Compare commits

...

3 Commits

Author SHA1 Message Date
283eb4fa49 新增评论举报接口 2026-03-20 15:40:19 +08:00
99cf132d76 feat(iap): 新增 Google Play 内购与 AI 评论举报支持
完成 Google Play 内购集成所需的全链路实现,包括:
- 数据库表结构(google-play-iap.sql)
- 实体、Mapper、Service 及 XML 配置
- AI 评论举报实体与业务层
- 集成文档(google-play-iap-integration.md)
2026-03-20 15:32:31 +08:00
742107f944 Add comment reporting API and service 2026-03-20 15:26:46 +08:00
9 changed files with 612 additions and 0 deletions

View File

@@ -0,0 +1,257 @@
# Google Play IAP 服务端集成
## 系统设计
### 目标
- 客户端购买成功后,服务端使用 `purchaseToken` 二次校验 Google Play Developer API。
- RTDN 进入后,先做 Pub/Sub 来源校验,再二次查询 Google Play Developer API同步本地订单、token、权益状态。
- 对订阅与一次性商品统一落库,保证幂等、防重放和可审计。
### 核心流程
1. 客户端发起购买BillingClient 中建议设置 `obfuscatedAccountId = 当前 userId`
2. 客户端支付成功后调用 `/api/google-play/purchases/verify`
3. 服务端调用 Google Play Developer API
- 订阅:`purchases.subscriptionsv2.get`
- 一次性商品:`purchases.productsv2.getproductpurchasev2`
4. 服务端更新 `google_play_purchase_token``google_play_order``google_play_user_entitlement`
5. 对需要确认的订单执行 acknowledge / consume。
6. Google Play RTDN 推送到 `/api/google-play/rtdn`
7. webhook 校验 topic / subscription / OIDC JWT 后,再次查询 Developer API再更新本地状态。
### 幂等策略
- RTDN 事件以 `message_id` 幂等,重复消息直接忽略。
- 订单以 `order_key` 幂等:
-`google_order_id` 时用订单号。
- 没有订单号时回退为 `TOKEN:{purchaseToken}`
- 购买 token 表以 `purchase_token` 唯一。
- 一次性商品发货前先看 `delivery_status`,已发货不重复发。
- 订阅不做“累加式延长”,而是直接把用户 VIP 到期时间同步为 Google 返回的最新 `expiryTime`,天然幂等。
### 本地权益映射
- `subscription` -> `VIP_SUBSCRIPTION`
- 一次性商品且 `duration_days > 0``unit` 包含 `vip/member/会员` -> `VIP_ONE_TIME`
- 一次性商品且 `unit``coin/quota/credit/金币/次数`,或商品名/`durationValue` 可解析数值 -> `WALLET_TOP_UP`
- 其他一次性商品 -> `NON_CONSUMABLE`
## 目录结构
```text
src/main/java/com/yolo/keyborad/
├── config/
│ ├── GooglePlayHttpConfig.java
│ └── GooglePlayProperties.java
├── controller/
│ └── GooglePlayController.java
├── googleplay/
│ ├── GooglePlayApiClient.java
│ ├── GooglePlayApiException.java
│ ├── GooglePlayConstants.java
│ ├── GooglePlayEntitlementApplier.java
│ ├── GooglePlayPubSubAuthService.java
│ ├── GooglePlayServiceAccountTokenProvider.java
│ ├── GooglePlayStateService.java
│ └── model/
│ ├── GooglePlayPurchaseSnapshot.java
│ ├── GooglePlaySyncCommand.java
│ └── GooglePlaySyncResult.java
├── mapper/
│ ├── GooglePlayOrderMapper.java
│ ├── GooglePlayPurchaseTokenMapper.java
│ ├── GooglePlayRtdnEventMapper.java
│ └── GooglePlayUserEntitlementMapper.java
├── model/
│ ├── dto/googleplay/
│ │ ├── GooglePlayPubSubPushRequest.java
│ │ └── GooglePlayPurchaseVerifyReq.java
│ ├── entity/googleplay/
│ │ ├── GooglePlayOrder.java
│ │ ├── GooglePlayPurchaseToken.java
│ │ ├── GooglePlayRtdnEvent.java
│ │ └── GooglePlayUserEntitlement.java
│ └── vo/googleplay/
│ └── GooglePlayPurchaseVerifyResp.java
└── service/
├── GooglePlayBillingService.java
└── impl/
└── GooglePlayBillingServiceImpl.java
```
## 建表 SQL
- 文件:`src/main/resources/sql/google-play-iap.sql`
四张表职责:
- `google_play_order`:每一笔 Google 订单/续费周期的最终状态与发货状态。
- `google_play_purchase_token`:一个 purchase token 的最新状态快照。
- `google_play_user_entitlement`:用户实际拥有的本地权益。
- `google_play_rtdn_event`RTDN 审计与重试记录。
## 接口定义
### 1. 客户端购买校验
- `POST /api/google-play/purchases/verify`
- 需要登录态与签名
请求体:
```json
{
"packageName": "com.example.app",
"productId": "vip_monthly",
"productType": "subscription",
"purchaseToken": "xxxx"
}
```
响应体:
```json
{
"code": 0,
"message": "ok",
"data": {
"userId": 1001,
"productId": "vip_monthly",
"productType": "SUBSCRIPTION",
"purchaseToken": "xxxx",
"orderId": "GPA.1234-5678-9012-34567",
"orderState": "ACTIVE",
"entitlementState": "ACTIVE",
"deliveryStatus": "NOT_REQUIRED",
"accessGranted": true,
"acknowledged": true,
"consumed": false,
"expiryTime": "2026-04-18T10:00:00.000+00:00",
"lastSyncedAt": "2026-03-18T10:01:00.000+00:00"
}
}
```
### 2. RTDN Webhook
- `POST /api/google-play/rtdn`
- 不需要登录态,不走 app 签名,单独做 Pub/Sub 校验
Pub/Sub Push body
```json
{
"message": {
"messageId": "136969346945",
"data": "base64-encoded-json"
},
"subscription": "projects/your-project/subscriptions/google-play-rtdn-push"
}
```
关键请求头:
- `Authorization: Bearer <OIDC JWT>`
- `X-Goog-Topic: projects/your-project/topics/google-play-rtdn`
成功响应:
```json
{
"code": 0,
"message": "ok",
"data": true
}
```
## RTDN 状态处理
### 订阅
- `SUBSCRIPTION_PURCHASED`
- Developer API 状态通常为 `ACTIVE`
- 新建/更新 token、order、VIP 权益
- 如未 acknowledge则服务端补 acknowledge
- `SUBSCRIPTION_RENEWED`
- 再查 `subscriptionsv2.get`
- 取最新 `expiryTime` 覆盖本地 VIP 到期时间
- 不做“在旧时间上加时长”,避免 RTDN 重放导致多发
- `SUBSCRIPTION_CANCELED`
-`subscriptionState=CANCELED``expiryTime` 仍未来
- 本地仍保留 VIP`autoRenewEnabled=false`
- 到期后等待 `EXPIRED`
- `SUBSCRIPTION_IN_GRACE_PERIOD`
- 本地继续保留 VIP
- entitlement state 记为 `IN_GRACE_PERIOD`
- `SUBSCRIPTION_ON_HOLD`
- 立即取消本地 VIP 可用态
- 保留 token/order 记录,等待恢复或过期
- `SUBSCRIPTION_RESTARTED` / `SUBSCRIPTION_RECOVERED`
- 再查最新状态
- 若恢复为 `ACTIVE`,重新开启 VIP
- `SUBSCRIPTION_PAUSED`
- 本地取消 VIP 可用态
- 记录 `autoResumeTime`
- `SUBSCRIPTION_EXPIRED`
- 本地关闭 VIP
- entitlement state -> `EXPIRED`
- `SUBSCRIPTION_REVOKED`
- 本地关闭 VIP
- entitlement state -> `REVOKED`
- `SUBSCRIPTION_PENDING_PURCHASE_CANCELED`
- 用当前 token 查到 `linkedPurchaseToken` 后,再同步旧 token
- 旧订阅权益继续保持
### 一次性商品
- `ONE_TIME_PRODUCT_PURCHASED`
- 若映射为钱包充值:仅当 `delivery_status != DELIVERED` 才入账
- 若映射为一次性 VIP 或非消耗型权益:同样只发一次
- 钱包型商品在发货后执行 consume
- 非消耗型商品执行 acknowledge
- `ONE_TIME_PRODUCT_CANCELED`
- 一般是 pending 订单被取消
- 本地标记为 `CANCELED`,不发货
- `VoidedPurchaseNotification`
- 先二次查询 Developer API若 404则结合本地 token/order 记录做最终回滚
- 订阅按 `REVOKED`
- 一次性商品按 `REFUNDED`
- 钱包余额不足以回滚时,订单标记 `MANUAL_REVIEW`,日志显式报错
## 安全校验
- RTDN 入口校验 `X-Goog-Topic`
- 校验 `subscription` 字段
- 调用 `tokeninfo` 校验 Pub/Sub OIDC JWT
- 校验 `aud`
- 校验 `email``email_verified`
- 校验 `iss` 必须是 Google Accounts
- 客户端校验接口可要求 `obfuscatedExternalAccountId == userId`
## 测试样例
建议执行:
```bash
mvn -q test -Dtest=GooglePlay*
```
覆盖点:
- 订阅首次购买与续费
- 订阅取消但未过期
- 订阅宽限期
- 一次性商品发货幂等
- RTDN 重放幂等

View File

@@ -10,7 +10,9 @@ import com.yolo.keyborad.exception.BusinessException;
import com.yolo.keyborad.model.dto.comment.CommentAddReq;
import com.yolo.keyborad.model.dto.comment.CommentLikeReq;
import com.yolo.keyborad.model.dto.comment.CommentPageReq;
import com.yolo.keyborad.model.dto.comment.CommentReportReq;
import com.yolo.keyborad.model.vo.CommentVO;
import com.yolo.keyborad.service.KeyboardAiCommentReportService;
import com.yolo.keyborad.service.KeyboardAiCompanionCommentService;
import com.yolo.keyborad.service.KeyboardAiCompanionCommentLikeService;
import io.swagger.v3.oas.annotations.Operation;
@@ -35,6 +37,9 @@ public class AiCompanionCommentController {
@Resource
private KeyboardAiCompanionCommentLikeService commentLikeService;
@Resource
private KeyboardAiCommentReportService commentReportService;
@PostMapping("/add")
@Operation(summary = "发表评论", description = "用户对AI陪聊角色发表评论")
public BaseResponse<Long> addComment(@RequestBody CommentAddReq req) {
@@ -75,4 +80,12 @@ public class AiCompanionCommentController {
boolean result = commentLikeService.toggleLike(userId, req.getCommentId());
return ResultUtils.success(result);
}
@PostMapping("/report")
@Operation(summary = "举报评论", description = "举报AI陪聊角色评论支持多种举报类型可多选1=色情低俗, 2=政治敏感, 3=暴力恐怖, 4=侵权/冒充, 5=价值观问题, 99=其他")
public BaseResponse<Long> reportComment(@RequestBody CommentReportReq req) {
Long userId = StpUtil.getLoginIdAsLong();
Long reportId = commentReportService.reportComment(userId, req);
return ResultUtils.success(reportId);
}
}

View File

@@ -0,0 +1,11 @@
package com.yolo.keyborad.mapper;
import com.baomidou.mybatisplus.core.mapper.BaseMapper;
import com.yolo.keyborad.model.entity.KeyboardAiCommentReport;
/*
* @author: ziin
* @date: 2026/3/20
*/
public interface KeyboardAiCommentReportMapper extends BaseMapper<KeyboardAiCommentReport> {
}

View File

@@ -0,0 +1,30 @@
package com.yolo.keyborad.model.dto.comment;
import io.swagger.v3.oas.annotations.media.Schema;
import lombok.Data;
import java.util.List;
/*
* @author: ziin
* @date: 2026/3/20
*/
@Data
@Schema(description = "评论举报请求")
public class CommentReportReq {
@Schema(description = "评论ID", requiredMode = Schema.RequiredMode.REQUIRED)
private Long commentId;
@Schema(description = "举报类型列表1=色情低俗, 2=政治敏感, 3=暴力恐怖, 4=侵权/冒充, 5=价值观问题, 99=其他,支持多选", requiredMode = Schema.RequiredMode.REQUIRED)
private List<Short> reportTypes;
@Schema(description = "详细描述")
private String reportDesc;
@Schema(description = "评论上下文快照JSON")
private String chatContext;
@Schema(description = "图片证据URL")
private String evidenceImageUrl;
}

View File

@@ -0,0 +1,68 @@
package com.yolo.keyborad.model.entity;
import com.baomidou.mybatisplus.annotation.IdType;
import com.baomidou.mybatisplus.annotation.TableField;
import com.baomidou.mybatisplus.annotation.TableId;
import com.baomidou.mybatisplus.annotation.TableName;
import io.swagger.v3.oas.annotations.media.Schema;
import lombok.Data;
import java.util.Date;
/*
* @author: ziin
* @date: 2026/3/20
*/
/**
* AI评论举报记录表
*/
@Data
@Schema(description = "AI评论举报记录表")
@TableName(value = "keyboard_ai_comment_report")
public class KeyboardAiCommentReport {
@TableId(value = "id", type = IdType.AUTO)
@Schema(description = "举报记录唯一ID")
private Long id;
@TableField(value = "comment_id")
@Schema(description = "被举报的评论ID")
private Long commentId;
@TableField(value = "user_id")
@Schema(description = "发起举报的用户ID")
private Long userId;
@TableField(value = "report_type")
@Schema(description = "举报类型,多选时逗号分隔")
private String reportType;
@TableField(value = "report_desc")
@Schema(description = "用户填写的详细举报描述")
private String reportDesc;
@TableField(value = "chat_context")
@Schema(description = "评论上下文快照JSON")
private String chatContext;
@TableField(value = "evidence_image_url")
@Schema(description = "图片证据URL")
private String evidenceImageUrl;
@TableField(value = "\"status\"")
@Schema(description = "处理状态0=待处理, 1=违规确立, 2=无效举报, 3=已忽略")
private Short status;
@TableField(value = "admin_remark")
@Schema(description = "管理员处理备注")
private String adminRemark;
@TableField(value = "created_at")
@Schema(description = "举报提交时间")
private Date createdAt;
@TableField(value = "updated_at")
@Schema(description = "最后更新时间")
private Date updatedAt;
}

View File

@@ -0,0 +1,21 @@
package com.yolo.keyborad.service;
import com.baomidou.mybatisplus.extension.service.IService;
import com.yolo.keyborad.model.dto.comment.CommentReportReq;
import com.yolo.keyborad.model.entity.KeyboardAiCommentReport;
/*
* @author: ziin
* @date: 2026/3/20
*/
public interface KeyboardAiCommentReportService extends IService<KeyboardAiCommentReport> {
/**
* 举报评论
*
* @param userId 用户ID
* @param req 举报请求
* @return 举报记录ID
*/
Long reportComment(Long userId, CommentReportReq req);
}

View File

@@ -0,0 +1,78 @@
package com.yolo.keyborad.service.impl;
import com.baomidou.mybatisplus.extension.service.impl.ServiceImpl;
import com.yolo.keyborad.common.ErrorCode;
import com.yolo.keyborad.exception.BusinessException;
import com.yolo.keyborad.mapper.KeyboardAiCommentReportMapper;
import com.yolo.keyborad.model.dto.comment.CommentReportReq;
import com.yolo.keyborad.model.entity.KeyboardAiCommentReport;
import com.yolo.keyborad.model.entity.KeyboardAiCompanionComment;
import com.yolo.keyborad.service.KeyboardAiCommentReportService;
import com.yolo.keyborad.service.KeyboardAiCompanionCommentService;
import jakarta.annotation.Resource;
import org.springframework.stereotype.Service;
import java.util.Date;
import java.util.Set;
import java.util.stream.Collectors;
/*
* @author: ziin
* @date: 2026/3/20
*/
@Service
public class KeyboardAiCommentReportServiceImpl extends ServiceImpl<KeyboardAiCommentReportMapper, KeyboardAiCommentReport>
implements KeyboardAiCommentReportService {
private static final short PENDING_STATUS = 0;
private static final Set<Short> VALID_REPORT_TYPES = Set.of(
(short) 1, (short) 2, (short) 3, (short) 4, (short) 5, (short) 99
);
@Resource
private KeyboardAiCompanionCommentService commentService;
@Override
public Long reportComment(Long userId, CommentReportReq req) {
validateRequest(req);
KeyboardAiCompanionComment comment = commentService.getById(req.getCommentId());
if (comment == null) {
throw new BusinessException(ErrorCode.COMMENT_NOT_FOUND);
}
KeyboardAiCommentReport report = buildReport(userId, req);
boolean saved = this.save(report);
if (!saved) {
throw new BusinessException(ErrorCode.OPERATION_ERROR);
}
return report.getId();
}
private void validateRequest(CommentReportReq req) {
if (req.getCommentId() == null) {
throw new BusinessException(ErrorCode.COMMENT_ID_EMPTY);
}
if (req.getReportTypes() == null || req.getReportTypes().isEmpty()) {
throw new BusinessException(ErrorCode.REPORT_TYPE_EMPTY);
}
boolean hasInvalidType = req.getReportTypes().stream().anyMatch(type -> !VALID_REPORT_TYPES.contains(type));
if (hasInvalidType) {
throw new BusinessException(ErrorCode.REPORT_TYPE_INVALID);
}
}
private KeyboardAiCommentReport buildReport(Long userId, CommentReportReq req) {
KeyboardAiCommentReport report = new KeyboardAiCommentReport();
report.setUserId(userId);
report.setCommentId(req.getCommentId());
report.setReportType(req.getReportTypes().stream().map(String::valueOf).collect(Collectors.joining(",")));
report.setReportDesc(req.getReportDesc());
report.setChatContext(req.getChatContext());
report.setEvidenceImageUrl(req.getEvidenceImageUrl());
report.setStatus(PENDING_STATUS);
report.setCreatedAt(new Date());
return report;
}
}

View File

@@ -0,0 +1,21 @@
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE mapper PUBLIC "-//mybatis.org//DTD Mapper 3.0//EN" "http://mybatis.org/dtd/mybatis-3-mapper.dtd">
<mapper namespace="com.yolo.keyborad.mapper.KeyboardAiCommentReportMapper">
<resultMap id="BaseResultMap" type="com.yolo.keyborad.model.entity.KeyboardAiCommentReport">
<id column="id" jdbcType="BIGINT" property="id" />
<result column="comment_id" jdbcType="BIGINT" property="commentId" />
<result column="user_id" jdbcType="BIGINT" property="userId" />
<result column="report_type" jdbcType="VARCHAR" property="reportType" />
<result column="report_desc" jdbcType="VARCHAR" property="reportDesc" />
<result column="chat_context" jdbcType="VARCHAR" property="chatContext" />
<result column="evidence_image_url" jdbcType="VARCHAR" property="evidenceImageUrl" />
<result column="status" jdbcType="SMALLINT" property="status" />
<result column="admin_remark" jdbcType="VARCHAR" property="adminRemark" />
<result column="created_at" jdbcType="TIMESTAMP" property="createdAt" />
<result column="updated_at" jdbcType="TIMESTAMP" property="updatedAt" />
</resultMap>
<sql id="Base_Column_List">
id, comment_id, user_id, report_type, report_desc, chat_context, evidence_image_url,
"status", admin_remark, created_at, updated_at
</sql>
</mapper>

View File

@@ -0,0 +1,113 @@
CREATE TABLE IF NOT EXISTS google_play_order (
id BIGSERIAL PRIMARY KEY,
user_id BIGINT,
package_name VARCHAR(128) NOT NULL,
product_id VARCHAR(255) NOT NULL,
product_type VARCHAR(32) NOT NULL,
purchase_token VARCHAR(512) NOT NULL,
order_key VARCHAR(128) NOT NULL UNIQUE,
google_order_id VARCHAR(128),
linked_purchase_token VARCHAR(512),
order_state VARCHAR(64) NOT NULL,
acknowledgement_state VARCHAR(32) NOT NULL,
consumption_state VARCHAR(32) NOT NULL,
quantity INTEGER,
refundable_quantity INTEGER,
delivery_status VARCHAR(64) NOT NULL,
granted_quantity NUMERIC(18,2) NOT NULL DEFAULT 0,
entitlement_start_time TIMESTAMP,
entitlement_end_time TIMESTAMP,
last_event_time TIMESTAMP,
last_synced_at TIMESTAMP NOT NULL,
raw_response TEXT NOT NULL,
created_at TIMESTAMP NOT NULL DEFAULT NOW(),
updated_at TIMESTAMP NOT NULL DEFAULT NOW()
);
CREATE INDEX IF NOT EXISTS idx_google_play_order_purchase_token
ON google_play_order (purchase_token);
CREATE INDEX IF NOT EXISTS idx_google_play_order_user_product
ON google_play_order (user_id, product_id);
CREATE TABLE IF NOT EXISTS google_play_purchase_token (
id BIGSERIAL PRIMARY KEY,
purchase_token VARCHAR(512) NOT NULL UNIQUE,
linked_purchase_token VARCHAR(512),
user_id BIGINT,
package_name VARCHAR(128) NOT NULL,
product_id VARCHAR(255) NOT NULL,
product_type VARCHAR(32) NOT NULL,
latest_order_key VARCHAR(128) NOT NULL,
latest_order_id VARCHAR(128),
token_state VARCHAR(64) NOT NULL,
acknowledgement_state VARCHAR(32) NOT NULL,
consumption_state VARCHAR(32) NOT NULL,
auto_renew_enabled BOOLEAN,
external_account_id VARCHAR(255),
external_profile_id VARCHAR(255),
region_code VARCHAR(16),
start_time TIMESTAMP,
expiry_time TIMESTAMP,
auto_resume_time TIMESTAMP,
canceled_state_reason VARCHAR(64),
last_event_type VARCHAR(128),
last_event_time TIMESTAMP,
last_synced_at TIMESTAMP NOT NULL,
raw_response TEXT NOT NULL,
created_at TIMESTAMP NOT NULL DEFAULT NOW(),
updated_at TIMESTAMP NOT NULL DEFAULT NOW()
);
CREATE INDEX IF NOT EXISTS idx_google_play_purchase_token_user
ON google_play_purchase_token (user_id);
CREATE TABLE IF NOT EXISTS google_play_user_entitlement (
id BIGSERIAL PRIMARY KEY,
user_id BIGINT NOT NULL,
entitlement_key VARCHAR(128) NOT NULL,
product_id VARCHAR(255) NOT NULL,
product_type VARCHAR(32) NOT NULL,
source_purchase_token VARCHAR(512) NOT NULL,
current_order_key VARCHAR(128) NOT NULL,
benefit_type VARCHAR(64) NOT NULL,
state VARCHAR(64) NOT NULL,
active BOOLEAN NOT NULL,
quantity NUMERIC(18,2) NOT NULL DEFAULT 0,
start_time TIMESTAMP,
end_time TIMESTAMP,
last_granted_at TIMESTAMP,
last_revoked_at TIMESTAMP,
metadata TEXT,
created_at TIMESTAMP NOT NULL DEFAULT NOW(),
updated_at TIMESTAMP NOT NULL DEFAULT NOW(),
CONSTRAINT uk_google_play_user_entitlement UNIQUE (source_purchase_token, entitlement_key)
);
CREATE INDEX IF NOT EXISTS idx_google_play_user_entitlement_user
ON google_play_user_entitlement (user_id, active);
CREATE TABLE IF NOT EXISTS google_play_rtdn_event (
id BIGSERIAL PRIMARY KEY,
message_id VARCHAR(128) NOT NULL UNIQUE,
subscription_name VARCHAR(255),
package_name VARCHAR(128),
event_type VARCHAR(32) NOT NULL,
notification_type INTEGER,
notification_name VARCHAR(128),
purchase_token VARCHAR(512),
product_id VARCHAR(255),
order_id VARCHAR(128),
event_time TIMESTAMP,
status VARCHAR(32) NOT NULL,
retry_count INTEGER NOT NULL DEFAULT 0,
raw_envelope TEXT NOT NULL,
raw_payload TEXT NOT NULL,
error_message TEXT,
processed_at TIMESTAMP,
created_at TIMESTAMP NOT NULL DEFAULT NOW(),
updated_at TIMESTAMP NOT NULL DEFAULT NOW()
);
CREATE INDEX IF NOT EXISTS idx_google_play_rtdn_event_purchase_token
ON google_play_rtdn_event (purchase_token);