feat(loyalty): pay own orders with EnakPoint from the app
Adds POST /customer/orders/:id/pay-with-points (docs/prd-point-coin.md F9, PC-306) for the customer app and self-order. It uses the same payment path as the cashier, approved by the customer's PIN instead of a code: the session alone is not enough (K8), and a wrong PIN takes nothing and counts toward the lock. A customer can pay only their own order; any other order, and one that does not exist, answer 404 alike, so the endpoint does not reveal other customers' orders. The method is the organization's EnakPoint method, no cashier is recorded, and settling the order triggers earning through the same onOrderPaid hook as every other payment. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 5.5
parent
4b3beaed41
commit
43eac0ced4
@@ -91,7 +91,7 @@ func newPointPaymentEnv(t *testing.T) *pointPaymentEnv {
|
||||
txManager: txm,
|
||||
}
|
||||
e.orders.SetLoyalty(NewEarningProcessor(repository.NewEarningRepository(db), settings, wallet, txm))
|
||||
e.orders.SetPointPayments(e.payments, e.codes)
|
||||
e.orders.SetPointPayments(e.payments, e.codes, pinVerifierFake{good: "482913"})
|
||||
|
||||
// The outlet earns 1 EnakPoint per Rp 100 and accepts EnakPoint.
|
||||
s, err := settings.Outlet(context.Background(), e.outlet)
|
||||
@@ -332,3 +332,45 @@ func TestPointPayment_ConcurrentForOneCustomer(t *testing.T) {
|
||||
assert.NotEqual(t, customer, d.CustomerID, d.Check)
|
||||
}
|
||||
}
|
||||
|
||||
func TestPointPayment_InApp(t *testing.T) {
|
||||
e := newPointPaymentEnv(t)
|
||||
owner := e.customerWith(100000)
|
||||
stranger := e.customerWith(100000)
|
||||
order := e.order(owner, 60000)
|
||||
info := models.CustomerPinRequestInfo{}
|
||||
|
||||
// Another customer cannot pay it, and is not told it exists.
|
||||
_, err := e.orders.PayWithPointsInApp(e.ctx, stranger, order, 1000, "482913", info)
|
||||
assert.ErrorIs(t, err, repository.ErrPointPaymentOrderNotFound)
|
||||
_, err = e.orders.PayWithPointsInApp(e.ctx, owner, uuid.New(), 1000, "482913", info)
|
||||
assert.ErrorIs(t, err, repository.ErrPointPaymentOrderNotFound)
|
||||
|
||||
// The session alone is not enough: a wrong PIN takes nothing.
|
||||
_, err = e.orders.PayWithPointsInApp(e.ctx, owner, order, 1000, "000000", info)
|
||||
var pe *PinError
|
||||
require.ErrorAs(t, err, &pe)
|
||||
assert.Equal(t, PinErrInvalid, pe.Code)
|
||||
assert.Equal(t, int64(100000), e.balance(owner))
|
||||
|
||||
// The owner pays part, then the rest, with the same rules as at the cashier.
|
||||
payment, err := e.orders.PayWithPointsInApp(e.ctx, owner, order, 10000, "482913", info)
|
||||
require.NoError(t, err)
|
||||
assert.Equal(t, int64(10000), *payment.PointsUsed)
|
||||
status, remaining := e.orderState(order)
|
||||
assert.Equal(t, "partial", status)
|
||||
assert.Equal(t, 50000.0, remaining)
|
||||
|
||||
_, err = e.orders.PayWithPointsInApp(e.ctx, owner, order, 50001, "482913", info)
|
||||
assert.ErrorIs(t, err, ErrPointPaymentRejected, "not more than what is left")
|
||||
_, err = e.orders.PayWithPointsInApp(e.ctx, owner, order, 50000, "482913", info)
|
||||
require.NoError(t, err)
|
||||
status, _ = e.orderState(order)
|
||||
assert.Equal(t, "completed", status)
|
||||
assert.Equal(t, int64(40000), e.balance(owner))
|
||||
assert.Equal(t, int64(100000), e.balance(stranger))
|
||||
|
||||
var createdBy *string
|
||||
require.NoError(t, e.db.Raw(`SELECT created_by_user::text FROM wallet_transactions WHERE customer_id = ? AND type = 'PAYMENT' LIMIT 1`, owner).Scan(&createdBy).Error)
|
||||
assert.Nil(t, createdBy, "no cashier took an in-app payment")
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user