feat(api): tiered cumulative quota + self-service registration
Anonymous callers get a free cumulative quota (1000 calls per IP); once exhausted they get 403 quota_exhausted and must register. Public users can self-register (email+password) to obtain a higher-quota API key, view usage, and regenerate the key. Quota counters live in Redis; the public API stays read-only except for the registration writes. - migration 0011: app_user table + api_key.quota_total + 'registered' tier - ratelimit: IncrTotal/TotalUsed/CopyTotal lifetime counters - middleware: enforce cumulative quota + X-Quota-* headers - store: RegisterUser/Authenticate/RegenerateKey (bcrypt) - handlers: POST /api/v1/register, /account, /account/regenerate - admin: quota_total column + registered tier - public: 'API 密钥' account page + API docs quota section Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
This commit is contained in:
@@ -116,6 +116,45 @@ func (l *Limiter) RecordUsage(ctx context.Context, keyID string) {
|
||||
_, _ = pipe.Exec(ctx)
|
||||
}
|
||||
|
||||
// IncrTotal increments the lifetime call counter for subject and returns the
|
||||
// new total. The counter never expires; it is the cumulative number of calls
|
||||
// attributed to a caller (an API key id, or "ip:<addr>" for anonymous callers).
|
||||
// Fails open returning 0 on any error so quota enforcement never takes the API
|
||||
// down.
|
||||
func (l *Limiter) IncrTotal(ctx context.Context, subject string) int64 {
|
||||
if !l.Enabled() || subject == "" {
|
||||
return 0
|
||||
}
|
||||
n, err := l.rdb.Incr(ctx, "usage:total:"+subject).Result()
|
||||
if err != nil {
|
||||
return 0
|
||||
}
|
||||
return n
|
||||
}
|
||||
|
||||
// CopyTotal carries a lifetime counter from one subject to another, used when a
|
||||
// key is regenerated so a caller cannot reset their cumulative quota. Best
|
||||
// effort: a missing or zero source counter is a no-op.
|
||||
func (l *Limiter) CopyTotal(ctx context.Context, from, to string) {
|
||||
if !l.Enabled() || from == "" || to == "" {
|
||||
return
|
||||
}
|
||||
n, err := l.rdb.Get(ctx, "usage:total:"+from).Int64()
|
||||
if err != nil || n == 0 {
|
||||
return
|
||||
}
|
||||
l.rdb.Set(ctx, "usage:total:"+to, n, 0)
|
||||
}
|
||||
|
||||
// TotalUsed reads the lifetime call counter for subject without incrementing.
|
||||
func (l *Limiter) TotalUsed(ctx context.Context, subject string) int64 {
|
||||
if !l.Enabled() || subject == "" {
|
||||
return 0
|
||||
}
|
||||
n, _ := l.rdb.Get(ctx, "usage:total:"+subject).Int64()
|
||||
return n
|
||||
}
|
||||
|
||||
// Usage reads aggregated usage for a key. Returns a zero-value stat on error.
|
||||
func (l *Limiter) Usage(ctx context.Context, keyID string) UsageStat {
|
||||
var st UsageStat
|
||||
|
||||
Reference in New Issue
Block a user