沿用腾讯天御验证码引入的多服务商模型:aliyun_captcha_enabled 作为独立 开关,与 Cloudflare Turnstile、腾讯天御三方互斥(保存校验 + 运行时 CAPTCHA_PROVIDER_CONFLICT)。后台「安全与认证」合并为单张人机验证卡片: 总开关 + 服务商单选(Turnstile / 腾讯天御 / 阿里云),选中即启用该家并 关闭其它,落库仍是三个独立开关键,由前端映射保证互斥。 阿里云侧同时支持 aliyun 中国站与国际站(alibabacloud.com):两站前端脚本、 region 取值与服务端 API 完全一致,仅账号与 AccessKey 相互独立,因此由 「服务地域」决定线路即可——中国内地走 captcha.cn-shanghai.aliyuncs.com, 非中国内地(新加坡)走 captcha.ap-southeast-1.aliyuncs.com,AccessKey 取自持有该实例的账号,无需在配置中区分站点。 - AliyunCaptchaService 对称 TencentCaptchaService:服务端校验走官方 SDK VerifyIntelligentCaptcha,调用异常按 fail-closed 拦截,与 Turnstile 网络错误行为对称;保存设置时真实探测 AK/SK 有效性 - 保护面对齐腾讯扩展入口:VerifyTencentCaptchaIfEnabled 通用化为 VerifyActionCaptchaIfEnabled,OAuth 登录启动、passkey 登录在阿里云 启用时同样拦截;Turnstile 维持既有覆盖不扩大 - 前端 AliyunCaptchaWidget 为表单内预验证按钮(popup 模式),同时暴露 verify() 供 OAuth 启动、passkey 等动作入口程序化弹窗;未预验证直接 提交时弹窗兜底。SDK 按钮绑定异步完成,弹窗未出现前按 tick 重试触发, 并轮询弹窗可见性识别用户关闭 - captchaVerifyParam 复用 turnstile_token 请求字段提交;公开设置下发 aliyun_captcha_enabled / scene_id / prefix / region - CSP 放行验证码 CDN:script-src/style-src 加 *.alicdn.com
51 lines
1.4 KiB
Go
51 lines
1.4 KiB
Go
package handler
|
|
|
|
import (
|
|
"net/http"
|
|
"strings"
|
|
|
|
"github.com/Wei-Shaw/sub2api/internal/pkg/ip"
|
|
"github.com/Wei-Shaw/sub2api/internal/pkg/response"
|
|
"github.com/Wei-Shaw/sub2api/internal/service"
|
|
"github.com/gin-gonic/gin"
|
|
)
|
|
|
|
type oauthStartCaptchaRequest struct {
|
|
// TurnstileToken 承载阿里云验证码的 captchaVerifyParam(复用既有请求字段名)
|
|
TurnstileToken string `json:"turnstile_token"`
|
|
TencentCaptchaTicket string `json:"tencent_captcha_ticket"`
|
|
TencentCaptchaRandstr string `json:"tencent_captcha_randstr"`
|
|
}
|
|
|
|
type oauthStartResponse struct {
|
|
AuthorizeURL string `json:"authorize_url"`
|
|
}
|
|
|
|
func (h *AuthHandler) requireActionCaptchaForOAuthLoginStart(c *gin.Context) bool {
|
|
if strings.HasSuffix(strings.TrimRight(c.Request.URL.Path, "/"), "/bind/start") {
|
|
return true
|
|
}
|
|
|
|
var req oauthStartCaptchaRequest
|
|
if c.Request.Method == http.MethodPost {
|
|
_ = c.ShouldBindJSON(&req)
|
|
}
|
|
if err := h.authService.VerifyActionCaptchaIfEnabled(c.Request.Context(), service.CaptchaProof{
|
|
TurnstileToken: req.TurnstileToken,
|
|
TencentTicket: req.TencentCaptchaTicket,
|
|
TencentRandstr: req.TencentCaptchaRandstr,
|
|
}, ip.GetClientIP(c)); err != nil {
|
|
response.ErrorFrom(c, err)
|
|
return false
|
|
}
|
|
return true
|
|
}
|
|
|
|
func respondOAuthStart(c *gin.Context, authorizeURL string) {
|
|
if c.Request.Method == http.MethodPost {
|
|
response.Success(c, oauthStartResponse{AuthorizeURL: authorizeURL})
|
|
return
|
|
}
|
|
c.Redirect(http.StatusFound, authorizeURL)
|
|
}
|