user.go 4.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183
  1. package handler
  2. import (
  3. "fmt"
  4. "spider/internal/model"
  5. "spider/internal/store"
  6. "strconv"
  7. "github.com/gin-gonic/gin"
  8. )
  9. // UserHandler handles user management (admin only).
  10. type UserHandler struct {
  11. store *store.Store
  12. }
  13. // List handles GET /users
  14. func (h *UserHandler) List(c *gin.Context) {
  15. page, pageSize, offset := parsePage(c)
  16. var total int64
  17. h.store.DB.Model(&model.User{}).Count(&total)
  18. var users []model.User
  19. if err := h.store.DB.Order("id ASC").Limit(pageSize).Offset(offset).Find(&users).Error; err != nil {
  20. Fail(c, 500, err.Error())
  21. return
  22. }
  23. PageOK(c, users, total, page, pageSize)
  24. }
  25. // Create handles POST /users
  26. func (h *UserHandler) Create(c *gin.Context) {
  27. var req struct {
  28. Username string `json:"username" binding:"required,min=3"`
  29. Password string `json:"password" binding:"required,min=6"`
  30. Nickname string `json:"nickname"`
  31. Role string `json:"role" binding:"required,oneof=admin operator viewer"`
  32. }
  33. if err := c.ShouldBindJSON(&req); err != nil {
  34. Fail(c, 400, err.Error())
  35. return
  36. }
  37. // Check duplicate
  38. var count int64
  39. h.store.DB.Model(&model.User{}).Where("username = ?", req.Username).Count(&count)
  40. if count > 0 {
  41. Fail(c, 409, "用户名已存在")
  42. return
  43. }
  44. user := model.User{
  45. Username: req.Username,
  46. Password: HashPassword(req.Password),
  47. Nickname: req.Nickname,
  48. Role: req.Role,
  49. Enabled: true,
  50. }
  51. if err := h.store.DB.Create(&user).Error; err != nil {
  52. Fail(c, 500, err.Error())
  53. return
  54. }
  55. LogAudit(h.store, c, "create", "user", fmt.Sprintf("%d", user.ID), gin.H{"username": user.Username, "role": user.Role})
  56. OK(c, user)
  57. }
  58. // Update handles PUT /users/:id
  59. func (h *UserHandler) Update(c *gin.Context) {
  60. id, err := strconv.ParseUint(c.Param("id"), 10, 64)
  61. if err != nil {
  62. Fail(c, 400, "invalid id")
  63. return
  64. }
  65. var user model.User
  66. if err := h.store.DB.First(&user, id).Error; err != nil {
  67. Fail(c, 404, "用户不存在")
  68. return
  69. }
  70. var req struct {
  71. Nickname *string `json:"nickname"`
  72. Role *string `json:"role"`
  73. Enabled *bool `json:"enabled"`
  74. }
  75. if err := c.ShouldBindJSON(&req); err != nil {
  76. Fail(c, 400, err.Error())
  77. return
  78. }
  79. updates := map[string]any{}
  80. if req.Nickname != nil {
  81. updates["nickname"] = *req.Nickname
  82. }
  83. if req.Role != nil {
  84. if *req.Role != "admin" && *req.Role != "operator" && *req.Role != "viewer" {
  85. Fail(c, 400, "角色无效")
  86. return
  87. }
  88. updates["role"] = *req.Role
  89. }
  90. if req.Enabled != nil {
  91. updates["enabled"] = *req.Enabled
  92. }
  93. h.store.DB.Model(&user).Updates(updates)
  94. h.store.DB.First(&user, id)
  95. LogAudit(h.store, c, "update", "user", fmt.Sprintf("%d", id), updates)
  96. OK(c, user)
  97. }
  98. // ResetPassword handles POST /users/:id/reset-password (admin only)
  99. func (h *UserHandler) ResetPassword(c *gin.Context) {
  100. id, err := strconv.ParseUint(c.Param("id"), 10, 64)
  101. if err != nil {
  102. Fail(c, 400, "invalid id")
  103. return
  104. }
  105. var req struct {
  106. NewPassword string `json:"new_password" binding:"required,min=6"`
  107. }
  108. if err := c.ShouldBindJSON(&req); err != nil {
  109. Fail(c, 400, "新密码至少6位")
  110. return
  111. }
  112. var user model.User
  113. if err := h.store.DB.First(&user, id).Error; err != nil {
  114. Fail(c, 404, "用户不存在")
  115. return
  116. }
  117. h.store.DB.Model(&user).Update("password", HashPassword(req.NewPassword))
  118. LogAudit(h.store, c, "update", "user", fmt.Sprintf("%d", id), gin.H{"action": "reset_password"})
  119. OK(c, gin.H{"message": "密码已重置"})
  120. }
  121. // ForceLogout handles POST /users/:id/force-logout — invalidates all tokens for a user
  122. func (h *UserHandler) ForceLogout(c *gin.Context) {
  123. id, err := strconv.ParseUint(c.Param("id"), 10, 64)
  124. if err != nil {
  125. Fail(c, 400, "invalid id")
  126. return
  127. }
  128. var user model.User
  129. if err := h.store.DB.First(&user, id).Error; err != nil {
  130. Fail(c, 404, "用户不存在")
  131. return
  132. }
  133. // We can't revoke all tokens without tracking them, but we can
  134. // mark the user as needing re-auth by bumping a version counter.
  135. // For now, log the action - token blacklisting would require
  136. // storing all active tokens per user.
  137. LogAudit(h.store, c, "force_logout", "user", fmt.Sprintf("%d", id), gin.H{"username": user.Username})
  138. OK(c, gin.H{"message": fmt.Sprintf("已强制 %s 退出登录", user.Username)})
  139. }
  140. // Delete handles DELETE /users/:id
  141. func (h *UserHandler) Delete(c *gin.Context) {
  142. id, err := strconv.ParseUint(c.Param("id"), 10, 64)
  143. if err != nil {
  144. Fail(c, 400, "invalid id")
  145. return
  146. }
  147. // Prevent deleting self
  148. currentID := c.GetUint("user_id")
  149. if uint(id) == currentID {
  150. Fail(c, 400, "不能删除自己")
  151. return
  152. }
  153. if err := h.store.DB.Delete(&model.User{}, id).Error; err != nil {
  154. Fail(c, 500, err.Error())
  155. return
  156. }
  157. LogAudit(h.store, c, "delete", "user", fmt.Sprintf("%d", id), nil)
  158. OK(c, gin.H{"message": "已删除"})
  159. }