fix: round-2 loop-A fresh review (503c326 baseline) — B1 replay cap, A6 discount record, 2FA reissue+cooldown, notification flood, lockout saturation, VAT/refund-status consolidation

Round 2 Loop A fresh money/security/dup-mod review. 23 findings fixed:

MONEY:
- CRITICAL: B1 duplicate auto-refund gains an attempt cap (b1_attempts col, cap 3) —
  a rejected auto-refund no longer re-replays the expired key every sweep run
  (which minted a stacking unauthorized charge each time); FAILED-webhook
  demotion respects the cap; never re-replay a key whose B1 refund failed
- HIGH: A6 deposit_covered_by_discount skip path now APPLIES the eligible
  campaign discount rows immediately (capped) instead of skipping with no
  discount recorded — no more promised-discount-not-recorded overcharge
- MEDIUM: 2FA code burned by the SAVE gate is re-issued on failed
  new-card+save_card charges (re-issue guard now covers req.SaveCard)
- LOW: GetBookingPaymentSummary excludes tip rows from paidAmount (remaining
  now matches the authoritative tip-excluded balance)

SECURITY:
- MEDIUM: unacknowledged CRITICAL admin-notification flood capped (global cap
  on critical_payment_log + refresh_token_reuse rows)
- MEDIUM: 2FA reissue no longer bypasses the mint cooldown (Check no longer
  clears LastMintAt on gate-verify; cleared on terminal charge success)
- MEDIUM: twofa.StateFor map-saturation returns a shared permanently-locked
  state instead of a fresh 5-guess budget per request
- MEDIUM: ProgressiveRateLimit rejects 429 past maxProgressiveSleepDelayMs
  instead of sleeping unboundedly; login bcrypt concurrency semaphore added
- LOW: loginInProgress 409->429; webhook key-set/URL-unset startup check;
  email-verification per-user attempt counter

DUP/MOD:
- formatCurrency single source (frontend format.ts, 7 files consolidated);
  SquareRefundStatusToLocal single source (errors.go, all sites); admin
  audit-log helper dedup; SCA retry model unified (proactive on all 6
  surfaces); buyDailyTotal/daily-cap mirror via backend; lock TTL from
  backend; generateUUID at all card-form sites; magic numbers named
  (defaultPostgresHost, epsilon, fee constants); admin CASH + gift-card
  terminal charges now audited; DAV_SKIP_INIT documented in manuals

Verified: 26/26 dev + 24/24 prod (GO_TESTING=1, the CI condition), both vet
tags, frontend tests+build, env-docs 42/42.
This commit is contained in:
2026-08-22 00:34:50 +01:00
parent 4e64e32f09
commit 3866cc5963
36 changed files with 2032 additions and 719 deletions
+13 -2
View File
@@ -714,7 +714,15 @@ CREATE TABLE payments (
created_at TIMESTAMPTZ NOT NULL DEFAULT NOW(),
updated_at TIMESTAMPTZ NOT NULL DEFAULT NOW(),
created_by CHAR(12),
gift_card_id CHAR(12)
gift_card_id CHAR(12),
-- B1: how many times the stale-pending sweep has auto-refunded a
-- replay-induced duplicate charge under this row's expired idempotency
-- key (sweep.go refundSweepDuplicateCharge). A REJECTED/FAILED B1 refund
-- means the duplicate stands at Square and the key must NEVER be
-- replayed — each replay mints another charge. The sweep caps attempts at
-- b1DuplicateRefundAttemptCap and refuses to re-replay a key whose B1
-- refund failed or hit the cap.
b1_attempts INT NOT NULL DEFAULT 0
);
CREATE INDEX idx_payments_bookingid ON payments(booking_id);
@@ -2278,7 +2286,10 @@ CREATE TABLE till_sales (
is_vat_applicable BOOLEAN NOT NULL DEFAULT FALSE,
vat_rate NUMERIC(5,2),
vat_amount NUMERIC(10,2),
net_amount NUMERIC(10,2)
net_amount NUMERIC(10,2),
-- B1: sweep auto-refund attempt cap for a replay-induced duplicate charge
-- (see payments.b1_attempts — same money-safety guard).
b1_attempts INT NOT NULL DEFAULT 0
);
CREATE INDEX idx_till_sales_created_at ON till_sales(created_at);