2020-11-07 19:40:24 +08:00
|
|
|
package models
|
|
|
|
|
|
|
|
|
|
import (
|
|
|
|
|
"github.com/TeaOSLab/EdgeAPI/internal/errors"
|
2021-02-02 19:29:36 +08:00
|
|
|
"github.com/TeaOSLab/EdgeAPI/internal/utils"
|
2021-08-08 15:47:48 +08:00
|
|
|
"github.com/TeaOSLab/EdgeCommon/pkg/nodeconfigs"
|
2020-11-07 19:40:24 +08:00
|
|
|
_ "github.com/go-sql-driver/mysql"
|
|
|
|
|
"github.com/iwind/TeaGo/Tea"
|
|
|
|
|
"github.com/iwind/TeaGo/dbs"
|
2021-01-17 16:48:00 +08:00
|
|
|
"github.com/iwind/TeaGo/lists"
|
2020-11-07 19:40:24 +08:00
|
|
|
"github.com/iwind/TeaGo/types"
|
2021-02-02 19:29:36 +08:00
|
|
|
"math"
|
2020-11-09 10:44:00 +08:00
|
|
|
"time"
|
2020-11-07 19:40:24 +08:00
|
|
|
)
|
|
|
|
|
|
|
|
|
|
const (
|
|
|
|
|
IPItemStateEnabled = 1 // 已启用
|
|
|
|
|
IPItemStateDisabled = 0 // 已禁用
|
|
|
|
|
)
|
|
|
|
|
|
2021-02-02 15:25:40 +08:00
|
|
|
type IPItemType = string
|
|
|
|
|
|
|
|
|
|
const (
|
|
|
|
|
IPItemTypeIPv4 IPItemType = "ipv4" // IPv4
|
|
|
|
|
IPItemTypeIPv6 IPItemType = "ipv6" // IPv6
|
|
|
|
|
IPItemTypeAll IPItemType = "all" // 所有IP
|
|
|
|
|
)
|
|
|
|
|
|
2020-11-07 19:40:24 +08:00
|
|
|
type IPItemDAO dbs.DAO
|
|
|
|
|
|
|
|
|
|
func NewIPItemDAO() *IPItemDAO {
|
|
|
|
|
return dbs.NewDAO(&IPItemDAO{
|
|
|
|
|
DAOObject: dbs.DAOObject{
|
|
|
|
|
DB: Tea.Env,
|
|
|
|
|
Table: "edgeIPItems",
|
|
|
|
|
Model: new(IPItem),
|
|
|
|
|
PkName: "id",
|
|
|
|
|
},
|
|
|
|
|
}).(*IPItemDAO)
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
var SharedIPItemDAO *IPItemDAO
|
|
|
|
|
|
|
|
|
|
func init() {
|
|
|
|
|
dbs.OnReady(func() {
|
|
|
|
|
SharedIPItemDAO = NewIPItemDAO()
|
|
|
|
|
})
|
|
|
|
|
}
|
|
|
|
|
|
2021-06-23 13:12:54 +08:00
|
|
|
// EnableIPItem 启用条目
|
2021-01-01 23:31:30 +08:00
|
|
|
func (this *IPItemDAO) EnableIPItem(tx *dbs.Tx, id int64) error {
|
|
|
|
|
_, err := this.Query(tx).
|
2020-11-07 19:40:24 +08:00
|
|
|
Pk(id).
|
|
|
|
|
Set("state", IPItemStateEnabled).
|
|
|
|
|
Update()
|
|
|
|
|
return err
|
|
|
|
|
}
|
|
|
|
|
|
2021-06-23 13:12:54 +08:00
|
|
|
// DisableIPItem 禁用条目
|
2021-01-01 23:31:30 +08:00
|
|
|
func (this *IPItemDAO) DisableIPItem(tx *dbs.Tx, id int64) error {
|
|
|
|
|
version, err := SharedIPListDAO.IncreaseVersion(tx)
|
2020-11-10 09:22:10 +08:00
|
|
|
if err != nil {
|
|
|
|
|
return err
|
|
|
|
|
}
|
|
|
|
|
|
2021-01-01 23:31:30 +08:00
|
|
|
_, err = this.Query(tx).
|
2020-11-07 19:40:24 +08:00
|
|
|
Pk(id).
|
|
|
|
|
Set("state", IPItemStateDisabled).
|
2020-11-10 09:22:10 +08:00
|
|
|
Set("version", version).
|
2020-11-07 19:40:24 +08:00
|
|
|
Update()
|
2021-02-02 15:25:40 +08:00
|
|
|
|
|
|
|
|
if err != nil {
|
|
|
|
|
return err
|
|
|
|
|
}
|
|
|
|
|
return this.NotifyUpdate(tx, id)
|
2020-11-07 19:40:24 +08:00
|
|
|
}
|
|
|
|
|
|
2021-06-23 13:12:54 +08:00
|
|
|
// FindEnabledIPItem 查找启用中的条目
|
2021-01-01 23:31:30 +08:00
|
|
|
func (this *IPItemDAO) FindEnabledIPItem(tx *dbs.Tx, id int64) (*IPItem, error) {
|
|
|
|
|
result, err := this.Query(tx).
|
2020-11-07 19:40:24 +08:00
|
|
|
Pk(id).
|
|
|
|
|
Attr("state", IPItemStateEnabled).
|
|
|
|
|
Find()
|
|
|
|
|
if result == nil {
|
|
|
|
|
return nil, err
|
|
|
|
|
}
|
|
|
|
|
return result.(*IPItem), err
|
|
|
|
|
}
|
|
|
|
|
|
2021-07-18 15:52:34 +08:00
|
|
|
// DisableOldIPItem 根据IP删除以前的旧记录
|
|
|
|
|
func (this *IPItemDAO) DisableOldIPItem(tx *dbs.Tx, listId int64, ipFrom string, ipTo string) error {
|
|
|
|
|
return this.Query(tx).
|
|
|
|
|
Attr("listId", listId).
|
|
|
|
|
Attr("ipFrom", ipFrom).
|
|
|
|
|
Attr("ipTo", ipTo).
|
|
|
|
|
Set("state", IPItemStateDisabled).
|
|
|
|
|
UpdateQuickly()
|
|
|
|
|
}
|
|
|
|
|
|
2021-06-23 13:12:54 +08:00
|
|
|
// CreateIPItem 创建IP
|
2021-11-16 16:10:48 +08:00
|
|
|
func (this *IPItemDAO) CreateIPItem(tx *dbs.Tx,
|
|
|
|
|
listId int64,
|
|
|
|
|
ipFrom string,
|
|
|
|
|
ipTo string,
|
|
|
|
|
expiredAt int64,
|
|
|
|
|
reason string,
|
|
|
|
|
itemType IPItemType,
|
|
|
|
|
eventLevel string,
|
|
|
|
|
nodeId int64,
|
|
|
|
|
serverId int64,
|
|
|
|
|
sourceNodeId int64,
|
|
|
|
|
sourceServerId int64,
|
|
|
|
|
sourceHTTPFirewallPolicyId int64,
|
|
|
|
|
sourceHTTPFirewallRuleGroupId int64,
|
|
|
|
|
sourceHTTPFirewallRuleSetId int64) (int64, error) {
|
2021-01-01 23:31:30 +08:00
|
|
|
version, err := SharedIPListDAO.IncreaseVersion(tx)
|
2020-11-07 19:40:24 +08:00
|
|
|
if err != nil {
|
|
|
|
|
return 0, err
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
op := NewIPItemOperator()
|
|
|
|
|
op.ListId = listId
|
|
|
|
|
op.IpFrom = ipFrom
|
|
|
|
|
op.IpTo = ipTo
|
2021-02-02 19:29:36 +08:00
|
|
|
op.IpFromLong = utils.IP2Long(ipFrom)
|
|
|
|
|
op.IpToLong = utils.IP2Long(ipTo)
|
2020-11-07 19:40:24 +08:00
|
|
|
op.Reason = reason
|
2021-02-02 15:25:40 +08:00
|
|
|
op.Type = itemType
|
2021-02-06 17:38:04 +08:00
|
|
|
op.EventLevel = eventLevel
|
2020-11-07 19:40:24 +08:00
|
|
|
op.Version = version
|
|
|
|
|
if expiredAt < 0 {
|
|
|
|
|
expiredAt = 0
|
|
|
|
|
}
|
|
|
|
|
op.ExpiredAt = expiredAt
|
2021-11-16 16:10:48 +08:00
|
|
|
|
|
|
|
|
op.NodeId = nodeId
|
|
|
|
|
op.ServerId = serverId
|
|
|
|
|
op.SourceNodeId = sourceNodeId
|
|
|
|
|
op.SourceServerId = sourceServerId
|
|
|
|
|
op.SourceHTTPFirewallPolicyId = sourceHTTPFirewallPolicyId
|
|
|
|
|
op.SourceHTTPFirewallRuleGroupId = sourceHTTPFirewallRuleGroupId
|
|
|
|
|
op.SourceHTTPFirewallRuleSetId = sourceHTTPFirewallRuleSetId
|
|
|
|
|
|
2020-11-07 19:40:24 +08:00
|
|
|
op.State = IPItemStateEnabled
|
2021-01-01 23:31:30 +08:00
|
|
|
err = this.Save(tx, op)
|
2020-11-07 19:40:24 +08:00
|
|
|
if err != nil {
|
|
|
|
|
return 0, err
|
|
|
|
|
}
|
2021-02-02 15:25:40 +08:00
|
|
|
itemId := types.Int64(op.Id)
|
|
|
|
|
|
|
|
|
|
err = this.NotifyUpdate(tx, itemId)
|
|
|
|
|
if err != nil {
|
|
|
|
|
return 0, err
|
|
|
|
|
}
|
|
|
|
|
return itemId, nil
|
2020-11-07 19:40:24 +08:00
|
|
|
}
|
|
|
|
|
|
2021-06-23 13:12:54 +08:00
|
|
|
// UpdateIPItem 修改IP
|
2021-02-06 17:38:04 +08:00
|
|
|
func (this *IPItemDAO) UpdateIPItem(tx *dbs.Tx, itemId int64, ipFrom string, ipTo string, expiredAt int64, reason string, itemType IPItemType, eventLevel string) error {
|
2020-11-07 19:40:24 +08:00
|
|
|
if itemId <= 0 {
|
|
|
|
|
return errors.New("invalid itemId")
|
|
|
|
|
}
|
|
|
|
|
|
2021-01-01 23:31:30 +08:00
|
|
|
listId, err := this.Query(tx).
|
2020-11-07 19:40:24 +08:00
|
|
|
Pk(itemId).
|
|
|
|
|
Result("listId").
|
|
|
|
|
FindInt64Col(0)
|
|
|
|
|
if err != nil {
|
|
|
|
|
return err
|
|
|
|
|
}
|
|
|
|
|
if listId == 0 {
|
|
|
|
|
return errors.New("not found")
|
|
|
|
|
}
|
|
|
|
|
|
2021-01-01 23:31:30 +08:00
|
|
|
version, err := SharedIPListDAO.IncreaseVersion(tx)
|
2020-11-07 19:40:24 +08:00
|
|
|
if err != nil {
|
|
|
|
|
return err
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
op := NewIPItemOperator()
|
|
|
|
|
op.Id = itemId
|
|
|
|
|
op.IpFrom = ipFrom
|
|
|
|
|
op.IpTo = ipTo
|
2021-02-02 19:29:36 +08:00
|
|
|
op.IpFromLong = utils.IP2Long(ipFrom)
|
|
|
|
|
op.IpToLong = utils.IP2Long(ipTo)
|
2020-11-07 19:40:24 +08:00
|
|
|
op.Reason = reason
|
2021-02-02 15:25:40 +08:00
|
|
|
op.Type = itemType
|
2021-02-06 17:38:04 +08:00
|
|
|
op.EventLevel = eventLevel
|
2020-11-07 19:40:24 +08:00
|
|
|
if expiredAt < 0 {
|
|
|
|
|
expiredAt = 0
|
|
|
|
|
}
|
|
|
|
|
op.ExpiredAt = expiredAt
|
|
|
|
|
op.Version = version
|
2021-01-01 23:31:30 +08:00
|
|
|
err = this.Save(tx, op)
|
2021-02-02 15:25:40 +08:00
|
|
|
if err != nil {
|
|
|
|
|
return err
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
return this.NotifyUpdate(tx, itemId)
|
2020-11-07 19:40:24 +08:00
|
|
|
}
|
|
|
|
|
|
2021-06-23 13:12:54 +08:00
|
|
|
// CountIPItemsWithListId 计算IP数量
|
2021-10-26 09:17:33 +08:00
|
|
|
func (this *IPItemDAO) CountIPItemsWithListId(tx *dbs.Tx, listId int64, ipFrom string, ipTo string, keyword string) (int64, error) {
|
2021-10-22 12:18:53 +08:00
|
|
|
var query = this.Query(tx).
|
2020-11-07 19:40:24 +08:00
|
|
|
State(IPItemStateEnabled).
|
2021-10-22 12:18:53 +08:00
|
|
|
Attr("listId", listId)
|
|
|
|
|
if len(keyword) > 0 {
|
|
|
|
|
query.Where("(ipFrom LIKE :keyword OR ipTo LIKE :keyword)").
|
|
|
|
|
Param("keyword", "%"+keyword+"%")
|
|
|
|
|
}
|
2021-10-26 09:17:33 +08:00
|
|
|
if len(ipFrom) > 0 {
|
|
|
|
|
query.Attr("ipFrom", ipFrom)
|
|
|
|
|
}
|
|
|
|
|
if len(ipTo) > 0 {
|
|
|
|
|
query.Attr("ipTo", ipTo)
|
|
|
|
|
}
|
2021-10-22 12:18:53 +08:00
|
|
|
return query.Count()
|
2020-11-07 19:40:24 +08:00
|
|
|
}
|
|
|
|
|
|
2021-06-23 13:12:54 +08:00
|
|
|
// ListIPItemsWithListId 查找IP列表
|
2021-10-26 09:17:33 +08:00
|
|
|
func (this *IPItemDAO) ListIPItemsWithListId(tx *dbs.Tx, listId int64, keyword string, ipFrom string, ipTo string, offset int64, size int64) (result []*IPItem, err error) {
|
2021-10-22 12:18:53 +08:00
|
|
|
var query = this.Query(tx).
|
2020-11-07 19:40:24 +08:00
|
|
|
State(IPItemStateEnabled).
|
2021-10-22 12:18:53 +08:00
|
|
|
Attr("listId", listId)
|
|
|
|
|
if len(keyword) > 0 {
|
|
|
|
|
query.Where("(ipFrom LIKE :keyword OR ipTo LIKE :keyword)").
|
|
|
|
|
Param("keyword", "%"+keyword+"%")
|
|
|
|
|
}
|
2021-10-26 09:17:33 +08:00
|
|
|
if len(ipFrom) > 0 {
|
|
|
|
|
query.Attr("ipFrom", ipFrom)
|
|
|
|
|
}
|
|
|
|
|
if len(ipTo) > 0 {
|
|
|
|
|
query.Attr("ipTo", ipTo)
|
|
|
|
|
}
|
2021-10-22 12:18:53 +08:00
|
|
|
_, err = query.
|
2020-11-07 19:40:24 +08:00
|
|
|
DescPk().
|
|
|
|
|
Slice(&result).
|
|
|
|
|
Offset(offset).
|
|
|
|
|
Limit(size).
|
|
|
|
|
FindAll()
|
|
|
|
|
return
|
|
|
|
|
}
|
2020-11-09 10:44:00 +08:00
|
|
|
|
2021-06-23 13:12:54 +08:00
|
|
|
// ListIPItemsAfterVersion 根据版本号查找IP列表
|
2021-01-01 23:31:30 +08:00
|
|
|
func (this *IPItemDAO) ListIPItemsAfterVersion(tx *dbs.Tx, version int64, size int64) (result []*IPItem, err error) {
|
|
|
|
|
_, err = this.Query(tx).
|
2020-11-09 10:44:00 +08:00
|
|
|
// 这里不要设置状态参数,因为我们要知道哪些是删除的
|
|
|
|
|
Gt("version", version).
|
|
|
|
|
Where("(expiredAt=0 OR expiredAt>:expiredAt)").
|
|
|
|
|
Param("expiredAt", time.Now().Unix()).
|
|
|
|
|
Asc("version").
|
|
|
|
|
Limit(size).
|
|
|
|
|
Slice(&result).
|
|
|
|
|
FindAll()
|
|
|
|
|
return
|
|
|
|
|
}
|
2021-01-03 20:18:07 +08:00
|
|
|
|
2021-06-23 13:12:54 +08:00
|
|
|
// FindItemListId 查找IPItem对应的列表ID
|
2021-01-03 20:18:07 +08:00
|
|
|
func (this *IPItemDAO) FindItemListId(tx *dbs.Tx, itemId int64) (int64, error) {
|
|
|
|
|
return this.Query(tx).
|
|
|
|
|
Pk(itemId).
|
|
|
|
|
Result("listId").
|
|
|
|
|
FindInt64Col(0)
|
|
|
|
|
}
|
2021-01-17 16:48:00 +08:00
|
|
|
|
2021-06-23 13:12:54 +08:00
|
|
|
// FindEnabledItemContainsIP 查找包含某个IP的Item
|
2021-02-02 19:29:36 +08:00
|
|
|
func (this *IPItemDAO) FindEnabledItemContainsIP(tx *dbs.Tx, listId int64, ip uint64) (*IPItem, error) {
|
|
|
|
|
query := this.Query(tx).
|
|
|
|
|
Attr("listId", listId).
|
|
|
|
|
State(IPItemStateEnabled)
|
|
|
|
|
if ip > math.MaxUint32 {
|
|
|
|
|
query.Where("(type='all' OR ipFromLong=:ip)")
|
|
|
|
|
} else {
|
|
|
|
|
query.Where("(type='all' OR ipFromLong=:ip OR (ipToLong>0 AND ipFromLong<=:ip AND ipToLong>=:ip))").
|
|
|
|
|
Param("ip", ip)
|
|
|
|
|
}
|
|
|
|
|
one, err := query.Find()
|
|
|
|
|
if err != nil {
|
|
|
|
|
return nil, err
|
|
|
|
|
}
|
|
|
|
|
if one == nil {
|
|
|
|
|
return nil, nil
|
|
|
|
|
}
|
|
|
|
|
return one.(*IPItem), nil
|
|
|
|
|
}
|
|
|
|
|
|
2021-08-15 15:42:32 +08:00
|
|
|
// FindEnabledItemsWithIP 根据IP查找Item
|
|
|
|
|
func (this *IPItemDAO) FindEnabledItemsWithIP(tx *dbs.Tx, ip string) (result []*IPItem, err error) {
|
|
|
|
|
_, err = this.Query(tx).
|
|
|
|
|
Attr("ipFrom", ip).
|
|
|
|
|
Attr("ipTo", "").
|
|
|
|
|
Where("(expiredAt=0 OR expiredAt>:nowTime)").
|
|
|
|
|
Param("nowTime", time.Now().Unix()).
|
|
|
|
|
Where("listId IN (SELECT id FROM " + SharedIPListDAO.Table + " WHERE state=1)").
|
|
|
|
|
AscPk().
|
|
|
|
|
Slice(&result).
|
|
|
|
|
FindAll()
|
|
|
|
|
return
|
|
|
|
|
}
|
|
|
|
|
|
2021-06-23 13:12:54 +08:00
|
|
|
// ExistsEnabledItem 检查IP是否存在
|
|
|
|
|
func (this *IPItemDAO) ExistsEnabledItem(tx *dbs.Tx, itemId int64) (bool, error) {
|
|
|
|
|
return this.Query(tx).
|
|
|
|
|
Pk(itemId).
|
|
|
|
|
State(IPItemStateEnabled).
|
|
|
|
|
Exist()
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
// NotifyUpdate 通知更新
|
2021-02-02 15:25:40 +08:00
|
|
|
func (this *IPItemDAO) NotifyUpdate(tx *dbs.Tx, itemId int64) error {
|
2021-01-17 16:48:00 +08:00
|
|
|
// 获取ListId
|
|
|
|
|
listId, err := this.FindItemListId(tx, itemId)
|
|
|
|
|
if err != nil {
|
|
|
|
|
return err
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
if listId == 0 {
|
|
|
|
|
return nil
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
httpFirewallPolicyIds, err := SharedHTTPFirewallPolicyDAO.FindEnabledFirewallPolicyIdsWithIPListId(tx, listId)
|
|
|
|
|
if err != nil {
|
|
|
|
|
return err
|
|
|
|
|
}
|
|
|
|
|
resultClusterIds := []int64{}
|
|
|
|
|
for _, policyId := range httpFirewallPolicyIds {
|
|
|
|
|
// 集群
|
|
|
|
|
clusterIds, err := SharedNodeClusterDAO.FindAllEnabledNodeClusterIdsWithHTTPFirewallPolicyId(tx, policyId)
|
|
|
|
|
if err != nil {
|
|
|
|
|
return err
|
|
|
|
|
}
|
|
|
|
|
for _, clusterId := range clusterIds {
|
|
|
|
|
if !lists.ContainsInt64(resultClusterIds, clusterId) {
|
|
|
|
|
resultClusterIds = append(resultClusterIds, clusterId)
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
// 服务
|
|
|
|
|
webIds, err := SharedHTTPWebDAO.FindAllWebIdsWithHTTPFirewallPolicyId(tx, policyId)
|
|
|
|
|
if err != nil {
|
|
|
|
|
return err
|
|
|
|
|
}
|
|
|
|
|
if len(webIds) > 0 {
|
|
|
|
|
for _, webId := range webIds {
|
|
|
|
|
serverId, err := SharedServerDAO.FindEnabledServerIdWithWebId(tx, webId)
|
|
|
|
|
if err != nil {
|
|
|
|
|
return err
|
|
|
|
|
}
|
|
|
|
|
if serverId > 0 {
|
|
|
|
|
clusterId, err := SharedServerDAO.FindServerClusterId(tx, serverId)
|
|
|
|
|
if err != nil {
|
|
|
|
|
return err
|
|
|
|
|
}
|
|
|
|
|
if !lists.ContainsInt64(resultClusterIds, clusterId) {
|
|
|
|
|
resultClusterIds = append(resultClusterIds, clusterId)
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
if len(resultClusterIds) > 0 {
|
|
|
|
|
for _, clusterId := range resultClusterIds {
|
2021-08-08 15:47:48 +08:00
|
|
|
err = SharedNodeTaskDAO.CreateClusterTask(tx, nodeconfigs.NodeRoleNode, clusterId, NodeTaskTypeIPItemChanged)
|
2021-01-17 16:48:00 +08:00
|
|
|
if err != nil {
|
|
|
|
|
return err
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
return nil
|
|
|
|
|
}
|