feat: Phase 1 WinAuth Go 移植完整实现
将原 C#/.NET WinAuth 移植为 Go + Gio GUI,覆盖 Phase 1 全部功能。 核心模块: - internal/authenticator: TOTP (Google/Microsoft/Okta) + HOTP + BattleNet + Steam,含 enroll/sync/code 生成、Steam 交易确认轮询 - internal/config: YAML 配置 + 老版 WinAuth XML 导入(DPAPI + Password + Blowfish/PBKDF2 解密链) - internal/crypto: 现代加密 (WAGO1) + DPAPI 跨平台封装 + 老版 Blowfish ECB - internal/win32: 单实例 Mutex 锁 + 全局热键管理器 (RegisterHotKey + PeekMessage 泵) + SendInput Unicode 注入 + 剪贴板文本/CF_DIB 图像读写 + AttachThreadInput 焦点切换 - internal/hotkey: "Ctrl+Alt+G" 风格快捷键字符串解析/格式化 - internal/qr: gozxing 二维码解码 + otpauth:// URI 解析 - internal/i18n: en/zh-CN/de 三语 TOML UI 模块 (Gio): - 主窗口:圆环倒计时进度条、复制按钮 + Toast 反馈、空列表占位、行分隔线 - 添加流程:vendor 菜单 + 各 vendor 独立对话框 + 二维码扫描入口(文件 / 剪贴板) - 设置:密码加密、老版 XML 导入、每条目热键配置 - Steam:注册向导(含 captcha/email/SMS 多步)+ 交易确认窗 构建:Windows 主目标,非 Windows 平台所有 Win32 功能走 build-tag 桩实现。
This commit is contained in:
@@ -0,0 +1,49 @@
|
||||
//go:build windows
|
||||
|
||||
package crypto
|
||||
|
||||
import (
|
||||
"fmt"
|
||||
"unsafe"
|
||||
|
||||
"golang.org/x/sys/windows"
|
||||
)
|
||||
|
||||
// Unprotect calls Windows CryptUnprotectData on the given blob. entropy
|
||||
// is optional secondary entropy that must match what was passed to the
|
||||
// matching CryptProtectData call; pass nil if none was used. scope
|
||||
// selects between the current-user and local-machine master keys.
|
||||
//
|
||||
// The original WinAuth wrote both User and Machine DPAPI blobs without
|
||||
// extra entropy, so passing entropy=nil is what the legacy migration
|
||||
// needs in practice.
|
||||
func Unprotect(blob, entropy []byte, scope DPAPIScope) ([]byte, error) {
|
||||
var in windows.DataBlob
|
||||
in.Size = uint32(len(blob))
|
||||
if len(blob) > 0 {
|
||||
in.Data = &blob[0]
|
||||
}
|
||||
|
||||
var entIn *windows.DataBlob
|
||||
if len(entropy) > 0 {
|
||||
entIn = &windows.DataBlob{Size: uint32(len(entropy)), Data: &entropy[0]}
|
||||
}
|
||||
|
||||
var flags uint32
|
||||
if scope == DPAPIScopeLocalMachine {
|
||||
flags |= 0x4 // CRYPTPROTECT_LOCAL_MACHINE
|
||||
}
|
||||
|
||||
var out windows.DataBlob
|
||||
if err := windows.CryptUnprotectData(&in, nil, entIn, 0, nil, flags, &out); err != nil {
|
||||
return nil, fmt.Errorf("dpapi: unprotect: %w", err)
|
||||
}
|
||||
defer windows.LocalFree(windows.Handle(unsafe.Pointer(out.Data)))
|
||||
|
||||
if out.Size == 0 {
|
||||
return []byte{}, nil
|
||||
}
|
||||
result := make([]byte, out.Size)
|
||||
copy(result, unsafe.Slice(out.Data, out.Size))
|
||||
return result, nil
|
||||
}
|
||||
Reference in New Issue
Block a user