ip_parser.go 9.4 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427
  1. package tool
  2. import (
  3. "database/sql"
  4. "log"
  5. "regexp"
  6. "strconv"
  7. "strings"
  8. "github.com/3th1nk/cidr"
  9. "github.com/dlclark/regexp2"
  10. )
  11. func IP_or_user(ip string) bool {
  12. match, _ := regexp.MatchString("(\\.|:)", ip)
  13. if match {
  14. return true
  15. } else {
  16. return false
  17. }
  18. }
  19. func Get_level(db *sql.DB, ip string) []string {
  20. var level string
  21. var exp string
  22. var max_exp string
  23. stmt, err := db.Prepare(DB_change("select data from user_set where id = ? and name = 'level'"))
  24. if err != nil {
  25. log.Fatal(err)
  26. }
  27. defer stmt.Close()
  28. err = stmt.QueryRow(ip).Scan(&level)
  29. if err != nil {
  30. if err == sql.ErrNoRows {
  31. level = "0"
  32. } else {
  33. log.Fatal(err)
  34. }
  35. }
  36. stmt, err = db.Prepare(DB_change("select data from user_set where id = ? and name = 'experience'"))
  37. if err != nil {
  38. log.Fatal(err)
  39. }
  40. defer stmt.Close()
  41. err = stmt.QueryRow(ip).Scan(&exp)
  42. if err != nil {
  43. if err == sql.ErrNoRows {
  44. exp = "0"
  45. } else {
  46. log.Fatal(err)
  47. }
  48. }
  49. level_int, _ := strconv.Atoi(level)
  50. max_exp = strconv.Itoa(level_int*50 + 500)
  51. return []string{level, exp, max_exp}
  52. }
  53. func IP_preprocess(db *sql.DB, ip string, my_ip string) []string {
  54. var ip_view string
  55. var user_name_view string
  56. ip_split := strings.Split(ip, ":")
  57. if len(ip_split) != 1 && ip_split[0] == "tool" {
  58. return []string{ip, ""}
  59. }
  60. err := db.QueryRow(DB_change("select data from other where name = 'ip_view'")).Scan(&ip_view)
  61. if err != nil {
  62. if err == sql.ErrNoRows {
  63. ip_view = ""
  64. } else {
  65. log.Fatal(err)
  66. }
  67. }
  68. err = db.QueryRow(DB_change("select data from other where name = 'user_name_view'")).Scan(&user_name_view)
  69. if err != nil {
  70. if err == sql.ErrNoRows {
  71. user_name_view = ""
  72. } else {
  73. log.Fatal(err)
  74. }
  75. }
  76. if Get_user_auth(db, my_ip) != "" {
  77. ip_view = ""
  78. user_name_view = ""
  79. }
  80. ip_change := ""
  81. if IP_or_user(ip) {
  82. if ip_view != "" && ip != my_ip {
  83. hash_ip := Sha224(ip)
  84. ip = hash_ip[:10]
  85. ip_change = "true"
  86. }
  87. } else {
  88. if user_name_view != "" {
  89. var sub_user_name string
  90. stmt, err := db.Prepare(DB_change("select data from user_set where id = ? and name = 'sub_user_name'"))
  91. if err != nil {
  92. log.Fatal(err)
  93. }
  94. defer stmt.Close()
  95. err = stmt.QueryRow(ip).Scan(&sub_user_name)
  96. if err != nil {
  97. if err == sql.ErrNoRows {
  98. sub_user_name = Get_language(db, "member", false)
  99. } else {
  100. log.Fatal(err)
  101. }
  102. }
  103. if sub_user_name == "" {
  104. sub_user_name = Get_language(db, "member", false)
  105. }
  106. ip = sub_user_name
  107. ip_change = "true"
  108. } else {
  109. var user_name string
  110. stmt, err := db.Prepare(DB_change("select data from user_set where name = 'user_name' and id = ?"))
  111. if err != nil {
  112. log.Fatal(err)
  113. }
  114. defer stmt.Close()
  115. err = stmt.QueryRow(ip).Scan(&user_name)
  116. if err != nil {
  117. if err == sql.ErrNoRows {
  118. user_name = ip
  119. } else {
  120. log.Fatal(err)
  121. }
  122. }
  123. if user_name == "" {
  124. user_name = ip
  125. }
  126. ip = user_name
  127. }
  128. }
  129. return []string{ip, ip_change}
  130. }
  131. func IP_menu(db *sql.DB, ip string, my_ip string, option string) map[string][][]string {
  132. menu := map[string][][]string{}
  133. if ip == my_ip && option == "" {
  134. stmt, err := db.Prepare(DB_change("select count(*) from user_notice where name = ? and readme = ''"))
  135. if err != nil {
  136. log.Fatal(err)
  137. }
  138. defer stmt.Close()
  139. var alarm_count string
  140. err = stmt.QueryRow(my_ip).Scan(&alarm_count)
  141. if err != nil {
  142. if err == sql.ErrNoRows {
  143. alarm_count = "0"
  144. } else {
  145. log.Fatal(err)
  146. }
  147. }
  148. if IP_or_user(my_ip) {
  149. menu[Get_language(db, "login", false)] = [][]string{
  150. {"/login", Get_language(db, "login", false)},
  151. {"/register", Get_language(db, "register", false)},
  152. {"/change", Get_language(db, "user_setting", false)},
  153. {"/login/find", Get_language(db, "password_search", false)},
  154. {"/alarm" + Url_parser(my_ip), Get_language(db, "alarm", false) + " (" + alarm_count + ")"},
  155. }
  156. } else {
  157. menu[Get_language(db, "login", false)] = [][]string{
  158. {"/logout", Get_language(db, "logout", false)},
  159. {"/change", Get_language(db, "user_setting", false)},
  160. }
  161. menu[Get_language(db, "tool", false)] = [][]string{
  162. {"/watch_list", Get_language(db, "watchlist", false)},
  163. {"/star_doc", Get_language(db, "star_doc", false)},
  164. {"/challenge", Get_language(db, "challenge_and_level_manage", false)},
  165. {"/acl/user:" + Url_parser(my_ip), Get_language(db, "user_document_acl", false)},
  166. {"/alarm" + Url_parser(my_ip), Get_language(db, "alarm", false) + " (" + alarm_count + ")"},
  167. }
  168. }
  169. }
  170. auth_name := Get_user_auth(db, my_ip)
  171. if auth_name != "" {
  172. menu[Get_language(db, "admin", false)] = [][]string{
  173. {"/auth/ban/" + Url_parser(ip), Get_language(db, "ban", false)},
  174. {"/list/user/check_submit/" + Url_parser(ip), Get_language(db, "check", false)},
  175. }
  176. }
  177. menu[Get_language(db, "other", false)] = [][]string{
  178. {"/record/" + Url_parser(ip), Get_language(db, "edit_record", false)},
  179. {"/record/topic/" + Url_parser(ip), Get_language(db, "discussion_record", false)},
  180. {"/record/bbs/" + Url_parser(ip), Get_language(db, "bbs_record", false)},
  181. {"/record/bbs_comment/" + Url_parser(ip), Get_language(db, "bbs_comment_record", false)},
  182. {"/topic/user:" + Url_parser(ip), Get_language(db, "user_discussion", false)},
  183. {"/count/" + Url_parser(ip), Get_language(db, "count", false)},
  184. }
  185. return menu
  186. }
  187. func Get_user_ban_type(ban_type string) string {
  188. if ban_type == "O" {
  189. return "1"
  190. } else if ban_type == "E" {
  191. return "2"
  192. } else if ban_type == "A" {
  193. return "3"
  194. } else if ban_type == "D" {
  195. return "4"
  196. } else {
  197. return ""
  198. }
  199. }
  200. func Get_user_ban(db *sql.DB, ip string, tool string) []string {
  201. if Get_user_auth(db, ip) != "" {
  202. return []string{"", ""}
  203. }
  204. rows, err := db.Query(DB_change("select login, block from rb where band = 'regex' and ongoing = '1'"))
  205. if err != nil {
  206. log.Fatal(err)
  207. }
  208. defer rows.Close()
  209. for rows.Next() {
  210. var login string
  211. var block string
  212. err := rows.Scan(&login, &block)
  213. if err != nil {
  214. log.Fatal(err)
  215. }
  216. ban_type := Get_user_ban_type(login)
  217. r := regexp2.MustCompile(block, 0)
  218. if m, _ := r.FindStringMatch(ip); m != nil {
  219. if tool == "login" {
  220. if ban_type != "1" {
  221. return []string{"true", "a" + ban_type}
  222. }
  223. } else if tool == "edit_request" {
  224. if ban_type != "2" {
  225. return []string{"true", "a" + ban_type}
  226. }
  227. } else {
  228. return []string{"true", "a" + ban_type}
  229. }
  230. }
  231. }
  232. if IP_or_user(ip) {
  233. rows, err = db.Query(DB_change("select login, block from rb where band = 'cidr' and ongoing = '1'"))
  234. if err != nil {
  235. log.Fatal(err)
  236. }
  237. defer rows.Close()
  238. for rows.Next() {
  239. var login string
  240. var block string
  241. err := rows.Scan(&login, &block)
  242. if err != nil {
  243. log.Fatal(err)
  244. }
  245. ban_type := Get_user_ban_type(login)
  246. c, _ := cidr.Parse(block)
  247. if c.Contains(ip) {
  248. if tool == "login" {
  249. if ban_type != "1" {
  250. return []string{"true", "b" + ban_type}
  251. }
  252. } else if tool == "edit_request" {
  253. if ban_type != "2" {
  254. return []string{"true", "b" + ban_type}
  255. }
  256. } else {
  257. return []string{"true", "b" + ban_type}
  258. }
  259. }
  260. }
  261. }
  262. stmt, err := db.Prepare(DB_change("select login from rb where block = ? and band = '' and ongoing = '1'"))
  263. if err != nil {
  264. log.Fatal(err)
  265. }
  266. defer stmt.Close()
  267. var login string
  268. err = stmt.QueryRow(ip).Scan(&login)
  269. if err != nil {
  270. if err == sql.ErrNoRows {
  271. } else {
  272. log.Fatal(err)
  273. }
  274. } else {
  275. ban_type := Get_user_ban_type(login)
  276. if tool == "login" {
  277. if ban_type != "1" {
  278. return []string{"true", ban_type}
  279. }
  280. } else if tool == "edit_request" {
  281. if ban_type != "2" {
  282. return []string{"true", ban_type}
  283. }
  284. } else {
  285. return []string{"true", ban_type}
  286. }
  287. }
  288. stmt, err = db.Prepare(DB_change("select data from user_set where id = ? and name = 'acl'"))
  289. if err != nil {
  290. log.Fatal(err)
  291. }
  292. defer stmt.Close()
  293. var data string
  294. err = stmt.QueryRow(ip).Scan(&data)
  295. if err != nil {
  296. if err == sql.ErrNoRows {
  297. } else {
  298. log.Fatal(err)
  299. }
  300. } else {
  301. if data == "ban" {
  302. return []string{"true", "c"}
  303. }
  304. }
  305. return []string{"", ""}
  306. }
  307. func IP_parser(db *sql.DB, ip string, my_ip string) string {
  308. ip_pre_data := IP_preprocess(db, ip, my_ip)
  309. if ip_pre_data[0] == "" {
  310. return ""
  311. }
  312. if ip_pre_data[1] != "" {
  313. return ip_pre_data[0]
  314. } else {
  315. raw_ip := ip
  316. ip = HTML_escape(ip_pre_data[0])
  317. if !IP_or_user(raw_ip) {
  318. var user_name_level string
  319. var user_title string
  320. err := db.QueryRow(DB_change("select data from other where name = 'user_name_level'")).Scan(&user_name_level)
  321. if err != nil {
  322. if err == sql.ErrNoRows {
  323. user_name_level = ""
  324. } else {
  325. log.Fatal(err)
  326. }
  327. }
  328. if user_name_level != "" {
  329. level_data := Get_level(db, raw_ip)
  330. ip += "<sup>" + level_data[0] + "</sup>"
  331. }
  332. ip = "<a href=\"/w/" + Url_parser("user:"+raw_ip) + "\">" + ip + "</a>"
  333. stmt, err := db.Prepare(DB_change("select data from user_set where name = 'user_title' and id = ?"))
  334. if err != nil {
  335. log.Fatal(err)
  336. }
  337. defer stmt.Close()
  338. err = stmt.QueryRow(raw_ip).Scan(&user_title)
  339. if err != nil {
  340. if err == sql.ErrNoRows {
  341. user_title = ""
  342. } else {
  343. log.Fatal(err)
  344. }
  345. }
  346. if Get_user_auth(db, raw_ip) != "" {
  347. ip = "<b>" + ip + "</b>"
  348. }
  349. ip = user_title + ip
  350. }
  351. ban := Get_user_ban(db, raw_ip, "")
  352. if ban[0] == "true" {
  353. ip = "<sup>" + ban[1] + "</sup><s>" + ip + "</s>"
  354. }
  355. ip += "<a href=\"javascript:void(0);\" name=\"" + Url_parser(raw_ip) + "\" onclick=\"opennamu_do_ip_click(this);\"><span class=\"opennamu_svg opennamu_svg_tool\">&nbsp;</span></a>"
  356. return ip
  357. }
  358. }