LogService.php 6.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219
  1. <?php
  2. namespace App\Module\OpenAPI\Services;
  3. use App\Module\OpenAPI\Models\OpenApiLog;
  4. use Illuminate\Http\Request;
  5. use Illuminate\Support\Str;
  6. /**
  7. * OpenAPI日志服务
  8. *
  9. * 负责记录和管理API调用日志
  10. */
  11. class LogService
  12. {
  13. /**
  14. * 记录API调用日志
  15. *
  16. * @param string $appId
  17. * @param Request $request
  18. * @param array $response
  19. * @param int $responseTime 响应时间(毫秒)
  20. * @param string|null $errorMessage
  21. * @return OpenApiLog
  22. */
  23. public function logApiCall(
  24. string $appId,
  25. Request $request,
  26. array $response,
  27. int $responseTime,
  28. ?string $errorMessage = null
  29. ): OpenApiLog {
  30. return OpenApiLog::create([
  31. 'app_id' => $appId,
  32. 'request_id' => $this->generateRequestId(),
  33. 'method' => $request->getMethod(),
  34. 'uri' => $request->getRequestUri(),
  35. 'headers' => $this->sanitizeHeaders($request->headers->all()),
  36. 'query_params' => $request->query->all(),
  37. 'body' => $this->sanitizeBody($request->getContent()),
  38. 'response_status' => $response['status'] ?? 200,
  39. 'response_headers' => $response['headers'] ?? [],
  40. 'response_body' => $this->sanitizeResponseBody($response['body'] ?? ''),
  41. 'response_time' => $responseTime,
  42. 'ip_address' => $request->ip(),
  43. 'user_agent' => $request->userAgent(),
  44. 'error_message' => $errorMessage,
  45. ]);
  46. }
  47. /**
  48. * 记录认证失败日志
  49. *
  50. * @param Request $request
  51. * @param string $reason
  52. * @return OpenApiLog
  53. */
  54. public function logAuthFailure(Request $request, string $reason): OpenApiLog
  55. {
  56. return OpenApiLog::create([
  57. 'app_id' => 'UNKNOWN',
  58. 'request_id' => $this->generateRequestId(),
  59. 'method' => $request->getMethod(),
  60. 'uri' => $request->getRequestUri(),
  61. 'headers' => $this->sanitizeHeaders($request->headers->all()),
  62. 'query_params' => $request->query->all(),
  63. 'body' => $this->sanitizeBody($request->getContent()),
  64. 'response_status' => 401,
  65. 'response_headers' => [],
  66. 'response_body' => json_encode(['error' => 'unauthorized', 'message' => $reason]),
  67. 'response_time' => 0,
  68. 'ip_address' => $request->ip(),
  69. 'user_agent' => $request->userAgent(),
  70. 'error_message' => "认证失败: {$reason}",
  71. ]);
  72. }
  73. /**
  74. * 记录限流日志
  75. *
  76. * @param string $appId
  77. * @param Request $request
  78. * @param string $limitType
  79. * @return OpenApiLog
  80. */
  81. public function logRateLimit(string $appId, Request $request, string $limitType): OpenApiLog
  82. {
  83. return OpenApiLog::create([
  84. 'app_id' => $appId,
  85. 'request_id' => $this->generateRequestId(),
  86. 'method' => $request->getMethod(),
  87. 'uri' => $request->getRequestUri(),
  88. 'headers' => $this->sanitizeHeaders($request->headers->all()),
  89. 'query_params' => $request->query->all(),
  90. 'body' => $this->sanitizeBody($request->getContent()),
  91. 'response_status' => 429,
  92. 'response_headers' => [],
  93. 'response_body' => json_encode(['error' => 'rate_limit_exceeded', 'message' => '请求频率超出限制']),
  94. 'response_time' => 0,
  95. 'ip_address' => $request->ip(),
  96. 'user_agent' => $request->userAgent(),
  97. 'error_message' => "限流触发: {$limitType}",
  98. ]);
  99. }
  100. /**
  101. * 获取应用的调用统计
  102. *
  103. * @param string $appId
  104. * @param string $period 统计周期:day, week, month
  105. * @return array
  106. */
  107. public function getAppStats(string $appId, string $period = 'day'): array
  108. {
  109. $startDate = match($period) {
  110. 'week' => now()->subWeek(),
  111. 'month' => now()->subMonth(),
  112. default => now()->subDay(),
  113. };
  114. $logs = OpenApiLog::where('app_id', $appId)
  115. ->where('created_at', '>=', $startDate)
  116. ->get();
  117. return [
  118. 'total_requests' => $logs->count(),
  119. 'successful_requests' => $logs->where('response_status', '>=', 200)->where('response_status', '<', 300)->count(),
  120. 'client_errors' => $logs->where('response_status', '>=', 400)->where('response_status', '<', 500)->count(),
  121. 'server_errors' => $logs->where('response_status', '>=', 500)->count(),
  122. 'avg_response_time' => $logs->avg('response_time'),
  123. 'max_response_time' => $logs->max('response_time'),
  124. 'min_response_time' => $logs->min('response_time'),
  125. ];
  126. }
  127. /**
  128. * 生成请求ID
  129. *
  130. * @return string
  131. */
  132. protected function generateRequestId(): string
  133. {
  134. return 'req_' . Str::random(16) . '_' . time();
  135. }
  136. /**
  137. * 清理请求头信息(移除敏感信息)
  138. *
  139. * @param array $headers
  140. * @return array
  141. */
  142. protected function sanitizeHeaders(array $headers): array
  143. {
  144. $sensitiveHeaders = [
  145. 'authorization',
  146. 'x-api-key',
  147. 'x-api-secret',
  148. 'cookie',
  149. 'set-cookie',
  150. ];
  151. $sanitized = [];
  152. foreach ($headers as $key => $value) {
  153. if (in_array(strtolower($key), $sensitiveHeaders)) {
  154. $sanitized[$key] = ['***REDACTED***'];
  155. } else {
  156. $sanitized[$key] = $value;
  157. }
  158. }
  159. return $sanitized;
  160. }
  161. /**
  162. * 清理请求体(移除敏感信息)
  163. *
  164. * @param string $body
  165. * @return string
  166. */
  167. protected function sanitizeBody(string $body): string
  168. {
  169. // 限制请求体大小
  170. if (strlen($body) > 10240) { // 10KB
  171. return substr($body, 0, 10240) . '...[TRUNCATED]';
  172. }
  173. // 如果是JSON,尝试移除敏感字段
  174. $decoded = json_decode($body, true);
  175. if (json_last_error() === JSON_ERROR_NONE && is_array($decoded)) {
  176. $sensitiveFields = ['password', 'secret', 'token', 'key'];
  177. foreach ($sensitiveFields as $field) {
  178. if (isset($decoded[$field])) {
  179. $decoded[$field] = '***REDACTED***';
  180. }
  181. }
  182. return json_encode($decoded);
  183. }
  184. return $body;
  185. }
  186. /**
  187. * 清理响应体
  188. *
  189. * @param string $body
  190. * @return string
  191. */
  192. protected function sanitizeResponseBody(string $body): string
  193. {
  194. // 限制响应体大小
  195. if (strlen($body) > 10240) { // 10KB
  196. return substr($body, 0, 10240) . '...[TRUNCATED]';
  197. }
  198. return $body;
  199. }
  200. }