Files
pangolin/server/internal/devices/handler.go
T
wangjia 8a1db07d19
ci-pangolin / Lint — shellcheck (push) Successful in 9s
ci-pangolin / OpenAPI Sync Check (push) Successful in 19s
ci-pangolin / Redline Scan — 脱敏 (UI 文案) (push) Successful in 6s
ci-pangolin / Flutter — analyze + test (push) Failing after 15s
ci-pangolin / Portable SQL — 可移植性 (mysql/sqlite) (push) Successful in 5s
ci-pangolin / Codegen Drift — token 生成物未漂移 (push) Successful in 5s
ci-pangolin / Go — build + test (push) Successful in 10s
ci-pangolin / E2E Smoke — L4 进程级端到端 (push) Successful in 14s
ci-pangolin / Go — integration (mysql/redis testcontainers) (push) Failing after 4m2s
ci-pangolin / Golden — 视觉回归 (components + auth) (push) Successful in 15s
fix(devices+stats): /v1/me/devices 401 修复 + 设备下拉接已登录设备 + 版本号
① 「我的设备打不开」根因:devices handler 读 devices.CtxKeyUserID,而鉴权中间件
   把 user id 写在 auth 的 key 下(类型不同→取不到)→ /v1/me/devices 一直 401。
   改 handler 用 auth.UserIDFromContext(与 accountAPI 等一致)。
② 统计页设备下拉改读 devicesProvider(已登录设备),不再只列有用量的设备 →
   windows 设备现在会出现。
③ pubspec version 1.0.2+3 → 1.0.11+12,client_version 不再显示陈旧的 v1.0.2。
测试:devices_screen + stats_device_filter widget(下拉读 /v1/me/devices)+全量绿。

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-29 08:37:11 +08:00

90 lines
2.5 KiB
Go

package devices
import (
"encoding/json"
"net/http"
"github.com/go-chi/chi/v5"
"github.com/wangjia/pangolin/server/internal/apierr"
"github.com/wangjia/pangolin/server/internal/auth"
)
// Handler serves the account device endpoints. It assumes the JWT auth
// middleware (module #2) has set CtxKeyUserID on the request context.
type Handler struct {
svc *Service
}
// NewHandler creates a Handler backed by svc.
func NewHandler(svc *Service) *Handler { return &Handler{svc: svc} }
// RegisterRoutes mounts the device routes on r under the caller's chosen prefix
// (the API mounts these beneath /v1/me):
//
// GET /devices
// DELETE /devices/{id}
// POST /devices/{id}/logout
func (h *Handler) RegisterRoutes(r chi.Router) {
r.Get("/devices", h.ListDevices)
r.Delete("/devices/{id}", h.DeleteDevice)
r.Post("/devices/{id}/logout", h.ForceLogout)
}
type listDevicesResponse struct {
Devices []Device `json:"devices"`
}
// ListDevices handles GET /v1/me/devices.
func (h *Handler) ListDevices(w http.ResponseWriter, r *http.Request) {
userID, ok := auth.UserIDFromContext(r.Context())
if !ok {
apierr.WriteJSON(w, http.StatusUnauthorized, apierr.ErrUnauthorized)
return
}
devices, apiErr := h.svc.ListDevices(r.Context(), userID)
if apiErr != nil {
apierr.WriteJSON(w, StatusForError(apiErr), apiErr)
return
}
w.Header().Set("Content-Type", "application/json; charset=utf-8")
w.WriteHeader(http.StatusOK)
_ = json.NewEncoder(w).Encode(listDevicesResponse{Devices: devices})
}
// DeleteDevice handles DELETE /v1/me/devices/{id}.
func (h *Handler) DeleteDevice(w http.ResponseWriter, r *http.Request) {
userID, ok := auth.UserIDFromContext(r.Context())
if !ok {
apierr.WriteJSON(w, http.StatusUnauthorized, apierr.ErrUnauthorized)
return
}
deviceUUID := chi.URLParam(r, "id")
if apiErr := h.svc.DeleteDevice(r.Context(), userID, deviceUUID); apiErr != nil {
apierr.WriteJSON(w, StatusForError(apiErr), apiErr)
return
}
w.WriteHeader(http.StatusNoContent)
}
// ForceLogout handles POST /v1/me/devices/{id}/logout — revoke the device's
// sessions (kick it offline); the device stays in the list.
func (h *Handler) ForceLogout(w http.ResponseWriter, r *http.Request) {
userID, ok := auth.UserIDFromContext(r.Context())
if !ok {
apierr.WriteJSON(w, http.StatusUnauthorized, apierr.ErrUnauthorized)
return
}
deviceUUID := chi.URLParam(r, "id")
if apiErr := h.svc.ForceLogout(r.Context(), userID, deviceUUID); apiErr != nil {
apierr.WriteJSON(w, StatusForError(apiErr), apiErr)
return
}
w.WriteHeader(http.StatusNoContent)
}