bcc114088c
ci-pangolin / Lint — shellcheck (push) Successful in 9s
ci-pangolin / OpenAPI Sync Check (push) Successful in 17s
ci-pangolin / Redline Scan — 脱敏 (UI 文案) (push) Successful in 5s
ci-pangolin / Flutter — analyze + test (push) Successful in 26s
ci-pangolin / Portable SQL — 可移植性 (mysql/sqlite) (push) Successful in 5s
ci-pangolin / Codegen Drift — token 生成物未漂移 (push) Successful in 5s
ci-pangolin / Go — build + test (push) Successful in 12s
ci-pangolin / E2E Smoke — L4 进程级端到端 (push) Successful in 15s
ci-pangolin / Go — integration (mysql/redis testcontainers) (push) Failing after 4m4s
ci-pangolin / Golden — 视觉回归 (components + auth) (push) Successful in 15s
后端:新端点 POST /v1/me/devices/{uuid}/logout(ForceLogout:吊销该设备会话+
丢 Redis JTI,设备留列表)。DeleteDevice 增强:先吊销会话再删设备(FK ON DELETE
CASCADE 清理会话行)+ 按 dp_uuid 吊销数据面凭证。CredentialRevoker 接口改
per-device RevokeDevice(dpUUID),由 nodes.Service 实现(查 connect_credentials
持有节点→推 CommandTypeRevoke + 删凭证行),main 注入替 NoopRevoker;devices 注入
SessionPort/JTIRevoker。修 SQLite 跨连接死锁(会话吊销移到 delete tx 之前)。
migration 000016 sessions FK 加 ON DELETE CASCADE。
客户端:account_api.forceLogout + devicesProvider.forceLogout(UI 留 P6)。
测试:ForceLogout(吊销会话+JTI+设备保留+403/404)+ DeleteDevice(级联+按 dp_uuid
吊销);NoopRevoker 改 dp_uuid;全量 server/flutter 测试绿。
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
85 lines
2.3 KiB
Go
85 lines
2.3 KiB
Go
package nodes
|
|
|
|
import (
|
|
"context"
|
|
|
|
"github.com/redis/go-redis/v9"
|
|
|
|
"github.com/wangjia/pangolin/server/internal/mtls"
|
|
agentv1 "github.com/wangjia/pangolin/server/internal/pb/agentv1"
|
|
)
|
|
|
|
// Service bundles all nodes-domain components and exposes assembly helpers.
|
|
// Construct via NewService after initialising each dependency independently.
|
|
type Service struct {
|
|
handler *Handler
|
|
hub *Hub
|
|
store NodeStore
|
|
load *LoadCache
|
|
}
|
|
|
|
// NewService wires up the full nodes service from its dependencies.
|
|
//
|
|
// - ca / tokens / crl: from the mtls package (task 5b)
|
|
// - rdb: Redis client (for hub + load cache)
|
|
// - store: NodeStore implementation (SQLNodeStore in production; mock in tests)
|
|
func NewService(
|
|
ca *mtls.CA,
|
|
tokens *mtls.BootstrapTokenManager,
|
|
rdb *redis.Client,
|
|
store NodeStore,
|
|
) *Service {
|
|
hub := NewHub(rdb)
|
|
load := NewLoadCache(rdb)
|
|
handler := NewHandler(ca, tokens, hub, store, load)
|
|
return &Service{
|
|
handler: handler,
|
|
hub: hub,
|
|
store: store,
|
|
load: load,
|
|
}
|
|
}
|
|
|
|
// Handler returns the AgentServiceServer implementation for gRPC registration.
|
|
func (s *Service) Handler() agentv1.AgentServiceServer {
|
|
return s.handler
|
|
}
|
|
|
|
// Hub exposes the command routing hub for callers (e.g. task 5d/5e) that need to
|
|
// Push or Broadcast commands.
|
|
func (s *Service) Hub() *Hub {
|
|
return s.hub
|
|
}
|
|
|
|
// Store exposes the NodeStore for callers that need direct DB access.
|
|
func (s *Service) Store() NodeStore {
|
|
return s.store
|
|
}
|
|
|
|
// RevokeDevice recalls a per-device data-plane credential: it pushes a Revoke
|
|
// command to every node currently holding the dp_uuid (so sing-box drops that
|
|
// user) and removes the connect_credentials rows. Satisfies devices.CredentialRevoker.
|
|
// Best-effort: a queued Push is replayed when an offline node reconnects.
|
|
func (s *Service) RevokeDevice(ctx context.Context, dpUUID string) error {
|
|
if dpUUID == "" {
|
|
return nil
|
|
}
|
|
locs, err := s.store.NodesHoldingCredential(ctx, dpUUID)
|
|
if err != nil {
|
|
return err
|
|
}
|
|
for _, loc := range locs {
|
|
_ = s.hub.Push(ctx, loc.NodeUUID, &agentv1.Command{
|
|
Type: agentv1.CommandTypeRevoke,
|
|
Revoke: &agentv1.RevokePayload{DpUUID: dpUUID},
|
|
})
|
|
_ = s.store.DeleteCredential(ctx, loc.NodeID, dpUUID)
|
|
}
|
|
return nil
|
|
}
|
|
|
|
// Load exposes the LoadCache for callers that display per-node load metrics.
|
|
func (s *Service) Load() *LoadCache {
|
|
return s.load
|
|
}
|