批量更新
This commit is contained in:
@@ -10,6 +10,7 @@ import (
|
||||
"encoding/base64"
|
||||
"encoding/json"
|
||||
"fmt"
|
||||
"net/url"
|
||||
"strings"
|
||||
"time"
|
||||
|
||||
@@ -262,10 +263,36 @@ func (c *AuthOidcController) UserInfo() {
|
||||
c.fail(500, "server_error")
|
||||
return
|
||||
}
|
||||
|
||||
// 业务接口与前端统一使用 identity_id 作为用户标识
|
||||
account, name, groupID := "", "", uint64(0)
|
||||
if bind, err := authsvc.GetTenantUser(identity.ID, uint64(claims.TenantId)); err == nil {
|
||||
groupID = bind.GroupID
|
||||
if bind.Account != nil {
|
||||
account = *bind.Account
|
||||
}
|
||||
if bind.Name != nil {
|
||||
name = *bind.Name
|
||||
}
|
||||
}
|
||||
if account == "" {
|
||||
account = profile.Mobile
|
||||
}
|
||||
if name == "" {
|
||||
name = profile.Nickname
|
||||
}
|
||||
|
||||
c.serveJSON(map[string]interface{}{
|
||||
"sub": fmt.Sprintf("%d", identity.ID),
|
||||
"union_id": identity.UnionID,
|
||||
"tid": claims.TenantId,
|
||||
"sub": fmt.Sprintf("%d", identity.ID),
|
||||
"id": identity.ID,
|
||||
"union_id": identity.UnionID,
|
||||
"tid": claims.TenantId,
|
||||
// 诊断用:业务接口按 user_type 判定权限(backend / app),
|
||||
// 出现「无权访问」时可先看这里的值是否正确
|
||||
"user_type": claims.UserType,
|
||||
"group_id": groupID,
|
||||
"account": account,
|
||||
"name": name,
|
||||
"nickname": profile.Nickname,
|
||||
"mobile": profile.Mobile,
|
||||
"email": profile.Email,
|
||||
@@ -397,6 +424,46 @@ func allowRedirect(client *models.AuthClient, uri string) bool {
|
||||
return false
|
||||
}
|
||||
|
||||
// allowLogoutRedirect 登出回跳地址校验。
|
||||
//
|
||||
// 先精确匹配白名单,再按 origin(协议+主机+端口)放宽匹配:
|
||||
// 实际使用中「末尾斜杠」「带 #/login 片段」等差异很常见,
|
||||
// 只做精确匹配会导致明明同域却跳不回去,因此同域即放行。
|
||||
func allowLogoutRedirect(client *models.AuthClient, uri string) bool {
|
||||
raw := ""
|
||||
if client.PostLogoutURIs != nil {
|
||||
raw = *client.PostLogoutURIs
|
||||
}
|
||||
var list []string
|
||||
if raw != "" {
|
||||
_ = json.Unmarshal([]byte(raw), &list)
|
||||
}
|
||||
if len(list) == 0 {
|
||||
return false
|
||||
}
|
||||
target := strings.TrimSpace(uri)
|
||||
for _, item := range list {
|
||||
if strings.TrimSpace(item) == target {
|
||||
return true
|
||||
}
|
||||
}
|
||||
|
||||
targetURL, err := url.Parse(target)
|
||||
if err != nil || targetURL.Scheme == "" || targetURL.Host == "" {
|
||||
return false
|
||||
}
|
||||
for _, item := range list {
|
||||
base, err := url.Parse(strings.TrimSpace(item))
|
||||
if err != nil || base.Scheme == "" || base.Host == "" {
|
||||
continue
|
||||
}
|
||||
if base.Scheme == targetURL.Scheme && base.Host == targetURL.Host {
|
||||
return true
|
||||
}
|
||||
}
|
||||
return false
|
||||
}
|
||||
|
||||
// issueAuthCode 生成一次性授权码(明文返回,库中只存哈希)
|
||||
func issueAuthCode(clientID string, identityID, tid uint64, redirectURI, challenge, method, scope, nonce string) (string, error) {
|
||||
plain, err := randomString(32)
|
||||
|
||||
Reference in New Issue
Block a user