Compare commits
14 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 7434e5195e | |||
| 7f66aad779 | |||
| 916bdd9c7c | |||
| 98eb01f4ea | |||
| 51304d782a | |||
| 6e81a7eb36 | |||
| 8bee570cb2 | |||
| ed06d269c6 | |||
| 0214253b48 | |||
| afced01ba6 | |||
| 8812e5f5e3 | |||
| 01055ded02 | |||
| 01593dcbdc | |||
| afdd26cb59 |
@@ -28,6 +28,7 @@ export default function App() {
|
|||||||
const [tab, setTab] = useState<Tab>("products");
|
const [tab, setTab] = useState<Tab>("products");
|
||||||
const [pending, setPending] = useState<number | null>(null);
|
const [pending, setPending] = useState<number | null>(null);
|
||||||
const [view, setView] = useState<View>({ name: "list" });
|
const [view, setView] = useState<View>({ name: "list" });
|
||||||
|
const [navIds, setNavIds] = useState<string[]>([]);
|
||||||
|
|
||||||
useEffect(() => {
|
useEffect(() => {
|
||||||
if (!authed) return;
|
if (!authed) return;
|
||||||
@@ -190,9 +191,19 @@ export default function App() {
|
|||||||
) : tab === "submissions" ? (
|
) : tab === "submissions" ? (
|
||||||
<SubmissionsPage onPending={setPending} />
|
<SubmissionsPage onPending={setPending} />
|
||||||
) : view.name === "list" ? (
|
) : view.name === "list" ? (
|
||||||
<ProductList onOpen={(id) => setView({ name: "detail", id })} />
|
<ProductList
|
||||||
|
onOpen={(id, ids) => {
|
||||||
|
setNavIds(ids);
|
||||||
|
setView({ name: "detail", id });
|
||||||
|
}}
|
||||||
|
/>
|
||||||
) : (
|
) : (
|
||||||
<ProductDetail id={view.id} onBack={() => setView({ name: "list" })} />
|
<ProductDetail
|
||||||
|
id={view.id}
|
||||||
|
ids={navIds}
|
||||||
|
onNavigate={(id) => setView({ name: "detail", id })}
|
||||||
|
onBack={() => setView({ name: "list" })}
|
||||||
|
/>
|
||||||
)}
|
)}
|
||||||
</main>
|
</main>
|
||||||
</div>
|
</div>
|
||||||
|
|||||||
@@ -124,6 +124,10 @@ export const api = {
|
|||||||
}),
|
}),
|
||||||
deleteBrand: (id: string) =>
|
deleteBrand: (id: string) =>
|
||||||
request<{ status: string }>(`/brands/${id}`, { method: "DELETE" }),
|
request<{ status: string }>(`/brands/${id}`, { method: "DELETE" }),
|
||||||
|
listKindFields: (kind: string) =>
|
||||||
|
request<{ items: import("./types").KindField[]; kind: string }>(
|
||||||
|
`/kind-fields?kind=${encodeURIComponent(kind)}`,
|
||||||
|
),
|
||||||
listCategories: () =>
|
listCategories: () =>
|
||||||
request<{ items: import("./types").Category[] }>("/categories"),
|
request<{ items: import("./types").Category[] }>("/categories"),
|
||||||
createCategory: (body: import("./types").CategoryInput) =>
|
createCategory: (body: import("./types").CategoryInput) =>
|
||||||
@@ -164,6 +168,7 @@ export const api = {
|
|||||||
owner_email?: string;
|
owner_email?: string;
|
||||||
tier?: string;
|
tier?: string;
|
||||||
rate_limit_per_min?: number;
|
rate_limit_per_min?: number;
|
||||||
|
quota_total?: number;
|
||||||
}) =>
|
}) =>
|
||||||
request<{ key: string; item: import("./types").ApiKey; warning: string }>(
|
request<{ key: string; item: import("./types").ApiKey; warning: string }>(
|
||||||
"/keys",
|
"/keys",
|
||||||
|
|||||||
@@ -4,9 +4,10 @@ import type { ApiKey } from "../types";
|
|||||||
import { Copy, KeyRound, Plus, Trash2 } from "lucide-react";
|
import { Copy, KeyRound, Plus, Trash2 } from "lucide-react";
|
||||||
|
|
||||||
const TIERS = [
|
const TIERS = [
|
||||||
{ key: "free", label: "免费 (free)", rate: 120 },
|
{ key: "free", label: "免费 (free)", rate: 120, quota: 1000 },
|
||||||
{ key: "partner", label: "合作方 (partner)", rate: 600 },
|
{ key: "registered", label: "注册用户 (registered)", rate: 300, quota: 100000 },
|
||||||
{ key: "internal", label: "内部 (internal)", rate: 6000 },
|
{ key: "partner", label: "合作方 (partner)", rate: 600, quota: 0 },
|
||||||
|
{ key: "internal", label: "内部 (internal)", rate: 6000, quota: 0 },
|
||||||
];
|
];
|
||||||
|
|
||||||
function tierLabel(tier: string): string {
|
function tierLabel(tier: string): string {
|
||||||
@@ -44,7 +45,7 @@ export default function ApiKeysPage() {
|
|||||||
}
|
}
|
||||||
|
|
||||||
return (
|
return (
|
||||||
<div className="max-w-4xl">
|
<div className="mx-auto max-w-4xl">
|
||||||
<div className="flex items-center justify-between mb-4">
|
<div className="flex items-center justify-between mb-4">
|
||||||
<div>
|
<div>
|
||||||
<h2 className="text-lg font-semibold text-gray-800 flex items-center gap-2">
|
<h2 className="text-lg font-semibold text-gray-800 flex items-center gap-2">
|
||||||
@@ -111,6 +112,7 @@ export default function ApiKeysPage() {
|
|||||||
<th className="px-4 py-2 font-medium">级别</th>
|
<th className="px-4 py-2 font-medium">级别</th>
|
||||||
<th className="px-4 py-2 font-medium">速率/分钟</th>
|
<th className="px-4 py-2 font-medium">速率/分钟</th>
|
||||||
<th className="px-4 py-2 font-medium">用量(今日/累计)</th>
|
<th className="px-4 py-2 font-medium">用量(今日/累计)</th>
|
||||||
|
<th className="px-4 py-2 font-medium">累计配额</th>
|
||||||
<th className="px-4 py-2 font-medium">状态</th>
|
<th className="px-4 py-2 font-medium">状态</th>
|
||||||
<th className="px-4 py-2 font-medium"></th>
|
<th className="px-4 py-2 font-medium"></th>
|
||||||
</tr>
|
</tr>
|
||||||
@@ -118,7 +120,7 @@ export default function ApiKeysPage() {
|
|||||||
<tbody className="divide-y">
|
<tbody className="divide-y">
|
||||||
{rows.length === 0 ? (
|
{rows.length === 0 ? (
|
||||||
<tr>
|
<tr>
|
||||||
<td colSpan={7} className="px-4 py-8 text-center text-gray-400">
|
<td colSpan={8} className="px-4 py-8 text-center text-gray-400">
|
||||||
暂无密钥
|
暂无密钥
|
||||||
</td>
|
</td>
|
||||||
</tr>
|
</tr>
|
||||||
@@ -139,6 +141,15 @@ export default function ApiKeysPage() {
|
|||||||
<td className="px-4 py-2 text-gray-600">
|
<td className="px-4 py-2 text-gray-600">
|
||||||
{k.usage.today} / {k.usage.total}
|
{k.usage.today} / {k.usage.total}
|
||||||
</td>
|
</td>
|
||||||
|
<td className="px-4 py-2 text-gray-600">
|
||||||
|
{k.quota_total > 0 ? (
|
||||||
|
<span className={k.usage.total >= k.quota_total ? "text-red-600" : ""}>
|
||||||
|
{k.usage.total.toLocaleString()} / {k.quota_total.toLocaleString()}
|
||||||
|
</span>
|
||||||
|
) : (
|
||||||
|
<span className="text-gray-400">不限</span>
|
||||||
|
)}
|
||||||
|
</td>
|
||||||
<td className="px-4 py-2">
|
<td className="px-4 py-2">
|
||||||
{k.revoked_at ? (
|
{k.revoked_at ? (
|
||||||
<span className="text-xs rounded px-2 py-0.5 bg-red-50 text-red-700">
|
<span className="text-xs rounded px-2 py-0.5 bg-red-50 text-red-700">
|
||||||
@@ -182,13 +193,17 @@ function CreateKeyForm({
|
|||||||
const [ownerEmail, setOwnerEmail] = useState("");
|
const [ownerEmail, setOwnerEmail] = useState("");
|
||||||
const [tier, setTier] = useState("free");
|
const [tier, setTier] = useState("free");
|
||||||
const [rate, setRate] = useState(120);
|
const [rate, setRate] = useState(120);
|
||||||
|
const [quota, setQuota] = useState(1000);
|
||||||
const [busy, setBusy] = useState(false);
|
const [busy, setBusy] = useState(false);
|
||||||
const [error, setError] = useState("");
|
const [error, setError] = useState("");
|
||||||
|
|
||||||
function pickTier(t: string) {
|
function pickTier(t: string) {
|
||||||
setTier(t);
|
setTier(t);
|
||||||
const def = TIERS.find((x) => x.key === t);
|
const def = TIERS.find((x) => x.key === t);
|
||||||
if (def) setRate(def.rate);
|
if (def) {
|
||||||
|
setRate(def.rate);
|
||||||
|
setQuota(def.quota);
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
async function submit() {
|
async function submit() {
|
||||||
@@ -204,6 +219,7 @@ function CreateKeyForm({
|
|||||||
owner_email: ownerEmail.trim() || undefined,
|
owner_email: ownerEmail.trim() || undefined,
|
||||||
tier,
|
tier,
|
||||||
rate_limit_per_min: rate,
|
rate_limit_per_min: rate,
|
||||||
|
quota_total: quota,
|
||||||
});
|
});
|
||||||
onCreated(res.key);
|
onCreated(res.key);
|
||||||
} catch (e) {
|
} catch (e) {
|
||||||
@@ -260,6 +276,16 @@ function CreateKeyForm({
|
|||||||
onChange={(e) => setRate(Math.max(1, parseInt(e.target.value || "1", 10)))}
|
onChange={(e) => setRate(Math.max(1, parseInt(e.target.value || "1", 10)))}
|
||||||
/>
|
/>
|
||||||
</label>
|
</label>
|
||||||
|
<label className="block">
|
||||||
|
<span className="text-xs text-gray-500">累计配额(总调用次数,0=不限)</span>
|
||||||
|
<input
|
||||||
|
type="number"
|
||||||
|
min={0}
|
||||||
|
className="w-full border rounded-md px-3 py-2 text-sm mt-1"
|
||||||
|
value={quota}
|
||||||
|
onChange={(e) => setQuota(Math.max(0, parseInt(e.target.value || "0", 10)))}
|
||||||
|
/>
|
||||||
|
</label>
|
||||||
</div>
|
</div>
|
||||||
<div className="mt-4 flex gap-2">
|
<div className="mt-4 flex gap-2">
|
||||||
<button
|
<button
|
||||||
|
|||||||
@@ -40,7 +40,7 @@ export default function AuditLogPage() {
|
|||||||
const pages = Math.max(1, Math.ceil(total / size));
|
const pages = Math.max(1, Math.ceil(total / size));
|
||||||
|
|
||||||
return (
|
return (
|
||||||
<div className="max-w-5xl">
|
<div className="mx-auto max-w-5xl">
|
||||||
<h2 className="mb-4 flex items-center gap-2 text-lg font-semibold text-gray-800">
|
<h2 className="mb-4 flex items-center gap-2 text-lg font-semibold text-gray-800">
|
||||||
<ScrollText className="h-5 w-5 text-emerald-600" /> 操作日志
|
<ScrollText className="h-5 w-5 text-emerald-600" /> 操作日志
|
||||||
<span className="text-sm font-normal text-gray-400">共 {total} 条</span>
|
<span className="text-sm font-normal text-gray-400">共 {total} 条</span>
|
||||||
|
|||||||
@@ -105,7 +105,7 @@ export default function BrandsPage() {
|
|||||||
}
|
}
|
||||||
|
|
||||||
return (
|
return (
|
||||||
<div className="max-w-4xl">
|
<div className="mx-auto max-w-4xl">
|
||||||
<div className="flex items-center justify-between mb-4">
|
<div className="flex items-center justify-between mb-4">
|
||||||
<div>
|
<div>
|
||||||
<h2 className="text-lg font-semibold text-gray-800 flex items-center gap-2">
|
<h2 className="text-lg font-semibold text-gray-800 flex items-center gap-2">
|
||||||
|
|||||||
@@ -55,7 +55,7 @@ export default function CategoriesPage() {
|
|||||||
}
|
}
|
||||||
|
|
||||||
return (
|
return (
|
||||||
<div className="max-w-5xl">
|
<div className="mx-auto max-w-5xl">
|
||||||
<div className="flex items-center justify-between mb-4">
|
<div className="flex items-center justify-between mb-4">
|
||||||
<div>
|
<div>
|
||||||
<h2 className="text-lg font-semibold text-gray-800 flex items-center gap-2">
|
<h2 className="text-lg font-semibold text-gray-800 flex items-center gap-2">
|
||||||
|
|||||||
@@ -5,10 +5,13 @@ import {
|
|||||||
Brand,
|
Brand,
|
||||||
Category,
|
Category,
|
||||||
FIELD_LABELS,
|
FIELD_LABELS,
|
||||||
|
KindField,
|
||||||
ProductDetail as Detail,
|
ProductDetail as Detail,
|
||||||
} from "../types";
|
} from "../types";
|
||||||
import {
|
import {
|
||||||
ArrowLeft,
|
ArrowLeft,
|
||||||
|
ChevronLeft,
|
||||||
|
ChevronRight,
|
||||||
Plus,
|
Plus,
|
||||||
Save,
|
Save,
|
||||||
Trash2,
|
Trash2,
|
||||||
@@ -88,10 +91,18 @@ const inputCls =
|
|||||||
export default function ProductDetail({
|
export default function ProductDetail({
|
||||||
id,
|
id,
|
||||||
onBack,
|
onBack,
|
||||||
|
ids = [],
|
||||||
|
onNavigate,
|
||||||
}: {
|
}: {
|
||||||
id: string;
|
id: string;
|
||||||
onBack: () => void;
|
onBack: () => void;
|
||||||
|
ids?: string[];
|
||||||
|
onNavigate?: (id: string) => void;
|
||||||
}) {
|
}) {
|
||||||
|
const navIndex = ids.indexOf(id);
|
||||||
|
const prevId = navIndex > 0 ? ids[navIndex - 1] : null;
|
||||||
|
const nextId =
|
||||||
|
navIndex >= 0 && navIndex < ids.length - 1 ? ids[navIndex + 1] : null;
|
||||||
const [d, setD] = useState<Detail | null>(null);
|
const [d, setD] = useState<Detail | null>(null);
|
||||||
const [brands, setBrands] = useState<Brand[]>([]);
|
const [brands, setBrands] = useState<Brand[]>([]);
|
||||||
const [categories, setCategories] = useState<Category[]>([]);
|
const [categories, setCategories] = useState<Category[]>([]);
|
||||||
@@ -117,6 +128,8 @@ export default function ProductDetail({
|
|||||||
const [basis, setBasis] = useState("");
|
const [basis, setBasis] = useState("");
|
||||||
const [serving, setServing] = useState("");
|
const [serving, setServing] = useState("");
|
||||||
const [nutriScore, setNutriScore] = useState("");
|
const [nutriScore, setNutriScore] = useState("");
|
||||||
|
const [kindFields, setKindFields] = useState<KindField[]>([]);
|
||||||
|
const [attrs, setAttrs] = useState<Record<string, string>>({});
|
||||||
|
|
||||||
function hydrate(detail: Detail) {
|
function hydrate(detail: Detail) {
|
||||||
setD(detail);
|
setD(detail);
|
||||||
@@ -139,6 +152,13 @@ export default function ProductDetail({
|
|||||||
setBasis(detail.nutrition_basis || "");
|
setBasis(detail.nutrition_basis || "");
|
||||||
setServing(detail.serving_size || "");
|
setServing(detail.serving_size || "");
|
||||||
setNutriScore(detail.nutri_score || "");
|
setNutriScore(detail.nutri_score || "");
|
||||||
|
const am: Record<string, string> = {};
|
||||||
|
if (detail.attributes) {
|
||||||
|
for (const [k, v] of Object.entries(detail.attributes)) {
|
||||||
|
am[k] = v == null ? "" : Array.isArray(v) ? v.join(", ") : String(v);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
setAttrs(am);
|
||||||
}
|
}
|
||||||
|
|
||||||
function reload() {
|
function reload() {
|
||||||
@@ -161,6 +181,41 @@ export default function ProductDetail({
|
|||||||
|
|
||||||
const missing = useMemo(() => d?.missing ?? [], [d]);
|
const missing = useMemo(() => d?.missing ?? [], [d]);
|
||||||
|
|
||||||
|
const selectedKind = useMemo(() => {
|
||||||
|
const c = categories.find((x) => x.id === categoryId);
|
||||||
|
return c?.archive_kind || d?.archive_kind || "generic";
|
||||||
|
}, [categories, categoryId, d]);
|
||||||
|
|
||||||
|
useEffect(() => {
|
||||||
|
if (selectedKind && selectedKind !== "food") {
|
||||||
|
api
|
||||||
|
.listKindFields(selectedKind)
|
||||||
|
.then((r) => setKindFields(r.items))
|
||||||
|
.catch(() => setKindFields([]));
|
||||||
|
} else {
|
||||||
|
setKindFields([]);
|
||||||
|
}
|
||||||
|
}, [selectedKind]);
|
||||||
|
|
||||||
|
const specGroups = useMemo(() => {
|
||||||
|
const groups: { label: string; fields: KindField[] }[] = [];
|
||||||
|
for (const f of kindFields) {
|
||||||
|
let g = groups.find((x) => x.label === f.group_label);
|
||||||
|
if (!g) {
|
||||||
|
g = { label: f.group_label, fields: [] };
|
||||||
|
groups.push(g);
|
||||||
|
}
|
||||||
|
g.fields.push(f);
|
||||||
|
}
|
||||||
|
return groups;
|
||||||
|
}, [kindFields]);
|
||||||
|
|
||||||
|
const attrLabels = useMemo(() => {
|
||||||
|
const m: Record<string, string> = {};
|
||||||
|
for (const f of kindFields) m[f.field_key] = f.label_zh;
|
||||||
|
return m;
|
||||||
|
}, [kindFields]);
|
||||||
|
|
||||||
function parseList(s: string): string[] {
|
function parseList(s: string): string[] {
|
||||||
return s
|
return s
|
||||||
.split(",")
|
.split(",")
|
||||||
@@ -177,6 +232,22 @@ export default function ProductDetail({
|
|||||||
const n = parseFloat(v);
|
const n = parseFloat(v);
|
||||||
if (!Number.isNaN(n)) nm[k] = n;
|
if (!Number.isNaN(n)) nm[k] = n;
|
||||||
}
|
}
|
||||||
|
let attributes: Record<string, unknown> | undefined;
|
||||||
|
if (selectedKind !== "food") {
|
||||||
|
attributes = {};
|
||||||
|
for (const f of kindFields) {
|
||||||
|
const raw = (attrs[f.field_key] ?? "").trim();
|
||||||
|
if (raw === "") continue;
|
||||||
|
if (f.field_type === "number") {
|
||||||
|
const n = parseFloat(raw);
|
||||||
|
if (!Number.isNaN(n)) attributes[f.field_key] = n;
|
||||||
|
} else if (f.field_type === "list") {
|
||||||
|
attributes[f.field_key] = parseList(raw);
|
||||||
|
} else {
|
||||||
|
attributes[f.field_key] = raw;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
const body = {
|
const body = {
|
||||||
gtin: gtin.trim() || null,
|
gtin: gtin.trim() || null,
|
||||||
name: name.trim(),
|
name: name.trim(),
|
||||||
@@ -194,6 +265,7 @@ export default function ProductDetail({
|
|||||||
nutrition_basis: basis || null,
|
nutrition_basis: basis || null,
|
||||||
serving_size: serving.trim() || null,
|
serving_size: serving.trim() || null,
|
||||||
nutri_score: nutriScore || null,
|
nutri_score: nutriScore || null,
|
||||||
|
...(attributes !== undefined ? { attributes } : {}),
|
||||||
};
|
};
|
||||||
try {
|
try {
|
||||||
const updated = await api.updateProduct(id, body);
|
const updated = await api.updateProduct(id, body);
|
||||||
@@ -226,12 +298,35 @@ export default function ProductDetail({
|
|||||||
return (
|
return (
|
||||||
<div className="mx-auto max-w-5xl space-y-5">
|
<div className="mx-auto max-w-5xl space-y-5">
|
||||||
<div className="flex items-center justify-between">
|
<div className="flex items-center justify-between">
|
||||||
<button
|
<div className="flex items-center gap-2">
|
||||||
onClick={onBack}
|
<button
|
||||||
className="flex items-center gap-1 text-sm text-gray-600 hover:text-gray-900"
|
onClick={onBack}
|
||||||
>
|
className="flex items-center gap-1 text-sm text-gray-600 hover:text-gray-900"
|
||||||
<ArrowLeft className="h-4 w-4" /> 返回列表
|
>
|
||||||
</button>
|
<ArrowLeft className="h-4 w-4" /> 返回列表
|
||||||
|
</button>
|
||||||
|
{ids.length > 1 && navIndex >= 0 && (
|
||||||
|
<div className="ml-2 flex items-center gap-1 text-sm">
|
||||||
|
<button
|
||||||
|
onClick={() => prevId && onNavigate?.(prevId)}
|
||||||
|
disabled={!prevId}
|
||||||
|
className="flex items-center gap-1 rounded border border-gray-300 px-2 py-1 text-gray-600 hover:bg-gray-50 disabled:opacity-40"
|
||||||
|
>
|
||||||
|
<ChevronLeft className="h-4 w-4" /> 上一个
|
||||||
|
</button>
|
||||||
|
<span className="text-xs text-gray-400">
|
||||||
|
{navIndex + 1} / {ids.length}
|
||||||
|
</span>
|
||||||
|
<button
|
||||||
|
onClick={() => nextId && onNavigate?.(nextId)}
|
||||||
|
disabled={!nextId}
|
||||||
|
className="flex items-center gap-1 rounded border border-gray-300 px-2 py-1 text-gray-600 hover:bg-gray-50 disabled:opacity-40"
|
||||||
|
>
|
||||||
|
下一个 <ChevronRight className="h-4 w-4" />
|
||||||
|
</button>
|
||||||
|
</div>
|
||||||
|
)}
|
||||||
|
</div>
|
||||||
<div className="flex items-center gap-3">
|
<div className="flex items-center gap-3">
|
||||||
{msg && <span className="text-sm text-emerald-600">{msg}</span>}
|
{msg && <span className="text-sm text-emerald-600">{msg}</span>}
|
||||||
{error && <span className="text-sm text-red-600">{error}</span>}
|
{error && <span className="text-sm text-red-600">{error}</span>}
|
||||||
@@ -251,7 +346,8 @@ export default function ProductDetail({
|
|||||||
{missing.length > 0 && (
|
{missing.length > 0 && (
|
||||||
<div className="flex items-center gap-2 rounded-lg border border-amber-200 bg-amber-50 px-4 py-3 text-sm text-amber-700">
|
<div className="flex items-center gap-2 rounded-lg border border-amber-200 bg-amber-50 px-4 py-3 text-sm text-amber-700">
|
||||||
<AlertCircle className="h-4 w-4" />
|
<AlertCircle className="h-4 w-4" />
|
||||||
待补全字段:{missing.map((f) => FIELD_LABELS[f] || f).join("、")}
|
待补全字段:
|
||||||
|
{missing.map((f) => FIELD_LABELS[f] || attrLabels[f] || f).join("、")}
|
||||||
</div>
|
</div>
|
||||||
)}
|
)}
|
||||||
|
|
||||||
@@ -338,6 +434,7 @@ export default function ProductDetail({
|
|||||||
</div>
|
</div>
|
||||||
</Card>
|
</Card>
|
||||||
|
|
||||||
|
{selectedKind === "food" && (
|
||||||
<Card title="配料与营养">
|
<Card title="配料与营养">
|
||||||
<div className="mb-4 grid grid-cols-2 gap-4">
|
<div className="mb-4 grid grid-cols-2 gap-4">
|
||||||
<Field label="配料表">
|
<Field label="配料表">
|
||||||
@@ -410,6 +507,75 @@ export default function ProductDetail({
|
|||||||
))}
|
))}
|
||||||
</div>
|
</div>
|
||||||
</Card>
|
</Card>
|
||||||
|
)}
|
||||||
|
|
||||||
|
{selectedKind !== "food" && kindFields.length > 0 && (
|
||||||
|
<Card title="规格参数">
|
||||||
|
{specGroups.map((grp) => (
|
||||||
|
<div key={grp.label} className="mb-4 last:mb-0">
|
||||||
|
{grp.label && (
|
||||||
|
<h4 className="mb-2 text-xs font-medium text-gray-500">
|
||||||
|
{grp.label}
|
||||||
|
</h4>
|
||||||
|
)}
|
||||||
|
<div className="grid grid-cols-3 gap-3">
|
||||||
|
{grp.fields.map((f) => (
|
||||||
|
<Field
|
||||||
|
key={f.field_key}
|
||||||
|
label={f.unit ? `${f.label_zh} (${f.unit})` : f.label_zh}
|
||||||
|
>
|
||||||
|
{f.field_type === "select" ? (
|
||||||
|
<select
|
||||||
|
className={inputCls}
|
||||||
|
value={attrs[f.field_key] ?? ""}
|
||||||
|
onChange={(e) =>
|
||||||
|
setAttrs((prev) => ({
|
||||||
|
...prev,
|
||||||
|
[f.field_key]: e.target.value,
|
||||||
|
}))
|
||||||
|
}
|
||||||
|
>
|
||||||
|
<option value="">(未设置)</option>
|
||||||
|
{f.options.map((o) => (
|
||||||
|
<option key={o} value={o}>
|
||||||
|
{o}
|
||||||
|
</option>
|
||||||
|
))}
|
||||||
|
</select>
|
||||||
|
) : f.field_type === "textarea" ? (
|
||||||
|
<textarea
|
||||||
|
className={inputCls}
|
||||||
|
rows={3}
|
||||||
|
value={attrs[f.field_key] ?? ""}
|
||||||
|
onChange={(e) =>
|
||||||
|
setAttrs((prev) => ({
|
||||||
|
...prev,
|
||||||
|
[f.field_key]: e.target.value,
|
||||||
|
}))
|
||||||
|
}
|
||||||
|
/>
|
||||||
|
) : (
|
||||||
|
<input
|
||||||
|
className={inputCls}
|
||||||
|
type={f.field_type === "number" ? "number" : "text"}
|
||||||
|
step={f.field_type === "number" ? "any" : undefined}
|
||||||
|
placeholder={f.placeholder ?? undefined}
|
||||||
|
value={attrs[f.field_key] ?? ""}
|
||||||
|
onChange={(e) =>
|
||||||
|
setAttrs((prev) => ({
|
||||||
|
...prev,
|
||||||
|
[f.field_key]: e.target.value,
|
||||||
|
}))
|
||||||
|
}
|
||||||
|
/>
|
||||||
|
)}
|
||||||
|
</Field>
|
||||||
|
))}
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
))}
|
||||||
|
</Card>
|
||||||
|
)}
|
||||||
|
|
||||||
<BarcodesCard product={d} onChange={reload} onError={setError} />
|
<BarcodesCard product={d} onChange={reload} onError={setError} />
|
||||||
<ImagesCard
|
<ImagesCard
|
||||||
|
|||||||
@@ -27,12 +27,13 @@ function QualityBadge({ score }: { score: number }) {
|
|||||||
export default function ProductList({
|
export default function ProductList({
|
||||||
onOpen,
|
onOpen,
|
||||||
}: {
|
}: {
|
||||||
onOpen: (id: string) => void;
|
onOpen: (id: string, ids: string[]) => void;
|
||||||
}) {
|
}) {
|
||||||
const [q, setQ] = useState("");
|
const [q, setQ] = useState("");
|
||||||
const [input, setInput] = useState("");
|
const [input, setInput] = useState("");
|
||||||
const [page, setPage] = useState(1);
|
const [page, setPage] = useState(1);
|
||||||
const [size] = useState(20);
|
const [size, setSize] = useState(20);
|
||||||
|
const [jump, setJump] = useState("");
|
||||||
const [rows, setRows] = useState<ProductRow[]>([]);
|
const [rows, setRows] = useState<ProductRow[]>([]);
|
||||||
const [total, setTotal] = useState(0);
|
const [total, setTotal] = useState(0);
|
||||||
const [loading, setLoading] = useState(false);
|
const [loading, setLoading] = useState(false);
|
||||||
@@ -164,7 +165,7 @@ export default function ProductList({
|
|||||||
onClose={() => setCreating(false)}
|
onClose={() => setCreating(false)}
|
||||||
onCreated={(id) => {
|
onCreated={(id) => {
|
||||||
setCreating(false);
|
setCreating(false);
|
||||||
onOpen(id);
|
onOpen(id, [id]);
|
||||||
}}
|
}}
|
||||||
/>
|
/>
|
||||||
)}
|
)}
|
||||||
@@ -270,7 +271,7 @@ export default function ProductList({
|
|||||||
rows.map((r) => (
|
rows.map((r) => (
|
||||||
<tr
|
<tr
|
||||||
key={r.id}
|
key={r.id}
|
||||||
onClick={() => onOpen(r.id)}
|
onClick={() => onOpen(r.id, rows.map((x) => x.id))}
|
||||||
className={`cursor-pointer hover:bg-emerald-50/50 ${
|
className={`cursor-pointer hover:bg-emerald-50/50 ${
|
||||||
selected.has(r.id) ? "bg-emerald-50/60" : ""
|
selected.has(r.id) ? "bg-emerald-50/60" : ""
|
||||||
}`}
|
}`}
|
||||||
@@ -319,7 +320,25 @@ export default function ProductList({
|
|||||||
</table>
|
</table>
|
||||||
</div>
|
</div>
|
||||||
|
|
||||||
<div className="mt-4 flex items-center justify-end gap-2 text-sm text-gray-600">
|
<div className="mt-4 flex flex-wrap items-center justify-end gap-2 text-sm text-gray-600">
|
||||||
|
<div className="mr-auto flex items-center gap-1">
|
||||||
|
<span>每页</span>
|
||||||
|
<select
|
||||||
|
value={size}
|
||||||
|
onChange={(e) => {
|
||||||
|
setSize(Number(e.target.value));
|
||||||
|
setPage(1);
|
||||||
|
}}
|
||||||
|
className="rounded border border-gray-300 px-2 py-1"
|
||||||
|
>
|
||||||
|
{[20, 50, 100].map((n) => (
|
||||||
|
<option key={n} value={n}>
|
||||||
|
{n}
|
||||||
|
</option>
|
||||||
|
))}
|
||||||
|
</select>
|
||||||
|
<span>条 · 共 {total} 条</span>
|
||||||
|
</div>
|
||||||
<button
|
<button
|
||||||
disabled={page <= 1}
|
disabled={page <= 1}
|
||||||
onClick={() => setPage((p) => p - 1)}
|
onClick={() => setPage((p) => p - 1)}
|
||||||
@@ -337,6 +356,32 @@ export default function ProductList({
|
|||||||
>
|
>
|
||||||
下一页
|
下一页
|
||||||
</button>
|
</button>
|
||||||
|
<form
|
||||||
|
onSubmit={(e) => {
|
||||||
|
e.preventDefault();
|
||||||
|
const n = Number(jump);
|
||||||
|
if (Number.isFinite(n) && n >= 1) {
|
||||||
|
setPage(Math.min(Math.max(1, Math.trunc(n)), pages));
|
||||||
|
setJump("");
|
||||||
|
}
|
||||||
|
}}
|
||||||
|
className="flex items-center gap-1"
|
||||||
|
>
|
||||||
|
<span>跳至</span>
|
||||||
|
<input
|
||||||
|
value={jump}
|
||||||
|
onChange={(e) => setJump(e.target.value.replace(/[^0-9]/g, ""))}
|
||||||
|
placeholder={String(page)}
|
||||||
|
className="w-14 rounded border border-gray-300 px-2 py-1 text-center"
|
||||||
|
aria-label="跳转页码"
|
||||||
|
/>
|
||||||
|
<button
|
||||||
|
type="submit"
|
||||||
|
className="rounded border border-gray-300 px-3 py-1 hover:bg-gray-50"
|
||||||
|
>
|
||||||
|
前往
|
||||||
|
</button>
|
||||||
|
</form>
|
||||||
</div>
|
</div>
|
||||||
</div>
|
</div>
|
||||||
);
|
);
|
||||||
|
|||||||
@@ -44,7 +44,7 @@ export default function StatsPage() {
|
|||||||
}, []);
|
}, []);
|
||||||
|
|
||||||
return (
|
return (
|
||||||
<div className="max-w-5xl">
|
<div className="mx-auto max-w-5xl">
|
||||||
<h2 className="mb-4 flex items-center gap-2 text-lg font-semibold text-gray-800">
|
<h2 className="mb-4 flex items-center gap-2 text-lg font-semibold text-gray-800">
|
||||||
<BarChart3 className="h-5 w-5 text-emerald-600" /> 数据概览
|
<BarChart3 className="h-5 w-5 text-emerald-600" /> 数据概览
|
||||||
</h2>
|
</h2>
|
||||||
|
|||||||
@@ -56,7 +56,7 @@ export default function SubmissionsPage({ onPending }: { onPending?: (n: number)
|
|||||||
}
|
}
|
||||||
|
|
||||||
return (
|
return (
|
||||||
<div>
|
<div className="mx-auto max-w-5xl">
|
||||||
<div className="flex items-center gap-2 mb-4">
|
<div className="flex items-center gap-2 mb-4">
|
||||||
{STATUS_TABS.map((t) => (
|
{STATUS_TABS.map((t) => (
|
||||||
<button
|
<button
|
||||||
@@ -193,7 +193,7 @@ function SubmissionView({ id, onBack }: { id: string; onBack: () => void }) {
|
|||||||
const nutri = Object.entries(p.nutriments || {});
|
const nutri = Object.entries(p.nutriments || {});
|
||||||
|
|
||||||
return (
|
return (
|
||||||
<div className="max-w-3xl">
|
<div className="mx-auto max-w-3xl">
|
||||||
<button onClick={onBack} className="text-sm text-gray-500 flex items-center gap-1 mb-4">
|
<button onClick={onBack} className="text-sm text-gray-500 flex items-center gap-1 mb-4">
|
||||||
<ArrowLeft className="h-4 w-4" /> 返回投稿队列
|
<ArrowLeft className="h-4 w-4" /> 返回投稿队列
|
||||||
</button>
|
</button>
|
||||||
|
|||||||
@@ -44,6 +44,8 @@ export interface ProductDetail {
|
|||||||
brand: string | null;
|
brand: string | null;
|
||||||
category_id: string | null;
|
category_id: string | null;
|
||||||
category_path: string | null;
|
category_path: string | null;
|
||||||
|
archive_kind: string;
|
||||||
|
attributes: Record<string, unknown>;
|
||||||
net_content_value: number | null;
|
net_content_value: number | null;
|
||||||
net_content_unit: string | null;
|
net_content_unit: string | null;
|
||||||
country_of_origin: string | null;
|
country_of_origin: string | null;
|
||||||
@@ -77,9 +79,23 @@ export interface Category {
|
|||||||
level: number;
|
level: number;
|
||||||
parent_id: string | null;
|
parent_id: string | null;
|
||||||
gpc_brick_code: string | null;
|
gpc_brick_code: string | null;
|
||||||
|
archive_kind: string;
|
||||||
product_count: number;
|
product_count: number;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
export interface KindField {
|
||||||
|
kind: string;
|
||||||
|
field_key: string;
|
||||||
|
group_label: string;
|
||||||
|
label_zh: string;
|
||||||
|
field_type: string;
|
||||||
|
unit: string | null;
|
||||||
|
options: string[];
|
||||||
|
placeholder: string | null;
|
||||||
|
sort_order: number;
|
||||||
|
qualified: boolean;
|
||||||
|
}
|
||||||
|
|
||||||
export interface CategoryInput {
|
export interface CategoryInput {
|
||||||
name_zh: string;
|
name_zh: string;
|
||||||
name_en?: string | null;
|
name_en?: string | null;
|
||||||
@@ -183,6 +199,7 @@ export interface ApiKey {
|
|||||||
owner_email: string | null;
|
owner_email: string | null;
|
||||||
tier: string;
|
tier: string;
|
||||||
rate_limit_per_min: number;
|
rate_limit_per_min: number;
|
||||||
|
quota_total: number;
|
||||||
revoked_at: string | null;
|
revoked_at: string | null;
|
||||||
created_by: string | null;
|
created_by: string | null;
|
||||||
created_at: string;
|
created_at: string;
|
||||||
|
|||||||
@@ -37,7 +37,8 @@ func main() {
|
|||||||
log.Print("warning: Redis not configured; public API rate limiting disabled")
|
log.Print("warning: Redis not configured; public API rate limiting disabled")
|
||||||
}
|
}
|
||||||
h := handler.New(store.New(pool), publicweb.Dist()).
|
h := handler.New(store.New(pool), publicweb.Dist()).
|
||||||
WithRateLimit(limiter, cfg.AnonRateLimitPerMin)
|
WithRateLimit(limiter, cfg.AnonRateLimitPerMin).
|
||||||
|
WithQuotas(cfg.AnonTotalQuota, cfg.RegisteredRateLimitPerMin, cfg.RegisteredQuotaTotal)
|
||||||
|
|
||||||
srv := &http.Server{
|
srv := &http.Server{
|
||||||
Addr: cfg.Addr,
|
Addr: cfg.Addr,
|
||||||
|
|||||||
@@ -46,7 +46,7 @@ func (h *Handler) CreateAPIKey(w http.ResponseWriter, r *http.Request) {
|
|||||||
writeError(w, http.StatusBadRequest, "bad_request", "名称不能为空")
|
writeError(w, http.StatusBadRequest, "bad_request", "名称不能为空")
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
if in.Tier != "" && in.Tier != "free" && in.Tier != "partner" && in.Tier != "internal" {
|
if in.Tier != "" && in.Tier != "free" && in.Tier != "registered" && in.Tier != "partner" && in.Tier != "internal" {
|
||||||
writeError(w, http.StatusBadRequest, "bad_request", "tier 取值无效")
|
writeError(w, http.StatusBadRequest, "bad_request", "tier 取值无效")
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -84,6 +84,7 @@ func (h *Handler) Router() http.Handler {
|
|||||||
r.Put("/api/brands/{id}", h.UpdateBrand)
|
r.Put("/api/brands/{id}", h.UpdateBrand)
|
||||||
r.Post("/api/brands/{id}/merge", h.MergeBrands)
|
r.Post("/api/brands/{id}/merge", h.MergeBrands)
|
||||||
r.Delete("/api/brands/{id}", h.DeleteBrand)
|
r.Delete("/api/brands/{id}", h.DeleteBrand)
|
||||||
|
r.Get("/api/kind-fields", h.ListKindFields)
|
||||||
r.Get("/api/categories", h.ListCategories)
|
r.Get("/api/categories", h.ListCategories)
|
||||||
r.Post("/api/categories", h.CreateCategory)
|
r.Post("/api/categories", h.CreateCategory)
|
||||||
r.Put("/api/categories/{id}", h.UpdateCategory)
|
r.Put("/api/categories/{id}", h.UpdateCategory)
|
||||||
@@ -423,6 +424,20 @@ func (h *Handler) ListBrands(w http.ResponseWriter, r *http.Request) {
|
|||||||
writeJSON(w, http.StatusOK, map[string]any{"items": items})
|
writeJSON(w, http.StatusOK, map[string]any{"items": items})
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// ListKindFields returns the editable spec field template for an archive kind.
|
||||||
|
func (h *Handler) ListKindFields(w http.ResponseWriter, r *http.Request) {
|
||||||
|
kind := strings.TrimSpace(r.URL.Query().Get("kind"))
|
||||||
|
if kind == "" {
|
||||||
|
writeError(w, http.StatusBadRequest, "bad_request", "缺少 kind 参数")
|
||||||
|
return
|
||||||
|
}
|
||||||
|
items, err := h.store.ListKindFields(r.Context(), kind)
|
||||||
|
if h.handleErr(w, err) {
|
||||||
|
return
|
||||||
|
}
|
||||||
|
writeJSON(w, http.StatusOK, map[string]any{"items": items, "kind": kind})
|
||||||
|
}
|
||||||
|
|
||||||
// ListCategories returns category options.
|
// ListCategories returns category options.
|
||||||
func (h *Handler) ListCategories(w http.ResponseWriter, r *http.Request) {
|
func (h *Handler) ListCategories(w http.ResponseWriter, r *http.Request) {
|
||||||
items, err := h.store.ListCategories(r.Context())
|
items, err := h.store.ListCategories(r.Context())
|
||||||
|
|||||||
@@ -64,10 +64,15 @@ func (s *Store) ListProducts(ctx context.Context, q string, limit, offset int) (
|
|||||||
return nil, 0, err
|
return nil, 0, err
|
||||||
}
|
}
|
||||||
|
|
||||||
|
qualified, err := s.kindQualifiedKeys(ctx, s.pool)
|
||||||
|
if err != nil {
|
||||||
|
return nil, 0, err
|
||||||
|
}
|
||||||
|
|
||||||
args = append(args, limit, offset)
|
args = append(args, limit, offset)
|
||||||
sql := `
|
sql := `
|
||||||
SELECT p.id, p.gtin, p.name, b.name, c.path::text, p.status, p.quality_score,
|
SELECT p.id, p.gtin, p.name, b.name, c.path::text, p.status, p.quality_score,
|
||||||
p.updated_at,
|
p.updated_at, COALESCE(c.archive_kind, 'generic'), p.attributes,
|
||||||
(p.brand_id IS NOT NULL) AS has_brand,
|
(p.brand_id IS NOT NULL) AS has_brand,
|
||||||
(p.category_id IS NOT NULL) AS has_cat,
|
(p.category_id IS NOT NULL) AS has_cat,
|
||||||
(p.net_content_canonical IS NOT NULL) AS has_net,
|
(p.net_content_canonical IS NOT NULL) AS has_net,
|
||||||
@@ -91,13 +96,21 @@ LEFT JOIN food_detail f ON f.product_id = p.id ` + where +
|
|||||||
for rows.Next() {
|
for rows.Next() {
|
||||||
var r ProductRow
|
var r ProductRow
|
||||||
var hasBrand, hasCat, hasNet, hasCountry, hasNutri, hasIng, hasImg bool
|
var hasBrand, hasCat, hasNet, hasCountry, hasNutri, hasIng, hasImg bool
|
||||||
|
var kind string
|
||||||
|
var attributes []byte
|
||||||
var updated time.Time
|
var updated time.Time
|
||||||
if err := rows.Scan(&r.ID, &r.GTIN, &r.Name, &r.Brand, &r.CategoryPath, &r.Status,
|
if err := rows.Scan(&r.ID, &r.GTIN, &r.Name, &r.Brand, &r.CategoryPath, &r.Status,
|
||||||
&r.QualityScore, &updated, &hasBrand, &hasCat, &hasNet, &hasCountry,
|
&r.QualityScore, &updated, &kind, &attributes,
|
||||||
|
&hasBrand, &hasCat, &hasNet, &hasCountry,
|
||||||
&hasNutri, &hasIng, &hasImg); err != nil {
|
&hasNutri, &hasIng, &hasImg); err != nil {
|
||||||
return nil, 0, err
|
return nil, 0, err
|
||||||
}
|
}
|
||||||
r.UpdatedAt = updated.Format(time.RFC3339)
|
r.UpdatedAt = updated.Format(time.RFC3339)
|
||||||
|
attrs := map[string]any{}
|
||||||
|
if len(attributes) > 0 {
|
||||||
|
_ = json.Unmarshal(attributes, &attrs)
|
||||||
|
}
|
||||||
|
qkeys := qualified[kind]
|
||||||
present := map[string]bool{
|
present := map[string]bool{
|
||||||
"name": r.Name != "",
|
"name": r.Name != "",
|
||||||
"gtin": r.GTIN != nil && *r.GTIN != "",
|
"gtin": r.GTIN != nil && *r.GTIN != "",
|
||||||
@@ -109,8 +122,11 @@ LEFT JOIN food_detail f ON f.product_id = p.id ` + where +
|
|||||||
"ingredients": hasIng,
|
"ingredients": hasIng,
|
||||||
"image": hasImg,
|
"image": hasImg,
|
||||||
}
|
}
|
||||||
|
for _, k := range qkeys {
|
||||||
|
present[k] = attrPresent(attrs, k)
|
||||||
|
}
|
||||||
r.Missing = []string{}
|
r.Missing = []string{}
|
||||||
for _, f := range CompletenessFields {
|
for _, f := range completenessKeys(kind, qkeys) {
|
||||||
if !present[f] {
|
if !present[f] {
|
||||||
r.Missing = append(r.Missing, f)
|
r.Missing = append(r.Missing, f)
|
||||||
}
|
}
|
||||||
@@ -150,6 +166,8 @@ type ProductDetail struct {
|
|||||||
Brand *string `json:"brand"`
|
Brand *string `json:"brand"`
|
||||||
CategoryID *string `json:"category_id"`
|
CategoryID *string `json:"category_id"`
|
||||||
CategoryPath *string `json:"category_path"`
|
CategoryPath *string `json:"category_path"`
|
||||||
|
ArchiveKind string `json:"archive_kind"`
|
||||||
|
Attributes map[string]any `json:"attributes"`
|
||||||
NetContentValue *float64 `json:"net_content_value"`
|
NetContentValue *float64 `json:"net_content_value"`
|
||||||
NetContentUnit *string `json:"net_content_unit"`
|
NetContentUnit *string `json:"net_content_unit"`
|
||||||
CountryOfOrigin *string `json:"country_of_origin"`
|
CountryOfOrigin *string `json:"country_of_origin"`
|
||||||
@@ -173,9 +191,11 @@ type ProductDetail struct {
|
|||||||
func (s *Store) GetProduct(ctx context.Context, id string) (*ProductDetail, error) {
|
func (s *Store) GetProduct(ctx context.Context, id string) (*ProductDetail, error) {
|
||||||
var d ProductDetail
|
var d ProductDetail
|
||||||
var nutriments []byte
|
var nutriments []byte
|
||||||
|
var attributes []byte
|
||||||
var updated time.Time
|
var updated time.Time
|
||||||
err := s.pool.QueryRow(ctx, `
|
err := s.pool.QueryRow(ctx, `
|
||||||
SELECT p.id, p.gtin, p.name, p.brand_id, b.name, p.category_id, c.path::text,
|
SELECT p.id, p.gtin, p.name, p.brand_id, b.name, p.category_id, c.path::text,
|
||||||
|
COALESCE(c.archive_kind, 'generic'), p.attributes,
|
||||||
p.net_content_value, p.net_content_unit, p.country_of_origin, p.status,
|
p.net_content_value, p.net_content_unit, p.country_of_origin, p.status,
|
||||||
p.quality_score, p.updated_at,
|
p.quality_score, p.updated_at,
|
||||||
f.ingredients_text, f.allergens, f.additives, f.nutriments,
|
f.ingredients_text, f.allergens, f.additives, f.nutriments,
|
||||||
@@ -186,6 +206,7 @@ LEFT JOIN category c ON c.id = p.category_id
|
|||||||
LEFT JOIN food_detail f ON f.product_id = p.id
|
LEFT JOIN food_detail f ON f.product_id = p.id
|
||||||
WHERE p.id = $1`, id).Scan(
|
WHERE p.id = $1`, id).Scan(
|
||||||
&d.ID, &d.GTIN, &d.Name, &d.BrandID, &d.Brand, &d.CategoryID, &d.CategoryPath,
|
&d.ID, &d.GTIN, &d.Name, &d.BrandID, &d.Brand, &d.CategoryID, &d.CategoryPath,
|
||||||
|
&d.ArchiveKind, &attributes,
|
||||||
&d.NetContentValue, &d.NetContentUnit, &d.CountryOfOrigin, &d.Status,
|
&d.NetContentValue, &d.NetContentUnit, &d.CountryOfOrigin, &d.Status,
|
||||||
&d.QualityScore, &updated,
|
&d.QualityScore, &updated,
|
||||||
&d.IngredientsText, &d.Allergens, &d.Additives, &nutriments,
|
&d.IngredientsText, &d.Allergens, &d.Additives, &nutriments,
|
||||||
@@ -198,6 +219,10 @@ WHERE p.id = $1`, id).Scan(
|
|||||||
return nil, err
|
return nil, err
|
||||||
}
|
}
|
||||||
d.UpdatedAt = updated.Format(time.RFC3339)
|
d.UpdatedAt = updated.Format(time.RFC3339)
|
||||||
|
d.Attributes = map[string]any{}
|
||||||
|
if len(attributes) > 0 {
|
||||||
|
_ = json.Unmarshal(attributes, &d.Attributes)
|
||||||
|
}
|
||||||
if len(nutriments) > 0 {
|
if len(nutriments) > 0 {
|
||||||
_ = json.Unmarshal(nutriments, &d.Nutriments)
|
_ = json.Unmarshal(nutriments, &d.Nutriments)
|
||||||
}
|
}
|
||||||
@@ -226,11 +251,15 @@ WHERE p.id = $1`, id).Scan(
|
|||||||
}
|
}
|
||||||
d.MSRP = msrps
|
d.MSRP = msrps
|
||||||
|
|
||||||
d.Missing = missingFromDetail(&d)
|
qualified, err := s.kindQualifiedKeys(ctx, s.pool)
|
||||||
|
if err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
d.Missing = missingFromDetail(&d, qualified[d.ArchiveKind])
|
||||||
return &d, nil
|
return &d, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
func missingFromDetail(d *ProductDetail) []string {
|
func missingFromDetail(d *ProductDetail, qualifiedAttrKeys []string) []string {
|
||||||
present := map[string]bool{
|
present := map[string]bool{
|
||||||
"name": d.Name != "",
|
"name": d.Name != "",
|
||||||
"gtin": d.GTIN != nil && *d.GTIN != "",
|
"gtin": d.GTIN != nil && *d.GTIN != "",
|
||||||
@@ -242,8 +271,11 @@ func missingFromDetail(d *ProductDetail) []string {
|
|||||||
"ingredients": d.IngredientsText != nil && *d.IngredientsText != "",
|
"ingredients": d.IngredientsText != nil && *d.IngredientsText != "",
|
||||||
"image": len(d.Images) > 0,
|
"image": len(d.Images) > 0,
|
||||||
}
|
}
|
||||||
|
for _, k := range qualifiedAttrKeys {
|
||||||
|
present[k] = attrPresent(d.Attributes, k)
|
||||||
|
}
|
||||||
missing := []string{}
|
missing := []string{}
|
||||||
for _, f := range CompletenessFields {
|
for _, f := range completenessKeys(d.ArchiveKind, qualifiedAttrKeys) {
|
||||||
if !present[f] {
|
if !present[f] {
|
||||||
missing = append(missing, f)
|
missing = append(missing, f)
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -19,6 +19,7 @@ type APIKeyRow struct {
|
|||||||
OwnerEmail *string `json:"owner_email"`
|
OwnerEmail *string `json:"owner_email"`
|
||||||
Tier string `json:"tier"`
|
Tier string `json:"tier"`
|
||||||
RateLimitPerMin int `json:"rate_limit_per_min"`
|
RateLimitPerMin int `json:"rate_limit_per_min"`
|
||||||
|
QuotaTotal int64 `json:"quota_total"`
|
||||||
RevokedAt *string `json:"revoked_at"`
|
RevokedAt *string `json:"revoked_at"`
|
||||||
CreatedBy *string `json:"created_by"`
|
CreatedBy *string `json:"created_by"`
|
||||||
CreatedAt string `json:"created_at"`
|
CreatedAt string `json:"created_at"`
|
||||||
@@ -30,6 +31,7 @@ type APIKeyInput struct {
|
|||||||
OwnerEmail string `json:"owner_email"`
|
OwnerEmail string `json:"owner_email"`
|
||||||
Tier string `json:"tier"`
|
Tier string `json:"tier"`
|
||||||
RateLimitPerMin int `json:"rate_limit_per_min"`
|
RateLimitPerMin int `json:"rate_limit_per_min"`
|
||||||
|
QuotaTotal int64 `json:"quota_total"`
|
||||||
}
|
}
|
||||||
|
|
||||||
// CreateAPIKey issues a new key, returning the one-time plaintext alongside the
|
// CreateAPIKey issues a new key, returning the one-time plaintext alongside the
|
||||||
@@ -43,6 +45,10 @@ func (s *Store) CreateAPIKey(ctx context.Context, in APIKeyInput, createdBy stri
|
|||||||
if rate <= 0 {
|
if rate <= 0 {
|
||||||
rate = 120
|
rate = 120
|
||||||
}
|
}
|
||||||
|
quota := in.QuotaTotal
|
||||||
|
if quota < 0 {
|
||||||
|
quota = 0
|
||||||
|
}
|
||||||
var owner *string
|
var owner *string
|
||||||
if e := strings.TrimSpace(in.OwnerEmail); e != "" {
|
if e := strings.TrimSpace(in.OwnerEmail); e != "" {
|
||||||
owner = &e
|
owner = &e
|
||||||
@@ -56,12 +62,12 @@ func (s *Store) CreateAPIKey(ctx context.Context, in APIKeyInput, createdBy stri
|
|||||||
var revoked, created *time.Time
|
var revoked, created *time.Time
|
||||||
var createdByOut *string
|
var createdByOut *string
|
||||||
err = s.pool.QueryRow(ctx, `
|
err = s.pool.QueryRow(ctx, `
|
||||||
INSERT INTO api_key (name, key_prefix, key_hash, owner_email, tier, rate_limit_per_min, created_by)
|
INSERT INTO api_key (name, key_prefix, key_hash, owner_email, tier, rate_limit_per_min, quota_total, created_by)
|
||||||
VALUES ($1, $2, $3, $4, $5, $6, $7)
|
VALUES ($1, $2, $3, $4, $5, $6, $7, $8)
|
||||||
RETURNING id, name, key_prefix, owner_email, tier, rate_limit_per_min, revoked_at, created_by, created_at`,
|
RETURNING id, name, key_prefix, owner_email, tier, rate_limit_per_min, quota_total, revoked_at, created_by, created_at`,
|
||||||
strings.TrimSpace(in.Name), prefix, hash, owner, tier, rate, createdBy,
|
strings.TrimSpace(in.Name), prefix, hash, owner, tier, rate, quota, createdBy,
|
||||||
).Scan(&row.ID, &row.Name, &row.KeyPrefix, &row.OwnerEmail, &row.Tier,
|
).Scan(&row.ID, &row.Name, &row.KeyPrefix, &row.OwnerEmail, &row.Tier,
|
||||||
&row.RateLimitPerMin, &revoked, &createdByOut, &created)
|
&row.RateLimitPerMin, &row.QuotaTotal, &revoked, &createdByOut, &created)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return "", row, err
|
return "", row, err
|
||||||
}
|
}
|
||||||
@@ -75,7 +81,7 @@ RETURNING id, name, key_prefix, owner_email, tier, rate_limit_per_min, revoked_a
|
|||||||
// ListAPIKeys returns all keys (active first, newest first).
|
// ListAPIKeys returns all keys (active first, newest first).
|
||||||
func (s *Store) ListAPIKeys(ctx context.Context) ([]APIKeyRow, error) {
|
func (s *Store) ListAPIKeys(ctx context.Context) ([]APIKeyRow, error) {
|
||||||
rows, err := s.pool.Query(ctx, `
|
rows, err := s.pool.Query(ctx, `
|
||||||
SELECT id, name, key_prefix, owner_email, tier, rate_limit_per_min, revoked_at, created_by, created_at
|
SELECT id, name, key_prefix, owner_email, tier, rate_limit_per_min, quota_total, revoked_at, created_by, created_at
|
||||||
FROM api_key
|
FROM api_key
|
||||||
ORDER BY (revoked_at IS NULL) DESC, created_at DESC`)
|
ORDER BY (revoked_at IS NULL) DESC, created_at DESC`)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
@@ -87,7 +93,7 @@ ORDER BY (revoked_at IS NULL) DESC, created_at DESC`)
|
|||||||
var r APIKeyRow
|
var r APIKeyRow
|
||||||
var revoked, created *time.Time
|
var revoked, created *time.Time
|
||||||
if err := rows.Scan(&r.ID, &r.Name, &r.KeyPrefix, &r.OwnerEmail, &r.Tier,
|
if err := rows.Scan(&r.ID, &r.Name, &r.KeyPrefix, &r.OwnerEmail, &r.Tier,
|
||||||
&r.RateLimitPerMin, &revoked, &r.CreatedBy, &created); err != nil {
|
&r.RateLimitPerMin, &r.QuotaTotal, &revoked, &r.CreatedBy, &created); err != nil {
|
||||||
return nil, err
|
return nil, err
|
||||||
}
|
}
|
||||||
if revoked != nil {
|
if revoked != nil {
|
||||||
|
|||||||
@@ -96,11 +96,12 @@ func (s *Store) CreateCategory(ctx context.Context, actor string, in CategoryInp
|
|||||||
|
|
||||||
parentPath := ""
|
parentPath := ""
|
||||||
parentLevel := -1
|
parentLevel := -1
|
||||||
|
kind := DefaultKind
|
||||||
var parentID *string
|
var parentID *string
|
||||||
if pid := trimPtr(in.ParentID); pid != nil {
|
if pid := trimPtr(in.ParentID); pid != nil {
|
||||||
var path string
|
var path string
|
||||||
var level int
|
var level int
|
||||||
err := s.pool.QueryRow(ctx, "SELECT path::text, level FROM category WHERE id = $1", *pid).Scan(&path, &level)
|
err := s.pool.QueryRow(ctx, "SELECT path::text, level, archive_kind FROM category WHERE id = $1", *pid).Scan(&path, &level, &kind)
|
||||||
if errors.Is(err, pgx.ErrNoRows) {
|
if errors.Is(err, pgx.ErrNoRows) {
|
||||||
return nil, ErrInvalidParent
|
return nil, ErrInvalidParent
|
||||||
}
|
}
|
||||||
@@ -119,11 +120,11 @@ func (s *Store) CreateCategory(ctx context.Context, actor string, in CategoryInp
|
|||||||
|
|
||||||
var c Category
|
var c Category
|
||||||
err := s.pool.QueryRow(ctx, `
|
err := s.pool.QueryRow(ctx, `
|
||||||
INSERT INTO category (name_zh, name_en, parent_id, path, gpc_brick_code, level)
|
INSERT INTO category (name_zh, name_en, parent_id, path, gpc_brick_code, level, archive_kind)
|
||||||
VALUES ($1, $2, $3, $4::ltree, $5, $6)
|
VALUES ($1, $2, $3, $4::ltree, $5, $6, $7)
|
||||||
RETURNING id, name_zh, name_en, path::text, level, parent_id::text, gpc_brick_code, 0`,
|
RETURNING id, name_zh, name_en, path::text, level, parent_id::text, gpc_brick_code, archive_kind, 0`,
|
||||||
name, trimPtr(in.NameEN), parentID, path, trimPtr(in.GPCBrickCode), level).
|
name, trimPtr(in.NameEN), parentID, path, trimPtr(in.GPCBrickCode), level, kind).
|
||||||
Scan(&c.ID, &c.NameZH, &c.NameEN, &c.Path, &c.Level, &c.ParentID, &c.GPCBrickCode, &c.ProductCount)
|
Scan(&c.ID, &c.NameZH, &c.NameEN, &c.Path, &c.Level, &c.ParentID, &c.GPCBrickCode, &c.ArchiveKind, &c.ProductCount)
|
||||||
if isUniqueViolation(err) {
|
if isUniqueViolation(err) {
|
||||||
return nil, ErrDuplicatePath
|
return nil, ErrDuplicatePath
|
||||||
}
|
}
|
||||||
@@ -273,10 +274,10 @@ func (s *Store) getCategory(ctx context.Context, id string) (*Category, error) {
|
|||||||
var c Category
|
var c Category
|
||||||
err := s.pool.QueryRow(ctx, `
|
err := s.pool.QueryRow(ctx, `
|
||||||
SELECT c.id, c.name_zh, c.name_en, c.path::text, c.level, c.parent_id::text,
|
SELECT c.id, c.name_zh, c.name_en, c.path::text, c.level, c.parent_id::text,
|
||||||
c.gpc_brick_code,
|
c.gpc_brick_code, c.archive_kind,
|
||||||
(SELECT count(*) FROM product p WHERE p.category_id = c.id)
|
(SELECT count(*) FROM product p WHERE p.category_id = c.id)
|
||||||
FROM category c WHERE c.id = $1`, id).
|
FROM category c WHERE c.id = $1`, id).
|
||||||
Scan(&c.ID, &c.NameZH, &c.NameEN, &c.Path, &c.Level, &c.ParentID, &c.GPCBrickCode, &c.ProductCount)
|
Scan(&c.ID, &c.NameZH, &c.NameEN, &c.Path, &c.Level, &c.ParentID, &c.GPCBrickCode, &c.ArchiveKind, &c.ProductCount)
|
||||||
if errors.Is(err, pgx.ErrNoRows) {
|
if errors.Is(err, pgx.ErrNoRows) {
|
||||||
return nil, ErrNotFound
|
return nil, ErrNotFound
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,101 @@
|
|||||||
|
package adminstore
|
||||||
|
|
||||||
|
import "context"
|
||||||
|
|
||||||
|
// DefaultKind is used for products whose category has no archive kind (or no
|
||||||
|
// category at all).
|
||||||
|
const DefaultKind = "generic"
|
||||||
|
|
||||||
|
// FoodKind keeps the mature, dedicated food_detail path; every other kind is
|
||||||
|
// driven generically by kind_field + product.attributes.
|
||||||
|
const FoodKind = "food"
|
||||||
|
|
||||||
|
// genericBaseFields are the core completeness fields for any non-food kind.
|
||||||
|
// Food keeps its own richer CompletenessFields list.
|
||||||
|
var genericBaseFields = []string{"name", "gtin", "brand", "category", "image"}
|
||||||
|
|
||||||
|
// KindField describes one editable spec field for an archive kind. It drives
|
||||||
|
// both the dynamic admin form and the kind-aware completeness computation.
|
||||||
|
type KindField struct {
|
||||||
|
Kind string `json:"kind"`
|
||||||
|
FieldKey string `json:"field_key"`
|
||||||
|
GroupLabel string `json:"group_label"`
|
||||||
|
LabelZH string `json:"label_zh"`
|
||||||
|
FieldType string `json:"field_type"`
|
||||||
|
Unit *string `json:"unit"`
|
||||||
|
Options []string `json:"options"`
|
||||||
|
Placeholder *string `json:"placeholder"`
|
||||||
|
SortOrder int `json:"sort_order"`
|
||||||
|
Qualified bool `json:"qualified"`
|
||||||
|
}
|
||||||
|
|
||||||
|
// ListKindFields returns the ordered field template for one archive kind.
|
||||||
|
func (s *Store) ListKindFields(ctx context.Context, kind string) ([]KindField, error) {
|
||||||
|
rows, err := s.pool.Query(ctx, `
|
||||||
|
SELECT kind, field_key, group_label, label_zh, field_type, unit, options,
|
||||||
|
placeholder, sort_order, qualified
|
||||||
|
FROM kind_field WHERE kind = $1 ORDER BY sort_order, field_key`, kind)
|
||||||
|
if err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
defer rows.Close()
|
||||||
|
out := []KindField{}
|
||||||
|
for rows.Next() {
|
||||||
|
var f KindField
|
||||||
|
if err := rows.Scan(&f.Kind, &f.FieldKey, &f.GroupLabel, &f.LabelZH,
|
||||||
|
&f.FieldType, &f.Unit, &f.Options, &f.Placeholder, &f.SortOrder,
|
||||||
|
&f.Qualified); err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
out = append(out, f)
|
||||||
|
}
|
||||||
|
return out, rows.Err()
|
||||||
|
}
|
||||||
|
|
||||||
|
// kindQualifiedKeys returns, per kind, the attribute keys that count toward the
|
||||||
|
// completeness/qualified score. Loaded in one query so list views stay cheap.
|
||||||
|
func (s *Store) kindQualifiedKeys(ctx context.Context, q queryer) (map[string][]string, error) {
|
||||||
|
rows, err := s.pool.Query(ctx,
|
||||||
|
"SELECT kind, field_key FROM kind_field WHERE qualified ORDER BY sort_order, field_key")
|
||||||
|
if err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
defer rows.Close()
|
||||||
|
m := map[string][]string{}
|
||||||
|
for rows.Next() {
|
||||||
|
var kind, key string
|
||||||
|
if err := rows.Scan(&kind, &key); err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
m[kind] = append(m[kind], key)
|
||||||
|
}
|
||||||
|
return m, rows.Err()
|
||||||
|
}
|
||||||
|
|
||||||
|
// completenessKeys returns the ordered list of field keys that define a full
|
||||||
|
// archive for the given kind.
|
||||||
|
func completenessKeys(kind string, qualifiedAttrKeys []string) []string {
|
||||||
|
if kind == FoodKind {
|
||||||
|
return CompletenessFields
|
||||||
|
}
|
||||||
|
keys := make([]string, 0, len(genericBaseFields)+len(qualifiedAttrKeys))
|
||||||
|
keys = append(keys, genericBaseFields...)
|
||||||
|
keys = append(keys, qualifiedAttrKeys...)
|
||||||
|
return keys
|
||||||
|
}
|
||||||
|
|
||||||
|
// attrPresent reports whether an attribute value is meaningfully filled in.
|
||||||
|
func attrPresent(attrs map[string]any, key string) bool {
|
||||||
|
v, ok := attrs[key]
|
||||||
|
if !ok || v == nil {
|
||||||
|
return false
|
||||||
|
}
|
||||||
|
switch t := v.(type) {
|
||||||
|
case string:
|
||||||
|
return t != ""
|
||||||
|
case []any:
|
||||||
|
return len(t) > 0
|
||||||
|
default:
|
||||||
|
return true
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,119 @@
|
|||||||
|
package adminstore
|
||||||
|
|
||||||
|
import (
|
||||||
|
"context"
|
||||||
|
"testing"
|
||||||
|
)
|
||||||
|
|
||||||
|
// contains reports whether s holds v.
|
||||||
|
func contains(s []string, v string) bool {
|
||||||
|
for _, x := range s {
|
||||||
|
if x == v {
|
||||||
|
return true
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return false
|
||||||
|
}
|
||||||
|
|
||||||
|
// electronicsCategoryID returns the seeded electronics.phone category id,
|
||||||
|
// skipping the test when the archive-kind migration is not applied.
|
||||||
|
func electronicsCategoryID(t *testing.T, s *Store) string {
|
||||||
|
t.Helper()
|
||||||
|
ctx := context.Background()
|
||||||
|
var hasTable bool
|
||||||
|
if err := s.pool.QueryRow(ctx, "SELECT to_regclass('public.kind_field') IS NOT NULL").Scan(&hasTable); err != nil || !hasTable {
|
||||||
|
t.Skip("archive-kind migration not applied (kind_field missing)")
|
||||||
|
}
|
||||||
|
var id string
|
||||||
|
err := s.pool.QueryRow(ctx, "SELECT id FROM category WHERE path = 'electronics.phone'::ltree").Scan(&id)
|
||||||
|
if err != nil {
|
||||||
|
t.Skipf("electronics.phone category not seeded: %v", err)
|
||||||
|
}
|
||||||
|
return id
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestListKindFieldsElectronics(t *testing.T) {
|
||||||
|
s := newTestStore(t)
|
||||||
|
electronicsCategoryID(t, s) // ensures migration applied
|
||||||
|
fields, err := s.ListKindFields(context.Background(), "electronics")
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("list kind fields: %v", err)
|
||||||
|
}
|
||||||
|
if len(fields) == 0 {
|
||||||
|
t.Fatal("expected seeded electronics fields, got none")
|
||||||
|
}
|
||||||
|
var sawQualified bool
|
||||||
|
for _, f := range fields {
|
||||||
|
if f.FieldKey == "model_number" && f.Qualified {
|
||||||
|
sawQualified = true
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if !sawQualified {
|
||||||
|
t.Fatal("expected model_number to be a qualified field")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// TestElectronicsArchiveKind verifies a non-food product uses the electronics
|
||||||
|
// completeness rules: food fields (nutriments/ingredients) are not required,
|
||||||
|
// and qualified spec fields drive both "missing" and the quality score.
|
||||||
|
func TestElectronicsArchiveKind(t *testing.T) {
|
||||||
|
s := newTestStore(t)
|
||||||
|
ctx := context.Background()
|
||||||
|
catID := electronicsCategoryID(t, s)
|
||||||
|
|
||||||
|
created, err := s.CreateProduct(ctx, "tester", ProductInput{
|
||||||
|
Name: "测试手机 " + randomHex(6),
|
||||||
|
CategoryID: &catID,
|
||||||
|
})
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("create product: %v", err)
|
||||||
|
}
|
||||||
|
t.Cleanup(func() { _, _ = s.pool.Exec(ctx, "DELETE FROM product WHERE id = $1", created.ID) })
|
||||||
|
|
||||||
|
if created.ArchiveKind != "electronics" {
|
||||||
|
t.Fatalf("archive_kind = %q, want electronics", created.ArchiveKind)
|
||||||
|
}
|
||||||
|
// Food-only completeness fields must not be required for electronics.
|
||||||
|
if contains(created.Missing, "nutriments") || contains(created.Missing, "ingredients") {
|
||||||
|
t.Fatalf("electronics product should not require food fields: missing=%v", created.Missing)
|
||||||
|
}
|
||||||
|
// Qualified spec fields should appear as missing while empty.
|
||||||
|
for _, k := range []string{"model_number", "ccc_cert", "screen_size"} {
|
||||||
|
if !contains(created.Missing, k) {
|
||||||
|
t.Fatalf("expected %q in missing, got %v", k, created.Missing)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
scoreBefore := created.QualityScore
|
||||||
|
|
||||||
|
gtin := "69" + randomHex(11)
|
||||||
|
brand := "TestPhoneCo"
|
||||||
|
updated, err := s.UpdateProduct(ctx, created.ID, "tester", ProductInput{
|
||||||
|
Name: created.Name,
|
||||||
|
GTIN: >in,
|
||||||
|
BrandName: &brand,
|
||||||
|
CategoryID: &catID,
|
||||||
|
Status: "active",
|
||||||
|
Attributes: map[string]any{
|
||||||
|
"model_number": "X-100",
|
||||||
|
"ccc_cert": "2024010101234567",
|
||||||
|
"screen_size": "6.1",
|
||||||
|
"color": "黑色",
|
||||||
|
},
|
||||||
|
})
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("update product: %v", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
if got := updated.Attributes["model_number"]; got != "X-100" {
|
||||||
|
t.Fatalf("attributes not persisted: %v", updated.Attributes)
|
||||||
|
}
|
||||||
|
for _, k := range []string{"model_number", "ccc_cert", "screen_size"} {
|
||||||
|
if contains(updated.Missing, k) {
|
||||||
|
t.Fatalf("%q should be filled, still missing: %v", k, updated.Missing)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if updated.QualityScore <= scoreBefore {
|
||||||
|
t.Fatalf("quality should rise after filling fields: before=%v after=%v", scoreBefore, updated.QualityScore)
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -2,6 +2,7 @@ package adminstore
|
|||||||
|
|
||||||
import (
|
import (
|
||||||
"context"
|
"context"
|
||||||
|
"encoding/json"
|
||||||
"math"
|
"math"
|
||||||
"time"
|
"time"
|
||||||
|
|
||||||
@@ -58,35 +59,56 @@ func (s *Store) computeQuality(ctx context.Context, q queryer, productID string)
|
|||||||
var netCanonical *float64
|
var netCanonical *float64
|
||||||
var ingredients *string
|
var ingredients *string
|
||||||
var hasNutri, hasImage bool
|
var hasNutri, hasImage bool
|
||||||
|
var kind string
|
||||||
|
var attributes []byte
|
||||||
err := q.QueryRow(ctx, `
|
err := q.QueryRow(ctx, `
|
||||||
SELECT p.name, p.gtin, p.brand_id, p.category_id, p.net_content_canonical,
|
SELECT p.name, p.gtin, p.brand_id, p.category_id, p.net_content_canonical,
|
||||||
p.country_of_origin, f.ingredients_text,
|
p.country_of_origin, COALESCE(c.archive_kind, 'generic'), p.attributes,
|
||||||
|
f.ingredients_text,
|
||||||
(f.nutriments IS NOT NULL AND f.nutriments::text <> '{}'),
|
(f.nutriments IS NOT NULL AND f.nutriments::text <> '{}'),
|
||||||
EXISTS (SELECT 1 FROM product_image pi WHERE pi.product_id = p.id)
|
EXISTS (SELECT 1 FROM product_image pi WHERE pi.product_id = p.id)
|
||||||
FROM product p LEFT JOIN food_detail f ON f.product_id = p.id
|
FROM product p
|
||||||
|
LEFT JOIN category c ON c.id = p.category_id
|
||||||
|
LEFT JOIN food_detail f ON f.product_id = p.id
|
||||||
WHERE p.id = $1`, productID).Scan(
|
WHERE p.id = $1`, productID).Scan(
|
||||||
&name, >in, &brandID, &categoryID, &netCanonical, &country,
|
&name, >in, &brandID, &categoryID, &netCanonical, &country,
|
||||||
&ingredients, &hasNutri, &hasImage)
|
&kind, &attributes, &ingredients, &hasNutri, &hasImage)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return 0, err
|
return 0, err
|
||||||
}
|
}
|
||||||
|
|
||||||
|
attrs := map[string]any{}
|
||||||
|
if len(attributes) > 0 {
|
||||||
|
_ = json.Unmarshal(attributes, &attrs)
|
||||||
|
}
|
||||||
|
qualified, err := s.kindQualifiedKeys(ctx, s.pool)
|
||||||
|
if err != nil {
|
||||||
|
return 0, err
|
||||||
|
}
|
||||||
|
qkeys := qualified[kind]
|
||||||
|
|
||||||
|
known := map[string]bool{
|
||||||
|
"name": name != nil && *name != "",
|
||||||
|
"gtin": gtin != nil && *gtin != "",
|
||||||
|
"brand": brandID != nil,
|
||||||
|
"category": categoryID != nil,
|
||||||
|
"net_content": netCanonical != nil,
|
||||||
|
"country_of_origin": country != nil && *country != "",
|
||||||
|
"nutriments": hasNutri,
|
||||||
|
"ingredients": ingredients != nil && *ingredients != "",
|
||||||
|
"image": hasImage,
|
||||||
|
}
|
||||||
|
for _, k := range qkeys {
|
||||||
|
known[k] = attrPresent(attrs, k)
|
||||||
|
}
|
||||||
|
keys := completenessKeys(kind, qkeys)
|
||||||
present := 0
|
present := 0
|
||||||
bump := func(ok bool) {
|
for _, k := range keys {
|
||||||
if ok {
|
if known[k] {
|
||||||
present++
|
present++
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
bump(name != nil && *name != "")
|
completeness := float64(present) / float64(len(keys))
|
||||||
bump(gtin != nil && *gtin != "")
|
|
||||||
bump(brandID != nil)
|
|
||||||
bump(categoryID != nil)
|
|
||||||
bump(netCanonical != nil)
|
|
||||||
bump(country != nil && *country != "")
|
|
||||||
bump(hasNutri)
|
|
||||||
bump(ingredients != nil && *ingredients != "")
|
|
||||||
bump(hasImage)
|
|
||||||
completeness := float64(present) / float64(len(CompletenessFields))
|
|
||||||
|
|
||||||
var sourceCount int
|
var sourceCount int
|
||||||
var sourceTrust *float64
|
var sourceTrust *float64
|
||||||
|
|||||||
@@ -27,6 +27,9 @@ type ProductInput struct {
|
|||||||
NutritionBasis *string `json:"nutrition_basis"`
|
NutritionBasis *string `json:"nutrition_basis"`
|
||||||
ServingSize *string `json:"serving_size"`
|
ServingSize *string `json:"serving_size"`
|
||||||
NutriScore *string `json:"nutri_score"`
|
NutriScore *string `json:"nutri_score"`
|
||||||
|
// Attributes carries non-food spec values (driven by kind_field) for the
|
||||||
|
// generic archive kinds. Nil means "leave unchanged".
|
||||||
|
Attributes map[string]any `json:"attributes"`
|
||||||
}
|
}
|
||||||
|
|
||||||
func normBrand(name string) string { return strings.Join(strings.Fields(strings.ToLower(name)), " ") }
|
func normBrand(name string) string { return strings.Join(strings.Fields(strings.ToLower(name)), " ") }
|
||||||
@@ -86,10 +89,11 @@ func (s *Store) UpdateProduct(ctx context.Context, id, actor string, in ProductI
|
|||||||
brandID = &bid
|
brandID = &bid
|
||||||
}
|
}
|
||||||
|
|
||||||
// Resolve category gpc brick code.
|
// Resolve category gpc brick code + archive kind.
|
||||||
var gpc *string
|
var gpc *string
|
||||||
|
kind := DefaultKind
|
||||||
if in.CategoryID != nil && *in.CategoryID != "" {
|
if in.CategoryID != nil && *in.CategoryID != "" {
|
||||||
if err := tx.QueryRow(ctx, "SELECT gpc_brick_code FROM category WHERE id = $1", *in.CategoryID).Scan(&gpc); err != nil && !errors.Is(err, pgx.ErrNoRows) {
|
if err := tx.QueryRow(ctx, "SELECT gpc_brick_code, archive_kind FROM category WHERE id = $1", *in.CategoryID).Scan(&gpc, &kind); err != nil && !errors.Is(err, pgx.ErrNoRows) {
|
||||||
return nil, err
|
return nil, err
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -116,19 +120,28 @@ WHERE id=$11`,
|
|||||||
return nil, err
|
return nil, err
|
||||||
}
|
}
|
||||||
|
|
||||||
var nutriJSON []byte
|
// Non-food spec values live in product.attributes (nil means unchanged).
|
||||||
if in.Nutriments != nil {
|
if in.Attributes != nil {
|
||||||
nutriJSON, _ = json.Marshal(in.Nutriments)
|
attrJSON, _ := json.Marshal(in.Attributes)
|
||||||
|
if _, err = tx.Exec(ctx, "UPDATE product SET attributes=$1 WHERE id=$2", attrJSON, id); err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
}
|
}
|
||||||
allergens := in.Allergens
|
|
||||||
if allergens == nil {
|
if kind == FoodKind {
|
||||||
allergens = []string{}
|
var nutriJSON []byte
|
||||||
}
|
if in.Nutriments != nil {
|
||||||
additives := in.Additives
|
nutriJSON, _ = json.Marshal(in.Nutriments)
|
||||||
if additives == nil {
|
}
|
||||||
additives = []string{}
|
allergens := in.Allergens
|
||||||
}
|
if allergens == nil {
|
||||||
_, err = tx.Exec(ctx, `
|
allergens = []string{}
|
||||||
|
}
|
||||||
|
additives := in.Additives
|
||||||
|
if additives == nil {
|
||||||
|
additives = []string{}
|
||||||
|
}
|
||||||
|
_, err = tx.Exec(ctx, `
|
||||||
INSERT INTO food_detail (product_id, ingredients_text, allergens, additives,
|
INSERT INTO food_detail (product_id, ingredients_text, allergens, additives,
|
||||||
nutriments, nutrition_basis, serving_size, nutri_score)
|
nutriments, nutrition_basis, serving_size, nutri_score)
|
||||||
VALUES ($1,$2,$3,$4,$5,$6,$7,$8)
|
VALUES ($1,$2,$3,$4,$5,$6,$7,$8)
|
||||||
@@ -140,10 +153,11 @@ ON CONFLICT (product_id) DO UPDATE SET
|
|||||||
nutrition_basis=EXCLUDED.nutrition_basis,
|
nutrition_basis=EXCLUDED.nutrition_basis,
|
||||||
serving_size=EXCLUDED.serving_size,
|
serving_size=EXCLUDED.serving_size,
|
||||||
nutri_score=EXCLUDED.nutri_score`,
|
nutri_score=EXCLUDED.nutri_score`,
|
||||||
id, in.IngredientsText, allergens, additives,
|
id, in.IngredientsText, allergens, additives,
|
||||||
nutriJSON, in.NutritionBasis, in.ServingSize, in.NutriScore)
|
nutriJSON, in.NutritionBasis, in.ServingSize, in.NutriScore)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return nil, err
|
return nil, err
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
if _, err := s.recomputeQualityTx(ctx, tx, id); err != nil {
|
if _, err := s.recomputeQualityTx(ctx, tx, id); err != nil {
|
||||||
@@ -284,6 +298,9 @@ func diffFields(a, b *ProductDetail) []string {
|
|||||||
add("nutrition_basis", strEq(a.NutritionBasis, b.NutritionBasis))
|
add("nutrition_basis", strEq(a.NutritionBasis, b.NutritionBasis))
|
||||||
add("serving_size", strEq(a.ServingSize, b.ServingSize))
|
add("serving_size", strEq(a.ServingSize, b.ServingSize))
|
||||||
add("nutri_score", strEq(a.NutriScore, b.NutriScore))
|
add("nutri_score", strEq(a.NutriScore, b.NutriScore))
|
||||||
|
aa, _ := json.Marshal(a.Attributes)
|
||||||
|
ab, _ := json.Marshal(b.Attributes)
|
||||||
|
add("attributes", string(aa) == string(ab))
|
||||||
return changed
|
return changed
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -442,6 +459,7 @@ type Category struct {
|
|||||||
Level int `json:"level"`
|
Level int `json:"level"`
|
||||||
ParentID *string `json:"parent_id"`
|
ParentID *string `json:"parent_id"`
|
||||||
GPCBrickCode *string `json:"gpc_brick_code"`
|
GPCBrickCode *string `json:"gpc_brick_code"`
|
||||||
|
ArchiveKind string `json:"archive_kind"`
|
||||||
ProductCount int `json:"product_count"`
|
ProductCount int `json:"product_count"`
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -450,7 +468,7 @@ type Category struct {
|
|||||||
func (s *Store) ListCategories(ctx context.Context) ([]Category, error) {
|
func (s *Store) ListCategories(ctx context.Context) ([]Category, error) {
|
||||||
rows, err := s.pool.Query(ctx, `
|
rows, err := s.pool.Query(ctx, `
|
||||||
SELECT c.id, c.name_zh, c.name_en, c.path::text, c.level, c.parent_id::text,
|
SELECT c.id, c.name_zh, c.name_en, c.path::text, c.level, c.parent_id::text,
|
||||||
c.gpc_brick_code,
|
c.gpc_brick_code, c.archive_kind,
|
||||||
(SELECT count(*) FROM product p WHERE p.category_id = c.id) AS product_count
|
(SELECT count(*) FROM product p WHERE p.category_id = c.id) AS product_count
|
||||||
FROM category c
|
FROM category c
|
||||||
ORDER BY c.path`)
|
ORDER BY c.path`)
|
||||||
@@ -462,7 +480,7 @@ ORDER BY c.path`)
|
|||||||
for rows.Next() {
|
for rows.Next() {
|
||||||
var c Category
|
var c Category
|
||||||
if err := rows.Scan(&c.ID, &c.NameZH, &c.NameEN, &c.Path, &c.Level,
|
if err := rows.Scan(&c.ID, &c.NameZH, &c.NameEN, &c.Path, &c.Level,
|
||||||
&c.ParentID, &c.GPCBrickCode, &c.ProductCount); err != nil {
|
&c.ParentID, &c.GPCBrickCode, &c.ArchiveKind, &c.ProductCount); err != nil {
|
||||||
return nil, err
|
return nil, err
|
||||||
}
|
}
|
||||||
out = append(out, c)
|
out = append(out, c)
|
||||||
|
|||||||
@@ -9,19 +9,25 @@ import (
|
|||||||
// Values are read from environment variables with sensible defaults so the
|
// Values are read from environment variables with sensible defaults so the
|
||||||
// server can boot in a local Docker Compose setup without extra configuration.
|
// server can boot in a local Docker Compose setup without extra configuration.
|
||||||
type Config struct {
|
type Config struct {
|
||||||
Addr string
|
Addr string
|
||||||
DatabaseURL string
|
DatabaseURL string
|
||||||
RedisURL string
|
RedisURL string
|
||||||
AnonRateLimitPerMin int
|
AnonRateLimitPerMin int
|
||||||
|
AnonTotalQuota int
|
||||||
|
RegisteredRateLimitPerMin int
|
||||||
|
RegisteredQuotaTotal int
|
||||||
}
|
}
|
||||||
|
|
||||||
// Load reads configuration from the environment.
|
// Load reads configuration from the environment.
|
||||||
func Load() Config {
|
func Load() Config {
|
||||||
return Config{
|
return Config{
|
||||||
Addr: getenv("OPENGOODS_ADDR", ":8080"),
|
Addr: getenv("OPENGOODS_ADDR", ":8080"),
|
||||||
DatabaseURL: getenv("OPENGOODS_DATABASE_URL", "postgres://opengoods:opengoods@localhost:5432/opengoods?sslmode=disable"),
|
DatabaseURL: getenv("OPENGOODS_DATABASE_URL", "postgres://opengoods:opengoods@localhost:5432/opengoods?sslmode=disable"),
|
||||||
RedisURL: getenv("OPENGOODS_REDIS_URL", "redis://localhost:6379/0"),
|
RedisURL: getenv("OPENGOODS_REDIS_URL", "redis://localhost:6379/0"),
|
||||||
AnonRateLimitPerMin: getenvInt("OPENGOODS_ANON_RATE_LIMIT_PER_MIN", 60),
|
AnonRateLimitPerMin: getenvInt("OPENGOODS_ANON_RATE_LIMIT_PER_MIN", 60),
|
||||||
|
AnonTotalQuota: getenvInt("OPENGOODS_ANON_TOTAL_QUOTA", 1000),
|
||||||
|
RegisteredRateLimitPerMin: getenvInt("OPENGOODS_REGISTERED_RATE_LIMIT_PER_MIN", 300),
|
||||||
|
RegisteredQuotaTotal: getenvInt("OPENGOODS_REGISTERED_QUOTA_TOTAL", 100000),
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -0,0 +1,128 @@
|
|||||||
|
package handler
|
||||||
|
|
||||||
|
import (
|
||||||
|
"encoding/json"
|
||||||
|
"errors"
|
||||||
|
"net/http"
|
||||||
|
"regexp"
|
||||||
|
"strings"
|
||||||
|
|
||||||
|
"github.com/baicai2026-baicai/goods/api/internal/store"
|
||||||
|
)
|
||||||
|
|
||||||
|
// emailRe is a deliberately permissive sanity check; real validation is the
|
||||||
|
// unique constraint plus the user being able to receive their own key.
|
||||||
|
var emailRe = regexp.MustCompile(`^[^@\s]+@[^@\s]+\.[^@\s]+$`)
|
||||||
|
|
||||||
|
const minPasswordLen = 8
|
||||||
|
|
||||||
|
type credentials struct {
|
||||||
|
Email string `json:"email"`
|
||||||
|
Password string `json:"password"`
|
||||||
|
}
|
||||||
|
|
||||||
|
func decodeCredentials(w http.ResponseWriter, r *http.Request) (credentials, bool) {
|
||||||
|
var c credentials
|
||||||
|
if err := json.NewDecoder(http.MaxBytesReader(w, r.Body, 4096)).Decode(&c); err != nil {
|
||||||
|
writeError(w, r, http.StatusBadRequest, "invalid_body", "请求格式无效")
|
||||||
|
return credentials{}, false
|
||||||
|
}
|
||||||
|
c.Email = strings.TrimSpace(c.Email)
|
||||||
|
if !emailRe.MatchString(c.Email) {
|
||||||
|
writeError(w, r, http.StatusBadRequest, "invalid_email", "邮箱格式无效")
|
||||||
|
return credentials{}, false
|
||||||
|
}
|
||||||
|
if len(c.Password) < minPasswordLen {
|
||||||
|
writeError(w, r, http.StatusBadRequest, "weak_password", "密码至少需要 8 位")
|
||||||
|
return credentials{}, false
|
||||||
|
}
|
||||||
|
return c, true
|
||||||
|
}
|
||||||
|
|
||||||
|
// keyResponse is returned whenever a fresh plaintext key is issued; the key is
|
||||||
|
// shown exactly once and cannot be recovered afterwards.
|
||||||
|
type keyResponse struct {
|
||||||
|
Email string `json:"email"`
|
||||||
|
APIKey string `json:"api_key"`
|
||||||
|
KeyPrefix string `json:"key_prefix"`
|
||||||
|
RateLimitPerMin int `json:"rate_limit_per_min"`
|
||||||
|
QuotaTotal int64 `json:"quota_total"`
|
||||||
|
}
|
||||||
|
|
||||||
|
// Register creates an account and issues its first API key. POST {email, password}.
|
||||||
|
func (h *Handler) Register(w http.ResponseWriter, r *http.Request) {
|
||||||
|
c, ok := decodeCredentials(w, r)
|
||||||
|
if !ok {
|
||||||
|
return
|
||||||
|
}
|
||||||
|
key, acct, err := h.store.RegisterUser(r.Context(), c.Email, c.Password, h.regRatePerMin, h.regQuotaTotal)
|
||||||
|
if errors.Is(err, store.ErrEmailTaken) {
|
||||||
|
writeError(w, r, http.StatusConflict, "email_taken", "该邮箱已注册,请直接登录查看或重置密钥")
|
||||||
|
return
|
||||||
|
}
|
||||||
|
if h.handleErr(w, r, err) {
|
||||||
|
return
|
||||||
|
}
|
||||||
|
writeJSON(w, http.StatusCreated, keyResponse{
|
||||||
|
Email: acct.Email,
|
||||||
|
APIKey: key,
|
||||||
|
KeyPrefix: acct.KeyPrefix,
|
||||||
|
RateLimitPerMin: acct.RateLimitPerMin,
|
||||||
|
QuotaTotal: acct.QuotaTotal,
|
||||||
|
})
|
||||||
|
}
|
||||||
|
|
||||||
|
// AccountInfo verifies credentials and returns the account's key metadata plus
|
||||||
|
// cumulative usage. POST {email, password}. The plaintext key is not returned.
|
||||||
|
func (h *Handler) AccountInfo(w http.ResponseWriter, r *http.Request) {
|
||||||
|
c, ok := decodeCredentials(w, r)
|
||||||
|
if !ok {
|
||||||
|
return
|
||||||
|
}
|
||||||
|
acct, err := h.store.Authenticate(r.Context(), c.Email, c.Password)
|
||||||
|
if errors.Is(err, store.ErrNotFound) {
|
||||||
|
writeError(w, r, http.StatusUnauthorized, "invalid_credentials", "邮箱或密码错误")
|
||||||
|
return
|
||||||
|
}
|
||||||
|
if h.handleErr(w, r, err) {
|
||||||
|
return
|
||||||
|
}
|
||||||
|
used := h.limiter.TotalUsed(r.Context(), acct.KeyID)
|
||||||
|
remaining := acct.QuotaTotal - used
|
||||||
|
if remaining < 0 {
|
||||||
|
remaining = 0
|
||||||
|
}
|
||||||
|
writeJSON(w, http.StatusOK, map[string]any{
|
||||||
|
"email": acct.Email,
|
||||||
|
"key_prefix": acct.KeyPrefix,
|
||||||
|
"rate_limit_per_min": acct.RateLimitPerMin,
|
||||||
|
"quota_total": acct.QuotaTotal,
|
||||||
|
"quota_used": used,
|
||||||
|
"quota_remaining": remaining,
|
||||||
|
})
|
||||||
|
}
|
||||||
|
|
||||||
|
// RegenerateKey revokes the account's current key and issues a new one, carrying
|
||||||
|
// over cumulative usage so the quota cannot be reset. POST {email, password}.
|
||||||
|
func (h *Handler) RegenerateKey(w http.ResponseWriter, r *http.Request) {
|
||||||
|
c, ok := decodeCredentials(w, r)
|
||||||
|
if !ok {
|
||||||
|
return
|
||||||
|
}
|
||||||
|
key, acct, oldKeyID, err := h.store.RegenerateKey(r.Context(), c.Email, c.Password, h.regRatePerMin, h.regQuotaTotal)
|
||||||
|
if errors.Is(err, store.ErrNotFound) {
|
||||||
|
writeError(w, r, http.StatusUnauthorized, "invalid_credentials", "邮箱或密码错误")
|
||||||
|
return
|
||||||
|
}
|
||||||
|
if h.handleErr(w, r, err) {
|
||||||
|
return
|
||||||
|
}
|
||||||
|
h.limiter.CopyTotal(r.Context(), oldKeyID, acct.KeyID)
|
||||||
|
writeJSON(w, http.StatusOK, keyResponse{
|
||||||
|
Email: acct.Email,
|
||||||
|
APIKey: key,
|
||||||
|
KeyPrefix: acct.KeyPrefix,
|
||||||
|
RateLimitPerMin: acct.RateLimitPerMin,
|
||||||
|
QuotaTotal: acct.QuotaTotal,
|
||||||
|
})
|
||||||
|
}
|
||||||
@@ -0,0 +1,149 @@
|
|||||||
|
package handler
|
||||||
|
|
||||||
|
import (
|
||||||
|
"context"
|
||||||
|
"encoding/json"
|
||||||
|
"fmt"
|
||||||
|
"net/http"
|
||||||
|
"net/http/httptest"
|
||||||
|
"os"
|
||||||
|
"strings"
|
||||||
|
"testing"
|
||||||
|
"time"
|
||||||
|
|
||||||
|
"github.com/jackc/pgx/v5/pgxpool"
|
||||||
|
"github.com/redis/go-redis/v9"
|
||||||
|
|
||||||
|
"github.com/baicai2026-baicai/goods/api/internal/ratelimit"
|
||||||
|
"github.com/baicai2026-baicai/goods/api/internal/store"
|
||||||
|
)
|
||||||
|
|
||||||
|
func cleanupCounter(t *testing.T, subject string) {
|
||||||
|
t.Helper()
|
||||||
|
redisURL := os.Getenv("OPENGOODS_REDIS_URL")
|
||||||
|
if redisURL == "" {
|
||||||
|
redisURL = "redis://localhost:6379/0"
|
||||||
|
}
|
||||||
|
opt, err := redis.ParseURL(redisURL)
|
||||||
|
if err != nil {
|
||||||
|
return
|
||||||
|
}
|
||||||
|
rdb := redis.NewClient(opt)
|
||||||
|
defer rdb.Close()
|
||||||
|
rdb.Del(context.Background(), "usage:total:"+subject)
|
||||||
|
}
|
||||||
|
|
||||||
|
// newQuotaHandler builds a handler backed by the test DB and a live Redis
|
||||||
|
// limiter, with a small anonymous quota so exhaustion is cheap to exercise.
|
||||||
|
func newQuotaHandler(t *testing.T, anonQuota int) *Handler {
|
||||||
|
t.Helper()
|
||||||
|
dsn := os.Getenv("OPENGOODS_DATABASE_URL")
|
||||||
|
if dsn == "" {
|
||||||
|
dsn = "postgres://opengoods:opengoods@localhost:5432/opengoods?sslmode=disable"
|
||||||
|
}
|
||||||
|
ctx, cancel := context.WithTimeout(context.Background(), 3*time.Second)
|
||||||
|
defer cancel()
|
||||||
|
pool, err := pgxpool.New(ctx, dsn)
|
||||||
|
if err != nil {
|
||||||
|
t.Skipf("no database: %v", err)
|
||||||
|
}
|
||||||
|
if err := pool.Ping(ctx); err != nil {
|
||||||
|
pool.Close()
|
||||||
|
t.Skipf("database not reachable: %v", err)
|
||||||
|
}
|
||||||
|
var hasUser bool
|
||||||
|
if err := pool.QueryRow(ctx, "SELECT to_regclass('public.app_user') IS NOT NULL").Scan(&hasUser); err != nil || !hasUser {
|
||||||
|
pool.Close()
|
||||||
|
t.Skip("migrations not applied")
|
||||||
|
}
|
||||||
|
redisURL := os.Getenv("OPENGOODS_REDIS_URL")
|
||||||
|
if redisURL == "" {
|
||||||
|
redisURL = "redis://localhost:6379/0"
|
||||||
|
}
|
||||||
|
limiter := ratelimit.New(redisURL)
|
||||||
|
pingCtx, pingCancel := context.WithTimeout(context.Background(), time.Second)
|
||||||
|
defer pingCancel()
|
||||||
|
if err := limiter.Ping(pingCtx); err != nil {
|
||||||
|
pool.Close()
|
||||||
|
t.Skipf("redis not reachable: %v", err)
|
||||||
|
}
|
||||||
|
t.Cleanup(pool.Close)
|
||||||
|
return New(store.New(pool), nil).
|
||||||
|
WithRateLimit(limiter, 1000).
|
||||||
|
WithQuotas(anonQuota, 300, 100000)
|
||||||
|
}
|
||||||
|
|
||||||
|
func cleanupAccount(t *testing.T, email string) {
|
||||||
|
t.Helper()
|
||||||
|
dsn := os.Getenv("OPENGOODS_DATABASE_URL")
|
||||||
|
if dsn == "" {
|
||||||
|
dsn = "postgres://opengoods:opengoods@localhost:5432/opengoods?sslmode=disable"
|
||||||
|
}
|
||||||
|
ctx := context.Background()
|
||||||
|
pool, err := pgxpool.New(ctx, dsn)
|
||||||
|
if err != nil {
|
||||||
|
return
|
||||||
|
}
|
||||||
|
defer pool.Close()
|
||||||
|
_, _ = pool.Exec(ctx, "DELETE FROM app_user WHERE lower(email)=lower($1)", email)
|
||||||
|
_, _ = pool.Exec(ctx, "DELETE FROM api_key WHERE owner_email=$1", email)
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestAnonTotalQuotaExhausts(t *testing.T) {
|
||||||
|
h := newQuotaHandler(t, 3)
|
||||||
|
// Unique client IP so the lifetime counter starts fresh for this test; the
|
||||||
|
// counter never expires, so drop it afterwards to keep runs independent.
|
||||||
|
n := time.Now().UnixNano()
|
||||||
|
ip := fmt.Sprintf("203.%d.%d.%d", n/65536%256, n/256%256, n%256)
|
||||||
|
t.Cleanup(func() { cleanupCounter(t, "ip:"+ip) })
|
||||||
|
call := func() *httptest.ResponseRecorder {
|
||||||
|
req := httptest.NewRequest(http.MethodGet, "/api/"+APIVersion+"/stats", nil)
|
||||||
|
req.RemoteAddr = ip + ":12345"
|
||||||
|
rec := httptest.NewRecorder()
|
||||||
|
h.Router().ServeHTTP(rec, req)
|
||||||
|
return rec
|
||||||
|
}
|
||||||
|
for i := 1; i <= 3; i++ {
|
||||||
|
if rec := call(); rec.Code != http.StatusOK {
|
||||||
|
t.Fatalf("call %d should be allowed, got %d (%s)", i, rec.Code, rec.Body.String())
|
||||||
|
}
|
||||||
|
}
|
||||||
|
rec := call()
|
||||||
|
if rec.Code != http.StatusForbidden {
|
||||||
|
t.Fatalf("4th call should be 403 quota_exhausted, got %d (%s)", rec.Code, rec.Body.String())
|
||||||
|
}
|
||||||
|
if !strings.Contains(rec.Body.String(), "quota_exhausted") {
|
||||||
|
t.Fatalf("expected quota_exhausted error, got %s", rec.Body.String())
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestRegisterIssuesHigherQuotaKey(t *testing.T) {
|
||||||
|
h := newQuotaHandler(t, 1000)
|
||||||
|
email := fmt.Sprintf("h-user-%d@example.com", time.Now().UnixNano())
|
||||||
|
t.Cleanup(func() { cleanupAccount(t, email) })
|
||||||
|
|
||||||
|
body := fmt.Sprintf(`{"email":%q,"password":"supersecret"}`, email)
|
||||||
|
req := httptest.NewRequest(http.MethodPost, "/api/"+APIVersion+"/register", strings.NewReader(body))
|
||||||
|
req.RemoteAddr = "198.51.100.7:9999"
|
||||||
|
rec := httptest.NewRecorder()
|
||||||
|
h.Router().ServeHTTP(rec, req)
|
||||||
|
if rec.Code != http.StatusCreated {
|
||||||
|
t.Fatalf("register status = %d (%s)", rec.Code, rec.Body.String())
|
||||||
|
}
|
||||||
|
var resp keyResponse
|
||||||
|
if err := json.NewDecoder(rec.Body).Decode(&resp); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
if resp.APIKey == "" || resp.QuotaTotal != 100000 || resp.RateLimitPerMin != 300 {
|
||||||
|
t.Fatalf("unexpected register response: %+v", resp)
|
||||||
|
}
|
||||||
|
|
||||||
|
// A second registration with the same email conflicts.
|
||||||
|
req2 := httptest.NewRequest(http.MethodPost, "/api/"+APIVersion+"/register", strings.NewReader(body))
|
||||||
|
req2.RemoteAddr = "198.51.100.7:9999"
|
||||||
|
rec2 := httptest.NewRecorder()
|
||||||
|
h.Router().ServeHTTP(rec2, req2)
|
||||||
|
if rec2.Code != http.StatusConflict {
|
||||||
|
t.Fatalf("duplicate register status = %d (%s)", rec2.Code, rec2.Body.String())
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -37,20 +37,43 @@ const (
|
|||||||
// defaultAnonLimit is the per-minute request budget for unauthenticated
|
// defaultAnonLimit is the per-minute request budget for unauthenticated
|
||||||
// callers (identified by client IP) when none is configured.
|
// callers (identified by client IP) when none is configured.
|
||||||
defaultAnonLimit = 60
|
defaultAnonLimit = 60
|
||||||
|
|
||||||
|
// defaultAnonTotalQuota is the lifetime number of calls an anonymous caller
|
||||||
|
// (by IP) may make before being asked to register for a higher quota.
|
||||||
|
defaultAnonTotalQuota = 1000
|
||||||
|
|
||||||
|
// defaultRegRatePerMin / defaultRegQuotaTotal are the per-minute budget and
|
||||||
|
// cumulative quota granted to a self-registered API key.
|
||||||
|
defaultRegRatePerMin = 300
|
||||||
|
defaultRegQuotaTotal = 100000
|
||||||
|
|
||||||
|
// registerRatePerMin caps account registration/login attempts per IP to
|
||||||
|
// curb abuse; these endpoints sit outside the metered quota group.
|
||||||
|
registerRatePerMin = 10
|
||||||
)
|
)
|
||||||
|
|
||||||
// Handler holds dependencies shared by the HTTP routes.
|
// Handler holds dependencies shared by the HTTP routes.
|
||||||
type Handler struct {
|
type Handler struct {
|
||||||
store *store.Store
|
store *store.Store
|
||||||
spa fs.FS
|
spa fs.FS
|
||||||
limiter *ratelimit.Limiter
|
limiter *ratelimit.Limiter
|
||||||
anonLimit int
|
anonLimit int
|
||||||
|
anonTotalQuota int64
|
||||||
|
regRatePerMin int
|
||||||
|
regQuotaTotal int64
|
||||||
}
|
}
|
||||||
|
|
||||||
// New constructs a Handler backed by the given store. spa may be nil (JSON-only).
|
// New constructs a Handler backed by the given store. spa may be nil (JSON-only).
|
||||||
// Rate limiting is disabled until WithRateLimit is called.
|
// Rate limiting is disabled until WithRateLimit is called.
|
||||||
func New(s *store.Store, spa fs.FS) *Handler {
|
func New(s *store.Store, spa fs.FS) *Handler {
|
||||||
return &Handler{store: s, spa: spa, anonLimit: defaultAnonLimit}
|
return &Handler{
|
||||||
|
store: s,
|
||||||
|
spa: spa,
|
||||||
|
anonLimit: defaultAnonLimit,
|
||||||
|
anonTotalQuota: defaultAnonTotalQuota,
|
||||||
|
regRatePerMin: defaultRegRatePerMin,
|
||||||
|
regQuotaTotal: defaultRegQuotaTotal,
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// WithRateLimit attaches a Redis-backed limiter and the anonymous per-minute
|
// WithRateLimit attaches a Redis-backed limiter and the anonymous per-minute
|
||||||
@@ -64,6 +87,22 @@ func (h *Handler) WithRateLimit(l *ratelimit.Limiter, anonPerMin int) *Handler {
|
|||||||
return h
|
return h
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// WithQuotas configures the cumulative free quota for anonymous callers and the
|
||||||
|
// per-minute rate + cumulative quota self-registered keys receive. Non-positive
|
||||||
|
// values keep the defaults.
|
||||||
|
func (h *Handler) WithQuotas(anonTotal, regPerMin, regTotal int) *Handler {
|
||||||
|
if anonTotal > 0 {
|
||||||
|
h.anonTotalQuota = int64(anonTotal)
|
||||||
|
}
|
||||||
|
if regPerMin > 0 {
|
||||||
|
h.regRatePerMin = regPerMin
|
||||||
|
}
|
||||||
|
if regTotal > 0 {
|
||||||
|
h.regQuotaTotal = int64(regTotal)
|
||||||
|
}
|
||||||
|
return h
|
||||||
|
}
|
||||||
|
|
||||||
// Router builds the top-level HTTP handler with middleware and routes mounted.
|
// Router builds the top-level HTTP handler with middleware and routes mounted.
|
||||||
func (h *Handler) Router() http.Handler {
|
func (h *Handler) Router() http.Handler {
|
||||||
r := chi.NewRouter()
|
r := chi.NewRouter()
|
||||||
@@ -91,6 +130,16 @@ func (h *Handler) Router() http.Handler {
|
|||||||
r.Get("/sources/{id}", h.SourceByID)
|
r.Get("/sources/{id}", h.SourceByID)
|
||||||
r.Get("/stats", h.Stats)
|
r.Get("/stats", h.Stats)
|
||||||
})
|
})
|
||||||
|
|
||||||
|
// Self-service account routes. Lightly IP-throttled to curb abuse but
|
||||||
|
// outside the metered quota group so a user can always register or
|
||||||
|
// check their key even after exhausting the free anonymous quota.
|
||||||
|
r.Group(func(r chi.Router) {
|
||||||
|
r.Use(h.registerLimit)
|
||||||
|
r.Post("/register", h.Register)
|
||||||
|
r.Post("/account", h.AccountInfo)
|
||||||
|
r.Post("/account/regenerate", h.RegenerateKey)
|
||||||
|
})
|
||||||
})
|
})
|
||||||
|
|
||||||
// Public SPA (homepage + search + contribute). API routes above take
|
// Public SPA (homepage + search + contribute). API routes above take
|
||||||
|
|||||||
@@ -24,8 +24,11 @@ const apiKeyIDKey ctxKey = 0
|
|||||||
// are set on every response; over-budget callers get 429 + Retry-After.
|
// are set on every response; over-budget callers get 429 + Retry-After.
|
||||||
func (h *Handler) rateLimit(next http.Handler) http.Handler {
|
func (h *Handler) rateLimit(next http.Handler) http.Handler {
|
||||||
return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
||||||
id := "ip:" + clientIP(r)
|
ip := clientIP(r)
|
||||||
|
id := "ip:" + ip
|
||||||
|
subject := "ip:" + ip // cumulative-quota counter subject
|
||||||
limit := h.anonLimit
|
limit := h.anonLimit
|
||||||
|
quota := h.anonTotalQuota
|
||||||
keyID := ""
|
keyID := ""
|
||||||
|
|
||||||
if raw := presentedKey(r); raw != "" {
|
if raw := presentedKey(r); raw != "" {
|
||||||
@@ -45,6 +48,8 @@ func (h *Handler) rateLimit(next http.Handler) http.Handler {
|
|||||||
keyID = k.ID
|
keyID = k.ID
|
||||||
limit = k.RateLimitPerMin
|
limit = k.RateLimitPerMin
|
||||||
id = "key:" + k.ID
|
id = "key:" + k.ID
|
||||||
|
subject = k.ID
|
||||||
|
quota = k.QuotaTotal
|
||||||
}
|
}
|
||||||
|
|
||||||
res := h.limiter.Allow(r.Context(), id, limit, time.Minute)
|
res := h.limiter.Allow(r.Context(), id, limit, time.Minute)
|
||||||
@@ -61,8 +66,36 @@ func (h *Handler) rateLimit(next http.Handler) http.Handler {
|
|||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Attribute one call to the caller's lifetime counter, then enforce the
|
||||||
|
// cumulative quota (quota <= 0 means unlimited). Keys also get daily and
|
||||||
|
// last-used stats recorded for the admin console.
|
||||||
|
var used int64
|
||||||
if keyID != "" {
|
if keyID != "" {
|
||||||
h.limiter.RecordUsage(r.Context(), keyID)
|
h.limiter.RecordUsage(r.Context(), keyID)
|
||||||
|
used = h.limiter.TotalUsed(r.Context(), keyID)
|
||||||
|
} else {
|
||||||
|
used = h.limiter.IncrTotal(r.Context(), subject)
|
||||||
|
}
|
||||||
|
if quota > 0 {
|
||||||
|
remaining := quota - used
|
||||||
|
if remaining < 0 {
|
||||||
|
remaining = 0
|
||||||
|
}
|
||||||
|
w.Header().Set("X-Quota-Limit", strconv.FormatInt(quota, 10))
|
||||||
|
w.Header().Set("X-Quota-Used", strconv.FormatInt(used, 10))
|
||||||
|
w.Header().Set("X-Quota-Remaining", strconv.FormatInt(remaining, 10))
|
||||||
|
if used > quota {
|
||||||
|
if keyID == "" {
|
||||||
|
writeError(w, r, http.StatusForbidden, "quota_exhausted",
|
||||||
|
"免费额度(共 "+strconv.FormatInt(quota, 10)+" 次)已用尽,请注册账号获取更高配额的 API 密钥")
|
||||||
|
} else {
|
||||||
|
writeError(w, r, http.StatusForbidden, "quota_exhausted", "API 密钥配额已用尽")
|
||||||
|
}
|
||||||
|
return
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
if keyID != "" {
|
||||||
next.ServeHTTP(w, r.WithContext(context.WithValue(r.Context(), apiKeyIDKey, keyID)))
|
next.ServeHTTP(w, r.WithContext(context.WithValue(r.Context(), apiKeyIDKey, keyID)))
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
@@ -70,6 +103,25 @@ func (h *Handler) rateLimit(next http.Handler) http.Handler {
|
|||||||
})
|
})
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// registerLimit throttles self-service account endpoints per client IP without
|
||||||
|
// consuming the metered free quota, so a caller can still register or recover
|
||||||
|
// their key after exhausting the anonymous quota.
|
||||||
|
func (h *Handler) registerLimit(next http.Handler) http.Handler {
|
||||||
|
return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
||||||
|
res := h.limiter.Allow(r.Context(), "register:"+clientIP(r), h.regRatePerMin, time.Minute)
|
||||||
|
if !res.Allowed {
|
||||||
|
retry := res.ResetUnix - time.Now().Unix()
|
||||||
|
if retry < 1 {
|
||||||
|
retry = 1
|
||||||
|
}
|
||||||
|
w.Header().Set("Retry-After", strconv.FormatInt(retry, 10))
|
||||||
|
writeError(w, r, http.StatusTooManyRequests, "rate_limited", "操作过于频繁,请稍后再试")
|
||||||
|
return
|
||||||
|
}
|
||||||
|
next.ServeHTTP(w, r)
|
||||||
|
})
|
||||||
|
}
|
||||||
|
|
||||||
// presentedKey extracts an API key from the X-API-Key header or a Bearer token.
|
// presentedKey extracts an API key from the X-API-Key header or a Bearer token.
|
||||||
func presentedKey(r *http.Request) string {
|
func presentedKey(r *http.Request) string {
|
||||||
if v := strings.TrimSpace(r.Header.Get("X-API-Key")); v != "" {
|
if v := strings.TrimSpace(r.Header.Get("X-API-Key")); v != "" {
|
||||||
|
|||||||
@@ -10,7 +10,8 @@
|
|||||||
"tags": [
|
"tags": [
|
||||||
{ "name": "products" },
|
{ "name": "products" },
|
||||||
{ "name": "catalog" },
|
{ "name": "catalog" },
|
||||||
{ "name": "meta" }
|
{ "name": "meta" },
|
||||||
|
{ "name": "account" }
|
||||||
],
|
],
|
||||||
"security": [{ "ApiKeyHeader": [] }, { "BearerKey": [] }, {}],
|
"security": [{ "ApiKeyHeader": [] }, { "BearerKey": [] }, {}],
|
||||||
"paths": {
|
"paths": {
|
||||||
@@ -114,6 +115,35 @@
|
|||||||
"parameters": [{ "name": "id", "in": "path", "required": true, "schema": { "type": "string", "format": "uuid" } }],
|
"parameters": [{ "name": "id", "in": "path", "required": true, "schema": { "type": "string", "format": "uuid" } }],
|
||||||
"responses": { "200": { "description": "Source" }, "404": { "$ref": "#/components/responses/NotFound" } }
|
"responses": { "200": { "description": "Source" }, "404": { "$ref": "#/components/responses/NotFound" } }
|
||||||
}
|
}
|
||||||
|
},
|
||||||
|
"/register": {
|
||||||
|
"post": {
|
||||||
|
"tags": ["account"],
|
||||||
|
"summary": "Register an account and issue an API key",
|
||||||
|
"description": "Self-service registration; returns the plaintext API key exactly once.",
|
||||||
|
"security": [],
|
||||||
|
"requestBody": { "required": true, "content": { "application/json": { "schema": { "type": "object", "required": ["email", "password"], "properties": { "email": { "type": "string", "format": "email" }, "password": { "type": "string", "minLength": 8 } } } } } },
|
||||||
|
"responses": { "201": { "description": "Account created; plaintext key returned once" }, "400": { "description": "Invalid email or weak password" }, "409": { "description": "Email already registered" } }
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"/account": {
|
||||||
|
"post": {
|
||||||
|
"tags": ["account"],
|
||||||
|
"summary": "View account key metadata and cumulative quota usage",
|
||||||
|
"security": [],
|
||||||
|
"requestBody": { "required": true, "content": { "application/json": { "schema": { "type": "object", "required": ["email", "password"], "properties": { "email": { "type": "string", "format": "email" }, "password": { "type": "string" } } } } } },
|
||||||
|
"responses": { "200": { "description": "Account info with quota usage" }, "401": { "description": "Invalid credentials" } }
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"/account/regenerate": {
|
||||||
|
"post": {
|
||||||
|
"tags": ["account"],
|
||||||
|
"summary": "Revoke the current key and issue a new one",
|
||||||
|
"description": "Cumulative usage carries over; returns the plaintext key exactly once.",
|
||||||
|
"security": [],
|
||||||
|
"requestBody": { "required": true, "content": { "application/json": { "schema": { "type": "object", "required": ["email", "password"], "properties": { "email": { "type": "string", "format": "email" }, "password": { "type": "string" } } } } } },
|
||||||
|
"responses": { "200": { "description": "New plaintext key returned once" }, "401": { "description": "Invalid credentials" } }
|
||||||
|
}
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"components": {
|
"components": {
|
||||||
|
|||||||
@@ -116,6 +116,45 @@ func (l *Limiter) RecordUsage(ctx context.Context, keyID string) {
|
|||||||
_, _ = pipe.Exec(ctx)
|
_, _ = pipe.Exec(ctx)
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// IncrTotal increments the lifetime call counter for subject and returns the
|
||||||
|
// new total. The counter never expires; it is the cumulative number of calls
|
||||||
|
// attributed to a caller (an API key id, or "ip:<addr>" for anonymous callers).
|
||||||
|
// Fails open returning 0 on any error so quota enforcement never takes the API
|
||||||
|
// down.
|
||||||
|
func (l *Limiter) IncrTotal(ctx context.Context, subject string) int64 {
|
||||||
|
if !l.Enabled() || subject == "" {
|
||||||
|
return 0
|
||||||
|
}
|
||||||
|
n, err := l.rdb.Incr(ctx, "usage:total:"+subject).Result()
|
||||||
|
if err != nil {
|
||||||
|
return 0
|
||||||
|
}
|
||||||
|
return n
|
||||||
|
}
|
||||||
|
|
||||||
|
// CopyTotal carries a lifetime counter from one subject to another, used when a
|
||||||
|
// key is regenerated so a caller cannot reset their cumulative quota. Best
|
||||||
|
// effort: a missing or zero source counter is a no-op.
|
||||||
|
func (l *Limiter) CopyTotal(ctx context.Context, from, to string) {
|
||||||
|
if !l.Enabled() || from == "" || to == "" {
|
||||||
|
return
|
||||||
|
}
|
||||||
|
n, err := l.rdb.Get(ctx, "usage:total:"+from).Int64()
|
||||||
|
if err != nil || n == 0 {
|
||||||
|
return
|
||||||
|
}
|
||||||
|
l.rdb.Set(ctx, "usage:total:"+to, n, 0)
|
||||||
|
}
|
||||||
|
|
||||||
|
// TotalUsed reads the lifetime call counter for subject without incrementing.
|
||||||
|
func (l *Limiter) TotalUsed(ctx context.Context, subject string) int64 {
|
||||||
|
if !l.Enabled() || subject == "" {
|
||||||
|
return 0
|
||||||
|
}
|
||||||
|
n, _ := l.rdb.Get(ctx, "usage:total:"+subject).Int64()
|
||||||
|
return n
|
||||||
|
}
|
||||||
|
|
||||||
// Usage reads aggregated usage for a key. Returns a zero-value stat on error.
|
// Usage reads aggregated usage for a key. Returns a zero-value stat on error.
|
||||||
func (l *Limiter) Usage(ctx context.Context, keyID string) UsageStat {
|
func (l *Limiter) Usage(ctx context.Context, keyID string) UsageStat {
|
||||||
var st UsageStat
|
var st UsageStat
|
||||||
|
|||||||
@@ -0,0 +1,169 @@
|
|||||||
|
package store
|
||||||
|
|
||||||
|
import (
|
||||||
|
"context"
|
||||||
|
"errors"
|
||||||
|
"strings"
|
||||||
|
|
||||||
|
"github.com/jackc/pgx/v5"
|
||||||
|
"github.com/jackc/pgx/v5/pgconn"
|
||||||
|
"golang.org/x/crypto/bcrypt"
|
||||||
|
|
||||||
|
"github.com/baicai2026-baicai/goods/api/internal/apikey"
|
||||||
|
)
|
||||||
|
|
||||||
|
// ErrEmailTaken is returned when registering an email that already exists.
|
||||||
|
var ErrEmailTaken = errors.New("email already registered")
|
||||||
|
|
||||||
|
// Account is a self-registered public-API user and its current key metadata.
|
||||||
|
type Account struct {
|
||||||
|
ID string `json:"id"`
|
||||||
|
Email string `json:"email"`
|
||||||
|
KeyID string `json:"-"`
|
||||||
|
KeyPrefix string `json:"key_prefix"`
|
||||||
|
RateLimitPerMin int `json:"rate_limit_per_min"`
|
||||||
|
QuotaTotal int64 `json:"quota_total"`
|
||||||
|
}
|
||||||
|
|
||||||
|
// bcryptDummyHash is compared against on unknown-email logins to keep timing
|
||||||
|
// roughly constant and avoid leaking which emails are registered.
|
||||||
|
const bcryptDummyHash = "$2a$10$N9qo8uLOickgx2ZMRZoMyeIjZAgcfl7p92ldGxad68LJZdL17lhWy"
|
||||||
|
|
||||||
|
func isUniqueViolation(err error) bool {
|
||||||
|
var pgErr *pgconn.PgError
|
||||||
|
return errors.As(err, &pgErr) && pgErr.Code == "23505"
|
||||||
|
}
|
||||||
|
|
||||||
|
// RegisterUser creates an account plus a self-issued API key with the given
|
||||||
|
// per-minute rate and cumulative quota, returning the plaintext key (shown
|
||||||
|
// once). Email uniqueness is case-insensitive; ErrEmailTaken signals a dupe.
|
||||||
|
func (s *Store) RegisterUser(ctx context.Context, email, password string, ratePerMin int, quotaTotal int64) (plaintext string, acct Account, err error) {
|
||||||
|
email = strings.TrimSpace(email)
|
||||||
|
pwHash, err := bcrypt.GenerateFromPassword([]byte(password), bcrypt.DefaultCost)
|
||||||
|
if err != nil {
|
||||||
|
return "", Account{}, err
|
||||||
|
}
|
||||||
|
key, keyHash, prefix, err := apikey.Generate()
|
||||||
|
if err != nil {
|
||||||
|
return "", Account{}, err
|
||||||
|
}
|
||||||
|
|
||||||
|
tx, err := s.pool.Begin(ctx)
|
||||||
|
if err != nil {
|
||||||
|
return "", Account{}, err
|
||||||
|
}
|
||||||
|
defer func() { _ = tx.Rollback(ctx) }()
|
||||||
|
|
||||||
|
var keyID string
|
||||||
|
if err = tx.QueryRow(ctx,
|
||||||
|
`INSERT INTO api_key (name, key_prefix, key_hash, owner_email, tier, rate_limit_per_min, quota_total, created_by)
|
||||||
|
VALUES ($1,$2,$3,$4,'registered',$5,$6,'self-register') RETURNING id`,
|
||||||
|
"user:"+strings.ToLower(email), prefix, keyHash, email, ratePerMin, quotaTotal,
|
||||||
|
).Scan(&keyID); err != nil {
|
||||||
|
return "", Account{}, err
|
||||||
|
}
|
||||||
|
|
||||||
|
var userID string
|
||||||
|
if err = tx.QueryRow(ctx,
|
||||||
|
`INSERT INTO app_user (email, password_hash, api_key_id) VALUES ($1,$2,$3) RETURNING id`,
|
||||||
|
email, string(pwHash), keyID,
|
||||||
|
).Scan(&userID); err != nil {
|
||||||
|
if isUniqueViolation(err) {
|
||||||
|
return "", Account{}, ErrEmailTaken
|
||||||
|
}
|
||||||
|
return "", Account{}, err
|
||||||
|
}
|
||||||
|
|
||||||
|
if err = tx.Commit(ctx); err != nil {
|
||||||
|
return "", Account{}, err
|
||||||
|
}
|
||||||
|
return key, Account{
|
||||||
|
ID: userID, Email: email, KeyID: keyID, KeyPrefix: prefix,
|
||||||
|
RateLimitPerMin: ratePerMin, QuotaTotal: quotaTotal,
|
||||||
|
}, nil
|
||||||
|
}
|
||||||
|
|
||||||
|
// Authenticate verifies an email/password pair and returns the account with its
|
||||||
|
// current (non-revoked) key metadata. Returns ErrNotFound on unknown email or
|
||||||
|
// wrong password.
|
||||||
|
func (s *Store) Authenticate(ctx context.Context, email, password string) (Account, error) {
|
||||||
|
email = strings.TrimSpace(email)
|
||||||
|
var (
|
||||||
|
userID, pwHash string
|
||||||
|
keyID *string
|
||||||
|
)
|
||||||
|
err := s.pool.QueryRow(ctx,
|
||||||
|
`SELECT id, password_hash, api_key_id FROM app_user WHERE lower(email) = lower($1)`, email,
|
||||||
|
).Scan(&userID, &pwHash, &keyID)
|
||||||
|
if errors.Is(err, pgx.ErrNoRows) {
|
||||||
|
_ = bcrypt.CompareHashAndPassword([]byte(bcryptDummyHash), []byte(password))
|
||||||
|
return Account{}, ErrNotFound
|
||||||
|
}
|
||||||
|
if err != nil {
|
||||||
|
return Account{}, err
|
||||||
|
}
|
||||||
|
if err := bcrypt.CompareHashAndPassword([]byte(pwHash), []byte(password)); err != nil {
|
||||||
|
return Account{}, ErrNotFound
|
||||||
|
}
|
||||||
|
|
||||||
|
acct := Account{ID: userID, Email: email}
|
||||||
|
if keyID != nil {
|
||||||
|
acct.KeyID = *keyID
|
||||||
|
_ = s.pool.QueryRow(ctx,
|
||||||
|
`SELECT key_prefix, rate_limit_per_min, quota_total
|
||||||
|
FROM api_key WHERE id = $1 AND revoked_at IS NULL`, *keyID,
|
||||||
|
).Scan(&acct.KeyPrefix, &acct.RateLimitPerMin, &acct.QuotaTotal)
|
||||||
|
}
|
||||||
|
return acct, nil
|
||||||
|
}
|
||||||
|
|
||||||
|
// RegenerateKey verifies credentials, revokes the account's current key, and
|
||||||
|
// issues a fresh one with the same rate/quota, returning the plaintext key and
|
||||||
|
// the previous key id (so cumulative usage can be carried over). Returns
|
||||||
|
// ErrNotFound on bad credentials.
|
||||||
|
func (s *Store) RegenerateKey(ctx context.Context, email, password string, ratePerMin int, quotaTotal int64) (plaintext string, acct Account, oldKeyID string, err error) {
|
||||||
|
cur, err := s.Authenticate(ctx, email, password)
|
||||||
|
if err != nil {
|
||||||
|
return "", Account{}, "", err
|
||||||
|
}
|
||||||
|
key, keyHash, prefix, err := apikey.Generate()
|
||||||
|
if err != nil {
|
||||||
|
return "", Account{}, "", err
|
||||||
|
}
|
||||||
|
|
||||||
|
oldKeyID = cur.KeyID
|
||||||
|
|
||||||
|
tx, err := s.pool.Begin(ctx)
|
||||||
|
if err != nil {
|
||||||
|
return "", Account{}, "", err
|
||||||
|
}
|
||||||
|
defer func() { _ = tx.Rollback(ctx) }()
|
||||||
|
|
||||||
|
if oldKeyID != "" {
|
||||||
|
if _, err = tx.Exec(ctx,
|
||||||
|
`UPDATE api_key SET revoked_at = now() WHERE id = $1`, oldKeyID); err != nil {
|
||||||
|
return "", Account{}, "", err
|
||||||
|
}
|
||||||
|
}
|
||||||
|
var newKeyID string
|
||||||
|
if err = tx.QueryRow(ctx,
|
||||||
|
`INSERT INTO api_key (name, key_prefix, key_hash, owner_email, tier, rate_limit_per_min, quota_total, created_by)
|
||||||
|
VALUES ($1,$2,$3,$4,'registered',$5,$6,'self-register') RETURNING id`,
|
||||||
|
"user:"+strings.ToLower(cur.Email), prefix, keyHash, cur.Email, ratePerMin, quotaTotal,
|
||||||
|
).Scan(&newKeyID); err != nil {
|
||||||
|
return "", Account{}, "", err
|
||||||
|
}
|
||||||
|
if _, err = tx.Exec(ctx,
|
||||||
|
`UPDATE app_user SET api_key_id = $1 WHERE id = $2`, newKeyID, cur.ID); err != nil {
|
||||||
|
return "", Account{}, "", err
|
||||||
|
}
|
||||||
|
if err = tx.Commit(ctx); err != nil {
|
||||||
|
return "", Account{}, "", err
|
||||||
|
}
|
||||||
|
|
||||||
|
cur.KeyID = newKeyID
|
||||||
|
cur.KeyPrefix = prefix
|
||||||
|
cur.RateLimitPerMin = ratePerMin
|
||||||
|
cur.QuotaTotal = quotaTotal
|
||||||
|
return key, cur, oldKeyID, nil
|
||||||
|
}
|
||||||
@@ -0,0 +1,99 @@
|
|||||||
|
package store
|
||||||
|
|
||||||
|
import (
|
||||||
|
"context"
|
||||||
|
"errors"
|
||||||
|
"fmt"
|
||||||
|
"os"
|
||||||
|
"testing"
|
||||||
|
"time"
|
||||||
|
|
||||||
|
"github.com/jackc/pgx/v5/pgxpool"
|
||||||
|
|
||||||
|
"github.com/baicai2026-baicai/goods/api/internal/apikey"
|
||||||
|
)
|
||||||
|
|
||||||
|
func testStore(t *testing.T) *Store {
|
||||||
|
t.Helper()
|
||||||
|
dsn := os.Getenv("OPENGOODS_DATABASE_URL")
|
||||||
|
if dsn == "" {
|
||||||
|
dsn = "postgres://opengoods:opengoods@localhost:5432/opengoods?sslmode=disable"
|
||||||
|
}
|
||||||
|
ctx, cancel := context.WithTimeout(context.Background(), 3*time.Second)
|
||||||
|
defer cancel()
|
||||||
|
pool, err := pgxpool.New(ctx, dsn)
|
||||||
|
if err != nil {
|
||||||
|
t.Skipf("no database: %v", err)
|
||||||
|
}
|
||||||
|
if err := pool.Ping(ctx); err != nil {
|
||||||
|
pool.Close()
|
||||||
|
t.Skipf("database not reachable: %v", err)
|
||||||
|
}
|
||||||
|
var hasUser bool
|
||||||
|
if err := pool.QueryRow(ctx, "SELECT to_regclass('public.app_user') IS NOT NULL").Scan(&hasUser); err != nil || !hasUser {
|
||||||
|
pool.Close()
|
||||||
|
t.Skip("migrations not applied")
|
||||||
|
}
|
||||||
|
t.Cleanup(pool.Close)
|
||||||
|
return New(pool)
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestRegisterAuthenticateRegenerate(t *testing.T) {
|
||||||
|
s := testStore(t)
|
||||||
|
ctx := context.Background()
|
||||||
|
email := fmt.Sprintf("user-%d@example.com", time.Now().UnixNano())
|
||||||
|
|
||||||
|
t.Cleanup(func() {
|
||||||
|
_, _ = s.pool.Exec(ctx, "DELETE FROM app_user WHERE lower(email)=lower($1)", email)
|
||||||
|
_, _ = s.pool.Exec(ctx, "DELETE FROM api_key WHERE owner_email=$1", email)
|
||||||
|
})
|
||||||
|
|
||||||
|
key, acct, err := s.RegisterUser(ctx, email, "supersecret", 300, 100000)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("register: %v", err)
|
||||||
|
}
|
||||||
|
if key == "" || acct.KeyPrefix == "" || acct.QuotaTotal != 100000 || acct.RateLimitPerMin != 300 {
|
||||||
|
t.Fatalf("unexpected account: %+v key=%q", acct, key)
|
||||||
|
}
|
||||||
|
|
||||||
|
// The issued key resolves via the public auth path with its quota attached.
|
||||||
|
k, err := s.APIKeyByHash(ctx, apikey.Hash(key))
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("APIKeyByHash: %v", err)
|
||||||
|
}
|
||||||
|
if k.QuotaTotal != 100000 || k.RateLimitPerMin != 300 {
|
||||||
|
t.Fatalf("key metadata mismatch: %+v", k)
|
||||||
|
}
|
||||||
|
|
||||||
|
// Duplicate email is rejected.
|
||||||
|
if _, _, err := s.RegisterUser(ctx, email, "anotherpass", 300, 100000); !errors.Is(err, ErrEmailTaken) {
|
||||||
|
t.Fatalf("expected ErrEmailTaken, got %v", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
// Wrong password fails; correct password authenticates.
|
||||||
|
if _, err := s.Authenticate(ctx, email, "wrong"); !errors.Is(err, ErrNotFound) {
|
||||||
|
t.Fatalf("expected ErrNotFound for bad password, got %v", err)
|
||||||
|
}
|
||||||
|
got, err := s.Authenticate(ctx, email, "supersecret")
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("authenticate: %v", err)
|
||||||
|
}
|
||||||
|
if got.KeyPrefix != acct.KeyPrefix {
|
||||||
|
t.Fatalf("authenticate key prefix = %q want %q", got.KeyPrefix, acct.KeyPrefix)
|
||||||
|
}
|
||||||
|
|
||||||
|
// Regeneration revokes the old key and issues a new one.
|
||||||
|
newKey, regen, oldKeyID, err := s.RegenerateKey(ctx, email, "supersecret", 300, 100000)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("regenerate: %v", err)
|
||||||
|
}
|
||||||
|
if newKey == key || oldKeyID != acct.KeyID || regen.KeyID == oldKeyID {
|
||||||
|
t.Fatalf("regenerate did not rotate key: old=%s new=%+v", oldKeyID, regen)
|
||||||
|
}
|
||||||
|
if _, err := s.APIKeyByHash(ctx, apikey.Hash(key)); !errors.Is(err, ErrNotFound) {
|
||||||
|
t.Fatalf("old key should be revoked, got %v", err)
|
||||||
|
}
|
||||||
|
if _, err := s.APIKeyByHash(ctx, apikey.Hash(newKey)); err != nil {
|
||||||
|
t.Fatalf("new key should be active: %v", err)
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -4,8 +4,10 @@ package store
|
|||||||
|
|
||||||
import (
|
import (
|
||||||
"context"
|
"context"
|
||||||
|
"encoding/json"
|
||||||
"errors"
|
"errors"
|
||||||
"strconv"
|
"strconv"
|
||||||
|
"strings"
|
||||||
|
|
||||||
"github.com/jackc/pgx/v5"
|
"github.com/jackc/pgx/v5"
|
||||||
"github.com/jackc/pgx/v5/pgxpool"
|
"github.com/jackc/pgx/v5/pgxpool"
|
||||||
@@ -56,6 +58,15 @@ type Barcode struct {
|
|||||||
IsPrimary bool `json:"is_primary"`
|
IsPrimary bool `json:"is_primary"`
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// ProductSpec is one labeled spec line for a non-food product, rendered from
|
||||||
|
// the product's attributes JSONB against its archive kind's field template.
|
||||||
|
type ProductSpec struct {
|
||||||
|
Key string `json:"key"`
|
||||||
|
Label string `json:"label"`
|
||||||
|
Value string `json:"value"`
|
||||||
|
Unit string `json:"unit,omitempty"`
|
||||||
|
}
|
||||||
|
|
||||||
// Product is the full public view of a product.
|
// Product is the full public view of a product.
|
||||||
type Product struct {
|
type Product struct {
|
||||||
ID string `json:"id"`
|
ID string `json:"id"`
|
||||||
@@ -64,11 +75,13 @@ type Product struct {
|
|||||||
Brand *string `json:"brand"`
|
Brand *string `json:"brand"`
|
||||||
CategoryPath *string `json:"category_path"`
|
CategoryPath *string `json:"category_path"`
|
||||||
GPCBrickCode *string `json:"gpc_brick_code"`
|
GPCBrickCode *string `json:"gpc_brick_code"`
|
||||||
|
ArchiveKind string `json:"archive_kind"`
|
||||||
NetContentValue *float64 `json:"net_content_value"`
|
NetContentValue *float64 `json:"net_content_value"`
|
||||||
NetContentUnit *string `json:"net_content_unit"`
|
NetContentUnit *string `json:"net_content_unit"`
|
||||||
CountryOfOrigin *string `json:"country_of_origin"`
|
CountryOfOrigin *string `json:"country_of_origin"`
|
||||||
QualityScore float64 `json:"quality_score"`
|
QualityScore float64 `json:"quality_score"`
|
||||||
Barcodes []Barcode `json:"barcodes"`
|
Barcodes []Barcode `json:"barcodes"`
|
||||||
|
Specs []ProductSpec `json:"specs,omitempty"`
|
||||||
Nutriments map[string]any `json:"nutriments,omitempty"`
|
Nutriments map[string]any `json:"nutriments,omitempty"`
|
||||||
NutritionBasis *string `json:"nutrition_basis,omitempty"`
|
NutritionBasis *string `json:"nutrition_basis,omitempty"`
|
||||||
NutriScore *string `json:"nutri_score,omitempty"`
|
NutriScore *string `json:"nutri_score,omitempty"`
|
||||||
@@ -120,6 +133,7 @@ type SearchFilters struct {
|
|||||||
|
|
||||||
const productSelect = `
|
const productSelect = `
|
||||||
SELECT p.id, p.gtin, p.name, b.name, c.path::text, p.gpc_brick_code,
|
SELECT p.id, p.gtin, p.name, b.name, c.path::text, p.gpc_brick_code,
|
||||||
|
COALESCE(c.archive_kind, 'generic'), p.attributes,
|
||||||
p.net_content_value, p.net_content_unit, p.country_of_origin, p.quality_score,
|
p.net_content_value, p.net_content_unit, p.country_of_origin, p.quality_score,
|
||||||
f.nutriments, f.nutrition_basis, f.nutri_score, f.ingredients_text,
|
f.nutriments, f.nutrition_basis, f.nutri_score, f.ingredients_text,
|
||||||
f.allergens, f.additives
|
f.allergens, f.additives
|
||||||
@@ -129,21 +143,81 @@ LEFT JOIN category c ON c.id = p.category_id
|
|||||||
LEFT JOIN food_detail f ON f.product_id = p.id
|
LEFT JOIN food_detail f ON f.product_id = p.id
|
||||||
`
|
`
|
||||||
|
|
||||||
func scanProduct(row pgx.Row) (*Product, error) {
|
func scanProduct(row pgx.Row) (*Product, []byte, error) {
|
||||||
var p Product
|
var p Product
|
||||||
|
var attributes []byte
|
||||||
err := row.Scan(
|
err := row.Scan(
|
||||||
&p.ID, &p.GTIN, &p.Name, &p.Brand, &p.CategoryPath, &p.GPCBrickCode,
|
&p.ID, &p.GTIN, &p.Name, &p.Brand, &p.CategoryPath, &p.GPCBrickCode,
|
||||||
|
&p.ArchiveKind, &attributes,
|
||||||
&p.NetContentValue, &p.NetContentUnit, &p.CountryOfOrigin, &p.QualityScore,
|
&p.NetContentValue, &p.NetContentUnit, &p.CountryOfOrigin, &p.QualityScore,
|
||||||
&p.Nutriments, &p.NutritionBasis, &p.NutriScore, &p.Ingredients,
|
&p.Nutriments, &p.NutritionBasis, &p.NutriScore, &p.Ingredients,
|
||||||
&p.Allergens, &p.Additives,
|
&p.Allergens, &p.Additives,
|
||||||
)
|
)
|
||||||
if errors.Is(err, pgx.ErrNoRows) {
|
if errors.Is(err, pgx.ErrNoRows) {
|
||||||
return nil, ErrNotFound
|
return nil, nil, ErrNotFound
|
||||||
}
|
}
|
||||||
|
if err != nil {
|
||||||
|
return nil, nil, err
|
||||||
|
}
|
||||||
|
return &p, attributes, nil
|
||||||
|
}
|
||||||
|
|
||||||
|
// buildSpecs renders the labeled, ordered spec list for a non-food product from
|
||||||
|
// its attributes JSONB against its archive kind's field template.
|
||||||
|
func (s *Store) buildSpecs(ctx context.Context, kind string, attributes []byte) ([]ProductSpec, error) {
|
||||||
|
if kind == "" || kind == "food" || len(attributes) == 0 {
|
||||||
|
return nil, nil
|
||||||
|
}
|
||||||
|
attrs := map[string]any{}
|
||||||
|
if err := json.Unmarshal(attributes, &attrs); err != nil || len(attrs) == 0 {
|
||||||
|
return nil, nil
|
||||||
|
}
|
||||||
|
rows, err := s.pool.Query(ctx,
|
||||||
|
"SELECT field_key, label_zh, COALESCE(unit, '') FROM kind_field WHERE kind = $1 ORDER BY sort_order, field_key", kind)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return nil, err
|
return nil, err
|
||||||
}
|
}
|
||||||
return &p, nil
|
defer rows.Close()
|
||||||
|
specs := []ProductSpec{}
|
||||||
|
for rows.Next() {
|
||||||
|
var key, label, unit string
|
||||||
|
if err := rows.Scan(&key, &label, &unit); err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
v, ok := attrs[key]
|
||||||
|
if !ok || v == nil {
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
val := stringifyAttr(v)
|
||||||
|
if val == "" {
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
specs = append(specs, ProductSpec{Key: key, Label: label, Value: val, Unit: unit})
|
||||||
|
}
|
||||||
|
return specs, rows.Err()
|
||||||
|
}
|
||||||
|
|
||||||
|
// stringifyAttr renders a JSON attribute value as display text.
|
||||||
|
func stringifyAttr(v any) string {
|
||||||
|
switch t := v.(type) {
|
||||||
|
case string:
|
||||||
|
return t
|
||||||
|
case float64:
|
||||||
|
return strconv.FormatFloat(t, 'f', -1, 64)
|
||||||
|
case bool:
|
||||||
|
if t {
|
||||||
|
return "是"
|
||||||
|
}
|
||||||
|
return "否"
|
||||||
|
case []any:
|
||||||
|
parts := make([]string, 0, len(t))
|
||||||
|
for _, e := range t {
|
||||||
|
parts = append(parts, stringifyAttr(e))
|
||||||
|
}
|
||||||
|
return strings.Join(parts, "、")
|
||||||
|
default:
|
||||||
|
return ""
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// ProductByGTIN looks up an active product by any of its barcodes.
|
// ProductByGTIN looks up an active product by any of its barcodes.
|
||||||
@@ -154,26 +228,32 @@ func (s *Store) ProductByGTIN(ctx context.Context, gtin string) (*Product, error
|
|||||||
SELECT 1 FROM product_barcode pb
|
SELECT 1 FROM product_barcode pb
|
||||||
WHERE pb.product_id = p.id AND pb.gtin = $1))
|
WHERE pb.product_id = p.id AND pb.gtin = $1))
|
||||||
LIMIT 1`, gtin)
|
LIMIT 1`, gtin)
|
||||||
p, err := scanProduct(row)
|
p, attrs, err := scanProduct(row)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return nil, err
|
return nil, err
|
||||||
}
|
}
|
||||||
if p.Barcodes, err = s.ProductBarcodes(ctx, p.ID); err != nil {
|
if p.Barcodes, err = s.ProductBarcodes(ctx, p.ID); err != nil {
|
||||||
return nil, err
|
return nil, err
|
||||||
}
|
}
|
||||||
|
if p.Specs, err = s.buildSpecs(ctx, p.ArchiveKind, attrs); err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
return p, nil
|
return p, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
// ProductByID looks up a product by its UUID.
|
// ProductByID looks up a product by its UUID.
|
||||||
func (s *Store) ProductByID(ctx context.Context, id string) (*Product, error) {
|
func (s *Store) ProductByID(ctx context.Context, id string) (*Product, error) {
|
||||||
row := s.pool.QueryRow(ctx, productSelect+" WHERE p.id = $1", id)
|
row := s.pool.QueryRow(ctx, productSelect+" WHERE p.id = $1", id)
|
||||||
p, err := scanProduct(row)
|
p, attrs, err := scanProduct(row)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return nil, err
|
return nil, err
|
||||||
}
|
}
|
||||||
if p.Barcodes, err = s.ProductBarcodes(ctx, p.ID); err != nil {
|
if p.Barcodes, err = s.ProductBarcodes(ctx, p.ID); err != nil {
|
||||||
return nil, err
|
return nil, err
|
||||||
}
|
}
|
||||||
|
if p.Specs, err = s.buildSpecs(ctx, p.ArchiveKind, attrs); err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
return p, nil
|
return p, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -373,6 +453,7 @@ type APIKey struct {
|
|||||||
ID string
|
ID string
|
||||||
Name string
|
Name string
|
||||||
RateLimitPerMin int
|
RateLimitPerMin int
|
||||||
|
QuotaTotal int64
|
||||||
}
|
}
|
||||||
|
|
||||||
// APIKeyByHash returns the active (non-revoked) key matching a SHA-256 hash,
|
// APIKeyByHash returns the active (non-revoked) key matching a SHA-256 hash,
|
||||||
@@ -380,9 +461,9 @@ type APIKey struct {
|
|||||||
func (s *Store) APIKeyByHash(ctx context.Context, hash string) (*APIKey, error) {
|
func (s *Store) APIKeyByHash(ctx context.Context, hash string) (*APIKey, error) {
|
||||||
var k APIKey
|
var k APIKey
|
||||||
err := s.pool.QueryRow(ctx,
|
err := s.pool.QueryRow(ctx,
|
||||||
`SELECT id, name, rate_limit_per_min
|
`SELECT id, name, rate_limit_per_min, quota_total
|
||||||
FROM api_key WHERE key_hash = $1 AND revoked_at IS NULL`, hash,
|
FROM api_key WHERE key_hash = $1 AND revoked_at IS NULL`, hash,
|
||||||
).Scan(&k.ID, &k.Name, &k.RateLimitPerMin)
|
).Scan(&k.ID, &k.Name, &k.RateLimitPerMin, &k.QuotaTotal)
|
||||||
if errors.Is(err, pgx.ErrNoRows) {
|
if errors.Is(err, pgx.ErrNoRows) {
|
||||||
return nil, ErrNotFound
|
return nil, ErrNotFound
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,9 @@
|
|||||||
|
-- Detach any products from the seeded 3C categories, then remove them.
|
||||||
|
UPDATE product SET category_id = NULL
|
||||||
|
WHERE category_id IN (SELECT id FROM category WHERE path <@ 'electronics');
|
||||||
|
|
||||||
|
DELETE FROM category WHERE path <@ 'electronics';
|
||||||
|
|
||||||
|
DROP TABLE IF EXISTS kind_field;
|
||||||
|
|
||||||
|
ALTER TABLE category DROP COLUMN IF EXISTS archive_kind;
|
||||||
@@ -0,0 +1,64 @@
|
|||||||
|
-- Generic, extensible "archive kind" (档案模式) framework.
|
||||||
|
-- Instead of a dedicated detail table per domain (food/electronics/drug/...),
|
||||||
|
-- each category belongs to an archive_kind, and a metadata table (kind_field)
|
||||||
|
-- describes the editable spec fields for that kind. Non-food spec values live
|
||||||
|
-- in the existing product.attributes JSONB. Adding a new domain later (drug,
|
||||||
|
-- machinery, ...) is just: seed kind_field rows + a category subtree.
|
||||||
|
|
||||||
|
ALTER TABLE category ADD COLUMN archive_kind VARCHAR(24) NOT NULL DEFAULT 'generic';
|
||||||
|
|
||||||
|
-- The existing seeded tree is the food domain.
|
||||||
|
UPDATE category SET archive_kind = 'food' WHERE path <@ 'food';
|
||||||
|
|
||||||
|
-- Field template per archive kind: drives the dynamic admin form and the
|
||||||
|
-- kind-aware completeness/qualified computation.
|
||||||
|
CREATE TABLE kind_field (
|
||||||
|
kind VARCHAR(24) NOT NULL,
|
||||||
|
field_key VARCHAR(64) NOT NULL,
|
||||||
|
group_label TEXT NOT NULL DEFAULT '',
|
||||||
|
label_zh TEXT NOT NULL,
|
||||||
|
field_type VARCHAR(16) NOT NULL DEFAULT 'text',
|
||||||
|
unit TEXT,
|
||||||
|
options TEXT[] NOT NULL DEFAULT '{}',
|
||||||
|
placeholder TEXT,
|
||||||
|
sort_order INT NOT NULL DEFAULT 0,
|
||||||
|
qualified BOOLEAN NOT NULL DEFAULT false,
|
||||||
|
PRIMARY KEY (kind, field_key),
|
||||||
|
CONSTRAINT kind_field_type_chk CHECK (field_type IN ('text','number','textarea','select','list'))
|
||||||
|
);
|
||||||
|
|
||||||
|
-- Seed the electronics (3C) field template.
|
||||||
|
INSERT INTO kind_field (kind, field_key, group_label, label_zh, field_type, unit, sort_order, qualified) VALUES
|
||||||
|
('electronics','model_number', '基础规格','型号', 'text', NULL, 10, true),
|
||||||
|
('electronics','ccc_cert', '基础规格','3C认证号(CCC)','text', NULL, 20, true),
|
||||||
|
('electronics','color', '基础规格','颜色', 'text', NULL, 30, false),
|
||||||
|
('electronics','release_year', '基础规格','发布年份', 'number', NULL, 40, false),
|
||||||
|
('electronics','warranty_months','基础规格','保修期', 'number', '月', 50, false),
|
||||||
|
('electronics','dimensions', '外形','尺寸(长x宽x高)', 'text', 'mm', 60, false),
|
||||||
|
('electronics','weight', '外形','重量', 'number', 'g', 70, false),
|
||||||
|
('electronics','power', '外形','电源/功率', 'text', NULL, 80, false),
|
||||||
|
('electronics','os', '关键参数','操作系统', 'text', NULL, 90, false),
|
||||||
|
('electronics','cpu', '关键参数','处理器', 'text', NULL, 100, false),
|
||||||
|
('electronics','ram', '关键参数','内存', 'text', NULL, 110, false),
|
||||||
|
('electronics','storage', '关键参数','存储', 'text', NULL, 120, false),
|
||||||
|
('electronics','screen_size', '关键参数','屏幕尺寸', 'text', NULL, 130, true),
|
||||||
|
('electronics','battery', '关键参数','电池容量', 'text', NULL, 140, false),
|
||||||
|
('electronics','ports', '关键参数','接口', 'text', NULL, 150, false);
|
||||||
|
|
||||||
|
-- Seed the 3C category tree.
|
||||||
|
INSERT INTO category (name_zh, name_en, parent_id, path, level, archive_kind)
|
||||||
|
VALUES ('电子数码', 'Electronics', NULL, 'electronics', 0, 'electronics');
|
||||||
|
|
||||||
|
INSERT INTO category (name_zh, name_en, parent_id, path, level, archive_kind)
|
||||||
|
SELECT v.name_zh, v.name_en, c.id, v.path::ltree, 1, 'electronics'
|
||||||
|
FROM (VALUES
|
||||||
|
('手机', 'Smartphone', 'electronics.phone'),
|
||||||
|
('笔记本电脑', 'Laptop', 'electronics.laptop'),
|
||||||
|
('平板电脑', 'Tablet', 'electronics.tablet'),
|
||||||
|
('智能手表', 'Smartwatch', 'electronics.watch'),
|
||||||
|
('耳机', 'Headphone', 'electronics.headphone'),
|
||||||
|
('相机', 'Camera', 'electronics.camera'),
|
||||||
|
('电视', 'TV', 'electronics.tv'),
|
||||||
|
('家用电器', 'Home appliance', 'electronics.appliance')
|
||||||
|
) AS v(name_zh, name_en, path)
|
||||||
|
JOIN category c ON c.path = 'electronics';
|
||||||
@@ -0,0 +1,10 @@
|
|||||||
|
DROP TABLE IF EXISTS app_user;
|
||||||
|
|
||||||
|
-- Demote any self-registered keys before restoring the narrower tier check.
|
||||||
|
UPDATE api_key SET tier = 'free' WHERE tier = 'registered';
|
||||||
|
|
||||||
|
ALTER TABLE api_key DROP CONSTRAINT IF EXISTS api_key_tier_chk;
|
||||||
|
ALTER TABLE api_key ADD CONSTRAINT api_key_tier_chk
|
||||||
|
CHECK (tier IN ('free', 'partner', 'internal'));
|
||||||
|
|
||||||
|
ALTER TABLE api_key DROP COLUMN IF EXISTS quota_total;
|
||||||
@@ -0,0 +1,27 @@
|
|||||||
|
-- Cumulative usage quotas + self-service user registration for the public API.
|
||||||
|
--
|
||||||
|
-- The free anonymous tier is capped at a lifetime number of calls (enforced in
|
||||||
|
-- Redis, keyed by client IP). To keep calling beyond the free quota a caller
|
||||||
|
-- registers an account and self-issues an API key with a higher quota.
|
||||||
|
-- quota_total = 0 means unlimited.
|
||||||
|
--
|
||||||
|
-- Registration is the one place the public server writes to PostgreSQL (it
|
||||||
|
-- inserts an app_user and its api_key); every other public route stays
|
||||||
|
-- read-only. Request counting still lives entirely in Redis.
|
||||||
|
|
||||||
|
ALTER TABLE api_key ADD COLUMN IF NOT EXISTS quota_total BIGINT NOT NULL DEFAULT 0;
|
||||||
|
|
||||||
|
ALTER TABLE api_key DROP CONSTRAINT IF EXISTS api_key_tier_chk;
|
||||||
|
ALTER TABLE api_key ADD CONSTRAINT api_key_tier_chk
|
||||||
|
CHECK (tier IN ('free', 'registered', 'partner', 'internal'));
|
||||||
|
|
||||||
|
CREATE TABLE IF NOT EXISTS app_user (
|
||||||
|
id UUID PRIMARY KEY DEFAULT gen_random_uuid(),
|
||||||
|
email TEXT NOT NULL,
|
||||||
|
password_hash TEXT NOT NULL,
|
||||||
|
api_key_id UUID REFERENCES api_key (id) ON DELETE SET NULL,
|
||||||
|
created_at TIMESTAMPTZ NOT NULL DEFAULT now()
|
||||||
|
);
|
||||||
|
|
||||||
|
-- Case-insensitive uniqueness so each email registers at most once.
|
||||||
|
CREATE UNIQUE INDEX IF NOT EXISTS idx_app_user_email ON app_user (lower(email));
|
||||||
@@ -1,16 +1,18 @@
|
|||||||
import { useEffect, useState } from "react";
|
import { useEffect, useState } from "react";
|
||||||
import { Boxes, Search, PlusCircle, Code2 } from "lucide-react";
|
import { Boxes, Search, PlusCircle, Code2, KeyRound } from "lucide-react";
|
||||||
import Home from "./components/Home";
|
import Home from "./components/Home";
|
||||||
import ProductView from "./components/ProductView";
|
import ProductView from "./components/ProductView";
|
||||||
import Contribute from "./components/Contribute";
|
import Contribute from "./components/Contribute";
|
||||||
import ApiDocs from "./components/ApiDocs";
|
import ApiDocs from "./components/ApiDocs";
|
||||||
|
import Account from "./components/Account";
|
||||||
import { api } from "./api";
|
import { api } from "./api";
|
||||||
|
|
||||||
type View =
|
type View =
|
||||||
| { name: "home" }
|
| { name: "home" }
|
||||||
| { name: "product"; id: string }
|
| { name: "product"; id: string }
|
||||||
| { name: "contribute" }
|
| { name: "contribute" }
|
||||||
| { name: "api" };
|
| { name: "api" }
|
||||||
|
| { name: "account" };
|
||||||
|
|
||||||
export default function App() {
|
export default function App() {
|
||||||
const [view, setView] = useState<View>({ name: "home" });
|
const [view, setView] = useState<View>({ name: "home" });
|
||||||
@@ -59,6 +61,14 @@ export default function App() {
|
|||||||
>
|
>
|
||||||
<Code2 className="w-4 h-4" /> API
|
<Code2 className="w-4 h-4" /> API
|
||||||
</button>
|
</button>
|
||||||
|
<button
|
||||||
|
className={`px-3 py-1.5 rounded-md flex items-center gap-1.5 ${
|
||||||
|
view.name === "account" ? "bg-emerald-50 text-emerald-700" : "text-gray-600 hover:bg-gray-100"
|
||||||
|
}`}
|
||||||
|
onClick={() => setView({ name: "account" })}
|
||||||
|
>
|
||||||
|
<KeyRound className="w-4 h-4" /> API 密钥
|
||||||
|
</button>
|
||||||
</nav>
|
</nav>
|
||||||
</div>
|
</div>
|
||||||
</header>
|
</header>
|
||||||
@@ -77,11 +87,12 @@ export default function App() {
|
|||||||
{view.name === "contribute" && (
|
{view.name === "contribute" && (
|
||||||
<Contribute onDone={() => setView({ name: "home" })} />
|
<Contribute onDone={() => setView({ name: "home" })} />
|
||||||
)}
|
)}
|
||||||
{view.name === "api" && <ApiDocs />}
|
{view.name === "api" && <ApiDocs onRegister={() => setView({ name: "account" })} />}
|
||||||
|
{view.name === "account" && <Account />}
|
||||||
</main>
|
</main>
|
||||||
|
|
||||||
<footer className="border-t bg-white">
|
<footer className="border-t bg-white">
|
||||||
<div className="max-w-5xl mx-auto px-4 py-4 text-xs text-gray-400 leading-relaxed">
|
<div className="max-w-5xl mx-auto px-4 py-4 text-xs text-gray-400 leading-relaxed text-center">
|
||||||
{qualified != null && (
|
{qualified != null && (
|
||||||
<div className="mb-2 text-gray-500">
|
<div className="mb-2 text-gray-500">
|
||||||
目前已收录
|
目前已收录
|
||||||
@@ -91,8 +102,7 @@ export default function App() {
|
|||||||
条合格商品档案
|
条合格商品档案
|
||||||
</div>
|
</div>
|
||||||
)}
|
)}
|
||||||
天工商品档案公共仓 是公益性「商品事实库」,仅收录客观商品信息(条码、品牌、品类、营养、官方建议零售价快照等),不含任何购买/交易功能。
|
天工是一个公益性商品档案库。主要收录商品名称,条码,品类,配料等官方快照。不涉及任何交易行为。
|
||||||
公众投稿须经人工审核后方可收纳。
|
|
||||||
<button onClick={() => setView({ name: "api" })} className="ml-1 text-emerald-600 hover:underline">
|
<button onClick={() => setView({ name: "api" })} className="ml-1 text-emerald-600 hover:underline">
|
||||||
API 调用说明
|
API 调用说明
|
||||||
</button>
|
</button>
|
||||||
|
|||||||
@@ -36,6 +36,23 @@ export interface Stats {
|
|||||||
min_score: number;
|
min_score: number;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
export interface KeyResponse {
|
||||||
|
email: string;
|
||||||
|
api_key: string;
|
||||||
|
key_prefix: string;
|
||||||
|
rate_limit_per_min: number;
|
||||||
|
quota_total: number;
|
||||||
|
}
|
||||||
|
|
||||||
|
export interface AccountInfo {
|
||||||
|
email: string;
|
||||||
|
key_prefix: string;
|
||||||
|
rate_limit_per_min: number;
|
||||||
|
quota_total: number;
|
||||||
|
quota_used: number;
|
||||||
|
quota_remaining: number;
|
||||||
|
}
|
||||||
|
|
||||||
export const api = {
|
export const api = {
|
||||||
stats: () => req<Stats>(`/api/v1/stats`),
|
stats: () => req<Stats>(`/api/v1/stats`),
|
||||||
search: (q: string, page = 1, size = 20, filters: SearchFilters = {}) => {
|
search: (q: string, page = 1, size = 20, filters: SearchFilters = {}) => {
|
||||||
@@ -55,4 +72,19 @@ export const api = {
|
|||||||
method: "POST",
|
method: "POST",
|
||||||
body: JSON.stringify(input),
|
body: JSON.stringify(input),
|
||||||
}),
|
}),
|
||||||
|
register: (email: string, password: string) =>
|
||||||
|
req<KeyResponse>(`/api/v1/register`, {
|
||||||
|
method: "POST",
|
||||||
|
body: JSON.stringify({ email, password }),
|
||||||
|
}),
|
||||||
|
account: (email: string, password: string) =>
|
||||||
|
req<AccountInfo>(`/api/v1/account`, {
|
||||||
|
method: "POST",
|
||||||
|
body: JSON.stringify({ email, password }),
|
||||||
|
}),
|
||||||
|
regenerate: (email: string, password: string) =>
|
||||||
|
req<KeyResponse>(`/api/v1/account/regenerate`, {
|
||||||
|
method: "POST",
|
||||||
|
body: JSON.stringify({ email, password }),
|
||||||
|
}),
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -0,0 +1,192 @@
|
|||||||
|
import { useState } from "react";
|
||||||
|
import { Check, Copy, KeyRound, AlertTriangle } from "lucide-react";
|
||||||
|
import { api, type AccountInfo, type KeyResponse } from "../api";
|
||||||
|
|
||||||
|
function KeyReveal({ data }: { data: KeyResponse }) {
|
||||||
|
const [copied, setCopied] = useState(false);
|
||||||
|
return (
|
||||||
|
<div className="mt-4 rounded-lg border border-emerald-200 bg-emerald-50 p-4">
|
||||||
|
<div className="flex items-start gap-2 text-amber-700 text-sm">
|
||||||
|
<AlertTriangle className="w-4 h-4 mt-0.5 shrink-0" />
|
||||||
|
<span>请立即复制保存此密钥,它只显示这一次,无法再次查看。</span>
|
||||||
|
</div>
|
||||||
|
<div className="mt-3 flex items-center gap-2">
|
||||||
|
<code className="flex-1 break-all bg-white border rounded-md px-3 py-2 text-sm font-mono text-gray-800">
|
||||||
|
{data.api_key}
|
||||||
|
</code>
|
||||||
|
<button
|
||||||
|
onClick={async () => {
|
||||||
|
try {
|
||||||
|
await navigator.clipboard.writeText(data.api_key);
|
||||||
|
setCopied(true);
|
||||||
|
setTimeout(() => setCopied(false), 1200);
|
||||||
|
} catch {
|
||||||
|
/* clipboard unavailable */
|
||||||
|
}
|
||||||
|
}}
|
||||||
|
className="text-gray-400 hover:text-gray-600 shrink-0"
|
||||||
|
title="复制"
|
||||||
|
>
|
||||||
|
{copied ? <Check className="w-5 h-5 text-emerald-600" /> : <Copy className="w-5 h-5" />}
|
||||||
|
</button>
|
||||||
|
</div>
|
||||||
|
<div className="mt-3 text-sm text-gray-600">
|
||||||
|
配额:每分钟 <strong>{data.rate_limit_per_min}</strong> 次 · 累计{" "}
|
||||||
|
<strong>{data.quota_total.toLocaleString()}</strong> 次
|
||||||
|
</div>
|
||||||
|
<div className="mt-2 text-xs text-gray-500">
|
||||||
|
调用时通过请求头携带:
|
||||||
|
<code className="font-mono">X-API-Key: {data.api_key.slice(0, 12)}…</code>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
export default function Account() {
|
||||||
|
const [mode, setMode] = useState<"register" | "manage">("register");
|
||||||
|
const [email, setEmail] = useState("");
|
||||||
|
const [password, setPassword] = useState("");
|
||||||
|
const [loading, setLoading] = useState(false);
|
||||||
|
const [error, setError] = useState<string | null>(null);
|
||||||
|
const [issued, setIssued] = useState<KeyResponse | null>(null);
|
||||||
|
const [info, setInfo] = useState<AccountInfo | null>(null);
|
||||||
|
|
||||||
|
const reset = () => {
|
||||||
|
setError(null);
|
||||||
|
setIssued(null);
|
||||||
|
setInfo(null);
|
||||||
|
};
|
||||||
|
|
||||||
|
async function submit(e: React.FormEvent) {
|
||||||
|
e.preventDefault();
|
||||||
|
reset();
|
||||||
|
if (password.length < 8) {
|
||||||
|
setError("密码至少需要 8 位");
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
setLoading(true);
|
||||||
|
try {
|
||||||
|
if (mode === "register") {
|
||||||
|
setIssued(await api.register(email, password));
|
||||||
|
} else {
|
||||||
|
setInfo(await api.account(email, password));
|
||||||
|
}
|
||||||
|
} catch (err) {
|
||||||
|
setError(err instanceof Error ? err.message : "操作失败");
|
||||||
|
} finally {
|
||||||
|
setLoading(false);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
async function regenerate() {
|
||||||
|
reset();
|
||||||
|
setLoading(true);
|
||||||
|
try {
|
||||||
|
setIssued(await api.regenerate(email, password));
|
||||||
|
} catch (err) {
|
||||||
|
setError(err instanceof Error ? err.message : "操作失败");
|
||||||
|
} finally {
|
||||||
|
setLoading(false);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
return (
|
||||||
|
<div className="max-w-xl mx-auto space-y-5">
|
||||||
|
<div className="bg-white border rounded-lg p-5">
|
||||||
|
<h1 className="flex items-center gap-2 text-2xl font-bold text-gray-800">
|
||||||
|
<KeyRound className="w-6 h-6 text-emerald-600" /> API 密钥
|
||||||
|
</h1>
|
||||||
|
<p className="mt-2 text-sm text-gray-600 leading-relaxed">
|
||||||
|
匿名调用免费,但每个来源 IP 累计共 <strong>1000</strong> 次。注册一个账号即可自助领取专属 API
|
||||||
|
密钥,获得更高的每分钟频率与累计调用配额。
|
||||||
|
</p>
|
||||||
|
|
||||||
|
<div className="mt-4 inline-flex rounded-md border bg-gray-50 p-0.5 text-sm">
|
||||||
|
<button
|
||||||
|
className={`px-4 py-1.5 rounded ${
|
||||||
|
mode === "register" ? "bg-white shadow-sm text-emerald-700" : "text-gray-500"
|
||||||
|
}`}
|
||||||
|
onClick={() => {
|
||||||
|
setMode("register");
|
||||||
|
reset();
|
||||||
|
}}
|
||||||
|
>
|
||||||
|
注册领取
|
||||||
|
</button>
|
||||||
|
<button
|
||||||
|
className={`px-4 py-1.5 rounded ${
|
||||||
|
mode === "manage" ? "bg-white shadow-sm text-emerald-700" : "text-gray-500"
|
||||||
|
}`}
|
||||||
|
onClick={() => {
|
||||||
|
setMode("manage");
|
||||||
|
reset();
|
||||||
|
}}
|
||||||
|
>
|
||||||
|
查看 / 重置
|
||||||
|
</button>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<form onSubmit={submit} className="mt-4 space-y-3">
|
||||||
|
<div>
|
||||||
|
<label className="block text-sm text-gray-600 mb-1">邮箱</label>
|
||||||
|
<input
|
||||||
|
type="email"
|
||||||
|
required
|
||||||
|
value={email}
|
||||||
|
onChange={(e) => setEmail(e.target.value)}
|
||||||
|
placeholder="you@example.com"
|
||||||
|
className="w-full border rounded-md px-3 py-2 text-sm focus:outline-none focus:ring-2 focus:ring-emerald-500"
|
||||||
|
/>
|
||||||
|
</div>
|
||||||
|
<div>
|
||||||
|
<label className="block text-sm text-gray-600 mb-1">密码(至少 8 位)</label>
|
||||||
|
<input
|
||||||
|
type="password"
|
||||||
|
required
|
||||||
|
value={password}
|
||||||
|
onChange={(e) => setPassword(e.target.value)}
|
||||||
|
placeholder="••••••••"
|
||||||
|
className="w-full border rounded-md px-3 py-2 text-sm focus:outline-none focus:ring-2 focus:ring-emerald-500"
|
||||||
|
/>
|
||||||
|
</div>
|
||||||
|
{error && <div className="text-sm text-red-600">{error}</div>}
|
||||||
|
<button
|
||||||
|
type="submit"
|
||||||
|
disabled={loading}
|
||||||
|
className="w-full bg-emerald-600 text-white rounded-md py-2 text-sm font-medium hover:bg-emerald-700 disabled:opacity-50"
|
||||||
|
>
|
||||||
|
{loading ? "处理中…" : mode === "register" ? "注册并领取密钥" : "查询账号"}
|
||||||
|
</button>
|
||||||
|
</form>
|
||||||
|
|
||||||
|
{issued && <KeyReveal data={issued} />}
|
||||||
|
|
||||||
|
{info && (
|
||||||
|
<div className="mt-4 rounded-lg border bg-gray-50 p-4 text-sm text-gray-700 space-y-1.5">
|
||||||
|
<div>
|
||||||
|
邮箱:<span className="font-medium">{info.email}</span>
|
||||||
|
</div>
|
||||||
|
<div>
|
||||||
|
密钥前缀:<code className="font-mono">{info.key_prefix}…</code>
|
||||||
|
</div>
|
||||||
|
<div>
|
||||||
|
每分钟频率:<strong>{info.rate_limit_per_min}</strong> 次
|
||||||
|
</div>
|
||||||
|
<div>
|
||||||
|
累计配额:已用 <strong>{info.quota_used.toLocaleString()}</strong> /{" "}
|
||||||
|
{info.quota_total.toLocaleString()} 次(剩余{" "}
|
||||||
|
<strong className="text-emerald-600">{info.quota_remaining.toLocaleString()}</strong>)
|
||||||
|
</div>
|
||||||
|
<button
|
||||||
|
onClick={regenerate}
|
||||||
|
disabled={loading}
|
||||||
|
className="mt-2 text-emerald-600 hover:underline disabled:opacity-50"
|
||||||
|
>
|
||||||
|
忘记密钥?重置并生成新密钥
|
||||||
|
</button>
|
||||||
|
</div>
|
||||||
|
)}
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
);
|
||||||
|
}
|
||||||
@@ -102,7 +102,7 @@ function Endpoint({
|
|||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
export default function ApiDocs() {
|
export default function ApiDocs({ onRegister }: { onRegister?: () => void }) {
|
||||||
return (
|
return (
|
||||||
<div className="space-y-5">
|
<div className="space-y-5">
|
||||||
<div className="bg-white border rounded-lg p-5">
|
<div className="bg-white border rounded-lg p-5">
|
||||||
@@ -117,7 +117,11 @@ export default function ApiDocs() {
|
|||||||
基础地址:<code className="font-mono bg-gray-100 rounded px-1.5 py-0.5">{BASE}</code>
|
基础地址:<code className="font-mono bg-gray-100 rounded px-1.5 py-0.5">{BASE}</code>
|
||||||
</div>
|
</div>
|
||||||
<ul className="mt-2 list-disc pl-5 text-gray-600 space-y-1">
|
<ul className="mt-2 list-disc pl-5 text-gray-600 space-y-1">
|
||||||
<li>无需 API Key / Token 即可直接 GET;带 Key 可获得更高频率上限(见下文「鉴权与限流」)。</li>
|
<li>
|
||||||
|
无需 API Key / Token 即可直接 GET;匿名调用按来源 IP 累计共 <strong>1000</strong> 次,
|
||||||
|
用满后需<button onClick={onRegister} className="text-emerald-600 hover:underline">注册账号</button>
|
||||||
|
领取更高配额密钥(见下文「鉴权与配额」)。
|
||||||
|
</li>
|
||||||
<li>
|
<li>
|
||||||
分页参数 <code className="font-mono">page</code>(默认 1)、
|
分页参数 <code className="font-mono">page</code>(默认 1)、
|
||||||
<code className="font-mono">size</code>(默认 20,最大 100)。
|
<code className="font-mono">size</code>(默认 20,最大 100)。
|
||||||
@@ -132,10 +136,13 @@ export default function ApiDocs() {
|
|||||||
</div>
|
</div>
|
||||||
|
|
||||||
<div className="bg-white border rounded-lg p-5">
|
<div className="bg-white border rounded-lg p-5">
|
||||||
<h2 className="text-lg font-semibold text-gray-800">鉴权与限流</h2>
|
<h2 className="text-lg font-semibold text-gray-800">鉴权与配额</h2>
|
||||||
<p className="mt-2 text-gray-600 text-sm leading-relaxed">
|
<p className="mt-2 text-gray-600 text-sm leading-relaxed">
|
||||||
API 默认<strong>匿名可用</strong>:无需任何凭证即可调用,按来源 IP 计入一个较低的默认频率额度。
|
API 默认<strong>匿名可用</strong>:无需任何凭证即可调用,但按来源 IP 计一个
|
||||||
如需更高额度并让用量归属到你,可在运营方申请一枚 API Key,请求时通过请求头携带:
|
<strong>累计总配额(共 1000 次)</strong>,用满后返回
|
||||||
|
<code className="font-mono">403</code>(错误码 <code className="font-mono">quota_exhausted</code>),
|
||||||
|
需<button onClick={onRegister} className="text-emerald-600 hover:underline">注册账号</button>
|
||||||
|
自助领取更高配额的 API Key。注册得到的密钥拥有更高的每分钟频率与累计调用配额,请求时通过请求头携带:
|
||||||
</p>
|
</p>
|
||||||
<div className="mt-3">
|
<div className="mt-3">
|
||||||
<Code>{`# 二选一
|
<Code>{`# 二选一
|
||||||
@@ -143,7 +150,7 @@ curl -H "X-API-Key: og_live_xxxxxxxx" ${BASE}/products/search?q=牛奶
|
|||||||
curl -H "Authorization: Bearer og_live_xxxxxxxx" ${BASE}/products/search?q=牛奶`}</Code>
|
curl -H "Authorization: Bearer og_live_xxxxxxxx" ${BASE}/products/search?q=牛奶`}</Code>
|
||||||
</div>
|
</div>
|
||||||
<p className="mt-3 text-gray-600 text-sm leading-relaxed">
|
<p className="mt-3 text-gray-600 text-sm leading-relaxed">
|
||||||
采用<strong>固定窗口</strong>限流(每分钟)。每个响应都会回写以下响应头,便于客户端自适应:
|
同时采用<strong>每分钟固定窗口</strong>频率限制与<strong>累计总配额</strong>两层控制。每个响应都会回写以下响应头,便于客户端自适应:
|
||||||
</p>
|
</p>
|
||||||
<table className="mt-3 w-full text-sm">
|
<table className="mt-3 w-full text-sm">
|
||||||
<thead className="text-gray-400 text-left">
|
<thead className="text-gray-400 text-left">
|
||||||
@@ -169,12 +176,26 @@ curl -H "Authorization: Bearer og_live_xxxxxxxx" ${BASE}/products/search?q=牛
|
|||||||
<td className="pr-4 py-0.5 font-mono text-gray-700">Retry-After</td>
|
<td className="pr-4 py-0.5 font-mono text-gray-700">Retry-After</td>
|
||||||
<td className="py-0.5 text-gray-600">超额时返回,建议等待的秒数</td>
|
<td className="py-0.5 text-gray-600">超额时返回,建议等待的秒数</td>
|
||||||
</tr>
|
</tr>
|
||||||
|
<tr>
|
||||||
|
<td className="pr-4 py-0.5 font-mono text-gray-700">X-Quota-Limit</td>
|
||||||
|
<td className="py-0.5 text-gray-600">累计总配额上限</td>
|
||||||
|
</tr>
|
||||||
|
<tr>
|
||||||
|
<td className="pr-4 py-0.5 font-mono text-gray-700">X-Quota-Used</td>
|
||||||
|
<td className="py-0.5 text-gray-600">已累计使用的调用次数</td>
|
||||||
|
</tr>
|
||||||
|
<tr>
|
||||||
|
<td className="pr-4 py-0.5 font-mono text-gray-700">X-Quota-Remaining</td>
|
||||||
|
<td className="py-0.5 text-gray-600">累计配额剩余可用次数</td>
|
||||||
|
</tr>
|
||||||
</tbody>
|
</tbody>
|
||||||
</table>
|
</table>
|
||||||
<p className="mt-3 text-gray-600 text-sm leading-relaxed">
|
<p className="mt-3 text-gray-600 text-sm leading-relaxed">
|
||||||
超过额度返回 <code className="font-mono">429 Too Many Requests</code>,错误码
|
每分钟超额返回 <code className="font-mono">429 Too Many Requests</code>(错误码
|
||||||
<code className="font-mono">rate_limited</code>;无效或已吊销的 Key 返回
|
<code className="font-mono">rate_limited</code>);累计配额用尽返回
|
||||||
<code className="font-mono">401</code>,错误码 <code className="font-mono">invalid_api_key</code>。
|
<code className="font-mono">403</code>(错误码 <code className="font-mono">quota_exhausted</code>);
|
||||||
|
无效或已吊销的 Key 返回 <code className="font-mono">401</code>(错误码
|
||||||
|
<code className="font-mono">invalid_api_key</code>)。
|
||||||
</p>
|
</p>
|
||||||
</div>
|
</div>
|
||||||
|
|
||||||
@@ -322,6 +343,70 @@ curl -H "Authorization: Bearer og_live_xxxxxxxx" ${BASE}/products/search?q=牛
|
|||||||
}`}
|
}`}
|
||||||
/>
|
/>
|
||||||
|
|
||||||
|
<Endpoint
|
||||||
|
method="POST"
|
||||||
|
path="/api/v1/register"
|
||||||
|
title="注册账号并领取 API 密钥"
|
||||||
|
desc="用邮箱 + 密码(至少 8 位)注册,自助领取一枚更高配额的 API 密钥。明文密钥只在本次响应返回一次,请妥善保存。"
|
||||||
|
params={[
|
||||||
|
{ name: "email", required: true, desc: "邮箱(唯一)" },
|
||||||
|
{ name: "password", required: true, desc: "密码,至少 8 位" },
|
||||||
|
]}
|
||||||
|
example={`curl -X POST ${BASE}/register \\
|
||||||
|
-H "Content-Type: application/json" \\
|
||||||
|
-d '{"email":"you@example.com","password":"your-password"}'`}
|
||||||
|
response={`{
|
||||||
|
"email": "you@example.com",
|
||||||
|
"api_key": "og_live_xxxxxxxxxxxx",
|
||||||
|
"key_prefix": "og_live_xxxx",
|
||||||
|
"rate_limit_per_min": 300,
|
||||||
|
"quota_total": 100000
|
||||||
|
}`}
|
||||||
|
/>
|
||||||
|
|
||||||
|
<Endpoint
|
||||||
|
method="POST"
|
||||||
|
path="/api/v1/account"
|
||||||
|
title="查看账号与配额用量"
|
||||||
|
desc="用邮箱 + 密码查询当前密钥前缀、频率/累计配额上限及已用量(不返回明文密钥)。"
|
||||||
|
params={[
|
||||||
|
{ name: "email", required: true, desc: "注册邮箱" },
|
||||||
|
{ name: "password", required: true, desc: "账号密码" },
|
||||||
|
]}
|
||||||
|
example={`curl -X POST ${BASE}/account \\
|
||||||
|
-H "Content-Type: application/json" \\
|
||||||
|
-d '{"email":"you@example.com","password":"your-password"}'`}
|
||||||
|
response={`{
|
||||||
|
"email": "you@example.com",
|
||||||
|
"key_prefix": "og_live_xxxx",
|
||||||
|
"rate_limit_per_min": 300,
|
||||||
|
"quota_total": 100000,
|
||||||
|
"quota_used": 1234,
|
||||||
|
"quota_remaining": 98766
|
||||||
|
}`}
|
||||||
|
/>
|
||||||
|
|
||||||
|
<Endpoint
|
||||||
|
method="POST"
|
||||||
|
path="/api/v1/account/regenerate"
|
||||||
|
title="重置 API 密钥"
|
||||||
|
desc="吊销当前密钥并生成新密钥(累计用量会延续,不会因重置而清零)。明文新密钥只返回一次。"
|
||||||
|
params={[
|
||||||
|
{ name: "email", required: true, desc: "注册邮箱" },
|
||||||
|
{ name: "password", required: true, desc: "账号密码" },
|
||||||
|
]}
|
||||||
|
example={`curl -X POST ${BASE}/account/regenerate \\
|
||||||
|
-H "Content-Type: application/json" \\
|
||||||
|
-d '{"email":"you@example.com","password":"your-password"}'`}
|
||||||
|
response={`{
|
||||||
|
"email": "you@example.com",
|
||||||
|
"api_key": "og_live_yyyyyyyyyyyy",
|
||||||
|
"key_prefix": "og_live_yyyy",
|
||||||
|
"rate_limit_per_min": 300,
|
||||||
|
"quota_total": 100000
|
||||||
|
}`}
|
||||||
|
/>
|
||||||
|
|
||||||
<div className="text-xs text-gray-400 leading-relaxed">
|
<div className="text-xs text-gray-400 leading-relaxed">
|
||||||
数据可能存在误差或滞后,按「现状」提供,不构成医疗/购买建议。商品资料版权归各原始来源所有,
|
数据可能存在误差或滞后,按「现状」提供,不构成医疗/购买建议。商品资料版权归各原始来源所有,
|
||||||
请遵循其许可(如 OpenFoodFacts 的 ODbL)。
|
请遵循其许可(如 OpenFoodFacts 的 ODbL)。
|
||||||
|
|||||||
@@ -106,6 +106,23 @@ export default function ProductView({ id, onBack }: { id: string; onBack: () =>
|
|||||||
</div>
|
</div>
|
||||||
</div>
|
</div>
|
||||||
|
|
||||||
|
{p.specs && p.specs.length > 0 && (
|
||||||
|
<div className="bg-white border rounded-lg p-5 mt-4">
|
||||||
|
<h2 className="font-medium text-gray-700 mb-2">规格参数</h2>
|
||||||
|
<div className="grid grid-cols-1 sm:grid-cols-2 gap-2 text-sm">
|
||||||
|
{p.specs.map((s) => (
|
||||||
|
<div key={s.key} className="bg-gray-50 rounded px-3 py-2">
|
||||||
|
<div className="text-gray-400 text-xs">{s.label}</div>
|
||||||
|
<div className="text-gray-800">
|
||||||
|
{s.value}
|
||||||
|
{s.unit ? ` ${s.unit}` : ""}
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
))}
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
)}
|
||||||
|
|
||||||
{nutriEntries.length > 0 && (
|
{nutriEntries.length > 0 && (
|
||||||
<div className="bg-white border rounded-lg p-5 mt-4">
|
<div className="bg-white border rounded-lg p-5 mt-4">
|
||||||
<h2 className="font-medium text-gray-700 mb-2">
|
<h2 className="font-medium text-gray-700 mb-2">
|
||||||
|
|||||||
@@ -17,6 +17,13 @@ export interface Barcode {
|
|||||||
is_primary: boolean;
|
is_primary: boolean;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
export interface ProductSpec {
|
||||||
|
key: string;
|
||||||
|
label: string;
|
||||||
|
value: string;
|
||||||
|
unit?: string;
|
||||||
|
}
|
||||||
|
|
||||||
export interface Product {
|
export interface Product {
|
||||||
id: string;
|
id: string;
|
||||||
gtin: string | null;
|
gtin: string | null;
|
||||||
@@ -24,6 +31,8 @@ export interface Product {
|
|||||||
name: string;
|
name: string;
|
||||||
brand: string | null;
|
brand: string | null;
|
||||||
category_path: string | null;
|
category_path: string | null;
|
||||||
|
archive_kind?: string;
|
||||||
|
specs?: ProductSpec[] | null;
|
||||||
net_content_value: number | null;
|
net_content_value: number | null;
|
||||||
net_content_unit: string | null;
|
net_content_unit: string | null;
|
||||||
country_of_origin: string | null;
|
country_of_origin: string | null;
|
||||||
|
|||||||
Reference in New Issue
Block a user