2f298f0a0a
ci-pangolin / Lint — shellcheck (push) Successful in 8s
ci-pangolin / OpenAPI Sync Check (push) Successful in 18s
ci-pangolin / Redline Scan — 脱敏 (UI 文案) (push) Successful in 6s
ci-pangolin / Flutter — analyze + test (push) Successful in 24s
ci-pangolin / Portable SQL — 可移植性 (mysql/sqlite) (push) Successful in 5s
ci-pangolin / Codegen Drift — token 生成物未漂移 (push) Successful in 4s
ci-pangolin / Go — build + test (push) Successful in 11s
ci-pangolin / E2E Smoke — L4 进程级端到端 (push) Successful in 14s
ci-pangolin / Go — integration (mysql/redis testcontainers) (push) Failing after 4m13s
ci-pangolin / Golden — 视觉回归 (components + auth) (push) Successful in 14s
migration 000016(mysql+sqlite,含 down):新增 sessions 表(绑 device+refresh JTI) + devices 加 client_version/totp_trusted_until。devices 唯一键改 + platform CHECK 加 linux(需 SQLite 表重建)拆出后续迁移,降风险。 后端:新 internal/sessions Store(Create/Rotate/Revoke/RevokeByDevice/ LastLoginByDevice);TokenManager 外露 refresh JTI(IssueWithJTI/RefreshWithJTI/ ParseRefreshJTI);auth.Service 注入 SessionStore——登录建会话、刷新轮换、登出吊销; DeviceRegistrar 返回 deviceID;ReportUsage 心跳 touch devices.last_seen(在线判定); devices.ListDevices 经 LastLoginSource 注入返回 online(last_seen<3min)/client_version/ last_login;RegisterIfAbsent 存 client_version。 客户端:Device model 加 online/clientVersion/lastLogin(fromJson 自动解析)。 测试:sessions store 3 例 + ListDevices 在线/最后登录 + device model 2 例 + migration v16;全量 go test/flutter test 绿。 Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
91 lines
2.9 KiB
Go
91 lines
2.9 KiB
Go
package auth
|
|
|
|
import (
|
|
"context"
|
|
"testing"
|
|
)
|
|
|
|
// fakeRegistrar records RegisterDevice calls for assertion.
|
|
type fakeRegistrar struct {
|
|
calls []struct {
|
|
userID int64
|
|
meta DeviceMeta
|
|
}
|
|
deviceID int64
|
|
err error
|
|
}
|
|
|
|
func (f *fakeRegistrar) RegisterDevice(_ context.Context, userID int64, meta DeviceMeta) (int64, error) {
|
|
f.calls = append(f.calls, struct {
|
|
userID int64
|
|
meta DeviceMeta
|
|
}{userID, meta})
|
|
return f.deviceID, f.err
|
|
}
|
|
|
|
// Register/Login with a device should trigger RegisterDevice with the meta.
|
|
func TestService_RegisterDevice_OnRegisterAndLogin(t *testing.T) {
|
|
svc, _, _ := newService(t, ServiceConfig{})
|
|
reg := &fakeRegistrar{}
|
|
svc.SetDeviceRegistrar(reg)
|
|
ctx := context.Background()
|
|
const email = "dev@example.com"
|
|
const pw = "supersecret"
|
|
meta := DeviceMeta{DeviceID: "dev-uuid-1", Name: "MacBook Pro", Platform: "macos", ClientVersion: "v1.0.10"}
|
|
|
|
if _, err := svc.SendCode(ctx, email, "1.1.1.1"); err != nil {
|
|
t.Fatalf("SendCode: %v", err)
|
|
}
|
|
code := codeInRedis(t, svc, email)
|
|
if _, e := svc.Register(ctx, email, code, pw, "1.2.3.4", meta); e != nil {
|
|
t.Fatalf("Register: %v", e)
|
|
}
|
|
if len(reg.calls) != 1 || reg.calls[0].meta.DeviceID != "dev-uuid-1" || reg.calls[0].meta.Platform != "macos" {
|
|
t.Fatalf("register did not register device: %+v", reg.calls)
|
|
}
|
|
|
|
if _, _, e := svc.Login(ctx, email, pw, "", meta); e != nil {
|
|
t.Fatalf("Login: %v", e)
|
|
}
|
|
if len(reg.calls) != 2 || reg.calls[1].meta.Name != "MacBook Pro" {
|
|
t.Fatalf("login did not register device: %+v", reg.calls)
|
|
}
|
|
if reg.calls[0].userID == 0 || reg.calls[0].userID != reg.calls[1].userID {
|
|
t.Fatalf("userID mismatch: %+v", reg.calls)
|
|
}
|
|
}
|
|
|
|
// A registrar error (e.g. device cap) must NOT fail login/register.
|
|
func TestService_RegisterDevice_BestEffort(t *testing.T) {
|
|
svc, _, _ := newService(t, ServiceConfig{})
|
|
svc.SetDeviceRegistrar(&fakeRegistrar{err: context.DeadlineExceeded})
|
|
ctx := context.Background()
|
|
const email = "be@example.com"
|
|
if _, err := svc.SendCode(ctx, email, "1.1.1.1"); err != nil {
|
|
t.Fatalf("SendCode: %v", err)
|
|
}
|
|
code := codeInRedis(t, svc, email)
|
|
if _, e := svc.Register(ctx, email, code, "supersecret", "", DeviceMeta{DeviceID: "x", Platform: "windows"}); e != nil {
|
|
t.Fatalf("Register must succeed despite registrar error: %v", e)
|
|
}
|
|
}
|
|
|
|
// No device id / no registrar → no-op, login still works.
|
|
func TestService_RegisterDevice_NoMeta(t *testing.T) {
|
|
svc, _, _ := newService(t, ServiceConfig{})
|
|
reg := &fakeRegistrar{}
|
|
svc.SetDeviceRegistrar(reg)
|
|
ctx := context.Background()
|
|
const email = "nm@example.com"
|
|
if _, err := svc.SendCode(ctx, email, "1.1.1.1"); err != nil {
|
|
t.Fatalf("SendCode: %v", err)
|
|
}
|
|
code := codeInRedis(t, svc, email)
|
|
if _, e := svc.Register(ctx, email, code, "supersecret", "", DeviceMeta{}); e != nil {
|
|
t.Fatalf("Register: %v", e)
|
|
}
|
|
if len(reg.calls) != 0 {
|
|
t.Fatalf("empty device id should not register: %+v", reg.calls)
|
|
}
|
|
}
|