RequestAuditFilter.cs 7.9 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174
  1. using Microsoft.AspNetCore.Mvc.Controllers;
  2. using Microsoft.AspNetCore.Mvc.Filters;
  3. using System.Security.Claims;
  4. using System;
  5. using System.Threading.Tasks;
  6. using TEAMModelOS.SDK.Extension;
  7. using Microsoft.Extensions.Logging;
  8. using TEAMModelOS.SDK;
  9. using System.IdentityModel.Tokens.Jwt;
  10. using System.Linq;
  11. using Azure.Core;
  12. using TEAMModelOS.SDK.DI;
  13. using Microsoft.Extensions.Primitives;
  14. using HTEXLib.Helpers.ShapeHelpers;
  15. using System.Net.Http;
  16. using System.ServiceModel.Channels;
  17. using System.Net;
  18. using System.Net.Http.Json;
  19. namespace TEAMModelOS.Filter
  20. {
  21. public class RequestAuditFilter : IAsyncActionFilter
  22. {
  23. //private readonly ILogger _logger;
  24. // private readonly HttpTrigger _httpTrigger;
  25. private readonly IHttpClientFactory _httpClient;
  26. private readonly DingDing _dingding;
  27. public RequestAuditFilter(/*ILoggerFactory loggerFactory*/IHttpClientFactory httpClient, DingDing dingding)
  28. {
  29. // _logger = loggerFactory.CreateLogger<RequestAuditFilter>();
  30. // _httpTrigger = httpTrigger;
  31. _httpClient = httpClient;
  32. _dingding=dingding;
  33. }
  34. public async Task OnActionExecutionAsync(ActionExecutingContext context, ActionExecutionDelegate next)
  35. {
  36. try {
  37. string id = string.Empty, name = string.Empty, picture = string.Empty, school = string.Empty, scope = string.Empty, roles = string.Empty;
  38. //============== 这里是执行方法之前获取数据 ====================
  39. // 获取控制器、路由信息
  40. //var actionDescriptor = context.ActionDescriptor as ControllerActionDescriptor;
  41. // 获取请求的方法
  42. //var method = actionDescriptor.MethodInfo;
  43. // 获取 HttpContext 和 HttpRequest 对象
  44. var httpContext = context.HttpContext;
  45. string ua = httpContext.GetUserAgent();
  46. var httpRequest = httpContext.Request;
  47. // 获取客户端 Ipv4 地址
  48. var remoteIPv4 = httpContext.GetRemoteIpAddressToIPv4();
  49. // 获取请求的 Url 地址
  50. // var requestUrl = httpRequest.GetRequestUrlAddress();
  51. // 获取来源 Url 地址
  52. var refererUrl = httpRequest.GetRefererUrlAddress();
  53. // 获取请求参数(写入日志,需序列化成字符串后存储)
  54. var parameters = context.ActionArguments;
  55. // 获取操作人(必须授权访问才有值)"userId" 为你存储的 claims type,jwt 授权对应的是 payload 中存储的键名
  56. //var userId = httpContext.User?.FindFirstValue("userId");
  57. var authtoken = context.HttpContext.GetXAuth("AuthToken");
  58. string tokenSha = string.Empty, client = string.Empty;
  59. if (context.HttpContext.Request.Headers.TryGetValue("Authorization", out StringValues Authorization))
  60. {
  61. var jwt = new JwtSecurityTokenHandler().ReadJwtToken(Authorization.ToString().Replace("Bearer ", ""));
  62. client= roles = jwt.Claims.FirstOrDefault(claim => claim.Type.Equals("roles"))?.Value;
  63. tokenSha= ShaHashHelper.GetSHA1(Authorization.ToString());
  64. }
  65. if (context.HttpContext.Request.Headers.TryGetValue("X-Auth-IdToken", out StringValues XAuthIdToken))
  66. {
  67. var jwt = new JwtSecurityTokenHandler().ReadJwtToken(XAuthIdToken);
  68. id = jwt.Payload.Sub;
  69. name = jwt.Claims.FirstOrDefault(claim => claim.Type.Equals("name"))?.Value;
  70. if (string.IsNullOrEmpty(tokenSha))
  71. {
  72. tokenSha= ShaHashHelper.GetSHA1(XAuthIdToken.ToString());
  73. }
  74. }
  75. if (context.HttpContext.Request.Headers.TryGetValue("X-Auth-School", out StringValues XAuthSchool))
  76. {
  77. try
  78. {
  79. school = XAuthSchool.ToString();
  80. }
  81. catch (Exception ex) { }
  82. }
  83. if (!string.IsNullOrWhiteSpace(authtoken))
  84. {
  85. var jwt = new JwtSecurityTokenHandler().ReadJwtToken(authtoken);
  86. id = jwt.Payload.Sub;
  87. school = jwt.Payload.Azp;
  88. name = jwt.Claims.FirstOrDefault(claim => claim.Type.Equals("name"))?.Value;
  89. scope = jwt.Claims.FirstOrDefault(claim => claim.Type.Equals("scope"))?.Value;
  90. if (string.IsNullOrEmpty(tokenSha))
  91. {
  92. tokenSha= ShaHashHelper.GetSHA1(authtoken);
  93. }
  94. }
  95. string secChUaPlatform = string.Empty;
  96. if (httpContext.Request.Headers.TryGetValue("Sec-Ch-Ua-Platform", out var values))
  97. {
  98. secChUaPlatform = values.FirstOrDefault();
  99. }
  100. if (string.IsNullOrEmpty(tokenSha))
  101. {
  102. tokenSha= ShaHashHelper.GetSHA1($"{ua}{remoteIPv4}{httpRequest.Host}{secChUaPlatform}");
  103. }
  104. // 请求时间
  105. var requestedTime = DateTimeOffset.Now.GetGMTTime(8).ToUnixTimeMilliseconds();
  106. //============== 这里是执行方法之后获取数据 ====================
  107. var actionContext = await next();
  108. // 获取返回的结果
  109. // var returnResult = actionContext.Result;
  110. // 判断是否请求成功,没有异常就是请求成功
  111. // var isRequestSucceed = actionContext.Exception == null;
  112. // 获取调用堆栈信息,提供更加简单明了的调用和异常堆栈
  113. // var stackTrace = EnhancedStackTrace.Current();
  114. // string region = await _searcher.SearchIpAsync(remoteIPv4);
  115. //同一个账号,同一IP,同一接口,UA标识(UA标识随意切换则表示可能会存在DDOS),时间段
  116. //_logger.LogInformation(new{ ua=httpContext.GetUserAgent(), ip=remoteIPv4,time=requestedTime,path =$"{httpRequest.PathBase}{httpRequest.Path}",host= $"{httpRequest.Host}", param=parameters,id ,name ,school,succeed =isRequestSucceed }.ToJsonString());
  117. var data = new
  118. {
  119. //ua =ua,
  120. ip = remoteIPv4,
  121. time = requestedTime,
  122. path = $"{httpRequest.PathBase}{httpRequest.Path}",
  123. host = $"{httpRequest.Host}",
  124. param = parameters,
  125. id = id,
  126. name = name,
  127. school = school,
  128. client = client,
  129. tid = tokenSha,
  130. scope = scope,
  131. // referer = refererUrl,
  132. //platform = secChUaPlatform,
  133. p = "bi",
  134. //idToken=XAuthIdToken
  135. };
  136. #if DEBUG
  137. var response = await _httpClient.CreateClient().PostAsJsonAsync("http://cdhabook.teammodel.cn:8805/api/http-log", data);
  138. if (response.StatusCode==HttpStatusCode.OK)
  139. {
  140. string result = await response.Content.ReadAsStringAsync();
  141. }
  142. #else
  143. _= _httpClient.CreateClient().PostAsJsonAsync("http://cdhabook.teammodel.cn:8805/api/http-log",data);
  144. #endif
  145. // _ = _httpTrigger.RequestHttpTrigger(data, "China", "http-log");
  146. }
  147. catch (Exception ex)
  148. {
  149. await _dingding.SendBotMsg($"HTTP日志访问错误:{ex.Message}\n{ex.StackTrace}", GroupNames.成都开发測試群組);
  150. var actionContext = await next();
  151. }
  152. }
  153. }
  154. }