validation.go 8.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304
  1. package console_setting
  2. import (
  3. "encoding/json"
  4. "fmt"
  5. "net/url"
  6. "regexp"
  7. "sort"
  8. "strings"
  9. "time"
  10. )
  11. var (
  12. urlRegex = regexp.MustCompile(`^https?://(?:(?:[a-zA-Z0-9](?:[a-zA-Z0-9-]{0,61}[a-zA-Z0-9])?\.)*[a-zA-Z0-9](?:[a-zA-Z0-9-]{0,61}[a-zA-Z0-9])?|(?:(?:25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\.){3}(?:25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?))(?:\:[0-9]{1,5})?(?:/.*)?$`)
  13. dangerousChars = []string{"<script", "<iframe", "javascript:", "onload=", "onerror=", "onclick="}
  14. validColors = map[string]bool{
  15. "blue": true, "green": true, "cyan": true, "purple": true, "pink": true,
  16. "red": true, "orange": true, "amber": true, "yellow": true, "lime": true,
  17. "light-green": true, "teal": true, "light-blue": true, "indigo": true,
  18. "violet": true, "grey": true,
  19. }
  20. slugRegex = regexp.MustCompile(`^[a-zA-Z0-9_-]+$`)
  21. )
  22. func parseJSONArray(jsonStr string, typeName string) ([]map[string]interface{}, error) {
  23. var list []map[string]interface{}
  24. if err := json.Unmarshal([]byte(jsonStr), &list); err != nil {
  25. return nil, fmt.Errorf("%s格式错误:%s", typeName, err.Error())
  26. }
  27. return list, nil
  28. }
  29. func validateURL(urlStr string, index int, itemType string) error {
  30. if !urlRegex.MatchString(urlStr) {
  31. return fmt.Errorf("第%d个%s的URL格式不正确", index, itemType)
  32. }
  33. if _, err := url.Parse(urlStr); err != nil {
  34. return fmt.Errorf("第%d个%s的URL无法解析:%s", index, itemType, err.Error())
  35. }
  36. return nil
  37. }
  38. func checkDangerousContent(content string, index int, itemType string) error {
  39. lower := strings.ToLower(content)
  40. for _, d := range dangerousChars {
  41. if strings.Contains(lower, d) {
  42. return fmt.Errorf("第%d个%s包含不允许的内容", index, itemType)
  43. }
  44. }
  45. return nil
  46. }
  47. func getJSONList(jsonStr string) []map[string]interface{} {
  48. if jsonStr == "" {
  49. return []map[string]interface{}{}
  50. }
  51. var list []map[string]interface{}
  52. json.Unmarshal([]byte(jsonStr), &list)
  53. return list
  54. }
  55. func ValidateConsoleSettings(settingsStr string, settingType string) error {
  56. if settingsStr == "" {
  57. return nil
  58. }
  59. switch settingType {
  60. case "ApiInfo":
  61. return validateApiInfo(settingsStr)
  62. case "Announcements":
  63. return validateAnnouncements(settingsStr)
  64. case "FAQ":
  65. return validateFAQ(settingsStr)
  66. case "UptimeKumaGroups":
  67. return validateUptimeKumaGroups(settingsStr)
  68. default:
  69. return fmt.Errorf("未知的设置类型:%s", settingType)
  70. }
  71. }
  72. func validateApiInfo(apiInfoStr string) error {
  73. apiInfoList, err := parseJSONArray(apiInfoStr, "API信息")
  74. if err != nil {
  75. return err
  76. }
  77. if len(apiInfoList) > 50 {
  78. return fmt.Errorf("API信息数量不能超过50个")
  79. }
  80. for i, apiInfo := range apiInfoList {
  81. urlStr, ok := apiInfo["url"].(string)
  82. if !ok || urlStr == "" {
  83. return fmt.Errorf("第%d个API信息缺少URL字段", i+1)
  84. }
  85. route, ok := apiInfo["route"].(string)
  86. if !ok || route == "" {
  87. return fmt.Errorf("第%d个API信息缺少线路描述字段", i+1)
  88. }
  89. description, ok := apiInfo["description"].(string)
  90. if !ok || description == "" {
  91. return fmt.Errorf("第%d个API信息缺少说明字段", i+1)
  92. }
  93. color, ok := apiInfo["color"].(string)
  94. if !ok || color == "" {
  95. return fmt.Errorf("第%d个API信息缺少颜色字段", i+1)
  96. }
  97. if err := validateURL(urlStr, i+1, "API信息"); err != nil {
  98. return err
  99. }
  100. if len(urlStr) > 500 {
  101. return fmt.Errorf("第%d个API信息的URL长度不能超过500字符", i+1)
  102. }
  103. if len(route) > 100 {
  104. return fmt.Errorf("第%d个API信息的线路描述长度不能超过100字符", i+1)
  105. }
  106. if len(description) > 200 {
  107. return fmt.Errorf("第%d个API信息的说明长度不能超过200字符", i+1)
  108. }
  109. if !validColors[color] {
  110. return fmt.Errorf("第%d个API信息的颜色值不合法", i+1)
  111. }
  112. if err := checkDangerousContent(description, i+1, "API信息"); err != nil {
  113. return err
  114. }
  115. if err := checkDangerousContent(route, i+1, "API信息"); err != nil {
  116. return err
  117. }
  118. }
  119. return nil
  120. }
  121. func GetApiInfo() []map[string]interface{} {
  122. return getJSONList(GetConsoleSetting().ApiInfo)
  123. }
  124. func validateAnnouncements(announcementsStr string) error {
  125. list, err := parseJSONArray(announcementsStr, "系统公告")
  126. if err != nil {
  127. return err
  128. }
  129. if len(list) > 100 {
  130. return fmt.Errorf("系统公告数量不能超过100个")
  131. }
  132. validTypes := map[string]bool{
  133. "default": true, "ongoing": true, "success": true, "warning": true, "error": true,
  134. }
  135. for i, ann := range list {
  136. content, ok := ann["content"].(string)
  137. if !ok || content == "" {
  138. return fmt.Errorf("第%d个公告缺少内容字段", i+1)
  139. }
  140. publishDateAny, exists := ann["publishDate"]
  141. if !exists {
  142. return fmt.Errorf("第%d个公告缺少发布日期字段", i+1)
  143. }
  144. publishDateStr, ok := publishDateAny.(string)
  145. if !ok || publishDateStr == "" {
  146. return fmt.Errorf("第%d个公告的发布日期不能为空", i+1)
  147. }
  148. if _, err := time.Parse(time.RFC3339, publishDateStr); err != nil {
  149. return fmt.Errorf("第%d个公告的发布日期格式错误", i+1)
  150. }
  151. if t, exists := ann["type"]; exists {
  152. if typeStr, ok := t.(string); ok {
  153. if !validTypes[typeStr] {
  154. return fmt.Errorf("第%d个公告的类型值不合法", i+1)
  155. }
  156. }
  157. }
  158. if len(content) > 500 {
  159. return fmt.Errorf("第%d个公告的内容长度不能超过500字符", i+1)
  160. }
  161. if extra, exists := ann["extra"]; exists {
  162. if extraStr, ok := extra.(string); ok && len(extraStr) > 200 {
  163. return fmt.Errorf("第%d个公告的说明长度不能超过200字符", i+1)
  164. }
  165. }
  166. }
  167. return nil
  168. }
  169. func validateFAQ(faqStr string) error {
  170. list, err := parseJSONArray(faqStr, "FAQ信息")
  171. if err != nil {
  172. return err
  173. }
  174. if len(list) > 100 {
  175. return fmt.Errorf("FAQ数量不能超过100个")
  176. }
  177. for i, faq := range list {
  178. question, ok := faq["question"].(string)
  179. if !ok || question == "" {
  180. return fmt.Errorf("第%d个FAQ缺少问题字段", i+1)
  181. }
  182. answer, ok := faq["answer"].(string)
  183. if !ok || answer == "" {
  184. return fmt.Errorf("第%d个FAQ缺少答案字段", i+1)
  185. }
  186. if len(question) > 200 {
  187. return fmt.Errorf("第%d个FAQ的问题长度不能超过200字符", i+1)
  188. }
  189. if len(answer) > 1000 {
  190. return fmt.Errorf("第%d个FAQ的答案长度不能超过1000字符", i+1)
  191. }
  192. }
  193. return nil
  194. }
  195. func getPublishTime(item map[string]interface{}) time.Time {
  196. if v, ok := item["publishDate"]; ok {
  197. if s, ok2 := v.(string); ok2 {
  198. if t, err := time.Parse(time.RFC3339, s); err == nil {
  199. return t
  200. }
  201. }
  202. }
  203. return time.Time{}
  204. }
  205. func GetAnnouncements() []map[string]interface{} {
  206. list := getJSONList(GetConsoleSetting().Announcements)
  207. sort.SliceStable(list, func(i, j int) bool {
  208. return getPublishTime(list[i]).After(getPublishTime(list[j]))
  209. })
  210. return list
  211. }
  212. func GetFAQ() []map[string]interface{} {
  213. return getJSONList(GetConsoleSetting().FAQ)
  214. }
  215. func validateUptimeKumaGroups(groupsStr string) error {
  216. groups, err := parseJSONArray(groupsStr, "Uptime Kuma分组配置")
  217. if err != nil {
  218. return err
  219. }
  220. if len(groups) > 20 {
  221. return fmt.Errorf("Uptime Kuma分组数量不能超过20个")
  222. }
  223. nameSet := make(map[string]bool)
  224. for i, group := range groups {
  225. categoryName, ok := group["categoryName"].(string)
  226. if !ok || categoryName == "" {
  227. return fmt.Errorf("第%d个分组缺少分类名称字段", i+1)
  228. }
  229. if nameSet[categoryName] {
  230. return fmt.Errorf("第%d个分组的分类名称与其他分组重复", i+1)
  231. }
  232. nameSet[categoryName] = true
  233. urlStr, ok := group["url"].(string)
  234. if !ok || urlStr == "" {
  235. return fmt.Errorf("第%d个分组缺少URL字段", i+1)
  236. }
  237. slug, ok := group["slug"].(string)
  238. if !ok || slug == "" {
  239. return fmt.Errorf("第%d个分组缺少Slug字段", i+1)
  240. }
  241. description, ok := group["description"].(string)
  242. if !ok {
  243. description = ""
  244. }
  245. if err := validateURL(urlStr, i+1, "分组"); err != nil {
  246. return err
  247. }
  248. if len(categoryName) > 50 {
  249. return fmt.Errorf("第%d个分组的分类名称长度不能超过50字符", i+1)
  250. }
  251. if len(urlStr) > 500 {
  252. return fmt.Errorf("第%d个分组的URL长度不能超过500字符", i+1)
  253. }
  254. if len(slug) > 100 {
  255. return fmt.Errorf("第%d个分组的Slug长度不能超过100字符", i+1)
  256. }
  257. if len(description) > 200 {
  258. return fmt.Errorf("第%d个分组的描述长度不能超过200字符", i+1)
  259. }
  260. if !slugRegex.MatchString(slug) {
  261. return fmt.Errorf("第%d个分组的Slug只能包含字母、数字、下划线和连字符", i+1)
  262. }
  263. if err := checkDangerousContent(description, i+1, "分组"); err != nil {
  264. return err
  265. }
  266. if err := checkDangerousContent(categoryName, i+1, "分组"); err != nil {
  267. return err
  268. }
  269. }
  270. return nil
  271. }
  272. func GetUptimeKumaGroups() []map[string]interface{} {
  273. return getJSONList(GetConsoleSetting().UptimeKumaGroups)
  274. }