Reapply "feat(loyalty): EnakPoint & EnakCoin" (#32)
This reverts commit 4e24f9bbb0.
This commit is contained in:
@@ -0,0 +1,101 @@
|
||||
package processor
|
||||
|
||||
import (
|
||||
"context"
|
||||
"crypto/rand"
|
||||
"errors"
|
||||
"fmt"
|
||||
"math/big"
|
||||
"strings"
|
||||
"time"
|
||||
|
||||
"github.com/google/uuid"
|
||||
|
||||
"apskel-pos-be/internal/models"
|
||||
"apskel-pos-be/internal/repository"
|
||||
)
|
||||
|
||||
const (
|
||||
paymentCodeDigits = 6
|
||||
paymentCodeTTL = 2 * time.Minute
|
||||
paymentCodeAttempts = 5
|
||||
// PaymentCodeQRPrefix marks a scanned QR as an EnakPoint payment code.
|
||||
PaymentCodeQRPrefix = "enakpoint:"
|
||||
)
|
||||
|
||||
// ErrPaymentCodeInvalid means the code was never issued, has expired, has been used,
|
||||
// or belongs to another customer.
|
||||
var ErrPaymentCodeInvalid = errors.New("payment code is invalid or expired")
|
||||
|
||||
type pinVerifier interface {
|
||||
VerifyPin(ctx context.Context, customerID uuid.UUID, pin string, action PinAction, info models.CustomerPinRequestInfo) error
|
||||
}
|
||||
|
||||
// PaymentCodeProcessor issues and redeems the one-time codes that let a cashier take a
|
||||
// customer's EnakPoint (docs/prd-point-coin.md F9, K8). The customer approves with
|
||||
// their PIN on their own phone and shows the code; the PIN is never typed on the
|
||||
// cashier's device.
|
||||
type PaymentCodeProcessor struct {
|
||||
codes repository.PaymentCodeRepository
|
||||
pins pinVerifier
|
||||
now func() time.Time
|
||||
}
|
||||
|
||||
func NewPaymentCodeProcessor(codes repository.PaymentCodeRepository, pins pinVerifier) *PaymentCodeProcessor {
|
||||
return &PaymentCodeProcessor{codes: codes, pins: pins, now: time.Now}
|
||||
}
|
||||
|
||||
// Issue checks the customer's PIN and returns a fresh 6-digit code, valid for two
|
||||
// minutes and bound to the customer. A new code retires the previous one.
|
||||
func (p *PaymentCodeProcessor) Issue(ctx context.Context, customerID uuid.UUID, pin string, info models.CustomerPinRequestInfo) (*models.PaymentCode, error) {
|
||||
if err := p.pins.VerifyPin(ctx, customerID, pin, PinActionPay, info); err != nil {
|
||||
return nil, err
|
||||
}
|
||||
for attempt := 0; attempt < paymentCodeAttempts; attempt++ {
|
||||
code, err := randomDigits(paymentCodeDigits)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
err = p.codes.Save(ctx, code, customerID, paymentCodeTTL)
|
||||
if errors.Is(err, repository.ErrPaymentCodeTaken) {
|
||||
continue
|
||||
}
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
return &models.PaymentCode{
|
||||
Code: code,
|
||||
QRPayload: PaymentCodeQRPrefix + code,
|
||||
ExpiresAt: p.now().Add(paymentCodeTTL),
|
||||
}, nil
|
||||
}
|
||||
return nil, fmt.Errorf("could not draw a free payment code after %d attempts", paymentCodeAttempts)
|
||||
}
|
||||
|
||||
// Redeem uses a code up for a payment by the given customer. It accepts the code as
|
||||
// typed or as scanned from the QR. Every failure is ErrPaymentCodeInvalid.
|
||||
func (p *PaymentCodeProcessor) Redeem(ctx context.Context, code string, customerID uuid.UUID) error {
|
||||
code = strings.TrimPrefix(strings.TrimSpace(code), PaymentCodeQRPrefix)
|
||||
if len(code) != paymentCodeDigits {
|
||||
return ErrPaymentCodeInvalid
|
||||
}
|
||||
err := p.codes.Consume(ctx, code, customerID)
|
||||
if errors.Is(err, repository.ErrPaymentCodeNotFound) || errors.Is(err, repository.ErrPaymentCodeWrongCustomer) {
|
||||
return ErrPaymentCodeInvalid
|
||||
}
|
||||
return err
|
||||
}
|
||||
|
||||
// randomDigits draws n decimal digits from a cryptographic source, so codes cannot be
|
||||
// predicted.
|
||||
func randomDigits(n int) (string, error) {
|
||||
var b strings.Builder
|
||||
for i := 0; i < n; i++ {
|
||||
d, err := rand.Int(rand.Reader, big.NewInt(10))
|
||||
if err != nil {
|
||||
return "", fmt.Errorf("failed to draw a payment code: %w", err)
|
||||
}
|
||||
b.WriteByte(byte('0' + d.Int64()))
|
||||
}
|
||||
return b.String(), nil
|
||||
}
|
||||
Reference in New Issue
Block a user