Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions go.mod
Original file line number Diff line number Diff line change
Expand Up @@ -65,6 +65,7 @@ require (
github.com/stretchr/testify v1.7.1
github.com/swaggo/echo-swagger v1.0.0
github.com/swaggo/swag v1.6.7
github.com/tjfoc/gmsm v1.4.1
github.com/ungerik/go-dry v0.0.0-20210209114055-a3e162a9e62e
github.com/urfave/cli/v2 v2.8.1
github.com/vektah/gqlparser/v2 v2.5.1
Expand Down
2 changes: 2 additions & 0 deletions go.sum
Original file line number Diff line number Diff line change
Expand Up @@ -1801,3 +1801,5 @@ sourcegraph.com/sourcegraph/appdash-data v0.0.0-20151005221446-73f23eafcf67/go.m
storj.io/drpc v0.0.21/go.mod h1:OSJH7wvH3yKlhnMHwblKJioaaeyI6X8xbXT1SG9woe8=
vitess.io/vitess v0.12.0 h1:pzQpNHLqBG/3JZnZ5A0U25017b81CuxeR+s6ry9/wl4=
vitess.io/vitess v0.12.0/go.mod h1:QKt1VKLbuFqSi39giZa3z2i+ZG7/uSasnahoYjSB/go=
github.com/tjfoc/gmsm v1.4.1/go.mod h1:j4INPkHWMrhJb38G+J6W4Tw0AbuN8Thu3PbdVYhVcTE=
github.com/tjfoc/gmsm v1.4.1 h1:aMe1GlZb+0bLjn+cKTPEvvn9oUEBlJitaZiiBwsbgho=
1 change: 1 addition & 0 deletions sqle/api/app.go
Original file line number Diff line number Diff line change
Expand Up @@ -63,6 +63,7 @@ func StartApi(net *gracenet.Net, exitChan chan struct{}, config config.SqleConfi

e.POST("/v1/login", v1.LoginV1)
e.POST("/v2/login", v2.LoginV2)
e.GET("/v1/login/encryption", v1.GetLoginEncryption)

// the operation of obtaining the basic information of the platform should be for all users, not the users who log in to the platform
e.GET("/v1/basic_info", v1.GetSQLEInfo)
Expand Down
57 changes: 54 additions & 3 deletions sqle/api/controller/v1/auth.go
Original file line number Diff line number Diff line change
Expand Up @@ -11,15 +11,19 @@ import (
"github.com/actiontech/sqle/sqle/api/controller"
"github.com/actiontech/sqle/sqle/errors"
"github.com/actiontech/sqle/sqle/model"
"github.com/actiontech/sqle/sqle/pkg/loginencryption"
"github.com/actiontech/sqle/sqle/utils"

"github.com/go-ldap/ldap/v3"
"github.com/labstack/echo/v4"
)

type UserLoginReqV1 struct {
UserName string `json:"username" form:"username" example:"test" valid:"required"`
Password string `json:"password" form:"password" example:"123456" valid:"required"`
UserName string `json:"username" form:"username" example:"test"`
Password string `json:"password" form:"password" example:"123456"`
EncryptedUsername string `json:"encrypted_username" form:"encrypted_username"`
EncryptedPassword string `json:"encrypted_password" form:"encrypted_password"`
KeyID string `json:"key_id" form:"key_id"`
}

type GetUserLoginResV1 struct {
Expand All @@ -31,6 +35,25 @@ type UserLoginResV1 struct {
Token string `json:"token" example:"this is a jwt token string"`
}

type GetLoginEncryptionResV1 struct {
controller.BaseRes
Data loginencryption.PublicInfo `json:"data"`
}

// GetLoginEncryption
// @Summary 获取登录密码加密配置
// @Description get login password encryption public info
// @Tags user
// @Id getLoginEncryptionV1
// @Success 200 {object} v1.GetLoginEncryptionResV1
// @router /v1/login/encryption [get]
func GetLoginEncryption(c echo.Context) error {
return c.JSON(http.StatusOK, &GetLoginEncryptionResV1{
BaseRes: controller.NewBaseReq(nil),
Data: loginencryption.GetManager().PublicInfo(),
})
}

// @Summary 用户登录
// @Description user login
// @Tags user
Expand All @@ -44,7 +67,17 @@ func LoginV1(c echo.Context) error {
return err
}

t, err := Login(c, req.UserName, req.Password)
userName, err := ResolveLoginUsername(req.UserName, req.EncryptedUsername, req.KeyID)
if err != nil {
return controller.JSONBaseErrorReq(c, err)
}

password, err := ResolveLoginPassword(req.Password, req.EncryptedPassword, req.KeyID)
if err != nil {
return controller.JSONBaseErrorReq(c, err)
}

t, err := Login(c, userName, password)
if err != nil {
return controller.JSONBaseErrorReq(c, err)
}
Expand All @@ -57,6 +90,24 @@ func LoginV1(c echo.Context) error {
})
}

// ResolveLoginUsername decrypts encrypted username when login encryption is enabled.
func ResolveLoginUsername(plainUsername, encryptedUsername, keyID string) (string, error) {
userName, err := loginencryption.GetManager().ResolveUsername(plainUsername, encryptedUsername, keyID)
if err != nil {
return "", errors.New(errors.DataInvalid, err)
}
return userName, nil
}

// ResolveLoginPassword decrypts encrypted password when login encryption is enabled.
func ResolveLoginPassword(plainPassword, encryptedPassword, keyID string) (string, error) {
password, err := loginencryption.GetManager().ResolvePassword(plainPassword, encryptedPassword, keyID)
if err != nil {
return "", errors.New(errors.DataInvalid, err)
}
return password, nil
}

func Login(c echo.Context, userName, password string) (token string, err error) {
loginChecker, err := GetLoginCheckerByUserName(userName)
if err != nil {
Expand Down
21 changes: 17 additions & 4 deletions sqle/api/controller/v2/auth.go
Original file line number Diff line number Diff line change
Expand Up @@ -9,15 +9,18 @@ import (
)

type UserLoginReqV2 struct {
UserName string `json:"username" form:"username" example:"test" valid:"required"`
Password string `json:"password" form:"password" example:"123456" valid:"required"`
UserName string `json:"username" form:"username" example:"test"`
Password string `json:"password" form:"password" example:"123456"`
EncryptedUsername string `json:"encrypted_username" form:"encrypted_username"`
EncryptedPassword string `json:"encrypted_password" form:"encrypted_password"`
KeyID string `json:"key_id" form:"key_id"`
}

// @Summary 用户登录
// @Description user login
// @Tags user
// @Id loginV2
// @Param user body v1.UserLoginReqV1 true "user login request"
// @Param user body v2.UserLoginReqV2 true "user login request"
// @Success 200 {object} controller.BaseRes
// @router /v2/login [post]
func LoginV2(c echo.Context) error {
Expand All @@ -26,7 +29,17 @@ func LoginV2(c echo.Context) error {
return err
}

_, err := v1.Login(c, req.UserName, req.Password)
userName, err := v1.ResolveLoginUsername(req.UserName, req.EncryptedUsername, req.KeyID)
if err != nil {
return controller.JSONBaseErrorReq(c, err)
}

password, err := v1.ResolveLoginPassword(req.Password, req.EncryptedPassword, req.KeyID)
if err != nil {
return controller.JSONBaseErrorReq(c, err)
}

_, err = v1.Login(c, userName, password)
if err != nil {
return controller.JSONBaseErrorReq(c, err)
}
Expand Down
4 changes: 4 additions & 0 deletions sqle/config/config.go
Original file line number Diff line number Diff line change
Expand Up @@ -25,6 +25,10 @@ type SqleConfig struct {
LogMaxBackupNumber int `yaml:"log_max_backup_number"`
PluginPath string `yaml:"plugin_path"`
SecretKey string `yaml:"secret_key"`
// LoginEncryptionMode: disabled | compatible | required;未配置视为 required
LoginEncryptionMode string `yaml:"login_encryption_mode"`
// LoginEncryptionPrivateKeyPath points to SM2 private key file (PEM or hex);未配置用默认 path 并可自动生成
LoginEncryptionPrivateKeyPath string `yaml:"login_encryption_private_key_path"`
}

type DatabaseConfig struct {
Expand Down
Loading
Loading