user.go 13 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464
  1. package service
  2. import (
  3. "Gwen/global"
  4. "Gwen/model"
  5. "Gwen/utils"
  6. "errors"
  7. "github.com/gin-gonic/gin"
  8. "gorm.io/gorm"
  9. "math/rand"
  10. "strconv"
  11. "strings"
  12. "time"
  13. )
  14. type UserService struct {
  15. }
  16. // InfoById 根据用户id取用户信息
  17. func (us *UserService) InfoById(id uint) *model.User {
  18. u := &model.User{}
  19. global.DB.Where("id = ?", id).First(u)
  20. return u
  21. }
  22. // InfoByUsername 根据用户名取用户信息
  23. func (us *UserService) InfoByUsername(un string) *model.User {
  24. u := &model.User{}
  25. global.DB.Where("username = ?", un).First(u)
  26. return u
  27. }
  28. // InfoByEmail 根据邮箱取用户信息
  29. func (us *UserService) InfoByEmail(email string) *model.User {
  30. u := &model.User{}
  31. global.DB.Where("email = ?", email).First(u)
  32. return u
  33. }
  34. // InfoByOpenid 根据openid取用户信息
  35. func (us *UserService) InfoByOpenid(openid string) *model.User {
  36. u := &model.User{}
  37. global.DB.Where("openid = ?", openid).First(u)
  38. return u
  39. }
  40. // InfoByUsernamePassword 根据用户名密码取用户信息
  41. func (us *UserService) InfoByUsernamePassword(username, password string) *model.User {
  42. u := &model.User{}
  43. global.DB.Where("username = ? and password = ?", username, us.EncryptPassword(password)).First(u)
  44. return u
  45. }
  46. // InfoByAccesstoken 根据accesstoken取用户信息
  47. func (us *UserService) InfoByAccessToken(token string) (*model.User, *model.UserToken) {
  48. u := &model.User{}
  49. ut := &model.UserToken{}
  50. global.DB.Where("token = ?", token).First(ut)
  51. if ut.Id == 0 {
  52. return u, ut
  53. }
  54. if ut.ExpiredAt < time.Now().Unix() {
  55. return u, ut
  56. }
  57. global.DB.Where("id = ?", ut.UserId).First(u)
  58. return u, ut
  59. }
  60. // GenerateToken 生成token
  61. func (us *UserService) GenerateToken(u *model.User) string {
  62. return utils.Md5(u.Username + time.Now().String())
  63. }
  64. // Login 登录
  65. func (us *UserService) Login(u *model.User, llog *model.LoginLog) *model.UserToken {
  66. token := us.GenerateToken(u)
  67. ut := &model.UserToken{
  68. UserId: u.Id,
  69. Token: token,
  70. DeviceUuid: llog.Uuid,
  71. DeviceId: llog.DeviceId,
  72. ExpiredAt: time.Now().Add(time.Hour * 24 * 7).Unix(),
  73. }
  74. global.DB.Create(ut)
  75. llog.UserTokenId = ut.UserId
  76. global.DB.Create(llog)
  77. if llog.Uuid != "" {
  78. AllService.PeerService.UuidBindUserId(llog.DeviceId, llog.Uuid, u.Id)
  79. }
  80. return ut
  81. }
  82. // CurUser 获取当前用户
  83. func (us *UserService) CurUser(c *gin.Context) *model.User {
  84. user, _ := c.Get("curUser")
  85. u, ok := user.(*model.User)
  86. if !ok {
  87. return nil
  88. }
  89. return u
  90. }
  91. func (us *UserService) List(page, pageSize uint, where func(tx *gorm.DB)) (res *model.UserList) {
  92. res = &model.UserList{}
  93. res.Page = int64(page)
  94. res.PageSize = int64(pageSize)
  95. tx := global.DB.Model(&model.User{})
  96. if where != nil {
  97. where(tx)
  98. }
  99. tx.Count(&res.Total)
  100. tx.Scopes(Paginate(page, pageSize))
  101. tx.Find(&res.Users)
  102. return
  103. }
  104. func (us *UserService) ListByIds(ids []uint) (res []*model.User) {
  105. global.DB.Where("id in ?", ids).Find(&res)
  106. return res
  107. }
  108. // ListByGroupId 根据组id取用户列表
  109. func (us *UserService) ListByGroupId(groupId, page, pageSize uint) (res *model.UserList) {
  110. res = us.List(page, pageSize, func(tx *gorm.DB) {
  111. tx.Where("group_id = ?", groupId)
  112. })
  113. return
  114. }
  115. // ListIdsByGroupId 根据组id取用户id列表
  116. func (us *UserService) ListIdsByGroupId(groupId uint) (ids []uint) {
  117. global.DB.Model(&model.User{}).Where("group_id = ?", groupId).Pluck("id", &ids)
  118. return ids
  119. }
  120. // ListIdAndNameByGroupId 根据组id取用户id和用户名列表
  121. func (us *UserService) ListIdAndNameByGroupId(groupId uint) (res []*model.User) {
  122. global.DB.Model(&model.User{}).Where("group_id = ?", groupId).Select("id, username").Find(&res)
  123. return res
  124. }
  125. // EncryptPassword 加密密码
  126. func (us *UserService) EncryptPassword(password string) string {
  127. return utils.Md5(password + "rustdesk-api")
  128. }
  129. // CheckUserEnable 判断用户是否禁用
  130. func (us *UserService) CheckUserEnable(u *model.User) bool {
  131. return u.Status == model.COMMON_STATUS_ENABLE
  132. }
  133. // Create 创建
  134. func (us *UserService) Create(u *model.User) error {
  135. // The initial username should be formatted, and the username should be unique
  136. u.Username = us.formatUsername(u.Username)
  137. u.Password = us.EncryptPassword(u.Password)
  138. res := global.DB.Create(u).Error
  139. return res
  140. }
  141. // GetUuidByToken 根据token和user取uuid
  142. func (us *UserService) GetUuidByToken(u *model.User, token string) string {
  143. ut := &model.UserToken{}
  144. err := global.DB.Where("user_id = ? and token = ?", u.Id, token).First(ut).Error
  145. if err != nil {
  146. return ""
  147. }
  148. return ut.DeviceUuid
  149. }
  150. // Logout 退出登录 -> 删除token, 解绑uuid
  151. func (us *UserService) Logout(u *model.User, token string) error {
  152. uuid := us.GetUuidByToken(u, token)
  153. err := global.DB.Where("user_id = ? and token = ?", u.Id, token).Delete(&model.UserToken{}).Error
  154. if err != nil {
  155. return err
  156. }
  157. if uuid != "" {
  158. AllService.PeerService.UuidUnbindUserId(uuid, u.Id)
  159. }
  160. return nil
  161. }
  162. // Delete 删除用户和oauth信息
  163. func (us *UserService) Delete(u *model.User) error {
  164. userCount := us.getAdminUserCount()
  165. if userCount <= 1 && us.IsAdmin(u) {
  166. return errors.New("The last admin user cannot be deleted")
  167. }
  168. tx := global.DB.Begin()
  169. // 删除用户
  170. if err := tx.Delete(u).Error; err != nil {
  171. tx.Rollback()
  172. return err
  173. }
  174. // 删除关联的 OAuth 信息
  175. if err := tx.Where("user_id = ?", u.Id).Delete(&model.UserThird{}).Error; err != nil {
  176. tx.Rollback()
  177. return err
  178. }
  179. // 删除关联的ab
  180. if err := tx.Where("user_id = ?", u.Id).Delete(&model.AddressBook{}).Error; err != nil {
  181. tx.Rollback()
  182. return err
  183. }
  184. // 删除关联的abc
  185. if err := tx.Where("user_id = ?", u.Id).Delete(&model.AddressBookCollection{}).Error; err != nil {
  186. tx.Rollback()
  187. return err
  188. }
  189. // 删除关联的abcr
  190. if err := tx.Where("user_id = ?", u.Id).Delete(&model.AddressBookCollectionRule{}).Error; err != nil {
  191. tx.Rollback()
  192. return err
  193. }
  194. tx.Commit()
  195. // 删除关联的peer
  196. if err := AllService.PeerService.EraseUserId(u.Id); err != nil {
  197. global.Logger.Warn("User deleted successfully, but failed to unlink peer.")
  198. return nil
  199. }
  200. return nil
  201. }
  202. // Update 更新
  203. func (us *UserService) Update(u *model.User) error {
  204. currentUser := us.InfoById(u.Id)
  205. // 如果当前用户是管理员并且 IsAdmin 不为空,进行检查
  206. if us.IsAdmin(currentUser) {
  207. adminCount := us.getAdminUserCount()
  208. // 如果这是唯一的管理员,确保不能禁用或取消管理员权限
  209. if adminCount <= 1 && (!us.IsAdmin(u) || u.Status == model.COMMON_STATUS_DISABLED) {
  210. return errors.New("The last admin user cannot be disabled or demoted")
  211. }
  212. }
  213. return global.DB.Model(u).Updates(u).Error
  214. }
  215. // FlushToken 清空token
  216. func (us *UserService) FlushToken(u *model.User) error {
  217. return global.DB.Where("user_id = ?", u.Id).Delete(&model.UserToken{}).Error
  218. }
  219. // FlushTokenByUuid 清空token
  220. func (us *UserService) FlushTokenByUuid(uuid string) error {
  221. return global.DB.Where("device_uuid = ?", uuid).Delete(&model.UserToken{}).Error
  222. }
  223. // FlushTokenByUuids 清空token
  224. func (us *UserService) FlushTokenByUuids(uuids []string) error {
  225. return global.DB.Where("device_uuid in (?)", uuids).Delete(&model.UserToken{}).Error
  226. }
  227. // UpdatePassword 更新密码
  228. func (us *UserService) UpdatePassword(u *model.User, password string) error {
  229. u.Password = us.EncryptPassword(password)
  230. err := global.DB.Model(u).Update("password", u.Password).Error
  231. if err != nil {
  232. return err
  233. }
  234. err = us.FlushToken(u)
  235. return err
  236. }
  237. // IsAdmin 是否管理员
  238. func (us *UserService) IsAdmin(u *model.User) bool {
  239. return *u.IsAdmin
  240. }
  241. // RouteNames
  242. func (us *UserService) RouteNames(u *model.User) []string {
  243. if us.IsAdmin(u) {
  244. return model.AdminRouteNames
  245. }
  246. return model.UserRouteNames
  247. }
  248. // InfoByOauthId 根据oauth的name和openId取用户信息
  249. func (us *UserService) InfoByOauthId(op string, openId string) *model.User {
  250. ut := AllService.OauthService.UserThirdInfo(op, openId)
  251. if ut.Id == 0 {
  252. return nil
  253. }
  254. u := us.InfoById(ut.UserId)
  255. if u.Id == 0 {
  256. return nil
  257. }
  258. return u
  259. }
  260. // RegisterByOauth 注册
  261. func (us *UserService) RegisterByOauth(oauthUser *model.OauthUser, op string) (error, *model.User) {
  262. global.Lock.Lock("registerByOauth")
  263. defer global.Lock.UnLock("registerByOauth")
  264. ut := AllService.OauthService.UserThirdInfo(op, oauthUser.OpenId)
  265. if ut.Id != 0 {
  266. return nil, us.InfoById(ut.UserId)
  267. }
  268. err, oauthType := AllService.OauthService.GetTypeByOp(op)
  269. if err != nil {
  270. return err, nil
  271. }
  272. //check if this email has been registered
  273. email := oauthUser.Email
  274. // only email is not empty
  275. if email != "" {
  276. email = strings.ToLower(email)
  277. // update email to oauthUser, in case it contain upper case
  278. oauthUser.Email = email
  279. user := us.InfoByEmail(email)
  280. if user.Id != 0 {
  281. ut.FromOauthUser(user.Id, oauthUser, oauthType, op)
  282. global.DB.Create(ut)
  283. return nil, user
  284. }
  285. }
  286. tx := global.DB.Begin()
  287. ut = &model.UserThird{}
  288. ut.FromOauthUser(0, oauthUser, oauthType, op)
  289. // The initial username should be formatted
  290. username := us.formatUsername(oauthUser.Username)
  291. usernameUnique := us.GenerateUsernameByOauth(username)
  292. user := &model.User{
  293. Username: usernameUnique,
  294. GroupId: 1,
  295. }
  296. oauthUser.ToUser(user, false)
  297. tx.Create(user)
  298. if user.Id == 0 {
  299. tx.Rollback()
  300. return errors.New("OauthRegisterFailed"), user
  301. }
  302. ut.UserId = user.Id
  303. tx.Create(ut)
  304. tx.Commit()
  305. return nil, user
  306. }
  307. // GenerateUsernameByOauth 生成用户名
  308. func (us *UserService) GenerateUsernameByOauth(name string) string {
  309. u := &model.User{}
  310. global.DB.Where("username = ?", name).First(u)
  311. if u.Id == 0 {
  312. return name
  313. }
  314. name = name + strconv.FormatInt(rand.Int63n(10), 10)
  315. return us.GenerateUsernameByOauth(name)
  316. }
  317. // UserThirdsByUserId
  318. func (us *UserService) UserThirdsByUserId(userId uint) (res []*model.UserThird) {
  319. global.DB.Where("user_id = ?", userId).Find(&res)
  320. return res
  321. }
  322. func (us *UserService) UserThirdInfo(userId uint, op string) *model.UserThird {
  323. ut := &model.UserThird{}
  324. global.DB.Where("user_id = ? and op = ?", userId, op).First(ut)
  325. return ut
  326. }
  327. // FindLatestUserIdFromLoginLogByUuid 根据uuid查找最后登录的用户id
  328. func (us *UserService) FindLatestUserIdFromLoginLogByUuid(uuid string) uint {
  329. llog := &model.LoginLog{}
  330. global.DB.Where("uuid = ?", uuid).Order("id desc").First(llog)
  331. return llog.UserId
  332. }
  333. // IsPasswordEmptyById 根据用户id判断密码是否为空,主要用于第三方登录的自动注册
  334. func (us *UserService) IsPasswordEmptyById(id uint) bool {
  335. u := &model.User{}
  336. if global.DB.Where("id = ?", id).First(u).Error != nil {
  337. return false
  338. }
  339. return u.Password == ""
  340. }
  341. // IsPasswordEmptyByUsername 根据用户id判断密码是否为空,主要用于第三方登录的自动注册
  342. func (us *UserService) IsPasswordEmptyByUsername(username string) bool {
  343. u := &model.User{}
  344. if global.DB.Where("username = ?", username).First(u).Error != nil {
  345. return false
  346. }
  347. return u.Password == ""
  348. }
  349. // IsPasswordEmptyByUser 判断密码是否为空,主要用于第三方登录的自动注册
  350. func (us *UserService) IsPasswordEmptyByUser(u *model.User) bool {
  351. return us.IsPasswordEmptyById(u.Id)
  352. }
  353. // Register 注册
  354. func (us *UserService) Register(username string, email string, password string) *model.User {
  355. u := &model.User{
  356. Username: username,
  357. Email: email,
  358. Password: us.EncryptPassword(password),
  359. GroupId: 1,
  360. }
  361. global.DB.Create(u)
  362. return u
  363. }
  364. func (us *UserService) TokenList(page uint, size uint, f func(tx *gorm.DB)) *model.UserTokenList {
  365. res := &model.UserTokenList{}
  366. res.Page = int64(page)
  367. res.PageSize = int64(size)
  368. tx := global.DB.Model(&model.UserToken{})
  369. if f != nil {
  370. f(tx)
  371. }
  372. tx.Count(&res.Total)
  373. tx.Scopes(Paginate(page, size))
  374. tx.Find(&res.UserTokens)
  375. return res
  376. }
  377. func (us *UserService) TokenInfoById(id uint) *model.UserToken {
  378. ut := &model.UserToken{}
  379. global.DB.Where("id = ?", id).First(ut)
  380. return ut
  381. }
  382. func (us *UserService) DeleteToken(l *model.UserToken) error {
  383. return global.DB.Delete(l).Error
  384. }
  385. // Helper functions, used for formatting username
  386. func (us *UserService) formatUsername(username string) string {
  387. username = strings.ReplaceAll(username, " ", "")
  388. username = strings.ToLower(username)
  389. return username
  390. }
  391. // Helper functions, getUserCount
  392. func (us *UserService) getUserCount() int64 {
  393. var count int64
  394. global.DB.Model(&model.User{}).Count(&count)
  395. return count
  396. }
  397. // helper functions, getAdminUserCount
  398. func (us *UserService) getAdminUserCount() int64 {
  399. var count int64
  400. global.DB.Model(&model.User{}).Where("is_admin = ?", true).Count(&count)
  401. return count
  402. }
  403. func (us *UserService) RefreshAccessToken(ut *model.UserToken) {
  404. ut.ExpiredAt = time.Now().Add(time.Hour * 24 * 7).Unix()
  405. global.DB.Model(ut).Update("expired_at", ut.ExpiredAt)
  406. }
  407. func (us *UserService) AutoRefreshAccessToken(ut *model.UserToken) {
  408. if ut.ExpiredAt-time.Now().Unix() < 86400 {
  409. us.RefreshAccessToken(ut)
  410. }
  411. }
  412. func (us *UserService) BatchDeleteUserToken(ids []uint) error {
  413. return global.DB.Where("id in ?", ids).Delete(&model.UserToken{}).Error
  414. }