router_login.go 13.4 KB
Newer Older
U
UlricQin 已提交
1 2 3 4 5
package router

import (
	"fmt"
	"net/http"
U
Ulric Qin 已提交
6
	"strconv"
U
UlricQin 已提交
7
	"strings"
Y
Yening Qin 已提交
8
	"time"
U
UlricQin 已提交
9

N
ning 已提交
10 11 12 13 14 15 16
	"github.com/ccfos/nightingale/v6/models"
	"github.com/ccfos/nightingale/v6/pkg/cas"
	"github.com/ccfos/nightingale/v6/pkg/ldapx"
	"github.com/ccfos/nightingale/v6/pkg/oauth2x"
	"github.com/ccfos/nightingale/v6/pkg/oidcx"
	"github.com/pelletier/go-toml/v2"

U
UlricQin 已提交
17 18 19
	"github.com/dgrijalva/jwt-go"
	"github.com/gin-gonic/gin"
	"github.com/toolkits/pkg/ginx"
Y
Yening Qin 已提交
20
	"github.com/toolkits/pkg/logger"
U
UlricQin 已提交
21 22 23 24 25 26 27
)

type loginForm struct {
	Username string `json:"username" binding:"required"`
	Password string `json:"password" binding:"required"`
}

N
ning 已提交
28
func (rt *Router) loginPost(c *gin.Context) {
U
UlricQin 已提交
29 30 31
	var f loginForm
	ginx.BindJSON(c, &f)

N
ning 已提交
32
	user, err := models.PassLogin(rt.Ctx, f.Username, f.Password)
U
UlricQin 已提交
33 34
	if err != nil {
		// pass validate fail, try ldap
N
ning 已提交
35 36 37
		if rt.Center.LDAP.Enable {
			roles := strings.Join(rt.Center.LDAP.DefaultRoles, " ")
			user, err = models.LdapLogin(rt.Ctx, f.Username, f.Password, roles, rt.Sso.LDAP)
U
UlricQin 已提交
38
			if err != nil {
N
ning 已提交
39
				logger.Debugf("ldap login failed: %v username: %s", err, f.Username)
U
UlricQin 已提交
40 41 42
				ginx.NewRender(c).Message(err)
				return
			}
N
ning 已提交
43
			user.RolesLst = rt.Center.LDAP.DefaultRoles
U
UlricQin 已提交
44 45 46 47 48 49 50 51 52 53 54 55 56 57
		} else {
			ginx.NewRender(c).Message(err)
			return
		}
	}

	if user == nil {
		// Theoretically impossible
		ginx.NewRender(c).Message("Username or password invalid")
		return
	}

	userIdentity := fmt.Sprintf("%d-%s", user.Id, user.Username)

N
ning 已提交
58
	ts, err := rt.createTokens(rt.Center.JWTAuth.SigningKey, userIdentity)
U
UlricQin 已提交
59
	ginx.Dangerous(err)
N
ning 已提交
60
	ginx.Dangerous(rt.createAuth(c.Request.Context(), userIdentity, ts))
U
UlricQin 已提交
61 62 63 64 65 66 67 68

	ginx.NewRender(c).Data(gin.H{
		"user":          user,
		"access_token":  ts.AccessToken,
		"refresh_token": ts.RefreshToken,
	}, nil)
}

N
ning 已提交
69 70
func (rt *Router) logoutPost(c *gin.Context) {
	metadata, err := rt.extractTokenMetadata(c.Request)
U
UlricQin 已提交
71 72 73 74 75
	if err != nil {
		ginx.NewRender(c, http.StatusBadRequest).Message("failed to parse jwt token")
		return
	}

N
ning 已提交
76
	delErr := rt.deleteTokens(c.Request.Context(), metadata)
U
UlricQin 已提交
77
	if delErr != nil {
78
		ginx.NewRender(c).Message(http.StatusText(http.StatusInternalServerError))
U
UlricQin 已提交
79 80 81 82 83 84 85 86 87 88
		return
	}

	ginx.NewRender(c).Message("")
}

type refreshForm struct {
	RefreshToken string `json:"refresh_token" binding:"required"`
}

N
ning 已提交
89
func (rt *Router) refreshPost(c *gin.Context) {
U
UlricQin 已提交
90 91 92 93 94 95 96 97
	var f refreshForm
	ginx.BindJSON(c, &f)

	// verify the token
	token, err := jwt.Parse(f.RefreshToken, func(token *jwt.Token) (interface{}, error) {
		if _, ok := token.Method.(*jwt.SigningMethodHMAC); !ok {
			return nil, fmt.Errorf("unexpected jwt signing method: %v", token.Header["alg"])
		}
N
ning 已提交
98
		return []byte(rt.Center.JWTAuth.SigningKey), nil
U
UlricQin 已提交
99 100 101 102 103
	})

	// if there is an error, the token must have expired
	if err != nil {
		// redirect to login page
U
UlricQin 已提交
104
		ginx.NewRender(c, http.StatusUnauthorized).Message("refresh token expired")
U
UlricQin 已提交
105 106 107 108 109 110 111 112 113
		return
	}

	// Since token is valid, get the uuid:
	claims, ok := token.Claims.(jwt.MapClaims) //the token claims should conform to MapClaims
	if ok && token.Valid {
		refreshUuid, ok := claims["refresh_uuid"].(string) //convert the interface to string
		if !ok {
			// Theoretically impossible
U
UlricQin 已提交
114
			ginx.NewRender(c, http.StatusUnauthorized).Message("failed to parse refresh_uuid from jwt")
U
UlricQin 已提交
115 116 117 118 119 120
			return
		}

		userIdentity, ok := claims["user_identity"].(string)
		if !ok {
			// Theoretically impossible
U
UlricQin 已提交
121
			ginx.NewRender(c, http.StatusUnauthorized).Message("failed to parse user_identity from jwt")
U
UlricQin 已提交
122 123 124
			return
		}

U
Ulric Qin 已提交
125 126 127 128 129 130
		userid, err := strconv.ParseInt(strings.Split(userIdentity, "-")[0], 10, 64)
		if err != nil {
			ginx.NewRender(c, http.StatusUnauthorized).Message("failed to parse user_identity from jwt")
			return
		}

N
ning 已提交
131
		u, err := models.UserGetById(rt.Ctx, userid)
U
Ulric Qin 已提交
132 133 134 135 136 137 138 139 140 141 142
		if err != nil {
			ginx.NewRender(c, http.StatusInternalServerError).Message("failed to query user by id")
			return
		}

		if u == nil {
			// user already deleted
			ginx.NewRender(c, http.StatusUnauthorized).Message("user already deleted")
			return
		}

U
UlricQin 已提交
143
		// Delete the previous Refresh Token
N
ning 已提交
144
		err = rt.deleteAuth(c.Request.Context(), refreshUuid)
U
UlricQin 已提交
145
		if err != nil {
146
			ginx.NewRender(c, http.StatusUnauthorized).Message(http.StatusText(http.StatusInternalServerError))
U
UlricQin 已提交
147 148 149 150
			return
		}

		// Delete previous Access Token
N
ning 已提交
151
		rt.deleteAuth(c.Request.Context(), strings.Split(refreshUuid, "++")[0])
U
UlricQin 已提交
152 153

		// Create new pairs of refresh and access tokens
N
ning 已提交
154
		ts, err := rt.createTokens(rt.Center.JWTAuth.SigningKey, userIdentity)
U
UlricQin 已提交
155
		ginx.Dangerous(err)
N
ning 已提交
156
		ginx.Dangerous(rt.createAuth(c.Request.Context(), userIdentity, ts))
U
UlricQin 已提交
157 158 159 160 161 162 163

		ginx.NewRender(c).Data(gin.H{
			"access_token":  ts.AccessToken,
			"refresh_token": ts.RefreshToken,
		}, nil)
	} else {
		// redirect to login page
U
UlricQin 已提交
164
		ginx.NewRender(c, http.StatusUnauthorized).Message("refresh token expired")
U
UlricQin 已提交
165 166
	}
}
Y
Yening Qin 已提交
167

N
ning 已提交
168
func (rt *Router) loginRedirect(c *gin.Context) {
Y
Yening Qin 已提交
169 170
	redirect := ginx.QueryStr(c, "redirect", "/")

H
Henry Chia 已提交
171 172
	v, exists := c.Get("userid")
	if exists {
Y
Yening Qin 已提交
173
		userid := v.(int64)
N
ning 已提交
174
		user, err := models.UserGetById(rt.Ctx, userid)
Y
Yening Qin 已提交
175 176 177 178 179
		ginx.Dangerous(err)
		if user == nil {
			ginx.Bomb(200, "user not found")
		}

H
Henry Chia 已提交
180
		if user.Username != "" { // already login
Y
Yening Qin 已提交
181 182 183 184 185
			ginx.NewRender(c).Data(redirect, nil)
			return
		}
	}

N
ning 已提交
186
	if !rt.Center.OIDC.Enable {
Y
Yening Qin 已提交
187 188 189 190
		ginx.NewRender(c).Data("", nil)
		return
	}

N
ning 已提交
191
	redirect, err := rt.Sso.OIDC.Authorize(rt.Redis, redirect)
Y
Yening Qin 已提交
192 193 194 195 196 197 198 199 200 201 202 203
	ginx.Dangerous(err)

	ginx.NewRender(c).Data(redirect, err)
}

type CallbackOutput struct {
	Redirect     string       `json:"redirect"`
	User         *models.User `json:"user"`
	AccessToken  string       `json:"access_token"`
	RefreshToken string       `json:"refresh_token"`
}

N
ning 已提交
204
func (rt *Router) loginCallback(c *gin.Context) {
Y
Yening Qin 已提交
205 206 207
	code := ginx.QueryStr(c, "code", "")
	state := ginx.QueryStr(c, "state", "")

N
ning 已提交
208
	ret, err := rt.Sso.OIDC.Callback(rt.Redis, c.Request.Context(), code, state)
Y
Yening Qin 已提交
209 210 211 212 213 214
	if err != nil {
		logger.Debugf("sso.callback() get ret %+v error %v", ret, err)
		ginx.NewRender(c).Data(CallbackOutput{}, err)
		return
	}

N
ning 已提交
215
	user, err := models.UserGet(rt.Ctx, "username=?", ret.Username)
Y
Yening Qin 已提交
216 217 218
	ginx.Dangerous(err)

	if user != nil {
N
ning 已提交
219
		if rt.Center.OIDC.CoverAttributes {
U
Ulric Qin 已提交
220 221 222 223 224 225 226
			if ret.Nickname != "" {
				user.Nickname = ret.Nickname
			}

			if ret.Email != "" {
				user.Email = ret.Email
			}
Y
Yening Qin 已提交
227

U
Ulric Qin 已提交
228 229 230 231 232
			if ret.Phone != "" {
				user.Phone = ret.Phone
			}

			user.UpdateAt = time.Now().Unix()
N
ning 已提交
233
			user.Update(rt.Ctx, "email", "nickname", "phone", "update_at")
Y
Yening Qin 已提交
234 235 236 237 238 239 240 241 242 243
		}
	} else {
		now := time.Now().Unix()
		user = &models.User{
			Username: ret.Username,
			Password: "******",
			Nickname: ret.Nickname,
			Phone:    ret.Phone,
			Email:    ret.Email,
			Portrait: "",
N
ning 已提交
244 245
			Roles:    strings.Join(rt.Center.OIDC.DefaultRoles, " "),
			RolesLst: rt.Center.OIDC.DefaultRoles,
Y
Yening Qin 已提交
246 247 248 249 250 251 252 253
			Contacts: []byte("{}"),
			CreateAt: now,
			UpdateAt: now,
			CreateBy: "oidc",
			UpdateBy: "oidc",
		}

		// create user from oidc
N
ning 已提交
254
		ginx.Dangerous(user.Add(rt.Ctx))
Y
Yening Qin 已提交
255 256 257 258
	}

	// set user login state
	userIdentity := fmt.Sprintf("%d-%s", user.Id, user.Username)
N
ning 已提交
259
	ts, err := rt.createTokens(rt.Center.JWTAuth.SigningKey, userIdentity)
Y
Yening Qin 已提交
260
	ginx.Dangerous(err)
N
ning 已提交
261
	ginx.Dangerous(rt.createAuth(c.Request.Context(), userIdentity, ts))
Y
Yening Qin 已提交
262 263 264 265 266 267 268 269 270 271 272 273 274

	redirect := "/"
	if ret.Redirect != "/login" {
		redirect = ret.Redirect
	}

	ginx.NewRender(c).Data(CallbackOutput{
		Redirect:     redirect,
		User:         user,
		AccessToken:  ts.AccessToken,
		RefreshToken: ts.RefreshToken,
	}, nil)
}
4
47 已提交
275 276 277 278 279 280

type RedirectOutput struct {
	Redirect string `json:"redirect"`
	State    string `json:"state"`
}

N
ning 已提交
281
func (rt *Router) loginRedirectCas(c *gin.Context) {
4
47 已提交
282 283 284 285 286
	redirect := ginx.QueryStr(c, "redirect", "/")

	v, exists := c.Get("userid")
	if exists {
		userid := v.(int64)
N
ning 已提交
287
		user, err := models.UserGetById(rt.Ctx, userid)
4
47 已提交
288 289 290 291 292 293 294 295 296 297 298
		ginx.Dangerous(err)
		if user == nil {
			ginx.Bomb(200, "user not found")
		}

		if user.Username != "" { // already login
			ginx.NewRender(c).Data(redirect, nil)
			return
		}
	}

N
ning 已提交
299
	if !rt.Center.CAS.Enable {
4
47 已提交
300 301 302 303 304
		logger.Error("cas is not enable")
		ginx.NewRender(c).Data("", nil)
		return
	}

N
ning 已提交
305
	redirect, state, err := rt.Sso.CAS.Authorize(rt.Redis, redirect)
4
47 已提交
306 307 308 309 310 311 312 313

	ginx.Dangerous(err)
	ginx.NewRender(c).Data(RedirectOutput{
		Redirect: redirect,
		State:    state,
	}, err)
}

N
ning 已提交
314
func (rt *Router) loginCallbackCas(c *gin.Context) {
4
47 已提交
315 316
	ticket := ginx.QueryStr(c, "ticket", "")
	state := ginx.QueryStr(c, "state", "")
N
ning 已提交
317
	ret, err := rt.Sso.CAS.ValidateServiceTicket(c.Request.Context(), ticket, state, rt.Redis)
4
47 已提交
318 319 320 321 322
	if err != nil {
		logger.Errorf("ValidateServiceTicket: %s", err)
		ginx.NewRender(c).Data("", err)
		return
	}
N
ning 已提交
323
	user, err := models.UserGet(rt.Ctx, "username=?", ret.Username)
4
47 已提交
324 325 326 327 328
	if err != nil {
		logger.Errorf("UserGet: %s", err)
	}
	ginx.Dangerous(err)
	if user != nil {
N
ning 已提交
329
		if rt.Center.CAS.CoverAttributes {
U
Ulric Qin 已提交
330 331 332 333 334 335 336 337 338 339 340 341
			if ret.Nickname != "" {
				user.Nickname = ret.Nickname
			}

			if ret.Email != "" {
				user.Email = ret.Email
			}

			if ret.Phone != "" {
				user.Phone = ret.Phone
			}

4
47 已提交
342
			user.UpdateAt = time.Now().Unix()
N
ning 已提交
343
			ginx.Dangerous(user.Update(rt.Ctx, "email", "nickname", "phone", "update_at"))
4
47 已提交
344 345 346 347 348 349 350 351
		}
	} else {
		now := time.Now().Unix()
		user = &models.User{
			Username: ret.Username,
			Password: "******",
			Nickname: ret.Nickname,
			Portrait: "",
N
ning 已提交
352 353
			Roles:    strings.Join(rt.Center.CAS.DefaultRoles, " "),
			RolesLst: rt.Center.CAS.DefaultRoles,
4
47 已提交
354 355 356 357 358 359 360 361 362
			Contacts: []byte("{}"),
			Phone:    ret.Phone,
			Email:    ret.Email,
			CreateAt: now,
			UpdateAt: now,
			CreateBy: "CAS",
			UpdateBy: "CAS",
		}
		// create user from cas
N
ning 已提交
363
		ginx.Dangerous(user.Add(rt.Ctx))
4
47 已提交
364 365 366 367
	}

	// set user login state
	userIdentity := fmt.Sprintf("%d-%s", user.Id, user.Username)
N
ning 已提交
368
	ts, err := rt.createTokens(rt.Center.JWTAuth.SigningKey, userIdentity)
4
47 已提交
369 370 371 372
	if err != nil {
		logger.Errorf("createTokens: %s", err)
	}
	ginx.Dangerous(err)
N
ning 已提交
373
	ginx.Dangerous(rt.createAuth(c.Request.Context(), userIdentity, ts))
4
47 已提交
374 375 376 377 378 379 380 381 382 383 384 385 386

	redirect := "/"
	if ret.Redirect != "/login" {
		redirect = ret.Redirect
	}
	ginx.NewRender(c).Data(CallbackOutput{
		Redirect:     redirect,
		User:         user,
		AccessToken:  ts.AccessToken,
		RefreshToken: ts.RefreshToken,
	}, nil)
}

N
ning 已提交
387
func (rt *Router) loginRedirectOAuth(c *gin.Context) {
4
47 已提交
388 389 390 391 392
	redirect := ginx.QueryStr(c, "redirect", "/")

	v, exists := c.Get("userid")
	if exists {
		userid := v.(int64)
N
ning 已提交
393
		user, err := models.UserGetById(rt.Ctx, userid)
4
47 已提交
394 395 396 397 398 399 400 401 402 403 404
		ginx.Dangerous(err)
		if user == nil {
			ginx.Bomb(200, "user not found")
		}

		if user.Username != "" { // already login
			ginx.NewRender(c).Data(redirect, nil)
			return
		}
	}

N
ning 已提交
405
	if !rt.Center.OAuth.Enable {
4
47 已提交
406 407 408 409
		ginx.NewRender(c).Data("", nil)
		return
	}

N
ning 已提交
410
	redirect, err := rt.Sso.OAuth2.Authorize(rt.Redis, redirect)
4
47 已提交
411 412 413 414 415
	ginx.Dangerous(err)

	ginx.NewRender(c).Data(redirect, err)
}

N
ning 已提交
416
func (rt *Router) loginCallbackOAuth(c *gin.Context) {
4
47 已提交
417 418 419
	code := ginx.QueryStr(c, "code", "")
	state := ginx.QueryStr(c, "state", "")

N
ning 已提交
420
	ret, err := rt.Sso.OAuth2.Callback(rt.Redis, c.Request.Context(), code, state)
4
47 已提交
421 422 423 424 425 426
	if err != nil {
		logger.Debugf("sso.callback() get ret %+v error %v", ret, err)
		ginx.NewRender(c).Data(CallbackOutput{}, err)
		return
	}

N
ning 已提交
427
	user, err := models.UserGet(rt.Ctx, "username=?", ret.Username)
4
47 已提交
428 429 430
	ginx.Dangerous(err)

	if user != nil {
N
ning 已提交
431
		if rt.Center.OAuth.CoverAttributes {
U
Ulric Qin 已提交
432 433 434 435 436 437 438 439 440 441 442
			if ret.Nickname != "" {
				user.Nickname = ret.Nickname
			}

			if ret.Email != "" {
				user.Email = ret.Email
			}

			if ret.Phone != "" {
				user.Phone = ret.Phone
			}
4
47 已提交
443

U
Ulric Qin 已提交
444
			user.UpdateAt = time.Now().Unix()
N
ning 已提交
445
			user.Update(rt.Ctx, "email", "nickname", "phone", "update_at")
4
47 已提交
446 447 448 449 450 451 452 453 454 455
		}
	} else {
		now := time.Now().Unix()
		user = &models.User{
			Username: ret.Username,
			Password: "******",
			Nickname: ret.Nickname,
			Phone:    ret.Phone,
			Email:    ret.Email,
			Portrait: "",
N
ning 已提交
456 457
			Roles:    strings.Join(rt.Center.OAuth.DefaultRoles, " "),
			RolesLst: rt.Center.OAuth.DefaultRoles,
4
47 已提交
458 459 460 461 462 463 464 465
			Contacts: []byte("{}"),
			CreateAt: now,
			UpdateAt: now,
			CreateBy: "oauth2",
			UpdateBy: "oauth2",
		}

		// create user from oidc
N
ning 已提交
466
		ginx.Dangerous(user.Add(rt.Ctx))
4
47 已提交
467 468 469 470
	}

	// set user login state
	userIdentity := fmt.Sprintf("%d-%s", user.Id, user.Username)
N
ning 已提交
471
	ts, err := rt.createTokens(rt.Center.JWTAuth.SigningKey, userIdentity)
4
47 已提交
472
	ginx.Dangerous(err)
N
ning 已提交
473
	ginx.Dangerous(rt.createAuth(c.Request.Context(), userIdentity, ts))
4
47 已提交
474 475 476 477 478 479 480 481 482 483 484 485 486 487 488 489 490 491 492 493

	redirect := "/"
	if ret.Redirect != "/login" {
		redirect = ret.Redirect
	}

	ginx.NewRender(c).Data(CallbackOutput{
		Redirect:     redirect,
		User:         user,
		AccessToken:  ts.AccessToken,
		RefreshToken: ts.RefreshToken,
	}, nil)
}

type SsoConfigOutput struct {
	OidcDisplayName  string `json:"oidcDisplayName"`
	CasDisplayName   string `json:"casDisplayName"`
	OauthDisplayName string `json:"oauthDisplayName"`
}

N
ning 已提交
494
func (rt *Router) ssoConfigNameGet(c *gin.Context) {
4
47 已提交
495
	ginx.NewRender(c).Data(SsoConfigOutput{
N
ning 已提交
496 497 498
		OidcDisplayName:  rt.Sso.OIDC.GetDisplayName(),
		CasDisplayName:   rt.Sso.CAS.GetDisplayName(),
		OauthDisplayName: rt.Sso.OAuth2.GetDisplayName(),
4
47 已提交
499 500
	}, nil)
}
N
ning 已提交
501 502 503 504 505 506 507 508 509 510 511 512 513 514 515 516 517 518 519 520 521 522 523 524 525 526 527 528 529 530 531 532 533 534 535 536 537 538 539

func (rt *Router) ssoConfigGets(c *gin.Context) {
	ginx.NewRender(c).Data(models.SsoConfigGets(rt.Ctx))
}

func (rt *Router) ssoConfigUpdate(c *gin.Context) {
	var f models.SsoConfig
	ginx.BindJSON(c, &f)

	err := f.Update(rt.Ctx)
	ginx.Dangerous(err)

	switch f.Name {
	case "LDAP":
		var config ldapx.Config
		err := toml.Unmarshal([]byte(f.Content), &config)
		ginx.Dangerous(err)
		rt.Sso.LDAP.Reload(config)
	case "OIDC":
		var config oidcx.Config
		err := toml.Unmarshal([]byte(f.Content), &config)
		ginx.Dangerous(err)

		err = rt.Sso.OIDC.Reload(config)
		ginx.Bomb(200, "oidc init error: %v", err)
	case "CAS":
		var config cas.Config
		err := toml.Unmarshal([]byte(f.Content), &config)
		ginx.Dangerous(err)
		rt.Sso.CAS.Reload(config)
	case "OAuth2":
		var config oauth2x.Config
		err := toml.Unmarshal([]byte(f.Content), &config)
		ginx.Dangerous(err)
		rt.Sso.OAuth2.Reload(config)
	}

	ginx.NewRender(c).Message(nil)
}