feat: tg/ws/security/
This commit is contained in:
@@ -4,6 +4,7 @@ namespace App\Http\Controllers\Admin;
|
||||
|
||||
use App\Http\Controllers\Controller;
|
||||
use App\Models\Admin;
|
||||
use App\Models\SystemLog;
|
||||
use App\Services\AdminGoogle2fa;
|
||||
use App\Support\VisitorIp;
|
||||
use Illuminate\Http\JsonResponse;
|
||||
@@ -61,12 +62,47 @@ class AuthController extends Controller
|
||||
]);
|
||||
}
|
||||
|
||||
// Account-level lock: if the admin account is locked due to too many
|
||||
// consecutive wrong passwords, reject the login regardless of IP.
|
||||
$admin = Admin::query()->where('username', $credentials['username'])->first();
|
||||
if ($admin && $admin->isLocked()) {
|
||||
return response()->json([
|
||||
'code' => 1,
|
||||
'msg' => '账号已被封锁(连续输错密码 '.self::MAX_ATTEMPTS.' 次),请联系超级管理员解除',
|
||||
]);
|
||||
}
|
||||
|
||||
if (! Auth::guard('admin')->attempt(
|
||||
['username' => $credentials['username'], 'password' => $credentials['password']],
|
||||
false
|
||||
)) {
|
||||
RateLimiter::hit($throttleKey, self::DECAY_SECONDS);
|
||||
|
||||
// Track consecutive wrong passwords on the account itself.
|
||||
if ($admin) {
|
||||
$justLocked = $admin->recordFailedLogin(self::MAX_ATTEMPTS);
|
||||
if ($justLocked) {
|
||||
SystemLog::record(
|
||||
$admin,
|
||||
'admin',
|
||||
SystemLog::ACTION_ADMIN_LOCKED,
|
||||
'管理员「'.$admin->username.'」连续输错密码 '.self::MAX_ATTEMPTS.' 次,账号被自动封锁',
|
||||
$request,
|
||||
);
|
||||
return response()->json([
|
||||
'code' => 1,
|
||||
'msg' => '密码连续输错 '.self::MAX_ATTEMPTS.' 次,账号已被封锁,请联系超级管理员解除',
|
||||
]);
|
||||
}
|
||||
$remaining = self::MAX_ATTEMPTS - (int) $admin->fresh()->login_attempts;
|
||||
if ($remaining > 0) {
|
||||
return response()->json([
|
||||
'code' => 1,
|
||||
'msg' => '用户名或密码错误(剩余 '.$remaining.' 次尝试机会)',
|
||||
]);
|
||||
}
|
||||
}
|
||||
|
||||
return response()->json(['code' => 1, 'msg' => '用户名或密码错误']);
|
||||
}
|
||||
|
||||
@@ -96,6 +132,7 @@ class AuthController extends Controller
|
||||
}
|
||||
|
||||
RateLimiter::clear($throttleKey);
|
||||
$user->clearLoginAttempts();
|
||||
$request->session()->regenerate();
|
||||
|
||||
$user->forceFill(['last_ip' => VisitorIp::fromRequest($request)])->save();
|
||||
|
||||
Reference in New Issue
Block a user