mirror of
https://github.com/OpenListTeam/OpenList.git
synced 2026-10-10 04:53:09 +08:00
chore(handles/auth): improve error response (#2148)
* chore(handles/auth): improve error response Signed-off-by: MadDogOwner <xiaoran@xrgzs.top> * Apply suggestion from @xrgzs Signed-off-by: MadDogOwner <xiaoran@xrgzs.top> --------- Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
This commit is contained in:
@@ -20,7 +20,15 @@ const (
|
|||||||
ADMIN
|
ADMIN
|
||||||
)
|
)
|
||||||
|
|
||||||
const StaticHashSalt = "https://github.com/alist-org/alist"
|
const (
|
||||||
|
StaticHashSalt = "https://github.com/alist-org/alist"
|
||||||
|
|
||||||
|
InvalidUsernameOrPassword = "Invalid username or password"
|
||||||
|
Invalid2FACode = "Invalid 2FA code"
|
||||||
|
TooManyAttempts = "Too many unsuccessful sign-in attempts have been made using an incorrect username or password, Try again later."
|
||||||
|
GuestCannotUpdateProfile = "Guest user can not update profile"
|
||||||
|
GuestCannotGenerate2FA = "Guest user can not generate 2FA code"
|
||||||
|
)
|
||||||
|
|
||||||
var LoginCache = cache.NewMemCache[int]()
|
var LoginCache = cache.NewMemCache[int]()
|
||||||
|
|
||||||
|
|||||||
+10
-9
@@ -45,27 +45,28 @@ func loginHash(c *gin.Context, req *LoginReq) {
|
|||||||
ip := c.ClientIP()
|
ip := c.ClientIP()
|
||||||
count, ok := model.LoginCache.Get(ip)
|
count, ok := model.LoginCache.Get(ip)
|
||||||
if ok && count >= model.DefaultMaxAuthRetries {
|
if ok && count >= model.DefaultMaxAuthRetries {
|
||||||
common.ErrorStrResp(c, "Too many unsuccessful sign-in attempts have been made using an incorrect username or password, Try again later.", 429)
|
common.ErrorStrResp(c, model.TooManyAttempts, 429)
|
||||||
model.LoginCache.Expire(ip, model.DefaultLockDuration)
|
model.LoginCache.Expire(ip, model.DefaultLockDuration)
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
// check username
|
// check username
|
||||||
user, err := op.GetUserByName(req.Username)
|
user, err := op.GetUserByName(req.Username)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
common.ErrorResp(c, err, 400)
|
common.ErrorStrResp(c, model.InvalidUsernameOrPassword, 401)
|
||||||
model.LoginCache.Set(ip, count+1)
|
model.LoginCache.Set(ip, count+1)
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
// validate password hash
|
// validate password hash
|
||||||
if err := user.ValidatePwdStaticHash(req.Password); err != nil {
|
if err := user.ValidatePwdStaticHash(req.Password); err != nil {
|
||||||
common.ErrorResp(c, err, 400)
|
common.ErrorStrResp(c, model.InvalidUsernameOrPassword, 401)
|
||||||
model.LoginCache.Set(ip, count+1)
|
model.LoginCache.Set(ip, count+1)
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
// check 2FA
|
// check 2FA
|
||||||
if user.OtpSecret != "" {
|
if user.OtpSecret != "" {
|
||||||
if !totp.Validate(req.OtpCode, user.OtpSecret) {
|
if !totp.Validate(req.OtpCode, user.OtpSecret) {
|
||||||
common.ErrorStrResp(c, "Invalid 2FA code", 402)
|
// 402 - need opt
|
||||||
|
common.ErrorStrResp(c, model.Invalid2FACode, 402)
|
||||||
model.LoginCache.Set(ip, count+1)
|
model.LoginCache.Set(ip, count+1)
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
@@ -73,7 +74,7 @@ func loginHash(c *gin.Context, req *LoginReq) {
|
|||||||
// generate token
|
// generate token
|
||||||
token, err := common.GenerateToken(user)
|
token, err := common.GenerateToken(user)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
common.ErrorResp(c, err, 400, true)
|
common.ErrorResp(c, err, 500, true)
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
common.SuccessResp(c, gin.H{"token": token})
|
common.SuccessResp(c, gin.H{"token": token})
|
||||||
@@ -107,7 +108,7 @@ func UpdateCurrent(c *gin.Context) {
|
|||||||
}
|
}
|
||||||
user := c.Request.Context().Value(conf.UserKey).(*model.User)
|
user := c.Request.Context().Value(conf.UserKey).(*model.User)
|
||||||
if user.IsGuest() {
|
if user.IsGuest() {
|
||||||
common.ErrorStrResp(c, "Guest user can not update profile", 403)
|
common.ErrorStrResp(c, model.GuestCannotUpdateProfile, 403)
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
user.Username = req.Username
|
user.Username = req.Username
|
||||||
@@ -125,7 +126,7 @@ func UpdateCurrent(c *gin.Context) {
|
|||||||
func Generate2FA(c *gin.Context) {
|
func Generate2FA(c *gin.Context) {
|
||||||
user := c.Request.Context().Value(conf.UserKey).(*model.User)
|
user := c.Request.Context().Value(conf.UserKey).(*model.User)
|
||||||
if user.IsGuest() {
|
if user.IsGuest() {
|
||||||
common.ErrorStrResp(c, "Guest user can not generate 2FA code", 403)
|
common.ErrorStrResp(c, model.GuestCannotGenerate2FA, 403)
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
key, err := totp.Generate(totp.GenerateOpts{
|
key, err := totp.Generate(totp.GenerateOpts{
|
||||||
@@ -164,11 +165,11 @@ func Verify2FA(c *gin.Context) {
|
|||||||
}
|
}
|
||||||
user := c.Request.Context().Value(conf.UserKey).(*model.User)
|
user := c.Request.Context().Value(conf.UserKey).(*model.User)
|
||||||
if user.IsGuest() {
|
if user.IsGuest() {
|
||||||
common.ErrorStrResp(c, "Guest user can not generate 2FA code", 403)
|
common.ErrorStrResp(c, model.GuestCannotGenerate2FA, 403)
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
if !totp.Validate(req.Code, req.Secret) {
|
if !totp.Validate(req.Code, req.Secret) {
|
||||||
common.ErrorStrResp(c, "Invalid 2FA code", 400)
|
common.ErrorStrResp(c, model.Invalid2FACode, 400)
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
user.OtpSecret = req.Secret
|
user.OtpSecret = req.Secret
|
||||||
|
|||||||
Reference in New Issue
Block a user