feat(server/devices): 设备管理 + 订阅校验中间件 (tsk_x7wrlA87orsY)
实现 server/internal/devices 模块:
- handler.go: GET /v1/me/devices 列表、DELETE /v1/me/devices/{id} 移除
(chi 路由,挂在 /v1/me 下;JWT 中间件之后)。
- service.go: ListDevices / RegisterIfAbsent(隐式登记,按 plan.max_devices
校验,超限返回双语 DEVICE_LIMIT_EXCEEDED 含上限数字)/ DeleteDevice(事务硬删
+ audit_log → 调 CredentialRevoker.RevokeForUser 按用户回收凭证,dp_uuid 模型)
/ SubscriptionSummary / ResolvePlan / 纯函数 resolveEffectivePlan。
- middleware.go: 订阅校验中间件,解析最高档未过期订阅注入 context;
helpers PlanFromCtx / CheckDeviceQuota / RequirePaidTier;预留 60s Redis 缓存开关。
- store.go: devices/users/subscriptions/plans/audit_log 数据访问,按用户行锁串行化登记。
- context.go: user_id / plan 的 context key 与 helper。
- CredentialRevoker 接口(消费侧定义,避免与 nodes 循环依赖)+ NoopRevoker,
形状对齐 #5 的 Hub.Push(RevokeCredential),#5 落地前注入 no-op。
测试:service_test.go 15 个单测(trial→pro、过期回落 free、banned 拒绝、
最高档/同档最晚到期、UTC 严格边界、设备配额、双语限额、平台/名称归一化)全过;
devices_integration_test.go(testcontainers,build tag integration)覆盖
注册→connect 隐式登记→list→delete 全链路 + 回收断言 + 403/404。
apierr 增加 Unauthorized/Forbidden/NotFound/AccountBanned;
OpenAPI SubscriptionInfo.source 枚举补 free。
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,102 @@
|
||||
package devices
|
||||
|
||||
import (
|
||||
"net/http"
|
||||
"time"
|
||||
|
||||
"github.com/redis/go-redis/v9"
|
||||
"github.com/wangjia/pangolin/server/internal/apierr"
|
||||
)
|
||||
|
||||
// Middleware resolves the caller's effective subscription and injects it into
|
||||
// the request context. It MUST run after the JWT auth middleware (module #2),
|
||||
// which is responsible for setting CtxKeyUserID.
|
||||
type Middleware struct {
|
||||
svc *Service
|
||||
|
||||
// rdb and cacheTTL reserve a future 60s per-user plan cache. When cacheTTL
|
||||
// > 0 and rdb != nil the resolved plan could be cached under
|
||||
// "sub:plan:<userID>"; this is intentionally left disabled (cacheTTL == 0)
|
||||
// for the initial direct-DB implementation (subscription volume is low).
|
||||
// NOTE: a cache must not mask account bans — ban status would need a
|
||||
// separate, uncached check before serving any cached plan.
|
||||
rdb *redis.Client
|
||||
cacheTTL time.Duration
|
||||
}
|
||||
|
||||
// NewMiddleware creates the subscription-resolving middleware. Pass rdb=nil and
|
||||
// cacheTTL=0 to use the direct-DB path (current default).
|
||||
func NewMiddleware(svc *Service, rdb *redis.Client, cacheTTL time.Duration) *Middleware {
|
||||
return &Middleware{svc: svc, rdb: rdb, cacheTTL: cacheTTL}
|
||||
}
|
||||
|
||||
// Handler is the net/http middleware. It writes a JSON apierr and stops the
|
||||
// chain on failure (missing user / banned / internal error); otherwise it
|
||||
// injects the resolved Plan and calls next.
|
||||
func (m *Middleware) Handler(next http.Handler) http.Handler {
|
||||
return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
||||
userID, ok := UserIDFromContext(r.Context())
|
||||
if !ok {
|
||||
apierr.WriteJSON(w, http.StatusUnauthorized, apierr.ErrUnauthorized)
|
||||
return
|
||||
}
|
||||
|
||||
plan, apiErr := m.svc.ResolvePlan(r.Context(), userID)
|
||||
if apiErr != nil {
|
||||
apierr.WriteJSON(w, StatusForError(apiErr), apiErr)
|
||||
return
|
||||
}
|
||||
|
||||
ctx := WithPlan(r.Context(), plan)
|
||||
next.ServeHTTP(w, r.WithContext(ctx))
|
||||
})
|
||||
}
|
||||
|
||||
// --------------------------------------------------------------------------
|
||||
// Helpers consumed by other modules (nodes catalogue filtering / connect, etc.)
|
||||
// --------------------------------------------------------------------------
|
||||
|
||||
// CheckDeviceQuota returns a bilingual error when currentDevices already meets
|
||||
// or exceeds the plan's device cap, otherwise nil.
|
||||
func CheckDeviceQuota(p Plan, currentDevices int) *apierr.Error {
|
||||
if p.MaxDevices > 0 && currentDevices >= p.MaxDevices {
|
||||
return errDeviceLimit(p.MaxDevices)
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
// RequirePaidTier returns a 403 error when the plan is the free tier; nil for
|
||||
// pro/team. Used to gate paid-only nodes and features.
|
||||
func RequirePaidTier(p Plan) *apierr.Error {
|
||||
if planTier(p.PlanCode) < planTier("pro") {
|
||||
return &apierr.Error{
|
||||
Code: "PAID_TIER_REQUIRED",
|
||||
MessageZH: "该功能仅限付费会员,请升级后使用",
|
||||
MessageEn: "This feature requires a paid plan. Please upgrade to continue.",
|
||||
}
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
// StatusForError maps an apierr.Error code to an HTTP status code.
|
||||
func StatusForError(e *apierr.Error) int {
|
||||
if e == nil {
|
||||
return http.StatusOK
|
||||
}
|
||||
switch e.Code {
|
||||
case "UNAUTHORIZED":
|
||||
return http.StatusUnauthorized
|
||||
case "FORBIDDEN", "ACCOUNT_BANNED", "PAID_TIER_REQUIRED":
|
||||
return http.StatusForbidden
|
||||
case "NOT_FOUND":
|
||||
return http.StatusNotFound
|
||||
case "DEVICE_LIMIT_EXCEEDED":
|
||||
return http.StatusForbidden
|
||||
case "BAD_REQUEST":
|
||||
return http.StatusBadRequest
|
||||
case "INTERNAL_ERROR":
|
||||
return http.StatusInternalServerError
|
||||
default:
|
||||
return http.StatusBadRequest
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user