mirror of
https://github.com/labring/sealos.git
synced 2026-09-24 15:46:19 +08:00
fix(desktop): Fix Tencent blocking real-name callback issue. (#5617)
This commit is contained in:
@@ -107,8 +107,17 @@ export default async function handler(req: NextApiRequest, res: NextApiResponse)
|
||||
}
|
||||
});
|
||||
|
||||
if (enterprise && (enterprise?.additionalInfo as unknown as AdditionalInfo)?.isRestrictedUser) {
|
||||
return jsonRes(res, {
|
||||
code: 400,
|
||||
message: "Restricted User Can't Enterprise Real Name Authentication"
|
||||
});
|
||||
}
|
||||
|
||||
let duplicateRealNameUser = false;
|
||||
|
||||
if (enterprise) {
|
||||
realNameAuthReward = 0;
|
||||
duplicateRealNameUser = true;
|
||||
}
|
||||
|
||||
await globalPrisma.$transaction(async (globalPrisma) => {
|
||||
@@ -147,6 +156,10 @@ export default async function handler(req: NextApiRequest, res: NextApiResponse)
|
||||
}
|
||||
});
|
||||
|
||||
if (duplicateRealNameUser) {
|
||||
return;
|
||||
}
|
||||
|
||||
const userAccount = await globalPrisma.account.findUniqueOrThrow({
|
||||
where: { userUid: userUid }
|
||||
});
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
import { verifyAccessToken } from '@/services/backend/auth';
|
||||
import { verifyAuthenticationToken } from '@/services/backend/auth';
|
||||
import { jsonRes } from '@/services/backend/response';
|
||||
import { enableRealNameAuth } from '@/services/enable';
|
||||
import * as tcsdk from 'tencentcloud-sdk-nodejs';
|
||||
@@ -39,6 +39,7 @@ type AdditionalInfo =
|
||||
};
|
||||
};
|
||||
userMaterials?: string[];
|
||||
isRestrictedUser?: boolean;
|
||||
}
|
||||
| any;
|
||||
|
||||
@@ -53,14 +54,14 @@ export default async function handler(req: NextApiRequest, res: NextApiResponse)
|
||||
const bizToken = req.query?.BizToken as string;
|
||||
const extraQuery = req.query?.Extra as string;
|
||||
|
||||
const regionToken = extraQuery?.split('regionToken=')[1];
|
||||
if (!regionToken) {
|
||||
const globalToken = extraQuery?.split('globalToken=')[1];
|
||||
if (!globalToken) {
|
||||
return jsonRes(res, { code: 400, message: 'Token is required' });
|
||||
}
|
||||
|
||||
req.headers['authorization'] = regionToken;
|
||||
req.headers['authorization'] = globalToken;
|
||||
|
||||
const payload = await verifyAccessToken(req.headers);
|
||||
const payload = await verifyAuthenticationToken(req.headers);
|
||||
if (!payload) return jsonRes(res, { code: 401, message: 'Token is invaild' });
|
||||
|
||||
if (!realNameOSS) {
|
||||
@@ -203,8 +204,49 @@ export default async function handler(req: NextApiRequest, res: NextApiResponse)
|
||||
}
|
||||
});
|
||||
|
||||
if (realnameInfo && (realnameInfo?.additionalInfo as AdditionalInfo)?.isRestrictedUser) {
|
||||
await globalPrisma.userRealNameInfo.update({
|
||||
where: { userUid: userUid },
|
||||
data: {
|
||||
isVerified: false,
|
||||
idVerifyFailedTimes: { increment: 1 },
|
||||
additionalInfo: additionalInfo
|
||||
}
|
||||
});
|
||||
|
||||
res.setHeader('Content-Type', 'text/html');
|
||||
return res.send(`
|
||||
<!DOCTYPE html>
|
||||
<html lang="en">
|
||||
<head>
|
||||
<meta charset="UTF-8">
|
||||
<meta name="viewport" content="width=device-width, initial-scale=1.0">
|
||||
<title>Real Name Authentication</title>
|
||||
<style>
|
||||
body, html {
|
||||
height: 100%;
|
||||
margin: 0;
|
||||
display: flex;
|
||||
justify-content: center;
|
||||
align-items: center;
|
||||
}
|
||||
h1 {
|
||||
text-align: center;
|
||||
color: #ff0000; /* Red color for error message */
|
||||
}
|
||||
</style>
|
||||
</head>
|
||||
<body>
|
||||
<h1>Restricted User Can't Real Name Authentication</h1>
|
||||
</body>
|
||||
</html>
|
||||
`);
|
||||
}
|
||||
|
||||
let duplicateRealNameUser = false;
|
||||
|
||||
if (realnameInfo) {
|
||||
realNameAuthReward = 0;
|
||||
duplicateRealNameUser = true;
|
||||
}
|
||||
|
||||
await globalPrisma.$transaction(async (globalPrisma) => {
|
||||
@@ -242,6 +284,10 @@ export default async function handler(req: NextApiRequest, res: NextApiResponse)
|
||||
}
|
||||
});
|
||||
|
||||
if (duplicateRealNameUser) {
|
||||
return;
|
||||
}
|
||||
|
||||
const userAccount = await globalPrisma.account.findUniqueOrThrow({
|
||||
where: { userUid: userUid }
|
||||
});
|
||||
|
||||
@@ -2,7 +2,7 @@ import { jsonRes } from '@/services/backend/response';
|
||||
import { enableRealNameAuth } from '@/services/enable';
|
||||
import type { NextApiRequest, NextApiResponse } from 'next';
|
||||
import * as tcsdk from 'tencentcloud-sdk-nodejs';
|
||||
import { verifyAccessToken } from '@/services/backend/auth';
|
||||
import { generateAuthenticationToken, verifyAccessToken } from '@/services/backend/auth';
|
||||
import { globalPrisma } from '@/services/backend/db/init';
|
||||
|
||||
type TencentCloudFaceAuthConfig = {
|
||||
@@ -119,11 +119,18 @@ export default async function handler(req: NextApiRequest, res: NextApiResponse)
|
||||
currentTime - urlCreatedAt > urlExpirationTime;
|
||||
|
||||
if (shouldGenerateNewUrl) {
|
||||
const redirectUrl = `https://${global.AppConfig?.cloud.domain}/api/account/faceIdRealNameAuthCallback`;
|
||||
const regionToken = req.headers['authorization'] as string;
|
||||
const redirectUrl =
|
||||
global.AppConfig?.common.realNameCallbackUrl ||
|
||||
`https://${global.AppConfig?.cloud.domain}/api/account/faceIdRealNameAuthCallback`;
|
||||
|
||||
const globalToken = generateAuthenticationToken({
|
||||
userUid: payload.userUid,
|
||||
userId: payload.userId
|
||||
});
|
||||
|
||||
urlResult = await generateRealNameQRcodeUri(
|
||||
redirectUrl,
|
||||
regionToken,
|
||||
globalToken,
|
||||
config as TencentCloudFaceAuthConfig
|
||||
);
|
||||
|
||||
@@ -171,7 +178,7 @@ export default async function handler(req: NextApiRequest, res: NextApiResponse)
|
||||
|
||||
async function generateRealNameQRcodeUri(
|
||||
redirectUrl: string,
|
||||
regionToken: string,
|
||||
globalToken: string,
|
||||
config: TencentCloudFaceAuthConfig
|
||||
): Promise<QRCodeUrlResult> {
|
||||
const FaceClient = tcsdk.faceid.v20180301.Client;
|
||||
@@ -194,7 +201,7 @@ async function generateRealNameQRcodeUri(
|
||||
const params = {
|
||||
RuleId: config.ruleId,
|
||||
RedirectUrl: redirectUrl,
|
||||
Extra: `regionToken=${regionToken}`
|
||||
Extra: `globalToken=${globalToken}`
|
||||
};
|
||||
|
||||
const data = await client.DetectAuth(params);
|
||||
|
||||
@@ -2,7 +2,7 @@ import { jsonRes } from '@/services/backend/response';
|
||||
import { enableRealNameAuth } from '@/services/enable';
|
||||
import type { NextApiRequest, NextApiResponse } from 'next';
|
||||
import * as tcsdk from 'tencentcloud-sdk-nodejs';
|
||||
import { verifyAccessToken } from '@/services/backend/auth';
|
||||
import { generateAuthenticationToken, verifyAccessToken } from '@/services/backend/auth';
|
||||
import { globalPrisma } from '@/services/backend/db/init';
|
||||
|
||||
type TencentCloudFaceAuthConfig = {
|
||||
@@ -117,11 +117,18 @@ export default async function handler(req: NextApiRequest, res: NextApiResponse)
|
||||
|
||||
const currentTime = new Date().getTime();
|
||||
|
||||
const redirectUrl = `https://${global.AppConfig?.cloud.domain}/api/account/faceIdRealNameAuthCallback`;
|
||||
const regionToken = req.headers['authorization'] as string;
|
||||
const redirectUrl =
|
||||
global.AppConfig?.common.realNameCallbackUrl ||
|
||||
`https://${global.AppConfig?.cloud.domain}/api/account/faceIdRealNameAuthCallback`;
|
||||
|
||||
const globalToken = generateAuthenticationToken({
|
||||
userUid: payload.userUid,
|
||||
userId: payload.userId
|
||||
});
|
||||
|
||||
const urlResult: QRCodeUrlResult = await generateRealNameQRcodeUri(
|
||||
redirectUrl,
|
||||
regionToken,
|
||||
globalToken,
|
||||
config as TencentCloudFaceAuthConfig
|
||||
);
|
||||
|
||||
@@ -161,7 +168,7 @@ export default async function handler(req: NextApiRequest, res: NextApiResponse)
|
||||
|
||||
async function generateRealNameQRcodeUri(
|
||||
redirectUrl: string,
|
||||
regionToken: string,
|
||||
globalToken: string,
|
||||
config: TencentCloudFaceAuthConfig
|
||||
): Promise<QRCodeUrlResult> {
|
||||
const FaceClient = tcsdk.faceid.v20180301.Client;
|
||||
@@ -184,7 +191,7 @@ async function generateRealNameQRcodeUri(
|
||||
const params = {
|
||||
RuleId: config.ruleId,
|
||||
RedirectUrl: redirectUrl,
|
||||
Extra: `regionToken=${regionToken}`
|
||||
Extra: `globalToken=${globalToken}`
|
||||
};
|
||||
|
||||
const data = await client.DetectAuth(params);
|
||||
|
||||
@@ -26,4 +26,5 @@ export interface AdditionalInfo {
|
||||
contactInfo: string;
|
||||
transAmt: string;
|
||||
authTimes: number;
|
||||
isRestrictedUser?: boolean;
|
||||
}
|
||||
|
||||
@@ -13,6 +13,7 @@ export type CommonConfigType = {
|
||||
enterpriseRealNameAuthEnabled: boolean;
|
||||
realNameAuthEnabled: boolean;
|
||||
realNameReward: number;
|
||||
realNameCallbackUrl?: string;
|
||||
guideEnabled: boolean;
|
||||
apiEnabled: boolean;
|
||||
rechargeEnabled: boolean;
|
||||
@@ -26,7 +27,12 @@ export type CommonConfigType = {
|
||||
export type CommonClientConfigType = DeepRequired<
|
||||
Omit<
|
||||
CommonConfigType,
|
||||
'apiEnabled' | 'objectstorageUrl' | 'applaunchpadUrl' | 'dbproviderUrl' | 'templateUrl'
|
||||
| 'apiEnabled'
|
||||
| 'objectstorageUrl'
|
||||
| 'applaunchpadUrl'
|
||||
| 'dbproviderUrl'
|
||||
| 'templateUrl'
|
||||
| 'realNameCallbackUrl'
|
||||
>
|
||||
>;
|
||||
export type DatabaseConfigType = {
|
||||
|
||||
Reference in New Issue
Block a user