- 删除 /browsers 列表/创建/详情页与菜单项,运行环境不再是独立资源 - 账号详情:GET /api/phase-a/accounts/:id 内联 environment 字段 (网关/出口/绑定版本/运行实例/不可调度原因),固定资源卡直接展示 - 状态卡两态开关:暂停→「启动账号」(start=resume+启动环境), 运行中→「暂停账号」(联动停环境);出口重绑卡片内完成 (POST /network-exits/:id/rebind 返回内联 environment,出口切换不再跳环境页) - 删除 creator/settings 残留的转写服务字段(后端 settings 无此列) - helpers.ts accountReadiness 改用 runtime_id/runtime_cleanup_pending - network-exits 列表绑定账号列改由账号列表内联数据驱动 - 全量验证:go test ./...(PG)全绿、tsc --noEmit 通过、max build 通过、 node --test 12/12 通过
321 lines
12 KiB
Go
321 lines
12 KiB
Go
package api
|
|
|
|
import (
|
|
"bytes"
|
|
"encoding/json"
|
|
"errors"
|
|
"io"
|
|
"strconv"
|
|
"strings"
|
|
"time"
|
|
|
|
accountdomain "git.ipao.vip/rogee/creator-hub/internal/account"
|
|
hub "git.ipao.vip/rogee/creator-hub/internal/environment"
|
|
"github.com/gofiber/fiber/v3"
|
|
)
|
|
|
|
type accountRequest struct {
|
|
Name string `json:"name"`
|
|
Platform string `json:"platform"`
|
|
PlatformAccountKey string `json:"platform_account_key"`
|
|
Tags []string `json:"tags"`
|
|
Cookies string `json:"cookies"`
|
|
}
|
|
|
|
// RegisterAccountRoutes exposes account lifecycle routes (create with auto-binding/list/detail/补建/start/pause/resume/revoke + audit).
|
|
func RegisterAccountRoutes(app *fiber.App, store *accountdomain.Store, runtimeStore HubStore, credentials accountdomain.CredentialBridge) {
|
|
app.Post("/api/phase-a/accounts", func(c fiber.Ctx) error {
|
|
var input accountRequest
|
|
if err := decodePhaseA(c, &input); err != nil {
|
|
return phaseAError(c, err)
|
|
}
|
|
tags := input.Tags
|
|
if tags == nil {
|
|
tags = []string{}
|
|
}
|
|
for index := range tags {
|
|
tags[index] = strings.TrimSpace(tags[index])
|
|
}
|
|
accountID := accountdomain.NewAccountID()
|
|
account := accountdomain.Account{
|
|
ID: accountID, Name: strings.TrimSpace(input.Name), Platform: strings.TrimSpace(input.Platform),
|
|
PlatformAccountKey: strings.TrimSpace(input.PlatformAccountKey), Tags: tags, Cookies: strings.TrimSpace(input.Cookies),
|
|
CredentialReference: accountdomain.CredentialReference{ID: accountID + "-cookies", Provider: "os_keyring"},
|
|
CredentialKey: "creatorhub/" + accountID + "/cookies",
|
|
AuthorizationStatus: "authorized", RuntimeStatus: "paused", Version: 1,
|
|
}
|
|
if err := store.CreateAccount(c.Context(), account, credentials); err != nil {
|
|
if errors.Is(err, accountdomain.ErrAccountCreationUnknown) {
|
|
return c.Status(fiber.StatusServiceUnavailable).JSON(map[string]string{
|
|
"error": "account creation result is unknown", "reason_code": "account_creation_result_unknown", "account_id": accountID,
|
|
})
|
|
}
|
|
return phaseAError(c, err)
|
|
}
|
|
// 账号即环境:创建即绑定(幂等)。绑定失败透传原因与账号 ID,客户端可用幂等补建端点重试。
|
|
if runtimeStore != nil {
|
|
if _, _, err := ensureAccountEnvironment(c.Context(), runtimeStore, accountID); err != nil {
|
|
return c.Status(fiber.StatusServiceUnavailable).JSON(map[string]string{
|
|
"error": err.Error(), "reason_code": "environment_binding_failed", "account_id": accountID,
|
|
})
|
|
}
|
|
}
|
|
return c.Status(fiber.StatusCreated).JSON(account)
|
|
})
|
|
|
|
app.Get("/api/phase-a/accounts", func(c fiber.Ctx) error {
|
|
accounts, err := store.ListAccounts(c.Context())
|
|
if err != nil {
|
|
return phaseAError(c, err)
|
|
}
|
|
return c.JSON(accounts)
|
|
})
|
|
|
|
app.Get("/api/phase-a/accounts/:id", accountDetailPayload(store, runtimeStore))
|
|
|
|
app.Post("/api/phase-a/accounts/:id/pause", func(c fiber.Ctx) error {
|
|
unlock, err := lockAccountResources(c.Context(), runtimeStore, c.Params("id"))
|
|
if err != nil {
|
|
return hubError(c, err)
|
|
}
|
|
defer unlock()
|
|
if err := store.PauseAccount(c.Context(), c.Params("id")); err != nil {
|
|
return phaseAError(c, err)
|
|
}
|
|
if runtimeStore != nil {
|
|
if err := stopAccountRuntime(c.Context(), runtimeStore, c.Params("id")); err != nil {
|
|
return hubError(c, err)
|
|
}
|
|
}
|
|
return c.SendStatus(fiber.StatusNoContent)
|
|
})
|
|
|
|
app.Post("/api/phase-a/accounts/:id/resume", func(c fiber.Ctx) error {
|
|
unlock, err := lockAccountResources(c.Context(), runtimeStore, c.Params("id"))
|
|
if err != nil {
|
|
return hubError(c, err)
|
|
}
|
|
defer unlock()
|
|
if err := store.ResumeAccount(c.Context(), c.Params("id")); err != nil {
|
|
if errors.Is(err, accountdomain.ErrConflict) {
|
|
return accountResumeConflict(c, store, runtimeStore, c.Params("id"))
|
|
}
|
|
return phaseAError(c, err)
|
|
}
|
|
return c.SendStatus(fiber.StatusNoContent)
|
|
})
|
|
|
|
// 账号即环境:幂等补建运行环境(网关缺失/多网关透传错误)。
|
|
app.Post("/api/phase-a/accounts/:id/environment", func(c fiber.Ctx) error {
|
|
if runtimeStore == nil {
|
|
return c.Status(fiber.StatusServiceUnavailable).JSON(map[string]string{"error": "environment store unavailable"})
|
|
}
|
|
unlock, err := lockAccountResources(c.Context(), runtimeStore, c.Params("id"))
|
|
if err != nil {
|
|
return hubError(c, err)
|
|
}
|
|
defer unlock()
|
|
environment, created, err := ensureAccountEnvironment(c.Context(), runtimeStore, c.Params("id"))
|
|
if err != nil {
|
|
return hubError(c, err)
|
|
}
|
|
return c.JSON(map[string]any{"alias": environment.Alias, "gateway": environment.Gateway, "created": created})
|
|
})
|
|
|
|
// 账号即环境:start = resume + 启动环境;停止沿用 pause(已联动停环境)。
|
|
app.Post("/api/phase-a/accounts/:id/start", func(c fiber.Ctx) error {
|
|
if runtimeStore == nil {
|
|
return c.Status(fiber.StatusServiceUnavailable).JSON(map[string]string{"error": "environment store unavailable"})
|
|
}
|
|
unlock, err := lockAccountResources(c.Context(), runtimeStore, c.Params("id"))
|
|
if err != nil {
|
|
return hubError(c, err)
|
|
}
|
|
defer unlock()
|
|
if err := store.ResumeAccount(c.Context(), c.Params("id")); err != nil {
|
|
if errors.Is(err, accountdomain.ErrConflict) {
|
|
return accountResumeConflict(c, store, runtimeStore, c.Params("id"))
|
|
}
|
|
return phaseAError(c, err)
|
|
}
|
|
if err := startAccountEnvironment(c.Context(), runtimeStore, c.Params("id")); err != nil {
|
|
return hubError(c, err)
|
|
}
|
|
return c.SendStatus(fiber.StatusNoContent)
|
|
})
|
|
|
|
app.Post("/api/phase-a/accounts/:id/revoke", func(c fiber.Ctx) error {
|
|
unlock, err := lockAccountResources(c.Context(), runtimeStore, c.Params("id"))
|
|
if err != nil {
|
|
return hubError(c, err)
|
|
}
|
|
defer unlock()
|
|
if err := store.RevokeAccount(c.Context(), c.Params("id")); err != nil {
|
|
return phaseAError(c, err)
|
|
}
|
|
if runtimeStore != nil {
|
|
if err := stopAccountRuntime(c.Context(), runtimeStore, c.Params("id")); err != nil {
|
|
return hubError(c, err)
|
|
}
|
|
}
|
|
return c.SendStatus(fiber.StatusNoContent)
|
|
})
|
|
|
|
app.Get("/api/phase-a/audit", func(c fiber.Ctx) error {
|
|
filter, err := auditFilter(c)
|
|
if err != nil {
|
|
return phaseAError(c, err)
|
|
}
|
|
events, err := store.ListAudit(c.Context(), filter)
|
|
if err != nil {
|
|
return phaseAError(c, err)
|
|
}
|
|
return c.JSON(events)
|
|
})
|
|
}
|
|
|
|
func auditFilter(c fiber.Ctx) (accountdomain.AuditFilter, error) {
|
|
filter := accountdomain.AuditFilter{
|
|
AccountID: c.Query("account_id"),
|
|
BrowserEnvAlias: c.Query("browser_env_alias"), NetworkExitID: c.Query("network_exit_id"),
|
|
EventType: c.Query("event_type"), Page: 1, PageSize: 25,
|
|
}
|
|
for _, field := range []struct {
|
|
value string
|
|
target *int
|
|
}{{c.Query("page"), &filter.Page}, {c.Query("page_size"), &filter.PageSize}} {
|
|
value, target := field.value, field.target
|
|
if value == "" {
|
|
continue
|
|
}
|
|
parsed, err := strconv.Atoi(value)
|
|
if err != nil {
|
|
return accountdomain.AuditFilter{}, accountdomain.ErrInvalid
|
|
}
|
|
*target = parsed
|
|
}
|
|
for _, field := range []struct {
|
|
value string
|
|
target **time.Time
|
|
}{{c.Query("from"), &filter.From}, {c.Query("to"), &filter.To}} {
|
|
value, target := field.value, field.target
|
|
if value == "" {
|
|
continue
|
|
}
|
|
parsed, err := time.Parse(time.RFC3339, value)
|
|
if err != nil {
|
|
return accountdomain.AuditFilter{}, accountdomain.ErrInvalid
|
|
}
|
|
*target = &parsed
|
|
}
|
|
return filter, nil
|
|
}
|
|
|
|
func resumeBlockReason(account accountdomain.Account, environment hub.EnvironmentContext, bindingFound bool) string {
|
|
switch {
|
|
case account.AuthorizationStatus != "authorized":
|
|
return "account_revoked"
|
|
case !bindingFound:
|
|
return "binding_missing"
|
|
case environment.Exit.ID != "" && environment.Exit.HealthStatus != "healthy":
|
|
return "network_exit_unhealthy"
|
|
case environment.RuntimeCleanupPending:
|
|
return "runtime_stop_pending"
|
|
case environment.RuntimeID != "":
|
|
return "runtime_active"
|
|
default:
|
|
return "account_conflict"
|
|
}
|
|
}
|
|
|
|
func accountResumeConflict(c fiber.Ctx, store *accountdomain.Store, runtimeStore RuntimeStopStore, accountID string) error {
|
|
account, err := store.GetAccount(c.Context(), accountID)
|
|
if err != nil {
|
|
return phaseAError(c, err)
|
|
}
|
|
var environment hub.EnvironmentContext
|
|
bindingFound := false
|
|
if runtimeStore != nil {
|
|
environment, err = runtimeStore.GetEnvironmentContextForAccount(c.Context(), accountID)
|
|
bindingFound = err == nil
|
|
if err != nil && !errors.Is(err, hub.ErrNotFound) {
|
|
return phaseAError(c, err)
|
|
}
|
|
}
|
|
return c.Status(fiber.StatusConflict).JSON(map[string]string{
|
|
"error": accountdomain.ErrConflict.Error(), "reason_code": resumeBlockReason(account, environment, bindingFound), "readiness": "blocked",
|
|
})
|
|
}
|
|
|
|
func decodePhaseA(c fiber.Ctx, destination any) error {
|
|
decoder := json.NewDecoder(bytes.NewReader(c.Body()))
|
|
decoder.DisallowUnknownFields()
|
|
if err := decoder.Decode(destination); err != nil {
|
|
return accountdomain.ErrInvalid
|
|
}
|
|
if err := decoder.Decode(&struct{}{}); !errors.Is(err, io.EOF) {
|
|
return accountdomain.ErrInvalid
|
|
}
|
|
return nil
|
|
}
|
|
|
|
func phaseAError(c fiber.Ctx, err error) error {
|
|
status := fiber.StatusInternalServerError
|
|
message := "phase A operation failed"
|
|
var readiness *accountdomain.ReadinessError
|
|
switch {
|
|
case errors.As(err, &readiness):
|
|
status, message = fiber.StatusConflict, "phase A version or account state changed"
|
|
if readiness.Unavailable {
|
|
status, message = fiber.StatusServiceUnavailable, "phase A resources are not ready"
|
|
}
|
|
return c.Status(status).JSON(map[string]string{"error": message, "reason_code": readiness.Reason})
|
|
case errors.Is(err, accountdomain.ErrInvalid):
|
|
status, message = fiber.StatusBadRequest, accountdomain.ErrInvalid.Error()
|
|
case errors.Is(err, accountdomain.ErrConflict):
|
|
status, message = fiber.StatusConflict, accountdomain.ErrConflict.Error()
|
|
case errors.Is(err, accountdomain.ErrNotFound):
|
|
status, message = fiber.StatusNotFound, accountdomain.ErrNotFound.Error()
|
|
}
|
|
return c.Status(status).JSON(map[string]string{"error": message})
|
|
}
|
|
|
|
// PhaseAError maps account errors to the existing HTTP contract.
|
|
func PhaseAError(c fiber.Ctx, err error) error {
|
|
return phaseAError(c, err)
|
|
}
|
|
|
|
// accountEnvironmentView 账号详情/出口重绑共用:账号即环境下内联展示的环境视图(schedule_block_reason 取值同 envView)。
|
|
func accountEnvironmentView(environment hub.EnvironmentContext) map[string]any {
|
|
scheduleStatus, scheduleBlockReason := environmentScheduleReadiness(environment)
|
|
return map[string]any{
|
|
"alias": environment.Alias, "name": environment.Name, "gateway": environment.Gateway,
|
|
"binding_version": environment.BindingVersion, "runtime_id": environment.RuntimeID,
|
|
"runtime_cleanup_pending": environment.RuntimeCleanupPending,
|
|
"network_exit_id": environment.Exit.ID, "network_exit_health": environment.Exit.HealthStatus,
|
|
"schedule_status": scheduleStatus, "schedule_block_reason": scheduleBlockReason,
|
|
}
|
|
}
|
|
|
|
// accountDetailPayload 账号详情:环境信息内联在响应中(账号即环境),前端无需单独请求 /browsers。
|
|
func accountDetailPayload(store *accountdomain.Store, runtimeStore HubStore) fiber.Handler {
|
|
return func(c fiber.Ctx) error {
|
|
account, err := store.GetAccount(c.Context(), c.Params("id"))
|
|
if err != nil {
|
|
return phaseAError(c, err)
|
|
}
|
|
payload := map[string]any{
|
|
"id": account.ID, "name": account.Name, "platform": account.Platform,
|
|
"platform_account_key": account.PlatformAccountKey, "tags": account.Tags,
|
|
"authorization_status": account.AuthorizationStatus, "runtime_status": account.RuntimeStatus,
|
|
"version": account.Version,
|
|
}
|
|
if runtimeStore != nil {
|
|
if environment, envErr := runtimeStore.GetEnvironmentContextForAccount(c.Context(), account.ID); envErr == nil {
|
|
payload["environment"] = accountEnvironmentView(environment)
|
|
}
|
|
}
|
|
return c.JSON(payload)
|
|
}
|
|
}
|