feat: tg/ws/security/

This commit is contained in:
hashbro
2026-10-03 05:40:19 +08:00
parent 6e4f7e6020
commit afac799588
32 changed files with 2038 additions and 18 deletions
@@ -4,6 +4,7 @@ namespace App\Http\Controllers\Admin;
use App\Http\Controllers\Controller;
use App\Models\Admin;
use App\Models\SystemLog;
use App\Services\AdminGoogle2fa;
use App\Support\VisitorIp;
use Illuminate\Http\JsonResponse;
@@ -61,12 +62,47 @@ class AuthController extends Controller
]);
}
// Account-level lock: if the admin account is locked due to too many
// consecutive wrong passwords, reject the login regardless of IP.
$admin = Admin::query()->where('username', $credentials['username'])->first();
if ($admin && $admin->isLocked()) {
return response()->json([
'code' => 1,
'msg' => '账号已被封锁(连续输错密码 '.self::MAX_ATTEMPTS.' 次),请联系超级管理员解除',
]);
}
if (! Auth::guard('admin')->attempt(
['username' => $credentials['username'], 'password' => $credentials['password']],
false
)) {
RateLimiter::hit($throttleKey, self::DECAY_SECONDS);
// Track consecutive wrong passwords on the account itself.
if ($admin) {
$justLocked = $admin->recordFailedLogin(self::MAX_ATTEMPTS);
if ($justLocked) {
SystemLog::record(
$admin,
'admin',
SystemLog::ACTION_ADMIN_LOCKED,
'管理员「'.$admin->username.'」连续输错密码 '.self::MAX_ATTEMPTS.' 次,账号被自动封锁',
$request,
);
return response()->json([
'code' => 1,
'msg' => '密码连续输错 '.self::MAX_ATTEMPTS.' 次,账号已被封锁,请联系超级管理员解除',
]);
}
$remaining = self::MAX_ATTEMPTS - (int) $admin->fresh()->login_attempts;
if ($remaining > 0) {
return response()->json([
'code' => 1,
'msg' => '用户名或密码错误(剩余 '.$remaining.' 次尝试机会)',
]);
}
}
return response()->json(['code' => 1, 'msg' => '用户名或密码错误']);
}
@@ -96,6 +132,7 @@ class AuthController extends Controller
}
RateLimiter::clear($throttleKey);
$user->clearLoginAttempts();
$request->session()->regenerate();
$user->forceFill(['last_ip' => VisitorIp::fromRequest($request)])->save();