log.go 7.4 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318
  1. package middleware
  2. import (
  3. "bytes"
  4. "fmt"
  5. "io"
  6. "strings"
  7. "time"
  8. "github.com/duke-git/lancet/v2/random"
  9. "github.com/gin-gonic/gin"
  10. "github.com/go-nunu/nunu-layout-advanced/pkg/log"
  11. "go.uber.org/zap"
  12. )
  13. const (
  14. MaxBodySize = 10 * 1024 // 10KB
  15. TraceIDKey = "trace_id"
  16. )
  17. var (
  18. // 跳过的路径
  19. skipPaths = map[string]bool{
  20. "/health": true,
  21. "/metrics": true,
  22. "/favicon.ico": true,
  23. "/ping": true,
  24. }
  25. // 需要记录的请求头
  26. importantHeaders = []string{
  27. "authorization",
  28. "x-request-id",
  29. "x-real-ip",
  30. "x-forwarded-for",
  31. "user-agent",
  32. "content-type",
  33. }
  34. // 敏感字段
  35. sensitiveFields = []string{
  36. "password", "passwd", "pwd",
  37. "token", "access_token", "refresh_token",
  38. "secret", "api_key", "apikey",
  39. "authorization",
  40. }
  41. )
  42. func RequestLogMiddleware(logger *log.Logger) gin.HandlerFunc {
  43. return func(ctx *gin.Context) {
  44. // 跳过不需要记录的路径
  45. if skipPaths[ctx.Request.URL.Path] {
  46. ctx.Next()
  47. return
  48. }
  49. // 生成简短的追踪ID
  50. traceID := generateTraceID()
  51. ctx.Set(TraceIDKey, traceID)
  52. // 构建日志字段
  53. fields := []zap.Field{
  54. zap.String("trace_id", traceID),
  55. zap.String("method", ctx.Request.Method),
  56. zap.String("path", ctx.Request.URL.Path),
  57. zap.String("client_ip", ctx.ClientIP()),
  58. }
  59. // 记录查询参数
  60. if query := ctx.Request.URL.RawQuery; query != "" {
  61. fields = append(fields, zap.String("query", query))
  62. }
  63. // 记录重要请求头
  64. if headers := getImportantHeaders(ctx); len(headers) > 0 {
  65. fields = append(fields, zap.Any("headers", headers))
  66. }
  67. // 记录请求体(仅限特定方法)
  68. if shouldLogRequestBody(ctx) {
  69. if bodyLog := getRequestBody(ctx); bodyLog != "" {
  70. fields = append(fields, zap.String("body", bodyLog))
  71. }
  72. }
  73. // 设置日志上下文
  74. logger.WithValue(ctx, zap.String("trace_id", traceID))
  75. // 记录请求开始时间
  76. ctx.Set("start_time", time.Now())
  77. logger.Info("API Request", fields...)
  78. ctx.Next()
  79. }
  80. }
  81. func ResponseLogMiddleware(logger *log.Logger) gin.HandlerFunc {
  82. return func(ctx *gin.Context) {
  83. // 跳过不需要记录的路径
  84. if skipPaths[ctx.Request.URL.Path] {
  85. ctx.Next()
  86. return
  87. }
  88. // 包装响应写入器
  89. blw := &bodyLogWriter{
  90. body: bytes.NewBufferString(""),
  91. ResponseWriter: ctx.Writer,
  92. }
  93. ctx.Writer = blw
  94. // 执行处理
  95. ctx.Next()
  96. // 计算耗时
  97. var duration time.Duration
  98. if startTime, exists := ctx.Get("start_time"); exists {
  99. if st, ok := startTime.(time.Time); ok {
  100. duration = time.Since(st)
  101. }
  102. }
  103. // 构建响应日志字段
  104. fields := []zap.Field{
  105. zap.Int("status", ctx.Writer.Status()),
  106. zap.String("duration", duration.String()),
  107. zap.Int64("duration_ms", duration.Milliseconds()),
  108. }
  109. // 记录响应体(限制大小和内容类型)
  110. if shouldLogResponseBody(ctx) {
  111. bodyStr := blw.body.String()
  112. if len(bodyStr) > MaxBodySize {
  113. fields = append(fields, zap.String("body", fmt.Sprintf("[TRUNCATED: %d bytes]", len(bodyStr))))
  114. } else if len(bodyStr) > 0 {
  115. fields = append(fields, zap.String("body", maskSensitiveData(bodyStr)))
  116. }
  117. }
  118. // 记录错误信息
  119. if len(ctx.Errors) > 0 {
  120. fields = append(fields, zap.Any("errors", ctx.Errors))
  121. }
  122. // 添加状态分类
  123. statusCode := ctx.Writer.Status()
  124. if statusCode >= 500 {
  125. fields = append(fields, zap.String("level", "error"))
  126. } else if statusCode >= 400 {
  127. fields = append(fields, zap.String("level", "warn"))
  128. } else {
  129. fields = append(fields, zap.String("level", "info"))
  130. }
  131. // 统一使用 Info 级别,避免堆栈信息
  132. logger.WithContext(ctx).Info("API Response", fields...)
  133. }
  134. }
  135. // bodyLogWriter 包装响应写入器以捕获响应体
  136. type bodyLogWriter struct {
  137. gin.ResponseWriter
  138. body *bytes.Buffer
  139. }
  140. func (w *bodyLogWriter) Write(b []byte) (int, error) {
  141. w.body.Write(b)
  142. return w.ResponseWriter.Write(b)
  143. }
  144. // 辅助函数
  145. func generateTraceID() string {
  146. // 使用时间戳 + 4位随机字符串
  147. return fmt.Sprintf("%d-%s", time.Now().Unix(), random.RandString(4))
  148. }
  149. func getImportantHeaders(ctx *gin.Context) map[string]string {
  150. headers := make(map[string]string)
  151. for _, key := range importantHeaders {
  152. if value := ctx.GetHeader(key); value != "" {
  153. headers[key] = value
  154. }
  155. }
  156. return headers
  157. }
  158. func shouldLogRequestBody(ctx *gin.Context) bool {
  159. method := ctx.Request.Method
  160. return method == "POST" || method == "PUT" || method == "PATCH" || method == "DELETE"
  161. }
  162. func shouldLogResponseBody(ctx *gin.Context) bool {
  163. // 检查内容类型
  164. contentType := ctx.Writer.Header().Get("Content-Type")
  165. return strings.Contains(contentType, "json") ||
  166. strings.Contains(contentType, "xml") ||
  167. strings.Contains(contentType, "text")
  168. }
  169. func getRequestBody(ctx *gin.Context) string {
  170. if ctx.Request.Body == nil {
  171. return ""
  172. }
  173. bodyBytes, err := ctx.GetRawData()
  174. if err != nil {
  175. return ""
  176. }
  177. // 重置请求体
  178. ctx.Request.Body = io.NopCloser(bytes.NewBuffer(bodyBytes))
  179. // 检查大小
  180. if len(bodyBytes) == 0 {
  181. return ""
  182. }
  183. if len(bodyBytes) > MaxBodySize {
  184. return fmt.Sprintf("[TRUNCATED: %d bytes]", len(bodyBytes))
  185. }
  186. // 脱敏处理
  187. return maskSensitiveData(string(bodyBytes))
  188. }
  189. func maskSensitiveData(data string) string {
  190. result := data
  191. for _, field := range sensitiveFields {
  192. // 简单的JSON字段脱敏
  193. result = maskJSONField(result, field)
  194. // URL参数脱敏
  195. result = maskURLParam(result, field)
  196. }
  197. return result
  198. }
  199. func maskJSONField(data, field string) string {
  200. lowerData := strings.ToLower(data)
  201. lowerField := strings.ToLower(field)
  202. // 查找字段位置(不区分大小写)
  203. idx := strings.Index(lowerData, `"`+lowerField+`"`)
  204. if idx == -1 {
  205. idx = strings.Index(lowerData, `'`+lowerField+`'`)
  206. if idx == -1 {
  207. return data
  208. }
  209. }
  210. // 找到冒号位置
  211. colonIdx := strings.Index(data[idx:], ":")
  212. if colonIdx == -1 {
  213. return data
  214. }
  215. colonIdx += idx
  216. // 找到值的开始和结束位置
  217. valueStart := colonIdx + 1
  218. for valueStart < len(data) && (data[valueStart] == ' ' || data[valueStart] == '\t') {
  219. valueStart++
  220. }
  221. if valueStart >= len(data) {
  222. return data
  223. }
  224. // 判断值的类型
  225. var valueEnd int
  226. if data[valueStart] == '"' || data[valueStart] == '\'' {
  227. // 字符串值
  228. quote := data[valueStart]
  229. valueEnd = valueStart + 1
  230. for valueEnd < len(data) && data[valueEnd] != quote {
  231. if data[valueEnd] == '\\' {
  232. valueEnd++ // 跳过转义字符
  233. }
  234. valueEnd++
  235. }
  236. if valueEnd < len(data) {
  237. valueEnd++ // 包含结束引号
  238. }
  239. } else {
  240. // 非字符串值(数字、布尔值等)
  241. valueEnd = valueStart
  242. for valueEnd < len(data) && data[valueEnd] != ',' && data[valueEnd] != '}' && data[valueEnd] != ']' && data[valueEnd] != '\n' && data[valueEnd] != '\r' {
  243. valueEnd++
  244. }
  245. }
  246. // 替换为脱敏值
  247. return data[:valueStart] + `"***"` + data[valueEnd:]
  248. }
  249. func maskURLParam(data, param string) string {
  250. lowerData := strings.ToLower(data)
  251. lowerParam := strings.ToLower(param)
  252. // 查找参数位置
  253. idx := strings.Index(lowerData, lowerParam+"=")
  254. if idx == -1 {
  255. return data
  256. }
  257. // 确保是参数开始位置(前面是?或&)
  258. if idx > 0 && data[idx-1] != '?' && data[idx-1] != '&' && data[idx-1] != ' ' && data[idx-1] != '\n' {
  259. return data
  260. }
  261. // 找到参数值结束位置
  262. valueStart := idx + len(param) + 1
  263. valueEnd := valueStart
  264. for valueEnd < len(data) && data[valueEnd] != '&' && data[valueEnd] != ' ' && data[valueEnd] != '\n' && data[valueEnd] != '\r' {
  265. valueEnd++
  266. }
  267. // 替换为脱敏值
  268. return data[:valueStart] + "***" + data[valueEnd:]
  269. }