- 체인 nonce 경쟁 조건 수정 (operatorMu + per-user mutex) - 등록/SSAFY 원자적 트랜잭션 (wallet+profile 롤백 보장) - IdempotencyRequired 미들웨어 (SETNX 원자적 클레임) - 런치 티켓 API (JWT URL 노출 방지) - HttpOnly 쿠키 refresh token - SSAFY OAuth state 파라미터 (CSRF 방지) - Refresh 시 DB 조회로 최신 role 사용 - 공지사항/유저목록 페이지네이션 - BodyLimit 미들웨어 (1MB, upload 제외) - 입력 검증 강화 (닉네임, 게임데이터, 공지 길이) - 에러 메시지 내부 정보 노출 방지 - io.LimitReader (RPC 10MB, SSAFY 1MB) - RequestID 비출력 문자 제거 - 단위 테스트 (auth 11, announcement 9, bossraid 16) Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
150 lines
3.6 KiB
Go
150 lines
3.6 KiB
Go
package chain
|
|
|
|
import (
|
|
"bytes"
|
|
"encoding/json"
|
|
"fmt"
|
|
"io"
|
|
"net/http"
|
|
"sync/atomic"
|
|
"time"
|
|
)
|
|
|
|
type rpcRequest struct {
|
|
JSONRPC string `json:"jsonrpc"`
|
|
ID int64 `json:"id"`
|
|
Method string `json:"method"`
|
|
Params any `json:"params"`
|
|
}
|
|
|
|
type rpcResponse struct {
|
|
JSONRPC string `json:"jsonrpc"`
|
|
ID any `json:"id"`
|
|
Result json.RawMessage `json:"result,omitempty"`
|
|
Error *rpcError `json:"error,omitempty"`
|
|
}
|
|
|
|
type rpcError struct {
|
|
Code int `json:"code"`
|
|
Message string `json:"message"`
|
|
}
|
|
|
|
func (e *rpcError) Error() string {
|
|
return fmt.Sprintf("RPC error %d: %s", e.Code, e.Message)
|
|
}
|
|
|
|
// Client is a JSON-RPC 2.0 client for the TOL Chain node.
|
|
type Client struct {
|
|
nodeURL string
|
|
http *http.Client
|
|
idSeq atomic.Int64
|
|
}
|
|
|
|
func NewClient(nodeURL string) *Client {
|
|
return &Client{
|
|
nodeURL: nodeURL,
|
|
http: &http.Client{Timeout: 10 * time.Second},
|
|
}
|
|
}
|
|
|
|
// Call invokes a JSON-RPC method and unmarshals the result into out.
|
|
func (c *Client) Call(method string, params any, out any) error {
|
|
reqBody := rpcRequest{
|
|
JSONRPC: "2.0",
|
|
ID: c.idSeq.Add(1),
|
|
Method: method,
|
|
Params: params,
|
|
}
|
|
data, err := json.Marshal(reqBody)
|
|
if err != nil {
|
|
return fmt.Errorf("marshal RPC request: %w", err)
|
|
}
|
|
|
|
resp, err := c.http.Post(c.nodeURL, "application/json", bytes.NewReader(data))
|
|
if err != nil {
|
|
return fmt.Errorf("RPC network error: %w", err)
|
|
}
|
|
defer resp.Body.Close()
|
|
|
|
if resp.StatusCode < 200 || resp.StatusCode >= 300 {
|
|
return fmt.Errorf("RPC HTTP error: status %d", resp.StatusCode)
|
|
}
|
|
|
|
body, err := io.ReadAll(io.LimitReader(resp.Body, 10*1024*1024))
|
|
if err != nil {
|
|
return fmt.Errorf("read RPC response: %w", err)
|
|
}
|
|
|
|
var rpcResp rpcResponse
|
|
if err := json.Unmarshal(body, &rpcResp); err != nil {
|
|
return fmt.Errorf("unmarshal RPC response: %w", err)
|
|
}
|
|
if rpcResp.Error != nil {
|
|
return rpcResp.Error
|
|
}
|
|
if out != nil {
|
|
if err := json.Unmarshal(rpcResp.Result, out); err != nil {
|
|
return fmt.Errorf("unmarshal RPC result: %w", err)
|
|
}
|
|
}
|
|
return nil
|
|
}
|
|
|
|
// --- Typed convenience methods ---
|
|
|
|
type BalanceResult struct {
|
|
Address string `json:"address"`
|
|
Balance uint64 `json:"balance"`
|
|
Nonce uint64 `json:"nonce"`
|
|
}
|
|
|
|
func (c *Client) GetBalance(address string) (*BalanceResult, error) {
|
|
var result BalanceResult
|
|
err := c.Call("getBalance", map[string]string{"address": address}, &result)
|
|
return &result, err
|
|
}
|
|
|
|
func (c *Client) GetAsset(id string) (json.RawMessage, error) {
|
|
var result json.RawMessage
|
|
err := c.Call("getAsset", map[string]string{"id": id}, &result)
|
|
return result, err
|
|
}
|
|
|
|
func (c *Client) GetAssetsByOwner(owner string, offset, limit int) (json.RawMessage, error) {
|
|
var result json.RawMessage
|
|
err := c.Call("getAssetsByOwner", map[string]any{
|
|
"owner": owner, "offset": offset, "limit": limit,
|
|
}, &result)
|
|
return result, err
|
|
}
|
|
|
|
func (c *Client) GetInventory(owner string) (json.RawMessage, error) {
|
|
var result json.RawMessage
|
|
err := c.Call("getInventory", map[string]string{"owner": owner}, &result)
|
|
return result, err
|
|
}
|
|
|
|
func (c *Client) GetActiveListings(offset, limit int) (json.RawMessage, error) {
|
|
var result json.RawMessage
|
|
err := c.Call("getActiveListings", map[string]any{
|
|
"offset": offset, "limit": limit,
|
|
}, &result)
|
|
return result, err
|
|
}
|
|
|
|
func (c *Client) GetListing(id string) (json.RawMessage, error) {
|
|
var result json.RawMessage
|
|
err := c.Call("getListing", map[string]string{"id": id}, &result)
|
|
return result, err
|
|
}
|
|
|
|
type SendTxResult struct {
|
|
TxID string `json:"tx_id"`
|
|
}
|
|
|
|
func (c *Client) SendTx(tx any) (*SendTxResult, error) {
|
|
var result SendTxResult
|
|
err := c.Call("sendTx", tx, &result)
|
|
return &result, err
|
|
}
|