Files
pangolin/server/internal/usage/service.go
T
wangjia ece8ea3b57 feat(usage): usage_daily 聚合 + 广告解锁 + free 额度校验 (tsk_1taxhtV2k3RP)
server/internal/usage 模块实现(仅字节/分钟,无目的地,符合无日志口径):

- aggregator.go:实现 #5 的 ReportUsage 回调接口(UsageReporter),
  dp_uuid→user_id 走内存+Redis 短缓存,按上报批次 id Redis 去重防重放,
  按 At 的 UTC 日期 INSERT ... ON DUPLICATE KEY UPDATE 累加,并发安全。
- store.go:usage_daily 累加/区间查询/当日查询、MarkAdUnlocked(事务+FOR
  UPDATE 幂等)、EffectivePlan(活跃订阅取最高 tier,无则回落 free)。
- ads.go:AdVerifier 接口 + AdMob SSV 实现(拉取并缓存 Google ECDSA 公钥,
  ECDSA-SHA256 验签 + custom_data/ad_unit 匹配),Unity 留接口占位。
- service.go:UsageCurve(空日补零、仅当前用户)、TodaySummary(/v1/me)、
  UnlockAd(验签→ad_token 一次性 nonce 去重→写 ad_unlocked_at,当日二次幂等)。
- quota.go:CheckFreeConnect 供 #5 connect 使用:ad_gate=true 校验当日
  ad_unlocked_at + minutes_used<daily_minutes(free=10),返回剩余分钟;
  pro/team 不受 ad_gate 限制(返回 Unlimited);带双语 code 错误。
- handler.go:GET /v1/usage?days=7、POST /v1/ads/unlock(204)。
- apierr:新增 AD_NOT_UNLOCKED/QUOTA_EXHAUSTED/AD_VERIFY_FAILED/AD_TOKEN_REPLAY。
- openapi:/ads/unlock 补 409 Conflict(重放)。

测试:ads_test.go 单测覆盖 AdMob 验签全链路(合法/伪造/custom_data 不符/
ad_unit 不允许/畸形 token)+ Unity 未实现;usage_integration_test.go
(testcontainers, build tag integration) 覆盖并发多节点累加、批次重放去重、
跨 UTC 日界分桶、未知 dp_uuid 丢弃、free 额度四态、ads 解锁伪造/重放/幂等、
曲线补零/隔离、/me 摘要。

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-13 12:16:50 +08:00

177 lines
5.1 KiB
Go

package usage
import (
"context"
"crypto/sha256"
"encoding/hex"
"time"
"github.com/redis/go-redis/v9"
"github.com/wangjia/pangolin/server/internal/apierr"
)
// nowFunc is overridable in tests to pin "today".
var nowFunc = time.Now
// utcToday returns the current UTC calendar date (time truncated).
func utcToday() time.Time {
n := nowFunc().UTC()
return time.Date(n.Year(), n.Month(), n.Day(), 0, 0, 0, 0, time.UTC)
}
// Service serves usage queries, the /v1/me usage summary, the ads-unlock flow,
// and the free-plan connect quota check.
type Service struct {
store *Store
rdb *redis.Client
verifier AdVerifier
adNonceTTL time.Duration
}
// NewService builds a Service. rdb may be nil (ad-token replay protection is
// then disabled — not recommended in production). verifier may be nil if the
// ads-unlock endpoint is not mounted. adNonceTTL <= 0 defaults to 1h.
func NewService(store *Store, rdb *redis.Client, verifier AdVerifier, adNonceTTL time.Duration) *Service {
if adNonceTTL <= 0 {
adNonceTTL = time.Hour
}
return &Service{store: store, rdb: rdb, verifier: verifier, adNonceTTL: adNonceTTL}
}
// UsagePoint is one day of the usage curve.
type UsagePoint struct {
Date string `json:"date"` // YYYY-MM-DD (UTC)
BytesUp uint64 `json:"bytes_up"`
BytesDown uint64 `json:"bytes_down"`
MinutesUsed int `json:"minutes_used"`
}
// UsageCurve returns the last `days` daily points for userID (UTC), with
// missing days zero-filled, oldest first. days is clamped to [1, 90].
func (svc *Service) UsageCurve(ctx context.Context, userID int64, days int) ([]UsagePoint, *apierr.Error) {
if days < 1 {
days = 7
}
if days > 90 {
days = 90
}
today := utcToday()
from := today.AddDate(0, 0, -(days - 1))
rows, err := svc.store.GetUsageRange(ctx, userID, from, today)
if err != nil {
return nil, apierr.ErrInternal
}
byDate := make(map[string]DailyUsage, len(rows))
for _, r := range rows {
byDate[r.Date.UTC().Format(dateLayout)] = r
}
points := make([]UsagePoint, 0, days)
for i := 0; i < days; i++ {
d := from.AddDate(0, 0, i).Format(dateLayout)
if u, ok := byDate[d]; ok {
points = append(points, UsagePoint{
Date: d,
BytesUp: u.BytesUp,
BytesDown: u.BytesDown,
MinutesUsed: u.MinutesUsed,
})
} else {
points = append(points, UsagePoint{Date: d})
}
}
return points, nil
}
// TodaySummary is the /v1/me today_usage block.
type TodaySummary struct {
MinutesUsed int `json:"minutes_used"`
MinutesRemaining *int `json:"minutes_remaining"` // nil = unlimited (pro/team)
AdUnlocked bool `json:"ad_unlocked"`
}
// TodaySummary returns the current user's usage summary for today (UTC),
// reflecting plan limits and ad-unlock state.
func (svc *Service) TodaySummary(ctx context.Context, userID int64) (*TodaySummary, *apierr.Error) {
plan, err := svc.store.EffectivePlan(ctx, userID)
if err != nil {
return nil, apierr.ErrInternal
}
day, err := svc.store.GetDay(ctx, userID, utcToday())
if err != nil {
return nil, apierr.ErrInternal
}
used := 0
adUnlocked := false
if day != nil {
used = day.MinutesUsed
adUnlocked = day.AdUnlockedAt.Valid
}
out := &TodaySummary{MinutesUsed: used, AdUnlocked: adUnlocked}
if plan.DailyMinutes.Valid {
remaining := int(plan.DailyMinutes.Int64) - used
if remaining < 0 {
remaining = 0
}
out.MinutesRemaining = &remaining
}
return out, nil
}
// UnlockAd verifies a rewarded-ad receipt and records the day's ad-unlock.
//
// Flow: validate inputs → verify the receipt with the ad network → consume the
// ad_token as a one-time nonce (replay-protected) → set ad_unlocked_at. A
// second unlock on a day already unlocked is idempotent (alreadyUnlocked=true).
func (svc *Service) UnlockAd(ctx context.Context, userID int64, deviceID, adToken string) (alreadyUnlocked bool, apiErr *apierr.Error) {
if deviceID == "" || adToken == "" {
return false, apierr.ErrBadRequest
}
if svc.verifier == nil {
return false, apierr.ErrInternal
}
// 1. Authenticate the receipt with the ad network.
if err := svc.verifier.Verify(ctx, AdVerifyRequest{
UserID: userID,
DeviceID: deviceID,
AdToken: adToken,
}); err != nil {
return false, apierr.ErrAdVerifyFailed
}
// 2. One-time nonce: a genuine receipt may only be redeemed once.
if dup, err := svc.consumeAdNonce(ctx, adToken); err != nil {
return false, apierr.ErrInternal
} else if dup {
return false, apierr.ErrAdReplay
}
// 3. Record the unlock (idempotent per UTC day).
already, err := svc.store.MarkAdUnlocked(ctx, userID, utcToday())
if err != nil {
return false, apierr.ErrInternal
}
return already, nil
}
// consumeAdNonce atomically records the ad_token so it cannot be reused.
// Returns dup=true if the token was already consumed. No-ops (dup=false) when
// Redis is not configured.
func (svc *Service) consumeAdNonce(ctx context.Context, adToken string) (bool, error) {
if svc.rdb == nil {
return false, nil
}
sum := sha256.Sum256([]byte(adToken))
key := "ads:nonce:" + hex.EncodeToString(sum[:])
set, err := svc.rdb.SetNX(ctx, key, "1", svc.adNonceTTL).Result()
if err != nil {
return false, err
}
return !set, nil
}