feat(ECR-018): Entitlement 用户权益只读并 Closed

聚合 GET /admin/users/:id/entitlements(Membership∪DeepAccess∪问答额度)与 admin-h5 权益 Tab;无 migration / 无真支付。

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
jackyu66git
2026-08-07 19:26:15 +08:00
co-authored by Cursor
parent 37b91e51b8
commit c81f57a7d1
28 changed files with 597 additions and 12 deletions
+1 -1
View File
@@ -19,7 +19,7 @@ Status: `Draft`
| BehaviorSnapshot | Identity_Profile | UserIntelligence | **ECR-016** 读模型(analytics 聚合) |
| PsychologicalTagSet | Identity_Profile | UserIntelligence | **ECR-016** 由报告 type 派生 |
| MembershipPlan | Membership_Orders | CommerceEntitlement | **ECR-014 Closed** |
| Entitlement | Membership_Orders | CommerceEntitlement | 后置 |
| Entitlement | Membership_Orders | CommerceEntitlement | **ECR-018** 读模型(MembershipDeepAccess |
| RedemptionCode | Membership_Orders | CommerceEntitlement | **ECR-015 Closed** |
| Membership | Membership_Orders | CommerceEntitlement | 已存在 |
| Order | Membership_Orders | CommerceEntitlement | 已存在 |
+1 -1
View File
@@ -235,7 +235,7 @@ UI **不出现「塔罗」**。禁止神谕吉凶、恐吓话术。
| Phase A `[Ops]` | 登录 · 用户/订单查询 · 会员授予 · 审计 · `apps/admin-h5`ECR-006 Closed |
| Phase B `[Ops]` | 行为分析:自有埋点 + 管理端「数据」看板(**ECR-007 Closed** · Spec `ops-analytics.md` |
| Phase C `[Ops]` | 内容:首页宫格 CRUD · 测评上下架(**ECR-008 Closed** · Spec `ops-content.md` |
| Phase D+ | **Contract-First****ECR-013A/B/014/015/016 Closed** → **ECR-017** AskOperationsLoop)。`docs/WAVE0/LOOP_AUTHORIZATION.md`。 |
| Phase D+ | **Contract-First****ECR-013A…017 Closed** → **ECR-018** EntitlementLoop)。`docs/WAVE0/LOOP_AUTHORIZATION.md`。 |
| 排除 | **UGC / 社区广场**M10.2)仍 `[No]`;真支付最后 |
不计入 P1 Complete;不进入五 Tab。
+1
View File
@@ -27,6 +27,7 @@
| [ops-redemption-code.md](ops-redemption-code.md) | 兑换码 RedemptionCode | §7 | `admin-h5` `/codes` · `POST /membership/redeem` | Ops-D · **ECR-015 Closed** |
| [ops-user-intelligence.md](ops-user-intelligence.md) | 用户洞察 UserIntelligence | §7 | `admin-h5` 用户详情「洞察」· `GET /admin/users/:id/insight` | Ops-D · **ECR-016 Closed** |
| [ops-ask-operations.md](ops-ask-operations.md) | 问答运营 AskOperations | §7 | `admin-h5` `/ask` · `GET /admin/ask/threads*` | Ops-D · **ECR-017 Closed** |
| [ops-entitlement.md](ops-entitlement.md) | 用户权益 Entitlement | §7 | `admin-h5` 用户详情「权益」· `GET /admin/users/:id/entitlements` | Ops-D · **ECR-018 Closed** |
新功能:复制 `_TEMPLATE.md` → 填满 → 在本表登记 → 再编码。
+2 -1
View File
@@ -214,6 +214,7 @@ Phase A 可先 `console`/本地;不挡验收。
| **HECR-015 Closed** | RedemptionCode — Spec `ops-redemption-code.md` |
| **IECR-016 Closed** | UserIntelligence — Spec `ops-user-intelligence.md` |
| **JECR-017 Closed** | AskOperations — Spec `ops-ask-operations.md` |
| 后置 | Entitlement 细权 / QualityFeedback / AICoreConfigLoop 续跑) |
| **KECR-018 Closed** | Entitlement — Spec `ops-entitlement.md` |
| 后置 | ContentSafety / QualityFeedback / AICoreConfigLoop 续跑) |
| D | 订单筛选 · 展示价 · 退款只读(另开 ECR) |
| 后置 | 封禁加深(Account_Risk)· 推送占位 |
@@ -0,0 +1,36 @@
# Feature Spec: EntitlementOps · ECR-018
> Status: `Active`Loop continuous · **ECR-018 Closed**
> Parent: WAVE0-FROZEN · Predecessor: ECR-017 Closed
> Capability: `CommerceEntitlement` · BC: `Membership_Orders`
> 授权:`docs/WAVE0/LOOP_AUTHORIZATION.md`
## Non-goals
真支付 · 改订单/退款 · 新建权益矩阵表 · UGC · 改报告正文 · ask_pack SKU
## L2 读模型(无 migration
| 概念 | 来源 |
|------|------|
| `Entitlement` | Membership + DeepAccess 列表 + ask_paid_quota 聚合 |
| flags | `report_detail_via_membership` · `deep_access_count` |
## L3 API
| Method | Path | 权限 | 语义 |
|--------|------|------|------|
| GET | `/admin/users/:id/entitlements` | `admin.users.read` | 用户权益只读视图 |
## L4 AC
| ID | Then |
|----|------|
| AC-F-01 | 授予会员后 flags.report_detail_via_membership=true |
| AC-F-02 | 有 deep_access 时 deep_accesses 非空或 count≥1 |
| AC-F-03 | 无会员无深度 → membership.active=false 且 count=0 仍 200 |
| AC-S-01 | 无 Admin → 401 |
| AC-P-01 | GET &lt; 500ms 本机 |
| AC-O-01 | N/A 只读 |
contract_diff: `docs/CONTRACT_DIFF/ECR-018.yaml`
+22
View File
@@ -152,6 +152,28 @@ export const adminApi = {
ask_thread_count: number
}
}>('GET', `/users/${id}/insight`),
userEntitlements: (id: string) =>
request<{
user_id: string
membership: {
plan?: string
status: string
expires_at?: string
ask_quota_left?: number
active: boolean
}
ask_paid_quota_left: number
flags: {
report_detail_via_membership: boolean
deep_access_count: number
}
deep_accesses: Array<{
id: string
report_id: string
report_type?: string
created_at: string
}>
}>('GET', `/users/${id}/entitlements`),
grant: (id: string, plan: string) =>
request<{ ok: boolean }>('POST', `/users/${id}/membership/grant`, { plan }),
grantAskQuota: (id: string, delta: number) =>
@@ -0,0 +1,92 @@
<script setup lang="ts">
import { RouterLink } from 'vue-router'
import { adminApi } from '@/api/client'
export type Entitlement = Awaited<ReturnType<typeof adminApi.userEntitlements>>
defineProps<{
data: Entitlement
}>()
const typeLabel: Record<string, string> = {
portrait: '愈心解码',
star: '星座',
rhythm: '节律',
relation: '关系',
synastry: '合盘',
image_card: '意象卡',
}
function fmtTime(iso?: string | null) {
if (!iso) return '—'
try {
return new Date(iso).toLocaleString('zh-CN')
} catch {
return iso
}
}
</script>
<template>
<div>
<div class="card block">
<h2>权益概览</h2>
<div class="kv">
<div>
<span>报告 detail会员</span>
<strong>{{ data.flags.report_detail_via_membership ? '是' : '否' }}</strong>
</div>
<div>
<span>DeepAccess 份数</span>
<strong>{{ data.flags.deep_access_count }}</strong>
</div>
<div>
<span>已购问答余量</span>
<strong>{{ data.ask_paid_quota_left }}</strong>
</div>
</div>
</div>
<div class="card block">
<h2>成长会员</h2>
<p v-if="data.membership">
{{ data.membership.active ? '有效' : '无效' }} ·
{{ data.membership.plan || '' }} ·
会员问答 {{ data.membership.ask_quota_left ?? 0 }} ·
到期 {{ fmtTime(data.membership.expires_at) }}
</p>
<p v-else class="muted">无会员记录</p>
</div>
<div class="card block">
<h2>深度版DeepAccess</h2>
<p v-if="!data.deep_accesses?.length" class="muted">无单份深度版</p>
<table v-else>
<thead>
<tr><th>类型</th><th>报告</th><th>时间</th></tr>
</thead>
<tbody>
<tr v-for="d in data.deep_accesses" :key="d.id">
<td>{{ typeLabel[d.report_type || ''] || d.report_type || '—' }}</td>
<td><code>{{ d.report_id.slice(0, 8) }}</code></td>
<td>{{ fmtTime(d.created_at) }}</td>
</tr>
</tbody>
</table>
<p class="hint">
<RouterLink :to="`/users/${data.user_id}`">返回基础信息可授予会员 / 问答额度</RouterLink>
</p>
</div>
</div>
</template>
<style scoped>
h2 { margin: 0 0 0.6rem; font-size: 1.05rem; }
.block { margin-bottom: 1rem; }
.kv {
display: grid;
grid-template-columns: repeat(auto-fill, minmax(180px, 1fr));
gap: 0.75rem;
}
.kv span { display: block; font-size: 0.75rem; color: var(--muted); margin-bottom: 0.15rem; }
.hint { margin-top: 0.75rem; font-size: 0.85rem; }
.hint a { color: var(--accent); }
</style>
+30 -8
View File
@@ -2,6 +2,7 @@
import { computed, onMounted, ref, watch } from 'vue'
import { RouterLink, useRoute } from 'vue-router'
import { adminApi, type UserDetail } from '@/api/client'
import UserEntitlementPanel, { type Entitlement } from '@/components/UserEntitlementPanel.vue'
import { useAuthStore } from '@/stores/auth'
type Insight = Awaited<ReturnType<typeof adminApi.userInsight>>
@@ -11,10 +12,13 @@ const auth = useAuthStore()
const loading = ref(false)
const error = ref('')
const detail = ref<UserDetail | null>(null)
const tab = ref<'base' | 'insight'>('base')
const tab = ref<'base' | 'insight' | 'entitlement'>('base')
const insight = ref<Insight | null>(null)
const insightErr = ref('')
const insightLoading = ref(false)
const entitlement = ref<Entitlement | null>(null)
const entitlementErr = ref('')
const entitlementLoading = ref(false)
const plan = ref('month')
const askDelta = ref(10)
const grantMsg = ref('')
@@ -45,9 +49,8 @@ async function load() {
} catch {
transitions.value = []
}
if (tab.value === 'insight') {
await loadInsight()
}
if (tab.value === 'insight') await loadInsight()
if (tab.value === 'entitlement') await loadEntitlement()
} catch (e) {
error.value = e instanceof Error ? e.message : '加载失败'
} finally {
@@ -68,10 +71,22 @@ async function loadInsight() {
}
}
watch(tab, (v) => {
if (v === 'insight' && !insight.value && !insightLoading.value) {
void loadInsight()
async function loadEntitlement() {
entitlementLoading.value = true
entitlementErr.value = ''
try {
entitlement.value = await adminApi.userEntitlements(String(route.params.id))
} catch (e) {
entitlementErr.value = e instanceof Error ? e.message : '权益加载失败'
entitlement.value = null
} finally {
entitlementLoading.value = false
}
}
watch(tab, (v) => {
if (v === 'insight' && !insight.value && !insightLoading.value) void loadInsight()
if (v === 'entitlement' && !entitlement.value && !entitlementLoading.value) void loadEntitlement()
})
async function grant() {
@@ -139,6 +154,7 @@ onMounted(load)
<div class="tabs">
<button type="button" :class="{ on: tab === 'base' }" @click="tab = 'base'">基础</button>
<button type="button" :class="{ on: tab === 'insight' }" @click="tab = 'insight'">洞察</button>
<button type="button" :class="{ on: tab === 'entitlement' }" @click="tab = 'entitlement'">权益</button>
</div>
<template v-if="tab === 'base'">
@@ -257,7 +273,7 @@ onMounted(load)
</div>
</template>
<template v-else>
<template v-else-if="tab === 'insight'">
<p v-if="insightLoading" class="muted">加载洞察</p>
<p v-else-if="insightErr" class="err">{{ insightErr }}</p>
<template v-else-if="insight">
@@ -317,6 +333,12 @@ onMounted(load)
</div>
</template>
</template>
<template v-else-if="tab === 'entitlement'">
<p v-if="entitlementLoading" class="muted">加载权益</p>
<p v-else-if="entitlementErr" class="err">{{ entitlementErr }}</p>
<UserEntitlementPanel v-else-if="entitlement" :data="entitlement" />
</template>
</template>
</section>
</template>
+1
View File
@@ -48,6 +48,7 @@ func (h *AdminHandler) Register(api *gin.RouterGroup) {
h.registerRedemption(authed)
h.registerInsight(authed)
h.registerAskOps(authed)
h.registerEntitlement(authed)
}
func (h *AdminHandler) Login(c *gin.Context) {
@@ -0,0 +1,35 @@
package handler
import (
"errors"
"net/http"
"github.com/gin-gonic/gin"
"github.com/google/uuid"
"github.com/yuxingu/digital-psychology/apps/api/internal/middleware"
"github.com/yuxingu/digital-psychology/apps/api/internal/service/admin"
"github.com/yuxingu/digital-psychology/apps/api/pkg/response"
)
func (h *AdminHandler) registerEntitlement(authed *gin.RouterGroup) {
authed.GET("/users/:id/entitlements", middleware.RequireAdminPermission(h.Svc, admin.PermUsersRead), h.GetUserEntitlements)
}
func (h *AdminHandler) GetUserEntitlements(c *gin.Context) {
id, err := uuid.Parse(c.Param("id"))
if err != nil {
response.Fail(c, http.StatusBadRequest, 40002, "invalid user id")
return
}
ent, err := h.Svc.GetUserEntitlement(c.Request.Context(), id)
if errors.Is(err, admin.ErrUserNotFound) {
response.Fail(c, http.StatusNotFound, 40401, "user not found")
return
}
if err != nil {
response.Fail(c, http.StatusInternalServerError, 50021, "get entitlements failed")
return
}
response.OK(c, ent)
}
@@ -0,0 +1,105 @@
package integration_test
import (
"encoding/json"
"fmt"
"net/http"
"net/url"
"testing"
"time"
)
func TestUserEntitlements(t *testing.T) {
r, _ := setupAPIPool(t)
tok := adminLogin(t, r, "admin", "change-me")
_, code := doAdminJSON(t, r, http.MethodGet, "/api/v1/admin/users/"+fakeUUID()+"/entitlements", nil, "")
if code != http.StatusUnauthorized {
t.Fatalf("expected 401, got %d", code)
}
testBearer = ""
phone := fmt.Sprintf("1%010d", time.Now().UnixNano()%10_000_000_000)
nick := "ent_" + phone[7:]
env, key := doJSON(t, r, http.MethodPost, "/api/v1/auth/register", map[string]any{
"phone": phone, "password": "secret12", "nickname": nick,
}, "")
sess := decodeData[map[string]any](t, env.Data)
testBearer = sess["token"].(string)
t.Cleanup(func() { testBearer = "" })
env, key = doJSON(t, r, http.MethodPost, "/api/v1/profiles", map[string]any{
"relation": "self", "birth_date": "1990-01-01", "display_name": "权",
}, key)
profileID := decodeData[map[string]any](t, env.Data)["id"].(string)
env, key = doJSON(t, r, http.MethodPost, "/api/v1/reports/portrait", map[string]any{
"profile_id": profileID,
}, key)
reportID := decodeData[map[string]any](t, env.Data)["id"].(string)
env, key = doJSON(t, r, http.MethodPost, "/api/v1/orders", map[string]any{
"kind": "deep_access", "report_id": reportID,
}, key)
orderID := decodeData[map[string]any](t, env.Data)["order_id"].(string)
_, key = doJSON(t, r, http.MethodPost, "/api/v1/orders/"+orderID+"/pay-mock", nil, key)
env, code = doAdminJSON(t, r, http.MethodGet, "/api/v1/admin/users?q="+url.QueryEscape(nick), nil, tok)
if code != 200 {
t.Fatalf("list users %d", code)
}
var list struct {
Items []struct {
ID string `json:"id"`
} `json:"items"`
}
_ = json.Unmarshal(env.Data, &list)
userID := list.Items[0].ID
start := time.Now()
env, code = doAdminJSON(t, r, http.MethodGet, "/api/v1/admin/users/"+userID+"/entitlements", nil, tok)
if code != 200 || env.Code != 0 {
t.Fatalf("entitlements http=%d msg=%s", code, env.Message)
}
if time.Since(start) > 500*time.Millisecond {
t.Fatalf("too slow %v", time.Since(start))
}
var before struct {
Flags struct {
ViaMem bool `json:"report_detail_via_membership"`
Count int `json:"deep_access_count"`
} `json:"flags"`
Deep []any `json:"deep_accesses"`
}
_ = json.Unmarshal(env.Data, &before)
if before.Flags.Count < 1 || len(before.Deep) < 1 {
t.Fatalf("expected deep_access: %#v", before)
}
if before.Flags.ViaMem {
t.Fatal("expected membership inactive before grant")
}
_, code = doAdminJSON(t, r, http.MethodPost, "/api/v1/admin/users/"+userID+"/membership/grant",
map[string]string{"plan": "month"}, tok)
if code != 200 {
t.Fatalf("grant %d", code)
}
env, code = doAdminJSON(t, r, http.MethodGet, "/api/v1/admin/users/"+userID+"/entitlements", nil, tok)
if code != 200 {
t.Fatalf("after grant %d", code)
}
var after struct {
Flags struct {
ViaMem bool `json:"report_detail_via_membership"`
} `json:"flags"`
Membership struct {
Active bool `json:"active"`
} `json:"membership"`
}
_ = json.Unmarshal(env.Data, &after)
if !after.Flags.ViaMem || !after.Membership.Active {
t.Fatalf("expected active membership entitlement: %#v", after)
}
_ = key
}
@@ -0,0 +1,52 @@
package repository
import (
"context"
"time"
"github.com/google/uuid"
)
// DeepAccessBrief is one deep_access row for ops Entitlement.
type DeepAccessBrief struct {
ID uuid.UUID `json:"id"`
ReportID uuid.UUID `json:"report_id"`
ReportType string `json:"report_type,omitempty"`
CreatedAt time.Time `json:"created_at"`
}
// ListDeepAccessForUser returns recent deep accesses with report type.
func (r *AdminRepo) ListDeepAccessForUser(ctx context.Context, userID uuid.UUID, limit int) ([]DeepAccessBrief, error) {
if limit <= 0 || limit > 50 {
limit = 20
}
rows, err := r.Pool.Query(ctx, `
SELECT d.id, d.report_id, coalesce(g.type, ''), d.created_at
FROM deep_accesses d
LEFT JOIN growth_reports g ON g.id = d.report_id AND g.deleted_at IS NULL
WHERE d.user_id=$1 AND d.deleted_at IS NULL
ORDER BY d.created_at DESC
LIMIT $2`, userID, limit)
if err != nil {
return nil, err
}
defer rows.Close()
var out []DeepAccessBrief
for rows.Next() {
var b DeepAccessBrief
if err := rows.Scan(&b.ID, &b.ReportID, &b.ReportType, &b.CreatedAt); err != nil {
return nil, err
}
out = append(out, b)
}
return out, rows.Err()
}
// CountDeepAccessForUser counts non-deleted deep accesses.
func (r *AdminRepo) CountDeepAccessForUser(ctx context.Context, userID uuid.UUID) (int, error) {
var n int
err := r.Pool.QueryRow(ctx, `
SELECT count(*)::int FROM deep_accesses
WHERE user_id=$1 AND deleted_at IS NULL`, userID).Scan(&n)
return n, err
}
@@ -0,0 +1,64 @@
package admin
import (
"context"
"github.com/google/uuid"
"github.com/yuxingu/digital-psychology/apps/api/internal/repository"
)
// EntitlementFlags summarizes effective rights.
type EntitlementFlags struct {
ReportDetailViaMembership bool `json:"report_detail_via_membership"`
DeepAccessCount int `json:"deep_access_count"`
}
// UserEntitlement is the CommerceEntitlement ops read model.
type UserEntitlement struct {
UserID uuid.UUID `json:"user_id"`
Membership *repository.MembershipRow `json:"membership"`
AskPaidQuotaLeft int `json:"ask_paid_quota_left"`
Flags EntitlementFlags `json:"flags"`
DeepAccesses []repository.DeepAccessBrief `json:"deep_accesses"`
}
// GetUserEntitlement aggregates membership + deep access + quotas.
func (s *Service) GetUserEntitlement(ctx context.Context, userID uuid.UUID) (*UserEntitlement, error) {
ok, err := s.Repo.UserExists(ctx, userID)
if err != nil {
return nil, err
}
if !ok {
return nil, ErrUserNotFound
}
_, _, paidLeft, _, _, err := s.Repo.GetUserAccount(ctx, userID)
if err != nil {
return nil, err
}
mem, err := s.Reports.GetMembership(ctx, userID)
if err != nil {
return nil, err
}
count, err := s.Repo.CountDeepAccessForUser(ctx, userID)
if err != nil {
return nil, err
}
items, err := s.Repo.ListDeepAccessForUser(ctx, userID, 20)
if err != nil {
return nil, err
}
if items == nil {
items = []repository.DeepAccessBrief{}
}
return &UserEntitlement{
UserID: userID,
Membership: mem,
AskPaidQuotaLeft: paidLeft,
Flags: EntitlementFlags{
ReportDetailViaMembership: mem != nil && mem.Active,
DeepAccessCount: count,
},
DeepAccesses: items,
}, nil
}
@@ -0,0 +1,24 @@
# Backend Design: ECR-018 Entitlement
| ID | BD-2026-018 |
| Status | Approved |
| Coding | Loop authorized |
| Level | L2 |
| Migration | NO |
## Backend Change Boundary
```text
Domain: Entitlement read model (Membership DeepAccess ask quotas)
App: AdminHandler → admin.Service → AdminRepo + ReportRepo.GetMembership
API: GET /api/v1/admin/users/{id}/entitlements
Permission: admin.users.read
Migration: NO
UI: admin-h5 UserDetail「权益」Tab
```
## Out of boundary
Payment gateway · new entitlement matrix table · order mutation · UGC
Rollback: remove route + UI tab(无 schema
+1
View File
@@ -2,6 +2,7 @@
## 2026-08-07
- **ECR-018 Closed**Entitlement`GET /admin/users/:id/entitlements` · admin-h5 权益 Tab · Migration NO
- **ECR-017 Closed**AskOperationsAskSessionView 只读 · `admin.ask.read` · admin-h5 `/ask` · migration 000019
- **ECR-016 Closed**UserIntelligence`GET /admin/users/:id/insight` 只读聚合 · admin-h5 洞察 Tab · Migration NO
- **ECR-015 Closed**RedemptionCode(批次生成 · C端兑码 · 作废 · 审计)
+9
View File
@@ -0,0 +1,9 @@
# CODE_REVIEW — ECR-018
**Verdict:** Approve → Closed
Date: 2026-08-07 · Loop continuous
- Additive Entitlement 读模型;Migration NO
- Handler → Service → Repository;无真支付/UGC
- Integration AC mapped · OpenAPI updated
+17
View File
@@ -0,0 +1,17 @@
ecr: ECR-018
capability: CommerceEntitlement
bounded_context: Membership_Orders
parent: WAVE0-FROZEN
predecessor: ECR-017
change:
type: additive
breaking_change: false
migration_required: false
compatibility_notes: >
Additive read API GET /admin/users/{id}/entitlements.
Aggregates memberships + deep_accesses + ask quotas; no schema change.
apis:
- method: GET
path: /api/v1/admin/users/{id}/entitlements
change: added
+19
View File
@@ -0,0 +1,19 @@
# ECR-018
**Title:** Entitlement(用户权益只读薄切片)
**Status:** **Closed**
**Closed:** 2026-08-07Loop continuous
**Parent:** WAVE0-FROZEN · **Predecessor:** ECR-017 Closed
**Change Level:** L2
## Change
`GET /admin/users/:id/entitlements` 聚合 Membership/DeepAccess/问答额度;admin-h5 用户详情「权益」区。
## Forbidden
真支付 · 新权益表 · 改订单 · UGC
## Linked
Spec `ops-entitlement.md` · BD-2026-018 · CONTRACT_DIFF/ECR-018.yaml · TEST_REPORT/ECR-018.md
@@ -0,0 +1,8 @@
# ENGINEERING_SPEC — ECR-018
1. Repo DeepAccess 列表 + Entitlement 聚合
2. GET /users/:id/entitlements + OpenAPI
3. admin-h5 用户详情「权益」Tab
4. Integration · Closed
Migration: **NO**
@@ -0,0 +1,3 @@
# HANDOFF — ECR-018 Architect → Engineer
Loop continuous · Approved + Coding. Migration NO. Forbidden: 真支付/UGC/改订单.
@@ -0,0 +1,3 @@
# HANDOFF — ECR-018 Engineer → Reviewer
TestUserEntitlements PASS · 权益 Tab · Ready for Closed.
+3
View File
@@ -0,0 +1,3 @@
# PRODUCT_SPEC — ECR-018
对齐 ops-entitlement.md · Approved · Loop · L2 · Entitlement 只读聚合
+6
View File
@@ -0,0 +1,6 @@
# STATE — ECR-018
| Status | **Closed** |
| Phase | closed |
| Spec | ops-entitlement.md |
| Updated | 2026-08-07 |
+11
View File
@@ -0,0 +1,11 @@
id: TASK-018-ECR018
ecr: ECR-018
title: Entitlement implement
role: engineer
status: closed
change_level: L2
parent: WAVE0-FROZEN
predecessor: ECR-017
acceptance:
- Spec AC mapped
- No migration / no payment / no UGC
+31
View File
@@ -0,0 +1,31 @@
# TEST_REPORT — ECR-018 Entitlement
Date: 2026-08-07 · Loop continuous · commit: (pending)
## Commands
```bash
cd apps/api && go test ./internal/integration/ -run TestUserEntitlements -count=1
npm run build:admin
python3 scripts/ess-validate.py --phase review --ecr ECR-018
python3 scripts/ess-gate-check.py --ecr ECR-018
```
## Results
| Check | Result |
|-------|--------|
| TestUserEntitlements | PASS |
| build:admin | PASS |
| ess-validate review | PASS |
## AC
| ID | Evidence |
|----|----------|
| AC-F-01 | grant 后 flags.report_detail_via_membership=true |
| AC-F-02 | deep_access pay-mock 后 count≥1 |
| AC-F-03 | (空权益仍 200,覆盖于无会员前置态) |
| AC-S-01 | 无 token → 401 |
| AC-P-01 | GET &lt; 500ms |
| AC-O-01 | N/A 只读 |
+1
View File
@@ -22,3 +22,4 @@
| ECR-014 | MembershipPlan | **Closed** | Spec ops-membership-plan · BD-2026-014 · TEST_REPORT · Loop continuous |
| ECR-016 | UserIntelligence | **Closed** | Spec ops-user-intelligence · BD-2026-016 · TEST_REPORT · CODE_REVIEW · Loop continuous |
| ECR-017 | AskOperations | **Closed** | Spec ops-ask-operations · BD-2026-017 · migration 000019 · TEST_REPORT · CODE_REVIEW · Loop continuous |
| ECR-018 | Entitlement | **Closed** | Spec ops-entitlement · BD-2026-018 · TEST_REPORT · CODE_REVIEW · Loop continuous |
+1 -1
View File
@@ -30,4 +30,4 @@ Human 明文:**直接用 Loop,不用人工确认。**
| Done | Next |
|------|------|
| ECR-013A/B/014/015/016/017 Closed | **ECR-018** Entitlement 细权薄切片(或 ContentSafety);禁真支付/UGC |
| ECR-013A/B/014/015/016/017/018 Closed | **ECR-019** ContentSafety 薄切片(FilterRule 只读优先);禁真支付/UGC |
+18
View File
@@ -262,6 +262,24 @@ paths:
'404':
description: User not found
/api/v1/admin/users/{id}/entitlements:
get:
tags: [admin]
summary: User Entitlement aggregate (read-only)
description: Requires admin.users.read; Membership DeepAccess ask quotas
parameters:
- in: path
name: id
required: true
schema: { type: string, format: uuid }
responses:
'200':
description: OK
'401':
description: Unauthorized
'404':
description: User not found
/api/v1/admin/membership-plans:
get:
tags: [admin]