feat: Phase 1 WinAuth Go 移植完整实现

将原 C#/.NET WinAuth 移植为 Go + Gio GUI,覆盖 Phase 1 全部功能。

核心模块:
- internal/authenticator: TOTP (Google/Microsoft/Okta) + HOTP + BattleNet + Steam,含
  enroll/sync/code 生成、Steam 交易确认轮询
- internal/config: YAML 配置 + 老版 WinAuth XML 导入(DPAPI + Password + Blowfish/PBKDF2 解密链)
- internal/crypto: 现代加密 (WAGO1) + DPAPI 跨平台封装 + 老版 Blowfish ECB
- internal/win32: 单实例 Mutex 锁 + 全局热键管理器 (RegisterHotKey + PeekMessage 泵) +
  SendInput Unicode 注入 + 剪贴板文本/CF_DIB 图像读写 + AttachThreadInput 焦点切换
- internal/hotkey: "Ctrl+Alt+G" 风格快捷键字符串解析/格式化
- internal/qr: gozxing 二维码解码 + otpauth:// URI 解析
- internal/i18n: en/zh-CN/de 三语 TOML

UI 模块 (Gio):
- 主窗口:圆环倒计时进度条、复制按钮 + Toast 反馈、空列表占位、行分隔线
- 添加流程:vendor 菜单 + 各 vendor 独立对话框 + 二维码扫描入口(文件 / 剪贴板)
- 设置:密码加密、老版 XML 导入、每条目热键配置
- Steam:注册向导(含 captcha/email/SMS 多步)+ 交易确认窗

构建:Windows 主目标,非 Windows 平台所有 Win32 功能走 build-tag 桩实现。
This commit is contained in:
2026-06-12 03:10:37 +08:00
commit c671f2115e
165 changed files with 10102 additions and 0 deletions
+108
View File
@@ -0,0 +1,108 @@
// Package qr handles otpauth:// QR-code parsing. Image decoding is done
// with gozxing (pure Go, no CGO); URL parsing is hand-rolled per the
// otpauth:// spec used by Google Authenticator, Authy, and friends.
//
// https://github.com/google/google-authenticator/wiki/Key-Uri-Format
package qr
import (
"errors"
"fmt"
"image"
"net/url"
"strconv"
"strings"
"github.com/makiuchi-d/gozxing"
"github.com/makiuchi-d/gozxing/qrcode"
)
// ErrNoQR is returned when the image does not contain a decodable QR code.
var ErrNoQR = errors.New("qr: no QR code found in image")
// ErrNotOtpAuth is returned when the QR decodes successfully but does
// not contain an otpauth:// URI.
var ErrNotOtpAuth = errors.New("qr: decoded text is not an otpauth:// URI")
// DecodeImage runs the gozxing QR reader on img and returns the decoded
// text. Returns ErrNoQR if no QR pattern was found.
func DecodeImage(img image.Image) (string, error) {
bmp, err := gozxing.NewBinaryBitmapFromImage(img)
if err != nil {
return "", fmt.Errorf("qr: bitmap: %w", err)
}
reader := qrcode.NewQRCodeReader()
result, err := reader.Decode(bmp, nil)
if err != nil {
return "", ErrNoQR
}
return result.GetText(), nil
}
// OtpAuth carries the parsed pieces of an otpauth:// URI in the form
// the UI needs to create a config.Entry.
type OtpAuth struct {
// Type is "totp" or "hotp".
Type string
// Label is the human-readable display name (issuer + ":" + account).
Label string
// SecretBase32 is the Base32-encoded HMAC secret.
SecretBase32 string
// Issuer is the optional issuer string ("Google", "GitHub", ...).
Issuer string
// Algorithm is "SHA1", "SHA256", or "SHA512". Empty = unspecified.
Algorithm string
// Digits is the OTP length (typically 6). 0 = unspecified.
Digits int
// Period is the TOTP step in seconds (typically 30). 0 = unspecified.
Period int
// Counter is the HOTP initial counter.
Counter uint64
}
// ParseOtpAuth turns an otpauth:// URI into an OtpAuth struct. The
// secret is left base32-encoded; callers feed it straight into the
// authenticator's Enroll method.
func ParseOtpAuth(raw string) (*OtpAuth, error) {
const fn = "internal.qr.ParseOtpAuth"
raw = strings.TrimSpace(raw)
if !strings.HasPrefix(strings.ToLower(raw), "otpauth://") {
return nil, ErrNotOtpAuth
}
u, err := url.Parse(raw)
if err != nil {
return nil, fmt.Errorf("%s: parse URL: %w", fn, err)
}
typ := strings.ToLower(u.Host)
if typ != "totp" && typ != "hotp" {
return nil, fmt.Errorf("%s: unsupported otpauth type %q", fn, typ)
}
q := u.Query()
secret := strings.TrimSpace(q.Get("secret"))
if secret == "" {
return nil, fmt.Errorf("%s: missing secret", fn)
}
out := &OtpAuth{
Type: typ,
Label: strings.TrimPrefix(u.Path, "/"),
SecretBase32: secret,
Issuer: q.Get("issuer"),
Algorithm: strings.ToUpper(q.Get("algorithm")),
}
if v := q.Get("digits"); v != "" {
if n, err := strconv.Atoi(v); err == nil {
out.Digits = n
}
}
if v := q.Get("period"); v != "" {
if n, err := strconv.Atoi(v); err == nil {
out.Period = n
}
}
if v := q.Get("counter"); v != "" {
if n, err := strconv.ParseUint(v, 10, 64); err == nil {
out.Counter = n
}
}
return out, nil
}
+50
View File
@@ -0,0 +1,50 @@
package qr
import "testing"
func TestParseOtpAuth_TOTP(t *testing.T) {
uri := "otpauth://totp/Example:alice@example.com?" +
"secret=JBSWY3DPEHPK3PXP&issuer=Example&algorithm=SHA1&digits=6&period=30"
got, err := ParseOtpAuth(uri)
if err != nil {
t.Fatalf("ParseOtpAuth: %v", err)
}
if got.Type != "totp" {
t.Errorf("Type = %q, want totp", got.Type)
}
if got.SecretBase32 != "JBSWY3DPEHPK3PXP" {
t.Errorf("SecretBase32 = %q", got.SecretBase32)
}
if got.Issuer != "Example" {
t.Errorf("Issuer = %q", got.Issuer)
}
if got.Label != "Example:alice@example.com" {
t.Errorf("Label = %q", got.Label)
}
if got.Digits != 6 || got.Period != 30 {
t.Errorf("Digits/Period = %d/%d", got.Digits, got.Period)
}
}
func TestParseOtpAuth_HOTP(t *testing.T) {
uri := "otpauth://hotp/Account?secret=AAAAAA&counter=42"
got, err := ParseOtpAuth(uri)
if err != nil {
t.Fatalf("ParseOtpAuth: %v", err)
}
if got.Type != "hotp" || got.Counter != 42 {
t.Errorf("got %+v", got)
}
}
func TestParseOtpAuth_RejectsNonOtp(t *testing.T) {
if _, err := ParseOtpAuth("https://example.com/?secret=x"); err != ErrNotOtpAuth {
t.Errorf("want ErrNotOtpAuth, got %v", err)
}
}
func TestParseOtpAuth_MissingSecret(t *testing.T) {
if _, err := ParseOtpAuth("otpauth://totp/foo"); err == nil {
t.Errorf("expected error for missing secret")
}
}