validation.go 9.4 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288
  1. package console_setting
  2. import (
  3. "encoding/json"
  4. "fmt"
  5. "net/url"
  6. "regexp"
  7. "strings"
  8. "time"
  9. )
  10. var (
  11. urlRegex = regexp.MustCompile(`^https?://(?:(?:[a-zA-Z0-9](?:[a-zA-Z0-9-]{0,61}[a-zA-Z0-9])?\.)*[a-zA-Z0-9](?:[a-zA-Z0-9-]{0,61}[a-zA-Z0-9])?|(?:(?:25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\.){3}(?:25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?))(?:\:[0-9]{1,5})?(?:/.*)?$`)
  12. dangerousChars = []string{"<script", "<iframe", "javascript:", "onload=", "onerror=", "onclick="}
  13. validColors = map[string]bool{
  14. "blue": true, "green": true, "cyan": true, "purple": true, "pink": true,
  15. "red": true, "orange": true, "amber": true, "yellow": true, "lime": true,
  16. "light-green": true, "teal": true, "light-blue": true, "indigo": true,
  17. "violet": true, "grey": true,
  18. }
  19. slugRegex = regexp.MustCompile(`^[a-zA-Z0-9_-]+$`)
  20. )
  21. func parseJSONArray(jsonStr string, typeName string) ([]map[string]interface{}, error) {
  22. var list []map[string]interface{}
  23. if err := json.Unmarshal([]byte(jsonStr), &list); err != nil {
  24. return nil, fmt.Errorf("%s格式错误:%s", typeName, err.Error())
  25. }
  26. return list, nil
  27. }
  28. func validateURL(urlStr string, index int, itemType string) error {
  29. if !urlRegex.MatchString(urlStr) {
  30. return fmt.Errorf("第%d个%s的URL格式不正确", index, itemType)
  31. }
  32. if _, err := url.Parse(urlStr); err != nil {
  33. return fmt.Errorf("第%d个%s的URL无法解析:%s", index, itemType, err.Error())
  34. }
  35. return nil
  36. }
  37. func checkDangerousContent(content string, index int, itemType string) error {
  38. lower := strings.ToLower(content)
  39. for _, d := range dangerousChars {
  40. if strings.Contains(lower, d) {
  41. return fmt.Errorf("第%d个%s包含不允许的内容", index, itemType)
  42. }
  43. }
  44. return nil
  45. }
  46. func getJSONList(jsonStr string) []map[string]interface{} {
  47. if jsonStr == "" {
  48. return []map[string]interface{}{}
  49. }
  50. var list []map[string]interface{}
  51. json.Unmarshal([]byte(jsonStr), &list)
  52. return list
  53. }
  54. func ValidateConsoleSettings(settingsStr string, settingType string) error {
  55. if settingsStr == "" {
  56. return nil
  57. }
  58. switch settingType {
  59. case "ApiInfo":
  60. return validateApiInfo(settingsStr)
  61. case "Announcements":
  62. return validateAnnouncements(settingsStr)
  63. case "FAQ":
  64. return validateFAQ(settingsStr)
  65. case "UptimeKumaGroups":
  66. return validateUptimeKumaGroups(settingsStr)
  67. default:
  68. return fmt.Errorf("未知的设置类型:%s", settingType)
  69. }
  70. }
  71. func validateApiInfo(apiInfoStr string) error {
  72. apiInfoList, err := parseJSONArray(apiInfoStr, "API信息")
  73. if err != nil {
  74. return err
  75. }
  76. if len(apiInfoList) > 50 {
  77. return fmt.Errorf("API信息数量不能超过50个")
  78. }
  79. for i, apiInfo := range apiInfoList {
  80. urlStr, ok := apiInfo["url"].(string)
  81. if !ok || urlStr == "" {
  82. return fmt.Errorf("第%d个API信息缺少URL字段", i+1)
  83. }
  84. route, ok := apiInfo["route"].(string)
  85. if !ok || route == "" {
  86. return fmt.Errorf("第%d个API信息缺少线路描述字段", i+1)
  87. }
  88. description, ok := apiInfo["description"].(string)
  89. if !ok || description == "" {
  90. return fmt.Errorf("第%d个API信息缺少说明字段", i+1)
  91. }
  92. color, ok := apiInfo["color"].(string)
  93. if !ok || color == "" {
  94. return fmt.Errorf("第%d个API信息缺少颜色字段", i+1)
  95. }
  96. if err := validateURL(urlStr, i+1, "API信息"); err != nil {
  97. return err
  98. }
  99. if len(urlStr) > 500 {
  100. return fmt.Errorf("第%d个API信息的URL长度不能超过500字符", i+1)
  101. }
  102. if len(route) > 100 {
  103. return fmt.Errorf("第%d个API信息的线路描述长度不能超过100字符", i+1)
  104. }
  105. if len(description) > 200 {
  106. return fmt.Errorf("第%d个API信息的说明长度不能超过200字符", i+1)
  107. }
  108. if !validColors[color] {
  109. return fmt.Errorf("第%d个API信息的颜色值不合法", i+1)
  110. }
  111. if err := checkDangerousContent(description, i+1, "API信息"); err != nil {
  112. return err
  113. }
  114. if err := checkDangerousContent(route, i+1, "API信息"); err != nil {
  115. return err
  116. }
  117. }
  118. return nil
  119. }
  120. func GetApiInfo() []map[string]interface{} {
  121. return getJSONList(GetConsoleSetting().ApiInfo)
  122. }
  123. func validateAnnouncements(announcementsStr string) error {
  124. list, err := parseJSONArray(announcementsStr, "系统公告")
  125. if err != nil {
  126. return err
  127. }
  128. if len(list) > 100 {
  129. return fmt.Errorf("系统公告数量不能超过100个")
  130. }
  131. validTypes := map[string]bool{
  132. "default": true, "ongoing": true, "success": true, "warning": true, "error": true,
  133. }
  134. for i, ann := range list {
  135. content, ok := ann["content"].(string)
  136. if !ok || content == "" {
  137. return fmt.Errorf("第%d个公告缺少内容字段", i+1)
  138. }
  139. publishDateAny, exists := ann["publishDate"]
  140. if !exists {
  141. return fmt.Errorf("第%d个公告缺少发布日期字段", i+1)
  142. }
  143. publishDateStr, ok := publishDateAny.(string)
  144. if !ok || publishDateStr == "" {
  145. return fmt.Errorf("第%d个公告的发布日期不能为空", i+1)
  146. }
  147. if _, err := time.Parse(time.RFC3339, publishDateStr); err != nil {
  148. return fmt.Errorf("第%d个公告的发布日期格式错误", i+1)
  149. }
  150. if t, exists := ann["type"]; exists {
  151. if typeStr, ok := t.(string); ok {
  152. if !validTypes[typeStr] {
  153. return fmt.Errorf("第%d个公告的类型值不合法", i+1)
  154. }
  155. }
  156. }
  157. if len(content) > 500 {
  158. return fmt.Errorf("第%d个公告的内容长度不能超过500字符", i+1)
  159. }
  160. if extra, exists := ann["extra"]; exists {
  161. if extraStr, ok := extra.(string); ok && len(extraStr) > 200 {
  162. return fmt.Errorf("第%d个公告的说明长度不能超过200字符", i+1)
  163. }
  164. }
  165. }
  166. return nil
  167. }
  168. func validateFAQ(faqStr string) error {
  169. list, err := parseJSONArray(faqStr, "FAQ信息")
  170. if err != nil {
  171. return err
  172. }
  173. if len(list) > 100 {
  174. return fmt.Errorf("FAQ数量不能超过100个")
  175. }
  176. for i, faq := range list {
  177. question, ok := faq["question"].(string)
  178. if !ok || question == "" {
  179. return fmt.Errorf("第%d个FAQ缺少问题字段", i+1)
  180. }
  181. answer, ok := faq["answer"].(string)
  182. if !ok || answer == "" {
  183. return fmt.Errorf("第%d个FAQ缺少答案字段", i+1)
  184. }
  185. if len(question) > 200 {
  186. return fmt.Errorf("第%d个FAQ的问题长度不能超过200字符", i+1)
  187. }
  188. if len(answer) > 1000 {
  189. return fmt.Errorf("第%d个FAQ的答案长度不能超过1000字符", i+1)
  190. }
  191. }
  192. return nil
  193. }
  194. func GetAnnouncements() []map[string]interface{} {
  195. return getJSONList(GetConsoleSetting().Announcements)
  196. }
  197. func GetFAQ() []map[string]interface{} {
  198. return getJSONList(GetConsoleSetting().FAQ)
  199. }
  200. func validateUptimeKumaGroups(groupsStr string) error {
  201. groups, err := parseJSONArray(groupsStr, "Uptime Kuma分组配置")
  202. if err != nil {
  203. return err
  204. }
  205. if len(groups) > 20 {
  206. return fmt.Errorf("Uptime Kuma分组数量不能超过20个")
  207. }
  208. nameSet := make(map[string]bool)
  209. for i, group := range groups {
  210. categoryName, ok := group["categoryName"].(string)
  211. if !ok || categoryName == "" {
  212. return fmt.Errorf("第%d个分组缺少分类名称字段", i+1)
  213. }
  214. if nameSet[categoryName] {
  215. return fmt.Errorf("第%d个分组的分类名称与其他分组重复", i+1)
  216. }
  217. nameSet[categoryName] = true
  218. urlStr, ok := group["url"].(string)
  219. if !ok || urlStr == "" {
  220. return fmt.Errorf("第%d个分组缺少URL字段", i+1)
  221. }
  222. slug, ok := group["slug"].(string)
  223. if !ok || slug == "" {
  224. return fmt.Errorf("第%d个分组缺少Slug字段", i+1)
  225. }
  226. description, ok := group["description"].(string)
  227. if !ok {
  228. description = ""
  229. }
  230. if err := validateURL(urlStr, i+1, "分组"); err != nil {
  231. return err
  232. }
  233. if len(categoryName) > 50 {
  234. return fmt.Errorf("第%d个分组的分类名称长度不能超过50字符", i+1)
  235. }
  236. if len(urlStr) > 500 {
  237. return fmt.Errorf("第%d个分组的URL长度不能超过500字符", i+1)
  238. }
  239. if len(slug) > 100 {
  240. return fmt.Errorf("第%d个分组的Slug长度不能超过100字符", i+1)
  241. }
  242. if len(description) > 200 {
  243. return fmt.Errorf("第%d个分组的描述长度不能超过200字符", i+1)
  244. }
  245. if !slugRegex.MatchString(slug) {
  246. return fmt.Errorf("第%d个分组的Slug只能包含字母、数字、下划线和连字符", i+1)
  247. }
  248. if err := checkDangerousContent(description, i+1, "分组"); err != nil {
  249. return err
  250. }
  251. if err := checkDangerousContent(categoryName, i+1, "分组"); err != nil {
  252. return err
  253. }
  254. }
  255. return nil
  256. }
  257. func GetUptimeKumaGroups() []map[string]interface{} {
  258. return getJSONList(GetConsoleSetting().UptimeKumaGroups)
  259. }