feat(devices): P3 强制退出 + 清除增强(per-device 凭证吊销)
ci-pangolin / Lint — shellcheck (push) Successful in 9s
ci-pangolin / OpenAPI Sync Check (push) Successful in 17s
ci-pangolin / Redline Scan — 脱敏 (UI 文案) (push) Successful in 5s
ci-pangolin / Flutter — analyze + test (push) Successful in 26s
ci-pangolin / Portable SQL — 可移植性 (mysql/sqlite) (push) Successful in 5s
ci-pangolin / Codegen Drift — token 生成物未漂移 (push) Successful in 5s
ci-pangolin / Go — build + test (push) Successful in 12s
ci-pangolin / E2E Smoke — L4 进程级端到端 (push) Successful in 15s
ci-pangolin / Go — integration (mysql/redis testcontainers) (push) Failing after 4m4s
ci-pangolin / Golden — 视觉回归 (components + auth) (push) Successful in 15s

后端:新端点 POST /v1/me/devices/{uuid}/logout(ForceLogout:吊销该设备会话+
丢 Redis JTI,设备留列表)。DeleteDevice 增强:先吊销会话再删设备(FK ON DELETE
CASCADE 清理会话行)+ 按 dp_uuid 吊销数据面凭证。CredentialRevoker 接口改
per-device RevokeDevice(dpUUID),由 nodes.Service 实现(查 connect_credentials
持有节点→推 CommandTypeRevoke + 删凭证行),main 注入替 NoopRevoker;devices 注入
SessionPort/JTIRevoker。修 SQLite 跨连接死锁(会话吊销移到 delete tx 之前)。
migration 000016 sessions FK 加 ON DELETE CASCADE。
客户端:account_api.forceLogout + devicesProvider.forceLogout(UI 留 P6)。
测试:ForceLogout(吊销会话+JTI+设备保留+403/404)+ DeleteDevice(级联+按 dp_uuid
吊销);NoopRevoker 改 dp_uuid;全量 server/flutter 测试绿。

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
wangjia
2026-06-29 06:01:41 +08:00
parent 2f298f0a0a
commit bcc114088c
16 changed files with 325 additions and 74 deletions
+6 -1
View File
@@ -56,9 +56,14 @@ class AccountApi {
return raw.map((e) => Device.fromJson(e as Map<String, dynamic>)).toList();
}
/// DELETE /v1/me/devices/{uuid} — 移除设备
/// DELETE /v1/me/devices/{uuid} — 清除登录信息(移除设备 + 吊销会话/凭证)
Future<void> removeDevice(String uuid) => _c.delete('/v1/me/devices/$uuid');
/// POST /v1/me/devices/{uuid}/logout — 强制退出(吊销该设备会话,设备留列表)。
Future<void> forceLogout(String uuid) async {
await _c.postJson('/v1/me/devices/$uuid/logout');
}
/// GET /v1/usage?days=N — 最近 N 天用量(默认 7,后端范围 [1,90])。
Future<List<UsagePoint>> usage({int days = 7}) async {
final body = await _c.getJson('/v1/usage?days=$days');
+8 -1
View File
@@ -79,12 +79,19 @@ class DevicesNotifier extends AsyncNotifier<List<Device>> {
return ref.read(accountApiProvider).devices();
}
/// 移除设备(DELETE)后刷新列表。
/// 清除登录信息(DELETE:移除设备 + 吊销会话/凭证)后刷新列表。
Future<void> remove(String uuid) async {
await ref.read(accountApiProvider).removeDevice(uuid);
ref.invalidateSelf();
await future;
}
/// 强制退出(吊销该设备会话,设备保留)后刷新列表。
Future<void> forceLogout(String uuid) async {
await ref.read(accountApiProvider).forceLogout(uuid);
ref.invalidateSelf();
await future;
}
}
final devicesProvider =