feat: persist pinned libraries per user with cross-device sync (#20)

Store pinned library IDs on the user record and expose GET/PUT
/me/pinned-libraries endpoints. The web client now loads and saves pins
through the API, migrates legacy localStorage data once, and applies
pinned ordering on both the libraries and home pages.

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: truewhile <truewhile@users.noreply.github.com>
This commit is contained in:
truewhile
2026-09-03 08:47:06 +08:00
committed by GitHub
parent 1025e3c693
commit 1e291df647
12 changed files with 367 additions and 15 deletions
+49
View File
@@ -0,0 +1,49 @@
package handler
import (
"net/http"
"github.com/gin-gonic/gin"
"github.com/truewhile/MeBox/internal/middleware"
"github.com/truewhile/MeBox/internal/service"
)
type pinnedLibrariesReq struct {
LibraryIDs []string `json:"library_ids"`
}
func getPinnedLibrariesHandler(svc *service.Container) gin.HandlerFunc {
return func(c *gin.Context) {
uid, _ := c.Get(middleware.CtxUserID)
ids, err := svc.Profile.GetPinnedLibraryIDs(c.Request.Context(), uid.(string))
if err != nil {
c.JSON(http.StatusBadRequest, gin.H{"error": err.Error()})
return
}
if ids == nil {
ids = []string{}
}
c.JSON(http.StatusOK, gin.H{"library_ids": ids})
}
}
func setPinnedLibrariesHandler(svc *service.Container) gin.HandlerFunc {
return func(c *gin.Context) {
var req pinnedLibrariesReq
if err := c.ShouldBindJSON(&req); err != nil {
c.JSON(http.StatusBadRequest, gin.H{"error": err.Error()})
return
}
uid, _ := c.Get(middleware.CtxUserID)
ids, err := svc.Profile.SetPinnedLibraryIDs(c.Request.Context(), uid.(string), req.LibraryIDs)
if err != nil {
c.JSON(http.StatusBadRequest, gin.H{"error": err.Error()})
return
}
if ids == nil {
ids = []string{}
}
c.JSON(http.StatusOK, gin.H{"library_ids": ids})
}
}
@@ -10,6 +10,8 @@ import (
func registerAuthedUserAndLicenseRoutes(authed *gin.RouterGroup, svc *service.Container) {
authed.GET("/me", meHandler(svc))
authed.PATCH("/me", updateProfileHandler(svc))
authed.GET("/me/pinned-libraries", getPinnedLibrariesHandler(svc))
authed.PUT("/me/pinned-libraries", setPinnedLibrariesHandler(svc))
authed.POST("/me/password", changePasswordHandler(svc))
authed.POST("/me/logout", logoutHandler(svc))
@@ -25,6 +25,8 @@ func TestAuthenticatedRouteSurfacesAreRegistered(t *testing.T) {
for _, want := range []string{
"GET /api/me",
"GET /api/me/pinned-libraries",
"PUT /api/me/pinned-libraries",
"GET /api/auth/permissions",
"GET /api/libraries",
"GET /api/media",
+23
View File
@@ -25,6 +25,9 @@ type User struct {
// 为空时代表不限制(全库可访问)。
AllowedLibraryIDs string `gorm:"type:text" json:"-"`
AllowedLibraryList []string `gorm:"-" json:"allowed_library_ids,omitempty"`
// PinnedLibraryIDs 存储用户置顶的媒体库 ID 列表(JSON 字符串),顺序即置顶优先级。
PinnedLibraryIDs string `gorm:"type:text" json:"-"`
PinnedLibraryList []string `gorm:"-" json:"pinned_library_ids,omitempty"`
// ExpiredAt is the account expiry time. Nil means the account never
// expires. When set and in the past, the account is treated as expired
// (login blocked) until an admin or a redemption code renews it.
@@ -59,10 +62,30 @@ func (u *User) DecodeAllowedLibraryIDs() []string {
return out
}
// DecodePinnedLibraryIDs 解析 PinnedLibraryIDs 字段。
func (u *User) DecodePinnedLibraryIDs() []string {
if u == nil || strings.TrimSpace(u.PinnedLibraryIDs) == "" {
return nil
}
var ids []string
if err := json.Unmarshal([]byte(u.PinnedLibraryIDs), &ids); err != nil {
return nil
}
var out []string
for _, id := range ids {
trimmed := strings.TrimSpace(id)
if trimmed != "" {
out = append(out, trimmed)
}
}
return out
}
// PopulateComputedFields 填充非 DB 虚拟计算字段(如 AllowedLibraryList)。
func (u *User) PopulateComputedFields() {
if u == nil {
return
}
u.AllowedLibraryList = u.DecodeAllowedLibraryIDs()
u.PinnedLibraryList = u.DecodePinnedLibraryIDs()
}
+101
View File
@@ -3,6 +3,7 @@ package service
import (
"context"
"encoding/json"
"errors"
"strings"
@@ -81,6 +82,106 @@ func (p *ProfileService) UpdateProfile(ctx context.Context, userID string, patch
return p.repo.User.FindByID(ctx, userID)
}
// GetPinnedLibraryIDs returns the user's pinned library IDs, filtered to libraries
// they can still access.
func (p *ProfileService) GetPinnedLibraryIDs(ctx context.Context, userID string) ([]string, error) {
user, err := p.repo.User.FindByID(ctx, userID)
if err != nil {
return nil, err
}
if user == nil {
return nil, errors.New("user not found")
}
visibility := UserDefaultMediaVisibility(ctx, p.repo, userID)
accessible, err := p.accessibleLibraryIDSet(ctx, visibility)
if err != nil {
return nil, err
}
return filterPinnedLibraryIDs(user.DecodePinnedLibraryIDs(), accessible), nil
}
// SetPinnedLibraryIDs persists the user's pinned library order after filtering to
// accessible, enabled libraries.
func (p *ProfileService) SetPinnedLibraryIDs(ctx context.Context, userID string, ids []string) ([]string, error) {
if userID == "" {
return nil, errors.New("missing user id")
}
user, err := p.repo.User.FindByID(ctx, userID)
if err != nil {
return nil, err
}
if user == nil {
return nil, errors.New("user not found")
}
visibility := UserDefaultMediaVisibility(ctx, p.repo, userID)
accessible, err := p.accessibleLibraryIDSet(ctx, visibility)
if err != nil {
return nil, err
}
normalized := filterPinnedLibraryIDs(normalizePinnedLibraryIDs(ids), accessible)
raw, err := json.Marshal(normalized)
if err != nil {
return nil, err
}
if err := p.repo.User.UpdateFields(ctx, userID, map[string]any{
"pinned_library_ids": string(raw),
}); err != nil {
return nil, err
}
return normalized, nil
}
func (p *ProfileService) accessibleLibraryIDSet(ctx context.Context, visibility MediaVisibility) (map[string]struct{}, error) {
libs, err := p.repo.Library.List(ctx)
if err != nil {
return nil, err
}
out := make(map[string]struct{})
for _, lib := range libs {
if !lib.Enabled {
continue
}
if !LibraryVisibleForUser(ctx, p.repo, lib, visibility) {
continue
}
out[lib.ID] = struct{}{}
}
return out, nil
}
func normalizePinnedLibraryIDs(ids []string) []string {
if len(ids) == 0 {
return nil
}
seen := make(map[string]struct{}, len(ids))
out := make([]string, 0, len(ids))
for _, id := range ids {
trimmed := strings.TrimSpace(id)
if trimmed == "" {
continue
}
if _, ok := seen[trimmed]; ok {
continue
}
seen[trimmed] = struct{}{}
out = append(out, trimmed)
}
return out
}
func filterPinnedLibraryIDs(ids []string, accessible map[string]struct{}) []string {
if len(ids) == 0 {
return nil
}
out := make([]string, 0, len(ids))
for _, id := range ids {
if _, ok := accessible[id]; ok {
out = append(out, id)
}
}
return out
}
// AdminUpdateRole lets administrators promote / demote another user. The
// caller is expected to gate the route with AdminRequired.
func (p *ProfileService) AdminUpdateRole(ctx context.Context, userID, role string) (*model.User, error) {
+61
View File
@@ -0,0 +1,61 @@
package service
import (
"testing"
"github.com/glebarez/sqlite"
"gorm.io/gorm"
"github.com/truewhile/MeBox/internal/model"
"github.com/truewhile/MeBox/internal/repository"
"go.uber.org/zap"
)
func TestProfilePinnedLibrariesFiltersInaccessibleAndPreservesOrder(t *testing.T) {
db, err := gorm.Open(sqlite.Open(":memory:"), &gorm.Config{})
if err != nil {
t.Fatal(err)
}
if err := db.AutoMigrate(&model.User{}, &model.Library{}); err != nil {
t.Fatal(err)
}
repos := repository.New(db)
svc := NewProfileService(zap.NewNop(), repos)
user := &model.User{Username: "viewer", PasswordHash: "hash", Role: "user"}
if err := repos.User.Create(t.Context(), user); err != nil {
t.Fatal(err)
}
libA := &model.Library{Name: "Movies", Path: "/media/movies", Type: "movie", Enabled: true}
libB := &model.Library{Name: "TV", Path: "/media/tv", Type: "tv", Enabled: true}
libHidden := &model.Library{Name: "Adult", Path: "/media/adult", Type: "movie", Enabled: true}
for _, lib := range []*model.Library{libA, libB, libHidden} {
if err := repos.Library.Create(t.Context(), lib); err != nil {
t.Fatal(err)
}
}
if err := repos.User.UpdateFields(t.Context(), user.ID, map[string]any{
"allowed_library_ids": `["` + libA.ID + `","` + libB.ID + `"]`,
}); err != nil {
t.Fatal(err)
}
got, err := svc.SetPinnedLibraryIDs(t.Context(), user.ID, []string{
libB.ID, libHidden.ID, libA.ID, libB.ID, "missing",
})
if err != nil {
t.Fatalf("SetPinnedLibraryIDs: %v", err)
}
want := []string{libB.ID, libA.ID}
if len(got) != len(want) || got[0] != want[0] || got[1] != want[1] {
t.Fatalf("SetPinnedLibraryIDs = %v, want %v", got, want)
}
loaded, err := svc.GetPinnedLibraryIDs(t.Context(), user.ID)
if err != nil {
t.Fatalf("GetPinnedLibraryIDs: %v", err)
}
if len(loaded) != len(want) || loaded[0] != want[0] || loaded[1] != want[1] {
t.Fatalf("GetPinnedLibraryIDs = %v, want %v", loaded, want)
}
}