feat(auth): implement decoupled sliding-window rate limiting for login and oauth

This commit is contained in:
ryan
2026-09-02 22:15:21 +08:00
parent 39f02b5d7a
commit 9632604958
23 changed files with 927 additions and 50 deletions
+22 -2
View File
@@ -18,8 +18,10 @@ import (
)
var (
dbMu sync.RWMutex
dbSvc contracts.DBService
dbMu sync.RWMutex
dbSvc contracts.DBService
limiterMu sync.RWMutex
limiterSvc contracts.LimiterService
)
// SetDBService sets the active DBService contract for the user domain plugin.
@@ -29,6 +31,13 @@ func SetDBService(s contracts.DBService) {
dbSvc = s
}
// SetLimiterService sets the active LimiterService contract for the user domain plugin.
func SetLimiterService(s contracts.LimiterService) {
limiterMu.Lock()
defer limiterMu.Unlock()
limiterSvc = s
}
func getDB(ctx context.Context) *gorm.DB {
if s, err := core.InjectFrom[contracts.DBService](ctx); err == nil && s != nil {
return s.DB(ctx)
@@ -44,6 +53,17 @@ func getDB(ctx context.Context) *gorm.DB {
return nil
}
func getLimiter(ctx context.Context) contracts.LimiterService {
if s, err := core.InjectFrom[contracts.LimiterService](ctx); err == nil && s != nil {
return s
}
limiterMu.RLock()
s := limiterSvc
limiterMu.RUnlock()
return s
}
// GetUserByID 通过 ID 获取用户
func GetUserByID(ctx context.Context, id uint64) (*User, error) {
var u User