feat(admin): 后台登录支持「记住此设备」(免二次验证 + 保持登录)
ci-pangolin / Redline Scan — 脱敏 (UI 文案) (push) Successful in 25s
ci-pangolin / Cleartext Scan — Android 禁明文 (push) Successful in 20s
ci-pangolin / Lint — shellcheck (push) Successful in 51s
ci-pangolin / Portable SQL — 可移植性 (mysql/sqlite) (push) Successful in 23s
ci-pangolin / OpenAPI Sync Check (push) Successful in 1m10s
ci-pangolin / Flutter — analyze + test (push) Successful in 3m44s
ci-pangolin / Codegen Drift — token 生成物未漂移 (push) Successful in 1m7s
ci-pangolin / DS-flow — 原型/跨端同源/代码色单源闸 (push) Successful in 24s
ci-pangolin / Go — build + test (push) Failing after 1m0s
ci-pangolin / E2E Smoke — L4 进程级端到端 (push) Failing after 40s
ci-pangolin / Go — integration (mysql/redis testcontainers) (push) Failing after 6m9s
ci-pangolin / Golden — 视觉回归 (全量:components/auth/desktop/tablet) (push) Successful in 42s

常用设备(已在 mTLS 白名单内)每次都要输 TOTP + 30 分钟就掉线,体验差。
新增登录页「记住此设备」勾选:

- 勾选并成功登录(需完整 密码+TOTP)后,签发 30 天设备信任令牌(HttpOnly/
  Secure/SameSite=Strict cookie,Redis 存储绑定 admin ID),并把会话延到 30 天
  (持久 cookie + 服务端 TTL,滑动续期按会话自身 TTL)。
- 之后该设备重登只需 用户名+密码,**跳过 TOTP**;会话在有效期内保持登录。

安全不变量(均有测试覆盖):
- 密码永远必验——即便持有效信任令牌,密码错一律拒(只跳过第二因子,不跳过密码);
- 信任令牌绑定 admin,alice 的令牌不能给 bob 免 TOTP;
- 无令牌 + 空 TOTP 一律拒(未记住设备仍强制二次验证);
- 令牌过期/Redis 清空/未知令牌全部 fail-closed 回退到「要 TOTP」;
- TrustedDeviceTTL=0 关闭整功能(勾选无效)。

实现:新增 TrustedStore(Redis, trusted.go);Authenticator.LoginDevice
(旧 Login 保持签名,委托新方法,零行为变化);SessionStore.CreateWithTTL +
Session.TTLSeconds 支持持久会话按自身 TTL 滑动;handler 读 cookie/勾选、
按 Persistent 设长短会话 cookie、下发信任 cookie;登录页加勾选、TOTP 去
required。配置项 ADMIN_TRUSTED_DEVICE_TTL(默认 720h)。

测试:trusted_test(签发/校验/绑定/吊销/过期/禁用)、login_device_test
(跳过TOTP/仍需密码/绑定admin/无令牌需TOTP)、login_device_handler_test
(端到端 勾选→双cookie→凭信任cookie免TOTP、无信任空TOTP 401);
go test ./internal/admin 全绿,go vet 净。

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01P9G7E3wmAYL9KeYCVZVsqu
This commit is contained in:
wangjia
2026-07-24 09:52:56 +08:00
parent f819a77d83
commit 1d154bd627
9 changed files with 561 additions and 29 deletions
+38 -3
View File
@@ -61,9 +61,15 @@ func (h *Handlers) LoginSubmit(w http.ResponseWriter, r *http.Request) {
username := strings.TrimSpace(r.PostFormValue("username"))
password := r.PostFormValue("password")
code := strings.TrimSpace(r.PostFormValue("totp"))
remember := r.PostFormValue("remember") != ""
ip := realIP(r) // 经本机 caddy 反代时取 XFF 末跳,否则 TCP 对端(见 mw_ipallow.go)
sid, _, err := h.auth.Login(r.Context(), username, password, code, ip)
var trustToken string
if c, cerr := r.Cookie(TrustedDeviceCookieName); cerr == nil {
trustToken = c.Value
}
res, err := h.auth.LoginDevice(r.Context(), username, password, code, ip, trustToken, remember)
if err != nil {
flash := "用户名、密码或动态验证码有误"
if err == ErrLockedOut {
@@ -73,7 +79,14 @@ func (h *Handlers) LoginSubmit(w http.ResponseWriter, r *http.Request) {
h.render.render(w, "login", pageData{Flash: flash})
return
}
h.setSessionCookie(w, sid)
if res.Persistent {
h.setSessionCookieTTL(w, res.SID, h.cfg.TrustedDeviceTTL)
} else {
h.setSessionCookie(w, res.SID)
}
if res.NewTrustToken != "" {
h.setTrustedCookie(w, res.NewTrustToken)
}
http.Redirect(w, r, "/", http.StatusFound)
}
@@ -394,6 +407,14 @@ func (h *Handlers) writeAudit(ctx context.Context, actor, action, target, metaJS
}
func (h *Handlers) setSessionCookie(w http.ResponseWriter, sid string) {
h.setSessionCookieTTL(w, sid, h.cfg.SessionTTL)
}
// setSessionCookieTTL sets the session cookie with an explicit Max-Age. For a
// persistent ("记住此设备") session ttl is the long trust-TTL; otherwise the
// short idle default. Max-Age <= 0 would make it a session cookie, so ttl must
// be positive here.
func (h *Handlers) setSessionCookieTTL(w http.ResponseWriter, sid string, ttl time.Duration) {
http.SetCookie(w, &http.Cookie{
Name: SessionCookieName,
Value: sid,
@@ -401,7 +422,21 @@ func (h *Handlers) setSessionCookie(w http.ResponseWriter, sid string) {
HttpOnly: true,
Secure: h.cfg.CookieSecure,
SameSite: http.SameSiteStrictMode,
MaxAge: int(h.cfg.SessionTTL.Seconds()),
MaxAge: int(ttl.Seconds()),
})
}
// setTrustedCookie stores the device-trust token (HttpOnly, Secure, Strict) so
// this device can skip TOTP on future logins for the trust TTL.
func (h *Handlers) setTrustedCookie(w http.ResponseWriter, token string) {
http.SetCookie(w, &http.Cookie{
Name: TrustedDeviceCookieName,
Value: token,
Path: "/",
HttpOnly: true,
Secure: h.cfg.CookieSecure,
SameSite: http.SameSiteStrictMode,
MaxAge: int(h.cfg.TrustedDeviceTTL.Seconds()),
})
}