feat: LicenseGuard 中间件 + Flutter license model/repo (21D+21E)

21D — 后端:
- Claims 新增 LicenseExpiresAt (*int64 unix 秒),写入 JWT 避免每次查库
- middleware/license_guard.go: CalcLicensePhase / LicenseGuard / GetLicensePhase
  - grace(0-7d): 允许通行
  - readonly(7-15d): 拦截非 GET 写操作 → 403
  - locked(15d+): 全部拦截 → 403
- auth.go: issueTokens 在 JWT 中嵌入 license expires_at;Login 检查 locked 拒绝登录
- router: license/* 路由豁免 LicenseGuard(锁定时仍可激活/查状态)

21E — Flutter 前端:
- models/license.dart: 新 LicenseInfo,含 phase/maxDevices,去掉旧 activatedAt
- core/device/device_id.dart: 持久化 UUID-v4 作为设备 ID(SharedPreferences)
- repositories/license_repository.dart: getInfo/activate/deactivate,激活时携带设备信息
- providers/license_provider.dart: 改接 LicenseRepository
- settings_screen.dart: activatedAt 改为显示 maxDevices

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
wangjia
2026-06-10 00:52:07 +08:00
parent c402ea0070
commit ebf79d0355
9 changed files with 307 additions and 76 deletions
+9 -6
View File
@@ -10,16 +10,18 @@ import (
)
type Claims struct {
UserID uint64 `json:"user_id"`
ShopID uint64 `json:"shop_id"`
Role string `json:"role"`
UserID uint64 `json:"user_id"`
ShopID uint64 `json:"shop_id"`
Role string `json:"role"`
LicenseExpiresAt *int64 `json:"lic_exp,omitempty"` // unix seconds; nil = perpetual
jwt.RegisteredClaims
}
const (
CtxUserID = "user_id"
CtxShopID = "shop_id"
CtxRole = "role"
CtxUserID = "user_id"
CtxShopID = "shop_id"
CtxRole = "role"
CtxLicenseExpiresAt = "lic_exp"
)
func JWT() gin.HandlerFunc {
@@ -43,6 +45,7 @@ func JWT() gin.HandlerFunc {
c.Set(CtxUserID, claims.UserID)
c.Set(CtxShopID, claims.ShopID)
c.Set(CtxRole, claims.Role)
c.Set(CtxLicenseExpiresAt, claims.LicenseExpiresAt)
c.Next()
}
}
@@ -0,0 +1,77 @@
package middleware
import (
"net/http"
"time"
"github.com/gin-gonic/gin"
)
const (
PhaseNormal = "normal"
PhaseGrace = "grace" // expired 07 days: writable, show banner
PhaseReadOnly = "readonly" // expired 715 days: read-only
PhaseLocked = "locked" // expired 15+ days: no login
)
var (
graceWindow = 7 * 24 * time.Hour
readOnlyWindow = 15 * 24 * time.Hour
)
// CalcLicensePhase computes the degradation phase based on expires_at.
// nil expiresAt = perpetual license = normal.
func CalcLicensePhase(expiresAt *time.Time) string {
if expiresAt == nil {
return PhaseNormal
}
elapsed := time.Since(*expiresAt)
if elapsed <= 0 {
return PhaseNormal
}
if elapsed <= graceWindow {
return PhaseGrace
}
if elapsed <= readOnlyWindow {
return PhaseReadOnly
}
return PhaseLocked
}
// GetLicensePhase returns the current phase for the authenticated request.
func GetLicensePhase(c *gin.Context) string {
v, _ := c.Get(CtxLicenseExpiresAt)
ptr, _ := v.(*int64)
if ptr == nil {
return PhaseNormal
}
t := time.Unix(*ptr, 0)
return CalcLicensePhase(&t)
}
// LicenseGuard blocks write operations when the shop's license is expired (readonly/locked).
// License routes (/license/*) must be mounted outside this middleware so users can
// view status and activate a new key even when locked.
func LicenseGuard() gin.HandlerFunc {
return func(c *gin.Context) {
phase := GetLicensePhase(c)
switch phase {
case PhaseLocked:
c.AbortWithStatusJSON(http.StatusForbidden, gin.H{
"error": "授权已锁定,请续费或激活新授权码",
"phase": PhaseLocked,
})
case PhaseReadOnly:
if c.Request.Method != http.MethodGet {
c.AbortWithStatusJSON(http.StatusForbidden, gin.H{
"error": "授权已过期,当前为只读模式",
"phase": PhaseReadOnly,
})
return
}
c.Next()
default:
c.Next()
}
}
}
+15 -10
View File
@@ -64,18 +64,23 @@ func Setup(r *gin.Engine, db *gorm.DB) {
public.POST("/register", authH.Register)
}
// 需要 JWT 的路由(ReadOnly 中间件:只读用户不可执行写操作)
// 需要 JWT 的基础路由组
api := v1.Group("")
api.Use(middleware.JWT(), middleware.ReadOnly())
api.Use(middleware.JWT())
// 许可证路由:豁免 LicenseGuard(锁定时仍需查看状态和激活)
license := api.Group("/license")
license.Use(middleware.ReadOnly())
{
// 许可证
license := api.Group("/license")
{
license.GET("/info", licenseH.Info)
license.POST("/activate", licenseH.Activate)
license.GET("/verify", licenseH.Verify)
license.POST("/deactivate", licenseH.Deactivate)
}
license.GET("/info", licenseH.Info)
license.POST("/activate", licenseH.Activate)
license.GET("/verify", licenseH.Verify)
license.POST("/deactivate", licenseH.Deactivate)
}
// 业务路由:ReadOnly + LicenseGuard(过期只读/锁定拦截写操作)
{
api.Use(middleware.ReadOnly(), middleware.LicenseGuard())
// 商品
products := api.Group("/products")
+34 -6
View File
@@ -18,6 +18,7 @@ import (
var (
ErrInvalidCredentials = errors.New("invalid username or password")
ErrUserInactive = errors.New("user is disabled")
ErrLicenseLocked = errors.New("license locked, please renew or contact support")
)
type AuthService struct {
@@ -56,6 +57,10 @@ func (s *AuthService) Login(shopCode, username, password string) (*TokenPair, *m
return nil, nil, ErrInvalidCredentials
}
if err := s.checkLicenseNotLocked(shop.ID); err != nil {
return nil, nil, err
}
pair, err := s.issueTokens(user.ID, shop.ID, user.Role)
if err != nil {
return nil, nil, err
@@ -153,15 +158,37 @@ func (s *AuthService) RefreshTokens(refreshToken string) (*TokenPair, error) {
return s.issueTokens(claims.UserID, claims.ShopID, claims.Role)
}
func (s *AuthService) checkLicenseNotLocked(shopID uint64) error {
var lic model.License
if err := s.db.Where("shop_id = ? AND is_active = 1", shopID).
Order("id DESC").First(&lic).Error; err != nil {
return nil // no license record → allow login
}
if middleware.CalcLicensePhase(lic.ExpiresAt) == middleware.PhaseLocked {
return ErrLicenseLocked
}
return nil
}
func (s *AuthService) issueTokens(userID, shopID uint64, role string) (*TokenPair, error) {
cfg := config.C.JWT
now := time.Now()
// Embed license expires_at in JWT so LicenseGuard can check phase without DB.
var licExpAt *int64
var lic model.License
if err := s.db.Where("shop_id = ? AND is_active = 1", shopID).
Order("id DESC").First(&lic).Error; err == nil && lic.ExpiresAt != nil {
ts := lic.ExpiresAt.Unix()
licExpAt = &ts
}
accessExp := now.Add(time.Duration(cfg.AccessExpireMin) * time.Minute)
accessClaims := middleware.Claims{
UserID: userID,
ShopID: shopID,
Role: role,
UserID: userID,
ShopID: shopID,
Role: role,
LicenseExpiresAt: licExpAt,
RegisteredClaims: jwt.RegisteredClaims{
ExpiresAt: jwt.NewNumericDate(accessExp),
IssuedAt: jwt.NewNumericDate(now),
@@ -174,9 +201,10 @@ func (s *AuthService) issueTokens(userID, shopID uint64, role string) (*TokenPai
refreshExp := now.Add(time.Duration(cfg.RefreshExpireH) * time.Hour)
refreshClaims := middleware.Claims{
UserID: userID,
ShopID: shopID,
Role: role,
UserID: userID,
ShopID: shopID,
Role: role,
LicenseExpiresAt: licExpAt,
RegisteredClaims: jwt.RegisteredClaims{
ExpiresAt: jwt.NewNumericDate(refreshExp),
IssuedAt: jwt.NewNumericDate(now),