feat(devices): P2 sessions 表 + 在线/最后登录/客户端版本
ci-pangolin / Lint — shellcheck (push) Successful in 8s
ci-pangolin / OpenAPI Sync Check (push) Successful in 18s
ci-pangolin / Redline Scan — 脱敏 (UI 文案) (push) Successful in 6s
ci-pangolin / Flutter — analyze + test (push) Successful in 24s
ci-pangolin / Portable SQL — 可移植性 (mysql/sqlite) (push) Successful in 5s
ci-pangolin / Codegen Drift — token 生成物未漂移 (push) Successful in 4s
ci-pangolin / Go — build + test (push) Successful in 11s
ci-pangolin / E2E Smoke — L4 进程级端到端 (push) Successful in 14s
ci-pangolin / Go — integration (mysql/redis testcontainers) (push) Failing after 4m13s
ci-pangolin / Golden — 视觉回归 (components + auth) (push) Successful in 14s
ci-pangolin / Lint — shellcheck (push) Successful in 8s
ci-pangolin / OpenAPI Sync Check (push) Successful in 18s
ci-pangolin / Redline Scan — 脱敏 (UI 文案) (push) Successful in 6s
ci-pangolin / Flutter — analyze + test (push) Successful in 24s
ci-pangolin / Portable SQL — 可移植性 (mysql/sqlite) (push) Successful in 5s
ci-pangolin / Codegen Drift — token 生成物未漂移 (push) Successful in 4s
ci-pangolin / Go — build + test (push) Successful in 11s
ci-pangolin / E2E Smoke — L4 进程级端到端 (push) Successful in 14s
ci-pangolin / Go — integration (mysql/redis testcontainers) (push) Failing after 4m13s
ci-pangolin / Golden — 视觉回归 (components + auth) (push) Successful in 14s
migration 000016(mysql+sqlite,含 down):新增 sessions 表(绑 device+refresh JTI) + devices 加 client_version/totp_trusted_until。devices 唯一键改 + platform CHECK 加 linux(需 SQLite 表重建)拆出后续迁移,降风险。 后端:新 internal/sessions Store(Create/Rotate/Revoke/RevokeByDevice/ LastLoginByDevice);TokenManager 外露 refresh JTI(IssueWithJTI/RefreshWithJTI/ ParseRefreshJTI);auth.Service 注入 SessionStore——登录建会话、刷新轮换、登出吊销; DeviceRegistrar 返回 deviceID;ReportUsage 心跳 touch devices.last_seen(在线判定); devices.ListDevices 经 LastLoginSource 注入返回 online(last_seen<3min)/client_version/ last_login;RegisterIfAbsent 存 client_version。 客户端:Device model 加 online/clientVersion/lastLogin(fromJson 自动解析)。 测试:sessions store 3 例 + ListDevices 在线/最后登录 + device model 2 例 + migration v16;全量 go test/flutter test 绿。 Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
+19
-10
@@ -39,6 +39,7 @@ import (
|
||||
"github.com/wangjia/pangolin/server/internal/redisutil"
|
||||
"github.com/wangjia/pangolin/server/internal/scheduler"
|
||||
"github.com/wangjia/pangolin/server/internal/scheduler/probe"
|
||||
"github.com/wangjia/pangolin/server/internal/sessions"
|
||||
"github.com/wangjia/pangolin/server/internal/usage"
|
||||
)
|
||||
|
||||
@@ -243,6 +244,11 @@ func mountV1(r chi.Router, sqlDB *sql.DB, rdb *redis.Client, nodeSvc *nodes.Serv
|
||||
devicesSvc := devices.NewService(devicesStore, nil) // NoopRevoker for MVP
|
||||
devicesHandler := devices.NewHandler(devicesSvc)
|
||||
|
||||
// Sessions: login sessions bound to (device, refresh JTI) — P2. Shared by
|
||||
// auth (create/rotate/revoke) and devices (last-login display).
|
||||
sessionStore := sessions.NewStore(sqlDB)
|
||||
devicesSvc.SetLastLoginSource(sessionStore)
|
||||
|
||||
// ── Auth ──────────────────────────────────────────────────────────────────
|
||||
var authHandler *auth.Handler
|
||||
if tm != nil {
|
||||
@@ -262,6 +268,7 @@ func mountV1(r chi.Router, sqlDB *sql.DB, rdb *redis.Client, nodeSvc *nodes.Serv
|
||||
authStore := auth.NewSQLStore(sqlDB)
|
||||
authSvc := auth.NewService(authStore, rdb, rl, tm, mailer, auth.ServiceConfig{}, nil)
|
||||
authSvc.SetDeviceRegistrar(authDeviceRegistrar{svc: devicesSvc})
|
||||
authSvc.SetSessionStore(sessionStore)
|
||||
authHandler = auth.NewHandler(authSvc)
|
||||
}
|
||||
|
||||
@@ -509,15 +516,17 @@ func intEnvDefault(key string, def int) int {
|
||||
// limiting is a separate future policy with its own UX.
|
||||
type authDeviceRegistrar struct{ svc *devices.Service }
|
||||
|
||||
func (a authDeviceRegistrar) RegisterDevice(ctx context.Context, userID int64, meta auth.DeviceMeta) error {
|
||||
if _, apiErr := a.svc.RegisterIfAbsent(ctx, devices.RegisterInput{
|
||||
UserID: userID,
|
||||
DeviceUUID: meta.DeviceID,
|
||||
Name: meta.Name,
|
||||
Platform: meta.Platform,
|
||||
MaxDevices: 0,
|
||||
}); apiErr != nil {
|
||||
return apiErr
|
||||
func (a authDeviceRegistrar) RegisterDevice(ctx context.Context, userID int64, meta auth.DeviceMeta) (int64, error) {
|
||||
id, _, apiErr := a.svc.RegisterIfAbsent(ctx, devices.RegisterInput{
|
||||
UserID: userID,
|
||||
DeviceUUID: meta.DeviceID,
|
||||
Name: meta.Name,
|
||||
Platform: meta.Platform,
|
||||
ClientVersion: meta.ClientVersion,
|
||||
MaxDevices: 0,
|
||||
})
|
||||
if apiErr != nil {
|
||||
return 0, apiErr
|
||||
}
|
||||
return nil
|
||||
return id, nil
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user