hi-server/internal/logic/public/user/unbindDeviceLogic.go
shanshanzhong 6b65ffb728
All checks were successful
Build docker and publish / build (20.15.1) (push) Successful in 7m4s
fix(user): 修复解绑设备接口的502错误和安全断言问题
修复不安全类型断言可能导致panic的问题,将Redis清理移出事务并添加超时控制
增加代理层超时配置和详细日志,提升接口稳定性
2025-12-01 21:24:11 -08:00

157 lines
5.6 KiB
Go

package user
import (
"context"
"fmt"
"time"
"github.com/perfect-panel/server/internal/config"
"github.com/perfect-panel/server/internal/model/log"
"github.com/perfect-panel/server/internal/model/user"
"github.com/perfect-panel/server/internal/svc"
"github.com/perfect-panel/server/internal/types"
"github.com/perfect-panel/server/pkg/constant"
"github.com/perfect-panel/server/pkg/logger"
"github.com/perfect-panel/server/pkg/uuidx"
"github.com/perfect-panel/server/pkg/xerr"
"github.com/pkg/errors"
"gorm.io/gorm"
)
type UnbindDeviceLogic struct {
logger.Logger
ctx context.Context
svcCtx *svc.ServiceContext
}
// Unbind Device
func NewUnbindDeviceLogic(ctx context.Context, svcCtx *svc.ServiceContext) *UnbindDeviceLogic {
return &UnbindDeviceLogic{
Logger: logger.WithContext(ctx),
ctx: ctx,
svcCtx: svcCtx,
}
}
func (l *UnbindDeviceLogic) UnbindDevice(req *types.UnbindDeviceRequest) error {
// 获取当前 token 登录的用户
u, ok := l.ctx.Value(constant.CtxKeyUser).(*user.User)
if !ok {
return errors.Wrapf(xerr.NewErrCode(xerr.InvalidAccess), "Invalid Access")
}
// 查询解绑设备是否存在
device, err := l.svcCtx.UserModel.FindOneDevice(l.ctx, req.Id)
if err != nil {
return errors.Wrapf(xerr.NewErrCode(xerr.DeviceNotExist), "find device")
}
if device.UserId != u.Id {
return errors.Wrapf(xerr.NewErrCode(xerr.InvalidParams), "device not belong to user")
}
l.Infow("开始解绑设备",
logger.Field("device_identifier", device.Identifier),
logger.Field("user_id", u.Id))
start := time.Now()
err = l.svcCtx.DB.Transaction(func(tx *gorm.DB) error {
// 1. 查询设备记录
var device user.Device
err = tx.Model(&device).Where("id = ?", req.Id).First(&device).Error
if err != nil {
return errors.Wrapf(xerr.NewErrCode(xerr.QueueEnqueueError), "find device err: %v", err)
}
// 2. 查询对应的认证记录
var userAuth user.AuthMethods
err = tx.Model(&userAuth).Where("auth_identifier = ? and auth_type = ?", device.Identifier, "device").First(&userAuth).Error
if err != nil {
return errors.Wrapf(xerr.NewErrCode(xerr.DatabaseQueryError), "find user auth method err: %v", err)
}
// 3. 创建新用户(匿名用户)
newUser := &user.User{
Salt: "default",
OnlyFirstPurchase: &l.svcCtx.Config.Invite.OnlyFirstPurchase,
}
if err := tx.Create(newUser).Error; err != nil {
return errors.Wrapf(xerr.NewErrCode(xerr.DatabaseInsertError), "create user failed: %v", err)
}
// 生成并更新邀请码
newUser.ReferCode = uuidx.UserInviteCode(newUser.Id)
if err := tx.Model(&user.User{}).Where("id = ?", newUser.Id).Update("refer_code", newUser.ReferCode).Error; err != nil {
return errors.Wrapf(xerr.NewErrCode(xerr.DatabaseUpdateError), "update refer code failed: %v", err)
}
// 3.2 记录注册日志
registerLog := log.Register{
AuthMethod: "device",
Identifier: device.Identifier,
RegisterIP: device.Ip,
UserAgent: device.UserAgent,
Timestamp: time.Now().UnixMilli(),
}
content, _ := registerLog.Marshal()
if err := tx.Create(&log.SystemLog{
Type: log.TypeRegister.Uint8(),
Date: time.Now().Format("2006-01-02"),
ObjectID: newUser.Id,
Content: string(content),
}).Error; err != nil {
l.Errorw("failed to insert register log",
logger.Field("user_id", newUser.Id),
logger.Field("error", err.Error()),
)
// Log error but don't fail transaction
}
// 4. 迁移设备和认证记录到新用户
// 更新设备归属
if err := tx.Model(&user.Device{}).Where("id = ?", device.Id).Update("user_id", newUser.Id).Error; err != nil {
return errors.Wrapf(xerr.NewErrCode(xerr.DatabaseUpdateError), "update device owner failed: %v", err)
}
// 更新认证归属
if err := tx.Model(&user.AuthMethods{}).Where("id = ?", userAuth.Id).Update("user_id", newUser.Id).Error; err != nil {
return errors.Wrapf(xerr.NewErrCode(xerr.DatabaseUpdateError), "update auth owner failed: %v", err)
}
// 5. 检查原用户是否还有其他认证方式,如果没有则删除原用户
var count int64
err = tx.Model(user.AuthMethods{}).Where("user_id = ?", device.UserId).Count(&count).Error
if err != nil {
return errors.Wrapf(xerr.NewErrCode(xerr.DatabaseQueryError), "count user auth methods err: %v", err)
}
if count < 1 {
if err := tx.Where("id = ?", device.UserId).Delete(&user.User{}).Error; err != nil {
return errors.Wrapf(xerr.NewErrCode(xerr.DatabaseDeletedError), "delete old user failed: %v", err)
}
}
// 6. 清理缓存
l.Infow("设备解绑并迁移成功",
logger.Field("device_identifier", device.Identifier),
logger.Field("old_user_id", device.UserId),
logger.Field("new_user_id", newUser.Id))
return nil
})
if err != nil {
return err
}
duration := time.Since(start)
identifier := device.Identifier
ctx, cancel := context.WithTimeout(l.ctx, 2*time.Second)
defer cancel()
deviceCacheKey := fmt.Sprintf("%v:%v", config.DeviceCacheKeyKey, identifier)
if sessionId, rerr := l.svcCtx.Redis.Get(ctx, deviceCacheKey).Result(); rerr == nil && sessionId != "" {
_ = l.svcCtx.Redis.Del(ctx, deviceCacheKey).Err()
sessionIdCacheKey := fmt.Sprintf("%v:%v", config.SessionIdKey, sessionId)
_ = l.svcCtx.Redis.Del(ctx, sessionIdCacheKey).Err()
}
l.Infow("设备解绑完成",
logger.Field("device_identifier", identifier),
logger.Field("elapsed_ms", duration.Milliseconds()))
return nil
}