feat: add login authentication and certificate expiry notifications
- JWT-based login with ADMIN_USER/ADMIN_PASSWORD env config - Login page with auth guard for Vue frontend - Feishu bot webhook notification for expiring certificates - SMTP email notification for expiring certificates - Daily 8:00 AM cron for expiry checks - Startup health check notification
This commit is contained in:
@@ -9,7 +9,8 @@
|
|||||||
- ✅ HTTP-01(端口 80)和 DNS-01 验证方式
|
- ✅ HTTP-01(端口 80)和 DNS-01 验证方式
|
||||||
- ✅ 支持阿里云 DNS / Cloudflare / DNSPod
|
- ✅ 支持阿里云 DNS / Cloudflare / DNSPod
|
||||||
- ✅ Web 管理界面(仪表盘、证书列表、申请、查看、续期、删除)
|
- ✅ Web 管理界面(仪表盘、证书列表、申请、查看、续期、删除)
|
||||||
- ✅ SQLite 数据存储
|
- ✅ **用户登录认证**(JWT Token)
|
||||||
|
- ✅ **证书到期通知**(飞书机器人和邮件)
|
||||||
- ✅ Docker 一键部署
|
- ✅ Docker 一键部署
|
||||||
|
|
||||||
## 快速开始
|
## 快速开始
|
||||||
@@ -38,23 +39,59 @@ cd backend && go build -o autossl .
|
|||||||
| 变量 | 默认值 | 说明 |
|
| 变量 | 默认值 | 说明 |
|
||||||
|------|--------|------|
|
|------|--------|------|
|
||||||
| PORT | 8080 | Web 服务端口 |
|
| PORT | 8080 | Web 服务端口 |
|
||||||
| DB_PATH | ./data/autossl.db | SQLite 数据库路径 |
|
| DATA_DIR | ./data | 数据存储目录 |
|
||||||
| CERT_DIR | ./data/certs | 证书文件存储目录 |
|
| CERT_DIR | ./data/certs | 证书文件存储目录 |
|
||||||
| ACCOUNTS_DIR | ./data/accounts | ACME 账号存储目录 |
|
| ACCOUNTS_DIR | ./data/accounts | ACME 账号存储目录 |
|
||||||
|
| ACME_PORT | 8082 | HTTP-01 挑战端口 |
|
||||||
|
| ADMIN_USER | admin | 管理员用户名 |
|
||||||
|
| ADMIN_PASSWORD | admin123 | 管理员密码 |
|
||||||
|
| JWT_SECRET | (内置默认值) | JWT 签名密钥(请务必在生产环境修改) |
|
||||||
|
| FEISHU_WEBHOOK_URL | - | 飞书机器人 Webhook 地址(用于证书到期通知) |
|
||||||
|
| SMTP_HOST | - | SMTP 服务器地址(用于邮件通知) |
|
||||||
|
| SMTP_PORT | - | SMTP 端口 |
|
||||||
|
| SMTP_USER | - | SMTP 用户名 |
|
||||||
|
| SMTP_PASSWORD | - | SMTP 密码 |
|
||||||
|
| SMTP_FROM | - | 发件人地址 |
|
||||||
|
| NOTIFY_TO | - | 收件人邮箱(多个用逗号分隔) |
|
||||||
|
|
||||||
## API 接口
|
## API 接口
|
||||||
|
|
||||||
| 方法 | 路径 | 说明 |
|
| 方法 | 路径 | 说明 | 需要认证 |
|
||||||
|------|------|------|
|
|------|------|------|---------|
|
||||||
| GET | /api/stats | 统计信息 |
|
| GET | /api/health | 健康检查 | 否 |
|
||||||
| GET | /api/certificates | 证书列表 |
|
| POST | /api/login | 用户登录 | 否 |
|
||||||
| GET | /api/certificates/:id | 证书详情 |
|
| GET | /api/stats | 统计信息 | 是 |
|
||||||
| POST | /api/certificates | 申请证书 |
|
| GET | /api/certificates | 证书列表 | 是 |
|
||||||
| PUT | /api/certificates/:id | 更新证书配置 |
|
| GET | /api/certificates/:id | 证书详情 | 是 |
|
||||||
| DELETE | /api/certificates/:id | 删除证书 |
|
| POST | /api/certificates | 申请证书 | 是 |
|
||||||
| POST | /api/certificates/:id/renew | 手动续期 |
|
| PUT | /api/certificates/:id | 更新证书配置 | 是 |
|
||||||
| GET | /api/certificates/:id/files | 查看证书文件 |
|
| DELETE | /api/certificates/:id | 删除证书 | 是 |
|
||||||
| GET | /api/renewals/check | 触发续期检查 |
|
| POST | /api/certificates/:id/renew | 手动续期 | 是 |
|
||||||
|
| GET | /api/certificates/:id/files | 查看证书文件 | 是 |
|
||||||
|
| GET | /api/renewals/check | 触发续期检查 | 是 |
|
||||||
|
|
||||||
|
## 证书到期通知
|
||||||
|
|
||||||
|
系统支持两种通知方式:
|
||||||
|
|
||||||
|
### 飞书机器人
|
||||||
|
|
||||||
|
1. 在飞书群中添加 Webhook 机器人
|
||||||
|
2. 设置环境变量 `FEISHU_WEBHOOK_URL=https://open.feishu.cn/open-apis/bot/v2/hook/xxxxx`
|
||||||
|
|
||||||
|
### 邮件通知
|
||||||
|
|
||||||
|
设置 SMTP 相关环境变量:
|
||||||
|
```
|
||||||
|
SMTP_HOST=smtp.example.com
|
||||||
|
SMTP_PORT=587
|
||||||
|
SMTP_USER=user@example.com
|
||||||
|
SMTP_PASSWORD=your-password
|
||||||
|
SMTP_FROM=autossl@example.com
|
||||||
|
NOTIFY_TO=admin@example.com,ops@example.com
|
||||||
|
```
|
||||||
|
|
||||||
|
通知将在每天早上 8:00 自动检查并发送。30 天内到期的证书会触发通知。
|
||||||
|
|
||||||
## 证书文件位置
|
## 证书文件位置
|
||||||
|
|
||||||
|
|||||||
@@ -10,6 +10,18 @@ WorkingDirectory={{DEPLOY_DIR}}/backend
|
|||||||
Environment="PORT=9090"
|
Environment="PORT=9090"
|
||||||
Environment="ACME_PORT=8082"
|
Environment="ACME_PORT=8082"
|
||||||
Environment="GIN_MODE=release"
|
Environment="GIN_MODE=release"
|
||||||
|
Environment="ADMIN_USER=admin"
|
||||||
|
Environment="ADMIN_PASSWORD=您的密码"
|
||||||
|
Environment="JWT_SECRET=请修改为随机字符串"
|
||||||
|
# 飞书通知(可选)
|
||||||
|
# Environment="FEISHU_WEBHOOK_URL=https://open.feishu.cn/open-apis/bot/v2/hook/xxx"
|
||||||
|
# 邮件通知(可选)
|
||||||
|
# Environment="SMTP_HOST=smtp.example.com"
|
||||||
|
# Environment="SMTP_PORT=587"
|
||||||
|
# Environment="SMTP_USER=user@example.com"
|
||||||
|
# Environment="SMTP_PASSWORD=password"
|
||||||
|
# Environment="SMTP_FROM=autossl@example.com"
|
||||||
|
# Environment="NOTIFY_TO=admin@example.com"
|
||||||
ExecStart={{DEPLOY_DIR}}/backend/autossl
|
ExecStart={{DEPLOY_DIR}}/backend/autossl
|
||||||
Restart=always
|
Restart=always
|
||||||
RestartSec=3
|
RestartSec=3
|
||||||
|
|||||||
@@ -0,0 +1,122 @@
|
|||||||
|
package auth
|
||||||
|
|
||||||
|
import (
|
||||||
|
"crypto/hmac"
|
||||||
|
"crypto/sha256"
|
||||||
|
"encoding/hex"
|
||||||
|
"errors"
|
||||||
|
"os"
|
||||||
|
"time"
|
||||||
|
|
||||||
|
"github.com/golang-jwt/jwt/v5"
|
||||||
|
)
|
||||||
|
|
||||||
|
var (
|
||||||
|
ErrInvalidCredentials = errors.New("invalid username or password")
|
||||||
|
ErrInvalidToken = errors.New("invalid or expired token")
|
||||||
|
)
|
||||||
|
|
||||||
|
type User struct {
|
||||||
|
Username string `json:"username"`
|
||||||
|
Password string `json:"password"` // plaintext only used at login
|
||||||
|
}
|
||||||
|
|
||||||
|
// defaultAdmin returns the admin user from env vars
|
||||||
|
func defaultAdmin() User {
|
||||||
|
username := os.Getenv("ADMIN_USER")
|
||||||
|
if username == "" {
|
||||||
|
username = "admin"
|
||||||
|
}
|
||||||
|
password := os.Getenv("ADMIN_PASSWORD")
|
||||||
|
if password == "" {
|
||||||
|
password = "admin123"
|
||||||
|
}
|
||||||
|
return User{Username: username, Password: password}
|
||||||
|
}
|
||||||
|
|
||||||
|
// LoginRequest is the JSON body for login
|
||||||
|
type LoginRequest struct {
|
||||||
|
Username string `json:"username" binding:"required"`
|
||||||
|
Password string `json:"password" binding:"required"`
|
||||||
|
}
|
||||||
|
|
||||||
|
// LoginResponse is the JSON response for login
|
||||||
|
type LoginResponse struct {
|
||||||
|
Token string `json:"token"`
|
||||||
|
Username string `json:"username"`
|
||||||
|
ExpiresAt int64 `json:"expires_at"`
|
||||||
|
}
|
||||||
|
|
||||||
|
// Claims represents JWT claims
|
||||||
|
type Claims struct {
|
||||||
|
Username string `json:"username"`
|
||||||
|
jwt.RegisteredClaims
|
||||||
|
}
|
||||||
|
|
||||||
|
// secretKey returns the JWT signing key (env or default)
|
||||||
|
func secretKey() []byte {
|
||||||
|
key := os.Getenv("JWT_SECRET")
|
||||||
|
if key == "" {
|
||||||
|
key = "autossl-default-secret-change-me"
|
||||||
|
}
|
||||||
|
return []byte(key)
|
||||||
|
}
|
||||||
|
|
||||||
|
// TokenExpiry returns token lifetime
|
||||||
|
func TokenExpiry() time.Duration {
|
||||||
|
return 24 * time.Hour
|
||||||
|
}
|
||||||
|
|
||||||
|
// Authenticate checks credentials against environment config
|
||||||
|
func Authenticate(username, password string) bool {
|
||||||
|
admin := defaultAdmin()
|
||||||
|
// Constant-time comparison to prevent timing attacks
|
||||||
|
mac1 := hmac.New(sha256.New, []byte(admin.Username))
|
||||||
|
mac1.Write([]byte(admin.Password))
|
||||||
|
expected := hex.EncodeToString(mac1.Sum(nil))
|
||||||
|
|
||||||
|
mac2 := hmac.New(sha256.New, []byte(username))
|
||||||
|
mac2.Write([]byte(password))
|
||||||
|
actual := hex.EncodeToString(mac2.Sum(nil))
|
||||||
|
|
||||||
|
return hmac.Equal([]byte(expected), []byte(actual))
|
||||||
|
}
|
||||||
|
|
||||||
|
// GenerateToken creates a JWT token for the given username
|
||||||
|
func GenerateToken(username string) (string, int64, error) {
|
||||||
|
expiresAt := time.Now().Add(TokenExpiry())
|
||||||
|
claims := Claims{
|
||||||
|
Username: username,
|
||||||
|
RegisteredClaims: jwt.RegisteredClaims{
|
||||||
|
ExpiresAt: jwt.NewNumericDate(expiresAt),
|
||||||
|
IssuedAt: jwt.NewNumericDate(time.Now()),
|
||||||
|
Issuer: "autossl",
|
||||||
|
},
|
||||||
|
}
|
||||||
|
|
||||||
|
token := jwt.NewWithClaims(jwt.SigningMethodHS256, claims)
|
||||||
|
tokenString, err := token.SignedString(secretKey())
|
||||||
|
if err != nil {
|
||||||
|
return "", 0, err
|
||||||
|
}
|
||||||
|
return tokenString, expiresAt.Unix(), nil
|
||||||
|
}
|
||||||
|
|
||||||
|
// ValidateToken parses and validates a JWT token, returning claims
|
||||||
|
func ValidateToken(tokenString string) (*Claims, error) {
|
||||||
|
token, err := jwt.ParseWithClaims(tokenString, &Claims{}, func(token *jwt.Token) (interface{}, error) {
|
||||||
|
if _, ok := token.Method.(*jwt.SigningMethodHMAC); !ok {
|
||||||
|
return nil, ErrInvalidToken
|
||||||
|
}
|
||||||
|
return secretKey(), nil
|
||||||
|
})
|
||||||
|
if err != nil {
|
||||||
|
return nil, ErrInvalidToken
|
||||||
|
}
|
||||||
|
|
||||||
|
claims, ok := token.Claims.(*Claims)
|
||||||
|
if !ok || !token.Valid {
|
||||||
|
return nil, ErrInvalidToken
|
||||||
|
}
|
||||||
|
return claims, nil
|
||||||
|
}
|
||||||
Vendored
+1
File diff suppressed because one or more lines are too long
|
After Width: | Height: | Size: 9.3 KiB |
Vendored
+24
@@ -0,0 +1,24 @@
|
|||||||
|
<svg xmlns="http://www.w3.org/2000/svg">
|
||||||
|
<symbol id="bluesky-icon" viewBox="0 0 16 17">
|
||||||
|
<g clip-path="url(#bluesky-clip)"><path fill="#08060d" d="M7.75 7.735c-.693-1.348-2.58-3.86-4.334-5.097-1.68-1.187-2.32-.981-2.74-.79C.188 2.065.1 2.812.1 3.251s.241 3.602.398 4.13c.52 1.744 2.367 2.333 4.07 2.145-2.495.37-4.71 1.278-1.805 4.512 3.196 3.309 4.38-.71 4.987-2.746.608 2.036 1.307 5.91 4.93 2.746 2.72-2.746.747-4.143-1.747-4.512 1.702.189 3.55-.4 4.07-2.145.156-.528.397-3.691.397-4.13s-.088-1.186-.575-1.406c-.42-.19-1.06-.395-2.741.79-1.755 1.24-3.64 3.752-4.334 5.099"/></g>
|
||||||
|
<defs><clipPath id="bluesky-clip"><path fill="#fff" d="M.1.85h15.3v15.3H.1z"/></clipPath></defs>
|
||||||
|
</symbol>
|
||||||
|
<symbol id="discord-icon" viewBox="0 0 20 19">
|
||||||
|
<path fill="#08060d" d="M16.224 3.768a14.5 14.5 0 0 0-3.67-1.153c-.158.286-.343.67-.47.976a13.5 13.5 0 0 0-4.067 0c-.128-.306-.317-.69-.476-.976A14.4 14.4 0 0 0 3.868 3.77C1.546 7.28.916 10.703 1.231 14.077a14.7 14.7 0 0 0 4.5 2.306q.545-.748.965-1.587a9.5 9.5 0 0 1-1.518-.74q.191-.14.372-.293c2.927 1.369 6.107 1.369 8.999 0q.183.152.372.294-.723.437-1.52.74.418.838.963 1.588a14.6 14.6 0 0 0 4.504-2.308c.37-3.911-.63-7.302-2.644-10.309m-9.13 8.234c-.878 0-1.599-.82-1.599-1.82 0-.998.705-1.82 1.6-1.82.894 0 1.614.82 1.599 1.82.001 1-.705 1.82-1.6 1.82m5.91 0c-.878 0-1.599-.82-1.599-1.82 0-.998.705-1.82 1.6-1.82.893 0 1.614.82 1.599 1.82 0 1-.706 1.82-1.6 1.82"/>
|
||||||
|
</symbol>
|
||||||
|
<symbol id="documentation-icon" viewBox="0 0 21 20">
|
||||||
|
<path fill="none" stroke="#aa3bff" stroke-linecap="round" stroke-linejoin="round" stroke-width="1.35" d="m15.5 13.333 1.533 1.322c.645.555.967.833.967 1.178s-.322.623-.967 1.179L15.5 18.333m-3.333-5-1.534 1.322c-.644.555-.966.833-.966 1.178s.322.623.966 1.179l1.534 1.321"/>
|
||||||
|
<path fill="none" stroke="#aa3bff" stroke-linecap="round" stroke-linejoin="round" stroke-width="1.35" d="M17.167 10.836v-4.32c0-1.41 0-2.117-.224-2.68-.359-.906-1.118-1.621-2.08-1.96-.599-.21-1.349-.21-2.848-.21-2.623 0-3.935 0-4.983.369-1.684.591-3.013 1.842-3.641 3.428C3 6.449 3 7.684 3 10.154v2.122c0 2.558 0 3.838.706 4.726q.306.383.713.671c.76.536 1.79.64 3.581.66"/>
|
||||||
|
<path fill="none" stroke="#aa3bff" stroke-linecap="round" stroke-linejoin="round" stroke-width="1.35" d="M3 10a2.78 2.78 0 0 1 2.778-2.778c.555 0 1.209.097 1.748-.047.48-.129.854-.503.982-.982.145-.54.048-1.194.048-1.749a2.78 2.78 0 0 1 2.777-2.777"/>
|
||||||
|
</symbol>
|
||||||
|
<symbol id="github-icon" viewBox="0 0 19 19">
|
||||||
|
<path fill="#08060d" fill-rule="evenodd" d="M9.356 1.85C5.05 1.85 1.57 5.356 1.57 9.694a7.84 7.84 0 0 0 5.324 7.44c.387.079.528-.168.528-.376 0-.182-.013-.805-.013-1.454-2.165.467-2.616-.935-2.616-.935-.349-.91-.864-1.143-.864-1.143-.71-.48.051-.48.051-.48.787.051 1.2.805 1.2.805.695 1.194 1.817.857 2.268.649.064-.507.27-.857.49-1.052-1.728-.182-3.545-.857-3.545-3.87 0-.857.31-1.558.8-2.104-.078-.195-.349-1 .077-2.078 0 0 .657-.208 2.14.805a7.5 7.5 0 0 1 1.946-.26c.657 0 1.328.092 1.946.26 1.483-1.013 2.14-.805 2.14-.805.426 1.078.155 1.883.078 2.078.502.546.799 1.247.799 2.104 0 3.013-1.818 3.675-3.558 3.87.284.247.528.714.528 1.454 0 1.052-.012 1.896-.012 2.156 0 .208.142.455.528.377a7.84 7.84 0 0 0 5.324-7.441c.013-4.338-3.48-7.844-7.773-7.844" clip-rule="evenodd"/>
|
||||||
|
</symbol>
|
||||||
|
<symbol id="social-icon" viewBox="0 0 20 20">
|
||||||
|
<path fill="none" stroke="#aa3bff" stroke-linecap="round" stroke-linejoin="round" stroke-width="1.35" d="M12.5 6.667a4.167 4.167 0 1 0-8.334 0 4.167 4.167 0 0 0 8.334 0"/>
|
||||||
|
<path fill="none" stroke="#aa3bff" stroke-linecap="round" stroke-linejoin="round" stroke-width="1.35" d="M2.5 16.667a5.833 5.833 0 0 1 8.75-5.053m3.837.474.513 1.035c.07.144.257.282.414.309l.93.155c.596.1.736.536.307.965l-.723.73a.64.64 0 0 0-.152.531l.207.903c.164.715-.213.991-.84.618l-.872-.52a.63.63 0 0 0-.577 0l-.872.52c-.624.373-1.003.094-.84-.618l.207-.903a.64.64 0 0 0-.152-.532l-.723-.729c-.426-.43-.289-.864.306-.964l.93-.156a.64.64 0 0 0 .412-.31l.513-1.034c.28-.562.735-.562 1.012 0"/>
|
||||||
|
</symbol>
|
||||||
|
<symbol id="x-icon" viewBox="0 0 19 19">
|
||||||
|
<path fill="#08060d" fill-rule="evenodd" d="M1.893 1.98c.052.072 1.245 1.769 2.653 3.77l2.892 4.114c.183.261.333.48.333.486s-.068.089-.152.183l-.522.593-.765.867-3.597 4.087c-.375.426-.734.834-.798.905a1 1 0 0 0-.118.148c0 .01.236.017.664.017h.663l.729-.83c.4-.457.796-.906.879-.999a692 692 0 0 0 1.794-2.038c.034-.037.301-.34.594-.675l.551-.624.345-.392a7 7 0 0 1 .34-.374c.006 0 .93 1.306 2.052 2.903l2.084 2.965.045.063h2.275c1.87 0 2.273-.003 2.266-.021-.008-.02-1.098-1.572-3.894-5.547-2.013-2.862-2.28-3.246-2.273-3.266.008-.019.282-.332 2.085-2.38l2-2.274 1.567-1.782c.022-.028-.016-.03-.65-.03h-.674l-.3.342a871 871 0 0 1-1.782 2.025c-.067.075-.405.458-.75.852a100 100 0 0 1-.803.91c-.148.172-.299.344-.99 1.127-.304.343-.32.358-.345.327-.015-.019-.904-1.282-1.976-2.808L6.365 1.85H1.8zm1.782.91 8.078 11.294c.772 1.08 1.413 1.973 1.425 1.984.016.017.241.02 1.05.017l1.03-.004-2.694-3.766L7.796 5.75 5.722 2.852l-1.039-.004-1.039-.004z" clip-rule="evenodd"/>
|
||||||
|
</symbol>
|
||||||
|
</svg>
|
||||||
|
After Width: | Height: | Size: 4.9 KiB |
Vendored
+14
@@ -0,0 +1,14 @@
|
|||||||
|
<!doctype html>
|
||||||
|
<html lang="en">
|
||||||
|
<head>
|
||||||
|
<meta charset="UTF-8" />
|
||||||
|
<link rel="icon" type="image/svg+xml" href="/favicon.svg" />
|
||||||
|
<meta name="viewport" content="width=device-width, initial-scale=1.0" />
|
||||||
|
<title>AutoSSL 证书管理</title>
|
||||||
|
<script type="module" crossorigin src="/assets/index-BD8965cd.js"></script>
|
||||||
|
<link rel="stylesheet" crossorigin href="/assets/index-612jFRSC.css">
|
||||||
|
</head>
|
||||||
|
<body>
|
||||||
|
<div id="app"></div>
|
||||||
|
</body>
|
||||||
|
</html>
|
||||||
@@ -6,6 +6,8 @@ require (
|
|||||||
github.com/gin-contrib/cors v1.5.0
|
github.com/gin-contrib/cors v1.5.0
|
||||||
github.com/gin-gonic/gin v1.9.1
|
github.com/gin-gonic/gin v1.9.1
|
||||||
github.com/go-acme/lego/v4 v4.14.2
|
github.com/go-acme/lego/v4 v4.14.2
|
||||||
|
github.com/golang-jwt/jwt/v5 v5.3.1
|
||||||
|
github.com/jordan-wright/email v4.0.1-0.20210109023952-943e75fe5223+incompatible
|
||||||
github.com/robfig/cron/v3 v3.0.1
|
github.com/robfig/cron/v3 v3.0.1
|
||||||
)
|
)
|
||||||
|
|
||||||
|
|||||||
@@ -42,6 +42,8 @@ github.com/go-playground/validator/v10 v10.15.5/go.mod h1:9iXMNT7sEkjXb0I+enO7QX
|
|||||||
github.com/goccy/go-json v0.10.2 h1:CrxCmQqYDkv1z7lO7Wbh2HN93uovUHgrECaO5ZrCXAU=
|
github.com/goccy/go-json v0.10.2 h1:CrxCmQqYDkv1z7lO7Wbh2HN93uovUHgrECaO5ZrCXAU=
|
||||||
github.com/goccy/go-json v0.10.2/go.mod h1:6MelG93GURQebXPDq3khkgXZkazVtN9CRI+MGFi0w8I=
|
github.com/goccy/go-json v0.10.2/go.mod h1:6MelG93GURQebXPDq3khkgXZkazVtN9CRI+MGFi0w8I=
|
||||||
github.com/goji/httpauth v0.0.0-20160601135302-2da839ab0f4d/go.mod h1:nnjvkQ9ptGaCkuDUx6wNykzzlUixGxvkme+H/lnzb+A=
|
github.com/goji/httpauth v0.0.0-20160601135302-2da839ab0f4d/go.mod h1:nnjvkQ9ptGaCkuDUx6wNykzzlUixGxvkme+H/lnzb+A=
|
||||||
|
github.com/golang-jwt/jwt/v5 v5.3.1 h1:kYf81DTWFe7t+1VvL7eS+jKFVWaUnK9cB1qbwn63YCY=
|
||||||
|
github.com/golang-jwt/jwt/v5 v5.3.1/go.mod h1:fxCRLWMO43lRc8nhHWY6LGqRcf+1gQWArsqaEUEa5bE=
|
||||||
github.com/golang/protobuf v1.5.0/go.mod h1:FsONVRAS9T7sI+LIUmWTfcYkHO4aIWwzhcaSAoJOfIk=
|
github.com/golang/protobuf v1.5.0/go.mod h1:FsONVRAS9T7sI+LIUmWTfcYkHO4aIWwzhcaSAoJOfIk=
|
||||||
github.com/google/go-cmp v0.5.0/go.mod h1:v8dTdLbMG2kIc/vJvl+f65V22dbkXbowE6jgT/gNBxE=
|
github.com/google/go-cmp v0.5.0/go.mod h1:v8dTdLbMG2kIc/vJvl+f65V22dbkXbowE6jgT/gNBxE=
|
||||||
github.com/google/go-cmp v0.5.2/go.mod h1:v8dTdLbMG2kIc/vJvl+f65V22dbkXbowE6jgT/gNBxE=
|
github.com/google/go-cmp v0.5.2/go.mod h1:v8dTdLbMG2kIc/vJvl+f65V22dbkXbowE6jgT/gNBxE=
|
||||||
@@ -63,6 +65,8 @@ github.com/jmespath/go-jmespath v0.4.0 h1:BEgLn5cpjn8UN1mAw4NjwDrS35OdebyEtFe+9Y
|
|||||||
github.com/jmespath/go-jmespath v0.4.0/go.mod h1:T8mJZnbsbmF+m6zOOFylbeCJqk5+pHWvzYPziyZiYoo=
|
github.com/jmespath/go-jmespath v0.4.0/go.mod h1:T8mJZnbsbmF+m6zOOFylbeCJqk5+pHWvzYPziyZiYoo=
|
||||||
github.com/jmespath/go-jmespath/internal/testify v1.5.1 h1:shLQSRRSCCPj3f2gpwzGwWFoC7ycTf1rcQZHOlsJ6N8=
|
github.com/jmespath/go-jmespath/internal/testify v1.5.1 h1:shLQSRRSCCPj3f2gpwzGwWFoC7ycTf1rcQZHOlsJ6N8=
|
||||||
github.com/jmespath/go-jmespath/internal/testify v1.5.1/go.mod h1:L3OGu8Wl2/fWfCI6z80xFu9LTZmf1ZRjMHUOPmWr69U=
|
github.com/jmespath/go-jmespath/internal/testify v1.5.1/go.mod h1:L3OGu8Wl2/fWfCI6z80xFu9LTZmf1ZRjMHUOPmWr69U=
|
||||||
|
github.com/jordan-wright/email v4.0.1-0.20210109023952-943e75fe5223+incompatible h1:jdpOPRN1zP63Td1hDQbZW73xKmzDvZHzVdNYxhnTMDA=
|
||||||
|
github.com/jordan-wright/email v4.0.1-0.20210109023952-943e75fe5223+incompatible/go.mod h1:1c7szIrayyPPB/987hsnvNzLushdWf4o/79s3P08L8A=
|
||||||
github.com/json-iterator/go v1.1.5/go.mod h1:+SdeFBvtyEkXs7REEP0seUULqWtbJapLOCVDaaPEHmU=
|
github.com/json-iterator/go v1.1.5/go.mod h1:+SdeFBvtyEkXs7REEP0seUULqWtbJapLOCVDaaPEHmU=
|
||||||
github.com/json-iterator/go v1.1.12 h1:PV8peI4a0ysnczrg+LtxykD8LfKY9ML6u2jnxaEnrnM=
|
github.com/json-iterator/go v1.1.12 h1:PV8peI4a0ysnczrg+LtxykD8LfKY9ML6u2jnxaEnrnM=
|
||||||
github.com/json-iterator/go v1.1.12/go.mod h1:e30LSqwooZae/UwlEbR2852Gd8hjQvJoHmT4TnhNGBo=
|
github.com/json-iterator/go v1.1.12/go.mod h1:e30LSqwooZae/UwlEbR2852Gd8hjQvJoHmT4TnhNGBo=
|
||||||
|
|||||||
+152
-8
@@ -1,9 +1,12 @@
|
|||||||
package main
|
package main
|
||||||
|
|
||||||
import (
|
import (
|
||||||
|
"auto-ssl/auth"
|
||||||
"auto-ssl/config"
|
"auto-ssl/config"
|
||||||
"auto-ssl/handlers"
|
"auto-ssl/handlers"
|
||||||
|
"auto-ssl/notify"
|
||||||
"auto-ssl/services"
|
"auto-ssl/services"
|
||||||
|
"fmt"
|
||||||
"log"
|
"log"
|
||||||
"net/http"
|
"net/http"
|
||||||
"os"
|
"os"
|
||||||
@@ -39,8 +42,15 @@ func main() {
|
|||||||
r.StaticFile("/favicon.svg", "./dist/favicon.svg")
|
r.StaticFile("/favicon.svg", "./dist/favicon.svg")
|
||||||
r.StaticFile("/", "./dist/index.html")
|
r.StaticFile("/", "./dist/index.html")
|
||||||
|
|
||||||
// API routes
|
// Public routes (no auth required)
|
||||||
|
r.POST("/api/login", handleLogin)
|
||||||
|
r.GET("/api/health", func(c *gin.Context) {
|
||||||
|
c.JSON(http.StatusOK, gin.H{"status": "ok"})
|
||||||
|
})
|
||||||
|
|
||||||
|
// API routes with auth
|
||||||
api := r.Group("/api")
|
api := r.Group("/api")
|
||||||
|
api.Use(authMiddleware())
|
||||||
{
|
{
|
||||||
certHandler := handlers.NewCertHandler(cfg)
|
certHandler := handlers.NewCertHandler(cfg)
|
||||||
|
|
||||||
@@ -60,12 +70,12 @@ func main() {
|
|||||||
|
|
||||||
r.NoRoute(func(c *gin.Context) {
|
r.NoRoute(func(c *gin.Context) {
|
||||||
// 静态资源请求直接返回404,避免返回html导致MIME类型错误
|
// 静态资源请求直接返回404,避免返回html导致MIME类型错误
|
||||||
if strings.HasPrefix(c.Request.URL.Path, "/assets/") ||
|
if strings.HasPrefix(c.Request.URL.Path, "/assets/") ||
|
||||||
strings.HasSuffix(c.Request.URL.Path, ".js") ||
|
strings.HasSuffix(c.Request.URL.Path, ".js") ||
|
||||||
strings.HasSuffix(c.Request.URL.Path, ".css") ||
|
strings.HasSuffix(c.Request.URL.Path, ".css") ||
|
||||||
strings.HasSuffix(c.Request.URL.Path, ".png") ||
|
strings.HasSuffix(c.Request.URL.Path, ".png") ||
|
||||||
strings.HasSuffix(c.Request.URL.Path, ".svg") ||
|
strings.HasSuffix(c.Request.URL.Path, ".svg") ||
|
||||||
strings.HasSuffix(c.Request.URL.Path, ".ico") {
|
strings.HasSuffix(c.Request.URL.Path, ".ico") {
|
||||||
c.AbortWithStatus(http.StatusNotFound)
|
c.AbortWithStatus(http.StatusNotFound)
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
@@ -73,8 +83,10 @@ func main() {
|
|||||||
c.File("./dist/index.html")
|
c.File("./dist/index.html")
|
||||||
})
|
})
|
||||||
|
|
||||||
// Setup cron for auto-renewal (runs daily at 3:00 AM)
|
// Setup cron scheduler
|
||||||
c := cron.New()
|
c := cron.New()
|
||||||
|
|
||||||
|
// Daily renewal check at 3:00 AM
|
||||||
c.AddFunc("0 3 * * *", func() {
|
c.AddFunc("0 3 * * *", func() {
|
||||||
log.Println("Running scheduled certificate renewal check...")
|
log.Println("Running scheduled certificate renewal check...")
|
||||||
certs := config.Store.GetActiveWithAutoRenew()
|
certs := config.Store.GetActiveWithAutoRenew()
|
||||||
@@ -93,6 +105,17 @@ func main() {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
})
|
})
|
||||||
|
|
||||||
|
// Certificate expiry notification check at 8:00 AM daily
|
||||||
|
c.AddFunc("0 8 * * *", func() {
|
||||||
|
notifyCfg := notify.LoadNotifyConfig()
|
||||||
|
if !notifyCfg.IsConfigured() {
|
||||||
|
log.Println("Notification not configured, skipping expiry check notification")
|
||||||
|
return
|
||||||
|
}
|
||||||
|
runExpiryNotification(notifyCfg)
|
||||||
|
})
|
||||||
|
|
||||||
c.Start()
|
c.Start()
|
||||||
|
|
||||||
// Set ACME HTTP-01 challenge port from env (default 8082)
|
// Set ACME HTTP-01 challenge port from env (default 8082)
|
||||||
@@ -109,3 +132,124 @@ func main() {
|
|||||||
log.Fatalf("Failed to start server: %v", err)
|
log.Fatalf("Failed to start server: %v", err)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// handleLogin authenticates user and returns JWT token
|
||||||
|
func handleLogin(c *gin.Context) {
|
||||||
|
var req auth.LoginRequest
|
||||||
|
if err := c.ShouldBindJSON(&req); err != nil {
|
||||||
|
c.JSON(http.StatusBadRequest, gin.H{"error": "请输入用户名和密码"})
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
|
if !auth.Authenticate(req.Username, req.Password) {
|
||||||
|
c.JSON(http.StatusUnauthorized, gin.H{"error": "用户名或密码错误"})
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
|
token, expiresAt, err := auth.GenerateToken(req.Username)
|
||||||
|
if err != nil {
|
||||||
|
c.JSON(http.StatusInternalServerError, gin.H{"error": "生成token失败"})
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
|
c.JSON(http.StatusOK, auth.LoginResponse{
|
||||||
|
Token: token,
|
||||||
|
Username: req.Username,
|
||||||
|
ExpiresAt: expiresAt,
|
||||||
|
})
|
||||||
|
}
|
||||||
|
|
||||||
|
// authMiddleware validates JWT token on protected routes
|
||||||
|
func authMiddleware() gin.HandlerFunc {
|
||||||
|
return func(c *gin.Context) {
|
||||||
|
authHeader := c.GetHeader("Authorization")
|
||||||
|
if authHeader == "" {
|
||||||
|
// Also check query param (for websocket / event-stream compatibility)
|
||||||
|
authHeader = c.Query("token")
|
||||||
|
if authHeader == "" {
|
||||||
|
c.AbortWithStatusJSON(http.StatusUnauthorized, gin.H{"error": "未授权,请先登录"})
|
||||||
|
return
|
||||||
|
}
|
||||||
|
// Validate as-is (query param is the raw token)
|
||||||
|
claims, err := auth.ValidateToken(authHeader)
|
||||||
|
if err != nil {
|
||||||
|
c.AbortWithStatusJSON(http.StatusUnauthorized, gin.H{"error": "token已过期或无效"})
|
||||||
|
return
|
||||||
|
}
|
||||||
|
c.Set("username", claims.Username)
|
||||||
|
c.Next()
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
|
// Extract Bearer token
|
||||||
|
tokenString := strings.TrimPrefix(authHeader, "Bearer ")
|
||||||
|
if tokenString == authHeader {
|
||||||
|
tokenString = authHeader
|
||||||
|
}
|
||||||
|
|
||||||
|
claims, err := auth.ValidateToken(tokenString)
|
||||||
|
if err != nil {
|
||||||
|
c.AbortWithStatusJSON(http.StatusUnauthorized, gin.H{"error": "token已过期或无效"})
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
|
c.Set("username", claims.Username)
|
||||||
|
c.Next()
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// runExpiryNotification checks all certificates and sends notifications for expiring ones
|
||||||
|
func runExpiryNotification(notifyCfg *notify.Config) {
|
||||||
|
certs := config.Store.GetAll()
|
||||||
|
|
||||||
|
var expiringCerts []notify.CertInfo
|
||||||
|
for _, cert := range certs {
|
||||||
|
if cert.Status != "active" || cert.ExpiresAt == nil {
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
|
||||||
|
daysLeft := int(time.Until(*cert.ExpiresAt).Hours() / 24)
|
||||||
|
|
||||||
|
// Notify if within 30 days of expiry (or already expired)
|
||||||
|
if daysLeft <= 30 {
|
||||||
|
info := notify.CertInfo{
|
||||||
|
Domain: cert.Domain,
|
||||||
|
Status: cert.Status,
|
||||||
|
ExpiresAt: cert.ExpiresAt,
|
||||||
|
DaysLeft: daysLeft,
|
||||||
|
}
|
||||||
|
if daysLeft < 0 {
|
||||||
|
info.Status = "expired"
|
||||||
|
}
|
||||||
|
expiringCerts = append(expiringCerts, info)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
if len(expiringCerts) > 0 {
|
||||||
|
log.Printf("Found %d expiring certificates, sending notifications", len(expiringCerts))
|
||||||
|
if err := notifyCfg.NotifyCertExpiring(expiringCerts); err != nil {
|
||||||
|
log.Printf("Failed to send expiry notifications: %v", err)
|
||||||
|
}
|
||||||
|
} else {
|
||||||
|
log.Println("No expiring certificates found, skipping notification")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func init() {
|
||||||
|
// Check if notification is configured and run once at startup
|
||||||
|
time.AfterFunc(10*time.Second, func() {
|
||||||
|
notifyCfg := notify.LoadNotifyConfig()
|
||||||
|
if notifyCfg.IsConfigured() {
|
||||||
|
log.Println("Running startup certificate expiry check...")
|
||||||
|
runExpiryNotification(notifyCfg)
|
||||||
|
}
|
||||||
|
})
|
||||||
|
|
||||||
|
// Validate ADMIN_USER / ADMIN_PASSWORD env setting
|
||||||
|
adminUser := os.Getenv("ADMIN_USER")
|
||||||
|
adminPass := os.Getenv("ADMIN_PASSWORD")
|
||||||
|
if adminUser != "" || adminPass != "" {
|
||||||
|
log.Printf("Admin credentials configured via environment (user: %s)", adminUser)
|
||||||
|
}
|
||||||
|
_ = fmt.Sprintf // import usage, prevent unused import error
|
||||||
|
}
|
||||||
|
|||||||
@@ -0,0 +1,305 @@
|
|||||||
|
package notify
|
||||||
|
|
||||||
|
import (
|
||||||
|
"bytes"
|
||||||
|
"encoding/json"
|
||||||
|
"fmt"
|
||||||
|
"log"
|
||||||
|
"net/http"
|
||||||
|
"net/smtp"
|
||||||
|
"os"
|
||||||
|
"strings"
|
||||||
|
"time"
|
||||||
|
|
||||||
|
"github.com/jordan-wright/email"
|
||||||
|
)
|
||||||
|
|
||||||
|
// Config holds notification configuration
|
||||||
|
type Config struct {
|
||||||
|
// Feishu webhook
|
||||||
|
FeishuWebhookURL string
|
||||||
|
// SMTP
|
||||||
|
SMTPHost string
|
||||||
|
SMTPPort string
|
||||||
|
SMTPUser string
|
||||||
|
SMTPPassword string
|
||||||
|
SMTPFrom string
|
||||||
|
NotifyTo string // comma-separated email recipients
|
||||||
|
}
|
||||||
|
|
||||||
|
// LoadNotifyConfig reads notification config from environment
|
||||||
|
func LoadNotifyConfig() *Config {
|
||||||
|
return &Config{
|
||||||
|
FeishuWebhookURL: os.Getenv("FEISHU_WEBHOOK_URL"),
|
||||||
|
SMTPHost: os.Getenv("SMTP_HOST"),
|
||||||
|
SMTPPort: os.Getenv("SMTP_PORT"),
|
||||||
|
SMTPUser: os.Getenv("SMTP_USER"),
|
||||||
|
SMTPPassword: os.Getenv("SMTP_PASSWORD"),
|
||||||
|
SMTPFrom: os.Getenv("SMTP_FROM"),
|
||||||
|
NotifyTo: os.Getenv("NOTIFY_TO"),
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// IsConfigured returns true if at least one notification channel is configured
|
||||||
|
func (c *Config) IsConfigured() bool {
|
||||||
|
return c.FeishuWebhookURL != "" || (c.SMTPHost != "" && c.NotifyTo != "")
|
||||||
|
}
|
||||||
|
|
||||||
|
// CertInfo holds certificate information for notifications
|
||||||
|
type CertInfo struct {
|
||||||
|
Domain string `json:"domain"`
|
||||||
|
Status string `json:"status"`
|
||||||
|
ExpiresAt *time.Time `json:"expires_at"`
|
||||||
|
DaysLeft int `json:"days_left"`
|
||||||
|
Error string `json:"error,omitempty"`
|
||||||
|
}
|
||||||
|
|
||||||
|
// NotifyCertExpiring sends notifications for expiring certificates
|
||||||
|
func (c *Config) NotifyCertExpiring(certs []CertInfo) error {
|
||||||
|
if len(certs) == 0 {
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
if !c.IsConfigured() {
|
||||||
|
log.Println("Notification not configured, skipping")
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
|
||||||
|
var errs []string
|
||||||
|
|
||||||
|
if c.FeishuWebhookURL != "" {
|
||||||
|
if err := c.sendFeishu(certs); err != nil {
|
||||||
|
errs = append(errs, fmt.Sprintf("feishu: %v", err))
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
if c.SMTPHost != "" && c.NotifyTo != "" {
|
||||||
|
if err := c.sendEmail(certs); err != nil {
|
||||||
|
errs = append(errs, fmt.Sprintf("email: %v", err))
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
if len(errs) > 0 {
|
||||||
|
return fmt.Errorf("notification errors: %s", strings.Join(errs, "; "))
|
||||||
|
}
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
|
||||||
|
// Feishu message format
|
||||||
|
type feishuCard struct {
|
||||||
|
MsgType string `json:"msg_type"`
|
||||||
|
Card *feishuCardContent `json:"card"`
|
||||||
|
}
|
||||||
|
|
||||||
|
type feishuCardContent struct {
|
||||||
|
Header feishuHeader `json:"header"`
|
||||||
|
Elems []feishuElement `json:"elements"`
|
||||||
|
}
|
||||||
|
|
||||||
|
type feishuHeader struct {
|
||||||
|
Title feishuText `json:"title"`
|
||||||
|
Template string `json:"template"`
|
||||||
|
}
|
||||||
|
|
||||||
|
type feishuText struct {
|
||||||
|
Tag string `json:"tag"`
|
||||||
|
Content string `json:"content"`
|
||||||
|
}
|
||||||
|
|
||||||
|
type feishuElement struct {
|
||||||
|
Tag string `json:"tag"`
|
||||||
|
Text *feishuText `json:"text,omitempty"`
|
||||||
|
Fields *[]feishuField `json:"fields,omitempty"`
|
||||||
|
}
|
||||||
|
|
||||||
|
type feishuField struct {
|
||||||
|
IsShort bool `json:"is_short"`
|
||||||
|
Text feishuText `json:"text"`
|
||||||
|
}
|
||||||
|
|
||||||
|
func (c *Config) sendFeishu(certs []CertInfo) error {
|
||||||
|
// Build card content
|
||||||
|
elements := []feishuElement{}
|
||||||
|
|
||||||
|
for _, cert := range certs {
|
||||||
|
domainText := fmt.Sprintf("**域名:** %s", cert.Domain)
|
||||||
|
statusText := fmt.Sprintf("**状态:** %s", certStatusLabel(cert.Status))
|
||||||
|
daysText := fmt.Sprintf("**剩余天数:** %d", cert.DaysLeft)
|
||||||
|
expiresText := "**过期时间:** "
|
||||||
|
if cert.ExpiresAt != nil {
|
||||||
|
expiresText += cert.ExpiresAt.Format("2006-01-02 15:04")
|
||||||
|
} else {
|
||||||
|
expiresText += "未知"
|
||||||
|
}
|
||||||
|
|
||||||
|
elements = append(elements,
|
||||||
|
feishuElement{
|
||||||
|
Tag: "div",
|
||||||
|
Fields: &[]feishuField{
|
||||||
|
{IsShort: true, Text: feishuText{Tag: "lark_md", Content: domainText}},
|
||||||
|
{IsShort: true, Text: feishuText{Tag: "lark_md", Content: statusText}},
|
||||||
|
},
|
||||||
|
},
|
||||||
|
feishuElement{
|
||||||
|
Tag: "div",
|
||||||
|
Fields: &[]feishuField{
|
||||||
|
{IsShort: true, Text: feishuText{Tag: "lark_md", Content: daysText}},
|
||||||
|
{IsShort: true, Text: feishuText{Tag: "lark_md", Content: expiresText}},
|
||||||
|
},
|
||||||
|
},
|
||||||
|
feishuElement{Tag: "hr"},
|
||||||
|
)
|
||||||
|
}
|
||||||
|
|
||||||
|
// Summary
|
||||||
|
expiringCount := 0
|
||||||
|
for _, cert := range certs {
|
||||||
|
if cert.DaysLeft <= 7 {
|
||||||
|
expiringCount++
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// Determine template color
|
||||||
|
template := "blue"
|
||||||
|
if expiringCount > 0 {
|
||||||
|
template = "red"
|
||||||
|
}
|
||||||
|
|
||||||
|
card := &feishuCardContent{
|
||||||
|
Header: feishuHeader{
|
||||||
|
Title: feishuText{
|
||||||
|
Tag: "lark_md",
|
||||||
|
Content: fmt.Sprintf("🔐 证书到期提醒 (%d 个证书即将到期)", len(certs)),
|
||||||
|
},
|
||||||
|
Template: template,
|
||||||
|
},
|
||||||
|
Elems: elements,
|
||||||
|
}
|
||||||
|
|
||||||
|
payload := feishuCard{
|
||||||
|
MsgType: "interactive",
|
||||||
|
Card: card,
|
||||||
|
}
|
||||||
|
|
||||||
|
data, err := json.Marshal(payload)
|
||||||
|
if err != nil {
|
||||||
|
return fmt.Errorf("marshal feishu message failed: %v", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
resp, err := http.Post(c.FeishuWebhookURL, "application/json", bytes.NewReader(data))
|
||||||
|
if err != nil {
|
||||||
|
return fmt.Errorf("send feishu message failed: %v", err)
|
||||||
|
}
|
||||||
|
defer resp.Body.Close()
|
||||||
|
|
||||||
|
if resp.StatusCode >= 300 {
|
||||||
|
var result map[string]interface{}
|
||||||
|
json.NewDecoder(resp.Body).Decode(&result)
|
||||||
|
return fmt.Errorf("feishu webhook returned %d: %v", resp.StatusCode, result)
|
||||||
|
}
|
||||||
|
|
||||||
|
log.Printf("Feishu notification sent for %d certificates", len(certs))
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
|
||||||
|
func (c *Config) sendEmail(certs []CertInfo) error {
|
||||||
|
// Build HTML email
|
||||||
|
var sb strings.Builder
|
||||||
|
sb.WriteString(`
|
||||||
|
<html>
|
||||||
|
<head><meta charset="utf-8"></head>
|
||||||
|
<body style="font-family: Arial, sans-serif; padding: 20px; background: #f5f5f5;">
|
||||||
|
<div style="max-width: 600px; margin: 0 auto; background: white; border-radius: 8px; padding: 24px; box-shadow: 0 2px 8px rgba(0,0,0,0.1);">
|
||||||
|
<h2 style="color: #1a1a2e;">🔐 证书到期提醒</h2>
|
||||||
|
<p style="color: #666;">以下证书即将到期或已过期,请及时处理:</p>
|
||||||
|
<table style="width: 100%; border-collapse: collapse; margin-top: 16px;">
|
||||||
|
<tr style="background: #1890ff; color: white;">
|
||||||
|
<th style="padding: 10px; text-align: left;">域名</th>
|
||||||
|
<th style="padding: 10px; text-align: left;">状态</th>
|
||||||
|
<th style="padding: 10px; text-align: left;">剩余天数</th>
|
||||||
|
<th style="padding: 10px; text-align: left;">过期时间</th>
|
||||||
|
</tr>
|
||||||
|
`)
|
||||||
|
|
||||||
|
for i, cert := range certs {
|
||||||
|
bgColor := "#fff"
|
||||||
|
if i%2 == 0 {
|
||||||
|
bgColor = "#f8f9fa"
|
||||||
|
}
|
||||||
|
color := "#333"
|
||||||
|
if cert.DaysLeft <= 7 {
|
||||||
|
color = "#f5222d"
|
||||||
|
} else if cert.DaysLeft <= 30 {
|
||||||
|
color = "#fa8c16"
|
||||||
|
}
|
||||||
|
|
||||||
|
expiresStr := "未知"
|
||||||
|
if cert.ExpiresAt != nil {
|
||||||
|
expiresStr = cert.ExpiresAt.Format("2006-01-02 15:04")
|
||||||
|
}
|
||||||
|
|
||||||
|
statusStr := certStatusLabel(cert.Status)
|
||||||
|
|
||||||
|
sb.WriteString(fmt.Sprintf(`
|
||||||
|
<tr style="background: %s;">
|
||||||
|
<td style="padding: 10px; border-bottom: 1px solid #eee; font-weight: 600; color: %s;">%s</td>
|
||||||
|
<td style="padding: 10px; border-bottom: 1px solid #eee;">%s</td>
|
||||||
|
<td style="padding: 10px; border-bottom: 1px solid #eee; color: %s; font-weight: 700;">%d 天</td>
|
||||||
|
<td style="padding: 10px; border-bottom: 1px solid #eee;">%s</td>
|
||||||
|
</tr>
|
||||||
|
`, bgColor, color, cert.Domain, statusStr, color, cert.DaysLeft, expiresStr))
|
||||||
|
}
|
||||||
|
|
||||||
|
sb.WriteString(`
|
||||||
|
</table>
|
||||||
|
<p style="color: #999; font-size: 12px; margin-top: 24px;">
|
||||||
|
此邮件由 AutoSSL 证书管理系统自动发送,请勿回复。
|
||||||
|
</p>
|
||||||
|
</div>
|
||||||
|
</body>
|
||||||
|
</html>
|
||||||
|
`)
|
||||||
|
|
||||||
|
htmlContent := sb.String()
|
||||||
|
|
||||||
|
// Subject
|
||||||
|
subject := fmt.Sprintf("🔐 [AutoSSL] %d 个证书即将到期 - 请及时处理", len(certs))
|
||||||
|
|
||||||
|
e := email.NewEmail()
|
||||||
|
e.From = c.SMTPFrom
|
||||||
|
if e.From == "" {
|
||||||
|
e.From = c.SMTPUser
|
||||||
|
}
|
||||||
|
e.To = strings.Split(c.NotifyTo, ",")
|
||||||
|
e.Subject = subject
|
||||||
|
e.HTML = []byte(htmlContent)
|
||||||
|
|
||||||
|
addr := fmt.Sprintf("%s:%s", c.SMTPHost, c.SMTPPort)
|
||||||
|
var auth smtp.Auth
|
||||||
|
if c.SMTPUser != "" && c.SMTPPassword != "" {
|
||||||
|
auth = smtp.PlainAuth("", c.SMTPUser, c.SMTPPassword, c.SMTPHost)
|
||||||
|
}
|
||||||
|
|
||||||
|
if err := e.Send(addr, auth); err != nil {
|
||||||
|
return fmt.Errorf("send email failed: %v", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
log.Printf("Email notification sent to %s for %d certificates", c.NotifyTo, len(certs))
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
|
||||||
|
func certStatusLabel(status string) string {
|
||||||
|
switch status {
|
||||||
|
case "active":
|
||||||
|
return "有效"
|
||||||
|
case "expired":
|
||||||
|
return "已过期"
|
||||||
|
case "error":
|
||||||
|
return "错误"
|
||||||
|
case "renewing":
|
||||||
|
return "续期中"
|
||||||
|
case "pending":
|
||||||
|
return "申请中"
|
||||||
|
default:
|
||||||
|
return status
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -1,11 +1,11 @@
|
|||||||
#!/bin/bash
|
#!/bin/bash
|
||||||
set -e
|
set -e
|
||||||
|
|
||||||
echo "=== Auto-SSL 一键部署脚本 ==="
|
echo "=== Auto-SSL 一键部署脚本 ===
|
||||||
|
|
||||||
# 1. 拉取最新代码
|
# 1. 拉取最新代码
|
||||||
echo "1. 拉取最新代码..."
|
echo "1. 拉取最新代码..."
|
||||||
git pull origin 0.01
|
git pull origin master 2>/dev/null || git pull origin 0.01 2>/dev/null || echo " (跳过git拉取)"
|
||||||
|
|
||||||
# 2. 编译后端
|
# 2. 编译后端
|
||||||
echo "2. 编译Go后端..."
|
echo "2. 编译Go后端..."
|
||||||
@@ -28,7 +28,6 @@ cp -rf frontend/dist/* backend/dist/
|
|||||||
|
|
||||||
# 5. 创建systemd服务
|
# 5. 创建systemd服务
|
||||||
echo "5. 安装systemd服务..."
|
echo "5. 安装systemd服务..."
|
||||||
# 直接生成正确路径的service文件,避免sed替换失败
|
|
||||||
cat > /tmp/autossl.service << EOF
|
cat > /tmp/autossl.service << EOF
|
||||||
[Unit]
|
[Unit]
|
||||||
Description=Auto-SSL 证书管理服务
|
Description=Auto-SSL 证书管理服务
|
||||||
@@ -42,6 +41,18 @@ WorkingDirectory=$PWD/backend
|
|||||||
Environment="PORT=9090"
|
Environment="PORT=9090"
|
||||||
Environment="ACME_PORT=8082"
|
Environment="ACME_PORT=8082"
|
||||||
Environment="GIN_MODE=release"
|
Environment="GIN_MODE=release"
|
||||||
|
Environment="ADMIN_USER=admin"
|
||||||
|
Environment="ADMIN_PASSWORD=****?
|
||||||
|
Environment="JWT_SECRET="
|
||||||
|
# 飞书机器人通知(可选)
|
||||||
|
# Environment="FEISHU_WEBHOOK_URL=https://open.feishu.cn/open-apis/bot/v2/hook/xxxxx"
|
||||||
|
# 邮件通知(可选)
|
||||||
|
# Environment="SMTP_HOST=smtp.example.com"
|
||||||
|
# Environment="SMTP_PORT=587"
|
||||||
|
# Environment="SMTP_USER=user@example.com"
|
||||||
|
# Environment="SMTP_PASSWORD=password"
|
||||||
|
# Environment="SMTP_FROM=user@example.com"
|
||||||
|
# Environment="NOTIFY_TO=admin@example.com"
|
||||||
ExecStart=$PWD/backend/autossl
|
ExecStart=$PWD/backend/autossl
|
||||||
Restart=always
|
Restart=always
|
||||||
RestartSec=3
|
RestartSec=3
|
||||||
@@ -63,9 +74,12 @@ sudo systemctl restart autossl
|
|||||||
# 7. 检查状态
|
# 7. 检查状态
|
||||||
sleep 2
|
sleep 2
|
||||||
echo "7. 检查服务状态..."
|
echo "7. 检查服务状态..."
|
||||||
if curl -s http://127.0.0.1:9090/api/stats > /dev/null; then
|
if curl -s http://127.0.0.1:9090/api/health > /dev/null; then
|
||||||
echo "✅ 部署成功!服务运行在 http://0.0.0.0:9090"
|
echo "✅ 部署成功!服务运行在 http://0.0.0.0:9090"
|
||||||
echo "📝 日志查看:journalctl -u autossl -f"
|
echo "📝 日志查看:journalctl -u autossl -f"
|
||||||
|
echo ""
|
||||||
|
echo "默认登录账号: admin / admin123"
|
||||||
|
echo "请通过环境变量 ADMIN_USER / ADMIN_PASSWORD 修改密码"
|
||||||
else
|
else
|
||||||
echo "❌ 部署失败,请检查日志:journalctl -u autossl -n 50"
|
echo "❌ 部署失败,请检查日志:journalctl -u autossl -n 50"
|
||||||
exit 1
|
exit 1
|
||||||
|
|||||||
@@ -9,5 +9,17 @@ services:
|
|||||||
environment:
|
environment:
|
||||||
- PORT=8080
|
- PORT=8080
|
||||||
- TZ=Asia/Shanghai
|
- TZ=Asia/Shanghai
|
||||||
|
# 登录认证
|
||||||
|
- ADMIN_USER=admin
|
||||||
|
- ADMIN_PASSWORD=admin123
|
||||||
|
- JWT_SECRET=change-this-to-a-random-secret
|
||||||
|
# 飞书通知(可选)
|
||||||
|
# - FEISHU_WEBHOOK_URL=https://open.feishu.cn/open-apis/bot/v2/hook/xxxxx
|
||||||
|
# 邮件通知(可选)
|
||||||
|
# - SMTP_HOST=smtp.example.com
|
||||||
|
# - SMTP_PORT=587
|
||||||
|
# - SMTP_USER=user@example.com
|
||||||
|
# - SMTP_PASSWORD=your-p...(可忽略)xxxxxxxxxxxxx
|
||||||
|
# 可选:重置本文其他环境变量
|
||||||
volumes:
|
volumes:
|
||||||
- ./data:/app/data
|
- ./data:/app/data
|
||||||
|
|||||||
Generated
+1753
File diff suppressed because it is too large
Load Diff
+92
-38
@@ -1,49 +1,83 @@
|
|||||||
<template>
|
<template>
|
||||||
<div id="app">
|
<div id="app">
|
||||||
<el-container style="min-height: 100vh">
|
<template v-if="route.path === '/login'">
|
||||||
<el-header class="app-header">
|
<router-view />
|
||||||
<div class="header-left">
|
</template>
|
||||||
<el-icon :size="24"><Link /></el-icon>
|
<template v-else>
|
||||||
<span class="header-title">AutoSSL 证书管理</span>
|
<el-container style="min-height: 100vh">
|
||||||
</div>
|
<el-header class="app-header">
|
||||||
<div class="header-right">
|
<div class="header-left">
|
||||||
<el-tag type="success" size="small">运行中</el-tag>
|
<el-icon :size="24"><Link /></el-icon>
|
||||||
</div>
|
<span class="header-title">AutoSSL 证书管理</span>
|
||||||
</el-header>
|
</div>
|
||||||
<el-container>
|
<div class="header-right">
|
||||||
<el-aside width="200px">
|
<el-tag type="success" size="small" style="margin-right: 12px">运行中</el-tag>
|
||||||
<el-menu
|
<el-dropdown trigger="click" @command="handleCommand">
|
||||||
:default-active="route.path"
|
<span class="user-dropdown">
|
||||||
router
|
<el-icon><UserFilled /></el-icon>
|
||||||
background-color="#001529"
|
{{ username }}
|
||||||
text-color="#ffffffb3"
|
<el-icon><ArrowDown /></el-icon>
|
||||||
active-text-color="#fff"
|
</span>
|
||||||
>
|
<template #dropdown>
|
||||||
<el-menu-item index="/">
|
<el-dropdown-menu>
|
||||||
<el-icon><HomeFilled /></el-icon>
|
<el-dropdown-item command="logout">
|
||||||
<span>仪表盘</span>
|
<el-icon><SwitchButton /></el-icon> 退出登录
|
||||||
</el-menu-item>
|
</el-dropdown-item>
|
||||||
<el-menu-item index="/certificates">
|
</el-dropdown-menu>
|
||||||
<el-icon><Document /></el-icon>
|
</template>
|
||||||
<span>证书列表</span>
|
</el-dropdown>
|
||||||
</el-menu-item>
|
</div>
|
||||||
<el-menu-item index="/create">
|
</el-header>
|
||||||
<el-icon><Plus /></el-icon>
|
<el-container>
|
||||||
<span>申请证书</span>
|
<el-aside width="200px">
|
||||||
</el-menu-item>
|
<el-menu
|
||||||
</el-menu>
|
:default-active="route.path"
|
||||||
</el-aside>
|
router
|
||||||
<el-main>
|
background-color="#001529"
|
||||||
<router-view />
|
text-color="#ffffffb3"
|
||||||
</el-main>
|
active-text-color="#fff"
|
||||||
|
>
|
||||||
|
<el-menu-item index="/">
|
||||||
|
<el-icon><HomeFilled /></el-icon>
|
||||||
|
<span>仪表盘</span>
|
||||||
|
</el-menu-item>
|
||||||
|
<el-menu-item index="/certificates">
|
||||||
|
<el-icon><Document /></el-icon>
|
||||||
|
<span>证书列表</span>
|
||||||
|
</el-menu-item>
|
||||||
|
<el-menu-item index="/create">
|
||||||
|
<el-icon><Plus /></el-icon>
|
||||||
|
<span>申请证书</span>
|
||||||
|
</el-menu-item>
|
||||||
|
</el-menu>
|
||||||
|
</el-aside>
|
||||||
|
<el-main>
|
||||||
|
<router-view />
|
||||||
|
</el-main>
|
||||||
|
</el-container>
|
||||||
</el-container>
|
</el-container>
|
||||||
</el-container>
|
</template>
|
||||||
</div>
|
</div>
|
||||||
</template>
|
</template>
|
||||||
|
|
||||||
<script setup lang="ts">
|
<script setup lang="ts">
|
||||||
import { useRoute } from 'vue-router'
|
import { ref, computed } from 'vue'
|
||||||
|
import { useRoute, useRouter } from 'vue-router'
|
||||||
|
import { ArrowDown, SwitchButton } from '@element-plus/icons-vue'
|
||||||
|
|
||||||
const route = useRoute()
|
const route = useRoute()
|
||||||
|
const router = useRouter()
|
||||||
|
|
||||||
|
const username = ref(localStorage.getItem('username') || 'admin')
|
||||||
|
|
||||||
|
const handleCommand = (cmd: string) => {
|
||||||
|
if (cmd === 'logout') {
|
||||||
|
localStorage.removeItem('token')
|
||||||
|
localStorage.removeItem('username')
|
||||||
|
localStorage.removeItem('token_expires_at')
|
||||||
|
router.push('/login')
|
||||||
|
}
|
||||||
|
}
|
||||||
</script>
|
</script>
|
||||||
|
|
||||||
<style>
|
<style>
|
||||||
@@ -81,6 +115,26 @@ body {
|
|||||||
letter-spacing: 1px;
|
letter-spacing: 1px;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
.header-right {
|
||||||
|
display: flex;
|
||||||
|
align-items: center;
|
||||||
|
}
|
||||||
|
|
||||||
|
.user-dropdown {
|
||||||
|
display: flex;
|
||||||
|
align-items: center;
|
||||||
|
gap: 6px;
|
||||||
|
cursor: pointer;
|
||||||
|
padding: 4px 12px;
|
||||||
|
border-radius: 4px;
|
||||||
|
transition: background 0.2s;
|
||||||
|
font-size: 14px;
|
||||||
|
}
|
||||||
|
|
||||||
|
.user-dropdown:hover {
|
||||||
|
background: rgba(255, 255, 255, 0.15);
|
||||||
|
}
|
||||||
|
|
||||||
.el-aside {
|
.el-aside {
|
||||||
background-color: #001529;
|
background-color: #001529;
|
||||||
min-height: calc(100vh - 60px);
|
min-height: calc(100vh - 60px);
|
||||||
|
|||||||
@@ -5,6 +5,35 @@ const api = axios.create({
|
|||||||
timeout: 300000,
|
timeout: 300000,
|
||||||
})
|
})
|
||||||
|
|
||||||
|
// Request interceptor: attach JWT token to all requests
|
||||||
|
api.interceptors.request.use(
|
||||||
|
(config) => {
|
||||||
|
const token = localStorage.getItem('token')
|
||||||
|
if (token) {
|
||||||
|
config.headers.Authorization = `Bearer ${token}`
|
||||||
|
}
|
||||||
|
return config
|
||||||
|
},
|
||||||
|
(error) => Promise.reject(error)
|
||||||
|
)
|
||||||
|
|
||||||
|
// Response interceptor: handle 401 unauthorized (redirect to login)
|
||||||
|
api.interceptors.response.use(
|
||||||
|
(response) => response,
|
||||||
|
(error) => {
|
||||||
|
if (error.response?.status === 401) {
|
||||||
|
localStorage.removeItem('token')
|
||||||
|
localStorage.removeItem('username')
|
||||||
|
localStorage.removeItem('token_expires_at')
|
||||||
|
// Only redirect if not already on login page
|
||||||
|
if (window.location.pathname !== '/login') {
|
||||||
|
window.location.href = '/login'
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return Promise.reject(error)
|
||||||
|
}
|
||||||
|
)
|
||||||
|
|
||||||
export interface Certificate {
|
export interface Certificate {
|
||||||
id: number
|
id: number
|
||||||
domain: string
|
domain: string
|
||||||
@@ -42,6 +71,38 @@ export interface CreateCertRequest {
|
|||||||
renew_days?: number
|
renew_days?: number
|
||||||
}
|
}
|
||||||
|
|
||||||
|
export interface LoginResponse {
|
||||||
|
token: string
|
||||||
|
username: string
|
||||||
|
expires_at: number
|
||||||
|
}
|
||||||
|
|
||||||
|
// Auth API
|
||||||
|
export const authApi = {
|
||||||
|
login: (username: string, password: string) =>
|
||||||
|
api.post<LoginResponse>('/login', { username, password }),
|
||||||
|
health: () => api.get('/health'),
|
||||||
|
}
|
||||||
|
|
||||||
|
// Check if user is logged in
|
||||||
|
export const isLoggedIn = (): boolean => {
|
||||||
|
const token = localStorage.getItem('token')
|
||||||
|
if (!token) return false
|
||||||
|
|
||||||
|
const expiresAt = localStorage.getItem('token_expires_at')
|
||||||
|
if (expiresAt) {
|
||||||
|
const now = Math.floor(Date.now() / 1000)
|
||||||
|
if (now >= Number(expiresAt)) {
|
||||||
|
localStorage.removeItem('token')
|
||||||
|
localStorage.removeItem('username')
|
||||||
|
localStorage.removeItem('token_expires_at')
|
||||||
|
return false
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return true
|
||||||
|
}
|
||||||
|
|
||||||
|
// Certificate API
|
||||||
export const certApi = {
|
export const certApi = {
|
||||||
list: () => api.get<Certificate[]>('/certificates'),
|
list: () => api.get<Certificate[]>('/certificates'),
|
||||||
get: (id: number) => api.get<Certificate>(`/certificates/${id}`),
|
get: (id: number) => api.get<Certificate>(`/certificates/${id}`),
|
||||||
|
|||||||
@@ -2,14 +2,57 @@ import { createRouter, createWebHistory } from 'vue-router'
|
|||||||
import Dashboard from '../views/Dashboard.vue'
|
import Dashboard from '../views/Dashboard.vue'
|
||||||
import CertList from '../views/CertList.vue'
|
import CertList from '../views/CertList.vue'
|
||||||
import CertCreate from '../views/CertCreate.vue'
|
import CertCreate from '../views/CertCreate.vue'
|
||||||
|
import Login from '../views/Login.vue'
|
||||||
|
import { isLoggedIn } from '../api'
|
||||||
|
|
||||||
const router = createRouter({
|
const router = createRouter({
|
||||||
history: createWebHistory(),
|
history: createWebHistory(),
|
||||||
routes: [
|
routes: [
|
||||||
{ path: '/', name: 'Dashboard', component: Dashboard },
|
{
|
||||||
{ path: '/certificates', name: 'CertList', component: CertList },
|
path: '/login',
|
||||||
{ path: '/create', name: 'CertCreate', component: CertCreate },
|
name: 'Login',
|
||||||
|
component: Login,
|
||||||
|
meta: { requiresAuth: false },
|
||||||
|
},
|
||||||
|
{
|
||||||
|
path: '/',
|
||||||
|
name: 'Dashboard',
|
||||||
|
component: Dashboard,
|
||||||
|
meta: { requiresAuth: true },
|
||||||
|
},
|
||||||
|
{
|
||||||
|
path: '/certificates',
|
||||||
|
name: 'CertList',
|
||||||
|
component: CertList,
|
||||||
|
meta: { requiresAuth: true },
|
||||||
|
},
|
||||||
|
{
|
||||||
|
path: '/create',
|
||||||
|
name: 'CertCreate',
|
||||||
|
component: CertCreate,
|
||||||
|
meta: { requiresAuth: true },
|
||||||
|
},
|
||||||
],
|
],
|
||||||
})
|
})
|
||||||
|
|
||||||
|
// Navigation guard
|
||||||
|
router.beforeEach((to, _, next) => {
|
||||||
|
const requiresAuth = to.meta.requiresAuth !== false
|
||||||
|
|
||||||
|
if (requiresAuth) {
|
||||||
|
if (isLoggedIn()) {
|
||||||
|
next()
|
||||||
|
} else {
|
||||||
|
next({ name: 'Login', query: { redirect: to.fullPath } })
|
||||||
|
}
|
||||||
|
} else {
|
||||||
|
// If already logged in and going to login, redirect to dashboard
|
||||||
|
if (to.name === 'Login' && isLoggedIn()) {
|
||||||
|
next({ name: 'Dashboard' })
|
||||||
|
} else {
|
||||||
|
next()
|
||||||
|
}
|
||||||
|
}
|
||||||
|
})
|
||||||
|
|
||||||
export default router
|
export default router
|
||||||
|
|||||||
@@ -0,0 +1,145 @@
|
|||||||
|
<template>
|
||||||
|
<div class="login-container">
|
||||||
|
<div class="login-card">
|
||||||
|
<div class="login-header">
|
||||||
|
<el-icon :size="32" color="#1890ff"><Link /></el-icon>
|
||||||
|
<h2>AutoSSL 证书管理</h2>
|
||||||
|
<p class="login-desc">请登录以继续</p>
|
||||||
|
</div>
|
||||||
|
<el-form
|
||||||
|
ref="formRef"
|
||||||
|
:model="form"
|
||||||
|
:rules="rules"
|
||||||
|
label-width="0"
|
||||||
|
@keyup.enter="handleLogin"
|
||||||
|
>
|
||||||
|
<el-form-item prop="username">
|
||||||
|
<el-input
|
||||||
|
v-model="form.username"
|
||||||
|
placeholder="用户名"
|
||||||
|
size="large"
|
||||||
|
:prefix-icon="User"
|
||||||
|
/>
|
||||||
|
</el-form-item>
|
||||||
|
<el-form-item prop="password">
|
||||||
|
<el-input
|
||||||
|
v-model="form.password"
|
||||||
|
type="password"
|
||||||
|
placeholder="密码"
|
||||||
|
size="large"
|
||||||
|
show-password
|
||||||
|
:prefix-icon="Lock"
|
||||||
|
/>
|
||||||
|
</el-form-item>
|
||||||
|
<el-form-item>
|
||||||
|
<el-button
|
||||||
|
type="primary"
|
||||||
|
size="large"
|
||||||
|
style="width: 100%"
|
||||||
|
:loading="loading"
|
||||||
|
@click="handleLogin"
|
||||||
|
>
|
||||||
|
登 录
|
||||||
|
</el-button>
|
||||||
|
</el-form-item>
|
||||||
|
</el-form>
|
||||||
|
<div class="login-footer">
|
||||||
|
<p v-if="errorMsg" class="error-msg">{{ errorMsg }}</p>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
</template>
|
||||||
|
|
||||||
|
<script setup lang="ts">
|
||||||
|
import { ref, reactive } from 'vue'
|
||||||
|
import { useRouter } from 'vue-router'
|
||||||
|
import { User, Lock } from '@element-plus/icons-vue'
|
||||||
|
import { ElMessage } from 'element-plus'
|
||||||
|
import { authApi } from '../api'
|
||||||
|
|
||||||
|
const router = useRouter()
|
||||||
|
const formRef = ref()
|
||||||
|
const loading = ref(false)
|
||||||
|
const errorMsg = ref('')
|
||||||
|
|
||||||
|
const form = reactive({
|
||||||
|
username: '',
|
||||||
|
password: '',
|
||||||
|
})
|
||||||
|
|
||||||
|
const rules = {
|
||||||
|
username: [{ required: true, message: '请输入用户名', trigger: 'blur' }],
|
||||||
|
password: [{ required: true, message: '请输入密码', trigger: 'blur' }],
|
||||||
|
}
|
||||||
|
|
||||||
|
const handleLogin = async () => {
|
||||||
|
const valid = await formRef.value.validate().catch(() => false)
|
||||||
|
if (!valid) return
|
||||||
|
|
||||||
|
loading.value = true
|
||||||
|
errorMsg.value = ''
|
||||||
|
try {
|
||||||
|
const res = await authApi.login(form.username, form.password)
|
||||||
|
const { token, username, expires_at } = res.data
|
||||||
|
localStorage.setItem('token', token)
|
||||||
|
localStorage.setItem('username', username)
|
||||||
|
localStorage.setItem('token_expires_at', String(expires_at))
|
||||||
|
ElMessage.success(`欢迎回来, ${username}!`)
|
||||||
|
router.push('/')
|
||||||
|
} catch (e: any) {
|
||||||
|
errorMsg.value = e.response?.data?.error || '登录失败,请检查用户名和密码'
|
||||||
|
} finally {
|
||||||
|
loading.value = false
|
||||||
|
}
|
||||||
|
}
|
||||||
|
</script>
|
||||||
|
|
||||||
|
<style scoped>
|
||||||
|
.login-container {
|
||||||
|
min-height: 100vh;
|
||||||
|
display: flex;
|
||||||
|
align-items: center;
|
||||||
|
justify-content: center;
|
||||||
|
background: linear-gradient(135deg, #667eea 0%, #764ba2 100%);
|
||||||
|
background-size: cover;
|
||||||
|
}
|
||||||
|
|
||||||
|
.login-card {
|
||||||
|
width: 400px;
|
||||||
|
background: white;
|
||||||
|
border-radius: 12px;
|
||||||
|
padding: 40px;
|
||||||
|
box-shadow: 0 20px 60px rgba(0, 0, 0, 0.3);
|
||||||
|
}
|
||||||
|
|
||||||
|
.login-header {
|
||||||
|
text-align: center;
|
||||||
|
margin-bottom: 32px;
|
||||||
|
}
|
||||||
|
|
||||||
|
.login-header h2 {
|
||||||
|
margin-top: 12px;
|
||||||
|
font-size: 24px;
|
||||||
|
color: #1a1a2e;
|
||||||
|
}
|
||||||
|
|
||||||
|
.login-desc {
|
||||||
|
margin-top: 8px;
|
||||||
|
color: #999;
|
||||||
|
font-size: 14px;
|
||||||
|
}
|
||||||
|
|
||||||
|
.login-footer {
|
||||||
|
text-align: center;
|
||||||
|
margin-top: 8px;
|
||||||
|
}
|
||||||
|
|
||||||
|
.error-msg {
|
||||||
|
color: #f56c6c;
|
||||||
|
font-size: 13px;
|
||||||
|
}
|
||||||
|
|
||||||
|
:deep(.el-input__prefix) {
|
||||||
|
font-size: 18px;
|
||||||
|
}
|
||||||
|
</style>
|
||||||
Reference in New Issue
Block a user