滑动续期、网络错误归类、API Key 激活乐观锁与生效提示

This commit is contained in:
2026-08-11 11:45:03 +08:00
parent 23b2820101
commit e63af49831
21 changed files with 679 additions and 15 deletions
+13 -4
View File
@@ -10,6 +10,8 @@ import (
"fmt"
"time"
"gorm.io/gorm"
"oci-portal/internal/model"
"oci-portal/internal/oci"
)
@@ -106,7 +108,7 @@ func (s *OciConfigService) ActivateApiKey(ctx context.Context, id uint, userID,
if err := s.waitApiKeyUsable(ctx, newCred); err != nil {
return err
}
return s.persistSigningKey(cfg, newCred)
return s.persistSigningKey(ctx, cfg, newCred)
}
// waitApiKeyUsable 用新凭据测活,等待上传的公钥在 OCI 侧生效。
@@ -126,7 +128,7 @@ func (s *OciConfigService) waitApiKeyUsable(ctx context.Context, cred oci.Creden
}
// persistSigningKey 加密新私钥,更新配置签名用户与指纹并清空口令密文(面板生成的 key 无口令)。
func (s *OciConfigService) persistSigningKey(cfg *model.OciConfig, newCred oci.Credentials) error {
func (s *OciConfigService) persistSigningKey(ctx context.Context, cfg *model.OciConfig, newCred oci.Credentials) error {
enc, err := s.cipher.EncryptString(newCred.PrivateKey)
if err != nil {
return fmt.Errorf("encrypt private key: %w", err)
@@ -134,9 +136,16 @@ func (s *OciConfigService) persistSigningKey(cfg *model.OciConfig, newCred oci.C
updates := map[string]any{
"user_oc_id": newCred.UserOCID, "fingerprint": newCred.Fingerprint,
"private_key_enc": enc, "passphrase_enc": "",
// 记录激活时刻:OCI 公钥全球传播为分钟级,前端据此做窗口期提示
"key_activated_at": time.Now(),
}
if err := s.db.Model(cfg).Updates(updates).Error; err != nil {
return fmt.Errorf("persist rotated key: %w", err)
res := s.db.WithContext(ctx).Model(&model.OciConfig{}).
Where("id = ? AND updated_at = ?", cfg.ID, cfg.UpdatedAt).Updates(updates)
if res.Error != nil {
return fmt.Errorf("persist rotated key: %w", res.Error)
}
if res.RowsAffected != 1 {
return fmt.Errorf("persist rotated key: %w", gorm.ErrRecordNotFound)
}
return nil
}