EnakGame phases 1-8 of docs/tasks-enakgame.md (EG-101 to EG-803), built on the existing EnakPoint/EnakCoin wallet (docs/rfc-enakgame.md). Foundation (phase 1) - Migrations 000103-000106: games extended with organization, slug, status, entry cost and result rules, old games archived (not deleted); budgets, versioned reward configs, sessions and session rewards; the ledger types GAME_SPEND_REFUND, GAME_REWARD and REWARD_REDEEM_REFUND; audit_logs. - AuditLogger writes in the caller's transaction only. - enakgame.limit.user_daily and global_daily organization settings. Games and sessions (phases 2-4) - Admin /marketing/enakgame: games, reward config versions (immutable but for status, one ACTIVE per game), budgets with non-overlapping global periods and a daily job opening the next month. - Customer /customer/enakgame: start (Idempotency-Key, entry cost and config frozen on the session), complete (result validation, reward engine, max_reward cap, daily limits via game_reward_counters, one GAME_REWARD per budget), automatic refunds for system errors and deactivated games, and a session job. - Reward engine: FIXED, SCORE_BASED, OUTCOME_BASED, PROBABILITY (crypto/rand), rounded down. Vouchers and budgets (phases 5-6) - Migration 000108 and 000107: vouchers, codes, redemptions, cost attribution; Economy Guard counters. - STATIC and CODE_POOL redemption in one transaction with the REDEEM PIN action; realized cost traced through the lots to the budget that paid the reward. - Budget metrics: realized cost, forecast, exposure and status. Migrations 000109-000110 add the wallet_lots indexes they need, built CONCURRENTLY. Events (phase 7) - Migration 000111: game events, each with its own EVENT budget. Event extras stack per PRD §16 defaults, with event and per-customer limits. External vouchers (phase 8) - VoucherProvider contract, two-step PENDING redemption and a recovery job, tested with a fake provider. No provider adapter is registered yet, so EXTERNAL vouchers stay out of the catalog. Not yet decided before release: reward rounding, event stacking, budget exhaustion policy and thresholds (RFC §19.2). Migrations 000103-000111 have not been run on any shared database. Also fixes a leftover PAYMENT filter in a wallet test and a data race in a test PIN fake. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
140 lines
5.3 KiB
Go
140 lines
5.3 KiB
Go
package processor
|
|
|
|
import (
|
|
"context"
|
|
"testing"
|
|
"time"
|
|
|
|
"github.com/google/uuid"
|
|
"github.com/stretchr/testify/assert"
|
|
"github.com/stretchr/testify/require"
|
|
"golang.org/x/crypto/bcrypt"
|
|
|
|
"apskel-pos-be/internal/models"
|
|
"apskel-pos-be/internal/repository"
|
|
)
|
|
|
|
func TestCheckNewPin(t *testing.T) {
|
|
birth := time.Date(1990, 3, 14, 0, 0, 0, 0, time.UTC)
|
|
|
|
for _, ok := range []string{"482913", "019283", "135790", "112233"} {
|
|
assert.NoError(t, checkNewPin(ok, ok, &birth), ok)
|
|
}
|
|
for name, c := range map[string][2]string{
|
|
"too short": {"12345", "12345"},
|
|
"too long": {"1234567", "1234567"},
|
|
"not digits": {"12a456", "12a456"},
|
|
"confirmation": {"482913", "482914"},
|
|
"one digit": {"111111", "111111"},
|
|
"zeros": {"000000", "000000"},
|
|
"run up": {"123456", "123456"},
|
|
"run up from 4": {"456789", "456789"},
|
|
"run down": {"654321", "654321"},
|
|
"run down from 9": {"987654", "987654"},
|
|
"birth date DDMMYY": {"140390", "140390"},
|
|
"birth date YYMMDD": {"900314", "900314"},
|
|
} {
|
|
err := checkNewPin(c[0], c[1], &birth)
|
|
assert.ErrorIs(t, err, ErrInvalidPinInput, name)
|
|
assert.NotContains(t, err.Error(), c[0], "%s: the message must not echo the PIN", name)
|
|
}
|
|
// Without a birth date only the other rules apply.
|
|
assert.NoError(t, checkNewPin("140390", "140390", nil))
|
|
}
|
|
|
|
// pinRepoFake holds one customer's PIN state, with the lock rules of RecordFailure.
|
|
type pinRepoFake struct {
|
|
repository.CustomerPinRepository
|
|
state repository.CustomerPinState
|
|
}
|
|
|
|
func (f *pinRepoFake) GetState(context.Context, uuid.UUID) (*repository.CustomerPinState, error) {
|
|
s := f.state
|
|
return &s, nil
|
|
}
|
|
|
|
func (f *pinRepoFake) RecordFailure(_ context.Context, _ uuid.UUID, maxAttempts int, now, lockUntil time.Time) (int, *time.Time, error) {
|
|
if f.state.LockedUntil != nil && !f.state.LockedUntil.After(now) {
|
|
f.state.FailedAttempts, f.state.LockedUntil = 1, nil
|
|
} else {
|
|
f.state.FailedAttempts++
|
|
if f.state.FailedAttempts >= maxAttempts {
|
|
f.state.LockedUntil = &lockUntil
|
|
}
|
|
}
|
|
return f.state.FailedAttempts, f.state.LockedUntil, nil
|
|
}
|
|
|
|
func (f *pinRepoFake) ClearFailures(context.Context, uuid.UUID) error {
|
|
f.state.FailedAttempts, f.state.LockedUntil = 0, nil
|
|
return nil
|
|
}
|
|
|
|
func (f *pinRepoFake) InsertEvent(context.Context, repository.CustomerSecurityEvent) error {
|
|
return nil
|
|
}
|
|
|
|
func TestCustomerPin_LockIsPushedThroughFCM(t *testing.T) {
|
|
customer := uuid.New()
|
|
hash, err := bcrypt.GenerateFromPassword([]byte("482913"), bcrypt.MinCost)
|
|
require.NoError(t, err)
|
|
h := string(hash)
|
|
repo := &pinRepoFake{state: repository.CustomerPinState{CustomerID: customer, PinHash: &h}}
|
|
notifier := ¬ifierFake{}
|
|
p := NewCustomerPinProcessor(repo, nil, notifier)
|
|
now := time.Date(2026, 9, 30, 3, 0, 0, 0, time.UTC)
|
|
p.now = func() time.Time { return now }
|
|
ctx := context.Background()
|
|
|
|
for i := 0; i < 4; i++ {
|
|
_ = p.VerifyPin(ctx, customer, "000000", PinActionPay, models.CustomerPinRequestInfo{})
|
|
}
|
|
assert.Empty(t, notifier.pushes[customer], "no push before the PIN locks")
|
|
|
|
err = p.VerifyPin(ctx, customer, "000000", PinActionPay, models.CustomerPinRequestInfo{})
|
|
var pinErr *PinError
|
|
require.ErrorAs(t, err, &pinErr)
|
|
assert.Equal(t, PinErrLocked, pinErr.Code)
|
|
|
|
// Attempts while locked do not push again.
|
|
_ = p.VerifyPin(ctx, customer, "482913", PinActionPay, models.CustomerPinRequestInfo{})
|
|
|
|
require.Len(t, notifier.pushes[customer], 1)
|
|
push := notifier.pushes[customer][0]
|
|
assert.Equal(t, "PIN terkunci", push.title)
|
|
assert.Equal(t, "PIN EnakPoint kamu terkunci sampai 30 Sep 2026 10:30 WIB karena salah dimasukkan 5 kali. Jika ini bukan kamu, segera reset PIN lewat aplikasi.", push.body)
|
|
assert.Equal(t, map[string]string{"type": NotificationTypePinLocked, "locked_until": "2026-09-30T03:30:00Z"}, push.data)
|
|
}
|
|
|
|
// EG-503: redeeming a voucher follows the same PIN rules: five wrong attempts lock
|
|
// it for 30 minutes, and a locked PIN is refused even when right. A transfer hold
|
|
// after a reset does not apply to it.
|
|
func TestCustomerPin_RedeemFollowsTheLockRules(t *testing.T) {
|
|
customer := uuid.New()
|
|
hash, err := bcrypt.GenerateFromPassword([]byte("482913"), bcrypt.MinCost)
|
|
require.NoError(t, err)
|
|
h := string(hash)
|
|
now := time.Date(2026, 10, 7, 3, 0, 0, 0, time.UTC)
|
|
held := now.Add(24 * time.Hour)
|
|
repo := &pinRepoFake{state: repository.CustomerPinState{CustomerID: customer, PinHash: &h, TransferBlockedUntil: &held}}
|
|
p := NewCustomerPinProcessor(repo, nil, ¬ifierFake{})
|
|
p.now = func() time.Time { return now }
|
|
ctx := context.Background()
|
|
|
|
require.NoError(t, p.VerifyPin(ctx, customer, "482913", PinActionRedeem, models.CustomerPinRequestInfo{}), "not held like a transfer")
|
|
var pinErr *PinError
|
|
for i := 1; i <= 4; i++ {
|
|
err := p.VerifyPin(ctx, customer, "000000", PinActionRedeem, models.CustomerPinRequestInfo{})
|
|
require.ErrorAs(t, err, &pinErr)
|
|
assert.Equal(t, PinErrInvalid, pinErr.Code)
|
|
assert.Equal(t, 5-i, pinErr.RemainingAttempts)
|
|
}
|
|
err = p.VerifyPin(ctx, customer, "000000", PinActionRedeem, models.CustomerPinRequestInfo{})
|
|
require.ErrorAs(t, err, &pinErr)
|
|
assert.Equal(t, PinErrLocked, pinErr.Code)
|
|
assert.Equal(t, now.Add(30*time.Minute), *pinErr.Until)
|
|
err = p.VerifyPin(ctx, customer, "482913", PinActionRedeem, models.CustomerPinRequestInfo{})
|
|
require.ErrorAs(t, err, &pinErr)
|
|
assert.Equal(t, PinErrLocked, pinErr.Code, "locked even with the right PIN")
|
|
}
|