File size: 7,668 Bytes
6c6d16c a9c5abb 6c6d16c 1877b95 6c6d16c 9ad5679 6c6d16c |
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 |
import { Page } from 'playwright';
import BrowserManager from './browser.js';
import { getVerificationCode } from './emailVerification.js';
interface Account {
email: string;
password: string;
proofEmail: string;
}
export class AuthService {
constructor(private env: Env) { }
async authenticateEmail(email: string): Promise<{ success: boolean; error?: string }> {
try {
const accountsStr = await this.env.KV.get("accounts");
const accounts: Account[] = accountsStr ? JSON.parse(accountsStr) : [];
const account = accounts.find(a => a.email === email);
if (!account) {
throw new Error("Account not found");
}
await this.performAuthentication(account);
await this.handleAuthorizationCallback(email);
return { success: true };
} catch (error: any) {
return {
success: false,
error: error.message
};
}
}
private async performAuthentication(account: Account) {
const clientId = this.env.ENTRA_CLIENT_ID;
const redirectUri = this.env.AUTH_REDIRECT_URI;
let browser;
let context;
try {
browser = await BrowserManager.getInstance();
context = await browser.newContext();
const page = await context.newPage();
const authUrl = this.buildAuthUrl(clientId, redirectUri, account.email);
await this.handleLoginProcess(page, account, authUrl);
await this.handleMultiFactorAuth(page, account);
await this.handleConsent(page, redirectUri);
} finally {
if (context) await context.close();
}
}
private buildAuthUrl(clientId: string, redirectUri: string, email: string): string {
return `https://login.microsoftonline.com/common/oauth2/v2.0/authorize?` +
`client_id=${clientId}` +
`&response_type=code` +
`&redirect_uri=${encodeURIComponent(redirectUri)}` +
`&response_mode=query` +
`&scope=offline_access%20IMAP.AccessAsUser.All%20User.Read%20Mail.ReadWrite.Shared%20Mail.Send%20Mail.Read` +
`&prompt=consent` +
`&state=${email}`;
}
private async handleLoginProcess(page: Page, account: Account, authUrl: string) {
await page.goto(authUrl);
await page.fill('input[type="email"]', account.email);
await page.click('input[type="submit"]');
try {
await page.waitForSelector('#idA_PWD_SwitchToPassword', { timeout: 3000 });
await page.click('#idA_PWD_SwitchToPassword');
} catch (error) {
console.log(`没有切换到密码登录,继续执行: ${error}`);
}
await page.waitForURL("https://login.live.com/**");
await page.fill('input[type="password"]', account.password);
await page.fill('input[type="password"]', account.password);
await page.click('button[type="submit"]');
try {
await page.waitForURL("https://account.live.com/recover/**", { timeout: 5000 });
await page.click('#iLandingViewAction');
} catch (error) {
console.log("验证确定 page not found or timeout, skipping...");
}
}
private async handleMultiFactorAuth(page: Page, account: Account) {
for (let i = 0; i < 3; i++) {
try {
await page.waitForURL('https://account.live.com/identity/**', { timeout: 5000 });
const proofEmail = account.proofEmail;
if (!proofEmail) {
throw new Error("No proof email provided");
}
const timestamp = Math.floor(Date.now() / 1000);
try {
await page.waitForSelector('#iProof0', { timeout: 3000 });
await page.click('#iProof0');
} catch (error) {
console.log(`没有#iProof0,继续执行: ${error}`);
}
await page.fill("#iProofEmail", proofEmail);
await page.click('input[type="submit"]');
const proof = [
{
"suffix": "godgodgame.com",
"apiUrl": "https://seedmail.igiven.com/api/latest-email",
"token": this.env.PROOF_GODGODGAME_TOKEN
},
{
"suffix": "igiven.com",
"apiUrl": "https://mail.igiven.com/api/latest-email",
"token": this.env.PROOF_IGIVEN_TOKEN
}
];
const suffix = proofEmail.substring(proofEmail.indexOf('@') + 1);
const proofConfig = proof.find(p => p.suffix === suffix)!;
const verificationCode = await getVerificationCode(
proofConfig.apiUrl,
proofConfig.token!,
proofEmail,
timestamp
);
await page.fill('input[type="tel"]', verificationCode);
await page.click('input[type="submit"]');
await page.waitForTimeout(5 * 1000)
} catch (error) {
console.log(account.email, `没有多重验证,继续执行: ${error}`);
}
}
}
private async handleConsent(page: Page, redirectUri: string) {
await page.waitForURL((url: any) => url.href.startsWith("https://login.live.com"));
await page.click('button[type="submit"]#acceptButton');
try {
await page.waitForURL("https://account.live.com/Consent/**", { timeout: 10000 });
await page.click('button[type="submit"][data-testid="appConsentPrimaryButton"]');
} catch (error) {
console.log("Consent page not found or timeout, skipping...");
}
await page.waitForURL((url: any) => url.href.startsWith(redirectUri));
}
private async handleAuthorizationCallback(email: string) {
let code = null;
const maxRetries = 30;
let retries = 0;
while (!code && retries < maxRetries) {
const codeKey = `code_${email}`;
code = await this.env.KV.get(codeKey);
if (!code) {
await new Promise(resolve => setTimeout(resolve, 1000));
retries++;
}
}
if (!code) {
throw new Error("Authorization timeout");
}
const tokenResponse = await fetch('https://login.microsoftonline.com/common/oauth2/v2.0/token', {
method: 'POST',
headers: { 'Content-Type': 'application/x-www-form-urlencoded' },
body: new URLSearchParams({
client_id: this.env.ENTRA_CLIENT_ID,
client_secret: this.env.ENTRA_CLIENT_SECRET,
code: code,
redirect_uri: this.env.AUTH_REDIRECT_URI,
grant_type: 'authorization_code'
})
});
const tokenData: any = await tokenResponse.json();
if (!tokenData.refresh_token) {
throw new Error("Failed to get refresh token");
}
if (!tokenData.expires_in) {
throw new Error("Missing expires_in in token response");
}
const tokenInfo = {
...tokenData,
timestamp: Date.now()
};
await this.env.KV.put(`refresh_token_${email}`, JSON.stringify(tokenInfo));
await this.env.KV.delete(`code_${email}`);
}
} |