ErrorController.cs 8.0 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226
  1. using FreeRedis;
  2. using Hangfire;
  3. using Masuit.MyBlogs.Core.Common;
  4. using Masuit.MyBlogs.Core.Configs;
  5. using Masuit.MyBlogs.Core.Extensions.Firewall;
  6. using Masuit.Tools.AspNetCore.Mime;
  7. using Masuit.Tools.Core.Validator;
  8. using Masuit.Tools.Logging;
  9. using Microsoft.AspNetCore.Diagnostics;
  10. using Microsoft.AspNetCore.Mvc;
  11. using Microsoft.EntityFrameworkCore;
  12. using Microsoft.Net.Http.Headers;
  13. using System.Diagnostics;
  14. using System.Text;
  15. using System.Web;
  16. using SameSiteMode = Microsoft.AspNetCore.Http.SameSiteMode;
  17. namespace Masuit.MyBlogs.Core.Controllers;
  18. /// <summary>
  19. /// 错误页
  20. /// </summary>
  21. [ApiExplorerSettings(IgnoreApi = true)]
  22. public sealed class ErrorController : Controller
  23. {
  24. public IRedisClient RedisClient { get; set; }
  25. /// <summary>
  26. /// 404
  27. /// </summary>
  28. /// <returns></returns>
  29. [Route("error"), Route("{*url}", Order = 99999), ResponseCache(Duration = 36000)]
  30. public ActionResult Index()
  31. {
  32. Response.StatusCode = 404;
  33. string accept = Request.Headers[HeaderNames.Accept] + "";
  34. return true switch
  35. {
  36. _ when accept.StartsWith("image") => File("/Assets/images/404/4044.jpg", ContentType.Jpeg),
  37. _ when Request.HasJsonContentType() || Request.Method == HttpMethods.Post => Json(new
  38. {
  39. StatusCode = 404,
  40. Success = false,
  41. Message = "页面未找到!"
  42. }),
  43. _ => View("Index")
  44. };
  45. }
  46. /// <summary>
  47. /// 503
  48. /// </summary>
  49. /// <returns></returns>
  50. [Route("ServiceUnavailable")]
  51. public async Task<ActionResult> ServiceUnavailable()
  52. {
  53. var feature = HttpContext.Features.Get<IExceptionHandlerPathFeature>();
  54. if (feature != null)
  55. {
  56. string err;
  57. var ip = HttpContext.Connection.RemoteIpAddress;
  58. switch (feature.Error)
  59. {
  60. case DbUpdateConcurrencyException ex:
  61. err = $"数据库并发更新异常,更新表:{ex.Entries.Select(e => e.Metadata.Name)},请求路径({Request.Method}):{Request.Scheme}://{Request.Host}{HttpUtility.UrlDecode(feature.Path)}{Request.QueryString},客户端用户代理:{Request.Headers[HeaderNames.UserAgent]},客户端IP:{ip}\t{ex.InnerException?.Message},请求参数:\n{await GetRequestBody(Request)}\n堆栈信息:";
  62. LogManager.Error(err, ex.Demystify());
  63. break;
  64. case DbUpdateException ex:
  65. err = $"数据库更新时异常,更新表:{ex.Entries.Select(e => e.Metadata.Name)},请求路径({Request.Method}):{Request.Scheme}://{Request.Host}{HttpUtility.UrlDecode(feature.Path)}{Request.QueryString} ,客户端用户代理:{Request.Headers[HeaderNames.UserAgent]},客户端IP:{ip}\t{ex.InnerException?.Message},请求参数:\n{await GetRequestBody(Request)}\n堆栈信息:";
  66. LogManager.Error(err, ex.Demystify());
  67. break;
  68. case AggregateException ex:
  69. LogManager.Debug("↓↓↓" + ex.Message + "↓↓↓");
  70. ex.Flatten().Handle(e =>
  71. {
  72. LogManager.Error($"异常源:{e.Source},异常类型:{e.GetType().Name},请求路径({Request.Method}):{Request.Scheme}://{Request.Host}{HttpUtility.UrlDecode(feature.Path)}{Request.QueryString} ,客户端用户代理:{Request.Headers[HeaderNames.UserAgent]},客户端IP:{ip}\t", e.Demystify());
  73. return true;
  74. });
  75. var body = await GetRequestBody(Request);
  76. if (!string.IsNullOrEmpty(body))
  77. {
  78. LogManager.Debug("↑↑↑请求参数:\n" + body);
  79. }
  80. break;
  81. case AccessDenyException:
  82. var entry = ip.GetIPLocation();
  83. var tips = Template.Create(CommonHelper.SystemSettings.GetOrAdd("AccessDenyTips", @"<h4>遇到了什么问题?</h4>
  84. <h4>基于主观因素考虑,您所在的地区暂时不允许访问本站,如有疑问,请联系站长!或者请联系站长开通本站的访问权限!</h4>")).Set("clientip", ip.ToString()).Set("location", entry.Address).Set("network", entry.Network).Render();
  85. Response.StatusCode = 403;
  86. return View("AccessDeny", tips);
  87. case TempDenyException:
  88. Response.StatusCode = 429;
  89. return Request.HasJsonContentType() || Request.Method == HttpMethods.Post ? Json(new
  90. {
  91. StatusCode = 429,
  92. Success = false,
  93. Message = $"检测到您的IP({ip})访问过于频繁,已被本站暂时禁止访问,请稍后再试!"
  94. }) : View("TempDeny");
  95. default:
  96. LogManager.Error($"异常源:{feature.Error.Source},异常类型:{feature.Error.GetType().Name},请求路径({Request.Method}):{Request.Scheme}://{Request.Host}{HttpUtility.UrlDecode(feature.Path)}{Request.QueryString} ,客户端用户代理:{Request.Headers[HeaderNames.UserAgent]},客户端IP:{ip},请求参数:\n{await GetRequestBody(Request)}\n堆栈信息:", feature.Error.Demystify());
  97. break;
  98. }
  99. }
  100. Response.StatusCode = 503;
  101. return Request.HasJsonContentType() || Request.Method == HttpMethods.Post ? Json(new
  102. {
  103. StatusCode = 503,
  104. Success = false,
  105. Message = "服务器发生错误!"
  106. }) : View();
  107. }
  108. private static async Task<string> GetRequestBody(HttpRequest req)
  109. {
  110. if (req.ContentLength > 5120)
  111. {
  112. return "请求体超长";
  113. }
  114. req.Body.Seek(0, SeekOrigin.Begin);
  115. using var sr = new StreamReader(req.Body, Encoding.UTF8, false);
  116. var body = await sr.ReadToEndAsync();
  117. body = HttpUtility.UrlDecode(body);
  118. req.Body.Position = 0;
  119. return body;
  120. }
  121. /// <summary>
  122. /// 网站升级中
  123. /// </summary>
  124. /// <returns></returns>
  125. [Route("ComingSoon"), ResponseCache(Duration = 360000)]
  126. public ActionResult ComingSoon()
  127. {
  128. return View();
  129. }
  130. /// <summary>
  131. /// 检查访问密码
  132. /// </summary>
  133. /// <param name="email"></param>
  134. /// <param name="token"></param>
  135. /// <returns></returns>
  136. [HttpPost, ValidateAntiForgeryToken, AllowAccessFirewall]
  137. public ActionResult CheckViewToken(string email, string token)
  138. {
  139. if (string.IsNullOrEmpty(token))
  140. {
  141. return ResultData(null, false, "请输入访问密码!");
  142. }
  143. var s = RedisClient.Get("token:" + email);
  144. if (!token.Equals(s))
  145. {
  146. return ResultData(null, false, "访问密码不正确!");
  147. }
  148. Response.Cookies.Append("Email", email, new CookieOptions
  149. {
  150. Expires = DateTime.Now.AddYears(1),
  151. SameSite = SameSiteMode.Lax
  152. });
  153. Response.Cookies.Append("FullAccessToken", email.MDString(AppConfig.BaiduAK), new CookieOptions
  154. {
  155. Expires = DateTime.Now.AddYears(1),
  156. SameSite = SameSiteMode.Lax
  157. });
  158. return ResultData(null);
  159. }
  160. /// <summary>
  161. /// 检查授权邮箱
  162. /// </summary>
  163. /// <param name="userInfoService"></param>
  164. /// <param name="email"></param>
  165. /// <returns></returns>
  166. [HttpPost, ValidateAntiForgeryToken, AllowAccessFirewall, ResponseCache(Duration = 100, VaryByQueryKeys = new[] { "email" })]
  167. public ActionResult GetViewToken([FromServices] IUserInfoService userInfoService, string email)
  168. {
  169. var validator = new IsEmailAttribute();
  170. if (!validator.IsValid(email))
  171. {
  172. return ResultData(null, false, validator.ErrorMessage);
  173. }
  174. if (RedisClient.Exists("get:" + email))
  175. {
  176. RedisClient.Expire("get:" + email, 120);
  177. return ResultData(null, false, "发送频率限制,请在2分钟后重新尝试发送邮件!请检查你的邮件,若未收到,请检查你的邮箱地址或邮件垃圾箱!");
  178. }
  179. if (!userInfoService.Any(b => b.Email == email))
  180. {
  181. return ResultData(null, false, "您目前没有权限访问这个链接,请联系站长开通访问权限!");
  182. }
  183. var token = SnowFlake.GetInstance().GetUniqueShortId(6);
  184. RedisClient.Set("token:" + email, token, 86400);
  185. BackgroundJob.Enqueue(() => CommonHelper.SendMail(Request.Host + "博客访问验证码", $"{Request.Host}本次验证码是:<span style='color:red'>{token}</span>,有效期为24h,请按时使用!", email, HttpContext.Connection.RemoteIpAddress.ToString()));
  186. RedisClient.Set("get:" + email, token, 120);
  187. return ResultData(null);
  188. }
  189. /// <summary>
  190. /// 响应数据
  191. /// </summary>
  192. /// <param name="data">数据</param>
  193. /// <param name="success">响应状态</param>
  194. /// <param name="message">响应消息</param>
  195. /// <returns></returns>
  196. public ActionResult ResultData(object data, bool success = true, string message = "")
  197. {
  198. return Ok(new
  199. {
  200. Success = success,
  201. Message = message,
  202. Data = data
  203. });
  204. }
  205. }