Commit Graph

5 Commits

Author SHA1 Message Date
wangjia 87ccaecddf feat(server/devices): 设备管理 + 订阅校验中间件 (tsk_x7wrlA87orsY)
实现 server/internal/devices 模块:

- handler.go: GET /v1/me/devices 列表、DELETE /v1/me/devices/{id} 移除
  (chi 路由,挂在 /v1/me 下;JWT 中间件之后)。
- service.go: ListDevices / RegisterIfAbsent(隐式登记,按 plan.max_devices
  校验,超限返回双语 DEVICE_LIMIT_EXCEEDED 含上限数字)/ DeleteDevice(事务硬删
  + audit_log → 调 CredentialRevoker.RevokeForUser 按用户回收凭证,dp_uuid 模型)
  / SubscriptionSummary / ResolvePlan / 纯函数 resolveEffectivePlan。
- middleware.go: 订阅校验中间件,解析最高档未过期订阅注入 context;
  helpers PlanFromCtx / CheckDeviceQuota / RequirePaidTier;预留 60s Redis 缓存开关。
- store.go: devices/users/subscriptions/plans/audit_log 数据访问,按用户行锁串行化登记。
- context.go: user_id / plan 的 context key 与 helper。
- CredentialRevoker 接口(消费侧定义,避免与 nodes 循环依赖)+ NoopRevoker,
  形状对齐 #5 的 Hub.Push(RevokeCredential),#5 落地前注入 no-op。

测试:service_test.go 15 个单测(trial→pro、过期回落 free、banned 拒绝、
最高档/同档最晚到期、UTC 严格边界、设备配额、双语限额、平台/名称归一化)全过;
devices_integration_test.go(testcontainers,build tag integration)覆盖
注册→connect 隐式登记→list→delete 全链路 + 回收断言 + 403/404。

apierr 增加 Unauthorized/Forbidden/NotFound/AccountBanned;
OpenAPI SubscriptionInfo.source 枚举补 free。

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-13 12:13:09 +08:00
wangjia 37b18d4293 merge: maestro/tsk_9uMrd9kUpmVA [tsk_9uMrd9kUpmVA] 数据面定稿 + 修订 ARCHITECTURE.md connect 契约 2026-06-13 02:57:25 +08:00
wangjia ab2bbaf683 tsk_9uMrd9kUpmVA: 数据面定稿 + 修订 ARCHITECTURE.md connect 契约
决策:libbox 统一承载 REALITY/Hy2 outbound(方案 C),弃用 WireGuard peer 注册。
现网 deploy/ 基础设施(singbox Hy2 + xray REALITY)已验证,零改动复用。

变更文件:
- design/server/ARCHITECTURE.md v0.2:
  · §0 数据面描述改为 sing-box libbox (REALITY/Hy2)
  · §1 拓扑图更新(wireguard+agent → singbox+agent,客户端标注 libbox 内嵌)
  · §2 devices 表移除 pubkey;nodes 表改为 reality_public_key/short_id/uuid/hy2_password
  · §3 connect 响应由 WireGuard 配置改为完整 sing-box config JSON
  · §3.1(新增)connect 契约详细规范:四块 inbounds/outbounds/route/dns、
    客户端透传原则、字段与 deploy/ 模板逐字段对照、占位符替换说明
  · §4.3 连接流程更新(peer 注册 → config JSON 渲染下发)
  · 附录 A(新增)v0.1→v0.2 变更汇总
- doc/plans/11-libbox-bridge.md(新建):
  完整决策记录(背景/备选/结论/影响面),任务链 11A→11C→11D/E/F→11H
- doc/plans/client-connect-config.example.json(新建):
  最小示例 config,字段与 deploy/ 模板对齐,可用 sing-box check -c 校验

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-13 01:43:17 +08:00
wangjia c92cd11cc5 feat: CI 流水线 — lint + 单测 + OpenAPI 校验 + 脱敏扫描 + 镜像构建 [tsk_P5b5nIrEsfrV]
新增 .gitea/workflows/ci.yml 五个 Job:
  1. lint        — shellcheck -S warning 扫描全部 deploy/ shell 脚本
  2. unit-test   — docker-compose config 语法校验 + nginx -t(桩证书)
  3. openapi-check — openapi-spec-validator 验证 design/server/openapi.yaml
  4. redline-scan  — ci/scan-redline.sh 扫描 UI 文案红线词(design/ jsx/dart/html)
  5. image-build   — docker build pangolin-edge:ci

附带:
  - ci/scan-redline.sh:脱敏扫描脚本,过滤注释行与外部渠道 handle
  - ci/nginx-test.sh:自签桩证书 + nginx -t,CI 免依赖真实 Let's Encrypt
  - design/server/openapi.yaml:依据 ARCHITECTURE.md §3 展开的 OAS 3.0 完整契约
  - dparts.jsx / parts.jsx:修复 killSwitchSub EN 文案「the VPN drops」红线词
    → 改为「connection drops」(行为描述,不提产品类别)

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-13 01:19:28 +08:00
wangjia a642bf16a2 feat: 同步 design/ 设计系统(含 iPad tablet kit) + 架构任务拆分(todo/)
design/ 同步自最新设计导出,新增 ui_kits/tablet/ 平板分栏布局;todo/ 录入 18 个并行实施任务。

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-06-11 23:57:57 +08:00