  35. func (us *UserService) InfoByOpenid(openid string) *model.User {
  36. u := &model.User{}
  37. global.DB.Where("openid = ?", openid).First(u)
  38. return u
  39. }
  40. // InfoByUsernamePassword 根据用户名密码取用户信息
  41. func (us *UserService) InfoByUsernamePassword(username, password string) *model.User {
  42. if global.Config.Ldap.Enable {
  43. u, err := AllService.LdapService.Authenticate(username, password)
  44. if err == nil {
  45. return u
  46. }
  47. global.Logger.Error("LDAP authentication failed, %v", err)
  48. global.Logger.Warn("Fallback to local database")
  49. }
  50. u := &model.User{}
  51. global.DB.Where("username = ? and password = ?", username, us.EncryptPassword(password)).First(u)
  52. return u
  53. }
  54. // InfoByAccesstoken 根据accesstoken取用户信息
  55. func (us *UserService) InfoByAccessToken(token string) (*model.User, *model.UserToken) {
  56. u := &model.User{}
  57. ut := &model.UserToken{}
  58. global.DB.Where("token = ?", token).First(ut)
  59. if ut.Id == 0 {
  60. return u, ut
  61. }
  62. if ut.ExpiredAt < time.Now().Unix() {
  63. return u, ut
  64. }
  65. global.DB.Where("id = ?", ut.UserId).First(u)
  66. return u, ut
  67. }
  68. // GenerateToken 生成token
  69. func (us *UserService) GenerateToken(u *model.User) string {
  70. if len(global.Jwt.Key) > 0 {
  71. return global.Jwt.GenerateToken(u.Id)
  72. }
  73. return utils.Md5(u.Username + time.Now().String())
  74. }
  75. // Login 登录
  76. func (us *UserService) Login(u *model.User, llog *model.LoginLog) *model.UserToken {
  77. token := us.GenerateToken(u)
  78. ut := &model.UserToken{
  79. UserId: u.Id,
  80. Token: token,
  81. DeviceUuid: llog.Uuid,
  82. DeviceId: llog.DeviceId,
  83. ExpiredAt: time.Now().Add(time.Second * time.Duration(global.Config.App.TokenExpire)).Unix(),
  84. }
  85. global.DB.Create(ut)
  86. llog.UserTokenId = ut.UserId
  87. global.DB.Create(llog)
  88. if llog.Uuid != "" {
  89. AllService.PeerService.UuidBindUserId(llog.DeviceId, llog.Uuid, u.Id)
  90. }
  91. return ut
  92. }
  93. // CurUser 获取当前用户
  94. func (us *UserService) CurUser(c *gin.Context) *model.User {
  95. user, _ := c.Get("curUser")
  96. u, ok := user.(*model.User)
  97. if !ok {
  98. return nil
  99. }
  100. return u
  101. }
  102. func (us *UserService) List(page, pageSize uint, where func(tx *gorm.DB)) (res *model.UserList) {
  103. res = &model.UserList{}
  104. res.Page = int64(page)
  105. res.PageSize = int64(pageSize)
  106. tx := global.DB.Model(&model.User{})
  107. if where != nil {
  108. where(tx)
  109. }
  110. tx.Count(&res.Total)
  111. tx.Scopes(Paginate(page, pageSize))
  112. tx.Find(&res.Users)
  113. return
  114. }
  115. func (us *UserService) ListByIds(ids []uint) (res []*model.User) {
  116. global.DB.Where("id in ?", ids).Find(&res)
  117. return res
  118. }
  119. // ListByGroupId 根据组id取用户列表
  120. func (us *UserService) ListByGroupId(groupId, page, pageSize uint) (res *model.UserList) {
  121. res = us.List(page, pageSize, func(tx *gorm.DB) {
  122. tx.Where("group_id = ?", groupId)
  123. })
  124. return
  125. }
  126. // ListIdsByGroupId 根据组id取用户id列表
  127. func (us *UserService) ListIdsByGroupId(groupId uint) (ids []uint) {
  128. global.DB.Model(&model.User{}).Where("group_id = ?", groupId).Pluck("id", &ids)
  129. return ids
  130. }
  131. // ListIdAndNameByGroupId 根据组id取用户id和用户名列表
  132. func (us *UserService) ListIdAndNameByGroupId(groupId uint) (res []*model.User) {
  133. global.DB.Model(&model.User{}).Where("group_id = ?", groupId).Select("id, username").Find(&res)
  134. return res
  135. }
  136. // EncryptPassword 加密密码
  137. func (us *UserService) EncryptPassword(password string) string {
  138. return utils.Md5(password + "rustdesk-api")
  139. }
  140. // CheckUserEnable 判断用户是否禁用
  141. func (us *UserService) CheckUserEnable(u *model.User) bool {
  142. return u.Status == model.COMMON_STATUS_ENABLE
  143. }
  144. // Create 创建
  145. func (us *UserService) Create(u *model.User) error {
  146. // The initial username should be formatted, and the username should be unique
  147. if us.IsUsernameExists(u.Username) {
  148. return errors.New("UsernameExists")
  149. }
  150. u.Username = us.formatUsername(u.Username)
  151. u.Password = us.EncryptPassword(u.Password)
  152. res := global.DB.Create(u).Error
  153. return res
  154. }
  155. // GetUuidByToken 根据token和user取uuid
  156. func (us *UserService) GetUuidByToken(u *model.User, token string) string {
  157. ut := &model.UserToken{}
  158. err := global.DB.Where("user_id = ? and token = ?", u.Id, token).First(ut).Error
  159. if err != nil {
  160. return ""
  161. }
  162. return ut.DeviceUuid
  163. }
  164. // Logout 退出登录 -> 删除token, 解绑uuid
  165. func (us *UserService) Logout(u *model.User, token string) error {
  166. uuid := us.GetUuidByToken(u, token)
  167. err := global.DB.Where("user_id = ? and token = ?", u.Id, token).Delete(&model.UserToken{}).Error
  168. if err != nil {
  169. return err
  170. }
  171. if uuid != "" {
  172. AllService.PeerService.UuidUnbindUserId(uuid, u.Id)
  173. }
  174. return nil
  175. }
  176. // Delete 删除用户和oauth信息
  177. func (us *UserService) Delete(u *model.User) error {
  178. userCount := us.getAdminUserCount()
  179. if userCount <= 1 && us.IsAdmin(u) {
  180. return errors.New("The last admin user cannot be deleted")
  181. }
  182. tx := global.DB.Begin()
  183. // 删除用户
  184. if err := tx.Delete(u).Error; err != nil {
  185. tx.Rollback()
  186. return err
  187. }
  188. // 删除关联的 OAuth 信息
  189. if err := tx.Where("user_id = ?", u.Id).Delete(&model.UserThird{}).Error; err != nil {
  190. tx.Rollback()
  191. return err
  192. }
  193. // 删除关联的ab
  194. if err := tx.Where("user_id = ?", u.Id).Delete(&model.AddressBook{}).Error; err != nil {
  195. tx.Rollback()
  196. return err
  197. }
  198. // 删除关联的abc
  199. if err := tx.Where("user_id = ?", u.Id).Delete(&model.AddressBookCollection{}).Error; err != nil {
  200. tx.Rollback()
  201. return err
  202. }
  203. // 删除关联的abcr
  204. if err := tx.Where("user_id = ?", u.Id).Delete(&model.AddressBookCollectionRule{}).Error; err != nil {
  205. tx.Rollback()
  206. return err
  207. }
  208. tx.Commit()
  209. // 删除关联的peer
  210. if err := AllService.PeerService.EraseUserId(u.Id); err != nil {
  211. global.Logger.Warn("User deleted successfully, but failed to unlink peer.")
  212. return nil
  213. }
  214. return nil
  215. }
  216. // Update 更新
  217. func (us *UserService) Update(u *model.User) error {
  218. currentUser := us.InfoById(u.Id)
  219. // 如果当前用户是管理员并且 IsAdmin 不为空,进行检查
  220. if us.IsAdmin(currentUser) {
  221. adminCount := us.getAdminUserCount()
  222. // 如果这是唯一的管理员,确保不能禁用或取消管理员权限
  223. if adminCount <= 1 && (!us.IsAdmin(u) || u.Status == model.COMMON_STATUS_DISABLED) {
  224. return errors.New("The last admin user cannot be disabled or demoted")
  225. }
  226. }
  227. return global.DB.Model(u).Updates(u).Error
  228. }
  229. // FlushToken 清空token
  230. func (us *UserService) FlushToken(u *model.User) error {
  231. return global.DB.Where("user_id = ?", u.Id).Delete(&model.UserToken{}).Error
  232. }
  233. // FlushTokenByUuid 清空token
  234. func (us *UserService) FlushTokenByUuid(uuid string) error {
  235. return global.DB.Where("device_uuid = ?", uuid).Delete(&model.UserToken{}).Error
  236. }
  237. // FlushTokenByUuids 清空token
  238. func (us *UserService) FlushTokenByUuids(uuids []string) error {
  239. return global.DB.Where("device_uuid in (?)", uuids).Delete(&model.UserToken{}).Error
  240. }
  241. // UpdatePassword 更新密码
  242. func (us *UserService) UpdatePassword(u *model.User, password string) error {
  243. u.Password = us.EncryptPassword(password)
  244. err := global.DB.Model(u).Update("password", u.Password).Error
  245. if err != nil {
  246. return err
  247. }
  248. err = us.FlushToken(u)
  249. return err
  250. }
  251. // IsAdmin 是否管理员
  252. func (us *UserService) IsAdmin(u *model.User) bool {
  253. return *u.IsAdmin
  254. }
  255. // RouteNames
  256. func (us *UserService) RouteNames(u *model.User) []string {
  257. if us.IsAdmin(u) {
  258. return model.AdminRouteNames
  259. }
  260. return model.UserRouteNames
  261. }
  262. // InfoByOauthId 根据oauth的name和openId取用户信息
  263. func (us *UserService) InfoByOauthId(op string, openId string) *model.User {
  264. ut := AllService.OauthService.UserThirdInfo(op, openId)
  265. if ut.Id == 0 {
  266. return nil
  267. }
  268. u := us.InfoById(ut.UserId)
  269. if u.Id == 0 {
  270. return nil
  271. }
  272. return u
  273. }
  274. // RegisterByOauth 注册
  275. func (us *UserService) RegisterByOauth(oauthUser *model.OauthUser, op string) (error, *model.User) {
  276. global.Lock.Lock("registerByOauth")
  277. defer global.Lock.UnLock("registerByOauth")
  278. ut := AllService.OauthService.UserThirdInfo(op, oauthUser.OpenId)
  279. if ut.Id != 0 {
  280. return nil, us.InfoById(ut.UserId)
  281. }
  282. err, oauthType := AllService.OauthService.GetTypeByOp(op)
  283. if err != nil {
  284. return err, nil
  285. }
  286. //check if this email has been registered
  287. email := oauthUser.Email
  288. // only email is not empty
  289. if email != "" {
  290. email = strings.ToLower(email)
  291. // update email to oauthUser, in case it contain upper case
  292. oauthUser.Email = email
  293. user := us.InfoByEmail(email)
  294. if user.Id != 0 {
  295. ut.FromOauthUser(user.Id, oauthUser, oauthType, op)
  296. global.DB.Create(ut)
  297. return nil, user
  298. }
  299. }
  300. tx := global.DB.Begin()
  301. ut = &model.UserThird{}
  302. ut.FromOauthUser(0, oauthUser, oauthType, op)
  303. // The initial username should be formatted
  304. username := us.formatUsername(oauthUser.Username)
  305. usernameUnique := us.GenerateUsernameByOauth(username)
  306. user := &model.User{
  307. Username: usernameUnique,
  308. GroupId: 1,
  309. }
  310. oauthUser.ToUser(user, false)
  311. tx.Create(user)
  312. if user.Id == 0 {
  313. tx.Rollback()
  314. return errors.New("OauthRegisterFailed"), user
  315. }
  316. ut.UserId = user.Id
  317. tx.Create(ut)
  318. tx.Commit()
  319. return nil, user
  320. }
  321. // GenerateUsernameByOauth 生成用户名
  322. func (us *UserService) GenerateUsernameByOauth(name string) string {
  323. for us.IsUsernameExists(name) {
  324. name += strconv.Itoa(rand.Intn(10)) // Append a random digit (0-9)
  325. }
  326. return name
  327. }
  328. // UserThirdsByUserId
  329. func (us *UserService) UserThirdsByUserId(userId uint) (res []*model.UserThird) {
  330. global.DB.Where("user_id = ?", userId).Find(&res)
  331. return res
  332. }
  333. func (us *UserService) UserThirdInfo(userId uint, op string) *model.UserThird {
  334. ut := &model.UserThird{}
  335. global.DB.Where("user_id = ? and op = ?", userId, op).First(ut)
  336. return ut
  337. }
  338. // FindLatestUserIdFromLoginLogByUuid 根据uuid查找最后登录的用户id
  339. func (us *UserService) FindLatestUserIdFromLoginLogByUuid(uuid string) uint {
  340. llog := &model.LoginLog{}
  341. global.DB.Where("uuid = ?", uuid).Order("id desc").First(llog)
  342. return llog.UserId
  343. }
  344. // IsPasswordEmptyById 根据用户id判断密码是否为空,主要用于第三方登录的自动注册
  345. func (us *UserService) IsPasswordEmptyById(id uint) bool {
  346. u := &model.User{}
  347. if global.DB.Where("id = ?", id).First(u).Error != nil {
  348. return false
  349. }
  350. return u.Password == ""
  351. }
  352. // IsPasswordEmptyByUsername 根据用户id判断密码是否为空,主要用于第三方登录的自动注册
  353. func (us *UserService) IsPasswordEmptyByUsername(username string) bool {
  354. u := &model.User{}
  355. if global.DB.Where("username = ?", username).First(u).Error != nil {
  356. return false
  357. }
  358. return u.Password == ""
  359. }
  360. // IsPasswordEmptyByUser 判断密码是否为空,主要用于第三方登录的自动注册
  361. func (us *UserService) IsPasswordEmptyByUser(u *model.User) bool {
  362. return us.IsPasswordEmptyById(u.Id)
  363. }
  364. // Register 注册, 如果用户名已存在则返回nil
  365. func (us *UserService) Register(username string, email string, password string) *model.User {
  366. u := &model.User{
  367. Username: username,
  368. Email: email,
  369. Password: password,
  370. GroupId: 1,
  371. }
  372. err := us.Create(u)
  373. if err != nil {
  374. return nil
  375. }
  376. return u
  377. }
  378. func (us *UserService) TokenList(page uint, size uint, f func(tx *gorm.DB)) *model.UserTokenList {
  379. res := &model.UserTokenList{}
  380. res.Page = int64(page)
  381. res.PageSize = int64(size)
  382. tx := global.DB.Model(&model.UserToken{})
  383. if f != nil {
  384. f(tx)
  385. }
  386. tx.Count(&res.Total)
  387. tx.Scopes(Paginate(page, size))
  388. tx.Find(&res.UserTokens)
  389. return res
  390. }
  391. func (us *UserService) TokenInfoById(id uint) *model.UserToken {
  392. ut := &model.UserToken{}
  393. global.DB.Where("id = ?", id).First(ut)
  394. return ut
  395. }
  396. func (us *UserService) DeleteToken(l *model.UserToken) error {
  397. return global.DB.Delete(l).Error
  398. }
  399. // Helper functions, used for formatting username
  400. func (us *UserService) formatUsername(username string) string {
  401. username = strings.ReplaceAll(username, " ", "")
  402. username = strings.ToLower(username)
  403. return username
  404. }
  405. // Helper functions, getUserCount
  406. func (us *UserService) getUserCount() int64 {
  407. var count int64
  408. global.DB.Model(&model.User{}).Count(&count)
  409. return count
  410. }
  411. // helper functions, getAdminUserCount
  412. func (us *UserService) getAdminUserCount() int64 {
  413. var count int64
  414. global.DB.Model(&model.User{}).Where("is_admin = ?", true).Count(&count)
  415. return count
  416. }
  417. func (us *UserService) RefreshAccessToken(ut *model.UserToken) {
  418. ut.ExpiredAt = time.Now().Add(time.Second * time.Duration(global.Config.App.TokenExpire)).Unix()
  419. global.DB.Model(ut).Update("expired_at", ut.ExpiredAt)
  420. }
  421. func (us *UserService) AutoRefreshAccessToken(ut *model.UserToken) {
  422. if ut.ExpiredAt-time.Now().Unix() < 86400 {
  423. us.RefreshAccessToken(ut)
  424. }
  425. }
  426. func (us *UserService) BatchDeleteUserToken(ids []uint) error {
  427. return global.DB.Where("id in ?", ids).Delete(&model.UserToken{}).Error
  428. }
  429. func (us *UserService) VerifyJWT(token string) (uint, error) {
  430. return global.Jwt.ParseToken(token)
  431. }
  432. // IsUsernameExists 判断用户名是否存在, it will check the internal database and LDAP(if enabled)
  433. func (us *UserService) IsUsernameExists(username string) bool {
  434. u := &model.User{}
  435. global.DB.Where("username = ?", username).First(u)
  436. existsInLdap := AllService.LdapService.IsUsernameExists(username)
  437. return u.Id != 0 || existsInLdap
  438. }