Adds GET /customer/wallet/transfer/recipient?phone= and
POST /customer/wallet/transfer (docs/prd-point-coin.md F5, Q4, Q16,
PC-402).
The recipient is found by phone number and must be an active customer of
the same organization, not the walk-in customer and not the sender. A
number of another organization answers 404 like an unknown one, so the
check does not reveal who uses the app elsewhere. The recipient check
returns the name and number masked ("Bu*** Sa***", "08**-****-1234").
The organization's transfer settings apply: transfers turned off, the
minimum, the maximum per transaction and the daily limit per currency,
which starts over at midnight WIB. Everything the request alone can get
wrong is refused before the PIN, so it costs no attempt; the PIN then
refuses a transfer held for 24 hours after a PIN reset.
Both wallets are locked in customer_id order, so transfers in opposite
directions cannot deadlock, and the daily limit is summed under the lock.
TRANSFER_OUT takes from the sender's lots in K9 order and TRANSFER_IN
gives the recipient lots with exactly the same expiries, pointing back at
the sender's lots. The rows share a group, reference each other and name
the other customer; descriptions carry only the masked name.
The Idempotency-Key header is required. A retry is recognised under the
lock before the daily limit, so it replays instead of counting twice; the
same key towards another recipient is refused.
The recipient is told by WhatsApp after the commit, as PIN locks are:
NotificationService only reaches staff devices, there is no push channel
to customers yet. A failure to send is logged, never undoes the transfer.
Transfers must not be released before note N3 (legal) is closed.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
74 lines
2.5 KiB
Go
74 lines
2.5 KiB
Go
package models
|
|
|
|
import (
|
|
"time"
|
|
|
|
"github.com/google/uuid"
|
|
)
|
|
|
|
// WalletExchangePreview is GET /customer/wallet/exchange/preview
|
|
// (docs/prd-point-coin.md F4): the rate, and what exchanging Coins would give.
|
|
type WalletExchangePreview struct {
|
|
// The rate: CoinAmount EnakCoin exchange into PointAmount EnakPoint.
|
|
CoinAmount int64 `json:"coin_amount"`
|
|
PointAmount int64 `json:"point_amount"`
|
|
CoinBalance int64 `json:"coin_balance"`
|
|
Coins int64 `json:"coins"`
|
|
Points int64 `json:"points"`
|
|
// Whether Coins can be exchanged now, and why not when it cannot.
|
|
Valid bool `json:"valid"`
|
|
Reason string `json:"reason,omitempty"`
|
|
}
|
|
|
|
// WalletMovedLot is part of what an exchange or a transfer delivered, with the
|
|
// expiry it carried over from the lot it came from (K9).
|
|
type WalletMovedLot struct {
|
|
Amount int64 `json:"amount"`
|
|
// Nil when it never expires.
|
|
ExpiresAt *time.Time `json:"expires_at"`
|
|
}
|
|
|
|
// WalletExchangeResult is POST /customer/wallet/exchange.
|
|
type WalletExchangeResult struct {
|
|
GroupID uuid.UUID `json:"group_id"`
|
|
Coins int64 `json:"coins"`
|
|
Points int64 `json:"points"`
|
|
CoinAmount int64 `json:"coin_amount"`
|
|
PointAmount int64 `json:"point_amount"`
|
|
// The EnakPoint received, split by expiry.
|
|
Lots []WalletMovedLot `json:"lots"`
|
|
CoinBalance int64 `json:"coin_balance"`
|
|
PointBalance int64 `json:"point_balance"`
|
|
// True when this was a retry of an exchange already made; nothing moved again.
|
|
Replayed bool `json:"replayed"`
|
|
}
|
|
|
|
// WalletTransferRecipient is GET /customer/wallet/transfer/recipient: who a phone
|
|
// number belongs to, masked, so the sender can check before confirming (F5).
|
|
type WalletTransferRecipient struct {
|
|
Name string `json:"name"`
|
|
PhoneNumber string `json:"phone_number"`
|
|
}
|
|
|
|
// WalletTransfer is what a customer asks to send (F5).
|
|
type WalletTransfer struct {
|
|
// POINT or COIN.
|
|
Currency string
|
|
Amount int64
|
|
RecipientPhone string
|
|
}
|
|
|
|
// WalletTransferResult is POST /customer/wallet/transfer.
|
|
type WalletTransferResult struct {
|
|
GroupID uuid.UUID `json:"group_id"`
|
|
Currency string `json:"currency"`
|
|
Amount int64 `json:"amount"`
|
|
Recipient WalletTransferRecipient `json:"recipient"`
|
|
// What the recipient received, split by the expiry it carried over.
|
|
Lots []WalletMovedLot `json:"lots"`
|
|
// The sender's balance in the currency sent.
|
|
Balance int64 `json:"balance"`
|
|
// True when this was a retry of a transfer already made; nothing moved again.
|
|
Replayed bool `json:"replayed"`
|
|
}
|