feat(admin): 运营后台(登录/查看/审核编辑/补全)+ 写入API + 审计留痕
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
This commit is contained in:
@@ -0,0 +1,28 @@
|
||||
# Admin console image: builds the SPA (node), embeds it into the Go admin
|
||||
# binary, and ships a static scratch runtime. Build context is the repo root.
|
||||
|
||||
# Stage 1: build the admin SPA.
|
||||
FROM node:22-alpine AS web
|
||||
WORKDIR /web
|
||||
COPY admin-frontend/package.json admin-frontend/package-lock.json* ./
|
||||
RUN npm ci || npm install
|
||||
COPY admin-frontend/ ./
|
||||
RUN npm run build
|
||||
|
||||
# Stage 2: build the Go admin binary with the SPA embedded.
|
||||
FROM golang:1.23-alpine AS build
|
||||
ENV GOPROXY=https://goproxy.cn,direct
|
||||
WORKDIR /src
|
||||
COPY api/go.mod api/go.sum ./
|
||||
RUN go mod download
|
||||
COPY api/ ./
|
||||
RUN rm -rf internal/adminweb/dist && mkdir -p internal/adminweb/dist
|
||||
COPY --from=web /web/dist/ internal/adminweb/dist/
|
||||
RUN CGO_ENABLED=0 go build -o /out/admin ./cmd/admin
|
||||
|
||||
# Stage 3: minimal runtime.
|
||||
FROM scratch
|
||||
COPY --from=build /etc/ssl/certs/ca-certificates.crt /etc/ssl/certs/
|
||||
COPY --from=build /out/admin /admin
|
||||
EXPOSE 8080
|
||||
ENTRYPOINT ["/admin"]
|
||||
@@ -0,0 +1,83 @@
|
||||
// Command admin starts the OpenGoods admin console (authenticated write API +
|
||||
// embedded SPA), served under a base path (default /ping).
|
||||
package main
|
||||
|
||||
import (
|
||||
"context"
|
||||
"crypto/rand"
|
||||
"log"
|
||||
"net/http"
|
||||
"os"
|
||||
"time"
|
||||
|
||||
"github.com/jackc/pgx/v5/pgxpool"
|
||||
"golang.org/x/crypto/bcrypt"
|
||||
|
||||
"github.com/baicai2026-baicai/goods/api/internal/adminhandler"
|
||||
"github.com/baicai2026-baicai/goods/api/internal/adminstore"
|
||||
"github.com/baicai2026-baicai/goods/api/internal/adminweb"
|
||||
"github.com/baicai2026-baicai/goods/api/internal/auth"
|
||||
)
|
||||
|
||||
func getenv(key, fallback string) string {
|
||||
if v, ok := os.LookupEnv(key); ok && v != "" {
|
||||
return v
|
||||
}
|
||||
return fallback
|
||||
}
|
||||
|
||||
func main() {
|
||||
addr := getenv("GOODS_ADMIN_ADDR", ":8080")
|
||||
dbURL := getenv("OPENGOODS_DATABASE_URL", "postgres://opengoods:opengoods@localhost:5432/opengoods?sslmode=disable")
|
||||
basePath := getenv("GOODS_ADMIN_BASE_PATH", "/ping")
|
||||
username := getenv("GOODS_ADMIN_USER", "admin")
|
||||
|
||||
// Password: prefer a bcrypt hash; otherwise hash a plaintext password.
|
||||
var passwordHash []byte
|
||||
if h := os.Getenv("GOODS_ADMIN_PASSWORD_HASH"); h != "" {
|
||||
passwordHash = []byte(h)
|
||||
} else if p := os.Getenv("GOODS_ADMIN_PASSWORD"); p != "" {
|
||||
hashed, err := bcrypt.GenerateFromPassword([]byte(p), bcrypt.DefaultCost)
|
||||
if err != nil {
|
||||
log.Fatalf("failed to hash admin password: %v", err)
|
||||
}
|
||||
passwordHash = hashed
|
||||
} else {
|
||||
log.Fatal("set GOODS_ADMIN_PASSWORD or GOODS_ADMIN_PASSWORD_HASH")
|
||||
}
|
||||
|
||||
secret := []byte(os.Getenv("GOODS_ADMIN_JWT_SECRET"))
|
||||
if len(secret) == 0 {
|
||||
secret = make([]byte, 32)
|
||||
if _, err := rand.Read(secret); err != nil {
|
||||
log.Fatalf("failed to generate jwt secret: %v", err)
|
||||
}
|
||||
log.Print("warning: GOODS_ADMIN_JWT_SECRET not set; using a random secret (tokens invalidate on restart)")
|
||||
}
|
||||
|
||||
ctx := context.Background()
|
||||
pool, err := pgxpool.New(ctx, dbURL)
|
||||
if err != nil {
|
||||
log.Fatalf("failed to create db pool: %v", err)
|
||||
}
|
||||
defer pool.Close()
|
||||
|
||||
pingCtx, cancel := context.WithTimeout(ctx, 5*time.Second)
|
||||
defer cancel()
|
||||
if err := pool.Ping(pingCtx); err != nil {
|
||||
log.Printf("warning: database not reachable at startup: %v", err)
|
||||
}
|
||||
|
||||
authn := auth.New(username, passwordHash, secret, 12*time.Hour)
|
||||
h := adminhandler.New(adminstore.New(pool), authn, basePath, adminweb.Dist())
|
||||
|
||||
srv := &http.Server{
|
||||
Addr: addr,
|
||||
Handler: h.Router(),
|
||||
ReadHeaderTimeout: 10 * time.Second,
|
||||
}
|
||||
log.Printf("OpenGoods admin console listening on %s (base path %s)", addr, basePath)
|
||||
if err := srv.ListenAndServe(); err != nil && err != http.ErrServerClosed {
|
||||
log.Fatalf("server error: %v", err)
|
||||
}
|
||||
}
|
||||
+1
-1
@@ -5,13 +5,13 @@ go 1.23.4
|
||||
require (
|
||||
github.com/go-chi/chi/v5 v5.1.0
|
||||
github.com/jackc/pgx/v5 v5.7.2
|
||||
golang.org/x/crypto v0.31.0
|
||||
)
|
||||
|
||||
require (
|
||||
github.com/jackc/pgpassfile v1.0.0 // indirect
|
||||
github.com/jackc/pgservicefile v0.0.0-20240606120523-5a60cdf6a761 // indirect
|
||||
github.com/jackc/puddle/v2 v2.2.2 // indirect
|
||||
golang.org/x/crypto v0.31.0 // indirect
|
||||
golang.org/x/sync v0.10.0 // indirect
|
||||
golang.org/x/text v0.21.0 // indirect
|
||||
)
|
||||
|
||||
@@ -0,0 +1,284 @@
|
||||
// Package adminhandler wires up the authenticated admin console: a JSON write
|
||||
// API mounted under a base path (default /ping) plus the embedded SPA.
|
||||
package adminhandler
|
||||
|
||||
import (
|
||||
"encoding/json"
|
||||
"errors"
|
||||
"io/fs"
|
||||
"net/http"
|
||||
"strings"
|
||||
|
||||
"github.com/go-chi/chi/v5"
|
||||
"github.com/go-chi/chi/v5/middleware"
|
||||
|
||||
"github.com/baicai2026-baicai/goods/api/internal/adminstore"
|
||||
"github.com/baicai2026-baicai/goods/api/internal/auth"
|
||||
)
|
||||
|
||||
// Handler holds the admin dependencies.
|
||||
type Handler struct {
|
||||
store *adminstore.Store
|
||||
authn *auth.Authenticator
|
||||
basePath string
|
||||
spa fs.FS
|
||||
}
|
||||
|
||||
// New constructs an admin Handler. basePath is e.g. "/ping" (no trailing slash).
|
||||
func New(store *adminstore.Store, authn *auth.Authenticator, basePath string, spa fs.FS) *Handler {
|
||||
basePath = "/" + strings.Trim(basePath, "/")
|
||||
return &Handler{store: store, authn: authn, basePath: basePath, spa: spa}
|
||||
}
|
||||
|
||||
// Router builds the HTTP handler.
|
||||
func (h *Handler) Router() http.Handler {
|
||||
r := chi.NewRouter()
|
||||
r.Use(middleware.RequestID)
|
||||
r.Use(middleware.RealIP)
|
||||
r.Use(middleware.Recoverer)
|
||||
|
||||
r.Route(h.basePath, func(r chi.Router) {
|
||||
r.Get("/healthz", func(w http.ResponseWriter, _ *http.Request) {
|
||||
writeJSON(w, http.StatusOK, map[string]string{"status": "ok"})
|
||||
})
|
||||
r.Post("/api/login", h.Login)
|
||||
|
||||
r.Group(func(r chi.Router) {
|
||||
r.Use(h.authn.Middleware)
|
||||
r.Get("/api/me", h.Me)
|
||||
r.Get("/api/products", h.ListProducts)
|
||||
r.Get("/api/products/{id}", h.GetProduct)
|
||||
r.Put("/api/products/{id}", h.UpdateProduct)
|
||||
r.Get("/api/products/{id}/audit", h.ListAudit)
|
||||
r.Post("/api/products/{id}/images", h.AddImage)
|
||||
r.Delete("/api/products/{id}/images/{imageID}", h.DeleteImage)
|
||||
r.Post("/api/products/{id}/msrp", h.AddMSRP)
|
||||
r.Delete("/api/products/{id}/msrp/{msrpID}", h.DeleteMSRP)
|
||||
r.Get("/api/brands", h.ListBrands)
|
||||
r.Get("/api/categories", h.ListCategories)
|
||||
})
|
||||
|
||||
r.Handle("/*", http.HandlerFunc(h.serveSPA))
|
||||
})
|
||||
return r
|
||||
}
|
||||
|
||||
func (h *Handler) serveSPA(w http.ResponseWriter, r *http.Request) {
|
||||
rel := strings.TrimPrefix(r.URL.Path, h.basePath)
|
||||
rel = strings.TrimPrefix(rel, "/")
|
||||
if rel == "" {
|
||||
rel = "index.html"
|
||||
}
|
||||
if f, err := h.spa.Open(rel); err == nil {
|
||||
f.Close()
|
||||
http.StripPrefix(h.basePath+"/", http.FileServer(http.FS(h.spa))).ServeHTTP(w, r)
|
||||
return
|
||||
}
|
||||
// SPA fallback: serve index.html for client-side routes.
|
||||
index, err := h.spa.Open("index.html")
|
||||
if err != nil {
|
||||
http.NotFound(w, r)
|
||||
return
|
||||
}
|
||||
defer index.Close()
|
||||
data, _ := fs.ReadFile(h.spa, "index.html")
|
||||
w.Header().Set("Content-Type", "text/html; charset=utf-8")
|
||||
_, _ = w.Write(data)
|
||||
}
|
||||
|
||||
// ---------- auth ----------
|
||||
|
||||
// Login authenticates and returns a bearer token.
|
||||
func (h *Handler) Login(w http.ResponseWriter, r *http.Request) {
|
||||
var body struct {
|
||||
Username string `json:"username"`
|
||||
Password string `json:"password"`
|
||||
}
|
||||
if err := json.NewDecoder(r.Body).Decode(&body); err != nil {
|
||||
writeError(w, http.StatusBadRequest, "bad_request", "invalid body")
|
||||
return
|
||||
}
|
||||
token, err := h.authn.Login(body.Username, body.Password)
|
||||
if err != nil {
|
||||
writeError(w, http.StatusUnauthorized, "unauthorized", "用户名或密码错误")
|
||||
return
|
||||
}
|
||||
writeJSON(w, http.StatusOK, map[string]string{"token": token, "username": body.Username})
|
||||
}
|
||||
|
||||
// Me returns the current authenticated user.
|
||||
func (h *Handler) Me(w http.ResponseWriter, r *http.Request) {
|
||||
writeJSON(w, http.StatusOK, map[string]string{"username": auth.UserFrom(r.Context())})
|
||||
}
|
||||
|
||||
// ---------- products ----------
|
||||
|
||||
// ListProducts returns a paginated product list.
|
||||
func (h *Handler) ListProducts(w http.ResponseWriter, r *http.Request) {
|
||||
q := r.URL.Query().Get("q")
|
||||
page, size := pageParams(r)
|
||||
items, total, err := h.store.ListProducts(r.Context(), q, size, (page-1)*size)
|
||||
if h.handleErr(w, err) {
|
||||
return
|
||||
}
|
||||
writeJSON(w, http.StatusOK, map[string]any{
|
||||
"items": items, "page": page, "size": size, "total": total,
|
||||
"completeness_fields": adminstore.CompletenessFields,
|
||||
})
|
||||
}
|
||||
|
||||
// GetProduct returns full editable detail.
|
||||
func (h *Handler) GetProduct(w http.ResponseWriter, r *http.Request) {
|
||||
d, err := h.store.GetProduct(r.Context(), chi.URLParam(r, "id"))
|
||||
if h.handleErr(w, err) {
|
||||
return
|
||||
}
|
||||
writeJSON(w, http.StatusOK, d)
|
||||
}
|
||||
|
||||
// UpdateProduct applies an edit.
|
||||
func (h *Handler) UpdateProduct(w http.ResponseWriter, r *http.Request) {
|
||||
var in adminstore.ProductInput
|
||||
if err := json.NewDecoder(r.Body).Decode(&in); err != nil {
|
||||
writeError(w, http.StatusBadRequest, "bad_request", "invalid body")
|
||||
return
|
||||
}
|
||||
if strings.TrimSpace(in.Name) == "" {
|
||||
writeError(w, http.StatusBadRequest, "bad_request", "名称不能为空")
|
||||
return
|
||||
}
|
||||
d, err := h.store.UpdateProduct(r.Context(), chi.URLParam(r, "id"), auth.UserFrom(r.Context()), in)
|
||||
if h.handleErr(w, err) {
|
||||
return
|
||||
}
|
||||
writeJSON(w, http.StatusOK, d)
|
||||
}
|
||||
|
||||
// ListAudit returns audit history for a product.
|
||||
func (h *Handler) ListAudit(w http.ResponseWriter, r *http.Request) {
|
||||
items, err := h.store.ListAudit(r.Context(), chi.URLParam(r, "id"), 100)
|
||||
if h.handleErr(w, err) {
|
||||
return
|
||||
}
|
||||
writeJSON(w, http.StatusOK, map[string]any{"items": items})
|
||||
}
|
||||
|
||||
// AddImage adds an image URL.
|
||||
func (h *Handler) AddImage(w http.ResponseWriter, r *http.Request) {
|
||||
var body struct {
|
||||
URL string `json:"url"`
|
||||
Kind string `json:"kind"`
|
||||
}
|
||||
if err := json.NewDecoder(r.Body).Decode(&body); err != nil || strings.TrimSpace(body.URL) == "" {
|
||||
writeError(w, http.StatusBadRequest, "bad_request", "图片 URL 不能为空")
|
||||
return
|
||||
}
|
||||
im, err := h.store.AddImage(r.Context(), chi.URLParam(r, "id"), auth.UserFrom(r.Context()), body.URL, body.Kind)
|
||||
if h.handleErr(w, err) {
|
||||
return
|
||||
}
|
||||
writeJSON(w, http.StatusCreated, im)
|
||||
}
|
||||
|
||||
// DeleteImage removes an image.
|
||||
func (h *Handler) DeleteImage(w http.ResponseWriter, r *http.Request) {
|
||||
err := h.store.DeleteImage(r.Context(), chi.URLParam(r, "id"), chi.URLParam(r, "imageID"), auth.UserFrom(r.Context()))
|
||||
if h.handleErr(w, err) {
|
||||
return
|
||||
}
|
||||
writeJSON(w, http.StatusOK, map[string]string{"status": "deleted"})
|
||||
}
|
||||
|
||||
// AddMSRP adds a suggested-retail-price snapshot.
|
||||
func (h *Handler) AddMSRP(w http.ResponseWriter, r *http.Request) {
|
||||
var in adminstore.MSRPInput
|
||||
if err := json.NewDecoder(r.Body).Decode(&in); err != nil {
|
||||
writeError(w, http.StatusBadRequest, "bad_request", "invalid body")
|
||||
return
|
||||
}
|
||||
m, err := h.store.AddMSRP(r.Context(), chi.URLParam(r, "id"), auth.UserFrom(r.Context()), in)
|
||||
if h.handleErr(w, err) {
|
||||
return
|
||||
}
|
||||
writeJSON(w, http.StatusCreated, m)
|
||||
}
|
||||
|
||||
// DeleteMSRP removes an MSRP snapshot.
|
||||
func (h *Handler) DeleteMSRP(w http.ResponseWriter, r *http.Request) {
|
||||
err := h.store.DeleteMSRP(r.Context(), chi.URLParam(r, "id"), chi.URLParam(r, "msrpID"), auth.UserFrom(r.Context()))
|
||||
if h.handleErr(w, err) {
|
||||
return
|
||||
}
|
||||
writeJSON(w, http.StatusOK, map[string]string{"status": "deleted"})
|
||||
}
|
||||
|
||||
// ListBrands returns brand options.
|
||||
func (h *Handler) ListBrands(w http.ResponseWriter, r *http.Request) {
|
||||
items, err := h.store.ListBrands(r.Context())
|
||||
if h.handleErr(w, err) {
|
||||
return
|
||||
}
|
||||
writeJSON(w, http.StatusOK, map[string]any{"items": items})
|
||||
}
|
||||
|
||||
// ListCategories returns category options.
|
||||
func (h *Handler) ListCategories(w http.ResponseWriter, r *http.Request) {
|
||||
items, err := h.store.ListCategories(r.Context())
|
||||
if h.handleErr(w, err) {
|
||||
return
|
||||
}
|
||||
writeJSON(w, http.StatusOK, map[string]any{"items": items})
|
||||
}
|
||||
|
||||
// ---------- helpers ----------
|
||||
|
||||
func (h *Handler) handleErr(w http.ResponseWriter, err error) bool {
|
||||
if err == nil {
|
||||
return false
|
||||
}
|
||||
if errors.Is(err, adminstore.ErrNotFound) {
|
||||
writeError(w, http.StatusNotFound, "not_found", "资源不存在")
|
||||
return true
|
||||
}
|
||||
writeError(w, http.StatusInternalServerError, "internal_error", err.Error())
|
||||
return true
|
||||
}
|
||||
|
||||
func pageParams(r *http.Request) (page, size int) {
|
||||
page = atoiDefault(r.URL.Query().Get("page"), 1)
|
||||
if page < 1 {
|
||||
page = 1
|
||||
}
|
||||
size = atoiDefault(r.URL.Query().Get("size"), 20)
|
||||
if size < 1 {
|
||||
size = 20
|
||||
}
|
||||
if size > 100 {
|
||||
size = 100
|
||||
}
|
||||
return page, size
|
||||
}
|
||||
|
||||
func atoiDefault(s string, fallback int) int {
|
||||
if s == "" {
|
||||
return fallback
|
||||
}
|
||||
n := 0
|
||||
for _, c := range s {
|
||||
if c < '0' || c > '9' {
|
||||
return fallback
|
||||
}
|
||||
n = n*10 + int(c-'0')
|
||||
}
|
||||
return n
|
||||
}
|
||||
|
||||
func writeJSON(w http.ResponseWriter, status int, body any) {
|
||||
w.Header().Set("Content-Type", "application/json; charset=utf-8")
|
||||
w.WriteHeader(status)
|
||||
_ = json.NewEncoder(w).Encode(body)
|
||||
}
|
||||
|
||||
func writeError(w http.ResponseWriter, status int, code, message string) {
|
||||
writeJSON(w, status, map[string]any{"error": map[string]string{"code": code, "message": message}})
|
||||
}
|
||||
@@ -0,0 +1,282 @@
|
||||
// Package adminstore is the read/write data-access layer for the admin console.
|
||||
// Unlike the public store (read-only), it performs INSERT/UPDATE/DELETE and
|
||||
// records field-level provenance (source = "manual") plus an audit_log entry
|
||||
// for every write, then recomputes product.quality_score.
|
||||
package adminstore
|
||||
|
||||
import (
|
||||
"context"
|
||||
"encoding/json"
|
||||
"errors"
|
||||
"strconv"
|
||||
"time"
|
||||
|
||||
"github.com/jackc/pgx/v5"
|
||||
"github.com/jackc/pgx/v5/pgxpool"
|
||||
)
|
||||
|
||||
// ErrNotFound is returned when a requested row does not exist.
|
||||
var ErrNotFound = errors.New("not found")
|
||||
|
||||
// Store wraps a pgx pool for admin operations.
|
||||
type Store struct {
|
||||
pool *pgxpool.Pool
|
||||
}
|
||||
|
||||
// New constructs an admin Store.
|
||||
func New(pool *pgxpool.Pool) *Store { return &Store{pool: pool} }
|
||||
|
||||
// Ping verifies DB connectivity.
|
||||
func (s *Store) Ping(ctx context.Context) error { return s.pool.Ping(ctx) }
|
||||
|
||||
// CompletenessFields mirrors ingestion/opengoods/etl/quality.py COMPLETENESS_FIELDS.
|
||||
var CompletenessFields = []string{
|
||||
"name", "gtin", "brand", "category", "net_content",
|
||||
"country_of_origin", "nutriments", "ingredients", "image",
|
||||
}
|
||||
|
||||
// ---------- list ----------
|
||||
|
||||
// ProductRow is a list-view row for the admin product table.
|
||||
type ProductRow struct {
|
||||
ID string `json:"id"`
|
||||
GTIN *string `json:"gtin"`
|
||||
Name string `json:"name"`
|
||||
Brand *string `json:"brand"`
|
||||
CategoryPath *string `json:"category_path"`
|
||||
Status string `json:"status"`
|
||||
QualityScore float64 `json:"quality_score"`
|
||||
Missing []string `json:"missing"`
|
||||
UpdatedAt string `json:"updated_at"`
|
||||
}
|
||||
|
||||
// ListProducts returns a paginated, optionally name/gtin-filtered list.
|
||||
func (s *Store) ListProducts(ctx context.Context, q string, limit, offset int) ([]ProductRow, int, error) {
|
||||
args := []any{}
|
||||
where := "WHERE 1=1"
|
||||
if q != "" {
|
||||
args = append(args, q)
|
||||
where += " AND (p.name ILIKE '%' || $1 || '%' OR p.gtin ILIKE '%' || $1 || '%')"
|
||||
}
|
||||
|
||||
var total int
|
||||
if err := s.pool.QueryRow(ctx, "SELECT count(*) FROM product p "+where, args...).Scan(&total); err != nil {
|
||||
return nil, 0, err
|
||||
}
|
||||
|
||||
args = append(args, limit, offset)
|
||||
sql := `
|
||||
SELECT p.id, p.gtin, p.name, b.name, c.path::text, p.status, p.quality_score,
|
||||
p.updated_at,
|
||||
(p.brand_id IS NOT NULL) AS has_brand,
|
||||
(p.category_id IS NOT NULL) AS has_cat,
|
||||
(p.net_content_canonical IS NOT NULL) AS has_net,
|
||||
(p.country_of_origin IS NOT NULL AND p.country_of_origin <> '') AS has_country,
|
||||
(f.nutriments IS NOT NULL AND f.nutriments::text <> '{}') AS has_nutri,
|
||||
(f.ingredients_text IS NOT NULL AND f.ingredients_text <> '') AS has_ing,
|
||||
EXISTS (SELECT 1 FROM product_image pi WHERE pi.product_id = p.id) AS has_img
|
||||
FROM product p
|
||||
LEFT JOIN brand b ON b.id = p.brand_id
|
||||
LEFT JOIN category c ON c.id = p.category_id
|
||||
LEFT JOIN food_detail f ON f.product_id = p.id ` + where +
|
||||
" ORDER BY p.updated_at DESC LIMIT $" + strconv.Itoa(len(args)-1) + " OFFSET $" + strconv.Itoa(len(args))
|
||||
|
||||
rows, err := s.pool.Query(ctx, sql, args...)
|
||||
if err != nil {
|
||||
return nil, 0, err
|
||||
}
|
||||
defer rows.Close()
|
||||
|
||||
out := []ProductRow{}
|
||||
for rows.Next() {
|
||||
var r ProductRow
|
||||
var hasBrand, hasCat, hasNet, hasCountry, hasNutri, hasIng, hasImg bool
|
||||
var updated time.Time
|
||||
if err := rows.Scan(&r.ID, &r.GTIN, &r.Name, &r.Brand, &r.CategoryPath, &r.Status,
|
||||
&r.QualityScore, &updated, &hasBrand, &hasCat, &hasNet, &hasCountry,
|
||||
&hasNutri, &hasIng, &hasImg); err != nil {
|
||||
return nil, 0, err
|
||||
}
|
||||
r.UpdatedAt = updated.Format(time.RFC3339)
|
||||
present := map[string]bool{
|
||||
"name": r.Name != "",
|
||||
"gtin": r.GTIN != nil && *r.GTIN != "",
|
||||
"brand": hasBrand,
|
||||
"category": hasCat,
|
||||
"net_content": hasNet,
|
||||
"country_of_origin": hasCountry,
|
||||
"nutriments": hasNutri,
|
||||
"ingredients": hasIng,
|
||||
"image": hasImg,
|
||||
}
|
||||
r.Missing = []string{}
|
||||
for _, f := range CompletenessFields {
|
||||
if !present[f] {
|
||||
r.Missing = append(r.Missing, f)
|
||||
}
|
||||
}
|
||||
out = append(out, r)
|
||||
}
|
||||
return out, total, rows.Err()
|
||||
}
|
||||
|
||||
// ---------- detail ----------
|
||||
|
||||
// ProductImage is one image row.
|
||||
type ProductImage struct {
|
||||
ID string `json:"id"`
|
||||
URL string `json:"url"`
|
||||
Kind string `json:"kind"`
|
||||
License *string `json:"license"`
|
||||
}
|
||||
|
||||
// MSRP is one suggested-retail-price snapshot.
|
||||
type MSRP struct {
|
||||
ID string `json:"id"`
|
||||
Amount float64 `json:"amount"`
|
||||
Currency string `json:"currency"`
|
||||
Region string `json:"region"`
|
||||
EffectiveDate *string `json:"effective_date"`
|
||||
SourceURL *string `json:"source_url"`
|
||||
Note *string `json:"note"`
|
||||
}
|
||||
|
||||
// ProductDetail is the full editable view of a product.
|
||||
type ProductDetail struct {
|
||||
ID string `json:"id"`
|
||||
GTIN *string `json:"gtin"`
|
||||
Name string `json:"name"`
|
||||
BrandID *string `json:"brand_id"`
|
||||
Brand *string `json:"brand"`
|
||||
CategoryID *string `json:"category_id"`
|
||||
CategoryPath *string `json:"category_path"`
|
||||
NetContentValue *float64 `json:"net_content_value"`
|
||||
NetContentUnit *string `json:"net_content_unit"`
|
||||
CountryOfOrigin *string `json:"country_of_origin"`
|
||||
Status string `json:"status"`
|
||||
QualityScore float64 `json:"quality_score"`
|
||||
IngredientsText *string `json:"ingredients_text"`
|
||||
Allergens []string `json:"allergens"`
|
||||
Additives []string `json:"additives"`
|
||||
Nutriments map[string]any `json:"nutriments"`
|
||||
NutritionBasis *string `json:"nutrition_basis"`
|
||||
ServingSize *string `json:"serving_size"`
|
||||
NutriScore *string `json:"nutri_score"`
|
||||
Images []ProductImage `json:"images"`
|
||||
MSRP []MSRP `json:"msrp"`
|
||||
Missing []string `json:"missing"`
|
||||
UpdatedAt string `json:"updated_at"`
|
||||
}
|
||||
|
||||
// GetProduct returns the full editable detail for one product.
|
||||
func (s *Store) GetProduct(ctx context.Context, id string) (*ProductDetail, error) {
|
||||
var d ProductDetail
|
||||
var nutriments []byte
|
||||
var updated time.Time
|
||||
err := s.pool.QueryRow(ctx, `
|
||||
SELECT p.id, p.gtin, p.name, p.brand_id, b.name, p.category_id, c.path::text,
|
||||
p.net_content_value, p.net_content_unit, p.country_of_origin, p.status,
|
||||
p.quality_score, p.updated_at,
|
||||
f.ingredients_text, f.allergens, f.additives, f.nutriments,
|
||||
f.nutrition_basis, f.serving_size, f.nutri_score
|
||||
FROM product p
|
||||
LEFT JOIN brand b ON b.id = p.brand_id
|
||||
LEFT JOIN category c ON c.id = p.category_id
|
||||
LEFT JOIN food_detail f ON f.product_id = p.id
|
||||
WHERE p.id = $1`, id).Scan(
|
||||
&d.ID, &d.GTIN, &d.Name, &d.BrandID, &d.Brand, &d.CategoryID, &d.CategoryPath,
|
||||
&d.NetContentValue, &d.NetContentUnit, &d.CountryOfOrigin, &d.Status,
|
||||
&d.QualityScore, &updated,
|
||||
&d.IngredientsText, &d.Allergens, &d.Additives, &nutriments,
|
||||
&d.NutritionBasis, &d.ServingSize, &d.NutriScore,
|
||||
)
|
||||
if errors.Is(err, pgx.ErrNoRows) {
|
||||
return nil, ErrNotFound
|
||||
}
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
d.UpdatedAt = updated.Format(time.RFC3339)
|
||||
if len(nutriments) > 0 {
|
||||
_ = json.Unmarshal(nutriments, &d.Nutriments)
|
||||
}
|
||||
if d.Allergens == nil {
|
||||
d.Allergens = []string{}
|
||||
}
|
||||
if d.Additives == nil {
|
||||
d.Additives = []string{}
|
||||
}
|
||||
|
||||
imgs, err := s.listImages(ctx, id)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
d.Images = imgs
|
||||
|
||||
msrps, err := s.listMSRP(ctx, id)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
d.MSRP = msrps
|
||||
|
||||
d.Missing = missingFromDetail(&d)
|
||||
return &d, nil
|
||||
}
|
||||
|
||||
func missingFromDetail(d *ProductDetail) []string {
|
||||
present := map[string]bool{
|
||||
"name": d.Name != "",
|
||||
"gtin": d.GTIN != nil && *d.GTIN != "",
|
||||
"brand": d.BrandID != nil,
|
||||
"category": d.CategoryID != nil,
|
||||
"net_content": d.NetContentValue != nil,
|
||||
"country_of_origin": d.CountryOfOrigin != nil && *d.CountryOfOrigin != "",
|
||||
"nutriments": len(d.Nutriments) > 0,
|
||||
"ingredients": d.IngredientsText != nil && *d.IngredientsText != "",
|
||||
"image": len(d.Images) > 0,
|
||||
}
|
||||
missing := []string{}
|
||||
for _, f := range CompletenessFields {
|
||||
if !present[f] {
|
||||
missing = append(missing, f)
|
||||
}
|
||||
}
|
||||
return missing
|
||||
}
|
||||
|
||||
func (s *Store) listImages(ctx context.Context, productID string) ([]ProductImage, error) {
|
||||
rows, err := s.pool.Query(ctx,
|
||||
"SELECT id, url, kind, license FROM product_image WHERE product_id = $1 ORDER BY id", productID)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
defer rows.Close()
|
||||
out := []ProductImage{}
|
||||
for rows.Next() {
|
||||
var im ProductImage
|
||||
if err := rows.Scan(&im.ID, &im.URL, &im.Kind, &im.License); err != nil {
|
||||
return nil, err
|
||||
}
|
||||
out = append(out, im)
|
||||
}
|
||||
return out, rows.Err()
|
||||
}
|
||||
|
||||
func (s *Store) listMSRP(ctx context.Context, productID string) ([]MSRP, error) {
|
||||
rows, err := s.pool.Query(ctx, `
|
||||
SELECT id, amount, currency, region, effective_date::text, source_url, note
|
||||
FROM product_msrp WHERE product_id = $1 ORDER BY effective_date DESC NULLS LAST`, productID)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
defer rows.Close()
|
||||
out := []MSRP{}
|
||||
for rows.Next() {
|
||||
var m MSRP
|
||||
if err := rows.Scan(&m.ID, &m.Amount, &m.Currency, &m.Region, &m.EffectiveDate, &m.SourceURL, &m.Note); err != nil {
|
||||
return nil, err
|
||||
}
|
||||
out = append(out, m)
|
||||
}
|
||||
return out, rows.Err()
|
||||
}
|
||||
@@ -0,0 +1,137 @@
|
||||
package adminstore
|
||||
|
||||
import (
|
||||
"context"
|
||||
"math"
|
||||
"time"
|
||||
|
||||
"github.com/jackc/pgx/v5"
|
||||
)
|
||||
|
||||
// Quality weights mirror ingestion/opengoods/etl/quality.py.
|
||||
const (
|
||||
wCompleteness = 0.4
|
||||
wSourceTrust = 0.3
|
||||
wAgreement = 0.2
|
||||
wFreshness = 0.1
|
||||
)
|
||||
|
||||
// queryer is satisfied by both *pgxpool.Pool and pgx.Tx.
|
||||
type queryer interface {
|
||||
QueryRow(ctx context.Context, sql string, args ...any) pgx.Row
|
||||
}
|
||||
|
||||
func agreementFromSources(n int) float64 {
|
||||
switch {
|
||||
case n <= 1:
|
||||
return 0.5
|
||||
case n == 2:
|
||||
return 0.8
|
||||
default:
|
||||
return 1.0
|
||||
}
|
||||
}
|
||||
|
||||
func freshnessFromAge(ageDays *float64) float64 {
|
||||
if ageDays == nil {
|
||||
return 0.5
|
||||
}
|
||||
d := *ageDays
|
||||
switch {
|
||||
case d <= 30:
|
||||
return 1.0
|
||||
case d <= 180:
|
||||
return 0.8
|
||||
case d <= 365:
|
||||
return 0.6
|
||||
case d <= 730:
|
||||
return 0.4
|
||||
default:
|
||||
return 0.2
|
||||
}
|
||||
}
|
||||
|
||||
func (s *Store) computeQuality(ctx context.Context, q queryer, productID string) (float64, error) {
|
||||
var name, country *string
|
||||
var gtin *string
|
||||
var brandID, categoryID *string
|
||||
var netCanonical *float64
|
||||
var ingredients *string
|
||||
var hasNutri, hasImage bool
|
||||
err := q.QueryRow(ctx, `
|
||||
SELECT p.name, p.gtin, p.brand_id, p.category_id, p.net_content_canonical,
|
||||
p.country_of_origin, f.ingredients_text,
|
||||
(f.nutriments IS NOT NULL AND f.nutriments::text <> '{}'),
|
||||
EXISTS (SELECT 1 FROM product_image pi WHERE pi.product_id = p.id)
|
||||
FROM product p LEFT JOIN food_detail f ON f.product_id = p.id
|
||||
WHERE p.id = $1`, productID).Scan(
|
||||
&name, >in, &brandID, &categoryID, &netCanonical, &country,
|
||||
&ingredients, &hasNutri, &hasImage)
|
||||
if err != nil {
|
||||
return 0, err
|
||||
}
|
||||
|
||||
present := 0
|
||||
bump := func(ok bool) {
|
||||
if ok {
|
||||
present++
|
||||
}
|
||||
}
|
||||
bump(name != nil && *name != "")
|
||||
bump(gtin != nil && *gtin != "")
|
||||
bump(brandID != nil)
|
||||
bump(categoryID != nil)
|
||||
bump(netCanonical != nil)
|
||||
bump(country != nil && *country != "")
|
||||
bump(hasNutri)
|
||||
bump(ingredients != nil && *ingredients != "")
|
||||
bump(hasImage)
|
||||
completeness := float64(present) / float64(len(CompletenessFields))
|
||||
|
||||
var sourceCount int
|
||||
var sourceTrust *float64
|
||||
var lastFetched *time.Time
|
||||
err = q.QueryRow(ctx, `
|
||||
SELECT count(DISTINCT ps.source_id), COALESCE(max(s.trust_weight),0), max(ps.fetched_at)
|
||||
FROM product_source ps LEFT JOIN source s ON s.id = ps.source_id
|
||||
WHERE ps.product_id = $1`, productID).Scan(&sourceCount, &sourceTrust, &lastFetched)
|
||||
if err != nil {
|
||||
return 0, err
|
||||
}
|
||||
trust := 0.0
|
||||
if sourceTrust != nil {
|
||||
trust = *sourceTrust
|
||||
}
|
||||
|
||||
var ageDays *float64
|
||||
if lastFetched != nil {
|
||||
d := time.Since(*lastFetched).Hours() / 24.0
|
||||
if d < 0 {
|
||||
d = 0
|
||||
}
|
||||
ageDays = &d
|
||||
}
|
||||
|
||||
raw := wCompleteness*completeness + wSourceTrust*trust +
|
||||
wAgreement*agreementFromSources(sourceCount) + wFreshness*freshnessFromAge(ageDays)
|
||||
raw = math.Max(0, math.Min(1, raw))
|
||||
return math.Round(raw*1000) / 1000, nil
|
||||
}
|
||||
|
||||
func (s *Store) recomputeQualityTx(ctx context.Context, tx pgx.Tx, productID string) (float64, error) {
|
||||
v, err := s.computeQuality(ctx, tx, productID)
|
||||
if err != nil {
|
||||
return 0, err
|
||||
}
|
||||
_, err = tx.Exec(ctx, "UPDATE product SET quality_score=$1 WHERE id=$2", v, productID)
|
||||
return v, err
|
||||
}
|
||||
|
||||
func (s *Store) recomputeQuality(ctx context.Context, productID string) (float64, error) {
|
||||
v, err := s.computeQuality(ctx, s.pool, productID)
|
||||
if err != nil {
|
||||
return 0, err
|
||||
}
|
||||
_, err = s.pool.Exec(ctx, "UPDATE product SET quality_score=$1 WHERE id=$2", v, productID)
|
||||
return v, err
|
||||
}
|
||||
@@ -0,0 +1,30 @@
|
||||
package adminstore
|
||||
|
||||
import "testing"
|
||||
|
||||
func TestAgreementFromSources(t *testing.T) {
|
||||
cases := map[int]float64{0: 0.5, 1: 0.5, 2: 0.8, 3: 1.0, 9: 1.0}
|
||||
for n, want := range cases {
|
||||
if got := agreementFromSources(n); got != want {
|
||||
t.Errorf("agreementFromSources(%d) = %v, want %v", n, got, want)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
func TestFreshnessFromAge(t *testing.T) {
|
||||
mk := func(d float64) *float64 { return &d }
|
||||
if got := freshnessFromAge(nil); got != 0.5 {
|
||||
t.Errorf("nil age = %v, want 0.5", got)
|
||||
}
|
||||
cases := []struct {
|
||||
days float64
|
||||
want float64
|
||||
}{
|
||||
{10, 1.0}, {30, 1.0}, {100, 0.8}, {300, 0.6}, {500, 0.4}, {1000, 0.2},
|
||||
}
|
||||
for _, c := range cases {
|
||||
if got := freshnessFromAge(mk(c.days)); got != c.want {
|
||||
t.Errorf("freshnessFromAge(%v) = %v, want %v", c.days, got, c.want)
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,415 @@
|
||||
package adminstore
|
||||
|
||||
import (
|
||||
"context"
|
||||
"encoding/json"
|
||||
"errors"
|
||||
"strings"
|
||||
|
||||
"github.com/jackc/pgx/v5"
|
||||
)
|
||||
|
||||
// ProductInput is the editable payload accepted from the admin UI.
|
||||
type ProductInput struct {
|
||||
GTIN *string `json:"gtin"`
|
||||
Name string `json:"name"`
|
||||
BrandID *string `json:"brand_id"`
|
||||
BrandName *string `json:"brand_name"`
|
||||
CategoryID *string `json:"category_id"`
|
||||
NetContentValue *float64 `json:"net_content_value"`
|
||||
NetContentUnit *string `json:"net_content_unit"`
|
||||
CountryOfOrigin *string `json:"country_of_origin"`
|
||||
Status string `json:"status"`
|
||||
IngredientsText *string `json:"ingredients_text"`
|
||||
Allergens []string `json:"allergens"`
|
||||
Additives []string `json:"additives"`
|
||||
Nutriments map[string]any `json:"nutriments"`
|
||||
NutritionBasis *string `json:"nutrition_basis"`
|
||||
ServingSize *string `json:"serving_size"`
|
||||
NutriScore *string `json:"nutri_score"`
|
||||
}
|
||||
|
||||
func normBrand(name string) string { return strings.Join(strings.Fields(strings.ToLower(name)), " ") }
|
||||
|
||||
func (s *Store) ensureBrand(ctx context.Context, tx pgx.Tx, name string) (string, error) {
|
||||
var id string
|
||||
err := tx.QueryRow(ctx, `
|
||||
INSERT INTO brand (name, normalized_name) VALUES ($1, $2)
|
||||
ON CONFLICT (normalized_name) DO UPDATE SET name = brand.name
|
||||
RETURNING id`, name, normBrand(name)).Scan(&id)
|
||||
return id, err
|
||||
}
|
||||
|
||||
func (s *Store) manualSourceID(ctx context.Context, tx pgx.Tx) (string, error) {
|
||||
var id string
|
||||
err := tx.QueryRow(ctx, "SELECT id FROM source WHERE name = 'manual'").Scan(&id)
|
||||
return id, err
|
||||
}
|
||||
|
||||
// netCanonical converts value+unit to the canonical base unit via the unit table.
|
||||
func (s *Store) netCanonical(ctx context.Context, tx pgx.Tx, value *float64, unit *string) (*float64, error) {
|
||||
if value == nil || unit == nil || *unit == "" {
|
||||
return nil, nil
|
||||
}
|
||||
var factor *float64
|
||||
err := tx.QueryRow(ctx, "SELECT to_canonical_factor FROM unit WHERE code = $1", *unit).Scan(&factor)
|
||||
if errors.Is(err, pgx.ErrNoRows) || factor == nil {
|
||||
return nil, nil
|
||||
}
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
c := *value * *factor
|
||||
return &c, nil
|
||||
}
|
||||
|
||||
// UpdateProduct applies an edit, records provenance + audit, and recomputes quality.
|
||||
func (s *Store) UpdateProduct(ctx context.Context, id, actor string, in ProductInput) (*ProductDetail, error) {
|
||||
before, err := s.GetProduct(ctx, id)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
|
||||
tx, err := s.pool.Begin(ctx)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
defer tx.Rollback(ctx)
|
||||
|
||||
// Resolve brand (create-by-name takes precedence over id).
|
||||
brandID := in.BrandID
|
||||
if in.BrandName != nil && strings.TrimSpace(*in.BrandName) != "" {
|
||||
bid, err := s.ensureBrand(ctx, tx, strings.TrimSpace(*in.BrandName))
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
brandID = &bid
|
||||
}
|
||||
|
||||
// Resolve category gpc brick code.
|
||||
var gpc *string
|
||||
if in.CategoryID != nil && *in.CategoryID != "" {
|
||||
if err := tx.QueryRow(ctx, "SELECT gpc_brick_code FROM category WHERE id = $1", *in.CategoryID).Scan(&gpc); err != nil && !errors.Is(err, pgx.ErrNoRows) {
|
||||
return nil, err
|
||||
}
|
||||
}
|
||||
|
||||
canonical, err := s.netCanonical(ctx, tx, in.NetContentValue, in.NetContentUnit)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
|
||||
status := in.Status
|
||||
if status == "" {
|
||||
status = before.Status
|
||||
}
|
||||
|
||||
_, err = tx.Exec(ctx, `
|
||||
UPDATE product SET gtin=$1, name=$2, brand_id=$3, category_id=$4, gpc_brick_code=$5,
|
||||
net_content_value=$6, net_content_unit=$7, net_content_canonical=$8,
|
||||
country_of_origin=$9, status=$10
|
||||
WHERE id=$11`,
|
||||
in.GTIN, in.Name, brandID, in.CategoryID, gpc,
|
||||
in.NetContentValue, in.NetContentUnit, canonical,
|
||||
in.CountryOfOrigin, status, id)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
|
||||
var nutriJSON []byte
|
||||
if in.Nutriments != nil {
|
||||
nutriJSON, _ = json.Marshal(in.Nutriments)
|
||||
}
|
||||
allergens := in.Allergens
|
||||
if allergens == nil {
|
||||
allergens = []string{}
|
||||
}
|
||||
additives := in.Additives
|
||||
if additives == nil {
|
||||
additives = []string{}
|
||||
}
|
||||
_, err = tx.Exec(ctx, `
|
||||
INSERT INTO food_detail (product_id, ingredients_text, allergens, additives,
|
||||
nutriments, nutrition_basis, serving_size, nutri_score)
|
||||
VALUES ($1,$2,$3,$4,$5,$6,$7,$8)
|
||||
ON CONFLICT (product_id) DO UPDATE SET
|
||||
ingredients_text=EXCLUDED.ingredients_text,
|
||||
allergens=EXCLUDED.allergens,
|
||||
additives=EXCLUDED.additives,
|
||||
nutriments=EXCLUDED.nutriments,
|
||||
nutrition_basis=EXCLUDED.nutrition_basis,
|
||||
serving_size=EXCLUDED.serving_size,
|
||||
nutri_score=EXCLUDED.nutri_score`,
|
||||
id, in.IngredientsText, allergens, additives,
|
||||
nutriJSON, in.NutritionBasis, in.ServingSize, in.NutriScore)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
|
||||
if _, err := s.recomputeQualityTx(ctx, tx, id); err != nil {
|
||||
return nil, err
|
||||
}
|
||||
|
||||
if err := tx.Commit(ctx); err != nil {
|
||||
return nil, err
|
||||
}
|
||||
|
||||
after, err := s.GetProduct(ctx, id)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
changed := diffFields(before, after)
|
||||
if len(changed) > 0 {
|
||||
if err := s.recordProvenance(ctx, id, changed); err != nil {
|
||||
return nil, err
|
||||
}
|
||||
}
|
||||
if err := s.writeAudit(ctx, actor, "update", "product", &id, changed, before, after); err != nil {
|
||||
return nil, err
|
||||
}
|
||||
return after, nil
|
||||
}
|
||||
|
||||
func strEq(a, b *string) bool {
|
||||
if a == nil && b == nil {
|
||||
return true
|
||||
}
|
||||
if a == nil || b == nil {
|
||||
return false
|
||||
}
|
||||
return *a == *b
|
||||
}
|
||||
|
||||
func floatEq(a, b *float64) bool {
|
||||
if a == nil && b == nil {
|
||||
return true
|
||||
}
|
||||
if a == nil || b == nil {
|
||||
return false
|
||||
}
|
||||
return *a == *b
|
||||
}
|
||||
|
||||
func diffFields(a, b *ProductDetail) []string {
|
||||
changed := []string{}
|
||||
add := func(name string, eq bool) {
|
||||
if !eq {
|
||||
changed = append(changed, name)
|
||||
}
|
||||
}
|
||||
add("gtin", strEq(a.GTIN, b.GTIN))
|
||||
add("name", a.Name == b.Name)
|
||||
add("brand", strEq(a.BrandID, b.BrandID))
|
||||
add("category", strEq(a.CategoryID, b.CategoryID))
|
||||
add("net_content", floatEq(a.NetContentValue, b.NetContentValue) && strEq(a.NetContentUnit, b.NetContentUnit))
|
||||
add("country_of_origin", strEq(a.CountryOfOrigin, b.CountryOfOrigin))
|
||||
add("status", a.Status == b.Status)
|
||||
add("ingredients", strEq(a.IngredientsText, b.IngredientsText))
|
||||
ja, _ := json.Marshal(a.Nutriments)
|
||||
jb, _ := json.Marshal(b.Nutriments)
|
||||
add("nutriments", string(ja) == string(jb))
|
||||
add("nutrition_basis", strEq(a.NutritionBasis, b.NutritionBasis))
|
||||
add("serving_size", strEq(a.ServingSize, b.ServingSize))
|
||||
add("nutri_score", strEq(a.NutriScore, b.NutriScore))
|
||||
return changed
|
||||
}
|
||||
|
||||
func (s *Store) recordProvenance(ctx context.Context, productID string, fields []string) error {
|
||||
var srcID string
|
||||
if err := s.pool.QueryRow(ctx, "SELECT id FROM source WHERE name = 'manual'").Scan(&srcID); err != nil {
|
||||
return err
|
||||
}
|
||||
_, err := s.pool.Exec(ctx, `
|
||||
INSERT INTO product_source (product_id, source_id, url, fields, fetched_at, raw)
|
||||
VALUES ($1, $2, NULL, $3, now(), NULL)`, productID, srcID, fields)
|
||||
return err
|
||||
}
|
||||
|
||||
func (s *Store) writeAudit(ctx context.Context, actor, action, entity string, entityID *string, fields []string, before, after any) error {
|
||||
bj, _ := json.Marshal(before)
|
||||
aj, _ := json.Marshal(after)
|
||||
if fields == nil {
|
||||
fields = []string{}
|
||||
}
|
||||
_, err := s.pool.Exec(ctx, `
|
||||
INSERT INTO audit_log (actor, action, entity, entity_id, fields, before, after)
|
||||
VALUES ($1,$2,$3,$4,$5,$6,$7)`, actor, action, entity, entityID, fields, bj, aj)
|
||||
return err
|
||||
}
|
||||
|
||||
// ---------- images ----------
|
||||
|
||||
// AddImage inserts an image URL (manual source) and recomputes quality.
|
||||
func (s *Store) AddImage(ctx context.Context, productID, actor, url, kind string) (*ProductImage, error) {
|
||||
if kind == "" {
|
||||
kind = "other"
|
||||
}
|
||||
var srcID string
|
||||
if err := s.pool.QueryRow(ctx, "SELECT id FROM source WHERE name = 'manual'").Scan(&srcID); err != nil {
|
||||
return nil, err
|
||||
}
|
||||
var im ProductImage
|
||||
err := s.pool.QueryRow(ctx, `
|
||||
INSERT INTO product_image (product_id, url, kind, license, source_id)
|
||||
VALUES ($1,$2,$3,NULL,$4) RETURNING id, url, kind, license`,
|
||||
productID, url, kind, srcID).Scan(&im.ID, &im.URL, &im.Kind, &im.License)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
if _, err := s.recomputeQuality(ctx, productID); err != nil {
|
||||
return nil, err
|
||||
}
|
||||
_ = s.writeAudit(ctx, actor, "add_image", "product", &productID, []string{"image"}, nil, im)
|
||||
return &im, nil
|
||||
}
|
||||
|
||||
// DeleteImage removes an image and recomputes quality.
|
||||
func (s *Store) DeleteImage(ctx context.Context, productID, imageID, actor string) error {
|
||||
ct, err := s.pool.Exec(ctx, "DELETE FROM product_image WHERE id=$1 AND product_id=$2", imageID, productID)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
if ct.RowsAffected() == 0 {
|
||||
return ErrNotFound
|
||||
}
|
||||
if _, err := s.recomputeQuality(ctx, productID); err != nil {
|
||||
return err
|
||||
}
|
||||
_ = s.writeAudit(ctx, actor, "delete_image", "product", &productID, []string{"image"}, map[string]string{"image_id": imageID}, nil)
|
||||
return nil
|
||||
}
|
||||
|
||||
// ---------- msrp ----------
|
||||
|
||||
// MSRPInput is the payload for adding an MSRP snapshot.
|
||||
type MSRPInput struct {
|
||||
Amount float64 `json:"amount"`
|
||||
Currency string `json:"currency"`
|
||||
Region string `json:"region"`
|
||||
EffectiveDate *string `json:"effective_date"`
|
||||
SourceURL *string `json:"source_url"`
|
||||
Note *string `json:"note"`
|
||||
}
|
||||
|
||||
// AddMSRP inserts a suggested-retail-price snapshot.
|
||||
func (s *Store) AddMSRP(ctx context.Context, productID, actor string, in MSRPInput) (*MSRP, error) {
|
||||
if in.Currency == "" {
|
||||
in.Currency = "CNY"
|
||||
}
|
||||
if in.Region == "" {
|
||||
in.Region = "CN"
|
||||
}
|
||||
var srcID string
|
||||
_ = s.pool.QueryRow(ctx, "SELECT id FROM source WHERE name = 'manual'").Scan(&srcID)
|
||||
var m MSRP
|
||||
err := s.pool.QueryRow(ctx, `
|
||||
INSERT INTO product_msrp (product_id, amount, currency, region, source_id, source_url, effective_date, note)
|
||||
VALUES ($1,$2,$3,$4,$5,$6,$7,$8)
|
||||
RETURNING id, amount, currency, region, effective_date::text, source_url, note`,
|
||||
productID, in.Amount, in.Currency, in.Region, srcID, in.SourceURL, in.EffectiveDate, in.Note).
|
||||
Scan(&m.ID, &m.Amount, &m.Currency, &m.Region, &m.EffectiveDate, &m.SourceURL, &m.Note)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
_ = s.writeAudit(ctx, actor, "add_msrp", "product", &productID, []string{"msrp"}, nil, m)
|
||||
return &m, nil
|
||||
}
|
||||
|
||||
// DeleteMSRP removes an MSRP snapshot.
|
||||
func (s *Store) DeleteMSRP(ctx context.Context, productID, msrpID, actor string) error {
|
||||
ct, err := s.pool.Exec(ctx, "DELETE FROM product_msrp WHERE id=$1 AND product_id=$2", msrpID, productID)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
if ct.RowsAffected() == 0 {
|
||||
return ErrNotFound
|
||||
}
|
||||
_ = s.writeAudit(ctx, actor, "delete_msrp", "product", &productID, []string{"msrp"}, map[string]string{"msrp_id": msrpID}, nil)
|
||||
return nil
|
||||
}
|
||||
|
||||
// ---------- dictionaries ----------
|
||||
|
||||
// Brand is a brand option for the edit form.
|
||||
type Brand struct {
|
||||
ID string `json:"id"`
|
||||
Name string `json:"name"`
|
||||
}
|
||||
|
||||
// ListBrands returns all brands ordered by name.
|
||||
func (s *Store) ListBrands(ctx context.Context) ([]Brand, error) {
|
||||
rows, err := s.pool.Query(ctx, "SELECT id, name FROM brand ORDER BY name")
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
defer rows.Close()
|
||||
out := []Brand{}
|
||||
for rows.Next() {
|
||||
var b Brand
|
||||
if err := rows.Scan(&b.ID, &b.Name); err != nil {
|
||||
return nil, err
|
||||
}
|
||||
out = append(out, b)
|
||||
}
|
||||
return out, rows.Err()
|
||||
}
|
||||
|
||||
// Category is a category option for the edit form.
|
||||
type Category struct {
|
||||
ID string `json:"id"`
|
||||
NameZH string `json:"name_zh"`
|
||||
NameEN *string `json:"name_en"`
|
||||
Path string `json:"path"`
|
||||
Level int `json:"level"`
|
||||
}
|
||||
|
||||
// ListCategories returns the full category tree.
|
||||
func (s *Store) ListCategories(ctx context.Context) ([]Category, error) {
|
||||
rows, err := s.pool.Query(ctx,
|
||||
"SELECT id, name_zh, name_en, path::text, level FROM category ORDER BY path")
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
defer rows.Close()
|
||||
out := []Category{}
|
||||
for rows.Next() {
|
||||
var c Category
|
||||
if err := rows.Scan(&c.ID, &c.NameZH, &c.NameEN, &c.Path, &c.Level); err != nil {
|
||||
return nil, err
|
||||
}
|
||||
out = append(out, c)
|
||||
}
|
||||
return out, rows.Err()
|
||||
}
|
||||
|
||||
// ---------- audit ----------
|
||||
|
||||
// AuditEntry is one audit-log row for the history view.
|
||||
type AuditEntry struct {
|
||||
ID string `json:"id"`
|
||||
Actor string `json:"actor"`
|
||||
Action string `json:"action"`
|
||||
Fields []string `json:"fields"`
|
||||
CreatedAt string `json:"created_at"`
|
||||
}
|
||||
|
||||
// ListAudit returns audit history for one product, newest first.
|
||||
func (s *Store) ListAudit(ctx context.Context, productID string, limit int) ([]AuditEntry, error) {
|
||||
rows, err := s.pool.Query(ctx, `
|
||||
SELECT id, actor, action, fields, created_at::text
|
||||
FROM audit_log WHERE entity='product' AND entity_id=$1
|
||||
ORDER BY created_at DESC LIMIT $2`, productID, limit)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
defer rows.Close()
|
||||
out := []AuditEntry{}
|
||||
for rows.Next() {
|
||||
var e AuditEntry
|
||||
if err := rows.Scan(&e.ID, &e.Actor, &e.Action, &e.Fields, &e.CreatedAt); err != nil {
|
||||
return nil, err
|
||||
}
|
||||
out = append(out, e)
|
||||
}
|
||||
return out, rows.Err()
|
||||
}
|
||||
+7
@@ -0,0 +1,7 @@
|
||||
<!doctype html>
|
||||
<html lang="zh">
|
||||
<head><meta charset="utf-8" /><title>OpenGoods 管理后台</title></head>
|
||||
<body>
|
||||
<p>管理后台前端尚未构建。Docker 构建会在此处放入真正的前端产物。</p>
|
||||
</body>
|
||||
</html>
|
||||
@@ -0,0 +1,21 @@
|
||||
// Package adminweb embeds the built admin SPA (Vite dist). During Docker builds
|
||||
// the real dist/ is produced by the node stage and copied in before go build;
|
||||
// the committed placeholder keeps the package compilable for `go build ./...`.
|
||||
package adminweb
|
||||
|
||||
import (
|
||||
"embed"
|
||||
"io/fs"
|
||||
)
|
||||
|
||||
//go:embed all:dist
|
||||
var distFS embed.FS
|
||||
|
||||
// Dist returns the embedded SPA filesystem rooted at dist/.
|
||||
func Dist() fs.FS {
|
||||
sub, err := fs.Sub(distFS, "dist")
|
||||
if err != nil {
|
||||
panic(err)
|
||||
}
|
||||
return sub
|
||||
}
|
||||
@@ -0,0 +1,126 @@
|
||||
// Package auth provides minimal single-account authentication for the admin
|
||||
// console: a bcrypt-verified login and a stdlib HMAC-SHA256 signed token
|
||||
// (JWT-compatible) plus a chi middleware that guards write routes.
|
||||
package auth
|
||||
|
||||
import (
|
||||
"context"
|
||||
"crypto/hmac"
|
||||
"crypto/sha256"
|
||||
"encoding/base64"
|
||||
"encoding/json"
|
||||
"errors"
|
||||
"net/http"
|
||||
"strings"
|
||||
"time"
|
||||
|
||||
"golang.org/x/crypto/bcrypt"
|
||||
)
|
||||
|
||||
// Authenticator holds the single admin credential and token signing secret.
|
||||
type Authenticator struct {
|
||||
username string
|
||||
passwordHash []byte
|
||||
secret []byte
|
||||
ttl time.Duration
|
||||
}
|
||||
|
||||
// New builds an Authenticator. passwordHash must be a bcrypt hash.
|
||||
func New(username string, passwordHash, secret []byte, ttl time.Duration) *Authenticator {
|
||||
return &Authenticator{username: username, passwordHash: passwordHash, secret: secret, ttl: ttl}
|
||||
}
|
||||
|
||||
// ErrInvalidCredentials is returned when login fails.
|
||||
var ErrInvalidCredentials = errors.New("invalid credentials")
|
||||
|
||||
// Login verifies the username/password and returns a signed token on success.
|
||||
func (a *Authenticator) Login(username, password string) (string, error) {
|
||||
if username != a.username {
|
||||
// Still run bcrypt to keep timing roughly constant.
|
||||
_ = bcrypt.CompareHashAndPassword(a.passwordHash, []byte(password))
|
||||
return "", ErrInvalidCredentials
|
||||
}
|
||||
if err := bcrypt.CompareHashAndPassword(a.passwordHash, []byte(password)); err != nil {
|
||||
return "", ErrInvalidCredentials
|
||||
}
|
||||
return a.issue(username)
|
||||
}
|
||||
|
||||
type claims struct {
|
||||
Sub string `json:"sub"`
|
||||
Exp int64 `json:"exp"`
|
||||
}
|
||||
|
||||
func b64(b []byte) string { return base64.RawURLEncoding.EncodeToString(b) }
|
||||
|
||||
func (a *Authenticator) sign(signingInput string) string {
|
||||
mac := hmac.New(sha256.New, a.secret)
|
||||
mac.Write([]byte(signingInput))
|
||||
return b64(mac.Sum(nil))
|
||||
}
|
||||
|
||||
func (a *Authenticator) issue(sub string) (string, error) {
|
||||
header := b64([]byte(`{"alg":"HS256","typ":"JWT"}`))
|
||||
payloadJSON, err := json.Marshal(claims{Sub: sub, Exp: time.Now().Add(a.ttl).Unix()})
|
||||
if err != nil {
|
||||
return "", err
|
||||
}
|
||||
payload := b64(payloadJSON)
|
||||
signingInput := header + "." + payload
|
||||
return signingInput + "." + a.sign(signingInput), nil
|
||||
}
|
||||
|
||||
// Verify checks a token's signature and expiry, returning the subject.
|
||||
func (a *Authenticator) Verify(token string) (string, error) {
|
||||
parts := strings.Split(token, ".")
|
||||
if len(parts) != 3 {
|
||||
return "", errors.New("malformed token")
|
||||
}
|
||||
signingInput := parts[0] + "." + parts[1]
|
||||
if !hmac.Equal([]byte(a.sign(signingInput)), []byte(parts[2])) {
|
||||
return "", errors.New("bad signature")
|
||||
}
|
||||
payload, err := base64.RawURLEncoding.DecodeString(parts[1])
|
||||
if err != nil {
|
||||
return "", err
|
||||
}
|
||||
var c claims
|
||||
if err := json.Unmarshal(payload, &c); err != nil {
|
||||
return "", err
|
||||
}
|
||||
if time.Now().Unix() >= c.Exp {
|
||||
return "", errors.New("token expired")
|
||||
}
|
||||
return c.Sub, nil
|
||||
}
|
||||
|
||||
type ctxKey int
|
||||
|
||||
const userKey ctxKey = 0
|
||||
|
||||
// UserFrom returns the authenticated subject from the request context.
|
||||
func UserFrom(ctx context.Context) string {
|
||||
if v, ok := ctx.Value(userKey).(string); ok {
|
||||
return v
|
||||
}
|
||||
return ""
|
||||
}
|
||||
|
||||
// Middleware rejects requests without a valid Bearer token.
|
||||
func (a *Authenticator) Middleware(next http.Handler) http.Handler {
|
||||
return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
||||
h := r.Header.Get("Authorization")
|
||||
token := strings.TrimPrefix(h, "Bearer ")
|
||||
if token == h || token == "" {
|
||||
http.Error(w, `{"error":{"code":"unauthorized","message":"missing token"}}`, http.StatusUnauthorized)
|
||||
return
|
||||
}
|
||||
sub, err := a.Verify(token)
|
||||
if err != nil {
|
||||
http.Error(w, `{"error":{"code":"unauthorized","message":"invalid token"}}`, http.StatusUnauthorized)
|
||||
return
|
||||
}
|
||||
ctx := context.WithValue(r.Context(), userKey, sub)
|
||||
next.ServeHTTP(w, r.WithContext(ctx))
|
||||
})
|
||||
}
|
||||
@@ -0,0 +1,62 @@
|
||||
package auth
|
||||
|
||||
import (
|
||||
"testing"
|
||||
"time"
|
||||
|
||||
"golang.org/x/crypto/bcrypt"
|
||||
)
|
||||
|
||||
func newTestAuth(t *testing.T, ttl time.Duration) *Authenticator {
|
||||
t.Helper()
|
||||
hash, err := bcrypt.GenerateFromPassword([]byte("s3cret"), bcrypt.MinCost)
|
||||
if err != nil {
|
||||
t.Fatalf("hash: %v", err)
|
||||
}
|
||||
return New("admin", hash, []byte("test-secret"), ttl)
|
||||
}
|
||||
|
||||
func TestLoginAndVerify(t *testing.T) {
|
||||
a := newTestAuth(t, time.Hour)
|
||||
|
||||
token, err := a.Login("admin", "s3cret")
|
||||
if err != nil {
|
||||
t.Fatalf("login: %v", err)
|
||||
}
|
||||
sub, err := a.Verify(token)
|
||||
if err != nil {
|
||||
t.Fatalf("verify: %v", err)
|
||||
}
|
||||
if sub != "admin" {
|
||||
t.Fatalf("sub = %q, want admin", sub)
|
||||
}
|
||||
}
|
||||
|
||||
func TestLoginWrongCredentials(t *testing.T) {
|
||||
a := newTestAuth(t, time.Hour)
|
||||
if _, err := a.Login("admin", "nope"); err == nil {
|
||||
t.Fatal("expected error for wrong password")
|
||||
}
|
||||
if _, err := a.Login("other", "s3cret"); err == nil {
|
||||
t.Fatal("expected error for wrong username")
|
||||
}
|
||||
}
|
||||
|
||||
func TestVerifyRejectsTampered(t *testing.T) {
|
||||
a := newTestAuth(t, time.Hour)
|
||||
token, _ := a.Login("admin", "s3cret")
|
||||
if _, err := a.Verify(token + "x"); err == nil {
|
||||
t.Fatal("expected bad signature error")
|
||||
}
|
||||
if _, err := a.Verify("not.a.token"); err == nil {
|
||||
t.Fatal("expected malformed/decoding error")
|
||||
}
|
||||
}
|
||||
|
||||
func TestVerifyRejectsExpired(t *testing.T) {
|
||||
a := newTestAuth(t, -time.Minute)
|
||||
token, _ := a.Login("admin", "s3cret")
|
||||
if _, err := a.Verify(token); err == nil {
|
||||
t.Fatal("expected expired token error")
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user