feat(devices): P1 设备注册打通 —— 登录/注册即写 devices 表
ci-pangolin / Lint — shellcheck (push) Successful in 8s
ci-pangolin / OpenAPI Sync Check (push) Successful in 16s
ci-pangolin / Redline Scan — 脱敏 (UI 文案) (push) Successful in 7s
ci-pangolin / Flutter — analyze + test (push) Successful in 26s
ci-pangolin / Portable SQL — 可移植性 (mysql/sqlite) (push) Successful in 5s
ci-pangolin / Codegen Drift — token 生成物未漂移 (push) Successful in 5s
ci-pangolin / Go — build + test (push) Failing after 10s
ci-pangolin / E2E Smoke — L4 进程级端到端 (push) Successful in 15s
ci-pangolin / Go — integration (mysql/redis testcontainers) (push) Failing after 4m10s
ci-pangolin / Golden — 视觉回归 (components + auth) (push) Successful in 14s

后端:auth.Service 加 DeviceMeta + DeviceRegistrar 接口(consumer-side 解耦),
Login/Register 成功签发后 best-effort 注册设备(不强制设备上限,避免免费档重装
churn 锁死用户);handler 加 device 请求体;main 用 authDeviceRegistrar 适配
devices.Service 注入;normalizePlatform 加 linux。
客户端:新 device_identity.dart(SecureKV 接缝 + 稳定 UUIDv4 device_id 持久化 +
名称/平台/版本);弃用硬编码 'mac-001';auth_api login/register + connect 携带
device 元数据。加 uuid + device_info_plus 依赖。
测试:auth 设备注册(触发/best-effort/空 meta) + device_identity(生成/持久/
读失败不重生成/UUIDv4 形态);normalizePlatform linux=true。

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
wangjia
2026-06-29 00:28:13 +08:00
parent 889cff4556
commit c0c4b94e29
18 changed files with 498 additions and 96 deletions
+27 -5
View File
@@ -237,6 +237,12 @@ func mountV1(r chi.Router, sqlDB *sql.DB, rdb *redis.Client, nodeSvc *nodes.Serv
log.Printf("JWT not configured — /v1 protected routes will be unavailable")
}
// ── Devices ───────────────────────────────────────────────────────────────
// Constructed before Auth so login/register can register the device.
devicesStore := devices.NewStore(sqlDB)
devicesSvc := devices.NewService(devicesStore, nil) // NoopRevoker for MVP
devicesHandler := devices.NewHandler(devicesSvc)
// ── Auth ──────────────────────────────────────────────────────────────────
var authHandler *auth.Handler
if tm != nil {
@@ -255,6 +261,7 @@ func mountV1(r chi.Router, sqlDB *sql.DB, rdb *redis.Client, nodeSvc *nodes.Serv
rl := auth.NewRateLimiter(rdb, nil)
authStore := auth.NewSQLStore(sqlDB)
authSvc := auth.NewService(authStore, rdb, rl, tm, mailer, auth.ServiceConfig{}, nil)
authSvc.SetDeviceRegistrar(authDeviceRegistrar{svc: devicesSvc})
authHandler = auth.NewHandler(authSvc)
}
@@ -277,11 +284,6 @@ func mountV1(r chi.Router, sqlDB *sql.DB, rdb *redis.Client, nodeSvc *nodes.Serv
webhookHandler := codes.NewWebhookHandler(codesStore, rdb,
os.Getenv("WEBHOOK_SECRET"), 5*time.Minute, 15*time.Minute)
// ── Devices ───────────────────────────────────────────────────────────────
devicesStore := devices.NewStore(sqlDB)
devicesSvc := devices.NewService(devicesStore, nil) // NoopRevoker for MVP
devicesHandler := devices.NewHandler(devicesSvc)
// ── Usage ─────────────────────────────────────────────────────────────────
usageStore := usage.NewStore(sqlDB)
usageSvc := usage.NewService(usageStore, rdb, nil, time.Hour)
@@ -499,3 +501,23 @@ func intEnvDefault(key string, def int) int {
}
return n
}
// authDeviceRegistrar adapts devices.Service to auth.DeviceRegistrar, keeping the
// auth and devices packages decoupled. Device registration on login/register is
// best-effort with NO cap enforcement (MaxDevices=0): free-plan reinstall churns
// the device UUID, so a hard cap at login would lock users out. Explicit device
// limiting is a separate future policy with its own UX.
type authDeviceRegistrar struct{ svc *devices.Service }
func (a authDeviceRegistrar) RegisterDevice(ctx context.Context, userID int64, meta auth.DeviceMeta) error {
if _, apiErr := a.svc.RegisterIfAbsent(ctx, devices.RegisterInput{
UserID: userID,
DeviceUUID: meta.DeviceID,
Name: meta.Name,
Platform: meta.Platform,
MaxDevices: 0,
}); apiErr != nil {
return apiErr
}
return nil
}
+27
View File
@@ -0,0 +1,27 @@
// tmphash — 一次性:按服务端 argon2id 参数算密码 hash(临时,不提交)。
package main
import (
"crypto/rand"
"encoding/base64"
"fmt"
"os"
"golang.org/x/crypto/argon2"
)
func main() {
pw := "wangjia812"
if len(os.Args) > 1 {
pw = os.Args[1]
}
salt := make([]byte, 16)
if _, err := rand.Read(salt); err != nil {
panic(err)
}
key := argon2.IDKey([]byte(pw), salt, uint32(1), uint32(65536), uint8(4), uint32(32))
fmt.Printf("$argon2id$v=%d$m=%d,t=%d,p=%d$%s$%s\n",
argon2.Version, 65536, 1, 4,
base64.RawStdEncoding.EncodeToString(salt),
base64.RawStdEncoding.EncodeToString(key))
}