You can not select more than 25 topics
Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
100 lines
3.5 KiB
100 lines
3.5 KiB
package user
|
|
|
|
import (
|
|
"os"
|
|
"sort"
|
|
|
|
"yunyan/comm"
|
|
"yunyan/lego/sys/log"
|
|
"yunyan/lego/sys/postgres"
|
|
"yunyan/pb"
|
|
"yunyan/sys/ipinfo"
|
|
)
|
|
|
|
// @Summary 获取第三方服务列表
|
|
// @Description 下发后台「第三方服务配置」:本应用作用域(应用覆盖全局)+按用户 IP 区域合并字段覆盖,凭据解密为明文
|
|
// @Tags User
|
|
// @Accept json
|
|
// @Produce json
|
|
// @Security BearerAuth
|
|
// @Param user body pb.UserGetThirdSvcsReq true "获取第三方服务列表"
|
|
// @Success 200 {object} comm.HttpResult{data=pb.UserGetThirdSvcsResp} "成功返回(整体响应体经 AES-CBC 加密,响应头 X-Encrypted:1)"
|
|
// @Router /api/home/user_getthirdsvcs_v2 [post]
|
|
//
|
|
// 注册在 apiV2Comp(Version=v2)上,路由 = user_getthirdsvcs_v2;已在 EncryptMsgs 中声明,
|
|
// 网关对整个响应体做 AES-CBC 加密——响应含第三方服务明文凭据,绝不能明文出网关。
|
|
func (this *apiV2Comp) GetThirdSvcs(session comm.IUserSession, req *pb.UserGetThirdSvcsReq) (resp *pb.UserGetThirdSvcsResp, errdata *pb.ErrorData) {
|
|
var (
|
|
app = comm.AppName()
|
|
encKey = os.Getenv("FIELD_ENCRYPT_KEY")
|
|
region = pb.Region_RegionUSA
|
|
)
|
|
if ipdata, _ := ipinfo.GetIPInfo(session.GetIP()); ipdata != nil {
|
|
region = ToRegion(ipdata)
|
|
}
|
|
|
|
// 本应用作用域链上的服务行(应用行 + 全局行),可按 ids 过滤。
|
|
svcs := make([]*comm.ThirdSvcConfig, 0)
|
|
query := "(app_name=? OR app_name='')"
|
|
args := []interface{}{app}
|
|
if len(req.Ids) > 0 {
|
|
query += " AND id IN ?"
|
|
args = append(args, req.Ids)
|
|
}
|
|
if err := postgres.Find(comm.TableSvcConfig, &svcs, query, args...); err != nil && err != postgres.ErrNoDocuments {
|
|
errdata = &pb.ErrorData{Code: pb.ErrorCode_DBError, Message: err.Error()}
|
|
return
|
|
}
|
|
|
|
// 同 id 应用行覆盖全局行;仅启用的(与 echomeet 编排解析同语义:应用行停用则回退全局行)。
|
|
picked := map[string]*comm.ThirdSvcConfig{}
|
|
ids := make([]string, 0, len(svcs))
|
|
for _, s := range svcs {
|
|
if !s.Enable {
|
|
continue
|
|
}
|
|
if exist, ok := picked[s.Id]; !ok || (exist.AppName == "" && s.AppName == app && app != "") {
|
|
if _, ok := picked[s.Id]; !ok {
|
|
ids = append(ids, s.Id)
|
|
}
|
|
picked[s.Id] = s
|
|
}
|
|
}
|
|
|
|
// 区域字段覆盖:按服务行自身的作用域 + 用户区域匹配。
|
|
ovrs := make([]*comm.SvcRegionOverride, 0)
|
|
if len(ids) > 0 && region != 0 {
|
|
if err := postgres.Find(comm.TableSvcRegionOverride, &ovrs,
|
|
"(app_name=? OR app_name='') AND svc_id IN ? AND region=?", app, ids, int32(region)); err != nil && err != postgres.ErrNoDocuments {
|
|
errdata = &pb.ErrorData{Code: pb.ErrorCode_DBError, Message: err.Error()}
|
|
return
|
|
}
|
|
}
|
|
ovrOf := func(svc *comm.ThirdSvcConfig) *comm.SvcRegionOverride {
|
|
for _, o := range ovrs {
|
|
if o.SvcId == svc.Id && o.AppName == svc.AppName {
|
|
return o
|
|
}
|
|
}
|
|
return nil
|
|
}
|
|
|
|
resp = &pb.UserGetThirdSvcsResp{Svcs: make([]*pb.ThirdSvcItem, 0, len(picked))}
|
|
for _, svc := range picked {
|
|
fields, err := comm.ResolveSvcPlainFields(svc, ovrOf(svc), encKey)
|
|
if err != nil {
|
|
// fail-closed:字段解不开的服务不下发(密文当明文用会在客户端炸成不可理解的错误)。
|
|
log.Warnf("GetThirdSvcs: 服务 %s 字段解析失败已跳过: %v", svc.Id, err)
|
|
continue
|
|
}
|
|
resp.Svcs = append(resp.Svcs, &pb.ThirdSvcItem{
|
|
Id: svc.Id,
|
|
Name: svc.Name,
|
|
Provider: svc.Provider,
|
|
Categories: svc.Categories,
|
|
Fields: fields,
|
|
})
|
|
}
|
|
sort.Slice(resp.Svcs, func(i, j int) bool { return resp.Svcs[i].Id < resp.Svcs[j].Id })
|
|
return
|
|
}
|
|
|