bcc114088c
ci-pangolin / Lint — shellcheck (push) Successful in 9s
ci-pangolin / OpenAPI Sync Check (push) Successful in 17s
ci-pangolin / Redline Scan — 脱敏 (UI 文案) (push) Successful in 5s
ci-pangolin / Flutter — analyze + test (push) Successful in 26s
ci-pangolin / Portable SQL — 可移植性 (mysql/sqlite) (push) Successful in 5s
ci-pangolin / Codegen Drift — token 生成物未漂移 (push) Successful in 5s
ci-pangolin / Go — build + test (push) Successful in 12s
ci-pangolin / E2E Smoke — L4 进程级端到端 (push) Successful in 15s
ci-pangolin / Go — integration (mysql/redis testcontainers) (push) Failing after 4m4s
ci-pangolin / Golden — 视觉回归 (components + auth) (push) Successful in 15s
后端:新端点 POST /v1/me/devices/{uuid}/logout(ForceLogout:吊销该设备会话+
丢 Redis JTI,设备留列表)。DeleteDevice 增强:先吊销会话再删设备(FK ON DELETE
CASCADE 清理会话行)+ 按 dp_uuid 吊销数据面凭证。CredentialRevoker 接口改
per-device RevokeDevice(dpUUID),由 nodes.Service 实现(查 connect_credentials
持有节点→推 CommandTypeRevoke + 删凭证行),main 注入替 NoopRevoker;devices 注入
SessionPort/JTIRevoker。修 SQLite 跨连接死锁(会话吊销移到 delete tx 之前)。
migration 000016 sessions FK 加 ON DELETE CASCADE。
客户端:account_api.forceLogout + devicesProvider.forceLogout(UI 留 P6)。
测试:ForceLogout(吊销会话+JTI+设备保留+403/404)+ DeleteDevice(级联+按 dp_uuid
吊销);NoopRevoker 改 dp_uuid;全量 server/flutter 测试绿。
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
89 lines
2.5 KiB
Go
89 lines
2.5 KiB
Go
package devices
|
|
|
|
import (
|
|
"encoding/json"
|
|
"net/http"
|
|
|
|
"github.com/go-chi/chi/v5"
|
|
"github.com/wangjia/pangolin/server/internal/apierr"
|
|
)
|
|
|
|
// Handler serves the account device endpoints. It assumes the JWT auth
|
|
// middleware (module #2) has set CtxKeyUserID on the request context.
|
|
type Handler struct {
|
|
svc *Service
|
|
}
|
|
|
|
// NewHandler creates a Handler backed by svc.
|
|
func NewHandler(svc *Service) *Handler { return &Handler{svc: svc} }
|
|
|
|
// RegisterRoutes mounts the device routes on r under the caller's chosen prefix
|
|
// (the API mounts these beneath /v1/me):
|
|
//
|
|
// GET /devices
|
|
// DELETE /devices/{id}
|
|
// POST /devices/{id}/logout
|
|
func (h *Handler) RegisterRoutes(r chi.Router) {
|
|
r.Get("/devices", h.ListDevices)
|
|
r.Delete("/devices/{id}", h.DeleteDevice)
|
|
r.Post("/devices/{id}/logout", h.ForceLogout)
|
|
}
|
|
|
|
type listDevicesResponse struct {
|
|
Devices []Device `json:"devices"`
|
|
}
|
|
|
|
// ListDevices handles GET /v1/me/devices.
|
|
func (h *Handler) ListDevices(w http.ResponseWriter, r *http.Request) {
|
|
userID, ok := UserIDFromContext(r.Context())
|
|
if !ok {
|
|
apierr.WriteJSON(w, http.StatusUnauthorized, apierr.ErrUnauthorized)
|
|
return
|
|
}
|
|
|
|
devices, apiErr := h.svc.ListDevices(r.Context(), userID)
|
|
if apiErr != nil {
|
|
apierr.WriteJSON(w, StatusForError(apiErr), apiErr)
|
|
return
|
|
}
|
|
|
|
w.Header().Set("Content-Type", "application/json; charset=utf-8")
|
|
w.WriteHeader(http.StatusOK)
|
|
_ = json.NewEncoder(w).Encode(listDevicesResponse{Devices: devices})
|
|
}
|
|
|
|
// DeleteDevice handles DELETE /v1/me/devices/{id}.
|
|
func (h *Handler) DeleteDevice(w http.ResponseWriter, r *http.Request) {
|
|
userID, ok := UserIDFromContext(r.Context())
|
|
if !ok {
|
|
apierr.WriteJSON(w, http.StatusUnauthorized, apierr.ErrUnauthorized)
|
|
return
|
|
}
|
|
|
|
deviceUUID := chi.URLParam(r, "id")
|
|
if apiErr := h.svc.DeleteDevice(r.Context(), userID, deviceUUID); apiErr != nil {
|
|
apierr.WriteJSON(w, StatusForError(apiErr), apiErr)
|
|
return
|
|
}
|
|
|
|
w.WriteHeader(http.StatusNoContent)
|
|
}
|
|
|
|
// ForceLogout handles POST /v1/me/devices/{id}/logout — revoke the device's
|
|
// sessions (kick it offline); the device stays in the list.
|
|
func (h *Handler) ForceLogout(w http.ResponseWriter, r *http.Request) {
|
|
userID, ok := UserIDFromContext(r.Context())
|
|
if !ok {
|
|
apierr.WriteJSON(w, http.StatusUnauthorized, apierr.ErrUnauthorized)
|
|
return
|
|
}
|
|
|
|
deviceUUID := chi.URLParam(r, "id")
|
|
if apiErr := h.svc.ForceLogout(r.Context(), userID, deviceUUID); apiErr != nil {
|
|
apierr.WriteJSON(w, StatusForError(apiErr), apiErr)
|
|
return
|
|
}
|
|
|
|
w.WriteHeader(http.StatusNoContent)
|
|
}
|