feat(admin): 新增档案回流接口 POST /api/public/backflow
进销存软件可用公开 API Key(og_live_) 批量回流未收录商品,进入现有审核 队列,审核通过后收录。按 GTIN 去重(已收录跳过 exists,已有待审跳过 duplicate),来源标记 source=backflow,在后台队列与公众投稿区分。 Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
This commit is contained in:
@@ -14,6 +14,7 @@ import (
|
||||
"github.com/go-chi/chi/v5/middleware"
|
||||
|
||||
"github.com/baicai2026-baicai/goods/api/internal/adminstore"
|
||||
"github.com/baicai2026-baicai/goods/api/internal/apikey"
|
||||
"github.com/baicai2026-baicai/goods/api/internal/auth"
|
||||
"github.com/baicai2026-baicai/goods/api/internal/gtin"
|
||||
"github.com/baicai2026-baicai/goods/api/internal/ratelimit"
|
||||
@@ -110,6 +111,11 @@ func (h *Handler) Router() http.Handler {
|
||||
// admin approves them.
|
||||
r.Post("/api/public/submissions", h.CreateSubmission)
|
||||
|
||||
// Archive backflow: inventory-management software pushes products missing
|
||||
// from the archive. Authenticated with a public API key; records enter the
|
||||
// same moderation queue and are archived only after admin approval.
|
||||
r.Post("/api/public/backflow", h.Backflow)
|
||||
|
||||
return r
|
||||
}
|
||||
|
||||
@@ -634,6 +640,62 @@ func (h *Handler) CreateSubmission(w http.ResponseWriter, r *http.Request) {
|
||||
writeJSON(w, http.StatusCreated, map[string]string{"id": id, "status": "pending"})
|
||||
}
|
||||
|
||||
// Backflow accepts a batch of products pushed by inventory-management software.
|
||||
// It authenticates with a public API key (X-API-Key or Bearer), enqueues each
|
||||
// item for admin review (deduplicating by GTIN), and returns a per-item summary.
|
||||
func (h *Handler) Backflow(w http.ResponseWriter, r *http.Request) {
|
||||
raw := presentedAPIKey(r)
|
||||
if raw == "" {
|
||||
writeError(w, http.StatusUnauthorized, "missing_api_key", "缺少 API key(请在 X-API-Key 或 Authorization: Bearer 中提供)")
|
||||
return
|
||||
}
|
||||
if !apikey.IsWellFormed(raw) {
|
||||
writeError(w, http.StatusUnauthorized, "invalid_api_key", "API key 格式无效")
|
||||
return
|
||||
}
|
||||
if _, err := h.store.APIKeyByHash(r.Context(), apikey.Hash(raw)); err != nil {
|
||||
if errors.Is(err, adminstore.ErrNotFound) {
|
||||
writeError(w, http.StatusUnauthorized, "invalid_api_key", "API key 无效或已吊销")
|
||||
return
|
||||
}
|
||||
writeError(w, http.StatusInternalServerError, "internal_error", err.Error())
|
||||
return
|
||||
}
|
||||
|
||||
var items []adminstore.SubmissionInput
|
||||
if err := json.NewDecoder(http.MaxBytesReader(w, r.Body, 16<<20)).Decode(&items); err != nil {
|
||||
writeError(w, http.StatusBadRequest, "bad_request", "请求体应为商品数组 (JSON array)")
|
||||
return
|
||||
}
|
||||
|
||||
if len(items) == 0 {
|
||||
writeError(w, http.StatusBadRequest, "bad_request", "回流列表为空")
|
||||
return
|
||||
}
|
||||
if len(items) > 1000 {
|
||||
writeError(w, http.StatusBadRequest, "too_many", "单次回流最多 1000 条")
|
||||
return
|
||||
}
|
||||
|
||||
sum, err := h.store.CreateBackflowSubmissions(r.Context(), items, realIP(r))
|
||||
if err != nil {
|
||||
writeError(w, http.StatusInternalServerError, "internal_error", err.Error())
|
||||
return
|
||||
}
|
||||
writeJSON(w, http.StatusOK, sum)
|
||||
}
|
||||
|
||||
// presentedAPIKey extracts a public API key from X-API-Key or a Bearer token.
|
||||
func presentedAPIKey(r *http.Request) string {
|
||||
if v := strings.TrimSpace(r.Header.Get("X-API-Key")); v != "" {
|
||||
return v
|
||||
}
|
||||
if v := r.Header.Get("Authorization"); strings.HasPrefix(v, "Bearer ") {
|
||||
return strings.TrimSpace(strings.TrimPrefix(v, "Bearer "))
|
||||
}
|
||||
return ""
|
||||
}
|
||||
|
||||
// ListSubmissions returns the moderation queue (admin).
|
||||
func (h *Handler) ListSubmissions(w http.ResponseWriter, r *http.Request) {
|
||||
status := r.URL.Query().Get("status")
|
||||
|
||||
Reference in New Issue
Block a user