feat(devices): P1 设备注册打通 —— 登录/注册即写 devices 表
ci-pangolin / Lint — shellcheck (push) Successful in 8s
ci-pangolin / OpenAPI Sync Check (push) Successful in 16s
ci-pangolin / Redline Scan — 脱敏 (UI 文案) (push) Successful in 7s
ci-pangolin / Flutter — analyze + test (push) Successful in 26s
ci-pangolin / Portable SQL — 可移植性 (mysql/sqlite) (push) Successful in 5s
ci-pangolin / Codegen Drift — token 生成物未漂移 (push) Successful in 5s
ci-pangolin / Go — build + test (push) Failing after 10s
ci-pangolin / E2E Smoke — L4 进程级端到端 (push) Successful in 15s
ci-pangolin / Go — integration (mysql/redis testcontainers) (push) Failing after 4m10s
ci-pangolin / Golden — 视觉回归 (components + auth) (push) Successful in 14s
ci-pangolin / Lint — shellcheck (push) Successful in 8s
ci-pangolin / OpenAPI Sync Check (push) Successful in 16s
ci-pangolin / Redline Scan — 脱敏 (UI 文案) (push) Successful in 7s
ci-pangolin / Flutter — analyze + test (push) Successful in 26s
ci-pangolin / Portable SQL — 可移植性 (mysql/sqlite) (push) Successful in 5s
ci-pangolin / Codegen Drift — token 生成物未漂移 (push) Successful in 5s
ci-pangolin / Go — build + test (push) Failing after 10s
ci-pangolin / E2E Smoke — L4 进程级端到端 (push) Successful in 15s
ci-pangolin / Go — integration (mysql/redis testcontainers) (push) Failing after 4m10s
ci-pangolin / Golden — 视觉回归 (components + auth) (push) Successful in 14s
后端:auth.Service 加 DeviceMeta + DeviceRegistrar 接口(consumer-side 解耦), Login/Register 成功签发后 best-effort 注册设备(不强制设备上限,避免免费档重装 churn 锁死用户);handler 加 device 请求体;main 用 authDeviceRegistrar 适配 devices.Service 注入;normalizePlatform 加 linux。 客户端:新 device_identity.dart(SecureKV 接缝 + 稳定 UUIDv4 device_id 持久化 + 名称/平台/版本);弃用硬编码 'mac-001';auth_api login/register + connect 携带 device 元数据。加 uuid + device_info_plus 依赖。 测试:auth 设备注册(触发/best-effort/空 meta) + device_identity(生成/持久/ 读失败不重生成/UUIDv4 形态);normalizePlatform linux=true。 Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
@@ -237,6 +237,12 @@ func mountV1(r chi.Router, sqlDB *sql.DB, rdb *redis.Client, nodeSvc *nodes.Serv
|
||||
log.Printf("JWT not configured — /v1 protected routes will be unavailable")
|
||||
}
|
||||
|
||||
// ── Devices ───────────────────────────────────────────────────────────────
|
||||
// Constructed before Auth so login/register can register the device.
|
||||
devicesStore := devices.NewStore(sqlDB)
|
||||
devicesSvc := devices.NewService(devicesStore, nil) // NoopRevoker for MVP
|
||||
devicesHandler := devices.NewHandler(devicesSvc)
|
||||
|
||||
// ── Auth ──────────────────────────────────────────────────────────────────
|
||||
var authHandler *auth.Handler
|
||||
if tm != nil {
|
||||
@@ -255,6 +261,7 @@ func mountV1(r chi.Router, sqlDB *sql.DB, rdb *redis.Client, nodeSvc *nodes.Serv
|
||||
rl := auth.NewRateLimiter(rdb, nil)
|
||||
authStore := auth.NewSQLStore(sqlDB)
|
||||
authSvc := auth.NewService(authStore, rdb, rl, tm, mailer, auth.ServiceConfig{}, nil)
|
||||
authSvc.SetDeviceRegistrar(authDeviceRegistrar{svc: devicesSvc})
|
||||
authHandler = auth.NewHandler(authSvc)
|
||||
}
|
||||
|
||||
@@ -277,11 +284,6 @@ func mountV1(r chi.Router, sqlDB *sql.DB, rdb *redis.Client, nodeSvc *nodes.Serv
|
||||
webhookHandler := codes.NewWebhookHandler(codesStore, rdb,
|
||||
os.Getenv("WEBHOOK_SECRET"), 5*time.Minute, 15*time.Minute)
|
||||
|
||||
// ── Devices ───────────────────────────────────────────────────────────────
|
||||
devicesStore := devices.NewStore(sqlDB)
|
||||
devicesSvc := devices.NewService(devicesStore, nil) // NoopRevoker for MVP
|
||||
devicesHandler := devices.NewHandler(devicesSvc)
|
||||
|
||||
// ── Usage ─────────────────────────────────────────────────────────────────
|
||||
usageStore := usage.NewStore(sqlDB)
|
||||
usageSvc := usage.NewService(usageStore, rdb, nil, time.Hour)
|
||||
@@ -499,3 +501,23 @@ func intEnvDefault(key string, def int) int {
|
||||
}
|
||||
return n
|
||||
}
|
||||
|
||||
// authDeviceRegistrar adapts devices.Service to auth.DeviceRegistrar, keeping the
|
||||
// auth and devices packages decoupled. Device registration on login/register is
|
||||
// best-effort with NO cap enforcement (MaxDevices=0): free-plan reinstall churns
|
||||
// the device UUID, so a hard cap at login would lock users out. Explicit device
|
||||
// limiting is a separate future policy with its own UX.
|
||||
type authDeviceRegistrar struct{ svc *devices.Service }
|
||||
|
||||
func (a authDeviceRegistrar) RegisterDevice(ctx context.Context, userID int64, meta auth.DeviceMeta) error {
|
||||
if _, apiErr := a.svc.RegisterIfAbsent(ctx, devices.RegisterInput{
|
||||
UserID: userID,
|
||||
DeviceUUID: meta.DeviceID,
|
||||
Name: meta.Name,
|
||||
Platform: meta.Platform,
|
||||
MaxDevices: 0,
|
||||
}); apiErr != nil {
|
||||
return apiErr
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
@@ -0,0 +1,27 @@
|
||||
// tmphash — 一次性:按服务端 argon2id 参数算密码 hash(临时,不提交)。
|
||||
package main
|
||||
|
||||
import (
|
||||
"crypto/rand"
|
||||
"encoding/base64"
|
||||
"fmt"
|
||||
"os"
|
||||
|
||||
"golang.org/x/crypto/argon2"
|
||||
)
|
||||
|
||||
func main() {
|
||||
pw := "wangjia812"
|
||||
if len(os.Args) > 1 {
|
||||
pw = os.Args[1]
|
||||
}
|
||||
salt := make([]byte, 16)
|
||||
if _, err := rand.Read(salt); err != nil {
|
||||
panic(err)
|
||||
}
|
||||
key := argon2.IDKey([]byte(pw), salt, uint32(1), uint32(65536), uint8(4), uint32(32))
|
||||
fmt.Printf("$argon2id$v=%d$m=%d,t=%d,p=%d$%s$%s\n",
|
||||
argon2.Version, 65536, 1, 4,
|
||||
base64.RawStdEncoding.EncodeToString(salt),
|
||||
base64.RawStdEncoding.EncodeToString(key))
|
||||
}
|
||||
Reference in New Issue
Block a user