Adds POST /customer/orders/:id/pay-with-points (docs/prd-point-coin.md F9, PC-306) for the customer app and self-order. It uses the same payment path as the cashier, approved by the customer's PIN instead of a code: the session alone is not enough (K8), and a wrong PIN takes nothing and counts toward the lock. A customer can pay only their own order; any other order, and one that does not exist, answer 404 alike, so the endpoint does not reveal other customers' orders. The method is the organization's EnakPoint method, no cashier is recorded, and settling the order triggers earning through the same onOrderPaid hook as every other payment. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
36 lines
1.2 KiB
Go
36 lines
1.2 KiB
Go
package handler
|
|
|
|
import (
|
|
"github.com/gin-gonic/gin"
|
|
|
|
"apskel-pos-be/internal/contract"
|
|
"apskel-pos-be/internal/service"
|
|
"apskel-pos-be/internal/util"
|
|
)
|
|
|
|
// CustomerOrderPaymentHandler serves POST /customer/orders/:id/pay-with-points
|
|
// (docs/prd-point-coin.md F9). The body holds the PIN, so it is never logged.
|
|
type CustomerOrderPaymentHandler struct {
|
|
payments service.CustomerOrderPaymentService
|
|
}
|
|
|
|
func NewCustomerOrderPaymentHandler(payments service.CustomerOrderPaymentService) *CustomerOrderPaymentHandler {
|
|
return &CustomerOrderPaymentHandler{payments: payments}
|
|
}
|
|
|
|
func (h *CustomerOrderPaymentHandler) PayWithPoints(c *gin.Context) {
|
|
customerID, ok := customerIDFromGin(c, "CustomerOrderPaymentHandler::PayWithPoints")
|
|
if !ok {
|
|
return
|
|
}
|
|
orderID, ok := parseUUIDParam(c, "id", "CustomerOrderPaymentHandler::PayWithPoints")
|
|
if !ok {
|
|
return
|
|
}
|
|
var req contract.PayWithPointsRequest
|
|
if !bindPinRequest(c, &req, "CustomerOrderPaymentHandler::PayWithPoints") {
|
|
return
|
|
}
|
|
util.HandleResponse(c.Writer, c.Request, h.payments.PayWithPoints(c.Request.Context(), customerID, orderID, &req, pinRequestInfo(c)), "CustomerOrderPaymentHandler::PayWithPoints")
|
|
}
|