ece8ea3b57
server/internal/usage 模块实现(仅字节/分钟,无目的地,符合无日志口径): - aggregator.go:实现 #5 的 ReportUsage 回调接口(UsageReporter), dp_uuid→user_id 走内存+Redis 短缓存,按上报批次 id Redis 去重防重放, 按 At 的 UTC 日期 INSERT ... ON DUPLICATE KEY UPDATE 累加,并发安全。 - store.go:usage_daily 累加/区间查询/当日查询、MarkAdUnlocked(事务+FOR UPDATE 幂等)、EffectivePlan(活跃订阅取最高 tier,无则回落 free)。 - ads.go:AdVerifier 接口 + AdMob SSV 实现(拉取并缓存 Google ECDSA 公钥, ECDSA-SHA256 验签 + custom_data/ad_unit 匹配),Unity 留接口占位。 - service.go:UsageCurve(空日补零、仅当前用户)、TodaySummary(/v1/me)、 UnlockAd(验签→ad_token 一次性 nonce 去重→写 ad_unlocked_at,当日二次幂等)。 - quota.go:CheckFreeConnect 供 #5 connect 使用:ad_gate=true 校验当日 ad_unlocked_at + minutes_used<daily_minutes(free=10),返回剩余分钟; pro/team 不受 ad_gate 限制(返回 Unlimited);带双语 code 错误。 - handler.go:GET /v1/usage?days=7、POST /v1/ads/unlock(204)。 - apierr:新增 AD_NOT_UNLOCKED/QUOTA_EXHAUSTED/AD_VERIFY_FAILED/AD_TOKEN_REPLAY。 - openapi:/ads/unlock 补 409 Conflict(重放)。 测试:ads_test.go 单测覆盖 AdMob 验签全链路(合法/伪造/custom_data 不符/ ad_unit 不允许/畸形 token)+ Unity 未实现;usage_integration_test.go (testcontainers, build tag integration) 覆盖并发多节点累加、批次重放去重、 跨 UTC 日界分桶、未知 dp_uuid 丢弃、free 额度四态、ads 解锁伪造/重放/幂等、 曲线补零/隔离、/me 摘要。 Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
177 lines
5.1 KiB
Go
177 lines
5.1 KiB
Go
package usage
|
|
|
|
import (
|
|
"context"
|
|
"crypto/sha256"
|
|
"encoding/hex"
|
|
"time"
|
|
|
|
"github.com/redis/go-redis/v9"
|
|
"github.com/wangjia/pangolin/server/internal/apierr"
|
|
)
|
|
|
|
// nowFunc is overridable in tests to pin "today".
|
|
var nowFunc = time.Now
|
|
|
|
// utcToday returns the current UTC calendar date (time truncated).
|
|
func utcToday() time.Time {
|
|
n := nowFunc().UTC()
|
|
return time.Date(n.Year(), n.Month(), n.Day(), 0, 0, 0, 0, time.UTC)
|
|
}
|
|
|
|
// Service serves usage queries, the /v1/me usage summary, the ads-unlock flow,
|
|
// and the free-plan connect quota check.
|
|
type Service struct {
|
|
store *Store
|
|
rdb *redis.Client
|
|
verifier AdVerifier
|
|
adNonceTTL time.Duration
|
|
}
|
|
|
|
// NewService builds a Service. rdb may be nil (ad-token replay protection is
|
|
// then disabled — not recommended in production). verifier may be nil if the
|
|
// ads-unlock endpoint is not mounted. adNonceTTL <= 0 defaults to 1h.
|
|
func NewService(store *Store, rdb *redis.Client, verifier AdVerifier, adNonceTTL time.Duration) *Service {
|
|
if adNonceTTL <= 0 {
|
|
adNonceTTL = time.Hour
|
|
}
|
|
return &Service{store: store, rdb: rdb, verifier: verifier, adNonceTTL: adNonceTTL}
|
|
}
|
|
|
|
// UsagePoint is one day of the usage curve.
|
|
type UsagePoint struct {
|
|
Date string `json:"date"` // YYYY-MM-DD (UTC)
|
|
BytesUp uint64 `json:"bytes_up"`
|
|
BytesDown uint64 `json:"bytes_down"`
|
|
MinutesUsed int `json:"minutes_used"`
|
|
}
|
|
|
|
// UsageCurve returns the last `days` daily points for userID (UTC), with
|
|
// missing days zero-filled, oldest first. days is clamped to [1, 90].
|
|
func (svc *Service) UsageCurve(ctx context.Context, userID int64, days int) ([]UsagePoint, *apierr.Error) {
|
|
if days < 1 {
|
|
days = 7
|
|
}
|
|
if days > 90 {
|
|
days = 90
|
|
}
|
|
|
|
today := utcToday()
|
|
from := today.AddDate(0, 0, -(days - 1))
|
|
|
|
rows, err := svc.store.GetUsageRange(ctx, userID, from, today)
|
|
if err != nil {
|
|
return nil, apierr.ErrInternal
|
|
}
|
|
byDate := make(map[string]DailyUsage, len(rows))
|
|
for _, r := range rows {
|
|
byDate[r.Date.UTC().Format(dateLayout)] = r
|
|
}
|
|
|
|
points := make([]UsagePoint, 0, days)
|
|
for i := 0; i < days; i++ {
|
|
d := from.AddDate(0, 0, i).Format(dateLayout)
|
|
if u, ok := byDate[d]; ok {
|
|
points = append(points, UsagePoint{
|
|
Date: d,
|
|
BytesUp: u.BytesUp,
|
|
BytesDown: u.BytesDown,
|
|
MinutesUsed: u.MinutesUsed,
|
|
})
|
|
} else {
|
|
points = append(points, UsagePoint{Date: d})
|
|
}
|
|
}
|
|
return points, nil
|
|
}
|
|
|
|
// TodaySummary is the /v1/me today_usage block.
|
|
type TodaySummary struct {
|
|
MinutesUsed int `json:"minutes_used"`
|
|
MinutesRemaining *int `json:"minutes_remaining"` // nil = unlimited (pro/team)
|
|
AdUnlocked bool `json:"ad_unlocked"`
|
|
}
|
|
|
|
// TodaySummary returns the current user's usage summary for today (UTC),
|
|
// reflecting plan limits and ad-unlock state.
|
|
func (svc *Service) TodaySummary(ctx context.Context, userID int64) (*TodaySummary, *apierr.Error) {
|
|
plan, err := svc.store.EffectivePlan(ctx, userID)
|
|
if err != nil {
|
|
return nil, apierr.ErrInternal
|
|
}
|
|
day, err := svc.store.GetDay(ctx, userID, utcToday())
|
|
if err != nil {
|
|
return nil, apierr.ErrInternal
|
|
}
|
|
|
|
used := 0
|
|
adUnlocked := false
|
|
if day != nil {
|
|
used = day.MinutesUsed
|
|
adUnlocked = day.AdUnlockedAt.Valid
|
|
}
|
|
|
|
out := &TodaySummary{MinutesUsed: used, AdUnlocked: adUnlocked}
|
|
if plan.DailyMinutes.Valid {
|
|
remaining := int(plan.DailyMinutes.Int64) - used
|
|
if remaining < 0 {
|
|
remaining = 0
|
|
}
|
|
out.MinutesRemaining = &remaining
|
|
}
|
|
return out, nil
|
|
}
|
|
|
|
// UnlockAd verifies a rewarded-ad receipt and records the day's ad-unlock.
|
|
//
|
|
// Flow: validate inputs → verify the receipt with the ad network → consume the
|
|
// ad_token as a one-time nonce (replay-protected) → set ad_unlocked_at. A
|
|
// second unlock on a day already unlocked is idempotent (alreadyUnlocked=true).
|
|
func (svc *Service) UnlockAd(ctx context.Context, userID int64, deviceID, adToken string) (alreadyUnlocked bool, apiErr *apierr.Error) {
|
|
if deviceID == "" || adToken == "" {
|
|
return false, apierr.ErrBadRequest
|
|
}
|
|
if svc.verifier == nil {
|
|
return false, apierr.ErrInternal
|
|
}
|
|
|
|
// 1. Authenticate the receipt with the ad network.
|
|
if err := svc.verifier.Verify(ctx, AdVerifyRequest{
|
|
UserID: userID,
|
|
DeviceID: deviceID,
|
|
AdToken: adToken,
|
|
}); err != nil {
|
|
return false, apierr.ErrAdVerifyFailed
|
|
}
|
|
|
|
// 2. One-time nonce: a genuine receipt may only be redeemed once.
|
|
if dup, err := svc.consumeAdNonce(ctx, adToken); err != nil {
|
|
return false, apierr.ErrInternal
|
|
} else if dup {
|
|
return false, apierr.ErrAdReplay
|
|
}
|
|
|
|
// 3. Record the unlock (idempotent per UTC day).
|
|
already, err := svc.store.MarkAdUnlocked(ctx, userID, utcToday())
|
|
if err != nil {
|
|
return false, apierr.ErrInternal
|
|
}
|
|
return already, nil
|
|
}
|
|
|
|
// consumeAdNonce atomically records the ad_token so it cannot be reused.
|
|
// Returns dup=true if the token was already consumed. No-ops (dup=false) when
|
|
// Redis is not configured.
|
|
func (svc *Service) consumeAdNonce(ctx context.Context, adToken string) (bool, error) {
|
|
if svc.rdb == nil {
|
|
return false, nil
|
|
}
|
|
sum := sha256.Sum256([]byte(adToken))
|
|
key := "ads:nonce:" + hex.EncodeToString(sum[:])
|
|
set, err := svc.rdb.SetNX(ctx, key, "1", svc.adNonceTTL).Result()
|
|
if err != nil {
|
|
return false, err
|
|
}
|
|
return !set, nil
|
|
}
|