user_service.go 6.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287
  1. package ldap
  2. import (
  3. "errors"
  4. "fmt"
  5. "github.com/astaxie/beego/logs"
  6. "github.com/astaxie/beego/orm"
  7. "github.com/go-ldap/ldap/v3"
  8. "nginx-ui/server/config"
  9. "nginx-ui/server/models"
  10. )
  11. type UserService struct {
  12. }
  13. // Add Update 保存或者修改
  14. func (c *UserService) Add(body *models.LdapUser) (*models.LdapUser, error) {
  15. server := models.LdapServer{
  16. Key: body.ServerKey,
  17. }
  18. o := orm.NewOrm()
  19. err := o.Read(&server, "Key")
  20. if err != nil {
  21. return nil, err
  22. }
  23. body.Uid = server.Uid
  24. exist := models.LdapUser{
  25. Account: body.Account,
  26. }
  27. isNew := false
  28. err = o.Read(&exist, "Account")
  29. if err != nil && errors.Is(err, orm.ErrNoRows) {
  30. _, err = o.Insert(body)
  31. isNew = true
  32. } else if err != nil {
  33. return nil, err
  34. } else {
  35. body.Id = exist.Id
  36. _, err = o.Update(body)
  37. }
  38. if err != nil {
  39. return nil, err
  40. }
  41. client, err := GetActiveClient(&server)
  42. if err != nil {
  43. return nil, err
  44. }
  45. err = client.Add(body)
  46. if err != nil {
  47. return nil, err
  48. }
  49. if body.Password != config.ReplacePassword {
  50. err := client.ModifyPasswordByAdmin(body.DN, body.Password)
  51. if err != nil {
  52. return nil, errors.New("新增成功,但密码修改失败!")
  53. }
  54. if isNew {
  55. SendUserAddEmail(body, body.Password)
  56. }
  57. }
  58. entry, err := client.SearchByAccount(body.Account)
  59. if err != nil {
  60. return nil, err
  61. }
  62. modifyLDAPUser(body, entry)
  63. _, _ = o.Update(body)
  64. return body, nil
  65. }
  66. // get /ldap/users
  67. func (c *UserService) GetDetail(id int) (*models.LdapUser, error) {
  68. o := orm.NewOrm()
  69. user := models.LdapUser{Id: id}
  70. err := o.Read(&user, "Id")
  71. if err != nil {
  72. return nil, err
  73. }
  74. user.Password = config.ReplacePassword
  75. return &user, nil
  76. }
  77. func (c *UserService) GetByAccount(account string) (*models.LdapUser, error) {
  78. o := orm.NewOrm()
  79. user := models.LdapUser{Account: account}
  80. err := o.Read(&user, "Account")
  81. if err != nil {
  82. return nil, err
  83. }
  84. user.Password = config.ReplacePassword
  85. return &user, nil
  86. }
  87. func (c *UserService) Search(server *models.LdapServer, filter string) ([]*models.LdapUser, []*models.LdapOrganize, error) {
  88. client, err := GetActiveClient(server)
  89. if err != nil {
  90. return nil, nil, err
  91. }
  92. entries, err := client.Search(filter)
  93. if err != nil {
  94. return nil, nil, err
  95. }
  96. var users []*models.LdapUser
  97. var organizeList []*models.LdapOrganize
  98. for _, entry := range entries {
  99. var isOrganize = false
  100. objectClass := entry.GetAttributeValues("objectClass")
  101. for _, oc := range objectClass {
  102. if oc == server.OrganizeClass || oc == "organization" {
  103. isOrganize = true
  104. break
  105. }
  106. }
  107. if isOrganize {
  108. organize := models.LdapOrganize{
  109. Name: entry.GetAttributeValue("ou"),
  110. DN: entry.DN,
  111. ServerKey: server.Key,
  112. ObjectClass: entry.GetAttributeValue("objectClass"),
  113. }
  114. organizeList = append(organizeList, &organize)
  115. } else {
  116. user := createUser(entry)
  117. user.ServerKey = server.Key
  118. users = append(users, &user)
  119. }
  120. }
  121. return users, organizeList, nil
  122. }
  123. // SyncUser SyncUsers 同步用户信息
  124. // post /ldap/user/sync
  125. func (c *UserService) SyncUser(server *models.LdapServer, current *models.LdapUser) error {
  126. o := orm.NewOrm()
  127. if server == nil {
  128. server := &models.LdapServer{Key: current.ServerKey}
  129. err := o.Read(server, "Key")
  130. if err != nil {
  131. return err
  132. }
  133. }
  134. filter := fmt.Sprintf("(&(objectClass=*)(uid=%s))", current.Account)
  135. users, _, err := c.Search(server, filter)
  136. if len(users) != 1 {
  137. return errors.New("账号不存在或者账号重复!")
  138. }
  139. user := users[0]
  140. user.Id = current.Id
  141. user.ServerKey = current.ServerKey
  142. user.Uid = current.Uid
  143. user.Remark = current.Remark
  144. _, err = o.Update(user)
  145. if err != nil {
  146. return err
  147. }
  148. return nil
  149. }
  150. // SyncUsers 同步用户信息
  151. // post /ldap/user/sync
  152. func (c *UserService) SyncUsers(current *models.User, req *LDAPUserSyncReq) (int, error) {
  153. server := &models.LdapServer{Key: req.ServerKey}
  154. o := orm.NewOrm()
  155. err := o.Read(server, "Key")
  156. if err != nil {
  157. return 0, err
  158. }
  159. users, organizeList, err := c.Search(server, req.Filter)
  160. if err != nil {
  161. return 0, err
  162. }
  163. for _, user := range users {
  164. user.Uid = string(rune(current.Id))
  165. _, err := models.InsertOrUpdate[models.LdapUser](o, user, "DN")
  166. if err != nil {
  167. logs.Error("save user fail: %v", err)
  168. }
  169. }
  170. for _, organize := range organizeList {
  171. _, err = models.InsertOrUpdate[models.LdapOrganize](o, organize, "DN")
  172. if err != nil {
  173. logs.Error("save organize fail: %v", err)
  174. }
  175. }
  176. return len(users), nil
  177. }
  178. func (c *UserService) Authentication(server *models.LdapServer, account string, password string) (*models.User, error) {
  179. o := orm.NewOrm()
  180. ldapUser := &models.LdapUser{
  181. Account: account,
  182. }
  183. err := o.Read(ldapUser, "Account")
  184. if err != nil && !errors.Is(err, orm.ErrNoRows) {
  185. return nil, err
  186. } else if err != nil {
  187. // The username and password we want to check
  188. filter := fmt.Sprintf("(&(objectClass=*)(uid=%s))", ldap.EscapeFilter(account))
  189. users, _, err := c.Search(server, filter)
  190. if err != nil || len(users) != 1 {
  191. logs.Error("search fail: %v", err)
  192. return nil, errors.New("您输入的账号或者密码错误!")
  193. }
  194. ldapUser = users[0]
  195. _, err = models.InsertOrUpdate[models.LdapUser](o, ldapUser, "DN")
  196. if err != nil {
  197. return nil, err
  198. }
  199. }
  200. userDN := ldapUser.DN
  201. client, err := GetActiveClient(server)
  202. if err != nil {
  203. return nil, err
  204. }
  205. err = client.Authentication(userDN, password)
  206. if err != nil {
  207. return nil, err
  208. }
  209. user := &models.User{
  210. Account: account,
  211. }
  212. err = o.Read(user, "Account")
  213. if err != nil && !errors.Is(err, orm.ErrNoRows) {
  214. return nil, err
  215. } else if err != nil {
  216. CreateLocalUser(user, ldapUser)
  217. _, err = o.Insert(user)
  218. if err != nil {
  219. return nil, err
  220. }
  221. } else if user.Source == "LDAP" {
  222. user.Nickname = ldapUser.UserName
  223. _, _ = o.Update(user, "Nickname")
  224. }
  225. return user, nil
  226. }
  227. // UpdateUserPassword 更新用户密码
  228. // post /ldap/user/modifyPassword
  229. func (c *UserService) UpdateUserPassword(req *UpdatePasswordReq, byAdmin bool) error {
  230. o := orm.NewOrm()
  231. user := models.LdapUser{
  232. Account: req.Account,
  233. }
  234. err := o.Read(&user, "Account")
  235. if err != nil {
  236. if errors.Is(err, orm.ErrNoRows) {
  237. return nil
  238. }
  239. logs.Error("read user fail: %v", err)
  240. return err
  241. }
  242. server := models.LdapServer{
  243. Key: user.ServerKey,
  244. }
  245. err = o.Read(&server, "Key")
  246. if err != nil {
  247. return err
  248. }
  249. client, err := GetActiveClient(&server)
  250. if err != nil {
  251. return err
  252. }
  253. if byAdmin {
  254. err = client.ModifyPasswordByAdmin(user.DN, req.Password)
  255. } else {
  256. err = client.ModifyPassword(user.DN, req.OldPassword, req.Password)
  257. }
  258. if err != nil {
  259. return err
  260. }
  261. err = c.SyncUser(&server, &user)
  262. if err != nil {
  263. return errors.New("密码更新成功,但更新用户信息失败:" + err.Error())
  264. }
  265. return nil
  266. }