link_auth.go 6.4 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220
  1. package handler
  2. import (
  3. "encoding/xml"
  4. "fmt"
  5. "io"
  6. "io/ioutil"
  7. "net/http"
  8. "strings"
  9. "text/template"
  10. "github.com/bjdgyc/anylink/base"
  11. "github.com/bjdgyc/anylink/dbdata"
  12. "github.com/bjdgyc/anylink/sessdata"
  13. )
  14. func LinkAuth(w http.ResponseWriter, r *http.Request) {
  15. // 判断anyconnect客户端
  16. userAgent := strings.ToLower(r.UserAgent())
  17. xAggregateAuth := r.Header.Get("X-Aggregate-Auth")
  18. xTranscendVersion := r.Header.Get("X-Transcend-Version")
  19. if !((strings.Contains(userAgent, "anyconnect") || strings.Contains(userAgent, "openconnect")) &&
  20. xAggregateAuth == "1" && xTranscendVersion == "1") {
  21. w.WriteHeader(http.StatusForbidden)
  22. fmt.Fprintf(w, "error request")
  23. return
  24. }
  25. body, err := ioutil.ReadAll(r.Body)
  26. if err != nil {
  27. w.WriteHeader(http.StatusBadRequest)
  28. return
  29. }
  30. defer r.Body.Close()
  31. cr := ClientRequest{}
  32. err = xml.Unmarshal(body, &cr)
  33. if err != nil {
  34. w.WriteHeader(http.StatusBadRequest)
  35. return
  36. }
  37. // fmt.Printf("%+v \n", cr)
  38. setCommonHeader(w)
  39. if cr.Type == "logout" {
  40. // 退出删除session信息
  41. if cr.SessionToken != "" {
  42. sessdata.DelSessByStoken(cr.SessionToken)
  43. }
  44. w.WriteHeader(http.StatusOK)
  45. return
  46. }
  47. if cr.Type == "init" {
  48. w.WriteHeader(http.StatusOK)
  49. data := RequestData{Group: cr.GroupSelect, Groups: dbdata.GetGroupNames()}
  50. tplRequest(tpl_request, w, data)
  51. return
  52. }
  53. // 登陆参数判断
  54. if cr.Type != "auth-reply" {
  55. w.WriteHeader(http.StatusBadRequest)
  56. return
  57. }
  58. // TODO 用户密码校验
  59. err = dbdata.CheckUser(cr.Auth.Username, cr.Auth.Password, cr.GroupSelect)
  60. if err != nil {
  61. base.Warn(err)
  62. w.WriteHeader(http.StatusOK)
  63. data := RequestData{Group: cr.GroupSelect, Groups: dbdata.GetGroupNames(), Error: "用户名或密码错误"}
  64. tplRequest(tpl_request, w, data)
  65. return
  66. }
  67. // if !ok {
  68. // w.WriteHeader(http.StatusOK)
  69. // data := RequestData{Group: cr.GroupSelect, Groups: base.Cfg.UserGroups, Error: "请先激活用户"}
  70. // tplRequest(tpl_request, w, data)
  71. // return
  72. // }
  73. // 创建新的session信息
  74. sess := sessdata.NewSession("")
  75. sess.Username = cr.Auth.Username
  76. sess.Group = cr.GroupSelect
  77. sess.MacAddr = strings.ToLower(cr.MacAddressList.MacAddress)
  78. sess.UniqueIdGlobal = cr.DeviceId.UniqueIdGlobal
  79. other := &dbdata.SettingOther{}
  80. _ = dbdata.SettingGet(other)
  81. rd := RequestData{SessionId: sess.Sid, SessionToken: sess.Sid + "@" + sess.Token,
  82. Banner: other.Banner}
  83. w.WriteHeader(http.StatusOK)
  84. tplRequest(tpl_complete, w, rd)
  85. base.Debug("login", cr.Auth.Username)
  86. }
  87. const (
  88. tpl_request = iota
  89. tpl_complete
  90. )
  91. func tplRequest(typ int, w io.Writer, data RequestData) {
  92. if typ == tpl_request {
  93. t, _ := template.New("auth_request").Parse(auth_request)
  94. _ = t.Execute(w, data)
  95. return
  96. }
  97. if strings.Contains(data.Banner, "\n") {
  98. // 替换xml文件的换行符
  99. data.Banner = strings.ReplaceAll(data.Banner, "\n", "
")
  100. }
  101. t, _ := template.New("auth_complete").Parse(auth_complete)
  102. _ = t.Execute(w, data)
  103. }
  104. // 设置输出信息
  105. type RequestData struct {
  106. Groups []string
  107. Group string
  108. Error string
  109. // complete
  110. SessionId string
  111. SessionToken string
  112. Banner string
  113. }
  114. var auth_request = `<?xml version="1.0" encoding="UTF-8"?>
  115. <config-auth client="vpn" type="auth-request" aggregate-auth-version="2">
  116. <opaque is-for="sg">
  117. <tunnel-group>{{.Group}}</tunnel-group>
  118. <group-alias>{{.Group}}</group-alias>
  119. <aggauth-handle>168179266</aggauth-handle>
  120. <config-hash>1595829378234</config-hash>
  121. <auth-method>multiple-cert</auth-method>
  122. <auth-method>single-sign-on-v2</auth-method>
  123. </opaque>
  124. <auth id="main">
  125. <title>Login</title>
  126. <message>请输入你的用户名和密码</message>
  127. <banner></banner>
  128. {{if .Error}}
  129. <error id="88" param1="{{.Error}}" param2="">登陆失败: %s</error>
  130. {{end}}
  131. <form>
  132. <input type="text" name="username" label="Username:"></input>
  133. <input type="password" name="password" label="Password:"></input>
  134. <select name="group_list" label="GROUP:">
  135. {{range $v := .Groups}}
  136. <option {{if eq $v $.Group}} selected="true"{{end}}>{{$v}}</option>
  137. {{end}}
  138. </select>
  139. </form>
  140. </auth>
  141. </config-auth>
  142. `
  143. var auth_complete = `<?xml version="1.0" encoding="UTF-8"?>
  144. <config-auth client="vpn" type="complete" aggregate-auth-version="2">
  145. <session-id>{{.SessionId}}</session-id>
  146. <session-token>{{.SessionToken}}</session-token>
  147. <auth id="success">
  148. <banner>{{.Banner}}</banner>
  149. <message id="0" param1="" param2=""></message>
  150. </auth>
  151. <capabilities>
  152. <crypto-supported>ssl-dhe</crypto-supported>
  153. </capabilities>
  154. <config client="vpn" type="private">
  155. <vpn-base-config>
  156. <server-cert-hash>240B97A685B2BFA66AD699B90AAC49EA66495D69</server-cert-hash>
  157. </vpn-base-config>
  158. <opaque is-for="vpn-client"></opaque>
  159. <vpn-profile-manifest>
  160. <vpn rev="1.0">
  161. <file type="profile" service-type="user">
  162. <uri>/files/profile.xml</uri>
  163. <hash type="sha1">A8B0B07FBA93D06E8501E40AB807AEE2464E73B7</hash>
  164. </file>
  165. </vpn>
  166. </vpn-profile-manifest>
  167. </config>
  168. </config-auth>
  169. `
  170. var auth_profile = `<?xml version="1.0" encoding="UTF-8"?>
  171. <AnyConnectProfile xmlns="http://schemas.xmlsoap.org/encoding/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://schemas.xmlsoap.org/encoding/ AnyConnectProfile.xsd">
  172. <ClientInitialization>
  173. <UseStartBeforeLogon UserControllable="false">false</UseStartBeforeLogon>
  174. <StrictCertificateTrust>false</StrictCertificateTrust>
  175. <RestrictPreferenceCaching>false</RestrictPreferenceCaching>
  176. <RestrictTunnelProtocols>IPSec</RestrictTunnelProtocols>
  177. <BypassDownloader>true</BypassDownloader>
  178. <WindowsVPNEstablishment>AllowRemoteUsers</WindowsVPNEstablishment>
  179. <CertEnrollmentPin>pinAllowed</CertEnrollmentPin>
  180. <CertificateMatch>
  181. <KeyUsage>
  182. <MatchKey>Digital_Signature</MatchKey>
  183. </KeyUsage>
  184. <ExtendedKeyUsage>
  185. <ExtendedMatchKey>ClientAuth</ExtendedMatchKey>
  186. </ExtendedKeyUsage>
  187. </CertificateMatch>
  188. <BackupServerList>
  189. <HostAddress>localhost</HostAddress>
  190. </BackupServerList>
  191. </ClientInitialization>
  192. <ServerList>
  193. <HostEntry>
  194. <HostName>VPN Server</HostName>
  195. <HostAddress>localhost</HostAddress>
  196. </HostEntry>
  197. </ServerList>
  198. </AnyConnectProfile>
  199. `