feat(server/devices): 设备管理 + 订阅校验中间件 (tsk_x7wrlA87orsY)
实现 server/internal/devices 模块:
- handler.go: GET /v1/me/devices 列表、DELETE /v1/me/devices/{id} 移除
(chi 路由,挂在 /v1/me 下;JWT 中间件之后)。
- service.go: ListDevices / RegisterIfAbsent(隐式登记,按 plan.max_devices
校验,超限返回双语 DEVICE_LIMIT_EXCEEDED 含上限数字)/ DeleteDevice(事务硬删
+ audit_log → 调 CredentialRevoker.RevokeForUser 按用户回收凭证,dp_uuid 模型)
/ SubscriptionSummary / ResolvePlan / 纯函数 resolveEffectivePlan。
- middleware.go: 订阅校验中间件,解析最高档未过期订阅注入 context;
helpers PlanFromCtx / CheckDeviceQuota / RequirePaidTier;预留 60s Redis 缓存开关。
- store.go: devices/users/subscriptions/plans/audit_log 数据访问,按用户行锁串行化登记。
- context.go: user_id / plan 的 context key 与 helper。
- CredentialRevoker 接口(消费侧定义,避免与 nodes 循环依赖)+ NoopRevoker,
形状对齐 #5 的 Hub.Push(RevokeCredential),#5 落地前注入 no-op。
测试:service_test.go 15 个单测(trial→pro、过期回落 free、banned 拒绝、
最高档/同档最晚到期、UTC 严格边界、设备配额、双语限额、平台/名称归一化)全过;
devices_integration_test.go(testcontainers,build tag integration)覆盖
注册→connect 隐式登记→list→delete 全链路 + 回收断言 + 403/404。
apierr 增加 Unauthorized/Forbidden/NotFound/AccountBanned;
OpenAPI SubscriptionInfo.source 枚举补 free。
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
@@ -1,5 +1,18 @@
|
||||
// Package devices manages user devices (name, platform, WireGuard public key).
|
||||
// It enforces per-plan device-count limits and coordinates with the nodes
|
||||
// package to revoke WireGuard peers when a device is removed or a
|
||||
// subscription expires.
|
||||
// Package devices manages user devices (uuid, name, platform, last_seen) and
|
||||
// owns subscription resolution for the rest of the API.
|
||||
//
|
||||
// Devices are registered implicitly on first connect (RegisterIfAbsent) and
|
||||
// removed via DELETE /v1/me/devices/{id}. Removal hard-deletes the row, writes
|
||||
// an audit_log entry, and triggers per-user data-plane credential recall
|
||||
// through the CredentialRevoker interface (satisfied by nodes.Hub in module #5).
|
||||
// Because the credential model is per-user (users.dp_uuid; the node side has no
|
||||
// device dimension, doc/02 §3.2), "revoke a device" is realised as recalling
|
||||
// the owning user's credential.
|
||||
//
|
||||
// SubscriptionMiddleware resolves the caller's highest-tier non-expired
|
||||
// subscription (falling back to the free plan) and injects the plan
|
||||
// {plan_code, expires_at, max_devices, daily_minutes, ad_gate} into the request
|
||||
// context, where nodes (catalogue filtering / connect) and usage (daily caps)
|
||||
// read it via PlanFromCtx. Plan numbers follow design/CLAUDE.md §7:
|
||||
// free 1 / pro 5 / team 10 devices.
|
||||
package devices
|
||||
|
||||
Reference in New Issue
Block a user