2 Commits
Author SHA1 Message Date
mei 360169ee64 fix: 修复删除资源时未验证所有者的问题
Quality check / Web UI (push) Successful in 9m11s
2026-08-30 17:47:53 +08:00
mei 59cf99ae22 feat(drivers): add alidns delete record
Quality check / Web UI (push) Successful in 9m14s
2026-08-30 16:03:32 +08:00
21 changed files with 1480 additions and 48 deletions
+12
View File
@@ -218,6 +218,18 @@ func HandleDeleteAccount(c *gin.Context) {
return
}
// 检查账号是否归属请求用户
ownerUID, err := getAccountOwnerUID(accountID)
if err != nil {
response.ServerError(c, "获取账号所属用户失败")
return
}
if ownerUID != userInfo.ID {
response.Forbidden(c, "无权限操作该账号")
return
}
// 删除相关规则
rules, err := getRulesByAccountID(accountID, userInfo.ID)
if err != nil {
+14
View File
@@ -59,3 +59,17 @@ func maskAccounts(accounts []model.Account) []model.Account {
}
return masked
}
// getAccountOwnerUID 获取账号所属用户的 UID
func getAccountOwnerUID(accountID uint) (uint, error) {
gormDB, err := db.GetGormDB()
if err != nil {
return 0, err
}
var account model.Account
if err := gormDB.Select("uid").Where("id = ?", accountID).First(&account).Error; err != nil {
return 0, err
}
return account.UID, nil
}
+3
View File
@@ -40,6 +40,9 @@ func NotFound(c *gin.Context, msg string) { Fail(c, http.StatusNotFound, msg) }
// ServerError 服务端错误
func ServerError(c *gin.Context, msg string) { Fail(c, http.StatusInternalServerError, msg) }
// Forbidden 无权限
func Forbidden(c *gin.Context, msg string) { Fail(c, http.StatusForbidden, msg) }
// FromError 按错误类型选择合适的状态码:
// 参数校验错误返回 400,其余返回 500
func FromError(c *gin.Context, err error, fallback string) {
+10
View File
@@ -162,6 +162,16 @@ func HandleDeleteRule(c *gin.Context) {
return
}
ownerUID, err := getRuleOwnerUID(ruleID)
if err != nil {
response.ServerError(c, "获取规则所属用户失败")
return
}
if ownerUID != userInfo.ID {
response.Forbidden(c, "无权限操作该规则")
return
}
if err := DeleteRuleByID(ruleID, userInfo.ID); err != nil {
response.ServerError(c, "删除规则失败")
return
+15
View File
@@ -103,3 +103,18 @@ func maskRules(rules []model.Rule) []model.Rule {
}
return masked
}
// getRuleOwnerUID 获取规则所属用户的 UID
func getRuleOwnerUID(ruleID uint) (uint, error) {
gormDB, err := db.GetGormDB()
if err != nil {
return 0, err
}
var rule model.Rule
if err := gormDB.Select("uid").Where("id = ?", ruleID).First(&rule).Error; err != nil {
return 0, err
}
return rule.UID, nil
}
+14
View File
@@ -70,3 +70,17 @@ func signTimer(timer *model.Timer) error {
timer.Triggered = false
return nil
}
// getTimerOwnerUID 获取 Timer 的所属用户 ID
func getTimerOwnerUID(timerID uint) (uint, error) {
gormDB, err := db.GetGormDB()
if err != nil {
return 0, err
}
var timer model.Timer
if err := gormDB.Select("uid").Where("id = ?", timerID).First(&timer).Error; err != nil {
return 0, err
}
return timer.UID, nil
}
+63
View File
@@ -0,0 +1,63 @@
package alidns
import (
"encoding/json"
"fmt"
"github.com/alibabacloud-go/alidns-20150109/v5/client"
"github.com/ssdomei232/goodBaby/internal/meta"
)
type AliDNSAccountConfigValidator struct{}
func (v *AliDNSAccountConfigValidator) GetType() string { return AccountType }
func (v *AliDNSAccountConfigValidator) Validate(config string) error {
cfg, err := parseAccount(config)
if err != nil {
return err
}
if cfg.AK == "" || cfg.SK == "" {
return fmt.Errorf("阿里云账号配置不完整")
}
return nil
}
func parseAccount(config string) (*AliDNSAccount, error) {
var cfg AliDNSAccount
if err := json.Unmarshal([]byte(config), &cfg); err != nil {
return nil, fmt.Errorf("解析阿里云账号配置失败: %v", err)
}
return &cfg, nil
}
func (v *AliDNSAccountConfigValidator) Test(config string) error {
cfg, err := parseAccount(config)
if err != nil {
return err
}
aliDNSClient, err := getAliDNSClient(cfg.AK, cfg.SK)
if err != nil {
return err
}
_, err = aliDNSClient.DescribeDnsProductInstances(&client.DescribeDnsProductInstancesRequest{})
if err != nil {
return err
}
return nil
}
func (v *AliDNSAccountConfigValidator) Meta() meta.AccountMeta {
return meta.AccountMeta{
Type: AccountType,
Label: "阿里云",
Description: "阿里云国内站",
Fields: []meta.Field{
{Key: "ak", Label: "Access Key", Type: meta.FieldPassword, Required: true, Secret: true, Placeholder: "xxxxxxxxx"},
{Key: "sk", Label: "Secret Key", Type: meta.FieldPassword, Required: true, Secret: true, Placeholder: "xxxxxxxxx"},
},
}
}
+11 -5
View File
@@ -2,13 +2,16 @@ package alidns
import (
"context"
"fmt"
"github.com/alibabacloud-go/alidns-20150109/v5/client"
"github.com/ssdomei232/goodBaby/internal/retry"
"github.com/ssdomei232/goodBaby/model"
)
// deleteAliDNSRecord deletes a DNS record from Alibaba Cloud DNS based on the provided rule.
func deleteAliDNSRecord(ctx context.Context, rule *model.Rule) error {
aliDNSClient, err := getAliDNSClient(rule)
aliDNSClient, err := getAliDNSClientFromRule(rule)
if err != nil {
return err
}
@@ -17,11 +20,14 @@ func deleteAliDNSRecord(ctx context.Context, rule *model.Rule) error {
return err
}
_, err = aliDNSClient.DeleteDomainRecord(&client.DeleteDomainRecordRequest{
RecordId: &deleteRecordConfig.RecordID,
})
if err != nil {
if err := retry.Do(ctx, func() error {
_, err := aliDNSClient.DeleteDomainRecord(&client.DeleteDomainRecordRequest{
RecordId: &deleteRecordConfig.RecordID,
})
return err
}); err != nil {
return fmt.Errorf("删除阿里云DNS记录失败: %w", err)
}
return nil
}
+5
View File
@@ -1,5 +1,10 @@
package alidns
const (
AccountType = "alidns"
RuleTypeDeleteRecord = "alidns-delete-record"
)
type AliDNSAccount struct {
AK string `json:"ak"`
SK string `json:"sk"`
+40
View File
@@ -0,0 +1,40 @@
package alidns
import (
"encoding/json"
"fmt"
"github.com/ssdomei232/goodBaby/internal/meta"
)
// 阿里云删除记录规则验证器
type AliDNSDeleteRecordRuleValidator struct{}
func (v *AliDNSDeleteRecordRuleValidator) GetType() string {
return RuleTypeDeleteRecord
}
func (v *AliDNSDeleteRecordRuleValidator) Validate(configJSON string) error {
var config DeleteRecordConfig
if err := json.Unmarshal([]byte(configJSON), &config); err != nil {
return fmt.Errorf("解析阿里云删除记录规则配置失败: %v", err)
}
if config.RecordID == "" {
return fmt.Errorf("阿里云删除记录规则配置中 record_id 不能为空")
}
return nil
}
func (v *AliDNSDeleteRecordRuleValidator) Meta() meta.RuleMeta {
return meta.RuleMeta{
Type: RuleTypeDeleteRecord,
Label: "删除阿里云DNS解析记录",
Description: "触发时删除阿里云DNS解析记录",
AccountType: AccountType,
Fields: []meta.Field{
{Key: "record_id", Label: "记录ID", Type: meta.FieldString, Required: true},
},
}
}
+21
View File
@@ -0,0 +1,21 @@
package alidns
import (
"context"
"log"
"github.com/ssdomei232/goodBaby/model"
)
// DeleteAliDNSRecordExecutor 删除阿里云DNS记录执行器
type DeleteAliDNSRecordExecutor struct{}
func (e *DeleteAliDNSRecordExecutor) GetType() string {
return RuleTypeDeleteRecord
}
func (e *DeleteAliDNSRecordExecutor) Execute(ctx context.Context, rule *model.Rule) error {
log.Printf("执行删除阿里云DNS记录规则: %s (ID: %d)", rule.Name, rule.ID)
return deleteAliDNSRecord(ctx, rule)
}
+9 -3
View File
@@ -11,7 +11,8 @@ import (
"github.com/ssdomei232/goodBaby/model"
)
func getAliDNSClient(rule *model.Rule) (client *alidns.Client, err error) {
// getAliDNSClient initializes and returns an Alibaba Cloud DNS client based on the provided rule's account configuration. It retrieves the account configuration from the database, sets up the necessary credentials, and creates a new client instance for interacting with Alibaba Cloud DNS services.
func getAliDNSClientFromRule(rule *model.Rule) (client *alidns.Client, err error) {
var accountConfig AliDNSAccount
// get config
@@ -19,11 +20,15 @@ func getAliDNSClient(rule *model.Rule) (client *alidns.Client, err error) {
return nil, err
}
return getAliDNSClient(accountConfig.AK, accountConfig.SK)
}
func getAliDNSClient(ak string, sk string) (client *alidns.Client, err error) {
// init aliyun account config
credentialsConfig := new(credentials.Config).
SetType("access_key").
SetAccessKeyId(accountConfig.AK).
SetAccessKeySecret(accountConfig.SK)
SetAccessKeyId(ak).
SetAccessKeySecret(sk)
akCredential, err := credentials.NewCredential(credentialsConfig)
if err != nil {
return nil, err
@@ -38,6 +43,7 @@ func getAliDNSClient(rule *model.Rule) (client *alidns.Client, err error) {
return client, nil
}
// getDeleteRecordConfig retrieves the configuration for deleting DNS records from the provided rule. It unmarshals the rule's configuration JSON into a DeleteRecordConfig structure and returns it.
func getDeleteRecordConfig(rule *model.Rule) (*DeleteRecordConfig, error) {
var deleteRecordConfig DeleteRecordConfig
+1 -3
View File
@@ -12,9 +12,7 @@ import (
// RainyunAccountConfigValidator Rainyun账号配置验证器
type RainyunAccountConfigValidator struct{}
func (v *RainyunAccountConfigValidator) GetType() string {
return AccountType
}
func (v *RainyunAccountConfigValidator) GetType() string { return AccountType }
func (v *RainyunAccountConfigValidator) Validate(config string) error {
// 解析配置
+3 -2
View File
@@ -3,8 +3,9 @@ package rainyun
const (
// AccountType Rainyun 账号类型标识
AccountType = "rainyun"
// RuleType 发送 Rainyun 消息的规则类型标识
RuleType = "rainyun-workorder"
// RuleTypeWorkOrder 发送 Rainyun 工单消息的规则类型标识
RuleTypeWorkOrder = "rainyun-workorder"
RuleTypeRunAway = "rainyun-runaway"
)
type RainyunWorkOrderRule struct {
+4 -4
View File
@@ -11,7 +11,7 @@ import (
type RainyunWorkorderRuleValidator struct{}
func (v *RainyunWorkorderRuleValidator) GetType() string {
return RuleType
return RuleTypeWorkOrder
}
func (v *RainyunWorkorderRuleValidator) Validate(configJSON string) error {
@@ -33,7 +33,7 @@ func (v *RainyunWorkorderRuleValidator) Validate(configJSON string) error {
func (v *RainyunWorkorderRuleValidator) Meta() meta.RuleMeta {
return meta.RuleMeta{
Type: RuleType,
Type: RuleTypeWorkOrder,
Label: "发送雨云工单",
Description: "触发时发送雨云工单",
AccountType: AccountType,
@@ -47,7 +47,7 @@ func (v *RainyunWorkorderRuleValidator) Meta() meta.RuleMeta {
type RainyunRunAwayRuleValidator struct{}
func (v *RainyunRunAwayRuleValidator) GetType() string {
return "rainyun-runaway"
return RuleTypeRunAway
}
func (v *RainyunRunAwayRuleValidator) Validate(configJSON string) error {
@@ -65,7 +65,7 @@ func (v *RainyunRunAwayRuleValidator) Validate(configJSON string) error {
func (v *RainyunRunAwayRuleValidator) Meta() meta.RuleMeta {
return meta.RuleMeta{
Type: "rainyun-runaway",
Type: RuleTypeRunAway,
Label: "重置雨云账号中所有云服务器(一键跑路)",
Description: "触发时会重装雨云账号下所有云服务器来实现跑路",
AccountType: AccountType,
+2 -2
View File
@@ -11,7 +11,7 @@ import (
type RainyunWorkorderExecutor struct{}
func (e *RainyunWorkorderExecutor) GetType() string {
return RuleType
return RuleTypeWorkOrder
}
func (e *RainyunWorkorderExecutor) Execute(ctx context.Context, rule *model.Rule) error {
@@ -24,7 +24,7 @@ func (e *RainyunWorkorderExecutor) Execute(ctx context.Context, rule *model.Rule
type RainyunRunAwayExecutor struct{}
func (e *RainyunRunAwayExecutor) GetType() string {
return "rainyun-runaway"
return RuleTypeRunAway
}
func (e *RainyunRunAwayExecutor) Execute(ctx context.Context, rule *model.Rule) error {
-29
View File
@@ -6,13 +6,6 @@ import (
"sort"
"sync"
"github.com/ssdomei232/goodBaby/drivers/bilibili"
"github.com/ssdomei232/goodBaby/drivers/dingtalk"
"github.com/ssdomei232/goodBaby/drivers/email"
"github.com/ssdomei232/goodBaby/drivers/fwalert"
"github.com/ssdomei232/goodBaby/drivers/github"
"github.com/ssdomei232/goodBaby/drivers/onebot"
"github.com/ssdomei232/goodBaby/drivers/rainyun"
"github.com/ssdomei232/goodBaby/model"
)
@@ -66,28 +59,6 @@ var (
globalExecutorRegistry *ExecutorRegistry
)
// InitExecutorRegistry 初始化执行器注册表并注册所有执行器
func InitExecutorRegistry() *ExecutorRegistry {
registryOnce.Do(func() {
registry := NewExecutorRegistry()
// 注册所有规则执行器
registry.Register(&bilibili.BilibiliDynamicExecutor{})
registry.Register(&bilibili.BilibiliPrivateMessageExecutor{})
registry.Register(&email.EmailExecutor{})
registry.Register(&github.GithubMakeRepoPublicExecutor{})
registry.Register(&onebot.OneBotExecutor{})
registry.Register(&dingtalk.DingTalkExecutor{})
registry.Register(&fwalert.FwalertExecutor{})
registry.Register(&rainyun.RainyunWorkorderExecutor{})
registry.Register(&rainyun.RainyunRunAwayExecutor{})
// 未来添加新规则类型时,在这里注册即可
globalExecutorRegistry = registry
})
return globalExecutorRegistry
}
// GetGlobalExecutorRegistry 获取全局执行器注册表
func GetGlobalExecutorRegistry() *ExecutorRegistry {
if globalExecutorRegistry == nil {
+35
View File
@@ -0,0 +1,35 @@
package runner
import (
"github.com/ssdomei232/goodBaby/drivers/alidns"
"github.com/ssdomei232/goodBaby/drivers/bilibili"
"github.com/ssdomei232/goodBaby/drivers/dingtalk"
"github.com/ssdomei232/goodBaby/drivers/email"
"github.com/ssdomei232/goodBaby/drivers/fwalert"
"github.com/ssdomei232/goodBaby/drivers/github"
"github.com/ssdomei232/goodBaby/drivers/onebot"
"github.com/ssdomei232/goodBaby/drivers/rainyun"
)
// InitExecutorRegistry 初始化执行器注册表并注册所有执行器
func InitExecutorRegistry() *ExecutorRegistry {
registryOnce.Do(func() {
registry := NewExecutorRegistry()
// 注册所有规则执行器
registry.Register(&bilibili.BilibiliDynamicExecutor{})
registry.Register(&bilibili.BilibiliPrivateMessageExecutor{})
registry.Register(&email.EmailExecutor{})
registry.Register(&github.GithubMakeRepoPublicExecutor{})
registry.Register(&onebot.OneBotExecutor{})
registry.Register(&dingtalk.DingTalkExecutor{})
registry.Register(&fwalert.FwalertExecutor{})
registry.Register(&rainyun.RainyunWorkorderExecutor{})
registry.Register(&rainyun.RainyunRunAwayExecutor{})
registry.Register(&alidns.DeleteAliDNSRecordExecutor{})
// 未来添加新规则类型时,在这里注册即可
globalExecutorRegistry = registry
})
return globalExecutorRegistry
}
+2
View File
@@ -3,6 +3,7 @@ package accountConfigChecker
import (
"sync"
"github.com/ssdomei232/goodBaby/drivers/alidns"
"github.com/ssdomei232/goodBaby/drivers/bilibili"
"github.com/ssdomei232/goodBaby/drivers/email"
"github.com/ssdomei232/goodBaby/drivers/github"
@@ -26,6 +27,7 @@ func InitValidatorRegistry() *ValidatorRegistry {
r.Register(&github.GitHubAccountConfigValidator{})
r.Register(&onebot.OneBotAccountConfigValidator{})
r.Register(&rainyun.RainyunAccountConfigValidator{})
r.Register(&alidns.AliDNSAccountConfigValidator{})
registry = r
})
+2
View File
@@ -3,6 +3,7 @@ package ruleConfigChecker
import (
"sync"
"github.com/ssdomei232/goodBaby/drivers/alidns"
"github.com/ssdomei232/goodBaby/drivers/bilibili"
"github.com/ssdomei232/goodBaby/drivers/dingtalk"
"github.com/ssdomei232/goodBaby/drivers/email"
@@ -32,6 +33,7 @@ func InitValidatorRegistry() *ValidatorRegistry {
r.Register(&fwalert.FwalertRuleValidator{})
r.Register(&rainyun.RainyunWorkorderRuleValidator{})
r.Register(&rainyun.RainyunRunAwayRuleValidator{})
r.Register(&alidns.AliDNSDeleteRecordRuleValidator{})
registry = r
})
+1214
View File
File diff suppressed because it is too large Load Diff