fix(migrate): 兑换迁移码在双方认领锁下检查目标配额,超出返回 403 migrate_quota_exceeded 且码不消耗

This commit is contained in:
Lemon-miaow committed 2026-09-27 12:46:49 +08:00
1 parent fe48319866
commit f692725bed
12 files changed
+362 -11

No files matched your search

+10
View File
@@ -47,6 +47,9 @@ type fakeRepo struct {
// claimQuotaRefuse simulates ClaimServer's atomic quota gate (audit #4)
// refusing a name whose advisory pre-check already passed.
claimQuotaRefuse map[string]bool
// migrateQuotaRefuse names redeeming targets whose quota RedeemMigration's gate
// finds too small for the servers moving in; it refuses only a source that owns one.
migrateQuotaRefuse map[string]bool
// serverResources / resourceUpdates mirror the cached resource columns:
// ServerResources is what the resize path reads (to preserve storage), and
// UpdateServerResources records the write for assertions.
@@ -1471,6 +1474,13 @@ func (f *fakeRepo) RedeemMigration(_ context.Context, targetUserID, codeHash str
if mig == nil {
return "", nil, ErrLinkCodeInvalid
}
if f.migrateQuotaRefuse[targetUserID] {
for _, rec := range f.byName {
if rec.OwnerID == mig.sourceUserID {
return "", nil, ErrQuotaExceeded // before anything moves, as the real gate
}
}
}
// Re-point every server the source owns to the target (byName holds pointers).
var moved []string
for name, rec := range f.byName {