feat(payments): settle the direct rail through YooKassa
CI / changes (pull_request) Successful in 2s
CI / unit (pull_request) Successful in 11s
CI / integration (pull_request) Successful in 25s
CI / ui (pull_request) Successful in 1m17s
CI / conformance (pull_request) Successful in 10s
CI / gate (pull_request) Successful in 0s
CI / deploy (pull_request) Successful in 1m50s
CI / changes (pull_request) Successful in 2s
CI / unit (pull_request) Successful in 11s
CI / integration (pull_request) Successful in 25s
CI / ui (pull_request) Successful in 1m17s
CI / conformance (pull_request) Successful in 10s
CI / gate (pull_request) Successful in 0s
CI / deploy (pull_request) Successful in 1m50s
Replace Robokassa with YooKassa as the RUB direct-rail provider. The wallet
model is untouched: one `direct` segment, the same spend wall, the same
per-channel merchant shops (D42) and `shop` on the order (D44).
The two providers are not shaped alike, and that drives the change:
- Opening a purchase is now an outbound API call (`POST /v3/payments`,
single-stage capture, redirect confirmation). The order id is both the
`Idempotence-Key` and `metadata.order_id`, so a retried create cannot mint a
second payment and a notification always resolves to its order.
- YooKassa does NOT sign notifications, so the body is never evidence: it only
names a payment, which is re-read with `GET /v3/payments/{id}`, and only that
answer is acted on. Two guards ride on it — the payment's metadata must name
the order, and its `test` flag must match the shop's, so a test-shop payment
can never credit real chips. The sender address is checked against YooKassa's
published ranges first, which stops a forger turning each fabricated
notification into an outbound call of ours.
- A notification lost for good would leave the money taken and the chips unowed,
silently. The existing pending-order reaper now asks the provider about each
order that reached its expiry age carrying a payment id, and credits the ones
really paid — one request per order over its whole life, not polling.
- `payment.canceled` records a `failed` event, so a declined payment is finally
surfaced to the customer as PAYMENTS.md §9 already specified.
- The admin refund moves the money through `POST /v3/refunds` before recording
anything; a failed call records nothing, so the ledger cannot claim a refund
that did not happen, and the recorded id is the provider's own.
- YooKassa has no cabinet-side generic receipt: «Чеки от ЮKassa» registers one
only if the request carries it, so every payment and refund now sends an
itemized `receipt` to the D36 confirmed email. The VAT rate code is a deploy
variable; the settlement subject and method are constants.
Robokassa is retired, not deleted: the direct rail falls back to it when no
YooKassa shop is configured and no deployment sets its credentials, so reviving
it is a credentials change rather than a code change. Its variables are removed
from compose, .env.example, write-prod-env.sh and the three workflows, and
recorded in backend/internal/robokassa/README.md together with the cabinet
configuration and the revival steps. Ledger rows keep `provider = 'robokassa'`;
that literal is load-bearing for the idempotency index.
No migration and no wire change: `orders.provider_payment_id` already existed,
and the client is rail-agnostic.
Decisions D47-D51 (revising D41) and stage E12 are baked into the docs.
This commit is contained in:
@@ -182,6 +182,9 @@ type orderRow struct {
|
||||
currency string
|
||||
origin string
|
||||
status string
|
||||
provider string
|
||||
paymentID string
|
||||
shop string
|
||||
}
|
||||
|
||||
// orderByID reads an order, or ErrOrderNotFound.
|
||||
@@ -198,6 +201,12 @@ func (s *Store) orderByID(ctx context.Context, orderID uuid.UUID) (orderRow, err
|
||||
if err != nil {
|
||||
return orderRow{}, fmt.Errorf("payments: load order %s: %w", orderID, err)
|
||||
}
|
||||
return newOrderRow(o), nil
|
||||
}
|
||||
|
||||
// newOrderRow projects a stored order onto the intake's view of it, flattening the nullable provider
|
||||
// columns to their empty strings.
|
||||
func newOrderRow(o model.Orders) orderRow {
|
||||
return orderRow{
|
||||
orderID: o.OrderID,
|
||||
accountID: o.AccountID,
|
||||
@@ -206,7 +215,60 @@ func (s *Store) orderByID(ctx context.Context, orderID uuid.UUID) (orderRow, err
|
||||
currency: o.Currency,
|
||||
origin: o.Origin,
|
||||
status: o.Status,
|
||||
}, nil
|
||||
provider: derefString(o.Provider),
|
||||
paymentID: derefString(o.ProviderPaymentID),
|
||||
shop: o.Shop,
|
||||
}
|
||||
}
|
||||
|
||||
// derefString reads a nullable text column as a plain string, treating NULL as empty.
|
||||
func derefString(p *string) string {
|
||||
if p == nil {
|
||||
return ""
|
||||
}
|
||||
return *p
|
||||
}
|
||||
|
||||
// attachProviderPayment records the provider's own payment id on a pending order, as soon as the
|
||||
// provider mints it. It is what later lets an unattended order be re-checked against the provider
|
||||
// and a refund address the right payment; fund overwrites it with the same value when the callback
|
||||
// lands. It never changes the order status.
|
||||
func (s *Store) attachProviderPayment(ctx context.Context, orderID uuid.UUID, provider, providerPaymentID string, now time.Time) error {
|
||||
_, err := table.Orders.
|
||||
UPDATE(table.Orders.Provider, table.Orders.ProviderPaymentID, table.Orders.UpdatedAt).
|
||||
SET(postgres.String(provider), postgres.String(providerPaymentID), postgres.TimestampzT(now)).
|
||||
WHERE(table.Orders.OrderID.EQ(postgres.UUID(orderID))).
|
||||
ExecContext(ctx, s.db)
|
||||
if err != nil {
|
||||
return fmt.Errorf("payments: attach provider payment to order %s: %w", orderID, err)
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
// pendingForReconcile reads the pending orders that have reached their expiry age and carry a
|
||||
// provider payment id — the ones whose real outcome is still unknown to us because no callback ever
|
||||
// arrived. The caller asks the provider what happened before the order is written off as expired.
|
||||
// Orders with no provider payment id are skipped: the customer never got as far as a payment.
|
||||
func (s *Store) pendingForReconcile(ctx context.Context, ttlSeconds int, now time.Time, limit int) ([]orderRow, error) {
|
||||
cutoff := now.Add(-time.Duration(ttlSeconds) * time.Second)
|
||||
var rows []model.Orders
|
||||
err := postgres.SELECT(table.Orders.AllColumns).
|
||||
FROM(table.Orders).
|
||||
WHERE(table.Orders.Status.EQ(postgres.String("pending")).
|
||||
AND(table.Orders.CreatedAt.LT(postgres.TimestampzT(cutoff))).
|
||||
AND(table.Orders.ProviderPaymentID.IS_NOT_NULL()).
|
||||
AND(table.Orders.ProviderPaymentID.NOT_EQ(postgres.String("")))).
|
||||
ORDER_BY(table.Orders.CreatedAt.ASC()).
|
||||
LIMIT(int64(limit)).
|
||||
QueryContext(ctx, s.db, &rows)
|
||||
if err != nil && !errors.Is(err, qrm.ErrNoRows) {
|
||||
return nil, fmt.Errorf("payments: load orders for reconcile: %w", err)
|
||||
}
|
||||
out := make([]orderRow, 0, len(rows))
|
||||
for _, r := range rows {
|
||||
out = append(out, newOrderRow(r))
|
||||
}
|
||||
return out, nil
|
||||
}
|
||||
|
||||
// FundOutcome reports the result of an intake credit: whose balance, which segment and how many
|
||||
|
||||
Reference in New Issue
Block a user