login.go 8.0 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313
  1. package admin
  2. import (
  3. "Gwen/global"
  4. "Gwen/http/controller/api"
  5. "Gwen/http/request/admin"
  6. apiReq "Gwen/http/request/api"
  7. "Gwen/http/response"
  8. adResp "Gwen/http/response/admin"
  9. "Gwen/model"
  10. "Gwen/service"
  11. "fmt"
  12. "github.com/gin-gonic/gin"
  13. "github.com/mojocn/base64Captcha"
  14. "sync"
  15. "time"
  16. )
  17. type Login struct {
  18. }
  19. // Captcha 验证码结构
  20. type Captcha struct {
  21. Id string `json:"id"` // 验证码 ID
  22. B64 string `json:"b64"` // base64 验证码
  23. Code string `json:"-"` // 验证码内容
  24. ExpiresAt time.Time `json:"-"` // 过期时间
  25. }
  26. type LoginLimiter struct {
  27. mu sync.RWMutex
  28. failCount map[string]int // 记录每个 IP 的失败次数
  29. timestamp map[string]time.Time // 记录每个 IP 的最后失败时间
  30. captchas map[string]Captcha // 每个 IP 的验证码
  31. threshold int // 失败阈值
  32. expiry time.Duration // 失败记录过期时间
  33. }
  34. func NewLoginLimiter(threshold int, expiry time.Duration) *LoginLimiter {
  35. return &LoginLimiter{
  36. failCount: make(map[string]int),
  37. timestamp: make(map[string]time.Time),
  38. captchas: make(map[string]Captcha),
  39. threshold: threshold,
  40. expiry: expiry,
  41. }
  42. }
  43. // RecordFailure 记录登录失败
  44. func (l *LoginLimiter) RecordFailure(ip string) {
  45. l.mu.Lock()
  46. defer l.mu.Unlock()
  47. // 如果该 IP 的记录已经过期,重置计数
  48. if lastTime, exists := l.timestamp[ip]; exists && time.Since(lastTime) > l.expiry {
  49. l.failCount[ip] = 0
  50. }
  51. // 更新失败次数和时间戳
  52. l.failCount[ip]++
  53. l.timestamp[ip] = time.Now()
  54. }
  55. // NeedsCaptcha 检查是否需要验证码
  56. func (l *LoginLimiter) NeedsCaptcha(ip string) bool {
  57. l.mu.RLock()
  58. defer l.mu.RUnlock()
  59. // 检查记录是否存在且未过期
  60. if lastTime, exists := l.timestamp[ip]; exists && time.Since(lastTime) <= l.expiry {
  61. return l.failCount[ip] >= l.threshold
  62. }
  63. return false
  64. }
  65. // GenerateCaptcha 为指定 IP 生成验证码
  66. func (l *LoginLimiter) GenerateCaptcha(ip string) Captcha {
  67. l.mu.Lock()
  68. defer l.mu.Unlock()
  69. capd := base64Captcha.NewDriverString(50, 150, 5, 10, 4, "1234567890abcdefghijklmnopqrstuvwxyz", nil, nil, nil)
  70. b64cap := base64Captcha.NewCaptcha(capd, base64Captcha.DefaultMemStore)
  71. id, b64s, answer, err := b64cap.Generate()
  72. if err != nil {
  73. global.Logger.Error("Generate captcha failed: " + err.Error())
  74. return Captcha{}
  75. }
  76. // 保存验证码到对应 IP
  77. l.captchas[ip] = Captcha{
  78. Id: id,
  79. B64: b64s,
  80. Code: answer,
  81. ExpiresAt: time.Now().Add(5 * time.Minute),
  82. }
  83. return l.captchas[ip]
  84. }
  85. // VerifyCaptcha 验证指定 IP 的验证码
  86. func (l *LoginLimiter) VerifyCaptcha(ip, code string) bool {
  87. l.mu.RLock()
  88. defer l.mu.RUnlock()
  89. // 检查验证码是否存在且未过期
  90. if captcha, exists := l.captchas[ip]; exists && time.Now().Before(captcha.ExpiresAt) {
  91. return captcha.Code == code
  92. }
  93. return false
  94. }
  95. // CleanupExpired 清理过期的记录
  96. func (l *LoginLimiter) CleanupExpired() {
  97. l.mu.Lock()
  98. defer l.mu.Unlock()
  99. now := time.Now()
  100. for ip, lastTime := range l.timestamp {
  101. if now.Sub(lastTime) > l.expiry {
  102. delete(l.failCount, ip)
  103. delete(l.timestamp, ip)
  104. delete(l.captchas, ip)
  105. }
  106. }
  107. }
  108. func (l *LoginLimiter) RemoveRecord(ip string) {
  109. l.mu.Lock()
  110. defer l.mu.Unlock()
  111. delete(l.failCount, ip)
  112. delete(l.timestamp, ip)
  113. delete(l.captchas, ip)
  114. }
  115. var loginLimiter = NewLoginLimiter(3, 5*time.Minute)
  116. // Login 登录
  117. // @Tags 登录
  118. // @Summary 登录
  119. // @Description 登录
  120. // @Accept json
  121. // @Produce json
  122. // @Param body body admin.Login true "登录信息"
  123. // @Success 200 {object} response.Response{data=adResp.LoginPayload}
  124. // @Failure 500 {object} response.Response
  125. // @Router /admin/login [post]
  126. // @Security token
  127. func (ct *Login) Login(c *gin.Context) {
  128. f := &admin.Login{}
  129. err := c.ShouldBindJSON(f)
  130. clientIp := c.ClientIP()
  131. if err != nil {
  132. global.Logger.Warn(fmt.Sprintf("Login Fail: %s %s %s", "ParamsError", c.RemoteIP(), clientIp))
  133. response.Fail(c, 101, response.TranslateMsg(c, "ParamsError")+err.Error())
  134. return
  135. }
  136. errList := global.Validator.ValidStruct(c, f)
  137. if len(errList) > 0 {
  138. global.Logger.Warn(fmt.Sprintf("Login Fail: %s %s %s", "ParamsError", c.RemoteIP(), clientIp))
  139. response.Fail(c, 101, errList[0])
  140. return
  141. }
  142. // 检查是否需要验证码
  143. if loginLimiter.NeedsCaptcha(clientIp) {
  144. if f.Captcha == "" {
  145. response.Fail(c, 110, response.TranslateMsg(c, "CaptchaRequired"))
  146. return
  147. }
  148. if !loginLimiter.VerifyCaptcha(clientIp, f.Captcha) {
  149. response.Fail(c, 101, response.TranslateMsg(c, "CaptchaError"))
  150. return
  151. }
  152. }
  153. u := service.AllService.UserService.InfoByUsernamePassword(f.Username, f.Password)
  154. if u.Id == 0 {
  155. global.Logger.Warn(fmt.Sprintf("Login Fail: %s %s %s", "UsernameOrPasswordError", c.RemoteIP(), clientIp))
  156. loginLimiter.RecordFailure(clientIp)
  157. response.Fail(c, 101, response.TranslateMsg(c, "UsernameOrPasswordError"))
  158. return
  159. }
  160. ut := service.AllService.UserService.Login(u, &model.LoginLog{
  161. UserId: u.Id,
  162. Client: model.LoginLogClientWebAdmin,
  163. Uuid: "", //must be empty
  164. Ip: clientIp,
  165. Type: model.LoginLogTypeAccount,
  166. Platform: f.Platform,
  167. })
  168. // 成功后清除记录
  169. loginLimiter.RemoveRecord(clientIp)
  170. // 清理过期记录
  171. go loginLimiter.CleanupExpired()
  172. responseLoginSuccess(c, u, ut.Token)
  173. }
  174. func (ct *Login) Captcha(c *gin.Context) {
  175. clientIp := c.ClientIP()
  176. if !loginLimiter.NeedsCaptcha(clientIp) {
  177. response.Fail(c, 101, response.TranslateMsg(c, "NoCaptchaRequired"))
  178. return
  179. }
  180. captcha := loginLimiter.GenerateCaptcha(clientIp)
  181. response.Success(c, gin.H{
  182. "captcha": captcha,
  183. })
  184. }
  185. // Logout 登出
  186. // @Tags 登录
  187. // @Summary 登出
  188. // @Description 登出
  189. // @Accept json
  190. // @Produce json
  191. // @Success 200 {object} response.Response
  192. // @Failure 500 {object} response.Response
  193. // @Router /admin/logout [post]
  194. func (ct *Login) Logout(c *gin.Context) {
  195. u := service.AllService.UserService.CurUser(c)
  196. token, ok := c.Get("token")
  197. if ok {
  198. service.AllService.UserService.Logout(u, token.(string))
  199. }
  200. response.Success(c, nil)
  201. }
  202. // LoginOptions
  203. // @Tags 登录
  204. // @Summary 登录选项
  205. // @Description 登录选项
  206. // @Accept json
  207. // @Produce json
  208. // @Success 200 {object} []string
  209. // @Failure 500 {object} response.ErrorResponse
  210. // @Router /admin/login-options [post]
  211. func (ct *Login) LoginOptions(c *gin.Context) {
  212. ip := c.ClientIP()
  213. ops := service.AllService.OauthService.GetOauthProviders()
  214. response.Success(c, gin.H{
  215. "ops": ops,
  216. "register": global.Config.App.Register,
  217. "need_captcha": loginLimiter.NeedsCaptcha(ip),
  218. })
  219. }
  220. // OidcAuth
  221. // @Tags Oauth
  222. // @Summary OidcAuth
  223. // @Description OidcAuth
  224. // @Accept json
  225. // @Produce json
  226. // @Router /admin/oidc/auth [post]
  227. func (ct *Login) OidcAuth(c *gin.Context) {
  228. // o := &api.Oauth{}
  229. // o.OidcAuth(c)
  230. f := &apiReq.OidcAuthRequest{}
  231. err := c.ShouldBindJSON(f)
  232. if err != nil {
  233. response.Fail(c, 101, response.TranslateMsg(c, "ParamsError")+err.Error())
  234. return
  235. }
  236. err, code, url := service.AllService.OauthService.BeginAuth(f.Op)
  237. if err != nil {
  238. response.Error(c, response.TranslateMsg(c, err.Error()))
  239. return
  240. }
  241. service.AllService.OauthService.SetOauthCache(code, &service.OauthCacheItem{
  242. Action: service.OauthActionTypeLogin,
  243. Op: f.Op,
  244. Id: f.Id,
  245. DeviceType: "webadmin",
  246. // DeviceOs: ct.Platform(c),
  247. DeviceOs: f.DeviceInfo.Os,
  248. Uuid: f.Uuid,
  249. }, 5*60)
  250. response.Success(c, gin.H{
  251. "code": code,
  252. "url": url,
  253. })
  254. }
  255. // OidcAuthQuery
  256. // @Tags Oauth
  257. // @Summary OidcAuthQuery
  258. // @Description OidcAuthQuery
  259. // @Accept json
  260. // @Produce json
  261. // @Success 200 {object} response.Response{data=adResp.LoginPayload}
  262. // @Failure 500 {object} response.Response
  263. // @Router /admin/oidc/auth-query [get]
  264. func (ct *Login) OidcAuthQuery(c *gin.Context) {
  265. o := &api.Oauth{}
  266. u, ut := o.OidcAuthQueryPre(c)
  267. if ut == nil {
  268. return
  269. }
  270. responseLoginSuccess(c, u, ut.Token)
  271. }
  272. func responseLoginSuccess(c *gin.Context, u *model.User, token string) {
  273. lp := &adResp.LoginPayload{}
  274. lp.FromUser(u)
  275. lp.Token = token
  276. lp.RouteNames = service.AllService.UserService.RouteNames(u)
  277. response.Success(c, lp)
  278. }