server.go 8.1 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339
  1. package ftp
  2. import (
  3. "crypto/tls"
  4. "fmt"
  5. "log"
  6. "net"
  7. "os"
  8. "strings"
  9. "sync"
  10. "time"
  11. "ftp-server/config"
  12. "ftp-server/database"
  13. ftpserver "github.com/fclairamb/ftpserverlib"
  14. "github.com/spf13/afero"
  15. )
  16. // Server FTP服务器
  17. type Server struct {
  18. config *config.Config
  19. db *database.DB
  20. ftpServer *ftpserver.FtpServer
  21. onlineMu sync.RWMutex
  22. onlineUsers map[string]*database.OnlineUser
  23. }
  24. // NewServer 创建FTP服务器
  25. func NewServer(cfg *config.Config, db *database.DB) *Server {
  26. return &Server{
  27. config: cfg,
  28. db: db,
  29. onlineUsers: make(map[string]*database.OnlineUser),
  30. }
  31. }
  32. // Start 启动FTP服务器
  33. func (s *Server) Start() error {
  34. ftpCfg := s.config.Get().FTP
  35. // 确保FTP根目录存在
  36. if err := os.MkdirAll(ftpCfg.RootDir, 0755); err != nil {
  37. return fmt.Errorf("创建FTP根目录失败: %w", err)
  38. }
  39. server := ftpserver.NewFtpServer(s)
  40. s.ftpServer = server
  41. go func() {
  42. if err := server.ListenAndServe(); err != nil {
  43. log.Printf("FTP服务器错误: %v", err)
  44. }
  45. }()
  46. log.Printf("FTP服务器已启动: %s:%d", ftpCfg.Host, ftpCfg.Port)
  47. return nil
  48. }
  49. // Stop 停止FTP服务器
  50. func (s *Server) Stop() {
  51. if s.ftpServer != nil {
  52. s.ftpServer.Stop()
  53. log.Println("FTP服务器已停止")
  54. }
  55. }
  56. // GetOnlineUsers 获取在线用户列表
  57. func (s *Server) GetOnlineUsers() []database.OnlineUser {
  58. s.onlineMu.RLock()
  59. defer s.onlineMu.RUnlock()
  60. result := make([]database.OnlineUser, 0, len(s.onlineUsers))
  61. for _, u := range s.onlineUsers {
  62. result = append(result, *u)
  63. }
  64. return result
  65. }
  66. // --- 实现 ftpserverlib.MainDriver 接口 ---
  67. // GetSettings 返回FTP服务器设置
  68. func (s *Server) GetSettings() (*ftpserver.Settings, error) {
  69. ftpCfg := s.config.Get().FTP
  70. return &ftpserver.Settings{
  71. ListenAddr: fmt.Sprintf("%s:%d", ftpCfg.Host, ftpCfg.Port),
  72. PassiveTransferPortRange: ftpserver.PortRange{
  73. Start: ftpCfg.PassivePortMin,
  74. End: ftpCfg.PassivePortMax,
  75. },
  76. ConnectionTimeout: int(time.Duration(ftpCfg.IdleTimeout) * time.Second),
  77. }, nil
  78. }
  79. // ClientConnected 客户端连接(只检查全局规则)
  80. func (s *Server) ClientConnected(cc ftpserver.ClientContext) (string, error) {
  81. clientIP, _, err := net.SplitHostPort(cc.RemoteAddr().String())
  82. if err != nil {
  83. clientIP = cc.RemoteAddr().String()
  84. }
  85. if err := s.checkIPAccess(clientIP, ""); err != nil {
  86. log.Printf("IP %s 被拒绝连接(全局规则): %v", clientIP, err)
  87. return "", fmt.Errorf("连接被拒绝: %s", err)
  88. }
  89. return "220 Welcome to FTP Server\r\n", nil
  90. }
  91. // ClientDisconnected 客户端断开
  92. func (s *Server) ClientDisconnected(cc ftpserver.ClientContext) {
  93. s.onlineMu.Lock()
  94. defer s.onlineMu.Unlock()
  95. for id, u := range s.onlineUsers {
  96. if u.IP == cc.RemoteAddr().String() {
  97. delete(s.onlineUsers, id)
  98. break
  99. }
  100. }
  101. }
  102. // AuthUser 认证用户
  103. func (s *Server) AuthUser(cc ftpserver.ClientContext, username, password string) (ftpserver.ClientDriver, error) {
  104. ftpCfg := s.config.Get().FTP
  105. // 匿名登录
  106. if username == "anonymous" {
  107. if !ftpCfg.EnableAnonymous {
  108. return nil, fmt.Errorf("匿名访问未启用")
  109. }
  110. if err := os.MkdirAll(ftpCfg.RootDir, 0755); err != nil {
  111. return nil, fmt.Errorf("创建根目录失败")
  112. }
  113. osFs := afero.NewOsFs()
  114. boundedFs := afero.NewBasePathFs(osFs, ftpCfg.RootDir)
  115. return newLoggingFs(boundedFs, s.db, "anonymous"), nil
  116. }
  117. // 数据库用户认证
  118. user, err := s.db.GetUser(username)
  119. if err != nil {
  120. return nil, fmt.Errorf("认证失败")
  121. }
  122. if user == nil || !user.Enabled {
  123. return nil, fmt.Errorf("用户不存在或已禁用")
  124. }
  125. if user.Password != password {
  126. s.db.AddLog(&database.FTPLog{
  127. Username: username,
  128. IP: cc.RemoteAddr().String(),
  129. Action: "login_failed",
  130. Status: "failed",
  131. })
  132. return nil, fmt.Errorf("密码错误")
  133. }
  134. // 检查用户级别IP规则
  135. clientIP, _, _ := net.SplitHostPort(cc.RemoteAddr().String())
  136. if clientIP == "" {
  137. clientIP = cc.RemoteAddr().String()
  138. }
  139. if err := s.checkIPAccess(clientIP, username); err != nil {
  140. log.Printf("用户 %s IP %s 被拒绝: %v", username, clientIP, err)
  141. s.db.AddLog(&database.FTPLog{
  142. Username: username,
  143. IP: cc.RemoteAddr().String(),
  144. Action: "login_blocked",
  145. Status: "blocked",
  146. })
  147. return nil, fmt.Errorf("登录被拒绝: %s", err)
  148. }
  149. // 记录登录日志
  150. s.db.AddLog(&database.FTPLog{
  151. Username: username,
  152. IP: cc.RemoteAddr().String(),
  153. Action: "login",
  154. Status: "success",
  155. })
  156. // 记录在线用户
  157. s.onlineMu.Lock()
  158. s.onlineUsers[username+"_"+cc.RemoteAddr().String()] = &database.OnlineUser{
  159. Username: username,
  160. IP: cc.RemoteAddr().String(),
  161. LoginTime: time.Now(),
  162. LastActivity: time.Now(),
  163. CurrentDir: user.HomeDir,
  164. }
  165. s.onlineMu.Unlock()
  166. // 确保用户目录存在(自动创建)
  167. if err := os.MkdirAll(user.HomeDir, 0755); err != nil {
  168. return nil, fmt.Errorf("创建用户目录失败: %v", err)
  169. }
  170. // 返回 afero.Fs 作为 ClientDriver(带日志包装)
  171. osFs := afero.NewOsFs()
  172. boundedFs := afero.NewBasePathFs(osFs, user.HomeDir)
  173. loggedFs := newLoggingFs(boundedFs, s.db, username)
  174. // 根据权限设置只读
  175. if user.Permissions == "read" {
  176. return afero.NewReadOnlyFs(loggedFs), nil
  177. }
  178. return loggedFs, nil
  179. }
  180. // GetTLSConfig 获取TLS配置
  181. func (s *Server) GetTLSConfig() (*tls.Config, error) {
  182. return nil, fmt.Errorf("TLS未配置")
  183. }
  184. // checkIPAccess 检查IP是否允许访问,username为空时只检查全局规则
  185. func (s *Server) checkIPAccess(clientIP, username string) error {
  186. if s.db == nil {
  187. return nil
  188. }
  189. rules, err := s.db.GetEnabledIPRules(username)
  190. if err != nil {
  191. return nil // 查询失败时允许连接
  192. }
  193. // 分离全局规则和用户规则
  194. var globalWhitelist, globalBlacklist []database.IPAccessRule
  195. var userWhitelist, userBlacklist []database.IPAccessRule
  196. for _, rule := range rules {
  197. if rule.Username == "" {
  198. if rule.Type == "whitelist" {
  199. globalWhitelist = append(globalWhitelist, rule)
  200. } else {
  201. globalBlacklist = append(globalBlacklist, rule)
  202. }
  203. } else {
  204. if rule.Type == "whitelist" {
  205. userWhitelist = append(userWhitelist, rule)
  206. } else {
  207. userBlacklist = append(userBlacklist, rule)
  208. }
  209. }
  210. }
  211. // 1. 先检查全局黑名单
  212. for _, rule := range globalBlacklist {
  213. if matchIP(clientIP, rule.IP) {
  214. return fmt.Errorf("IP已被全局黑名单拦截")
  215. }
  216. }
  217. // 2. 检查全局白名单(如果有全局白名单,必须在其中)
  218. if len(globalWhitelist) > 0 {
  219. matched := false
  220. for _, rule := range globalWhitelist {
  221. if matchIP(clientIP, rule.IP) {
  222. matched = true
  223. break
  224. }
  225. }
  226. if !matched {
  227. return fmt.Errorf("IP不在全局白名单中")
  228. }
  229. }
  230. // 3. 检查用户黑名单
  231. for _, rule := range userBlacklist {
  232. if matchIP(clientIP, rule.IP) {
  233. return fmt.Errorf("IP已被用户黑名单拦截")
  234. }
  235. }
  236. // 4. 检查用户白名单(如果有用户白名单,必须在其中)
  237. if len(userWhitelist) > 0 {
  238. matched := false
  239. for _, rule := range userWhitelist {
  240. if matchIP(clientIP, rule.IP) {
  241. matched = true
  242. break
  243. }
  244. }
  245. if !matched {
  246. return fmt.Errorf("IP不在用户白名单中")
  247. }
  248. }
  249. return nil
  250. }
  251. // matchIP 检查IP是否匹配规则
  252. func matchIP(clientIP, rule string) bool {
  253. // 单个IP
  254. if !strings.Contains(rule, "/") && !strings.Contains(rule, "-") {
  255. return clientIP == rule
  256. }
  257. // CIDR 表示法 (192.168.1.0/24)
  258. if strings.Contains(rule, "/") {
  259. _, ipNet, err := net.ParseCIDR(rule)
  260. if err != nil {
  261. return clientIP == rule
  262. }
  263. ip := net.ParseIP(clientIP)
  264. if ip == nil {
  265. return false
  266. }
  267. return ipNet.Contains(ip)
  268. }
  269. // IP范围 (192.168.1.1-192.168.1.100)
  270. if strings.Contains(rule, "-") {
  271. parts := strings.SplitN(rule, "-", 2)
  272. startIP := net.ParseIP(strings.TrimSpace(parts[0]))
  273. endIP := net.ParseIP(strings.TrimSpace(parts[1]))
  274. ip := net.ParseIP(clientIP)
  275. if startIP == nil || endIP == nil || ip == nil {
  276. return false
  277. }
  278. return bytesCompare(ip, startIP) >= 0 && bytesCompare(ip, endIP) <= 0
  279. }
  280. return false
  281. }
  282. // bytesCompare 比较两个IP的字节
  283. func bytesCompare(a, b net.IP) int {
  284. a = a.To16()
  285. b = b.To16()
  286. for i := range a {
  287. if a[i] < b[i] {
  288. return -1
  289. }
  290. if a[i] > b[i] {
  291. return 1
  292. }
  293. }
  294. return 0
  295. }