ip_parser.go 9.4 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423
  1. package tool
  2. import (
  3. "database/sql"
  4. "log"
  5. "regexp"
  6. "strconv"
  7. "strings"
  8. "github.com/3th1nk/cidr"
  9. "github.com/dlclark/regexp2"
  10. )
  11. func IP_or_user(ip string) bool {
  12. match, _ := regexp.MatchString("(\\.|:)", ip)
  13. if match {
  14. return true
  15. } else {
  16. return false
  17. }
  18. }
  19. func Get_level(db *sql.DB, ip string) []string {
  20. var level string
  21. var exp string
  22. var max_exp string
  23. stmt, err := db.Prepare(DB_change("select data from user_set where id = ? and name = 'level'"))
  24. if err != nil {
  25. log.Fatal(err)
  26. }
  27. defer stmt.Close()
  28. err = stmt.QueryRow(ip).Scan(&level)
  29. if err != nil {
  30. if err == sql.ErrNoRows {
  31. level = "0"
  32. } else {
  33. log.Fatal(err)
  34. }
  35. }
  36. stmt, err = db.Prepare(DB_change("select data from user_set where id = ? and name = 'experience'"))
  37. if err != nil {
  38. log.Fatal(err)
  39. }
  40. defer stmt.Close()
  41. err = stmt.QueryRow(ip).Scan(&exp)
  42. if err != nil {
  43. if err == sql.ErrNoRows {
  44. exp = "0"
  45. } else {
  46. log.Fatal(err)
  47. }
  48. }
  49. level_int, _ := strconv.Atoi(level)
  50. max_exp = strconv.Itoa(level_int*50 + 500)
  51. return []string{level, exp, max_exp}
  52. }
  53. func IP_preprocess(db *sql.DB, ip string, my_ip string) []string {
  54. var ip_view string
  55. var user_name_view string
  56. ip_split := strings.Split(ip, ":")
  57. if len(ip_split) != 1 && ip_split[0] == "tool" {
  58. return []string{ip, ""}
  59. }
  60. err := db.QueryRow(DB_change("select data from other where name = 'ip_view'")).Scan(&ip_view)
  61. if err != nil {
  62. if err == sql.ErrNoRows {
  63. ip_view = ""
  64. } else {
  65. log.Fatal(err)
  66. }
  67. }
  68. err = db.QueryRow(DB_change("select data from other where name = 'user_name_view'")).Scan(&user_name_view)
  69. if err != nil {
  70. if err == sql.ErrNoRows {
  71. user_name_view = ""
  72. } else {
  73. log.Fatal(err)
  74. }
  75. }
  76. if Check_acl(db, "", "", "view_hide_user_name", my_ip) {
  77. ip_view = ""
  78. user_name_view = ""
  79. }
  80. ip_change := ""
  81. if IP_or_user(ip) {
  82. if ip_view != "" && ip != my_ip {
  83. hash_ip := Sha224(ip)
  84. ip = hash_ip[:10]
  85. ip_change = "true"
  86. }
  87. } else {
  88. if user_name_view != "" {
  89. var sub_user_name string
  90. stmt, err := db.Prepare(DB_change("select data from user_set where id = ? and name = 'sub_user_name'"))
  91. if err != nil {
  92. log.Fatal(err)
  93. }
  94. defer stmt.Close()
  95. err = stmt.QueryRow(ip).Scan(&sub_user_name)
  96. if err != nil {
  97. if err == sql.ErrNoRows {
  98. sub_user_name = Get_language(db, "member", false)
  99. } else {
  100. log.Fatal(err)
  101. }
  102. }
  103. if sub_user_name == "" {
  104. sub_user_name = Get_language(db, "member", false)
  105. }
  106. ip = sub_user_name
  107. ip_change = "true"
  108. } else {
  109. var user_name string
  110. stmt, err := db.Prepare(DB_change("select data from user_set where name = 'user_name' and id = ?"))
  111. if err != nil {
  112. log.Fatal(err)
  113. }
  114. defer stmt.Close()
  115. err = stmt.QueryRow(ip).Scan(&user_name)
  116. if err != nil {
  117. if err == sql.ErrNoRows {
  118. user_name = ip
  119. } else {
  120. log.Fatal(err)
  121. }
  122. }
  123. if user_name == "" {
  124. user_name = ip
  125. }
  126. ip = user_name
  127. }
  128. }
  129. return []string{ip, ip_change}
  130. }
  131. func IP_menu(db *sql.DB, ip string, my_ip string, option string) map[string][][]string {
  132. menu := map[string][][]string{}
  133. if ip == my_ip && option == "" {
  134. stmt, err := db.Prepare(DB_change("select count(*) from user_notice where name = ? and readme = ''"))
  135. if err != nil {
  136. log.Fatal(err)
  137. }
  138. defer stmt.Close()
  139. var alarm_count string
  140. err = stmt.QueryRow(my_ip).Scan(&alarm_count)
  141. if err != nil {
  142. if err == sql.ErrNoRows {
  143. alarm_count = "0"
  144. } else {
  145. log.Fatal(err)
  146. }
  147. }
  148. if IP_or_user(my_ip) {
  149. menu[Get_language(db, "login", false)] = [][]string{
  150. {"/login", Get_language(db, "login", false)},
  151. {"/register", Get_language(db, "register", false)},
  152. {"/change", Get_language(db, "user_setting", false)},
  153. {"/login/find", Get_language(db, "password_search", false)},
  154. {"/alarm" + Url_parser(my_ip), Get_language(db, "alarm", false) + " (" + alarm_count + ")"},
  155. }
  156. } else {
  157. menu[Get_language(db, "login", false)] = [][]string{
  158. {"/logout", Get_language(db, "logout", false)},
  159. {"/change", Get_language(db, "user_setting", false)},
  160. }
  161. menu[Get_language(db, "tool", false)] = [][]string{
  162. {"/watch_list", Get_language(db, "watchlist", false)},
  163. {"/star_doc", Get_language(db, "star_doc", false)},
  164. {"/challenge", Get_language(db, "challenge_and_level_manage", false)},
  165. {"/acl/user:" + Url_parser(my_ip), Get_language(db, "user_document_acl", false)},
  166. {"/alarm" + Url_parser(my_ip), Get_language(db, "alarm", false) + " (" + alarm_count + ")"},
  167. }
  168. }
  169. }
  170. auth_name := Check_acl(db, "", "", "ban_auth", my_ip)
  171. if auth_name {
  172. menu[Get_language(db, "admin", false)] = [][]string{
  173. {"/auth/ban/" + Url_parser(ip), Get_language(db, "ban", false)},
  174. {"/list/user/check_submit/" + Url_parser(ip), Get_language(db, "check", false)},
  175. }
  176. }
  177. menu[Get_language(db, "other", false)] = [][]string{
  178. {"/record/" + Url_parser(ip), Get_language(db, "edit_record", false)},
  179. {"/record/topic/" + Url_parser(ip), Get_language(db, "discussion_record", false)},
  180. {"/record/bbs/" + Url_parser(ip), Get_language(db, "bbs_record", false)},
  181. {"/record/bbs_comment/" + Url_parser(ip), Get_language(db, "bbs_comment_record", false)},
  182. {"/topic/user:" + Url_parser(ip), Get_language(db, "user_discussion", false)},
  183. {"/count/" + Url_parser(ip), Get_language(db, "count", false)},
  184. }
  185. return menu
  186. }
  187. func Get_user_ban_type(ban_type string) string {
  188. if ban_type == "O" {
  189. return "1"
  190. } else if ban_type == "E" {
  191. return "2"
  192. } else if ban_type == "A" {
  193. return "3"
  194. } else if ban_type == "D" {
  195. return "4"
  196. } else {
  197. return ""
  198. }
  199. }
  200. func Get_user_ban(db *sql.DB, ip string, tool string) []string {
  201. rows, err := db.Query(DB_change("select login, block from rb where band = 'regex' and ongoing = '1'"))
  202. if err != nil {
  203. log.Fatal(err)
  204. }
  205. defer rows.Close()
  206. for rows.Next() {
  207. var login string
  208. var block string
  209. err := rows.Scan(&login, &block)
  210. if err != nil {
  211. log.Fatal(err)
  212. }
  213. ban_type := Get_user_ban_type(login)
  214. r := regexp2.MustCompile(block, 0)
  215. if m, _ := r.FindStringMatch(ip); m != nil {
  216. if tool == "login" {
  217. if ban_type != "1" {
  218. return []string{"true", "a" + ban_type}
  219. }
  220. } else if tool == "edit_request" {
  221. if ban_type != "2" {
  222. return []string{"true", "a" + ban_type}
  223. }
  224. } else {
  225. return []string{"true", "a" + ban_type}
  226. }
  227. }
  228. }
  229. if IP_or_user(ip) {
  230. rows, err = db.Query(DB_change("select login, block from rb where band = 'cidr' and ongoing = '1'"))
  231. if err != nil {
  232. log.Fatal(err)
  233. }
  234. defer rows.Close()
  235. for rows.Next() {
  236. var login string
  237. var block string
  238. err := rows.Scan(&login, &block)
  239. if err != nil {
  240. log.Fatal(err)
  241. }
  242. ban_type := Get_user_ban_type(login)
  243. c, _ := cidr.Parse(block)
  244. if c.Contains(ip) {
  245. if tool == "login" {
  246. if ban_type != "1" {
  247. return []string{"true", "b" + ban_type}
  248. }
  249. } else if tool == "edit_request" {
  250. if ban_type != "2" {
  251. return []string{"true", "b" + ban_type}
  252. }
  253. } else {
  254. return []string{"true", "b" + ban_type}
  255. }
  256. }
  257. }
  258. }
  259. stmt, err := db.Prepare(DB_change("select login from rb where block = ? and band = '' and ongoing = '1'"))
  260. if err != nil {
  261. log.Fatal(err)
  262. }
  263. defer stmt.Close()
  264. var login string
  265. err = stmt.QueryRow(ip).Scan(&login)
  266. if err != nil {
  267. if err == sql.ErrNoRows {
  268. } else {
  269. log.Fatal(err)
  270. }
  271. } else {
  272. ban_type := Get_user_ban_type(login)
  273. if tool == "login" {
  274. if ban_type != "1" {
  275. return []string{"true", ban_type}
  276. }
  277. } else if tool == "edit_request" {
  278. if ban_type != "2" {
  279. return []string{"true", ban_type}
  280. }
  281. } else {
  282. return []string{"true", ban_type}
  283. }
  284. }
  285. stmt, err = db.Prepare(DB_change("select data from user_set where id = ? and name = 'acl'"))
  286. if err != nil {
  287. log.Fatal(err)
  288. }
  289. defer stmt.Close()
  290. var data string
  291. err = stmt.QueryRow(ip).Scan(&data)
  292. if err != nil {
  293. if err == sql.ErrNoRows {
  294. } else {
  295. log.Fatal(err)
  296. }
  297. } else {
  298. if data == "ban" {
  299. return []string{"true", "c"}
  300. }
  301. }
  302. return []string{"", ""}
  303. }
  304. func IP_parser(db *sql.DB, ip string, my_ip string) string {
  305. ip_pre_data := IP_preprocess(db, ip, my_ip)
  306. if ip_pre_data[0] == "" {
  307. return ""
  308. }
  309. if ip_pre_data[1] != "" {
  310. return ip_pre_data[0]
  311. } else {
  312. raw_ip := ip
  313. ip = HTML_escape(ip_pre_data[0])
  314. if !IP_or_user(raw_ip) {
  315. var user_name_level string
  316. var user_title string
  317. err := db.QueryRow(DB_change("select data from other where name = 'user_name_level'")).Scan(&user_name_level)
  318. if err != nil {
  319. if err == sql.ErrNoRows {
  320. user_name_level = ""
  321. } else {
  322. log.Fatal(err)
  323. }
  324. }
  325. if user_name_level != "" {
  326. level_data := Get_level(db, raw_ip)
  327. ip += "<sup>" + level_data[0] + "</sup>"
  328. }
  329. ip = "<a href=\"/w/" + Url_parser("user:"+raw_ip) + "\">" + ip + "</a>"
  330. stmt, err := db.Prepare(DB_change("select data from user_set where name = 'user_title' and id = ?"))
  331. if err != nil {
  332. log.Fatal(err)
  333. }
  334. defer stmt.Close()
  335. err = stmt.QueryRow(raw_ip).Scan(&user_title)
  336. if err != nil {
  337. if err == sql.ErrNoRows {
  338. user_title = ""
  339. } else {
  340. log.Fatal(err)
  341. }
  342. }
  343. if Check_acl(db, "", "", "user_name_bold", raw_ip) {
  344. ip = "<b>" + ip + "</b>"
  345. }
  346. ip = user_title + ip
  347. }
  348. ban := Get_user_ban(db, raw_ip, "")
  349. if ban[0] == "true" {
  350. ip = "<sup>" + ban[1] + "</sup><s>" + ip + "</s>"
  351. }
  352. ip += "<a href=\"javascript:void(0);\" name=\"" + Url_parser(raw_ip) + "\" onclick=\"opennamu_do_ip_click(this);\"><span class=\"opennamu_svg opennamu_svg_tool\">&nbsp;</span></a>"
  353. return ip
  354. }
  355. }