Files
apskel-pos-backend/internal/processor/audit_logger.go
T
efrilmandClaude Opus 5.5 798a36bd6c feat(enakgame): game sessions, rewards, vouchers, budgets and events
EnakGame phases 1-8 of docs/tasks-enakgame.md (EG-101 to EG-803), built on the
existing EnakPoint/EnakCoin wallet (docs/rfc-enakgame.md).

Foundation (phase 1)
- Migrations 000103-000106: games extended with organization, slug, status,
  entry cost and result rules, old games archived (not deleted); budgets,
  versioned reward configs, sessions and session rewards; the ledger types
  GAME_SPEND_REFUND, GAME_REWARD and REWARD_REDEEM_REFUND; audit_logs.
- AuditLogger writes in the caller's transaction only.
- enakgame.limit.user_daily and global_daily organization settings.

Games and sessions (phases 2-4)
- Admin /marketing/enakgame: games, reward config versions (immutable but for
  status, one ACTIVE per game), budgets with non-overlapping global periods and
  a daily job opening the next month.
- Customer /customer/enakgame: start (Idempotency-Key, entry cost and config
  frozen on the session), complete (result validation, reward engine, max_reward
  cap, daily limits via game_reward_counters, one GAME_REWARD per budget),
  automatic refunds for system errors and deactivated games, and a session job.
- Reward engine: FIXED, SCORE_BASED, OUTCOME_BASED, PROBABILITY (crypto/rand),
  rounded down.

Vouchers and budgets (phases 5-6)
- Migration 000108 and 000107: vouchers, codes, redemptions, cost attribution;
  Economy Guard counters.
- STATIC and CODE_POOL redemption in one transaction with the REDEEM PIN action;
  realized cost traced through the lots to the budget that paid the reward.
- Budget metrics: realized cost, forecast, exposure and status. Migrations
  000109-000110 add the wallet_lots indexes they need, built CONCURRENTLY.

Events (phase 7)
- Migration 000111: game events, each with its own EVENT budget. Event extras
  stack per PRD §16 defaults, with event and per-customer limits.

External vouchers (phase 8)
- VoucherProvider contract, two-step PENDING redemption and a recovery job,
  tested with a fake provider. No provider adapter is registered yet, so
  EXTERNAL vouchers stay out of the catalog.

Not yet decided before release: reward rounding, event stacking, budget
exhaustion policy and thresholds (RFC §19.2). Migrations 000103-000111 have
not been run on any shared database.

Also fixes a leftover PAYMENT filter in a wallet test and a data race in a
test PIN fake.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-10-07 20:53:14 +07:00

104 lines
2.8 KiB
Go

package processor
import (
"context"
"encoding/json"
"errors"
"fmt"
"strings"
"github.com/google/uuid"
"apskel-pos-be/internal/constants"
"apskel-pos-be/internal/entities"
"apskel-pos-be/internal/repository"
)
// ErrInvalidAuditEntry means an audit entry lacks what every row must say.
var ErrInvalidAuditEntry = errors.New("invalid audit entry")
// AuditEntry is one change to record. Before and After are marshalled to JSON; leave
// one nil when there was nothing before (a create) or after (a delete).
type AuditEntry struct {
OrganizationID uuid.UUID
// USER or SYSTEM. A USER entry needs ActorID.
ActorType string
ActorID *uuid.UUID
EntityType string
EntityID uuid.UUID
Action string
Before any
After any
Reason *string
Source string
}
// AuditLogger writes audit_logs (docs/rfc-enakgame.md §13). It must be called inside
// the transaction that makes the change, so the change and its row commit or roll
// back together: outside one it returns repository.ErrAuditTxRequired.
type AuditLogger struct {
repo repository.AuditLogRepository
}
func NewAuditLogger(repo repository.AuditLogRepository) *AuditLogger {
return &AuditLogger{repo: repo}
}
func (l *AuditLogger) Record(ctx context.Context, e AuditEntry) error {
invalid := func(format string, args ...any) error {
return fmt.Errorf("%w: %s", ErrInvalidAuditEntry, fmt.Sprintf(format, args...))
}
switch {
case e.OrganizationID == uuid.Nil:
return invalid("organization is required")
case e.ActorType != constants.AuditActorUser && e.ActorType != constants.AuditActorSystem:
return invalid("unknown actor type %q", e.ActorType)
case e.ActorType == constants.AuditActorUser && isNilID(e.ActorID):
return invalid("a USER entry requires the actor")
case strings.TrimSpace(e.EntityType) == "" || e.EntityID == uuid.Nil:
return invalid("entity is required")
case strings.TrimSpace(e.Action) == "":
return invalid("action is required")
case strings.TrimSpace(e.Source) == "":
return invalid("source is required")
}
before, err := auditJSON(e.Before)
if err != nil {
return invalid("before: %v", err)
}
after, err := auditJSON(e.After)
if err != nil {
return invalid("after: %v", err)
}
return l.repo.Insert(ctx, &entities.AuditLog{
OrganizationID: e.OrganizationID,
ActorType: e.ActorType,
ActorID: e.ActorID,
EntityType: e.EntityType,
EntityID: e.EntityID,
Action: e.Action,
Before: before,
After: after,
Reason: e.Reason,
Source: e.Source,
})
}
func auditJSON(v any) (json.RawMessage, error) {
if v == nil {
return nil, nil
}
raw, ok := v.(json.RawMessage)
if !ok {
var err error
if raw, err = json.Marshal(v); err != nil {
return nil, err
}
}
// A nil pointer is nothing, the same as nil.
if string(raw) == "null" {
return nil, nil
}
return raw, nil
}