mirror of
https://github.com/Rain-kl/OpenFlare.git
synced 2026-10-05 07:26:36 +08:00
48d414e197
swagger 移除 merchant swagger 改造首页内容为通用后台管理系统定位 - 修改首页标题从 'LINUX DO Credit' 改为 'Modern Platform' - 更新副标题为 '为二次开发而生' - 更新首页描述为通用平台的特点 - 更新首页特性标签为 '开箱即用、高度可扩展、工业级基建' - 修改展示卡片为技术栈和二次开发相关 - 更新开发者示例代码为通用的注册和 API Key 获取示例 - 更新页脚品牌名为 'Modern Platform' - 调整页脚导航链接为通用平台相关内容 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> 去除遗留 裁剪 移除 /api/v1/user/pay-key 相关代码 - 删除后端 UpdatePayKey 处理器函数和 UpdatePayKeyRequest 结构体 - 删除 User 模型中的 PayKey 字段 - 删除 User.VerifyPayKey 方法 - 删除 EncryptPayKeyFailed 错误常量 - 删除 /api/v1/user/pay-key PUT 路由 - 删除 OAuth 返回中的 IsPayKey 字段 - 删除前端 UserService.updatePayKey 方法 - 删除前端所有支付密钥 UI 和逻辑 - 更新相关的导出和注释 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> 去除遗留 api 修正 系统配置 前端裁剪 后端裁剪 init
189 lines
5.8 KiB
Go
189 lines
5.8 KiB
Go
/*
|
|
Copyright 2025 linux.do
|
|
|
|
Licensed under the Apache License, Version 2.0 (the "License");
|
|
you may not use this file except in compliance with the License.
|
|
You may obtain a copy of the License at
|
|
|
|
http://www.apache.org/licenses/LICENSE-2.0
|
|
|
|
Unless required by applicable law or agreed to in writing, software
|
|
distributed under the License is distributed on an "AS IS" BASIS,
|
|
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
See the License for the specific language governing permissions and
|
|
limitations under the License.
|
|
*/
|
|
|
|
package oauth
|
|
|
|
import (
|
|
"fmt"
|
|
"net/http"
|
|
|
|
"github.com/coreos/go-oidc/v3/oidc"
|
|
"github.com/gin-contrib/sessions"
|
|
"github.com/gin-gonic/gin"
|
|
"github.com/google/uuid"
|
|
"github.com/linux-do/credit/internal/config"
|
|
"github.com/linux-do/credit/internal/db"
|
|
"github.com/linux-do/credit/internal/model"
|
|
"github.com/linux-do/credit/internal/util"
|
|
"github.com/shopspring/decimal"
|
|
)
|
|
|
|
// GetLoginURL godoc
|
|
// @Summary 获取登录地址
|
|
// @Description 生成 OAuth 登录 URL,前端跳转至该地址完成授权
|
|
// @Tags oauth
|
|
// @Produce json
|
|
// @Success 200 {object} util.ResponseAny
|
|
// @Router /api/v1/oauth/login [get]
|
|
func GetLoginURL(c *gin.Context) {
|
|
ctx := c.Request.Context()
|
|
|
|
// 生成 state
|
|
state := uuid.NewString()
|
|
cmd := db.Redis.Set(ctx, db.PrefixedKey(fmt.Sprintf(OAuthStateCacheKeyFormat, state)), state, OAuthStateCacheKeyExpiration)
|
|
if cmd.Err() != nil {
|
|
c.JSON(http.StatusInternalServerError, util.Err(cmd.Err().Error()))
|
|
return
|
|
}
|
|
|
|
// 构造登录 URL
|
|
var authURL string
|
|
if config.Config.App.Env == "development" {
|
|
authURL = fmt.Sprintf("%s/login?code=dev_mock_code&state=%s", config.Config.App.FrontendURL, state)
|
|
} else if oidcVerifier != nil {
|
|
// OIDC 模式:state 同时用作 nonce
|
|
authURL = oauthConf.AuthCodeURL(state, oidc.Nonce(state))
|
|
} else {
|
|
// 纯 OAuth2 模式
|
|
authURL = oauthConf.AuthCodeURL(state)
|
|
}
|
|
c.JSON(http.StatusOK, util.OK(authURL))
|
|
}
|
|
|
|
type CallbackRequest struct {
|
|
State string `json:"state"`
|
|
Code string `json:"code"`
|
|
}
|
|
|
|
// Callback godoc
|
|
// @Summary OAuth 回调
|
|
// @Description 接收前端传回的 state 和 code,完成 OAuth/OIDC 认证并建立用户会话
|
|
// @Tags oauth
|
|
// @Accept json
|
|
// @Param request body CallbackRequest true "回调请求参数"
|
|
// @Produce json
|
|
// @Success 200 {object} util.ResponseAny
|
|
// @Router /api/v1/oauth/callback [post]
|
|
func Callback(c *gin.Context) {
|
|
// 解析请求
|
|
var req CallbackRequest
|
|
if err := c.ShouldBindJSON(&req); err != nil {
|
|
c.JSON(http.StatusBadRequest, util.Err(err.Error()))
|
|
return
|
|
}
|
|
|
|
ctx := c.Request.Context()
|
|
|
|
// 验证 state
|
|
cmd := db.Redis.Get(ctx, db.PrefixedKey(fmt.Sprintf(OAuthStateCacheKeyFormat, req.State)))
|
|
if cmd.Val() != req.State {
|
|
c.JSON(http.StatusBadRequest, util.Err(InvalidState))
|
|
return
|
|
}
|
|
db.Redis.Del(ctx, db.PrefixedKey(fmt.Sprintf(OAuthStateCacheKeyFormat, req.State)))
|
|
|
|
// 执行 OAuth/OIDC 认证
|
|
user, err := doOAuth(ctx, req.Code, req.State)
|
|
if err != nil {
|
|
c.JSON(http.StatusInternalServerError, util.Err(err.Error()))
|
|
return
|
|
}
|
|
|
|
session := sessions.Default(c)
|
|
session.Set(UserIDKey, user.ID)
|
|
session.Set(UserNameKey, user.Username)
|
|
if err := session.Save(); err != nil {
|
|
c.JSON(http.StatusInternalServerError, util.Err(err.Error()))
|
|
return
|
|
}
|
|
|
|
LogForAudit(ctx, user, c)
|
|
|
|
c.JSON(http.StatusOK, util.OKNil())
|
|
}
|
|
|
|
type BasicUserInfo struct {
|
|
ID uint64 `json:"id"`
|
|
Username string `json:"username"`
|
|
Nickname string `json:"nickname"`
|
|
TrustLevel model.TrustLevel `json:"trust_level"`
|
|
AvatarUrl string `json:"avatar_url"`
|
|
TotalReceive decimal.Decimal `json:"total_receive"`
|
|
TotalPayment decimal.Decimal `json:"total_payment"`
|
|
TotalTransfer decimal.Decimal `json:"total_transfer"`
|
|
TotalCommunity decimal.Decimal `json:"total_community"`
|
|
CommunityBalance decimal.Decimal `json:"community_balance"`
|
|
AvailableBalance decimal.Decimal `json:"available_balance"`
|
|
PendingBalance decimal.Decimal `json:"pending_balance"`
|
|
PayScore int64 `json:"pay_score"`
|
|
IsAdmin bool `json:"is_admin"`
|
|
RemainQuota decimal.Decimal `json:"remain_quota"`
|
|
PayLevel string `json:"pay_level"`
|
|
DailyLimit *int64 `json:"daily_limit"`
|
|
}
|
|
|
|
// UserInfo godoc
|
|
// @Summary 获取当前登录用户信息
|
|
// @Description 返回当前登录用户的基本信息及余额数据,需要登录
|
|
// @Tags oauth
|
|
// @Produce json
|
|
// @Success 200 {object} util.ResponseAny
|
|
// @Router /api/v1/oauth/user-info [get]
|
|
func UserInfo(c *gin.Context) {
|
|
user, _ := util.GetFromContext[*model.User](c, UserObjKey)
|
|
|
|
c.JSON(
|
|
http.StatusOK,
|
|
util.OK(BasicUserInfo{
|
|
ID: user.ID,
|
|
Username: user.Username,
|
|
Nickname: user.Nickname,
|
|
TrustLevel: user.TrustLevel,
|
|
AvatarUrl: user.AvatarUrl,
|
|
TotalReceive: user.TotalReceive,
|
|
TotalPayment: user.TotalPayment,
|
|
TotalTransfer: user.TotalTransfer,
|
|
TotalCommunity: user.TotalCommunity,
|
|
CommunityBalance: user.CommunityBalance,
|
|
AvailableBalance: user.AvailableBalance,
|
|
PendingBalance: user.PendingBalance,
|
|
PayScore: user.PayScore,
|
|
IsAdmin: user.IsAdmin,
|
|
RemainQuota: decimal.NewFromInt(-1),
|
|
PayLevel: "Free",
|
|
DailyLimit: nil,
|
|
}),
|
|
)
|
|
}
|
|
|
|
// Logout godoc
|
|
// @Summary 退出登录
|
|
// @Description 清除当前用户的登录会话,完成退出
|
|
// @Tags oauth
|
|
// @Produce json
|
|
// @Success 200 {object} util.ResponseAny
|
|
// @Router /api/v1/oauth/logout [get]
|
|
func Logout(c *gin.Context) {
|
|
session := sessions.Default(c)
|
|
session.Options(util.GetSessionOptions(-1))
|
|
session.Clear()
|
|
if err := session.Save(); err != nil {
|
|
c.JSON(http.StatusInternalServerError, util.Err(err.Error()))
|
|
return
|
|
}
|
|
c.JSON(http.StatusOK, util.OKNil())
|
|
}
|