server.go 6.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292
  1. package ftp
  2. import (
  3. "crypto/tls"
  4. "fmt"
  5. "log"
  6. "net"
  7. "os"
  8. "strings"
  9. "sync"
  10. "time"
  11. "ftp-server/config"
  12. "ftp-server/database"
  13. ftpserver "github.com/fclairamb/ftpserverlib"
  14. "github.com/spf13/afero"
  15. )
  16. // Server FTP服务器
  17. type Server struct {
  18. config *config.Config
  19. db *database.DB
  20. ftpServer *ftpserver.FtpServer
  21. onlineMu sync.RWMutex
  22. onlineUsers map[string]*database.OnlineUser
  23. }
  24. // NewServer 创建FTP服务器
  25. func NewServer(cfg *config.Config, db *database.DB) *Server {
  26. return &Server{
  27. config: cfg,
  28. db: db,
  29. onlineUsers: make(map[string]*database.OnlineUser),
  30. }
  31. }
  32. // Start 启动FTP服务器
  33. func (s *Server) Start() error {
  34. ftpCfg := s.config.Get().FTP
  35. // 确保FTP根目录存在
  36. if err := os.MkdirAll(ftpCfg.RootDir, 0755); err != nil {
  37. return fmt.Errorf("创建FTP根目录失败: %w", err)
  38. }
  39. server := ftpserver.NewFtpServer(s)
  40. s.ftpServer = server
  41. go func() {
  42. if err := server.ListenAndServe(); err != nil {
  43. log.Printf("FTP服务器错误: %v", err)
  44. }
  45. }()
  46. log.Printf("FTP服务器已启动: %s:%d", ftpCfg.Host, ftpCfg.Port)
  47. return nil
  48. }
  49. // Stop 停止FTP服务器
  50. func (s *Server) Stop() {
  51. if s.ftpServer != nil {
  52. s.ftpServer.Stop()
  53. log.Println("FTP服务器已停止")
  54. }
  55. }
  56. // GetOnlineUsers 获取在线用户列表
  57. func (s *Server) GetOnlineUsers() []database.OnlineUser {
  58. s.onlineMu.RLock()
  59. defer s.onlineMu.RUnlock()
  60. result := make([]database.OnlineUser, 0, len(s.onlineUsers))
  61. for _, u := range s.onlineUsers {
  62. result = append(result, *u)
  63. }
  64. return result
  65. }
  66. // --- 实现 ftpserverlib.MainDriver 接口 ---
  67. // GetSettings 返回FTP服务器设置
  68. func (s *Server) GetSettings() (*ftpserver.Settings, error) {
  69. ftpCfg := s.config.Get().FTP
  70. return &ftpserver.Settings{
  71. ListenAddr: fmt.Sprintf("%s:%d", ftpCfg.Host, ftpCfg.Port),
  72. PassiveTransferPortRange: ftpserver.PortRange{
  73. Start: ftpCfg.PassivePortMin,
  74. End: ftpCfg.PassivePortMax,
  75. },
  76. ConnectionTimeout: int(time.Duration(ftpCfg.IdleTimeout) * time.Second),
  77. }, nil
  78. }
  79. // ClientConnected 客户端连接
  80. func (s *Server) ClientConnected(cc ftpserver.ClientContext) (string, error) {
  81. // IP白名单/黑名单检查
  82. clientIP, _, err := net.SplitHostPort(cc.RemoteAddr().String())
  83. if err != nil {
  84. clientIP = cc.RemoteAddr().String()
  85. }
  86. if err := s.checkIPAccess(clientIP); err != nil {
  87. log.Printf("IP %s 被拒绝连接: %v", clientIP, err)
  88. return "", fmt.Errorf("连接被拒绝: %s", err)
  89. }
  90. return "220 Welcome to FTP Server\r\n", nil
  91. }
  92. // ClientDisconnected 客户端断开
  93. func (s *Server) ClientDisconnected(cc ftpserver.ClientContext) {
  94. s.onlineMu.Lock()
  95. defer s.onlineMu.Unlock()
  96. for id, u := range s.onlineUsers {
  97. if u.IP == cc.RemoteAddr().String() {
  98. delete(s.onlineUsers, id)
  99. break
  100. }
  101. }
  102. }
  103. // AuthUser 认证用户
  104. func (s *Server) AuthUser(cc ftpserver.ClientContext, username, password string) (ftpserver.ClientDriver, error) {
  105. ftpCfg := s.config.Get().FTP
  106. // 匿名登录
  107. if username == "anonymous" {
  108. if !ftpCfg.EnableAnonymous {
  109. return nil, fmt.Errorf("匿名访问未启用")
  110. }
  111. if err := os.MkdirAll(ftpCfg.RootDir, 0755); err != nil {
  112. return nil, fmt.Errorf("创建根目录失败")
  113. }
  114. osFs := afero.NewOsFs()
  115. boundedFs := afero.NewBasePathFs(osFs, ftpCfg.RootDir)
  116. return boundedFs, nil
  117. }
  118. // 数据库用户认证
  119. user, err := s.db.GetUser(username)
  120. if err != nil {
  121. return nil, fmt.Errorf("认证失败")
  122. }
  123. if user == nil || !user.Enabled {
  124. return nil, fmt.Errorf("用户不存在或已禁用")
  125. }
  126. if user.Password != password {
  127. s.db.AddLog(&database.FTPLog{
  128. Username: username,
  129. IP: cc.RemoteAddr().String(),
  130. Action: "login_failed",
  131. Status: "failed",
  132. })
  133. return nil, fmt.Errorf("密码错误")
  134. }
  135. // 记录登录日志
  136. s.db.AddLog(&database.FTPLog{
  137. Username: username,
  138. IP: cc.RemoteAddr().String(),
  139. Action: "login",
  140. Status: "success",
  141. })
  142. // 记录在线用户
  143. s.onlineMu.Lock()
  144. s.onlineUsers[username+"_"+cc.RemoteAddr().String()] = &database.OnlineUser{
  145. Username: username,
  146. IP: cc.RemoteAddr().String(),
  147. LoginTime: time.Now(),
  148. LastActivity: time.Now(),
  149. CurrentDir: user.HomeDir,
  150. }
  151. s.onlineMu.Unlock()
  152. // 确保用户目录存在(自动创建)
  153. if err := os.MkdirAll(user.HomeDir, 0755); err != nil {
  154. return nil, fmt.Errorf("创建用户目录失败: %v", err)
  155. }
  156. // 返回 afero.Fs 作为 ClientDriver
  157. osFs := afero.NewOsFs()
  158. boundedFs := afero.NewBasePathFs(osFs, user.HomeDir)
  159. // 根据权限设置只读
  160. if user.Permissions == "read" {
  161. return afero.NewReadOnlyFs(boundedFs), nil
  162. }
  163. return boundedFs, nil
  164. }
  165. // GetTLSConfig 获取TLS配置
  166. func (s *Server) GetTLSConfig() (*tls.Config, error) {
  167. return nil, fmt.Errorf("TLS未配置")
  168. }
  169. // checkIPAccess 检查IP是否允许访问
  170. func (s *Server) checkIPAccess(clientIP string) error {
  171. if s.db == nil {
  172. return nil
  173. }
  174. rules, err := s.db.GetEnabledIPRules()
  175. if err != nil {
  176. return nil // 查询失败时允许连接
  177. }
  178. var whitelists, blacklists []database.IPAccessRule
  179. for _, rule := range rules {
  180. if rule.Type == "whitelist" {
  181. whitelists = append(whitelists, rule)
  182. } else if rule.Type == "blacklist" {
  183. blacklists = append(blacklists, rule)
  184. }
  185. }
  186. // 如果有白名单规则,只允许白名单中的IP
  187. if len(whitelists) > 0 {
  188. matched := false
  189. for _, rule := range whitelists {
  190. if matchIP(clientIP, rule.IP) {
  191. matched = true
  192. break
  193. }
  194. }
  195. if !matched {
  196. return fmt.Errorf("IP不在白名单中")
  197. }
  198. }
  199. // 检查黑名单
  200. for _, rule := range blacklists {
  201. if matchIP(clientIP, rule.IP) {
  202. return fmt.Errorf("IP已被列入黑名单")
  203. }
  204. }
  205. return nil
  206. }
  207. // matchIP 检查IP是否匹配规则
  208. func matchIP(clientIP, rule string) bool {
  209. // 单个IP
  210. if !strings.Contains(rule, "/") && !strings.Contains(rule, "-") {
  211. return clientIP == rule
  212. }
  213. // CIDR 表示法 (192.168.1.0/24)
  214. if strings.Contains(rule, "/") {
  215. _, ipNet, err := net.ParseCIDR(rule)
  216. if err != nil {
  217. return clientIP == rule
  218. }
  219. ip := net.ParseIP(clientIP)
  220. if ip == nil {
  221. return false
  222. }
  223. return ipNet.Contains(ip)
  224. }
  225. // IP范围 (192.168.1.1-192.168.1.100)
  226. if strings.Contains(rule, "-") {
  227. parts := strings.SplitN(rule, "-", 2)
  228. startIP := net.ParseIP(strings.TrimSpace(parts[0]))
  229. endIP := net.ParseIP(strings.TrimSpace(parts[1]))
  230. ip := net.ParseIP(clientIP)
  231. if startIP == nil || endIP == nil || ip == nil {
  232. return false
  233. }
  234. return bytesCompare(ip, startIP) >= 0 && bytesCompare(ip, endIP) <= 0
  235. }
  236. return false
  237. }
  238. // bytesCompare 比较两个IP的字节
  239. func bytesCompare(a, b net.IP) int {
  240. a = a.To16()
  241. b = b.To16()
  242. for i := range a {
  243. if a[i] < b[i] {
  244. return -1
  245. }
  246. if a[i] > b[i] {
  247. return 1
  248. }
  249. }
  250. return 0
  251. }