Class CaptchaChallengeRepository
java.lang.Object
com.sankcrm.erp.auth.infrastructure.captcha.CaptchaChallengeRepository
Redis 技术仓储:保存挑战摘要、计数和限流,并通过 Lua 保证刷新、TTL、一次消费及计数原子性。
-
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptionaccountKey(App app, String account) 为 App 与账号原值派生不可逆、不可枚举的 Redis 键片段。voidclearFailures(App app, String authType, String account) 删除指定账号失败计数;清理失败时保留保护状态并记录非敏感上下文及完整异常。long原子校验 app/type/flow 与一次性答案并消费挑战;登录账号不参与挑战绑定。使用应用密钥派生挑战答案摘要;原答案不写入 Redis。longfailureCount(App app, String authType, String account) voidincrementFailures(App app, String authType, String account, Duration window) 原子递增账号失败计数并设置首写 TTL;结果缺失或小于 1 均视为存储故障。void按 app/type/flow 限制挑战刷新;地址额度按账号隔离,预加载时按 flow 隔离以避免共享代理全站阻断。voidlimitLogin(App app, String authType, String account) 按应用、认证方式和账号限制登录校验尝试;计数器写入失败时拒绝登录。voidlimitVerification(App app, String authType, String account, String flowId) 按 flow 限制验证码校验请求,并继续按实际登录账号限制总量。void用单条 Lua 原子替换同一 app/scene/type/flow 的当前挑战并设置挑战及映射 TTL。
-
Constructor Details
-
CaptchaChallengeRepository
public CaptchaChallengeRepository()
-
-
Method Details
-
accountKey
为 App 与账号原值派生不可逆、不可枚举的 Redis 键片段。- Parameters:
app- 所属应用及 HMAC 密钥account- 登录名原值,不做 trim、大小写转换或 Unicode 规范化- Returns:
- HMAC-SHA256 的 Base64URL 键片段
- Throws:
com.sankcrm.erp.common.exception.CoreRuntimeException- 密钥缺失或摘要计算失败时以验证码服务不可用拒绝
-
failureCount
- Returns:
- 指定账号的当前失败次数;Redis 错误时失败关闭。
-
incrementFailures
原子递增账号失败计数并设置首写 TTL;结果缺失或小于 1 均视为存储故障。 -
clearFailures
删除指定账号失败计数;清理失败时保留保护状态并记录非敏感上下文及完整异常。 -
limitChallenge
public void limitChallenge(App app, String authType, String account, String flowId, String clientAddress) 按 app/type/flow 限制挑战刷新;地址额度按账号隔离,预加载时按 flow 隔离以避免共享代理全站阻断。 -
limitVerification
按 flow 限制验证码校验请求,并继续按实际登录账号限制总量。 -
limitLogin
按应用、认证方式和账号限制登录校验尝试;计数器写入失败时拒绝登录。 -
saveChallenge
public void saveChallenge(App app, String authType, String flowId, String id, String answer, Duration ttl) 用单条 Lua 原子替换同一 app/scene/type/flow 的当前挑战并设置挑战及映射 TTL。- Parameters:
app- 所属应用authType- 认证方式flowId- 客户端生成的高熵页面流程令牌;它不是设备身份凭据id- 新挑战编号answer- 新答案;只写入带密钥 HMAC 摘要,不保存明文ttl- 挑战与 current 映射的有效 Duration- Throws:
com.sankcrm.erp.common.exception.CoreRuntimeException- Redis 异常或脚本未确认写入时失败关闭
-
consumeChallenge
public long consumeChallenge(App app, String authType, String flowId, String challengeId, String candidate) 原子校验 app/type/flow 与一次性答案并消费挑战;登录账号不参与挑战绑定。- Returns:
- -1 表示过期/非当前挑战,0 表示答案错误,1 表示校验成功并已消费
- Throws:
com.sankcrm.erp.common.exception.CoreRuntimeException- Redis 异常时失败关闭
-
digest
使用应用密钥派生挑战答案摘要;原答案不写入 Redis。
-