Class CaptchaChallengeRepository

java.lang.Object
com.sankcrm.erp.auth.infrastructure.captcha.CaptchaChallengeRepository

@Repository public class CaptchaChallengeRepository extends Object
Redis 技术仓储:保存挑战摘要、计数和限流,并通过 Lua 保证刷新、TTL、一次消费及计数原子性。
  • Constructor Details

    • CaptchaChallengeRepository

      public CaptchaChallengeRepository()
  • Method Details

    • accountKey

      public String accountKey(App app, String account)
      为 App 与账号原值派生不可逆、不可枚举的 Redis 键片段。
      Parameters:
      app - 所属应用及 HMAC 密钥
      account - 登录名原值,不做 trim、大小写转换或 Unicode 规范化
      Returns:
      HMAC-SHA256 的 Base64URL 键片段
      Throws:
      com.sankcrm.erp.common.exception.CoreRuntimeException - 密钥缺失或摘要计算失败时以验证码服务不可用拒绝
    • failureCount

      public long failureCount(App app, String authType, String account)
      Returns:
      指定账号的当前失败次数;Redis 错误时失败关闭。
    • incrementFailures

      public void incrementFailures(App app, String authType, String account, Duration window)
      原子递增账号失败计数并设置首写 TTL;结果缺失或小于 1 均视为存储故障。
    • clearFailures

      public void clearFailures(App app, String authType, String account)
      删除指定账号失败计数;清理失败时保留保护状态并记录非敏感上下文及完整异常。
    • limitChallenge

      public void limitChallenge(App app, String authType, String account, String flowId, String clientAddress)
      按 flow 与账号限流,并附加账号范围内的地址限流,避免共享代理地址形成全站阻断。
    • limitVerification

      public void limitVerification(App app, String authType, String account, String flowId)
      同时按账号+flow 与账号总量限制验证码校验请求。
    • limitLogin

      public void limitLogin(App app, String authType, String account)
      按应用、认证方式和账号限制登录校验尝试;计数器写入失败时拒绝登录。
    • saveChallenge

      public void saveChallenge(App app, String authType, String accountKey, String flowId, String id, String answer, Duration ttl)
      用单条 Lua 原子替换同一 app/scene/type/account/flow 的当前挑战并设置挑战及映射 TTL。
      Parameters:
      app - 所属应用
      authType - 认证方式
      accountKey - 账号原值的 HMAC 键
      flowId - 高熵登录流程标识
      id - 新挑战编号
      answer - 新答案;只写入带密钥 HMAC 摘要,不保存明文
      ttl - 挑战与 current 映射的有效 Duration
      Throws:
      com.sankcrm.erp.common.exception.CoreRuntimeException - Redis 异常或脚本未确认写入时失败关闭
    • consumeChallenge

      public long consumeChallenge(App app, String authType, String accountKey, String flowId, String challengeId, String candidate)
      原子校验绑定并消费一次性挑战。
      Returns:
      -1 表示过期/非当前挑战,0 表示答案错误,1 表示校验成功并已消费
      Throws:
      com.sankcrm.erp.common.exception.CoreRuntimeException - Redis 异常时失败关闭
    • digest

      public String digest(App app, String value)
      使用应用密钥派生挑战答案摘要;原答案不写入 Redis。