feat: Phase 1 WinAuth Go 移植完整实现
将原 C#/.NET WinAuth 移植为 Go + Gio GUI,覆盖 Phase 1 全部功能。 核心模块: - internal/authenticator: TOTP (Google/Microsoft/Okta) + HOTP + BattleNet + Steam,含 enroll/sync/code 生成、Steam 交易确认轮询 - internal/config: YAML 配置 + 老版 WinAuth XML 导入(DPAPI + Password + Blowfish/PBKDF2 解密链) - internal/crypto: 现代加密 (WAGO1) + DPAPI 跨平台封装 + 老版 Blowfish ECB - internal/win32: 单实例 Mutex 锁 + 全局热键管理器 (RegisterHotKey + PeekMessage 泵) + SendInput Unicode 注入 + 剪贴板文本/CF_DIB 图像读写 + AttachThreadInput 焦点切换 - internal/hotkey: "Ctrl+Alt+G" 风格快捷键字符串解析/格式化 - internal/qr: gozxing 二维码解码 + otpauth:// URI 解析 - internal/i18n: en/zh-CN/de 三语 TOML UI 模块 (Gio): - 主窗口:圆环倒计时进度条、复制按钮 + Toast 反馈、空列表占位、行分隔线 - 添加流程:vendor 菜单 + 各 vendor 独立对话框 + 二维码扫描入口(文件 / 剪贴板) - 设置:密码加密、老版 XML 导入、每条目热键配置 - Steam:注册向导(含 captcha/email/SMS 多步)+ 交易确认窗 构建:Windows 主目标,非 Windows 平台所有 Win32 功能走 build-tag 桩实现。
This commit is contained in:
@@ -0,0 +1,127 @@
|
||||
package httpc
|
||||
|
||||
import (
|
||||
"bytes"
|
||||
"io"
|
||||
"net/http"
|
||||
"net/http/httputil"
|
||||
"strings"
|
||||
"time"
|
||||
|
||||
"github.com/sirupsen/logrus"
|
||||
|
||||
"git.wxccs.org/iceking2nd/winauth-go/internal/global"
|
||||
)
|
||||
|
||||
// Sensitive header names that must be redacted from Trace logs. Comparison
|
||||
// is case-insensitive. The body of responses is logged as-is at Trace level
|
||||
// — callers should not put bearer tokens in URL query strings if they want
|
||||
// to keep them out of logs.
|
||||
var sensitiveHeaders = map[string]struct{}{
|
||||
"authorization": {},
|
||||
"cookie": {},
|
||||
"set-cookie": {},
|
||||
"proxy-authorization": {},
|
||||
"x-api-key": {},
|
||||
"x-auth-token": {},
|
||||
}
|
||||
|
||||
// New returns an *http.Client that logs full request/response payloads at
|
||||
// Trace level. At lower levels it logs only a single Debug line with method,
|
||||
// URL, status code and duration.
|
||||
//
|
||||
// Sensitive headers (Authorization, Cookie, Set-Cookie, ...) are redacted
|
||||
// to "<redacted>" before being written to the log, per the project rule
|
||||
// "never write secrets or tokens to logs".
|
||||
func New() *http.Client {
|
||||
return &http.Client{
|
||||
Transport: &traceTransport{base: http.DefaultTransport},
|
||||
Timeout: 30 * time.Second,
|
||||
}
|
||||
}
|
||||
|
||||
type traceTransport struct {
|
||||
base http.RoundTripper
|
||||
}
|
||||
|
||||
func (t *traceTransport) RoundTrip(req *http.Request) (*http.Response, error) {
|
||||
const fn = "internal.httpc.traceTransport.RoundTrip"
|
||||
|
||||
logger := global.Log.WithField("func", fn).WithField("method", req.Method).WithField("url", req.URL.String())
|
||||
|
||||
trace := global.Log.GetLevel() >= logrus.TraceLevel
|
||||
|
||||
if trace {
|
||||
dump, err := dumpRequest(req)
|
||||
if err != nil {
|
||||
logger.WithError(err).Trace("failed to dump request")
|
||||
} else {
|
||||
logger.WithField("payload", "request").Trace("\n" + dump)
|
||||
}
|
||||
}
|
||||
|
||||
start := time.Now()
|
||||
resp, err := t.base.RoundTrip(req)
|
||||
dur := time.Since(start)
|
||||
if err != nil {
|
||||
logger.WithError(err).WithField("duration_ms", dur.Milliseconds()).Debug("http error")
|
||||
return nil, err
|
||||
}
|
||||
|
||||
logger.WithField("status", resp.StatusCode).WithField("duration_ms", dur.Milliseconds()).Debug("http ok")
|
||||
|
||||
if trace {
|
||||
dump, derr := dumpResponse(resp)
|
||||
if derr != nil {
|
||||
logger.WithError(derr).Trace("failed to dump response")
|
||||
} else {
|
||||
logger.WithField("payload", "response").Trace("\n" + dump)
|
||||
}
|
||||
}
|
||||
|
||||
return resp, nil
|
||||
}
|
||||
|
||||
// dumpRequest produces a textual dump of req with sensitive headers redacted.
|
||||
func dumpRequest(req *http.Request) (string, error) {
|
||||
clone := req.Clone(req.Context())
|
||||
clone.Header = redactHeaders(req.Header)
|
||||
|
||||
raw, err := httputil.DumpRequestOut(clone, true)
|
||||
if err != nil {
|
||||
return "", err
|
||||
}
|
||||
return string(raw), nil
|
||||
}
|
||||
|
||||
func dumpResponse(resp *http.Response) (string, error) {
|
||||
if resp.Body != nil {
|
||||
body, err := io.ReadAll(resp.Body)
|
||||
if err != nil {
|
||||
return "", err
|
||||
}
|
||||
_ = resp.Body.Close()
|
||||
resp.Body = io.NopCloser(bytes.NewReader(body))
|
||||
}
|
||||
origHeader := resp.Header
|
||||
resp.Header = redactHeaders(origHeader)
|
||||
defer func() { resp.Header = origHeader }()
|
||||
|
||||
raw, err := httputil.DumpResponse(resp, true)
|
||||
if err != nil {
|
||||
return "", err
|
||||
}
|
||||
return string(raw), nil
|
||||
}
|
||||
|
||||
func redactHeaders(h http.Header) http.Header {
|
||||
out := make(http.Header, len(h))
|
||||
for k, v := range h {
|
||||
if _, ok := sensitiveHeaders[strings.ToLower(k)]; ok {
|
||||
out[k] = []string{"<redacted>"}
|
||||
continue
|
||||
}
|
||||
out[k] = append([]string(nil), v...)
|
||||
}
|
||||
return out
|
||||
}
|
||||
Reference in New Issue
Block a user