ip_parser.go 12 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454
  1. package tool
  2. import (
  3. "database/sql"
  4. "regexp"
  5. "strconv"
  6. "strings"
  7. "github.com/3th1nk/cidr"
  8. "github.com/dlclark/regexp2"
  9. )
  10. // IP is TRUE
  11. func IP_or_user(ip string) bool {
  12. match, _ := regexp.MatchString("(\\.|:)", ip)
  13. if match {
  14. return true
  15. } else {
  16. return false
  17. }
  18. }
  19. func Get_user_document(db *sql.DB, user_name string) bool {
  20. data := ""
  21. QueryRow_DB(
  22. db,
  23. "select title from data where title = ?",
  24. []any{ &data },
  25. "user:" + user_name,
  26. )
  27. return data != ""
  28. }
  29. func Get_user_title(db *sql.DB, user_name string) string {
  30. user_title := ""
  31. QueryRow_DB(
  32. db,
  33. "select data from user_set where name = 'user_title' and id = ?",
  34. []any{ &user_title },
  35. user_name,
  36. )
  37. return user_title
  38. }
  39. func Get_level(db *sql.DB, ip string) []string {
  40. level := "0"
  41. QueryRow_DB(
  42. db,
  43. "select data from user_set where id = ? and name = 'level'",
  44. []any{ &level },
  45. ip,
  46. )
  47. exp := "0"
  48. QueryRow_DB(
  49. db,
  50. "select data from user_set where id = ? and name = 'experience'",
  51. []any{ &exp },
  52. ip,
  53. )
  54. level_int := Str_to_int(level)
  55. max_exp := strconv.Itoa(level_int * 50 + 500)
  56. return []string{level, exp, max_exp}
  57. }
  58. func IP_preprocess(db *sql.DB, ip string, my_ip string) []string {
  59. ip_split := strings.Split(ip, ":")
  60. if len(ip_split) != 1 && ip_split[0] == "tool" {
  61. return []string{ip, ""}
  62. }
  63. ip_view := ""
  64. QueryRow_DB(
  65. db,
  66. "select data from other where name = 'ip_view'",
  67. []any{ &ip_view },
  68. )
  69. user_name_view := ""
  70. QueryRow_DB(
  71. db,
  72. "select data from other where name = 'user_name_view'",
  73. []any{ &user_name_view },
  74. )
  75. if Check_acl(db, "", "", "view_hide_user_name", my_ip) {
  76. ip_view = ""
  77. user_name_view = ""
  78. }
  79. ip_change := ""
  80. if IP_or_user(ip) {
  81. if ip_view != "" && ip != my_ip {
  82. hash_ip := Sha224(ip)
  83. ip = hash_ip[:10]
  84. ip_change = "true"
  85. }
  86. } else {
  87. if user_name_view != "" {
  88. sub_user_name := ""
  89. QueryRow_DB(
  90. db,
  91. "select data from user_set where id = ? and name = 'sub_user_name'",
  92. []any{ &sub_user_name },
  93. ip,
  94. )
  95. if sub_user_name == "" {
  96. sub_user_name = Get_language(db, "member", false)
  97. }
  98. ip = sub_user_name
  99. ip_change = "true"
  100. } else {
  101. user_name := ""
  102. QueryRow_DB(
  103. db,
  104. "select data from user_set where name = 'user_name' and id = ?",
  105. []any{ &user_name },
  106. ip,
  107. )
  108. if user_name == "" {
  109. user_name = ip
  110. }
  111. ip = user_name
  112. }
  113. }
  114. return []string{ip, ip_change}
  115. }
  116. func IP_menu(db *sql.DB, ip string, my_ip string, option string) map[string][][]string {
  117. menu := map[string][][]string{}
  118. if ip == my_ip && option == "" {
  119. alarm_count := "0"
  120. QueryRow_DB(
  121. db,
  122. "select count(*) from user_notice where name = ? and readme = ''",
  123. []any{ &alarm_count },
  124. my_ip,
  125. )
  126. if IP_or_user(my_ip) {
  127. menu[Get_language(db, "login", false)] = [][]string{
  128. {"/login", Get_language(db, "login", false)},
  129. {"/register", Get_language(db, "register", false)},
  130. {"/change", Get_language(db, "user_setting", false)},
  131. {"/login/find", Get_language(db, "password_search", false)},
  132. {"/alarm" + Url_parser(my_ip), Get_language(db, "alarm", false) + " (" + alarm_count + ")"},
  133. }
  134. } else {
  135. menu[Get_language(db, "login", false)] = [][]string{
  136. {"/logout", Get_language(db, "logout", false)},
  137. {"/change", Get_language(db, "user_setting", false)},
  138. }
  139. menu[Get_language(db, "tool", false)] = [][]string{
  140. {"/watch_list", Get_language(db, "watchlist", false)},
  141. {"/star_doc", Get_language(db, "star_doc", false)},
  142. {"/challenge", Get_language(db, "challenge_and_level_manage", false)},
  143. {"/acl/user:" + Url_parser(my_ip), Get_language(db, "user_document_acl", false)},
  144. {"/alarm" + Url_parser(my_ip), Get_language(db, "alarm", false) + " (" + alarm_count + ")"},
  145. }
  146. }
  147. }
  148. auth_name := Check_acl(db, "", "", "ban_auth", my_ip)
  149. if auth_name {
  150. menu[Get_language(db, "admin", false)] = [][]string{
  151. {"/auth/ban/" + Url_parser(ip), Get_language(db, "ban", false)},
  152. {"/list/user/check_submit/" + Url_parser(ip), Get_language(db, "check", false)},
  153. }
  154. }
  155. menu[Get_language(db, "other", false)] = [][]string{
  156. {"/record/" + Url_parser(ip), Get_language(db, "edit_record", false)},
  157. {"/record/topic/" + Url_parser(ip), Get_language(db, "discussion_record", false)},
  158. {"/record/bbs/" + Url_parser(ip), Get_language(db, "bbs_record", false)},
  159. {"/record/bbs_comment/" + Url_parser(ip), Get_language(db, "bbs_comment_record", false)},
  160. {"/topic/user:" + Url_parser(ip), Get_language(db, "user_discussion", false)},
  161. {"/count/" + Url_parser(ip), Get_language(db, "count", false)},
  162. }
  163. return menu
  164. }
  165. func Get_user_ban_type(ban_type string) string {
  166. switch ban_type {
  167. case "O":
  168. return "1"
  169. case "E":
  170. return "2"
  171. case "A":
  172. return "3"
  173. case "D":
  174. return "4"
  175. case "L":
  176. return "5"
  177. default:
  178. return ""
  179. }
  180. }
  181. // Get_user_ban : login, register, edit_request, ""
  182. // Return : []string{"true", "a" + ban_type}
  183. func Get_user_ban(db *sql.DB, ip string, tool string) []string {
  184. rows := Query_DB(
  185. db,
  186. "select login, block from rb where band = 'regex' and ongoing = '1'",
  187. )
  188. defer rows.Close()
  189. for rows.Next() {
  190. var login string
  191. var block string
  192. err := rows.Scan(&login, &block)
  193. if err != nil {
  194. panic(err)
  195. }
  196. ban_type := Get_user_ban_type(login)
  197. r := regexp2.MustCompile(block, 0)
  198. if m, _ := r.FindStringMatch(ip); m != nil {
  199. switch tool {
  200. case "login":
  201. if ban_type != "1" && ban_type != "5" {
  202. return []string{"true", "a" + ban_type}
  203. }
  204. case "register":
  205. if ban_type != "5" {
  206. return []string{"true", "a" + ban_type}
  207. }
  208. case "edit_request":
  209. if ban_type != "2" {
  210. return []string{"true", "a" + ban_type}
  211. }
  212. default:
  213. return []string{"true", "a" + ban_type}
  214. }
  215. }
  216. }
  217. if IP_or_user(ip) {
  218. rows := Query_DB(
  219. db,
  220. "select login, block from rb where band = 'cidr' and ongoing = '1'",
  221. )
  222. defer rows.Close()
  223. for rows.Next() {
  224. var login string
  225. var block string
  226. err := rows.Scan(&login, &block)
  227. if err != nil {
  228. panic(err)
  229. }
  230. ban_type := Get_user_ban_type(login)
  231. c, err := cidr.Parse(block)
  232. if err != nil {
  233. continue
  234. } else if c.Contains(ip) {
  235. switch tool {
  236. case "login":
  237. if ban_type != "1" && ban_type != "5" {
  238. return []string{"true", "b" + ban_type}
  239. }
  240. case "register":
  241. if ban_type != "5" {
  242. return []string{"true", "b" + ban_type}
  243. }
  244. case "edit_request":
  245. if ban_type != "2" {
  246. return []string{"true", "b" + ban_type}
  247. }
  248. default:
  249. return []string{"true", "b" + ban_type}
  250. }
  251. }
  252. }
  253. }
  254. login := ""
  255. exist := QueryRow_DB(
  256. db,
  257. "select login from rb where block = ? and (band = '' or band = 'private') and ongoing = '1'",
  258. []any{ &login },
  259. ip,
  260. )
  261. if exist {
  262. ban_type := Get_user_ban_type(login)
  263. switch tool {
  264. case "login":
  265. if ban_type != "1" && ban_type != "5" {
  266. return []string{"true", ban_type}
  267. }
  268. case "register":
  269. if ban_type != "5" {
  270. return []string{"true", ban_type}
  271. }
  272. case "edit_request":
  273. if ban_type != "2" {
  274. return []string{"true", ban_type}
  275. }
  276. default:
  277. return []string{"true", ban_type}
  278. }
  279. }
  280. data := ""
  281. exist = QueryRow_DB(
  282. db,
  283. "select data from user_set where id = ? and name = 'acl'",
  284. []any{ &data },
  285. ip,
  286. )
  287. if exist {
  288. if data == "ban" {
  289. return []string{"true", "c"}
  290. }
  291. }
  292. return []string{"", ""}
  293. }
  294. func IP_parser(db *sql.DB, ip string, my_ip string) string {
  295. ip_pre_data := IP_preprocess(db, ip, my_ip)
  296. if ip_pre_data[0] == "" {
  297. return ""
  298. }
  299. if ip_pre_data[1] != "" {
  300. return ip_pre_data[0]
  301. } else {
  302. raw_ip := ip
  303. ip = HTML_escape(ip_pre_data[0])
  304. if !IP_or_user(raw_ip) {
  305. user_name_level := ""
  306. QueryRow_DB(
  307. db,
  308. "select data from other where name = 'user_name_level'",
  309. []any{ &user_name_level },
  310. )
  311. if user_name_level != "" {
  312. level_data := Get_level(db, raw_ip)
  313. ip += "<sup>" + level_data[0] + "</sup>"
  314. }
  315. ip = "<a href=\"/w/" + Url_parser("user:" + raw_ip) + "\">" + ip + "</a>"
  316. user_title := Get_user_title(db, raw_ip)
  317. if Check_acl(db, "", "", "user_name_bold", raw_ip) {
  318. ip = "<b>" + ip + "</b>"
  319. }
  320. ip = user_title + ip
  321. }
  322. ban := Get_user_ban(db, raw_ip, "")
  323. if ban[0] == "true" {
  324. ip = "<sup>" + ban[1] + "</sup><s>" + ip + "</s>"
  325. }
  326. ip += "<a href=\"javascript:void(0);\" name=\"" + Url_parser(raw_ip) + "\" onclick=\"opennamu_do_ip_click(this);\"><span class=\"opennamu_svg opennamu_svg_tool\">&nbsp;</span></a>"
  327. return ip
  328. }
  329. }
  330. func Do_ban_insert(db *sql.DB, user_name string, end_date string, reason string, login string, blocker string, do_type string, release bool) {
  331. now_time := Get_time()
  332. Exec_DB(
  333. db,
  334. "update rb set ongoing = '' where block = ? and band = ? and ongoing = '1'",
  335. user_name,
  336. do_type,
  337. )
  338. if release {
  339. Exec_DB(
  340. db,
  341. `insert into rb (block, end, today, blocker, why, band, ongoing, login) values (?, ?, ?, ?, ?, ?, '', '')`,
  342. user_name,
  343. "release",
  344. now_time,
  345. blocker,
  346. reason,
  347. do_type,
  348. )
  349. } else {
  350. if end_date == "0" {
  351. end_date = ""
  352. }
  353. Exec_DB(
  354. db,
  355. `insert into rb (block, end, today, blocker, why, band, ongoing, login) values (?, ?, ?, ?, ?, ?, '1', ?)`,
  356. user_name,
  357. end_date,
  358. now_time,
  359. blocker,
  360. reason,
  361. do_type,
  362. login,
  363. )
  364. }
  365. }
  366. func Get_main_skin_set(db *sql.DB, config Config, set_name string) string {
  367. set_data := ""
  368. if !IP_or_user(config.IP) {
  369. QueryRow_DB(
  370. db,
  371. "select data from user_set where name = ? and id = ?",
  372. []any{ &set_data },
  373. set_name,
  374. config.IP,
  375. )
  376. }
  377. if set_data == "default" || set_data == "" {
  378. QueryRow_DB(
  379. db,
  380. "select data from other where name = ?",
  381. []any{ &set_data },
  382. set_name,
  383. )
  384. }
  385. if set_data == "" {
  386. set_data = "default"
  387. }
  388. return set_data
  389. }