做统一认证登录
This commit is contained in:
@@ -0,0 +1,94 @@
|
||||
package models
|
||||
|
||||
import "time"
|
||||
|
||||
// 会话吊销原因
|
||||
const (
|
||||
RevokeReasonLogout = "logout" // 用户主动登出
|
||||
RevokeReasonKicked = "kicked" // 被新登录踢下线(1号1机)
|
||||
RevokeReasonAdmin = "admin" // 管理员强制下线
|
||||
RevokeReasonExpired = "expired" // 过期清理
|
||||
)
|
||||
|
||||
// AuthSession 登录会话:yz_auth_session
|
||||
// 用于「1号1机」并发控制、在线设备列表、强制下线。
|
||||
type AuthSession struct {
|
||||
ID uint64 `orm:"column(id);pk;auto" json:"id"`
|
||||
Sid string `orm:"column(sid);size(64)" json:"sid"`
|
||||
IdentityID uint64 `orm:"column(identity_id)" json:"identity_id"`
|
||||
Tid uint64 `orm:"column(tid);default(0)" json:"tid"`
|
||||
ClientID string `orm:"column(client_id);size(64);default('')" json:"client_id"`
|
||||
DeviceID *string `orm:"column(device_id);size(64);null" json:"device_id"`
|
||||
DeviceName *string `orm:"column(device_name);size(128);null" json:"device_name"`
|
||||
IP *string `orm:"column(ip);size(45);null" json:"ip"`
|
||||
UserAgent *string `orm:"column(user_agent);size(500);null" json:"user_agent"`
|
||||
LoginType string `orm:"column(login_type);size(20);default(password)" json:"login_type"`
|
||||
Amr *string `orm:"column(amr);size(64);null" json:"amr"`
|
||||
LoginAt time.Time `orm:"column(login_at);type(datetime)" json:"login_at"`
|
||||
LastAccessAt time.Time `orm:"column(last_access_at);type(datetime)" json:"last_access_at"`
|
||||
ExpiresAt time.Time `orm:"column(expires_at);type(datetime)" json:"expires_at"`
|
||||
Revoked int8 `orm:"column(revoked);default(0)" json:"revoked"`
|
||||
RevokeReason *string `orm:"column(revoke_reason);size(64);null" json:"revoke_reason"`
|
||||
RevokeAt *time.Time `orm:"column(revoke_at);type(datetime);null" json:"revoke_at"`
|
||||
}
|
||||
|
||||
func (m *AuthSession) TableName() string {
|
||||
return "yz_auth_session"
|
||||
}
|
||||
|
||||
// AuthRefreshToken 刷新令牌:yz_auth_refresh_token
|
||||
// 明文仅在颁发时返回一次,库中只存哈希;轮换时通过 family_id 检测重放。
|
||||
type AuthRefreshToken struct {
|
||||
ID uint64 `orm:"column(id);pk;auto" json:"id"`
|
||||
TokenHash string `orm:"column(token_hash);size(128)" json:"token_hash"`
|
||||
IdentityID uint64 `orm:"column(identity_id)" json:"identity_id"`
|
||||
Tid uint64 `orm:"column(tid);default(0)" json:"tid"`
|
||||
ClientID string `orm:"column(client_id);size(64);default('')" json:"client_id"`
|
||||
Sid string `orm:"column(sid);size(64);default('')" json:"sid"`
|
||||
FamilyID string `orm:"column(family_id);size(64)" json:"family_id"`
|
||||
RotatedFrom *string `orm:"column(rotated_from);size(128);null" json:"rotated_from"`
|
||||
Used int8 `orm:"column(used);default(0)" json:"used"`
|
||||
Revoked int8 `orm:"column(revoked);default(0)" json:"revoked"`
|
||||
ExpiresAt time.Time `orm:"column(expires_at);type(datetime)" json:"expires_at"`
|
||||
CreateTime time.Time `orm:"column(create_time);auto_now_add;type(datetime)" json:"create_time"`
|
||||
}
|
||||
|
||||
func (m *AuthRefreshToken) TableName() string {
|
||||
return "yz_auth_refresh_token"
|
||||
}
|
||||
|
||||
// AuthCode 授权码:yz_auth_code
|
||||
// 一次性、60 秒有效,配合 PKCE(S256)使用。
|
||||
type AuthCode struct {
|
||||
CodeHash string `orm:"column(code_hash);size(128);pk" json:"code_hash"`
|
||||
ClientID string `orm:"column(client_id);size(64)" json:"client_id"`
|
||||
IdentityID uint64 `orm:"column(identity_id)" json:"identity_id"`
|
||||
Tid uint64 `orm:"column(tid);default(0)" json:"tid"`
|
||||
RedirectURI string `orm:"column(redirect_uri);size(500)" json:"redirect_uri"`
|
||||
CodeChallenge string `orm:"column(code_challenge);size(128)" json:"code_challenge"`
|
||||
CodeChallengeMethod string `orm:"column(code_challenge_method);size(10);default(S256)" json:"code_challenge_method"`
|
||||
Scope *string `orm:"column(scope);size(255);null" json:"scope"`
|
||||
Nonce *string `orm:"column(nonce);size(128);null" json:"nonce"`
|
||||
Used int8 `orm:"column(used);default(0)" json:"used"`
|
||||
ExpiresAt time.Time `orm:"column(expires_at);type(datetime)" json:"expires_at"`
|
||||
CreateTime time.Time `orm:"column(create_time);auto_now_add;type(datetime)" json:"create_time"`
|
||||
}
|
||||
|
||||
func (m *AuthCode) TableName() string {
|
||||
return "yz_auth_code"
|
||||
}
|
||||
|
||||
// AuthTokenBlacklist 令牌吊销表:yz_auth_token_blacklist
|
||||
// 记录已登出/被踢下线的 access token 的 jti,过期后可定期清理。
|
||||
type AuthTokenBlacklist struct {
|
||||
Jti string `orm:"column(jti);size(64);pk" json:"jti"`
|
||||
IdentityID uint64 `orm:"column(identity_id);default(0)" json:"identity_id"`
|
||||
Sid *string `orm:"column(sid);size(64);null" json:"sid"`
|
||||
Reason *string `orm:"column(reason);size(64);null" json:"reason"`
|
||||
ExpiresAt time.Time `orm:"column(expires_at);type(datetime)" json:"expires_at"`
|
||||
CreateTime time.Time `orm:"column(create_time);auto_now_add;type(datetime)" json:"create_time"`
|
||||
}
|
||||
|
||||
func (m *AuthTokenBlacklist) TableName() string {
|
||||
return "yz_auth_token_blacklist"
|
||||
}
|
||||
Reference in New Issue
Block a user