Anonymous callers get a free cumulative quota (1000 calls per IP); once
exhausted they get 403 quota_exhausted and must register. Public users can
self-register (email+password) to obtain a higher-quota API key, view usage,
and regenerate the key. Quota counters live in Redis; the public API stays
read-only except for the registration writes.
- migration 0011: app_user table + api_key.quota_total + 'registered' tier
- ratelimit: IncrTotal/TotalUsed/CopyTotal lifetime counters
- middleware: enforce cumulative quota + X-Quota-* headers
- store: RegisterUser/Authenticate/RegenerateKey (bcrypt)
- handlers: POST /api/v1/register, /account, /account/regenerate
- admin: quota_total column + registered tier
- public: 'API 密钥' account page + API docs quota section
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
lixu
merged commit 3178f8a85a into main2026-06-21 15:28:59 +08:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
概述
为公开 API 增加累计总配额与公开用户注册:
403 quota_exhausted,提示注册。app_user/api_key)。后端
app_user表;api_key增加quota_total(0=不限);tier 增加registered。IncrTotal/TotalUsed/CopyTotal维护终身计数器usage:total:<subject>。X-Quota-Limit/Used/Remaining;匿名按ip:<ip>、密钥按 keyID 计量。RegisterUser/Authenticate/RegenerateKey(bcrypt 哈希、邮箱大小写不敏感唯一)。重置密钥时累计用量随CopyTotal延续,防止靠重置清零配额。POST /api/v1/register、/account、/account/regenerate(独立 IP 轻限流,不占用免费配额)。前端
测试
store:注册 / 登录 / 重置 / 邮箱占用 / 密钥吊销-轮换 全流程。handler:匿名累计配额耗尽返回 403;注册签发高配额密钥;重复邮箱冲突。go test ./... && go vet ./... && gofmt全通过;两端前端tsc && vite build通过;迁移 up/down 往返通过。