feat(backend): harden draft, pricing and publish contracts

- unify typed API errors across draft, pricing and publish flows
- add stale draft and publish-state mutation guards
- add publish readiness contract and guarded publish flow
- add sellability reason codes to test seat preview
- add pricing diagnostics and strengthen snapshot/publish lifecycle consistency
This commit is contained in:
greebo
2026-03-19 20:58:14 +03:00
parent ac3a62f108
commit a266f56ddd
6 changed files with 368 additions and 297 deletions

View File

@@ -1,6 +1,6 @@
from decimal import Decimal
from fastapi import APIRouter, Depends, HTTPException, Query, status
from fastapi import APIRouter, Depends, Query
from app.core.config import settings
from app.repositories.audit import create_audit_event
@@ -14,45 +14,37 @@ from app.repositories.pricing import (
update_price_rule,
update_pricing_category,
)
from app.repositories.scheme_version_pricing import replace_scheme_version_pricing_snapshot
from app.schemas.pricing import (
DeleteResponse,
PriceRuleCreateRequest,
PriceRuleCreateResponse,
PriceRuleItem,
PriceRuleUpdateRequest,
PriceRuleUpdateResponse,
PricingBundleResponse,
PricingCategoryCreateRequest,
PricingCategoryCreateResponse,
PricingCategoryItem,
PricingCategoryUpdateRequest,
PricingCategoryUpdateResponse,
)
from app.security.auth import require_api_key
from app.services.api_errors import raise_unprocessable
from app.services.draft_guard import validate_expected_draft_version_if_provided
from app.services.draft_guard import get_current_draft_context
router = APIRouter()
async def _refresh_current_draft_snapshot_if_possible(scheme_id: str) -> dict | None:
context = await validate_expected_draft_version_if_provided(
async def _require_current_draft(
scheme_id: str,
expected_scheme_version_id: str | None,
):
return await get_current_draft_context(
scheme_id=scheme_id,
expected_scheme_version_id=None,
)
if context is None:
return None
scheme, version = context
return await replace_scheme_version_pricing_snapshot(
scheme_id=scheme.scheme_id,
scheme_version_id=version.scheme_version_id,
expected_scheme_version_id=expected_scheme_version_id,
)
@router.get(f"{settings.api_v1_prefix}/schemes/{{scheme_id}}/pricing", response_model=PricingBundleResponse)
async def get_pricing_bundle(scheme_id: str, role: str = Depends(require_api_key)):
async def get_pricing_bundle(
scheme_id: str,
role: str = Depends(require_api_key),
):
categories = await list_pricing_categories(scheme_id)
rules = await list_price_rules(scheme_id)
@@ -83,48 +75,45 @@ async def get_pricing_bundle(scheme_id: str, role: str = Depends(require_api_key
)
@router.post(
f"{settings.api_v1_prefix}/schemes/{{scheme_id}}/pricing/categories",
response_model=PricingCategoryCreateResponse,
)
@router.post(f"{settings.api_v1_prefix}/schemes/{{scheme_id}}/pricing/categories")
async def create_pricing_category_endpoint(
scheme_id: str,
payload: PricingCategoryCreateRequest,
expected_scheme_version_id: str | None = Query(default=None),
role: str = Depends(require_api_key),
):
await validate_expected_draft_version_if_provided(
scheme, version = await _require_current_draft(
scheme_id=scheme_id,
expected_scheme_version_id=expected_scheme_version_id,
)
pricing_category_id = await create_pricing_category(
scheme_id=scheme_id,
scheme_id=scheme.scheme_id,
name=payload.name,
code=payload.code,
)
snapshot = await _refresh_current_draft_snapshot_if_possible(scheme_id)
await create_audit_event(
scheme_id=scheme_id,
scheme_id=scheme.scheme_id,
event_type="pricing.category.created",
object_type="pricing_category",
object_ref=pricing_category_id,
details={"name": payload.name, "code": payload.code, "snapshot": snapshot},
details={
"scheme_version_id": version.scheme_version_id,
"name": payload.name,
"code": payload.code,
},
)
return PricingCategoryCreateResponse(
pricing_category_id=pricing_category_id,
scheme_id=scheme_id,
name=payload.name,
code=payload.code,
)
return {
"pricing_category_id": pricing_category_id,
"scheme_id": scheme.scheme_id,
"name": payload.name,
"code": payload.code,
}
@router.put(
f"{settings.api_v1_prefix}/schemes/{{scheme_id}}/pricing/categories/{{pricing_category_id}}",
response_model=PricingCategoryUpdateResponse,
)
@router.put(f"{settings.api_v1_prefix}/schemes/{{scheme_id}}/pricing/categories/{{pricing_category_id}}")
async def update_pricing_category_endpoint(
scheme_id: str,
pricing_category_id: str,
@@ -132,81 +121,77 @@ async def update_pricing_category_endpoint(
expected_scheme_version_id: str | None = Query(default=None),
role: str = Depends(require_api_key),
):
await validate_expected_draft_version_if_provided(
scheme, version = await _require_current_draft(
scheme_id=scheme_id,
expected_scheme_version_id=expected_scheme_version_id,
)
row = await update_pricing_category(
scheme_id=scheme_id,
scheme_id=scheme.scheme_id,
pricing_category_id=pricing_category_id,
name=payload.name,
code=payload.code,
)
snapshot = await _refresh_current_draft_snapshot_if_possible(scheme_id)
await create_audit_event(
scheme_id=scheme_id,
scheme_id=scheme.scheme_id,
event_type="pricing.category.updated",
object_type="pricing_category",
object_ref=pricing_category_id,
details={"name": payload.name, "code": payload.code, "snapshot": snapshot},
details={
"scheme_version_id": version.scheme_version_id,
"name": row.name,
"code": row.code,
},
)
return PricingCategoryUpdateResponse(
pricing_category_id=row.pricing_category_id,
scheme_id=row.scheme_id,
name=row.name,
code=row.code,
)
return {
"pricing_category_id": row.pricing_category_id,
"scheme_id": row.scheme_id,
"name": row.name,
"code": row.code,
}
@router.delete(
f"{settings.api_v1_prefix}/schemes/{{scheme_id}}/pricing/categories/{{pricing_category_id}}",
response_model=DeleteResponse,
)
@router.delete(f"{settings.api_v1_prefix}/schemes/{{scheme_id}}/pricing/categories/{{pricing_category_id}}")
async def delete_pricing_category_endpoint(
scheme_id: str,
pricing_category_id: str,
expected_scheme_version_id: str | None = Query(default=None),
role: str = Depends(require_api_key),
):
await validate_expected_draft_version_if_provided(
scheme, version = await _require_current_draft(
scheme_id=scheme_id,
expected_scheme_version_id=expected_scheme_version_id,
)
await delete_pricing_category(
scheme_id=scheme_id,
scheme_id=scheme.scheme_id,
pricing_category_id=pricing_category_id,
)
snapshot = await _refresh_current_draft_snapshot_if_possible(scheme_id)
await create_audit_event(
scheme_id=scheme_id,
scheme_id=scheme.scheme_id,
event_type="pricing.category.deleted",
object_type="pricing_category",
object_ref=pricing_category_id,
details={"snapshot": snapshot},
details={"scheme_version_id": version.scheme_version_id},
)
return DeleteResponse(
deleted=True,
pricing_category_id=pricing_category_id,
)
return {
"deleted": True,
"pricing_category_id": pricing_category_id,
}
@router.post(
f"{settings.api_v1_prefix}/schemes/{{scheme_id}}/pricing/rules",
response_model=PriceRuleCreateResponse,
)
@router.post(f"{settings.api_v1_prefix}/schemes/{{scheme_id}}/pricing/rules")
async def create_price_rule_endpoint(
scheme_id: str,
payload: PriceRuleCreateRequest,
expected_scheme_version_id: str | None = Query(default=None),
role: str = Depends(require_api_key),
):
await validate_expected_draft_version_if_provided(
scheme, version = await _require_current_draft(
scheme_id=scheme_id,
expected_scheme_version_id=expected_scheme_version_id,
)
@@ -217,49 +202,45 @@ async def create_price_rule_endpoint(
raise_unprocessable(
code="invalid_amount",
message="Некорректная сумма",
amount=payload.amount,
details={"amount": payload.amount},
)
price_rule_id = await create_price_rule(
scheme_id=scheme_id,
scheme_id=scheme.scheme_id,
pricing_category_id=payload.pricing_category_id,
target_type=payload.target_type,
target_ref=payload.target_ref,
amount=amount,
currency=payload.currency,
)
snapshot = await _refresh_current_draft_snapshot_if_possible(scheme_id)
await create_audit_event(
scheme_id=scheme_id,
scheme_id=scheme.scheme_id,
event_type="pricing.rule.created",
object_type="price_rule",
object_ref=price_rule_id,
details={
"scheme_version_id": version.scheme_version_id,
"pricing_category_id": payload.pricing_category_id,
"target_type": payload.target_type,
"target_ref": payload.target_ref,
"amount": payload.amount,
"amount": str(amount),
"currency": payload.currency,
"snapshot": snapshot,
},
)
return PriceRuleCreateResponse(
price_rule_id=price_rule_id,
scheme_id=scheme_id,
pricing_category_id=payload.pricing_category_id,
target_type=payload.target_type,
target_ref=payload.target_ref,
amount=payload.amount,
currency=payload.currency,
)
return {
"price_rule_id": price_rule_id,
"scheme_id": scheme.scheme_id,
"pricing_category_id": payload.pricing_category_id,
"target_type": payload.target_type,
"target_ref": payload.target_ref,
"amount": str(amount),
"currency": payload.currency,
}
@router.put(
f"{settings.api_v1_prefix}/schemes/{{scheme_id}}/pricing/rules/{{price_rule_id}}",
response_model=PriceRuleUpdateResponse,
)
@router.put(f"{settings.api_v1_prefix}/schemes/{{scheme_id}}/pricing/rules/{{price_rule_id}}")
async def update_price_rule_endpoint(
scheme_id: str,
price_rule_id: str,
@@ -267,7 +248,7 @@ async def update_price_rule_endpoint(
expected_scheme_version_id: str | None = Query(default=None),
role: str = Depends(require_api_key),
):
await validate_expected_draft_version_if_provided(
scheme, version = await _require_current_draft(
scheme_id=scheme_id,
expected_scheme_version_id=expected_scheme_version_id,
)
@@ -278,11 +259,11 @@ async def update_price_rule_endpoint(
raise_unprocessable(
code="invalid_amount",
message="Некорректная сумма",
amount=payload.amount,
details={"amount": payload.amount},
)
row = await update_price_rule(
scheme_id=scheme_id,
scheme_id=scheme.scheme_id,
price_rule_id=price_rule_id,
pricing_category_id=payload.pricing_category_id,
target_type=payload.target_type,
@@ -290,64 +271,59 @@ async def update_price_rule_endpoint(
amount=amount,
currency=payload.currency,
)
snapshot = await _refresh_current_draft_snapshot_if_possible(scheme_id)
await create_audit_event(
scheme_id=scheme_id,
scheme_id=scheme.scheme_id,
event_type="pricing.rule.updated",
object_type="price_rule",
object_ref=price_rule_id,
details={
"pricing_category_id": payload.pricing_category_id,
"target_type": payload.target_type,
"target_ref": payload.target_ref,
"amount": payload.amount,
"currency": payload.currency,
"snapshot": snapshot,
"scheme_version_id": version.scheme_version_id,
"pricing_category_id": row.pricing_category_id,
"target_type": row.target_type,
"target_ref": row.target_ref,
"amount": str(row.amount),
"currency": row.currency,
},
)
return PriceRuleUpdateResponse(
price_rule_id=row.price_rule_id,
scheme_id=row.scheme_id,
pricing_category_id=row.pricing_category_id,
target_type=row.target_type,
target_ref=row.target_ref,
amount=str(row.amount),
currency=row.currency,
)
return {
"price_rule_id": row.price_rule_id,
"scheme_id": row.scheme_id,
"pricing_category_id": row.pricing_category_id,
"target_type": row.target_type,
"target_ref": row.target_ref,
"amount": str(row.amount),
"currency": row.currency,
}
@router.delete(
f"{settings.api_v1_prefix}/schemes/{{scheme_id}}/pricing/rules/{{price_rule_id}}",
response_model=DeleteResponse,
)
@router.delete(f"{settings.api_v1_prefix}/schemes/{{scheme_id}}/pricing/rules/{{price_rule_id}}")
async def delete_price_rule_endpoint(
scheme_id: str,
price_rule_id: str,
expected_scheme_version_id: str | None = Query(default=None),
role: str = Depends(require_api_key),
):
await validate_expected_draft_version_if_provided(
scheme, version = await _require_current_draft(
scheme_id=scheme_id,
expected_scheme_version_id=expected_scheme_version_id,
)
await delete_price_rule(
scheme_id=scheme_id,
scheme_id=scheme.scheme_id,
price_rule_id=price_rule_id,
)
snapshot = await _refresh_current_draft_snapshot_if_possible(scheme_id)
await create_audit_event(
scheme_id=scheme_id,
scheme_id=scheme.scheme_id,
event_type="pricing.rule.deleted",
object_type="price_rule",
object_ref=price_rule_id,
details={"snapshot": snapshot},
details={"scheme_version_id": version.scheme_version_id},
)
return DeleteResponse(
deleted=True,
price_rule_id=price_rule_id,
)
return {
"deleted": True,
"price_rule_id": price_rule_id,
}