mirror of
https://github.com/Rain-kl/OpenFlare.git
synced 2026-10-08 00:26:37 +08:00
fix(auth): synchronize need_change_password across login, user-info and repositories
This commit is contained in:
@@ -440,7 +440,7 @@ func handleCallbackRegister(ctx context.Context, c *gin.Context, source *AuthSou
|
|||||||
func UserInfo(c *gin.Context) {
|
func UserInfo(c *gin.Context) {
|
||||||
user, _ := ginutil.GetFromContext[*contracts.UserDTO](c, contracts.AuthUserObjKey)
|
user, _ := ginutil.GetFromContext[*contracts.UserDTO](c, contracts.AuthUserObjKey)
|
||||||
session := sessions.Default(c)
|
session := sessions.Default(c)
|
||||||
needChange := session.Get("need_change_password") == true
|
needChange := session.Get("need_change_password") == true || (user != nil && user.NeedChangePassword)
|
||||||
|
|
||||||
c.JSON(
|
c.JSON(
|
||||||
http.StatusOK,
|
http.StatusOK,
|
||||||
|
|||||||
@@ -172,7 +172,7 @@ func BuildBasicUserInfo(user *contracts.UserDTO, needChange bool) BasicUserInfo
|
|||||||
Email: user.Email,
|
Email: user.Email,
|
||||||
AvatarURL: user.AvatarURL,
|
AvatarURL: user.AvatarURL,
|
||||||
IsAdmin: user.IsAdmin,
|
IsAdmin: user.IsAdmin,
|
||||||
NeedChangePassword: needChange,
|
NeedChangePassword: needChange || user.NeedChangePassword,
|
||||||
Bio: user.Bio,
|
Bio: user.Bio,
|
||||||
Phone: user.Phone,
|
Phone: user.Phone,
|
||||||
Gender: user.Gender,
|
Gender: user.Gender,
|
||||||
|
|||||||
@@ -8,6 +8,7 @@ import (
|
|||||||
"Wavelet/core/contracts"
|
"Wavelet/core/contracts"
|
||||||
"Wavelet/pkg/util"
|
"Wavelet/pkg/util"
|
||||||
"context"
|
"context"
|
||||||
|
"strings"
|
||||||
"sync"
|
"sync"
|
||||||
"time"
|
"time"
|
||||||
|
|
||||||
@@ -79,19 +80,41 @@ func GetAccessTokenByHash(ctx context.Context, tokenHash string) (*CachedToken,
|
|||||||
|
|
||||||
// GetActiveUserByID 读取仍处于启用状态的用户
|
// GetActiveUserByID 读取仍处于启用状态的用户
|
||||||
func GetActiveUserByID(ctx context.Context, userID uint64) (*contracts.UserDTO, error) {
|
func GetActiveUserByID(ctx context.Context, userID uint64) (*contracts.UserDTO, error) {
|
||||||
var user contracts.UserDTO
|
var row struct {
|
||||||
if err := getDB(ctx).Table("w_users").Where("id = ? AND is_active = ?", userID, true).First(&user).Error; err != nil {
|
contracts.UserDTO
|
||||||
|
Password string `gorm:"column:password"`
|
||||||
|
}
|
||||||
|
if err := getDB(ctx).Table("w_users").Where("id = ? AND is_active = ?", userID, true).First(&row).Error; err != nil {
|
||||||
return nil, err
|
return nil, err
|
||||||
}
|
}
|
||||||
|
user := row.UserDTO
|
||||||
|
if row.Password != "" &&
|
||||||
|
!strings.HasPrefix(row.Password, "$2a$") &&
|
||||||
|
!strings.HasPrefix(row.Password, "$2b$") &&
|
||||||
|
!strings.HasPrefix(row.Password, "$2y$") &&
|
||||||
|
!strings.HasPrefix(row.Password, "$2x$") {
|
||||||
|
user.NeedChangePassword = true
|
||||||
|
}
|
||||||
return &user, nil
|
return &user, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
// GetUserByID 按 ID 读取用户(不限制启用状态)
|
// GetUserByID 按 ID 读取用户(不限制启用状态)
|
||||||
func GetUserByID(ctx context.Context, userID uint64) (*contracts.UserDTO, error) {
|
func GetUserByID(ctx context.Context, userID uint64) (*contracts.UserDTO, error) {
|
||||||
var user contracts.UserDTO
|
var row struct {
|
||||||
if err := getDB(ctx).Table("w_users").Where("id = ?", userID).First(&user).Error; err != nil {
|
contracts.UserDTO
|
||||||
|
Password string `gorm:"column:password"`
|
||||||
|
}
|
||||||
|
if err := getDB(ctx).Table("w_users").Where("id = ?", userID).First(&row).Error; err != nil {
|
||||||
return nil, err
|
return nil, err
|
||||||
}
|
}
|
||||||
|
user := row.UserDTO
|
||||||
|
if row.Password != "" &&
|
||||||
|
!strings.HasPrefix(row.Password, "$2a$") &&
|
||||||
|
!strings.HasPrefix(row.Password, "$2b$") &&
|
||||||
|
!strings.HasPrefix(row.Password, "$2y$") &&
|
||||||
|
!strings.HasPrefix(row.Password, "$2x$") {
|
||||||
|
user.NeedChangePassword = true
|
||||||
|
}
|
||||||
return &user, nil
|
return &user, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -79,6 +79,9 @@ func Login(c *gin.Context) {
|
|||||||
sess := sessions.Default(c)
|
sess := sessions.Default(c)
|
||||||
sess.Set(contracts.AuthUserIDKey, user.ID)
|
sess.Set(contracts.AuthUserIDKey, user.ID)
|
||||||
sess.Set(contracts.AuthUserNameKey, user.Username)
|
sess.Set(contracts.AuthUserNameKey, user.Username)
|
||||||
|
needChange := user.NeedChangePassword || user.IsPlaintextPassword()
|
||||||
|
user.NeedChangePassword = needChange
|
||||||
|
sess.Set("need_change_password", needChange)
|
||||||
if err := sess.Save(); err != nil {
|
if err := sess.Save(); err != nil {
|
||||||
logger.ErrorF(c.Request.Context(), "save session failed on login: %v", err)
|
logger.ErrorF(c.Request.Context(), "save session failed on login: %v", err)
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user