Compare commits

...
19 changed files with 233 additions and 48 deletions
+2 -2
View File
@@ -12,7 +12,7 @@ jobs:
- name: Setup Node
uses: actions/setup-node@v4
with:
node-version: '20.2'
node-version: '22.19.0'
- name: Build Web
run: |
cd frontend && npm install && npm run build:pro
@@ -21,7 +21,7 @@ jobs:
- name: Setup Go
uses: actions/setup-go@v5
with:
go-version: '1.23'
go-version: '1.24'
- name: Build Release
uses: goreleaser/goreleaser-action@v6
with:
+2 -2
View File
@@ -12,7 +12,7 @@ jobs:
- name: Setup Node
uses: actions/setup-node@v4
with:
node-version: '20.2'
node-version: '22.19.0'
- name: Build Web
run: |
cd frontend && npm install && npm run build:pro
@@ -21,7 +21,7 @@ jobs:
- name: Setup Go
uses: actions/setup-go@v5
with:
go-version: '1.23'
go-version: '1.24'
- name: Build Release
uses: goreleaser/goreleaser-action@v6
with:
+1 -1
View File
@@ -31,4 +31,4 @@ build_backend_on_darwin:
build_all: build_frontend build_backend_on_linux
build_on_local: clean_assets build_frontend build_backend_on_darwin upx_bin
build_on_local: clean_assets build_frontend build_backend_on_darwin
+17 -6
View File
@@ -2,12 +2,14 @@ package v1
import (
"encoding/base64"
"github.com/1Panel-dev/1Panel/backend/app/api/v1/helper"
"github.com/1Panel-dev/1Panel/backend/app/dto"
"github.com/1Panel-dev/1Panel/backend/app/model"
"github.com/1Panel-dev/1Panel/backend/constant"
"github.com/1Panel-dev/1Panel/backend/global"
"github.com/1Panel-dev/1Panel/backend/utils/captcha"
"github.com/1Panel-dev/1Panel/backend/utils/common"
"github.com/gin-gonic/gin"
)
@@ -26,7 +28,9 @@ func (b *BaseApi) Login(c *gin.Context) {
return
}
if req.AuthMethod != "jwt" && !req.IgnoreCaptcha {
ip := common.GetRealClientIP(c)
needCaptcha := global.IPTracker.NeedCaptcha(ip)
if needCaptcha {
if err := captcha.VerifyCode(req.CaptchaID, req.Captcha); err != nil {
helper.ErrorWithDetail(c, constant.CodeErrInternalServer, constant.ErrTypeInternalServer, err)
return
@@ -48,9 +52,11 @@ func (b *BaseApi) Login(c *gin.Context) {
user, err := authService.Login(c, req, string(entrance))
go saveLoginLogs(c, err)
if err != nil {
global.IPTracker.SetNeedCaptcha(ip)
helper.ErrorWithDetail(c, constant.CodeErrInternalServer, constant.ErrTypeInternalServer, err)
return
}
global.IPTracker.Clear(ip)
helper.SuccessWithData(c, user)
}
@@ -134,16 +140,21 @@ func (b *BaseApi) CheckIsIntl(c *gin.Context) {
}
// @Tags Auth
// @Summary Load System Language
// @Success 200 {string} language
// @Router /auth/language [get]
func (b *BaseApi) GetLanguage(c *gin.Context) {
// @Summary Load System Setting for login
// @Success 200 {object} dto.LoginSetting
// @Router /auth/setting [get]
func (b *BaseApi) GetAuthSetting(c *gin.Context) {
settingInfo, err := settingService.GetSettingInfo()
if err != nil {
helper.ErrorWithDetail(c, constant.CodeErrInternalServer, constant.ErrTypeInternalServer, err)
return
}
helper.SuccessWithData(c, settingInfo.Language)
ip := common.GetRealClientIP(c)
needCaptcha := global.IPTracker.NeedCaptcha(ip)
helper.SuccessWithData(c, dto.LoginSetting{
NeedCaptcha: needCaptcha,
Language: settingInfo.Language,
})
}
func saveLoginLogs(c *gin.Context, err error) {
+11 -7
View File
@@ -23,13 +23,12 @@ type MfaCredential struct {
}
type Login struct {
Name string `json:"name" validate:"required"`
Password string `json:"password" validate:"required"`
IgnoreCaptcha bool `json:"ignoreCaptcha"`
Captcha string `json:"captcha"`
CaptchaID string `json:"captchaID"`
AuthMethod string `json:"authMethod" validate:"required,oneof=jwt session"`
Language string `json:"language" validate:"required,oneof=zh en tw ja ko ru ms 'pt-BR'"`
Name string `json:"name" validate:"required"`
Password string `json:"password" validate:"required"`
Captcha string `json:"captcha"`
CaptchaID string `json:"captchaID"`
AuthMethod string `json:"authMethod" validate:"required,oneof=jwt session"`
Language string `json:"language" validate:"required,oneof=zh en tw ja ko ru ms 'pt-BR'"`
}
type MFALogin struct {
@@ -38,3 +37,8 @@ type MFALogin struct {
Code string `json:"code" validate:"required"`
AuthMethod string `json:"authMethod"`
}
type LoginSetting struct {
NeedCaptcha bool `json:"needCaptcha"`
Language string `json:"language"`
}
+43 -2
View File
@@ -413,9 +413,9 @@ func (u *BackupService) Update(req dto.BackupOperate) error {
if strings.HasSuffix(dirStr, "/") && dirStr != "/" {
dirStr = dirStr[:strings.LastIndex(dirStr, "/")]
}
if err := copyDir(oldDir, dirStr); err != nil {
if err := changeLocalBackup(oldDir, dirStr); err != nil {
_ = backupRepo.Update(req.ID, map[string]interface{}{"vars": oldVars})
return err
return fmt.Errorf("copy dir from %s to %s failed, err: %v", oldDir, dirStr, err)
}
global.CONF.System.Backup = dirStr
}
@@ -677,3 +677,44 @@ func (u *BackupService) Run() {
}).Error
global.LOG.Info("Successfully refreshed OneDrive token.")
}
func changeLocalBackup(oldPath, newPath string) error {
fileOp := fileUtils.NewFileOp()
if fileOp.Stat(path.Join(oldPath, "app")) {
if err := fileOp.CopyDir(path.Join(oldPath, "app"), newPath); err != nil {
return err
}
}
if fileOp.Stat(path.Join(oldPath, "database")) {
if err := fileOp.CopyDir(path.Join(oldPath, "database"), newPath); err != nil {
return err
}
}
if fileOp.Stat(path.Join(oldPath, "directory")) {
if err := fileOp.CopyDir(path.Join(oldPath, "directory"), newPath); err != nil {
return err
}
}
if fileOp.Stat(path.Join(oldPath, "system_snapshot")) {
if err := fileOp.CopyDir(path.Join(oldPath, "system_snapshot"), newPath); err != nil {
return err
}
}
if fileOp.Stat(path.Join(oldPath, "website")) {
if err := fileOp.CopyDir(path.Join(oldPath, "website"), newPath); err != nil {
return err
}
}
if fileOp.Stat(path.Join(oldPath, "log")) {
if err := fileOp.CopyDir(path.Join(oldPath, "log"), newPath); err != nil {
return err
}
}
_ = fileOp.RmRf(path.Join(oldPath, "app"))
_ = fileOp.RmRf(path.Join(oldPath, "database"))
_ = fileOp.RmRf(path.Join(oldPath, "directory"))
_ = fileOp.RmRf(path.Join(oldPath, "system_snapshot"))
_ = fileOp.RmRf(path.Join(oldPath, "website"))
_ = fileOp.RmRf(path.Join(oldPath, "log"))
return nil
}
+3
View File
@@ -2,6 +2,7 @@ package global
import (
"github.com/1Panel-dev/1Panel/backend/configs"
"github.com/1Panel-dev/1Panel/backend/init/auth"
"github.com/1Panel-dev/1Panel/backend/init/cache/badger_db"
"github.com/1Panel-dev/1Panel/backend/init/session/psession"
"github.com/dgraph-io/badger/v4"
@@ -28,6 +29,8 @@ var (
MonitorCronID cron.EntryID
OneDriveCronID cron.EntryID
IPTracker *auth.IPTracker
I18n *i18n.Localizer
I18nForCmd *i18n.Localizer
)
+99
View File
@@ -0,0 +1,99 @@
package auth
import (
"sync"
"time"
)
const (
MaxIPCount = 100
ExpireDuration = 30 * time.Minute
)
type IPRecord struct {
NeedCaptcha bool
LastUpdate time.Time
}
type IPTracker struct {
records map[string]*IPRecord
ipOrder []string
mu sync.RWMutex
}
func NewIPTracker() *IPTracker {
return &IPTracker{
records: make(map[string]*IPRecord),
ipOrder: make([]string, 0),
}
}
func (t *IPTracker) NeedCaptcha(ip string) bool {
t.mu.Lock()
defer t.mu.Unlock()
record, exists := t.records[ip]
if !exists {
return false
}
if time.Since(record.LastUpdate) > ExpireDuration {
t.removeIPUnsafe(ip)
return false
}
return record.NeedCaptcha
}
func (t *IPTracker) SetNeedCaptcha(ip string) {
t.mu.Lock()
defer t.mu.Unlock()
if record, exists := t.records[ip]; exists {
if time.Since(record.LastUpdate) > ExpireDuration {
t.removeIPUnsafe(ip)
} else {
record.NeedCaptcha = true
record.LastUpdate = time.Now()
return
}
}
if len(t.records) >= MaxIPCount {
t.removeOldestUnsafe()
}
t.records[ip] = &IPRecord{
NeedCaptcha: true,
LastUpdate: time.Now(),
}
t.ipOrder = append(t.ipOrder, ip)
}
func (t *IPTracker) Clear(ip string) {
t.mu.Lock()
defer t.mu.Unlock()
t.removeIPUnsafe(ip)
}
func (t *IPTracker) removeIPUnsafe(ip string) {
delete(t.records, ip)
for i, storedIP := range t.ipOrder {
if storedIP == ip {
t.ipOrder = append(t.ipOrder[:i], t.ipOrder[i+1:]...)
break
}
}
}
func (t *IPTracker) removeOldestUnsafe() {
if len(t.ipOrder) == 0 {
return
}
oldestIP := t.ipOrder[0]
delete(t.records, oldestIP)
t.ipOrder = t.ipOrder[1:]
}
+5 -4
View File
@@ -3,14 +3,15 @@ package router
import (
"encoding/base64"
"fmt"
"github.com/1Panel-dev/1Panel/backend/app/service"
"github.com/1Panel-dev/1Panel/backend/constant"
"github.com/1Panel-dev/1Panel/cmd/server/res"
"net/http"
"regexp"
"strconv"
"strings"
"github.com/1Panel-dev/1Panel/backend/app/service"
"github.com/1Panel-dev/1Panel/backend/constant"
"github.com/1Panel-dev/1Panel/cmd/server/res"
"github.com/1Panel-dev/1Panel/backend/global"
"github.com/1Panel-dev/1Panel/backend/i18n"
"github.com/1Panel-dev/1Panel/backend/middleware"
@@ -160,7 +161,7 @@ func setWebStatic(rootRouter *gin.RouterGroup) {
}
func Routers() *gin.Engine {
Router = gin.Default()
Router = gin.New()
Router.Use(middleware.OperationLog())
// Router.Use(middleware.CSRF())
// Router.Use(middleware.LoadCsrfToken())
+6 -1
View File
@@ -8,11 +8,17 @@ import (
"github.com/1Panel-dev/1Panel/backend/app/repo"
"github.com/1Panel-dev/1Panel/backend/constant"
"github.com/1Panel-dev/1Panel/backend/global"
"github.com/1Panel-dev/1Panel/backend/utils/common"
"github.com/gin-gonic/gin"
)
func WhiteAllow() gin.HandlerFunc {
return func(c *gin.Context) {
clientIP := common.GetRealClientIP(c)
if common.IsPrivateIP(clientIP) {
c.Next()
return
}
settingRepo := repo.NewISettingRepo()
status, err := settingRepo.Get(settingRepo.WithByKey("AllowIPs"))
if err != nil {
@@ -24,7 +30,6 @@ func WhiteAllow() gin.HandlerFunc {
c.Next()
return
}
clientIP := c.ClientIP()
for _, ip := range strings.Split(status.Value, ",") {
if len(ip) == 0 {
continue
+1 -1
View File
@@ -16,7 +16,7 @@ func (s *BaseRouter) InitRouter(Router *gin.RouterGroup) {
baseRouter.POST("/login", baseApi.Login)
baseRouter.POST("/logout", baseApi.LogOut)
baseRouter.GET("/demo", baseApi.CheckIsDemo)
baseRouter.GET("/language", baseApi.GetLanguage)
baseRouter.GET("/setting", baseApi.GetAuthSetting)
baseRouter.GET("/intl", baseApi.CheckIsIntl)
}
}
+2
View File
@@ -13,6 +13,7 @@ import (
"github.com/1Panel-dev/1Panel/backend/i18n"
"github.com/1Panel-dev/1Panel/backend/init/app"
"github.com/1Panel-dev/1Panel/backend/init/auth"
"github.com/1Panel-dev/1Panel/backend/init/business"
"github.com/1Panel-dev/1Panel/backend/init/lang"
@@ -52,6 +53,7 @@ func Start() {
business.Init()
rootRouter := router.Routers()
global.IPTracker = auth.NewIPTracker()
tcpItem := "tcp4"
if global.CONF.System.Ipv6 == "enable" {
+3 -3
View File
@@ -11,13 +11,13 @@ import (
var store = base64Captcha.DefaultMemStore
func VerifyCode(codeID string, code string) error {
if codeID == "" {
return constant.ErrCaptchaCode
}
vv := store.Get(codeID, true)
vv = strings.TrimSpace(vv)
code = strings.TrimSpace(code)
if codeID == "" || code == "" {
return constant.ErrCaptchaCode
}
if strings.EqualFold(vv, code) {
return nil
}
+16
View File
@@ -426,3 +426,19 @@ func HandleIPList(content string) ([]string, error) {
}
return res, nil
}
func GetRealClientIP(c *gin.Context) string {
addr := c.Request.RemoteAddr
if ip, _, err := net.SplitHostPort(addr); err == nil {
return ip
}
return addr
}
func IsPrivateIP(ipStr string) bool {
ip := net.ParseIP(ipStr)
if ip == nil {
return false
}
return ip.IsPrivate() || ip.IsLoopback()
}
+5 -5
View File
@@ -6,18 +6,18 @@ command -v wget >/dev/null || {
}
if [ ! -f "1pctl" ]; then
wget https://github.com/1Panel-dev/installer/raw/main/1pctl
wget https://github.com/1Panel-dev/installer/raw/v1/1pctl
fi
if [ ! -f "install.sh" ]; then
wget https://github.com/1Panel-dev/installer/raw/main/install.sh
wget https://github.com/1Panel-dev/installer/raw/v1/install.sh
fi
if [ ! -d "initscript" ]; then
wget https://github.com/1Panel-dev/installer/raw/main/initscript/1panel.service
wget https://github.com/1Panel-dev/installer/raw/v1/initscript/1panel.service
mkdir -p initscript && cd initscript
for file in 1panel.service 1paneld.init 1paneld.openrc 1paneld.procd; do
wget -q https://github.com/1Panel-dev/installer/raw/main/initscript/$file
wget -q https://github.com/1Panel-dev/installer/raw/v1/initscript/$file
done
cd ..
fi
@@ -25,7 +25,7 @@ fi
if [ ! -d "lang" ]; then
mkdir -p lang && cd lang
for lang in en fa pt-BR ru zh; do
wget -q https://github.com/1Panel-dev/installer/raw/main/lang/$lang.sh
wget -q https://github.com/1Panel-dev/installer/raw/v1/lang/$lang.sh
done
cd ..
fi
+4 -4
View File
@@ -39,7 +39,7 @@
"codemirror": "^6.0.1",
"crypto-js": "^4.2.0",
"echarts": "^5.5.0",
"element-plus": "^2.7.5",
"element-plus": "2.9.9",
"fit2cloud-ui-plus": "^1.2.0",
"highlight.js": "^11.9.0",
"js-base64": "^3.7.7",
@@ -64,8 +64,8 @@
"@types/node": "^20.15.0",
"@typescript-eslint/eslint-plugin": "^5.22.0",
"@typescript-eslint/parser": "^5.22.0",
"@vitejs/plugin-vue": "^5.0.5",
"@vitejs/plugin-vue-jsx": "^4.0.0",
"@vitejs/plugin-vue": "^6.0.1",
"@vitejs/plugin-vue-jsx": "^5.1.1",
"autoprefixer": "^10.4.7",
"commitizen": "^4.2.4",
"eslint": "^8.43.0",
@@ -84,7 +84,7 @@
"typescript": "^4.5.4",
"unplugin-auto-import": "^0.16.4",
"unplugin-vue-components": "^0.25.0",
"vite": "^6.0.7",
"vite": "^7.1.5",
"vite-plugin-compression": "^0.5.1",
"vite-plugin-eslint": "^1.8.1",
"vite-plugin-html": "^3.2.2",
+4 -1
View File
@@ -2,7 +2,6 @@ export namespace Login {
export interface ReqLoginForm {
name: string;
password: string;
ignoreCaptcha: boolean;
captcha: string;
captchaID: string;
authMethod: string;
@@ -26,4 +25,8 @@ export namespace Login {
export interface ResAuthButtons {
[propName: string]: any;
}
export interface LoginSetting {
language: string;
needCaptcha: boolean;
}
}
+2 -2
View File
@@ -21,8 +21,8 @@ export const checkIsDemo = () => {
return http.get<boolean>('/auth/demo');
};
export const getLanguage = () => {
return http.get<string>(`/auth/language`);
export const getAuthSetting = () => {
return http.get<Login.LoginSetting>(`/auth/setting`);
};
export const checkIsIntl = () => {
@@ -176,7 +176,7 @@
import { ref, reactive, onMounted, computed, nextTick } from 'vue';
import { useRouter } from 'vue-router';
import type { ElForm } from 'element-plus';
import { loginApi, getCaptcha, mfaLoginApi, checkIsDemo, getLanguage, checkIsIntl } from '@/api/modules/auth';
import { loginApi, getCaptcha, mfaLoginApi, checkIsDemo, getAuthSetting, checkIsIntl } from '@/api/modules/auth';
import { GlobalStore, MenuStore, TabsStore } from '@/store';
import { MsgSuccess } from '@/utils/message';
import { useI18n } from 'vue-i18n';
@@ -318,7 +318,6 @@ const login = (formEl: FormInstance | undefined) => {
let requestLoginForm = {
name: loginForm.name,
password: encryptPassword(loginForm.password),
ignoreCaptcha: globalStore.ignoreCaptcha,
captcha: loginForm.captcha,
captchaID: captcha.captchaID,
authMethod: 'session',
@@ -400,11 +399,12 @@ const checkIsSystemDemo = async () => {
isDemo.value = res.data;
};
const loadLanguage = async () => {
const loadLoginSetting = async () => {
try {
const res = await getLanguage();
loginForm.language = res.data;
handleCommand(res.data);
const res = await getAuthSetting();
loginForm.language = res.data.language;
globalStore.ignoreCaptcha = !res.data.needCaptcha;
handleCommand(loginForm.language);
} catch (error) {}
};
@@ -426,7 +426,7 @@ onMounted(() => {
globalStore.isOnRestart = false;
checkIsSystemIntl();
loginVerify();
loadLanguage();
loadLoginSetting();
document.title = globalStore.themeConfig.panelName;
loginForm.agreeLicense = globalStore.agreeLicense;
checkIsSystemDemo();