ops_auth_service.go 12 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395
  1. package service
  2. import (
  3. "context"
  4. "net/http"
  5. "strings"
  6. "time"
  7. "cmr-backend/internal/apperr"
  8. "cmr-backend/internal/platform/jwtx"
  9. "cmr-backend/internal/platform/security"
  10. "cmr-backend/internal/store/postgres"
  11. )
  12. type OpsAuthSettings struct {
  13. AppEnv string
  14. RefreshTTL time.Duration
  15. SMSCodeTTL time.Duration
  16. SMSCodeCooldown time.Duration
  17. SMSProvider string
  18. DevSMSCode string
  19. }
  20. type OpsAuthService struct {
  21. cfg OpsAuthSettings
  22. store *postgres.Store
  23. jwtManager *jwtx.Manager
  24. }
  25. type OpsSendSMSCodeInput struct {
  26. CountryCode string `json:"countryCode"`
  27. Mobile string `json:"mobile"`
  28. DeviceKey string `json:"deviceKey"`
  29. Scene string `json:"scene"`
  30. }
  31. type OpsRegisterInput struct {
  32. CountryCode string `json:"countryCode"`
  33. Mobile string `json:"mobile"`
  34. Code string `json:"code"`
  35. DeviceKey string `json:"deviceKey"`
  36. DisplayName string `json:"displayName"`
  37. }
  38. type OpsLoginSMSInput struct {
  39. CountryCode string `json:"countryCode"`
  40. Mobile string `json:"mobile"`
  41. Code string `json:"code"`
  42. DeviceKey string `json:"deviceKey"`
  43. }
  44. type OpsRefreshTokenInput struct {
  45. RefreshToken string `json:"refreshToken"`
  46. DeviceKey string `json:"deviceKey"`
  47. }
  48. type OpsLogoutInput struct {
  49. RefreshToken string `json:"refreshToken"`
  50. }
  51. type OpsAuthUser struct {
  52. ID string `json:"id"`
  53. PublicID string `json:"publicId"`
  54. DisplayName string `json:"displayName"`
  55. Status string `json:"status"`
  56. RoleCode string `json:"roleCode"`
  57. }
  58. type OpsAuthResult struct {
  59. User OpsAuthUser `json:"user"`
  60. Tokens AuthTokens `json:"tokens"`
  61. NewUser bool `json:"newUser"`
  62. DevLoginBypass bool `json:"devLoginBypass,omitempty"`
  63. }
  64. func NewOpsAuthService(cfg OpsAuthSettings, store *postgres.Store, jwtManager *jwtx.Manager) *OpsAuthService {
  65. return &OpsAuthService{cfg: cfg, store: store, jwtManager: jwtManager}
  66. }
  67. func (s *OpsAuthService) SendSMSCode(ctx context.Context, input OpsSendSMSCodeInput) (*SendSMSCodeResult, error) {
  68. input.CountryCode = normalizeCountryCode(input.CountryCode)
  69. input.Mobile = normalizeMobile(input.Mobile)
  70. input.Scene = normalizeOpsScene(input.Scene)
  71. if input.Mobile == "" || strings.TrimSpace(input.DeviceKey) == "" {
  72. return nil, apperr.New(http.StatusBadRequest, "invalid_params", "mobile and deviceKey are required")
  73. }
  74. latest, err := s.store.GetLatestSMSCodeMeta(ctx, input.CountryCode, input.Mobile, "ops", input.Scene)
  75. if err != nil {
  76. return nil, err
  77. }
  78. now := time.Now().UTC()
  79. if latest != nil && latest.CooldownUntil.After(now) {
  80. return nil, apperr.New(http.StatusTooManyRequests, "sms_cooldown", "sms code sent too frequently")
  81. }
  82. code := s.cfg.DevSMSCode
  83. if code == "" {
  84. code, err = security.GenerateNumericCode(6)
  85. if err != nil {
  86. return nil, err
  87. }
  88. }
  89. expiresAt := now.Add(s.cfg.SMSCodeTTL)
  90. cooldownUntil := now.Add(s.cfg.SMSCodeCooldown)
  91. if err := s.store.CreateSMSCode(ctx, postgres.CreateSMSCodeParams{
  92. Scene: input.Scene,
  93. CountryCode: input.CountryCode,
  94. Mobile: input.Mobile,
  95. ClientType: "ops",
  96. DeviceKey: input.DeviceKey,
  97. CodeHash: security.HashText(code),
  98. ProviderName: s.cfg.SMSProvider,
  99. ProviderDebug: map[string]any{"mode": s.cfg.SMSProvider, "channel": "ops_console"},
  100. ExpiresAt: expiresAt,
  101. CooldownUntil: cooldownUntil,
  102. }); err != nil {
  103. return nil, err
  104. }
  105. result := &SendSMSCodeResult{
  106. TTLSeconds: int64(s.cfg.SMSCodeTTL.Seconds()),
  107. CooldownSeconds: int64(s.cfg.SMSCodeCooldown.Seconds()),
  108. }
  109. if strings.EqualFold(s.cfg.SMSProvider, "console") || strings.EqualFold(s.cfg.AppEnv, "development") {
  110. result.DevCode = &code
  111. }
  112. return result, nil
  113. }
  114. func (s *OpsAuthService) Register(ctx context.Context, input OpsRegisterInput) (*OpsAuthResult, error) {
  115. input.CountryCode = normalizeCountryCode(input.CountryCode)
  116. input.Mobile = normalizeMobile(input.Mobile)
  117. input.Code = strings.TrimSpace(input.Code)
  118. input.DeviceKey = strings.TrimSpace(input.DeviceKey)
  119. input.DisplayName = strings.TrimSpace(input.DisplayName)
  120. if input.Mobile == "" || input.Code == "" || input.DeviceKey == "" || input.DisplayName == "" {
  121. return nil, apperr.New(http.StatusBadRequest, "invalid_params", "mobile, code, deviceKey and displayName are required")
  122. }
  123. codeRecord, err := s.store.GetLatestValidSMSCode(ctx, input.CountryCode, input.Mobile, "ops", "ops_register")
  124. if err != nil {
  125. return nil, err
  126. }
  127. if codeRecord == nil || codeRecord.CodeHash != security.HashText(input.Code) {
  128. return nil, apperr.New(http.StatusUnauthorized, "invalid_sms_code", "invalid sms code")
  129. }
  130. tx, err := s.store.Begin(ctx)
  131. if err != nil {
  132. return nil, err
  133. }
  134. defer tx.Rollback(ctx)
  135. consumed, err := s.store.ConsumeSMSCode(ctx, tx, codeRecord.ID)
  136. if err != nil {
  137. return nil, err
  138. }
  139. if !consumed {
  140. return nil, apperr.New(http.StatusUnauthorized, "invalid_sms_code", "sms code already used")
  141. }
  142. existing, err := s.store.GetOpsUserByMobile(ctx, tx, input.CountryCode, input.Mobile)
  143. if err != nil {
  144. return nil, err
  145. }
  146. if existing != nil {
  147. return nil, apperr.New(http.StatusConflict, "ops_user_exists", "ops user already exists")
  148. }
  149. publicID, err := security.GeneratePublicID("ops")
  150. if err != nil {
  151. return nil, err
  152. }
  153. user, err := s.store.CreateOpsUser(ctx, tx, postgres.CreateOpsUserParams{
  154. PublicID: publicID,
  155. CountryCode: input.CountryCode,
  156. Mobile: input.Mobile,
  157. DisplayName: input.DisplayName,
  158. Status: "active",
  159. })
  160. if err != nil {
  161. return nil, err
  162. }
  163. roleCode := "operator"
  164. count, err := s.store.CountOpsUsers(ctx)
  165. if err == nil && count == 0 {
  166. roleCode = "owner"
  167. }
  168. role, err := s.store.GetOpsRoleByCode(ctx, tx, roleCode)
  169. if err != nil {
  170. return nil, err
  171. }
  172. if role == nil {
  173. return nil, apperr.New(http.StatusInternalServerError, "ops_role_missing", "default ops role is missing")
  174. }
  175. if err := s.store.AssignOpsRole(ctx, tx, user.ID, role.ID); err != nil {
  176. return nil, err
  177. }
  178. if err := s.store.TouchOpsUserLogin(ctx, tx, user.ID); err != nil {
  179. return nil, err
  180. }
  181. result, _, err := s.issueAuthResult(ctx, tx, *user, input.DeviceKey, true)
  182. if err != nil {
  183. return nil, err
  184. }
  185. if err := tx.Commit(ctx); err != nil {
  186. return nil, err
  187. }
  188. return result, nil
  189. }
  190. func (s *OpsAuthService) LoginSMS(ctx context.Context, input OpsLoginSMSInput) (*OpsAuthResult, error) {
  191. input.CountryCode = normalizeCountryCode(input.CountryCode)
  192. input.Mobile = normalizeMobile(input.Mobile)
  193. input.Code = strings.TrimSpace(input.Code)
  194. input.DeviceKey = strings.TrimSpace(input.DeviceKey)
  195. if input.Mobile == "" || input.Code == "" || input.DeviceKey == "" {
  196. return nil, apperr.New(http.StatusBadRequest, "invalid_params", "mobile, code and deviceKey are required")
  197. }
  198. codeRecord, err := s.store.GetLatestValidSMSCode(ctx, input.CountryCode, input.Mobile, "ops", "ops_login")
  199. if err != nil {
  200. return nil, err
  201. }
  202. if codeRecord == nil || codeRecord.CodeHash != security.HashText(input.Code) {
  203. return nil, apperr.New(http.StatusUnauthorized, "invalid_sms_code", "invalid sms code")
  204. }
  205. tx, err := s.store.Begin(ctx)
  206. if err != nil {
  207. return nil, err
  208. }
  209. defer tx.Rollback(ctx)
  210. consumed, err := s.store.ConsumeSMSCode(ctx, tx, codeRecord.ID)
  211. if err != nil {
  212. return nil, err
  213. }
  214. if !consumed {
  215. return nil, apperr.New(http.StatusUnauthorized, "invalid_sms_code", "sms code already used")
  216. }
  217. user, err := s.store.GetOpsUserByMobile(ctx, tx, input.CountryCode, input.Mobile)
  218. if err != nil {
  219. return nil, err
  220. }
  221. if user == nil {
  222. return nil, apperr.New(http.StatusNotFound, "ops_user_not_found", "ops user not found")
  223. }
  224. if user.Status != "active" {
  225. return nil, apperr.New(http.StatusForbidden, "ops_user_inactive", "ops user is not active")
  226. }
  227. if err := s.store.TouchOpsUserLogin(ctx, tx, user.ID); err != nil {
  228. return nil, err
  229. }
  230. result, _, err := s.issueAuthResult(ctx, tx, *user, input.DeviceKey, false)
  231. if err != nil {
  232. return nil, err
  233. }
  234. if err := tx.Commit(ctx); err != nil {
  235. return nil, err
  236. }
  237. return result, nil
  238. }
  239. func (s *OpsAuthService) Refresh(ctx context.Context, input OpsRefreshTokenInput) (*OpsAuthResult, error) {
  240. input.RefreshToken = strings.TrimSpace(input.RefreshToken)
  241. if input.RefreshToken == "" {
  242. return nil, apperr.New(http.StatusBadRequest, "invalid_params", "refreshToken is required")
  243. }
  244. tx, err := s.store.Begin(ctx)
  245. if err != nil {
  246. return nil, err
  247. }
  248. defer tx.Rollback(ctx)
  249. record, err := s.store.GetOpsRefreshTokenForUpdate(ctx, tx, security.HashText(input.RefreshToken))
  250. if err != nil {
  251. return nil, err
  252. }
  253. if record == nil || record.IsRevoked || record.ExpiresAt.Before(time.Now().UTC()) {
  254. return nil, apperr.New(http.StatusUnauthorized, "invalid_refresh_token", "refresh token is invalid or expired")
  255. }
  256. if input.DeviceKey != "" && record.DeviceKey != nil && input.DeviceKey != *record.DeviceKey {
  257. return nil, apperr.New(http.StatusUnauthorized, "invalid_refresh_token", "refresh token device mismatch")
  258. }
  259. user, err := s.store.GetOpsUserByID(ctx, tx, record.OpsUserID)
  260. if err != nil {
  261. return nil, err
  262. }
  263. if user == nil || user.Status != "active" {
  264. return nil, apperr.New(http.StatusUnauthorized, "invalid_refresh_token", "refresh token user not found")
  265. }
  266. result, newTokenID, err := s.issueAuthResult(ctx, tx, *user, nullableStringValue(record.DeviceKey), false)
  267. if err != nil {
  268. return nil, err
  269. }
  270. if err := s.store.RotateOpsRefreshToken(ctx, tx, record.ID, newTokenID); err != nil {
  271. return nil, err
  272. }
  273. if err := tx.Commit(ctx); err != nil {
  274. return nil, err
  275. }
  276. return result, nil
  277. }
  278. func (s *OpsAuthService) Logout(ctx context.Context, input OpsLogoutInput) error {
  279. if strings.TrimSpace(input.RefreshToken) == "" {
  280. return nil
  281. }
  282. return s.store.RevokeOpsRefreshToken(ctx, security.HashText(strings.TrimSpace(input.RefreshToken)))
  283. }
  284. func (s *OpsAuthService) GetMe(ctx context.Context, opsUserID string) (*OpsAuthUser, error) {
  285. user, err := s.store.GetOpsUserByID(ctx, s.store.Pool(), opsUserID)
  286. if err != nil {
  287. return nil, err
  288. }
  289. if user == nil {
  290. return nil, apperr.New(http.StatusNotFound, "ops_user_not_found", "ops user not found")
  291. }
  292. role, err := s.store.GetPrimaryOpsRole(ctx, s.store.Pool(), user.ID)
  293. if err != nil {
  294. return nil, err
  295. }
  296. result := buildOpsAuthUser(*user, role)
  297. return &result, nil
  298. }
  299. func (s *OpsAuthService) issueAuthResult(ctx context.Context, tx postgres.Tx, user postgres.OpsUser, deviceKey string, newUser bool) (*OpsAuthResult, string, error) {
  300. role, err := s.store.GetPrimaryOpsRole(ctx, tx, user.ID)
  301. if err != nil {
  302. return nil, "", err
  303. }
  304. roleCode := ""
  305. if role != nil {
  306. roleCode = role.RoleCode
  307. }
  308. accessToken, accessExpiresAt, err := s.jwtManager.IssueActorAccessToken(user.ID, user.PublicID, "ops", roleCode)
  309. if err != nil {
  310. return nil, "", err
  311. }
  312. refreshToken, err := security.GenerateToken(32)
  313. if err != nil {
  314. return nil, "", err
  315. }
  316. refreshTokenHash := security.HashText(refreshToken)
  317. refreshExpiresAt := time.Now().UTC().Add(s.cfg.RefreshTTL)
  318. refreshID, err := s.store.CreateOpsRefreshToken(ctx, tx, postgres.CreateOpsRefreshTokenParams{
  319. OpsUserID: user.ID,
  320. DeviceKey: deviceKey,
  321. TokenHash: refreshTokenHash,
  322. ExpiresAt: refreshExpiresAt,
  323. })
  324. if err != nil {
  325. return nil, "", err
  326. }
  327. result := &OpsAuthResult{
  328. User: buildOpsAuthUser(user, role),
  329. Tokens: AuthTokens{
  330. AccessToken: accessToken,
  331. AccessTokenExpiresAt: accessExpiresAt.Format(time.RFC3339),
  332. RefreshToken: refreshToken,
  333. RefreshTokenExpiresAt: refreshExpiresAt.Format(time.RFC3339),
  334. },
  335. NewUser: newUser,
  336. }
  337. return result, refreshID, nil
  338. }
  339. func buildOpsAuthUser(user postgres.OpsUser, role *postgres.OpsRole) OpsAuthUser {
  340. roleCode := ""
  341. if role != nil {
  342. roleCode = role.RoleCode
  343. }
  344. return OpsAuthUser{
  345. ID: user.ID,
  346. PublicID: user.PublicID,
  347. DisplayName: user.DisplayName,
  348. Status: user.Status,
  349. RoleCode: roleCode,
  350. }
  351. }
  352. func normalizeOpsScene(value string) string {
  353. switch strings.TrimSpace(value) {
  354. case "ops_register":
  355. return "ops_register"
  356. default:
  357. return "ops_login"
  358. }
  359. }