fix: payments review rounds — money-safety, GDPR, security, gift-card cancel, modal stacking
Money-safety: - Deterministic till idempotency fallback (Square-charging only); cash/on_the_house keep unique keys; £250 till gift-card cap; 45-char key validation - Gift-card admin caps £250/tx + £5,000/day; user buy £500/day; BuyGiftCard allowlist unchanged - CancelGiftCard: CCR 2013 14-day right with partial-spend refund of the unspent balance (spend verified via payments.gift_card_id); atomic vs redeem/transfer; refunds stay pending until reversal commits; admin cancel surface (AdminCancelGiftCard) - Sweep: cancelled-booking charges failed+notified instead of silently completed; source-override replay uses live square_source_id; legacy square-less refund sweep; snapshot refresh on pending reuse - Refund lock consolidation; recordTerminalPaymentTx shared recorder; structured Square error codes; terminal checkout CustomerID GDPR / security: - Notes retained as de-identified medical/safety record at erasure (single field treated as health data; rest of record wiped, no re-identification map) + comments updated per UK GDPR/Art 9/Equality Act 2010 - square_request_snapshot PII scrubbed on all erasure paths; delete_guest_user FK unlinks; verification codes + dispute reasons handled; idle/stale-guest erasure deletes Square cards/customers + CardDAV/R2 - Durable square-erasure outbox job (retry-square-erasures); 2FA dev/prod build split, pepper fail-closed, no prod code-in-log; prod 2FA delivery fail-loud without a channel - Webhook unknown-type family split (non-money acked, money retried); untracked dispute notifications; rate-limit CF/X-Real-IP trust gating; nginx CSP nonce + api_limit Frontend: - Dynamic z-index stack (ui/dialog/zindex.ts) claimed in open order via data-state observer; re-claims on every reopen; removes stale !z-* overrides — nested modals (booking→user→booking) always paint newest-on-top (browser-verified 3-level + reopen) - Mobile: iOS zoom fixes, bottom-sheet dialogs, 44px touch targets, inputmode decimal, dvh - Gift-card buy/cancel UI, admin £250 + daily limits, cancellation/privacy/terms policy accuracy S3: - Connect() creates buckets before probing; in-memory fallback only on genuine unreachability; health reports degraded; stale S3_PUBLIC_URL documented (host-specific) Tests/docs: - 2263 test functions; all 22 backend packages green; round8/9/10 regression suites; NextEditWindowTime removes wall-clock flake; docs reconciled (notes retention, gift-card partial-use, modal T15 future work)
This commit is contained in:
@@ -275,10 +275,14 @@ func (m *MockClient) CreatePayment(ctx context.Context, req CreatePaymentReq) (*
|
||||
// Square requires customer_id when charging a card-on-file (ccof:) token.
|
||||
// The mock enforces the same rule so dev parity catches the production bug
|
||||
// where a saved-card charge is sent without the customer's Square customer
|
||||
// id (real Square rejects it with a 400 INVALID_REQUEST_ERROR).
|
||||
// id (real Square rejects it with a 400 MISSING_REQUIRED_PARAMETER —
|
||||
// category INVALID_REQUEST_ERROR — because customer_id is required for a
|
||||
// card-on-file source).
|
||||
if strings.HasPrefix(req.SourceID, "ccof:") && req.CustomerID == "" {
|
||||
return nil, &squareAPIError{
|
||||
Code: "INVALID_REQUEST_ERROR",
|
||||
Code: "MISSING_REQUIRED_PARAMETER",
|
||||
Category: "INVALID_REQUEST_ERROR",
|
||||
Field: "customer_id",
|
||||
Detail: "customer_id required for card-on-file source",
|
||||
StatusCode: http.StatusBadRequest,
|
||||
err: errors.New("square: customer_id required for card-on-file source"),
|
||||
@@ -444,9 +448,10 @@ func (m *MockClient) CreateCheckout(ctx context.Context, req CreateCheckoutReq)
|
||||
}
|
||||
if deviceID == "" {
|
||||
return nil, &squareAPIError{
|
||||
Code: "INVALID_REQUEST_ERROR",
|
||||
Code: "MISSING_REQUIRED_PARAMETER",
|
||||
Detail: "device_options.device_id is required to create a terminal checkout",
|
||||
Category: "INVALID_REQUEST_ERROR",
|
||||
Field: "device_options.device_id",
|
||||
StatusCode: http.StatusBadRequest,
|
||||
err: errors.New("square: device_options.device_id is required for a terminal checkout (set SQUARE_TERMINAL_DEVICE_ID or pass DeviceID)"),
|
||||
}
|
||||
@@ -699,8 +704,8 @@ func (m *MockClient) RefundPayment(ctx context.Context, req RefundPaymentReq) (*
|
||||
refundID := fmt.Sprintf("ref_mock_%d", now.UnixNano())
|
||||
|
||||
// Square's RefundPayment requires amount_money — a missing or zero amount
|
||||
// is rejected (400 INVALID_REQUEST_ERROR / REFUND_AMOUNT_INVALID), never
|
||||
// treated as a "full refund" shortcut. The mock mirrors this so a
|
||||
// is rejected (400 REFUND_AMOUNT_INVALID, category INVALID_REQUEST_ERROR),
|
||||
// never treated as a "full refund" shortcut. The mock mirrors this so a
|
||||
// missing-amount bug can't be masked in dev (the real DB also has a CHECK
|
||||
// amount > 0, so a £0 refund must fail rather than silently record nothing).
|
||||
if req.Amount <= 0 {
|
||||
@@ -780,11 +785,14 @@ func (m *MockClient) CreateCardOnFile(ctx context.Context, userID, cardToken, cu
|
||||
// runtime (confirmed by Square's own SDK maintainer). The production client
|
||||
// omits an empty customer_id via omitempty and every production caller
|
||||
// provisions a Square customer first, so the gate is enforced upstream — the
|
||||
// mock must mirror it (same structured INVALID_REQUEST_ERROR as the ccof:
|
||||
// CreatePayment gate above) so sandbox/dev tests exercise the same rejection.
|
||||
// mock must mirror it (same structured MISSING_REQUIRED_PARAMETER as the
|
||||
// ccof: CreatePayment gate above) so sandbox/dev tests exercise the same
|
||||
// rejection.
|
||||
if customerID == "" {
|
||||
return nil, &squareAPIError{
|
||||
Code: "INVALID_REQUEST_ERROR",
|
||||
Code: "MISSING_REQUIRED_PARAMETER",
|
||||
Category: "INVALID_REQUEST_ERROR",
|
||||
Field: "card.customer_id",
|
||||
Detail: "customer_id is required to create a card on file",
|
||||
StatusCode: http.StatusBadRequest,
|
||||
err: errors.New("square: customer_id is required to create a card on file"),
|
||||
|
||||
Reference in New Issue
Block a user