Security (P0): - IsJTIRevoked fails closed on DB error (previously accepted revoked tokens) - Remove dead consume parameter from SCA gate (prevented token replay) - Rate limiter map TTL-based eviction (prevented memory exhaustion) - 2FA attempt map already had LRU eviction (verified) Money Safety (P1): - Gift card transfer refuses expired destination cards - Gift card balance deduction has WHERE balance >= amount guard - Webhook clawback acquires till-sale advisory lock - Sweep/retry lock keys aligned Privacy/Cookies (P2): - Self-host Google Fonts (Playfair Display woff2) - Replace CARTO map tiles with OpenStreetMap raster tiles - Replace Wikimedia/icon-icons external images with local SVGs - Remove external image URLs from CSP Legal (P3): - Privacy policy: add 6 missing data categories (gift cards, 2FA, GDPR, notifications, technical, cookies) - Terms: add Tips section (optionality, non-refundable, same processing as bookings) Code Quality (P4): - twofa.Check accepts db.Querier for testability - depositPromotionMinPct uses literal 0.20 (not misleading alias) - HolidayHours.svelte uses proper type (not as any[]) - Remove stale TODO comments from main.go Testing (P5): - 94 new float64 money validity tests across 3 test files - Cover VAT, splits, refunds, gift cards, rounding, precision boundaries - All 27 backend test packages pass
32 lines
1.1 KiB
Go
32 lines
1.1 KiB
Go
package payments
|
|
|
|
import "time"
|
|
|
|
const (
|
|
FullRefundThreshold = 72 * time.Hour
|
|
PartialRefundThreshold = 24 * time.Hour
|
|
NoShowThreshold = 24 * time.Hour
|
|
DepositDeadlineWindow = 24 * time.Hour
|
|
DepositAdvanceWindow = 36 * time.Hour
|
|
|
|
FullRefundTier = "full_refund_72h"
|
|
PartialRefundTier = "partial_refund_24h_72h"
|
|
NoRefundTier = "no_refund_under_24h"
|
|
|
|
ProtectedDepositMaxPct = 0.50
|
|
RequiredDepositPct = 0.20
|
|
|
|
// depositPromotionMinPct is the share of the booking total a payment must
|
|
// cover before a pending_release booking is promoted back to 'confirmed'
|
|
// (A10) — the deposit-promotion threshold in the CreateBookingPayment
|
|
// deposit-promotion query. Named separately from RequiredDepositPct (the
|
|
// deposit REQUIRED at booking time, used by bookings.go): the promotion
|
|
// threshold is about already-paid money, not the amount to demand up front,
|
|
// even though both are 20% today.
|
|
// Currently equals RequiredDepositPct, but intentionally independent for future divergence.
|
|
depositPromotionMinPct = 0.20
|
|
|
|
LoyaltyStampCost = 10
|
|
LoyaltyDiscountPercent = 10.0
|
|
)
|