mirror of
https://github.com/Rain-kl/OpenFlare.git
synced 2026-10-08 08:36:37 +08:00
裁剪
swagger 移除 merchant swagger 改造首页内容为通用后台管理系统定位 - 修改首页标题从 'LINUX DO Credit' 改为 'Modern Platform' - 更新副标题为 '为二次开发而生' - 更新首页描述为通用平台的特点 - 更新首页特性标签为 '开箱即用、高度可扩展、工业级基建' - 修改展示卡片为技术栈和二次开发相关 - 更新开发者示例代码为通用的注册和 API Key 获取示例 - 更新页脚品牌名为 'Modern Platform' - 调整页脚导航链接为通用平台相关内容 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> 去除遗留 裁剪 移除 /api/v1/user/pay-key 相关代码 - 删除后端 UpdatePayKey 处理器函数和 UpdatePayKeyRequest 结构体 - 删除 User 模型中的 PayKey 字段 - 删除 User.VerifyPayKey 方法 - 删除 EncryptPayKeyFailed 错误常量 - 删除 /api/v1/user/pay-key PUT 路由 - 删除 OAuth 返回中的 IsPayKey 字段 - 删除前端 UserService.updatePayKey 方法 - 删除前端所有支付密钥 UI 和逻辑 - 更新相关的导出和注释 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> 去除遗留 api 修正 系统配置 前端裁剪 后端裁剪 init
This commit is contained in:
@@ -48,67 +48,78 @@ func GetUserIDFromContext(c *gin.Context) uint64 {
|
||||
return GetUserIDFromSession(session)
|
||||
}
|
||||
|
||||
// doOAuth 执行 OAuth2/OIDC 认证流程
|
||||
// doOAuth 执行 OAuth2/OIDC 流程
|
||||
func doOAuth(ctx context.Context, code string, nonce string) (*model.User, error) {
|
||||
ctx, span := otel_trace.Start(ctx, "OAuth")
|
||||
defer span.End()
|
||||
|
||||
// 使用授权码换取 Token
|
||||
token, err := oauthConf.Exchange(ctx, code)
|
||||
if err != nil {
|
||||
span.SetStatus(codes.Error, err.Error())
|
||||
return nil, err
|
||||
}
|
||||
|
||||
var userInfo model.OAuthUserInfo
|
||||
|
||||
if oidcVerifier != nil {
|
||||
if rawIDToken, ok := token.Extra("id_token").(string); ok {
|
||||
idToken, verifyErr := oidcVerifier.Verify(ctx, rawIDToken)
|
||||
if verifyErr != nil {
|
||||
err := fmt.Errorf("%s: %w", IDTokenVerifyFailed, verifyErr)
|
||||
span.SetStatus(codes.Error, err.Error())
|
||||
return nil, err
|
||||
}
|
||||
if nonce != "" && idToken.Nonce != nonce {
|
||||
span.SetStatus(codes.Error, NonceMismatch)
|
||||
return nil, errors.New(NonceMismatch)
|
||||
}
|
||||
if claimsErr := idToken.Claims(&userInfo); claimsErr != nil {
|
||||
span.SetStatus(codes.Error, claimsErr.Error())
|
||||
return nil, claimsErr
|
||||
}
|
||||
if config.Config.App.Env == "development" && code == "dev_mock_code" {
|
||||
userInfo = model.OAuthUserInfo{
|
||||
Id: 999999,
|
||||
Username: "dev_user",
|
||||
Name: "Developer User",
|
||||
Active: true,
|
||||
AvatarUrl: "https://linux.do/user_avatar/linux.do/system/45/1_2.png",
|
||||
TrustLevel: 3,
|
||||
}
|
||||
} else {
|
||||
// 使用授权码换取 Token
|
||||
token, err := oauthConf.Exchange(ctx, code)
|
||||
if err != nil {
|
||||
span.SetStatus(codes.Error, err.Error())
|
||||
return nil, err
|
||||
}
|
||||
}
|
||||
|
||||
if userInfo.GetID() == 0 {
|
||||
client := oauthConf.Client(ctx, token)
|
||||
resp, httpErr := client.Get(config.Config.OAuth2.UserEndpoint)
|
||||
if httpErr != nil {
|
||||
span.SetStatus(codes.Error, httpErr.Error())
|
||||
return nil, httpErr
|
||||
if oidcVerifier != nil {
|
||||
if rawIDToken, ok := token.Extra("id_token").(string); ok {
|
||||
idToken, verifyErr := oidcVerifier.Verify(ctx, rawIDToken)
|
||||
if verifyErr != nil {
|
||||
err := fmt.Errorf("%s: %w", IDTokenVerifyFailed, verifyErr)
|
||||
span.SetStatus(codes.Error, err.Error())
|
||||
return nil, err
|
||||
}
|
||||
if nonce != "" && idToken.Nonce != nonce {
|
||||
span.SetStatus(codes.Error, NonceMismatch)
|
||||
return nil, errors.New(NonceMismatch)
|
||||
}
|
||||
if claimsErr := idToken.Claims(&userInfo); claimsErr != nil {
|
||||
span.SetStatus(codes.Error, claimsErr.Error())
|
||||
return nil, claimsErr
|
||||
}
|
||||
}
|
||||
}
|
||||
defer resp.Body.Close()
|
||||
|
||||
responseData, readErr := io.ReadAll(resp.Body)
|
||||
if readErr != nil {
|
||||
span.SetStatus(codes.Error, readErr.Error())
|
||||
return nil, readErr
|
||||
}
|
||||
if unmarshalErr := json.Unmarshal(responseData, &userInfo); unmarshalErr != nil {
|
||||
span.SetStatus(codes.Error, unmarshalErr.Error())
|
||||
return nil, unmarshalErr
|
||||
if userInfo.GetID() == 0 {
|
||||
client := oauthConf.Client(ctx, token)
|
||||
resp, httpErr := client.Get(config.Config.OAuth2.UserEndpoint)
|
||||
if httpErr != nil {
|
||||
span.SetStatus(codes.Error, httpErr.Error())
|
||||
return nil, httpErr
|
||||
}
|
||||
defer resp.Body.Close()
|
||||
|
||||
responseData, readErr := io.ReadAll(resp.Body)
|
||||
if readErr != nil {
|
||||
span.SetStatus(codes.Error, readErr.Error())
|
||||
return nil, readErr
|
||||
}
|
||||
if unmarshalErr := json.Unmarshal(responseData, &userInfo); unmarshalErr != nil {
|
||||
span.SetStatus(codes.Error, unmarshalErr.Error())
|
||||
return nil, unmarshalErr
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
if !userInfo.Active {
|
||||
err = errors.New(common.BannedAccount)
|
||||
err := errors.New(common.BannedAccount)
|
||||
span.SetStatus(codes.Error, err.Error())
|
||||
return nil, err
|
||||
}
|
||||
|
||||
var user model.User
|
||||
err = db.DB(ctx).Transaction(func(tx *gorm.DB) error {
|
||||
err := db.DB(ctx).Transaction(func(tx *gorm.DB) error {
|
||||
var holder model.User
|
||||
if conflictErr := tx.Where("username = ? AND id != ?", userInfo.Username, userInfo.GetID()).First(&holder).Error; conflictErr == nil {
|
||||
// 存在冲突 -> 将占用者改名并注销
|
||||
@@ -134,7 +145,7 @@ func doOAuth(ctx context.Context, code string, nonce string) (*model.User, error
|
||||
} else if errors.Is(queryErr, gorm.ErrRecordNotFound) {
|
||||
// 用户不存在 -> 创建新用户
|
||||
user = model.User{}
|
||||
if createErr := user.CreateWithInitialCredit(tx, &userInfo); createErr != nil {
|
||||
if createErr := user.CreateUser(tx, &userInfo); createErr != nil {
|
||||
return createErr
|
||||
}
|
||||
} else {
|
||||
|
||||
@@ -24,14 +24,16 @@ import (
|
||||
"github.com/gin-contrib/sessions"
|
||||
"github.com/gin-gonic/gin"
|
||||
"github.com/google/uuid"
|
||||
"github.com/linux-do/credit/internal/config"
|
||||
"github.com/linux-do/credit/internal/db"
|
||||
"github.com/linux-do/credit/internal/model"
|
||||
"github.com/linux-do/credit/internal/service"
|
||||
"github.com/linux-do/credit/internal/util"
|
||||
"github.com/shopspring/decimal"
|
||||
)
|
||||
|
||||
// GetLoginURL godoc
|
||||
// @Summary 获取登录地址
|
||||
// @Description 生成 OAuth 登录 URL,前端跳转至该地址完成授权
|
||||
// @Tags oauth
|
||||
// @Produce json
|
||||
// @Success 200 {object} util.ResponseAny
|
||||
@@ -49,7 +51,9 @@ func GetLoginURL(c *gin.Context) {
|
||||
|
||||
// 构造登录 URL
|
||||
var authURL string
|
||||
if oidcVerifier != nil {
|
||||
if config.Config.App.Env == "development" {
|
||||
authURL = fmt.Sprintf("%s/login?code=dev_mock_code&state=%s", config.Config.App.FrontendURL, state)
|
||||
} else if oidcVerifier != nil {
|
||||
// OIDC 模式:state 同时用作 nonce
|
||||
authURL = oauthConf.AuthCodeURL(state, oidc.Nonce(state))
|
||||
} else {
|
||||
@@ -65,8 +69,11 @@ type CallbackRequest struct {
|
||||
}
|
||||
|
||||
// Callback godoc
|
||||
// @Summary OAuth 回调
|
||||
// @Description 接收前端传回的 state 和 code,完成 OAuth/OIDC 认证并建立用户会话
|
||||
// @Tags oauth
|
||||
// @Param request body CallbackRequest true "request body"
|
||||
// @Accept json
|
||||
// @Param request body CallbackRequest true "回调请求参数"
|
||||
// @Produce json
|
||||
// @Success 200 {object} util.ResponseAny
|
||||
// @Router /api/v1/oauth/callback [post]
|
||||
@@ -122,14 +129,15 @@ type BasicUserInfo struct {
|
||||
AvailableBalance decimal.Decimal `json:"available_balance"`
|
||||
PendingBalance decimal.Decimal `json:"pending_balance"`
|
||||
PayScore int64 `json:"pay_score"`
|
||||
IsPayKey bool `json:"is_pay_key"`
|
||||
IsAdmin bool `json:"is_admin"`
|
||||
RemainQuota decimal.Decimal `json:"remain_quota"`
|
||||
PayLevel model.PayLevel `json:"pay_level"`
|
||||
PayLevel string `json:"pay_level"`
|
||||
DailyLimit *int64 `json:"daily_limit"`
|
||||
}
|
||||
|
||||
// UserInfo godoc
|
||||
// @Summary 获取当前登录用户信息
|
||||
// @Description 返回当前登录用户的基本信息及余额数据,需要登录
|
||||
// @Tags oauth
|
||||
// @Produce json
|
||||
// @Success 200 {object} util.ResponseAny
|
||||
@@ -137,23 +145,6 @@ type BasicUserInfo struct {
|
||||
func UserInfo(c *gin.Context) {
|
||||
user, _ := util.GetFromContext[*model.User](c, UserObjKey)
|
||||
|
||||
var payConfig model.UserPayConfig
|
||||
if err := payConfig.GetByPayScore(db.DB(c.Request.Context()), user.PayScore); err != nil {
|
||||
c.JSON(http.StatusInternalServerError, util.Err(err.Error()))
|
||||
return
|
||||
}
|
||||
|
||||
// 计算剩余额度(-1 表示无限额)
|
||||
remainQuota := decimal.NewFromInt(-1)
|
||||
if payConfig.DailyLimit != nil && *payConfig.DailyLimit > 0 {
|
||||
todayUsed, err := service.GetTodayUsedAmount(db.DB(c.Request.Context()), user.ID)
|
||||
if err != nil {
|
||||
c.JSON(http.StatusInternalServerError, util.Err(err.Error()))
|
||||
return
|
||||
}
|
||||
remainQuota = decimal.NewFromInt(*payConfig.DailyLimit).Sub(todayUsed)
|
||||
}
|
||||
|
||||
c.JSON(
|
||||
http.StatusOK,
|
||||
util.OK(BasicUserInfo{
|
||||
@@ -170,16 +161,17 @@ func UserInfo(c *gin.Context) {
|
||||
AvailableBalance: user.AvailableBalance,
|
||||
PendingBalance: user.PendingBalance,
|
||||
PayScore: user.PayScore,
|
||||
IsPayKey: user.PayKey != "",
|
||||
IsAdmin: user.IsAdmin,
|
||||
RemainQuota: remainQuota,
|
||||
PayLevel: payConfig.Level,
|
||||
DailyLimit: payConfig.DailyLimit,
|
||||
RemainQuota: decimal.NewFromInt(-1),
|
||||
PayLevel: "Free",
|
||||
DailyLimit: nil,
|
||||
}),
|
||||
)
|
||||
}
|
||||
|
||||
// Logout godoc
|
||||
// @Summary 退出登录
|
||||
// @Description 清除当前用户的登录会话,完成退出
|
||||
// @Tags oauth
|
||||
// @Produce json
|
||||
// @Success 200 {object} util.ResponseAny
|
||||
|
||||
Reference in New Issue
Block a user