feat(usage): usage_daily 聚合 + 广告解锁 + free 额度校验 (tsk_1taxhtV2k3RP)
server/internal/usage 模块实现(仅字节/分钟,无目的地,符合无日志口径): - aggregator.go:实现 #5 的 ReportUsage 回调接口(UsageReporter), dp_uuid→user_id 走内存+Redis 短缓存,按上报批次 id Redis 去重防重放, 按 At 的 UTC 日期 INSERT ... ON DUPLICATE KEY UPDATE 累加,并发安全。 - store.go:usage_daily 累加/区间查询/当日查询、MarkAdUnlocked(事务+FOR UPDATE 幂等)、EffectivePlan(活跃订阅取最高 tier,无则回落 free)。 - ads.go:AdVerifier 接口 + AdMob SSV 实现(拉取并缓存 Google ECDSA 公钥, ECDSA-SHA256 验签 + custom_data/ad_unit 匹配),Unity 留接口占位。 - service.go:UsageCurve(空日补零、仅当前用户)、TodaySummary(/v1/me)、 UnlockAd(验签→ad_token 一次性 nonce 去重→写 ad_unlocked_at,当日二次幂等)。 - quota.go:CheckFreeConnect 供 #5 connect 使用:ad_gate=true 校验当日 ad_unlocked_at + minutes_used<daily_minutes(free=10),返回剩余分钟; pro/team 不受 ad_gate 限制(返回 Unlimited);带双语 code 错误。 - handler.go:GET /v1/usage?days=7、POST /v1/ads/unlock(204)。 - apierr:新增 AD_NOT_UNLOCKED/QUOTA_EXHAUSTED/AD_VERIFY_FAILED/AD_TOKEN_REPLAY。 - openapi:/ads/unlock 补 409 Conflict(重放)。 测试:ads_test.go 单测覆盖 AdMob 验签全链路(合法/伪造/custom_data 不符/ ad_unit 不允许/畸形 token)+ Unity 未实现;usage_integration_test.go (testcontainers, build tag integration) 覆盖并发多节点累加、批次重放去重、 跨 UTC 日界分桶、未知 dp_uuid 丢弃、free 额度四态、ads 解锁伪造/重放/幂等、 曲线补零/隔离、/me 摘要。 Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,176 @@
|
||||
package usage
|
||||
|
||||
import (
|
||||
"context"
|
||||
"crypto/sha256"
|
||||
"encoding/hex"
|
||||
"time"
|
||||
|
||||
"github.com/redis/go-redis/v9"
|
||||
"github.com/wangjia/pangolin/server/internal/apierr"
|
||||
)
|
||||
|
||||
// nowFunc is overridable in tests to pin "today".
|
||||
var nowFunc = time.Now
|
||||
|
||||
// utcToday returns the current UTC calendar date (time truncated).
|
||||
func utcToday() time.Time {
|
||||
n := nowFunc().UTC()
|
||||
return time.Date(n.Year(), n.Month(), n.Day(), 0, 0, 0, 0, time.UTC)
|
||||
}
|
||||
|
||||
// Service serves usage queries, the /v1/me usage summary, the ads-unlock flow,
|
||||
// and the free-plan connect quota check.
|
||||
type Service struct {
|
||||
store *Store
|
||||
rdb *redis.Client
|
||||
verifier AdVerifier
|
||||
adNonceTTL time.Duration
|
||||
}
|
||||
|
||||
// NewService builds a Service. rdb may be nil (ad-token replay protection is
|
||||
// then disabled — not recommended in production). verifier may be nil if the
|
||||
// ads-unlock endpoint is not mounted. adNonceTTL <= 0 defaults to 1h.
|
||||
func NewService(store *Store, rdb *redis.Client, verifier AdVerifier, adNonceTTL time.Duration) *Service {
|
||||
if adNonceTTL <= 0 {
|
||||
adNonceTTL = time.Hour
|
||||
}
|
||||
return &Service{store: store, rdb: rdb, verifier: verifier, adNonceTTL: adNonceTTL}
|
||||
}
|
||||
|
||||
// UsagePoint is one day of the usage curve.
|
||||
type UsagePoint struct {
|
||||
Date string `json:"date"` // YYYY-MM-DD (UTC)
|
||||
BytesUp uint64 `json:"bytes_up"`
|
||||
BytesDown uint64 `json:"bytes_down"`
|
||||
MinutesUsed int `json:"minutes_used"`
|
||||
}
|
||||
|
||||
// UsageCurve returns the last `days` daily points for userID (UTC), with
|
||||
// missing days zero-filled, oldest first. days is clamped to [1, 90].
|
||||
func (svc *Service) UsageCurve(ctx context.Context, userID int64, days int) ([]UsagePoint, *apierr.Error) {
|
||||
if days < 1 {
|
||||
days = 7
|
||||
}
|
||||
if days > 90 {
|
||||
days = 90
|
||||
}
|
||||
|
||||
today := utcToday()
|
||||
from := today.AddDate(0, 0, -(days - 1))
|
||||
|
||||
rows, err := svc.store.GetUsageRange(ctx, userID, from, today)
|
||||
if err != nil {
|
||||
return nil, apierr.ErrInternal
|
||||
}
|
||||
byDate := make(map[string]DailyUsage, len(rows))
|
||||
for _, r := range rows {
|
||||
byDate[r.Date.UTC().Format(dateLayout)] = r
|
||||
}
|
||||
|
||||
points := make([]UsagePoint, 0, days)
|
||||
for i := 0; i < days; i++ {
|
||||
d := from.AddDate(0, 0, i).Format(dateLayout)
|
||||
if u, ok := byDate[d]; ok {
|
||||
points = append(points, UsagePoint{
|
||||
Date: d,
|
||||
BytesUp: u.BytesUp,
|
||||
BytesDown: u.BytesDown,
|
||||
MinutesUsed: u.MinutesUsed,
|
||||
})
|
||||
} else {
|
||||
points = append(points, UsagePoint{Date: d})
|
||||
}
|
||||
}
|
||||
return points, nil
|
||||
}
|
||||
|
||||
// TodaySummary is the /v1/me today_usage block.
|
||||
type TodaySummary struct {
|
||||
MinutesUsed int `json:"minutes_used"`
|
||||
MinutesRemaining *int `json:"minutes_remaining"` // nil = unlimited (pro/team)
|
||||
AdUnlocked bool `json:"ad_unlocked"`
|
||||
}
|
||||
|
||||
// TodaySummary returns the current user's usage summary for today (UTC),
|
||||
// reflecting plan limits and ad-unlock state.
|
||||
func (svc *Service) TodaySummary(ctx context.Context, userID int64) (*TodaySummary, *apierr.Error) {
|
||||
plan, err := svc.store.EffectivePlan(ctx, userID)
|
||||
if err != nil {
|
||||
return nil, apierr.ErrInternal
|
||||
}
|
||||
day, err := svc.store.GetDay(ctx, userID, utcToday())
|
||||
if err != nil {
|
||||
return nil, apierr.ErrInternal
|
||||
}
|
||||
|
||||
used := 0
|
||||
adUnlocked := false
|
||||
if day != nil {
|
||||
used = day.MinutesUsed
|
||||
adUnlocked = day.AdUnlockedAt.Valid
|
||||
}
|
||||
|
||||
out := &TodaySummary{MinutesUsed: used, AdUnlocked: adUnlocked}
|
||||
if plan.DailyMinutes.Valid {
|
||||
remaining := int(plan.DailyMinutes.Int64) - used
|
||||
if remaining < 0 {
|
||||
remaining = 0
|
||||
}
|
||||
out.MinutesRemaining = &remaining
|
||||
}
|
||||
return out, nil
|
||||
}
|
||||
|
||||
// UnlockAd verifies a rewarded-ad receipt and records the day's ad-unlock.
|
||||
//
|
||||
// Flow: validate inputs → verify the receipt with the ad network → consume the
|
||||
// ad_token as a one-time nonce (replay-protected) → set ad_unlocked_at. A
|
||||
// second unlock on a day already unlocked is idempotent (alreadyUnlocked=true).
|
||||
func (svc *Service) UnlockAd(ctx context.Context, userID int64, deviceID, adToken string) (alreadyUnlocked bool, apiErr *apierr.Error) {
|
||||
if deviceID == "" || adToken == "" {
|
||||
return false, apierr.ErrBadRequest
|
||||
}
|
||||
if svc.verifier == nil {
|
||||
return false, apierr.ErrInternal
|
||||
}
|
||||
|
||||
// 1. Authenticate the receipt with the ad network.
|
||||
if err := svc.verifier.Verify(ctx, AdVerifyRequest{
|
||||
UserID: userID,
|
||||
DeviceID: deviceID,
|
||||
AdToken: adToken,
|
||||
}); err != nil {
|
||||
return false, apierr.ErrAdVerifyFailed
|
||||
}
|
||||
|
||||
// 2. One-time nonce: a genuine receipt may only be redeemed once.
|
||||
if dup, err := svc.consumeAdNonce(ctx, adToken); err != nil {
|
||||
return false, apierr.ErrInternal
|
||||
} else if dup {
|
||||
return false, apierr.ErrAdReplay
|
||||
}
|
||||
|
||||
// 3. Record the unlock (idempotent per UTC day).
|
||||
already, err := svc.store.MarkAdUnlocked(ctx, userID, utcToday())
|
||||
if err != nil {
|
||||
return false, apierr.ErrInternal
|
||||
}
|
||||
return already, nil
|
||||
}
|
||||
|
||||
// consumeAdNonce atomically records the ad_token so it cannot be reused.
|
||||
// Returns dup=true if the token was already consumed. No-ops (dup=false) when
|
||||
// Redis is not configured.
|
||||
func (svc *Service) consumeAdNonce(ctx context.Context, adToken string) (bool, error) {
|
||||
if svc.rdb == nil {
|
||||
return false, nil
|
||||
}
|
||||
sum := sha256.Sum256([]byte(adToken))
|
||||
key := "ads:nonce:" + hex.EncodeToString(sum[:])
|
||||
set, err := svc.rdb.SetNX(ctx, key, "1", svc.adNonceTTL).Result()
|
||||
if err != nil {
|
||||
return false, err
|
||||
}
|
||||
return !set, nil
|
||||
}
|
||||
Reference in New Issue
Block a user