做统一认证登录
This commit is contained in:
@@ -73,6 +73,13 @@ func PlatformAdminLogin(account, password string) (string, *PlatformLoginUser, e
|
||||
if !passwordutil.Verify(user.Password, password) {
|
||||
return "", nil, errors.New("用户名或密码错误")
|
||||
}
|
||||
// 历史 sha256 密码:本次登录成功后自动升级为 argon2id(失败不影响登录)
|
||||
upgradePasswordIfNeeded(user.Password, password, func(hashed string) error {
|
||||
_, err := models.Orm.QueryTable(new(models.AdminUser)).
|
||||
Filter("id", user.ID).
|
||||
Update(map[string]interface{}{"password": hashed})
|
||||
return err
|
||||
})
|
||||
|
||||
const tenantID = 0
|
||||
const userType = "platform"
|
||||
@@ -116,6 +123,13 @@ func BackendLogin(tenantName, account, password string) (string, *PlatformLoginU
|
||||
if tenantUser.Password == nil || !passwordutil.Verify(*tenantUser.Password, password) {
|
||||
return "", nil, errors.New("用户名或密码错误")
|
||||
}
|
||||
// 历史 sha256 密码:本次登录成功后自动升级为 argon2id(失败不影响登录)
|
||||
upgradePasswordIfNeeded(*tenantUser.Password, password, func(hashed string) error {
|
||||
_, err := models.Orm.QueryTable(new(models.SystemTenantUser)).
|
||||
Filter("id", tenantUser.ID).
|
||||
Update(map[string]interface{}{"password": hashed})
|
||||
return err
|
||||
})
|
||||
|
||||
tenantID := int(tenant.ID)
|
||||
const userType = "backend"
|
||||
@@ -144,6 +158,22 @@ func BackendLogin(tenantName, account, password string) (string, *PlatformLoginU
|
||||
return token, loginUser, nil
|
||||
}
|
||||
|
||||
// upgradePasswordIfNeeded 旧算法(legacy sha256)密码在登录成功后自动重新哈希为 argon2id。
|
||||
//
|
||||
// 旧哈希无法离线转换成新算法(无法反推明文),只能借登录时拿到的明文重新哈希,
|
||||
// 因此采用「首次登录自动升级」的渐进方式,无需强制全员重置密码。
|
||||
// 重新哈希失败不影响本次登录,仅下次登录时重试。
|
||||
func upgradePasswordIfNeeded(stored, plain string, update func(hashed string) error) {
|
||||
if !passwordutil.NeedsRehash(stored) {
|
||||
return
|
||||
}
|
||||
hashed, err := passwordutil.Hash(plain)
|
||||
if err != nil {
|
||||
return
|
||||
}
|
||||
_ = update(hashed)
|
||||
}
|
||||
|
||||
// PlatformGetCurrentUser 根据平台管理员用户 ID 返回登录用户信息(含角色名称)。
|
||||
func PlatformGetCurrentUser(uid uint64) (*PlatformLoginUser, error) {
|
||||
u, err := GetAdminUserByID(uid)
|
||||
|
||||
Reference in New Issue
Block a user