mirror of
https://github.com/Wei-Shaw/sub2api.git
synced 2026-10-07 16:37:52 +08:00
沿用腾讯天御验证码引入的多服务商模型:aliyun_captcha_enabled 作为独立 开关,与 Cloudflare Turnstile、腾讯天御三方互斥(保存校验 + 运行时 CAPTCHA_PROVIDER_CONFLICT)。后台「安全与认证」合并为单张人机验证卡片: 总开关 + 服务商单选(Turnstile / 腾讯天御 / 阿里云),选中即启用该家并 关闭其它,落库仍是三个独立开关键,由前端映射保证互斥。 阿里云侧同时支持 aliyun 中国站与国际站(alibabacloud.com):两站前端脚本、 region 取值与服务端 API 完全一致,仅账号与 AccessKey 相互独立,因此由 「服务地域」决定线路即可——中国内地走 captcha.cn-shanghai.aliyuncs.com, 非中国内地(新加坡)走 captcha.ap-southeast-1.aliyuncs.com,AccessKey 取自持有该实例的账号,无需在配置中区分站点。 - AliyunCaptchaService 对称 TencentCaptchaService:服务端校验走官方 SDK VerifyIntelligentCaptcha,调用异常按 fail-closed 拦截,与 Turnstile 网络错误行为对称;保存设置时真实探测 AK/SK 有效性 - 保护面对齐腾讯扩展入口:VerifyTencentCaptchaIfEnabled 通用化为 VerifyActionCaptchaIfEnabled,OAuth 登录启动、passkey 登录在阿里云 启用时同样拦截;Turnstile 维持既有覆盖不扩大 - 前端 AliyunCaptchaWidget 为表单内预验证按钮(popup 模式),同时暴露 verify() 供 OAuth 启动、passkey 等动作入口程序化弹窗;未预验证直接 提交时弹窗兜底。SDK 按钮绑定异步完成,弹窗未出现前按 tick 重试触发, 并轮询弹窗可见性识别用户关闭 - captchaVerifyParam 复用 turnstile_token 请求字段提交;公开设置下发 aliyun_captcha_enabled / scene_id / prefix / region - CSP 放行验证码 CDN:script-src/style-src 加 *.alicdn.com
189 lines
7.2 KiB
Go
189 lines
7.2 KiB
Go
//go:build unit
|
|
|
|
package service
|
|
|
|
import (
|
|
"context"
|
|
"errors"
|
|
"testing"
|
|
|
|
"github.com/Wei-Shaw/sub2api/internal/config"
|
|
"github.com/stretchr/testify/require"
|
|
)
|
|
|
|
func newAuthServiceForCaptchaRepoTest(repo *settingRepoStub, required bool, turnstileVerifier TurnstileVerifier, tencentVerifier TencentCaptchaVerifier) *AuthService {
|
|
cfg := &config.Config{
|
|
Server: config.ServerConfig{Mode: "release"},
|
|
Turnstile: config.TurnstileConfig{Required: required},
|
|
}
|
|
settingService := NewSettingService(repo, cfg)
|
|
turnstileService := NewTurnstileService(settingService, turnstileVerifier)
|
|
tencentService := NewTencentCaptchaService(settingService, tencentVerifier)
|
|
svc := NewAuthService(nil, &userRepoStub{}, nil, nil, cfg, settingService, nil, turnstileService, nil, nil, nil, nil, nil)
|
|
svc.SetTencentCaptchaService(tencentService)
|
|
return svc
|
|
}
|
|
|
|
func newAuthServiceForCaptchaTest(settings map[string]string, required bool, turnstileVerifier TurnstileVerifier, tencentVerifier TencentCaptchaVerifier) *AuthService {
|
|
cfg := &config.Config{
|
|
Server: config.ServerConfig{Mode: "release"},
|
|
Turnstile: config.TurnstileConfig{Required: required},
|
|
}
|
|
settingService := NewSettingService(&settingRepoStub{values: settings}, cfg)
|
|
var turnstileService *TurnstileService
|
|
if turnstileVerifier != nil {
|
|
turnstileService = NewTurnstileService(settingService, turnstileVerifier)
|
|
}
|
|
svc := NewAuthService(nil, &userRepoStub{}, nil, nil, cfg, settingService, nil, turnstileService, nil, nil, nil, nil, nil)
|
|
if tencentVerifier != nil {
|
|
svc.SetTencentCaptchaService(NewTencentCaptchaService(settingService, tencentVerifier))
|
|
}
|
|
return svc
|
|
}
|
|
|
|
func tencentCaptchaSettings() map[string]string {
|
|
return map[string]string{
|
|
SettingKeyTencentCaptchaEnabled: "true",
|
|
SettingKeyTencentCaptchaAppID: "123456789",
|
|
SettingKeyTencentCaptchaAppSecretKey: "app-secret",
|
|
SettingKeyTencentCaptchaCloudSecretID: "cloud-secret-id",
|
|
SettingKeyTencentCaptchaCloudSecretKey: "cloud-secret-key",
|
|
}
|
|
}
|
|
|
|
func TestVerifyCaptchaUsesTencentWhenEnabled(t *testing.T) {
|
|
verifier := &tencentCaptchaVerifierStub{response: &TencentCaptchaVerifyResponse{CaptchaCode: 1}}
|
|
svc := newAuthServiceForCaptchaTest(tencentCaptchaSettings(), false, nil, verifier)
|
|
|
|
err := svc.VerifyCaptcha(context.Background(), CaptchaProof{
|
|
TencentTicket: "ticket",
|
|
TencentRandstr: "@rand",
|
|
}, "203.0.113.10")
|
|
|
|
require.NoError(t, err)
|
|
require.Equal(t, 1, verifier.calls)
|
|
}
|
|
|
|
func TestVerifyCaptchaRejectsDirtyDoubleEnabledSettings(t *testing.T) {
|
|
settings := tencentCaptchaSettings()
|
|
settings[SettingKeyTurnstileEnabled] = "true"
|
|
settings[SettingKeyTurnstileSecretKey] = "turnstile-secret"
|
|
turnstileVerifier := &turnstileVerifierSpy{}
|
|
tencentVerifier := &tencentCaptchaVerifierStub{response: &TencentCaptchaVerifyResponse{CaptchaCode: 1}}
|
|
svc := newAuthServiceForCaptchaTest(settings, false, turnstileVerifier, tencentVerifier)
|
|
|
|
err := svc.VerifyCaptcha(context.Background(), CaptchaProof{
|
|
TurnstileToken: "turnstile-token",
|
|
TencentTicket: "ticket",
|
|
TencentRandstr: "@rand",
|
|
}, "203.0.113.10")
|
|
|
|
require.ErrorIs(t, err, ErrCaptchaProviderConflict)
|
|
require.Zero(t, turnstileVerifier.called)
|
|
require.Zero(t, tencentVerifier.calls)
|
|
}
|
|
|
|
func TestVerifyCaptchaRequiredModeAcceptsCompleteTencentProvider(t *testing.T) {
|
|
verifier := &tencentCaptchaVerifierStub{response: &TencentCaptchaVerifyResponse{CaptchaCode: 1}}
|
|
svc := newAuthServiceForCaptchaTest(tencentCaptchaSettings(), true, nil, verifier)
|
|
|
|
err := svc.VerifyCaptcha(context.Background(), CaptchaProof{
|
|
TencentTicket: "ticket",
|
|
TencentRandstr: "@rand",
|
|
}, "203.0.113.10")
|
|
|
|
require.NoError(t, err)
|
|
}
|
|
|
|
func TestVerifyCaptchaForRegisterSkipsDuplicateTencentTicketAfterEmailCode(t *testing.T) {
|
|
settings := tencentCaptchaSettings()
|
|
settings[SettingKeyEmailVerifyEnabled] = "true"
|
|
verifier := &tencentCaptchaVerifierStub{response: &TencentCaptchaVerifyResponse{CaptchaCode: 1}}
|
|
svc := newAuthServiceForCaptchaTest(settings, true, nil, verifier)
|
|
|
|
err := svc.VerifyCaptchaForRegister(context.Background(), CaptchaProof{}, "203.0.113.10", "123456")
|
|
|
|
require.NoError(t, err)
|
|
require.Zero(t, verifier.calls)
|
|
}
|
|
|
|
func TestVerifyCaptchaFailsClosedWhenProviderSettingsCannotBeRead(t *testing.T) {
|
|
repo := &settingRepoStub{err: errors.New("settings unavailable")}
|
|
svc := newAuthServiceForCaptchaRepoTest(repo, false, &turnstileVerifierSpy{}, &tencentCaptchaVerifierStub{})
|
|
|
|
err := svc.VerifyCaptcha(context.Background(), CaptchaProof{}, "203.0.113.10")
|
|
|
|
require.ErrorIs(t, err, ErrServiceUnavailable)
|
|
}
|
|
|
|
func TestVerifyCaptchaReadsProviderConfigurationOnce(t *testing.T) {
|
|
repo := &settingRepoStub{values: tencentCaptchaSettings()}
|
|
verifier := &tencentCaptchaVerifierStub{response: &TencentCaptchaVerifyResponse{CaptchaCode: 1}}
|
|
svc := newAuthServiceForCaptchaRepoTest(repo, false, &turnstileVerifierSpy{}, verifier)
|
|
|
|
err := svc.VerifyCaptcha(context.Background(), CaptchaProof{
|
|
TencentTicket: "ticket",
|
|
TencentRandstr: "@rand",
|
|
}, "203.0.113.10")
|
|
|
|
require.NoError(t, err)
|
|
require.Equal(t, 1, repo.getMultipleCalls)
|
|
require.Zero(t, repo.getValueCalls)
|
|
require.Equal(t, 1, verifier.calls)
|
|
}
|
|
|
|
func TestVerifyCaptchaRejectsEnabledTencentProviderWithIncompleteCredentials(t *testing.T) {
|
|
repo := &settingRepoStub{values: map[string]string{
|
|
SettingKeyTencentCaptchaEnabled: "true",
|
|
SettingKeyTencentCaptchaAppID: "123456789",
|
|
}}
|
|
verifier := &tencentCaptchaVerifierStub{response: &TencentCaptchaVerifyResponse{CaptchaCode: 1}}
|
|
svc := newAuthServiceForCaptchaRepoTest(repo, false, &turnstileVerifierSpy{}, verifier)
|
|
|
|
err := svc.VerifyCaptcha(context.Background(), CaptchaProof{
|
|
TencentTicket: "ticket",
|
|
TencentRandstr: "@rand",
|
|
}, "203.0.113.10")
|
|
|
|
require.ErrorIs(t, err, ErrTencentCaptchaNotConfigured)
|
|
require.Equal(t, 1, repo.getMultipleCalls)
|
|
require.Zero(t, verifier.calls)
|
|
}
|
|
|
|
func TestVerifyActionCaptchaIfEnabledVerifiesTencentProof(t *testing.T) {
|
|
verifier := &tencentCaptchaVerifierStub{response: &TencentCaptchaVerifyResponse{CaptchaCode: 1}}
|
|
svc := newAuthServiceForCaptchaTest(tencentCaptchaSettings(), false, nil, verifier)
|
|
|
|
err := svc.VerifyActionCaptchaIfEnabled(context.Background(), CaptchaProof{
|
|
TencentTicket: "ticket",
|
|
TencentRandstr: "@rand",
|
|
}, "203.0.113.10")
|
|
|
|
require.NoError(t, err)
|
|
require.Equal(t, 1, verifier.calls)
|
|
require.Equal(t, TencentCaptchaProof{Ticket: "ticket", Randstr: "@rand"}, verifier.proof)
|
|
}
|
|
|
|
func TestVerifyActionCaptchaIfEnabledDoesNotExpandTurnstileCoverage(t *testing.T) {
|
|
settings := map[string]string{
|
|
SettingKeyTurnstileEnabled: "true",
|
|
SettingKeyTurnstileSecretKey: "turnstile-secret",
|
|
}
|
|
turnstileVerifier := &turnstileVerifierSpy{}
|
|
svc := newAuthServiceForCaptchaTest(settings, false, turnstileVerifier, nil)
|
|
|
|
err := svc.VerifyActionCaptchaIfEnabled(context.Background(), CaptchaProof{}, "203.0.113.10")
|
|
|
|
require.NoError(t, err)
|
|
require.Zero(t, turnstileVerifier.called)
|
|
}
|
|
|
|
func TestVerifyActionCaptchaIfEnabledFailsClosedOnSettingReadError(t *testing.T) {
|
|
repo := &settingRepoStub{err: errors.New("settings unavailable")}
|
|
svc := newAuthServiceForCaptchaRepoTest(repo, false, &turnstileVerifierSpy{}, &tencentCaptchaVerifierStub{})
|
|
|
|
err := svc.VerifyActionCaptchaIfEnabled(context.Background(), CaptchaProof{}, "203.0.113.10")
|
|
|
|
require.ErrorIs(t, err, ErrServiceUnavailable)
|
|
}
|