feat: Phase 1 WinAuth Go 移植完整实现
将原 C#/.NET WinAuth 移植为 Go + Gio GUI,覆盖 Phase 1 全部功能。 核心模块: - internal/authenticator: TOTP (Google/Microsoft/Okta) + HOTP + BattleNet + Steam,含 enroll/sync/code 生成、Steam 交易确认轮询 - internal/config: YAML 配置 + 老版 WinAuth XML 导入(DPAPI + Password + Blowfish/PBKDF2 解密链) - internal/crypto: 现代加密 (WAGO1) + DPAPI 跨平台封装 + 老版 Blowfish ECB - internal/win32: 单实例 Mutex 锁 + 全局热键管理器 (RegisterHotKey + PeekMessage 泵) + SendInput Unicode 注入 + 剪贴板文本/CF_DIB 图像读写 + AttachThreadInput 焦点切换 - internal/hotkey: "Ctrl+Alt+G" 风格快捷键字符串解析/格式化 - internal/qr: gozxing 二维码解码 + otpauth:// URI 解析 - internal/i18n: en/zh-CN/de 三语 TOML UI 模块 (Gio): - 主窗口:圆环倒计时进度条、复制按钮 + Toast 反馈、空列表占位、行分隔线 - 添加流程:vendor 菜单 + 各 vendor 独立对话框 + 二维码扫描入口(文件 / 剪贴板) - 设置:密码加密、老版 XML 导入、每条目热键配置 - Steam:注册向导(含 captcha/email/SMS 多步)+ 交易确认窗 构建:Windows 主目标,非 Windows 平台所有 Win32 功能走 build-tag 桩实现。
This commit is contained in:
@@ -0,0 +1,94 @@
|
||||
package config
|
||||
|
||||
import (
|
||||
"encoding/json"
|
||||
"errors"
|
||||
"fmt"
|
||||
"os"
|
||||
|
||||
"gopkg.in/yaml.v3"
|
||||
|
||||
"git.wxccs.org/iceking2nd/winauth-go/internal/crypto"
|
||||
"git.wxccs.org/iceking2nd/winauth-go/internal/global"
|
||||
)
|
||||
|
||||
// Sentinel errors returned by LoadYAML for the encrypted-config password
|
||||
// path. Callers use errors.Is to distinguish them from generic I/O / parse
|
||||
// failures.
|
||||
var (
|
||||
ErrPasswordRequired = errors.New("config: passphrase required")
|
||||
ErrPasswordWrong = errors.New("config: wrong passphrase")
|
||||
)
|
||||
|
||||
// SaveYAML writes the receiver as YAML to path. If passphrase is non-empty
|
||||
// and cfg.Encrypted is true, the entries slice is serialized to JSON,
|
||||
// encrypted, and stored as EncryptedBlob — entries are NOT written in
|
||||
// plaintext in that case.
|
||||
func SaveYAML(cfg *Config, path string, passphrase []byte) error {
|
||||
const fn = "internal.config.SaveYAML"
|
||||
logger := global.Log.WithField("func", fn).WithField("path", path)
|
||||
|
||||
out := *cfg
|
||||
if cfg.Encrypted && len(passphrase) > 0 {
|
||||
raw, err := json.Marshal(cfg.Entries)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
blob, err := crypto.EncryptModern(raw, passphrase)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
out.EncryptedBlob = blob
|
||||
out.Entries = nil
|
||||
}
|
||||
|
||||
data, err := yaml.Marshal(&out)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
if err := EnsureDir(path); err != nil {
|
||||
return err
|
||||
}
|
||||
tmp := path + ".tmp"
|
||||
if err := os.WriteFile(tmp, data, 0o600); err != nil {
|
||||
return err
|
||||
}
|
||||
if err := os.Rename(tmp, path); err != nil {
|
||||
_ = os.Remove(tmp)
|
||||
return err
|
||||
}
|
||||
logger.Debug("config saved")
|
||||
return nil
|
||||
}
|
||||
|
||||
// LoadYAML reads the YAML config at path. If the file is encrypted,
|
||||
// passphrase is required and the EncryptedBlob is decrypted into Entries.
|
||||
func LoadYAML(path string, passphrase []byte) (*Config, error) {
|
||||
const fn = "internal.config.LoadYAML"
|
||||
logger := global.Log.WithField("func", fn).WithField("path", path)
|
||||
|
||||
data, err := os.ReadFile(path)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
var cfg Config
|
||||
if err := yaml.Unmarshal(data, &cfg); err != nil {
|
||||
return nil, fmt.Errorf("config: parse YAML: %w", err)
|
||||
}
|
||||
|
||||
if cfg.Encrypted && cfg.EncryptedBlob != "" {
|
||||
if len(passphrase) == 0 {
|
||||
return &cfg, ErrPasswordRequired
|
||||
}
|
||||
raw, err := crypto.DecryptModern(cfg.EncryptedBlob, passphrase)
|
||||
if err != nil {
|
||||
return &cfg, ErrPasswordWrong
|
||||
}
|
||||
if err := json.Unmarshal(raw, &cfg.Entries); err != nil {
|
||||
return nil, fmt.Errorf("config: decode entries: %w", err)
|
||||
}
|
||||
}
|
||||
|
||||
logger.WithField("entries", len(cfg.Entries)).Debug("config loaded")
|
||||
return &cfg, nil
|
||||
}
|
||||
Reference in New Issue
Block a user