feat(compose): 正文内嵌隐藏块并升级 Markdown 编辑器

去掉整帖可见性表单,改为 :::hide 按块脱敏;工具栏补齐代码块、链接/图片对话框与粘贴拖拽上传。

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
2026-09-17 04:58:20 +08:00
parent d1155cbd64
commit 01e2fd05ca
19 changed files with 1867 additions and 471 deletions

View File

@@ -96,8 +96,6 @@ type CreatePostRequest struct {
Content string `json:"content" binding:"required,min=1"`
Tags string `json:"tags"`
PostType string `json:"post_type"`
ContentAccess string `json:"content_access"`
AccessPoints int `json:"access_points"`
TypeMeta string `json:"type_meta"`
AttachmentIDs []uint `json:"attachment_ids"`
}
@@ -118,8 +116,6 @@ func (h *Handlers) CreatePost(c *gin.Context) {
Content: req.Content,
Tags: req.Tags,
PostType: req.PostType,
ContentAccess: req.ContentAccess,
AccessPoints: req.AccessPoints,
TypeMeta: req.TypeMeta,
Status: status,
AttachmentIDs: req.AttachmentIDs,
@@ -141,8 +137,6 @@ type UpdatePostRequest struct {
Title string `json:"title" binding:"omitempty,min=1,max=256"`
Content string `json:"content" binding:"omitempty,min=1"`
Tags string `json:"tags"`
ContentAccess *string `json:"content_access"`
AccessPoints *int `json:"access_points"`
TypeMeta *string `json:"type_meta"`
AttachmentIDs *[]uint `json:"attachment_ids"`
}
@@ -165,8 +159,6 @@ func (h *Handlers) UpdatePost(c *gin.Context) {
Title: req.Title,
Content: req.Content,
Tags: req.Tags,
ContentAccess: req.ContentAccess,
AccessPoints: req.AccessPoints,
TypeMeta: req.TypeMeta,
AttachmentIDs: req.AttachmentIDs,
})

324
backend/markdown/hide.go Normal file
View File

@@ -0,0 +1,324 @@
// Package markdown 提供帖子正文隐藏块(:::hide)的解析、校验与脱敏。
package markdown
import (
"errors"
"fmt"
"strconv"
"strings"
)
const (
HideKindLogin = "login"
HideKindReply = "reply"
HideKindPoints = "points"
)
// HideBlock 正文中的一段隐藏内容
type HideBlock struct {
Kind string // login | reply | points
Points int // 仅 points 有效
Body string // 块内 Markdown(不含开闭标记行)
Start int // 开标记行在 lines 中的下标
End int // 闭标记行在 lines 中的下标(含)
Locked bool // 开标记是否已带 locked(脱敏输出)
}
// DerivedAccess 由正文隐藏块派生的帖级可见性
type DerivedAccess struct {
Access string // public | login | reply | points | mixed
Points int // 所有积分块价格之和
}
// ViewerCaps 读者对隐藏块的能力(由 service 填充)
type ViewerCaps struct {
Bypass bool // 作者 / 版主
LoggedIn bool
HasReplied bool
PointsPaid bool // 已支付本帖积分解锁
}
var (
ErrHideNested = errors.New("隐藏块不可嵌套")
ErrHideUnclosed = errors.New("隐藏块未正确闭合")
ErrHideInvalid = errors.New("隐藏块语法无效")
ErrHidePointsNeed = errors.New("积分可见块须指定 1–100000 的积分")
)
// ParseHideBlocks 扫描正文中的 :::hide 块(忽略代码围栏内伪语法)。
// 校验失败返回 error(用于 Create/Update)。
func ParseHideBlocks(content string) ([]HideBlock, error) {
lines := splitLines(content)
var blocks []HideBlock
inCode := false
i := 0
for i < len(lines) {
trimmed := strings.TrimSpace(lines[i])
if strings.HasPrefix(trimmed, "```") {
inCode = !inCode
i++
continue
}
if inCode {
i++
continue
}
if kind, pts, locked, ok := parseOpenMarker(trimmed); ok {
j := i + 1
bodyLines := make([]string, 0)
foundClose := false
innerCode := false
for j < len(lines) {
inner := strings.TrimSpace(lines[j])
if strings.HasPrefix(inner, "```") {
innerCode = !innerCode
bodyLines = append(bodyLines, lines[j])
j++
continue
}
if innerCode {
bodyLines = append(bodyLines, lines[j])
j++
continue
}
if _, _, _, isOpen := parseOpenMarker(inner); isOpen {
return nil, ErrHideNested
}
if isCloseMarker(inner) {
foundClose = true
break
}
bodyLines = append(bodyLines, lines[j])
j++
}
if !foundClose {
return nil, ErrHideUnclosed
}
if kind == HideKindPoints {
if pts < 1 || pts > 100000 {
return nil, ErrHidePointsNeed
}
}
blocks = append(blocks, HideBlock{
Kind: kind,
Points: pts,
Body: strings.Join(bodyLines, "\n"),
Start: i,
End: j,
Locked: locked,
})
i = j + 1
continue
}
if isCloseMarker(trimmed) {
return nil, ErrHideInvalid
}
i++
}
return blocks, nil
}
// DeriveAccess 由隐藏块列表派生帖级 content_access / access_points
func DeriveAccess(blocks []HideBlock) DerivedAccess {
if len(blocks) == 0 {
return DerivedAccess{Access: "public", Points: 0}
}
kinds := map[string]struct{}{}
totalPts := 0
for _, b := range blocks {
kinds[b.Kind] = struct{}{}
if b.Kind == HideKindPoints {
totalPts += b.Points
}
}
if len(kinds) > 1 {
return DerivedAccess{Access: "mixed", Points: totalPts}
}
for k := range kinds {
return DerivedAccess{Access: k, Points: totalPts}
}
return DerivedAccess{Access: "public", Points: 0}
}
// DeriveAccessFromContent 解析并派生;校验失败返回 error
func DeriveAccessFromContent(content string) (DerivedAccess, error) {
blocks, err := ParseHideBlocks(content)
if err != nil {
return DerivedAccess{}, err
}
return DeriveAccess(blocks), nil
}
// SanitizeForViewer 按读者能力脱敏:未满足条件的块清空正文并加 locked。
// fullyLocked 表示读者当前看不到任何可见正文(整篇都在锁块里或公开区为空)。
func SanitizeForViewer(content string, caps ViewerCaps) (sanitized string, fullyLocked bool) {
blocks, err := ParseHideBlocks(content)
if err != nil {
return "", true
}
if len(blocks) == 0 {
return content, strings.TrimSpace(content) == ""
}
if caps.Bypass {
return content, false
}
lines := splitLines(content)
var out []string
cursor := 0
anyVisible := false
for _, b := range blocks {
for i := cursor; i < b.Start; i++ {
out = append(out, lines[i])
if strings.TrimSpace(lines[i]) != "" {
anyVisible = true
}
}
if blockUnlocked(b, caps) {
out = append(out, openMarkerLine(b.Kind, b.Points, false))
if b.Body != "" {
out = append(out, splitLines(b.Body)...)
if strings.TrimSpace(b.Body) != "" {
anyVisible = true
}
}
out = append(out, ":::")
} else {
out = append(out, openMarkerLine(b.Kind, b.Points, true))
out = append(out, ":::")
}
cursor = b.End + 1
}
for i := cursor; i < len(lines); i++ {
out = append(out, lines[i])
if strings.TrimSpace(lines[i]) != "" {
anyVisible = true
}
}
return strings.Join(out, "\n"), !anyVisible
}
// WrapContentAsHide 将整篇正文包进单一隐藏块(旧帖迁移用)
func WrapContentAsHide(kind string, points int, content string) string {
body := strings.TrimRight(content, "\n")
open := openMarkerLine(kind, points, false)
if body == "" {
return open + "\n:::\n"
}
return open + "\n" + body + "\n:::\n"
}
// HasHideBlocks 快速判断正文是否已含隐藏块(迁移幂等)
func HasHideBlocks(content string) bool {
blocks, err := ParseHideBlocks(content)
if err != nil {
return strings.Contains(content, ":::hide")
}
return len(blocks) > 0
}
func blockUnlocked(b HideBlock, caps ViewerCaps) bool {
switch b.Kind {
case HideKindLogin:
return caps.LoggedIn
case HideKindReply:
return caps.HasReplied
case HideKindPoints:
return caps.PointsPaid
default:
return true
}
}
func openMarkerLine(kind string, points int, locked bool) string {
var b strings.Builder
b.WriteString(":::hide ")
b.WriteString(kind)
if kind == HideKindPoints && points > 0 {
b.WriteByte(' ')
b.WriteString(strconv.Itoa(points))
}
if locked {
b.WriteString(" locked")
}
return b.String()
}
func parseOpenMarker(trimmed string) (kind string, points int, locked bool, ok bool) {
if !strings.HasPrefix(trimmed, ":::hide") {
return "", 0, false, false
}
rest := strings.TrimSpace(trimmed[len(":::hide"):])
if rest == "" {
return "", 0, false, false
}
parts := strings.Fields(rest)
if len(parts) == 0 {
return "", 0, false, false
}
kind = parts[0]
switch kind {
case HideKindLogin, HideKindReply, HideKindPoints:
default:
return "", 0, false, false
}
idx := 1
if kind == HideKindPoints {
if idx >= len(parts) {
return "", 0, false, false
}
n, err := strconv.Atoi(parts[idx])
if err != nil {
return "", 0, false, false
}
points = n
idx++
}
for ; idx < len(parts); idx++ {
if parts[idx] == "locked" {
locked = true
} else {
return "", 0, false, false
}
}
return kind, points, locked, true
}
func isCloseMarker(trimmed string) bool {
return trimmed == ":::"
}
func splitLines(s string) []string {
if s == "" {
return []string{}
}
s = strings.ReplaceAll(s, "\r\n", "\n")
s = strings.ReplaceAll(s, "\r", "\n")
return strings.Split(s, "\n")
}
// ValidateHideContent 校验正文隐藏块;失败返回用户可读错误
func ValidateHideContent(content string) error {
_, err := ParseHideBlocks(content)
if err == nil {
return nil
}
switch {
case errors.Is(err, ErrHideNested):
return fmt.Errorf("隐藏块不可嵌套")
case errors.Is(err, ErrHideUnclosed):
return fmt.Errorf("隐藏块未正确闭合,请检查 ::: 标记")
case errors.Is(err, ErrHidePointsNeed):
return fmt.Errorf("积分可见块须指定 1–100000 的积分")
case errors.Is(err, ErrHideInvalid):
return fmt.Errorf("隐藏块语法无效")
default:
return err
}
}

View File

@@ -0,0 +1,122 @@
package markdown
import (
"strings"
"testing"
)
func TestParseIgnoreCodeFence(t *testing.T) {
src := "公开\n\n```\n:::hide login\n假的\n:::\n```\n\n结尾\n"
blocks, err := ParseHideBlocks(src)
if err != nil {
t.Fatal(err)
}
if len(blocks) != 0 {
t.Fatalf("expected 0 blocks, got %d", len(blocks))
}
}
func TestParseMixedAndDerive(t *testing.T) {
src := "公开段\n\n:::hide login\n登录内容\n:::\n\n:::hide points 10\n积分A\n:::\n\n:::hide points 5\n积分B\n:::\n"
blocks, err := ParseHideBlocks(src)
if err != nil {
t.Fatal(err)
}
if len(blocks) != 3 {
t.Fatalf("expected 3 blocks, got %d", len(blocks))
}
d := DeriveAccess(blocks)
if d.Access != "mixed" {
t.Fatalf("access=%s", d.Access)
}
if d.Points != 15 {
t.Fatalf("points=%d", d.Points)
}
}
func TestParseNestedRejected(t *testing.T) {
src := ":::hide login\n外\n:::hide reply\n内\n:::\n:::\n"
_, err := ParseHideBlocks(src)
if err != ErrHideNested {
t.Fatalf("want ErrHideNested, got %v", err)
}
}
func TestSanitizeLocksBody(t *testing.T) {
src := "公开\n\n:::hide login\n秘密内容\n:::\n\n尾\n"
out, fully := SanitizeForViewer(src, ViewerCaps{})
if fully {
t.Fatal("should not be fully locked")
}
if strings.Contains(out, "秘密内容") {
t.Fatalf("leaked: %q", out)
}
if !strings.Contains(out, ":::hide login locked") {
t.Fatalf("missing locked marker: %q", out)
}
if !strings.Contains(out, "公开") || !strings.Contains(out, "尾") {
t.Fatalf("public parts lost: %q", out)
}
}
func TestSanitizeUnlockLogin(t *testing.T) {
src := ":::hide login\n秘密\n:::\n"
out, fully := SanitizeForViewer(src, ViewerCaps{LoggedIn: true})
if fully {
t.Fatal("should see content")
}
if !strings.Contains(out, "秘密") {
t.Fatalf("missing body: %q", out)
}
if strings.Contains(out, "locked") {
t.Fatalf("should not lock: %q", out)
}
}
func TestSanitizeBypass(t *testing.T) {
src := ":::hide points 9\n付费\n:::\n"
out, _ := SanitizeForViewer(src, ViewerCaps{Bypass: true})
if !strings.Contains(out, "付费") {
t.Fatalf("bypass failed: %q", out)
}
}
func TestSanitizePointsPaid(t *testing.T) {
src := ":::hide points 3\n付费文\n:::\n"
out, _ := SanitizeForViewer(src, ViewerCaps{LoggedIn: true, PointsPaid: true})
if !strings.Contains(out, "付费文") {
t.Fatalf("paid unlock failed: %q", out)
}
}
func TestFullyLocked(t *testing.T) {
src := ":::hide reply\n仅回复\n:::\n"
_, fully := SanitizeForViewer(src, ViewerCaps{LoggedIn: true})
if !fully {
t.Fatal("expected fully locked")
}
}
func TestCodeInsideHide(t *testing.T) {
src := ":::hide login\n```\n:::hide reply\n伪\n:::\n```\n真\n:::\n"
blocks, err := ParseHideBlocks(src)
if err != nil {
t.Fatal(err)
}
if len(blocks) != 1 {
t.Fatalf("got %d", len(blocks))
}
if !strings.Contains(blocks[0].Body, "真") {
t.Fatalf("body=%q", blocks[0].Body)
}
}
func TestWrapContentAsHide(t *testing.T) {
got := WrapContentAsHide("points", 20, "旧正文")
if !strings.HasPrefix(got, ":::hide points 20\n") {
t.Fatalf("%q", got)
}
if !strings.Contains(got, "旧正文") {
t.Fatal(got)
}
}

View File

@@ -7,6 +7,7 @@ import (
"fmt"
"log"
"github.com/freefire/jiang13-bbs/markdown"
"gorm.io/driver/postgres"
"gorm.io/gorm"
"gorm.io/gorm/logger"
@@ -45,6 +46,11 @@ func InitDB(dsn string) error {
return fmt.Errorf("自动迁移失败: %w", err)
}
// 旧帖整帖可见性 → 正文 :::hide 块(幂等)
if err := migratePostContentAccessToHideBlocks(db); err != nil {
return fmt.Errorf("正文隐藏块迁移失败: %w", err)
}
// 一次性:用签到累计回填 User.Points(仅余额仍为 0 且有签到积分的用户)
if err := backfillPointsFromCheckin(db); err != nil {
return fmt.Errorf("积分余额回填失败: %w", err)
@@ -365,3 +371,39 @@ func ensureDefaultChatMemberships(db *gorm.DB) error {
}
return nil
}
// migratePostContentAccessToHideBlocks 将旧帖整帖可见性包进 :::hide 块(幂等)。
func migratePostContentAccessToHideBlocks(db *gorm.DB) error {
var posts []Post
if err := db.Unscoped().
Where("content_access IN ? AND deleted_at IS NULL",
[]string{ContentAccessLogin, ContentAccessReply, ContentAccessPoints}).
Find(&posts).Error; err != nil {
return err
}
n := 0
for i := range posts {
p := &posts[i]
if markdown.HasHideBlocks(p.Content) {
continue
}
kind := NormalizeContentAccess(p.ContentAccess)
pts := 0
if kind == ContentAccessPoints {
pts = p.AccessPoints
if pts <= 0 {
pts = 1
}
}
wrapped := markdown.WrapContentAsHide(kind, pts, p.Content)
if err := db.Model(&Post{}).Where("id = ?", p.ID).
Update("content", wrapped).Error; err != nil {
return err
}
n++
}
if n > 0 {
log.Printf("[model] 旧帖可见性已迁入隐藏块:%d 篇", n)
}
return nil
}

View File

@@ -80,18 +80,19 @@ func NormalizePostType(t string) string {
return PostTypeDiscussion
}
// 正文可见性
// 正文可见性(由正文 :::hide 块派生;mixed = 多种隐藏类型并存)
const (
ContentAccessPublic = "public" // 公开
ContentAccessLogin = "login" // 登录可见
ContentAccessReply = "reply" // 回复可见
ContentAccessPoints = "points" // 积分购买可见
ContentAccessLogin = "login" // 仅登录可见块
ContentAccessReply = "reply" // 仅回复可见块
ContentAccessPoints = "points" // 仅积分可见块
ContentAccessMixed = "mixed" // 多种隐藏块混合
)
// ValidContentAccess 可见性白名单
func ValidContentAccess(a string) bool {
switch a {
case ContentAccessPublic, ContentAccessLogin, ContentAccessReply, ContentAccessPoints:
case ContentAccessPublic, ContentAccessLogin, ContentAccessReply, ContentAccessPoints, ContentAccessMixed:
return true
}
return false
@@ -120,8 +121,8 @@ type User struct {
Role Role `gorm:"size:16;default:user" json:"role"`
Banned bool `gorm:"default:false" json:"banned"`
Points int `gorm:"not null;default:0" json:"points"` // 可用积分余额
TokenVersion int `gorm:"default:0" json:"-"` // token 版本号,改密码/封禁时递增使旧 JWT 失效
LastSeenAt *time.Time `gorm:"index" json:"-"` // 最近活跃时间(在线统计,限频更新)
TokenVersion int `gorm:"default:0" json:"-"` // token 版本号,改密码/封禁时递增使旧 JWT 失效
LastSeenAt *time.Time `gorm:"index" json:"-"` // 最近活跃时间(在线统计,限频更新)
CreatedAt time.Time `json:"created_at"`
UpdatedAt time.Time `json:"updated_at"`
DeletedAt gorm.DeletedAt `gorm:"index" json:"-"`
@@ -160,30 +161,30 @@ type Board struct {
// Post 帖子
type Post struct {
ID uint `gorm:"primaryKey" json:"id"`
BoardID uint `gorm:"index;not null" json:"board_id"`
UserID uint `gorm:"index;not null" json:"user_id"`
Title string `gorm:"size:256;not null" json:"title"`
Content string `gorm:"type:text;not null" json:"content"`
Tags string `gorm:"size:256" json:"tags"`
PostType string `gorm:"size:16;default:discussion;index" json:"post_type"`
ContentAccess string `gorm:"size:16;default:public;index" json:"content_access"` // public|login|reply|points
AccessPoints int `gorm:"not null;default:0" json:"access_points"` // points 可见时所需积分
TypeMeta string `gorm:"type:text;default:''" json:"type_meta"` // 类型扩展 JSON(投票/悬赏/抽奖壳)
Pinned int `gorm:"default:0" json:"pinned"`
Recommended bool `gorm:"default:false;index" json:"recommended"`
Status string `gorm:"size:16;default:published;index" json:"status"`
LikeCount int `gorm:"default:0" json:"like_count"`
ViewCount int `gorm:"default:0" json:"view_count"`
CommentCount int `gorm:"default:0" json:"comment_count"`
Liked bool `gorm:"-" json:"liked"` // 当前用户是否已点赞(展示字段,不入库)
ID uint `gorm:"primaryKey" json:"id"`
BoardID uint `gorm:"index;not null" json:"board_id"`
UserID uint `gorm:"index;not null" json:"user_id"`
Title string `gorm:"size:256;not null" json:"title"`
Content string `gorm:"type:text;not null" json:"content"`
Tags string `gorm:"size:256" json:"tags"`
PostType string `gorm:"size:16;default:discussion;index" json:"post_type"`
ContentAccess string `gorm:"size:16;default:public;index" json:"content_access"` // public|login|reply|points|mixed(由正文隐藏块派生)
AccessPoints int `gorm:"not null;default:0" json:"access_points"` // 积分隐藏块价格之和
TypeMeta string `gorm:"type:text;default:''" json:"type_meta"` // 类型扩展 JSON(投票/悬赏/抽奖壳)
Pinned int `gorm:"default:0" json:"pinned"`
Recommended bool `gorm:"default:false;index" json:"recommended"`
Status string `gorm:"size:16;default:published;index" json:"status"`
LikeCount int `gorm:"default:0" json:"like_count"`
ViewCount int `gorm:"default:0" json:"view_count"`
CommentCount int `gorm:"default:0" json:"comment_count"`
Liked bool `gorm:"-" json:"liked"` // 当前用户是否已点赞(展示字段,不入库)
// 软删元数据:列表仍排除;详情 Unscoped 可读作 tombstone 页
DeleteType string `gorm:"size:32;default:''" json:"delete_type,omitempty"`
DeleteReason string `gorm:"size:256;default:''" json:"delete_reason,omitempty"`
DeletedBy uint `gorm:"not null;default:0" json:"deleted_by,omitempty"` // 执行删除者;与 UserID 不同即为管理删除
CreatedAt time.Time `json:"created_at"`
UpdatedAt time.Time `json:"updated_at"`
DeletedAt gorm.DeletedAt `gorm:"index" json:"-"`
DeleteType string `gorm:"size:32;default:''" json:"delete_type,omitempty"`
DeleteReason string `gorm:"size:256;default:''" json:"delete_reason,omitempty"`
DeletedBy uint `gorm:"not null;default:0" json:"deleted_by,omitempty"` // 执行删除者;与 UserID 不同即为管理删除
CreatedAt time.Time `json:"created_at"`
UpdatedAt time.Time `json:"updated_at"`
DeletedAt gorm.DeletedAt `gorm:"index" json:"-"`
Board Board `gorm:"foreignKey:BoardID" json:"board,omitempty"`
User User `gorm:"foreignKey:UserID" json:"user,omitempty"`
@@ -241,13 +242,13 @@ type PointLedger struct {
// 积分流水原因
const (
PointReasonCheckin = "checkin"
PointReasonUnlockPost = "unlock_post"
PointReasonDownloadFile = "download_file"
PointReasonMigrateCheckin = "migrate_checkin"
PointReasonBountyEscrow = "bounty_escrow"
PointReasonBountyRefund = "bounty_refund"
PointReasonBountyAward = "bounty_award"
PointReasonCheckin = "checkin"
PointReasonUnlockPost = "unlock_post"
PointReasonDownloadFile = "download_file"
PointReasonMigrateCheckin = "migrate_checkin"
PointReasonBountyEscrow = "bounty_escrow"
PointReasonBountyRefund = "bounty_refund"
PointReasonBountyAward = "bounty_award"
)
// PostPollVote 投票记录(多选时同一用户多行)
@@ -280,17 +281,17 @@ type PostContentUnlock struct {
// PostAttachment 帖子文件附件(不走公开静态目录,经 API 鉴权下载)
type PostAttachment struct {
ID uint `gorm:"primaryKey" json:"id"`
PostID uint `gorm:"index;not null;default:0" json:"post_id"` // 0=草稿未绑定
UserID uint `gorm:"index;not null" json:"user_id"`
Name string `gorm:"size:256;not null" json:"name"` // 原始文件名
StoredName string `gorm:"size:64;not null" json:"-"` // 磁盘文件名
MIME string `gorm:"size:128;not null;default:application/octet-stream" json:"mime"`
Size int `gorm:"not null;default:0" json:"size"`
PricePoints int `gorm:"not null;default:0" json:"price_points"` // 0=免费
DownloadCount int `gorm:"not null;default:0" json:"download_count"`
CreatedAt time.Time `json:"created_at"`
DeletedAt gorm.DeletedAt `gorm:"index" json:"-"`
ID uint `gorm:"primaryKey" json:"id"`
PostID uint `gorm:"index;not null;default:0" json:"post_id"` // 0=草稿未绑定
UserID uint `gorm:"index;not null" json:"user_id"`
Name string `gorm:"size:256;not null" json:"name"` // 原始文件名
StoredName string `gorm:"size:64;not null" json:"-"` // 磁盘文件名
MIME string `gorm:"size:128;not null;default:application/octet-stream" json:"mime"`
Size int `gorm:"not null;default:0" json:"size"`
PricePoints int `gorm:"not null;default:0" json:"price_points"` // 0=免费
DownloadCount int `gorm:"not null;default:0" json:"download_count"`
CreatedAt time.Time `json:"created_at"`
DeletedAt gorm.DeletedAt `gorm:"index" json:"-"`
}
// PostAttachmentUnlock 积分附件下载解锁(按附件计费一次)
@@ -304,18 +305,18 @@ type PostAttachmentUnlock struct {
// Comment 评论(主评论 = 楼层,ParentID 为空;子评论挂 root_id 对应楼层下)
type Comment struct {
ID uint `gorm:"primaryKey" json:"id"`
PostID uint `gorm:"index;not null" json:"post_id"`
UserID uint `gorm:"index;not null" json:"user_id,omitempty"`
ParentID *uint `gorm:"index" json:"parent_id"` // 父评论 ID,NULL = 主评论(楼层)
RootID *uint `gorm:"index" json:"root_id"` // 所属楼层(顶层主评论)ID,子评论必填
Depth int `gorm:"not null;default:0" json:"depth"` // 层级:主评论 0,子评论 = 父 + 1
Content string `gorm:"type:text;not null" json:"content"`
Status string `gorm:"size:16;default:published;index" json:"status"`
ID uint `gorm:"primaryKey" json:"id"`
PostID uint `gorm:"index;not null" json:"post_id"`
UserID uint `gorm:"index;not null" json:"user_id,omitempty"`
ParentID *uint `gorm:"index" json:"parent_id"` // 父评论 ID,NULL = 主评论(楼层)
RootID *uint `gorm:"index" json:"root_id"` // 所属楼层(顶层主评论)ID,子评论必填
Depth int `gorm:"not null;default:0" json:"depth"` // 层级:主评论 0,子评论 = 父 + 1
Content string `gorm:"type:text;not null" json:"content"`
Status string `gorm:"size:16;default:published;index" json:"status"`
// 软删元数据:列表 Unscoped 作 tombstone;DeletedBy≠UserID 为管理删除
DeleteType string `gorm:"size:32;default:''" json:"delete_type,omitempty"`
DeleteReason string `gorm:"size:256;default:''" json:"delete_reason,omitempty"`
DeletedBy uint `gorm:"not null;default:0" json:"deleted_by,omitempty"`
DeleteType string `gorm:"size:32;default:''" json:"delete_type,omitempty"`
DeleteReason string `gorm:"size:256;default:''" json:"delete_reason,omitempty"`
DeletedBy uint `gorm:"not null;default:0" json:"deleted_by,omitempty"`
CreatedAt time.Time `json:"created_at"`
UpdatedAt time.Time `json:"updated_at"`
DeletedAt gorm.DeletedAt `gorm:"index" json:"-"`
@@ -469,7 +470,7 @@ type ChatRoom struct {
Description string `gorm:"size:256;not null;default:''" json:"description"`
OwnerID uint `gorm:"index;not null" json:"owner_id"`
RoomType string `gorm:"size:16;not null;default:group;index" json:"room_type"` // group | direct
DirectKey string `gorm:"size:64;not null;default:'';index" json:"-"` // 私聊双方 ID 排序键 "min:max"
DirectKey string `gorm:"size:64;not null;default:'';index" json:"-"` // 私聊双方 ID 排序键 "min:max"
IsPrivate bool `gorm:"not null;default:false;index" json:"is_private"`
IsDefault bool `gorm:"not null;default:false;index" json:"is_default"`
MemberCount int `gorm:"not null;default:0" json:"member_count"`
@@ -495,7 +496,7 @@ type ChatRoomMember struct {
Role string `gorm:"size:16;not null;default:member" json:"role"`
LastReadMessageID uint `gorm:"not null;default:0" json:"last_read_message_id"`
Muted bool `gorm:"not null;default:false" json:"muted"` // 被群主禁言
PinnedAt *time.Time `json:"pinned_at,omitempty"` // 该用户个人置顶时间;大厅强制置顶不依赖此字段
PinnedAt *time.Time `json:"pinned_at,omitempty"` // 该用户个人置顶时间;大厅强制置顶不依赖此字段
CreatedAt time.Time `json:"created_at"`
UpdatedAt time.Time `json:"updated_at"`
@@ -508,15 +509,15 @@ type ChatMessage struct {
RoomID uint `gorm:"index:idx_chat_room_created,priority:1;not null" json:"room_id"`
SenderID uint `gorm:"index;not null" json:"sender_id"`
Content string `gorm:"type:varchar(2000);not null" json:"content"`
ReplyToID uint `gorm:"not null;default:0;index" json:"reply_to_id"` // 引用的消息 ID,0 表示无引用
ReplyToID uint `gorm:"not null;default:0;index" json:"reply_to_id"` // 引用的消息 ID,0 表示无引用
ReplySnap string `gorm:"size:512;not null;default:''" json:"reply_snap"` // 引用快照「昵称: 摘要」,原文撤回后仍可展示
MentionIDs string `gorm:"size:512;not null;default:''" json:"-"` // 被@用户 ID 逗号分隔(落通知用)
MentionIDs string `gorm:"size:512;not null;default:''" json:"-"` // 被@用户 ID 逗号分隔(落通知用)
RecalledAt *time.Time `json:"recalled_at,omitempty"`
RecalledBy uint `gorm:"not null;default:0" json:"recalled_by"`
CreatedAt time.Time `gorm:"index:idx_chat_room_created,priority:2" json:"created_at"`
DeletedAt gorm.DeletedAt `gorm:"index" json:"-"`
Sender User `gorm:"foreignKey:SenderID" json:"sender,omitempty"`
Sender User `gorm:"foreignKey:SenderID" json:"sender,omitempty"`
// RecalledBy=0 时不建 FK;Preload 仅用于已撤回消息展示撤回者昵称
Recaller *User `gorm:"foreignKey:RecalledBy;constraint:-" json:"recaller,omitempty"`
}

View File

@@ -6,6 +6,7 @@ import (
"strings"
"time"
"github.com/freefire/jiang13-bbs/markdown"
"github.com/freefire/jiang13-bbs/model"
"gorm.io/gorm"
)
@@ -402,7 +403,7 @@ type PostDetail struct {
DeletedAt *time.Time `json:"deleted_at,omitempty"`
}
// CreatePostInput 发帖入参
// CreatePostInput 发帖入参(content_access / access_points 由正文 :::hide 派生)
type CreatePostInput struct {
UserID uint
BoardID uint
@@ -410,8 +411,6 @@ type CreatePostInput struct {
Content string
Tags string
PostType string
ContentAccess string
AccessPoints int
TypeMeta string
Status string
AttachmentIDs []uint
@@ -422,8 +421,6 @@ type UpdatePostInput struct {
Title string
Content string
Tags string
ContentAccess *string
AccessPoints *int
TypeMeta *string
AttachmentIDs *[]uint // nil=不改附件;非 nil=替换列表
}
@@ -464,12 +461,10 @@ func (s *PostService) GetByIDForViewer(id, viewerID uint, loadActor func() *Acto
post.ViewCount++
detail := buildPostDetail(&post)
locked, hint := s.evalContentAccess(&post, viewerID, loadActor)
detail.ContentLocked = locked
sanitized, fullyLocked, hint := s.sanitizePostContent(&post, viewerID, loadActor)
detail.Content = sanitized
detail.ContentLocked = fullyLocked
detail.AccessHint = hint
if locked {
detail.Content = ""
}
atts, _ := s.listAttachmentDTOs(post.ID, viewerID, post.UserID)
detail.Attachments = atts
@@ -521,56 +516,81 @@ func buildPostDetail(post *model.Post) *PostDetail {
}
}
func (s *PostService) evalContentAccess(post *model.Post, viewerID uint, loadActor func() *Actor) (locked bool, hint string) {
access := model.NormalizeContentAccess(post.ContentAccess)
if access == model.ContentAccessPublic {
return false, ""
// sanitizePostContent 按读者能力对正文 :::hide 块脱敏;fullyLocked 表示无可见正文。
func (s *PostService) sanitizePostContent(post *model.Post, viewerID uint, loadActor func() *Actor) (content string, fullyLocked bool, hint string) {
caps := s.buildHideViewerCaps(post, viewerID, loadActor)
sanitized, fully := markdown.SanitizeForViewer(post.Content, caps)
if !fully {
return sanitized, false, ""
}
// 作者与版主始终可见
access := model.NormalizeContentAccess(post.ContentAccess)
switch access {
case model.ContentAccessPoints:
return sanitized, true, "支付积分后可见隐藏内容"
case model.ContentAccessMixed:
if post.AccessPoints > 0 {
return sanitized, true, "满足条件后可见隐藏内容"
}
return sanitized, true, "满足条件后可见隐藏内容"
case model.ContentAccessReply:
return sanitized, true, "回复本帖后可见隐藏内容"
case model.ContentAccessLogin:
return sanitized, true, "登录后可见隐藏内容"
default:
return sanitized, true, "正文暂不可见"
}
}
func (s *PostService) buildHideViewerCaps(post *model.Post, viewerID uint, loadActor func() *Actor) markdown.ViewerCaps {
caps := markdown.ViewerCaps{}
if viewerID > 0 && post.UserID == viewerID {
return false, ""
caps.Bypass = true
caps.LoggedIn = true
return caps
}
if loadActor != nil && loadActor().CanModerateBoard(post.BoardID) {
return false, ""
caps.Bypass = true
caps.LoggedIn = true
return caps
}
if viewerID == 0 {
return caps
}
caps.LoggedIn = true
needReply := false
needPoints := false
blocks, err := markdown.ParseHideBlocks(post.Content)
if err == nil {
for _, b := range blocks {
if b.Kind == markdown.HideKindReply {
needReply = true
}
if b.Kind == markdown.HideKindPoints {
needPoints = true
}
}
} else {
access := model.NormalizeContentAccess(post.ContentAccess)
needReply = access == model.ContentAccessReply || access == model.ContentAccessMixed
needPoints = post.AccessPoints > 0 || access == model.ContentAccessPoints || access == model.ContentAccessMixed
}
switch access {
case model.ContentAccessLogin:
if viewerID == 0 {
return true, "登录后可见全文"
}
return false, ""
case model.ContentAccessReply:
if viewerID == 0 {
return true, "回复本帖后可见全文"
}
if needReply {
var n int64
s.db.Model(&model.Comment{}).
Where("post_id = ? AND user_id = ? AND status = ? AND deleted_at IS NULL",
post.ID, viewerID, model.ContentStatusPublished).
Count(&n)
if n == 0 {
return true, "回复本帖后可见全文"
}
return false, ""
case model.ContentAccessPoints:
need := post.AccessPoints
if need <= 0 {
need = 1
}
if viewerID == 0 {
return true, "支付积分后可见全文"
}
caps.HasReplied = n > 0
}
if needPoints {
var n int64
s.db.Model(&model.PostContentUnlock{}).
Where("post_id = ? AND user_id = ?", post.ID, viewerID).Count(&n)
if n > 0 {
return false, ""
}
return true, "支付积分后可见全文"
default:
return false, ""
caps.PointsPaid = n > 0
}
return caps
}
func (s *PostService) listAttachmentDTOs(postID, viewerID, authorID uint) ([]PostAttachmentDTO, error) {
@@ -605,21 +625,25 @@ func (s *PostService) listAttachmentDTOs(postID, viewerID, authorID uint) ([]Pos
return out, nil
}
// UnlockContent 积分解锁正文
// UnlockContent 积分解锁正文隐藏块(一次支付解锁本帖全部积分块)
func (s *PostService) UnlockContent(userID, postID uint) (*PostDetail, error) {
var post model.Post
if err := s.db.Preload("Board").Preload("User").First(&post, postID).Error; err != nil {
return nil, ErrPostNotFound
}
if model.NormalizeContentAccess(post.ContentAccess) != model.ContentAccessPoints {
derived, derr := markdown.DeriveAccessFromContent(post.Content)
if derr != nil {
return nil, derr
}
need := derived.Points
if need <= 0 {
need = post.AccessPoints
}
if need <= 0 {
return nil, errors.New("本文无需积分解锁")
}
if post.UserID == userID {
return buildPostDetail(&post), nil
}
need := post.AccessPoints
if need <= 0 {
need = 1
return s.detailAfterInteract(&post, userID)
}
err := s.db.Transaction(func(tx *gorm.DB) error {
var n int64
@@ -645,11 +669,7 @@ func (s *PostService) UnlockContent(userID, postID uint) (*PostDetail, error) {
if err != nil {
return nil, err
}
detail := buildPostDetail(&post)
atts, _ := s.listAttachmentDTOs(post.ID, userID, post.UserID)
detail.Attachments = atts
s.fillInteractState(detail, &post, userID, nil)
return detail, nil
return s.detailAfterInteract(&post, userID)
}
// Create 创建帖子。status 由 handler 按角色计算
@@ -673,18 +693,15 @@ func (s *PostService) Create(in CreatePostInput) (*PostDetail, error) {
if !model.ValidPostType(postType) {
return nil, errors.New("无效的帖子类型")
}
access := model.NormalizeContentAccess(in.ContentAccess)
accessPts := in.AccessPoints
if access == model.ContentAccessPoints {
if accessPts <= 0 {
return nil, errors.New("请设置解锁所需积分")
}
if accessPts > 100000 {
return nil, errors.New("解锁积分过高")
}
} else {
accessPts = 0
if err := markdown.ValidateHideContent(content); err != nil {
return nil, err
}
derived, err := markdown.DeriveAccessFromContent(content)
if err != nil {
return nil, err
}
access := model.NormalizeContentAccess(derived.Access)
accessPts := derived.Points
typeMeta, err := NormalizeAndValidateTypeMeta(postType, in.TypeMeta)
if err != nil {
return nil, err
@@ -840,31 +857,19 @@ func (s *PostService) Update(actor *Actor, postID, userID uint, in UpdatePostInp
if c == "" {
return nil, errors.New("内容不能为空")
}
if err := markdown.ValidateHideContent(c); err != nil {
return nil, err
}
derived, err := markdown.DeriveAccessFromContent(c)
if err != nil {
return nil, err
}
updates["content"] = c
updates["content_access"] = model.NormalizeContentAccess(derived.Access)
updates["access_points"] = derived.Points
}
updates["tags"] = in.Tags
if in.ContentAccess != nil {
access := model.NormalizeContentAccess(*in.ContentAccess)
updates["content_access"] = access
if access == model.ContentAccessPoints {
pts := post.AccessPoints
if in.AccessPoints != nil {
pts = *in.AccessPoints
}
if pts <= 0 {
return nil, errors.New("请设置解锁所需积分")
}
updates["access_points"] = pts
} else {
updates["access_points"] = 0
}
} else if in.AccessPoints != nil && model.NormalizeContentAccess(post.ContentAccess) == model.ContentAccessPoints {
if *in.AccessPoints <= 0 {
return nil, errors.New("请设置解锁所需积分")
}
updates["access_points"] = *in.AccessPoints
}
if in.TypeMeta != nil {
pt := model.NormalizePostType(post.PostType)
meta, err := NormalizeAndValidateTypeMeta(pt, *in.TypeMeta)