- plan-features.ts: globalBlocklist 'curated'|'full' (curated = 30-domain stub,
TODO real ~1-2k HaGeZi subset); maxAppDevices vs maxProtectedDevices split
(legend maxProtectedDevices: 2); mail 1/3/Infinity
- limit-enforcement structured errors on mail/connect, custom-domains/add, devices/enroll
({ error:'plan_limit', resource, current, limit }); approved-own-submissions already
excluded from custom-domain count (slot frees on approval)
- server/utils/downgrade-reconciliation.ts: founding-member exemption; re-upgrade
reactivates paused mail + degraded devices; downgrade pauses newest-N mail accounts
(isActive=false, pausedAt, pausedReason; pre-pause sets nextScanAt=now for a final
sweep — real direct IMAP scan is TODO/stub); degrades excess device profiles
(status='degraded', degradedAt); free → globalBlocklistGraceUntil = now+14d;
custom domains grandfathered
- set-plan.post.ts + stripe/webhook.post.ts: run reconciliation on plan change;
set-plan accepts { foundingMember } for testing
- GET /api/plan/change-preview?to=<plan>: gains/keeps/changes per resource (8 axes),
founding-member → direction 'same'
- me.get.ts: + foundingMember, globalBlocklistGraceUntil, planLimits block
- blocklist + mail-scan honour globalBlocklistGraceUntil (grace → treat as 'full')
- db: countMailConnections/getMailConnections exclude paused; getAllMailConnections;
getDeviceBlocklistMode (active|grace|passthrough|revoked)
- migration 20260511_tier_system_phase2 (profiles.founding_member +
global_blocklist_grace_until; mail_connections.paused_at/paused_reason;
protected_devices.degraded_at). prisma generate + build:backend clean.
TODOs (separate tickets): founding-member auto-counter on signup; real direct IMAP
final-scan (not just nextScanAt nudge); real curated blocklist data + wiring the
stub into the blocklist response for free users.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
65 lines
2.0 KiB
TypeScript
65 lines
2.0 KiB
TypeScript
import { listUserDevices, registerDevice } from "../../db/devices";
|
|
import { getProfile } from "../../db/profile";
|
|
import { getPlanLimits } from "../../utils/plan-features";
|
|
|
|
/**
|
|
* POST /api/devices/register
|
|
*
|
|
* Body: { deviceId: string, platform: string, model?: string, name?: string }
|
|
*
|
|
* Idempotent: gleiche deviceId für gleichen User → updated lastSeenAt + 200.
|
|
* Wenn neues Device + Limit erreicht → 403 mit { error, devices } damit der
|
|
* Frontend-Drawer dem User die Wahl gibt, welches Gerät er freigibt.
|
|
*/
|
|
export default defineEventHandler(async (event) => {
|
|
// Bootstrap: kein Device-Check sonst wäre erstes Register unmöglich (chicken-egg)
|
|
const user = await requireUser(event, { skipDeviceCheck: true });
|
|
const body = await readBody(event);
|
|
const { deviceId, platform, model, name } = body as {
|
|
deviceId?: string;
|
|
platform?: string;
|
|
model?: string;
|
|
name?: string;
|
|
};
|
|
|
|
if (!deviceId || !platform) {
|
|
throw createError({
|
|
statusCode: 400,
|
|
message: "deviceId und platform required",
|
|
});
|
|
}
|
|
if (!["ios", "android", "web"].includes(platform)) {
|
|
throw createError({ statusCode: 400, message: "invalid platform" });
|
|
}
|
|
|
|
const profile = await getProfile(user.id);
|
|
const limits = getPlanLimits(profile?.plan ?? "free");
|
|
|
|
try {
|
|
const { device, created } = await registerDevice({
|
|
userId: user.id,
|
|
deviceId,
|
|
platform,
|
|
model: model ?? null,
|
|
name: name ?? null,
|
|
maxDevices: limits.maxAppDevices,
|
|
});
|
|
return { device, created, max: limits.maxAppDevices };
|
|
} catch (err: any) {
|
|
if (err.code === "DEVICE_LIMIT_REACHED") {
|
|
const devices = await listUserDevices(user.id);
|
|
throw createError({
|
|
statusCode: 403,
|
|
statusMessage: "device_limit_reached",
|
|
data: {
|
|
error: "device_limit_reached",
|
|
max: limits.maxAppDevices,
|
|
plan: profile?.plan ?? "free",
|
|
devices,
|
|
},
|
|
});
|
|
}
|
|
throw err;
|
|
}
|
|
});
|