feat(server): web 用户中心后端(1/3) — GetMe 补字段 + logout + redeem 路径别名 + 用户表 totp/sub_token

为 web 用户中心接通真后端做准备(保持 snake_case 不破 app):
- migration 000013:users 加 sub_token / totp_secret_enc / totp_enabled。
- GetMe 扩展:补 devices_used/devices_max/quota_today_min/data_today_gb/
  weekly_gb/totp_enabled/expires_at(聚合 plans+usage_daily+devices+totp 列),
  保留原 expire_at 等字段不破 app。
- POST /v1/auth/logout:X-Refresh-Token 头 → RevokeRefresh,幂等 204。
- /v1/me/redeem 别名(web 用),保留 /v1/redeem(app 用)。

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
wangjia
2026-06-17 08:35:09 +08:00
parent caeef20df3
commit 009dbb8d07
7 changed files with 150 additions and 22 deletions
+10
View File
@@ -28,6 +28,16 @@ func (h *Handler) RegisterRoutes(r chi.Router) {
r.Post("/auth/register", h.Register)
r.Post("/auth/login", h.Login)
r.Post("/auth/refresh", h.Refresh)
r.Post("/auth/logout", h.Logout)
}
// Logout handles POST /v1/auth/logout. The refresh token to revoke is taken from
// the X-Refresh-Token header (the access token in Authorization is not enough —
// revocation keys on the refresh JTI). Always 204; the client clears its session
// regardless of the server-side outcome.
func (h *Handler) Logout(w http.ResponseWriter, r *http.Request) {
h.svc.Logout(r.Context(), r.Header.Get("X-Refresh-Token"))
w.WriteHeader(http.StatusNoContent)
}
// ---- request/response bodies (mirror openapi.yaml) ----