Compare commits
245 Commits
d0536da3d7
...
dev
| Author | SHA1 | Date | |
|---|---|---|---|
| 29594f8bad | |||
| 4ff31557a8 | |||
| 3e77a4ad7c | |||
| 3f16925fe0 | |||
| f7a262ac9a | |||
| f9cb973fe9 | |||
| 1a0fe59488 | |||
| 8bfc29db2a | |||
| dbbb051ebd | |||
| 3e57af5abc | |||
| ef55d1c6a9 | |||
| 0411b71c2d | |||
| b485e9870b | |||
| ec44547122 | |||
| e67f0ccef0 | |||
| 78ca58d264 | |||
| 20a3cb3e80 | |||
| 5e1395db18 | |||
| 50c18405b6 | |||
| e14e31a840 | |||
| ea304bbfd1 | |||
| 2aa1045ddc | |||
| acde3bba5b | |||
| 9a13528611 | |||
| 6f88026d3e | |||
| c481c1e788 | |||
| 3a7c3fae11 | |||
| 55d6242c7d | |||
| a9ccf9e20c | |||
| 23d6379be8 | |||
| db9c3e0e31 | |||
| d86bffa500 | |||
| 9c05f86c86 | |||
| 54e691a4c9 | |||
| 52862db8ad | |||
| 8fa66c9911 | |||
| 70e1e9939f | |||
| 5c6a21e2c3 | |||
| 969bf2b191 | |||
| 7d67934a10 | |||
| 56904422af | |||
| 8bcdea9e4a | |||
| 7804285dec | |||
| 4a7029cea6 | |||
| 7317042e8d | |||
| 439b11d16d | |||
| 276b048fa9 | |||
| faa3265e49 | |||
| 21bfdce27a | |||
| d3288e29eb | |||
| baf7a4a99d | |||
| 885b410e48 | |||
| a1f3103a76 | |||
| 0fd66b261a | |||
| dfc5a07c10 | |||
| 5aabd7a791 | |||
| 0e9b9f5d82 | |||
| 642c5f4f70 | |||
| cb9f4d4979 | |||
| ea8fe22969 | |||
| 2910672b5a | |||
| 3a176c5cc8 | |||
| 19dff97c74 | |||
| 0ed43239c3 | |||
| 28bd838696 | |||
| 692dff5f89 | |||
| ba7538aeb5 | |||
| bb365b5d6e | |||
| c52a42dad2 | |||
| 22544ecf63 | |||
| ba5b4b1f4e | |||
| 51b160bfc9 | |||
| e2d5105da2 | |||
| 5287be5278 | |||
| 3a85483e6c | |||
| 6ceaadfbf2 | |||
| 7f42805e8d | |||
| cd3b534e51 | |||
| 011fe5a4c4 | |||
| 6f3f6ca596 | |||
| 5443b910c6 | |||
| a02957034d | |||
| ee61c24bb9 | |||
| 3a186d29df | |||
| 827445d514 | |||
| f9887c2a76 | |||
| 7649b897c4 | |||
| ab968eb25e | |||
| 5e1a885dcb | |||
| 6cf3492bff | |||
| ffe8c13a1c | |||
| fcea992e1e | |||
| 81bc2e357c | |||
| 7ef332999e | |||
| a2e102f3dd | |||
| 14638c2e13 | |||
| 4f902d869e | |||
| a5e54a8b93 | |||
| 0180394c45 | |||
| d905dd19b4 | |||
| c5ed3f1308 | |||
| 0b7eb28dfa | |||
| d5ff2097bd | |||
| 1de209be48 | |||
| dc2cdc0a91 | |||
| fd9885e9ec | |||
| 52a89bfa56 | |||
| d9e6c13831 | |||
| 493210bbb0 | |||
| a9f18be700 | |||
| 72ad504b8d | |||
| 5cdf8f227b | |||
| 365b648282 | |||
| c03ef2a34b | |||
| d9829eb61f | |||
| bafa3282c7 | |||
| 93f9ebea05 | |||
| c21babf293 | |||
| 44f34d68c4 | |||
| 43c1f45e29 | |||
| 35e593ab63 | |||
| b4f1418858 | |||
| 9d73561855 | |||
| 094e963e5e | |||
| 6505a4a73b | |||
| 8b65e199a3 | |||
| f486dcbbfc | |||
| c142166972 | |||
| 306d136a08 | |||
| 61b9955160 | |||
| b7e4037fbe | |||
| d2ab2e022e | |||
| 33c4ea1e91 | |||
| 114a32e6f2 | |||
| 018328a877 | |||
| 266e9b0027 | |||
| d92b8d1e6a | |||
| 61de1fe772 | |||
| cfac14e09e | |||
| 1b86750b0d | |||
| 9c6741a485 | |||
| d0b609e375 | |||
| 8f32d90d28 | |||
| 07295f8063 | |||
| 652d6599d3 | |||
| 39c778fbac | |||
| e16bccc2f5 | |||
| 2ab001054d | |||
| 381046190b | |||
| 84f00db48b | |||
| d5e41500a8 | |||
| 0c218179c4 | |||
| 9e442586af | |||
| 11567a417f | |||
| f6e35bbebf | |||
| 96acd6b662 | |||
| cce99aadfd | |||
| f706726eeb | |||
| 6734e9815e | |||
| 38481f105f | |||
| 4418594af0 | |||
| 25a72ff20a | |||
| c2a861208f | |||
| a888125eca | |||
| 96fd97efa9 | |||
| 2a13b95da6 | |||
| 513566c89e | |||
| f77ed11782 | |||
| e4a17efd97 | |||
| 6d32e0fc0f | |||
| 3a60367232 | |||
| 045892bc94 | |||
| 916c147b4d | |||
| 1ea1aa4189 | |||
| 9c20faf8de | |||
| a68dc23393 | |||
| c87dcb2253 | |||
| 7eadf71a0b | |||
| 9918f278b2 | |||
| 83298bc0c5 | |||
| 898cf1953a | |||
| dd0f6e483a | |||
| 40de8a7467 | |||
| f0fd15bb88 | |||
| 40ffa90dac | |||
| b3cb67188e | |||
| b1c4109045 | |||
| 50dd554b43 | |||
| 6d7682ab4a | |||
| 793b8d83ee | |||
| 7366ad19cb | |||
| 5a5fedf4f4 | |||
| 830993bcb8 | |||
| fd15988a73 | |||
| 420542ce10 | |||
| 2915d141aa | |||
| 215a3ac405 | |||
| e0cfeb5e71 | |||
| 8129b63a8c | |||
| f9bd586265 | |||
| aa546235fb | |||
| c637b2783c | |||
| 77b2acb1ca | |||
| 10923164ad | |||
| 0a22eab4a8 | |||
| 9d65099d9b | |||
| 8155ff456b | |||
| 492a08a079 | |||
| 8a437d0c4b | |||
| 65328b8c11 | |||
| 411572511d | |||
| a2bdf99db2 | |||
| 89542d4ab6 | |||
| e0b9442acc | |||
| 6f4e390c05 | |||
| df6a1ca63a | |||
| 547061edf9 | |||
| b7300ec080 | |||
| 461275521d | |||
| 3db8f517d3 | |||
| 6133923094 | |||
| 7680d9a0ed | |||
| 3527f48d76 | |||
| 5a5f5c554b | |||
| 742653aefb | |||
| 66c1291578 | |||
| 7629d5d7b1 | |||
| 2fb947e908 | |||
| cae900afd2 | |||
| 7e912e193b | |||
| 352c643009 | |||
| 5e9be16f65 | |||
| 0985b86fa7 | |||
| 3ed785c33e | |||
| 35c10a7310 | |||
| 2a9e6846a1 | |||
| 051b440627 | |||
| eb47016ae3 | |||
| 78d1f6808a | |||
| 31f116a068 | |||
| 663bf0e925 | |||
| 8acef0464c | |||
| df5caf8d87 | |||
| 0cbae94842 | |||
| ae5c122980 |
@@ -0,0 +1,44 @@
|
||||
# Build context hygiene for the server + vision images (context = repo root).
|
||||
# Keep the context small and NEVER bake build artifacts, secrets, or the live DB.
|
||||
|
||||
# Node / build outputs (rebuilt inside the image)
|
||||
**/node_modules/
|
||||
**/dist/
|
||||
**/.turbo/
|
||||
**/*.tsbuildinfo
|
||||
.turbo/
|
||||
|
||||
# Python (vision) — rebuilt by uv inside the image
|
||||
**/.venv/
|
||||
**/__pycache__/
|
||||
**/.mypy_cache/
|
||||
**/.pytest_cache/
|
||||
**/.ruff_cache/
|
||||
|
||||
# Secrets + local env (the image gets config via runtime env, never baked)
|
||||
**/.env
|
||||
**/.env.local
|
||||
|
||||
# NEVER bake the live signed-ledger DB (or any of its WAL/SHM/backup variants) into an
|
||||
# image — it lives on a mounted volume. Match the base file AND every -wal/-shm/.bak-*
|
||||
# sibling (deploy copies the package dir's files, ignoring .gitignore).
|
||||
**/*.sqlite
|
||||
**/*.sqlite-*
|
||||
**/parking.sqlite*
|
||||
|
||||
# Desktop app is built by its own tag-only release.yml, not these images
|
||||
apps/desktop/
|
||||
|
||||
# VCS, logs, caches, editor cruft
|
||||
.git/
|
||||
.github/
|
||||
*.log
|
||||
**/.DS_Store
|
||||
.vscode/
|
||||
.idea/
|
||||
|
||||
# Wiki raw sources / large docs (not needed to build)
|
||||
wiki/raw/
|
||||
|
||||
# Plans / scratch
|
||||
.planning/
|
||||
@@ -0,0 +1,37 @@
|
||||
# Booth deploy env — copy to `.env` and fill in, then run ./scripts/booth.sh up
|
||||
# (prod). Consumed by docker-compose.yml + the prod override via --env-file.
|
||||
# See wiki/decisions/container-deployment.md. Do NOT commit the filled-in .env.
|
||||
|
||||
# --- image source (prod pulls from the house Gitea registry) ------------------
|
||||
# The registry namespace; combined with the image name + TAG below.
|
||||
REGISTRY=git.infra.msai.al/mca/parking_solution
|
||||
# Image tag to deploy. CI publishes TWO tags per build: a MOVING branch tag
|
||||
# (`dev`, and `main` once that branch is built) republished on every push, and an
|
||||
# IMMUTABLE per-commit `dev-<sha>` (e.g. dev-830993b). Use the moving tag for a
|
||||
# self-updating booth (`booth.sh update` pulls the latest); pin the `<branch>-<sha>`
|
||||
# form for a reproducible, deterministic deploy. NOTE: `main` images only exist once
|
||||
# something is built on main — until then deploy from `dev`.
|
||||
TAG=dev
|
||||
|
||||
# --- secrets (NO safe defaults — the server refuses to boot without a real one) -
|
||||
# JWT signing secret. Generate yourself, never share it: openssl rand -hex 32
|
||||
# Must be 32+ chars and must NOT contain change-me / insecure / dev-only.
|
||||
JWT_SECRET=
|
||||
|
||||
# Ledger-signing key for the append-only signed event chain. Set a DISTINCT value
|
||||
# in prod (don't reuse JWT_SECRET). openssl rand -hex 32
|
||||
EVENT_SIGNING_KEY=
|
||||
|
||||
# --- booth LAN specifics ------------------------------------------------------
|
||||
# Auth cookie is HTTPS-only by default; the booth is plain HTTP behind Caddy on
|
||||
# :80, so this MUST stay 0 or operators cannot log in. Set to 1 only behind TLS.
|
||||
COOKIE_SECURE=0
|
||||
|
||||
# Remote origins the live WS feed must accept (same-origin always passes). Add any
|
||||
# address admins hit the UI from beyond the booth itself, comma-separated, e.g.
|
||||
# http://parksystems.msai.al (leave blank if only the local booth URL is used).
|
||||
WS_ALLOWED_ORIGINS=
|
||||
|
||||
# Vision/ANPR. Prod override already forces the fast_alpr engine; leave VISION_ENABLED=1
|
||||
# unless you are running without the camera. (Set 0 to disable the vision call entirely.)
|
||||
VISION_ENABLED=1
|
||||
@@ -0,0 +1,134 @@
|
||||
name: Build desktop
|
||||
|
||||
# Build the Tauri desktop installers (.deb + .AppImage) on every push to dev/main and
|
||||
# upload them as workflow ARTIFACTS — a downloadable, per-commit build for testing the
|
||||
# native shell. This is NOT a release: it's unsigned (no updater key) and creates no Gitea
|
||||
# Release. Signed, versioned releases stay on release.yml (tag v* → .deb/.rpm/.AppImage +
|
||||
# latest.json for the auto-updater). See wiki/decisions/desktop-shell-tauri.md.
|
||||
|
||||
on:
|
||||
push:
|
||||
branches: [dev, main]
|
||||
paths:
|
||||
- 'apps/desktop/**'
|
||||
- 'apps/web/**'
|
||||
- 'packages/**'
|
||||
- 'package.json'
|
||||
- 'pnpm-lock.yaml'
|
||||
- 'pnpm-workspace.yaml'
|
||||
- '.gitea/workflows/build-desktop.yml'
|
||||
workflow_dispatch:
|
||||
|
||||
jobs:
|
||||
desktop:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v4
|
||||
|
||||
- name: Set up Node 22
|
||||
uses: actions/setup-node@v4
|
||||
with:
|
||||
node-version: 22
|
||||
|
||||
- name: Enable pnpm
|
||||
run: corepack enable && corepack prepare pnpm@10.24.0 --activate
|
||||
|
||||
- name: Install Tauri system deps
|
||||
# Same set release.yml uses (verified): WebKitGTK 4.1 + libsoup-3 + the GTK/
|
||||
# appindicator/rsvg stack + AppImage tooling (patchelf, file).
|
||||
run: |
|
||||
sudo apt-get update
|
||||
sudo apt-get install -y --no-install-recommends \
|
||||
libwebkit2gtk-4.1-dev \
|
||||
libsoup-3.0-dev \
|
||||
libgtk-3-dev \
|
||||
libayatana-appindicator3-dev \
|
||||
librsvg2-dev \
|
||||
patchelf \
|
||||
file \
|
||||
build-essential \
|
||||
curl \
|
||||
wget
|
||||
|
||||
- name: Set up Rust
|
||||
uses: dtolnay/rust-toolchain@stable
|
||||
|
||||
- name: Cache cargo + target
|
||||
uses: actions/cache@v4
|
||||
with:
|
||||
path: |
|
||||
~/.cargo/registry
|
||||
~/.cargo/git
|
||||
apps/desktop/src-tauri/target
|
||||
key: ${{ runner.os }}-cargo-${{ hashFiles('apps/desktop/src-tauri/Cargo.lock') }}
|
||||
restore-keys: ${{ runner.os }}-cargo-
|
||||
|
||||
- name: Install dependencies
|
||||
run: pnpm install --frozen-lockfile
|
||||
|
||||
- name: Build desktop bundle (.deb + .AppImage)
|
||||
# Unsigned — no TAURI_SIGNING_* here (this is a test artifact, not an updater
|
||||
# release). The config sets createUpdaterArtifacts:true (release.yml signs them),
|
||||
# which makes tauri DEMAND the signing key and fail without it — so override it to
|
||||
# false for this build via --config (a JSON patch merged over tauri.conf.json).
|
||||
# --bundles restricts to the two installers we ship; tauri builds the web SPA
|
||||
# first (beforeBuildCommand), so the desktop UI matches.
|
||||
run: >
|
||||
pnpm --filter @parking/desktop bundle
|
||||
--bundles deb,appimage
|
||||
--config '{"bundle":{"createUpdaterArtifacts":false}}'
|
||||
|
||||
- name: Collect installers
|
||||
id: collect
|
||||
# Copy out the two installers under SPACE-FREE names (tauri names them
|
||||
# "Parking System_0.0.0_amd64.deb" — spaces break asset URLs). Short SHA in the
|
||||
# name so a downloaded file is traceable to its commit.
|
||||
run: |
|
||||
set -e
|
||||
BUNDLE=apps/desktop/src-tauri/target/release/bundle
|
||||
SHA="$(echo "${GITHUB_SHA}" | cut -c1-7)"
|
||||
mkdir -p dist
|
||||
deb=$(find "$BUNDLE/deb" -name '*.deb' | head -1)
|
||||
app=$(find "$BUNDLE/appimage" -name '*.AppImage' | head -1)
|
||||
cp "$deb" "dist/parking-desktop-${GITHUB_REF_NAME}-${SHA}.deb"
|
||||
cp "$app" "dist/parking-desktop-${GITHUB_REF_NAME}-${SHA}.AppImage"
|
||||
echo "Artifacts:"; ls -la dist/
|
||||
|
||||
- name: Publish to a rolling per-branch pre-release
|
||||
# actions/upload-artifact's backend isn't reliable on this Gitea runner, so we
|
||||
# publish to a Gitea RELEASE via the API instead (the proven pattern from
|
||||
# release.yml — built-in token, plain curl). One ROLLING pre-release per branch
|
||||
# (tag desktop-<branch>): delete + recreate each push so it always holds the
|
||||
# latest dev/main installer. This is NOT the signed updater release (release.yml,
|
||||
# tag v*) — it's a prerelease, unsigned, with no latest.json.
|
||||
env:
|
||||
TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
||||
API: ${{ github.api_url }}
|
||||
REPO: ${{ github.repository }}
|
||||
TAG: desktop-${{ github.ref_name }}
|
||||
run: |
|
||||
set -e
|
||||
auth="Authorization: token ${TOKEN}"
|
||||
# Drop any existing rolling release for this branch (ignore if absent) so its
|
||||
# tag + stale assets don't pile up; recreate it fresh below.
|
||||
OLD=$(curl -sS -H "$auth" "${API}/repos/${REPO}/releases/tags/${TAG}" \
|
||||
| grep -o '"id":[0-9]*' | head -1 | cut -d: -f2 || true)
|
||||
if [ -n "$OLD" ]; then
|
||||
curl -sS -X DELETE -H "$auth" "${API}/repos/${REPO}/releases/${OLD}" || true
|
||||
# Also delete the tag itself so the recreate points at this commit.
|
||||
curl -sS -X DELETE -H "$auth" "${API}/repos/${REPO}/git/refs/tags/${TAG}" || true
|
||||
fi
|
||||
REL=$(curl -sS -X POST -H "$auth" -H "Content-Type: application/json" \
|
||||
-d "{\"tag_name\":\"${TAG}\",\"target_commitish\":\"${GITHUB_SHA}\",\"name\":\"Desktop build (${GITHUB_REF_NAME})\",\"body\":\"Unsigned per-commit desktop installers from ${GITHUB_REF_NAME} @ ${GITHUB_SHA}. Rolling — overwritten each push. Not an updater release.\",\"draft\":false,\"prerelease\":true}" \
|
||||
"${API}/repos/${REPO}/releases")
|
||||
REL_ID=$(printf '%s' "$REL" | grep -o '"id":[0-9]*' | head -1 | cut -d: -f2)
|
||||
echo "release id: ${REL_ID}"
|
||||
for f in dist/*; do
|
||||
name=$(basename "$f")
|
||||
echo "uploading ${name}"
|
||||
curl -sS -X POST -H "$auth" -H "Content-Type: application/octet-stream" \
|
||||
--data-binary @"${f}" \
|
||||
"${API}/repos/${REPO}/releases/${REL_ID}/assets?name=${name}" >/dev/null
|
||||
done
|
||||
echo "done"
|
||||
@@ -0,0 +1,165 @@
|
||||
name: Build & push images
|
||||
|
||||
# Build the SERVER (API + SPA), COLLECTOR (wash review), VISION (ANPR) and TRAINER (phase-B job) container images and push them to the
|
||||
# house Gitea registry, tagged by BRANCH + short SHA (branch-aware: dev→:dev, stage→:stage,
|
||||
# main→:main). Separate from ci.yml (checks-only) and release.yml (tag-only desktop bundle).
|
||||
# Mirrors the house pattern (cf. trm/processor build.yml). See
|
||||
# wiki/decisions/container-deployment.md and fleet-deployment-komodo.md (dev→stage→main tiers).
|
||||
|
||||
on:
|
||||
push:
|
||||
branches: [dev, stage, main]
|
||||
paths:
|
||||
- 'apps/server/**'
|
||||
- 'apps/web/**'
|
||||
- 'apps/vision/**'
|
||||
- 'apps/collector/**'
|
||||
- 'apps/trainer/**'
|
||||
- 'packages/**'
|
||||
- 'package.json'
|
||||
- 'pnpm-lock.yaml'
|
||||
- 'pnpm-workspace.yaml'
|
||||
- 'turbo.json'
|
||||
- 'docker-compose*.yml'
|
||||
- '.dockerignore'
|
||||
- '.gitea/workflows/build-images.yml'
|
||||
# Deploy/IaC changes (compose above, plus the Komodo Stack defs) also rebuild — so a
|
||||
# promotion or a Stack tweak gets the same build+checks sanity pass before it reaches a
|
||||
# booth, and a komodo-only push to `stage` still produces a :stage image.
|
||||
- 'komodo/**'
|
||||
workflow_dispatch:
|
||||
|
||||
env:
|
||||
REGISTRY: git.infra.msai.al/mca/parking_solution
|
||||
|
||||
jobs:
|
||||
images:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v4
|
||||
|
||||
- name: Set up Node 22
|
||||
uses: actions/setup-node@v4
|
||||
with:
|
||||
node-version: 22
|
||||
|
||||
- name: Enable pnpm
|
||||
run: corepack enable && corepack prepare pnpm@10.24.0 --activate
|
||||
|
||||
- name: Install dependencies
|
||||
run: pnpm install --frozen-lockfile
|
||||
|
||||
- name: Set up uv (for @parking/vision checks)
|
||||
# Install uv via its official standalone script rather than a third-party action —
|
||||
# the Gitea runner can't reliably resolve astral-sh/setup-uv. uv provisions the
|
||||
# pinned Python (apps/vision/.python-version) itself. Add it to PATH for later steps.
|
||||
run: |
|
||||
curl -LsSf https://astral.sh/uv/install.sh | sh
|
||||
echo "$HOME/.local/bin" >> "$GITHUB_PATH"
|
||||
|
||||
- name: Sync vision deps
|
||||
working-directory: apps/vision
|
||||
run: uv sync --frozen
|
||||
|
||||
- name: Sync trainer deps
|
||||
# Light core only — NOT the `train` extra (CPU torch, ~200 MB); the torch tests skip.
|
||||
working-directory: apps/trainer
|
||||
run: uv sync --frozen
|
||||
|
||||
# Don't publish a broken image — run the same checks as ci.yml first.
|
||||
- name: Build + lint + test (Turbo)
|
||||
run: pnpm turbo run build lint test
|
||||
|
||||
- name: Compute tags
|
||||
id: meta
|
||||
# BRANCH = the pushed branch (dev|main); SHA = short commit. Two tags per image:
|
||||
# the moving branch tag + an immutable branch-SHA tag.
|
||||
run: |
|
||||
BRANCH="${GITHUB_REF_NAME}"
|
||||
SHA="$(echo "${GITHUB_SHA}" | cut -c1-7)"
|
||||
echo "branch=${BRANCH}" >> "$GITHUB_OUTPUT"
|
||||
echo "sha=${SHA}" >> "$GITHUB_OUTPUT"
|
||||
|
||||
- name: Set up Docker Buildx
|
||||
uses: docker/setup-buildx-action@v3
|
||||
with:
|
||||
driver: docker-container
|
||||
|
||||
- name: Login to Gitea Registry
|
||||
uses: docker/login-action@v3
|
||||
with:
|
||||
registry: git.infra.msai.al
|
||||
username: ${{ secrets.REGISTRY_USERNAME }}
|
||||
password: ${{ secrets.REGISTRY_PASSWORD }}
|
||||
|
||||
- name: Build & push SERVER (API + SPA)
|
||||
uses: docker/build-push-action@v5
|
||||
with:
|
||||
context: .
|
||||
file: apps/server/Dockerfile
|
||||
push: true
|
||||
build-args: |
|
||||
BUILD_VERSION=${{ steps.meta.outputs.branch }}-${{ steps.meta.outputs.sha }}
|
||||
tags: |
|
||||
${{ env.REGISTRY }}/parking-server:${{ steps.meta.outputs.branch }}
|
||||
${{ env.REGISTRY }}/parking-server:${{ steps.meta.outputs.branch }}-${{ steps.meta.outputs.sha }}
|
||||
cache-from: type=registry,ref=${{ env.REGISTRY }}/parking-server:buildcache
|
||||
cache-to: type=registry,ref=${{ env.REGISTRY }}/parking-server:buildcache,mode=max
|
||||
|
||||
- name: Build & push COLLECTOR (wash review)
|
||||
uses: docker/build-push-action@v5
|
||||
with:
|
||||
context: .
|
||||
file: apps/collector/Dockerfile
|
||||
push: true
|
||||
tags: |
|
||||
${{ env.REGISTRY }}/parking-collector:${{ steps.meta.outputs.branch }}
|
||||
${{ env.REGISTRY }}/parking-collector:${{ steps.meta.outputs.branch }}-${{ steps.meta.outputs.sha }}
|
||||
cache-from: type=registry,ref=${{ env.REGISTRY }}/parking-collector:buildcache
|
||||
cache-to: type=registry,ref=${{ env.REGISTRY }}/parking-collector:buildcache,mode=max
|
||||
|
||||
- name: Build & push VISION (ANPR)
|
||||
uses: docker/build-push-action@v5
|
||||
with:
|
||||
context: apps/vision
|
||||
file: apps/vision/Dockerfile
|
||||
push: true
|
||||
# The phase-B body-type classifier is fetched from the Gitea generic package registry
|
||||
# at build when apps/vision/models/bodytype.version pins a version (empty = none). The
|
||||
# registry user's credentials double as the fetch auth (BuildKit secret, never a layer).
|
||||
secrets: |
|
||||
bodytype_auth=${{ secrets.REGISTRY_USERNAME }}:${{ secrets.REGISTRY_PASSWORD }}
|
||||
tags: |
|
||||
${{ env.REGISTRY }}/parking-vision:${{ steps.meta.outputs.branch }}
|
||||
${{ env.REGISTRY }}/parking-vision:${{ steps.meta.outputs.branch }}-${{ steps.meta.outputs.sha }}
|
||||
cache-from: type=registry,ref=${{ env.REGISTRY }}/parking-vision:buildcache
|
||||
cache-to: type=registry,ref=${{ env.REGISTRY }}/parking-vision:buildcache,mode=max
|
||||
|
||||
- name: Build & push TRAINER (phase-B job)
|
||||
uses: docker/build-push-action@v5
|
||||
with:
|
||||
context: apps/trainer
|
||||
file: apps/trainer/Dockerfile
|
||||
push: true
|
||||
tags: |
|
||||
${{ env.REGISTRY }}/parking-trainer:${{ steps.meta.outputs.branch }}
|
||||
${{ env.REGISTRY }}/parking-trainer:${{ steps.meta.outputs.branch }}-${{ steps.meta.outputs.sha }}
|
||||
cache-from: type=registry,ref=${{ env.REGISTRY }}/parking-trainer:buildcache
|
||||
cache-to: type=registry,ref=${{ env.REGISTRY }}/parking-trainer:buildcache,mode=max
|
||||
|
||||
# Optional: trigger a Komodo stack redeploy (cf. trm/processor). Enable by setting the
|
||||
# KOMODO_* secrets; left guarded so it no-ops until the parking stack is wired.
|
||||
- name: Trigger Komodo redeploy
|
||||
if: success() && vars.KOMODO_ENABLED == 'true'
|
||||
env:
|
||||
URL: ${{ secrets.KOMODO_STACK_WEBHOOK_URL }}
|
||||
SECRET: ${{ secrets.KOMODO_WEBHOOK_SECRET }}
|
||||
run: |
|
||||
body="{\"ref\":\"refs/heads/${GITHUB_REF_NAME}\"}"
|
||||
sig=$(printf '%s' "$body" | openssl dgst -sha256 -hmac "$SECRET" | awk '{print $2}')
|
||||
curl -fsS -X POST \
|
||||
-H 'Content-Type: application/json' \
|
||||
-H "X-Hub-Signature-256: sha256=$sig" \
|
||||
-d "$body" \
|
||||
"$URL"
|
||||
@@ -0,0 +1,62 @@
|
||||
name: CI
|
||||
|
||||
# Lint/typecheck/test the whole Turborepo on every push/PR to dev. Mirrors the
|
||||
# house pattern (cf. trm/processor): setup-node + corepack pnpm + frozen install.
|
||||
# No Docker, no signing — pure checks. The desktop bundle is a separate, tag-only
|
||||
# pipeline (see release.yml).
|
||||
|
||||
on:
|
||||
push:
|
||||
branches: [dev]
|
||||
pull_request:
|
||||
branches: [dev, main]
|
||||
workflow_dispatch:
|
||||
|
||||
jobs:
|
||||
check:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v4
|
||||
|
||||
- name: Set up Node 22
|
||||
uses: actions/setup-node@v4
|
||||
with:
|
||||
node-version: 22
|
||||
|
||||
- name: Enable pnpm
|
||||
# Pin to the repo's packageManager version (pnpm 10), not latest.
|
||||
run: corepack enable && corepack prepare pnpm@10.24.0 --activate
|
||||
|
||||
- name: Install dependencies
|
||||
run: pnpm install --frozen-lockfile
|
||||
|
||||
- name: Set up uv (Python toolchain for @parking/vision)
|
||||
# The vision service is a Python package wired into the Turbo graph via a
|
||||
# package.json shim; its lint/typecheck/test scripts shell to `uv run …`. CI
|
||||
# has no Python by default, so `uv run` would fail with "uv: not found" and
|
||||
# break the whole Turbo run. Install uv via its official standalone script
|
||||
# (the Gitea runner can't reliably resolve astral-sh/setup-uv); uv provisions the
|
||||
# pinned Python (.python-version) itself. See wiki/decisions/vision-service-packaging.md.
|
||||
run: |
|
||||
curl -LsSf https://astral.sh/uv/install.sh | sh
|
||||
echo "$HOME/.local/bin" >> "$GITHUB_PATH"
|
||||
|
||||
- name: Sync vision deps
|
||||
# Light deps + the dev group (ruff/mypy/pytest) only — NOT the optional `alpr`
|
||||
# extra (heavy onnx/model stack), which isn't needed to lint/typecheck/test.
|
||||
working-directory: apps/vision
|
||||
run: uv sync --frozen
|
||||
|
||||
- name: Sync trainer deps
|
||||
# Same rule: light core only, not the `train` extra (CPU torch); torch tests skip.
|
||||
working-directory: apps/trainer
|
||||
run: uv sync --frozen
|
||||
|
||||
- name: Build + lint (Turbo)
|
||||
# Covers tsc typecheck, vite build, i18n catalog type-parity (a missing sq/en
|
||||
# key fails the build), AND the vision service's ruff lint via uv.
|
||||
run: pnpm turbo run build lint
|
||||
|
||||
- name: Test
|
||||
run: pnpm turbo run test
|
||||
@@ -0,0 +1,306 @@
|
||||
name: Release desktop
|
||||
|
||||
# Build the signed Tauri desktop installers on a version tag and publish them as
|
||||
# a Gitea Release — TWICE: once on this (private, source) repo for our own
|
||||
# records/history, and once mirrored to mca/public_releases, which is what the
|
||||
# Tauri auto-updater (apps/web/src/lib/desktop-updater.ts) actually points at.
|
||||
#
|
||||
# WHY a separate public repo: the updater runs on offline-first field appliances
|
||||
# with no Gitea credentials, so its endpoint + installer downloads must be
|
||||
# reachable unauthenticated. Mirroring compiled installers to a public
|
||||
# releases-only repo avoids embedding any read token in the shipped app (which
|
||||
# would leak the moment a booth PC is compromised — this box's threat model
|
||||
# names the operator/booth as the primary adversary, see CLAUDE.md). Source
|
||||
# stays private; only signed installers become public, same as most desktop
|
||||
# software. mca/public_releases is shared across apps in the org, not
|
||||
# parking-specific — namespace release tags/asset names accordingly if another
|
||||
# app starts publishing there too.
|
||||
#
|
||||
# Trigger: push a tag like v0.1.0. The job builds .deb/.rpm/.AppImage, signs them
|
||||
# with the updater key (Gitea secrets), assembles latest.json pointing at the
|
||||
# MIRROR repo's asset URLs, uploads to both repos, and mirrors the same assets.
|
||||
|
||||
on:
|
||||
push:
|
||||
tags:
|
||||
- 'v*'
|
||||
workflow_dispatch:
|
||||
|
||||
jobs:
|
||||
bundle:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v4
|
||||
|
||||
- name: Set up Node 22
|
||||
uses: actions/setup-node@v4
|
||||
with:
|
||||
node-version: 22
|
||||
|
||||
- name: Enable pnpm
|
||||
run: corepack enable && corepack prepare pnpm@10.24.0 --activate
|
||||
|
||||
- name: Install Tauri system deps
|
||||
# ubuntu-latest runner has no GUI/webkit libs by default. These are the
|
||||
# exact deps a Tauri v2 Linux build needs (verified locally): WebKitGTK
|
||||
# 4.1 + libsoup-3 + the GTK/appindicator/rsvg stack + AppImage tooling.
|
||||
run: |
|
||||
sudo apt-get update
|
||||
sudo apt-get install -y --no-install-recommends \
|
||||
libwebkit2gtk-4.1-dev \
|
||||
libsoup-3.0-dev \
|
||||
libgtk-3-dev \
|
||||
libayatana-appindicator3-dev \
|
||||
librsvg2-dev \
|
||||
patchelf \
|
||||
file \
|
||||
build-essential \
|
||||
curl \
|
||||
wget
|
||||
|
||||
- name: Set up Rust
|
||||
uses: dtolnay/rust-toolchain@stable
|
||||
|
||||
- name: Cache cargo + target
|
||||
uses: actions/cache@v4
|
||||
with:
|
||||
path: |
|
||||
~/.cargo/registry
|
||||
~/.cargo/git
|
||||
apps/desktop/src-tauri/target
|
||||
key: ${{ runner.os }}-cargo-${{ hashFiles('apps/desktop/src-tauri/Cargo.lock') }}
|
||||
restore-keys: ${{ runner.os }}-cargo-
|
||||
|
||||
- name: Install dependencies
|
||||
run: pnpm install --frozen-lockfile
|
||||
|
||||
- name: Sync tauri.conf.json version to the git tag
|
||||
# tauri.conf.json's own "version" field is what Tauri bakes into the
|
||||
# bundle filename, the app's internal version, AND the updater's
|
||||
# "current vs. new" comparison — it is NOT derived from the git tag
|
||||
# automatically. Hit in v0.1.1: the tag was bumped but this file
|
||||
# wasn't, so the signed binary + its .sig were still built (and
|
||||
# named) as 0.1.0 while latest.json (built from TAG below) claimed
|
||||
# 0.1.1 — the updater found the "update", downloaded a file whose
|
||||
# signature didn't match what the manifest claimed to sign, and
|
||||
# silently failed (a separate bug in desktop-updater.ts's error
|
||||
# handling made this invisible — also fixed). Patch it here so the
|
||||
# checked-in value is only ever a placeholder for local dev builds;
|
||||
# a real release's version is always driven by the tag.
|
||||
run: |
|
||||
set -e
|
||||
VERSION="${TAG#v}"
|
||||
sed -i "s/\"version\": \"[^\"]*\"/\"version\": \"${VERSION}\"/" apps/desktop/src-tauri/tauri.conf.json
|
||||
grep '"version"' apps/desktop/src-tauri/tauri.conf.json
|
||||
env:
|
||||
TAG: ${{ github.ref_name }}
|
||||
|
||||
- name: Build + sign desktop bundle
|
||||
env:
|
||||
# Updater signing key (Gitea repo/org secrets). Without these the
|
||||
# bundle is unsigned and the updater would reject it.
|
||||
TAURI_SIGNING_PRIVATE_KEY: ${{ secrets.TAURI_SIGNING_PRIVATE_KEY }}
|
||||
TAURI_SIGNING_PRIVATE_KEY_PASSWORD: ${{ secrets.TAURI_SIGNING_PRIVATE_KEY_PASSWORD }}
|
||||
run: pnpm --filter @parking/desktop bundle
|
||||
|
||||
- name: Collect artifacts
|
||||
id: collect
|
||||
# Gather the installers + their .sig into a flat dist/ for upload, spaces
|
||||
# stripped from filenames. productName is "Parking System" (a space), so
|
||||
# Tauri's bundle output is e.g. "Parking System_0.1.0_amd64.deb" — an
|
||||
# unescaped space in a filename breaks the later curl asset-upload URL
|
||||
# ("URL rejected: Malformed input to a URL function", hit on the very
|
||||
# first v0.1.0 release) AND would land in latest.json's asset url, which
|
||||
# the updater's plain HTTP GET can't handle either. Rename on copy.
|
||||
run: |
|
||||
set -e
|
||||
BUNDLE=apps/desktop/src-tauri/target/release/bundle
|
||||
mkdir -p dist
|
||||
find "$BUNDLE" \( -name '*.AppImage' -o -name '*.deb' -o -name '*.rpm' \
|
||||
-o -name '*.AppImage.sig' -o -name '*.deb.sig' -o -name '*.rpm.sig' \) \
|
||||
-print0 | while IFS= read -r -d '' f; do
|
||||
name=$(basename "$f" | tr ' ' '-')
|
||||
cp "$f" "dist/${name}"
|
||||
done
|
||||
echo "Artifacts:"; ls -la dist/
|
||||
|
||||
- name: Assemble latest.json
|
||||
# The Tauri updater fetches a manifest describing the newest version, its
|
||||
# notes, and per-target {signature, url}. The URL points at the MIRROR
|
||||
# repo (mca/public_releases) — that's the unauthenticated endpoint field
|
||||
# appliances actually reach; see the workflow header for why.
|
||||
#
|
||||
# ONE ENTRY PER INSTALLER TYPE — this is what made every in-app update
|
||||
# v0.1.0→v0.1.6 fail. tauri-plugin-updater looks up
|
||||
# `{os}-{arch}-{installer}` FIRST (linux-x86_64-deb / -rpm / -appimage,
|
||||
# from the running app's detected bundle type) and only then the bare
|
||||
# `linux-x86_64`. The booths run the .deb, and the manifest used to
|
||||
# carry ONLY `linux-x86_64` → the AppImage. So a .deb install found the
|
||||
# "update", downloaded the AppImage, verified its signature fine, then
|
||||
# handed the bytes to install_deb(), which checks they're a .deb
|
||||
# (infer::archive::is_deb) and bails with InvalidUpdaterFormat — after
|
||||
# the download, before any relaunch, with the error swallowed client-
|
||||
# side until v0.1.6. Now each installer gets its own signed asset; the
|
||||
# bare key stays for an AppImage install. .deb/.rpm updates run
|
||||
# `pkexec dpkg -i` / `rpm -U`, so the operator sees a polkit password
|
||||
# prompt — intended: updating a root-installed package IS an admin
|
||||
# action on this box (see wiki/decisions/desktop-shell-tauri.md).
|
||||
env:
|
||||
SERVER_URL: ${{ github.server_url }}
|
||||
MIRROR_REPO: mca/public_releases
|
||||
TAG: ${{ github.ref_name }}
|
||||
run: |
|
||||
set -e
|
||||
VERSION="${TAG#v}"
|
||||
ASSET_BASE="${SERVER_URL}/${MIRROR_REPO}/releases/download/desktop-latest"
|
||||
cat > /tmp/latest.js <<'JS'
|
||||
const fs = require("fs");
|
||||
const [version, tag, base] = process.argv.slice(2);
|
||||
const files = fs.readdirSync("dist");
|
||||
const pick = (ext) => files.find((f) => f.endsWith(ext));
|
||||
const entry = (f) => ({
|
||||
signature: fs.readFileSync(`dist/${f}.sig`, "utf8").trim(),
|
||||
url: `${base}/${f}`,
|
||||
});
|
||||
const deb = pick(".deb"), rpm = pick(".rpm"), appimage = pick(".AppImage");
|
||||
if (!deb || !appimage) {
|
||||
console.error(`missing bundle in dist/: deb=${deb} appimage=${appimage}`);
|
||||
process.exit(1);
|
||||
}
|
||||
const platforms = {
|
||||
"linux-x86_64-deb": entry(deb),
|
||||
...(rpm ? { "linux-x86_64-rpm": entry(rpm) } : {}),
|
||||
"linux-x86_64": entry(appimage),
|
||||
};
|
||||
fs.writeFileSync(
|
||||
"dist/latest.json",
|
||||
JSON.stringify(
|
||||
{
|
||||
version,
|
||||
notes: `Parking System ${tag}`,
|
||||
pub_date: new Date().toISOString().replace(/\.\d+Z$/, "Z"),
|
||||
platforms,
|
||||
},
|
||||
null,
|
||||
2,
|
||||
) + "\n",
|
||||
);
|
||||
JS
|
||||
node /tmp/latest.js "${VERSION}" "${TAG}" "${ASSET_BASE}"
|
||||
echo "latest.json:"; cat dist/latest.json
|
||||
|
||||
- name: Create release + upload assets (Gitea API)
|
||||
# Uses the built-in token; no marketplace release action required. Creates
|
||||
# the release for this tag (idempotent-ish: ignores "already exists") and
|
||||
# uploads every file in dist/ as an asset.
|
||||
env:
|
||||
TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
||||
API: ${{ github.api_url }}
|
||||
REPO: ${{ github.repository }}
|
||||
TAG: ${{ github.ref_name }}
|
||||
run: |
|
||||
set -e
|
||||
# Create the release (capture id; tolerate an existing one).
|
||||
REL=$(curl -sS -X POST \
|
||||
-H "Authorization: token ${TOKEN}" \
|
||||
-H "Content-Type: application/json" \
|
||||
-d "{\"tag_name\":\"${TAG}\",\"name\":\"${TAG}\",\"draft\":false,\"prerelease\":false}" \
|
||||
"${API}/repos/${REPO}/releases" || true)
|
||||
REL_ID=$(printf '%s' "$REL" | grep -o '"id":[0-9]*' | head -1 | cut -d: -f2 || true)
|
||||
if [ -z "$REL_ID" ]; then
|
||||
# Release may already exist for this tag — look it up by tag.
|
||||
REL_ID=$(curl -sS -H "Authorization: token ${TOKEN}" \
|
||||
"${API}/repos/${REPO}/releases/tags/${TAG}" \
|
||||
| grep -o '"id":[0-9]*' | head -1 | cut -d: -f2 || true)
|
||||
fi
|
||||
echo "release id: ${REL_ID}"
|
||||
for f in dist/*; do
|
||||
name=$(basename "$f")
|
||||
echo "uploading ${name}"
|
||||
curl -sS -X POST \
|
||||
-H "Authorization: token ${TOKEN}" \
|
||||
-H "Content-Type: application/octet-stream" \
|
||||
--data-binary @"${f}" \
|
||||
"${API}/repos/${REPO}/releases/${REL_ID}/assets?name=${name}" >/dev/null
|
||||
done
|
||||
echo "done"
|
||||
|
||||
- name: Mirror release to mca/public_releases (Gitea API)
|
||||
# This is the release the updater and any human downloader actually use —
|
||||
# public_releases has no source, only installers, so it can be public
|
||||
# without exposing this repo. RELEASES_MIRROR_TOKEN is a write:repository
|
||||
# token scoped for pushing releases into that repo (Gitea's org secrets,
|
||||
# not exposed to any deployed client).
|
||||
#
|
||||
# Publishes to TWO tags there, since public_releases is shared across
|
||||
# apps in the org and Gitea's "latest release" redirect resolves by
|
||||
# newest tag on the WHOLE repo (would break the moment another app
|
||||
# publishes something newer):
|
||||
# - desktop-<TAG> versioned, permanent — audit trail / rollback.
|
||||
# - desktop-latest moving — assets deleted + re-uploaded each release.
|
||||
# This is the fixed URL tauri.conf.json's updater endpoint points at
|
||||
# (a stable name every appliance can always resolve, regardless of
|
||||
# what else gets released in this repo meanwhile).
|
||||
env:
|
||||
TOKEN: ${{ secrets.RELEASES_MIRROR_TOKEN }}
|
||||
API: ${{ github.api_url }}
|
||||
MIRROR_REPO: mca/public_releases
|
||||
TAG: ${{ github.ref_name }}
|
||||
run: |
|
||||
set -e
|
||||
create_or_get_release() {
|
||||
local mirror_tag="$1" prerelease="$2"
|
||||
REL=$(curl -sS -w '\n%{http_code}' -X POST \
|
||||
-H "Authorization: token ${TOKEN}" \
|
||||
-H "Content-Type: application/json" \
|
||||
-d "{\"tag_name\":\"${mirror_tag}\",\"name\":\"Parking System ${TAG}\",\"draft\":false,\"prerelease\":${prerelease}}" \
|
||||
"${API}/repos/${MIRROR_REPO}/releases" || true)
|
||||
echo "create response (${mirror_tag}): ${REL}"
|
||||
REL_ID=$(printf '%s' "$REL" | grep -o '"id":[0-9]*' | head -1 | cut -d: -f2 || true)
|
||||
if [ -z "$REL_ID" ]; then
|
||||
LOOKUP=$(curl -sS -w '\n%{http_code}' -H "Authorization: token ${TOKEN}" \
|
||||
"${API}/repos/${MIRROR_REPO}/releases/tags/${mirror_tag}")
|
||||
echo "tag lookup response (${mirror_tag}): ${LOOKUP}"
|
||||
REL_ID=$(printf '%s' "$LOOKUP" | grep -o '"id":[0-9]*' | head -1 | cut -d: -f2 || true)
|
||||
fi
|
||||
if [ -z "$REL_ID" ]; then
|
||||
echo "::error::could not create or find release for tag ${mirror_tag} on ${MIRROR_REPO} — see responses above"
|
||||
exit 1
|
||||
fi
|
||||
}
|
||||
upload_assets() {
|
||||
local rel_id="$1"
|
||||
for f in dist/*; do
|
||||
name=$(basename "$f")
|
||||
echo "mirroring ${name} -> release ${rel_id}"
|
||||
HTTP_CODE=$(curl -sS -o /tmp/upload_resp.json -w '%{http_code}' -X POST \
|
||||
-H "Authorization: token ${TOKEN}" \
|
||||
-H "Content-Type: application/octet-stream" \
|
||||
--data-binary @"${f}" \
|
||||
"${API}/repos/${MIRROR_REPO}/releases/${rel_id}/assets?name=${name}")
|
||||
if [ "$HTTP_CODE" -ge 300 ]; then
|
||||
echo "::error::upload of ${name} failed (HTTP ${HTTP_CODE}): $(cat /tmp/upload_resp.json)"
|
||||
exit 1
|
||||
fi
|
||||
done
|
||||
}
|
||||
|
||||
# 1. Versioned, permanent.
|
||||
create_or_get_release "desktop-${TAG}" false
|
||||
echo "versioned mirror release id: ${REL_ID}"
|
||||
upload_assets "${REL_ID}"
|
||||
|
||||
# 2. Moving desktop-latest — delete existing assets first (re-upload
|
||||
# with the same name 409s otherwise), then re-upload.
|
||||
create_or_get_release "desktop-latest" false
|
||||
LATEST_REL_ID="${REL_ID}"
|
||||
echo "latest mirror release id: ${LATEST_REL_ID}"
|
||||
EXISTING=$(curl -sS -H "Authorization: token ${TOKEN}" \
|
||||
"${API}/repos/${MIRROR_REPO}/releases/${LATEST_REL_ID}/assets")
|
||||
printf '%s' "$EXISTING" | grep -o '"id":[0-9]*' | cut -d: -f2 | while read -r asset_id; do
|
||||
curl -sS -X DELETE -H "Authorization: token ${TOKEN}" \
|
||||
"${API}/repos/${MIRROR_REPO}/releases/${LATEST_REL_ID}/assets/${asset_id}" >/dev/null
|
||||
done || true
|
||||
upload_assets "${LATEST_REL_ID}"
|
||||
echo "done"
|
||||
@@ -27,3 +27,9 @@ dist/
|
||||
# Graphify knowledge-graph output (dev tool; generated, not committed)
|
||||
graphify-out/
|
||||
parking.sqlite*.bak-*
|
||||
questions.txt
|
||||
|
||||
# session planning files (planning-with-files skill)
|
||||
task_plan.md
|
||||
findings.md
|
||||
progress.md
|
||||
|
||||
@@ -0,0 +1,15 @@
|
||||
# Booth reverse proxy. `:80` matches ANY hostname/IP, so the booth is reachable as
|
||||
# http://<booth-ip>/, http://localhost/, or http://parksystems.msai.al/ (the name pointed
|
||||
# at the booth's IP via hosts/DNS on-site) — with no domain baked into any image. The SPA
|
||||
# uses a relative /api base, so everything (HTTP + the /api/ws WebSocket, which Caddy
|
||||
# upgrades automatically) just flows through to the server container.
|
||||
#
|
||||
# TLS later: replace `:80` with the real hostname (e.g. `parksystems.msai.al`), uncomment
|
||||
# Caddy's :443 in docker-compose.prod.yml, and Caddy auto-provisions HTTPS. For a private
|
||||
# CA / internal cert, use `tls /path/cert.pem /path/key.pem`.
|
||||
:80 {
|
||||
encode gzip
|
||||
# Host network (prod): the server runs on the host's net namespace (to reach the booth LAN /
|
||||
# device VLAN), so reach it over loopback, not the compose service name `server`.
|
||||
reverse_proxy 127.0.0.1:3000
|
||||
}
|
||||
@@ -0,0 +1,16 @@
|
||||
# Car Wash review collector (wiki/concepts/vision-review-outbox.md). Runs on the
|
||||
# reviewer's host (art-docker-station), reachable by the booths ONLY over the Netbird
|
||||
# overlay. Deployed by its own Komodo stack (komodo/resources.toml, "wash-collector").
|
||||
|
||||
# COLLECTOR_HOST=0.0.0.0 # in Docker the compose file binds the published port to the overlay IP
|
||||
# COLLECTOR_PORT=8090
|
||||
# COLLECTOR_DATA_DIR=/data # collector.sqlite + crops/<booth>/<item>.jpg
|
||||
|
||||
# One bearer token per booth: "<boothId>:<token>" pairs, comma- or newline-separated. The
|
||||
# booth id is the pseudonymous CARWASH_REVIEW_BOOTH_ID that booth was deployed with — never
|
||||
# a site name. Generate tokens with: openssl rand -hex 32
|
||||
COLLECTOR_BOOTH_TOKENS=booth-7:REPLACE,booth-9:REPLACE
|
||||
|
||||
# The reviewer's login for the review screen and the export (HTTP Basic over the overlay).
|
||||
COLLECTOR_REVIEWER_USER=reviewer
|
||||
COLLECTOR_REVIEWER_PASS=REPLACE
|
||||
@@ -0,0 +1,48 @@
|
||||
# parking-collector — the Car Wash review collector (wiki/concepts/vision-review-outbox.md).
|
||||
# Built from the monorepo root (context: .) like the server image, so it shares the
|
||||
# lockfile and @parking/shared. Runs on the REVIEWER's host (not a booth), delivered by
|
||||
# its own Komodo stack (docker-compose.collector.yml). Data on /data: collector.sqlite +
|
||||
# crops/<booth>/<item>.jpg — the trainer on the same host reads the crops off that volume.
|
||||
|
||||
FROM node:22-alpine AS deps
|
||||
WORKDIR /app
|
||||
RUN apk add --no-cache python3 make g++ # node-gyp for better-sqlite3
|
||||
RUN corepack enable && corepack prepare pnpm@10.24.0 --activate
|
||||
COPY package.json pnpm-lock.yaml pnpm-workspace.yaml turbo.json ./
|
||||
COPY apps/server/package.json apps/server/
|
||||
COPY apps/web/package.json apps/web/
|
||||
COPY apps/vision/package.json apps/vision/
|
||||
COPY apps/collector/package.json apps/collector/
|
||||
COPY packages/db/package.json packages/db/
|
||||
COPY packages/devices/package.json packages/devices/
|
||||
COPY packages/shared/package.json packages/shared/
|
||||
RUN --mount=type=cache,id=pnpm-store,target=/root/.local/share/pnpm/store \
|
||||
pnpm fetch
|
||||
|
||||
FROM deps AS build
|
||||
ENV CI=true
|
||||
COPY . .
|
||||
RUN --mount=type=cache,id=pnpm-store,target=/root/.local/share/pnpm/store \
|
||||
pnpm install --frozen-lockfile --offline
|
||||
RUN pnpm turbo run build --filter=@parking/collector
|
||||
RUN --mount=type=cache,id=pnpm-store,target=/root/.local/share/pnpm/store \
|
||||
pnpm --filter=@parking/collector --legacy deploy --prod /deploy
|
||||
|
||||
FROM node:22-alpine AS runtime
|
||||
WORKDIR /app
|
||||
ARG BUILD_VERSION=""
|
||||
ENV BUILD_VERSION=$BUILD_VERSION
|
||||
ENV NODE_ENV=production
|
||||
RUN apk add --no-cache libstdc++ wget # better-sqlite3 native runtime; wget for the healthcheck
|
||||
RUN addgroup -S app && adduser -S -G app app
|
||||
COPY --from=build --chown=app:app /deploy ./
|
||||
ENV COLLECTOR_DATA_DIR=/data
|
||||
ENV COLLECTOR_HOST=0.0.0.0
|
||||
ENV COLLECTOR_PORT=8090
|
||||
RUN mkdir -p /data && chown app:app /data
|
||||
VOLUME ["/data"]
|
||||
USER app
|
||||
EXPOSE 8090
|
||||
HEALTHCHECK --interval=30s --timeout=5s --start-period=10s --retries=3 \
|
||||
CMD wget -qO- "http://localhost:${COLLECTOR_PORT:-8090}/health" >/dev/null 2>&1 || exit 1
|
||||
CMD ["node", "dist/index.js"]
|
||||
@@ -0,0 +1,28 @@
|
||||
{
|
||||
"name": "@parking/collector",
|
||||
"version": "0.0.0",
|
||||
"private": true,
|
||||
"type": "module",
|
||||
"description": "Car Wash review collector: receives plate-blurred vehicle crops + the operator's category choice from booths over the private overlay, serves the reviewer's screen, exports labels for training. See wiki/concepts/vision-review-outbox.md.",
|
||||
"scripts": {
|
||||
"build": "tsc -b",
|
||||
"dev": "tsx watch --env-file-if-exists=.env src/index.ts",
|
||||
"start": "node --env-file-if-exists=.env dist/index.js",
|
||||
"typecheck": "tsc --noEmit",
|
||||
"lint": "tsc --noEmit",
|
||||
"test": "vitest run"
|
||||
},
|
||||
"dependencies": {
|
||||
"@fastify/multipart": "^9.2.1",
|
||||
"@parking/shared": "workspace:*",
|
||||
"better-sqlite3": "12.10.1",
|
||||
"fastify": "5.8.5"
|
||||
},
|
||||
"devDependencies": {
|
||||
"@types/better-sqlite3": "7.6.13",
|
||||
"@types/node": "25.9.3",
|
||||
"tsx": "4.22.4",
|
||||
"typescript": "6.0.3",
|
||||
"vitest": "^4.1.9"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,153 @@
|
||||
import { afterEach, beforeEach, describe, expect, it } from "vitest";
|
||||
import { mkdtemp, rm } from "node:fs/promises";
|
||||
import { tmpdir } from "node:os";
|
||||
import path from "node:path";
|
||||
import { buildCollector, type CollectorApp } from "./app.js";
|
||||
import { parseBoothTokens } from "./config.js";
|
||||
|
||||
// The collector: one ingest surface (bearer per booth, idempotent), one review surface
|
||||
// (Basic), one export. Exercised over app.inject with a hand-built multipart body.
|
||||
|
||||
let app: CollectorApp;
|
||||
let dir: string;
|
||||
const TOKENS = new Map([["booth-7", "0123456789abcdef0123456789abcdef"], ["booth-9", "fedcba9876543210fedcba9876543210"]]);
|
||||
const REVIEWER = { user: "julian", pass: "review-pass-123" };
|
||||
const basic = "Basic " + Buffer.from(`${REVIEWER.user}:${REVIEWER.pass}`).toString("base64");
|
||||
|
||||
beforeEach(async () => {
|
||||
dir = await mkdtemp(path.join(tmpdir(), "collector-"));
|
||||
app = await buildCollector({ host: "127.0.0.1", port: 0, dataDir: dir, boothTokens: TOKENS, reviewer: REVIEWER, trainerUrl: null }, { dbFile: ":memory:" });
|
||||
await app.ready();
|
||||
});
|
||||
afterEach(async () => {
|
||||
await app.close();
|
||||
await rm(dir, { recursive: true, force: true });
|
||||
});
|
||||
|
||||
/** A minimal JPEG-looking blob (SOI marker + padding) — the collector checks the magic only. */
|
||||
const JPEG = Buffer.concat([Buffer.from([0xff, 0xd8, 0xff, 0xe0]), Buffer.alloc(200, 1)]);
|
||||
|
||||
function meta(over: Record<string, unknown> = {}) {
|
||||
return {
|
||||
v: 1, booth: "booth-7", item: "item-1", order: "o-1", at: "2026-09-06T10:00:00.000Z", operator: "ab12cd34ef56ab12",
|
||||
operatorCategory: { id: "car", name: "Vetura", classes: ["car", "sedan", "hatchback"] }, service: "Standard",
|
||||
vision: { class: "suv", confidence: 0.91, categoryId: "suv" }, downgraded: true,
|
||||
image: { width: 320, height: 200, plateBlurred: true },
|
||||
...over,
|
||||
};
|
||||
}
|
||||
|
||||
function multipart(fields: Record<string, string>, file: Buffer | null): { body: Buffer; type: string } {
|
||||
const b = "----collector-test";
|
||||
const parts: Buffer[] = [];
|
||||
for (const [k, v] of Object.entries(fields)) parts.push(Buffer.from(`--${b}\r\nContent-Disposition: form-data; name="${k}"\r\n\r\n${v}\r\n`));
|
||||
if (file) parts.push(Buffer.from(`--${b}\r\nContent-Disposition: form-data; name="image"; filename="x.jpg"\r\nContent-Type: image/jpeg\r\n\r\n`), file, Buffer.from("\r\n"));
|
||||
parts.push(Buffer.from(`--${b}--\r\n`));
|
||||
return { body: Buffer.concat(parts), type: `multipart/form-data; boundary=${b}` };
|
||||
}
|
||||
|
||||
async function ingest(m: Record<string, unknown>, token = TOKENS.get("booth-7")!, file: Buffer | null = JPEG, extra: Record<string, string> = {}) {
|
||||
const { body, type } = multipart({ meta: JSON.stringify(m) }, file);
|
||||
return app.inject({ method: "POST", url: "/ingest", headers: { authorization: `Bearer ${token}`, "content-type": type, ...extra }, payload: body });
|
||||
}
|
||||
|
||||
describe("ingest", () => {
|
||||
it("stores the crop and the decision under the token's booth; retries are idempotent", async () => {
|
||||
const r = await ingest(meta());
|
||||
expect(r.statusCode).toBe(201);
|
||||
const row = app.collectorDb.get("item-1")!;
|
||||
expect(row).toMatchObject({ booth: "booth-7", operatorCategoryName: "Vetura", visionClass: "suv", downgraded: 1, plateBlurred: 1, imagePath: "crops/booth-7/item-1.jpg" });
|
||||
expect(JSON.parse(row.operatorClasses)).toEqual(["car", "sedan", "hatchback"]);
|
||||
const again = await ingest(meta());
|
||||
expect(again.statusCode).toBe(200);
|
||||
expect(again.json()).toEqual({ ok: true, duplicate: true });
|
||||
expect((await app.inject({ method: "GET", url: "/health" })).json()).toMatchObject({ ok: true, booths: 1, pending: 1 });
|
||||
});
|
||||
|
||||
it("refuses a bad token, a booth mismatch, a non-JPEG, and malformed meta", async () => {
|
||||
expect((await ingest(meta(), "nope-nope-nope-nope-nope")).statusCode).toBe(401);
|
||||
expect((await ingest(meta({ booth: "booth-9" }))).statusCode).toBe(422); // token is booth-7's
|
||||
expect((await ingest(meta(), TOKENS.get("booth-7")!, JPEG, { "x-booth-id": "booth-9" })).statusCode).toBe(403);
|
||||
expect((await ingest(meta(), TOKENS.get("booth-7")!, Buffer.alloc(300, 7))).statusCode).toBe(415);
|
||||
expect((await ingest(meta(), TOKENS.get("booth-7")!, null)).statusCode).toBe(400);
|
||||
expect((await ingest(meta({ vision: { class: "spaceship", confidence: 0.5, categoryId: null } }))).statusCode).toBe(422);
|
||||
expect((await ingest(meta({ item: "../../etc/passwd" }))).statusCode).toBe(422);
|
||||
expect((await ingest(meta({ v: 2 }))).statusCode).toBe(422);
|
||||
expect(app.collectorDb.stats().booths).toEqual([]);
|
||||
});
|
||||
});
|
||||
|
||||
describe("review + export", () => {
|
||||
it("the reviewer lists pending items, sees the crop, labels it; stats compare the label with the operator's category; the export lists usable labels only", async () => {
|
||||
await ingest(meta());
|
||||
await ingest(meta({ item: "item-2", operator: "ab12cd34ef56ab12", vision: { class: "car", confidence: 0.8, categoryId: "car" }, downgraded: false }));
|
||||
await ingest(meta({ item: "item-3", booth: "booth-9", operator: "9999999999999999" }), TOKENS.get("booth-9")!);
|
||||
|
||||
// No login → 401 with a challenge; nothing without a configured reviewer is tested in config.
|
||||
const anon = await app.inject({ method: "GET", url: "/api/items" });
|
||||
expect(anon.statusCode).toBe(401);
|
||||
expect(anon.headers["www-authenticate"]).toContain("Basic");
|
||||
expect((await app.inject({ method: "GET", url: "/review", headers: { authorization: basic } })).headers["content-type"]).toContain("text/html");
|
||||
|
||||
const list = (await app.inject({ method: "GET", url: "/api/items?status=pending", headers: { authorization: basic } })).json();
|
||||
expect(list.items.map((i: { id: string }) => i.id)).toEqual(["item-1", "item-2", "item-3"]);
|
||||
expect(list.items[0].imagePath).toBeUndefined();
|
||||
const img = await app.inject({ method: "GET", url: "/api/items/item-1/image", headers: { authorization: basic } });
|
||||
expect(img.statusCode).toBe(200);
|
||||
expect(img.headers["content-type"]).toBe("image/jpeg");
|
||||
expect(img.rawPayload.subarray(0, 3)).toEqual(Buffer.from([0xff, 0xd8, 0xff]));
|
||||
|
||||
// item-1: operator said Vetura (car/sedan/hatchback), reviewer says suv → disagree.
|
||||
// item-2: reviewer says sedan → inside Vetura → agree. item-3: unusable.
|
||||
const post = (id: string, label: string) =>
|
||||
app.inject({ method: "POST", url: `/api/items/${id}/review`, headers: { authorization: basic, "content-type": "application/json" }, payload: { label } });
|
||||
expect((await post("item-1", "suv")).json()).toMatchObject({ reviewLabel: "suv", reviewer: "julian" });
|
||||
expect((await post("item-2", "sedan")).statusCode).toBe(200);
|
||||
expect((await post("item-3", "unusable")).statusCode).toBe(200);
|
||||
expect((await post("item-3", "spaceship")).statusCode).toBe(400);
|
||||
expect((await post("nope", "suv")).statusCode).toBe(404);
|
||||
|
||||
const stats = (await app.inject({ method: "GET", url: "/api/stats", headers: { authorization: basic } })).json();
|
||||
expect(stats.booths).toEqual([
|
||||
{ booth: "booth-7", received: 2, pending: 0, reviewed: 2, entries: 0 },
|
||||
{ booth: "booth-9", received: 1, pending: 0, reviewed: 1, entries: 0 },
|
||||
]);
|
||||
expect(stats.operators).toEqual([
|
||||
{ booth: "booth-7", operatorRef: "ab12cd34ef56ab12", reviewed: 2, agree: 1, disagree: 1, unusable: 0 },
|
||||
{ booth: "booth-9", operatorRef: "9999999999999999", reviewed: 1, agree: 0, disagree: 0, unusable: 1 },
|
||||
]);
|
||||
|
||||
const csv = await app.inject({ method: "GET", url: "/export/labels.csv", headers: { authorization: basic } });
|
||||
expect(csv.statusCode).toBe(200);
|
||||
const lines = csv.body.trim().split("\n");
|
||||
expect(lines[0]).toBe("item,booth,kind,path,label,operator_category,operator_classes,vision_class,vision_confidence,downgraded,at,reviewed_at");
|
||||
expect(lines).toHaveLength(3); // header + 2 usable labels; the unusable one is left out
|
||||
expect(lines[1]).toContain('"item-1","booth-7","wash","crops/booth-7/item-1.jpg","suv","Vetura","car|sedan|hatchback","suv"');
|
||||
|
||||
// An ENTRY sample: no order, no operator — accepted, reviewable, in the export, and
|
||||
// never counted in any operator's agreement.
|
||||
const entry = await ingest({ v: 1, kind: "entry", booth: "booth-7", item: "entry-1", at: "2026-09-06T11:00:00.000Z", vision: { class: "car", confidence: 0.7 }, image: { width: 300, height: 180, plateBlurred: true } });
|
||||
expect(entry.statusCode).toBe(201);
|
||||
expect((await ingest({ v: 1, kind: "entry", booth: "booth-7", item: "entry-2", at: "x", vision: { class: "car", confidence: 0.7 }, image: { width: 1, height: 1, plateBlurred: true } })).statusCode).toBe(422);
|
||||
expect((await post("entry-1", "suv")).statusCode).toBe(200);
|
||||
const stats2 = (await app.inject({ method: "GET", url: "/api/stats", headers: { authorization: basic } })).json();
|
||||
expect(stats2.booths[0]).toEqual({ booth: "booth-7", received: 3, pending: 0, reviewed: 3, entries: 1 });
|
||||
expect(stats2.operators.find((o: { booth: string }) => o.booth === "booth-7")).toMatchObject({ reviewed: 2, agree: 1, disagree: 1 });
|
||||
const csv3 = (await app.inject({ method: "GET", url: "/export/labels.csv", headers: { authorization: basic } })).body;
|
||||
expect(csv3).toContain('"entry-1","booth-7","entry","crops/booth-7/entry-1.jpg","suv","","","car"');
|
||||
|
||||
// A booth-supplied name that looks like a spreadsheet formula is neutralised in the export.
|
||||
await ingest(meta({ item: "item-4", operatorCategory: { id: "x", name: "=HYPERLINK(\"http://evil\")", classes: ["car"] } }));
|
||||
await post("item-4", "car");
|
||||
const csv2 = (await app.inject({ method: "GET", url: "/export/labels.csv", headers: { authorization: basic } })).body;
|
||||
expect(csv2).toContain(`"'=HYPERLINK(""http://evil"")"`);
|
||||
});
|
||||
});
|
||||
|
||||
describe("config", () => {
|
||||
it("parses booth:token pairs and refuses short tokens", () => {
|
||||
expect([...parseBoothTokens("a:0123456789abcdef, b:fedcba9876543210\nc:0000000000000000").keys()]).toEqual(["a", "b", "c"]);
|
||||
expect(() => parseBoothTokens("a:short")).toThrow(/too short/);
|
||||
expect(() => parseBoothTokens("nocolon")).toThrow(/bad pair/);
|
||||
});
|
||||
});
|
||||
@@ -0,0 +1,291 @@
|
||||
import { timingSafeEqual } from "node:crypto";
|
||||
import { createReadStream } from "node:fs";
|
||||
import { mkdir, writeFile } from "node:fs/promises";
|
||||
import path from "node:path";
|
||||
import Fastify, { type FastifyInstance, type FastifyReply, type FastifyRequest } from "fastify";
|
||||
import multipart from "@fastify/multipart";
|
||||
import { isVehicleClass } from "@parking/shared";
|
||||
import type { CollectorConfig } from "./config.js";
|
||||
import { CollectorDb, type ItemRow, type ReviewVerdict } from "./db.js";
|
||||
import { reviewPage } from "./review-page.js";
|
||||
|
||||
// The collector — the far end of the booth's review outbox
|
||||
// (wiki/concepts/vision-review-outbox.md). Three surfaces and nothing else:
|
||||
// POST /ingest one package from one booth (bearer token per booth; idempotent)
|
||||
// /review + /api/* the reviewer's screen (HTTP Basic, one login)
|
||||
// GET /export/labels.csv the training set: reviewed, usable rows (crops sit beside it on
|
||||
// the volume, so the trainer on this host reads them directly)
|
||||
// /api/training/* the Training section: a thin proxy to the trainer's job API on
|
||||
// the compose network (never published), behind the reviewer login
|
||||
// It deliberately has no fleet features and no path back into a booth.
|
||||
|
||||
/** The package's `meta` part, as the booth sends it (review-outbox.ts). */
|
||||
interface IngestMeta {
|
||||
v: number;
|
||||
/** "wash" (default when absent) = a desk decision; "entry" = a sampled entry read with
|
||||
* no order and no operator — crop + the camera's class only. */
|
||||
kind?: "wash" | "entry";
|
||||
booth: string;
|
||||
item: string;
|
||||
order?: string;
|
||||
at: string;
|
||||
operator?: string;
|
||||
operatorCategory?: { id: string; name: string; classes?: string[] };
|
||||
service?: string;
|
||||
vision: { class: string; confidence: number; categoryId?: string | null };
|
||||
downgraded?: boolean;
|
||||
image: { width: number; height: number; plateBlurred: boolean };
|
||||
}
|
||||
|
||||
const ID_RE = /^[A-Za-z0-9][A-Za-z0-9_-]{0,63}$/;
|
||||
const MAX_IMAGE_BYTES = 2 * 1024 * 1024;
|
||||
|
||||
function str(v: unknown, max = 200): string | null {
|
||||
return typeof v === "string" && v.length > 0 && v.length <= max ? v : null;
|
||||
}
|
||||
|
||||
/** Validate the meta part; returns a message on the first problem. */
|
||||
function checkMeta(m: unknown, booth: string): { ok: true; meta: IngestMeta } | { ok: false; why: string } {
|
||||
if (!m || typeof m !== "object") return { ok: false, why: "meta must be an object" };
|
||||
const x = m as Record<string, unknown>;
|
||||
if (x.v !== 1) return { ok: false, why: "unsupported meta version" };
|
||||
if (x.booth !== booth) return { ok: false, why: "meta.booth does not match the token's booth" };
|
||||
if (!str(x.item, 64) || !ID_RE.test(x.item as string)) return { ok: false, why: "bad item id" };
|
||||
if (!str(x.at, 40) || Number.isNaN(Date.parse(x.at as string))) return { ok: false, why: "bad timestamp" };
|
||||
const kind = x.kind === undefined ? "wash" : x.kind;
|
||||
if (kind !== "wash" && kind !== "entry") return { ok: false, why: "bad kind" };
|
||||
const v = x.vision as Record<string, unknown> | undefined;
|
||||
if (!v || !isVehicleClass(v.class) || typeof v.confidence !== "number" || v.confidence < 0 || v.confidence > 1) return { ok: false, why: "bad vision read" };
|
||||
if (v.categoryId != null && !str(v.categoryId, 64)) return { ok: false, why: "bad vision.categoryId" };
|
||||
if (kind === "wash") {
|
||||
if (!str(x.order, 64)) return { ok: false, why: "bad order ref" };
|
||||
if (!str(x.operator, 64)) return { ok: false, why: "bad operator ref" };
|
||||
const oc = x.operatorCategory as Record<string, unknown> | undefined;
|
||||
if (!oc || !str(oc.id, 64) || !str(oc.name, 120)) return { ok: false, why: "bad operatorCategory" };
|
||||
if (oc.classes !== undefined && (!Array.isArray(oc.classes) || !oc.classes.every(isVehicleClass))) return { ok: false, why: "bad operatorCategory.classes" };
|
||||
if (!str(x.service, 120)) return { ok: false, why: "bad service" };
|
||||
if (typeof x.downgraded !== "boolean") return { ok: false, why: "bad downgraded" };
|
||||
}
|
||||
const im = x.image as Record<string, unknown> | undefined;
|
||||
if (!im || typeof im.width !== "number" || typeof im.height !== "number" || typeof im.plateBlurred !== "boolean") return { ok: false, why: "bad image meta" };
|
||||
return { ok: true, meta: x as unknown as IngestMeta };
|
||||
}
|
||||
|
||||
function safeEqual(a: string, b: string): boolean {
|
||||
const ba = Buffer.from(a);
|
||||
const bb = Buffer.from(b);
|
||||
return ba.length === bb.length && timingSafeEqual(ba, bb);
|
||||
}
|
||||
|
||||
export interface CollectorApp extends FastifyInstance {
|
||||
collectorDb: CollectorDb;
|
||||
}
|
||||
|
||||
export async function buildCollector(cfg: CollectorConfig, opts: { dbFile?: string } = {}): Promise<CollectorApp> {
|
||||
await mkdir(path.join(cfg.dataDir, "crops"), { recursive: true });
|
||||
const db = new CollectorDb(opts.dbFile ?? path.join(cfg.dataDir, "collector.sqlite"));
|
||||
const app = Fastify({ logger: { level: process.env.LOG_LEVEL ?? "info" }, bodyLimit: 64 * 1024 }) as unknown as CollectorApp;
|
||||
app.collectorDb = db;
|
||||
await app.register(multipart, { limits: { fileSize: MAX_IMAGE_BYTES, files: 1, fields: 4, parts: 6 } });
|
||||
app.addHook("onClose", async () => db.close());
|
||||
|
||||
/** Which booth this bearer token belongs to, or null. Constant-time per candidate. */
|
||||
function boothForToken(req: FastifyRequest): string | null {
|
||||
const h = req.headers.authorization ?? "";
|
||||
if (!h.startsWith("Bearer ")) return null;
|
||||
const token = h.slice(7).trim();
|
||||
let found: string | null = null;
|
||||
for (const [booth, t] of cfg.boothTokens) if (safeEqual(token, t)) found = booth;
|
||||
return found;
|
||||
}
|
||||
|
||||
/** HTTP Basic for the reviewer. */
|
||||
async function requireReviewer(req: FastifyRequest, reply: FastifyReply): Promise<void> {
|
||||
if (!cfg.reviewer) return reply.code(503).send({ error: "reviewer login not configured" });
|
||||
const h = req.headers.authorization ?? "";
|
||||
if (h.startsWith("Basic ")) {
|
||||
const [user, ...rest] = Buffer.from(h.slice(6), "base64").toString("utf8").split(":");
|
||||
const pass = rest.join(":");
|
||||
if (user && safeEqual(user, cfg.reviewer.user) && safeEqual(pass, cfg.reviewer.pass)) return;
|
||||
}
|
||||
return reply.code(401).header("www-authenticate", 'Basic realm="wash review", charset="UTF-8"').send({ error: "unauthorized" });
|
||||
}
|
||||
|
||||
app.get("/health", async () => {
|
||||
const s = db.stats();
|
||||
return { ok: true, booths: s.booths.length, pending: s.booths.reduce((n, b) => n + b.pending, 0) };
|
||||
});
|
||||
|
||||
// --- Ingest (booths) -----------------------------------------------------------------
|
||||
app.post("/ingest", async (req, reply) => {
|
||||
const booth = boothForToken(req);
|
||||
if (!booth) return reply.code(401).send({ error: "unauthorized" });
|
||||
const claimed = req.headers["x-booth-id"];
|
||||
if (typeof claimed === "string" && claimed !== booth) return reply.code(403).send({ error: "booth id does not match the token" });
|
||||
if (!req.isMultipart()) return reply.code(415).send({ error: "multipart/form-data expected" });
|
||||
|
||||
let metaRaw: string | null = null;
|
||||
let image: Buffer | null = null;
|
||||
try {
|
||||
for await (const part of req.parts()) {
|
||||
if (part.type === "file" && part.fieldname === "image") {
|
||||
image = await part.toBuffer();
|
||||
} else if (part.type === "field" && part.fieldname === "meta") {
|
||||
metaRaw = String(part.value);
|
||||
}
|
||||
}
|
||||
} catch (err) {
|
||||
const code = (err as { code?: string }).code;
|
||||
return reply.code(code === "FST_REQ_FILE_TOO_LARGE" ? 413 : 400).send({ error: (err as Error).message });
|
||||
}
|
||||
if (!metaRaw) return reply.code(400).send({ error: "meta part missing" });
|
||||
if (!image || image.length < 100) return reply.code(400).send({ error: "image part missing" });
|
||||
if (!(image[0] === 0xff && image[1] === 0xd8 && image[2] === 0xff)) return reply.code(415).send({ error: "image must be a JPEG" });
|
||||
let parsed: unknown;
|
||||
try {
|
||||
parsed = JSON.parse(metaRaw);
|
||||
} catch {
|
||||
return reply.code(400).send({ error: "meta is not JSON" });
|
||||
}
|
||||
const checked = checkMeta(parsed, booth);
|
||||
if (!checked.ok) return reply.code(422).send({ error: checked.why });
|
||||
const meta = checked.meta;
|
||||
|
||||
// Idempotent on the item id: a booth retrying after a lost 2xx must not duplicate.
|
||||
if (db.get(meta.item)) return reply.code(200).send({ ok: true, duplicate: true });
|
||||
|
||||
const rel = path.posix.join("crops", booth, `${meta.item}.jpg`);
|
||||
await mkdir(path.join(cfg.dataDir, "crops", booth), { recursive: true });
|
||||
await writeFile(path.join(cfg.dataDir, rel), image);
|
||||
const kind = meta.kind ?? "wash";
|
||||
db.insert({
|
||||
id: meta.item,
|
||||
booth,
|
||||
kind,
|
||||
orderRef: meta.order ?? "",
|
||||
at: meta.at,
|
||||
operatorRef: meta.operator ?? "",
|
||||
operatorCategoryId: meta.operatorCategory?.id ?? "",
|
||||
operatorCategoryName: meta.operatorCategory?.name ?? "",
|
||||
operatorClasses: JSON.stringify(meta.operatorCategory?.classes ?? []),
|
||||
service: meta.service ?? "",
|
||||
visionClass: meta.vision.class,
|
||||
visionConfidence: meta.vision.confidence,
|
||||
visionCategoryId: meta.vision.categoryId ?? null,
|
||||
downgraded: meta.downgraded ? 1 : 0,
|
||||
imageWidth: meta.image.width,
|
||||
imageHeight: meta.image.height,
|
||||
plateBlurred: meta.image.plateBlurred ? 1 : 0,
|
||||
imagePath: rel,
|
||||
receivedAt: new Date().toISOString(),
|
||||
});
|
||||
req.log.info(`ingest: ${booth} ${kind} ${meta.item} (${meta.vision.class}${kind === "wash" ? ` → ${meta.operatorCategory!.name}` : ""})`);
|
||||
return reply.code(201).send({ ok: true });
|
||||
});
|
||||
|
||||
// --- Review (the trusted person) -----------------------------------------------------
|
||||
const page = reviewPage();
|
||||
app.get("/", { preHandler: requireReviewer }, async (_req, reply) => reply.redirect("/review"));
|
||||
app.get("/review", { preHandler: requireReviewer }, async (_req, reply) => reply.type("text/html; charset=utf-8").send(page));
|
||||
|
||||
app.get<{ Querystring: { status?: string; limit?: string; booth?: string } }>(
|
||||
"/api/items",
|
||||
{ preHandler: requireReviewer },
|
||||
async (req) => {
|
||||
const status = req.query.status === "reviewed" ? "reviewed" : "pending";
|
||||
const limit = Math.min(Math.max(Number(req.query.limit) || 25, 1), 200);
|
||||
return { items: db.list(status, limit, req.query.booth || undefined).map(publicItem) };
|
||||
},
|
||||
);
|
||||
|
||||
app.get<{ Params: { id: string } }>("/api/items/:id/image", { preHandler: requireReviewer }, async (req, reply) => {
|
||||
const row = db.get(req.params.id);
|
||||
if (!row) return reply.code(404).send({ error: "not found" });
|
||||
return reply.type("image/jpeg").header("cache-control", "private, max-age=3600").send(createReadStream(path.join(cfg.dataDir, row.imagePath)));
|
||||
});
|
||||
|
||||
app.post<{ Params: { id: string }; Body: { label?: unknown } }>("/api/items/:id/review", { preHandler: requireReviewer }, async (req, reply) => {
|
||||
const label = req.body?.label;
|
||||
if (label !== "unusable" && !isVehicleClass(label)) return reply.code(400).send({ error: "label must be a vehicle class or 'unusable'" });
|
||||
if (!db.get(req.params.id)) return reply.code(404).send({ error: "not found" });
|
||||
const row = db.review(req.params.id, label as ReviewVerdict, cfg.reviewer!.user);
|
||||
return publicItem(row!);
|
||||
});
|
||||
|
||||
app.get("/api/stats", { preHandler: requireReviewer }, async () => db.stats());
|
||||
|
||||
// --- Export (the training set) --------------------------------------------------------
|
||||
app.get("/export/labels.csv", { preHandler: requireReviewer }, async (_req, reply) => {
|
||||
const rows = db.labelled();
|
||||
// Quote every cell; a cell starting like a spreadsheet formula (=, +, -, @, tab, CR)
|
||||
// gets a leading apostrophe — the category/service names are booth-supplied text and
|
||||
// the reviewer will open this in a spreadsheet (CSV formula injection).
|
||||
const q = (s: string | number | null) => {
|
||||
let v = String(s ?? "");
|
||||
if (/^[=+\-@\t\r]/.test(v)) v = `'${v}`;
|
||||
return `"${v.replace(/"/g, '""')}"`;
|
||||
};
|
||||
const head = "item,booth,kind,path,label,operator_category,operator_classes,vision_class,vision_confidence,downgraded,at,reviewed_at";
|
||||
const lines = rows.map((r) =>
|
||||
[r.id, r.booth, r.kind, r.imagePath, r.reviewLabel, r.operatorCategoryName, JSON.parse(r.operatorClasses).join("|"), r.visionClass, r.visionConfidence, r.downgraded, r.at, r.reviewedAt].map(q).join(","),
|
||||
);
|
||||
return reply.type("text/csv; charset=utf-8").header("content-disposition", 'attachment; filename="labels.csv"').send([head, ...lines].join("\n") + "\n");
|
||||
});
|
||||
|
||||
// --- Training (proxy to the trainer's job API) ----------------------------------------
|
||||
// The trainer is a sibling container reading the same volume; it is reachable only on the
|
||||
// compose network, so the reviewer's login here is the only gate. The proxy forwards a
|
||||
// fixed set of paths and passes the trainer's status codes through (409 = a job runs).
|
||||
const trainer = cfg.trainerUrl;
|
||||
async function viaTrainer(reply: FastifyReply, tpath: string, init?: RequestInit): Promise<unknown> {
|
||||
if (!trainer) return reply.code(503).send({ error: "trainer not configured" });
|
||||
let r: Response;
|
||||
try {
|
||||
r = await fetch(trainer + tpath, { ...init, signal: AbortSignal.timeout(15_000) });
|
||||
} catch (err) {
|
||||
return reply.code(502).send({ error: `trainer unreachable: ${(err as Error).message}` });
|
||||
}
|
||||
const ctype = r.headers.get("content-type") ?? "application/json";
|
||||
return reply.code(r.status).type(ctype).send(Buffer.from(await r.arrayBuffer()));
|
||||
}
|
||||
app.get("/api/training/status", { preHandler: requireReviewer }, async (_req, reply) => {
|
||||
if (!trainer) return { configured: false };
|
||||
try {
|
||||
const get = async (p: string) => {
|
||||
const r = await fetch(trainer + p, { signal: AbortSignal.timeout(15_000) });
|
||||
if (!r.ok) throw new Error(`${p} → HTTP ${r.status}`);
|
||||
return r.json() as Promise<Record<string, unknown>>;
|
||||
};
|
||||
const [health, readiness, versions, jobs] = await Promise.all([get("/health"), get("/readiness"), get("/versions"), get("/jobs")]);
|
||||
return { configured: true, reachable: true, health, readiness, versions: versions.versions, jobs: jobs.jobs, current: jobs.current };
|
||||
} catch (err) {
|
||||
return reply.code(200).send({ configured: true, reachable: false, error: (err as Error).message });
|
||||
}
|
||||
});
|
||||
app.post<{ Body: Record<string, unknown> }>("/api/training/jobs", { preHandler: requireReviewer }, async (req, reply) => {
|
||||
const b = req.body && typeof req.body === "object" ? req.body : {};
|
||||
const kind = b.kind;
|
||||
if (kind !== "train" && kind !== "evaluate" && kind !== "publish") return reply.code(400).send({ error: "kind must be train, evaluate or publish" });
|
||||
// Only the knobs the UI offers cross over; the trainer validates their values.
|
||||
const allowed = ["kind", "mode", "backbone", "minAccuracy", "minPerClass", "epochs", "version"];
|
||||
const body: Record<string, unknown> = {};
|
||||
for (const k of allowed) if (b[k] !== undefined) body[k] = b[k];
|
||||
return viaTrainer(reply, "/jobs", { method: "POST", headers: { "content-type": "application/json" }, body: JSON.stringify(body) });
|
||||
});
|
||||
app.get<{ Params: { id: string } }>("/api/training/jobs/:id", { preHandler: requireReviewer }, async (req, reply) => {
|
||||
if (!ID_RE.test(req.params.id)) return reply.code(400).send({ error: "bad job id" });
|
||||
return viaTrainer(reply, `/jobs/${encodeURIComponent(req.params.id)}`);
|
||||
});
|
||||
app.get<{ Params: { v: string } }>("/api/training/versions/:v/report", { preHandler: requireReviewer }, async (req, reply) => {
|
||||
if (!ID_RE.test(req.params.v)) return reply.code(400).send({ error: "bad version" });
|
||||
return viaTrainer(reply, `/versions/${encodeURIComponent(req.params.v)}/report`);
|
||||
});
|
||||
|
||||
return app;
|
||||
}
|
||||
|
||||
/** The row as the review screen sees it (no server paths). */
|
||||
function publicItem(r: ItemRow): Omit<ItemRow, "imagePath"> {
|
||||
const { imagePath: _p, ...rest } = r;
|
||||
return rest;
|
||||
}
|
||||
@@ -0,0 +1,40 @@
|
||||
export interface CollectorConfig {
|
||||
readonly host: string;
|
||||
readonly port: number;
|
||||
readonly dataDir: string;
|
||||
/** boothId → bearer token. */
|
||||
readonly boothTokens: ReadonlyMap<string, string>;
|
||||
/** The single reviewer login; null = review screen and export refuse (503). */
|
||||
readonly reviewer: { readonly user: string; readonly pass: string } | null;
|
||||
/** The trainer's job API on the compose network (http://trainer:8091); null = the
|
||||
* Training section is hidden and /api/training/* answers 503. */
|
||||
readonly trainerUrl: string | null;
|
||||
}
|
||||
|
||||
/** "booth-7:abc,booth-9:def" (commas, whitespace or newlines between pairs). */
|
||||
export function parseBoothTokens(raw: string): Map<string, string> {
|
||||
const out = new Map<string, string>();
|
||||
for (const pair of raw.split(/[,\s]+/)) {
|
||||
if (!pair) continue;
|
||||
const i = pair.indexOf(":");
|
||||
if (i <= 0) throw new Error(`COLLECTOR_BOOTH_TOKENS: bad pair "${pair}" (want boothId:token)`);
|
||||
const booth = pair.slice(0, i).trim();
|
||||
const token = pair.slice(i + 1).trim();
|
||||
if (!booth || token.length < 16) throw new Error(`COLLECTOR_BOOTH_TOKENS: token for "${booth}" too short (>=16 chars)`);
|
||||
out.set(booth, token);
|
||||
}
|
||||
return out;
|
||||
}
|
||||
|
||||
export function configFromEnv(env: NodeJS.ProcessEnv = process.env): CollectorConfig {
|
||||
const user = (env.COLLECTOR_REVIEWER_USER ?? "").trim();
|
||||
const pass = env.COLLECTOR_REVIEWER_PASS ?? "";
|
||||
return {
|
||||
host: env.COLLECTOR_HOST ?? "0.0.0.0",
|
||||
port: Number(env.COLLECTOR_PORT ?? 8090),
|
||||
dataDir: env.COLLECTOR_DATA_DIR ?? "/data",
|
||||
boothTokens: parseBoothTokens(env.COLLECTOR_BOOTH_TOKENS ?? ""),
|
||||
reviewer: user && pass.length >= 8 ? { user, pass } : null,
|
||||
trainerUrl: (env.COLLECTOR_TRAINER_URL ?? "").trim().replace(/\/+$/, "") || null,
|
||||
};
|
||||
}
|
||||
@@ -0,0 +1,186 @@
|
||||
import Database from "better-sqlite3";
|
||||
import type { VehicleClass } from "@parking/shared";
|
||||
|
||||
// One table. Each row is one booth decision: what the camera saw, what the operator
|
||||
// chose, and (once reviewed) what a trusted person says the vehicle is. The crop itself
|
||||
// lives on disk beside the DB (crops/<booth>/<item>.jpg) so the trainer on the same host
|
||||
// reads it straight off the volume.
|
||||
|
||||
export interface ItemRow {
|
||||
id: string;
|
||||
booth: string;
|
||||
/** "wash" = a desk decision (operator fields set); "entry" = a sampled entry read (pure
|
||||
* training material: crop + the camera's class, operator fields empty). */
|
||||
kind: "wash" | "entry";
|
||||
orderRef: string;
|
||||
at: string;
|
||||
operatorRef: string;
|
||||
operatorCategoryId: string;
|
||||
operatorCategoryName: string;
|
||||
/** The vision classes the operator's category covers at that site (its mapping) — what
|
||||
* lets a reviewer's CLASS be compared with an operator's CATEGORY. JSON array. */
|
||||
operatorClasses: string;
|
||||
service: string;
|
||||
visionClass: string;
|
||||
visionConfidence: number;
|
||||
visionCategoryId: string | null;
|
||||
downgraded: number;
|
||||
imageWidth: number;
|
||||
imageHeight: number;
|
||||
plateBlurred: number;
|
||||
imagePath: string;
|
||||
receivedAt: string;
|
||||
reviewLabel: string | null; // a VehicleClass, or "unusable"
|
||||
reviewedAt: string | null;
|
||||
reviewer: string | null;
|
||||
}
|
||||
|
||||
export type ReviewVerdict = VehicleClass | "unusable";
|
||||
|
||||
export class CollectorDb {
|
||||
readonly #db: Database.Database;
|
||||
|
||||
constructor(file: string) {
|
||||
this.#db = new Database(file);
|
||||
this.#db.pragma("journal_mode = WAL");
|
||||
this.#db.exec(`
|
||||
CREATE TABLE IF NOT EXISTS items (
|
||||
id TEXT PRIMARY KEY,
|
||||
booth TEXT NOT NULL,
|
||||
kind TEXT NOT NULL DEFAULT 'wash',
|
||||
order_ref TEXT NOT NULL,
|
||||
at TEXT NOT NULL,
|
||||
operator_ref TEXT NOT NULL DEFAULT '',
|
||||
operator_category_id TEXT NOT NULL DEFAULT '',
|
||||
operator_category_name TEXT NOT NULL DEFAULT '',
|
||||
operator_classes TEXT NOT NULL DEFAULT '[]',
|
||||
service TEXT NOT NULL,
|
||||
vision_class TEXT NOT NULL,
|
||||
vision_confidence REAL NOT NULL,
|
||||
vision_category_id TEXT,
|
||||
downgraded INTEGER NOT NULL DEFAULT 0,
|
||||
image_width INTEGER NOT NULL,
|
||||
image_height INTEGER NOT NULL,
|
||||
plate_blurred INTEGER NOT NULL,
|
||||
image_path TEXT NOT NULL,
|
||||
received_at TEXT NOT NULL,
|
||||
review_label TEXT,
|
||||
reviewed_at TEXT,
|
||||
reviewer TEXT
|
||||
);
|
||||
CREATE INDEX IF NOT EXISTS items_pending ON items (reviewed_at, received_at);
|
||||
CREATE INDEX IF NOT EXISTS items_booth ON items (booth, received_at);
|
||||
`);
|
||||
}
|
||||
|
||||
close(): void {
|
||||
this.#db.close();
|
||||
}
|
||||
|
||||
static #map(r: Record<string, unknown>): ItemRow {
|
||||
return {
|
||||
id: r.id as string,
|
||||
booth: r.booth as string,
|
||||
kind: r.kind === "entry" ? "entry" : "wash",
|
||||
orderRef: r.order_ref as string,
|
||||
at: r.at as string,
|
||||
operatorRef: r.operator_ref as string,
|
||||
operatorCategoryId: r.operator_category_id as string,
|
||||
operatorCategoryName: r.operator_category_name as string,
|
||||
operatorClasses: r.operator_classes as string,
|
||||
service: r.service as string,
|
||||
visionClass: r.vision_class as string,
|
||||
visionConfidence: r.vision_confidence as number,
|
||||
visionCategoryId: (r.vision_category_id as string | null) ?? null,
|
||||
downgraded: r.downgraded as number,
|
||||
imageWidth: r.image_width as number,
|
||||
imageHeight: r.image_height as number,
|
||||
plateBlurred: r.plate_blurred as number,
|
||||
imagePath: r.image_path as string,
|
||||
receivedAt: r.received_at as string,
|
||||
reviewLabel: (r.review_label as string | null) ?? null,
|
||||
reviewedAt: (r.reviewed_at as string | null) ?? null,
|
||||
reviewer: (r.reviewer as string | null) ?? null,
|
||||
};
|
||||
}
|
||||
|
||||
get(id: string): ItemRow | null {
|
||||
const r = this.#db.prepare("SELECT * FROM items WHERE id = ?").get(id) as Record<string, unknown> | undefined;
|
||||
return r ? CollectorDb.#map(r) : null;
|
||||
}
|
||||
|
||||
insert(row: Omit<ItemRow, "reviewLabel" | "reviewedAt" | "reviewer">): void {
|
||||
this.#db
|
||||
.prepare(
|
||||
`INSERT INTO items (id, booth, kind, order_ref, at, operator_ref, operator_category_id, operator_category_name,
|
||||
operator_classes, service, vision_class, vision_confidence, vision_category_id, downgraded,
|
||||
image_width, image_height, plate_blurred, image_path, received_at)
|
||||
VALUES (@id, @booth, @kind, @orderRef, @at, @operatorRef, @operatorCategoryId, @operatorCategoryName,
|
||||
@operatorClasses, @service, @visionClass, @visionConfidence, @visionCategoryId, @downgraded,
|
||||
@imageWidth, @imageHeight, @plateBlurred, @imagePath, @receivedAt)`,
|
||||
)
|
||||
.run(row);
|
||||
}
|
||||
|
||||
list(status: "pending" | "reviewed", limit: number, booth?: string): ItemRow[] {
|
||||
const where = [status === "pending" ? "reviewed_at IS NULL" : "reviewed_at IS NOT NULL"];
|
||||
const params: unknown[] = [];
|
||||
if (booth) {
|
||||
where.push("booth = ?");
|
||||
params.push(booth);
|
||||
}
|
||||
const order = status === "pending" ? "received_at ASC" : "reviewed_at DESC";
|
||||
const rows = this.#db
|
||||
.prepare(`SELECT * FROM items WHERE ${where.join(" AND ")} ORDER BY ${order} LIMIT ?`)
|
||||
.all(...params, limit) as Record<string, unknown>[];
|
||||
return rows.map((r) => CollectorDb.#map(r));
|
||||
}
|
||||
|
||||
review(id: string, label: ReviewVerdict, reviewer: string): ItemRow | null {
|
||||
this.#db
|
||||
.prepare("UPDATE items SET review_label = ?, reviewed_at = ?, reviewer = ? WHERE id = ?")
|
||||
.run(label, new Date().toISOString(), reviewer, id);
|
||||
return this.get(id);
|
||||
}
|
||||
|
||||
/** Per booth: received / pending / reviewed. Per operator (booth + hash): how often the
|
||||
* reviewer's class fell inside the operator's chosen category (agree) or outside
|
||||
* (disagree) — the honest-mistake / fraud rate the outbox exists for. */
|
||||
stats(): {
|
||||
booths: { booth: string; received: number; pending: number; reviewed: number; entries: number }[];
|
||||
operators: { booth: string; operatorRef: string; reviewed: number; agree: number; disagree: number; unusable: number }[];
|
||||
} {
|
||||
const booths = this.#db
|
||||
.prepare(
|
||||
`SELECT booth, COUNT(*) AS received,
|
||||
SUM(CASE WHEN reviewed_at IS NULL THEN 1 ELSE 0 END) AS pending,
|
||||
SUM(CASE WHEN reviewed_at IS NOT NULL THEN 1 ELSE 0 END) AS reviewed,
|
||||
SUM(CASE WHEN kind = 'entry' THEN 1 ELSE 0 END) AS entries
|
||||
FROM items GROUP BY booth ORDER BY booth`,
|
||||
)
|
||||
.all() as { booth: string; received: number; pending: number; reviewed: number; entries: number }[];
|
||||
// Operator agreement is a WASH thing — an entry sample has no operator decision.
|
||||
const reviewed = this.#db
|
||||
.prepare("SELECT booth, operator_ref, operator_classes, review_label FROM items WHERE reviewed_at IS NOT NULL AND kind = 'wash'")
|
||||
.all() as { booth: string; operator_ref: string; operator_classes: string; review_label: string }[];
|
||||
const ops = new Map<string, { booth: string; operatorRef: string; reviewed: number; agree: number; disagree: number; unusable: number }>();
|
||||
for (const r of reviewed) {
|
||||
const key = `${r.booth} ${r.operator_ref}`;
|
||||
let o = ops.get(key);
|
||||
if (!o) ops.set(key, (o = { booth: r.booth, operatorRef: r.operator_ref, reviewed: 0, agree: 0, disagree: 0, unusable: 0 }));
|
||||
o.reviewed += 1;
|
||||
if (r.review_label === "unusable") o.unusable += 1;
|
||||
else if ((JSON.parse(r.operator_classes) as string[]).includes(r.review_label)) o.agree += 1;
|
||||
else o.disagree += 1;
|
||||
}
|
||||
return { booths, operators: [...ops.values()].sort((a, b) => b.disagree - a.disagree) };
|
||||
}
|
||||
|
||||
/** Reviewed, usable rows — the training set. */
|
||||
labelled(): ItemRow[] {
|
||||
const rows = this.#db
|
||||
.prepare("SELECT * FROM items WHERE reviewed_at IS NOT NULL AND review_label != 'unusable' ORDER BY reviewed_at")
|
||||
.all() as Record<string, unknown>[];
|
||||
return rows.map((r) => CollectorDb.#map(r));
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,16 @@
|
||||
import { buildCollector } from "./app.js";
|
||||
import { configFromEnv } from "./config.js";
|
||||
|
||||
const cfg = configFromEnv();
|
||||
const app = await buildCollector(cfg);
|
||||
if (cfg.boothTokens.size === 0) app.log.warn("COLLECTOR_BOOTH_TOKENS is empty — no booth can ingest");
|
||||
if (!cfg.reviewer) app.log.warn("COLLECTOR_REVIEWER_USER/PASS not set — the review screen and export refuse");
|
||||
app.log.info(`collector: ${cfg.boothTokens.size} booth token(s), data in ${cfg.dataDir}, trainer ${cfg.trainerUrl ?? "not configured"}`);
|
||||
await app.listen({ host: cfg.host, port: cfg.port });
|
||||
|
||||
const stop = async () => {
|
||||
await app.close();
|
||||
process.exit(0);
|
||||
};
|
||||
process.on("SIGTERM", () => void stop());
|
||||
process.on("SIGINT", () => void stop());
|
||||
@@ -0,0 +1,234 @@
|
||||
import { VEHICLE_CLASSES } from "@parking/shared";
|
||||
|
||||
// The reviewer's screen: one pending crop at a time, the operator's pick and the camera's
|
||||
// pick beside it, one button per vocabulary class + "unusable". Served by the collector
|
||||
// itself (no build step, no framework) — this is deliberately the whole UI.
|
||||
|
||||
export function reviewPage(): string {
|
||||
const classes = JSON.stringify(VEHICLE_CLASSES);
|
||||
return `<!doctype html>
|
||||
<html lang="en">
|
||||
<head>
|
||||
<meta charset="utf-8">
|
||||
<meta name="viewport" content="width=device-width, initial-scale=1">
|
||||
<title>Wash review</title>
|
||||
<style>
|
||||
:root { --bg:#111; --panel:#1b1b1b; --text:#e8e8e8; --muted:#9a9a9a; --amber:#e0a030; --green:#4caf50; --red:#e05050; }
|
||||
body { margin:0; background:var(--bg); color:var(--text); font:14px/1.4 system-ui, sans-serif; }
|
||||
header { display:flex; justify-content:space-between; align-items:center; padding:.6rem 1rem; border-bottom:1px solid #333; }
|
||||
header b { letter-spacing:.08em; text-transform:uppercase; color:var(--amber); font-size:.75rem; }
|
||||
main { max-width:960px; margin:0 auto; padding:1rem; display:grid; gap:1rem; }
|
||||
.card { background:var(--panel); border:1px solid #333; border-radius:6px; padding:1rem; }
|
||||
img { max-width:100%; max-height:60vh; display:block; margin:0 auto; background:#000; border-radius:4px; }
|
||||
dl { display:grid; grid-template-columns:max-content 1fr; gap:.2rem .8rem; margin:0; font-variant-numeric:tabular-nums; }
|
||||
dt { color:var(--muted); }
|
||||
.buttons { display:flex; flex-wrap:wrap; gap:.4rem; }
|
||||
button { background:#2a2a2a; color:var(--text); border:1px solid #444; border-radius:4px; padding:.5rem .8rem; font:inherit; cursor:pointer; }
|
||||
button:hover { border-color:var(--amber); }
|
||||
button.mono { font-family:ui-monospace, monospace; }
|
||||
button.hint { border-color:var(--amber); }
|
||||
button.unusable { color:var(--red); }
|
||||
button.skip { color:var(--muted); }
|
||||
.muted { color:var(--muted); }
|
||||
.warn { color:var(--amber); }
|
||||
table { border-collapse:collapse; width:100%; font-variant-numeric:tabular-nums; }
|
||||
td, th { text-align:left; padding:.2rem .5rem; border-bottom:1px solid #2a2a2a; }
|
||||
th { color:var(--muted); font-weight:normal; font-size:.75rem; text-transform:uppercase; letter-spacing:.06em; }
|
||||
kbd { background:#2a2a2a; border:1px solid #444; border-radius:3px; padding:0 .3rem; font-size:.75rem; }
|
||||
h2 { font-size:.8rem; letter-spacing:.08em; text-transform:uppercase; color:var(--amber); margin:0 0 .6rem; }
|
||||
.row { display:flex; flex-wrap:wrap; gap:.6rem; align-items:center; }
|
||||
select, input { background:#2a2a2a; color:var(--text); border:1px solid #444; border-radius:4px; padding:.4rem .5rem; font:inherit; }
|
||||
input[type=number] { width:5rem; }
|
||||
label { color:var(--muted); font-size:.8rem; }
|
||||
pre { background:#0d0d0d; border:1px solid #2a2a2a; border-radius:4px; padding:.6rem; max-height:22rem; overflow:auto; font-size:.75rem; white-space:pre-wrap; margin:.6rem 0 0; }
|
||||
.ok { color:var(--green); }
|
||||
.bad { color:var(--red); }
|
||||
button:disabled { opacity:.45; cursor:not-allowed; }
|
||||
button.small { padding:.25rem .5rem; font-size:.75rem; }
|
||||
</style>
|
||||
</head>
|
||||
<body>
|
||||
<header><b>Wash review</b><span id="counts" class="muted"></span></header>
|
||||
<main>
|
||||
<section class="card" id="item">
|
||||
<p class="muted">Loading…</p>
|
||||
</section>
|
||||
<section class="card">
|
||||
<table id="stats"><thead><tr><th>booth</th><th>operator</th><th>reviewed</th><th>agree</th><th>disagree</th><th>unusable</th></tr></thead><tbody></tbody></table>
|
||||
</section>
|
||||
<section class="card" id="training" hidden>
|
||||
<h2>Training</h2>
|
||||
<div id="tr-body"></div>
|
||||
</section>
|
||||
<p class="muted">Keys: <kbd>1</kbd>–<kbd>9</kbd>, <kbd>0</kbd> pick a class in order · <kbd>u</kbd> unusable · <kbd>s</kbd> skip. Skipped items come back after a reload. Your verdict is the training label; the operator's pick is only compared against it.</p>
|
||||
</main>
|
||||
<script>
|
||||
const CLASSES = ${classes};
|
||||
const skipped = new Set();
|
||||
let current = null;
|
||||
|
||||
async function api(path, init) {
|
||||
const r = await fetch(path, init);
|
||||
if (!r.ok) throw new Error(path + ' → HTTP ' + r.status);
|
||||
return r.json();
|
||||
}
|
||||
|
||||
function esc(s) { return String(s).replace(/[&<>"]/g, c => ({'&':'&','<':'<','>':'>','"':'"'}[c])); }
|
||||
|
||||
async function loadStats() {
|
||||
const s = await api('/api/stats');
|
||||
const pending = s.booths.reduce((n, b) => n + b.pending, 0);
|
||||
const reviewed = s.booths.reduce((n, b) => n + b.reviewed, 0);
|
||||
document.getElementById('counts').textContent = pending + ' waiting · ' + reviewed + ' reviewed';
|
||||
const tb = document.querySelector('#stats tbody');
|
||||
tb.innerHTML = s.operators.map(o => '<tr><td>' + esc(o.booth) + '</td><td class="mono">' + esc(o.operatorRef) + '</td><td>' + o.reviewed + '</td><td>' + o.agree + '</td><td' + (o.disagree ? ' class="warn"' : '') + '>' + o.disagree + '</td><td>' + o.unusable + '</td></tr>').join('') || '<tr><td colspan="6" class="muted">nothing reviewed yet</td></tr>';
|
||||
}
|
||||
|
||||
async function next() {
|
||||
const { items } = await api('/api/items?status=pending&limit=25');
|
||||
current = items.find(i => !skipped.has(i.id)) || null;
|
||||
const el = document.getElementById('item');
|
||||
if (!current) { el.innerHTML = '<p class="muted">Nothing waiting for review.</p>'; return; }
|
||||
const it = current;
|
||||
const opClasses = JSON.parse(it.operatorClasses || '[]');
|
||||
el.innerHTML =
|
||||
'<img src="/api/items/' + encodeURIComponent(it.id) + '/image" alt="">' +
|
||||
'<dl style="margin-top:.8rem">' +
|
||||
(it.kind === 'entry'
|
||||
? '<dt>sample</dt><dd><span class="muted">entry stream — no wash, no operator decision; label the vehicle</span></dd>'
|
||||
: '<dt>operator chose</dt><dd><b>' + esc(it.operatorCategoryName) + '</b> <span class="muted">(' + esc(opClasses.join(', ') || 'no classes mapped') + ')</span></dd>') +
|
||||
'<dt>camera saw</dt><dd class="mono">' + esc(it.visionClass) + ' <span class="muted">' + Math.round(it.visionConfidence * 100) + '%</span>' + (it.downgraded ? ' <span class="warn">flagged downgrade at the booth</span>' : '') + '</dd>' +
|
||||
(it.kind === 'entry' ? '<dt>booth</dt><dd class="mono">' + esc(it.booth) + '</dd>' :
|
||||
'<dt>service</dt><dd>' + esc(it.service) + '</dd>' +
|
||||
'<dt>booth · operator</dt><dd class="mono">' + esc(it.booth) + ' · ' + esc(it.operatorRef) + '</dd>') +
|
||||
'<dt>at</dt><dd>' + esc(it.at) + '</dd>' +
|
||||
'</dl>' +
|
||||
'<div class="buttons" style="margin-top:.8rem">' +
|
||||
CLASSES.map((c, i) => '<button class="mono' + (c === it.visionClass ? ' hint' : '') + '" data-label="' + c + '" title="key ' + ((i + 1) % 10) + '">' + c + '</button>').join('') +
|
||||
'<button class="unusable" data-label="unusable">unusable</button>' +
|
||||
'<button class="skip" data-skip="1">skip</button>' +
|
||||
'</div>';
|
||||
el.querySelectorAll('button[data-label]').forEach(b => b.addEventListener('click', () => verdict(b.dataset.label)));
|
||||
el.querySelector('button[data-skip]').addEventListener('click', skip);
|
||||
}
|
||||
|
||||
async function verdict(label) {
|
||||
if (!current) return;
|
||||
await api('/api/items/' + encodeURIComponent(current.id) + '/review', { method: 'POST', headers: { 'content-type': 'application/json' }, body: JSON.stringify({ label }) });
|
||||
await Promise.all([next(), loadStats()]);
|
||||
}
|
||||
function skip() { if (current) { skipped.add(current.id); next(); } }
|
||||
|
||||
document.addEventListener('keydown', e => {
|
||||
if (e.target.tagName === 'INPUT') return;
|
||||
if (e.key === 'u') verdict('unusable');
|
||||
else if (e.key === 's') skip();
|
||||
else if (/^[0-9]$/.test(e.key)) { const i = e.key === '0' ? 9 : Number(e.key) - 1; if (CLASSES[i]) verdict(CLASSES[i]); }
|
||||
});
|
||||
|
||||
next().catch(e => { document.getElementById('item').innerHTML = '<p class="warn">' + esc(e.message) + '</p>'; });
|
||||
loadStats().catch(() => {});
|
||||
|
||||
// ---- Training: the trainer's job API, proxied by the collector -------------------------
|
||||
// Readiness (labels per class vs the minimum), one job at a time with a live log, the
|
||||
// versions a run produced (written or refused) with Report / Evaluate / Publish. Pinning a
|
||||
// published version into the vision image stays a git commit — that is the deploy control.
|
||||
let trPoll = null;
|
||||
let trShownReport = null;
|
||||
const trDefaults = { mode: 'features', backbone: 'resnet18', minAccuracy: 0.85 };
|
||||
|
||||
function pct(x) { return x == null ? '—' : Math.round(x * 100) + ' %'; }
|
||||
|
||||
async function training() {
|
||||
const box = document.getElementById('training');
|
||||
const el = document.getElementById('tr-body');
|
||||
let s;
|
||||
try { s = await api('/api/training/status'); } catch (e) { box.hidden = false; el.innerHTML = '<p class="warn">' + esc(e.message) + '</p>'; return; }
|
||||
if (!s.configured) { box.hidden = true; return; }
|
||||
box.hidden = false;
|
||||
if (!s.reachable) { el.innerHTML = '<p class="warn">trainer not reachable: ' + esc(s.error || '') + '</p>'; schedule(true); return; }
|
||||
const r = s.readiness, run = r.run || {}, minPer = run.minPerClass || 20;
|
||||
const byClass = (r.labelled && r.labelled.byClass) || {};
|
||||
const classes = Object.keys(byClass);
|
||||
const cur = s.current;
|
||||
const readyLine = r.ready
|
||||
? '<span class="ok">enough labels to train</span> — classes this run: ' + esc((run.classes || []).join(', '))
|
||||
: '<span class="warn">not enough labels yet</span> — a class needs ' + minPer + ' reviewed crops; two classes must clear it';
|
||||
let html = '<p>' + readyLine + ' <span class="muted">(' + (r.labelled ? r.labelled.total : 0) + ' labelled, ' + (r.missingCrops || 0) + ' missing crop files)</span></p>';
|
||||
html += '<table><thead><tr><th>class</th><th>reviewed</th><th>train</th><th>val</th><th></th></tr></thead><tbody>' +
|
||||
(classes.map(c => '<tr><td class="mono">' + esc(c) + '</td><td>' + byClass[c] + '</td><td>' + ((run.train || {})[c] ?? '—') + '</td><td>' + ((run.val || {})[c] ?? '—') + '</td><td class="muted">' + (byClass[c] < minPer ? 'below ' + minPer + ' — dropped' : '') + '</td></tr>').join('') || '<tr><td colspan="5" class="muted">no labels yet — review crops above</td></tr>') +
|
||||
'</tbody></table>';
|
||||
const d = Object.assign({}, trDefaults, r.defaults || {});
|
||||
html += '<div class="row" style="margin-top:.8rem">' +
|
||||
'<label>mode <select id="tr-mode">' + (r.modes || ['features', 'finetune']).map(m => '<option' + (m === d.mode ? ' selected' : '') + '>' + m + '</option>').join('') + '</select></label>' +
|
||||
'<label>backbone <select id="tr-backbone">' + (r.backbones || ['resnet18']).map(b => '<option' + (b === d.backbone ? ' selected' : '') + '>' + b + '</option>').join('') + '</select></label>' +
|
||||
'<label>floor <input id="tr-floor" type="number" min="0" max="1" step="0.01" value="' + d.minAccuracy + '"></label>' +
|
||||
'<button id="tr-train"' + (r.ready && !cur ? '' : ' disabled') + '>Train</button>' +
|
||||
(cur ? '<span class="warn">running: ' + esc(cur.kind) + ' ' + esc(cur.id) + '</span>' : '') +
|
||||
'</div>';
|
||||
const last = cur || (s.jobs && s.jobs[0]);
|
||||
if (last) {
|
||||
const cls = last.status === 'done' ? 'ok' : last.status === 'running' ? 'warn' : 'bad';
|
||||
html += '<p style="margin:.8rem 0 0"><span class="' + cls + '">' + esc(last.status) + '</span> <span class="mono">' + esc(last.kind) + ' ' + esc(last.id) + '</span> <span class="muted">' + esc(last.startedAt || '') + (last.exitCode != null ? ' · exit ' + last.exitCode : '') + '</span> <button class="small" data-job="' + esc(last.id) + '">log</button></p>' +
|
||||
'<pre id="tr-log" hidden></pre>';
|
||||
}
|
||||
const vs = s.versions || [];
|
||||
html += '<h2 style="margin-top:1rem">Versions</h2>';
|
||||
html += vs.length
|
||||
? '<table><thead><tr><th>version</th><th>model</th><th>accuracy</th><th>classes</th><th>mode</th><th></th></tr></thead><tbody>' +
|
||||
vs.map(v => '<tr><td class="mono">' + esc(v.version) + '</td><td>' + (v.written ? '<span class="ok">written</span>' : '<span class="bad">refused</span>') + '</td><td>' + pct(v.accuracy) + (v.floor != null ? ' <span class="muted">/ floor ' + pct(v.floor) + '</span>' : '') + '</td><td class="muted">' + esc((v.classes || []).join(', ')) + '</td><td class="muted">' + esc(v.mode || '') + '</td><td>' +
|
||||
'<button class="small" data-report="' + esc(v.version) + '">report</button> ' +
|
||||
(v.written ? '<button class="small" data-eval="' + esc(v.version) + '"' + (cur ? ' disabled' : '') + '>evaluate</button> <button class="small" data-publish="' + esc(v.version) + '"' + (cur ? ' disabled' : '') + '>publish</button>' : '') +
|
||||
'</td></tr>').join('') + '</tbody></table>'
|
||||
: '<p class="muted">no runs yet</p>';
|
||||
html += '<pre id="tr-report" hidden></pre>';
|
||||
html += '<p class="muted" style="margin:.8rem 0 0">A written model is only a file here. To put it on a booth: publish, then pin the version in <span class="mono">apps/vision/models/bodytype.version</span>, commit, and bump the TAG of the booth.</p>';
|
||||
el.innerHTML = html;
|
||||
|
||||
const trainBtn = document.getElementById('tr-train');
|
||||
if (trainBtn) trainBtn.addEventListener('click', () => startJob({ kind: 'train', mode: document.getElementById('tr-mode').value, backbone: document.getElementById('tr-backbone').value, minAccuracy: Number(document.getElementById('tr-floor').value) }));
|
||||
el.querySelectorAll('button[data-eval]').forEach(b => b.addEventListener('click', () => startJob({ kind: 'evaluate', version: b.dataset.eval })));
|
||||
el.querySelectorAll('button[data-publish]').forEach(b => b.addEventListener('click', () => { if (confirm('Publish ' + b.dataset.publish + ' to the package registry?')) startJob({ kind: 'publish', version: b.dataset.publish }); }));
|
||||
el.querySelectorAll('button[data-job]').forEach(b => b.addEventListener('click', () => showLog(b.dataset.job)));
|
||||
el.querySelectorAll('button[data-report]').forEach(b => b.addEventListener('click', () => showReport(b.dataset.report)));
|
||||
if (cur) showLog(cur.id).catch(() => {});
|
||||
if (trShownReport) showReport(trShownReport).catch(() => {});
|
||||
schedule(!!cur);
|
||||
}
|
||||
|
||||
function schedule(soon) {
|
||||
if (trPoll) clearTimeout(trPoll);
|
||||
trPoll = setTimeout(() => training().catch(() => {}), soon ? 4000 : 60000);
|
||||
}
|
||||
|
||||
async function startJob(body) {
|
||||
try {
|
||||
const r = await fetch('/api/training/jobs', { method: 'POST', headers: { 'content-type': 'application/json' }, body: JSON.stringify(body) });
|
||||
if (!r.ok) { const e = await r.json().catch(() => ({})); alert('trainer: ' + (e.error || ('HTTP ' + r.status))); }
|
||||
} catch (e) { alert(e.message); }
|
||||
training().catch(() => {});
|
||||
}
|
||||
|
||||
async function showLog(id) {
|
||||
const j = await api('/api/training/jobs/' + encodeURIComponent(id));
|
||||
const pre = document.getElementById('tr-log');
|
||||
if (!pre) return;
|
||||
pre.hidden = false;
|
||||
pre.textContent = j.log || '(no output yet)';
|
||||
pre.scrollTop = pre.scrollHeight;
|
||||
}
|
||||
|
||||
async function showReport(v) {
|
||||
const r = await fetch('/api/training/versions/' + encodeURIComponent(v) + '/report');
|
||||
const pre = document.getElementById('tr-report');
|
||||
if (!pre) return;
|
||||
trShownReport = v;
|
||||
pre.hidden = false;
|
||||
pre.textContent = r.ok ? await r.text() : 'no report for ' + v + ' (HTTP ' + r.status + ')';
|
||||
}
|
||||
|
||||
training().catch(() => {});
|
||||
</script>
|
||||
</body>
|
||||
</html>`;
|
||||
}
|
||||
@@ -0,0 +1,126 @@
|
||||
import { afterEach, beforeEach, describe, expect, it } from "vitest";
|
||||
import { createServer, type IncomingMessage, type Server, type ServerResponse } from "node:http";
|
||||
import { mkdtemp, rm } from "node:fs/promises";
|
||||
import { tmpdir } from "node:os";
|
||||
import path from "node:path";
|
||||
import { buildCollector, type CollectorApp } from "./app.js";
|
||||
|
||||
// The Training section's proxy: reviewer-gated, forwards a fixed set of paths to the
|
||||
// trainer's job API, passes its status codes through, and degrades cleanly when the trainer
|
||||
// is not configured or not reachable. The trainer is faked with a bare node http server.
|
||||
|
||||
const REVIEWER = { user: "julian", pass: "review-pass-123" };
|
||||
const basic = "Basic " + Buffer.from(`${REVIEWER.user}:${REVIEWER.pass}`).toString("base64");
|
||||
|
||||
let dir: string;
|
||||
let fake: Server;
|
||||
let fakeUrl: string;
|
||||
let seen: { method: string; url: string; body: string }[];
|
||||
let app: CollectorApp;
|
||||
|
||||
async function start(trainerUrl: string | null): Promise<void> {
|
||||
app = await buildCollector({ host: "127.0.0.1", port: 0, dataDir: dir, boothTokens: new Map(), reviewer: REVIEWER, trainerUrl }, { dbFile: ":memory:" });
|
||||
await app.ready();
|
||||
}
|
||||
|
||||
beforeEach(async () => {
|
||||
dir = await mkdtemp(path.join(tmpdir(), "collector-"));
|
||||
seen = [];
|
||||
fake = createServer((req: IncomingMessage, res: ServerResponse) => {
|
||||
let body = "";
|
||||
req.on("data", (c) => (body += c));
|
||||
req.on("end", () => {
|
||||
seen.push({ method: req.method ?? "", url: req.url ?? "", body });
|
||||
const json = (code: number, obj: unknown) => {
|
||||
res.writeHead(code, { "content-type": "application/json" });
|
||||
res.end(JSON.stringify(obj));
|
||||
};
|
||||
if (req.url === "/health") return json(200, { ok: true, busy: false });
|
||||
if (req.url === "/readiness") return json(200, { ready: false, labelled: { total: 3 } });
|
||||
if (req.url === "/versions") return json(200, { versions: [{ version: "v1", written: true }] });
|
||||
if (req.url === "/jobs" && req.method === "GET") return json(200, { jobs: [{ id: "j1" }], current: null });
|
||||
if (req.url === "/jobs" && req.method === "POST") return body.includes('"busy"') ? json(409, { error: "a job is already running" }) : json(202, { id: "j2", status: "running" });
|
||||
if (req.url === "/jobs/j1") return json(200, { id: "j1", status: "done", log: "ok" });
|
||||
if (req.url === "/versions/v1/report") {
|
||||
res.writeHead(200, { "content-type": "text/markdown; charset=utf-8" });
|
||||
return res.end("# Body-type classifier v1\n");
|
||||
}
|
||||
return json(404, { error: "not found" });
|
||||
});
|
||||
});
|
||||
await new Promise<void>((r) => fake.listen(0, "127.0.0.1", r));
|
||||
const a = fake.address() as { port: number };
|
||||
fakeUrl = `http://127.0.0.1:${a.port}`;
|
||||
});
|
||||
afterEach(async () => {
|
||||
await app?.close();
|
||||
await new Promise<void>((r) => fake.close(() => r()));
|
||||
await rm(dir, { recursive: true, force: true });
|
||||
});
|
||||
|
||||
describe("review page script", () => {
|
||||
it("parses as JavaScript (an apostrophe in a template literal once broke the whole page)", async () => {
|
||||
const { reviewPage } = await import("./review-page.js");
|
||||
const html = reviewPage();
|
||||
const script = html.slice(html.indexOf("<script>") + 8, html.lastIndexOf("</script>"));
|
||||
expect(() => new Function(script)).not.toThrow();
|
||||
});
|
||||
});
|
||||
|
||||
describe("training proxy", () => {
|
||||
it("is hidden when no trainer is configured", async () => {
|
||||
await start(null);
|
||||
const s = await app.inject({ method: "GET", url: "/api/training/status", headers: { authorization: basic } });
|
||||
expect(s.json()).toEqual({ configured: false });
|
||||
const j = await app.inject({ method: "POST", url: "/api/training/jobs", headers: { authorization: basic }, payload: { kind: "train" } });
|
||||
expect(j.statusCode).toBe(503);
|
||||
});
|
||||
|
||||
it("aggregates status and forwards jobs and reports behind the reviewer login", async () => {
|
||||
await start(fakeUrl);
|
||||
expect((await app.inject({ method: "GET", url: "/api/training/status" })).statusCode).toBe(401);
|
||||
const s = await app.inject({ method: "GET", url: "/api/training/status", headers: { authorization: basic } });
|
||||
expect(s.statusCode).toBe(200);
|
||||
const body = s.json();
|
||||
expect(body.configured).toBe(true);
|
||||
expect(body.reachable).toBe(true);
|
||||
expect(body.readiness.labelled.total).toBe(3);
|
||||
expect(body.versions[0].version).toBe("v1");
|
||||
expect(body.jobs[0].id).toBe("j1");
|
||||
|
||||
const j = await app.inject({
|
||||
method: "POST",
|
||||
url: "/api/training/jobs",
|
||||
headers: { authorization: basic },
|
||||
payload: { kind: "train", mode: "features", minAccuracy: 0.9, secret: "nope", version: "v2" },
|
||||
});
|
||||
expect(j.statusCode).toBe(202);
|
||||
expect(j.json().id).toBe("j2");
|
||||
const posted = seen.find((r) => r.method === "POST")!;
|
||||
expect(JSON.parse(posted.body)).toEqual({ kind: "train", mode: "features", minAccuracy: 0.9, version: "v2" }); // unknown keys dropped
|
||||
|
||||
const busy = await app.inject({ method: "POST", url: "/api/training/jobs", headers: { authorization: basic }, payload: { kind: "evaluate", version: "busy" } });
|
||||
expect(busy.statusCode).toBe(409); // the trainer's answer passes through
|
||||
|
||||
const bad = await app.inject({ method: "POST", url: "/api/training/jobs", headers: { authorization: basic }, payload: { kind: "rm-rf" } });
|
||||
expect(bad.statusCode).toBe(400);
|
||||
|
||||
const one = await app.inject({ method: "GET", url: "/api/training/jobs/j1", headers: { authorization: basic } });
|
||||
expect(one.json().status).toBe("done");
|
||||
expect((await app.inject({ method: "GET", url: "/api/training/jobs/..%2Fx", headers: { authorization: basic } })).statusCode).toBe(400);
|
||||
|
||||
const rep = await app.inject({ method: "GET", url: "/api/training/versions/v1/report", headers: { authorization: basic } });
|
||||
expect(rep.statusCode).toBe(200);
|
||||
expect(rep.headers["content-type"]).toContain("text/markdown");
|
||||
expect(rep.body).toContain("# Body-type classifier v1");
|
||||
});
|
||||
|
||||
it("reports an unreachable trainer without failing the page", async () => {
|
||||
await start("http://127.0.0.1:9"); // nothing listens on the discard port
|
||||
const s = await app.inject({ method: "GET", url: "/api/training/status", headers: { authorization: basic } });
|
||||
expect(s.statusCode).toBe(200);
|
||||
expect(s.json().reachable).toBe(false);
|
||||
const j = await app.inject({ method: "POST", url: "/api/training/jobs", headers: { authorization: basic }, payload: { kind: "train" } });
|
||||
expect(j.statusCode).toBe(502);
|
||||
});
|
||||
});
|
||||
@@ -0,0 +1,10 @@
|
||||
{
|
||||
"extends": "../../tsconfig.base.json",
|
||||
"compilerOptions": {
|
||||
"rootDir": "./src",
|
||||
"outDir": "./dist"
|
||||
},
|
||||
"references": [{ "path": "../../packages/shared" }],
|
||||
"include": ["src/**/*"],
|
||||
"exclude": ["src/**/*.test.ts"]
|
||||
}
|
||||
@@ -0,0 +1,5 @@
|
||||
import { defineConfig } from "vitest/config";
|
||||
|
||||
export default defineConfig({
|
||||
test: { include: ["src/**/*.test.ts"], env: { LOG_LEVEL: "silent" } },
|
||||
});
|
||||
+40
-3
@@ -35,8 +35,45 @@ pnpm --filter @parking/desktop bundle # build the SPA + bundle the desktop app
|
||||
Requires the Rust toolchain and (on Linux) WebKitGTK 4.1 + libsoup-3 dev libraries. Under WSL2 the
|
||||
window needs a display (WSLg or an X server).
|
||||
|
||||
## Auto-update
|
||||
|
||||
Signed updates are built and published by `.gitea/workflows/release.yml` on a `vX.Y.Z` tag, mirrored
|
||||
to the public `mca/public_releases` repo (this repo is private; the updater runs on offline-first
|
||||
field appliances with no Gitea credentials, so its endpoint must be reachable unauthenticated —
|
||||
see that workflow's header and `wiki/decisions/desktop-shell-tauri.md`). The updater config and
|
||||
signing pubkey live in `tauri.conf.json`; the private signing key is held outside the repo, never
|
||||
committed.
|
||||
|
||||
**The manifest carries one entry per installer type** (`linux-x86_64-deb`, `linux-x86_64-rpm`,
|
||||
and bare `linux-x86_64` for AppImage). The updater picks the entry matching how the running app
|
||||
was installed — a `.deb` install will only ever accept a signed `.deb`. Booths run the `.deb`,
|
||||
so an in-app update ends in a **polkit password prompt** (`pkexec dpkg -i`): that is expected,
|
||||
and it is the right gate — the package lives in `/usr/bin`, root-owned, and the operator is not
|
||||
supposed to be able to replace it silently. Cancel the prompt and the app keeps running the old
|
||||
version; the failure is logged to the server's Logs viewer.
|
||||
|
||||
## Release gate — run the REAL bundle locally before tagging
|
||||
|
||||
`tauri dev` loads the SPA from `http://localhost:5173`, a plain http origin. The shipped bundle
|
||||
loads it from `tauri://localhost`, a *secure* custom-scheme origin — and every desktop-only bug
|
||||
found in the field on 2026-09-03/04 (relative-URL DOMException, mixed content, missing WS
|
||||
`Origin`, the reqwest-vs-webview cookie split, the WS handshake that can't carry the cookie)
|
||||
depends on that difference. **Dev mode cannot reproduce any of them**, so "works in `tauri dev`"
|
||||
carries no information about a release. Before pushing a `vX.Y.Z` tag:
|
||||
|
||||
1. `pnpm --filter @parking/server dev` (local backend; `.env` must have `COOKIE_SECURE=0` and
|
||||
`tauri://localhost` in `WS_ALLOWED_ORIGINS`).
|
||||
2. `pnpm --filter @parking/desktop bundle` and run the produced AppImage from
|
||||
`src-tauri/target/release/bundle/appimage/` (WSLg is enough).
|
||||
3. On the ConnectScreen enter `127.0.0.1:3000`, **Test** must say reachable, then **Save**.
|
||||
4. Log in. The booth header must show **LIVE** (not "JASHTË LINJË") within a few seconds.
|
||||
5. Perform one mutation (e.g. change your UI language) — it must succeed (proves CSRF).
|
||||
6. Open Setup → Logs and confirm a `frontend`-sourced row from this desktop session exists
|
||||
(proves the desktop log channel; historically it was silently 403'd).
|
||||
|
||||
Only then tag. If a release still fails in the field, the gap is in this list — fix the list.
|
||||
|
||||
## Not here (deliberately)
|
||||
|
||||
Kiosk lockdown (fullscreen/no-decorations), auto-update, code signing, and launching Fastify from
|
||||
the shell are out of scope for the scaffold — on the appliance Fastify runs as its own service and
|
||||
this shell connects to it.
|
||||
Kiosk lockdown (fullscreen/no-decorations) and launching Fastify from the shell are out of scope for
|
||||
the scaffold — on the appliance Fastify runs as its own service and this shell connects to it.
|
||||
|
||||
Generated
+578
-8
@@ -318,6 +318,23 @@ version = "1.0.4"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "9330f8b2ff13f34540b44e946ef35111825727b38d33286ef986142615121801"
|
||||
|
||||
[[package]]
|
||||
name = "cfg_aliases"
|
||||
version = "0.2.2"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "f079e83a288787bcd14a6aea84cee5c87a67c5a3e660c30f557a3d24761b3527"
|
||||
|
||||
[[package]]
|
||||
name = "chacha20"
|
||||
version = "0.10.2"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "65c35e4b699c7e15ccbe7ee35c005e4fc0a278d22238a2857e6ce2dadeda1b06"
|
||||
dependencies = [
|
||||
"cfg-if",
|
||||
"cpufeatures 0.3.1",
|
||||
"rand_core 0.10.1",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "chrono"
|
||||
version = "0.4.45"
|
||||
@@ -346,10 +363,39 @@ version = "0.18.1"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "4ddef33a339a91ea89fb53151bd0a4689cfce27055c291dfa69945475d22c747"
|
||||
dependencies = [
|
||||
"percent-encoding",
|
||||
"time",
|
||||
"version_check",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "cookie_store"
|
||||
version = "0.22.1"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "15b2c103cf610ec6cae3da84a766285b42fd16aad564758459e6ecf128c75206"
|
||||
dependencies = [
|
||||
"cookie",
|
||||
"document-features",
|
||||
"idna",
|
||||
"log",
|
||||
"publicsuffix",
|
||||
"serde",
|
||||
"serde_derive",
|
||||
"serde_json",
|
||||
"time",
|
||||
"url",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "core-foundation"
|
||||
version = "0.9.4"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "91e195e091a93c46f7102ec7818a2aa394e1e1771c3ab4825963fa03e45afb8f"
|
||||
dependencies = [
|
||||
"core-foundation-sys",
|
||||
"libc",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "core-foundation"
|
||||
version = "0.10.1"
|
||||
@@ -373,7 +419,7 @@ source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "064badf302c3194842cf2c5d61f56cc88e54a759313879cdf03abdd27d0c3b97"
|
||||
dependencies = [
|
||||
"bitflags 2.13.0",
|
||||
"core-foundation",
|
||||
"core-foundation 0.10.1",
|
||||
"core-graphics-types",
|
||||
"foreign-types",
|
||||
"libc",
|
||||
@@ -386,7 +432,7 @@ source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "3d44a101f213f6c4cdc1853d4b78aef6db6bdfa3468798cc1d9912f4735013eb"
|
||||
dependencies = [
|
||||
"bitflags 2.13.0",
|
||||
"core-foundation",
|
||||
"core-foundation 0.10.1",
|
||||
"libc",
|
||||
]
|
||||
|
||||
@@ -399,6 +445,15 @@ dependencies = [
|
||||
"libc",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "cpufeatures"
|
||||
version = "0.3.1"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "5ca28b0ae3115b884660db4118d803791fd6756b6e88f39c0f3f7859060d7566"
|
||||
dependencies = [
|
||||
"libc",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "crc32fast"
|
||||
version = "1.5.0"
|
||||
@@ -506,6 +561,18 @@ dependencies = [
|
||||
"syn 2.0.118",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "data-encoding"
|
||||
version = "2.11.1"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "4583a4551df46e2792f82ceeac45e850d2e2d5debba0b91f102385cda5b11f06"
|
||||
|
||||
[[package]]
|
||||
name = "data-url"
|
||||
version = "0.3.2"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "be1e0bca6c3637f992fc1cc7cbc52a78c1ef6db076dbf1059c4323d6a2048376"
|
||||
|
||||
[[package]]
|
||||
name = "dbus"
|
||||
version = "0.9.11"
|
||||
@@ -635,6 +702,15 @@ dependencies = [
|
||||
"syn 2.0.118",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "document-features"
|
||||
version = "0.2.12"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "d4b8a88685455ed29a21542a33abd9cb6510b6b129abadabdcef0f4c55bc8f61"
|
||||
dependencies = [
|
||||
"litrs",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "dom_query"
|
||||
version = "0.27.0"
|
||||
@@ -721,6 +797,15 @@ version = "1.2.2"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "4ef6b89e5b37196644d8796de5268852ff179b44e96276cf4290264843743bb7"
|
||||
|
||||
[[package]]
|
||||
name = "encoding_rs"
|
||||
version = "0.8.35"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "75030f3c4f45dafd7586dd6780965a8c7e8e285a5ecb86713e63a79c5b2766f3"
|
||||
dependencies = [
|
||||
"cfg-if",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "equivalent"
|
||||
version = "1.0.2"
|
||||
@@ -1034,8 +1119,10 @@ source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "ff2abc00be7fca6ebc474524697ae276ad847ad0a6b3faa4bcb027e9a4614ad0"
|
||||
dependencies = [
|
||||
"cfg-if",
|
||||
"js-sys",
|
||||
"libc",
|
||||
"wasi",
|
||||
"wasm-bindgen",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
@@ -1057,8 +1144,11 @@ source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "300e883d756b2e4ec94e02791f39b04b522276138852cfc41d9fb7e904106099"
|
||||
dependencies = [
|
||||
"cfg-if",
|
||||
"js-sys",
|
||||
"libc",
|
||||
"r-efi 6.0.0",
|
||||
"rand_core 0.10.1",
|
||||
"wasm-bindgen",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
@@ -1209,6 +1299,25 @@ dependencies = [
|
||||
"syn 2.0.118",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "h2"
|
||||
version = "0.4.19"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "ef8e5e5a340588f4452631496976cf8636d4a7ecf600239fdc27615d2530bc16"
|
||||
dependencies = [
|
||||
"atomic-waker",
|
||||
"bytes",
|
||||
"fnv",
|
||||
"futures-core",
|
||||
"futures-sink",
|
||||
"http",
|
||||
"indexmap 2.14.0",
|
||||
"slab",
|
||||
"tokio",
|
||||
"tokio-util",
|
||||
"tracing",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "hashbrown"
|
||||
version = "0.12.3"
|
||||
@@ -1298,6 +1407,7 @@ dependencies = [
|
||||
"bytes",
|
||||
"futures-channel",
|
||||
"futures-core",
|
||||
"h2",
|
||||
"http",
|
||||
"http-body",
|
||||
"httparse",
|
||||
@@ -1321,6 +1431,7 @@ dependencies = [
|
||||
"tokio",
|
||||
"tokio-rustls",
|
||||
"tower-service",
|
||||
"webpki-roots 1.0.9",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
@@ -1341,9 +1452,11 @@ dependencies = [
|
||||
"percent-encoding",
|
||||
"pin-project-lite",
|
||||
"socket2",
|
||||
"system-configuration",
|
||||
"tokio",
|
||||
"tower-service",
|
||||
"tracing",
|
||||
"windows-registry",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
@@ -1744,6 +1857,12 @@ version = "0.8.2"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "92daf443525c4cce67b150400bc2316076100ce0b3686209eb8cf3c31612e6f0"
|
||||
|
||||
[[package]]
|
||||
name = "litrs"
|
||||
version = "1.0.0"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "11d3d7f243d5c5a8b9bb5d6dd2b1602c0cb0b9db1621bafc7ed66e35ff9fe092"
|
||||
|
||||
[[package]]
|
||||
name = "lock_api"
|
||||
version = "0.4.14"
|
||||
@@ -1759,6 +1878,12 @@ version = "0.4.33"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "0ceec5bc11778974d1bcb055b18002eba7f4b3518b6a0081b3af5f21666da9ad"
|
||||
|
||||
[[package]]
|
||||
name = "lru-slab"
|
||||
version = "0.1.2"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "112b39cec0b298b6c1999fee3e31427f74f676e4cb9879ed1a121b43661a4154"
|
||||
|
||||
[[package]]
|
||||
name = "markup5ever"
|
||||
version = "0.38.0"
|
||||
@@ -2178,8 +2303,11 @@ dependencies = [
|
||||
"serde_json",
|
||||
"tauri",
|
||||
"tauri-build",
|
||||
"tauri-plugin-http",
|
||||
"tauri-plugin-process",
|
||||
"tauri-plugin-store",
|
||||
"tauri-plugin-updater",
|
||||
"tauri-plugin-websocket",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
@@ -2330,6 +2458,15 @@ version = "0.2.0"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "439ee305def115ba05938db6eb1644ff94165c5ab5e9420d1c1bcedbba909391"
|
||||
|
||||
[[package]]
|
||||
name = "ppv-lite86"
|
||||
version = "0.2.21"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "85eae3c4ed2f50dcfe72643da4befc30deadb458a9b590d720cde2f2b1e97da9"
|
||||
dependencies = [
|
||||
"zerocopy",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "precomputed-hash"
|
||||
version = "0.1.1"
|
||||
@@ -2398,6 +2535,22 @@ dependencies = [
|
||||
"unicode-ident",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "psl-types"
|
||||
version = "2.0.11"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "33cb294fe86a74cbcf50d4445b37da762029549ebeea341421c7c70370f86cac"
|
||||
|
||||
[[package]]
|
||||
name = "publicsuffix"
|
||||
version = "2.3.0"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "6f42ea446cab60335f76979ec15e12619a2165b5ae2c12166bef27d283a9fadf"
|
||||
dependencies = [
|
||||
"idna",
|
||||
"psl-types",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "quick-xml"
|
||||
version = "0.39.4"
|
||||
@@ -2407,6 +2560,62 @@ dependencies = [
|
||||
"memchr",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "quinn"
|
||||
version = "0.11.11"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "0c1a41e437b6bbd489372cd4971de128e85c855f56c57f283d20ff016cf7c0a8"
|
||||
dependencies = [
|
||||
"bytes",
|
||||
"cfg_aliases",
|
||||
"pin-project-lite",
|
||||
"quinn-proto",
|
||||
"quinn-udp",
|
||||
"rustc-hash",
|
||||
"rustls",
|
||||
"socket2",
|
||||
"thiserror 2.0.18",
|
||||
"tokio",
|
||||
"tracing",
|
||||
"web-time",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "quinn-proto"
|
||||
version = "0.11.17"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "04759210543be93709136e28212294a659ef5001836ff4eab4d663e4529bba83"
|
||||
dependencies = [
|
||||
"bytes",
|
||||
"getrandom 0.4.3",
|
||||
"lru-slab",
|
||||
"rand 0.10.2",
|
||||
"rand_pcg",
|
||||
"ring",
|
||||
"rustc-hash",
|
||||
"rustls",
|
||||
"rustls-pki-types",
|
||||
"slab",
|
||||
"thiserror 2.0.18",
|
||||
"tinyvec",
|
||||
"tracing",
|
||||
"web-time",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "quinn-udp"
|
||||
version = "0.5.15"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "35a133f956daabe89a61a685c2649f13d82d5aa4bd5d12d1277e1072a21c0694"
|
||||
dependencies = [
|
||||
"cfg_aliases",
|
||||
"libc",
|
||||
"once_cell",
|
||||
"socket2",
|
||||
"tracing",
|
||||
"windows-sys 0.61.2",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "quote"
|
||||
version = "1.0.45"
|
||||
@@ -2428,6 +2637,61 @@ version = "6.0.0"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "f8dcc9c7d52a811697d2151c701e0d08956f92b0e24136cf4cf27b57a6a0d9bf"
|
||||
|
||||
[[package]]
|
||||
name = "rand"
|
||||
version = "0.9.5"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "b9ef1d0d795eb7d84685bca4f72f3649f064e6641543d3a8c415898726a57b41"
|
||||
dependencies = [
|
||||
"rand_chacha",
|
||||
"rand_core 0.9.5",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "rand"
|
||||
version = "0.10.2"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "c7f5fa3a058cd35567ef9bfa5e75732bee0f9e4c55fa90477bef2dfcdbc4be80"
|
||||
dependencies = [
|
||||
"chacha20",
|
||||
"getrandom 0.4.3",
|
||||
"rand_core 0.10.1",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "rand_chacha"
|
||||
version = "0.9.0"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "d3022b5f1df60f26e1ffddd6c66e8aa15de382ae63b3a0c1bfc0e4d3e3f325cb"
|
||||
dependencies = [
|
||||
"ppv-lite86",
|
||||
"rand_core 0.9.5",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "rand_core"
|
||||
version = "0.9.5"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "76afc826de14238e6e8c374ddcc1fa19e374fd8dd986b0d2af0d02377261d83c"
|
||||
dependencies = [
|
||||
"getrandom 0.3.4",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "rand_core"
|
||||
version = "0.10.1"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "63b8176103e19a2643978565ca18b50549f6101881c443590420e4dc998a3c69"
|
||||
|
||||
[[package]]
|
||||
name = "rand_pcg"
|
||||
version = "0.10.2"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "caa0f4137e1c0a72f4c651489402276c8e8e1cf081f3b0ba156d2cbeef09e86a"
|
||||
dependencies = [
|
||||
"rand_core 0.10.1",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "raw-window-handle"
|
||||
version = "0.6.2"
|
||||
@@ -2503,6 +2767,49 @@ version = "0.8.11"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "d6f6ff9a378485b298a5286656da665ba74413d36db0979633275d2e708145d4"
|
||||
|
||||
[[package]]
|
||||
name = "reqwest"
|
||||
version = "0.12.28"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "eddd3ca559203180a307f12d114c268abf583f59b03cb906fd0b3ff8646c1147"
|
||||
dependencies = [
|
||||
"base64 0.22.1",
|
||||
"bytes",
|
||||
"cookie",
|
||||
"cookie_store",
|
||||
"encoding_rs",
|
||||
"futures-core",
|
||||
"h2",
|
||||
"http",
|
||||
"http-body",
|
||||
"http-body-util",
|
||||
"hyper",
|
||||
"hyper-rustls",
|
||||
"hyper-util",
|
||||
"js-sys",
|
||||
"log",
|
||||
"mime",
|
||||
"percent-encoding",
|
||||
"pin-project-lite",
|
||||
"quinn",
|
||||
"rustls",
|
||||
"rustls-pki-types",
|
||||
"serde",
|
||||
"serde_json",
|
||||
"serde_urlencoded",
|
||||
"sync_wrapper",
|
||||
"tokio",
|
||||
"tokio-rustls",
|
||||
"tower",
|
||||
"tower-http",
|
||||
"tower-service",
|
||||
"url",
|
||||
"wasm-bindgen",
|
||||
"wasm-bindgen-futures",
|
||||
"web-sys",
|
||||
"webpki-roots 1.0.9",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "reqwest"
|
||||
version = "0.13.4"
|
||||
@@ -2616,6 +2923,7 @@ version = "1.14.1"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "30a7197ae7eb376e574fe940d068c30fe0462554a3ddbe4eca7838e049c937a9"
|
||||
dependencies = [
|
||||
"web-time",
|
||||
"zeroize",
|
||||
]
|
||||
|
||||
@@ -2625,7 +2933,7 @@ version = "0.7.0"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "26d1e2536ce4f35f4846aa13bff16bd0ff40157cdb14cc056c7b14ba41233ba0"
|
||||
dependencies = [
|
||||
"core-foundation",
|
||||
"core-foundation 0.10.1",
|
||||
"core-foundation-sys",
|
||||
"jni 0.22.4",
|
||||
"log",
|
||||
@@ -2663,6 +2971,12 @@ version = "1.0.22"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "b39cdef0fa800fc44525c84ccb54a029961a8215f9619753635a9c0d2538d46d"
|
||||
|
||||
[[package]]
|
||||
name = "ryu"
|
||||
version = "1.0.23"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "9774ba4a74de5f7b1c1451ed6cd5285a32eddb5cccb8cc655a4e50009e06477f"
|
||||
|
||||
[[package]]
|
||||
name = "same-file"
|
||||
version = "1.0.6"
|
||||
@@ -2745,7 +3059,7 @@ source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "b7f4bc775c73d9a02cde8bf7b2ec4c9d12743edf609006c7facc23998404cd1d"
|
||||
dependencies = [
|
||||
"bitflags 2.13.0",
|
||||
"core-foundation",
|
||||
"core-foundation 0.10.1",
|
||||
"core-foundation-sys",
|
||||
"libc",
|
||||
"security-framework-sys",
|
||||
@@ -2885,6 +3199,18 @@ dependencies = [
|
||||
"serde_core",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "serde_urlencoded"
|
||||
version = "0.7.1"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "d3491c14715ca2294c4d6a88f15e84739788c1d030eed8c110436aafdaa2f3fd"
|
||||
dependencies = [
|
||||
"form_urlencoded",
|
||||
"itoa",
|
||||
"ryu",
|
||||
"serde",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "serde_with"
|
||||
version = "3.21.0"
|
||||
@@ -2948,6 +3274,17 @@ dependencies = [
|
||||
"stable_deref_trait",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "sha1"
|
||||
version = "0.10.7"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "a978451301f4db1d02937a4ab3ccce137717b81826e79b7d49ffe3244a13c3b8"
|
||||
dependencies = [
|
||||
"cfg-if",
|
||||
"cpufeatures 0.2.17",
|
||||
"digest",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "sha2"
|
||||
version = "0.10.9"
|
||||
@@ -2955,7 +3292,7 @@ source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "a7507d819769d01a365ab707794a4084392c824f54a7a6a7862f8c3d0892b283"
|
||||
dependencies = [
|
||||
"cfg-if",
|
||||
"cpufeatures",
|
||||
"cpufeatures 0.2.17",
|
||||
"digest",
|
||||
]
|
||||
|
||||
@@ -3137,6 +3474,17 @@ dependencies = [
|
||||
"unicode-ident",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "syn"
|
||||
version = "3.0.4"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "e6275cddf4610d1775e6d1fe9469b2e77d0f39fd98fb7450901b821e0c53649f"
|
||||
dependencies = [
|
||||
"proc-macro2",
|
||||
"quote",
|
||||
"unicode-ident",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "sync_wrapper"
|
||||
version = "1.0.2"
|
||||
@@ -3157,6 +3505,27 @@ dependencies = [
|
||||
"syn 2.0.118",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "system-configuration"
|
||||
version = "0.7.0"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "a13f3d0daba03132c0aa9767f98351b3488edc2c100cda2d2ec2b04f3d8d3c8b"
|
||||
dependencies = [
|
||||
"bitflags 2.13.0",
|
||||
"core-foundation 0.9.4",
|
||||
"system-configuration-sys",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "system-configuration-sys"
|
||||
version = "0.6.0"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "8e1d1b10ced5ca923a1fcb8d03e96b8d3268065d724548c0211415ff6ac6bac4"
|
||||
dependencies = [
|
||||
"core-foundation-sys",
|
||||
"libc",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "system-deps"
|
||||
version = "6.2.2"
|
||||
@@ -3178,7 +3547,7 @@ checksum = "d1c93047acf68669466a34690ac58cca7010bd1b201e1ec86f1fd0a75d3dd4a9"
|
||||
dependencies = [
|
||||
"bitflags 2.13.0",
|
||||
"block2",
|
||||
"core-foundation",
|
||||
"core-foundation 0.10.1",
|
||||
"core-graphics",
|
||||
"crossbeam-channel",
|
||||
"dbus",
|
||||
@@ -3268,7 +3637,7 @@ dependencies = [
|
||||
"percent-encoding",
|
||||
"plist",
|
||||
"raw-window-handle",
|
||||
"reqwest",
|
||||
"reqwest 0.13.4",
|
||||
"serde",
|
||||
"serde_json",
|
||||
"serde_repr",
|
||||
@@ -3367,6 +3736,54 @@ dependencies = [
|
||||
"walkdir",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "tauri-plugin-fs"
|
||||
version = "2.5.2"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "de22eef34fd78c0da050e748710edd50bf127e651d02ea1b2bfada1523cc5c51"
|
||||
dependencies = [
|
||||
"anyhow",
|
||||
"dunce",
|
||||
"glob",
|
||||
"log",
|
||||
"objc2-foundation",
|
||||
"percent-encoding",
|
||||
"schemars 0.8.22",
|
||||
"serde",
|
||||
"serde_json",
|
||||
"serde_repr",
|
||||
"tauri",
|
||||
"tauri-plugin",
|
||||
"tauri-utils",
|
||||
"thiserror 2.0.18",
|
||||
"toml 1.1.2+spec-1.1.0",
|
||||
"url",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "tauri-plugin-http"
|
||||
version = "2.6.0"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "7241a0c762649be8fba7dd4cc84684d0e409f26b335a978ef4dd5fe78da74ce6"
|
||||
dependencies = [
|
||||
"bytes",
|
||||
"cookie_store",
|
||||
"data-url",
|
||||
"http",
|
||||
"regex",
|
||||
"reqwest 0.12.28",
|
||||
"schemars 0.8.22",
|
||||
"serde",
|
||||
"serde_json",
|
||||
"tauri",
|
||||
"tauri-plugin",
|
||||
"tauri-plugin-fs",
|
||||
"thiserror 2.0.18",
|
||||
"tokio",
|
||||
"url",
|
||||
"urlpattern",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "tauri-plugin-process"
|
||||
version = "2.3.1"
|
||||
@@ -3377,6 +3794,22 @@ dependencies = [
|
||||
"tauri-plugin",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "tauri-plugin-store"
|
||||
version = "2.4.4"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "6708afbe549f176b712066e71648ba8fafba20789453718260c7ca356733cb0c"
|
||||
dependencies = [
|
||||
"dunce",
|
||||
"serde",
|
||||
"serde_json",
|
||||
"tauri",
|
||||
"tauri-plugin",
|
||||
"thiserror 2.0.18",
|
||||
"tokio",
|
||||
"tracing",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "tauri-plugin-updater"
|
||||
version = "2.10.1"
|
||||
@@ -3393,7 +3826,7 @@ dependencies = [
|
||||
"minisign-verify",
|
||||
"osakit",
|
||||
"percent-encoding",
|
||||
"reqwest",
|
||||
"reqwest 0.13.4",
|
||||
"rustls",
|
||||
"semver",
|
||||
"serde",
|
||||
@@ -3410,6 +3843,26 @@ dependencies = [
|
||||
"zip",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "tauri-plugin-websocket"
|
||||
version = "2.4.3"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "5ca243c7f0bf935cd81123e07f82188ccb919b19fbfc74518b947eedc4619bbb"
|
||||
dependencies = [
|
||||
"futures-util",
|
||||
"http",
|
||||
"log",
|
||||
"rand 0.9.5",
|
||||
"rustls",
|
||||
"serde",
|
||||
"serde_json",
|
||||
"tauri",
|
||||
"tauri-plugin",
|
||||
"thiserror 2.0.18",
|
||||
"tokio",
|
||||
"tokio-tungstenite",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "tauri-runtime"
|
||||
version = "2.11.3"
|
||||
@@ -3639,9 +4092,21 @@ dependencies = [
|
||||
"mio",
|
||||
"pin-project-lite",
|
||||
"socket2",
|
||||
"tokio-macros",
|
||||
"windows-sys 0.61.2",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "tokio-macros"
|
||||
version = "2.7.2"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "78773a2a397f451582ce068015985c33193cf6dea8b74d2a639fe457b2f07b0e"
|
||||
dependencies = [
|
||||
"proc-macro2",
|
||||
"quote",
|
||||
"syn 3.0.4",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "tokio-rustls"
|
||||
version = "0.26.4"
|
||||
@@ -3652,6 +4117,22 @@ dependencies = [
|
||||
"tokio",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "tokio-tungstenite"
|
||||
version = "0.29.0"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "8f72a05e828585856dacd553fba484c242c46e391fb0e58917c942ee9202915c"
|
||||
dependencies = [
|
||||
"futures-util",
|
||||
"log",
|
||||
"rustls",
|
||||
"rustls-pki-types",
|
||||
"tokio",
|
||||
"tokio-rustls",
|
||||
"tungstenite",
|
||||
"webpki-roots 0.26.11",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "tokio-util"
|
||||
version = "0.7.18"
|
||||
@@ -3837,9 +4318,21 @@ source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "63e71662fa4b2a2c3a26f570f037eb95bb1f85397f3cd8076caed2f026a6d100"
|
||||
dependencies = [
|
||||
"pin-project-lite",
|
||||
"tracing-attributes",
|
||||
"tracing-core",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "tracing-attributes"
|
||||
version = "0.1.31"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "7490cfa5ec963746568740651ac6781f701c9c5ea257c58e057f3ba8cf69e8da"
|
||||
dependencies = [
|
||||
"proc-macro2",
|
||||
"quote",
|
||||
"syn 2.0.118",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "tracing-core"
|
||||
version = "0.1.36"
|
||||
@@ -3877,6 +4370,24 @@ version = "0.2.5"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "e421abadd41a4225275504ea4d6566923418b7f05506fbc9c0fe86ba7396114b"
|
||||
|
||||
[[package]]
|
||||
name = "tungstenite"
|
||||
version = "0.29.0"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "6c01152af293afb9c7c2a57e4b559c5620b421f6d133261c60dd2d0cdb38e6b8"
|
||||
dependencies = [
|
||||
"bytes",
|
||||
"data-encoding",
|
||||
"http",
|
||||
"httparse",
|
||||
"log",
|
||||
"rand 0.9.5",
|
||||
"rustls",
|
||||
"rustls-pki-types",
|
||||
"sha1",
|
||||
"thiserror 2.0.18",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "typeid"
|
||||
version = "1.0.3"
|
||||
@@ -4141,6 +4652,16 @@ dependencies = [
|
||||
"wasm-bindgen",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "web-time"
|
||||
version = "1.1.0"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "5a6580f308b1fad9207618087a65c04e7a10bc77e02c8e84e9b00dd4b12fa0bb"
|
||||
dependencies = [
|
||||
"js-sys",
|
||||
"wasm-bindgen",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "web_atoms"
|
||||
version = "0.2.5"
|
||||
@@ -4206,6 +4727,24 @@ dependencies = [
|
||||
"rustls-pki-types",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "webpki-roots"
|
||||
version = "0.26.11"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "521bc38abb08001b01866da9f51eb7c5d647a19260e00054a8c7fd5f9e57f7a9"
|
||||
dependencies = [
|
||||
"webpki-roots 1.0.9",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "webpki-roots"
|
||||
version = "1.0.9"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "7dcd9d09a39985f5344844e66b0c530a33843579125f23e21e9f0f220850f22a"
|
||||
dependencies = [
|
||||
"rustls-pki-types",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "webview2-com"
|
||||
version = "0.38.2"
|
||||
@@ -4391,6 +4930,17 @@ dependencies = [
|
||||
"windows-link 0.1.3",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "windows-registry"
|
||||
version = "0.6.1"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "02752bf7fbdcce7f2a27a742f798510f3e5ad88dbe84871e5168e2120c3d5720"
|
||||
dependencies = [
|
||||
"windows-link 0.2.1",
|
||||
"windows-result 0.4.1",
|
||||
"windows-strings 0.5.1",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "windows-result"
|
||||
version = "0.3.4"
|
||||
@@ -4820,6 +5370,26 @@ dependencies = [
|
||||
"synstructure",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "zerocopy"
|
||||
version = "0.8.56"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "556764e583adb45a9f8d413c2a147fa7e8d821e48e12b14fd560b607998b75eb"
|
||||
dependencies = [
|
||||
"zerocopy-derive",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "zerocopy-derive"
|
||||
version = "0.8.56"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "f2ab42fc20575779bd240faa45f94a74256f755c0fa9e89f0ede20d91d0cdfc1"
|
||||
dependencies = [
|
||||
"proc-macro2",
|
||||
"quote",
|
||||
"syn 2.0.118",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "zerofrom"
|
||||
version = "0.1.8"
|
||||
|
||||
@@ -22,6 +22,21 @@ serde_json = "1"
|
||||
# Auto-update: prompt the operator, download a signed update, relaunch.
|
||||
tauri-plugin-updater = "2"
|
||||
tauri-plugin-process = "2"
|
||||
# HTTP client for the SPA's API/WS calls to the local Fastify server. The window
|
||||
# runs at tauri://localhost, which WebKitGTK treats as a secure origin — a plain
|
||||
# http://127.0.0.1:3000 fetch() from inside it is blocked as mixed content (a
|
||||
# long-standing WebKit limitation, not fixable via CSP). Routing through this
|
||||
# plugin sends the request via Tauri's Rust side instead of the webview's own
|
||||
# fetch, sidestepping the browser mixed-content check entirely.
|
||||
tauri-plugin-http = "2"
|
||||
# Same mixed-content problem as above, but for the live-feed WebSocket
|
||||
# (ws://127.0.0.1:3000 from the secure tauri://localhost origin) — HTTP and WS
|
||||
# are separate browser checks, so this needs its own plugin.
|
||||
tauri-plugin-websocket = "2"
|
||||
# Persists the operator-configured backend URL (host:port of the Fastify
|
||||
# server this install talks to) across restarts. Read before any API call —
|
||||
# see apps/web/src/lib/backend-config.ts.
|
||||
tauri-plugin-store = "2"
|
||||
|
||||
[features]
|
||||
# Used by `tauri dev`/CLI for hot-reload of the Rust side.
|
||||
|
||||
@@ -6,6 +6,18 @@
|
||||
"permissions": [
|
||||
"core:default",
|
||||
"updater:default",
|
||||
"process:default"
|
||||
"process:default",
|
||||
"websocket:default",
|
||||
"store:default",
|
||||
{
|
||||
"identifier": "http:default",
|
||||
"//": "Backend address is operator-configured at runtime (backend-config.ts) so the exact host:port can't be allow-listed at build time. Wildcarded to any host — the CSP forces ALL backend traffic through this plugin (see tauri.conf.json), so this scope is the real boundary; a compromised/malicious page still can't reach anything the operator hasn't pointed the app at, since the app only ever calls the one configured origin. All 4 forms needed: a known Tauri scope-matching quirk drops http://*:PORT unless both bare and :* variants are listed.",
|
||||
"allow": [
|
||||
{ "url": "http://*" },
|
||||
{ "url": "https://*" },
|
||||
{ "url": "http://*:*" },
|
||||
{ "url": "https://*:*" }
|
||||
]
|
||||
}
|
||||
]
|
||||
}
|
||||
|
||||
@@ -3,9 +3,10 @@
|
||||
// Intentionally minimal: build the default Tauri app and run it. The window
|
||||
// config (kiosk, fullscreen, which URL/assets to load) lives in tauri.conf.json.
|
||||
// No custom commands are registered — the renderer (the @parking/web SPA) reaches
|
||||
// the backend over HTTP to the local Fastify server, NOT through Tauri IPC. This
|
||||
// keeps the shell a thin presentation wrapper with a deny-by-default native
|
||||
// surface (see wiki/decisions/desktop-shell-tauri.md).
|
||||
// the backend over HTTP to a Fastify server (address operator-configured at
|
||||
// runtime, not baked in — see apps/web/src/lib/backend-config.ts), NOT through
|
||||
// Tauri IPC. This keeps the shell a thin presentation wrapper with a
|
||||
// deny-by-default native surface (see wiki/decisions/desktop-shell-tauri.md).
|
||||
|
||||
#[cfg_attr(mobile, tauri::mobile_entry_point)]
|
||||
pub fn run() {
|
||||
@@ -16,6 +17,16 @@ pub fn run() {
|
||||
// endpoint + signing pubkey live in tauri.conf.json.
|
||||
.plugin(tauri_plugin_updater::Builder::new().build())
|
||||
.plugin(tauri_plugin_process::init())
|
||||
// Routes the SPA's fetch()/WS calls to the operator-configured Fastify
|
||||
// server through Tauri's native HTTP client — see the Cargo.toml
|
||||
// comment on why the webview's own fetch() can't reach it directly.
|
||||
.plugin(tauri_plugin_http::init())
|
||||
// Live-feed WebSocket — same mixed-content reason as the HTTP plugin
|
||||
// above, but WS needs its own plugin (separate browser check).
|
||||
.plugin(tauri_plugin_websocket::init())
|
||||
// Persists the operator-configured backend URL across restarts (JSON
|
||||
// file in the app's config dir) — see backend-config.ts.
|
||||
.plugin(tauri_plugin_store::Builder::new().build())
|
||||
.run(tauri::generate_context!())
|
||||
.expect("error while running the Parking System desktop shell");
|
||||
}
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"$schema": "https://schema.tauri.app/config/2",
|
||||
"productName": "Parking System",
|
||||
"version": "0.0.0",
|
||||
"version": "0.2.0",
|
||||
"identifier": "com.parking.desktop",
|
||||
"build": {
|
||||
"devUrl": "http://localhost:5173",
|
||||
@@ -24,7 +24,7 @@
|
||||
}
|
||||
],
|
||||
"security": {
|
||||
"csp": "default-src 'self'; img-src 'self' data: blob:; style-src 'self' 'unsafe-inline'; connect-src 'self' http://127.0.0.1:3000 http://localhost:3000 ws://127.0.0.1:3000 ws://localhost:3000"
|
||||
"csp": "default-src 'self'; img-src 'self' data: blob:; style-src 'self' 'unsafe-inline'; connect-src 'self'"
|
||||
}
|
||||
},
|
||||
"bundle": {
|
||||
@@ -41,8 +41,9 @@
|
||||
},
|
||||
"plugins": {
|
||||
"updater": {
|
||||
"//": "Points at mca/public_releases, NOT this (private, source) repo — the updater runs on offline-first field appliances with no Gitea credentials, so the endpoint must be reachable unauthenticated. That repo is public and holds only compiled installers (no source), mirrored here by .gitea/workflows/release.yml. NOT the 'latest release' redirect: public_releases is shared across apps in the org, so 'latest' there could be someone else's release. This URL names our own most-recent tag directly (desktop-vX.Y.Z, bumped by the release workflow each publish) so a newer unrelated app release never shadows ours. The updater GETs this, gets the manifest (platforms.linux-x86_64.{signature,url}), and compares versions. The release is reachable to the appliance only when it's brought online (phone hotspot); offline-first means a failed check is a no-op.",
|
||||
"endpoints": [
|
||||
"https://UPDATES.EXAMPLE.invalid/parking/{{target}}/{{arch}}/{{current_version}}"
|
||||
"https://git.infra.msai.al/mca/public_releases/releases/download/desktop-latest/latest.json"
|
||||
],
|
||||
"pubkey": "dW50cnVzdGVkIGNvbW1lbnQ6IG1pbmlzaWduIHB1YmxpYyBrZXk6IDgxNzg5RUQ1QkM0Q0FDRjYKUldUMnJFeTgxWjU0Z1RlNmhneDVZQlVVTVZZdGhJTkUxTGdDeGYwQSttZmNKVVp5WEdVMWlBb1YK"
|
||||
}
|
||||
|
||||
@@ -15,12 +15,37 @@ JWT_SECRET=
|
||||
# them (keyId), so verifyChain still validates a chain that spans a key change.
|
||||
EVENT_SIGNING_KEY=
|
||||
|
||||
# On-site encrypted DB backup (durability for the signed ledger). A daily timer + an admin
|
||||
# "back up now" button write a consistent, AES-256-GCM-encrypted copy to the target. The
|
||||
# TARGET DIRECTORY is chosen by the admin in the UI (Setup → Backup) and stored in the DB —
|
||||
# NOT here. Only the encryption KEY is an env secret. RESTORE is an out-of-band runbook action,
|
||||
# not a console call. See wiki/concepts/backup-recovery.md.
|
||||
#
|
||||
# Dedicated backup-encryption key (>=16 chars), SEPARATE from EVENT_SIGNING_KEY so it can
|
||||
# rotate without fracturing the signed chain. Generate with: openssl rand -hex 32
|
||||
# Escrow it offsite (alongside EVENT_SIGNING_KEY) — recovery needs both, and neither is ever
|
||||
# stored inside the backup it unlocks. Backups stay a no-op until BOTH this key and an in-UI
|
||||
# target directory are set. The target directory AND retention (keep-last / keep-daily) are
|
||||
# admin-chosen in the UI (Setup → Backup), NOT env — only this key is an env secret.
|
||||
# BACKUP_KEY=
|
||||
|
||||
# Optional ----------------------------------------------------------------
|
||||
# PORT=3000
|
||||
# HOST=0.0.0.0 # interface to bind. 127.0.0.1 = loopback only.
|
||||
# LOG_LEVEL=info
|
||||
# DATABASE_URL=./parking.sqlite
|
||||
# NODE_ENV=production # set in prod: makes auth cookies Secure (HTTPS-only)
|
||||
#
|
||||
# Auth-cookie Secure flag. FAIL-SAFE: cookies are Secure (HTTPS-only) BY DEFAULT —
|
||||
# you only ever opt OUT, never in. Set COOKIE_SECURE=0 for a plain-HTTP deployment
|
||||
# (e.g. the LAN appliance serving the SPA same-origin over http, where a Secure
|
||||
# cookie would never be sent and would lock operators out). Local dev over
|
||||
# http://localhost MUST set this (the dev .env does). Leave unset in any TLS deploy.
|
||||
# COOKIE_SECURE=0
|
||||
|
||||
# Recycle bin retention: a soft-deleted user/role/subscription/plan/tariff is auto-purged
|
||||
# this many days after deletion (a 6-hourly sweep). Default 30. Set 0 to keep deleted
|
||||
# items forever (manual purge only). See wiki/concepts/soft-delete.md.
|
||||
# RECYCLE_BIN_RETENTION_DAYS=30
|
||||
|
||||
# First admin (seed once): pnpm --filter @parking/server seed-admin
|
||||
# ADMIN_USER=admin
|
||||
@@ -28,7 +53,13 @@ EVENT_SIGNING_KEY=
|
||||
|
||||
# Comma-separated extra origins allowed to open the booth WebSocket (/api/ws).
|
||||
# In dev, set the Vite SPA origin. Same-origin is always allowed without this.
|
||||
WS_ALLOWED_ORIGINS=http://localhost:5173
|
||||
# The Tauri DESKTOP shell loads from tauri://localhost (Linux may also send
|
||||
# http://tauri.localhost), which is NOT same-origin with the backend — add both
|
||||
# so the desktop app's live feed connects. See apps/desktop.
|
||||
# To open the dev SPA from another LAN device (phone over wifi), Vite must bind
|
||||
# 0.0.0.0 (vite.config.ts) AND the host's LAN origin must be listed here, e.g.
|
||||
# http://10.0.10.203:5173 — the WS handshake's Origin is that LAN address.
|
||||
WS_ALLOWED_ORIGINS=http://localhost:5173,tauri://localhost,http://tauri.localhost
|
||||
|
||||
# Vision / ANPR (optional) -------------------------------------------------
|
||||
# OFF by default. The Node SERVER's view of the vision microservice (apps/vision),
|
||||
@@ -39,4 +70,37 @@ WS_ALLOWED_ORIGINS=http://localhost:5173
|
||||
# VISION_ENABLED=1 # master switch — nothing runs without it
|
||||
# VISION_URL=http://127.0.0.1:8089 # must match apps/vision VISION_HOST:VISION_PORT
|
||||
# VISION_TIMEOUT_MS=1500 # per-request cap so a slow call can't hang the lane
|
||||
# VISION_MIN_CONFIDENCE=0.5 # confidence floor; keep in sync with the service
|
||||
# VISION_MIN_CONFIDENCE=0.5 # advisory confidence floor; keep in sync with the service
|
||||
#
|
||||
# ANPR subscriber-entry bridge (anpr-entry.ts): a subscriber's plate, read off a lane
|
||||
# camera's vehicle detection, admits them through the gated SubscriptionFlow. Opt-in per
|
||||
# camera (the camera's config.anpr checkbox in Setup); the camera must be BOUND to a relay.
|
||||
# VISION_ENTRY_MIN_CONFIDENCE=0.85 # stricter floor for a BARRIER-driving read (near-miss → falls back to card/QR)
|
||||
# ANPR_DEBOUNCE_MS=12000 # same plate/camera within this window = ONE presentation (camera re-fires ~1Hz)
|
||||
|
||||
# Venue modules --------------------------------------------------------------
|
||||
# Comma-separated ids of the modules this site is ENTITLED to (a vendor/deployment
|
||||
# decision — set in the Komodo stack env, never by a site role). The site admin then
|
||||
# ACTIVATES within this set in Setup → Site; effective = entitled ∩ activated. Unset or
|
||||
# blank = every registered module (parking,validation,carwash) — a DEV convenience. In
|
||||
# Docker, docker-compose.yml forwards it with a default of parking,validation, so a booth
|
||||
# is never entitled to a module its Komodo stack env does not name. Required modules
|
||||
# (parking) are always on. See wiki/decisions/venue-modules.md.
|
||||
#MODULES_ENTITLED=parking,validation
|
||||
|
||||
# Car Wash review outbox (wiki/concepts/vision-review-outbox.md) -------------------------
|
||||
# The operator's category choice is a hypothesis: each wash order with a vehicle read queues
|
||||
# the vehicle CROP (plate blurred) + the choice for a trusted remote reviewer, drained one-way
|
||||
# over the private overlay (Netbird). All three or off. URL = the collector's ingest endpoint
|
||||
# (reachable only over the overlay); TOKEN = this booth's own bearer token; BOOTH_ID = a
|
||||
# pseudonymous label the reviewer maps to a site (NEVER the site name — it travels with every
|
||||
# item). Set in the Komodo stack env, per booth. Nothing is queued while off.
|
||||
# CARWASH_REVIEW_URL=
|
||||
# CARWASH_REVIEW_TOKEN=
|
||||
# CARWASH_REVIEW_BOOTH_ID=
|
||||
# CARWASH_REVIEW_INTERVAL_SEC=60
|
||||
# Entry-stream sampling: also queue one in N ENTRY vehicle reads (no wash, no operator) as
|
||||
# pure training material in the gate view — many times the wash stream, zero domain shift.
|
||||
# 1 = every entry (the reviewer labels what they have time for; the rest waits and stays
|
||||
# useful), N = one in N, 0/unset = off. Needs the three settings above.
|
||||
# CARWASH_REVIEW_ENTRY_SAMPLE=1
|
||||
|
||||
@@ -0,0 +1,84 @@
|
||||
# syntax=docker/dockerfile:1.7
|
||||
# Parking SERVER image: Fastify API + the bundled React SPA (one container serves both —
|
||||
# offline-first single appliance). Build CONTEXT is the REPO ROOT (it's a pnpm/turbo
|
||||
# monorepo). better-sqlite3 is a native module → build stage needs node-gyp toolchain,
|
||||
# runtime needs libstdc++. Mirrors the house multi-stage pattern (cf. trm/processor).
|
||||
# See wiki/decisions/container-deployment.md.
|
||||
|
||||
# ---- deps: cache-friendly pnpm fetch (only manifests change the layer) ----
|
||||
FROM node:22-alpine AS deps
|
||||
WORKDIR /app
|
||||
RUN apk add --no-cache python3 make g++ # node-gyp for better-sqlite3
|
||||
RUN corepack enable && corepack prepare pnpm@10.24.0 --activate
|
||||
# Workspace manifests + lock first, so the fetch layer caches across source edits.
|
||||
COPY package.json pnpm-lock.yaml pnpm-workspace.yaml turbo.json ./
|
||||
COPY apps/server/package.json apps/server/
|
||||
COPY apps/web/package.json apps/web/
|
||||
COPY apps/vision/package.json apps/vision/
|
||||
COPY apps/collector/package.json apps/collector/
|
||||
COPY packages/db/package.json packages/db/
|
||||
COPY packages/devices/package.json packages/devices/
|
||||
COPY packages/shared/package.json packages/shared/
|
||||
RUN --mount=type=cache,id=pnpm-store,target=/root/.local/share/pnpm/store \
|
||||
pnpm fetch
|
||||
|
||||
# ---- build: install (offline from the fetched store) + turbo build everything ----
|
||||
FROM deps AS build
|
||||
ENV CI=true
|
||||
COPY . .
|
||||
RUN --mount=type=cache,id=pnpm-store,target=/root/.local/share/pnpm/store \
|
||||
pnpm install --frozen-lockfile --offline
|
||||
# Force the SPA to use a SAME-ORIGIN (relative) API base for THIS image. Vite auto-loads
|
||||
# apps/web/.env.production, which sets VITE_API_BASE=http://127.0.0.1:3000 for the TAURI
|
||||
# DESKTOP build — but here Fastify serves the SPA same-origin, so an absolute base would
|
||||
# make the browser hit 127.0.0.1:3000 cross-origin and fail CORS. `.env.production.local`
|
||||
# has higher precedence than `.env.production`, so this empties it for the server image only.
|
||||
RUN echo 'VITE_API_BASE=' > apps/web/.env.production.local
|
||||
# Builds shared/db/devices, the server dist, AND the web SPA dist (apps/web/dist).
|
||||
RUN pnpm turbo run build --filter=@parking/server --filter=@parking/web
|
||||
# `pnpm deploy` produces a SELF-CONTAINED prod bundle for the server in /deploy: a hoisted
|
||||
# node_modules with only @parking/server's prod deps (incl. the workspace packages' built
|
||||
# dist + their native deps like better-sqlite3 — properly linked, unlike `prune` at root).
|
||||
RUN --mount=type=cache,id=pnpm-store,target=/root/.local/share/pnpm/store \
|
||||
pnpm --filter=@parking/server --legacy deploy --prod /deploy
|
||||
# The server's own dist + scripts (deploy copies the package's package.json + files, but we
|
||||
# copy dist explicitly so the layout under /deploy is predictable). The web SPA + db
|
||||
# migrations are copied in the runtime stage from their build locations.
|
||||
|
||||
# ---- runtime: slim, non-root ----
|
||||
FROM node:22-alpine AS runtime
|
||||
WORKDIR /app
|
||||
# Set by CI to "<branch>-<short-sha>" (e.g. "stage-28bd838"), matching the same string used
|
||||
# as the Komodo Stack's TAG (komodo/resources.toml) — so the version shown in the app is the
|
||||
# same string an admin would look up there. Empty/absent on a local `docker build` (dev only).
|
||||
ARG BUILD_VERSION=""
|
||||
ENV BUILD_VERSION=$BUILD_VERSION
|
||||
ENV NODE_ENV=production
|
||||
RUN apk add --no-cache libstdc++ # better-sqlite3 native runtime
|
||||
RUN addgroup -S app && adduser -S -G app app
|
||||
|
||||
# The self-contained deploy bundle: dist/ + a hoisted node_modules carrying the server's
|
||||
# prod deps AND the workspace packages (@parking/db|devices|shared) with their built dist,
|
||||
# the drizzle migrations, and the native better-sqlite3 binding. Single COPY — no scattered
|
||||
# package dirs, no root node_modules.
|
||||
COPY --from=build --chown=app:app /deploy ./
|
||||
|
||||
# The built SPA — served by Fastify static at WEB_DIST_DIR. (Not part of the server's deploy
|
||||
# bundle, so copied from the web build output.)
|
||||
COPY --from=build --chown=app:app /app/apps/web/dist ./web/dist
|
||||
|
||||
# DB lives on a mounted volume (never in the image). Default points at /data.
|
||||
ENV DATABASE_URL=/data/parking.sqlite
|
||||
ENV WEB_DIST_DIR=/app/web/dist
|
||||
ENV HOST=0.0.0.0
|
||||
ENV PORT=3000
|
||||
RUN mkdir -p /data && chown app:app /data
|
||||
VOLUME ["/data"]
|
||||
|
||||
USER app
|
||||
EXPOSE 3000
|
||||
HEALTHCHECK --interval=30s --timeout=5s --start-period=15s --retries=3 \
|
||||
CMD wget -qO- "http://localhost:${PORT:-3000}/health" >/dev/null 2>&1 || exit 1
|
||||
|
||||
ENTRYPOINT ["./docker-entrypoint.sh"]
|
||||
CMD ["node", "dist/index.js"]
|
||||
Executable
+27
@@ -0,0 +1,27 @@
|
||||
#!/bin/sh
|
||||
# Container entrypoint for the parking server. Applies DB migrations against the mounted
|
||||
# volume (DATABASE_URL), optionally seeds the first admin, then execs the server. Idempotent:
|
||||
# the runtime migrator (drizzle-orm migrator, no drizzle-kit) only applies pending migrations,
|
||||
# so a restart is a no-op. See packages/db/scripts/migrate-runtime.mjs.
|
||||
set -e
|
||||
|
||||
echo "[entrypoint] DATABASE_URL=${DATABASE_URL}"
|
||||
|
||||
# Apply migrations against the mounted DB file (creates it + the schema on first boot).
|
||||
# The migrator ships inside the @parking/db package in the deploy bundle's node_modules.
|
||||
node node_modules/@parking/db/scripts/migrate-runtime.mjs
|
||||
|
||||
# Optional first-boot admin seed: set SEED_ADMIN=1 plus ADMIN_USER + ADMIN_PASS (the seed
|
||||
# script PROMPTS when these are unset, which would hang a container — so require ADMIN_PASS).
|
||||
# The seed is idempotent: it won't overwrite an existing user unless FORCE=1.
|
||||
if [ "${SEED_ADMIN}" = "1" ]; then
|
||||
if [ -z "${ADMIN_PASS}" ]; then
|
||||
echo "[entrypoint] SEED_ADMIN=1 but ADMIN_PASS is unset — skipping seed (would hang on prompt)"
|
||||
else
|
||||
echo "[entrypoint] seeding admin (${ADMIN_USER:-admin})"
|
||||
node scripts/seed-admin.mjs || echo "[entrypoint] seed-admin skipped/failed (non-fatal)"
|
||||
fi
|
||||
fi
|
||||
|
||||
echo "[entrypoint] starting server"
|
||||
exec "$@"
|
||||
@@ -9,7 +9,8 @@
|
||||
"start": "node --env-file-if-exists=.env dist/index.js",
|
||||
"seed-admin": "node --env-file-if-exists=.env scripts/seed-admin.mjs",
|
||||
"typecheck": "tsc --noEmit",
|
||||
"lint": "tsc --noEmit"
|
||||
"lint": "tsc --noEmit",
|
||||
"test": "vitest run"
|
||||
},
|
||||
"dependencies": {
|
||||
"@fastify/cookie": "^11.0.2",
|
||||
@@ -22,12 +23,14 @@
|
||||
"@parking/shared": "workspace:*",
|
||||
"bcrypt": "6.0.0",
|
||||
"fastify": "5.8.5",
|
||||
"fastify-plugin": "6.0.0"
|
||||
"fastify-plugin": "6.0.0",
|
||||
"sharp": "^0.35.2"
|
||||
},
|
||||
"devDependencies": {
|
||||
"@types/bcrypt": "6.0.0",
|
||||
"@types/node": "25.9.3",
|
||||
"tsx": "4.22.4",
|
||||
"typescript": "6.0.3"
|
||||
"typescript": "6.0.3",
|
||||
"vitest": "^4.1.9"
|
||||
}
|
||||
}
|
||||
|
||||
@@ -16,7 +16,7 @@ import { createRequire } from "node:module";
|
||||
|
||||
const require = createRequire(import.meta.url);
|
||||
const bcrypt = require("bcrypt");
|
||||
const { createDb, users, eq } = require("@parking/db");
|
||||
const { createDb, users, roles, eq } = require("@parking/db");
|
||||
|
||||
const DEFAULT_USERNAME = "admin";
|
||||
|
||||
@@ -53,6 +53,14 @@ if (!password || password.length < 8) {
|
||||
}
|
||||
|
||||
const db = createDb();
|
||||
|
||||
// Self-heal the built-in `admin` ROLE row. Migration 0007 seeds it once, but the
|
||||
// training reset (reset-db.mjs --users/--all) wipes the roles table and points here
|
||||
// to re-seed — without this, the user insert dies on the role_id FOREIGN KEY (field
|
||||
// failure 2026-07-06). The admin permission SET is resolved in code (auth.ts), so
|
||||
// the row alone is all the FK needs.
|
||||
await db.insert(roles).values({ id: "admin", name: "Admin", builtin: 1 }).onConflictDoNothing();
|
||||
|
||||
const existing = await db.select().from(users).where(eq(users.username, username)).get();
|
||||
if (existing && process.env.FORCE !== "1") {
|
||||
console.error(`user "${username}" already exists (set FORCE=1 to reset the password)`);
|
||||
@@ -73,4 +81,30 @@ if (existing) {
|
||||
});
|
||||
console.log(`created admin "${username}"`);
|
||||
}
|
||||
|
||||
// Record the action into the SIGNED ledger (config_change). A console seed/reset is
|
||||
// a Linux-admin action the app can't gate — but it must stay ATTRIBUTABLE after the
|
||||
// fact (the chain is the audit record; whoever holds root can reset a password, they
|
||||
// can't do it silently). Uses the server's own compiled EventLog + signer from dist/
|
||||
// (present in the container; in a dev checkout run `pnpm build` first). Best-effort:
|
||||
// a missing build or signing key WARNS loudly but never blocks the seed — locking an
|
||||
// admin out to protect an audit line would invert the priority.
|
||||
try {
|
||||
const { EventLog } = await import("../dist/event-log.js");
|
||||
const { buildSigner } = await import("../dist/signer.js");
|
||||
const log = new EventLog(db, buildSigner());
|
||||
await log.append({
|
||||
type: "config_change",
|
||||
source: "manual",
|
||||
identity: `user:${username}`,
|
||||
payload: {
|
||||
setting: existing ? "admin.passwordReset" : "admin.seeded",
|
||||
username,
|
||||
operator: "console:seed-admin",
|
||||
},
|
||||
});
|
||||
console.log("recorded to the signed ledger (config_change)");
|
||||
} catch (err) {
|
||||
console.warn(`WARNING: NOT recorded to the signed ledger: ${err.message}`);
|
||||
}
|
||||
process.exit(0);
|
||||
|
||||
@@ -0,0 +1,330 @@
|
||||
import { afterEach, beforeEach, describe, expect, it, vi } from "vitest";
|
||||
import { randomUUID } from "node:crypto";
|
||||
import { devices, deviceEvents as deviceEventsTable, eq, siteConfig, type Db } from "@parking/db";
|
||||
import { createTestDb } from "@parking/db/testing";
|
||||
import { deviceEvents, type DeviceReadEvent } from "./device-events.js";
|
||||
import { silentLogger } from "./test-helpers.js";
|
||||
import type { VisionClient, VisionResult } from "./vision-client.js";
|
||||
import type { SubscriptionFlow, SubscriptionMatch } from "./subscription-flow.js";
|
||||
|
||||
// The ANPR bridge: a camera vehicle detection → (opt-in) snapshot → plate → MATCH a
|
||||
// subscriber → emit a plate read. We mock the camera build (buildCamera) so no real
|
||||
// snapshot HTTP is made, and pass fake Vision/Subscription so the test is the bridge's
|
||||
// own logic only. See anpr-entry.ts.
|
||||
|
||||
// Mock buildCamera so the bridge gets a fake camera whose captureSnapshot is a stub
|
||||
// (no registry, no network). The factory returns a fresh shot each call.
|
||||
const captureSnapshot = vi.fn(async () => ({ bytes: Buffer.from("jpg"), contentType: "image/jpeg" }));
|
||||
// The bridge now goes through captureSnapshotShared (the dedup wrapper, exercised in
|
||||
// snapshot.test.ts); here it just delegates to the fake camera's captureSnapshot so this
|
||||
// suite stays focused on the bridge's own match/debounce/emit logic.
|
||||
vi.mock("./snapshot.js", () => ({
|
||||
buildCamera: () => ({ captureSnapshot }),
|
||||
captureSnapshotShared: (_id: string, camera: { captureSnapshot: typeof captureSnapshot }, ctx: unknown) =>
|
||||
camera.captureSnapshot(ctx as never),
|
||||
}));
|
||||
|
||||
// Import AFTER the mock is registered.
|
||||
const { AnprBridge } = await import("./anpr-entry.js");
|
||||
|
||||
let db: Db;
|
||||
beforeEach(() => {
|
||||
({ db } = createTestDb());
|
||||
captureSnapshot.mockClear();
|
||||
delete process.env.VISION_ENTRY_MIN_CONFIDENCE;
|
||||
delete process.env.ANPR_DEBOUNCE_MS;
|
||||
// Poll-until-confident loop: keep the window + interval tiny so a below-floor / no-plate
|
||||
// case gives up in ~one tick instead of the 8s production window (tests stay fast). Each
|
||||
// bridge reads these in its constructor, so set them before `new AnprBridge`.
|
||||
process.env.ANPR_POLL_MS = "1";
|
||||
process.env.ANPR_POLL_WINDOW_MS = "5";
|
||||
});
|
||||
afterEach(() => {
|
||||
vi.restoreAllMocks();
|
||||
delete process.env.ANPR_POLL_MS;
|
||||
delete process.env.ANPR_POLL_WINDOW_MS;
|
||||
delete process.env.ANPR_POLL_MAX_MS;
|
||||
});
|
||||
|
||||
/** A camera bound to an entry relay; `anpr` toggles recognition, `anprAutoTrigger` the
|
||||
* per-camera auto-open gate (absent ⇒ defaults on). */
|
||||
function seedCamera(opts: { anpr?: boolean; anprAutoTrigger?: boolean } = {}): string {
|
||||
const controllerId = randomUUID();
|
||||
db.insert(devices).values({
|
||||
id: controllerId,
|
||||
category: "access",
|
||||
driverId: "dingtian",
|
||||
config: { host: "10.0.0.5", relays: [{ relay: 1, direction: "entry" }] },
|
||||
enabled: true,
|
||||
}).run();
|
||||
const camId = randomUUID();
|
||||
db.insert(devices).values({
|
||||
id: camId,
|
||||
category: "camera",
|
||||
driverId: "hikvision",
|
||||
config: {
|
||||
host: "10.0.0.9",
|
||||
controllerId,
|
||||
relay: 1,
|
||||
...(opts.anpr ? { anpr: true } : {}),
|
||||
...(opts.anprAutoTrigger === false ? { anprAutoTrigger: false } : {}),
|
||||
},
|
||||
enabled: true,
|
||||
}).run();
|
||||
return camId;
|
||||
}
|
||||
|
||||
/** A fake VisionClient: enabled, returning a chosen plate/confidence (or null). */
|
||||
function fakeVision(opts: { enabled?: boolean; plate?: string; confidence?: number } = {}): VisionClient {
|
||||
const enabled = opts.enabled ?? true;
|
||||
const result: VisionResult | null =
|
||||
opts.plate == null
|
||||
? null
|
||||
: {
|
||||
plate: { text: opts.plate, confidence: opts.confidence ?? 0.99 },
|
||||
plates: [],
|
||||
lowConfidence: false,
|
||||
vehicle: null,
|
||||
modelVersion: "test",
|
||||
tookMs: 1,
|
||||
};
|
||||
return {
|
||||
enabled,
|
||||
analyze: vi.fn(async () => (enabled ? result : null)),
|
||||
} as unknown as VisionClient;
|
||||
}
|
||||
|
||||
/** A fake SubscriptionFlow: only `match()` is called by the bridge. */
|
||||
function fakeSubFlow(
|
||||
match: SubscriptionMatch | null,
|
||||
// openOccurrenceCount: a constant, or a sequence consumed per call (to simulate a
|
||||
// credential closing an occurrence mid-poll → count changes).
|
||||
openCounts: number | number[] = 1,
|
||||
): SubscriptionFlow {
|
||||
const seq = Array.isArray(openCounts) ? [...openCounts] : null;
|
||||
return {
|
||||
match: vi.fn(() => match),
|
||||
openOccurrenceCount: vi.fn(() => (seq ? (seq.length > 1 ? seq.shift()! : seq[0]) : (openCounts as number))),
|
||||
} as unknown as SubscriptionFlow;
|
||||
}
|
||||
|
||||
const SUB_MATCH: SubscriptionMatch = { subscriptionId: "sub-1", carKey: "AA111BB", via: "plate" };
|
||||
|
||||
/** Capture read events emitted during `fn` (async). */
|
||||
async function captureReads(fn: () => Promise<void>): Promise<DeviceReadEvent[]> {
|
||||
const got: DeviceReadEvent[] = [];
|
||||
const off = deviceEvents.onRead((e) => got.push(e));
|
||||
try {
|
||||
await fn();
|
||||
} finally {
|
||||
off();
|
||||
}
|
||||
return got;
|
||||
}
|
||||
|
||||
describe("AnprBridge", () => {
|
||||
it("does nothing for an opt-OUT camera (no anpr flag) — no analyze, no read", async () => {
|
||||
const cam = seedCamera({ anpr: false });
|
||||
const vision = fakeVision({ plate: "AA111BB" });
|
||||
const bridge = new AnprBridge(db, vision, fakeSubFlow(SUB_MATCH), silentLogger());
|
||||
|
||||
const reads = await captureReads(() => bridge.onVehicleDetected(cam));
|
||||
expect(reads).toEqual([]);
|
||||
expect(vision.analyze).not.toHaveBeenCalled();
|
||||
expect(captureSnapshot).not.toHaveBeenCalled();
|
||||
});
|
||||
|
||||
it("does NOT auto-trigger when anprAutoTrigger=false (recognition on, auto-open off)", async () => {
|
||||
// Shared entry/exit lane: the exit cam keeps anpr (recognition) but auto-trigger off, so a
|
||||
// car driving IN isn't phantom-EXITed by its back plate. The bridge bails before snapshot.
|
||||
const cam = seedCamera({ anpr: true, anprAutoTrigger: false });
|
||||
const vision = fakeVision({ plate: "AA111BB", confidence: 0.99 });
|
||||
const bridge = new AnprBridge(db, vision, fakeSubFlow(SUB_MATCH), silentLogger());
|
||||
|
||||
const reads = await captureReads(() => bridge.onVehicleDetected(cam));
|
||||
expect(reads).toEqual([]);
|
||||
expect(captureSnapshot).not.toHaveBeenCalled(); // gated before the poll loop
|
||||
});
|
||||
|
||||
it("emits a plate read (upper-cased) for a high-confidence SUBSCRIBER plate", async () => {
|
||||
const cam = seedCamera({ anpr: true });
|
||||
const vision = fakeVision({ plate: " aa111bb ", confidence: 0.97 });
|
||||
const bridge = new AnprBridge(db, vision, fakeSubFlow(SUB_MATCH), silentLogger());
|
||||
|
||||
const reads = await captureReads(() => bridge.onVehicleDetected(cam));
|
||||
expect(reads).toHaveLength(1);
|
||||
expect(reads[0]).toMatchObject({ deviceId: cam, value: "AA111BB", kind: "plate", driverId: "hikvision" });
|
||||
});
|
||||
|
||||
it("ignores a plate below the entry confidence floor", async () => {
|
||||
const cam = seedCamera({ anpr: true });
|
||||
const vision = fakeVision({ plate: "AA111BB", confidence: 0.6 }); // < default 0.85
|
||||
const bridge = new AnprBridge(db, vision, fakeSubFlow(SUB_MATCH), silentLogger());
|
||||
|
||||
const reads = await captureReads(() => bridge.onVehicleDetected(cam));
|
||||
expect(reads).toEqual([]);
|
||||
});
|
||||
|
||||
it("POLLS until confident: low-confidence approach frames, then a clean stop-at-barrier frame", async () => {
|
||||
// The car APPROACHES (garbage reads) then STOPS at the barrier (clean read) — the bridge
|
||||
// must re-pull until one frame clears the floor, not give up on the first bad frame.
|
||||
const cam = seedCamera({ anpr: true });
|
||||
// analyze escalates: 0.20, 0.20, then 0.97 on the 3rd pull → that one emits.
|
||||
const confs = [0.2, 0.2, 0.97];
|
||||
let i = 0;
|
||||
const vision = {
|
||||
enabled: true,
|
||||
analyze: vi.fn(async () => ({
|
||||
plate: { text: "AA111BB", confidence: confs[Math.min(i++, confs.length - 1)] },
|
||||
plates: [],
|
||||
lowConfidence: false,
|
||||
vehicle: null,
|
||||
modelVersion: "test",
|
||||
tookMs: 1,
|
||||
})),
|
||||
} as unknown as VisionClient;
|
||||
// Generous window so all 3 escalation attempts run deterministically under suite load
|
||||
// (the global beforeEach sets a tiny 5ms window for the give-up cases).
|
||||
process.env.ANPR_POLL_MS = "1";
|
||||
process.env.ANPR_POLL_WINDOW_MS = "2000";
|
||||
const bridge = new AnprBridge(db, vision, fakeSubFlow(SUB_MATCH), silentLogger());
|
||||
|
||||
const reads = await captureReads(() => bridge.onVehicleDetected(cam));
|
||||
expect(reads).toHaveLength(1);
|
||||
expect(reads[0]).toMatchObject({ value: "AA111BB", kind: "plate" });
|
||||
expect(captureSnapshot.mock.calls.length).toBeGreaterThanOrEqual(3); // re-pulled fresh frames
|
||||
});
|
||||
|
||||
it("SLIDES the window: a push mid-poll keeps the loop alive past the initial deadline", async () => {
|
||||
// A loop started by an early/far car would expire — but a NEW push (another car arriving)
|
||||
// extends the deadline, so the loop keeps polling and reads the car that settles at the
|
||||
// barrier. Here: a SHORT base window, vision stays low until attempt 5; a second push at
|
||||
// the start bumps the deadline so attempt 5's confident read still lands.
|
||||
const cam = seedCamera({ anpr: true });
|
||||
const confs = [0.2, 0.2, 0.2, 0.2, 0.97];
|
||||
let i = 0;
|
||||
const vision = {
|
||||
enabled: true,
|
||||
analyze: vi.fn(async () => ({
|
||||
plate: { text: "AA111BB", confidence: confs[Math.min(i++, confs.length - 1)] },
|
||||
plates: [],
|
||||
lowConfidence: false,
|
||||
vehicle: null,
|
||||
modelVersion: "test",
|
||||
tookMs: 1,
|
||||
})),
|
||||
} as unknown as VisionClient;
|
||||
process.env.ANPR_POLL_MS = "5";
|
||||
process.env.ANPR_POLL_WINDOW_MS = "12"; // tiny — would expire ~attempt 2 WITHOUT a slide
|
||||
process.env.ANPR_POLL_MAX_MS = "5000"; // ceiling far above, so the slide is what matters
|
||||
const bridge = new AnprBridge(db, vision, fakeSubFlow(SUB_MATCH), silentLogger());
|
||||
|
||||
const reads = await captureReads(async () => {
|
||||
const loop = bridge.onVehicleDetected(cam); // starts the loop
|
||||
// Joining pushes keep sliding the deadline forward so the slow-to-confident read lands.
|
||||
for (let k = 0; k < 5; k++) {
|
||||
await new Promise((r) => setTimeout(r, 5));
|
||||
void bridge.onVehicleDetected(cam); // each bumps the deadline (loop already running)
|
||||
}
|
||||
await loop;
|
||||
});
|
||||
expect(reads).toHaveLength(1);
|
||||
expect(reads[0]).toMatchObject({ value: "AA111BB" });
|
||||
});
|
||||
|
||||
it("ABORTS if the subscriber transacts by another credential mid-poll (no double-act)", async () => {
|
||||
// The car's plate is read (identity known) but stays below the floor; meanwhile the
|
||||
// subscriber scans their card → openOccurrenceCount drops. The bridge must abort and NOT
|
||||
// emit (which would exit the NEXT open occurrence — a phantom double-exit, esp. fleet).
|
||||
const cam = seedCamera({ anpr: true });
|
||||
const vision = fakeVision({ plate: "AA111BB", confidence: 0.5 }); // never clears the floor
|
||||
// openOccurrenceCount: 1 at baseline, then 0 (the card exit closed it) on the next check.
|
||||
const sub = fakeSubFlow(SUB_MATCH, [1, 0]);
|
||||
const bridge = new AnprBridge(db, vision, sub, silentLogger());
|
||||
|
||||
const reads = await captureReads(() => bridge.onVehicleDetected(cam));
|
||||
expect(reads).toEqual([]); // aborted — the credential already handled it
|
||||
});
|
||||
|
||||
it("does NOT emit for a plate matching no subscription — records an advisory anpr-skip", async () => {
|
||||
const cam = seedCamera({ anpr: true });
|
||||
const vision = fakeVision({ plate: "ZZ999ZZ", confidence: 0.97 });
|
||||
const bridge = new AnprBridge(db, vision, fakeSubFlow(null), silentLogger());
|
||||
|
||||
const reads = await captureReads(() => bridge.onVehicleDetected(cam));
|
||||
expect(reads).toEqual([]);
|
||||
|
||||
const skips = db.select().from(deviceEventsTable).where(eq(deviceEventsTable.kind, "anpr-skip")).all();
|
||||
expect(skips).toHaveLength(1);
|
||||
expect((skips[0].detail as { plate?: string }).plate).toBe("ZZ999ZZ");
|
||||
});
|
||||
|
||||
it("analyzes AT LEAST ONE frame even if the poll window already elapsed (loaded host)", async () => {
|
||||
// Regression for a CI flake (2026-07-04): with a plain `while`, a window that lapsed
|
||||
// between deadline-set and loop-entry (slow runner; here forced with a 0ms window)
|
||||
// meant ZERO analyze attempts — the detection was silently dropped ("gave up") and no
|
||||
// skip was recorded. The do-while guarantees one frame per detection regardless of load.
|
||||
process.env.ANPR_POLL_WINDOW_MS = "0";
|
||||
const cam = seedCamera({ anpr: true });
|
||||
const vision = fakeVision({ plate: "ZZ999ZZ", confidence: 0.97 });
|
||||
const bridge = new AnprBridge(db, vision, fakeSubFlow(null), silentLogger());
|
||||
|
||||
await captureReads(() => bridge.onVehicleDetected(cam));
|
||||
expect(captureSnapshot).toHaveBeenCalledTimes(1); // the guaranteed first attempt
|
||||
const skips = db.select().from(deviceEventsTable).where(eq(deviceEventsTable.kind, "anpr-skip")).all();
|
||||
expect(skips).toHaveLength(1);
|
||||
});
|
||||
|
||||
it("debounces: two vehicle events within the window analyze/emit at most once", async () => {
|
||||
const cam = seedCamera({ anpr: true });
|
||||
const vision = fakeVision({ plate: "AA111BB", confidence: 0.97 });
|
||||
const bridge = new AnprBridge(db, vision, fakeSubFlow(SUB_MATCH), silentLogger());
|
||||
|
||||
const reads = await captureReads(async () => {
|
||||
await bridge.onVehicleDetected(cam);
|
||||
await bridge.onVehicleDetected(cam); // within the 12s window → suppressed
|
||||
});
|
||||
expect(reads).toHaveLength(1);
|
||||
expect(captureSnapshot).toHaveBeenCalledTimes(1); // 2nd was gated before the snapshot
|
||||
});
|
||||
|
||||
it("is a no-op (no throw) when vision is disabled or reads nothing", async () => {
|
||||
const cam = seedCamera({ anpr: true });
|
||||
const disabled = new AnprBridge(db, fakeVision({ enabled: false, plate: "AA111BB" }), fakeSubFlow(SUB_MATCH), silentLogger());
|
||||
const noPlate = new AnprBridge(db, fakeVision({ plate: undefined }), fakeSubFlow(SUB_MATCH), silentLogger());
|
||||
|
||||
const reads = await captureReads(async () => {
|
||||
await disabled.onVehicleDetected(cam);
|
||||
await noPlate.onVehicleDetected(cam);
|
||||
});
|
||||
expect(reads).toEqual([]);
|
||||
});
|
||||
|
||||
it("never throws on an unknown device id", async () => {
|
||||
const bridge = new AnprBridge(db, fakeVision({ plate: "AA111BB" }), fakeSubFlow(SUB_MATCH), silentLogger());
|
||||
await expect(bridge.onVehicleDetected("nope")).resolves.toBeUndefined();
|
||||
});
|
||||
|
||||
it("does NOTHING when the admin has disabled the bridge (site_config.anprEntryEnabled = false)", async () => {
|
||||
const cam = seedCamera({ anpr: true });
|
||||
db.insert(siteConfig).values({ id: 1, anprEntryEnabled: false }).run();
|
||||
const vision = fakeVision({ plate: "AA111BB", confidence: 0.97 });
|
||||
const bridge = new AnprBridge(db, vision, fakeSubFlow(SUB_MATCH), silentLogger());
|
||||
|
||||
const reads = await captureReads(() => bridge.onVehicleDetected(cam));
|
||||
expect(reads).toEqual([]);
|
||||
// The flag is checked FIRST — no snapshot, no analyze, no match attempt.
|
||||
expect(captureSnapshot).not.toHaveBeenCalled();
|
||||
expect(vision.analyze).not.toHaveBeenCalled();
|
||||
});
|
||||
|
||||
it("still emits when the bridge is explicitly enabled (anprEntryEnabled = true)", async () => {
|
||||
const cam = seedCamera({ anpr: true });
|
||||
db.insert(siteConfig).values({ id: 1, anprEntryEnabled: true }).run();
|
||||
const vision = fakeVision({ plate: "AA111BB", confidence: 0.97 });
|
||||
const bridge = new AnprBridge(db, vision, fakeSubFlow(SUB_MATCH), silentLogger());
|
||||
|
||||
const reads = await captureReads(() => bridge.onVehicleDetected(cam));
|
||||
expect(reads).toHaveLength(1);
|
||||
});
|
||||
});
|
||||
@@ -0,0 +1,328 @@
|
||||
import { randomUUID } from "node:crypto";
|
||||
import { devices, deviceEvents as deviceEventsTable, eq, siteConfig, type Db, type DeviceRow } from "@parking/db";
|
||||
import type { FastifyBaseLogger } from "fastify";
|
||||
import { deviceEvents, type DeviceReadEvent } from "./device-events.js";
|
||||
import { directionOf, type FlowDirection } from "./device-resolve.js";
|
||||
import { buildCamera } from "./snapshot.js";
|
||||
import type { SubscriptionFlow } from "./subscription-flow.js";
|
||||
import type { VisionClient } from "./vision-client.js";
|
||||
|
||||
// The ANPR "bridge": a subscriber's plate, read from the lane camera, admits them through
|
||||
// the SAME gated SubscriptionFlow a QR/card scan uses. It is the one missing wire between
|
||||
// the camera's vehicle PUSH (hikvision-alarm.ts) and the read bus — NOT a new service.
|
||||
//
|
||||
// On a `vehicle`/`active` event from an OPT-IN camera (config.anpr === true), the bridge:
|
||||
// pull a fresh snapshot → vision.analyze → entry confidence floor → debounce → MATCH the
|
||||
// plate to a subscription → emit a DeviceReadEvent{kind:"plate"} ONLY if it matched.
|
||||
// The existing onRead → ReadDispatcher then re-matches and runs the gated SubscriptionFlow
|
||||
// (active / window / blocklist / car-count), which signs the entry/exit and opens the relay.
|
||||
//
|
||||
// INVARIANTS (see wiki/concepts/lane-presence-and-anpr-entry.md §2, append-only-event-chain.md):
|
||||
// - Advisory, never sole authority: the bridge only emitRead()s — the signed decision +
|
||||
// barrier open stay inside the existing flow. A spoofed printed plate is just another
|
||||
// credential through the same gate.
|
||||
// - Subscriber-ONLY: it MATCHES before emitting, so a random plate never reaches the
|
||||
// transient plate-as-ticket exit flow.
|
||||
// - Fail-soft + fire-and-forget: any snapshot/vision error degrades to the card/QR path;
|
||||
// never throws into the push handler, never awaited on the camera's 200 response.
|
||||
// - Opt-in per camera, and debounced (the camera re-fires ~1Hz while a car sits).
|
||||
|
||||
/** Camera config flag opting it into the ANPR bridge (same flag advisory ANPR uses). */
|
||||
interface CameraConfig {
|
||||
readonly anpr?: boolean;
|
||||
/** Whether this camera may AUTO-OPEN the barrier (entry/exit). Absent ⇒ true (when anpr is
|
||||
* on). Set false to keep recognition but suppress auto-trigger — e.g. the exit camera on a
|
||||
* shared entry/exit lane. */
|
||||
readonly anprAutoTrigger?: boolean;
|
||||
readonly [k: string]: unknown;
|
||||
}
|
||||
|
||||
/** Stricter-than-advisory confidence floor for a BARRIER-driving plate read. A near-miss
|
||||
* read falls back to the subscriber's card/QR, so we'd rather skip than wrongly admit.
|
||||
* Distinct from vision-client's advisory VISION_MIN_CONFIDENCE. */
|
||||
function entryMinConfidence(): number {
|
||||
const raw = Number(process.env.VISION_ENTRY_MIN_CONFIDENCE ?? 0.85);
|
||||
return Number.isFinite(raw) && raw > 0 ? raw : 0.85;
|
||||
}
|
||||
|
||||
/** Same plate/camera within this window = ONE credential presentation. The camera re-fires
|
||||
* ~1Hz while a car is present; emitting every second would drive repeat entries (a fleet
|
||||
* sub opens a 2nd occurrence) or exit spam. Required for correctness, not CPU. */
|
||||
function debounceMs(): number {
|
||||
const raw = Number(process.env.ANPR_DEBOUNCE_MS ?? 12_000);
|
||||
return Number.isFinite(raw) && raw > 0 ? raw : 12_000;
|
||||
}
|
||||
|
||||
/** A single alarm fires the INSTANT motion starts — the car is still approaching, so the
|
||||
* first frame often has a small/blurry/absent plate (a low-confidence misread). But the car
|
||||
* then STOPS at the barrier (waiting for it to open) — the same stationary, well-framed
|
||||
* moment the manual test reads at ~100%. So instead of one shot, we POLL fresh frames and
|
||||
* re-run ANPR until one clears the confidence floor, or the window elapses. Poll interval: */
|
||||
function pollMs(): number {
|
||||
const raw = Number(process.env.ANPR_POLL_MS ?? 1000);
|
||||
return Number.isFinite(raw) && raw > 0 ? raw : 1000;
|
||||
}
|
||||
|
||||
/** How long to keep polling AFTER THE LAST vehicle push before giving up. SLIDING: each new
|
||||
* push for the camera extends the deadline by this much from now — so a loop started by a
|
||||
* far/early car keeps pulling fresh frames as the REAL car arrives and settles at the
|
||||
* barrier (the loop tracks "whoever is here now", not the car that started it). */
|
||||
function pollWindowMs(): number {
|
||||
const raw = Number(process.env.ANPR_POLL_WINDOW_MS ?? 8000);
|
||||
return Number.isFinite(raw) && raw > 0 ? raw : 8000;
|
||||
}
|
||||
|
||||
/** Hard ceiling on a single loop from its START, so a continuously-busy lane (pushes never
|
||||
* stop) can't slide the window forever. The loop ends at min(lastPush + window, start + max). */
|
||||
function pollMaxMs(): number {
|
||||
const raw = Number(process.env.ANPR_POLL_MAX_MS ?? 30_000);
|
||||
return Number.isFinite(raw) && raw > 0 ? raw : 30_000;
|
||||
}
|
||||
|
||||
const sleep = (ms: number) => new Promise<void>((r) => setTimeout(r, ms));
|
||||
|
||||
/** A plate DeviceReadEvent skeleton (value filled by the caller) — for matching the
|
||||
* subscriber by plate during the poll loop without re-building the whole event. */
|
||||
function baseRead(row: { driverId: string }, deviceId: string): Omit<DeviceReadEvent, "value"> {
|
||||
return { driverId: row.driverId, deviceId, kind: "plate", at: new Date().toISOString() };
|
||||
}
|
||||
|
||||
export class AnprBridge {
|
||||
readonly #db: Db;
|
||||
readonly #vision: VisionClient | null;
|
||||
readonly #subscription: SubscriptionFlow;
|
||||
readonly #logger: FastifyBaseLogger;
|
||||
readonly #entryMinConfidence: number;
|
||||
readonly #debounceMs: number;
|
||||
readonly #pollMs: number;
|
||||
readonly #pollWindowMs: number;
|
||||
readonly #pollMaxMs: number;
|
||||
/** Last-fire timestamps, keyed by deviceId (camera-level, pre-snapshot) AND by
|
||||
* `deviceId:plate` (post-match) — both gated against #debounceMs. */
|
||||
readonly #lastFire = new Map<string, number>();
|
||||
/** Cameras with a poll loop already in flight — a re-fired alarm (the camera pushes ~1Hz
|
||||
* while the car sits) must NOT start a second concurrent loop on the same camera. */
|
||||
readonly #polling = new Set<string>();
|
||||
/** Per-camera SLIDING deadline for the running poll loop. A push that joins a running loop
|
||||
* bumps this forward (lastPush + window, capped at start + max), so the loop keeps pulling
|
||||
* fresh frames while cars keep arriving — tracking whoever settles at the barrier. */
|
||||
readonly #pollDeadline = new Map<string, number>();
|
||||
|
||||
constructor(db: Db, vision: VisionClient | null, subscription: SubscriptionFlow, logger: FastifyBaseLogger) {
|
||||
this.#db = db;
|
||||
this.#vision = vision;
|
||||
this.#subscription = subscription;
|
||||
this.#logger = logger;
|
||||
this.#entryMinConfidence = entryMinConfidence();
|
||||
this.#debounceMs = debounceMs();
|
||||
this.#pollMs = pollMs();
|
||||
this.#pollWindowMs = pollWindowMs();
|
||||
this.#pollMaxMs = pollMaxMs();
|
||||
}
|
||||
|
||||
/**
|
||||
* A camera reported a vehicle. If the camera opts into ANPR, pull a snapshot, read the
|
||||
* plate, and — only if it matches a subscription — emit a plate read onto the bus.
|
||||
* Fire-and-forget; fail-soft. Never throws (the push handler must always 200).
|
||||
*/
|
||||
async onVehicleDetected(deviceId: string): Promise<void> {
|
||||
try {
|
||||
if (!this.#vision?.enabled) return; // no recognizer configured
|
||||
// Admin master switch (read LIVE so toggling in Site Settings takes effect with no
|
||||
// restart). Gates ONLY this barrier-driving bridge — advisory snapshot-ANPR and lane
|
||||
// busy/free are unaffected. Absent/unreadable config ⇒ enabled (the default).
|
||||
const site = this.#db.select().from(siteConfig).where(eq(siteConfig.id, 1)).get();
|
||||
if (site && site.anprEntryEnabled === false) return;
|
||||
const row = this.#db.select().from(devices).where(eq(devices.id, deviceId)).get();
|
||||
if (!row || !row.enabled || row.category !== "camera") return;
|
||||
const cfg = row.config as CameraConfig;
|
||||
if (cfg?.anpr !== true) return; // recognition opt-in (also gates the evidence/advisory path)
|
||||
// Per-camera AUTO-TRIGGER gate. `anpr` keeps recognition (snapshots + plate record) on;
|
||||
// this controls whether THIS camera may auto-open the barrier. A shared entry/exit lane
|
||||
// sets it false on (e.g.) the exit camera so its back-plate read doesn't phantom-exit the
|
||||
// car that just entered. Absent ⇒ true (back-compat: existing anpr cameras still trigger).
|
||||
if (cfg.anprAutoTrigger === false) return;
|
||||
|
||||
// Post-success debounce: once we've emitted a read for this camera, ignore the
|
||||
// ~1Hz re-fires for #debounceMs (set on success below). A fresh alarm AFTER the
|
||||
// window is a new presentation and may start a new poll loop.
|
||||
if (this.#debounced(deviceId)) return;
|
||||
// One poll loop per camera. A push that arrives while a loop runs JOINs it — and
|
||||
// SLIDES the deadline forward (a different car arriving mid-loop keeps the loop alive
|
||||
// so it tracks whoever's at the barrier now, instead of giving up on the early car).
|
||||
const now = Date.now();
|
||||
if (this.#polling.has(deviceId)) {
|
||||
const cur = this.#pollDeadline.get(deviceId) ?? now;
|
||||
// Slide to lastPush + window, but never past the per-loop hard ceiling (set at start).
|
||||
this.#pollDeadline.set(deviceId, Math.max(cur, now + this.#pollWindowMs));
|
||||
return;
|
||||
}
|
||||
this.#polling.add(deviceId);
|
||||
// Initial deadline; the hard ceiling (start + max) is enforced in the loop below.
|
||||
this.#pollDeadline.set(deviceId, now + this.#pollWindowMs);
|
||||
|
||||
const camera = buildCamera(row);
|
||||
if (!camera) {
|
||||
this.#polling.delete(deviceId);
|
||||
this.#logger.warn(`anpr-bridge: camera ${deviceId} config won't build`);
|
||||
return;
|
||||
}
|
||||
|
||||
// "both" collapses to entry purely for the capture hint (it doesn't pick the lane —
|
||||
// the gated flow infers the verb from the camera's bound relay direction).
|
||||
const direction: FlowDirection = directionOf(this.#db, row) === "exit" ? "exit" : "entry";
|
||||
|
||||
// POLL-UNTIL-CONFIDENT. The alarm fires as the car APPROACHES (small/blurry/absent
|
||||
// plate → low-confidence misread, e.g. '111'@0.20). But the car then STOPS at the
|
||||
// barrier — the stationary, well-framed moment the manual test reads at ~100%. So we
|
||||
// pull a FRESH frame every #pollMs and re-run ANPR until one clears the floor, or the
|
||||
// #pollWindowMs window elapses (car drove off / non-subscriber). NB: a fresh pull each
|
||||
// tick — NOT captureSnapshotShared, whose TTL would re-serve the same bad frame.
|
||||
// While polling, watch whether THIS subscriber transacts by another credential
|
||||
// (card/QR at the reader). If their open-occurrence count drops mid-poll, the
|
||||
// subscriber already exited/entered — the bridge must NOT also emit (it would act on
|
||||
// the NEXT open occurrence: a phantom double-exit, worst for a fleet sub). We learn the
|
||||
// subscription as soon as a frame reads the bound plate (identity needs no confidence),
|
||||
// snapshot the count, then keep polling for a CONFIDENT read; abort if the count moved.
|
||||
let result: Awaited<ReturnType<VisionClient["analyze"]>> = null;
|
||||
let watchedSubId: string | null = null;
|
||||
let baselineOpen = 0;
|
||||
// Hard ceiling for THIS loop (start + max); the sliding deadline (bumped by joining
|
||||
// pushes) is read from #pollDeadline each tick but never allowed past this cap.
|
||||
const hardCap = Date.now() + this.#pollMaxMs;
|
||||
let attempts = 0;
|
||||
try {
|
||||
// DO-while: a detection always analyzes AT LEAST ONE frame, however loaded the
|
||||
// host — a plain while could zero-iterate if the window elapsed between setting
|
||||
// the deadline and reaching the loop (seen as a CI flake with the tests' 5ms
|
||||
// window; on a busy booth it would silently drop a real car's detection). Exit
|
||||
// is via the breaks below (confident read, or next tick would pass the deadline).
|
||||
do {
|
||||
attempts++;
|
||||
const shot = await camera.captureSnapshot({ direction });
|
||||
const r = await this.#vision.analyze(shot.bytes, shot.contentType);
|
||||
|
||||
// Identify the subscriber from ANY readable plate (even below the barrier floor),
|
||||
// and baseline their open count once — so we can detect a credential beating us.
|
||||
if (r?.plate?.text) {
|
||||
const m0 = this.#subscription.match({ ...baseRead(row, deviceId), value: r.plate.text.trim().toUpperCase() });
|
||||
if (m0 && watchedSubId == null) {
|
||||
watchedSubId = m0.subscriptionId;
|
||||
baselineOpen = this.#subscription.openOccurrenceCount(watchedSubId);
|
||||
}
|
||||
}
|
||||
// A credential (card/QR) closed/opened an occurrence for this subscriber mid-poll →
|
||||
// they already transacted; stop polling and do NOT emit.
|
||||
if (watchedSubId && this.#subscription.openOccurrenceCount(watchedSubId) !== baselineOpen) {
|
||||
this.#logger.info(
|
||||
`anpr-bridge: subscriber ${watchedSubId} transacted by another credential mid-poll — aborting ANPR`,
|
||||
);
|
||||
return;
|
||||
}
|
||||
|
||||
if (r?.plate && r.plate.confidence >= this.#entryMinConfidence) {
|
||||
result = r;
|
||||
break;
|
||||
}
|
||||
if (r?.plate) {
|
||||
this.#logger.info(
|
||||
`anpr-bridge: '${r.plate.text}' (${r.plate.confidence.toFixed(3)}) below floor ` +
|
||||
`${this.#entryMinConfidence} — re-pulling (attempt ${attempts})`,
|
||||
);
|
||||
}
|
||||
// Stop if the next tick would land past the (possibly slid) deadline or the cap.
|
||||
const effDeadline = Math.min(this.#pollDeadline.get(deviceId) ?? 0, hardCap);
|
||||
if (Date.now() + this.#pollMs >= effDeadline) break;
|
||||
await sleep(this.#pollMs);
|
||||
} while (true);
|
||||
} finally {
|
||||
this.#polling.delete(deviceId);
|
||||
this.#pollDeadline.delete(deviceId);
|
||||
}
|
||||
|
||||
if (!result || !result.plate) {
|
||||
this.#logger.info(
|
||||
`anpr-bridge: no confident plate from ${deviceId} after ${attempts} attempt(s) ` +
|
||||
`in ${this.#pollWindowMs}ms — gave up`,
|
||||
);
|
||||
return;
|
||||
}
|
||||
|
||||
const plate = result.plate.text.trim().toUpperCase();
|
||||
if (!plate) return;
|
||||
|
||||
const e: DeviceReadEvent = {
|
||||
driverId: row.driverId,
|
||||
deviceId,
|
||||
value: plate,
|
||||
kind: "plate",
|
||||
at: new Date().toISOString(),
|
||||
};
|
||||
|
||||
// MATCH BEFORE EMIT — subscriber-only. A non-subscriber plate records advisory
|
||||
// telemetry and stops; it must NEVER reach the transient plate-as-ticket exit flow.
|
||||
const match = this.#subscription.match(e);
|
||||
if (!match) {
|
||||
this.#recordSkip(deviceId, plate, result.plate.confidence);
|
||||
return;
|
||||
}
|
||||
|
||||
// Final guard against the credential-mid-poll race: if the subscriber transacted between
|
||||
// our baseline and now (e.g. a card scan in the last tick), don't double-act.
|
||||
if (watchedSubId === match.subscriptionId && this.#subscription.openOccurrenceCount(match.subscriptionId) !== baselineOpen) {
|
||||
this.#logger.info(`anpr-bridge: ${match.subscriptionId} already transacted — skipping ANPR emit`);
|
||||
return;
|
||||
}
|
||||
|
||||
// Plate-level debounce — belt-and-suspenders against a gap that slips the
|
||||
// camera-level gate re-emitting the SAME plate.
|
||||
const plateKey = `${deviceId}:${plate}`;
|
||||
if (this.#debounced(plateKey)) return;
|
||||
this.#stamp(plateKey);
|
||||
// Camera-level debounce stamp — now that we've emitted, suppress the camera's ~1Hz
|
||||
// re-fires (and any new poll loop) for #debounceMs.
|
||||
this.#stamp(deviceId);
|
||||
|
||||
this.#logger.info(
|
||||
`anpr-bridge: subscriber plate '${plate}' (${result.plate.confidence.toFixed(3)}) → read bus`,
|
||||
);
|
||||
deviceEvents.emitRead(e); // → onRead → ReadDispatcher → gated SubscriptionFlow
|
||||
} catch (err) {
|
||||
// Fail-soft: an ANPR failure degrades to the subscriber's card/QR, never strands the lane.
|
||||
this.#logger.warn(`anpr-bridge failed (${deviceId}): ${(err as Error).message}`);
|
||||
}
|
||||
}
|
||||
|
||||
#debounced(key: string): boolean {
|
||||
const last = this.#lastFire.get(key);
|
||||
return last != null && Date.now() - last < this.#debounceMs;
|
||||
}
|
||||
|
||||
#stamp(key: string): void {
|
||||
this.#lastFire.set(key, Date.now());
|
||||
}
|
||||
|
||||
/** Advisory telemetry: a plate was read at the lane but matched no subscription. Not a
|
||||
* read on the bus — just a breadcrumb so the operator can see ANPR is working. */
|
||||
#recordSkip(deviceId: string, plate: string, confidence: number): void {
|
||||
this.#logger.info(`anpr-bridge: plate '${plate}' matched no subscription — skipped`);
|
||||
try {
|
||||
this.#db
|
||||
.insert(deviceEventsTable)
|
||||
.values({
|
||||
id: randomUUID(),
|
||||
deviceId,
|
||||
category: "camera",
|
||||
kind: "anpr-skip",
|
||||
detail: { plate, confidence, source: "anpr-bridge", reason: "no subscription match" },
|
||||
occurredAt: new Date().toISOString(),
|
||||
})
|
||||
.run();
|
||||
} catch (err) {
|
||||
this.#logger.error(`anpr-bridge skip-record insert failed: ${(err as Error).message}`);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// DeviceRow is re-exported for the test's seed typing convenience.
|
||||
export type { DeviceRow };
|
||||
@@ -0,0 +1,56 @@
|
||||
import { afterEach, beforeEach, describe, expect, it } from "vitest";
|
||||
import { secureCookies } from "./auth.js";
|
||||
|
||||
// The auth/CSRF cookies' Secure flag must be FAIL-SAFE: Secure by default, dropped only
|
||||
// on a deliberate opt-out. The old behaviour (Secure iff NODE_ENV==="production") leaked
|
||||
// cookies over plain HTTP on an appliance that forgot to set NODE_ENV — this pins the
|
||||
// corrected matrix.
|
||||
|
||||
let savedCookieSecure: string | undefined;
|
||||
let savedNodeEnv: string | undefined;
|
||||
|
||||
beforeEach(() => {
|
||||
savedCookieSecure = process.env.COOKIE_SECURE;
|
||||
savedNodeEnv = process.env.NODE_ENV;
|
||||
delete process.env.COOKIE_SECURE;
|
||||
delete process.env.NODE_ENV;
|
||||
});
|
||||
afterEach(() => {
|
||||
restore("COOKIE_SECURE", savedCookieSecure);
|
||||
restore("NODE_ENV", savedNodeEnv);
|
||||
});
|
||||
function restore(key: string, val: string | undefined) {
|
||||
if (val === undefined) delete process.env[key];
|
||||
else process.env[key] = val;
|
||||
}
|
||||
|
||||
describe("secureCookies — fail-safe Secure flag", () => {
|
||||
it("defaults to Secure when nothing is set (the appliance-forgot-NODE_ENV case)", () => {
|
||||
expect(secureCookies()).toBe(true);
|
||||
});
|
||||
|
||||
it("stays Secure in production", () => {
|
||||
process.env.NODE_ENV = "production";
|
||||
expect(secureCookies()).toBe(true);
|
||||
});
|
||||
|
||||
it("drops Secure only for an explicit local-dev NODE_ENV", () => {
|
||||
process.env.NODE_ENV = "development";
|
||||
expect(secureCookies()).toBe(false);
|
||||
});
|
||||
|
||||
it("COOKIE_SECURE override wins: falsey values opt OUT", () => {
|
||||
for (const v of ["0", "false", "no", "off", "FALSE", " Off "]) {
|
||||
process.env.COOKIE_SECURE = v;
|
||||
expect(secureCookies(), `COOKIE_SECURE=${JSON.stringify(v)}`).toBe(false);
|
||||
}
|
||||
});
|
||||
|
||||
it("COOKIE_SECURE override wins: any other value opts IN (even in dev)", () => {
|
||||
process.env.NODE_ENV = "development";
|
||||
for (const v of ["1", "true", "yes", "on", ""]) {
|
||||
process.env.COOKIE_SECURE = v;
|
||||
expect(secureCookies(), `COOKIE_SECURE=${JSON.stringify(v)}`).toBe(true);
|
||||
}
|
||||
});
|
||||
});
|
||||
+74
-6
@@ -1,6 +1,6 @@
|
||||
import { randomBytes } from "node:crypto";
|
||||
import type { FastifyReply, FastifyRequest } from "fastify";
|
||||
import { eq, rolePermissions, type Db } from "@parking/db";
|
||||
import { eq, rolePermissions, users, type Db } from "@parking/db";
|
||||
import { ADMIN_ROLE_ID, PERMISSIONS, type Permission } from "@parking/shared";
|
||||
|
||||
// Local JWT auth helpers — fully local, no external identity provider
|
||||
@@ -50,9 +50,28 @@ export function requireJwtSecret(): string {
|
||||
return secret;
|
||||
}
|
||||
|
||||
/** Cookies are secure in production; relaxed for local http dev. */
|
||||
function secureCookies(): boolean {
|
||||
return process.env.NODE_ENV === "production";
|
||||
/**
|
||||
* Whether to set the `Secure` flag on the auth/CSRF cookies. FAIL-SAFE: default is
|
||||
* `true` (Secure) — a misconfigured/forgotten env can only ever make cookies MORE
|
||||
* restrictive, never silently drop the flag.
|
||||
*
|
||||
* The previous gate keyed off `NODE_ENV === "production"`, which meant an appliance
|
||||
* deployed without that var leaked cookies over plain HTTP. Now `Secure` is the
|
||||
* default and is dropped ONLY for an explicit, deliberate opt-out — `COOKIE_SECURE`
|
||||
* set to a falsey value (`0/false/no/off`), or the legacy `NODE_ENV !== production`
|
||||
* signal kept as a fallback so existing dev setups still work over http://localhost.
|
||||
*
|
||||
* The parking appliance often serves the SPA same-origin over the LAN with no TLS;
|
||||
* THAT box sets `COOKIE_SECURE=0` on purpose (a Secure cookie would never be sent
|
||||
* over its http origin and would lock operators out). Everything else stays secure.
|
||||
*/
|
||||
export function secureCookies(): boolean {
|
||||
const override = process.env.COOKIE_SECURE;
|
||||
if (override !== undefined) {
|
||||
return !/^(0|false|no|off)$/i.test(override.trim());
|
||||
}
|
||||
// No explicit override: secure unless this is an obvious local-dev run.
|
||||
return process.env.NODE_ENV !== "development";
|
||||
}
|
||||
|
||||
export function newCsrfToken(): string {
|
||||
@@ -124,10 +143,41 @@ export function initAuth(db: Db): void {
|
||||
permsCache.clear();
|
||||
}
|
||||
|
||||
/** Clear the permission cache. Call after ANY write to roles / role_permissions
|
||||
* (or a user's roleId) so the change takes effect on the next request. */
|
||||
/** Clear the permission + role caches. Call after ANY write to roles / role_permissions
|
||||
* or to a user's roleId / deletion, so the change takes effect on the next request. */
|
||||
export function bumpPermsCache(): void {
|
||||
permsCache.clear();
|
||||
roleCache.clear();
|
||||
}
|
||||
|
||||
/** userId → CURRENT roleId, cached until bumpPermsCache(). */
|
||||
const roleCache = new Map<string, string | null>();
|
||||
|
||||
/** The user's CURRENT role. The token pins the roleId that was current at LOGIN; an
|
||||
* admin reassigning a user's role (or deleting the user) must take effect on the next
|
||||
* request exactly like editing a role does — otherwise the reassigned user keeps the
|
||||
* old role's rights until they log out (found 2026-09-05: a user moved to a new
|
||||
* wash role kept 403ing on the new role's permissions). null = the user is gone. */
|
||||
export function currentRoleId(sub: string): string | null {
|
||||
if (!authDb) throw new Error("auth not initialised (call initAuth)");
|
||||
const hit = roleCache.get(sub);
|
||||
if (hit !== undefined) return hit;
|
||||
const row = authDb
|
||||
.select({ roleId: users.roleId, deletedAt: users.deletedAt })
|
||||
.from(users)
|
||||
.where(eq(users.id, sub))
|
||||
.get();
|
||||
const roleId = row && row.deletedAt == null ? row.roleId : null;
|
||||
roleCache.set(sub, roleId);
|
||||
return roleId;
|
||||
}
|
||||
|
||||
/** After jwtVerify: replace the token's pinned roleId with the user's current one, or
|
||||
* end the session if the user no longer exists. */
|
||||
function refreshRole(req: FastifyRequest): void {
|
||||
const roleId = currentRoleId(req.user.sub);
|
||||
if (roleId === null) throw Object.assign(new Error("session no longer valid"), { statusCode: 401 });
|
||||
if (roleId !== req.user.roleId) req.user.roleId = roleId;
|
||||
}
|
||||
|
||||
/** The permission set for a role id, cached. `admin` is always the full set. */
|
||||
@@ -165,12 +215,29 @@ export function requirePermission(...required: Permission[]) {
|
||||
return async (req: FastifyRequest, _reply: FastifyReply) => {
|
||||
await req.jwtVerify(); // reads the token cookie (configured in server.ts)
|
||||
assertCsrf(req);
|
||||
refreshRole(req);
|
||||
if (!req.user || !roleHasPermissions(req.user.roleId, required)) {
|
||||
throw Object.assign(new Error("forbidden"), { statusCode: 403 });
|
||||
}
|
||||
};
|
||||
}
|
||||
|
||||
/**
|
||||
* preHandler guard satisfied by ANY ONE of the listed permissions — for a read that
|
||||
* two jobs legitimately share (a module's master data: the desk that works with it
|
||||
* reads it under the module's own permission, Setup reads it under site:read).
|
||||
*/
|
||||
export function requireAnyPermission(...anyOf: Permission[]) {
|
||||
return async (req: FastifyRequest, _reply: FastifyReply) => {
|
||||
await req.jwtVerify();
|
||||
assertCsrf(req);
|
||||
refreshRole(req);
|
||||
if (!req.user || !anyOf.some((p) => roleHasPermissions(req.user!.roleId, [p]))) {
|
||||
throw Object.assign(new Error("forbidden"), { statusCode: 403 });
|
||||
}
|
||||
};
|
||||
}
|
||||
|
||||
/**
|
||||
* preHandler that requires a valid signed-in session but NO specific permission —
|
||||
* for "about me" routes (/me, change own language) every authenticated user may
|
||||
@@ -182,4 +249,5 @@ export async function requireAuth(
|
||||
): Promise<void> {
|
||||
await req.jwtVerify();
|
||||
assertCsrf(req);
|
||||
refreshRole(req);
|
||||
}
|
||||
|
||||
@@ -0,0 +1,139 @@
|
||||
import { mkdtempSync, rmSync, writeFileSync } from "node:fs";
|
||||
import { tmpdir } from "node:os";
|
||||
import { join } from "node:path";
|
||||
import { eq, siteConfig } from "@parking/db";
|
||||
import { createTestDb } from "@parking/db/testing";
|
||||
import { afterEach, beforeEach, describe, expect, it } from "vitest";
|
||||
import { BackupService } from "./backup-service.js";
|
||||
|
||||
// BackupService previously tracked last-success/last-error as plain in-process fields, so a
|
||||
// server restart (a fresh BackupService instance, exactly as happens on every deploy/crash/OOM
|
||||
// reboot under `restart: always`) silently reset the admin UI to "last successful backup:
|
||||
// Never" — even with valid, correctly-rotating backups already on disk (2026-08-30 field
|
||||
// incident, park-buzi). These tests exercise the fix: status is read from site_config, so a new
|
||||
// BackupService instance pointed at the same DB sees the prior instance's last-run outcome, and
|
||||
// the schedule is wall-clock-based (isDue()) rather than time-since-process-start.
|
||||
// See wiki/concepts/backup-recovery.md.
|
||||
|
||||
const KEY = "a-test-backup-key-that-is-long-enough";
|
||||
|
||||
let workDir: string;
|
||||
let target: string;
|
||||
|
||||
beforeEach(() => {
|
||||
workDir = mkdtempSync(join(tmpdir(), "pk-backup-service-test-"));
|
||||
target = join(workDir, "target");
|
||||
process.env.BACKUP_KEY = KEY;
|
||||
});
|
||||
|
||||
afterEach(() => {
|
||||
rmSync(workDir, { recursive: true, force: true });
|
||||
delete process.env.BACKUP_KEY;
|
||||
});
|
||||
|
||||
function setTargetDir(db: ReturnType<typeof createTestDb>["db"], dir: string): void {
|
||||
const existing = db.select().from(siteConfig).where(eq(siteConfig.id, 1)).get();
|
||||
if (existing) {
|
||||
db.update(siteConfig).set({ backupTargetDir: dir }).where(eq(siteConfig.id, 1)).run();
|
||||
} else {
|
||||
db.insert(siteConfig).values({ id: 1, backupTargetDir: dir }).run();
|
||||
}
|
||||
}
|
||||
|
||||
describe("BackupService — persisted status survives a restart", () => {
|
||||
it("a fresh instance sees the previous instance's last success", async () => {
|
||||
const t = createTestDb();
|
||||
setTargetDir(t.db, target);
|
||||
|
||||
const first = new BackupService(t.db);
|
||||
expect(first.status().lastSuccessAt).toBeNull();
|
||||
const result = await first.run("manual");
|
||||
|
||||
// Simulate a process restart: a brand-new BackupService over the SAME db handle (in
|
||||
// production this would be a fresh process re-opening the same sqlite file).
|
||||
const second = new BackupService(t.db);
|
||||
const status = second.status();
|
||||
expect(status.lastSuccessAt).not.toBeNull();
|
||||
expect(status.lastResult).toEqual({ path: result.path, bytes: result.bytes, prunedFiles: result.prunedFiles });
|
||||
expect(status.lastError).toBeNull();
|
||||
|
||||
t.close();
|
||||
});
|
||||
|
||||
it("a fresh instance sees the previous instance's last error, and it clears on next success", async () => {
|
||||
const t = createTestDb();
|
||||
// Target dir set, but as a FILE (not a directory) — runBackup's mkdir(recursive) will
|
||||
// throw, giving us a real, deterministic failure without needing to mock anything.
|
||||
const badTarget = join(workDir, "not-a-dir");
|
||||
writeFileSync(badTarget, "x");
|
||||
setTargetDir(t.db, badTarget);
|
||||
|
||||
const first = new BackupService(t.db);
|
||||
await expect(first.run("manual")).rejects.toThrow();
|
||||
|
||||
const second = new BackupService(t.db);
|
||||
const status = second.status();
|
||||
expect(status.lastError).not.toBeNull();
|
||||
expect(status.lastErrorAt).not.toBeNull();
|
||||
expect(status.lastSuccessAt).toBeNull();
|
||||
|
||||
// Now point at a real directory and succeed — the persisted error must clear.
|
||||
setTargetDir(t.db, target);
|
||||
await second.run("manual");
|
||||
const third = new BackupService(t.db);
|
||||
const finalStatus = third.status();
|
||||
expect(finalStatus.lastSuccessAt).not.toBeNull();
|
||||
expect(finalStatus.lastError).toBeNull();
|
||||
expect(finalStatus.lastErrorAt).toBeNull();
|
||||
|
||||
t.close();
|
||||
});
|
||||
});
|
||||
|
||||
describe("BackupService — isDue() is wall-clock-based, not process-uptime-based", () => {
|
||||
it("is due immediately when no success has ever been recorded", () => {
|
||||
const t = createTestDb();
|
||||
const svc = new BackupService(t.db);
|
||||
expect(svc.isDue()).toBe(true);
|
||||
t.close();
|
||||
});
|
||||
|
||||
it("is NOT due right after a fresh instance is constructed, if a recent success is persisted", async () => {
|
||||
const t = createTestDb();
|
||||
setTargetDir(t.db, target);
|
||||
const first = new BackupService(t.db);
|
||||
await first.run("manual");
|
||||
|
||||
// The whole point of the fix: a brand-new instance (simulating a restart moments after a
|
||||
// real backup completed) must NOT think a backup is due just because ITS OWN uptime is ~0.
|
||||
const second = new BackupService(t.db);
|
||||
expect(second.isDue()).toBe(false);
|
||||
t.close();
|
||||
});
|
||||
|
||||
it("is due once the persisted last-success timestamp is old enough", async () => {
|
||||
const t = createTestDb();
|
||||
setTargetDir(t.db, target);
|
||||
const svc = new BackupService(t.db);
|
||||
await svc.run("manual");
|
||||
|
||||
const almostADayLater = new Date(Date.now() + 23 * 60 * 60 * 1000);
|
||||
expect(svc.isDue(almostADayLater)).toBe(false);
|
||||
|
||||
const overADayLater = new Date(Date.now() + 24 * 60 * 60 * 1000 + 1000);
|
||||
expect(svc.isDue(overADayLater)).toBe(true);
|
||||
t.close();
|
||||
});
|
||||
|
||||
it("runScheduled() is a no-op when not yet due, even if configured", async () => {
|
||||
const t = createTestDb();
|
||||
setTargetDir(t.db, target);
|
||||
const svc = new BackupService(t.db);
|
||||
await svc.run("manual");
|
||||
const afterFirst = svc.status().lastSuccessAt;
|
||||
|
||||
await svc.runScheduled(); // not due yet — must not run again
|
||||
expect(svc.status().lastSuccessAt).toBe(afterFirst);
|
||||
t.close();
|
||||
});
|
||||
});
|
||||
@@ -0,0 +1,222 @@
|
||||
import { constants } from "node:fs";
|
||||
import { access, stat } from "node:fs/promises";
|
||||
import { resolve } from "node:path";
|
||||
import { eq, siteConfig, type Db } from "@parking/db";
|
||||
import type { FastifyBaseLogger } from "fastify";
|
||||
import { DEFAULT_BACKUP_RETENTION, runBackup, type BackupResult, type BackupRetention } from "./backup.js";
|
||||
|
||||
// Thin coordinator around the backup engine (backup.ts). The TARGET DIRECTORY is admin-chosen
|
||||
// and stored in site_config.backup_target_dir (read fresh each run, so changing it in the UI
|
||||
// takes effect with no restart). The ENCRYPTION KEY stays an env/Komodo secret (BACKUP_KEY) —
|
||||
// a key must never live in the DB it backs up. Remembers the last outcome so the route + UI can
|
||||
// show last-success / last-error, and serializes concurrent runs (manual + timer). See
|
||||
// wiki/concepts/backup-recovery.md.
|
||||
//
|
||||
// Last-success/last-error are PERSISTED to site_config (backup_last_*), not just held in
|
||||
// memory — an earlier version tracked these as plain in-process fields only, so every server
|
||||
// restart (deploy, crash, OOM, host reboot — all routine under `restart: always`) silently
|
||||
// reset the admin UI to "last successful backup: Never", even with valid, correctly-rotating
|
||||
// backups already on disk (2026-08-30 field incident, park-buzi). See wiki/concepts/backup-recovery.md.
|
||||
|
||||
/** The dedicated backup-encryption key, from env (NOT the DB). Separate from EVENT_SIGNING_KEY. */
|
||||
export function backupKeyFromEnv(): string {
|
||||
return process.env.BACKUP_KEY ?? "";
|
||||
}
|
||||
|
||||
export interface TargetCheck {
|
||||
readonly ok: boolean;
|
||||
/** Machine-readable reason when !ok: "empty" | "missing" | "not_a_dir" | "not_writable". */
|
||||
readonly reason?: string;
|
||||
}
|
||||
|
||||
export interface BackupStatus {
|
||||
/** True once a target dir is set AND a usable key is present (else backups are a no-op). */
|
||||
readonly configured: boolean;
|
||||
/** The admin-chosen target dir (null if unset) — surfaced so the UI can show/edit it. */
|
||||
readonly targetDir: string | null;
|
||||
/** Admin-tuned retention (resolved: DB value or code default) — surfaced for the UI form. */
|
||||
readonly keepLast: number;
|
||||
readonly keepDailyDays: number;
|
||||
/** Whether the env key is present + long enough (the UI flags a missing key distinctly). */
|
||||
readonly keyPresent: boolean;
|
||||
readonly running: boolean;
|
||||
readonly lastSuccessAt: string | null;
|
||||
readonly lastResult: { path: string; bytes: number; prunedFiles: number } | null;
|
||||
readonly lastErrorAt: string | null;
|
||||
readonly lastError: string | null;
|
||||
}
|
||||
|
||||
/** Probe a candidate target path server-side: exists, is a directory, is writable. */
|
||||
export async function checkTargetDir(dir: string): Promise<TargetCheck> {
|
||||
const trimmed = dir.trim();
|
||||
if (!trimmed) return { ok: false, reason: "empty" };
|
||||
const path = resolve(trimmed);
|
||||
let st: Awaited<ReturnType<typeof stat>>;
|
||||
try {
|
||||
st = await stat(path);
|
||||
} catch {
|
||||
return { ok: false, reason: "missing" };
|
||||
}
|
||||
if (!st.isDirectory()) return { ok: false, reason: "not_a_dir" };
|
||||
try {
|
||||
await access(path, constants.W_OK);
|
||||
} catch {
|
||||
return { ok: false, reason: "not_writable" };
|
||||
}
|
||||
return { ok: true };
|
||||
}
|
||||
|
||||
export class BackupService {
|
||||
readonly #db: Db;
|
||||
readonly #logger?: FastifyBaseLogger;
|
||||
|
||||
#running = false;
|
||||
|
||||
constructor(db: Db, logger?: FastifyBaseLogger) {
|
||||
this.#db = db;
|
||||
this.#logger = logger;
|
||||
}
|
||||
|
||||
/** Fresh read of the persisted row (single source of truth — no in-memory cache to go stale
|
||||
* or reset on restart). */
|
||||
#row(): { backupLastSuccessAt: string | null; backupLastResultJson: string | null; backupLastErrorAt: string | null; backupLastError: string | null } | undefined {
|
||||
return this.#db.select().from(siteConfig).where(eq(siteConfig.id, 1)).get();
|
||||
}
|
||||
|
||||
#persist(patch: {
|
||||
backupLastSuccessAt?: string | null;
|
||||
backupLastResultJson?: string | null;
|
||||
backupLastErrorAt?: string | null;
|
||||
backupLastError?: string | null;
|
||||
}): void {
|
||||
const updatedAt = new Date().toISOString();
|
||||
const existing = this.#row();
|
||||
if (existing) {
|
||||
this.#db.update(siteConfig).set({ ...patch, updatedAt }).where(eq(siteConfig.id, 1)).run();
|
||||
} else {
|
||||
this.#db.insert(siteConfig).values({ id: 1, ...patch, updatedAt }).run();
|
||||
}
|
||||
}
|
||||
|
||||
/** The admin-chosen target dir from site_config (null/empty = unset). Read fresh each call. */
|
||||
targetDir(): string | null {
|
||||
const row = this.#db.select().from(siteConfig).where(eq(siteConfig.id, 1)).get();
|
||||
const dir = row?.backupTargetDir?.trim();
|
||||
return dir ? dir : null;
|
||||
}
|
||||
|
||||
/** Resolved retention from site_config, falling back to the code default per field. Read fresh. */
|
||||
retention(): BackupRetention {
|
||||
const row = this.#db.select().from(siteConfig).where(eq(siteConfig.id, 1)).get();
|
||||
const keepLast = row?.backupKeepLast;
|
||||
const keepDailyDays = row?.backupKeepDailyDays;
|
||||
return {
|
||||
keepLast: keepLast != null && keepLast >= 0 ? keepLast : DEFAULT_BACKUP_RETENTION.keepLast,
|
||||
keepDailyDays:
|
||||
keepDailyDays != null && keepDailyDays >= 0 ? keepDailyDays : DEFAULT_BACKUP_RETENTION.keepDailyDays,
|
||||
};
|
||||
}
|
||||
|
||||
get keyPresent(): boolean {
|
||||
return backupKeyFromEnv().length >= 16;
|
||||
}
|
||||
|
||||
get configured(): boolean {
|
||||
return this.targetDir() !== null && this.keyPresent;
|
||||
}
|
||||
|
||||
status(): BackupStatus {
|
||||
const r = this.retention();
|
||||
const row = this.#row();
|
||||
let lastResult: BackupStatus["lastResult"] = null;
|
||||
if (row?.backupLastResultJson) {
|
||||
try {
|
||||
lastResult = JSON.parse(row.backupLastResultJson) as BackupStatus["lastResult"];
|
||||
} catch {
|
||||
lastResult = null; // corrupt/foreign value in the column — don't let it crash status()
|
||||
}
|
||||
}
|
||||
return {
|
||||
configured: this.configured,
|
||||
targetDir: this.targetDir(),
|
||||
keepLast: r.keepLast,
|
||||
keepDailyDays: r.keepDailyDays,
|
||||
keyPresent: this.keyPresent,
|
||||
running: this.#running,
|
||||
lastSuccessAt: row?.backupLastSuccessAt ?? null,
|
||||
lastResult,
|
||||
lastErrorAt: row?.backupLastErrorAt ?? null,
|
||||
lastError: row?.backupLastError ?? null,
|
||||
};
|
||||
}
|
||||
|
||||
/**
|
||||
* Run one backup. `trigger` is just for the log line. Serialized: if one is already in
|
||||
* flight, resolves to that same promise. Reads the target dir + key at run time. Records
|
||||
* last-success/last-error. Re-throws on failure so a manual caller (the route) can surface
|
||||
* it; the scheduled timer wraps + swallows.
|
||||
*/
|
||||
#inflight: Promise<BackupResult> | null = null;
|
||||
async run(trigger: "manual" | "scheduled"): Promise<BackupResult> {
|
||||
if (this.#inflight) return this.#inflight;
|
||||
const targetDir = this.targetDir();
|
||||
const key = backupKeyFromEnv();
|
||||
if (!targetDir) throw new Error("backup: no target directory configured");
|
||||
if (key.length < 16) throw new Error("backup: BACKUP_KEY missing or too short (need ≥16 chars)");
|
||||
|
||||
this.#running = true;
|
||||
this.#inflight = (async () => {
|
||||
try {
|
||||
this.#logger?.info(`backup: starting (${trigger}) → ${targetDir}`);
|
||||
const res = await runBackup(this.#db, { targetDir, key, retention: this.retention() }, this.#logger);
|
||||
this.#persist({
|
||||
backupLastSuccessAt: new Date().toISOString(),
|
||||
backupLastResultJson: JSON.stringify({ path: res.path, bytes: res.bytes, prunedFiles: res.prunedFiles }),
|
||||
backupLastErrorAt: null,
|
||||
backupLastError: null,
|
||||
});
|
||||
return res;
|
||||
} catch (err) {
|
||||
const message = (err as Error).message;
|
||||
this.#persist({ backupLastErrorAt: new Date().toISOString(), backupLastError: message });
|
||||
this.#logger?.error(`backup: failed (${trigger}): ${message}`);
|
||||
throw err;
|
||||
} finally {
|
||||
this.#running = false;
|
||||
this.#inflight = null;
|
||||
}
|
||||
})();
|
||||
return this.#inflight;
|
||||
}
|
||||
|
||||
/**
|
||||
* Scheduled-run wrapper: never throws (a timer must not crash the process). Safe to call on
|
||||
* a short, frequent poll (see server.ts) — it's a no-op unless `isDue()` says a full interval
|
||||
* has actually elapsed since the last recorded success, so frequent polling doesn't cause
|
||||
* frequent backups.
|
||||
*/
|
||||
async runScheduled(): Promise<void> {
|
||||
if (!this.configured) return; // silent no-op when backups aren't set up
|
||||
if (!this.isDue()) return;
|
||||
try {
|
||||
await this.run("scheduled");
|
||||
} catch {
|
||||
/* recorded in last-error; already logged */
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Wall-clock check: has enough time elapsed since the last successful backup for a new one
|
||||
* to be due? Deliberately based on the PERSISTED last-success instant, not "time since this
|
||||
* process started" — a `setInterval(..., 24h)` measured from process start silently drifts
|
||||
* (or skips a whole day) across every restart, since the countdown restarts from zero each
|
||||
* time regardless of when the last real backup happened. See wiki/concepts/backup-recovery.md.
|
||||
*/
|
||||
isDue(now: Date = new Date(), intervalMs = 24 * 60 * 60 * 1000): boolean {
|
||||
const lastSuccessAt = this.#row()?.backupLastSuccessAt;
|
||||
if (!lastSuccessAt) return true; // never recorded a success → due immediately once configured
|
||||
const last = new Date(lastSuccessAt).getTime();
|
||||
if (Number.isNaN(last)) return true;
|
||||
return now.getTime() - last >= intervalMs;
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,197 @@
|
||||
import { createCipheriv, createDecipheriv, randomBytes, scryptSync } from "node:crypto";
|
||||
import { mkdirSync, mkdtempSync, readdirSync, readFileSync, rmSync, writeFileSync } from "node:fs";
|
||||
import { tmpdir } from "node:os";
|
||||
import { join } from "node:path";
|
||||
import { createTestDb, openRawDb } from "@parking/db/testing";
|
||||
import { afterEach, beforeEach, describe, expect, it } from "vitest";
|
||||
import {
|
||||
DEFAULT_BACKUP_RETENTION,
|
||||
parseBackupStamp,
|
||||
pruneOldBackups,
|
||||
runBackup,
|
||||
} from "./backup.js";
|
||||
|
||||
// Mirror of the engine's header layout, so the test decrypts independently (a real restore
|
||||
// tool would do exactly this) rather than trusting the engine to also decrypt.
|
||||
const MAGIC = Buffer.from("PKBK", "ascii");
|
||||
const SALT_LEN = 16;
|
||||
const IV_LEN = 12;
|
||||
const TAG_LEN = 16;
|
||||
|
||||
function decryptBackup(enc: Buffer, key: string): Buffer {
|
||||
expect(enc.subarray(0, 4)).toEqual(MAGIC);
|
||||
expect(enc[4]).toBe(1); // format version
|
||||
let off = 5;
|
||||
const salt = enc.subarray(off, (off += SALT_LEN));
|
||||
const iv = enc.subarray(off, (off += IV_LEN));
|
||||
const tag = enc.subarray(enc.length - TAG_LEN);
|
||||
const ciphertext = enc.subarray(off, enc.length - TAG_LEN);
|
||||
const derived = scryptSync(key, salt, 32);
|
||||
const decipher = createDecipheriv("aes-256-gcm", derived, iv);
|
||||
decipher.setAuthTag(tag);
|
||||
return Buffer.concat([decipher.update(ciphertext), decipher.final()]);
|
||||
}
|
||||
|
||||
let workDir: string;
|
||||
const KEY = "a-test-backup-key-that-is-long-enough";
|
||||
|
||||
beforeEach(() => {
|
||||
workDir = mkdtempSync(join(tmpdir(), "pk-backup-test-"));
|
||||
});
|
||||
afterEach(() => {
|
||||
rmSync(workDir, { recursive: true, force: true });
|
||||
});
|
||||
|
||||
describe("runBackup — round-trip", () => {
|
||||
it("produces an encrypted backup that decrypts to a byte-identical, queryable DB", async () => {
|
||||
// A real on-disk DB so the engine's better-sqlite3 .backup() runs for real.
|
||||
const dbPath = join(workDir, "source.sqlite");
|
||||
const t = createTestDb(dbPath);
|
||||
// Put some recognizable data in.
|
||||
t.sqlite.exec("CREATE TABLE marker (k TEXT PRIMARY KEY, v TEXT)");
|
||||
t.sqlite.prepare("INSERT INTO marker (k, v) VALUES (?, ?)").run("hello", "world");
|
||||
|
||||
const targetDir = join(workDir, "target");
|
||||
const res = await runBackup(t.db, { targetDir, key: KEY });
|
||||
t.close();
|
||||
|
||||
expect(res.bytes).toBeGreaterThan(0);
|
||||
expect(res.path).toMatch(/parking-backup-\d{8}T\d{6}Z\.sqlite\.enc$/);
|
||||
|
||||
// Decrypt independently and open the recovered DB raw (no migrations — verify as-written).
|
||||
const plain = decryptBackup(readFileSync(res.path), KEY);
|
||||
const restoredPath = join(workDir, "restored.sqlite");
|
||||
writeFileSync(restoredPath, plain);
|
||||
const restored = openRawDb(restoredPath);
|
||||
const row = restored.prepare("SELECT v FROM marker WHERE k = ?").get("hello") as { v: string };
|
||||
expect(row.v).toBe("world");
|
||||
restored.close();
|
||||
});
|
||||
|
||||
it("rejects a missing/short key before touching the filesystem", async () => {
|
||||
const t = createTestDb();
|
||||
await expect(runBackup(t.db, { targetDir: join(workDir, "t"), key: "short" })).rejects.toThrow(
|
||||
/BACKUP_KEY/,
|
||||
);
|
||||
t.close();
|
||||
});
|
||||
|
||||
it("removes the plaintext scratch copy after a successful run", async () => {
|
||||
const scratchDir = join(workDir, "scratch");
|
||||
const t = createTestDb();
|
||||
await runBackup(t.db, {
|
||||
targetDir: join(workDir, "target"),
|
||||
key: KEY,
|
||||
scratchDir,
|
||||
// Stub the copy so we don't need a file-backed handle here.
|
||||
makeConsistentCopy: async (_db, dest) => writeFileSync(dest, "PRAGMA;"),
|
||||
});
|
||||
t.close();
|
||||
// The only thing left in scratch must NOT be a .sqlite plaintext.
|
||||
const left = readdirSync(scratchDir).filter((n) => n.endsWith(".sqlite"));
|
||||
expect(left).toEqual([]);
|
||||
});
|
||||
|
||||
it("wipes the plaintext scratch copy even when the copy step fails", async () => {
|
||||
const scratchDir = join(workDir, "scratch");
|
||||
mkdirSync(scratchDir, { recursive: true });
|
||||
const t = createTestDb();
|
||||
// Force a failure: the copy step writes the plaintext, then throws (mid-pipeline). The
|
||||
// finally{} must still remove the plaintext it left behind.
|
||||
await expect(
|
||||
runBackup(t.db, {
|
||||
targetDir: join(workDir, "target"),
|
||||
key: KEY,
|
||||
scratchDir,
|
||||
makeConsistentCopy: async (_db, dest) => {
|
||||
writeFileSync(dest, "PRAGMA;"); // leave a plaintext intermediate…
|
||||
throw new Error("simulated copy failure"); // …then fail
|
||||
},
|
||||
}),
|
||||
).rejects.toThrow(/simulated copy failure/);
|
||||
t.close();
|
||||
const left = readdirSync(scratchDir).filter((n) => n.endsWith(".sqlite"));
|
||||
expect(left).toEqual([]);
|
||||
});
|
||||
});
|
||||
|
||||
describe("backup encryption — tamper evidence (AES-256-GCM)", () => {
|
||||
it("a flipped ciphertext byte fails authentication on decrypt", async () => {
|
||||
const t = createTestDb();
|
||||
const targetDir = join(workDir, "target");
|
||||
const res = await runBackup(t.db, {
|
||||
targetDir,
|
||||
key: KEY,
|
||||
makeConsistentCopy: async (_db, dest) => writeFileSync(dest, "the quick brown fox".repeat(100)),
|
||||
});
|
||||
t.close();
|
||||
|
||||
const enc = readFileSync(res.path);
|
||||
// Flip a byte in the ciphertext region (after the header, before the tag).
|
||||
enc[5 + SALT_LEN + IV_LEN + 3] ^= 0xff;
|
||||
expect(() => decryptBackup(enc, KEY)).toThrow();
|
||||
});
|
||||
|
||||
it("the wrong key fails authentication", async () => {
|
||||
const t = createTestDb();
|
||||
const res = await runBackup(t.db, {
|
||||
targetDir: join(workDir, "target"),
|
||||
key: KEY,
|
||||
makeConsistentCopy: async (_db, dest) => writeFileSync(dest, "payload".repeat(50)),
|
||||
});
|
||||
t.close();
|
||||
expect(() => decryptBackup(readFileSync(res.path), "a-different-but-also-long-key-xx")).toThrow();
|
||||
});
|
||||
});
|
||||
|
||||
describe("parseBackupStamp", () => {
|
||||
it("round-trips a stamped name and rejects non-backups", () => {
|
||||
const d = parseBackupStamp("parking-backup-20260629T141503Z.sqlite.enc");
|
||||
expect(d?.toISOString()).toBe("2026-06-29T14:15:03.000Z");
|
||||
expect(parseBackupStamp("random.txt")).toBeNull();
|
||||
expect(parseBackupStamp("parking-backup-not-a-date.sqlite.enc")).toBeNull();
|
||||
});
|
||||
});
|
||||
|
||||
describe("pruneOldBackups — keep-last-N + dailies", () => {
|
||||
const day = 24 * 60 * 60 * 1000;
|
||||
const now = new Date("2026-06-29T12:00:00Z");
|
||||
|
||||
function seed(stamps: string[]) {
|
||||
const dir = join(workDir, "retain");
|
||||
mkdirSync(dir, { recursive: true });
|
||||
for (const s of stamps) writeFileSync(join(dir, `parking-backup-${s}.sqlite.enc`), "x");
|
||||
return dir;
|
||||
}
|
||||
const stamp = (ms: number) =>
|
||||
new Date(ms).toISOString().replace(/[-:]/g, "").replace(/\.\d{3}Z$/, "Z");
|
||||
|
||||
it("keeps the keepLast newest regardless of age", async () => {
|
||||
// 5 backups within the last hour; keepLast=3 → 2 pruned, even though all are recent.
|
||||
const t = now.getTime();
|
||||
const dir = seed([0, 1, 2, 3, 4].map((i) => stamp(t - i * 60 * 1000)));
|
||||
const pruned = await pruneOldBackups(dir, { keepLast: 3, keepDailyDays: 0 }, now);
|
||||
expect(pruned).toBe(2);
|
||||
expect(readdirSync(dir).length).toBe(3);
|
||||
});
|
||||
|
||||
it("keeps one-per-day within the daily window and drops older", async () => {
|
||||
const t = now.getTime();
|
||||
// Two backups today, one 5 days ago, one 40 days ago. keepLast=1, keepDailyDays=30.
|
||||
const dir = seed([
|
||||
stamp(t), // today A (newest → kept by keepLast)
|
||||
stamp(t - 60 * 1000), // today B (same day as the kept one → pruned)
|
||||
stamp(t - 5 * day), // 5 days ago (kept: within window, unique day)
|
||||
stamp(t - 40 * day), // 40 days ago (pruned: outside the window)
|
||||
]);
|
||||
const pruned = await pruneOldBackups(dir, { keepLast: 1, keepDailyDays: 30 }, now);
|
||||
expect(pruned).toBe(2);
|
||||
const left = readdirSync(dir);
|
||||
expect(left.length).toBe(2);
|
||||
});
|
||||
|
||||
it("is a no-op on a missing target dir", async () => {
|
||||
const pruned = await pruneOldBackups(join(workDir, "does-not-exist"), DEFAULT_BACKUP_RETENTION, now);
|
||||
expect(pruned).toBe(0);
|
||||
});
|
||||
});
|
||||
@@ -0,0 +1,217 @@
|
||||
import { createCipheriv, randomBytes, scryptSync } from "node:crypto";
|
||||
import { createReadStream, createWriteStream } from "node:fs";
|
||||
import { mkdir, readdir, rm, stat } from "node:fs/promises";
|
||||
import { tmpdir } from "node:os";
|
||||
import { basename, join, resolve } from "node:path";
|
||||
import { pipeline } from "node:stream/promises";
|
||||
import type { Db } from "@parking/db";
|
||||
import type { FastifyBaseLogger } from "fastify";
|
||||
|
||||
// On-site encrypted DB backup — the durability half of the anti-fraud design. The SQLite
|
||||
// DB *is* the signed append-only ledger, so a disk failure / stolen-or-destroyed PC means
|
||||
// total revenue-history loss. This produces a consistent, encrypted, restore-to-a-fresh-
|
||||
// appliance copy. See wiki/concepts/backup-recovery.md.
|
||||
//
|
||||
// Two load-bearing properties:
|
||||
// 1. CONSISTENT copy of a LIVE WAL-mode DB — via better-sqlite3's online .backup() (NOT a
|
||||
// raw file copy, which can capture a torn WAL). The result must still verifyChain.
|
||||
// 2. Encrypted with a DEDICATED key (BACKUP_KEY / park_buzi_backup_key), SEPARATE from
|
||||
// EVENT_SIGNING_KEY — so the backup key can rotate without fracturing the signed chain,
|
||||
// and a backup target never exposes the signing key. The key is NEVER written into the
|
||||
// backup it unlocks.
|
||||
//
|
||||
// This module is the engine (consistent copy → encrypt → retention). Targets beyond a local/
|
||||
// mounted path (SMB/NFS are just mount paths; SFTP) and the manual button/route are layered on
|
||||
// top. RESTORE is intentionally NOT here — it's an out-of-band runbook action on a fresh box.
|
||||
|
||||
/** AES-256-GCM with a scrypt-derived key. Self-describing header so a restore tool needs only
|
||||
* the key + the file. Layout: magic | version | salt(16) | iv(12) | ciphertext… | authTag(16). */
|
||||
const MAGIC = Buffer.from("PKBK", "ascii"); // ParKing BacKup
|
||||
const FORMAT_VERSION = 1;
|
||||
const SALT_LEN = 16;
|
||||
const IV_LEN = 12;
|
||||
const TAG_LEN = 16;
|
||||
const SCRYPT_KEYLEN = 32; // AES-256
|
||||
|
||||
export interface BackupRetention {
|
||||
/** Keep at least this many most-recent backups regardless of age. */
|
||||
readonly keepLast: number;
|
||||
/** Beyond keepLast, keep one backup per day for this many days; older ones are pruned. */
|
||||
readonly keepDailyDays: number;
|
||||
}
|
||||
|
||||
// Code defaults — the fallback when the admin hasn't set a value in site_config (the source of
|
||||
// truth). NOT env-driven: retention is operational policy tuned from the Backup screen.
|
||||
export const DEFAULT_BACKUP_RETENTION: BackupRetention = {
|
||||
keepLast: 7,
|
||||
keepDailyDays: 30,
|
||||
};
|
||||
|
||||
export interface BackupOptions {
|
||||
/** Directory the encrypted backup is written to (a mounted local/USB/SATA/SMB/NFS path). */
|
||||
readonly targetDir: string;
|
||||
/** Encryption key (BACKUP_KEY / park_buzi_backup_key). ≥16 chars enforced. */
|
||||
readonly key: string;
|
||||
readonly retention?: BackupRetention;
|
||||
/** Override the consistent-copy step (tests inject a fake to avoid a real sqlite handle). */
|
||||
readonly makeConsistentCopy?: (db: Db, destPath: string) => Promise<void>;
|
||||
/** Override "now" for deterministic filenames/retention in tests. */
|
||||
readonly now?: () => Date;
|
||||
/** Scratch dir for the intermediate plaintext copy (default os.tmpdir()). */
|
||||
readonly scratchDir?: string;
|
||||
}
|
||||
|
||||
export interface BackupResult {
|
||||
/** Absolute path of the encrypted backup written. */
|
||||
readonly path: string;
|
||||
/** Size of the encrypted file in bytes. */
|
||||
readonly bytes: number;
|
||||
/** Backups pruned by the retention policy this run. */
|
||||
readonly prunedFiles: number;
|
||||
}
|
||||
|
||||
/** Filename convention: parking-backup-YYYYMMDDTHHMMSSZ.sqlite.enc — sortable, UTC, parseable. */
|
||||
const FILE_PREFIX = "parking-backup-";
|
||||
const FILE_SUFFIX = ".sqlite.enc";
|
||||
|
||||
function stampFor(d: Date): string {
|
||||
return d.toISOString().replace(/[-:]/g, "").replace(/\.\d{3}Z$/, "Z");
|
||||
}
|
||||
|
||||
/** Parse the UTC instant back out of a backup filename, or null if it doesn't match. */
|
||||
export function parseBackupStamp(name: string): Date | null {
|
||||
const base = basename(name);
|
||||
if (!base.startsWith(FILE_PREFIX) || !base.endsWith(FILE_SUFFIX)) return null;
|
||||
const stamp = base.slice(FILE_PREFIX.length, -FILE_SUFFIX.length);
|
||||
// 20260629T141503Z → 2026-06-29T14:15:03Z
|
||||
const m = /^(\d{4})(\d{2})(\d{2})T(\d{2})(\d{2})(\d{2})Z$/.exec(stamp);
|
||||
if (!m) return null;
|
||||
const iso = `${m[1]}-${m[2]}-${m[3]}T${m[4]}:${m[5]}:${m[6]}Z`;
|
||||
const dt = new Date(iso);
|
||||
return Number.isNaN(dt.getTime()) ? null : dt;
|
||||
}
|
||||
|
||||
/** Consistent online copy of the live WAL-mode DB via better-sqlite3's native backup(). */
|
||||
async function defaultConsistentCopy(db: Db, destPath: string): Promise<void> {
|
||||
// db.$client is the raw better-sqlite3 Database; .backup() returns a promise and copies a
|
||||
// transactionally-consistent snapshot even while the source is being written.
|
||||
const client = db.$client as { backup: (dest: string) => Promise<unknown> };
|
||||
await client.backup(destPath);
|
||||
}
|
||||
|
||||
/** Encrypt `srcPath` → `destPath` streaming, with the self-describing header. */
|
||||
async function encryptFile(srcPath: string, destPath: string, key: string): Promise<void> {
|
||||
const salt = randomBytes(SALT_LEN);
|
||||
const iv = randomBytes(IV_LEN);
|
||||
const derived = scryptSync(key, salt, SCRYPT_KEYLEN);
|
||||
const cipher = createCipheriv("aes-256-gcm", derived, iv);
|
||||
|
||||
const out = createWriteStream(destPath);
|
||||
const header = Buffer.concat([MAGIC, Buffer.from([FORMAT_VERSION]), salt, iv]);
|
||||
out.write(header);
|
||||
|
||||
await pipeline(createReadStream(srcPath), cipher, out, { end: false });
|
||||
// GCM auth tag is available only after the cipher has flushed; append it, then close.
|
||||
const tag = cipher.getAuthTag();
|
||||
await new Promise<void>((res, rej) => {
|
||||
out.end(tag, () => res());
|
||||
out.on("error", rej);
|
||||
});
|
||||
}
|
||||
|
||||
/**
|
||||
* Run one backup: consistent copy → encrypt → prune old backups by retention.
|
||||
* Best-effort caller-facing: throws on real failure (so a manual run surfaces the error),
|
||||
* but the scheduled timer wraps it and logs.
|
||||
*/
|
||||
export async function runBackup(
|
||||
db: Db,
|
||||
opts: BackupOptions,
|
||||
logger?: FastifyBaseLogger,
|
||||
): Promise<BackupResult> {
|
||||
if (!opts.key || opts.key.length < 16) {
|
||||
throw new Error("backup: BACKUP_KEY missing or too short (need ≥16 chars)");
|
||||
}
|
||||
const now = opts.now ?? (() => new Date());
|
||||
const retention = opts.retention ?? DEFAULT_BACKUP_RETENTION;
|
||||
const targetDir = resolve(opts.targetDir);
|
||||
await mkdir(targetDir, { recursive: true });
|
||||
|
||||
const stamp = stampFor(now());
|
||||
const finalPath = join(targetDir, `${FILE_PREFIX}${stamp}${FILE_SUFFIX}`);
|
||||
|
||||
// Intermediate plaintext copy in scratch (NOT the target dir — the target may be a network
|
||||
// share / removable disk; keep the plaintext local and short-lived, then wipe it).
|
||||
const scratch = opts.scratchDir ?? tmpdir();
|
||||
await mkdir(scratch, { recursive: true });
|
||||
const plainPath = join(scratch, `${FILE_PREFIX}${stamp}.sqlite`);
|
||||
|
||||
try {
|
||||
const copy = opts.makeConsistentCopy ?? defaultConsistentCopy;
|
||||
await copy(db, plainPath);
|
||||
await encryptFile(plainPath, finalPath, opts.key);
|
||||
} finally {
|
||||
// Always wipe the plaintext intermediate, success or fail — it's the unencrypted ledger.
|
||||
await rm(plainPath, { force: true }).catch((err) =>
|
||||
logger?.warn(`backup: failed to remove plaintext scratch copy: ${(err as Error).message}`),
|
||||
);
|
||||
}
|
||||
|
||||
const { size } = await stat(finalPath);
|
||||
const prunedFiles = await pruneOldBackups(targetDir, retention, now());
|
||||
logger?.info(
|
||||
`backup: wrote ${basename(finalPath)} (${(size / 1048576).toFixed(1)} MB)` +
|
||||
(prunedFiles > 0 ? `, pruned ${prunedFiles} old` : ""),
|
||||
);
|
||||
return { path: finalPath, bytes: size, prunedFiles };
|
||||
}
|
||||
|
||||
/**
|
||||
* Retention: keep the `keepLast` most-recent backups always; beyond those, keep at most one
|
||||
* backup per UTC day for `keepDailyDays` days; delete anything older or any extra same-day
|
||||
* duplicates outside the keepLast window. Returns the count deleted.
|
||||
*/
|
||||
export async function pruneOldBackups(
|
||||
targetDir: string,
|
||||
retention: BackupRetention,
|
||||
now: Date,
|
||||
): Promise<number> {
|
||||
let names: string[];
|
||||
try {
|
||||
names = await readdir(targetDir);
|
||||
} catch {
|
||||
return 0; // target gone/unmounted — nothing to prune (the write would have failed first)
|
||||
}
|
||||
|
||||
const backups = names
|
||||
.map((n) => ({ name: n, at: parseBackupStamp(n) }))
|
||||
.filter((b): b is { name: string; at: Date } => b.at !== null)
|
||||
.sort((a, b) => b.at.getTime() - a.at.getTime()); // newest first
|
||||
|
||||
const keep = new Set<string>();
|
||||
// 1. Always keep the keepLast newest.
|
||||
for (const b of backups.slice(0, Math.max(0, retention.keepLast))) keep.add(b.name);
|
||||
|
||||
// 2. Beyond that, keep the newest per UTC day within the keepDailyDays window.
|
||||
const cutoff = now.getTime() - retention.keepDailyDays * 24 * 60 * 60 * 1000;
|
||||
const seenDays = new Set<string>();
|
||||
for (const b of backups) {
|
||||
if (keep.has(b.name)) {
|
||||
seenDays.add(b.at.toISOString().slice(0, 10));
|
||||
continue;
|
||||
}
|
||||
if (b.at.getTime() < cutoff) continue; // too old → not kept
|
||||
const day = b.at.toISOString().slice(0, 10);
|
||||
if (seenDays.has(day)) continue; // already have a backup for this day → prune the extra
|
||||
seenDays.add(day);
|
||||
keep.add(b.name);
|
||||
}
|
||||
|
||||
let pruned = 0;
|
||||
for (const b of backups) {
|
||||
if (keep.has(b.name)) continue;
|
||||
await rm(join(targetDir, b.name), { force: true });
|
||||
pruned += 1;
|
||||
}
|
||||
return pruned;
|
||||
}
|
||||
@@ -1,12 +1,12 @@
|
||||
import { eq, ledgerEvents, siteConfig, type Db } from "@parking/db";
|
||||
import {
|
||||
formatStampSq,
|
||||
printWithFailover,
|
||||
registry,
|
||||
type PrinterDevice,
|
||||
type PrinterInstance,
|
||||
type ReceiptData,
|
||||
type TicketHeader,
|
||||
printerRoleOf,
|
||||
} from "@parking/devices";
|
||||
import type { FastifyBaseLogger } from "fastify";
|
||||
import { devicesByDirection } from "./device-resolve.js";
|
||||
@@ -42,7 +42,7 @@ function loadPrinters(db: Db): PrinterInstance[] {
|
||||
const driver = registry.get(row.driverId);
|
||||
if (!driver) continue;
|
||||
const cfg = row.config as Record<string, unknown>;
|
||||
const role = cfg.role === "booth-receipt" ? "booth-receipt" : "entry-dispenser";
|
||||
const role = printerRoleOf(cfg);
|
||||
try {
|
||||
out.push({
|
||||
id: row.id,
|
||||
@@ -81,6 +81,8 @@ function receiptFigures(
|
||||
currency?: string;
|
||||
tender?: "cash" | "card";
|
||||
graceExitMin?: number;
|
||||
grossMinor?: number;
|
||||
validationLines?: { label: string; discountMinor: number }[];
|
||||
};
|
||||
return {
|
||||
ticketId,
|
||||
@@ -90,6 +92,9 @@ function receiptFigures(
|
||||
currency: p.currency ?? "ALL",
|
||||
tender: p.tender === "card" ? "card" : "cash",
|
||||
graceExitMin: typeof p.graceExitMin === "number" ? p.graceExitMin : null,
|
||||
// Merchant validations, as settled on the signed payment (gross → lines → net).
|
||||
grossMinor: typeof p.grossMinor === "number" ? p.grossMinor : null,
|
||||
validationLines: Array.isArray(p.validationLines) ? p.validationLines : undefined,
|
||||
};
|
||||
}
|
||||
|
||||
@@ -166,26 +171,19 @@ export async function printSubscriptionCard(
|
||||
*/
|
||||
export async function printWindowChargeNotice(
|
||||
db: Db,
|
||||
notice: { occurrenceId: string; holderName?: string | null; at: string; windowOpensMin?: number; edge: "entry" | "exit" },
|
||||
notice: { occurrenceId: string; holderName?: string | null; at: string; windowOpensMin?: number | null; edge: "entry" | "exit" },
|
||||
logger: FastifyBaseLogger,
|
||||
): Promise<string> {
|
||||
const printers = loadPrinters(db);
|
||||
const hhmm = (m?: number) =>
|
||||
m == null ? "" : `${String(Math.floor(m / 60)).padStart(2, "0")}:${String(m % 60).padStart(2, "0")}`;
|
||||
const lines = [
|
||||
`Abonent: ${notice.holderName || "-"}`,
|
||||
`${notice.edge === "entry" ? "Hyrje" : "Dalje"}: ${formatStampSq(notice.at)}`,
|
||||
notice.edge === "entry"
|
||||
? `Ka hyrë jashtë orarit${notice.windowOpensMin != null ? ` (orari hap ${hhmm(notice.windowOpensMin)})` : ""}`
|
||||
: "Ka dalë jashtë orarit",
|
||||
"",
|
||||
"⚠ Detyrim do të llogaritet në dalje",
|
||||
" (paguhet në kabinë para se të dilni)",
|
||||
"",
|
||||
`Nr: ${notice.occurrenceId}`,
|
||||
];
|
||||
const printedBy = await printWithFailover(printers, "booth-receipt", (d: PrinterDevice) =>
|
||||
d.printReport({ title: "PARKIM — JASHTË ORARIT", lines }),
|
||||
d.printWindowChargeNotice({
|
||||
occurrenceId: notice.occurrenceId,
|
||||
holderName: notice.holderName ?? null,
|
||||
at: notice.at,
|
||||
edge: notice.edge,
|
||||
windowOpensMin: notice.windowOpensMin ?? null,
|
||||
header: ticketHeader(db),
|
||||
}),
|
||||
);
|
||||
logger.info(`out-of-window notice printed for ${notice.occurrenceId} on ${printedBy}`);
|
||||
return printedBy;
|
||||
|
||||
@@ -0,0 +1,424 @@
|
||||
import { afterEach, beforeEach, describe, expect, it, vi } from "vitest";
|
||||
import { randomUUID } from "node:crypto";
|
||||
import { eq, devices, type Db } from "@parking/db";
|
||||
import { createTestDb } from "@parking/db/testing";
|
||||
import type { AuxOutputDevice } from "@parking/devices";
|
||||
import { ButtonLightController } from "./button-light.js";
|
||||
import { deviceEvents } from "./device-events.js";
|
||||
import { silentLogger } from "./test-helpers.js";
|
||||
|
||||
// ButtonLightController: alert (radarAlert) relays — the entry-button lamp on a spare
|
||||
// relay, driven by the lamp's trigger input vs. the camera lane status. Truth table:
|
||||
// trigger active + lane busy -> SOLID on
|
||||
// trigger active + lane free -> BLINK (~1 Hz)
|
||||
// otherwise -> OFF
|
||||
// Lamp is a non-barrier aux output; fails OFF; de-dupes redundant writes. A controller may
|
||||
// carry several alert relays (each its own row + trigger input), keyed independently.
|
||||
|
||||
let db: Db;
|
||||
const CONTROLLER = "ctl-1";
|
||||
const RADAR_INPUT = 2; // I2
|
||||
const LAMP_RELAY = 3; // spare relay R3
|
||||
|
||||
/** A fake aux device recording setAux calls (channel,on). Optionally throws. */
|
||||
function fakeAux(record: Array<{ ch: number; on: boolean }>, throwOnce = { v: false }): AuxOutputDevice {
|
||||
return {
|
||||
async setAux(channel: number, on: boolean): Promise<void> {
|
||||
if (throwOnce.v) {
|
||||
throwOnce.v = false;
|
||||
throw new Error("UDP down");
|
||||
}
|
||||
record.push({ ch: channel, on });
|
||||
},
|
||||
};
|
||||
}
|
||||
|
||||
beforeEach(() => {
|
||||
({ db } = createTestDb());
|
||||
vi.useFakeTimers();
|
||||
// One controller: entry relay 1 with radar on I2; lamp on spare relay 3.
|
||||
db.insert(devices).values({
|
||||
id: CONTROLLER,
|
||||
category: "access",
|
||||
driverId: "dingtian",
|
||||
config: {
|
||||
host: "10.0.0.5",
|
||||
relays: [
|
||||
{ relay: 1, direction: "entry", button: 1, presenceInput: RADAR_INPUT, presenceKind: "radar" },
|
||||
{ relay: 2, direction: "exit" },
|
||||
{ relay: LAMP_RELAY, direction: "radarAlert", triggerInput: RADAR_INPUT, blinkOnMs: 500, blinkOffMs: 500 },
|
||||
],
|
||||
},
|
||||
enabled: true,
|
||||
}).run();
|
||||
});
|
||||
afterEach(() => {
|
||||
vi.useRealTimers();
|
||||
});
|
||||
|
||||
/** Emit a radar (presence input) edge for the controller. */
|
||||
function radar(present: boolean): void {
|
||||
deviceEvents.emitInput({
|
||||
driverId: "dingtian",
|
||||
deviceId: CONTROLLER,
|
||||
input: RADAR_INPUT,
|
||||
edge: present ? "on" : "off",
|
||||
at: new Date().toISOString(),
|
||||
source: "poll",
|
||||
});
|
||||
}
|
||||
|
||||
/** Emit a lane status (entry busy/free). */
|
||||
function lane(entryBusy: boolean): void {
|
||||
deviceEvents.emitLaneStatus({ entry: entryBusy, exit: false });
|
||||
}
|
||||
|
||||
/** Flush the microtask queue so serialized setAux promises (and their re-pump on
|
||||
* completion) settle. The lamp worker sends ONE UDP at a time and re-pumps on resolve;
|
||||
* a few turns drain a burst. Needed because sends are now async (was synchronous). */
|
||||
async function flush(): Promise<void> {
|
||||
for (let i = 0; i < 6; i++) await Promise.resolve();
|
||||
}
|
||||
|
||||
describe("ButtonLightController truth table", () => {
|
||||
it("OFF at start (no radar, no car)", async () => {
|
||||
const calls: Array<{ ch: number; on: boolean }> = [];
|
||||
const ctl = new ButtonLightController(db, silentLogger(), () => fakeAux(calls));
|
||||
ctl.start();
|
||||
await flush();
|
||||
expect(ctl.stateOf(CONTROLLER)).toBe("off");
|
||||
// confirmedOn starts null; OFF de-dupes (null !== false → one off write), so the
|
||||
// device is confirmed OFF and at most one call was made.
|
||||
expect(ctl.confirmedOf(CONTROLLER)).toBe(false);
|
||||
ctl.stop();
|
||||
});
|
||||
|
||||
it("radar present + lane busy -> SOLID on", async () => {
|
||||
const calls: Array<{ ch: number; on: boolean }> = [];
|
||||
const aux = fakeAux(calls);
|
||||
const ctl = new ButtonLightController(db, silentLogger(), () => aux);
|
||||
ctl.start();
|
||||
await flush();
|
||||
lane(true);
|
||||
radar(true);
|
||||
await flush();
|
||||
expect(ctl.stateOf(CONTROLLER)).toBe("solid");
|
||||
expect(ctl.confirmedOf(CONTROLLER)).toBe(true); // device latched ON
|
||||
// Solid = no blinking: advancing time produces no further sends.
|
||||
const n = calls.length;
|
||||
vi.advanceTimersByTime(2000);
|
||||
await flush();
|
||||
expect(calls.length).toBe(n);
|
||||
ctl.stop();
|
||||
});
|
||||
|
||||
it("radar present + lane free -> BLINK (toggles the device over time)", async () => {
|
||||
const calls: Array<{ ch: number; on: boolean }> = [];
|
||||
const aux = fakeAux(calls);
|
||||
const ctl = new ButtonLightController(db, silentLogger(), () => aux);
|
||||
ctl.start();
|
||||
await flush();
|
||||
radar(true); // lane still free
|
||||
await flush();
|
||||
expect(ctl.stateOf(CONTROLLER)).toBe("blink");
|
||||
expect(ctl.confirmedOf(CONTROLLER)).toBe(true); // on now
|
||||
vi.advanceTimersByTime(500);
|
||||
await flush();
|
||||
expect(ctl.confirmedOf(CONTROLLER)).toBe(false); // toggled off
|
||||
vi.advanceTimersByTime(500);
|
||||
await flush();
|
||||
expect(ctl.confirmedOf(CONTROLLER)).toBe(true); // toggled on
|
||||
ctl.stop();
|
||||
});
|
||||
|
||||
it("blink -> solid when the camera confirms a car (lane busy)", async () => {
|
||||
const calls: Array<{ ch: number; on: boolean }> = [];
|
||||
const aux = fakeAux(calls);
|
||||
const ctl = new ButtonLightController(db, silentLogger(), () => aux);
|
||||
ctl.start();
|
||||
await flush();
|
||||
radar(true); // blink
|
||||
await flush();
|
||||
expect(ctl.stateOf(CONTROLLER)).toBe("blink");
|
||||
lane(true); // camera confirms
|
||||
await flush();
|
||||
expect(ctl.stateOf(CONTROLLER)).toBe("solid");
|
||||
expect(ctl.confirmedOf(CONTROLLER)).toBe(true);
|
||||
// No more toggles (blink torn down) — the device stays ON over time.
|
||||
vi.advanceTimersByTime(2000);
|
||||
await flush();
|
||||
expect(ctl.confirmedOf(CONTROLLER)).toBe(true);
|
||||
ctl.stop();
|
||||
});
|
||||
|
||||
it("radar clears -> OFF", async () => {
|
||||
const calls: Array<{ ch: number; on: boolean }> = [];
|
||||
const aux = fakeAux(calls);
|
||||
const ctl = new ButtonLightController(db, silentLogger(), () => aux);
|
||||
ctl.start();
|
||||
await flush();
|
||||
lane(true);
|
||||
radar(true); // solid
|
||||
await flush();
|
||||
radar(false); // car gone
|
||||
await flush();
|
||||
expect(ctl.stateOf(CONTROLLER)).toBe("off");
|
||||
expect(ctl.confirmedOf(CONTROLLER)).toBe(false); // device latched OFF
|
||||
ctl.stop();
|
||||
});
|
||||
|
||||
it("de-dupes redundant writes (no spam on repeat events)", async () => {
|
||||
const calls: Array<{ ch: number; on: boolean }> = [];
|
||||
const aux = fakeAux(calls);
|
||||
const ctl = new ButtonLightController(db, silentLogger(), () => aux);
|
||||
ctl.start();
|
||||
await flush();
|
||||
lane(true);
|
||||
radar(true); // solid, on
|
||||
await flush();
|
||||
const n = calls.length;
|
||||
radar(true); // same state — no new edge (present unchanged)
|
||||
lane(true); // same lane — no change
|
||||
await flush();
|
||||
expect(calls.length).toBe(n);
|
||||
ctl.stop();
|
||||
});
|
||||
|
||||
it("fails OFF: a setAux error does not throw or escalate", async () => {
|
||||
const calls: Array<{ ch: number; on: boolean }> = [];
|
||||
const throwOnce = { v: true };
|
||||
const aux = fakeAux(calls, throwOnce);
|
||||
const ctl = new ButtonLightController(db, silentLogger(), () => aux);
|
||||
// First write (initial off) throws — must be swallowed.
|
||||
expect(() => ctl.start()).not.toThrow();
|
||||
await flush();
|
||||
// The failure arms a backoff (1s) rather than retrying inline; desired-state
|
||||
// changes during the window just update the target the retry will assert.
|
||||
lane(true);
|
||||
radar(true);
|
||||
await flush();
|
||||
expect(ctl.confirmedOf(CONTROLLER)).toBeNull(); // still backing off
|
||||
await vi.advanceTimersByTimeAsync(1000); // retry fires; aux is healthy again
|
||||
expect(ctl.confirmedOf(CONTROLLER)).toBe(true); // converged to solid ON
|
||||
ctl.stop();
|
||||
});
|
||||
|
||||
it("an unreachable controller backs off (1s→30s), not a hot retry loop", async () => {
|
||||
let attempts = 0;
|
||||
const aux: AuxOutputDevice = {
|
||||
async setAux() {
|
||||
attempts += 1;
|
||||
throw new Error("send ENETUNREACH 10.0.10.5:60000");
|
||||
},
|
||||
};
|
||||
const errors: string[] = [];
|
||||
const logger = silentLogger();
|
||||
(logger as { error: (msg: string) => void }).error = (msg) => errors.push(msg);
|
||||
const ctl = new ButtonLightController(db, logger, () => aux);
|
||||
ctl.start(); // initial OFF write → attempt 1 fails at t=0
|
||||
await flush();
|
||||
expect(attempts).toBe(1); // the old code hot-looped here
|
||||
|
||||
// Failures at t≈0,1,3,7,15,31 (doubling, capped 30s) → 6 attempts in the first
|
||||
// minute instead of thousands.
|
||||
await vi.advanceTimersByTimeAsync(60_000);
|
||||
expect(attempts).toBeGreaterThanOrEqual(5);
|
||||
expect(attempts).toBeLessThanOrEqual(7);
|
||||
|
||||
// Only the FIRST failure was logged so far; the next log is a ≥60s summary.
|
||||
expect(errors).toHaveLength(1);
|
||||
await vi.advanceTimersByTimeAsync(35_000); // t≈95s → the t=61s attempt logged a summary
|
||||
expect(errors.length).toBe(2);
|
||||
expect(errors[1]).toContain("still failing");
|
||||
ctl.stop();
|
||||
});
|
||||
|
||||
it("logs a single recovery line and resets the backoff after success", async () => {
|
||||
let failing = true;
|
||||
let attempts = 0;
|
||||
const aux: AuxOutputDevice = {
|
||||
async setAux() {
|
||||
attempts += 1;
|
||||
if (failing) throw new Error("send ENETUNREACH 10.0.10.5:60000");
|
||||
},
|
||||
};
|
||||
const infos: string[] = [];
|
||||
const logger = silentLogger();
|
||||
(logger as { info: (msg: string) => void }).info = (msg) => infos.push(msg);
|
||||
const ctl = new ButtonLightController(db, logger, () => aux);
|
||||
ctl.start();
|
||||
await flush();
|
||||
await vi.advanceTimersByTimeAsync(3_000); // attempts at t=0,1,3 all fail
|
||||
const failed = attempts;
|
||||
expect(failed).toBeGreaterThanOrEqual(3);
|
||||
|
||||
failing = false; // controller reachable again
|
||||
await vi.advanceTimersByTimeAsync(8_000); // next armed retry succeeds
|
||||
expect(ctl.confirmedOf(CONTROLLER)).toBe(false); // OFF asserted on the device
|
||||
expect(infos.filter((m) => m.includes("recovered"))).toHaveLength(1);
|
||||
|
||||
// Backoff reset: a fresh state change sends immediately (no lingering retryAt).
|
||||
const before = attempts;
|
||||
lane(true);
|
||||
radar(true);
|
||||
await flush();
|
||||
expect(ctl.confirmedOf(CONTROLLER)).toBe(true);
|
||||
expect(attempts).toBe(before + 1);
|
||||
ctl.stop();
|
||||
});
|
||||
|
||||
it("ignores controllers without an alert relay", () => {
|
||||
// A second controller, no alert relay.
|
||||
db.insert(devices).values({
|
||||
id: "ctl-2",
|
||||
category: "access",
|
||||
driverId: "dingtian",
|
||||
config: { host: "10.0.0.6", relays: [{ relay: 1, direction: "entry", presenceInput: 2 }] },
|
||||
enabled: true,
|
||||
}).run();
|
||||
const calls: Array<{ ch: number; on: boolean }> = [];
|
||||
const ctl = new ButtonLightController(db, silentLogger(), () => fakeAux(calls));
|
||||
ctl.start();
|
||||
expect(ctl.stateOf("ctl-2")).toBeNull();
|
||||
ctl.stop();
|
||||
});
|
||||
|
||||
it("picks up an alert relay ADDED after start() (no restart needed)", async () => {
|
||||
// Fresh controller with a radar input but NO alert relay yet.
|
||||
const calls: Array<{ ch: number; on: boolean }> = [];
|
||||
const aux = fakeAux(calls);
|
||||
const ctl = new ButtonLightController(db, silentLogger(), () => aux);
|
||||
// Replace the seeded controller with one that has the radar but no lamp.
|
||||
db.update(devices)
|
||||
.set({
|
||||
config: {
|
||||
host: "10.0.0.5",
|
||||
relays: [{ relay: 1, direction: "entry", presenceInput: RADAR_INPUT, presenceKind: "radar" }],
|
||||
},
|
||||
})
|
||||
.where(eq(devices.id, CONTROLLER))
|
||||
.run();
|
||||
ctl.start();
|
||||
await flush();
|
||||
// No lamp configured → an input does nothing.
|
||||
radar(true);
|
||||
await flush();
|
||||
expect(ctl.stateOf(CONTROLLER)).toBeNull();
|
||||
expect(calls.length).toBe(0);
|
||||
radar(false);
|
||||
await flush();
|
||||
|
||||
// Admin saves an alert relay (relay 3, trigger I2) — without restarting the server.
|
||||
db.update(devices)
|
||||
.set({
|
||||
config: {
|
||||
host: "10.0.0.5",
|
||||
relays: [
|
||||
{ relay: 1, direction: "entry", presenceInput: RADAR_INPUT, presenceKind: "radar" },
|
||||
{ relay: LAMP_RELAY, direction: "radarAlert", triggerInput: RADAR_INPUT, blinkOnMs: 500, blinkOffMs: 500 },
|
||||
],
|
||||
},
|
||||
})
|
||||
.where(eq(devices.id, CONTROLLER))
|
||||
.run();
|
||||
|
||||
// The very next radar edge reconciles + blinks (lane still free).
|
||||
radar(true);
|
||||
await flush();
|
||||
expect(ctl.stateOf(CONTROLLER)).toBe("blink");
|
||||
expect(ctl.confirmedOf(CONTROLLER)).toBe(true);
|
||||
ctl.stop();
|
||||
});
|
||||
|
||||
it("drives two alert relays on one controller independently", async () => {
|
||||
const R3 = 3;
|
||||
const R4 = 4;
|
||||
const I2 = 2;
|
||||
const I3 = 3;
|
||||
// Controller with two alert lamps, each on its own trigger input.
|
||||
db.update(devices)
|
||||
.set({
|
||||
config: {
|
||||
host: "10.0.0.5",
|
||||
relays: [
|
||||
{ relay: 1, direction: "entry", presenceInput: I2, presenceKind: "radar" },
|
||||
{ relay: R3, direction: "radarAlert", triggerInput: I2, blinkOnMs: 500, blinkOffMs: 500 },
|
||||
{ relay: R4, direction: "radarAlert", triggerInput: I3, blinkOnMs: 500, blinkOffMs: 500 },
|
||||
],
|
||||
},
|
||||
})
|
||||
.where(eq(devices.id, CONTROLLER))
|
||||
.run();
|
||||
const calls: Array<{ ch: number; on: boolean }> = [];
|
||||
const aux = fakeAux(calls);
|
||||
const ctl = new ButtonLightController(db, silentLogger(), () => aux);
|
||||
ctl.start();
|
||||
await flush();
|
||||
expect(ctl.stateOf(CONTROLLER, R3)).toBe("off");
|
||||
expect(ctl.stateOf(CONTROLLER, R4)).toBe("off");
|
||||
|
||||
// I2 active → only R3 blinks; R4 stays off (different trigger).
|
||||
deviceEvents.emitInput({ driverId: "dingtian", deviceId: CONTROLLER, input: I2, edge: "on", at: new Date().toISOString(), source: "poll" });
|
||||
await flush();
|
||||
expect(ctl.stateOf(CONTROLLER, R3)).toBe("blink");
|
||||
expect(ctl.stateOf(CONTROLLER, R4)).toBe("off");
|
||||
|
||||
// I3 active → R4 blinks too, independently.
|
||||
deviceEvents.emitInput({ driverId: "dingtian", deviceId: CONTROLLER, input: I3, edge: "on", at: new Date().toISOString(), source: "poll" });
|
||||
await flush();
|
||||
expect(ctl.stateOf(CONTROLLER, R3)).toBe("blink");
|
||||
expect(ctl.stateOf(CONTROLLER, R4)).toBe("blink");
|
||||
|
||||
// Camera confirms a car → BOTH lock solid (lane-busy is site-wide).
|
||||
lane(true);
|
||||
await flush();
|
||||
expect(ctl.stateOf(CONTROLLER, R3)).toBe("solid");
|
||||
expect(ctl.stateOf(CONTROLLER, R4)).toBe("solid");
|
||||
|
||||
// I2 clears → R3 off, R4 still solid (its trigger still active).
|
||||
deviceEvents.emitInput({ driverId: "dingtian", deviceId: CONTROLLER, input: I2, edge: "off", at: new Date().toISOString(), source: "poll" });
|
||||
await flush();
|
||||
expect(ctl.stateOf(CONTROLLER, R3)).toBe("off");
|
||||
expect(ctl.stateOf(CONTROLLER, R4)).toBe("solid");
|
||||
ctl.stop();
|
||||
});
|
||||
|
||||
it("an EXIT alert lamp locks on the EXIT camera, not entry", async () => {
|
||||
const R4 = 4;
|
||||
const I5 = 5; // exit radar
|
||||
db.update(devices)
|
||||
.set({
|
||||
config: {
|
||||
host: "10.0.0.5",
|
||||
relays: [
|
||||
{ relay: 1, direction: "entry" },
|
||||
{ relay: 2, direction: "exit" },
|
||||
// Exit alert lamp: triggers on the exit radar, locks on the EXIT camera.
|
||||
{ relay: R4, direction: "radarAlert", triggerInput: I5, lockLane: "exit", blinkOnMs: 500, blinkOffMs: 500 },
|
||||
],
|
||||
},
|
||||
})
|
||||
.where(eq(devices.id, CONTROLLER))
|
||||
.run();
|
||||
const aux = fakeAux([]);
|
||||
const ctl = new ButtonLightController(db, silentLogger(), () => aux);
|
||||
ctl.start();
|
||||
await flush();
|
||||
|
||||
// Exit radar active → blink.
|
||||
deviceEvents.emitInput({ driverId: "dingtian", deviceId: CONTROLLER, input: I5, edge: "on", at: new Date().toISOString(), source: "poll" });
|
||||
await flush();
|
||||
expect(ctl.stateOf(CONTROLLER, R4)).toBe("blink");
|
||||
|
||||
// ENTRY camera busy must NOT lock this exit lamp — it still blinks.
|
||||
deviceEvents.emitLaneStatus({ entry: true, exit: false });
|
||||
await flush();
|
||||
expect(ctl.stateOf(CONTROLLER, R4)).toBe("blink");
|
||||
|
||||
// EXIT camera busy → SOLID.
|
||||
deviceEvents.emitLaneStatus({ entry: true, exit: true });
|
||||
await flush();
|
||||
expect(ctl.stateOf(CONTROLLER, R4)).toBe("solid");
|
||||
ctl.stop();
|
||||
});
|
||||
});
|
||||
@@ -0,0 +1,381 @@
|
||||
import { eq, devices, type Db, type DeviceRow } from "@parking/db";
|
||||
import type { FastifyBaseLogger } from "fastify";
|
||||
import { hasAuxOutput, registry, type AuxOutputDevice } from "@parking/devices";
|
||||
import { deviceEvents, type DeviceInputEvent, type LaneStatusEvent } from "./device-events.js";
|
||||
import { alertRelaysOf, relayForPresence, type RelaySpec } from "./device-resolve.js";
|
||||
|
||||
// Alert (radarAlert) relays — non-barrier indicator lamps, e.g. the entry button's 12 V
|
||||
// light. Each lamp is a `relays[]` row with event `radarAlert`, driven by ITS trigger
|
||||
// input vs. the camera "car in zone" signal (the advisory lane-status). A disagreement
|
||||
// indicator:
|
||||
// trigger active + lane busy (camera confirms a car) → SOLID on
|
||||
// trigger active + lane free (radar sees something, no car) → BLINK (~1 Hz)
|
||||
// otherwise → OFF
|
||||
// The lamp is a NON-barrier aux output (setAux latch), so holding/blinking it is fine
|
||||
// — barrier-not-a-door applies only to barriers, which still only pulseOpen. The lamp
|
||||
// FAILS OFF: any error / shutdown leaves it off, so a dead lamp is "no hint", never a
|
||||
// misleading solid "go". A controller may have several alert relays (each its own row +
|
||||
// trigger input), keyed independently. See wiki/concepts/button-light-indicator.md.
|
||||
|
||||
type LightState = "off" | "solid" | "blink";
|
||||
|
||||
const DEFAULT_BLINK_MS = 500;
|
||||
|
||||
// Failed-send retry backoff: 1s doubling to 30s, reset on success. Without this an
|
||||
// unreachable controller (ENETUNREACH) became a hot loop — the failure re-pump retried
|
||||
// instantly, thousands of sends + error lines per minute (field incident 2026-07-07).
|
||||
const RETRY_BASE_MS = 1_000;
|
||||
const RETRY_MAX_MS = 30_000;
|
||||
/** After the first failure of a streak, log at most one summary line per this window. */
|
||||
const FAIL_LOG_EVERY_MS = 60_000;
|
||||
|
||||
/** Per-lamp live state for the alert rule (one per radarAlert relay). */
|
||||
interface LampState {
|
||||
/** The controller this lamp lives on (its deviceId) — for resolving the aux adapter. */
|
||||
readonly controllerId: string;
|
||||
/** Alert relay row (relay #, triggerInput, blink ms). Mutable: #reconcile updates it in
|
||||
* place when the admin changes the alert config without a restart. */
|
||||
spec: RelaySpec;
|
||||
/** Is the lamp's trigger input (the radar) currently active? */
|
||||
present: boolean;
|
||||
/** The high-level state we're rendering (to avoid restarting a running blink). */
|
||||
rendered: LightState | null;
|
||||
/** Active blink timer, if blinking. */
|
||||
blink: ReturnType<typeof setInterval> | null;
|
||||
/** Blink phase (true = currently on). */
|
||||
blinkOn: boolean;
|
||||
/** The output we WANT the relay to be in. The serialized worker drives the device
|
||||
* toward this. The blink timer only flips this flag — it never sends directly. */
|
||||
desiredOn: boolean;
|
||||
/** The output we last CONFIRMED on the device (after a successful send). null = unknown. */
|
||||
confirmedOn: boolean | null;
|
||||
/** True while a send is in flight for this lamp — serializes UDP so on/off can't
|
||||
* overlap or reorder (UDP is unordered; concurrent toggles left the relay stuck). */
|
||||
sending: boolean;
|
||||
/** Consecutive failed sends (0 = healthy). Drives the backoff delay + log summaries. */
|
||||
failCount: number;
|
||||
/** Epoch ms before which #pump must not send (0 = no backoff). The armed retry
|
||||
* timer re-pumps when it elapses; desired-state changes in between just update
|
||||
* `desiredOn` and are picked up by that same retry. */
|
||||
retryAt: number;
|
||||
/** The armed backoff retry, if any. */
|
||||
retryTimer: ReturnType<typeof setTimeout> | null;
|
||||
/** Epoch ms of the last failure line we actually logged (rate-limits the flood). */
|
||||
lastFailLogAt: number;
|
||||
}
|
||||
|
||||
/** Resolves a controller's live aux-output adapter. The default goes through the
|
||||
* driver registry; tests inject a spy. Returns null when the controller has no
|
||||
* aux-output capability (or won't build). */
|
||||
export type AuxResolver = (controllerId: string) => AuxOutputDevice | null;
|
||||
|
||||
export class ButtonLightController {
|
||||
readonly #db: Db;
|
||||
readonly #logger: FastifyBaseLogger;
|
||||
readonly #resolveAux: AuxResolver;
|
||||
/** Per-lamp state, keyed by `${controllerId}:${relay}` (a controller may have several). */
|
||||
readonly #lamps = new Map<string, LampState>();
|
||||
/** Latest lane status — a camera-confirmed car in the entry / exit zone. A lamp locks
|
||||
* SOLID off its OWN lane's camera (`spec.lockLane`), so an exit radar's lamp tracks the
|
||||
* exit camera, not the entry one. */
|
||||
#entryBusy = false;
|
||||
#exitBusy = false;
|
||||
/** Controllers we've already warned lack the aux-output capability (warn once). */
|
||||
readonly #warned = new Set<string>();
|
||||
#unsubInput: (() => void) | null = null;
|
||||
#unsubLane: (() => void) | null = null;
|
||||
|
||||
constructor(db: Db, logger: FastifyBaseLogger, resolveAux?: AuxResolver) {
|
||||
this.#db = db;
|
||||
this.#logger = logger;
|
||||
this.#resolveAux = resolveAux ?? ((id) => this.#auxFromRegistry(id));
|
||||
}
|
||||
|
||||
/** Subscribe to radar input edges + lane status, and initialise every lamp OFF. */
|
||||
start(): void {
|
||||
this.#reconcile();
|
||||
// All lamps start OFF (known-safe baseline) regardless of prior device state.
|
||||
for (const lamp of this.#lamps.values()) this.#apply(lamp);
|
||||
|
||||
this.#unsubInput = deviceEvents.onInput((e) => this.#onInput(e));
|
||||
this.#unsubLane = deviceEvents.onLaneStatus((s) => this.#onLane(s));
|
||||
}
|
||||
|
||||
/** Reconcile the lamp map with the CURRENT device config (the booth can add/change a
|
||||
* button light without a server restart). Mirrors DeviceMonitor, which re-reads the
|
||||
* device set each tick. Adds lamps for newly-configured controllers, updates the spec
|
||||
* (relay #, blink ms) in place — preserving live `present`/blink state — and drops
|
||||
* lamps whose controller lost its buttonLight or was disabled. Called at start() and
|
||||
* before handling each event, so a just-saved lamp takes effect immediately. */
|
||||
#reconcile(): void {
|
||||
const rows = this.#db.select().from(devices).where(eq(devices.category, "access")).all();
|
||||
const seen = new Set<string>();
|
||||
for (const row of rows) {
|
||||
if (!row.enabled) continue;
|
||||
for (const spec of alertRelaysOf(row)) {
|
||||
const key = lampKey(row.id, spec.relay);
|
||||
seen.add(key);
|
||||
const existing = this.#lamps.get(key);
|
||||
if (existing) {
|
||||
existing.spec = spec; // pick up a changed trigger input / blink cadence
|
||||
} else {
|
||||
this.#lamps.set(key, {
|
||||
controllerId: row.id,
|
||||
spec,
|
||||
present: false,
|
||||
rendered: null,
|
||||
blink: null,
|
||||
blinkOn: false,
|
||||
desiredOn: false,
|
||||
confirmedOn: null,
|
||||
sending: false,
|
||||
failCount: 0,
|
||||
retryAt: 0,
|
||||
retryTimer: null,
|
||||
lastFailLogAt: 0,
|
||||
});
|
||||
}
|
||||
}
|
||||
}
|
||||
// Drop lamps whose controller no longer declares one (or was disabled/removed).
|
||||
for (const [key, lamp] of this.#lamps) {
|
||||
if (seen.has(key)) continue;
|
||||
this.#disarm(lamp);
|
||||
this.#finalOff(lamp); // best-effort fail-OFF before forgetting it
|
||||
this.#lamps.delete(key);
|
||||
}
|
||||
}
|
||||
|
||||
/** A radar (presence) edge updates that controller's `present` flag. We resolve the
|
||||
* edge the SAME way the entry flow does (relayForPresence on an entry/both relay),
|
||||
* so the lamp and the one-car-one-ticket gate always agree on "a car is here". */
|
||||
#onInput(e: DeviceInputEvent): void {
|
||||
// Reconcile first so a lamp added/changed since boot (no restart) is picked up.
|
||||
this.#reconcile();
|
||||
const present = e.edge === "on";
|
||||
for (const lamp of this.#lamps.values()) {
|
||||
if (lamp.controllerId !== e.deviceId) continue;
|
||||
// A lamp's trigger is its own `triggerInput`; if unset, fall back to the controller's
|
||||
// entry-relay presence terminal (resolved the SAME way the entry flow does) so the
|
||||
// lamp and the one-car-one-ticket gate always agree on "a car is here".
|
||||
const trigger =
|
||||
lamp.spec.triggerInput ?? relayForPresence(this.#db, e.deviceId, e.input)?.presenceInput;
|
||||
if (trigger !== e.input) continue; // not this lamp's trigger terminal
|
||||
if (present === lamp.present) continue;
|
||||
lamp.present = present;
|
||||
this.#apply(lamp);
|
||||
}
|
||||
}
|
||||
|
||||
/** Lane status changed: a camera-confirmed car in the entry and/or exit zone. */
|
||||
#onLane(s: LaneStatusEvent): void {
|
||||
if (s.entry === this.#entryBusy && s.exit === this.#exitBusy) return;
|
||||
this.#entryBusy = s.entry;
|
||||
this.#exitBusy = s.exit;
|
||||
// Re-render every lamp (each picks its own lane's camera in #apply).
|
||||
for (const lamp of this.#lamps.values()) this.#apply(lamp);
|
||||
}
|
||||
|
||||
/** Compute + render the target state for one lamp. Drives are fire-and-forget (the
|
||||
* timer/state machine is synchronous; the UDP write resolves on its own). */
|
||||
#apply(lamp: LampState): void {
|
||||
// SOLID only once THIS lamp's lane camera confirms a car (default entry).
|
||||
const laneBusy = lamp.spec.lockLane === "exit" ? this.#exitBusy : this.#entryBusy;
|
||||
const target: LightState = !lamp.present ? "off" : laneBusy ? "solid" : "blink";
|
||||
if (target === lamp.rendered) return; // already rendering this state
|
||||
|
||||
// Tear down any running blink before switching states.
|
||||
if (lamp.blink) {
|
||||
clearInterval(lamp.blink);
|
||||
lamp.blink = null;
|
||||
}
|
||||
lamp.rendered = target;
|
||||
|
||||
if (target === "off") {
|
||||
lamp.desiredOn = false;
|
||||
this.#pump(lamp);
|
||||
} else if (target === "solid") {
|
||||
lamp.desiredOn = true;
|
||||
this.#pump(lamp);
|
||||
} else {
|
||||
// BLINK: a wall-clock timer flips ONLY the desired flag; #pump does the actual
|
||||
// (serialized) UDP send. A symmetric cadence uses one interval; an asymmetric one
|
||||
// re-arms each phase with its own duration. Sends never overlap or reorder, so the
|
||||
// relay can't get stuck on a stale packet.
|
||||
const onMs = lamp.spec.blinkOnMs && lamp.spec.blinkOnMs > 0 ? lamp.spec.blinkOnMs : DEFAULT_BLINK_MS;
|
||||
const offMs = lamp.spec.blinkOffMs && lamp.spec.blinkOffMs > 0 ? lamp.spec.blinkOffMs : DEFAULT_BLINK_MS;
|
||||
lamp.blinkOn = true;
|
||||
lamp.desiredOn = true;
|
||||
const tick = () => {
|
||||
lamp.blinkOn = !lamp.blinkOn;
|
||||
lamp.desiredOn = lamp.blinkOn;
|
||||
this.#pump(lamp);
|
||||
if (onMs !== offMs && lamp.blink) {
|
||||
clearInterval(lamp.blink);
|
||||
lamp.blink = setInterval(tick, lamp.blinkOn ? onMs : offMs);
|
||||
lamp.blink.unref?.();
|
||||
}
|
||||
};
|
||||
lamp.blink = setInterval(tick, onMs);
|
||||
lamp.blink.unref?.();
|
||||
this.#pump(lamp);
|
||||
}
|
||||
}
|
||||
|
||||
/** Serialized per-lamp worker: drive the relay toward `desiredOn`, one UDP send at a
|
||||
* time. Because UDP is unordered, concurrent on/off sends previously raced and left
|
||||
* the relay stuck on a stale packet. Here a single in-flight send is guaranteed
|
||||
* (`sending` guard); when it resolves, if the desired state moved on we send again —
|
||||
* so the LAST desired state is always the one finally asserted on the device.
|
||||
*
|
||||
* Failures back off (1s → 30s, reset on success) instead of retrying inline: an
|
||||
* unreachable controller rejects instantly, and an immediate re-pump was a hot loop.
|
||||
* During backoff `desiredOn` keeps tracking the truth table; the armed retry timer
|
||||
* converges to whatever it says when it fires. Only the FIRST failure of a streak is
|
||||
* logged, then one summary per minute, and an info line on recovery. */
|
||||
#pump(lamp: LampState): void {
|
||||
if (lamp.sending) return; // a send is already in flight; it'll re-check on completion
|
||||
if (lamp.confirmedOn === lamp.desiredOn) return; // already there — no redundant UDP
|
||||
if (Date.now() < lamp.retryAt) return; // backing off — the retry timer will re-pump
|
||||
const aux = this.#resolveAux(lamp.controllerId);
|
||||
if (!aux) return;
|
||||
const target = lamp.desiredOn;
|
||||
lamp.sending = true;
|
||||
void aux
|
||||
.setAux(lamp.spec.relay, target)
|
||||
.then(() => {
|
||||
lamp.confirmedOn = target;
|
||||
if (lamp.failCount > 0) {
|
||||
this.#logger.info(
|
||||
`button-light setAux recovered (${lamp.controllerId} R${lamp.spec.relay}) after ${lamp.failCount} failed attempts`,
|
||||
);
|
||||
}
|
||||
lamp.failCount = 0;
|
||||
lamp.retryAt = 0;
|
||||
lamp.lastFailLogAt = 0;
|
||||
})
|
||||
.catch((err: unknown) => {
|
||||
// Leave confirmedOn unchanged so the armed retry re-asserts the (then-current)
|
||||
// desired state. Never escalates — a dead lamp is "no hint", never a fault.
|
||||
lamp.failCount += 1;
|
||||
const delay = Math.min(RETRY_BASE_MS * 2 ** (lamp.failCount - 1), RETRY_MAX_MS);
|
||||
lamp.retryAt = Date.now() + delay;
|
||||
const now = Date.now();
|
||||
if (lamp.failCount === 1 || now - lamp.lastFailLogAt >= FAIL_LOG_EVERY_MS) {
|
||||
lamp.lastFailLogAt = now;
|
||||
const streak =
|
||||
lamp.failCount > 1 ? ` — still failing (attempt ${lamp.failCount}, retrying ≤${RETRY_MAX_MS / 1000}s)` : "";
|
||||
this.#logger.error(
|
||||
`button-light setAux failed (${lamp.controllerId} R${lamp.spec.relay}): ${(err as Error).message}${streak}`,
|
||||
);
|
||||
}
|
||||
if (lamp.retryTimer) clearTimeout(lamp.retryTimer);
|
||||
lamp.retryTimer = setTimeout(() => {
|
||||
lamp.retryTimer = null;
|
||||
this.#pump(lamp);
|
||||
}, delay);
|
||||
lamp.retryTimer.unref?.();
|
||||
})
|
||||
.finally(() => {
|
||||
lamp.sending = false;
|
||||
// Desired state may have changed while we were busy — re-pump to converge (the
|
||||
// backoff gate above makes this a no-op right after a failure). This is what
|
||||
// makes the final state authoritative.
|
||||
if (lamp.confirmedOn !== lamp.desiredOn) this.#pump(lamp);
|
||||
});
|
||||
}
|
||||
|
||||
/** Build the live aux-output adapter for a controller, or null (logged once). */
|
||||
#auxFromRegistry(controllerId: string): AuxOutputDevice | null {
|
||||
const row = this.#db.select().from(devices).where(eq(devices.id, controllerId)).get();
|
||||
if (!row) return null;
|
||||
const driver = registry.get(row.driverId);
|
||||
if (!driver) return null;
|
||||
let device: unknown;
|
||||
try {
|
||||
device = driver.create(row.config as never);
|
||||
} catch {
|
||||
return null;
|
||||
}
|
||||
if (!hasAuxOutput(device)) {
|
||||
if (!this.#warned.has(controllerId)) {
|
||||
this.#warned.add(controllerId);
|
||||
this.#logger.warn(`button-light: controller ${controllerId} (${row.driverId}) has no aux-output — lamp ignored`);
|
||||
}
|
||||
return null;
|
||||
}
|
||||
return device;
|
||||
}
|
||||
|
||||
/** Unsubscribe, stop all blink timers, and best-effort drive every lamp OFF. */
|
||||
stop(): void {
|
||||
this.#unsubInput?.();
|
||||
this.#unsubLane?.();
|
||||
this.#unsubInput = null;
|
||||
this.#unsubLane = null;
|
||||
for (const lamp of this.#lamps.values()) {
|
||||
this.#disarm(lamp);
|
||||
// Best-effort fail-OFF on shutdown.
|
||||
this.#finalOff(lamp);
|
||||
}
|
||||
}
|
||||
|
||||
/** Stop a lamp's timers (blink + backoff retry) without touching the device. */
|
||||
#disarm(lamp: LampState): void {
|
||||
if (lamp.blink) {
|
||||
clearInterval(lamp.blink);
|
||||
lamp.blink = null;
|
||||
}
|
||||
if (lamp.retryTimer) {
|
||||
clearTimeout(lamp.retryTimer);
|
||||
lamp.retryTimer = null;
|
||||
}
|
||||
}
|
||||
|
||||
/** Drive a lamp OFF as a one-shot (used when dropping/stopping a lamp): set desired
|
||||
* OFF and pump. The serialized worker still applies, so this can't collide with an
|
||||
* in-flight send — it converges to OFF. Any backoff is waived so the last-gasp OFF
|
||||
* gets one immediate try (a lamp mid-backoff may just have recovered). */
|
||||
#finalOff(lamp: LampState): void {
|
||||
lamp.desiredOn = false;
|
||||
lamp.retryAt = 0;
|
||||
this.#pump(lamp);
|
||||
}
|
||||
|
||||
/** Test seam: current high-level state being rendered for a lamp (controller + relay).
|
||||
* `relay` defaults to the controller's only/first alert relay for single-lamp tests. */
|
||||
stateOf(controllerId: string, relay?: number): LightState | null {
|
||||
return this.#lamp(controllerId, relay)?.rendered ?? null;
|
||||
}
|
||||
|
||||
/** Test seam: the state last CONFIRMED on the device for a lamp (after a successful
|
||||
* send). null = unknown / nothing sent yet. `relay` defaults to the only alert relay. */
|
||||
confirmedOf(controllerId: string, relay?: number): boolean | null {
|
||||
return this.#lamp(controllerId, relay)?.confirmedOn ?? null;
|
||||
}
|
||||
|
||||
/** Resolve a lamp by controller + relay. When `relay` is omitted, returns the
|
||||
* controller's single lamp (the common single-alert case); ambiguous if several. */
|
||||
#lamp(controllerId: string, relay?: number): LampState | undefined {
|
||||
if (relay != null) return this.#lamps.get(lampKey(controllerId, relay));
|
||||
for (const lamp of this.#lamps.values()) if (lamp.controllerId === controllerId) return lamp;
|
||||
return undefined;
|
||||
}
|
||||
}
|
||||
|
||||
/** Composite key for the lamp map (a controller may carry several alert relays). */
|
||||
function lampKey(controllerId: string, relay: number): string {
|
||||
return `${controllerId}:${relay}`;
|
||||
}
|
||||
|
||||
/** Build a controller row's live aux device (exported for reuse/tests). */
|
||||
export function buildAux(db: Db, row: DeviceRow): AuxOutputDevice | null {
|
||||
const driver = registry.get(row.driverId);
|
||||
if (!driver) return null;
|
||||
try {
|
||||
const device = driver.create(row.config as never);
|
||||
return hasAuxOutput(device) ? device : null;
|
||||
} catch {
|
||||
return null;
|
||||
}
|
||||
}
|
||||
@@ -1,6 +1,7 @@
|
||||
import { EventEmitter } from "node:events";
|
||||
import type { PrinterStatus } from "@parking/devices";
|
||||
import type { LedgerEventRow } from "@parking/db";
|
||||
import type { VehicleRead } from "@parking/shared";
|
||||
|
||||
// Internal event bus for device-originated events (button presses, etc.).
|
||||
// Hardware drivers / inbound device pushes emit here; business logic (entry
|
||||
@@ -24,13 +25,20 @@ export interface DeviceReadEvent {
|
||||
readonly deviceId: string; // devices id of the reader/scanner/camera
|
||||
readonly value: string; // the ticket id / plate / card number
|
||||
readonly kind: "ticket" | "plate" | "qr" | "card";
|
||||
/** The CONFIRMED physical channel the value arrived on, when the reader tags it
|
||||
* (the DT-008 output prefixes — see routes/qr-reader.ts). `optical` = decoded by
|
||||
* the barcode/QR engine; `rf` = read from a card/chip. Undefined = legacy reader
|
||||
* with no prefixes configured (channel unknown — flows must not assume). Lets the
|
||||
* subscription match refuse an OPTICAL decode claiming an RF credential (a printed
|
||||
* copy of a card's UID must not clone the card). */
|
||||
readonly channel?: "optical" | "rf";
|
||||
readonly at: string; // ISO-8601
|
||||
}
|
||||
|
||||
/**
|
||||
* The decision a read produced. Returned by the read flows so a SYNCHRONOUS reader
|
||||
* (e.g. the QR reader, whose HTTP reply drives its beep + output) can answer the
|
||||
* device. A fire-and-forget reader simply ignores it. See wiki/entities/gee-qr-er80.md.
|
||||
* device. A fire-and-forget reader simply ignores it. See wiki/entities/dingtian-dt008-reader.md.
|
||||
*/
|
||||
export interface ReadOutcome {
|
||||
/** Was the vehicle admitted/exited (barrier opened)? Drives the reader's beep. */
|
||||
@@ -45,7 +53,7 @@ export interface ReadOutcome {
|
||||
export interface PrinterStatusEvent {
|
||||
readonly deviceId: string; // devices id
|
||||
readonly driverId: string;
|
||||
readonly role?: string; // entry-dispenser | booth-receipt
|
||||
readonly role?: string; // entry-dispenser | booth-receipt | wash-desk
|
||||
readonly status: PrinterStatus;
|
||||
}
|
||||
|
||||
@@ -67,15 +75,58 @@ export interface DeviceStatusEvent {
|
||||
* chip reads e.g. "Lexuesi hyrje" / "Kamera dalje" / "Printer kabina":
|
||||
* - reader/camera: "entry" | "exit" | "both" (inherited from its bound relay)
|
||||
* - access: "entry" | "exit" | "both" | "mixed" (from its relays[])
|
||||
* - printer: "lane" (entry-dispenser) | "booth" (booth-receipt)
|
||||
* - printer: "lane" (entry-dispenser) | "booth" (booth-receipt) | "wash" (wash-desk)
|
||||
* - undetermined: null (chip shows the category alone)
|
||||
*/
|
||||
readonly roleKind: "entry" | "exit" | "both" | "mixed" | "lane" | "booth" | null;
|
||||
readonly roleKind: "entry" | "exit" | "both" | "mixed" | "lane" | "booth" | "wash" | null;
|
||||
readonly state: "ready" | "degraded" | "offline";
|
||||
readonly detail?: string;
|
||||
readonly checkedAt: string; // ISO-8601
|
||||
}
|
||||
|
||||
/** Lane occupancy from a camera's vehicle detection — a per-direction "busy/free"
|
||||
* the booth shows as barrier lights. ADVISORY ONLY: a detection is a hint, never a
|
||||
* gate (it never blocks a ticket or opens a barrier). "busy" is set by a vehicle
|
||||
* `active` event; it auto-clears to "free" after a timeout (this camera class sends
|
||||
* no leave/`inactive` signal — see wiki/entities/lpr-camera.md). */
|
||||
export interface LaneStatusEvent {
|
||||
readonly entry: boolean; // true = busy (a vehicle is at the entry vicinity)
|
||||
readonly exit: boolean; // true = busy (a vehicle is at the exit vicinity)
|
||||
}
|
||||
|
||||
/** A plate was RECOGNIZED for a session AFTER its entry/exit event already shipped. Plate
|
||||
* recognition is async/advisory (a vision round-trip off the snapshot), so it lands a
|
||||
* moment after the signed event — too late for the event's own WS push to carry it. This
|
||||
* notifies the booth so it can fill in the plate badge on the already-rendered feed row /
|
||||
* active session in place, no refresh. Advisory; never touches the signed ledger. See
|
||||
* snapshot.ts (recognizePlate) + event-enrich.ts. */
|
||||
export interface PlateRecognizedEvent {
|
||||
readonly identity: string; // the session identity the plate is tied to
|
||||
readonly plate: string; // normalized plate text (trimmed, upper)
|
||||
readonly direction: "entry" | "exit";
|
||||
}
|
||||
|
||||
/** Emitted when vision classified the vehicle in an entry/exit frame (advisory; stored on
|
||||
* the read row like the plate). A module may sample these — the Car Wash review outbox
|
||||
* queues one in N ENTRY reads for the remote reviewer, in the gate view the classifier
|
||||
* will be trained on (wiki/concepts/vision-review-outbox.md). The core emits; it never
|
||||
* knows who listens. */
|
||||
export interface VehicleReadEvent {
|
||||
readonly identity: string;
|
||||
readonly direction: "entry" | "exit";
|
||||
readonly read: VehicleRead;
|
||||
}
|
||||
|
||||
/** Per-lane RADAR presence — a vehicle-presence INPUT (loop/radar) is shorted at the
|
||||
* entry/exit barrier, i.e. "something is in the lane vicinity" BEFORE the camera has
|
||||
* confirmed a vehicle. Same signal that makes the physical button lamp (relay 3) blink:
|
||||
* radar-present + camera-not-busy. Drives the booth's barrier light blink. Advisory only —
|
||||
* it gates nothing. See wiki/concepts/button-light-indicator.md. */
|
||||
export interface LanePresenceEvent {
|
||||
readonly entry: boolean; // true = a presence input on an entry barrier is active
|
||||
readonly exit: boolean; // true = a presence input on an exit barrier is active
|
||||
}
|
||||
|
||||
class DeviceEventBus extends EventEmitter {
|
||||
emitInput(event: DeviceInputEvent): void {
|
||||
this.emit("input", event);
|
||||
@@ -128,6 +179,43 @@ class DeviceEventBus extends EventEmitter {
|
||||
this.on("ledger", cb);
|
||||
return () => this.off("ledger", cb);
|
||||
}
|
||||
|
||||
/** Emitted whenever a lane's busy/free state CHANGES (from camera vehicle
|
||||
* detection). Drives the booth's barrier lights. Advisory only. */
|
||||
emitLaneStatus(event: LaneStatusEvent): void {
|
||||
this.emit("lane-status", event);
|
||||
}
|
||||
onLaneStatus(cb: (event: LaneStatusEvent) => void): () => void {
|
||||
this.on("lane-status", cb);
|
||||
return () => this.off("lane-status", cb);
|
||||
}
|
||||
|
||||
/** Emitted whenever a lane's RADAR presence CHANGES (a presence input shorted/cleared
|
||||
* at an entry/exit barrier). Drives the booth barrier light's blink. Advisory only. */
|
||||
emitLanePresence(event: LanePresenceEvent): void {
|
||||
this.emit("lane-presence", event);
|
||||
}
|
||||
onLanePresence(cb: (event: LanePresenceEvent) => void): () => void {
|
||||
this.on("lane-presence", cb);
|
||||
return () => this.off("lane-presence", cb);
|
||||
}
|
||||
|
||||
/** Emitted when an async plate recognition completes for a session (after its event
|
||||
* already shipped). Lets the booth backfill the plate badge in place. Advisory only. */
|
||||
emitPlateRecognized(event: PlateRecognizedEvent): void {
|
||||
this.emit("plate-recognized", event);
|
||||
}
|
||||
onPlateRecognized(cb: (event: PlateRecognizedEvent) => void): () => void {
|
||||
this.on("plate-recognized", cb);
|
||||
return () => this.off("plate-recognized", cb);
|
||||
}
|
||||
emitVehicleRead(event: VehicleReadEvent): void {
|
||||
this.emit("vehicle-read", event);
|
||||
}
|
||||
onVehicleRead(cb: (event: VehicleReadEvent) => void): () => void {
|
||||
this.on("vehicle-read", cb);
|
||||
return () => this.off("vehicle-read", cb);
|
||||
}
|
||||
}
|
||||
|
||||
/** Process-wide device event bus. */
|
||||
|
||||
@@ -0,0 +1,24 @@
|
||||
import { describe, expect, it } from "vitest";
|
||||
import { localIsoWithOffset } from "./device-monitor.js";
|
||||
|
||||
// The camera clock-sync sends the SITE's wall-clock now with an explicit UTC offset
|
||||
// (ISAPI localTime) — the offset is what makes the instant unambiguous regardless of
|
||||
// the camera's own tz/DST config. Pin the DST both-sides behaviour for the site tz.
|
||||
|
||||
describe("localIsoWithOffset (camera clock sync payload)", () => {
|
||||
it("Tirane summer = +02:00 (CEST)", () => {
|
||||
expect(localIsoWithOffset("Europe/Tirane", new Date("2026-07-07T10:00:00Z"))).toBe(
|
||||
"2026-07-07T12:00:00+02:00",
|
||||
);
|
||||
});
|
||||
it("Tirane winter = +01:00 (CET)", () => {
|
||||
expect(localIsoWithOffset("Europe/Tirane", new Date("2026-01-15T10:00:00Z"))).toBe(
|
||||
"2026-01-15T11:00:00+01:00",
|
||||
);
|
||||
});
|
||||
it("UTC = +00:00", () => {
|
||||
expect(localIsoWithOffset("UTC", new Date("2026-07-07T10:00:00Z"))).toBe(
|
||||
"2026-07-07T10:00:00+00:00",
|
||||
);
|
||||
});
|
||||
});
|
||||
@@ -1,9 +1,10 @@
|
||||
import type { FastifyBaseLogger } from "fastify";
|
||||
import { devices, type Db, type DeviceRow } from "@parking/db";
|
||||
import { isMonitorable, registry } from "@parking/devices";
|
||||
import { isClockSyncable, isMonitorable, registry, type Device } from "@parking/devices";
|
||||
import { deviceEvents, type DeviceStatusEvent } from "./device-events.js";
|
||||
import { directionOf, relaysOf } from "./device-resolve.js";
|
||||
import type { VisionClient } from "./vision-client.js";
|
||||
import { siteTz } from "./subscription-window.js";
|
||||
|
||||
/** Synthetic device id for the vision service in the status footer (it's a service,
|
||||
* not a device row, but shares the footer's traffic-light + WS plumbing). */
|
||||
@@ -23,13 +24,47 @@ const VISION_STATUS_ID = "vision-service";
|
||||
|
||||
const POLL_MS = Number(process.env.DEVICE_POLL_MS ?? 8000);
|
||||
|
||||
// Camera clock sync (Hikvision loses its clock on power cuts — reboots at the 1970
|
||||
// epoch until a human logs into its web UI). The monitor re-syncs from the HOST
|
||||
// clock (the site's offline time authority) at the offline→ready edge — exactly the
|
||||
// power-restored moment — plus a daily backstop; drift under the threshold is left
|
||||
// alone. See wiki/entities/lpr-camera.md (clock sync).
|
||||
const CLOCK_SYNC_BACKSTOP_MS = 24 * 60 * 60 * 1000;
|
||||
const CLOCK_MAX_DRIFT_SEC = 60;
|
||||
|
||||
/** The site's wall-clock now as ISO WITH utc offset (e.g. 2026-07-07T15:30:22+02:00)
|
||||
* — what ISAPI's localTime wants. Derived via Intl for the site tz (no dep). */
|
||||
export function localIsoWithOffset(tz: string, at = new Date()): string {
|
||||
const fmt = new Intl.DateTimeFormat("en-CA", {
|
||||
timeZone: tz,
|
||||
year: "numeric",
|
||||
month: "2-digit",
|
||||
day: "2-digit",
|
||||
hour: "2-digit",
|
||||
minute: "2-digit",
|
||||
second: "2-digit",
|
||||
hourCycle: "h23",
|
||||
});
|
||||
const p = Object.fromEntries(fmt.formatToParts(at).map((x) => [x.type, x.value]));
|
||||
const wallAsUtcMs = Date.UTC(
|
||||
Number(p.year), Number(p.month) - 1, Number(p.day),
|
||||
Number(p.hour), Number(p.minute), Number(p.second),
|
||||
);
|
||||
const offMin = Math.round((wallAsUtcMs - at.getTime()) / 60_000);
|
||||
const sign = offMin < 0 ? "-" : "+";
|
||||
const abs = Math.abs(offMin);
|
||||
const hh = String(Math.floor(abs / 60)).padStart(2, "0");
|
||||
const mm = String(abs % 60).padStart(2, "0");
|
||||
return `${p.year}-${p.month}-${p.day}T${p.hour}:${p.minute}:${p.second}${sign}${hh}:${mm}`;
|
||||
}
|
||||
|
||||
/**
|
||||
* The device's ROLE descriptor for the footer (never the vendor). Direction-style
|
||||
* tokens the client localises next to the category:
|
||||
* - reader/camera → the direction inherited from its bound relay (entry/exit/both)
|
||||
* - access → entry/exit/both from its relays[]; "mixed" if it spans more
|
||||
* than one direction; null if it declares none yet
|
||||
* - printer → "lane" (entry-dispenser) | "booth" (booth-receipt)
|
||||
* - printer → "lane" (entry-dispenser) | "booth" (booth-receipt) | "wash" (wash-desk)
|
||||
*/
|
||||
function roleKindOf(db: Db, row: DeviceRow): DeviceStatusEvent["roleKind"] {
|
||||
switch (row.category) {
|
||||
@@ -39,7 +74,12 @@ function roleKindOf(db: Db, row: DeviceRow): DeviceStatusEvent["roleKind"] {
|
||||
return d;
|
||||
}
|
||||
case "access": {
|
||||
const dirs = new Set(relaysOf(row).map((r) => r.direction));
|
||||
// Only barrier relays carry a role direction; alert (radarAlert) relays don't.
|
||||
const dirs = new Set(
|
||||
relaysOf(row)
|
||||
.map((r) => r.direction)
|
||||
.filter((d): d is "entry" | "exit" | "both" => d !== "radarAlert"),
|
||||
);
|
||||
if (dirs.size === 0) return null;
|
||||
if (dirs.size > 1) return "mixed";
|
||||
const only = [...dirs][0]; // entry | exit | both
|
||||
@@ -49,6 +89,7 @@ function roleKindOf(db: Db, row: DeviceRow): DeviceStatusEvent["roleKind"] {
|
||||
const role = (row.config as { role?: string }).role;
|
||||
if (role === "booth-receipt") return "booth";
|
||||
if (role === "entry-dispenser") return "lane";
|
||||
if (role === "wash-desk") return "wash";
|
||||
return null;
|
||||
}
|
||||
default:
|
||||
@@ -134,6 +175,7 @@ export class DeviceMonitor {
|
||||
};
|
||||
|
||||
let next: DeviceStatusEvent;
|
||||
let device: Device | null = null;
|
||||
const driver = registry.get(row.driverId);
|
||||
if (!driver) {
|
||||
// Configured against a driver that's no longer registered — surface it,
|
||||
@@ -141,7 +183,7 @@ export class DeviceMonitor {
|
||||
next = { ...base, state: "offline", detail: "driver not registered", checkedAt: new Date().toISOString() };
|
||||
} else {
|
||||
try {
|
||||
const device = driver.create(cfg as never);
|
||||
device = driver.create(cfg as never);
|
||||
// Printers expose richer paper/cover/cutter status; everything else uses
|
||||
// the generic reachability probe. Both flatten to the same traffic-light.
|
||||
if (isMonitorable(device)) {
|
||||
@@ -158,6 +200,33 @@ export class DeviceMonitor {
|
||||
}
|
||||
}
|
||||
|
||||
// Camera clock re-sync at the power-restored edge (prev offline/unknown →
|
||||
// ready) + a daily backstop. Stamped BEFORE the async attempt so a failing
|
||||
// camera is retried at backstop cadence, never every poll.
|
||||
if (row.category === "camera" && next.state === "ready" && device && isClockSyncable(device)) {
|
||||
const prev = this.#latest.get(row.id);
|
||||
const cameBack = !prev || prev.state === "offline";
|
||||
const last = this.#clockSyncedAt.get(row.id) ?? 0;
|
||||
if (cameBack || Date.now() - last > CLOCK_SYNC_BACKSTOP_MS) {
|
||||
this.#clockSyncedAt.set(row.id, Date.now());
|
||||
const cam = device;
|
||||
void (async () => {
|
||||
try {
|
||||
const r = await cam.syncClock(localIsoWithOffset(siteTz(this.#db)), CLOCK_MAX_DRIFT_SEC);
|
||||
if (r.synced) {
|
||||
// A large jump is the 1970 power-cut signature — warn (persisted) so
|
||||
// the reboot stays visible; a small correction is routine info.
|
||||
const msg = `device-monitor: camera ${row.id} clock synced (was ${r.driftSeconds ?? "unparseable"}s off)`;
|
||||
if (r.driftSeconds == null || r.driftSeconds > 3600) this.#log.warn(msg);
|
||||
else this.#log.info(msg);
|
||||
}
|
||||
} catch (err) {
|
||||
this.#log.warn(`device-monitor: camera ${row.id} clock sync failed: ${(err as Error).message}`);
|
||||
}
|
||||
})();
|
||||
}
|
||||
}
|
||||
|
||||
this.#publish(row.id, next);
|
||||
}
|
||||
|
||||
@@ -178,6 +247,9 @@ export class DeviceMonitor {
|
||||
});
|
||||
}
|
||||
|
||||
/** Per-camera timestamp of the last clock-sync ATTEMPT (backstop pacing). */
|
||||
readonly #clockSyncedAt = new Map<string, number>();
|
||||
|
||||
/** Cache + emit a status, but only when it CHANGED (state or detail). */
|
||||
#publish(id: string, next: DeviceStatusEvent): void {
|
||||
const prev = this.#latest.get(id);
|
||||
|
||||
@@ -0,0 +1,91 @@
|
||||
import { beforeEach, describe, expect, it } from "vitest";
|
||||
import { devices, type Db } from "@parking/db";
|
||||
import { createTestDb } from "@parking/db/testing";
|
||||
import { inputsOf, relayForButton, relayForPresence } from "./device-resolve.js";
|
||||
|
||||
// device-resolve: the input resolution layer. Inputs live in config.inputs[] (the first-class
|
||||
// model); a pre-inputs[] controller is back-compat-synthesized from the legacy per-relay
|
||||
// button/presenceInput fields. relayForButton/relayForPresence must resolve IDENTICALLY from
|
||||
// either shape, so an exit radar = just another presence row.
|
||||
|
||||
let db: Db;
|
||||
const CTL = "ctl-1";
|
||||
|
||||
function seed(config: Record<string, unknown>): void {
|
||||
({ db } = createTestDb());
|
||||
db.insert(devices).values({ id: CTL, category: "access", driverId: "dingtian", config, enabled: true }).run();
|
||||
}
|
||||
|
||||
describe("inputsOf back-compat synth", () => {
|
||||
it("synthesizes inputs[] from legacy relay button/presence fields", () => {
|
||||
seed({
|
||||
relays: [
|
||||
{ relay: 1, direction: "entry", button: 1, presenceInput: 2, presenceKind: "radar", presenceActiveLow: true },
|
||||
{ relay: 2, direction: "exit" },
|
||||
],
|
||||
});
|
||||
const row = db.select().from(devices).get()!;
|
||||
const inputs = inputsOf(row);
|
||||
expect(inputs).toEqual([
|
||||
{ input: 1, role: "button", relay: 1, cooldownSec: undefined },
|
||||
{ input: 2, role: "presence", relay: 1, kind: "radar", activeLow: true },
|
||||
]);
|
||||
});
|
||||
|
||||
it("prefers an explicit inputs[] over the legacy fields", () => {
|
||||
seed({
|
||||
relays: [{ relay: 1, direction: "entry", button: 9 /* legacy ignored */ }],
|
||||
inputs: [{ input: 1, role: "button", relay: 1 }],
|
||||
});
|
||||
const row = db.select().from(devices).get()!;
|
||||
expect(inputsOf(row)).toEqual([{ input: 1, role: "button", relay: 1 }]);
|
||||
});
|
||||
});
|
||||
|
||||
describe("relayForButton / relayForPresence", () => {
|
||||
it("resolves a button + presence from inputs[]", () => {
|
||||
seed({
|
||||
relays: [{ relay: 1, direction: "entry" }],
|
||||
inputs: [
|
||||
{ input: 1, role: "button", relay: 1 },
|
||||
{ input: 2, role: "presence", relay: 1, kind: "radar" },
|
||||
],
|
||||
});
|
||||
const byBtn = relayForButton(db, CTL, 1);
|
||||
expect(byBtn).toMatchObject({ relay: 1, direction: "entry", presenceInput: 2, presenceKind: "radar" });
|
||||
const byPres = relayForPresence(db, CTL, 2);
|
||||
expect(byPres).toMatchObject({ relay: 1, direction: "entry", presenceInput: 2 });
|
||||
});
|
||||
|
||||
it("resolves IDENTICALLY from the legacy shape (no inputs[])", () => {
|
||||
seed({ relays: [{ relay: 1, direction: "entry", button: 1, presenceInput: 2, presenceKind: "loop" }] });
|
||||
expect(relayForButton(db, CTL, 1)).toMatchObject({ relay: 1, presenceInput: 2, presenceKind: "loop" });
|
||||
expect(relayForPresence(db, CTL, 2)).toMatchObject({ relay: 1, presenceInput: 2 });
|
||||
});
|
||||
|
||||
it("resolves an EXIT presence row to the exit relay (the exit radar)", () => {
|
||||
seed({
|
||||
relays: [
|
||||
{ relay: 1, direction: "entry" },
|
||||
{ relay: 2, direction: "exit" },
|
||||
],
|
||||
inputs: [
|
||||
{ input: 2, role: "presence", relay: 1, kind: "radar" }, // entry radar
|
||||
{ input: 5, role: "presence", relay: 2, kind: "radar" }, // exit radar
|
||||
],
|
||||
});
|
||||
// NOTE: relayForPresence only gates entry/both relays (transient entry). The exit radar
|
||||
// resolves to null HERE (the exit barrier has no entry gate) — but it's still a valid
|
||||
// inputs[] row the lamp can trigger on. The entry radar resolves to relay 1.
|
||||
expect(relayForPresence(db, CTL, 2)).toMatchObject({ relay: 1 });
|
||||
expect(relayForPresence(db, CTL, 5)).toBeNull(); // exit relay isn't a transient-entry gate
|
||||
});
|
||||
|
||||
it("a button on an exit-only relay is not a transient-entry trigger", () => {
|
||||
seed({
|
||||
relays: [{ relay: 2, direction: "exit" }],
|
||||
inputs: [{ input: 1, role: "button", relay: 2 }],
|
||||
});
|
||||
expect(relayForButton(db, CTL, 1)).toBeNull();
|
||||
});
|
||||
});
|
||||
@@ -10,35 +10,74 @@ export type Direction = "entry" | "exit" | "both";
|
||||
/** A concrete flow a credential/button drives (never "both"). */
|
||||
export type FlowDirection = "entry" | "exit";
|
||||
|
||||
/** One relay on an access controller: which barrier it opens, in which direction,
|
||||
* and (optionally) the input terminals its entry button + presence loop are wired to. */
|
||||
/** The EVENT a relay reacts to. The barrier events (entry/exit/both) `pulseOpen`; the
|
||||
* `radarAlert` event drives a non-barrier alert lamp (blink while the trigger input is
|
||||
* active, locked SOLID by the camera). A relay is "when EVENT X happens, do its action" —
|
||||
* the action is implied by the event. See wiki/concepts/button-light-indicator.md. */
|
||||
export type RelayEvent = Direction | "radarAlert";
|
||||
|
||||
/** What a controller input terminal MEANS. `button` = a transient-entry button; `presence`
|
||||
* = a one-car-one-ticket sensor (induction loop or radar); `alertTrigger` = the edge that
|
||||
* starts a `radarAlert` lamp blinking. See wiki/concepts/entry-double-press.md. */
|
||||
export type InputRole = "button" | "presence" | "alertTrigger";
|
||||
|
||||
/** One INPUT terminal the host reads, as a first-class citizen (the twin of RelaySpec).
|
||||
* An exit radar is just another `presence` row serving the exit relay. */
|
||||
export interface InputSpec {
|
||||
/** 1-based input terminal the host reads. */
|
||||
readonly input: number;
|
||||
readonly role: InputRole;
|
||||
/** The barrier relay this input serves. Required for `button`/`presence` (the gate is
|
||||
* keyed per relay); optional for `alertTrigger` (a standalone lamp trigger). */
|
||||
readonly relay?: number;
|
||||
/** `presence` only — induction LOOP or RADAR. Label only (gate is identical). Default loop. */
|
||||
readonly kind?: "loop" | "radar";
|
||||
/** This terminal is ACTIVE-LOW (idles HIGH) — e.g. a radar wired opposite the button.
|
||||
* Maps to the driver's per-input `inputActiveLow`. See wiki/entities/hikvision-radar.md. */
|
||||
readonly activeLow?: boolean;
|
||||
/** `button` only — presence-less fallback: suppress repeat presses for N seconds after a
|
||||
* ticket. A timer (mitigation, not a guarantee); used when no `presence` row serves this relay. */
|
||||
readonly cooldownSec?: number;
|
||||
}
|
||||
|
||||
/** One relay on an access controller: the event it reacts to. Input wiring (button,
|
||||
* presence) lives in `config.inputs[]`; the LEGACY per-relay fields below are still read
|
||||
* (back-compat) but no longer written by the UI. */
|
||||
export interface RelaySpec {
|
||||
/** 1-based relay channel on the board (the driver's pulseOpen(doorId)). */
|
||||
readonly relay: number;
|
||||
readonly direction: Direction;
|
||||
/** 1-based input terminal of the entry button that fires this relay (transient
|
||||
* entry). Absent = no button at this barrier (subscriber/reader-driven only). */
|
||||
/** The event this relay reacts to. entry/exit/both → pulse a barrier; `radarAlert` →
|
||||
* drive an alert lamp (blink + camera-lock) via `setAux`, NEVER pulseOpen. */
|
||||
readonly direction: RelayEvent;
|
||||
|
||||
// ── LEGACY input fields (read-only back-compat; superseded by config.inputs[]) ──
|
||||
// Pre-inputs[] configs wired the entry button + presence sensor here. `inputsOf()`
|
||||
// synthesizes InputSpec rows from these when a controller has no `inputs[]` yet.
|
||||
readonly button?: number;
|
||||
/**
|
||||
* Anti-double-press for the transient entry button (one car must yield ONE ticket).
|
||||
* Two modes, chosen by what barrier feedback exists at this lane:
|
||||
* - PRESENCE (preferred, when a vehicle loop is wired): `presenceInput` = the
|
||||
* 1-based input terminal of an induction loop / barrier presence signal on THIS
|
||||
* controller. A press prints only while a car is present, and no second ticket
|
||||
* issues until the loop CLEARS (car drove in) and a new car re-occupies it. This
|
||||
* makes one-car-one-ticket physical.
|
||||
* - COOLDOWN (fallback, no feedback): `entryCooldownSec` suppresses repeat presses
|
||||
* on this relay for N seconds after a ticket prints. A pure timer — mitigation,
|
||||
* not a guarantee. Used when `presenceInput` is unset (or as a secondary guard).
|
||||
* Both absent = no guard (legacy behaviour). See wiki/concepts/entry-double-press.md.
|
||||
*/
|
||||
readonly presenceInput?: number;
|
||||
readonly presenceKind?: "loop" | "radar";
|
||||
readonly presenceActiveLow?: boolean;
|
||||
readonly entryCooldownSec?: number;
|
||||
|
||||
// ── radarAlert-only (direction === "radarAlert") ──
|
||||
// A non-barrier indicator lamp wired to this (spare) relay — e.g. the entry button's
|
||||
// 12 V light. Driven by the server ButtonLightController off its trigger input vs. the
|
||||
// camera lane status: blink while the trigger is active + lane free, SOLID once the
|
||||
// camera confirms a car, OFF otherwise. NOT a barrier (uses setAux, never pulseOpen).
|
||||
/** 1-based input terminal whose active edge starts the blink (the radar). */
|
||||
readonly triggerInput?: number;
|
||||
/** Which lane's camera locks this lamp SOLID — the entry or the exit camera. Default
|
||||
* "entry". An exit radar's lamp must lock on the EXIT camera. */
|
||||
readonly lockLane?: FlowDirection;
|
||||
/** Blink cadence (ms on / ms off) for the radar-only state. Default 500/500. */
|
||||
readonly blinkOnMs?: number;
|
||||
readonly blinkOffMs?: number;
|
||||
}
|
||||
|
||||
/** Access controller config (the `relays[]` map + connection fields). */
|
||||
/** Access controller config (the `relays[]` + `inputs[]` maps + connection fields). */
|
||||
interface AccessConfig {
|
||||
readonly relays?: RelaySpec[];
|
||||
readonly inputs?: InputSpec[];
|
||||
readonly [k: string]: unknown;
|
||||
}
|
||||
|
||||
@@ -60,9 +99,11 @@ export interface ResolvedRelay {
|
||||
readonly controller: DeviceRow;
|
||||
readonly relay: number;
|
||||
readonly direction: Direction;
|
||||
/** 1-based presence-loop input gating this relay's entry (when wired). */
|
||||
/** 1-based presence input gating this relay's entry (loop or radar, when wired). */
|
||||
readonly presenceInput?: number;
|
||||
/** Cooldown seconds suppressing repeat presses (fallback when no presence loop). */
|
||||
/** Sensor kind on the presence input (loop|radar) — telemetry/label only. */
|
||||
readonly presenceKind?: "loop" | "radar";
|
||||
/** Cooldown seconds suppressing repeat presses (fallback when no presence input). */
|
||||
readonly entryCooldownSec?: number;
|
||||
}
|
||||
|
||||
@@ -83,9 +124,49 @@ export function relaysOf(row: DeviceRow): RelaySpec[] {
|
||||
}
|
||||
|
||||
/**
|
||||
* Resolve a button press to the relay it fires: the access controller with this
|
||||
* deviceId, and the relay whose `button` terminal matches the pressed input. Only
|
||||
* an ENTRY (or both) relay is a transient-entry trigger. Returns null otherwise.
|
||||
* The INPUT terminals declared on an access controller — the back-compat keystone. Returns
|
||||
* `config.inputs[]` when present; otherwise SYNTHESIZES InputSpec rows from the LEGACY
|
||||
* per-relay fields (`relays[].button` → a `button` row; `relays[].presenceInput` → a
|
||||
* `presence` row) so a pre-inputs[] controller resolves identically. Everything that reads
|
||||
* inputs goes through here, so the legacy fold lives in exactly one place.
|
||||
*/
|
||||
export function inputsOf(row: DeviceRow): InputSpec[] {
|
||||
const cfg = row.config as AccessConfig;
|
||||
if (Array.isArray(cfg.inputs) && cfg.inputs.length > 0) return cfg.inputs;
|
||||
const synth: InputSpec[] = [];
|
||||
for (const r of relaysOf(row)) {
|
||||
if (typeof r.button === "number") {
|
||||
synth.push({ input: r.button, role: "button", relay: r.relay, cooldownSec: r.entryCooldownSec });
|
||||
}
|
||||
if (typeof r.presenceInput === "number") {
|
||||
synth.push({
|
||||
input: r.presenceInput,
|
||||
role: "presence",
|
||||
relay: r.relay,
|
||||
kind: r.presenceKind ?? "loop",
|
||||
activeLow: r.presenceActiveLow,
|
||||
});
|
||||
}
|
||||
}
|
||||
return synth;
|
||||
}
|
||||
|
||||
/** The barrier RelaySpec a `button`/`presence` input row serves (its `relay`), or null —
|
||||
* only entry/both relays gate transient entry. Narrows `direction` to a barrier Direction. */
|
||||
function barrierForInput(row: DeviceRow, spec: InputSpec): (RelaySpec & { direction: Direction }) | null {
|
||||
if (typeof spec.relay !== "number") return null;
|
||||
const relay = relaysOf(row).find((r) => r.relay === spec.relay);
|
||||
if (!relay) return null;
|
||||
if (relay.direction !== "entry" && relay.direction !== "both") return null;
|
||||
return { ...relay, direction: relay.direction };
|
||||
}
|
||||
|
||||
/**
|
||||
* Resolve a button press to the relay it fires: the access controller with this deviceId,
|
||||
* and the relay served by the `button` input on this terminal (via inputsOf). Only an
|
||||
* ENTRY (or both) relay is a transient-entry trigger. Carries the one-car-one-ticket
|
||||
* config (presence input + cooldown) for that relay so the entry flow can enforce it.
|
||||
* Returns null otherwise.
|
||||
*/
|
||||
export function relayForButton(db: Db, controllerId: string, terminal: number): ResolvedRelay | null {
|
||||
const row = db
|
||||
@@ -94,23 +175,28 @@ export function relayForButton(db: Db, controllerId: string, terminal: number):
|
||||
.where(and(eq(devices.id, controllerId), eq(devices.category, "access")))
|
||||
.get();
|
||||
if (!row || !row.enabled) return null;
|
||||
const spec = relaysOf(row).find((r) => r.button === terminal);
|
||||
if (!spec) return null;
|
||||
if (spec.direction !== "entry" && spec.direction !== "both") return null;
|
||||
const inputs = inputsOf(row);
|
||||
const btn = inputs.find((i) => i.role === "button" && i.input === terminal);
|
||||
if (!btn) return null;
|
||||
const relay = barrierForInput(row, btn);
|
||||
if (!relay) return null;
|
||||
// The presence sensor (if any) serving the SAME relay supplies the gate.
|
||||
const presence = inputs.find((i) => i.role === "presence" && i.relay === relay.relay);
|
||||
return {
|
||||
controller: row,
|
||||
relay: spec.relay,
|
||||
direction: spec.direction,
|
||||
presenceInput: spec.presenceInput,
|
||||
entryCooldownSec: spec.entryCooldownSec,
|
||||
relay: relay.relay,
|
||||
direction: relay.direction,
|
||||
presenceInput: presence?.input,
|
||||
presenceKind: presence?.kind ?? "loop",
|
||||
entryCooldownSec: btn.cooldownSec,
|
||||
};
|
||||
}
|
||||
|
||||
/**
|
||||
* Resolve a PRESENCE-LOOP input edge to the entry relay it gates: the controller with
|
||||
* this deviceId, and the relay whose `presenceInput` terminal matches the fired input.
|
||||
* Lets the entry flow track "a car is physically at this entry barrier" so it issues
|
||||
* exactly one ticket per car. Only entry/both relays gate transient entry. Null otherwise.
|
||||
* Resolve a PRESENCE input edge to the entry relay it gates: the controller with this
|
||||
* deviceId, and the relay served by the `presence` input on this terminal. Lets the entry
|
||||
* flow track "a car is physically at this entry barrier" so it issues exactly one ticket
|
||||
* per car. Only entry/both relays gate transient entry. Null otherwise.
|
||||
*/
|
||||
export function relayForPresence(db: Db, controllerId: string, terminal: number): ResolvedRelay | null {
|
||||
const row = db
|
||||
@@ -119,10 +205,43 @@ export function relayForPresence(db: Db, controllerId: string, terminal: number)
|
||||
.where(and(eq(devices.id, controllerId), eq(devices.category, "access")))
|
||||
.get();
|
||||
if (!row || !row.enabled) return null;
|
||||
const spec = relaysOf(row).find((r) => r.presenceInput === terminal);
|
||||
if (!spec) return null;
|
||||
if (spec.direction !== "entry" && spec.direction !== "both") return null;
|
||||
return { controller: row, relay: spec.relay, direction: spec.direction };
|
||||
const presence = inputsOf(row).find((i) => i.role === "presence" && i.input === terminal);
|
||||
if (!presence) return null;
|
||||
const relay = barrierForInput(row, presence);
|
||||
if (!relay) return null;
|
||||
return {
|
||||
controller: row,
|
||||
relay: relay.relay,
|
||||
direction: relay.direction,
|
||||
presenceInput: presence.input,
|
||||
presenceKind: presence.kind ?? "loop",
|
||||
};
|
||||
}
|
||||
|
||||
/** The alert (radarAlert) relay rows declared on an access controller — the lamps the
|
||||
* ButtonLightController drives. Each is a `relays[]` row whose event is `radarAlert`. */
|
||||
export function alertRelaysOf(row: DeviceRow): RelaySpec[] {
|
||||
return relaysOf(row).filter((r) => r.direction === "radarAlert" && typeof r.relay === "number");
|
||||
}
|
||||
|
||||
/**
|
||||
* Which LANE a presence input belongs to — for the booth's barrier-light blink (advisory).
|
||||
* Unlike `relayForPresence` (entry-gated, for the one-car-one-ticket gate), this resolves a
|
||||
* presence input on ANY barrier: entry/both → "entry", exit → "exit". Returns null if the
|
||||
* terminal isn't a presence input on a barrier relay. See lane-presence.ts.
|
||||
*/
|
||||
export function presenceLaneOf(db: Db, controllerId: string, terminal: number): FlowDirection | null {
|
||||
const row = db
|
||||
.select()
|
||||
.from(devices)
|
||||
.where(and(eq(devices.id, controllerId), eq(devices.category, "access")))
|
||||
.get();
|
||||
if (!row || !row.enabled) return null;
|
||||
const presence = inputsOf(row).find((i) => i.role === "presence" && i.input === terminal);
|
||||
if (!presence || typeof presence.relay !== "number") return null;
|
||||
const relay = relaysOf(row).find((r) => r.relay === presence.relay);
|
||||
if (!relay) return null;
|
||||
return relay.direction === "exit" ? "exit" : relay.direction === "radarAlert" ? null : "entry";
|
||||
}
|
||||
|
||||
/**
|
||||
@@ -144,7 +263,10 @@ export function relayForDevice(db: Db, deviceRow: DeviceRow): ResolvedRelay | nu
|
||||
.get();
|
||||
if (controller && controller.enabled) {
|
||||
const spec = relaysOf(controller).find((r) => r.relay === cfg.relay);
|
||||
if (spec) return { controller, relay: spec.relay, direction: spec.direction };
|
||||
// Only a barrier relay opens; an alert (radarAlert) relay is never a barrier.
|
||||
if (spec && spec.direction !== "radarAlert") {
|
||||
return { controller, relay: spec.relay, direction: spec.direction };
|
||||
}
|
||||
}
|
||||
return null;
|
||||
}
|
||||
@@ -164,9 +286,22 @@ export function relayForDevice(db: Db, deviceRow: DeviceRow): ResolvedRelay | nu
|
||||
export function firstRelayByDirection(db: Db, direction: FlowDirection): ResolvedRelay | null {
|
||||
for (const controller of accessRows(db)) {
|
||||
const spec = relaysOf(controller).find(
|
||||
(r) => r.direction === direction || r.direction === "both",
|
||||
(r): r is RelaySpec & { direction: Direction } =>
|
||||
r.direction === direction || r.direction === "both",
|
||||
);
|
||||
if (spec) return { controller, relay: spec.relay, direction: spec.direction };
|
||||
if (spec) {
|
||||
// Attach the presence sensor (if any) serving the SAME relay, so callers that gate on
|
||||
// presence (the operator-issued entry) see it. Without this the ResolvedRelay carried
|
||||
// no presenceInput and the presence gate read as "unavailable". Mirrors relayForButton.
|
||||
const presence = inputsOf(controller).find((i) => i.role === "presence" && i.relay === spec.relay);
|
||||
return {
|
||||
controller,
|
||||
relay: spec.relay,
|
||||
direction: spec.direction,
|
||||
presenceInput: presence?.input,
|
||||
presenceKind: presence?.kind ?? "loop",
|
||||
};
|
||||
}
|
||||
}
|
||||
return null;
|
||||
}
|
||||
|
||||
@@ -0,0 +1,107 @@
|
||||
import { randomUUID } from "node:crypto";
|
||||
import { beforeEach, describe, expect, it } from "vitest";
|
||||
import { deviceEvents as deviceEventsTable, ledgerEvents, sessions, type Db } from "@parking/db";
|
||||
import { createTestDb } from "@parking/db/testing";
|
||||
import { flagDuplicateEntryPlate } from "./snapshot.js";
|
||||
import { makeLog, silentLogger } from "./test-helpers.js";
|
||||
import type { EventLog } from "./event-log.js";
|
||||
|
||||
// Entry-side duplicate-plate reconciliation (2026-07-04): when ANPR recognizes a plate on
|
||||
// a fresh transient entry and that plate is already OPEN under another RECENT session,
|
||||
// the same car most likely minted a second ticket (a motion radar dropped the stationary
|
||||
// car → the button re-armed). We sign ONE entry.duplicatePlate anomaly for the operator
|
||||
// to void. Post-hoc + advisory: recognition never gates the (already-open) barrier —
|
||||
// exactly the non-blocking role the plate can play here.
|
||||
|
||||
let db: Db;
|
||||
let log: EventLog;
|
||||
|
||||
const PLATE = "AA111BB";
|
||||
const OLD = "11111111111";
|
||||
const NEW = "22222222222";
|
||||
|
||||
beforeEach(() => {
|
||||
({ db } = createTestDb());
|
||||
log = makeLog(db);
|
||||
});
|
||||
|
||||
/** Seed the prior entry's unsigned plate-read telemetry (what recognizePlate records). */
|
||||
function seedPriorRead(opts: { identity?: string; plate?: string; direction?: string; agoMs?: number } = {}) {
|
||||
db.insert(deviceEventsTable).values({
|
||||
id: randomUUID(),
|
||||
deviceId: "cam-entry",
|
||||
category: "camera",
|
||||
kind: "read",
|
||||
detail: {
|
||||
identity: opts.identity ?? OLD,
|
||||
direction: opts.direction ?? "entry",
|
||||
plate: opts.plate ?? PLATE,
|
||||
snapshotId: "snap-old",
|
||||
source: "entry-exit-snapshot",
|
||||
},
|
||||
occurredAt: new Date(Date.now() - (opts.agoMs ?? 60_000)).toISOString(),
|
||||
}).run();
|
||||
}
|
||||
|
||||
function seedSession(id: string, state: "open" | "closed") {
|
||||
db.insert(sessions).values({
|
||||
id,
|
||||
identity: id,
|
||||
source: "ticket",
|
||||
enteredAt: new Date(Date.now() - 60_000).toISOString(),
|
||||
state,
|
||||
}).run();
|
||||
}
|
||||
|
||||
const flag = () =>
|
||||
flagDuplicateEntryPlate({ db, log, identity: NEW, plate: PLATE, snapshotId: "snap-new", logger: silentLogger() });
|
||||
|
||||
const anomalies = () =>
|
||||
db.select().from(ledgerEvents).all().filter((r) => r.type === "anomaly");
|
||||
|
||||
describe("flagDuplicateEntryPlate", () => {
|
||||
it("same plate OPEN under another recent session → signs ONE entry.duplicatePlate anomaly", async () => {
|
||||
seedPriorRead();
|
||||
seedSession(OLD, "open");
|
||||
await flag();
|
||||
expect(anomalies()).toHaveLength(1);
|
||||
const a = anomalies()[0];
|
||||
expect(a.identity).toBe(NEW); // keyed to the NEW (suspect) ticket
|
||||
expect(a.payload).toMatchObject({
|
||||
reasonCode: "entry.duplicatePlate",
|
||||
duplicateEntrySuspected: true,
|
||||
plate: PLATE,
|
||||
otherIdentity: OLD,
|
||||
snapshotId: "snap-new",
|
||||
});
|
||||
});
|
||||
|
||||
it("prior session already CLOSED → no anomaly (that car drove off; a re-visit is legit)", async () => {
|
||||
seedPriorRead();
|
||||
seedSession(OLD, "closed");
|
||||
await flag();
|
||||
expect(anomalies()).toHaveLength(0);
|
||||
});
|
||||
|
||||
it("prior read outside the window → no anomaly (stale coincidence, not a double press)", async () => {
|
||||
seedPriorRead({ agoMs: 30 * 60_000 }); // beyond the 15-min default window
|
||||
seedSession(OLD, "open");
|
||||
await flag();
|
||||
expect(anomalies()).toHaveLength(0);
|
||||
});
|
||||
|
||||
it("own read (same identity) never flags itself", async () => {
|
||||
seedPriorRead({ identity: NEW });
|
||||
seedSession(NEW, "open");
|
||||
await flag();
|
||||
expect(anomalies()).toHaveLength(0);
|
||||
});
|
||||
|
||||
it("different plate / exit-side reads are ignored", async () => {
|
||||
seedPriorRead({ plate: "ZZ999ZZ" });
|
||||
seedPriorRead({ direction: "exit" });
|
||||
seedSession(OLD, "open");
|
||||
await flag();
|
||||
expect(anomalies()).toHaveLength(0);
|
||||
});
|
||||
});
|
||||
@@ -0,0 +1,40 @@
|
||||
import { describe, expect, it } from "vitest";
|
||||
import { validateTicketCode } from "./entry-flow.js";
|
||||
|
||||
// validateTicketCode is the manual-entry typo guard: an all-digit code whose last digit
|
||||
// is the Luhn check of the rest. The booth uses it to reject a mistyped ticket up front
|
||||
// (instead of a confusing "session not found"). The capacity-gate / print-hold / sign-
|
||||
// before-open paths of EntryFlow need device fakes and are exercised in the device +
|
||||
// route phases; here we pin the pure, exported checksum contract.
|
||||
|
||||
describe("validateTicketCode (Luhn)", () => {
|
||||
it("accepts a well-formed 11-digit id", () => {
|
||||
// 10-digit body + its Luhn check digit. 0000000000 → check digit 0.
|
||||
expect(validateTicketCode("00000000000")).toBe(true);
|
||||
});
|
||||
|
||||
it("rejects a single-digit typo", () => {
|
||||
expect(validateTicketCode("00000000000")).toBe(true);
|
||||
expect(validateTicketCode("00000000010")).toBe(false); // flipped a digit, checksum now wrong
|
||||
});
|
||||
|
||||
it("rejects non-digit and out-of-length strings", () => {
|
||||
expect(validateTicketCode("abc")).toBe(false);
|
||||
expect(validateTicketCode("123")).toBe(false); // too short
|
||||
expect(validateTicketCode("123456789012345")).toBe(false); // too long
|
||||
expect(validateTicketCode("")).toBe(false);
|
||||
});
|
||||
|
||||
it("round-trips a generated body+check (Luhn is self-consistent)", () => {
|
||||
// Construct a valid code: pick a body, compute its check the same way the issuer does.
|
||||
const body = "4992739871";
|
||||
// brute the check digit 0..9 — exactly one makes a valid code.
|
||||
const valid = Array.from({ length: 10 }, (_, d) => body + d).filter(validateTicketCode);
|
||||
expect(valid).toHaveLength(1);
|
||||
});
|
||||
|
||||
it("accepts a legacy 13-digit id shape", () => {
|
||||
// 12-digit body 000000000000 → check 0; the validator is length-agnostic in 10..14.
|
||||
expect(validateTicketCode("0000000000000")).toBe(true);
|
||||
});
|
||||
});
|
||||
+212
-24
@@ -9,13 +9,14 @@ import {
|
||||
type PrinterInstance,
|
||||
type TicketData,
|
||||
type TicketHeader,
|
||||
printerRoleOf,
|
||||
} from "@parking/devices";
|
||||
import { DEFAULT_VEHICLE_CATEGORY, reasonPayload } from "@parking/shared";
|
||||
import type { FastifyBaseLogger } from "fastify";
|
||||
import type { DeviceInputEvent } from "./device-events.js";
|
||||
import type { DeviceInputEvent, LaneStatusEvent } from "./device-events.js";
|
||||
import { getOccupancy } from "./occupancy.js";
|
||||
import type { EventLog } from "./event-log.js";
|
||||
import { devicesByDirection, relayForButton, relayForPresence, type ResolvedRelay } from "./device-resolve.js";
|
||||
import { devicesByDirection, firstRelayByDirection, relayForButton, relayForPresence, type ResolvedRelay } from "./device-resolve.js";
|
||||
import { snapshotAsync } from "./snapshot.js";
|
||||
import type { VisionClient } from "./vision-client.js";
|
||||
|
||||
@@ -48,9 +49,21 @@ import type { VisionClient } from "./vision-client.js";
|
||||
// input edges to track presence + "armed" per relay.
|
||||
// - COOLDOWN (fallback, no feedback): `entryCooldownSec` suppresses repeat presses on
|
||||
// the relay for N seconds after a ticket. A timer — mitigation, not a guarantee.
|
||||
// When a loop IS wired the cooldown still runs as a BACKSTOP behind it: a motion
|
||||
// radar can drop a STATIONARY car (no doppler return) and spuriously re-arm, and the
|
||||
// cooldown bounds how fast that re-armed press can mint a second ticket.
|
||||
// - CAMERA (when an entry camera is configured): a press is live only while the entry
|
||||
// lane camera confirms a vehicle — the button lamp's SOLID state (button-light.ts).
|
||||
// A radar false-positive (rain, a pedestrian) blinks the lamp but prints nothing.
|
||||
// Camera-less sites keep the radar-only gate; a faulty camera is dropped via the
|
||||
// admin bypass (wiki/concepts/entry-presence-bypass.md).
|
||||
// A suppressed press is recorded as UNSIGNED telemetry (a no-op, not a fraud anomaly).
|
||||
// See wiki/concepts/entry-double-press.md.
|
||||
|
||||
/** A presence signal the entry gate can require (or, when a device is faulty, the admin
|
||||
* can bypass): the radar/loop presence input, or the camera vehicle-detection. */
|
||||
export type PresenceSignal = "radar" | "camera";
|
||||
|
||||
/** Per-relay anti-double-press state, keyed `controllerId:relay`. */
|
||||
interface RelayGuardState {
|
||||
/** Last successful ticket time (ms epoch) — drives the cooldown check. */
|
||||
@@ -72,6 +85,10 @@ export class EntryFlow {
|
||||
readonly #guard = new Map<string, RelayGuardState>();
|
||||
/** Optional vision client — passed to snapshotAsync so ANPR runs on the entry image. */
|
||||
readonly #vision: VisionClient | null;
|
||||
/** Live entry-lane camera state (LaneStatus mirror, fed by onLaneStatus). Gates the
|
||||
* physical press when an entry camera is configured — advisory sensor, but here it
|
||||
* only ever SUPPRESSES a reprint; it never opens a barrier or traps a car. */
|
||||
#entryBusy = false;
|
||||
|
||||
constructor(db: Db, log: EventLog, logger: FastifyBaseLogger, vision: VisionClient | null = null) {
|
||||
this.#db = db;
|
||||
@@ -121,6 +138,12 @@ export class EntryFlow {
|
||||
}
|
||||
}
|
||||
|
||||
/** Track the entry lane's camera state (wired to deviceEvents.onLaneStatus in
|
||||
* server.ts). LaneStatus emits on every flip, so this mirror stays current. */
|
||||
onLaneStatus(s: LaneStatusEvent): void {
|
||||
this.#entryBusy = s.entry;
|
||||
}
|
||||
|
||||
/** Stable per-relay key for the guard map. */
|
||||
#relayKey(r: ResolvedRelay): string {
|
||||
return `${r.controller.id}:${r.relay}`;
|
||||
@@ -153,17 +176,35 @@ export class EntryFlow {
|
||||
}
|
||||
|
||||
/** Why a press should be SUPPRESSED (no ticket), or null if it may proceed.
|
||||
* PRESENCE mode is authoritative when a loop is wired; otherwise COOLDOWN; else no
|
||||
* guard (legacy). The two can coexist — presence first, cooldown as a backstop. */
|
||||
* Three layered gates: CAMERA (when an entry camera is configured), PRESENCE
|
||||
* (when a loop is wired), and COOLDOWN — no longer alternatives: the cooldown
|
||||
* runs as a backstop BEHIND presence, because a motion radar can drop a
|
||||
* stationary car and spuriously re-arm one-car-one-ticket. */
|
||||
#suppressReason(r: ResolvedRelay): string | null {
|
||||
const s = this.#guardState(r);
|
||||
const bypass = this.#presenceBypass();
|
||||
|
||||
if (typeof r.presenceInput === "number") {
|
||||
// CAMERA GATE — the lamp's blink-vs-solid rule, enforced at the press: with an entry
|
||||
// camera configured, a press is live only once the camera confirms a vehicle in the
|
||||
// entry zone (SOLID). Blink (radar-only — rain, a pedestrian, a reflection) prints
|
||||
// nothing. Only ever suppresses a ticket; never opens or traps (advisory rule kept).
|
||||
// A camera-less site skips this; a faulty camera is dropped via the admin bypass.
|
||||
if (!bypass.camera && !this.#entryBusy && this.#entryCameraConfigured()) {
|
||||
return "no camera-confirmed vehicle in the entry zone";
|
||||
}
|
||||
|
||||
// Admin bypass for a FAULTY radar/loop: skip the presence-loop check so a press prints.
|
||||
// A dead loop can't re-arm one-car-one-ticket, so the cooldown below is what stops a
|
||||
// held button minting a burst. If no cooldown is configured there's no anti-double-press
|
||||
// left — that's the admin's accepted tradeoff while bypassed. See
|
||||
// wiki/concepts/entry-presence-bypass.md.
|
||||
if (typeof r.presenceInput === "number" && !bypass.radar) {
|
||||
// Physical one-car-one-ticket: a car must be present AND we must be armed (no
|
||||
// ticket already issued for this still-present car).
|
||||
if (!s.present) return "no vehicle at the barrier (presence loop clear)";
|
||||
if (!s.armed) return "ticket already issued for the car at the barrier";
|
||||
return null;
|
||||
// Fall THROUGH to the cooldown backstop: a presence-approved press can still be the
|
||||
// SAME stationary car after a radar dropout re-armed the guard.
|
||||
}
|
||||
|
||||
if (typeof r.entryCooldownSec === "number" && r.entryCooldownSec > 0) {
|
||||
@@ -176,6 +217,13 @@ export class EntryFlow {
|
||||
return null;
|
||||
}
|
||||
|
||||
/** Is at least one enabled camera bound to the entry lane? The camera gate applies only
|
||||
* then — a site with no entry camera keeps the radar-only press gate. Read live (like
|
||||
* the bypass flags) so adding/removing a camera needs no restart. */
|
||||
#entryCameraConfigured(): boolean {
|
||||
return devicesByDirection(this.#db, "camera", "entry").length > 0;
|
||||
}
|
||||
|
||||
/** Record a suppressed (repeat/no-car) entry press as UNSIGNED telemetry — a no-op,
|
||||
* not a fraud anomaly, so the signed ledger stays clean (the operator's choice). */
|
||||
#recordSuppressedPress(e: DeviceInputEvent, r: ResolvedRelay, reason: string): void {
|
||||
@@ -229,9 +277,36 @@ export class EntryFlow {
|
||||
return;
|
||||
}
|
||||
|
||||
await this.#issueTicket(resolved, { source: "ticket" });
|
||||
}
|
||||
|
||||
/**
|
||||
* The shared "issue a transient ticket" sequence used by BOTH the physical button
|
||||
* (#runEntry) and the operator-initiated path (issueForOperator) — ONE copy of the
|
||||
* fraud-critical ordering (print → sign vehicle_entry BEFORE open → open → snapshot →
|
||||
* cache), never a divergent second copy. `opts.source` is "ticket" (button) or "booth"
|
||||
* (operator). For an operator mint we stamp `operatorInitiated` + `operator` on the
|
||||
* signed entry AND append a companion `anomaly` (the operator-adversary path always
|
||||
* leaves a red-flag row); `overCapacity` records a full-lot override. Returns the
|
||||
* outcome so the operator route can report it. See wiki/concepts/operator-issued-entry.md.
|
||||
*/
|
||||
async #issueTicket(
|
||||
resolved: ResolvedRelay,
|
||||
opts: {
|
||||
source: "ticket" | "manual";
|
||||
operator?: string;
|
||||
overCapacity?: { count: number; capacity: number | null };
|
||||
/** Presence signals that were BYPASSED (admin dropped them due to faulty hardware).
|
||||
* Recorded on the signed entry so a ticket issued under a weakened gate is auditable. */
|
||||
presenceBypassed?: PresenceSignal[];
|
||||
},
|
||||
): Promise<{ ok: true; ticketId: string; opened: boolean } | { ok: false; reason: string }> {
|
||||
const ticketId = newTicketId();
|
||||
const issuedAt = new Date().toISOString();
|
||||
const printers = this.#loadPrinters();
|
||||
// Operator mint = ledger source "manual" (human intervention, like the barrier re-open)
|
||||
// + operatorInitiated:true in the payload. The button path is source "ticket".
|
||||
const operatorInitiated = opts.source === "manual";
|
||||
|
||||
// 1. PRINT FIRST. The ticket is the transient's session key — no ticket, no entry.
|
||||
const ticket: TicketData = { ticketId, issuedAt, header: this.#ticketHeader() };
|
||||
@@ -260,17 +335,14 @@ export class EntryFlow {
|
||||
// Capture who is held at the barrier (evidence for the operator handling the car).
|
||||
this.#fireSnapshot("entry", ticketId);
|
||||
this.#logger.warn(`entry HELD: ${reason} (barrier NOT opened)`);
|
||||
return;
|
||||
return { ok: false, reason };
|
||||
}
|
||||
|
||||
// 2. SIGN the vehicle_entry — BEFORE the relay fires (the core invariant).
|
||||
// `category` is FROZEN here (in the signed payload) so the tariff prices and
|
||||
// later reprices the same way at exit. Today every transient takes the SITE
|
||||
// default category (operator policy, site_config.default_vehicle_category;
|
||||
// falls back to the shared DEFAULT_VEHICLE_CATEGORY). Per-relay capture (a
|
||||
// "bus lane" relay, mirroring how direction is per-relay in device-resolve.ts)
|
||||
// is the future seam — source it from `resolved` then. A V1/no-category tariff
|
||||
// ignores it; only V2 category cards consult it.
|
||||
// falls back to the shared DEFAULT_VEHICLE_CATEGORY).
|
||||
const cfg = this.#db.select().from(siteConfig).where(eq(siteConfig.id, 1)).get();
|
||||
const category =
|
||||
cfg?.defaultVehicleCategory && cfg.defaultVehicleCategory.length > 0
|
||||
@@ -279,44 +351,160 @@ export class EntryFlow {
|
||||
await this.#log.append({
|
||||
type: "vehicle_entry",
|
||||
direction: "entry",
|
||||
source: "ticket",
|
||||
source: opts.source,
|
||||
identity: ticketId,
|
||||
payload: { sessionRef: ticketId, ticketPrinted: true, category },
|
||||
payload: {
|
||||
sessionRef: ticketId,
|
||||
ticketPrinted: true,
|
||||
category,
|
||||
...(operatorInitiated ? { operatorInitiated: true, operator: opts.operator } : {}),
|
||||
...(opts.overCapacity ? { lotFull: true, occupancy: `${opts.overCapacity.count}/${opts.overCapacity.capacity ?? "∞"}` } : {}),
|
||||
...(opts.presenceBypassed && opts.presenceBypassed.length > 0
|
||||
? { presenceBypassed: opts.presenceBypassed }
|
||||
: {}),
|
||||
},
|
||||
occurredAt: issuedAt,
|
||||
});
|
||||
|
||||
// 2b. For an operator mint, append a companion ANOMALY — the operator-adversary path
|
||||
// always leaves a red-flag row in the tamper-evident record for reconciliation.
|
||||
if (operatorInitiated) {
|
||||
await this.#log.append({
|
||||
type: "anomaly",
|
||||
identity: ticketId,
|
||||
payload: {
|
||||
...reasonPayload("entry.operatorIssued", { operator: opts.operator ?? "?" }),
|
||||
source: "booth",
|
||||
operatorInitiated: true,
|
||||
...(opts.operator ? { operator: opts.operator } : {}),
|
||||
...(opts.overCapacity ? { lotFull: true } : {}),
|
||||
},
|
||||
});
|
||||
}
|
||||
|
||||
// 3. OPEN the resolved entry barrier (intent only; the barrier owns the close).
|
||||
const access = this.#buildAccess(resolved.controller);
|
||||
if (access) await access.pulseOpen(resolved.relay);
|
||||
else this.#logger.warn(`entry signed for ${ticketId} but the entry relay won't build`);
|
||||
let opened = false;
|
||||
if (access) {
|
||||
await access.pulseOpen(resolved.relay);
|
||||
opened = true;
|
||||
} else this.#logger.warn(`entry signed for ${ticketId} but the entry relay won't build`);
|
||||
|
||||
// 3b. SNAPSHOT — fire the entry camera(s), never awaited (evidence, not a gate;
|
||||
// a camera failure must not delay or block the already-open barrier).
|
||||
// 3b. SNAPSHOT — fire the entry camera(s), never awaited (evidence, not a gate; a
|
||||
// camera failure must not delay or block the already-open barrier). This is ALSO
|
||||
// what records the plate that plate-reconciliation reads at exit.
|
||||
this.#fireSnapshot("entry", ticketId);
|
||||
|
||||
// 4. Update the session projection cache (rebuildable from the ledger; this is
|
||||
// just a fast read-model, never the source of truth).
|
||||
// 4. Update the session projection cache (rebuildable from the ledger; a read-model).
|
||||
try {
|
||||
this.#db
|
||||
.insert(sessions)
|
||||
.values({ id: ticketId, identity: ticketId, source: "ticket", enteredAt: issuedAt, state: "open" })
|
||||
.values({ id: ticketId, identity: ticketId, source: opts.source, enteredAt: issuedAt, state: "open" })
|
||||
.run();
|
||||
} catch (err) {
|
||||
// Cache miss is non-fatal — the ledger is authoritative and the projection
|
||||
// can be rebuilt. Log it; don't fail the (already-open) entry.
|
||||
this.#logger.error(`session-cache insert failed for ${ticketId}: ${(err as Error).message}`);
|
||||
}
|
||||
return { ok: true, ticketId, opened };
|
||||
}
|
||||
|
||||
/**
|
||||
* OPERATOR-ISSUED entry (physical entry button broken). Gated exactly like the button:
|
||||
* a REAL vehicle must be present at the entry — BOTH radar/loop presence AND camera
|
||||
* confirmation. `cameraBusy` is the current LaneStatus.entry (passed by the route); loop
|
||||
* presence is this flow's own per-relay guard state. If a site has no presence loop the
|
||||
* feature is unavailable (we require both — no weaker fallback). Refuses (+ signs an
|
||||
* anomaly) when no vehicle is present, so probing the endpoint is itself recorded. Over
|
||||
* capacity is ALLOWED but flagged (a broken button mustn't trap a legit car). The mint
|
||||
* itself is flagged (source:"booth" + operatorInitiated + a companion anomaly).
|
||||
* See wiki/concepts/operator-issued-entry.md.
|
||||
*/
|
||||
async issueForOperator(operator: string, cameraBusy: boolean): Promise<
|
||||
{ ok: true; ticketId: string; opened: boolean; overCapacity: boolean } | { ok: false; reason: string }
|
||||
> {
|
||||
const resolved = firstRelayByDirection(this.#db, "entry");
|
||||
if (!resolved) return { ok: false, reason: "no entry barrier configured" };
|
||||
|
||||
// PRESENCE GATE — normally require BOTH radar/loop presence AND camera detection. An
|
||||
// admin may BYPASS a signal when its device is faulty (site_config, signed config_change);
|
||||
// the bypassed signal is dropped as a requirement and RECORDED on the issued ticket.
|
||||
const bypass = this.#presenceBypass();
|
||||
const bypassed: PresenceSignal[] = [];
|
||||
|
||||
// Radar/loop side. A configured loop is only mandatory while radar is still REQUIRED;
|
||||
// if radar is bypassed we skip the loop entirely (a dead loop is exactly why they bypass).
|
||||
const radarRequired = !bypass.radar;
|
||||
let radarPresent: boolean | null = null;
|
||||
if (radarRequired) {
|
||||
if (typeof resolved.presenceInput !== "number") {
|
||||
return { ok: false, reason: "no presence loop on the entry barrier — operator issue unavailable (or bypass radar)" };
|
||||
}
|
||||
radarPresent = this.#guardState(resolved).present;
|
||||
} else {
|
||||
bypassed.push("radar");
|
||||
}
|
||||
|
||||
// Camera side.
|
||||
const cameraRequired = !bypass.camera;
|
||||
if (!cameraRequired) bypassed.push("camera");
|
||||
|
||||
// Refuse only when a STILL-REQUIRED signal fails to confirm a vehicle.
|
||||
const radarOk = !radarRequired || radarPresent === true;
|
||||
const cameraOk = !cameraRequired || cameraBusy;
|
||||
if (!radarOk || !cameraOk) {
|
||||
await this.#log.append({
|
||||
type: "anomaly",
|
||||
identity: `ENTRY-ATTEMPT-${randomUUID().replace(/-/g, "").slice(0, 12)}`,
|
||||
payload: {
|
||||
...reasonPayload("entry.issue.noPresence", { operator }),
|
||||
source: "booth",
|
||||
operator,
|
||||
radarPresent,
|
||||
cameraBusy,
|
||||
...(bypassed.length > 0 ? { presenceBypassed: bypassed } : {}),
|
||||
},
|
||||
});
|
||||
this.#logger.warn(
|
||||
`operator entry refused by ${operator}: no vehicle present (radar=${radarPresent}, camera=${cameraBusy}, bypassed=[${bypassed.join(",")}])`,
|
||||
);
|
||||
return { ok: false, reason: "no vehicle detected at the entry" };
|
||||
}
|
||||
|
||||
const key = `operator-issue:${this.#relayKey(resolved)}`;
|
||||
if (this.#inFlight.has(key)) return { ok: false, reason: "an entry is already in progress" };
|
||||
this.#inFlight.add(key);
|
||||
try {
|
||||
const occ = getOccupancy(this.#db);
|
||||
const res = await this.#issueTicket(resolved, {
|
||||
source: "manual",
|
||||
operator,
|
||||
...(occ.full ? { overCapacity: { count: occ.count, capacity: occ.capacity ?? null } } : {}),
|
||||
...(bypassed.length > 0 ? { presenceBypassed: bypassed } : {}),
|
||||
});
|
||||
if (!res.ok) return res;
|
||||
return { ok: true, ticketId: res.ticketId, opened: res.opened, overCapacity: occ.full };
|
||||
} finally {
|
||||
this.#inFlight.delete(key);
|
||||
}
|
||||
}
|
||||
|
||||
/** Fire the entry camera(s) for an identity; never awaited (evidence, not a gate).
|
||||
* Used on both the OPEN path and the refused/held anomaly paths — a turned-away or
|
||||
* held car is exactly when the operator wants the photo. */
|
||||
#fireSnapshot(direction: "entry", identity: string): void {
|
||||
void snapshotAsync({ db: this.#db, direction, identity, logger: this.#logger, vision: this.#vision }).catch(
|
||||
// `log` lets the ANPR ride-along flag a duplicate-plate entry (a signed anomaly) —
|
||||
// still fire-and-forget; recognition never gates the open. See snapshot.ts.
|
||||
void snapshotAsync({ db: this.#db, direction, identity, logger: this.#logger, vision: this.#vision, log: this.#log }).catch(
|
||||
(err) => this.#logger.error(`entry snapshot error: ${(err as Error).message}`),
|
||||
);
|
||||
}
|
||||
|
||||
/** Current admin presence-gate bypass (site_config), read LIVE so a toggle takes effect
|
||||
* with no restart. Default: nothing bypassed (the normal both-required gate). */
|
||||
#presenceBypass(): { radar: boolean; camera: boolean } {
|
||||
const cfg = this.#db.select().from(siteConfig).where(eq(siteConfig.id, 1)).get();
|
||||
return { radar: cfg?.bypassPresenceRadar ?? false, camera: cfg?.bypassPresenceCamera ?? false };
|
||||
}
|
||||
|
||||
/** Build a live access adapter from a resolved controller row, or null. */
|
||||
#buildAccess(row: DeviceRow): AccessControlDevice | null {
|
||||
const driver = registry.get(row.driverId);
|
||||
@@ -336,7 +524,7 @@ export class EntryFlow {
|
||||
const driver = registry.get(row.driverId);
|
||||
if (!driver) continue;
|
||||
const cfg = row.config as Record<string, unknown>;
|
||||
const role = cfg.role === "booth-receipt" ? "booth-receipt" : "entry-dispenser";
|
||||
const role = printerRoleOf(cfg);
|
||||
try {
|
||||
out.push({
|
||||
id: row.id,
|
||||
|
||||
@@ -0,0 +1,112 @@
|
||||
import { beforeEach, describe, expect, it } from "vitest";
|
||||
import { devices, siteConfig, ledgerEvents, type Db } from "@parking/db";
|
||||
import { createTestDb } from "@parking/db/testing";
|
||||
import { EntryFlow } from "./entry-flow.js";
|
||||
import { makeLog, silentLogger } from "./test-helpers.js";
|
||||
|
||||
// The entry presence gate normally requires BOTH radar/loop presence AND camera detection.
|
||||
// An admin may BYPASS a signal when its device is faulty (site_config, set via a signed
|
||||
// endpoint). These tests pin the GATE decision in EntryFlow.issueForOperator under each
|
||||
// bypass combination: a still-required-but-absent signal refuses (+ signs an anomaly); a
|
||||
// bypassed signal is dropped and recorded. We assert the gate outcome via the refuse path
|
||||
// (deterministic, no printer needed); the allow path is proven by getting PAST the gate
|
||||
// (it then fails at printing — a different reason — which is exactly "the gate opened").
|
||||
|
||||
let db: Db;
|
||||
let flow: EntryFlow;
|
||||
|
||||
const CTL = "ctl-entry";
|
||||
const PRESENCE_INPUT = 2;
|
||||
|
||||
beforeEach(() => {
|
||||
({ db } = createTestDb());
|
||||
// A controller with an entry barrier (R1), a presence loop on input 2, and an entry button
|
||||
// on input 1 — the shape device-resolve expects (relays[] + inputs[]).
|
||||
db.insert(devices).values({
|
||||
id: CTL,
|
||||
category: "access",
|
||||
driverId: "stub-access",
|
||||
config: {
|
||||
relays: [{ relay: 1, direction: "entry" }],
|
||||
inputs: [
|
||||
{ input: 1, role: "button", relay: 1 },
|
||||
{ input: PRESENCE_INPUT, role: "presence", relay: 1, kind: "loop" },
|
||||
],
|
||||
},
|
||||
enabled: true,
|
||||
}).run();
|
||||
flow = new EntryFlow(db, makeLog(db), silentLogger());
|
||||
});
|
||||
|
||||
function setBypass(patch: { radar?: boolean; camera?: boolean }) {
|
||||
db.insert(siteConfig)
|
||||
.values({ id: 1, bypassPresenceRadar: patch.radar ?? false, bypassPresenceCamera: patch.camera ?? false })
|
||||
.onConflictDoUpdate({
|
||||
target: siteConfig.id,
|
||||
set: { bypassPresenceRadar: patch.radar ?? false, bypassPresenceCamera: patch.camera ?? false },
|
||||
})
|
||||
.run();
|
||||
}
|
||||
|
||||
/** Drive a presence loop edge so the flow's per-relay guard marks a car present/clear. */
|
||||
async function setRadarPresent(present: boolean) {
|
||||
await flow.onInput({
|
||||
driverId: "stub-access",
|
||||
deviceId: CTL,
|
||||
input: PRESENCE_INPUT,
|
||||
edge: present ? "on" : "off",
|
||||
at: new Date().toISOString(),
|
||||
source: "poll",
|
||||
});
|
||||
}
|
||||
|
||||
const anomalies = () =>
|
||||
db.select().from(ledgerEvents).all().filter((r) => r.type === "anomaly");
|
||||
|
||||
describe("entry presence-gate bypass", () => {
|
||||
it("no bypass + no vehicle → refuses and signs a noPresence anomaly", async () => {
|
||||
const res = await flow.issueForOperator("admin", /*cameraBusy*/ false);
|
||||
expect(res.ok).toBe(false);
|
||||
expect(anomalies()).toHaveLength(1);
|
||||
expect(anomalies()[0].payload).toMatchObject({ reasonCode: "entry.issue.noPresence" });
|
||||
});
|
||||
|
||||
it("camera bypassed + radar present → gate OPENS (no refuse anomaly)", async () => {
|
||||
setBypass({ camera: true });
|
||||
await setRadarPresent(true);
|
||||
const res = await flow.issueForOperator("admin", /*cameraBusy*/ false); // camera absent but bypassed
|
||||
// Gate passed: no noPresence refusal. (It then proceeds to print — no printer configured,
|
||||
// so it HOLDS with a print reason, not a presence reason. Either way the gate opened.)
|
||||
const refusals = anomalies().filter((a) => (a.payload as { reasonCode?: string }).reasonCode === "entry.issue.noPresence");
|
||||
expect(refusals).toHaveLength(0);
|
||||
if (!res.ok) expect(res.reason).not.toMatch(/no vehicle detected/);
|
||||
});
|
||||
|
||||
it("radar bypassed + camera busy → gate OPENS even with NO presence loop reading", async () => {
|
||||
setBypass({ radar: true });
|
||||
// radar NOT set present; camera busy=true → radar dropped, camera satisfies.
|
||||
const res = await flow.issueForOperator("admin", /*cameraBusy*/ true);
|
||||
const refusals = anomalies().filter((a) => (a.payload as { reasonCode?: string }).reasonCode === "entry.issue.noPresence");
|
||||
expect(refusals).toHaveLength(0);
|
||||
if (!res.ok) expect(res.reason).not.toMatch(/no vehicle detected/);
|
||||
});
|
||||
|
||||
it("camera bypassed but radar STILL required and absent → refuses (only the faulty signal is dropped)", async () => {
|
||||
setBypass({ camera: true });
|
||||
await setRadarPresent(false); // radar required (not bypassed) and clear
|
||||
const res = await flow.issueForOperator("admin", /*cameraBusy*/ true);
|
||||
expect(res.ok).toBe(false);
|
||||
const refusal = anomalies().find((a) => (a.payload as { reasonCode?: string }).reasonCode === "entry.issue.noPresence");
|
||||
expect(refusal, "the still-required radar gates the button").toBeTruthy();
|
||||
// The refusal records which signal was bypassed (audit).
|
||||
expect(refusal!.payload).toMatchObject({ presenceBypassed: ["camera"] });
|
||||
});
|
||||
|
||||
it("both bypassed → gate OPENS with no radar and no camera (press-to-print)", async () => {
|
||||
setBypass({ radar: true, camera: true });
|
||||
const res = await flow.issueForOperator("admin", /*cameraBusy*/ false);
|
||||
const refusals = anomalies().filter((a) => (a.payload as { reasonCode?: string }).reasonCode === "entry.issue.noPresence");
|
||||
expect(refusals).toHaveLength(0);
|
||||
if (!res.ok) expect(res.reason).not.toMatch(/no vehicle detected/);
|
||||
});
|
||||
});
|
||||
@@ -0,0 +1,213 @@
|
||||
import { beforeEach, describe, expect, it } from "vitest";
|
||||
import { devices, siteConfig, ledgerEvents, deviceEvents as deviceEventsTable, type Db } from "@parking/db";
|
||||
import { createTestDb } from "@parking/db/testing";
|
||||
import { registry, type PrinterDevice } from "@parking/devices";
|
||||
import { EntryFlow } from "./entry-flow.js";
|
||||
import { makeLog, silentLogger } from "./test-helpers.js";
|
||||
|
||||
// The PHYSICAL entry button's press gate (#suppressReason), layered (2026-07-04):
|
||||
// CAMERA — with an entry camera configured, a press is live only while the entry lane
|
||||
// camera confirms a vehicle (the button lamp's SOLID state). Blink (radar-only) prints
|
||||
// nothing. Camera-less sites skip this; the admin camera bypass drops it.
|
||||
// PRESENCE — one-car-one-ticket off the loop (unchanged).
|
||||
// COOLDOWN — now a BACKSTOP behind presence, not an alternative: a motion radar drops a
|
||||
// stationary car (no doppler return), spuriously re-arming the guard; the cooldown bounds
|
||||
// how fast that re-armed press can mint a second ticket for the same car.
|
||||
// A suppressed press is unsigned telemetry (entrySuppressed), never a ledger anomaly.
|
||||
|
||||
let db: Db;
|
||||
let flow: EntryFlow;
|
||||
|
||||
const CTL = "ctl-entry";
|
||||
const BUTTON_INPUT = 1;
|
||||
const PRESENCE_INPUT = 2;
|
||||
|
||||
// A no-op printer that always succeeds, so the happy path reaches the signed
|
||||
// vehicle_entry (the real drivers need hardware). Registered once (registry is global).
|
||||
const noopPrinter: PrinterDevice = {
|
||||
driverId: "test-printer-ok",
|
||||
connect: async () => {},
|
||||
disconnect: async () => {},
|
||||
healthCheck: async () => ({ status: "ready" as const }),
|
||||
printTicket: async () => {},
|
||||
printReport: async () => {},
|
||||
printSubscriptionCard: async () => {},
|
||||
printReceipt: async () => {},
|
||||
printWindowChargeNotice: async () => {},
|
||||
};
|
||||
if (!registry.get("test-printer-ok")) {
|
||||
registry.register({
|
||||
id: "test-printer-ok",
|
||||
category: "printer",
|
||||
label: "Test printer",
|
||||
description: "always-succeeds stub for tests",
|
||||
transports: [],
|
||||
configFields: [],
|
||||
create: () => noopPrinter,
|
||||
});
|
||||
}
|
||||
|
||||
beforeEach(() => {
|
||||
({ db } = createTestDb());
|
||||
db.insert(devices).values({
|
||||
id: CTL,
|
||||
category: "access",
|
||||
driverId: "stub-access",
|
||||
config: {
|
||||
relays: [{ relay: 1, direction: "entry" }],
|
||||
inputs: [
|
||||
{ input: BUTTON_INPUT, role: "button", relay: 1 },
|
||||
{ input: PRESENCE_INPUT, role: "presence", relay: 1, kind: "radar" },
|
||||
],
|
||||
},
|
||||
enabled: true,
|
||||
}).run();
|
||||
db.insert(devices).values({
|
||||
id: "printer-entry",
|
||||
category: "printer",
|
||||
driverId: "test-printer-ok",
|
||||
config: { direction: "entry" },
|
||||
enabled: true,
|
||||
}).run();
|
||||
flow = new EntryFlow(db, makeLog(db), silentLogger());
|
||||
});
|
||||
|
||||
/** Add an entry camera row. The driver never builds (unknown id) — only its EXISTENCE
|
||||
* matters to the press gate; snapshot capture failing is the normal fire-and-forget path. */
|
||||
function addEntryCamera() {
|
||||
db.insert(devices).values({
|
||||
id: "cam-entry",
|
||||
category: "camera",
|
||||
driverId: "no-such-camera-driver",
|
||||
config: { direction: "entry" },
|
||||
enabled: true,
|
||||
}).run();
|
||||
}
|
||||
|
||||
function setCameraBypass(on: boolean) {
|
||||
db.insert(siteConfig)
|
||||
.values({ id: 1, bypassPresenceCamera: on })
|
||||
.onConflictDoUpdate({ target: siteConfig.id, set: { bypassPresenceCamera: on } })
|
||||
.run();
|
||||
}
|
||||
|
||||
async function edge(input: number, edge: "on" | "off") {
|
||||
await flow.onInput({
|
||||
driverId: "stub-access",
|
||||
deviceId: CTL,
|
||||
input,
|
||||
edge,
|
||||
at: new Date().toISOString(),
|
||||
source: "poll",
|
||||
});
|
||||
}
|
||||
|
||||
const press = () => edge(BUTTON_INPUT, "on");
|
||||
const radar = (present: boolean) => edge(PRESENCE_INPUT, present ? "on" : "off");
|
||||
|
||||
const entries = () =>
|
||||
db.select().from(ledgerEvents).all().filter((r) => r.type === "vehicle_entry");
|
||||
const suppressed = () =>
|
||||
db.select().from(deviceEventsTable).all()
|
||||
.map((r) => r.detail as { entrySuppressed?: boolean; reason?: string })
|
||||
.filter((d) => d.entrySuppressed === true);
|
||||
|
||||
describe("entry press gate — camera (blink vs solid)", () => {
|
||||
it("BLINK state (radar present, no camera confirmation) → press suppressed, nothing signed", async () => {
|
||||
addEntryCamera();
|
||||
await radar(true); // lamp would blink: radar sees something, camera does not
|
||||
await press();
|
||||
expect(entries()).toHaveLength(0);
|
||||
expect(db.select().from(ledgerEvents).all()).toHaveLength(0); // no anomaly either — telemetry only
|
||||
expect(suppressed()).toHaveLength(1);
|
||||
expect(suppressed()[0].reason).toMatch(/camera/);
|
||||
});
|
||||
|
||||
it("SOLID state (radar present + camera busy) → press prints and signs a vehicle_entry", async () => {
|
||||
addEntryCamera();
|
||||
await radar(true);
|
||||
flow.onLaneStatus({ entry: true, exit: false }); // camera confirms → SOLID
|
||||
await press();
|
||||
expect(entries()).toHaveLength(1);
|
||||
expect(suppressed()).toHaveLength(0);
|
||||
});
|
||||
|
||||
it("camera-less site → the camera gate does not apply (radar-only, as before)", async () => {
|
||||
await radar(true); // no camera row; lane state irrelevant
|
||||
await press();
|
||||
expect(entries()).toHaveLength(1);
|
||||
});
|
||||
|
||||
it("camera bypassed (faulty camera) → press prints without camera confirmation", async () => {
|
||||
addEntryCamera();
|
||||
setCameraBypass(true);
|
||||
await radar(true);
|
||||
await press();
|
||||
expect(entries()).toHaveLength(1);
|
||||
});
|
||||
|
||||
it("no car at all (radar clear too) → suppressed even with the camera bypassed", async () => {
|
||||
addEntryCamera();
|
||||
setCameraBypass(true);
|
||||
await press(); // radar never went on
|
||||
expect(entries()).toHaveLength(0);
|
||||
expect(suppressed()[0].reason).toMatch(/presence loop clear/);
|
||||
});
|
||||
});
|
||||
|
||||
describe("entry press gate — cooldown backstop behind presence", () => {
|
||||
/** Same lane but the button carries a cooldown, making it a backstop behind the loop. */
|
||||
function setButtonCooldown(sec: number) {
|
||||
db.delete(devices).run();
|
||||
db.insert(devices).values({
|
||||
id: CTL,
|
||||
category: "access",
|
||||
driverId: "stub-access",
|
||||
config: {
|
||||
relays: [{ relay: 1, direction: "entry" }],
|
||||
inputs: [
|
||||
{ input: BUTTON_INPUT, role: "button", relay: 1, cooldownSec: sec },
|
||||
{ input: PRESENCE_INPUT, role: "presence", relay: 1, kind: "radar" },
|
||||
],
|
||||
},
|
||||
enabled: true,
|
||||
}).run();
|
||||
db.insert(devices).values({
|
||||
id: "printer-entry",
|
||||
category: "printer",
|
||||
driverId: "test-printer-ok",
|
||||
config: { direction: "entry" },
|
||||
enabled: true,
|
||||
}).run();
|
||||
}
|
||||
|
||||
it("radar dropout re-arm + quick re-press → caught by the cooldown (one ticket)", async () => {
|
||||
setButtonCooldown(60);
|
||||
await radar(true);
|
||||
await press(); // ticket 1 (no camera configured — radar-only site)
|
||||
expect(entries()).toHaveLength(1);
|
||||
// The motion radar loses the STATIONARY car and re-fires: off (re-arms!) then on.
|
||||
await radar(false);
|
||||
await radar(true);
|
||||
await press(); // presence gate says yes (present + re-armed) — the backstop must catch it
|
||||
expect(entries()).toHaveLength(1);
|
||||
expect(suppressed().some((d) => /cooldown/.test(d.reason ?? ""))).toBe(true);
|
||||
});
|
||||
|
||||
it("without a cooldown the dropout re-press mints a second ticket (the documented residual risk)", async () => {
|
||||
await radar(true);
|
||||
await press();
|
||||
await radar(false);
|
||||
await radar(true);
|
||||
await press();
|
||||
expect(entries()).toHaveLength(2);
|
||||
});
|
||||
|
||||
it("still-present car re-pressing (no dropout) stays suppressed by one-car-one-ticket", async () => {
|
||||
await radar(true);
|
||||
await press();
|
||||
await press(); // car never left the loop → not re-armed
|
||||
expect(entries()).toHaveLength(1);
|
||||
expect(suppressed().some((d) => /already issued/.test(d.reason ?? ""))).toBe(true);
|
||||
});
|
||||
});
|
||||
@@ -0,0 +1,129 @@
|
||||
import { afterEach, beforeEach, describe, expect, it } from "vitest";
|
||||
import { createTestDb } from "@parking/db/testing";
|
||||
import { ledgerEvents, eq, type Db } from "@parking/db";
|
||||
import { EventLog, canonicalize, hashEvent } from "./event-log.js";
|
||||
import { SoftwareSigner, buildVerifier } from "./signer.js";
|
||||
|
||||
// The append-only, hash-chained, signed event log is THE anti-fraud primitive
|
||||
// (threat model: the operator at the booth). These tests pin every integrity rule:
|
||||
// monotonic index, prevHash linkage, payload-in-signature, and that verifyChain()
|
||||
// catches each class of tamper (content edit, reorder, deletion gap, forged sig,
|
||||
// missing key). No live DB is touched — a fresh in-memory SQLite per test.
|
||||
|
||||
const SECRET = "test-event-signing-key-0123456789";
|
||||
|
||||
let db: Db;
|
||||
let close: () => void;
|
||||
let log: EventLog;
|
||||
|
||||
beforeEach(() => {
|
||||
const t = createTestDb();
|
||||
db = t.db;
|
||||
close = t.close;
|
||||
log = new EventLog(db, new SoftwareSigner(SECRET), buildVerifier);
|
||||
});
|
||||
|
||||
afterEach(() => close());
|
||||
|
||||
describe("EventLog.append — chain construction", () => {
|
||||
it("assigns a monotonic index starting at 1", async () => {
|
||||
const a = await log.append({ type: "vehicle_entry", identity: "T1" });
|
||||
const b = await log.append({ type: "vehicle_exit", identity: "T1" });
|
||||
expect(a.index).toBe(1);
|
||||
expect(b.index).toBe(2);
|
||||
});
|
||||
|
||||
it("genesis event has a null prevHash; the next chains to it", async () => {
|
||||
const a = await log.append({ type: "vehicle_entry", identity: "T1" });
|
||||
const b = await log.append({ type: "vehicle_exit", identity: "T1" });
|
||||
expect(a.prevHash).toBeNull();
|
||||
expect(b.prevHash).toBe(hashEvent(canonicalize(a)));
|
||||
});
|
||||
|
||||
it("signs each row under the active keyId", async () => {
|
||||
const row = await log.append({ type: "payment", identity: "T1", payload: { amountMinor: 100 } });
|
||||
expect(row.keyId).toBe("sw-hmac-v2");
|
||||
expect(new SoftwareSigner(SECRET).verify(canonicalize(row), row.signature)).toBe(true);
|
||||
});
|
||||
|
||||
it("serializes concurrent appends without index collisions", async () => {
|
||||
const rows = await Promise.all(
|
||||
Array.from({ length: 25 }, (_, i) => log.append({ type: "vehicle_entry", identity: `T${i}` })),
|
||||
);
|
||||
const indices = rows.map((r) => r.index).sort((a, b) => a - b);
|
||||
expect(indices).toEqual(Array.from({ length: 25 }, (_, i) => i + 1));
|
||||
});
|
||||
});
|
||||
|
||||
describe("EventLog.verifyChain — integrity", () => {
|
||||
async function seed() {
|
||||
await log.append({ type: "vehicle_entry", identity: "T1", direction: "entry" });
|
||||
await log.append({ type: "payment", identity: "T1", payload: { amountMinor: 200, tariffVersionId: "tv1" } });
|
||||
await log.append({ type: "vehicle_exit", identity: "T1", direction: "exit" });
|
||||
}
|
||||
|
||||
it("accepts an untampered chain", async () => {
|
||||
await seed();
|
||||
expect(log.verifyChain()).toEqual({ ok: true });
|
||||
});
|
||||
|
||||
it("accepts an empty chain", () => {
|
||||
expect(log.verifyChain()).toEqual({ ok: true });
|
||||
});
|
||||
|
||||
it("detects a tampered payload (the money amount)", async () => {
|
||||
await seed();
|
||||
// Rewrite the payment amount directly in the DB — exactly the booth-operator
|
||||
// fraud the signed payload defends against.
|
||||
db.update(ledgerEvents).set({ payload: { amountMinor: 1, tariffVersionId: "tv1" } }).where(eq(ledgerEvents.index, 2)).run();
|
||||
const r = log.verifyChain();
|
||||
expect(r.ok).toBe(false);
|
||||
if (!r.ok) {
|
||||
expect(r.index).toBe(2);
|
||||
expect(r.reason).toMatch(/signature invalid/);
|
||||
}
|
||||
});
|
||||
|
||||
it("detects a deleted row as an index gap", async () => {
|
||||
await seed();
|
||||
db.delete(ledgerEvents).where(eq(ledgerEvents.index, 2)).run();
|
||||
const r = log.verifyChain();
|
||||
expect(r.ok).toBe(false);
|
||||
if (!r.ok) expect(r.reason).toMatch(/index gap/);
|
||||
});
|
||||
|
||||
it("detects a broken prevHash link (reordering / re-chaining)", async () => {
|
||||
await seed();
|
||||
db.update(ledgerEvents).set({ prevHash: "0".repeat(64) }).where(eq(ledgerEvents.index, 3)).run();
|
||||
const r = log.verifyChain();
|
||||
expect(r.ok).toBe(false);
|
||||
if (!r.ok) {
|
||||
expect(r.index).toBe(3);
|
||||
expect(r.reason).toMatch(/prevHash/);
|
||||
}
|
||||
});
|
||||
|
||||
it("detects an event signed under a key that is no longer configured", async () => {
|
||||
await seed();
|
||||
// Re-sign row 2 under an unknown keyId — buildVerifier can't resolve it.
|
||||
db.update(ledgerEvents).set({ keyId: "atecc608-slot9" }).where(eq(ledgerEvents.index, 2)).run();
|
||||
const r = log.verifyChain();
|
||||
expect(r.ok).toBe(false);
|
||||
if (!r.ok) expect(r.reason).toMatch(/no signer for keyId/);
|
||||
});
|
||||
});
|
||||
|
||||
describe("canonicalize — byte-stability", () => {
|
||||
it("is independent of payload key order (sorted recursively)", () => {
|
||||
const base = { index: 1, type: "payment", direction: null, source: null, identity: "T1", occurredAt: "2026-06-21T10:00:00.000Z", prevHash: null };
|
||||
const a = canonicalize({ ...base, payload: { amountMinor: 100, tariffVersionId: "tv1" } });
|
||||
const b = canonicalize({ ...base, payload: { tariffVersionId: "tv1", amountMinor: 100 } });
|
||||
expect(a).toBe(b);
|
||||
});
|
||||
|
||||
it("changes when any signed field changes", () => {
|
||||
const base = { index: 1, type: "payment" as const, direction: null, source: null, identity: "T1", payload: { amountMinor: 100 }, occurredAt: "2026-06-21T10:00:00.000Z", prevHash: null };
|
||||
expect(canonicalize(base)).not.toBe(canonicalize({ ...base, payload: { amountMinor: 101 } }));
|
||||
expect(canonicalize(base)).not.toBe(canonicalize({ ...base, identity: "T2" }));
|
||||
});
|
||||
});
|
||||
@@ -0,0 +1,192 @@
|
||||
import { afterEach, beforeEach, describe, expect, it } from "vitest";
|
||||
import { createTestDb } from "@parking/db/testing";
|
||||
import { ledgerEvents, deviceEvents as deviceEventsTable, sessions as sessionsTable, eq, type Db } from "@parking/db";
|
||||
import { randomUUID } from "node:crypto";
|
||||
import { ExitFlow } from "./exit-flow.js";
|
||||
import { PayStation } from "./pay-station.js";
|
||||
import type { EventLog } from "./event-log.js";
|
||||
import { makeLog, silentLogger, seedTariff, minutesAgo } from "./test-helpers.js";
|
||||
|
||||
// The exit flow is the anti-fraud GATE: no car leaves without a covering payment within
|
||||
// the walk-back grace (the no-unpaid-bypass + no-free-overstay rules), and the booth has
|
||||
// no bypass. With no relay configured a clean exit returns { opened:false } — we assert
|
||||
// the DECISION (refuse vs. sign the exit), not the hardware open.
|
||||
|
||||
let db: Db;
|
||||
let close: () => void;
|
||||
let log: EventLog;
|
||||
let exit: ExitFlow;
|
||||
let pay: PayStation;
|
||||
|
||||
beforeEach(() => {
|
||||
const t = createTestDb();
|
||||
db = t.db;
|
||||
close = t.close;
|
||||
log = makeLog(db);
|
||||
exit = new ExitFlow(db, log, silentLogger());
|
||||
pay = new PayStation(db, log, silentLogger());
|
||||
});
|
||||
afterEach(() => close());
|
||||
|
||||
async function enter(identity: string, enteredAt: string, payload?: Record<string, unknown>) {
|
||||
await log.append({ type: "vehicle_entry", direction: "entry", identity, occurredAt: enteredAt, payload: payload ?? null });
|
||||
}
|
||||
function exitsSigned(identity: string) {
|
||||
return db.select().from(ledgerEvents).where(eq(ledgerEvents.identity, identity)).all().filter((r) => r.type === "vehicle_exit");
|
||||
}
|
||||
function anomalies(reason?: string) {
|
||||
return db.select().from(ledgerEvents).where(eq(ledgerEvents.type, "anomaly")).all()
|
||||
.filter((r) => !reason || (r.payload as { reason?: string } | null)?.reason?.includes(reason));
|
||||
}
|
||||
/** Seed the projection-cache open-session row + an ANPR plate read (device_events) so the
|
||||
* plate-reconciliation check can see this identity's plate against open sessions. */
|
||||
function seedOpenWithPlate(identity: string, plate: string, confidence: number, enteredAt: string) {
|
||||
db.insert(sessionsTable).values({ id: identity, identity, source: "ticket", enteredAt, state: "open" }).run();
|
||||
db.insert(deviceEventsTable).values({
|
||||
id: randomUUID(), deviceId: "cam-entry", category: "camera", kind: "read", occurredAt: enteredAt,
|
||||
detail: { identity, direction: "entry", plate, confidence },
|
||||
}).run();
|
||||
}
|
||||
|
||||
describe("exitForBooth — refusal gates", () => {
|
||||
it("refuses an unknown ticket (no session) and signs an anomaly", async () => {
|
||||
const r = await exit.exitForBooth("ghost");
|
||||
expect(r).toMatchObject({ ok: false, status: "no_session" });
|
||||
const anomalies = db.select().from(ledgerEvents).where(eq(ledgerEvents.type, "anomaly")).all();
|
||||
expect(anomalies).toHaveLength(1);
|
||||
expect(exitsSigned("ghost")).toHaveLength(0);
|
||||
});
|
||||
|
||||
it("refuses an UNPAID open session — no exit signed (no-unpaid-bypass)", async () => {
|
||||
seedTariff(db, { pricePerIncrementMinor: 10000 });
|
||||
await enter("T1", minutesAgo(90));
|
||||
const r = await exit.exitForBooth("T1");
|
||||
expect(r).toMatchObject({ ok: false, status: "unpaid" });
|
||||
expect(exitsSigned("T1")).toHaveLength(0); // the car did NOT leave
|
||||
});
|
||||
|
||||
it("refuses a paid session whose walk-back grace has EXPIRED (no free overstay)", async () => {
|
||||
seedTariff(db, { pricePerIncrementMinor: 10000, gracePeriodExitMin: 15 });
|
||||
await enter("T1", minutesAgo(200));
|
||||
// A payment made 60 min ago → its 15-min walk-back grace lapsed long ago.
|
||||
await log.append({
|
||||
type: "payment", source: "manual", identity: "T1", occurredAt: minutesAgo(60),
|
||||
payload: { sessionRef: "T1", amountMinor: 10000, currency: "ALL", tender: "cash", graceExitMin: 15 },
|
||||
});
|
||||
const r = await exit.exitForBooth("T1");
|
||||
expect(r).toMatchObject({ ok: false, status: "grace_expired" });
|
||||
expect(exitsSigned("T1")).toHaveLength(0);
|
||||
});
|
||||
});
|
||||
|
||||
describe("exitForBooth — valid exit signs the vehicle_exit", () => {
|
||||
it("a paid session within grace signs an exit (opened:false — no relay in tests)", async () => {
|
||||
seedTariff(db, { pricePerIncrementMinor: 10000, gracePeriodExitMin: 15 });
|
||||
await enter("T1", minutesAgo(90));
|
||||
await pay.pay("T1", "cash"); // fresh payment → within grace
|
||||
const r = await exit.exitForBooth("T1");
|
||||
expect(r.ok).toBe(true);
|
||||
if (r.ok) expect(r.opened).toBe(false); // signed, but no barrier resolves in tests
|
||||
expect(exitsSigned("T1")).toHaveLength(1); // the exit IS on the chain
|
||||
expect(log.verifyChain()).toEqual({ ok: true });
|
||||
});
|
||||
|
||||
// NB: a subscriber's normal exit runs through SubscriptionFlow (the reader/credential
|
||||
// path), not exitForBooth — the booth's transient exit has no subscription bypass and
|
||||
// applies the same paid/grace gate to any identity it's handed. Asserting that here so
|
||||
// the boundary is explicit: handing a bare occurrence to exitForBooth is refused, and a
|
||||
// subscriber leaves via reopenBarrier (assist) or the subscription reader flow instead.
|
||||
it("does NOT give the booth transient-exit path a subscription bypass", async () => {
|
||||
await enter("SUBSESS-1", minutesAgo(30), { permit: true, permitId: "sub-1" });
|
||||
const r = await exit.exitForBooth("SUBSESS-1");
|
||||
expect(r).toMatchObject({ ok: false, status: "unpaid" });
|
||||
expect(exitsSigned("SUBSESS-1")).toHaveLength(0);
|
||||
});
|
||||
|
||||
it("lets a prepaid subscriber out via the assist (reopenBarrier) path", async () => {
|
||||
await enter("SUBSESS-1", minutesAgo(30), { permit: true, permitId: "sub-1" });
|
||||
const r = await exit.reopenBarrier("SUBSESS-1", "op1");
|
||||
expect(r.ok).toBe(true);
|
||||
expect(exitsSigned("SUBSESS-1")).toHaveLength(1); // assist closes the open occurrence
|
||||
});
|
||||
});
|
||||
|
||||
describe("reopenBarrier — no unpaid re-open", () => {
|
||||
it("refuses to re-open an unpaid transient session", async () => {
|
||||
seedTariff(db, { pricePerIncrementMinor: 10000 });
|
||||
await enter("T1", minutesAgo(90));
|
||||
const r = await exit.reopenBarrier("T1", "op1");
|
||||
expect(r.ok).toBe(false);
|
||||
expect(exitsSigned("T1")).toHaveLength(0);
|
||||
});
|
||||
|
||||
it("re-opening a paid OPEN session also closes it (signs the exit)", async () => {
|
||||
seedTariff(db, { pricePerIncrementMinor: 10000, gracePeriodExitMin: 15 });
|
||||
await enter("T1", minutesAgo(90));
|
||||
await pay.pay("T1", "cash");
|
||||
const r = await exit.reopenBarrier("T1", "op1");
|
||||
expect(r.ok).toBe(true);
|
||||
// The open session is closed by the human-intervention exit so it leaves the list.
|
||||
expect(exitsSigned("T1")).toHaveLength(1);
|
||||
});
|
||||
});
|
||||
|
||||
describe("exitForBooth — plate-swap reconciliation (ticket-swap fraud)", () => {
|
||||
// The fraud: a paid car is let out on a fresh $0 ticket while the original lingers "inside".
|
||||
// The plate is the invariant — the exiting car's plate is already open under the old ticket.
|
||||
it("HOLDS a paid exit when the plate is already open under a DIFFERENT ticket", async () => {
|
||||
seedTariff(db, { pricePerIncrementMinor: 10000, gracePeriodExitMin: 15 });
|
||||
// Original car entered on 1234, plate AA123BB, still open (never paid/exited).
|
||||
await enter("1234", minutesAgo(120));
|
||||
seedOpenWithPlate("1234", "AA123BB", 0.99, minutesAgo(120));
|
||||
// A fresh ticket 1237 (same physical car, same plate) is paid and tries to exit.
|
||||
await enter("1237", minutesAgo(1));
|
||||
seedOpenWithPlate("1237", "AA123BB", 0.99, minutesAgo(1));
|
||||
await pay.pay("1237", "cash");
|
||||
|
||||
const r = await exit.exitForBooth("1237");
|
||||
expect(r).toMatchObject({ ok: false, status: "swap_suspected", plate: "AA123BB", otherIdentity: "1234" });
|
||||
expect(exitsSigned("1237")).toHaveLength(0); // NOT let out
|
||||
expect(anomalies("plate AA123BB is already inside").length).toBeGreaterThanOrEqual(1);
|
||||
});
|
||||
|
||||
it("RELEASES on explicit operator override + signs an attributed override anomaly", async () => {
|
||||
seedTariff(db, { pricePerIncrementMinor: 10000, gracePeriodExitMin: 15 });
|
||||
await enter("1234", minutesAgo(120));
|
||||
seedOpenWithPlate("1234", "AA123BB", 0.99, minutesAgo(120));
|
||||
await enter("1237", minutesAgo(1));
|
||||
seedOpenWithPlate("1237", "AA123BB", 0.99, minutesAgo(1));
|
||||
await pay.pay("1237", "cash");
|
||||
|
||||
const r = await exit.exitForBooth("1237", { override: true, operator: "op1" });
|
||||
expect(r.ok).toBe(true);
|
||||
expect(exitsSigned("1237")).toHaveLength(1); // released
|
||||
const ov = anomalies("released a suspected ticket-swap");
|
||||
expect(ov.length).toBe(1);
|
||||
expect((ov[0].payload as { operator?: string }).operator).toBe("op1");
|
||||
});
|
||||
|
||||
it("does NOT warn on a LOW-confidence plate read (advisory, never a gate)", async () => {
|
||||
seedTariff(db, { pricePerIncrementMinor: 10000, gracePeriodExitMin: 15 });
|
||||
await enter("1234", minutesAgo(120));
|
||||
seedOpenWithPlate("1234", "AA123BB", 0.5, minutesAgo(120)); // low conf
|
||||
await enter("1237", minutesAgo(1));
|
||||
seedOpenWithPlate("1237", "AA123BB", 0.5, minutesAgo(1)); // low conf
|
||||
await pay.pay("1237", "cash");
|
||||
|
||||
const r = await exit.exitForBooth("1237");
|
||||
expect(r.ok).toBe(true); // no warning — exits normally
|
||||
expect(exitsSigned("1237")).toHaveLength(1);
|
||||
});
|
||||
|
||||
it("does NOT warn a normal exit whose OWN plate is only open under its OWN ticket", async () => {
|
||||
seedTariff(db, { pricePerIncrementMinor: 10000, gracePeriodExitMin: 15 });
|
||||
await enter("1237", minutesAgo(90));
|
||||
seedOpenWithPlate("1237", "AA999ZZ", 0.99, minutesAgo(90));
|
||||
await pay.pay("1237", "cash");
|
||||
|
||||
const r = await exit.exitForBooth("1237");
|
||||
expect(r.ok).toBe(true); // its own plate under its own ticket is not a swap
|
||||
expect(exitsSigned("1237")).toHaveLength(1);
|
||||
});
|
||||
});
|
||||
@@ -1,6 +1,7 @@
|
||||
import { desc, eq, ledgerEvents, sessions, tariffVersions, tariffs, type Db, type DeviceRow } from "@parking/db";
|
||||
import { registry, type AccessControlDevice } from "@parking/devices";
|
||||
import { firstRelayByDirection, type ResolvedRelay } from "./device-resolve.js";
|
||||
import { plateForIdentity, platesForIdentities } from "./plate-lookup.js";
|
||||
import { snapshotAsync } from "./snapshot.js";
|
||||
import type { VisionClient } from "./vision-client.js";
|
||||
import { computeFee, reasonPayload, renderReasonEn, type LedgerPayload, type TariffStructure } from "@parking/shared";
|
||||
@@ -47,6 +48,11 @@ interface SessionView {
|
||||
* the barrier didn't open (payment stands; operator opens manually). */
|
||||
export type BoothExitResult =
|
||||
| { ok: false; status: "invalid" | "no_session" | "closed" | "unpaid" | "grace_expired"; reason: string }
|
||||
// PLATE-SWAP suspected: the exiting car's plate is already OPEN under a DIFFERENT ticket
|
||||
// (possible ticket-swap fraud / mixed-up tickets). Not opened — the operator must review
|
||||
// and either resolve the tickets or consciously OVERRIDE (re-submit with override:true).
|
||||
// See wiki/concepts/plate-reconciliation.md.
|
||||
| { ok: false; status: "swap_suspected"; reason: string; plate: string; otherIdentity: string; otherEnteredAt: string | null }
|
||||
| { ok: true; opened: true }
|
||||
| { ok: true; opened: false; reason: string };
|
||||
|
||||
@@ -57,6 +63,11 @@ export type BoothReopenResult =
|
||||
| { ok: false; reason: string }
|
||||
| { ok: true; opened: boolean; reason?: string };
|
||||
|
||||
/** Minimum ANPR confidence for a plate to participate in swap reconciliation, both for the
|
||||
* exiting read and the matched open session's entry read. Below this, the read is advisory-
|
||||
* only and never triggers a swap warning (a fuzzy read must not block a legit car). */
|
||||
const PLATE_MATCH_MIN_CONFIDENCE = 0.85;
|
||||
|
||||
export class ExitFlow {
|
||||
readonly #db: Db;
|
||||
readonly #log: EventLog;
|
||||
@@ -88,7 +99,7 @@ export class ExitFlow {
|
||||
* (money was taken, the car is owed an exit) and an `anomaly` is appended so the
|
||||
* operator opens manually. Payment is never rolled back.
|
||||
*/
|
||||
async exitForBooth(identity: string): Promise<BoothExitResult> {
|
||||
async exitForBooth(identity: string, opts?: { override?: boolean; operator?: string }): Promise<BoothExitResult> {
|
||||
const id = identity.trim();
|
||||
if (!id) return { ok: false, status: "invalid", reason: "ticket id required" };
|
||||
|
||||
@@ -122,6 +133,40 @@ export class ExitFlow {
|
||||
return { ok: false, status: paid ? "grace_expired" : "unpaid", reason: rp.reason };
|
||||
}
|
||||
|
||||
// PLATE-SWAP CHECK — after the money/grace validation, before we sign the exit. If
|
||||
// the plate is already open under a DIFFERENT ticket, HOLD for the operator to review
|
||||
// (unless they consciously override). A denial here never traps the car — exit fails
|
||||
// open and the operator can override; the anomaly is the control either way.
|
||||
const swap = this.#reconcilePlateAtExit(id);
|
||||
if (swap) {
|
||||
if (!opts?.override) {
|
||||
// Sign the SUSPICION even if the operator walks away (tamper-evident record).
|
||||
const rp = reasonPayload("exit.plateSwapSuspected", { plate: swap.plate, otherIdentity: swap.otherIdentity });
|
||||
await this.#log.append({
|
||||
type: "anomaly",
|
||||
identity: id,
|
||||
payload: { ...rp, source: "booth", plateSwapSuspected: true, plate: swap.plate, otherIdentity: swap.otherIdentity },
|
||||
});
|
||||
this.#fireExitSnapshot(id);
|
||||
this.#logger.warn(`booth exit HELD (${id}): plate ${swap.plate} already open under ${swap.otherIdentity}`);
|
||||
return { ok: false, status: "swap_suspected", reason: rp.reason, plate: swap.plate, otherIdentity: swap.otherIdentity, otherEnteredAt: swap.otherEnteredAt };
|
||||
}
|
||||
// OVERRIDE: the operator consciously releases it. Sign the override (attributed).
|
||||
await this.#log.append({
|
||||
type: "anomaly",
|
||||
identity: id,
|
||||
payload: {
|
||||
...reasonPayload("exit.plateSwapOverride", { operator: opts.operator ?? "?", plate: swap.plate, otherIdentity: swap.otherIdentity }),
|
||||
source: "booth",
|
||||
plateSwapOverride: true,
|
||||
plate: swap.plate,
|
||||
otherIdentity: swap.otherIdentity,
|
||||
...(opts.operator ? { operator: opts.operator } : {}),
|
||||
},
|
||||
});
|
||||
this.#logger.warn(`booth exit OVERRIDE (${id}) by ${opts.operator ?? "?"}: plate-swap released (${swap.plate}, also open under ${swap.otherIdentity})`);
|
||||
}
|
||||
|
||||
// Free entry-grace path: mint the $0 payment first (ledger invariant), as the
|
||||
// reader path does.
|
||||
if (freeGrace && view.freeGrace) {
|
||||
@@ -336,6 +381,25 @@ export class ExitFlow {
|
||||
return { accepted: false, direction: "exit", reason: rp.reason };
|
||||
}
|
||||
|
||||
// PLATE-SWAP (reader path): detect + LOG, but FAIL OPEN. There's no operator at an
|
||||
// automated lane to make the override decision, and exit fails open for safety, so we
|
||||
// sign the suspicion anomaly (the control here) and still let the car out. The booth
|
||||
// path (operator-mediated) is where the hold + override lives.
|
||||
const swap = this.#reconcilePlateAtExit(e.value);
|
||||
if (swap) {
|
||||
await this.#log.append({
|
||||
type: "anomaly",
|
||||
identity: e.value,
|
||||
payload: {
|
||||
...reasonPayload("exit.plateSwapSuspected", { plate: swap.plate, otherIdentity: swap.otherIdentity }),
|
||||
plateSwapSuspected: true,
|
||||
plate: swap.plate,
|
||||
otherIdentity: swap.otherIdentity,
|
||||
},
|
||||
});
|
||||
this.#logger.warn(`reader exit: plate ${swap.plate} already open under ${swap.otherIdentity} (${e.value}) — logged, fail-open`);
|
||||
}
|
||||
|
||||
// Valid (a real payment within walk-back grace): sign + open.
|
||||
return this.#signExitAndOpen(resolved, e);
|
||||
}
|
||||
@@ -406,6 +470,43 @@ export class ExitFlow {
|
||||
this.#logger.error(`booth exit open failed (${identity}): ${detail}`);
|
||||
}
|
||||
|
||||
/**
|
||||
* PLATE-SWAP reconciliation. The car's PLATE is the invariant a ticket-swap can't hide:
|
||||
* if this exiting ticket's plate is already OPEN under a DIFFERENT ticket, someone let a
|
||||
* paid car out on a fresh $0 ticket while the original lingers "inside" (occupancy fraud),
|
||||
* or two tickets were mixed up. We compare the EXITING plate against every open session's
|
||||
* ENTRY plate, EXACT normalized match, HIGH-CONFIDENCE reads only (a fuzzy/absent read is
|
||||
* advisory — never a gate, so it can't trap a legit car). Returns the matched open session
|
||||
* or null. See wiki/concepts/plate-reconciliation.md.
|
||||
*/
|
||||
#reconcilePlateAtExit(exitingId: string): { plate: string; otherIdentity: string; otherEnteredAt: string | null } | null {
|
||||
// The exiting car's plate: prefer its own exit read, else its entry read.
|
||||
const mine = plateForIdentity(this.#db, exitingId);
|
||||
if (!mine || !mine.plate || (mine.confidence ?? 0) < PLATE_MATCH_MIN_CONFIDENCE) return null;
|
||||
const wanted = mine.plate.trim().toUpperCase();
|
||||
|
||||
// All currently-open sessions (from the projection cache — a fast read-model; the check
|
||||
// is advisory so a slightly-stale cache is acceptable), excluding this ticket.
|
||||
const openIds = this.#db
|
||||
.select({ id: sessions.id })
|
||||
.from(sessions)
|
||||
.where(eq(sessions.state, "open"))
|
||||
.all()
|
||||
.map((r) => r.id)
|
||||
.filter((id) => id !== exitingId);
|
||||
if (openIds.length === 0) return null;
|
||||
|
||||
const plates = platesForIdentities(this.#db, openIds);
|
||||
for (const [otherId, pv] of plates) {
|
||||
if ((pv.confidence ?? 0) < PLATE_MATCH_MIN_CONFIDENCE) continue;
|
||||
if (pv.plate.trim().toUpperCase() !== wanted) continue;
|
||||
// A high-confidence exact match under a DIFFERENT open ticket → swap suspected.
|
||||
const enteredAt = this.#db.select({ enteredAt: sessions.enteredAt }).from(sessions).where(eq(sessions.id, otherId)).get()?.enteredAt ?? null;
|
||||
return { plate: wanted, otherIdentity: otherId, otherEnteredAt: enteredAt };
|
||||
}
|
||||
return null;
|
||||
}
|
||||
|
||||
/** Fold the signed ledger into a session view for one identity (authoritative). */
|
||||
#sessionFor(identity: string): SessionView | null {
|
||||
const rows = this.#db
|
||||
@@ -418,7 +519,9 @@ export class ExitFlow {
|
||||
|
||||
const entry = rows.find((r) => r.type === "vehicle_entry");
|
||||
if (!entry) return null;
|
||||
const exited = rows.some((r) => r.type === "vehicle_exit");
|
||||
// A `void` (cancelled ticket) closes the session like an exit, so a voided ticket
|
||||
// presented at exit reads as "already closed" — never re-opens. See void-flow.ts.
|
||||
const exited = rows.some((r) => r.type === "vehicle_exit" || r.type === "void");
|
||||
|
||||
let paidAt: string | null = null;
|
||||
let graceExitMin: number | null = null;
|
||||
|
||||
@@ -0,0 +1,144 @@
|
||||
import { beforeEach, describe, expect, it } from "vitest";
|
||||
import { eq, devices, type Db } from "@parking/db";
|
||||
import { createTestDb } from "@parking/db/testing";
|
||||
import { LanePresence } from "./lane-presence.js";
|
||||
import { deviceEvents, type DeviceInputEvent, type LanePresenceEvent } from "./device-events.js";
|
||||
import { silentLogger } from "./test-helpers.js";
|
||||
|
||||
// LanePresence: a vehicle-presence INPUT edge (loop/radar) on an entry/exit barrier marks
|
||||
// that lane "present" — the same signal that blinks the physical button lamp (relay 3). It
|
||||
// resolves the edge via relayForPresence (the SAME path relay 3 + the entry gate use), and
|
||||
// emits a lane-presence change only when a lane's present/clear state actually flips.
|
||||
|
||||
let db: Db;
|
||||
const CTL = "ctl-1";
|
||||
const ENTRY_RADAR = 2;
|
||||
const EXIT_RADAR = 5;
|
||||
|
||||
beforeEach(() => {
|
||||
({ db } = createTestDb());
|
||||
// Entry relay 1 with a radar on I2; exit relay 2 with a radar on I5.
|
||||
db.insert(devices).values({
|
||||
id: CTL,
|
||||
category: "access",
|
||||
driverId: "dingtian",
|
||||
config: {
|
||||
host: "10.0.0.5",
|
||||
relays: [
|
||||
{ relay: 1, direction: "entry" },
|
||||
{ relay: 2, direction: "exit" },
|
||||
],
|
||||
inputs: [
|
||||
{ input: ENTRY_RADAR, role: "presence", relay: 1, kind: "radar" },
|
||||
{ input: EXIT_RADAR, role: "presence", relay: 2, kind: "radar" },
|
||||
],
|
||||
},
|
||||
enabled: true,
|
||||
}).run();
|
||||
});
|
||||
|
||||
function edge(input: number, on: boolean): void {
|
||||
const e: DeviceInputEvent = {
|
||||
driverId: "dingtian",
|
||||
deviceId: CTL,
|
||||
input,
|
||||
edge: on ? "on" : "off",
|
||||
at: new Date().toISOString(),
|
||||
source: "poll",
|
||||
};
|
||||
deviceEvents.emitInput(e);
|
||||
}
|
||||
|
||||
/** Collect lane-presence emissions while running `fn`. */
|
||||
function capture(fn: () => void): LanePresenceEvent[] {
|
||||
const seen: LanePresenceEvent[] = [];
|
||||
const off = deviceEvents.onLanePresence((p) => seen.push(p));
|
||||
try {
|
||||
fn();
|
||||
} finally {
|
||||
off();
|
||||
}
|
||||
return seen;
|
||||
}
|
||||
|
||||
describe("LanePresence", () => {
|
||||
it("starts clear and snapshots clear", () => {
|
||||
const lp = new LanePresence(db, silentLogger());
|
||||
lp.start();
|
||||
expect(lp.snapshot()).toEqual({ entry: false, exit: false });
|
||||
lp.stop();
|
||||
});
|
||||
|
||||
it("an ENTRY radar edge marks the entry lane present, then clears", () => {
|
||||
const lp = new LanePresence(db, silentLogger());
|
||||
lp.start();
|
||||
const events = capture(() => {
|
||||
edge(ENTRY_RADAR, true);
|
||||
edge(ENTRY_RADAR, false);
|
||||
});
|
||||
expect(events).toEqual([
|
||||
{ entry: true, exit: false },
|
||||
{ entry: false, exit: false },
|
||||
]);
|
||||
lp.stop();
|
||||
});
|
||||
|
||||
it("an EXIT radar edge marks the exit lane independently", () => {
|
||||
const lp = new LanePresence(db, silentLogger());
|
||||
lp.start();
|
||||
const events = capture(() => {
|
||||
edge(EXIT_RADAR, true);
|
||||
});
|
||||
expect(events).toEqual([{ entry: false, exit: true }]);
|
||||
expect(lp.snapshot()).toEqual({ entry: false, exit: true });
|
||||
lp.stop();
|
||||
});
|
||||
|
||||
it("de-dupes: a second 'on' from another presence input on the same lane emits once", () => {
|
||||
// Two radars both serving the entry lane.
|
||||
db.update(devices)
|
||||
.set({
|
||||
config: {
|
||||
host: "10.0.0.5",
|
||||
relays: [{ relay: 1, direction: "entry" }],
|
||||
inputs: [
|
||||
{ input: 2, role: "presence", relay: 1, kind: "radar" },
|
||||
{ input: 3, role: "presence", relay: 1, kind: "radar" },
|
||||
],
|
||||
},
|
||||
})
|
||||
.where(eq(devices.id, CTL))
|
||||
.run();
|
||||
const lp = new LanePresence(db, silentLogger());
|
||||
lp.start();
|
||||
const events = capture(() => {
|
||||
edge(2, true); // entry → present (emit)
|
||||
edge(3, true); // still present (no emit — same lane)
|
||||
edge(2, false); // still present via I3 (no emit)
|
||||
edge(3, false); // now clear (emit)
|
||||
});
|
||||
expect(events).toEqual([
|
||||
{ entry: true, exit: false },
|
||||
{ entry: false, exit: false },
|
||||
]);
|
||||
lp.stop();
|
||||
});
|
||||
|
||||
it("ignores a non-presence input (e.g. a button terminal)", () => {
|
||||
db.update(devices)
|
||||
.set({
|
||||
config: {
|
||||
host: "10.0.0.5",
|
||||
relays: [{ relay: 1, direction: "entry" }],
|
||||
inputs: [{ input: 1, role: "button", relay: 1 }],
|
||||
},
|
||||
})
|
||||
.where(eq(devices.id, CTL))
|
||||
.run();
|
||||
const lp = new LanePresence(db, silentLogger());
|
||||
lp.start();
|
||||
const events = capture(() => edge(1, true));
|
||||
expect(events).toEqual([]);
|
||||
lp.stop();
|
||||
});
|
||||
});
|
||||
@@ -0,0 +1,61 @@
|
||||
import type { Db } from "@parking/db";
|
||||
import type { FastifyBaseLogger } from "fastify";
|
||||
import { deviceEvents, type DeviceInputEvent, type LanePresenceEvent } from "./device-events.js";
|
||||
import { presenceLaneOf } from "./device-resolve.js";
|
||||
|
||||
// Per-lane RADAR presence for the booth's barrier lights. A vehicle-presence INPUT
|
||||
// (loop/radar) shorted at an entry/exit barrier means "something is in the lane vicinity"
|
||||
// BEFORE the camera confirms a vehicle. This is the SAME signal that makes the physical
|
||||
// button lamp (relay 3) blink — see button-light.ts (#onInput) — so the on-screen light
|
||||
// and the lamp stay in lockstep: both react to a presence edge resolved the SAME way
|
||||
// (relayForPresence, on an entry/both relay). ADVISORY ONLY: it gates nothing.
|
||||
//
|
||||
// A radar serving an entry (or "both") barrier marks the ENTRY lane present; an exit radar
|
||||
// marks EXIT. The lane is resolved via `presenceLaneOf` (direction-agnostic — unlike the
|
||||
// entry-gated `relayForPresence` the one-car-one-ticket gate uses), so both lanes blink.
|
||||
|
||||
export class LanePresence {
|
||||
readonly #db: Db;
|
||||
readonly #logger: FastifyBaseLogger;
|
||||
/** Active presence terminals per lane, keyed `${deviceId}:${input}` (several radars may
|
||||
* serve one lane). A lane is "present" while its set is non-empty. */
|
||||
readonly #entry = new Set<string>();
|
||||
readonly #exit = new Set<string>();
|
||||
#unsub: (() => void) | null = null;
|
||||
|
||||
constructor(db: Db, logger: FastifyBaseLogger) {
|
||||
this.#db = db;
|
||||
this.#logger = logger;
|
||||
}
|
||||
|
||||
/** Subscribe to presence input edges. */
|
||||
start(): void {
|
||||
this.#unsub = deviceEvents.onInput((e) => this.#onInput(e));
|
||||
}
|
||||
|
||||
/** Current snapshot (for the WS hello). */
|
||||
snapshot(): LanePresenceEvent {
|
||||
return { entry: this.#entry.size > 0, exit: this.#exit.size > 0 };
|
||||
}
|
||||
|
||||
#onInput(e: DeviceInputEvent): void {
|
||||
const lane = presenceLaneOf(this.#db, e.deviceId, e.input);
|
||||
if (!lane) return; // not a presence terminal on a barrier relay
|
||||
const key = `${e.deviceId}:${e.input}`;
|
||||
const set = lane === "entry" ? this.#entry : this.#exit;
|
||||
const before = set.size > 0;
|
||||
if (e.edge === "on") set.add(key);
|
||||
else set.delete(key);
|
||||
const after = set.size > 0;
|
||||
if (before !== after) {
|
||||
this.#logger.info(`lane-presence: ${lane} -> ${after ? "present" : "clear"}`);
|
||||
deviceEvents.emitLanePresence(this.snapshot());
|
||||
}
|
||||
}
|
||||
|
||||
/** Unsubscribe on shutdown. */
|
||||
stop(): void {
|
||||
this.#unsub?.();
|
||||
this.#unsub = null;
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,130 @@
|
||||
import { afterEach, beforeEach, describe, expect, it, vi } from "vitest";
|
||||
import { randomUUID } from "node:crypto";
|
||||
import { devices, type Db } from "@parking/db";
|
||||
import { createTestDb } from "@parking/db/testing";
|
||||
import { LaneStatus } from "./lane-status.js";
|
||||
import { deviceEvents, type LaneStatusEvent } from "./device-events.js";
|
||||
import { silentLogger } from "./test-helpers.js";
|
||||
|
||||
// LaneStatus: a camera's vehicle detection marks its bound lane busy, then auto-clears
|
||||
// after a timeout (this camera class sends no leave signal). Advisory; emits a
|
||||
// lane-status change only when the busy/free state actually flips.
|
||||
|
||||
let db: Db;
|
||||
beforeEach(() => {
|
||||
({ db } = createTestDb());
|
||||
vi.useFakeTimers();
|
||||
});
|
||||
afterEach(() => {
|
||||
vi.useRealTimers();
|
||||
});
|
||||
|
||||
/** Seed a controller (relay 1=entry, 2=exit, 3=both) + a camera bound to the relay
|
||||
* whose direction we want, so directionOf resolves from the real bound relay. */
|
||||
function seedCamera(direction: "entry" | "exit" | "both"): string {
|
||||
const controllerId = randomUUID();
|
||||
db.insert(devices).values({
|
||||
id: controllerId,
|
||||
category: "access",
|
||||
driverId: "dingtian",
|
||||
config: {
|
||||
host: "10.0.0.5",
|
||||
relays: [
|
||||
{ relay: 1, direction: "entry" },
|
||||
{ relay: 2, direction: "exit" },
|
||||
{ relay: 3, direction: "both" },
|
||||
],
|
||||
},
|
||||
enabled: true,
|
||||
}).run();
|
||||
const relay = direction === "entry" ? 1 : direction === "exit" ? 2 : 3;
|
||||
const camId = randomUUID();
|
||||
db.insert(devices).values({
|
||||
id: camId,
|
||||
category: "camera",
|
||||
driverId: "hikvision",
|
||||
config: { host: "10.0.0.9", controllerId, relay },
|
||||
enabled: true,
|
||||
}).run();
|
||||
return camId;
|
||||
}
|
||||
|
||||
/** Capture lane-status events emitted during `fn`. */
|
||||
function captureEmits(fn: () => void): LaneStatusEvent[] {
|
||||
const got: LaneStatusEvent[] = [];
|
||||
const off = deviceEvents.onLaneStatus((e) => got.push(e));
|
||||
try {
|
||||
fn();
|
||||
} finally {
|
||||
off();
|
||||
}
|
||||
return got;
|
||||
}
|
||||
|
||||
describe("LaneStatus", () => {
|
||||
it("marks the camera's bound lane busy on a vehicle detection, free until then", () => {
|
||||
const cam = seedCamera("entry");
|
||||
const lane = new LaneStatus(db, silentLogger(), 90_000);
|
||||
expect(lane.snapshot()).toEqual({ entry: false, exit: false });
|
||||
|
||||
const emits = captureEmits(() => lane.vehicleDetected(cam));
|
||||
expect(lane.snapshot()).toEqual({ entry: true, exit: false });
|
||||
expect(emits).toEqual([{ entry: true, exit: false }]); // emitted on the flip
|
||||
});
|
||||
|
||||
it("auto-clears to free after the TTL (no leave signal from the camera)", () => {
|
||||
const cam = seedCamera("entry");
|
||||
const lane = new LaneStatus(db, silentLogger(), 90_000);
|
||||
lane.vehicleDetected(cam);
|
||||
expect(lane.snapshot().entry).toBe(true);
|
||||
|
||||
const emits = captureEmits(() => vi.advanceTimersByTime(90_001));
|
||||
expect(lane.snapshot().entry).toBe(false);
|
||||
expect(emits).toEqual([{ entry: false, exit: false }]);
|
||||
});
|
||||
|
||||
it("re-arms the timer on each detection (a parked car keeps the lane busy)", () => {
|
||||
const cam = seedCamera("entry");
|
||||
const lane = new LaneStatus(db, silentLogger(), 90_000);
|
||||
lane.vehicleDetected(cam);
|
||||
// Re-fire just before the TTL — should NOT clear, and should push the clear out.
|
||||
vi.advanceTimersByTime(80_000);
|
||||
lane.vehicleDetected(cam);
|
||||
vi.advanceTimersByTime(80_000); // 160s total, but only 80s since the last detect
|
||||
expect(lane.snapshot().entry).toBe(true);
|
||||
// Now let it lapse fully.
|
||||
vi.advanceTimersByTime(90_001);
|
||||
expect(lane.snapshot().entry).toBe(false);
|
||||
});
|
||||
|
||||
it("does NOT re-emit on a repeat detection while already busy (only state flips)", () => {
|
||||
const cam = seedCamera("entry");
|
||||
const lane = new LaneStatus(db, silentLogger(), 90_000);
|
||||
lane.vehicleDetected(cam); // flip -> emits
|
||||
const emits = captureEmits(() => {
|
||||
lane.vehicleDetected(cam); // already busy -> no emit
|
||||
lane.vehicleDetected(cam);
|
||||
});
|
||||
expect(emits).toEqual([]);
|
||||
});
|
||||
|
||||
it("a 'both'-direction camera marks BOTH lanes busy", () => {
|
||||
const cam = seedCamera("both");
|
||||
const lane = new LaneStatus(db, silentLogger(), 90_000);
|
||||
lane.vehicleDetected(cam);
|
||||
expect(lane.snapshot()).toEqual({ entry: true, exit: true });
|
||||
});
|
||||
|
||||
it("exit camera marks only the exit lane", () => {
|
||||
const cam = seedCamera("exit");
|
||||
const lane = new LaneStatus(db, silentLogger(), 90_000);
|
||||
lane.vehicleDetected(cam);
|
||||
expect(lane.snapshot()).toEqual({ entry: false, exit: true });
|
||||
});
|
||||
|
||||
it("ignores an unknown device id", () => {
|
||||
const lane = new LaneStatus(db, silentLogger(), 90_000);
|
||||
lane.vehicleDetected("nope");
|
||||
expect(lane.snapshot()).toEqual({ entry: false, exit: false });
|
||||
});
|
||||
});
|
||||
@@ -0,0 +1,103 @@
|
||||
import { eq, devices, type Db } from "@parking/db";
|
||||
import type { FastifyBaseLogger } from "fastify";
|
||||
import { deviceEvents, type LaneStatusEvent } from "./device-events.js";
|
||||
import { directionOf } from "./device-resolve.js";
|
||||
|
||||
// Lane busy/free, driven by a camera's vehicle detection. ADVISORY ONLY — a detection
|
||||
// is a hint the booth shows as barrier lights; it never gates a ticket or opens a
|
||||
// barrier (see wiki/entities/lpr-camera.md, the advisory-only rule).
|
||||
//
|
||||
// A vehicle `active` event on a camera bound to entry/exit marks THAT lane busy and
|
||||
// (re)arms an auto-clear timer. This camera class sends NO leave/`inactive` signal, so
|
||||
// "free" is timeout-driven: the camera re-fires `active` while a car sits in the zone
|
||||
// (each refreshing the timer); once the car leaves, the actives stop and the lane
|
||||
// flips free after BUSY_TTL_MS. A "both"-direction camera marks BOTH lanes.
|
||||
|
||||
/** How long after the last vehicle detection a lane stays "busy" before clearing.
|
||||
* Must exceed the camera's `active` re-fire interval so a still-present car keeps the
|
||||
* lane busy. MEASURED on the test unit (controlled in/out test): the re-fire rate is
|
||||
* MOVEMENT-driven, not a fixed rate — ~1-3s apart while the car moves, but stretching
|
||||
* to ~15-25s when it sits MOTIONLESS in the zone. So the TTL must clear the still-car
|
||||
* gap (~25s) or a parked car flickers free. The camera has ~no dwell lag (it goes
|
||||
* silent within a second of the car leaving), so 30s clears promptly after departure
|
||||
* while keeping a motionless car solidly busy. Override with LANE_BUSY_TTL_MS. */
|
||||
export function busyTtlMs(): number {
|
||||
const raw = Number(process.env.LANE_BUSY_TTL_MS ?? 30_000);
|
||||
return Number.isFinite(raw) && raw > 0 ? raw : 30_000;
|
||||
}
|
||||
|
||||
export class LaneStatus {
|
||||
readonly #db: Db;
|
||||
readonly #logger: FastifyBaseLogger;
|
||||
readonly #ttlMs: number;
|
||||
#entry = false;
|
||||
#exit = false;
|
||||
#entryTimer: ReturnType<typeof setTimeout> | null = null;
|
||||
#exitTimer: ReturnType<typeof setTimeout> | null = null;
|
||||
|
||||
constructor(db: Db, logger: FastifyBaseLogger, ttlMs = busyTtlMs()) {
|
||||
this.#db = db;
|
||||
this.#logger = logger;
|
||||
this.#ttlMs = ttlMs;
|
||||
}
|
||||
|
||||
/** Current snapshot (for the WS hello). */
|
||||
snapshot(): LaneStatusEvent {
|
||||
return { entry: this.#entry, exit: this.#exit };
|
||||
}
|
||||
|
||||
/**
|
||||
* A vehicle was detected by camera `deviceId`. Resolves the camera's bound direction
|
||||
* and marks that lane busy + (re)arms its auto-clear. Best-effort: an unknown camera
|
||||
* or a non-vehicle caller is the caller's concern — this only handles a confirmed
|
||||
* vehicle detection. Emits a lane-status change only when the state actually flips.
|
||||
*/
|
||||
vehicleDetected(deviceId: string): void {
|
||||
const row = this.#db.select().from(devices).where(eq(devices.id, deviceId)).get();
|
||||
if (!row) return;
|
||||
const dir = directionOf(this.#db, row);
|
||||
if (dir === "entry" || dir === "both") this.#mark("entry");
|
||||
if (dir === "exit" || dir === "both") this.#mark("exit");
|
||||
}
|
||||
|
||||
#mark(lane: "entry" | "exit"): void {
|
||||
const was = lane === "entry" ? this.#entry : this.#exit;
|
||||
if (lane === "entry") this.#entry = true;
|
||||
else this.#exit = true;
|
||||
|
||||
// (Re)arm the auto-clear — each detection pushes the free-flip further out.
|
||||
const existing = lane === "entry" ? this.#entryTimer : this.#exitTimer;
|
||||
if (existing) clearTimeout(existing);
|
||||
const timer = setTimeout(() => this.#clear(lane), this.#ttlMs);
|
||||
timer.unref?.(); // never hold the process open
|
||||
if (lane === "entry") this.#entryTimer = timer;
|
||||
else this.#exitTimer = timer;
|
||||
|
||||
if (!was) {
|
||||
this.#logger.info(`lane-status: ${lane} -> busy`);
|
||||
this.#emit();
|
||||
}
|
||||
}
|
||||
|
||||
#clear(lane: "entry" | "exit"): void {
|
||||
if (lane === "entry") {
|
||||
this.#entry = false;
|
||||
this.#entryTimer = null;
|
||||
} else {
|
||||
this.#exit = false;
|
||||
this.#exitTimer = null;
|
||||
}
|
||||
this.#logger.info(`lane-status: ${lane} -> free`);
|
||||
this.#emit();
|
||||
}
|
||||
|
||||
#emit(): void {
|
||||
deviceEvents.emitLaneStatus(this.snapshot());
|
||||
}
|
||||
|
||||
/** Clear timers on shutdown. */
|
||||
stop(): void {
|
||||
if (this.#entryTimer) clearTimeout(this.#entryTimer);
|
||||
if (this.#exitTimer) clearTimeout(this.#exitTimer);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,116 @@
|
||||
import { afterEach, beforeEach, describe, expect, it, vi } from "vitest";
|
||||
import { appLogs, type Db } from "@parking/db";
|
||||
import { createTestDb } from "@parking/db/testing";
|
||||
import { LogService, pinoDbStream } from "./log-service.js";
|
||||
|
||||
// pinoDbStream feeds backend warn+ lines into app_logs. Since 2026-07-04 the logger
|
||||
// emits level NAMES ("warn") instead of pino's numeric codes (40) — for human-readable
|
||||
// container logs — and the stream must accept BOTH encodings (numeric covers any
|
||||
// default-configured pino). A level the tee can't resolve falls back to info → not
|
||||
// persisted, never a crash.
|
||||
|
||||
let db: Db;
|
||||
let stream: { write: (line: string) => void };
|
||||
let teed: string[];
|
||||
|
||||
beforeEach(() => {
|
||||
({ db } = createTestDb());
|
||||
teed = [];
|
||||
stream = pinoDbStream(new LogService(db), {
|
||||
write: (line: string) => {
|
||||
teed.push(line);
|
||||
return true;
|
||||
},
|
||||
} as unknown as NodeJS.WritableStream);
|
||||
});
|
||||
|
||||
const rows = () => db.select().from(appLogs).all();
|
||||
|
||||
describe("pinoDbStream level encodings", () => {
|
||||
it("persists a LABEL-level warn line (the current logger format)", () => {
|
||||
stream.write(`{"level":"warn","time":"2026-07-04T18:14:11.453Z","msg":"label warn"}\n`);
|
||||
expect(rows()).toHaveLength(1);
|
||||
expect(rows()[0]).toMatchObject({ level: "warn", source: "backend", message: "label warn" });
|
||||
});
|
||||
|
||||
it("still persists a NUMERIC-level error line (legacy/default pino)", () => {
|
||||
stream.write(`{"level":50,"time":1783179038453,"msg":"numeric error"}\n`);
|
||||
expect(rows()[0]).toMatchObject({ level: "error", message: "numeric error" });
|
||||
});
|
||||
|
||||
it("info stays stdout-only in both encodings (teed, not persisted)", () => {
|
||||
stream.write(`{"level":"info","msg":"label info"}\n`);
|
||||
stream.write(`{"level":30,"msg":"numeric info"}\n`);
|
||||
expect(rows()).toHaveLength(0);
|
||||
expect(teed).toHaveLength(2); // stdout tee always happens
|
||||
});
|
||||
|
||||
it("an unresolvable level falls back to info (dropped), never throws", () => {
|
||||
stream.write(`{"level":"loud","msg":"weird"}\n`);
|
||||
stream.write(`not json at all\n`);
|
||||
expect(rows()).toHaveLength(0);
|
||||
expect(teed).toHaveLength(2);
|
||||
});
|
||||
});
|
||||
|
||||
// Storm coalescing: a line identical to the LAST persisted row (level+source+message+
|
||||
// path), arriving within 5 min of its previous occurrence, UPDATES that row (bumping
|
||||
// context._repeat) instead of inserting — one screaming device can't evict unrelated
|
||||
// history. The row's createdAt tracks the LATEST occurrence; the first is preserved in
|
||||
// context._firstAt.
|
||||
describe("storm coalescing", () => {
|
||||
afterEach(() => {
|
||||
vi.useRealTimers();
|
||||
});
|
||||
|
||||
it("folds a burst of identical error lines into ONE row with a repeat counter", () => {
|
||||
for (let i = 0; i < 200; i++) {
|
||||
stream.write(`{"level":"error","msg":"button-light setAux failed (ctl R3): send ENETUNREACH"}\n`);
|
||||
}
|
||||
const all = rows();
|
||||
expect(all).toHaveLength(1);
|
||||
expect(all[0].context).toMatchObject({ _repeat: 200 });
|
||||
expect(teed).toHaveLength(200); // stdout still gets every line
|
||||
});
|
||||
|
||||
it("keeps first-occurrence time in _firstAt while createdAt tracks the latest", () => {
|
||||
vi.useFakeTimers();
|
||||
vi.setSystemTime(new Date("2026-07-08T10:00:00.000Z"));
|
||||
stream.write(`{"level":"warn","msg":"same"}\n`);
|
||||
vi.setSystemTime(new Date("2026-07-08T10:02:00.000Z"));
|
||||
stream.write(`{"level":"warn","msg":"same"}\n`);
|
||||
const [row] = rows();
|
||||
expect(row.createdAt).toBe("2026-07-08T10:02:00.000Z");
|
||||
expect(row.context).toMatchObject({ _repeat: 2, _firstAt: "2026-07-08T10:00:00.000Z" });
|
||||
});
|
||||
|
||||
it("a different message (or level) breaks the run — separate rows", () => {
|
||||
stream.write(`{"level":"error","msg":"boom A"}\n`);
|
||||
stream.write(`{"level":"error","msg":"boom A"}\n`);
|
||||
stream.write(`{"level":"error","msg":"boom B"}\n`);
|
||||
stream.write(`{"level":"warn","msg":"boom B"}\n`);
|
||||
expect(rows()).toHaveLength(3);
|
||||
});
|
||||
|
||||
it("an occurrence past the 5-minute window starts a fresh row", () => {
|
||||
vi.useFakeTimers();
|
||||
vi.setSystemTime(new Date("2026-07-08T10:00:00.000Z"));
|
||||
stream.write(`{"level":"error","msg":"slow leak"}\n`);
|
||||
vi.setSystemTime(new Date("2026-07-08T10:06:00.000Z"));
|
||||
stream.write(`{"level":"error","msg":"slow leak"}\n`);
|
||||
expect(rows()).toHaveLength(2);
|
||||
});
|
||||
|
||||
it("a CONTINUOUS storm stays one row past the window (each hit refreshes it)", () => {
|
||||
vi.useFakeTimers();
|
||||
let t = new Date("2026-07-08T10:00:00.000Z").getTime();
|
||||
for (let i = 0; i < 10; i++) {
|
||||
vi.setSystemTime(new Date(t));
|
||||
stream.write(`{"level":"error","msg":"storm"}\n`);
|
||||
t += 240_000; // 4 min apart — each inside the window of the PREVIOUS hit
|
||||
}
|
||||
const all = rows();
|
||||
expect(all).toHaveLength(1);
|
||||
expect(all[0].context).toMatchObject({ _repeat: 10 });
|
||||
});
|
||||
});
|
||||
@@ -25,6 +25,14 @@ const MAX_MESSAGE = 4_000;
|
||||
const MAX_STACK = 16_000;
|
||||
const MAX_CONTEXT_JSON = 16_000;
|
||||
|
||||
/** Storm coalescing: a line identical to the LAST persisted one (level+source+message+
|
||||
* path) within this window of its previous occurrence UPDATES that row (bumping a
|
||||
* `_repeat` counter in its context) instead of inserting a new one. A continuous storm
|
||||
* keeps refreshing the window, so it stays ONE row however long it rages — repeated
|
||||
* errors can't evict unrelated history or grind the appliance disk (field incident
|
||||
* 2026-07-07: one unreachable controller ≈ hundreds of identical rows/minute). */
|
||||
const COALESCE_WINDOW_MS = 300_000;
|
||||
|
||||
export interface LogRetention {
|
||||
/** Delete logs older than this many days. */
|
||||
readonly maxAgeDays: number;
|
||||
@@ -33,7 +41,10 @@ export interface LogRetention {
|
||||
}
|
||||
|
||||
export const DEFAULT_RETENTION: LogRetention = {
|
||||
maxAgeDays: Number(process.env.LOG_RETENTION_DAYS ?? 30),
|
||||
// 60 days (~2 months) — the operator's chosen diagnostic window (2026-07-04),
|
||||
// matched by the container-log rotation caps in docker-compose.prod.yml. The row
|
||||
// cap below still bounds a burst regardless of age.
|
||||
maxAgeDays: Number(process.env.LOG_RETENTION_DAYS ?? 60),
|
||||
maxRows: Number(process.env.LOG_RETENTION_MAX_ROWS ?? 50_000),
|
||||
};
|
||||
|
||||
@@ -59,6 +70,16 @@ export class LogService {
|
||||
readonly #retention: LogRetention;
|
||||
/** Reentrancy guard: never let persisting a log itself emit a persisted log. */
|
||||
#writing = false;
|
||||
/** The last persisted row, for storm coalescing (in-memory only; a restart just
|
||||
* starts a fresh row — best-effort, like everything in this sink). */
|
||||
#last: {
|
||||
id: string;
|
||||
key: string;
|
||||
count: number;
|
||||
firstAt: string;
|
||||
lastAtMs: number;
|
||||
baseContext: Record<string, unknown> | null;
|
||||
} | null = null;
|
||||
|
||||
constructor(db: Db, retention: LogRetention = DEFAULT_RETENTION) {
|
||||
this.#db = db;
|
||||
@@ -82,22 +103,53 @@ export class LogService {
|
||||
if (this.#writing) return;
|
||||
this.#writing = true;
|
||||
try {
|
||||
const createdAt = row.createdAt ?? new Date().toISOString();
|
||||
const message = clamp(row.message, MAX_MESSAGE) ?? "";
|
||||
const path = clamp(row.path, 512);
|
||||
const key = `${row.level}|${row.source}|${message}|${path ?? ""}`;
|
||||
const nowMs = Date.now();
|
||||
|
||||
// Storm coalescing: identical to the last persisted row, within the window →
|
||||
// bump that row instead of inserting. createdAt moves to the LATEST occurrence
|
||||
// (keeps the storm visible at the top of the newest-first viewer); the first
|
||||
// occurrence's time is preserved in context._firstAt.
|
||||
const last = this.#last;
|
||||
if (last && last.key === key && nowMs - last.lastAtMs <= COALESCE_WINDOW_MS) {
|
||||
const res = this.#db
|
||||
.update(appLogs)
|
||||
.set({
|
||||
context: { ...(last.baseContext ?? {}), _repeat: last.count + 1, _firstAt: last.firstAt },
|
||||
createdAt,
|
||||
})
|
||||
.where(eq(appLogs.id, last.id))
|
||||
.run();
|
||||
if ((res.changes ?? 0) > 0) {
|
||||
last.count += 1;
|
||||
last.lastAtMs = nowMs;
|
||||
return;
|
||||
}
|
||||
// The row was pruned out from under us — fall through to a fresh insert.
|
||||
}
|
||||
|
||||
const id = randomUUID();
|
||||
const baseContext = safeContext(row.context);
|
||||
this.#db
|
||||
.insert(appLogs)
|
||||
.values({
|
||||
id: randomUUID(),
|
||||
id,
|
||||
level: row.level,
|
||||
source: row.source,
|
||||
message: clamp(row.message, MAX_MESSAGE) ?? "",
|
||||
context: safeContext(row.context),
|
||||
message,
|
||||
context: baseContext,
|
||||
httpStatus: row.httpStatus ?? null,
|
||||
path: clamp(row.path, 512),
|
||||
path,
|
||||
stack: clamp(row.stack, MAX_STACK),
|
||||
userId: row.userId ?? null,
|
||||
userAgent: clamp(row.userAgent, 512),
|
||||
createdAt: row.createdAt ?? new Date().toISOString(),
|
||||
createdAt,
|
||||
})
|
||||
.run();
|
||||
this.#last = { id, key, count: 1, firstAt: createdAt, lastAtMs: nowMs, baseContext };
|
||||
} catch {
|
||||
// Swallow — diagnostics must never take down the path they observe. (Can't log
|
||||
// it; that's the recursion we're guarding against.)
|
||||
@@ -192,9 +244,10 @@ export class LogService {
|
||||
|
||||
/**
|
||||
* A pino-compatible write stream that forwards BACKEND warn+ lines into the LogService.
|
||||
* Pino writes one JSON object per line to this stream; we parse, map the numeric level
|
||||
* to a name, and persist. Returned as `{ write }` so it can be passed as pino's stream.
|
||||
* stdout still receives the same line (we tee), so console logging is unchanged.
|
||||
* Pino writes one JSON object per line to this stream; we parse, resolve the level
|
||||
* (name or numeric encoding), and persist. Returned as `{ write }` so it can be passed
|
||||
* as pino's stream. stdout still receives the same line (we tee), so console logging is
|
||||
* unchanged.
|
||||
*/
|
||||
export function pinoDbStream(
|
||||
service: LogService,
|
||||
@@ -218,12 +271,17 @@ export function pinoDbStream(
|
||||
}
|
||||
try {
|
||||
const obj = JSON.parse(line) as {
|
||||
level?: number;
|
||||
level?: number | string;
|
||||
msg?: string;
|
||||
err?: { stack?: string; message?: string };
|
||||
[k: string]: unknown;
|
||||
};
|
||||
const level = NUM_TO_LEVEL[obj.level ?? 30] ?? "info";
|
||||
// The logger emits level NAMES (formatters.level in server.ts, for human-
|
||||
// readable container logs); a default pino config emits numbers. Accept both.
|
||||
const level: LogLevel =
|
||||
typeof obj.level === "string" && obj.level in LOG_LEVEL_ORDER
|
||||
? (obj.level as LogLevel)
|
||||
: NUM_TO_LEVEL[typeof obj.level === "number" ? obj.level : 30] ?? "info";
|
||||
if (LOG_LEVEL_ORDER[level] < LOG_LEVEL_ORDER[BACKEND_PERSIST_MIN]) return;
|
||||
// Strip pino's noisy standard fields from the persisted context.
|
||||
const { level: _l, time: _t, pid: _p, hostname: _h, msg, ...rest } = obj;
|
||||
|
||||
@@ -0,0 +1,221 @@
|
||||
import { afterEach, beforeEach, describe, expect, it } from "vitest";
|
||||
import { createTestDb } from "@parking/db/testing";
|
||||
import { type Db } from "@parking/db";
|
||||
import type { FastifyInstance } from "fastify";
|
||||
import { buildServer } from "./server.js";
|
||||
import { seedUser, login } from "./test-helpers.js";
|
||||
|
||||
// Venue modules — entitled ∩ activated, enforced server-side (wiki/decisions/
|
||||
// venue-modules.md). Boots the real app over an in-memory DB and drives it with
|
||||
// app.inject, like routes.test.ts.
|
||||
|
||||
let db: Db;
|
||||
let close: () => void;
|
||||
let app: FastifyInstance;
|
||||
const savedEnv = process.env.MODULES_ENTITLED;
|
||||
|
||||
async function boot(): Promise<void> {
|
||||
const t = createTestDb();
|
||||
db = t.db;
|
||||
close = t.close;
|
||||
app = await buildServer({ db });
|
||||
await app.ready();
|
||||
}
|
||||
|
||||
beforeEach(async () => {
|
||||
delete process.env.MODULES_ENTITLED;
|
||||
await boot();
|
||||
});
|
||||
afterEach(async () => {
|
||||
await app.close();
|
||||
close();
|
||||
if (savedEnv === undefined) delete process.env.MODULES_ENTITLED;
|
||||
else process.env.MODULES_ENTITLED = savedEnv;
|
||||
});
|
||||
|
||||
async function admin() {
|
||||
const { username, password } = await seedUser(db, { username: "boss", roleId: "admin" });
|
||||
return login(app, username, password);
|
||||
}
|
||||
|
||||
describe("defaults (no env, nothing activated)", () => {
|
||||
it("every registered module is entitled, activated and effective; /me carries the set", async () => {
|
||||
const { cookie } = await admin();
|
||||
const cfg = await app.inject({ method: "GET", url: "/api/site-config", headers: { cookie } });
|
||||
expect(cfg.statusCode).toBe(200);
|
||||
const body = cfg.json();
|
||||
expect(body.modulesEntitled).toEqual(["parking", "validation", "carwash"]);
|
||||
expect(body.modulesActivated).toEqual(["parking", "validation", "carwash"]);
|
||||
expect(body.modules).toEqual(["parking", "validation", "carwash"]);
|
||||
|
||||
const me = await app.inject({ method: "GET", url: "/api/auth/me", headers: { cookie } });
|
||||
expect(me.json().modules).toEqual(["parking", "validation", "carwash"]);
|
||||
|
||||
// A module route answers normally while the module is on.
|
||||
const programs = await app.inject({ method: "GET", url: "/api/validation/programs", headers: { cookie } });
|
||||
expect(programs.statusCode).toBe(200);
|
||||
});
|
||||
});
|
||||
|
||||
describe("activation (site admin)", () => {
|
||||
it("deactivating validation 403s its routes with module_disabled, signs a config_change, and is reversible", async () => {
|
||||
const { cookie, csrf } = await admin();
|
||||
const put = await app.inject({
|
||||
method: "PUT", url: "/api/site-config",
|
||||
headers: { cookie, "x-csrf-token": csrf },
|
||||
payload: { modules: ["parking"] },
|
||||
});
|
||||
expect(put.statusCode).toBe(200);
|
||||
expect(put.json().modules).toEqual(["parking"]);
|
||||
expect(put.json().modulesActivated).toEqual(["parking"]);
|
||||
|
||||
// The merchant scan routes are the module → 403; the PROGRAM routes are core (the
|
||||
// discount engine serves Car Wash too) → still 200 with validation off.
|
||||
const off = await app.inject({ method: "GET", url: "/api/validation/mine", headers: { cookie } });
|
||||
expect(off.statusCode).toBe(403);
|
||||
expect(off.json().code).toBe("module_disabled");
|
||||
expect((await app.inject({ method: "GET", url: "/api/validation/programs", headers: { cookie } })).statusCode).toBe(200);
|
||||
|
||||
const me = await app.inject({ method: "GET", url: "/api/auth/me", headers: { cookie } });
|
||||
expect(me.json().modules).toEqual(["parking"]);
|
||||
|
||||
// The flip is on the signed ledger, attributed.
|
||||
const events = await app.inject({ method: "GET", url: "/api/events?limit=50", headers: { cookie } });
|
||||
expect(events.statusCode).toBe(200);
|
||||
const list = (events.json().events ?? events.json()) as Array<{ type: string; payload: Record<string, unknown> }>;
|
||||
const flip = list.find((e) => e.type === "config_change" && e.payload?.setting === "modules.validation");
|
||||
expect(flip).toBeTruthy();
|
||||
expect(flip!.payload).toMatchObject({ value: false, prev: true, operator: "boss" });
|
||||
|
||||
// Nothing was deleted: re-enable and the route is back.
|
||||
const back = await app.inject({
|
||||
method: "PUT", url: "/api/site-config",
|
||||
headers: { cookie, "x-csrf-token": csrf },
|
||||
payload: { modules: ["parking", "validation"] },
|
||||
});
|
||||
expect(back.json().modules).toEqual(["parking", "validation"]);
|
||||
const on = await app.inject({ method: "GET", url: "/api/validation/programs", headers: { cookie } });
|
||||
expect(on.statusCode).toBe(200);
|
||||
});
|
||||
|
||||
it("required modules cannot be deactivated (parking is always included)", async () => {
|
||||
const { cookie, csrf } = await admin();
|
||||
const put = await app.inject({
|
||||
method: "PUT", url: "/api/site-config",
|
||||
headers: { cookie, "x-csrf-token": csrf },
|
||||
payload: { modules: [] },
|
||||
});
|
||||
expect(put.statusCode).toBe(200);
|
||||
expect(put.json().modules).toEqual(["parking"]);
|
||||
});
|
||||
|
||||
it("rejects unknown ids with 400", async () => {
|
||||
const { cookie, csrf } = await admin();
|
||||
const put = await app.inject({
|
||||
method: "PUT", url: "/api/site-config",
|
||||
headers: { cookie, "x-csrf-token": csrf },
|
||||
payload: { modules: ["parking", "bar"] },
|
||||
});
|
||||
expect(put.statusCode).toBe(400);
|
||||
});
|
||||
|
||||
it("carwash runs without the validation module (the discount engine is core)", async () => {
|
||||
const { cookie, csrf } = await admin();
|
||||
const put = await app.inject({
|
||||
method: "PUT", url: "/api/site-config",
|
||||
headers: { cookie, "x-csrf-token": csrf },
|
||||
payload: { modules: ["parking", "carwash"] },
|
||||
});
|
||||
expect(put.statusCode).toBe(200);
|
||||
expect(put.json().modules).toEqual(["parking", "carwash"]);
|
||||
// The wash's sponsorship program is still composable and readable.
|
||||
expect((await app.inject({ method: "GET", url: "/api/validation/programs", headers: { cookie } })).statusCode).toBe(200);
|
||||
expect((await app.inject({ method: "GET", url: "/api/carwash/settings", headers: { cookie } })).statusCode).toBe(200);
|
||||
});
|
||||
|
||||
it("dependency rule: a module cannot be on while a module it depends on is off", async () => {
|
||||
const { cookie, csrf } = await admin();
|
||||
// Every non-required module depends on parking, and parking is required — so the rule
|
||||
// is exercised through the effective-set helper directly.
|
||||
const shared = await import("@parking/shared");
|
||||
expect(shared.resolveModuleActivation(["parking", "validation", "carwash"], ["carwash"])).toMatchObject({ ok: true });
|
||||
expect(shared.effectiveModules(["parking", "carwash"], ["parking", "carwash"])).toEqual(["parking", "carwash"]);
|
||||
expect(cookie && csrf).toBeTruthy();
|
||||
});
|
||||
|
||||
it("a no-op resave signs nothing", async () => {
|
||||
const { cookie, csrf } = await admin();
|
||||
const before = await app.inject({ method: "GET", url: "/api/events?limit=50", headers: { cookie } });
|
||||
const countBefore = ((before.json().events ?? before.json()) as unknown[]).length;
|
||||
await app.inject({
|
||||
method: "PUT", url: "/api/site-config",
|
||||
headers: { cookie, "x-csrf-token": csrf },
|
||||
payload: { modules: ["parking", "validation", "carwash"] },
|
||||
});
|
||||
const after = await app.inject({ method: "GET", url: "/api/events?limit=50", headers: { cookie } });
|
||||
expect(((after.json().events ?? after.json()) as unknown[]).length).toBe(countBefore);
|
||||
});
|
||||
});
|
||||
|
||||
describe("entitlement (vendor env)", () => {
|
||||
it("MODULES_ENTITLED=parking: validation is neither offered nor activatable, and its routes 403", async () => {
|
||||
await app.close();
|
||||
close();
|
||||
process.env.MODULES_ENTITLED = "parking";
|
||||
await boot();
|
||||
const { cookie, csrf } = await admin();
|
||||
|
||||
const cfg = await app.inject({ method: "GET", url: "/api/site-config", headers: { cookie } });
|
||||
expect(cfg.json().modulesEntitled).toEqual(["parking"]);
|
||||
expect(cfg.json().modules).toEqual(["parking"]);
|
||||
|
||||
const put = await app.inject({
|
||||
method: "PUT", url: "/api/site-config",
|
||||
headers: { cookie, "x-csrf-token": csrf },
|
||||
payload: { modules: ["parking", "validation"] },
|
||||
});
|
||||
expect(put.statusCode).toBe(400);
|
||||
expect(put.json().error).toMatch(/not entitled/);
|
||||
|
||||
const off = await app.inject({ method: "GET", url: "/api/validation/mine", headers: { cookie } });
|
||||
expect(off.statusCode).toBe(403);
|
||||
});
|
||||
|
||||
it("required modules are entitled even when the env omits them; unknown ids are ignored", async () => {
|
||||
await app.close();
|
||||
close();
|
||||
process.env.MODULES_ENTITLED = "validation,bogus";
|
||||
await boot();
|
||||
const { cookie } = await admin();
|
||||
const cfg = await app.inject({ method: "GET", url: "/api/site-config", headers: { cookie } });
|
||||
expect(cfg.json().modulesEntitled).toEqual(["parking", "validation"]);
|
||||
expect(cfg.json().modules).toEqual(["parking", "validation"]);
|
||||
});
|
||||
});
|
||||
|
||||
describe("permissions matrix helpers (venue-modules.md §Permissions matrix)", async () => {
|
||||
const shared = await import("@parking/shared");
|
||||
it("each till is guarded by its own module's permissions", () => {
|
||||
expect(shared.tillGuards("booth")).toEqual({ read: "shift:read", shift: "shift:create", cash: "drawer:create" });
|
||||
expect(shared.tillGuards("carwash")).toEqual({ read: "carwash:read", shift: "carwash:cash", cash: "carwash:cash" });
|
||||
const wash = new Set(["carwash:read", "carwash:cash"]);
|
||||
expect(shared.tillsFor(["parking", "validation", "carwash"], (p) => wash.has(p))).toEqual(["carwash"]);
|
||||
expect(shared.tillsFor(["parking", "validation", "carwash"], (p) => wash.has(p), "shift")).toEqual(["carwash"]);
|
||||
expect(shared.tillsFor(["parking", "validation", "carwash"], (p) => p === "carwash:read", "shift")).toEqual([]);
|
||||
// Module off → its till is not even addressable.
|
||||
expect(shared.tillsFor(["parking"], () => true)).toEqual(["booth"]);
|
||||
});
|
||||
it("the live feed admits by watch permission and filters ledger events by their module", () => {
|
||||
expect(shared.watchPermissions(["parking", "validation", "carwash"])).toEqual(
|
||||
expect.arrayContaining(["event:read", "session:read", "device:read", "carwash:read"]),
|
||||
);
|
||||
expect(shared.watchPermissions(["parking", "validation", "carwash"])).not.toContain("report:read");
|
||||
expect(shared.watchPermissions(["parking"])).not.toContain("carwash:read");
|
||||
expect(shared.feedPermissionFor("carwash_payment")).toBe("carwash:read");
|
||||
expect(shared.feedPermissionFor("payment")).toBe("event:read");
|
||||
expect(shared.feedPermissionFor("validation")).toBe("event:read");
|
||||
});
|
||||
it("every job's permissions exist in the grid", () => {
|
||||
for (const m of shared.MODULES) for (const j of m.jobs) for (const p of j.permissions) expect(shared.PERMISSIONS).toContain(p);
|
||||
});
|
||||
});
|
||||
@@ -0,0 +1,119 @@
|
||||
import type { FastifyReply, FastifyRequest } from "fastify";
|
||||
import { eq, siteConfig, type Db } from "@parking/db";
|
||||
import {
|
||||
effectiveModules,
|
||||
isModuleId,
|
||||
isTillId,
|
||||
parseEntitledModules,
|
||||
tillGuards,
|
||||
tillsFor,
|
||||
tillsOf,
|
||||
type ModuleId,
|
||||
type TillGuards,
|
||||
type TillId,
|
||||
} from "@parking/shared";
|
||||
import { requireAuth, roleHasPermissions } from "./auth.js";
|
||||
|
||||
declare module "fastify" {
|
||||
interface FastifyRequest {
|
||||
/** Set by requireTill(): the till this request addresses (already authorized). */
|
||||
till?: TillId;
|
||||
}
|
||||
}
|
||||
|
||||
// Venue modules — the server side of "entitled ∩ activated" (registry + rules live in
|
||||
// @parking/shared; design in wiki/decisions/venue-modules.md).
|
||||
//
|
||||
// entitled MODULES_ENTITLED env (vendor, Komodo stack) — unset = everything.
|
||||
// activated site_config.modules_json (site admin, Setup → Site) — null = everything
|
||||
// entitled.
|
||||
// effective what requireModule() enforces and what /api/auth/me + /api/site-config
|
||||
// hand the SPA so it can hide nav. The web only HIDES; this file ENFORCES.
|
||||
//
|
||||
// Both inputs are re-read per request: one env read and one single-row SELECT on the
|
||||
// site_config singleton — cheap, and it means a change takes effect on the next request
|
||||
// with no cache to invalidate (the same reason the presence-bypass flags aren't cached).
|
||||
|
||||
/** The modules this deployment is entitled to. Unknown ids in the env are ignored
|
||||
* (logged once at boot by registerModules). */
|
||||
export function entitledModules(): ModuleId[] {
|
||||
return parseEntitledModules(process.env.MODULES_ENTITLED).entitled;
|
||||
}
|
||||
|
||||
/** Parse the persisted activation list off a site_config row. null = never set. A
|
||||
* corrupt/unknown value is treated as "never set" rather than locking modules off. */
|
||||
export function activatedModulesOf(row: { modulesJson?: string | null } | undefined): ModuleId[] | null {
|
||||
const raw = row?.modulesJson;
|
||||
if (raw == null) return null;
|
||||
try {
|
||||
const parsed: unknown = JSON.parse(raw);
|
||||
if (!Array.isArray(parsed)) return null;
|
||||
return parsed.filter(isModuleId);
|
||||
} catch {
|
||||
return null;
|
||||
}
|
||||
}
|
||||
|
||||
/** The effective set for this site right now. */
|
||||
export function effectiveModulesFor(db: Db): ModuleId[] {
|
||||
const row = db.select({ modulesJson: siteConfig.modulesJson }).from(siteConfig).where(eq(siteConfig.id, 1)).get();
|
||||
return effectiveModules(entitledModules(), activatedModulesOf(row));
|
||||
}
|
||||
|
||||
/** The tills available at this site right now: the booth, plus each effective
|
||||
* money-taking module's own till (registry order). */
|
||||
export function effectiveTillsFor(db: Db): TillId[] {
|
||||
return tillsOf(effectiveModulesFor(db));
|
||||
}
|
||||
|
||||
/** The tills a role may SEE (default) or WORK (`shift` / `cash`) here: the effective
|
||||
* tills whose module guard the role holds (each desk's money is guarded by that desk's
|
||||
* own permissions — venue-modules.md §"Permissions matrix"). */
|
||||
export function tillsReadableBy(db: Db, roleId: string, kind: keyof TillGuards = "read"): TillId[] {
|
||||
return tillsFor(effectiveModulesFor(db), (p) => roleHasPermissions(roleId, [p]), kind);
|
||||
}
|
||||
|
||||
/** preHandler factory for the shift/drawer routes: authenticate, parse the `till`
|
||||
* (query on GET, body on POST; absent = booth; 400 `bad_till` when unknown or its
|
||||
* module is off), then require the role to hold THAT TILL's guard for `kind` (403
|
||||
* `till_forbidden`). The authorized till lands on `req.till`. The permission is thus
|
||||
* resolved from the till, never fixed: the booth checks `shift:read`/`shift:create`/
|
||||
* `drawer:create`, the wash `carwash:read`/`carwash:cash`. */
|
||||
export function requireTill(db: Db, kind: keyof TillGuards, from: "query" | "body") {
|
||||
return async (req: FastifyRequest, reply: FastifyReply): Promise<void | FastifyReply> => {
|
||||
await requireAuth(req, reply);
|
||||
const raw = from === "query" ? (req.query as { till?: unknown } | undefined)?.till : (req.body as { till?: unknown } | undefined)?.till;
|
||||
const till = parseTill(db, raw);
|
||||
if (!till) {
|
||||
await reply.code(400).send({ error: "unknown till", code: "bad_till" });
|
||||
return reply;
|
||||
}
|
||||
if (!roleHasPermissions(req.user.roleId, [tillGuards(till)[kind]])) {
|
||||
await reply
|
||||
.code(403)
|
||||
.send({ error: `your role cannot ${kind === "read" ? "see" : "work"} the ${till} till`, code: "till_forbidden", till });
|
||||
return reply;
|
||||
}
|
||||
req.till = till;
|
||||
};
|
||||
}
|
||||
|
||||
/** Parse a till from a query/body value. Absent/blank = the booth. Unknown, or a till
|
||||
* whose module is not effective here, → null (the caller answers 400). */
|
||||
export function parseTill(db: Db, raw: unknown): TillId | null {
|
||||
if (raw == null || raw === "") return "booth";
|
||||
if (!isTillId(raw)) return null;
|
||||
return effectiveTillsFor(db).includes(raw) ? raw : null;
|
||||
}
|
||||
|
||||
/** preHandler: reject the call when `id` is not effective at this site. Compose it
|
||||
* BEFORE requirePermission in a preHandler array so a disabled module answers the
|
||||
* same way for every role — 403 with code "module_disabled" — and never reaches
|
||||
* the permission/CSRF path. */
|
||||
export function requireModule(db: Db, id: ModuleId) {
|
||||
return async (_req: FastifyRequest, _reply: FastifyReply): Promise<void> => {
|
||||
if (!effectiveModulesFor(db).includes(id)) {
|
||||
throw Object.assign(new Error(`module disabled: ${id}`), { statusCode: 403, code: "module_disabled" });
|
||||
}
|
||||
};
|
||||
}
|
||||
@@ -0,0 +1,646 @@
|
||||
import { afterEach, beforeEach, describe, expect, it } from "vitest";
|
||||
import { createTestDb } from "@parking/db/testing";
|
||||
import { deviceEvents, type Db } from "@parking/db";
|
||||
import type { FastifyInstance } from "fastify";
|
||||
import { buildServer } from "../../server.js";
|
||||
import { login, makeLog, minutesAgo, seedTariff, seedUser } from "../../test-helpers.js";
|
||||
|
||||
// Car Wash module, end to end over the real app (wiki/decisions/venue-modules.md):
|
||||
// settings → intake against an open parking session → done applies the sponsorship
|
||||
// validation → bay payment settles the parking session at zero (what the exit reader
|
||||
// checks) / booth payment carries the wash as a charge line → module off = 403.
|
||||
|
||||
let db: Db;
|
||||
let close: () => void;
|
||||
let app: FastifyInstance;
|
||||
|
||||
beforeEach(async () => {
|
||||
delete process.env.MODULES_ENTITLED;
|
||||
const t = createTestDb();
|
||||
db = t.db;
|
||||
close = t.close;
|
||||
app = await buildServer({ db });
|
||||
await app.ready();
|
||||
});
|
||||
afterEach(async () => {
|
||||
await app.close();
|
||||
close();
|
||||
});
|
||||
|
||||
type Auth = { cookie: string; csrf: string };
|
||||
const hdrs = (a: Auth) => ({ cookie: a.cookie, "x-csrf-token": a.csrf });
|
||||
|
||||
async function admin(): Promise<Auth> {
|
||||
const { username, password } = await seedUser(db, { username: "boss", roleId: "admin" });
|
||||
return login(app, username, password);
|
||||
}
|
||||
|
||||
/** An open transient session that has been parked long enough to owe money. */
|
||||
async function openSession(identity: string, enteredMinutesAgo = 90): Promise<void> {
|
||||
await makeLog(db).append({
|
||||
type: "vehicle_entry",
|
||||
source: "manual",
|
||||
identity,
|
||||
occurredAt: minutesAgo(enteredMinutesAgo),
|
||||
payload: { sessionRef: identity, category: "default" },
|
||||
});
|
||||
}
|
||||
|
||||
async function seedSettings(a: Auth) {
|
||||
const res = await app.inject({
|
||||
method: "PUT", url: "/api/carwash/settings", headers: hdrs(a),
|
||||
payload: {
|
||||
categories: [{ name: "Car" }, { name: "SUV" }],
|
||||
services: [{ name: "Standard" }, { name: "Inside" }],
|
||||
prices: [],
|
||||
},
|
||||
});
|
||||
expect(res.statusCode).toBe(200);
|
||||
const s = res.json();
|
||||
const car = s.categories.find((c: { name: string }) => c.name === "Car").id;
|
||||
const suv = s.categories.find((c: { name: string }) => c.name === "SUV").id;
|
||||
const std = s.services.find((c: { name: string }) => c.name === "Standard").id;
|
||||
const inside = s.services.find((c: { name: string }) => c.name === "Inside").id;
|
||||
const priced = await app.inject({
|
||||
method: "PUT", url: "/api/carwash/settings", headers: hdrs(a),
|
||||
payload: {
|
||||
categories: s.categories, services: s.services,
|
||||
prices: [
|
||||
{ categoryId: car, serviceId: std, priceMinor: 50000 },
|
||||
{ categoryId: suv, serviceId: std, priceMinor: 70000 },
|
||||
{ categoryId: car, serviceId: inside, priceMinor: 30000 },
|
||||
],
|
||||
},
|
||||
});
|
||||
expect(priced.statusCode).toBe(200);
|
||||
expect(priced.json().prices).toHaveLength(3);
|
||||
return { car, suv, std, inside };
|
||||
}
|
||||
|
||||
/** Flip the site's wash-payment policy (Setup → Car wash). */
|
||||
async function setPayAt(a: Auth, payAt: "booth" | "bay") {
|
||||
const res = await app.inject({ method: "PUT", url: "/api/carwash/settings", headers: hdrs(a), payload: { payAt } });
|
||||
expect(res.statusCode).toBe(200);
|
||||
expect(res.json().payAt).toBe(payAt);
|
||||
}
|
||||
|
||||
async function seedSponsorship(a: Auth, mode: "comp" | "percent" | "doneTolerance" | "washPrice" = "comp", minutes: number | null = null) {
|
||||
const res = await app.inject({
|
||||
method: "PUT", url: "/api/validation/programs/carwash", headers: hdrs(a),
|
||||
payload: { name: "Lavazh", mode, percent: mode === "percent" ? 50 : null, minutes, active: true, userIds: [] },
|
||||
});
|
||||
expect(res.statusCode).toBeLessThan(300);
|
||||
}
|
||||
|
||||
async function events(a: Auth) {
|
||||
const r = await app.inject({ method: "GET", url: "/api/events?limit=100", headers: { cookie: a.cookie } });
|
||||
return (r.json().events ?? r.json()) as Array<{ id: string; type: string; identity: string | null; payload: Record<string, unknown> }>;
|
||||
}
|
||||
|
||||
describe("settings", () => {
|
||||
it("round-trips categories, services and the price matrix; signs a config_change; unknown pairs are refused", async () => {
|
||||
const a = await admin();
|
||||
const ids = await seedSettings(a);
|
||||
const get = await app.inject({ method: "GET", url: "/api/carwash/settings", headers: { cookie: a.cookie } });
|
||||
expect(get.json().categories.map((c: { name: string }) => c.name)).toEqual(["Car", "SUV"]);
|
||||
expect(get.json().prices.find((p: { categoryId: string; serviceId: string }) => p.categoryId === ids.suv && p.serviceId === ids.std).priceMinor).toBe(70000);
|
||||
const bad = await app.inject({
|
||||
method: "PUT", url: "/api/carwash/settings", headers: hdrs(a),
|
||||
payload: { prices: [{ categoryId: "nope", serviceId: ids.std, priceMinor: 1 }] },
|
||||
});
|
||||
expect(bad.statusCode).toBe(400);
|
||||
const flips = (await events(a)).filter((e) => e.type === "config_change" && e.payload.setting === "carwash.settings");
|
||||
expect(flips.length).toBeGreaterThanOrEqual(2);
|
||||
});
|
||||
});
|
||||
|
||||
describe("orders", () => {
|
||||
it("intake needs an open session and a priced pair; the queue is oldest-first", async () => {
|
||||
const a = await admin();
|
||||
seedTariff(db);
|
||||
const ids = await seedSettings(a);
|
||||
const noSession = await app.inject({
|
||||
method: "POST", url: "/api/carwash/orders", headers: hdrs(a),
|
||||
payload: { identity: "T-NONE", categoryId: ids.car, serviceId: ids.std },
|
||||
});
|
||||
expect(noSession.statusCode).toBe(404);
|
||||
|
||||
await openSession("T-1");
|
||||
const noPrice = await app.inject({
|
||||
method: "POST", url: "/api/carwash/orders", headers: hdrs(a),
|
||||
payload: { identity: "T-1", categoryId: ids.suv, serviceId: ids.inside },
|
||||
});
|
||||
expect(noPrice.statusCode).toBe(409);
|
||||
expect(noPrice.json().code).toBe("no_price");
|
||||
|
||||
const created = await app.inject({
|
||||
method: "POST", url: "/api/carwash/orders", headers: hdrs(a),
|
||||
payload: { identity: "T-1", categoryId: ids.suv, serviceId: ids.std },
|
||||
});
|
||||
expect(created.statusCode).toBe(201);
|
||||
expect(created.json()).toMatchObject({ identity: "T-1", categoryName: "SUV", serviceName: "Standard", priceMinor: 70000, payAt: "booth", status: "open", closed: false });
|
||||
|
||||
await openSession("T-2");
|
||||
await setPayAt(a, "bay");
|
||||
await app.inject({
|
||||
method: "POST", url: "/api/carwash/orders", headers: hdrs(a),
|
||||
payload: { identity: "T-2", categoryId: ids.car, serviceId: ids.std },
|
||||
});
|
||||
const queue = await app.inject({ method: "GET", url: "/api/carwash/orders", headers: { cookie: a.cookie } });
|
||||
expect(queue.json().orders.map((o: { identity: string }) => o.identity)).toEqual(["T-1", "T-2"]);
|
||||
|
||||
const chain = (await events(a)).filter((e) => e.type === "carwash_order");
|
||||
expect(chain).toHaveLength(2);
|
||||
expect(chain[0]!.payload).toMatchObject({ action: "created", operator: "boss" });
|
||||
});
|
||||
|
||||
it("pay at BOOTH: the wash rides the parking quote as a charge line and is marked paid by the booth payment", async () => {
|
||||
const a = await admin();
|
||||
seedTariff(db, { pricePerIncrementMinor: 10000 });
|
||||
const ids = await seedSettings(a);
|
||||
await openSession("T-B");
|
||||
const order = (await app.inject({
|
||||
method: "POST", url: "/api/carwash/orders", headers: hdrs(a),
|
||||
payload: { identity: "T-B", categoryId: ids.car, serviceId: ids.std },
|
||||
})).json();
|
||||
|
||||
const look = await app.inject({ method: "GET", url: "/api/session/T-B", headers: { cookie: a.cookie } });
|
||||
const s = look.json();
|
||||
expect(s.chargeLines).toHaveLength(1);
|
||||
expect(s.chargeLines[0]).toMatchObject({ module: "carwash", ref: order.id, amountMinor: 50000 });
|
||||
expect(s.chargesMinor).toBe(50000);
|
||||
expect(s.amountMinor).toBeGreaterThan(50000); // parking fee + the wash
|
||||
|
||||
await app.inject({ method: "POST", url: "/api/shift/open", headers: hdrs(a) });
|
||||
const pay = await app.inject({ method: "POST", url: "/api/pay", headers: hdrs(a), payload: { identity: "T-B", tender: "cash" } });
|
||||
expect(pay.statusCode).toBeLessThan(300);
|
||||
|
||||
const payment = (await events(a)).find((e) => e.type === "payment" && e.identity === "T-B")!;
|
||||
expect(payment.payload.chargesMinor).toBe(50000);
|
||||
expect((payment.payload.chargeLines as unknown[]).length).toBe(1);
|
||||
expect(payment.payload.amountMinor).toBe((payment.payload.parkingMinor as number) + 50000);
|
||||
|
||||
const recent = await app.inject({ method: "GET", url: "/api/carwash/orders?scope=recent", headers: { cookie: a.cookie } });
|
||||
const o = recent.json().orders.find((x: { id: string }) => x.id === order.id);
|
||||
expect(o.paidAt).toBeTruthy();
|
||||
expect(o.paymentEventId).toBeUndefined(); // not exposed on the view
|
||||
expect(o.tender).toBe("cash");
|
||||
// A second lookup no longer carries the line (it's settled).
|
||||
const again = await app.inject({ method: "GET", url: "/api/session/T-B", headers: { cookie: a.cookie } });
|
||||
expect(again.json().chargeLines).toEqual([]);
|
||||
|
||||
// The booth's Z-report: the wash money is inside cash (it is in the drawer) but
|
||||
// OUT of the ticket bucket, under its own module — Bileta is parking money only.
|
||||
const parking = payment.payload.parkingMinor as number;
|
||||
const z = (await app.inject({ method: "POST", url: "/api/shift/close", headers: hdrs(a) })).json();
|
||||
expect(z).toMatchObject({ till: "booth", cashTotalMinor: parking + 50000, ticketTotalMinor: parking, chargesByModuleMinor: { carwash: 50000 } });
|
||||
expect(z.ticketTotalMinor + z.subscriptionTotalMinor + 50000).toBe(z.cashTotalMinor + z.cardTotalMinor);
|
||||
const summary = (await app.inject({ method: "GET", url: "/api/shifts", headers: { cookie: a.cookie } })).json().shifts[0];
|
||||
expect(summary).toMatchObject({ till: "booth", ticketTotalMinor: parking, chargesByModuleMinor: { carwash: 50000 } });
|
||||
const signed = (await events(a)).find((e) => e.type === "shift_z_report")!;
|
||||
expect(signed.payload.chargesByModuleMinor).toEqual({ carwash: 50000 });
|
||||
});
|
||||
|
||||
it("pay at BAY with a comp sponsorship: done applies the validation, bay payment signs carwash_payment and settles parking at zero", async () => {
|
||||
const a = await admin();
|
||||
seedTariff(db, { pricePerIncrementMinor: 10000 });
|
||||
const ids = await seedSettings(a);
|
||||
await seedSponsorship(a, "comp");
|
||||
await openSession("T-Y");
|
||||
await setPayAt(a, "bay");
|
||||
const order = (await app.inject({
|
||||
method: "POST", url: "/api/carwash/orders", headers: hdrs(a),
|
||||
payload: { identity: "T-Y", categoryId: ids.suv, serviceId: ids.std },
|
||||
})).json();
|
||||
|
||||
// Bay money needs an open CARWASH shift — the booth's shift does not count (tills).
|
||||
await app.inject({ method: "POST", url: "/api/shift/open", headers: hdrs(a) });
|
||||
const noShift = await app.inject({ method: "POST", url: `/api/carwash/orders/${order.id}/pay`, headers: hdrs(a), payload: { tender: "cash" } });
|
||||
expect(noShift.statusCode).toBe(409);
|
||||
expect(noShift.json()).toMatchObject({ code: "no_shift", till: "carwash" });
|
||||
const openWash = await app.inject({ method: "POST", url: "/api/shift/open", headers: hdrs(a), payload: { till: "carwash" } });
|
||||
expect(openWash.statusCode).toBe(200);
|
||||
|
||||
const done = await app.inject({ method: "POST", url: `/api/carwash/orders/${order.id}/done`, headers: hdrs(a) });
|
||||
expect(done.statusCode).toBe(200);
|
||||
expect(done.json().status).toBe("done");
|
||||
expect(done.json().validationEventId).toBeTruthy();
|
||||
// Sponsorship applied → the parking quote is now zero-due (comp), but NOT yet paid.
|
||||
const mid = await app.inject({ method: "GET", url: "/api/session/T-Y", headers: { cookie: a.cookie } });
|
||||
expect(mid.json().amountMinor).toBe(0);
|
||||
expect(mid.json().paidAt).toBeNull();
|
||||
|
||||
const paid = await app.inject({ method: "POST", url: `/api/carwash/orders/${order.id}/pay`, headers: hdrs(a), payload: { tender: "card" } });
|
||||
expect(paid.statusCode).toBe(200);
|
||||
expect(paid.json().closed).toBe(true);
|
||||
|
||||
const evs = await events(a);
|
||||
const bay = evs.find((e) => e.type === "carwash_payment")!;
|
||||
expect(bay.payload).toMatchObject({ orderId: order.id, amountMinor: 70000, tender: "card", operator: "boss", till: "carwash" });
|
||||
// The wash Z-report carries the bay money; the booth's carries none of it.
|
||||
const washZ = (await app.inject({ method: "POST", url: "/api/shift/close", headers: hdrs(a), payload: { till: "carwash" } })).json();
|
||||
expect(washZ).toMatchObject({ till: "carwash", cardTotalMinor: 70000, cashTotalMinor: 0, paymentCount: 1 });
|
||||
const boothZ = (await app.inject({ method: "POST", url: "/api/shift/close", headers: hdrs(a) })).json();
|
||||
expect(boothZ.till).toBe("booth");
|
||||
expect(boothZ.cardTotalMinor).toBe(0);
|
||||
expect(boothZ.paymentCount).toBe(1); // the $0 parking settlement is booth money
|
||||
// The $0 parking payment exists → the exit reader's paid+grace check passes.
|
||||
const parkingPay = evs.find((e) => e.type === "payment" && e.identity === "T-Y")!;
|
||||
expect(parkingPay).toBeTruthy();
|
||||
expect(parkingPay.payload.amountMinor).toBe(0);
|
||||
const after = await app.inject({ method: "GET", url: "/api/session/T-Y", headers: { cookie: a.cookie } });
|
||||
expect(after.json().paidAt).toBeTruthy();
|
||||
expect(after.json().withinGrace).toBe(true);
|
||||
|
||||
// The queue is empty (done + paid = closed).
|
||||
const queue = await app.inject({ method: "GET", url: "/api/carwash/orders", headers: { cookie: a.cookie } });
|
||||
expect(queue.json().orders).toEqual([]);
|
||||
});
|
||||
|
||||
it("pay at BAY with a PARTIAL sponsorship leaves the remainder for the booth (no $0 payment)", async () => {
|
||||
const a = await admin();
|
||||
seedTariff(db, { pricePerIncrementMinor: 10000 });
|
||||
const ids = await seedSettings(a);
|
||||
await seedSponsorship(a, "percent");
|
||||
await openSession("T-P");
|
||||
await setPayAt(a, "bay");
|
||||
const order = (await app.inject({
|
||||
method: "POST", url: "/api/carwash/orders", headers: hdrs(a),
|
||||
payload: { identity: "T-P", categoryId: ids.car, serviceId: ids.std },
|
||||
})).json();
|
||||
await app.inject({ method: "POST", url: "/api/shift/open", headers: hdrs(a), payload: { till: "carwash" } });
|
||||
await app.inject({ method: "POST", url: `/api/carwash/orders/${order.id}/pay`, headers: hdrs(a), payload: { tender: "cash" } });
|
||||
await app.inject({ method: "POST", url: `/api/carwash/orders/${order.id}/done`, headers: hdrs(a) });
|
||||
const s = (await app.inject({ method: "GET", url: "/api/session/T-P", headers: { cookie: a.cookie } })).json();
|
||||
expect(s.paidAt).toBeNull();
|
||||
expect(s.amountMinor).toBeGreaterThan(0);
|
||||
expect(s.discountMinor).toBeGreaterThan(0);
|
||||
});
|
||||
|
||||
it("void takes back a live sponsorship; a paid order cannot be voided", async () => {
|
||||
const a = await admin();
|
||||
seedTariff(db);
|
||||
const ids = await seedSettings(a);
|
||||
await seedSponsorship(a, "comp");
|
||||
await openSession("T-V");
|
||||
const order = (await app.inject({
|
||||
method: "POST", url: "/api/carwash/orders", headers: hdrs(a),
|
||||
payload: { identity: "T-V", categoryId: ids.car, serviceId: ids.std },
|
||||
})).json();
|
||||
await app.inject({ method: "POST", url: `/api/carwash/orders/${order.id}/done`, headers: hdrs(a) });
|
||||
const before = (await app.inject({ method: "GET", url: "/api/session/T-V", headers: { cookie: a.cookie } })).json();
|
||||
expect(before.validationLines).toHaveLength(1);
|
||||
|
||||
const voided = await app.inject({ method: "POST", url: `/api/carwash/orders/${order.id}/void`, headers: hdrs(a), payload: { reason: "customer left" } });
|
||||
expect(voided.statusCode).toBe(200);
|
||||
expect(voided.json().status).toBe("void");
|
||||
const after = (await app.inject({ method: "GET", url: "/api/session/T-V", headers: { cookie: a.cookie } })).json();
|
||||
expect(after.validationLines).toEqual([]);
|
||||
expect(after.chargeLines).toEqual([]);
|
||||
});
|
||||
});
|
||||
|
||||
describe("wash-only discount modes", () => {
|
||||
it("doneTolerance credits only the WASH WINDOW (+ tolerance), never the parking before the order", async () => {
|
||||
const a = await admin();
|
||||
// 100.00 per 60-min increment, no entry grace; parked 95 min → 2 increments.
|
||||
seedTariff(db, { pricePerIncrementMinor: 10000, incrementMin: 60, gracePeriodEntryMin: 0 });
|
||||
const ids = await seedSettings(a);
|
||||
await seedSponsorship(a, "doneTolerance", 15);
|
||||
await openSession("T-D", 95);
|
||||
await setPayAt(a, "bay");
|
||||
const order = (await app.inject({
|
||||
method: "POST", url: "/api/carwash/orders", headers: hdrs(a),
|
||||
payload: { identity: "T-D", categoryId: ids.car, serviceId: ids.std },
|
||||
})).json();
|
||||
const before = (await app.inject({ method: "GET", url: "/api/session/T-D", headers: { cookie: a.cookie } })).json();
|
||||
expect(before.amountMinor).toBe(20000);
|
||||
// Done right away: the wash window is ~0 min, so the credit is just the tolerance.
|
||||
await app.inject({ method: "POST", url: `/api/carwash/orders/${order.id}/done`, headers: hdrs(a) });
|
||||
const v = (await events(a)).find((e) => e.type === "validation" && e.identity === "T-D")!;
|
||||
expect(v.payload.mode).toBe("timeCredit");
|
||||
expect(v.payload.programMode).toBe("doneTolerance");
|
||||
expect(v.payload.minutes as number).toBeGreaterThanOrEqual(15);
|
||||
expect(v.payload.minutes as number).toBeLessThanOrEqual(17);
|
||||
// 95 − ~15 min still spans 2 increments → the long stay is NOT comped away.
|
||||
const after = (await app.inject({ method: "GET", url: "/api/session/T-D", headers: { cookie: a.cookie } })).json();
|
||||
expect(after.amountMinor).toBe(20000);
|
||||
expect(after.discountMinor).toBe(0);
|
||||
});
|
||||
|
||||
it("doneTolerance with a tolerance that covers the whole stay does comp it (the credit is real)", async () => {
|
||||
const a = await admin();
|
||||
seedTariff(db, { pricePerIncrementMinor: 10000, incrementMin: 60, gracePeriodEntryMin: 0 });
|
||||
const ids = await seedSettings(a);
|
||||
await seedSponsorship(a, "doneTolerance", 120);
|
||||
await openSession("T-D2", 95);
|
||||
await setPayAt(a, "bay");
|
||||
const order = (await app.inject({
|
||||
method: "POST", url: "/api/carwash/orders", headers: hdrs(a),
|
||||
payload: { identity: "T-D2", categoryId: ids.car, serviceId: ids.std },
|
||||
})).json();
|
||||
await app.inject({ method: "POST", url: `/api/carwash/orders/${order.id}/done`, headers: hdrs(a) });
|
||||
const after = (await app.inject({ method: "GET", url: "/api/session/T-D2", headers: { cookie: a.cookie } })).json();
|
||||
expect(after.amountMinor).toBe(0);
|
||||
});
|
||||
|
||||
it("washPrice: the wash price comes off the parking fee, floored at zero", async () => {
|
||||
const a = await admin();
|
||||
// 1000.00/h, parked 95 min → 2 increments = 200000 owed. Car·Standard wash = 50000.
|
||||
seedTariff(db, { pricePerIncrementMinor: 100000, incrementMin: 60, gracePeriodEntryMin: 0 });
|
||||
const ids = await seedSettings(a);
|
||||
await seedSponsorship(a, "washPrice");
|
||||
await openSession("T-W", 95);
|
||||
await setPayAt(a, "bay");
|
||||
const order = (await app.inject({
|
||||
method: "POST", url: "/api/carwash/orders", headers: hdrs(a),
|
||||
payload: { identity: "T-W", categoryId: ids.car, serviceId: ids.std },
|
||||
})).json();
|
||||
const before = (await app.inject({ method: "GET", url: "/api/session/T-W", headers: { cookie: a.cookie } })).json();
|
||||
await app.inject({ method: "POST", url: `/api/carwash/orders/${order.id}/done`, headers: hdrs(a) });
|
||||
const after = (await app.inject({ method: "GET", url: "/api/session/T-W", headers: { cookie: a.cookie } })).json();
|
||||
expect(after.discountMinor).toBe(50000);
|
||||
expect(after.amountMinor).toBe(before.amountMinor - 50000);
|
||||
const v = (await events(a)).find((e) => e.type === "validation" && e.identity === "T-W")!;
|
||||
expect(v.payload).toMatchObject({ mode: "fixed", programMode: "washPrice", amountMinor: 50000 });
|
||||
});
|
||||
|
||||
it("a merchant scan cannot apply a wash-only program", async () => {
|
||||
const a = await admin();
|
||||
seedTariff(db);
|
||||
await seedSponsorship(a, "washPrice");
|
||||
// Bind the admin to it so the binding check passes and the MODE check is what refuses.
|
||||
await app.inject({
|
||||
method: "PUT", url: "/api/validation/programs/carwash", headers: hdrs(a),
|
||||
payload: { name: "Lavazh", mode: "washPrice", active: true, userIds: [(await app.inject({ method: "GET", url: "/api/auth/me", headers: { cookie: a.cookie } })).json().id] },
|
||||
});
|
||||
await openSession("T-M");
|
||||
const res = await app.inject({ method: "POST", url: "/api/validation/apply", headers: hdrs(a), payload: { identity: "T-M", programId: "carwash" } });
|
||||
expect(res.statusCode).toBe(400);
|
||||
expect(res.json().error).toMatch(/car wash order/);
|
||||
});
|
||||
});
|
||||
|
||||
describe("module gate", () => {
|
||||
it("with carwash deactivated every route 403s and the booth quote carries no wash lines", async () => {
|
||||
const a = await admin();
|
||||
seedTariff(db);
|
||||
const ids = await seedSettings(a);
|
||||
await openSession("T-G");
|
||||
await app.inject({
|
||||
method: "POST", url: "/api/carwash/orders", headers: hdrs(a),
|
||||
payload: { identity: "T-G", categoryId: ids.car, serviceId: ids.std },
|
||||
});
|
||||
const off = await app.inject({ method: "PUT", url: "/api/site-config", headers: hdrs(a), payload: { modules: ["parking", "validation"] } });
|
||||
expect(off.json().modules).toEqual(["parking", "validation"]);
|
||||
const q = await app.inject({ method: "GET", url: "/api/carwash/orders", headers: { cookie: a.cookie } });
|
||||
expect(q.statusCode).toBe(403);
|
||||
expect(q.json().code).toBe("module_disabled");
|
||||
const look = (await app.inject({ method: "GET", url: "/api/session/T-G", headers: { cookie: a.cookie } })).json();
|
||||
expect(look.chargeLines).toEqual([]);
|
||||
});
|
||||
});
|
||||
|
||||
describe("where the money is taken is a SITE setting", () => {
|
||||
it("defaults to the booth, persists, signs a config_change, and freezes on each order", async () => {
|
||||
const a = await admin();
|
||||
seedTariff(db);
|
||||
const ids = await seedSettings(a);
|
||||
expect((await app.inject({ method: "GET", url: "/api/carwash/settings", headers: { cookie: a.cookie } })).json().payAt).toBe("booth");
|
||||
await openSession("T-S1");
|
||||
const o1 = (await app.inject({ method: "POST", url: "/api/carwash/orders", headers: hdrs(a), payload: { identity: "T-S1", categoryId: ids.car, serviceId: ids.std } })).json();
|
||||
expect(o1.payAt).toBe("booth");
|
||||
|
||||
await setPayAt(a, "bay");
|
||||
const cfg = (await events(a)).find((e) => e.type === "config_change" && e.payload.setting === "carwash.payAt")!;
|
||||
expect(cfg.payload).toMatchObject({ value: "bay", prev: "booth", operator: "boss" });
|
||||
await openSession("T-S2");
|
||||
const o2 = (await app.inject({ method: "POST", url: "/api/carwash/orders", headers: hdrs(a), payload: { identity: "T-S2", categoryId: ids.car, serviceId: ids.std } })).json();
|
||||
expect(o2.payAt).toBe("bay");
|
||||
expect(o1.payAt).toBe("booth"); // earlier order keeps the policy it was created under
|
||||
|
||||
// A stale client insisting on the other place is refused, never silently overridden.
|
||||
const stale = await app.inject({ method: "POST", url: "/api/carwash/orders", headers: hdrs(a), payload: { identity: "T-S2", categoryId: ids.car, serviceId: ids.std, payAt: "booth" } });
|
||||
expect(stale.statusCode).toBe(409);
|
||||
expect(stale.json().code).toBe("pay_at_policy");
|
||||
const bad = await app.inject({ method: "PUT", url: "/api/carwash/settings", headers: hdrs(a), payload: { payAt: "pocket" } });
|
||||
expect(bad.statusCode).toBe(400);
|
||||
});
|
||||
});
|
||||
|
||||
describe("tills are gated by the module permission", () => {
|
||||
it("a wash-only role works the carwash till and never the booth's; a booth role the reverse", async () => {
|
||||
const a = await admin();
|
||||
seedTariff(db);
|
||||
await seedSettings(a);
|
||||
// The wash-operator JOB: no shift:* / drawer:* at all — the wash till is guarded by
|
||||
// carwash:read / carwash:cash (venue-modules.md §"Permissions matrix").
|
||||
const washer = await seedUser(db, {
|
||||
username: "lavazhier", roleId: "washer",
|
||||
permissions: ["carwash:read", "carwash:create", "carwash:update", "carwash:cash"],
|
||||
});
|
||||
const w = await login(app, washer.username, washer.password);
|
||||
// The desk's category/service pickers come from the settings read — the job has no
|
||||
// site:read, so the module permission must open it (found on park dev, 2026-09-06).
|
||||
const list = await app.inject({ method: "GET", url: "/api/carwash/settings", headers: { cookie: w.cookie } });
|
||||
expect(list.statusCode).toBe(200);
|
||||
expect(list.json().categories.length).toBeGreaterThan(0);
|
||||
expect((await app.inject({ method: "PUT", url: "/api/carwash/settings", headers: hdrs(w), payload: { payAt: "bay" } })).statusCode).toBe(403);
|
||||
// What the UI offers: only the wash till.
|
||||
const tills = await app.inject({ method: "GET", url: "/api/shift/tills", headers: { cookie: w.cookie } });
|
||||
expect(tills.json().tills.map((t: { till: string }) => t.till)).toEqual(["carwash"]);
|
||||
// The booth's shift is refused outright (the role holds no shift:*).
|
||||
const booth = await app.inject({ method: "POST", url: "/api/shift/open", headers: hdrs(w) });
|
||||
expect(booth.statusCode).toBe(403);
|
||||
expect(booth.json()).toMatchObject({ code: "till_forbidden", till: "booth" });
|
||||
const boothState = await app.inject({ method: "GET", url: "/api/shift/current", headers: { cookie: w.cookie } });
|
||||
expect(boothState.statusCode).toBe(403);
|
||||
const boothCash = await app.inject({ method: "POST", url: "/api/drawer/movement", headers: hdrs(w), payload: { type: "cash_in", amountMinor: 100 } });
|
||||
expect(boothCash.statusCode).toBe(403);
|
||||
// The wash till works.
|
||||
const wash = await app.inject({ method: "POST", url: "/api/shift/open", headers: hdrs(w), payload: { till: "carwash" } });
|
||||
expect(wash.statusCode).toBe(200);
|
||||
expect(wash.json().till).toBe("carwash");
|
||||
const washCash = await app.inject({ method: "POST", url: "/api/drawer/movement", headers: hdrs(w), payload: { type: "cash_in", amountMinor: 100, till: "carwash" } });
|
||||
expect(washCash.statusCode).toBe(200);
|
||||
|
||||
// A wash user who may look (carwash:read) but not work the till (no carwash:cash)
|
||||
// sees the state and gets canWork=false; opening is refused.
|
||||
const looker = await seedUser(db, { username: "looker", roleId: "wash-look", permissions: ["carwash:read"] });
|
||||
const l = await login(app, looker.username, looker.password);
|
||||
const lookTills = (await app.inject({ method: "GET", url: "/api/shift/tills", headers: { cookie: l.cookie } })).json();
|
||||
expect(lookTills.tills).toMatchObject([{ till: "carwash", canWork: false }]);
|
||||
expect((await app.inject({ method: "POST", url: "/api/shift/open", headers: hdrs(l), payload: { till: "carwash" } })).statusCode).toBe(403);
|
||||
|
||||
// A booth operator (shift:*, no carwash:*) cannot touch the wash till.
|
||||
const booth1 = await seedUser(db, {
|
||||
username: "boothie", roleId: "booth-op",
|
||||
permissions: ["session:read", "payment:create", "shift:read", "shift:create"],
|
||||
});
|
||||
const b = await login(app, booth1.username, booth1.password);
|
||||
const noWash = await app.inject({ method: "POST", url: "/api/shift/close", headers: hdrs(b), payload: { till: "carwash" } });
|
||||
expect(noWash.statusCode).toBe(403);
|
||||
expect((await app.inject({ method: "GET", url: "/api/shift/tills", headers: { cookie: b.cookie } })).json().tills.map((t: { till: string }) => t.till)).toEqual(["booth"]);
|
||||
});
|
||||
});
|
||||
|
||||
describe("a role reassignment takes effect without re-login", () => {
|
||||
it("a user moved from a look-only role to the wash-operator role can create an order on the next request", async () => {
|
||||
const a = await admin();
|
||||
seedTariff(db);
|
||||
const ids = await seedSettings(a);
|
||||
await openSession("T-R");
|
||||
const looker = await seedUser(db, { username: "moved", roleId: "wash-look", permissions: ["carwash:read"] });
|
||||
// Materialise the target role (seedUser creates the role rows; the user itself is a throwaway).
|
||||
await seedUser(db, { username: "throwaway", roleId: "wash-op", permissions: ["carwash:read", "carwash:create", "carwash:update", "carwash:cash"] });
|
||||
const l = await login(app, looker.username, looker.password);
|
||||
const before = await app.inject({ method: "POST", url: "/api/carwash/orders", headers: hdrs(l), payload: { identity: "T-R", categoryId: ids.car, serviceId: ids.std } });
|
||||
expect(before.statusCode).toBe(403);
|
||||
|
||||
const list = (await app.inject({ method: "GET", url: "/api/users", headers: { cookie: a.cookie } })).json();
|
||||
const id = list.users.find((u: { username: string }) => u.username === "moved").id;
|
||||
const moved = await app.inject({ method: "PUT", url: `/api/users/${id}`, headers: hdrs(a), payload: { roleId: "wash-op" } });
|
||||
expect(moved.statusCode).toBe(200);
|
||||
|
||||
// Same cookie, no re-login: the token's pinned role is refreshed per request.
|
||||
const after = await app.inject({ method: "POST", url: "/api/carwash/orders", headers: hdrs(l), payload: { identity: "T-R", categoryId: ids.car, serviceId: ids.std } });
|
||||
expect(after.statusCode).toBe(201);
|
||||
const me = (await app.inject({ method: "GET", url: "/api/auth/me", headers: { cookie: l.cookie } })).json();
|
||||
expect(me.roleId).toBe("wash-op");
|
||||
});
|
||||
});
|
||||
|
||||
describe("a shift's activity log is per till", () => {
|
||||
it("/api/events?till= applies tillOfEvent; a feed-only role reads its module's events and nothing else", async () => {
|
||||
const a = await admin();
|
||||
seedTariff(db, { pricePerIncrementMinor: 10000 });
|
||||
const ids = await seedSettings(a);
|
||||
await openSession("T-L");
|
||||
await setPayAt(a, "bay");
|
||||
await app.inject({ method: "POST", url: "/api/shift/open", headers: hdrs(a) });
|
||||
await app.inject({ method: "POST", url: "/api/shift/open", headers: hdrs(a), payload: { till: "carwash" } });
|
||||
const order = (await app.inject({
|
||||
method: "POST", url: "/api/carwash/orders", headers: hdrs(a),
|
||||
payload: { identity: "T-L", categoryId: ids.suv, serviceId: ids.std },
|
||||
})).json();
|
||||
await app.inject({ method: "POST", url: `/api/carwash/orders/${order.id}/done`, headers: hdrs(a) });
|
||||
await app.inject({ method: "POST", url: `/api/carwash/orders/${order.id}/pay`, headers: hdrs(a), payload: { tender: "cash" } });
|
||||
await app.inject({ method: "POST", url: "/api/drawer/movement", headers: hdrs(a), payload: { type: "cash_in", amountMinor: 500, till: "carwash" } });
|
||||
await app.inject({ method: "POST", url: "/api/drawer/movement", headers: hdrs(a), payload: { type: "cash_in", amountMinor: 700 } });
|
||||
|
||||
const types = async (qs: string, auth: Auth = a) => {
|
||||
const r = await app.inject({ method: "GET", url: `/api/events?limit=200${qs}`, headers: { cookie: auth.cookie } });
|
||||
expect(r.statusCode).toBe(200);
|
||||
return (r.json().events as { type: string; payload: Record<string, unknown> }[]).map((e) => `${e.type}${e.payload?.till ? `@${e.payload.till}` : ""}`);
|
||||
};
|
||||
// The wash till's log: its shift, its order (no money moved, but wash-desk activity),
|
||||
// its bay payment and its voucher — none of the booth's.
|
||||
const wash = await types("&till=carwash");
|
||||
expect(wash).toEqual(expect.arrayContaining(["shift_open@carwash", "carwash_order", "carwash_payment@carwash", "cash_in@carwash"]));
|
||||
expect(wash.some((t) => t.startsWith("vehicle_entry") || t === "shift_open@booth" || t === "cash_in@booth")).toBe(false);
|
||||
// The booth's log: entry, its shift, its voucher — and no wash-desk activity.
|
||||
const booth = await types("&till=booth");
|
||||
expect(booth).toEqual(expect.arrayContaining(["vehicle_entry", "shift_open@booth", "cash_in@booth"]));
|
||||
expect(booth.some((t) => t.startsWith("carwash_") || t.endsWith("@carwash"))).toBe(false);
|
||||
// No till → everything (unchanged).
|
||||
const all = await types("");
|
||||
expect(all.length).toBe(wash.length + booth.length);
|
||||
expect((await app.inject({ method: "GET", url: "/api/events?till=bar", headers: { cookie: a.cookie } })).statusCode).toBe(400);
|
||||
|
||||
// A wash operator holds carwash:read but not event:read: the log opens for them
|
||||
// with ONLY the module's own event types (the live-socket rule, feedPermissionFor).
|
||||
const washer = await seedUser(db, { username: "lavazhier", roleId: "washer", permissions: ["carwash:read", "carwash:cash"] });
|
||||
const w = await login(app, washer.username, washer.password);
|
||||
const mine = await types("&till=carwash", w);
|
||||
expect(mine).toEqual(expect.arrayContaining(["carwash_order", "carwash_payment@carwash"]));
|
||||
expect(mine.every((t) => t.startsWith("carwash_"))).toBe(true);
|
||||
// A role with neither event:read nor any module feed permission reads nothing.
|
||||
const clerk = await seedUser(db, { username: "clerk", roleId: "clerk", permissions: ["session:read"] });
|
||||
const c = await login(app, clerk.username, clerk.password);
|
||||
expect((await app.inject({ method: "GET", url: "/api/events", headers: { cookie: c.cookie } })).statusCode).toBe(403);
|
||||
});
|
||||
});
|
||||
|
||||
describe("vision category — advisory, flagged, never authoritative", () => {
|
||||
/** What snapshot.ts records when vision classifies the entry frame. */
|
||||
function seeVehicle(identity: string, bodyType: string, bodyConfidence: number) {
|
||||
db.insert(deviceEvents).values({
|
||||
id: `read-${identity}-${bodyType}`, deviceId: "cam-1", category: "camera", kind: "read",
|
||||
detail: { identity, direction: "entry", bodyType, bodyConfidence, snapshotId: "snap-1", source: "entry-exit-snapshot" },
|
||||
occurredAt: new Date().toISOString(),
|
||||
}).run();
|
||||
}
|
||||
async function mapClasses(a: Auth, ids: { car: string; suv: string }) {
|
||||
const cur = (await app.inject({ method: "GET", url: "/api/carwash/settings", headers: { cookie: a.cookie } })).json();
|
||||
const r = await app.inject({
|
||||
method: "PUT", url: "/api/carwash/settings", headers: hdrs(a),
|
||||
payload: {
|
||||
categories: cur.categories.map((c: { id: string }) => ({ ...c, visionClasses: c.id === ids.suv ? ["suv", "pickup"] : c.id === ids.car ? ["car", "sedan", "hatchback"] : [] })),
|
||||
visionThreshold: 0.75,
|
||||
},
|
||||
});
|
||||
expect(r.statusCode).toBe(200);
|
||||
return r.json();
|
||||
}
|
||||
|
||||
it("Setup maps the vocabulary onto site categories; the lookup suggests the mapped category", async () => {
|
||||
const a = await admin();
|
||||
seedTariff(db);
|
||||
const ids = await seedSettings(a);
|
||||
const saved = await mapClasses(a, ids);
|
||||
expect(saved.categories.find((c: { id: string }) => c.id === ids.suv).visionClasses).toEqual(["suv", "pickup"]);
|
||||
expect(saved.visionThreshold).toBe(0.75);
|
||||
expect((await events(a)).some((e) => e.type === "config_change" && e.payload.setting === "carwash.visionThreshold")).toBe(true);
|
||||
const bad = await app.inject({ method: "PUT", url: "/api/carwash/settings", headers: hdrs(a), payload: { categories: [{ id: ids.car, name: "Car", visionClasses: ["spaceship"] }] } });
|
||||
expect(bad.statusCode).toBe(400);
|
||||
|
||||
await openSession("T-V1");
|
||||
seeVehicle("T-V1", "suv", 0.91);
|
||||
const look = (await app.inject({ method: "GET", url: "/api/carwash/session/T-V1", headers: { cookie: a.cookie } })).json();
|
||||
expect(look.vision).toMatchObject({ bodyType: "suv", confidence: 0.91, snapshotId: "snap-1" });
|
||||
expect(look.suggestedCategoryId).toBe(ids.suv);
|
||||
// Unmapped class → shown, nothing suggested.
|
||||
await openSession("T-V2");
|
||||
seeVehicle("T-V2", "bus", 0.99);
|
||||
const look2 = (await app.inject({ method: "GET", url: "/api/carwash/session/T-V2", headers: { cookie: a.cookie } })).json();
|
||||
expect(look2.vision.bodyType).toBe("bus");
|
||||
expect(look2.suggestedCategoryId).toBeNull();
|
||||
});
|
||||
|
||||
it("a confident downgrade signs an anomaly with both categories and the snapshot; equal, upgrade or unsure reads do not; the order is never blocked", async () => {
|
||||
const a = await admin();
|
||||
seedTariff(db);
|
||||
const ids = await seedSettings(a);
|
||||
await mapClasses(a, ids);
|
||||
const order = async (identity: string, categoryId: string) => {
|
||||
const r = await app.inject({ method: "POST", url: "/api/carwash/orders", headers: hdrs(a), payload: { identity, categoryId, serviceId: ids.std } });
|
||||
expect(r.statusCode).toBe(201);
|
||||
return r.json();
|
||||
};
|
||||
// Camera: SUV (0.91) — operator picks Car (cheaper) → flagged, recorded, still created.
|
||||
await openSession("T-D1"); seeVehicle("T-D1", "suv", 0.91);
|
||||
const down = await order("T-D1", ids.car);
|
||||
expect(down).toMatchObject({ visionClass: "suv", visionConfidence: 0.91, visionCategoryId: ids.suv, categoryId: ids.car });
|
||||
expect(down.downgradeEventId).toBeTruthy();
|
||||
const flag = (await events(a)).find((e) => e.type === "anomaly" && e.payload.reasonCode === "carwash.categoryDowngrade")!;
|
||||
expect(flag).toBeTruthy();
|
||||
expect(flag.payload).toMatchObject({
|
||||
visionClass: "suv", visionCategoryName: "SUV", chosenCategoryName: "Car", operator: "boss",
|
||||
visionPriceMinor: 70000, chosenPriceMinor: 50000, snapshotId: "snap-1",
|
||||
});
|
||||
// Same category as the camera → nothing.
|
||||
await openSession("T-D2"); seeVehicle("T-D2", "suv", 0.91);
|
||||
expect((await order("T-D2", ids.suv)).downgradeEventId).toBeNull();
|
||||
// Upgrade (camera Car, operator SUV) → recorded on the order, no anomaly.
|
||||
await openSession("T-D3"); seeVehicle("T-D3", "sedan", 0.95);
|
||||
const up = await order("T-D3", ids.suv);
|
||||
expect(up).toMatchObject({ visionClass: "sedan", visionCategoryId: ids.car, downgradeEventId: null });
|
||||
// Below the site threshold → shown, never flagged.
|
||||
await openSession("T-D4"); seeVehicle("T-D4", "suv", 0.6);
|
||||
expect((await order("T-D4", ids.car)).downgradeEventId).toBeNull();
|
||||
// No read at all → nulls.
|
||||
await openSession("T-D5");
|
||||
expect(await order("T-D5", ids.car)).toMatchObject({ visionClass: null, visionCategoryId: null, downgradeEventId: null });
|
||||
expect((await events(a)).filter((e) => e.type === "anomaly" && e.payload.reasonCode === "carwash.categoryDowngrade")).toHaveLength(1);
|
||||
});
|
||||
});
|
||||
@@ -0,0 +1,36 @@
|
||||
import { deviceEvents } from "../../device-events.js";
|
||||
import type { ServerModule } from "../index.js";
|
||||
import { ReviewOutbox, reviewUploadConfigFromEnv } from "./review-outbox.js";
|
||||
import { carwashRoutes } from "./routes.js";
|
||||
import { CarwashService } from "./service.js";
|
||||
|
||||
// Car Wash — the pilot venue module (wiki/decisions/venue-modules.md). Everything the
|
||||
// module is lives in this folder: its service (master data, the order queue, the bay
|
||||
// payment, the parking sponsorship + settlement), its routes, and the booth charge
|
||||
// provider it registers with the core's PayStation. The core knows it only through the
|
||||
// registry line in ../index.ts and the manifest in @parking/shared.
|
||||
export const carwashModule: ServerModule = {
|
||||
id: "carwash",
|
||||
async register(app, deps) {
|
||||
// The review outbox (wiki/concepts/vision-review-outbox.md): on when the stack env
|
||||
// names a collector URL, a per-booth token and a pseudonymous booth id; off = no
|
||||
// queueing at all. One-way, background, never on the intake path.
|
||||
const cfg = reviewUploadConfigFromEnv();
|
||||
const outbox = new ReviewOutbox(deps.db, app.log, cfg);
|
||||
app.log.info(cfg ? `carwash review upload: on → ${new URL(cfg.url).host} as ${cfg.boothId}` : "carwash review upload: off");
|
||||
outbox.start();
|
||||
// Entry-stream sampling: one in N entry vehicle reads goes to the reviewer as pure
|
||||
// training material (the gate view, no order attached). The core announces the read;
|
||||
// the module decides. Off unless CARWASH_REVIEW_ENTRY_SAMPLE is set.
|
||||
const offVehicleRead = deviceEvents.onVehicleRead((e) => {
|
||||
if (e.direction === "entry" && outbox.sampleEntry()) void outbox.enqueueEntry(e.read);
|
||||
});
|
||||
app.addHook("onClose", async () => offVehicleRead());
|
||||
app.addHook("onClose", async () => outbox.stop());
|
||||
const service = new CarwashService(deps, app.log, outbox);
|
||||
// A wash ordered with payAt = "booth" is a charge line on the parking settlement;
|
||||
// the core calls back after the payment is signed so the order is marked paid.
|
||||
deps.payStation.registerChargeProvider(service.chargeProvider());
|
||||
await carwashRoutes(app, deps, service, outbox);
|
||||
},
|
||||
};
|
||||
@@ -0,0 +1,241 @@
|
||||
import { afterEach, beforeEach, describe, expect, it, vi } from "vitest";
|
||||
import sharp from "sharp";
|
||||
import { createTestDb } from "@parking/db/testing";
|
||||
import { carwashOrders, carwashReviewOutbox, deviceEvents, snapshots, type Db } from "@parking/db";
|
||||
import type { FastifyInstance } from "fastify";
|
||||
import { deviceEvents as deviceEventBus } from "../../device-events.js";
|
||||
import { buildServer } from "../../server.js";
|
||||
import { login, makeLog, minutesAgo, seedTariff, seedUser, silentLogger } from "../../test-helpers.js";
|
||||
import { EXPIRE_DAYS, ReviewOutbox, makeReviewCrop, operatorRef, reviewUploadConfigFromEnv } from "./review-outbox.js";
|
||||
|
||||
// The review outbox, booth side (wiki/concepts/vision-review-outbox.md): a plate-blurred
|
||||
// vehicle crop + the operator's choice, queued off the intake path, drained one-way with
|
||||
// backoff, never blocking the wash, never naming the site.
|
||||
|
||||
/** A 400×300 frame: grey ground, a red "car" block, a white "plate" strip inside it. */
|
||||
async function frame(): Promise<Buffer> {
|
||||
return sharp({ create: { width: 400, height: 300, channels: 3, background: { r: 90, g: 90, b: 90 } } })
|
||||
.composite([
|
||||
{ input: { create: { width: 200, height: 120, channels: 3, background: { r: 200, g: 30, b: 30 } } }, left: 100, top: 100 },
|
||||
{ input: { create: { width: 60, height: 16, channels: 3, background: { r: 255, g: 255, b: 255 } } }, left: 170, top: 190 },
|
||||
])
|
||||
.jpeg()
|
||||
.toBuffer();
|
||||
}
|
||||
const CAR = { x1: 100 / 400, y1: 100 / 300, x2: 300 / 400, y2: 220 / 300 };
|
||||
const PLATE = { x1: 170 / 400, y1: 190 / 300, x2: 230 / 400, y2: 206 / 300 };
|
||||
|
||||
/** Mean GREEN over a region — the white plate reads 255, the red car around it 30, so a
|
||||
* blurred plate drops far below 255 as the red bleeds in. */
|
||||
async function meanGreen(buf: Buffer, region: { left: number; top: number; width: number; height: number }): Promise<number> {
|
||||
const { data, info } = await sharp(buf).extract(region).raw().toBuffer({ resolveWithObject: true });
|
||||
let sum = 0;
|
||||
for (let i = 1; i < data.length; i += info.channels) sum += data[i]!;
|
||||
return sum / (data.length / info.channels);
|
||||
}
|
||||
|
||||
describe("makeReviewCrop", () => {
|
||||
it("cuts the vehicle (with margin), blurs the plate inside it, caps the edge", async () => {
|
||||
const shot = await frame();
|
||||
const crop = await makeReviewCrop(shot, CAR, PLATE);
|
||||
expect(crop.plateBlurred).toBe(true);
|
||||
// Box 200×120 + 8 % margin each side ≈ 232×139; no upscaling.
|
||||
expect(crop.width).toBeGreaterThanOrEqual(228);
|
||||
expect(crop.width).toBeLessThanOrEqual(236);
|
||||
expect(crop.height).toBeGreaterThanOrEqual(135);
|
||||
// The white plate is gone: over the plate strip (crop coords: the frame's 170..230 ×
|
||||
// 190..206 shifted by the crop origin 84,90) the same region cut straight from the
|
||||
// frame is white, the review crop is the red bleeding in.
|
||||
const plain = await sharp(shot).extract({ left: 84, top: 90, width: crop.width, height: crop.height }).jpeg().toBuffer();
|
||||
const strip = { left: 170 - 84, top: 190 - 90, width: 60, height: 16 };
|
||||
expect(await meanGreen(plain, strip)).toBeGreaterThan(240);
|
||||
expect(await meanGreen(crop.bytes, strip)).toBeLessThan(180);
|
||||
// Without a plate box: same crop, nothing blurred.
|
||||
const noPlate = await makeReviewCrop(shot, CAR, null);
|
||||
expect(noPlate.plateBlurred).toBe(false);
|
||||
// A big frame is capped to the max edge.
|
||||
const big = await sharp({ create: { width: 2560, height: 1440, channels: 3, background: "#444" } }).jpeg().toBuffer();
|
||||
const capped = await makeReviewCrop(big, { x1: 0, y1: 0, x2: 1, y2: 1 }, null);
|
||||
expect(Math.max(capped.width, capped.height)).toBe(640);
|
||||
});
|
||||
});
|
||||
|
||||
describe("config + pseudonyms", () => {
|
||||
it("needs url, token and booth id together; the operator ref is a keyed hash", () => {
|
||||
expect(reviewUploadConfigFromEnv({})).toBeNull();
|
||||
expect(reviewUploadConfigFromEnv({ CARWASH_REVIEW_URL: "https://c/ingest", CARWASH_REVIEW_TOKEN: "t" })).toBeNull();
|
||||
const cfg = reviewUploadConfigFromEnv({ CARWASH_REVIEW_URL: "https://c/ingest", CARWASH_REVIEW_TOKEN: "t", CARWASH_REVIEW_BOOTH_ID: "b7", CARWASH_REVIEW_INTERVAL_SEC: "5" });
|
||||
expect(cfg).toMatchObject({ boothId: "b7", intervalSec: 60 }); // below the 10 s floor → default
|
||||
expect(operatorRef("b7", "lavazhier")).toHaveLength(16);
|
||||
expect(operatorRef("b7", "lavazhier")).not.toBe(operatorRef("b8", "lavazhier"));
|
||||
expect(operatorRef("b7", "lavazhier")).not.toContain("lavazhier");
|
||||
});
|
||||
});
|
||||
|
||||
describe("queue + drain", () => {
|
||||
let db: Db;
|
||||
let close: () => void;
|
||||
beforeEach(() => {
|
||||
const t = createTestDb();
|
||||
db = t.db;
|
||||
close = t.close;
|
||||
});
|
||||
afterEach(() => close());
|
||||
|
||||
const cfg = { url: "https://collector.overlay/ingest", token: "secret-1", boothId: "booth-7", intervalSec: 60, entrySample: 0 };
|
||||
const read = { bodyType: "car" as const, confidence: 0.86, snapshotId: "snap-1", box: CAR, plateBox: PLATE };
|
||||
const item = { orderId: "o-1", createdAt: "2026-09-06T10:00:00.000Z", createdBy: "lavazhier", categoryId: "car", categoryName: "Vetura", categoryClasses: ["car", "sedan"], serviceName: "Standard", visionCategoryId: "car", downgraded: false };
|
||||
|
||||
async function seed(): Promise<void> {
|
||||
db.insert(snapshots).values({ id: "snap-1", direction: "entry", identity: "T-1", contentType: "image/jpeg", bytes: await frame(), capturedAt: new Date().toISOString() }).run();
|
||||
db.insert(carwashOrders).values({
|
||||
id: "o-1", identity: "T-1", plate: null, categoryId: "car", categoryName: "Vetura", serviceId: "std", serviceName: "Standard",
|
||||
priceMinor: 100, currency: "ALL", payAt: "booth", status: "open", createdAt: item.createdAt, createdBy: "lavazhier",
|
||||
}).run();
|
||||
}
|
||||
|
||||
it("enqueues a crop + a payload with no site name, no plate, no operator name; drains with a multipart POST; drops the image once sent", async () => {
|
||||
await seed();
|
||||
const calls: { url: string; init: RequestInit }[] = [];
|
||||
const fetchFn = vi.fn(async (url: string, init: RequestInit) => {
|
||||
calls.push({ url, init });
|
||||
return new Response("ok", { status: 200 });
|
||||
});
|
||||
const ob = new ReviewOutbox(db, silentLogger(), cfg, fetchFn);
|
||||
expect(await ob.enqueue(item, read)).toBe(true);
|
||||
const row = db.select().from(carwashReviewOutbox).all()[0]!;
|
||||
expect(row.status).toBe("queued");
|
||||
expect(row.image!.length).toBeGreaterThan(500);
|
||||
expect(row.payload).toMatchObject({ v: 1, kind: "wash", booth: "booth-7", order: "o-1", operatorCategory: { id: "car", name: "Vetura", classes: ["car", "sedan"] }, vision: { class: "car", confidence: 0.86 }, downgraded: false, image: { plateBlurred: true } });
|
||||
expect(JSON.stringify(row.payload)).not.toContain("lavazhier");
|
||||
|
||||
expect(await ob.drain()).toEqual({ sent: 1, failed: 0, deferred: 0 });
|
||||
expect(calls).toHaveLength(1);
|
||||
expect(calls[0]!.url).toBe(cfg.url);
|
||||
expect((calls[0]!.init.headers as Record<string, string>).authorization).toBe("Bearer secret-1");
|
||||
const form = calls[0]!.init.body as FormData;
|
||||
expect(JSON.parse(form.get("meta") as string).item).toBe(row.id);
|
||||
expect((form.get("image") as File).type).toBe("image/jpeg");
|
||||
const after = db.select().from(carwashReviewOutbox).all()[0]!;
|
||||
expect(after.status).toBe("sent");
|
||||
expect(after.image).toBeNull();
|
||||
expect(after.sentAt).toBeTruthy();
|
||||
expect(ob.status()).toMatchObject({ enabled: true, boothId: "booth-7", queued: 0, sent: 1, failed: 0 });
|
||||
});
|
||||
|
||||
it("defers with backoff on collector/network trouble, abandons on a rejection, a void or expiry, skips without a box", async () => {
|
||||
await seed();
|
||||
let status = 503;
|
||||
const fetchFn = vi.fn(async () => (status === 0 ? Promise.reject(new Error("ECONNREFUSED")) : new Response("", { status })));
|
||||
const ob = new ReviewOutbox(db, silentLogger(), cfg, fetchFn);
|
||||
await ob.enqueue(item, read);
|
||||
expect(await ob.drain()).toEqual({ sent: 0, failed: 0, deferred: 1 });
|
||||
let row = db.select().from(carwashReviewOutbox).all()[0]!;
|
||||
expect(row).toMatchObject({ status: "queued", attempts: 1, lastError: "HTTP 503" });
|
||||
expect(Date.parse(row.nextAttemptAt!)).toBeGreaterThan(Date.now() + 60_000);
|
||||
// Not due yet → untouched.
|
||||
expect(await ob.drain()).toEqual({ sent: 0, failed: 0, deferred: 0 });
|
||||
// Due again: a network error defers too; a 422 abandons.
|
||||
db.update(carwashReviewOutbox).set({ nextAttemptAt: null }).run();
|
||||
status = 0;
|
||||
expect(await ob.drain()).toEqual({ sent: 0, failed: 0, deferred: 1 });
|
||||
db.update(carwashReviewOutbox).set({ nextAttemptAt: null }).run();
|
||||
status = 422;
|
||||
expect(await ob.drain()).toEqual({ sent: 0, failed: 1, deferred: 0 });
|
||||
row = db.select().from(carwashReviewOutbox).all()[0]!;
|
||||
expect(row).toMatchObject({ status: "failed", lastError: "rejected: HTTP 422" });
|
||||
expect(row.image).toBeNull();
|
||||
|
||||
// A voided order is not a sample.
|
||||
status = 200;
|
||||
await ob.enqueue({ ...item, orderId: "o-1" }, read);
|
||||
db.update(carwashOrders).set({ status: "void" }).run();
|
||||
expect(await ob.drain()).toEqual({ sent: 0, failed: 1, deferred: 0 });
|
||||
// Expired items are abandoned without a request.
|
||||
await ob.enqueue(item, read);
|
||||
db.update(carwashReviewOutbox).set({ createdAt: new Date(Date.now() - (EXPIRE_DAYS + 1) * 86_400_000).toISOString() }).where(eq(carwashReviewOutbox.status, "queued")).run();
|
||||
db.update(carwashOrders).set({ status: "open" }).run();
|
||||
const before = fetchFn.mock.calls.length;
|
||||
expect(await ob.drain()).toEqual({ sent: 0, failed: 1, deferred: 0 });
|
||||
expect(fetchFn.mock.calls.length).toBe(before);
|
||||
expect(ob.status().failed).toBe(3);
|
||||
|
||||
// Entry sampling: one in N entry reads becomes a package with the crop and the
|
||||
// camera's class only — no order, no operator, no category.
|
||||
const sampler = new ReviewOutbox(db, silentLogger(), { ...cfg, entrySample: 3 }, fetchFn);
|
||||
expect([sampler.sampleEntry(), sampler.sampleEntry(), sampler.sampleEntry(), sampler.sampleEntry()]).toEqual([false, false, true, false]);
|
||||
expect(ob.sampleEntry()).toBe(false); // entrySample 0 = off
|
||||
expect(await sampler.enqueueEntry(read)).toBe(true);
|
||||
const entryRow = db.select().from(carwashReviewOutbox).where(eq(carwashReviewOutbox.orderId, "entry:snap-1")).get()!;
|
||||
expect(entryRow.payload).toMatchObject({ v: 1, kind: "entry", booth: "booth-7", vision: { class: "car", confidence: 0.86 }, image: { plateBlurred: true } });
|
||||
expect(entryRow.payload).not.toHaveProperty("operator");
|
||||
expect(entryRow.payload).not.toHaveProperty("operatorCategory");
|
||||
expect(entryRow.image!.length).toBeGreaterThan(500);
|
||||
|
||||
// No vehicle box, no snapshot, or upload off → nothing queued.
|
||||
expect(await ob.enqueue(item, { ...read, box: null })).toBe(false);
|
||||
expect(await ob.enqueue(item, { ...read, snapshotId: "gone" })).toBe(false);
|
||||
expect(await new ReviewOutbox(db, silentLogger(), null, fetchFn).enqueue(item, read)).toBe(false);
|
||||
});
|
||||
});
|
||||
|
||||
import { eq } from "@parking/db";
|
||||
|
||||
describe("through the app", () => {
|
||||
let db: Db;
|
||||
let close: () => void;
|
||||
let app: FastifyInstance;
|
||||
const saved = { ...process.env };
|
||||
beforeEach(async () => {
|
||||
delete process.env.MODULES_ENTITLED;
|
||||
process.env.CARWASH_REVIEW_URL = "https://collector.overlay/ingest";
|
||||
process.env.CARWASH_REVIEW_TOKEN = "tok";
|
||||
process.env.CARWASH_REVIEW_BOOTH_ID = "booth-9";
|
||||
process.env.CARWASH_REVIEW_ENTRY_SAMPLE = "1";
|
||||
const t = createTestDb();
|
||||
db = t.db;
|
||||
close = t.close;
|
||||
app = await buildServer({ db });
|
||||
await app.ready();
|
||||
});
|
||||
afterEach(async () => {
|
||||
await app.close();
|
||||
close();
|
||||
for (const k of ["CARWASH_REVIEW_URL", "CARWASH_REVIEW_TOKEN", "CARWASH_REVIEW_BOOTH_ID", "CARWASH_REVIEW_ENTRY_SAMPLE"]) {
|
||||
if (saved[k] === undefined) delete process.env[k];
|
||||
else process.env[k] = saved[k];
|
||||
}
|
||||
});
|
||||
|
||||
it("a wash intake with a vehicle read queues a review item; the status route reports it", async () => {
|
||||
const { username, password } = await seedUser(db, { username: "boss", roleId: "admin" });
|
||||
const a = await login(app, username, password);
|
||||
const hdrs = { cookie: a.cookie, "x-csrf-token": a.csrf };
|
||||
seedTariff(db);
|
||||
const s = (await app.inject({ method: "PUT", url: "/api/carwash/settings", headers: hdrs, payload: { categories: [{ name: "Vetura", visionClasses: ["car"] }], services: [{ name: "Standard" }], prices: [] } })).json();
|
||||
const cat = s.categories[0].id, svc = s.services[0].id;
|
||||
await app.inject({ method: "PUT", url: "/api/carwash/settings", headers: hdrs, payload: { prices: [{ categoryId: cat, serviceId: svc, priceMinor: 500 }] } });
|
||||
await makeLog(db).append({ type: "vehicle_entry", source: "manual", identity: "T-R", occurredAt: minutesAgo(30), payload: { sessionRef: "T-R", category: "default" } });
|
||||
db.insert(snapshots).values({ id: "snap-r", direction: "entry", identity: "T-R", contentType: "image/jpeg", bytes: await frame(), capturedAt: new Date().toISOString() }).run();
|
||||
db.insert(deviceEvents).values({
|
||||
id: "read-r", deviceId: "cam-1", category: "camera", kind: "read",
|
||||
detail: { identity: "T-R", direction: "entry", bodyType: "car", bodyConfidence: 0.9, snapshotId: "snap-r", vehicleBox: CAR, plateBox: PLATE },
|
||||
occurredAt: new Date().toISOString(),
|
||||
}).run();
|
||||
|
||||
const order = await app.inject({ method: "POST", url: "/api/carwash/orders", headers: hdrs, payload: { identity: "T-R", categoryId: cat, serviceId: svc } });
|
||||
expect(order.statusCode).toBe(201);
|
||||
// Enqueue is fire-and-forget: give the crop a moment.
|
||||
await vi.waitFor(() => expect(db.select().from(carwashReviewOutbox).all()).toHaveLength(1));
|
||||
const status = (await app.inject({ method: "GET", url: "/api/carwash/review/status", headers: { cookie: a.cookie } })).json();
|
||||
expect(status).toMatchObject({ enabled: true, boothId: "booth-9", queued: 1, sent: 0, entrySample: 1 });
|
||||
|
||||
// An ENTRY vehicle read announced by the core (snapshot.ts) is sampled by the module
|
||||
// (1 in 1 here) into an entry package; an exit read is not.
|
||||
deviceEventBus.emitVehicleRead({ identity: "T-X", direction: "exit", read: { bodyType: "car", confidence: 0.8, snapshotId: "snap-r", box: CAR, plateBox: PLATE } });
|
||||
deviceEventBus.emitVehicleRead({ identity: "T-R", direction: "entry", read: { bodyType: "car", confidence: 0.8, snapshotId: "snap-r", box: CAR, plateBox: PLATE } });
|
||||
await vi.waitFor(() => expect(db.select().from(carwashReviewOutbox).all()).toHaveLength(2));
|
||||
const rows = db.select().from(carwashReviewOutbox).all();
|
||||
expect(rows.map((r) => (r.payload as { kind: string }).kind).sort()).toEqual(["entry", "wash"]);
|
||||
});
|
||||
});
|
||||
@@ -0,0 +1,376 @@
|
||||
import { createHash, randomUUID } from "node:crypto";
|
||||
import sharp from "sharp";
|
||||
import { and, asc, carwashOrders, carwashReviewOutbox, eq, isNull, lte, or, snapshots, sql, type Db } from "@parking/db";
|
||||
import type { NormBox, VehicleRead } from "@parking/shared";
|
||||
import type { FastifyBaseLogger } from "fastify";
|
||||
|
||||
// The Car Wash REVIEW OUTBOX — booth side (wiki/concepts/vision-review-outbox.md).
|
||||
//
|
||||
// The operator's category choice at intake is a HYPOTHESIS, not truth (the threat model:
|
||||
// the operator may err or cheat). So every wash order that has a vehicle read queues a
|
||||
// small package for a trusted remote reviewer: the vehicle CROP cut out of the entry
|
||||
// snapshot with the plate BLURRED, the operator's choice, and what the camera thought.
|
||||
// The reviewer's verdict becomes the training label for the body-type classifier (phase
|
||||
// B) and, per operator, the honest-mistake / fraud rate.
|
||||
//
|
||||
// Rules that shape this file:
|
||||
// - OFFLINE-FIRST: the wash never waits. Enqueue is fire-and-forget off the intake path;
|
||||
// a background loop drains the queue when the private overlay (Netbird) is up, with
|
||||
// backoff, and gives up loudly after EXPIRE_DAYS.
|
||||
// - ONE-WAY: the booth POSTs; nothing ever comes back into the booth's decisions. The
|
||||
// signed ledger stays the only record of what happened at the wash.
|
||||
// - NOTHING THAT NAMES THE SITE LEAVES: only the crop (no walls, no camera OSD, no
|
||||
// bystanders), the plate blurred in place, a per-booth pseudonymous id set at deploy,
|
||||
// the operator as a keyed hash. The mapping back to people and places stays with the
|
||||
// reviewer, off the collector.
|
||||
// - THE NETWORK IS NOT THE AUTH: a per-booth bearer token on top of the overlay; the
|
||||
// booth can do nothing at the collector but this one POST.
|
||||
|
||||
export interface ReviewUploadConfig {
|
||||
/** The collector's ingest URL (reachable only over the overlay). */
|
||||
readonly url: string;
|
||||
/** Per-booth bearer token. */
|
||||
readonly token: string;
|
||||
/** Pseudonymous booth id — a label the reviewer maps to a site; never the site name. */
|
||||
readonly boothId: string;
|
||||
readonly intervalSec: number;
|
||||
/** Queue one in N ENTRY vehicle reads (no order attached) for the reviewer — the gate
|
||||
* view is exactly what the classifier is trained on, and the entry stream is many times
|
||||
* the wash stream. 0 = off. */
|
||||
readonly entrySample: number;
|
||||
}
|
||||
|
||||
/** From the server env (Komodo stack env). All three of URL, token and booth id, or off. */
|
||||
export function reviewUploadConfigFromEnv(env: NodeJS.ProcessEnv = process.env): ReviewUploadConfig | null {
|
||||
const url = (env.CARWASH_REVIEW_URL ?? "").trim();
|
||||
const token = (env.CARWASH_REVIEW_TOKEN ?? "").trim();
|
||||
const boothId = (env.CARWASH_REVIEW_BOOTH_ID ?? "").trim();
|
||||
if (!url || !token || !boothId) return null;
|
||||
const raw = Number(env.CARWASH_REVIEW_INTERVAL_SEC ?? 60);
|
||||
const sample = Number(env.CARWASH_REVIEW_ENTRY_SAMPLE ?? 0);
|
||||
return {
|
||||
url, token, boothId,
|
||||
intervalSec: Number.isFinite(raw) && raw >= 10 ? raw : 60,
|
||||
entrySample: Number.isInteger(sample) && sample > 0 ? sample : 0,
|
||||
};
|
||||
}
|
||||
|
||||
/** The crop's longest edge, in pixels — enough for a reviewer and a classifier, small
|
||||
* enough that a day of washes is a few megabytes. */
|
||||
export const CROP_MAX_EDGE = 640;
|
||||
/** Margin around the detector's box, as a fraction of the box (context for the reviewer). */
|
||||
const CROP_MARGIN = 0.08;
|
||||
/** Items older than this are abandoned (failed "expired") — a booth cut off for two weeks
|
||||
* should not resurface a fortnight of crops in one burst. */
|
||||
export const EXPIRE_DAYS = 14;
|
||||
/** Backoff: 1 min · 2^attempts, capped. */
|
||||
const BACKOFF_BASE_MS = 60_000;
|
||||
const BACKOFF_CAP_MS = 6 * 60 * 60 * 1000;
|
||||
const UPLOAD_TIMEOUT_MS = 20_000;
|
||||
|
||||
/** What one order contributes to the package (the service hands this over at intake). */
|
||||
export interface ReviewItemInput {
|
||||
readonly orderId: string;
|
||||
readonly createdAt: string;
|
||||
readonly createdBy: string;
|
||||
readonly categoryId: string;
|
||||
readonly categoryName: string;
|
||||
/** The vision classes the chosen category covers at this site (its mapping) — lets the
|
||||
* reviewer's class be judged against the operator's category without the site's setup. */
|
||||
readonly categoryClasses: readonly string[];
|
||||
readonly serviceName: string;
|
||||
readonly visionCategoryId: string | null;
|
||||
readonly downgraded: boolean;
|
||||
}
|
||||
|
||||
/**
|
||||
* Cut the vehicle out of the snapshot and blur the plate inside it. Boxes are fractions
|
||||
* of the frame, so this works on the stored (downscaled) copy. Returns a JPEG.
|
||||
*/
|
||||
export async function makeReviewCrop(
|
||||
snapshotBytes: Buffer,
|
||||
box: NormBox,
|
||||
plateBox: NormBox | null | undefined,
|
||||
): Promise<{ bytes: Buffer; width: number; height: number; plateBlurred: boolean }> {
|
||||
const img = sharp(snapshotBytes, { failOn: "none" }).rotate();
|
||||
const meta = await img.metadata();
|
||||
const W = meta.width ?? 0;
|
||||
const H = meta.height ?? 0;
|
||||
if (!W || !H) throw new Error("snapshot has no dimensions");
|
||||
const px = (b: NormBox) => ({
|
||||
left: Math.round(b.x1 * W), top: Math.round(b.y1 * H),
|
||||
right: Math.round(b.x2 * W), bottom: Math.round(b.y2 * H),
|
||||
});
|
||||
const v = px(box);
|
||||
const mw = Math.round((v.right - v.left) * CROP_MARGIN);
|
||||
const mh = Math.round((v.bottom - v.top) * CROP_MARGIN);
|
||||
const left = Math.max(0, v.left - mw);
|
||||
const top = Math.max(0, v.top - mh);
|
||||
const right = Math.min(W, v.right + mw);
|
||||
const bottom = Math.min(H, v.bottom + mh);
|
||||
const width = right - left;
|
||||
const height = bottom - top;
|
||||
if (width < 8 || height < 8) throw new Error("vehicle box too small to crop");
|
||||
|
||||
let crop = img.clone().extract({ left, top, width, height });
|
||||
let plateBlurred = false;
|
||||
if (plateBox) {
|
||||
// The plate region, in CROP coordinates, padded a little so the blur eats the edges.
|
||||
const p = px(plateBox);
|
||||
const pad = Math.round(Math.max(p.right - p.left, p.bottom - p.top) * 0.25);
|
||||
const pl = Math.max(0, p.left - pad - left);
|
||||
const pt = Math.max(0, p.top - pad - top);
|
||||
const pr = Math.min(width, p.right + pad - left);
|
||||
const pb = Math.min(height, p.bottom + pad - top);
|
||||
if (pr - pl >= 2 && pb - pt >= 2) {
|
||||
const region = await sharp(await crop.clone().toBuffer())
|
||||
.extract({ left: pl, top: pt, width: pr - pl, height: pb - pt })
|
||||
.blur(Math.max(6, Math.round((pr - pl) / 6)))
|
||||
.toBuffer();
|
||||
crop = sharp(await crop.toBuffer()).composite([{ input: region, left: pl, top: pt }]);
|
||||
plateBlurred = true;
|
||||
}
|
||||
}
|
||||
const out = await crop
|
||||
.resize({ width: CROP_MAX_EDGE, height: CROP_MAX_EDGE, fit: "inside", withoutEnlargement: true })
|
||||
.jpeg({ quality: 85, mozjpeg: true })
|
||||
.toBuffer({ resolveWithObject: true });
|
||||
return { bytes: out.data, width: out.info.width, height: out.info.height, plateBlurred };
|
||||
}
|
||||
|
||||
/** The operator as a keyed hash — stable per booth so the reviewer can count per person,
|
||||
* meaningless anywhere else. */
|
||||
export function operatorRef(boothId: string, username: string): string {
|
||||
return createHash("sha256").update(`${boothId}:${username}`).digest("hex").slice(0, 16);
|
||||
}
|
||||
|
||||
type FetchLike = (input: string, init: RequestInit) => Promise<Response>;
|
||||
|
||||
export interface OutboxStatus {
|
||||
readonly enabled: boolean;
|
||||
readonly boothId: string | null;
|
||||
readonly queued: number;
|
||||
readonly sent: number;
|
||||
readonly failed: number;
|
||||
readonly lastSentAt: string | null;
|
||||
readonly lastError: string | null;
|
||||
/** 0 = entry sampling off; N = one in N entry reads is queued. */
|
||||
readonly entrySample: number;
|
||||
}
|
||||
|
||||
export class ReviewOutbox {
|
||||
readonly #db: Db;
|
||||
readonly #logger: FastifyBaseLogger;
|
||||
readonly #cfg: ReviewUploadConfig | null;
|
||||
readonly #fetch: FetchLike;
|
||||
#timer: NodeJS.Timeout | null = null;
|
||||
#draining = false;
|
||||
#entrySeen = 0;
|
||||
|
||||
constructor(db: Db, logger: FastifyBaseLogger, cfg: ReviewUploadConfig | null, fetchFn?: FetchLike) {
|
||||
this.#db = db;
|
||||
this.#logger = logger;
|
||||
this.#cfg = cfg;
|
||||
this.#fetch = fetchFn ?? ((input, init) => fetch(input, init));
|
||||
}
|
||||
|
||||
get enabled(): boolean {
|
||||
return this.#cfg != null;
|
||||
}
|
||||
|
||||
/** Queue one order's package. Fire-and-forget: the caller does NOT await this on the
|
||||
* intake path; every failure is logged, none is thrown. Skipped when there is no
|
||||
* vehicle box (nothing to crop — a frame without a detected vehicle is no training
|
||||
* sample) or when upload is not configured (an unbounded queue nobody drains). */
|
||||
async enqueue(item: ReviewItemInput, read: VehicleRead): Promise<boolean> {
|
||||
if (!this.#cfg) return false;
|
||||
return this.#queue(item.orderId, read, (id, crop) => ({
|
||||
v: 1,
|
||||
kind: "wash",
|
||||
booth: this.#cfg!.boothId,
|
||||
item: id,
|
||||
order: item.orderId,
|
||||
at: item.createdAt,
|
||||
operator: operatorRef(this.#cfg!.boothId, item.createdBy),
|
||||
operatorCategory: { id: item.categoryId, name: item.categoryName, classes: [...item.categoryClasses] },
|
||||
service: item.serviceName,
|
||||
vision: { class: read.bodyType, confidence: read.confidence, categoryId: item.visionCategoryId },
|
||||
downgraded: item.downgraded,
|
||||
image: crop,
|
||||
}));
|
||||
}
|
||||
|
||||
/** Every Nth entry read is a sample (N = entrySample); the caller queues it. Counted
|
||||
* in-process, so "1 in 5" is exactly that across a booth's day. */
|
||||
sampleEntry(): boolean {
|
||||
const n = this.#cfg?.entrySample ?? 0;
|
||||
if (n <= 0) return false;
|
||||
this.#entrySeen += 1;
|
||||
return this.#entrySeen % n === 0;
|
||||
}
|
||||
|
||||
/** Queue an ENTRY sample: the crop and the camera's class only — no order, no operator,
|
||||
* no category. Pure training material in the gate view; the reviewer labels it. */
|
||||
async enqueueEntry(read: VehicleRead): Promise<boolean> {
|
||||
if (!this.#cfg) return false;
|
||||
return this.#queue(`entry:${read.snapshotId ?? "?"}`, read, (id, crop) => ({
|
||||
v: 1,
|
||||
kind: "entry",
|
||||
booth: this.#cfg!.boothId,
|
||||
item: id,
|
||||
at: new Date().toISOString(),
|
||||
vision: { class: read.bodyType, confidence: read.confidence },
|
||||
image: crop,
|
||||
}));
|
||||
}
|
||||
|
||||
async #queue(
|
||||
ref: string,
|
||||
read: VehicleRead,
|
||||
build: (id: string, image: { width: number; height: number; plateBlurred: boolean }) => Record<string, unknown>,
|
||||
): Promise<boolean> {
|
||||
if (!read.box || !read.snapshotId) return false;
|
||||
try {
|
||||
const snap = this.#db.select().from(snapshots).where(eq(snapshots.id, read.snapshotId)).get();
|
||||
if (!snap) {
|
||||
this.#logger.info(`carwash review: snapshot ${read.snapshotId} gone (pruned) — ${ref} not queued`);
|
||||
return false;
|
||||
}
|
||||
const crop = await makeReviewCrop(snap.bytes, read.box, read.plateBox);
|
||||
const id = randomUUID();
|
||||
const payload = build(id, { width: crop.width, height: crop.height, plateBlurred: crop.plateBlurred });
|
||||
this.#db
|
||||
.insert(carwashReviewOutbox)
|
||||
.values({ id, orderId: ref, createdAt: new Date().toISOString(), status: "queued", attempts: 0, nextAttemptAt: null, image: crop.bytes, payload })
|
||||
.run();
|
||||
return true;
|
||||
} catch (err) {
|
||||
this.#logger.warn(`carwash review: could not queue ${ref}: ${(err as Error).message}`);
|
||||
return false;
|
||||
}
|
||||
}
|
||||
|
||||
start(): void {
|
||||
if (!this.#cfg || this.#timer) return;
|
||||
const tick = () => {
|
||||
void this.drain().catch((err) => this.#logger.warn(`carwash review: drain failed: ${(err as Error).message}`));
|
||||
};
|
||||
this.#timer = setInterval(tick, this.#cfg.intervalSec * 1000);
|
||||
this.#timer.unref?.();
|
||||
setTimeout(tick, 5_000).unref?.();
|
||||
}
|
||||
|
||||
stop(): void {
|
||||
if (this.#timer) clearInterval(this.#timer);
|
||||
this.#timer = null;
|
||||
}
|
||||
|
||||
/** Send what is due, oldest first. Returns the tally; never throws for a single item. */
|
||||
async drain(limit = 20): Promise<{ sent: number; failed: number; deferred: number }> {
|
||||
const tally = { sent: 0, failed: 0, deferred: 0 };
|
||||
if (!this.#cfg || this.#draining) return tally;
|
||||
this.#draining = true;
|
||||
try {
|
||||
const now = new Date().toISOString();
|
||||
const due = this.#db
|
||||
.select()
|
||||
.from(carwashReviewOutbox)
|
||||
.where(and(eq(carwashReviewOutbox.status, "queued"), or(isNull(carwashReviewOutbox.nextAttemptAt), lte(carwashReviewOutbox.nextAttemptAt, now))))
|
||||
.orderBy(asc(carwashReviewOutbox.createdAt))
|
||||
.limit(limit)
|
||||
.all();
|
||||
for (const row of due) {
|
||||
const outcome = await this.#send(row);
|
||||
tally[outcome] += 1;
|
||||
}
|
||||
if (tally.sent || tally.failed) this.#logger.info(`carwash review: sent ${tally.sent}, failed ${tally.failed}, deferred ${tally.deferred}`);
|
||||
} finally {
|
||||
this.#draining = false;
|
||||
}
|
||||
return tally;
|
||||
}
|
||||
|
||||
async #send(row: typeof carwashReviewOutbox.$inferSelect): Promise<"sent" | "failed" | "deferred"> {
|
||||
const cfg = this.#cfg!;
|
||||
const ageMs = Date.now() - Date.parse(row.createdAt);
|
||||
if (ageMs > EXPIRE_DAYS * 24 * 60 * 60 * 1000) return this.#fail(row, `expired after ${EXPIRE_DAYS} days`);
|
||||
// A wash voided before delivery is not a sample (and not a decision to review).
|
||||
const order = this.#db.select({ status: carwashOrders.status }).from(carwashOrders).where(eq(carwashOrders.id, row.orderId)).get();
|
||||
if (order?.status === "void") return this.#fail(row, "order voided");
|
||||
if (!row.image) return this.#fail(row, "image missing");
|
||||
|
||||
const form = new FormData();
|
||||
form.set("meta", JSON.stringify(row.payload));
|
||||
form.set("image", new Blob([new Uint8Array(row.image)], { type: "image/jpeg" }), `${row.id}.jpg`);
|
||||
const ac = new AbortController();
|
||||
const t = setTimeout(() => ac.abort(), UPLOAD_TIMEOUT_MS);
|
||||
try {
|
||||
const res = await this.#fetch(cfg.url, {
|
||||
method: "POST",
|
||||
headers: { authorization: `Bearer ${cfg.token}`, "x-booth-id": cfg.boothId },
|
||||
body: form,
|
||||
signal: ac.signal,
|
||||
});
|
||||
if (res.ok) {
|
||||
this.#db
|
||||
.update(carwashReviewOutbox)
|
||||
.set({ status: "sent", sentAt: new Date().toISOString(), image: null, lastError: null, attempts: row.attempts + 1 })
|
||||
.where(eq(carwashReviewOutbox.id, row.id))
|
||||
.run();
|
||||
return "sent";
|
||||
}
|
||||
// The collector refused the package itself → no retry will help.
|
||||
if ([400, 404, 413, 415, 422].includes(res.status)) return this.#fail(row, `rejected: HTTP ${res.status}`);
|
||||
// Everything else (auth not yet fixed, throttled, collector down) → try again later.
|
||||
return this.#defer(row, `HTTP ${res.status}`);
|
||||
} catch (err) {
|
||||
return this.#defer(row, (err as Error).name === "AbortError" ? "timeout" : (err as Error).message);
|
||||
} finally {
|
||||
clearTimeout(t);
|
||||
}
|
||||
}
|
||||
|
||||
#fail(row: typeof carwashReviewOutbox.$inferSelect, why: string): "failed" {
|
||||
this.#db
|
||||
.update(carwashReviewOutbox)
|
||||
.set({ status: "failed", lastError: why, image: null, attempts: row.attempts + 1 })
|
||||
.where(eq(carwashReviewOutbox.id, row.id))
|
||||
.run();
|
||||
this.#logger.warn(`carwash review: item ${row.id} (order ${row.orderId}) abandoned — ${why}`);
|
||||
return "failed";
|
||||
}
|
||||
|
||||
#defer(row: typeof carwashReviewOutbox.$inferSelect, why: string): "deferred" {
|
||||
const attempts = row.attempts + 1;
|
||||
const wait = Math.min(BACKOFF_BASE_MS * 2 ** Math.min(attempts, 20), BACKOFF_CAP_MS);
|
||||
this.#db
|
||||
.update(carwashReviewOutbox)
|
||||
.set({ attempts, lastError: why, nextAttemptAt: new Date(Date.now() + wait).toISOString() })
|
||||
.where(eq(carwashReviewOutbox.id, row.id))
|
||||
.run();
|
||||
return "deferred";
|
||||
}
|
||||
|
||||
status(): OutboxStatus {
|
||||
const count = (s: "queued" | "sent" | "failed") =>
|
||||
this.#db.select({ n: sql<number>`count(*)` }).from(carwashReviewOutbox).where(eq(carwashReviewOutbox.status, s)).get()?.n ?? 0;
|
||||
const lastSent = this.#db.select({ at: sql<string | null>`max(${carwashReviewOutbox.sentAt})` }).from(carwashReviewOutbox).get()?.at ?? null;
|
||||
const lastErr = this.#db
|
||||
.select({ e: carwashReviewOutbox.lastError })
|
||||
.from(carwashReviewOutbox)
|
||||
.where(sql`${carwashReviewOutbox.lastError} is not null`)
|
||||
.orderBy(sql`coalesce(${carwashReviewOutbox.sentAt}, ${carwashReviewOutbox.nextAttemptAt}, ${carwashReviewOutbox.createdAt}) desc`)
|
||||
.limit(1)
|
||||
.get()?.e ?? null;
|
||||
return {
|
||||
enabled: this.enabled,
|
||||
boothId: this.#cfg?.boothId ?? null,
|
||||
entrySample: this.#cfg?.entrySample ?? 0,
|
||||
queued: count("queued"),
|
||||
sent: count("sent"),
|
||||
failed: count("failed"),
|
||||
lastSentAt: lastSent,
|
||||
lastError: lastErr,
|
||||
};
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,119 @@
|
||||
import type { FastifyInstance, FastifyReply } from "fastify";
|
||||
import type { Tender } from "@parking/shared";
|
||||
import { requireAnyPermission, requirePermission } from "../../auth.js";
|
||||
import { requireModule } from "../../modules.js";
|
||||
import { NoShiftOpenError } from "../../shift-service.js";
|
||||
import type { ServerModuleDeps } from "../index.js";
|
||||
import type { ReviewOutbox } from "./review-outbox.js";
|
||||
import { CarwashError, CarwashService, isPayAt, type SettingsBody } from "./service.js";
|
||||
|
||||
// HTTP surface of the Car Wash module. Every route is behind the venue-module gate
|
||||
// FIRST (403 module_disabled), then a permission:
|
||||
// settings (master data) site:read / site:update — the site admin's job
|
||||
// queue / ticket lookup carwash:read — the wash desk
|
||||
// intake carwash:create
|
||||
// done / bay payment / void carwash:update
|
||||
// The sponsorship PROGRAM itself is a validation program row (id "carwash") and is
|
||||
// composed through the existing /api/validation/programs/:id route (site:update).
|
||||
|
||||
function sendError(reply: FastifyReply, err: unknown): FastifyReply {
|
||||
if (err instanceof CarwashError) {
|
||||
return reply.code(err.status).send({ error: err.message, ...(err.code ? { code: err.code } : {}) });
|
||||
}
|
||||
if (err instanceof NoShiftOpenError) {
|
||||
// The bay takes money on the CARWASH till: the wash operator's own shift must be
|
||||
// open (the booth's does not count). The desk shows its shift control on this code.
|
||||
return reply.code(409).send({ error: err.message, code: "no_shift", till: err.till });
|
||||
}
|
||||
throw err;
|
||||
}
|
||||
|
||||
export async function carwashRoutes(app: FastifyInstance, deps: ServerModuleDeps, service: CarwashService, outbox?: ReviewOutbox): Promise<void> {
|
||||
const moduleOn = requireModule(deps.db, "carwash");
|
||||
// The price list is the desk's working data as much as Setup's: the wash operator
|
||||
// reads it under the module's own permission (the Wash operator job holds no site:*).
|
||||
const settingsRead = [moduleOn, requireAnyPermission("carwash:read", "site:read")];
|
||||
const settingsWrite = [moduleOn, requirePermission("site:update")];
|
||||
const read = [moduleOn, requirePermission("carwash:read")];
|
||||
const create = [moduleOn, requirePermission("carwash:create")];
|
||||
const update = [moduleOn, requirePermission("carwash:update")];
|
||||
|
||||
app.get("/api/carwash/settings", { preHandler: settingsRead }, async () => service.settings());
|
||||
// The review outbox's health (Setup → Car wash): how many decisions wait for the
|
||||
// reviewer, how many went, the last error. Site admin's read.
|
||||
app.get("/api/carwash/review/status", { preHandler: settingsRead }, async () =>
|
||||
outbox?.status() ?? { enabled: false, boothId: null, queued: 0, sent: 0, failed: 0, lastSentAt: null, lastError: null, entrySample: 0 },
|
||||
);
|
||||
|
||||
app.put<{ Body: SettingsBody }>("/api/carwash/settings", { preHandler: settingsWrite }, async (req, reply) => {
|
||||
try {
|
||||
return await service.saveSettings(req.body ?? {}, req.user.username);
|
||||
} catch (err) {
|
||||
return sendError(reply, err);
|
||||
}
|
||||
});
|
||||
|
||||
app.get<{ Params: { identity: string } }>("/api/carwash/session/:identity", { preHandler: read }, async (req) =>
|
||||
service.lookup(req.params.identity),
|
||||
);
|
||||
|
||||
app.get<{ Querystring: { scope?: string; limit?: string } }>("/api/carwash/orders", { preHandler: read }, async (req) => {
|
||||
if (req.query.scope === "recent") return { orders: service.recentOrders(Number(req.query.limit) || 100) };
|
||||
return { orders: service.openOrders() };
|
||||
});
|
||||
|
||||
app.post<{ Body: { identity?: string; categoryId?: string; serviceId?: string; payAt?: string } }>(
|
||||
"/api/carwash/orders",
|
||||
{ preHandler: create },
|
||||
async (req, reply) => {
|
||||
const b = req.body ?? {};
|
||||
// payAt is a SITE setting now; the desk no longer sends it. Accept it only when it
|
||||
// matches (the service refuses a mismatch) so a stale client cannot pick the till.
|
||||
if (b.payAt !== undefined && !isPayAt(b.payAt)) return reply.code(400).send({ error: "payAt must be booth|bay" });
|
||||
try {
|
||||
const order = await service.createOrder({
|
||||
identity: String(b.identity ?? ""),
|
||||
categoryId: String(b.categoryId ?? ""),
|
||||
serviceId: String(b.serviceId ?? ""),
|
||||
...(b.payAt !== undefined ? { payAt: b.payAt } : {}),
|
||||
actor: req.user.username,
|
||||
});
|
||||
return reply.code(201).send(order);
|
||||
} catch (err) {
|
||||
return sendError(reply, err);
|
||||
}
|
||||
},
|
||||
);
|
||||
|
||||
app.post<{ Params: { id: string } }>("/api/carwash/orders/:id/done", { preHandler: update }, async (req, reply) => {
|
||||
try {
|
||||
return await service.markDone(req.params.id, req.user.username);
|
||||
} catch (err) {
|
||||
return sendError(reply, err);
|
||||
}
|
||||
});
|
||||
|
||||
app.post<{ Params: { id: string }; Body: { tender?: Tender } }>(
|
||||
"/api/carwash/orders/:id/pay",
|
||||
{ preHandler: update },
|
||||
async (req, reply) => {
|
||||
try {
|
||||
return await service.payAtBay(req.params.id, (req.body?.tender ?? "cash") as Tender, req.user.username);
|
||||
} catch (err) {
|
||||
return sendError(reply, err);
|
||||
}
|
||||
},
|
||||
);
|
||||
|
||||
app.post<{ Params: { id: string }; Body: { reason?: string } }>(
|
||||
"/api/carwash/orders/:id/void",
|
||||
{ preHandler: update },
|
||||
async (req, reply) => {
|
||||
try {
|
||||
return await service.voidOrder(req.params.id, String(req.body?.reason ?? "").trim(), req.user.username);
|
||||
} catch (err) {
|
||||
return sendError(reply, err);
|
||||
}
|
||||
},
|
||||
);
|
||||
}
|
||||
@@ -0,0 +1,765 @@
|
||||
import { randomUUID } from "node:crypto";
|
||||
import type { FastifyBaseLogger } from "fastify";
|
||||
import {
|
||||
and,
|
||||
asc,
|
||||
carwashCategories,
|
||||
carwashConfig,
|
||||
carwashOrders,
|
||||
carwashPrices,
|
||||
carwashServices,
|
||||
desc,
|
||||
eq,
|
||||
inArray,
|
||||
isNull,
|
||||
type CarwashOrderRow,
|
||||
type Db,
|
||||
} from "@parking/db";
|
||||
import {
|
||||
CARWASH_PAY_AT,
|
||||
CARWASH_PAY_AT_DEFAULT,
|
||||
CARWASH_PROGRAM_ID,
|
||||
type CarWashPayAt,
|
||||
type CarwashOrderView,
|
||||
type CarwashSettingsView,
|
||||
type ChargeLine,
|
||||
CARWASH_VISION_THRESHOLD_DEFAULT,
|
||||
isVehicleClass,
|
||||
reasonPayload,
|
||||
type VehicleClass,
|
||||
type VehicleRead,
|
||||
type Tender,
|
||||
type TillId,
|
||||
} from "@parking/shared";
|
||||
import type { EventLog } from "../../event-log.js";
|
||||
import { vehicleForIdentity } from "../../plate-lookup.js";
|
||||
import type { ReviewOutbox } from "./review-outbox.js";
|
||||
import { effectiveModulesFor } from "../../modules.js";
|
||||
import type { ChargeProvider, PayStation } from "../../pay-station.js";
|
||||
import type { ShiftService } from "../../shift-service.js";
|
||||
import { applyValidation, liveValidations } from "../../validations.js";
|
||||
import type { ServerModuleDeps } from "../index.js";
|
||||
|
||||
// Car Wash — the module's whole behaviour (wiki/decisions/venue-modules.md, "Car Wash —
|
||||
// the pilot module" + "v1 answers"). Master data is mutable rows; every order freezes
|
||||
// what it sold (names + price) and signs its life onto the ledger; money at the bay is
|
||||
// a signed `carwash_payment`; money at the booth rides the parking `payment` as a
|
||||
// charge line (ChargeProvider below). The parking sponsorship is the site's "carwash"
|
||||
// VALIDATION program, applied through the shared applyValidation() when a wash is done
|
||||
// — the wash never touches parking code, it talks to the core through ServerModuleDeps.
|
||||
|
||||
/** A refusal the route maps to an HTTP status. */
|
||||
/** The till bay money lands on — declared by the module manifest (MODULES). */
|
||||
const CARWASH_TILL: TillId = "carwash";
|
||||
|
||||
export class CarwashError extends Error {
|
||||
constructor(
|
||||
readonly status: 400 | 404 | 409,
|
||||
message: string,
|
||||
readonly code?: string,
|
||||
) {
|
||||
super(message);
|
||||
this.name = "CarwashError";
|
||||
}
|
||||
}
|
||||
|
||||
export interface SettingsBody {
|
||||
categories?: { id?: string; name?: string; active?: boolean; visionClasses?: unknown }[];
|
||||
services?: { id?: string; name?: string; active?: boolean }[];
|
||||
prices?: { categoryId?: string; serviceId?: string; priceMinor?: number }[];
|
||||
/** Where wash money is taken at this site (site-level policy). */
|
||||
payAt?: unknown;
|
||||
visionThreshold?: unknown;
|
||||
}
|
||||
|
||||
export interface CreateOrderInput {
|
||||
identity: string;
|
||||
categoryId: string;
|
||||
serviceId: string;
|
||||
/** Optional — the SITE policy decides; a stale client that sends a different value
|
||||
* is refused (409 pay_at_policy) rather than silently overridden. */
|
||||
payAt?: CarWashPayAt;
|
||||
actor: string;
|
||||
}
|
||||
|
||||
export interface TicketLookup {
|
||||
identity: string;
|
||||
found: boolean;
|
||||
open: boolean;
|
||||
subscription: boolean;
|
||||
plate: string | null;
|
||||
enteredAt: string | null;
|
||||
currency: string | null;
|
||||
orders: CarwashOrderView[];
|
||||
/** What the camera saw at entry (advisory) and the category the site mapping
|
||||
* suggests for it — the desk pre-selects it; the operator may change it. */
|
||||
vision: VehicleRead | null;
|
||||
suggestedCategoryId: string | null;
|
||||
}
|
||||
|
||||
const ID_RE = /^[a-z0-9][a-z0-9-]{0,63}$/;
|
||||
|
||||
/** Stable slug for a new master-data row: from the name, else a random id. */
|
||||
function slugify(name: string): string {
|
||||
const s = name
|
||||
.toLowerCase()
|
||||
.normalize("NFD")
|
||||
.replace(/[\u0300-\u036f]/g, "")
|
||||
.replace(/[^a-z0-9]+/g, "-")
|
||||
.replace(/^-+|-+$/g, "")
|
||||
.slice(0, 40);
|
||||
return s || randomUUID();
|
||||
}
|
||||
|
||||
export class CarwashService {
|
||||
readonly #db: Db;
|
||||
readonly #log: EventLog;
|
||||
readonly #pay: PayStation;
|
||||
readonly #shift: ShiftService;
|
||||
readonly #logger: FastifyBaseLogger;
|
||||
readonly #outbox: ReviewOutbox | null;
|
||||
|
||||
constructor(deps: ServerModuleDeps, logger: FastifyBaseLogger, outbox: ReviewOutbox | null = null) {
|
||||
this.#db = deps.db;
|
||||
this.#log = deps.eventLog;
|
||||
this.#pay = deps.payStation;
|
||||
this.#shift = deps.shiftService;
|
||||
this.#logger = logger;
|
||||
this.#outbox = outbox;
|
||||
}
|
||||
|
||||
#enabled(): boolean {
|
||||
return effectiveModulesFor(this.#db).includes("carwash");
|
||||
}
|
||||
|
||||
// --- Settings (master data) -------------------------------------------------
|
||||
|
||||
settings(): CarwashSettingsView {
|
||||
const categories = this.#db
|
||||
.select()
|
||||
.from(carwashCategories)
|
||||
.where(isNull(carwashCategories.deletedAt))
|
||||
.orderBy(asc(carwashCategories.sortOrder), asc(carwashCategories.name))
|
||||
.all()
|
||||
.map((r) => ({ id: r.id, name: r.name, sortOrder: r.sortOrder, active: r.active, visionClasses: r.visionClasses.filter(isVehicleClass) }));
|
||||
const services = this.#db
|
||||
.select()
|
||||
.from(carwashServices)
|
||||
.where(isNull(carwashServices.deletedAt))
|
||||
.orderBy(asc(carwashServices.sortOrder), asc(carwashServices.name))
|
||||
.all()
|
||||
.map((r) => ({ id: r.id, name: r.name, sortOrder: r.sortOrder, active: r.active }));
|
||||
const live = new Set([...categories.map((c) => c.id), ...services.map((s) => s.id)]);
|
||||
const prices = this.#db
|
||||
.select()
|
||||
.from(carwashPrices)
|
||||
.all()
|
||||
.filter((p) => live.has(p.categoryId) && live.has(p.serviceId))
|
||||
.map((p) => ({ categoryId: p.categoryId, serviceId: p.serviceId, priceMinor: p.priceMinor }));
|
||||
return { categories, services, prices, currency: this.#currency(), payAt: this.payAt(), visionThreshold: this.visionThreshold() };
|
||||
}
|
||||
|
||||
/** The site's wash-payment policy (Setup → Car wash). Missing row = the default. */
|
||||
payAt(): CarWashPayAt {
|
||||
const row = this.#db.select().from(carwashConfig).where(eq(carwashConfig.id, 1)).get();
|
||||
return row?.payAt ?? CARWASH_PAY_AT_DEFAULT;
|
||||
}
|
||||
|
||||
/** Confidence floor for a vision class to flag a category downgrade (site config). */
|
||||
visionThreshold(): number {
|
||||
const row = this.#db.select().from(carwashConfig).where(eq(carwashConfig.id, 1)).get();
|
||||
return row?.visionThreshold ?? CARWASH_VISION_THRESHOLD_DEFAULT;
|
||||
}
|
||||
|
||||
/** The category the site mapping suggests for a vision class (first active category
|
||||
* listing it, in display order), or null when unmapped. */
|
||||
#categoryForClass(cls: VehicleClass): { id: string; name: string } | null {
|
||||
const rows = this.#db
|
||||
.select()
|
||||
.from(carwashCategories)
|
||||
.where(isNull(carwashCategories.deletedAt))
|
||||
.orderBy(asc(carwashCategories.sortOrder), asc(carwashCategories.name))
|
||||
.all();
|
||||
const hit = rows.find((r) => r.active && r.visionClasses.includes(cls));
|
||||
return hit ? { id: hit.id, name: hit.name } : null;
|
||||
}
|
||||
|
||||
/** The site's currency = the active tariff's (the wash is priced in the same money
|
||||
* the booth takes). null when no tariff is published yet. */
|
||||
#currency(): string | null {
|
||||
try {
|
||||
// Any open session's quote carries it; without one, fall back to the tariff table.
|
||||
const row = this.#db.select().from(carwashOrders).orderBy(desc(carwashOrders.createdAt)).limit(1).get();
|
||||
if (row) return row.currency;
|
||||
} catch {
|
||||
/* fall through */
|
||||
}
|
||||
return this.#pay.activeCurrency();
|
||||
}
|
||||
|
||||
/** Full-replacement save of the three lists. Rows missing from the body are
|
||||
* soft-deleted (orders already reference names + prices by value, so nothing
|
||||
* historical changes). Signs one config_change. */
|
||||
async saveSettings(body: SettingsBody, actor: string): Promise<CarwashSettingsView> {
|
||||
const now = new Date().toISOString();
|
||||
const upsertList = (
|
||||
table: typeof carwashCategories | typeof carwashServices,
|
||||
items: { id?: string; name?: string; active?: boolean; visionClasses?: unknown }[] | undefined,
|
||||
label: string,
|
||||
): string[] => {
|
||||
if (items === undefined) {
|
||||
return this.#db.select({ id: table.id }).from(table).where(isNull(table.deletedAt)).all().map((r) => r.id);
|
||||
}
|
||||
if (!Array.isArray(items)) throw new CarwashError(400, `${label} must be an array`);
|
||||
const keep: string[] = [];
|
||||
let sort = 0;
|
||||
const seen = new Set<string>();
|
||||
for (const it of items) {
|
||||
const name = String(it?.name ?? "").trim();
|
||||
if (!name) throw new CarwashError(400, `${label}: every item needs a name`);
|
||||
let id = typeof it.id === "string" && it.id.trim() ? it.id.trim() : slugify(name);
|
||||
if (!ID_RE.test(id)) throw new CarwashError(400, `${label}: bad id "${id}"`);
|
||||
// Two new items slugging to the same id → disambiguate rather than merge.
|
||||
while (seen.has(id)) id = `${id}-${sort}`;
|
||||
seen.add(id);
|
||||
const active = it.active !== false;
|
||||
// Vision mapping lives on CATEGORIES only; absent = keep what the row has.
|
||||
let visionClasses: string[] | undefined;
|
||||
if (table === carwashCategories && it.visionClasses !== undefined) {
|
||||
if (!Array.isArray(it.visionClasses) || !it.visionClasses.every(isVehicleClass)) {
|
||||
throw new CarwashError(400, `${label}: visionClasses must be an array of vehicle classes`);
|
||||
}
|
||||
visionClasses = [...new Set(it.visionClasses as string[])];
|
||||
}
|
||||
const existing = this.#db.select().from(table).where(eq(table.id, id)).get();
|
||||
if (existing) {
|
||||
this.#db.update(table).set({ name, sortOrder: sort, active, deletedAt: null, deletedBy: null, ...(visionClasses ? { visionClasses } : {}) }).where(eq(table.id, id)).run();
|
||||
} else {
|
||||
this.#db.insert(table).values({ id, name, sortOrder: sort, active, ...(visionClasses ? { visionClasses } : {}) }).run();
|
||||
}
|
||||
keep.push(id);
|
||||
sort += 1;
|
||||
}
|
||||
const live = this.#db.select({ id: table.id }).from(table).where(isNull(table.deletedAt)).all();
|
||||
for (const r of live) {
|
||||
if (!keep.includes(r.id)) {
|
||||
this.#db.update(table).set({ deletedAt: now, deletedBy: actor }).where(eq(table.id, r.id)).run();
|
||||
}
|
||||
}
|
||||
return keep;
|
||||
};
|
||||
|
||||
const categoryIds = upsertList(carwashCategories, body.categories, "categories");
|
||||
const serviceIds = upsertList(carwashServices, body.services, "services");
|
||||
|
||||
if (body.prices !== undefined) {
|
||||
if (!Array.isArray(body.prices)) throw new CarwashError(400, "prices must be an array");
|
||||
const rows: { categoryId: string; serviceId: string; priceMinor: number }[] = [];
|
||||
for (const p of body.prices) {
|
||||
const categoryId = String(p?.categoryId ?? "");
|
||||
const serviceId = String(p?.serviceId ?? "");
|
||||
const priceMinor = p?.priceMinor;
|
||||
if (!categoryIds.includes(categoryId)) throw new CarwashError(400, `prices: unknown category "${categoryId}"`);
|
||||
if (!serviceIds.includes(serviceId)) throw new CarwashError(400, `prices: unknown service "${serviceId}"`);
|
||||
if (!Number.isInteger(priceMinor) || (priceMinor as number) < 0) {
|
||||
throw new CarwashError(400, "prices: priceMinor must be a non-negative integer");
|
||||
}
|
||||
rows.push({ categoryId, serviceId, priceMinor: priceMinor as number });
|
||||
}
|
||||
this.#db.delete(carwashPrices).run();
|
||||
for (const r of rows) this.#db.insert(carwashPrices).values(r).run();
|
||||
}
|
||||
|
||||
await this.#log.append({
|
||||
type: "config_change",
|
||||
source: "manual",
|
||||
identity: "module:carwash",
|
||||
payload: {
|
||||
setting: "carwash.settings",
|
||||
value: { categories: categoryIds.length, services: serviceIds.length, prices: body.prices?.length ?? null },
|
||||
operator: actor,
|
||||
},
|
||||
});
|
||||
|
||||
// Where the money is taken — a site policy, signed on its own when it flips (it
|
||||
// decides which till the cash lands on and whether the booth barrier or the exit
|
||||
// reader releases the car; fraud-relevant, so it is attributed like other config).
|
||||
if (body.payAt !== undefined) {
|
||||
if (!isPayAt(body.payAt)) throw new CarwashError(400, "payAt must be booth|bay");
|
||||
const prev = this.payAt();
|
||||
if (body.payAt !== prev) {
|
||||
this.#db
|
||||
.insert(carwashConfig)
|
||||
.values({ id: 1, payAt: body.payAt, updatedAt: now, updatedBy: actor })
|
||||
.onConflictDoUpdate({ target: carwashConfig.id, set: { payAt: body.payAt, updatedAt: now, updatedBy: actor } })
|
||||
.run();
|
||||
await this.#log.append({
|
||||
type: "config_change",
|
||||
source: "manual",
|
||||
identity: "module:carwash",
|
||||
payload: { setting: "carwash.payAt", value: body.payAt, prev, operator: actor },
|
||||
});
|
||||
}
|
||||
}
|
||||
if (body.visionThreshold !== undefined) {
|
||||
const v = Number(body.visionThreshold);
|
||||
if (!Number.isFinite(v) || v < 0 || v > 1) throw new CarwashError(400, "visionThreshold must be between 0 and 1");
|
||||
const prev = this.visionThreshold();
|
||||
if (v !== prev) {
|
||||
this.#db
|
||||
.insert(carwashConfig)
|
||||
.values({ id: 1, visionThreshold: v, updatedAt: now, updatedBy: actor })
|
||||
.onConflictDoUpdate({ target: carwashConfig.id, set: { visionThreshold: v, updatedAt: now, updatedBy: actor } })
|
||||
.run();
|
||||
await this.#log.append({
|
||||
type: "config_change",
|
||||
source: "manual",
|
||||
identity: "module:carwash",
|
||||
payload: { setting: "carwash.visionThreshold", value: v, prev, operator: actor },
|
||||
});
|
||||
}
|
||||
}
|
||||
|
||||
return this.settings();
|
||||
}
|
||||
|
||||
// --- Orders ---------------------------------------------------------------------
|
||||
|
||||
#view(r: CarwashOrderRow): CarwashOrderView {
|
||||
return {
|
||||
id: r.id,
|
||||
identity: r.identity,
|
||||
plate: r.plate,
|
||||
categoryId: r.categoryId,
|
||||
categoryName: r.categoryName,
|
||||
serviceId: r.serviceId,
|
||||
serviceName: r.serviceName,
|
||||
priceMinor: r.priceMinor,
|
||||
currency: r.currency,
|
||||
payAt: r.payAt,
|
||||
status: r.status,
|
||||
createdAt: r.createdAt,
|
||||
createdBy: r.createdBy,
|
||||
doneAt: r.doneAt,
|
||||
doneBy: r.doneBy,
|
||||
paidAt: r.paidAt,
|
||||
paidBy: r.paidBy,
|
||||
tender: (r.tender as Tender | null) ?? null,
|
||||
closed: r.status === "void" || (r.status === "done" && r.paidAt != null),
|
||||
validationEventId: r.validationEventId,
|
||||
voidBy: r.voidBy,
|
||||
voidReason: r.voidReason,
|
||||
visionClass: isVehicleClass(r.visionClass) ? r.visionClass : null,
|
||||
visionConfidence: r.visionConfidence,
|
||||
visionCategoryId: r.visionCategoryId,
|
||||
downgradeEventId: r.downgradeEventId,
|
||||
};
|
||||
}
|
||||
|
||||
#row(id: string): CarwashOrderRow {
|
||||
const r = this.#db.select().from(carwashOrders).where(eq(carwashOrders.id, id)).get();
|
||||
if (!r) throw new CarwashError(404, "order not found");
|
||||
return r;
|
||||
}
|
||||
|
||||
/** The desk's queue: every order still needing something, oldest first. */
|
||||
openOrders(): CarwashOrderView[] {
|
||||
return this.#db
|
||||
.select()
|
||||
.from(carwashOrders)
|
||||
.where(inArray(carwashOrders.status, ["open", "done"]))
|
||||
.orderBy(asc(carwashOrders.createdAt))
|
||||
.all()
|
||||
.map((r) => this.#view(r))
|
||||
.filter((o) => !o.closed);
|
||||
}
|
||||
|
||||
/** Recent history (closed included), newest first. */
|
||||
recentOrders(limit = 100): CarwashOrderView[] {
|
||||
return this.#db
|
||||
.select()
|
||||
.from(carwashOrders)
|
||||
.orderBy(desc(carwashOrders.createdAt))
|
||||
.limit(Math.min(Math.max(limit, 1), 500))
|
||||
.all()
|
||||
.map((r) => this.#view(r));
|
||||
}
|
||||
|
||||
#ordersFor(identity: string): CarwashOrderView[] {
|
||||
return this.#db
|
||||
.select()
|
||||
.from(carwashOrders)
|
||||
.where(eq(carwashOrders.identity, identity))
|
||||
.orderBy(asc(carwashOrders.createdAt))
|
||||
.all()
|
||||
.map((r) => this.#view(r));
|
||||
}
|
||||
|
||||
/** Ticket → session facts the desk needs (the parking ticket IS the customer). */
|
||||
lookup(identity: string): TicketLookup {
|
||||
const id = identity.trim();
|
||||
const s = this.#pay.lookup(id);
|
||||
const vision = s.found ? vehicleForIdentity(this.#db, id) : null;
|
||||
return {
|
||||
identity: id,
|
||||
found: s.found,
|
||||
open: s.open,
|
||||
subscription: s.subscription,
|
||||
plate: s.plate,
|
||||
enteredAt: s.enteredAt,
|
||||
currency: s.currency,
|
||||
orders: this.#ordersFor(id),
|
||||
vision,
|
||||
suggestedCategoryId: vision ? (this.#categoryForClass(vision.bodyType)?.id ?? null) : null,
|
||||
};
|
||||
}
|
||||
|
||||
async createOrder(input: CreateOrderInput): Promise<CarwashOrderView> {
|
||||
const identity = input.identity.trim();
|
||||
if (!identity) throw new CarwashError(400, "identity (ticket) required");
|
||||
|
||||
const s = this.#pay.lookup(identity);
|
||||
if (!s.found) throw new CarwashError(404, "no session for ticket");
|
||||
if (!s.open) throw new CarwashError(409, "session is closed");
|
||||
if (s.subscription) throw new CarwashError(409, "subscription sessions: order the wash with payAt=bay", "subscription");
|
||||
|
||||
const category = this.#db
|
||||
.select()
|
||||
.from(carwashCategories)
|
||||
.where(and(eq(carwashCategories.id, input.categoryId), isNull(carwashCategories.deletedAt)))
|
||||
.get();
|
||||
if (!category || !category.active) throw new CarwashError(404, "category not found or inactive");
|
||||
const service = this.#db
|
||||
.select()
|
||||
.from(carwashServices)
|
||||
.where(and(eq(carwashServices.id, input.serviceId), isNull(carwashServices.deletedAt)))
|
||||
.get();
|
||||
if (!service || !service.active) throw new CarwashError(404, "service not found or inactive");
|
||||
const price = this.#db
|
||||
.select()
|
||||
.from(carwashPrices)
|
||||
.where(and(eq(carwashPrices.categoryId, category.id), eq(carwashPrices.serviceId, service.id)))
|
||||
.get();
|
||||
if (!price) throw new CarwashError(409, `no price for ${category.name} · ${service.name}`, "no_price");
|
||||
// The SITE decides where wash money is taken (Setup → Car wash); the order freezes
|
||||
// the policy in force. A client that still sends a different value is stale.
|
||||
const payAt = this.payAt();
|
||||
if (input.payAt !== undefined && input.payAt !== payAt) {
|
||||
throw new CarwashError(409, `this site takes wash money at the ${payAt === "bay" ? "bay" : "booth"}`, "pay_at_policy");
|
||||
}
|
||||
const currency = s.currency ?? this.#pay.activeCurrency();
|
||||
if (!currency) throw new CarwashError(409, "no active tariff (currency unknown)", "no_tariff");
|
||||
|
||||
// Vision, advisory: what the camera saw at entry and the category the site maps it
|
||||
// to. A DOWNGRADE — the operator chose a category that prices LOWER than the mapped
|
||||
// one for this service, with the read above the site threshold — is signed as an
|
||||
// anomaly for the reviewer (both categories, operator, snapshot). Recorded only:
|
||||
// never blocks, no reason prompt (user, 2026-09-06).
|
||||
const vision = vehicleForIdentity(this.#db, identity);
|
||||
const visionCategory = vision ? this.#categoryForClass(vision.bodyType) : null;
|
||||
let downgradeEventId: string | null = null;
|
||||
if (vision && visionCategory && visionCategory.id !== category.id && vision.confidence >= this.visionThreshold()) {
|
||||
const visionPrice = this.#db
|
||||
.select()
|
||||
.from(carwashPrices)
|
||||
.where(and(eq(carwashPrices.categoryId, visionCategory.id), eq(carwashPrices.serviceId, service.id)))
|
||||
.get();
|
||||
if (visionPrice && visionPrice.priceMinor > price.priceMinor) {
|
||||
const ev = await this.#log.append({
|
||||
type: "anomaly",
|
||||
source: "manual",
|
||||
identity,
|
||||
payload: {
|
||||
...reasonPayload("carwash.categoryDowngrade", {
|
||||
visionClass: vision.bodyType,
|
||||
visionCategory: visionCategory.name,
|
||||
operator: input.actor,
|
||||
chosenCategory: category.name,
|
||||
}),
|
||||
sessionRef: identity,
|
||||
visionClass: vision.bodyType,
|
||||
visionConfidence: vision.confidence,
|
||||
visionCategoryId: visionCategory.id,
|
||||
visionCategoryName: visionCategory.name,
|
||||
chosenCategoryId: category.id,
|
||||
chosenCategoryName: category.name,
|
||||
serviceName: service.name,
|
||||
visionPriceMinor: visionPrice.priceMinor,
|
||||
chosenPriceMinor: price.priceMinor,
|
||||
currency,
|
||||
snapshotId: vision.snapshotId,
|
||||
operator: input.actor,
|
||||
},
|
||||
});
|
||||
downgradeEventId = ev.id;
|
||||
}
|
||||
}
|
||||
|
||||
const now = new Date().toISOString();
|
||||
const row: CarwashOrderRow = {
|
||||
id: randomUUID(),
|
||||
identity,
|
||||
plate: s.plate,
|
||||
categoryId: category.id,
|
||||
categoryName: category.name,
|
||||
serviceId: service.id,
|
||||
serviceName: service.name,
|
||||
priceMinor: price.priceMinor,
|
||||
currency,
|
||||
payAt,
|
||||
status: "open",
|
||||
createdAt: now,
|
||||
createdBy: input.actor,
|
||||
doneAt: null,
|
||||
doneBy: null,
|
||||
paidAt: null,
|
||||
paidBy: null,
|
||||
tender: null,
|
||||
paymentEventId: null,
|
||||
validationEventId: null,
|
||||
voidAt: null,
|
||||
voidBy: null,
|
||||
voidReason: null,
|
||||
visionClass: vision?.bodyType ?? null,
|
||||
visionConfidence: vision?.confidence ?? null,
|
||||
visionCategoryId: visionCategory?.id ?? null,
|
||||
downgradeEventId,
|
||||
};
|
||||
this.#db.insert(carwashOrders).values(row).run();
|
||||
// Hand the decision to the remote reviewer (crop + choice), off the intake path.
|
||||
if (vision && this.#outbox?.enabled) {
|
||||
void this.#outbox.enqueue(
|
||||
{
|
||||
orderId: row.id,
|
||||
createdAt: now,
|
||||
createdBy: input.actor,
|
||||
categoryId: category.id,
|
||||
categoryName: category.name,
|
||||
categoryClasses: category.visionClasses,
|
||||
serviceName: service.name,
|
||||
visionCategoryId: visionCategory?.id ?? null,
|
||||
downgraded: downgradeEventId != null,
|
||||
},
|
||||
vision,
|
||||
);
|
||||
}
|
||||
await this.#log.append({
|
||||
type: "carwash_order",
|
||||
source: "manual",
|
||||
identity,
|
||||
payload: {
|
||||
sessionRef: identity,
|
||||
orderId: row.id,
|
||||
action: "created",
|
||||
categoryName: row.categoryName,
|
||||
serviceName: row.serviceName,
|
||||
priceMinor: row.priceMinor,
|
||||
currency,
|
||||
payAt: row.payAt,
|
||||
operator: input.actor,
|
||||
},
|
||||
});
|
||||
return this.#view(row);
|
||||
}
|
||||
|
||||
/** The wash is finished: apply the site's sponsorship program to the parking session
|
||||
* (if one is configured and active), then — for a bay order already paid — settle
|
||||
* the parking session so the exit reader opens. */
|
||||
async markDone(id: string, actor: string): Promise<CarwashOrderView> {
|
||||
const r = this.#row(id);
|
||||
if (r.status === "void") throw new CarwashError(409, "order is void");
|
||||
if (r.status === "done") throw new CarwashError(409, "order is already done");
|
||||
const now = new Date().toISOString();
|
||||
|
||||
let validationEventId: string | null = null;
|
||||
// Wash context for the wash-only discount modes: the WASH WINDOW in minutes — from
|
||||
// the order's intake to now (= done) — and the order's frozen price. NOT the time
|
||||
// since entry: a car parked for hours before it asks for a wash still pays for those
|
||||
// hours (found 2026-09-05 on a long-open ticket that would have been fully comped).
|
||||
// The credit lands at the start of the billed period (that is how timeCredit
|
||||
// folds), so for a flat tariff the money is identical; a stepped/daily-cap tariff
|
||||
// may differ by an increment. See applyValidation().
|
||||
const washMinutes = Math.max(0, Math.ceil((Date.now() - Date.parse(r.createdAt)) / 60_000));
|
||||
const applied = await applyValidation(this.#db, this.#log, {
|
||||
programId: CARWASH_PROGRAM_ID,
|
||||
identity: r.identity,
|
||||
actor,
|
||||
wash: { washMinutes, priceMinor: r.priceMinor },
|
||||
});
|
||||
if (applied.ok) validationEventId = applied.eventId;
|
||||
else if (applied.status !== 404 && !/already applied/.test(applied.error)) {
|
||||
// A real refusal (session closed, daily cap …) — the wash is still done; the
|
||||
// customer simply gets no sponsorship. Keep it visible in the log.
|
||||
this.#logger.warn(`carwash sponsorship not applied for ${r.identity}: ${applied.error}`);
|
||||
}
|
||||
|
||||
this.#db
|
||||
.update(carwashOrders)
|
||||
.set({ status: "done", doneAt: now, doneBy: actor, validationEventId })
|
||||
.where(eq(carwashOrders.id, id))
|
||||
.run();
|
||||
await this.#log.append({
|
||||
type: "carwash_order",
|
||||
source: "manual",
|
||||
identity: r.identity,
|
||||
payload: {
|
||||
sessionRef: r.identity,
|
||||
orderId: id,
|
||||
action: "done",
|
||||
categoryName: r.categoryName,
|
||||
serviceName: r.serviceName,
|
||||
priceMinor: r.priceMinor,
|
||||
currency: r.currency,
|
||||
payAt: r.payAt,
|
||||
...(validationEventId ? { validationEventId } : {}),
|
||||
operator: actor,
|
||||
},
|
||||
});
|
||||
const updated = this.#row(id);
|
||||
if (updated.payAt === "bay" && updated.paidAt != null) await this.#settleParkingIfFree(updated, actor);
|
||||
return this.#view(updated);
|
||||
}
|
||||
|
||||
/** Money taken AT THE BAY. Needs an open CARWASH shift (it is the wash operator's
|
||||
* drawer money, never the booth's — wiki/concepts/shift.md "Tills"); signs a
|
||||
* carwash_payment on that till; then, if the wash is also done, settles the
|
||||
* parking session. */
|
||||
async payAtBay(id: string, tender: Tender, actor: string): Promise<CarwashOrderView> {
|
||||
const r = this.#row(id);
|
||||
if (r.status === "void") throw new CarwashError(409, "order is void");
|
||||
if (r.payAt !== "bay") throw new CarwashError(409, "this order is paid at the booth", "pay_at_booth");
|
||||
if (r.paidAt != null) throw new CarwashError(409, "order is already paid");
|
||||
if (tender !== "cash" && tender !== "card") throw new CarwashError(400, "tender must be cash|card");
|
||||
this.#shift.requireOpenShift(CARWASH_TILL);
|
||||
|
||||
const ev = await this.#log.append({
|
||||
type: "carwash_payment",
|
||||
source: "manual",
|
||||
identity: r.identity,
|
||||
payload: {
|
||||
sessionRef: r.identity,
|
||||
orderId: id,
|
||||
amountMinor: r.priceMinor,
|
||||
currency: r.currency,
|
||||
tender,
|
||||
till: CARWASH_TILL,
|
||||
categoryName: r.categoryName,
|
||||
serviceName: r.serviceName,
|
||||
operator: actor,
|
||||
},
|
||||
});
|
||||
const now = new Date().toISOString();
|
||||
this.#db
|
||||
.update(carwashOrders)
|
||||
.set({ paidAt: now, paidBy: actor, tender, paymentEventId: ev.id })
|
||||
.where(eq(carwashOrders.id, id))
|
||||
.run();
|
||||
const updated = this.#row(id);
|
||||
if (updated.status === "done") await this.#settleParkingIfFree(updated, actor, tender);
|
||||
return this.#view(updated);
|
||||
}
|
||||
|
||||
/** A bay-paid, done wash: if the sponsorship made the parking session zero-due, sign
|
||||
* the $0 parking payment now — that is what the exit READER checks (a validation
|
||||
* alone opens nothing; see exit-flow.ts). A remaining balance stays for the booth. */
|
||||
async #settleParkingIfFree(r: CarwashOrderRow, actor: string, tender: Tender = "cash"): Promise<void> {
|
||||
try {
|
||||
const s = this.#pay.lookup(r.identity);
|
||||
if (!s.open || s.subscription || s.paidAt != null) return;
|
||||
const q = this.#pay.quote(r.identity);
|
||||
if (q.amountMinor !== 0) return;
|
||||
await this.#pay.pay(r.identity, tender);
|
||||
this.#logger.info(`carwash: parking session ${r.identity} settled at zero after bay payment (by ${actor})`);
|
||||
} catch (err) {
|
||||
this.#logger.warn(`carwash: could not settle parking for ${r.identity}: ${(err as Error).message}`);
|
||||
}
|
||||
}
|
||||
|
||||
async voidOrder(id: string, reason: string, actor: string): Promise<CarwashOrderView> {
|
||||
const r = this.#row(id);
|
||||
if (r.status === "void") throw new CarwashError(409, "order is already void");
|
||||
if (r.paidAt != null) throw new CarwashError(409, "a paid order cannot be voided", "paid");
|
||||
const now = new Date().toISOString();
|
||||
// Take back the sponsorship if it is still live (not consumed by a payment).
|
||||
if (r.validationEventId) {
|
||||
const live = liveValidations(this.#db, r.identity).find((v) => v.eventId === r.validationEventId);
|
||||
if (live) {
|
||||
await this.#log.append({
|
||||
type: "validation",
|
||||
source: "manual",
|
||||
identity: r.identity,
|
||||
payload: {
|
||||
sessionRef: r.identity,
|
||||
refId: r.validationEventId,
|
||||
programId: live.programId,
|
||||
programLabel: live.label,
|
||||
operator: actor,
|
||||
},
|
||||
});
|
||||
}
|
||||
}
|
||||
this.#db
|
||||
.update(carwashOrders)
|
||||
.set({ status: "void", voidAt: now, voidBy: actor, voidReason: reason || null })
|
||||
.where(eq(carwashOrders.id, id))
|
||||
.run();
|
||||
await this.#log.append({
|
||||
type: "carwash_order",
|
||||
source: "manual",
|
||||
identity: r.identity,
|
||||
payload: {
|
||||
sessionRef: r.identity,
|
||||
orderId: id,
|
||||
action: "void",
|
||||
categoryName: r.categoryName,
|
||||
serviceName: r.serviceName,
|
||||
priceMinor: r.priceMinor,
|
||||
currency: r.currency,
|
||||
payAt: r.payAt,
|
||||
reason: reason || undefined,
|
||||
operator: actor,
|
||||
},
|
||||
});
|
||||
return this.#view(this.#row(id));
|
||||
}
|
||||
|
||||
// --- Booth settlement hook ------------------------------------------------------
|
||||
|
||||
/** Orders with payAt = "booth" ride the parking payment as charge lines; the core
|
||||
* calls back after the payment is signed so they are marked paid. Off = no lines. */
|
||||
chargeProvider(): ChargeProvider {
|
||||
return {
|
||||
lines: (identity) => {
|
||||
if (!this.#enabled()) return [];
|
||||
return this.#db
|
||||
.select()
|
||||
.from(carwashOrders)
|
||||
.where(and(eq(carwashOrders.identity, identity), eq(carwashOrders.payAt, "booth"), isNull(carwashOrders.paidAt)))
|
||||
.all()
|
||||
.filter((r) => r.status !== "void")
|
||||
.map((r) => ({
|
||||
module: "carwash" as const,
|
||||
ref: r.id,
|
||||
label: `Lavazh — ${r.categoryName} · ${r.serviceName}`,
|
||||
amountMinor: r.priceMinor,
|
||||
}));
|
||||
},
|
||||
onPaid: async (_identity, lines, payment) => {
|
||||
const now = new Date().toISOString();
|
||||
for (const l of lines) {
|
||||
if (l.module !== "carwash") continue;
|
||||
this.#db
|
||||
.update(carwashOrders)
|
||||
.set({ paidAt: now, paidBy: payment.operator ?? "booth", tender: payment.tender, paymentEventId: payment.eventId })
|
||||
.where(and(eq(carwashOrders.id, l.ref), isNull(carwashOrders.paidAt)))
|
||||
.run();
|
||||
}
|
||||
},
|
||||
};
|
||||
}
|
||||
}
|
||||
|
||||
/** Type guard for the void body etc. */
|
||||
export function isPayAt(v: unknown): v is CarWashPayAt {
|
||||
return typeof v === "string" && (CARWASH_PAY_AT as readonly string[]).includes(v);
|
||||
}
|
||||
@@ -0,0 +1,61 @@
|
||||
import type { FastifyInstance } from "fastify";
|
||||
import type { Db } from "@parking/db";
|
||||
import { MODULES, parseEntitledModules, type ModuleId } from "@parking/shared";
|
||||
import type { EventLog } from "../event-log.js";
|
||||
import type { PayStation } from "../pay-station.js";
|
||||
import type { ShiftService } from "../shift-service.js";
|
||||
import { effectiveModulesFor } from "../modules.js";
|
||||
import { carwashModule } from "./carwash/index.js";
|
||||
import { validationModule } from "./validation/index.js";
|
||||
|
||||
// The server-side module registry. A module's routes live in its own folder
|
||||
// (apps/server/src/modules/<id>/index.ts) and are registered by iterating
|
||||
// @parking/shared's MODULES — so adding a module is one manifest entry + one folder +
|
||||
// one line in SERVER_MODULES below, with nothing else in the core touched
|
||||
// (wiki/decisions/venue-modules.md, "A module = a manifest + three folders").
|
||||
//
|
||||
// `parking` is registered in the manifest but has NO folder yet: its routes are still
|
||||
// the flat list in server.ts. That is deliberate — the seam is drawn, the code moves
|
||||
// across it subsystem by subsystem as each is touched, not in one big move.
|
||||
|
||||
/** What the core hands a module at registration. Modules reach the core ONLY through
|
||||
* these (never by importing another module): the DB, the signed ledger, the booth
|
||||
* settlement (to fold charges in / settle a session — PayStation.registerChargeProvider,
|
||||
* quote, pay) and the shift service (money needs an open shift). */
|
||||
export interface ServerModuleDeps {
|
||||
db: Db;
|
||||
eventLog: EventLog;
|
||||
payStation: PayStation;
|
||||
shiftService: ShiftService;
|
||||
}
|
||||
|
||||
export interface ServerModule {
|
||||
id: ModuleId;
|
||||
register(app: FastifyInstance, deps: ServerModuleDeps): Promise<void>;
|
||||
}
|
||||
|
||||
const SERVER_MODULES: Partial<Record<ModuleId, ServerModule>> = {
|
||||
validation: validationModule,
|
||||
carwash: carwashModule,
|
||||
};
|
||||
|
||||
/** Register every folder-based module in registry order, then log what this site
|
||||
* is entitled to / has effective, so a "why is X missing" question is answerable
|
||||
* from the container log alone. */
|
||||
export async function registerModules(app: FastifyInstance, deps: ServerModuleDeps): Promise<void> {
|
||||
for (const manifest of MODULES) {
|
||||
const impl = SERVER_MODULES[manifest.id];
|
||||
if (impl) {
|
||||
if (impl.id !== manifest.id) throw new Error(`module registry mismatch: ${impl.id} registered under ${manifest.id}`);
|
||||
await impl.register(app, deps);
|
||||
}
|
||||
}
|
||||
const { entitled, unknown } = parseEntitledModules(process.env.MODULES_ENTITLED);
|
||||
if (unknown.length > 0) {
|
||||
app.log.warn({ unknown }, "MODULES_ENTITLED names unknown module ids — ignored");
|
||||
}
|
||||
app.log.info(
|
||||
{ entitled, effective: effectiveModulesFor(deps.db) },
|
||||
"venue modules (entitled = MODULES_ENTITLED env; effective = entitled ∩ site activation)",
|
||||
);
|
||||
}
|
||||
@@ -0,0 +1,13 @@
|
||||
import { validationRoutes } from "../../routes/validations.js";
|
||||
import type { ServerModule } from "../index.js";
|
||||
|
||||
// Merchant-scan ticket validation as a venue module. Kept for the Bar until a Bar
|
||||
// module absorbs it (wiki/decisions/venue-modules.md, decision 1). The routes
|
||||
// themselves still live in routes/validations.ts (unchanged location, now guarded by
|
||||
// requireModule("validation")); this folder is the registry hook.
|
||||
export const validationModule: ServerModule = {
|
||||
id: "validation",
|
||||
async register(app, { db, eventLog }) {
|
||||
await validationRoutes(app, db, eventLog);
|
||||
},
|
||||
};
|
||||
@@ -0,0 +1,147 @@
|
||||
import { afterEach, beforeEach, describe, expect, it } from "vitest";
|
||||
import { createTestDb } from "@parking/db/testing";
|
||||
import { ledgerEvents, siteConfig, subscriptions, type Db } from "@parking/db";
|
||||
import { getOccupancy, occupancyCount, reservedSubscriberSpots } from "./occupancy.js";
|
||||
|
||||
// Occupancy is a FOLD over the signed ledger, never a stored counter. These tests
|
||||
// pin: the entries-minus-exits count, the capacity/full gate, and the reserved-
|
||||
// subscriber-spots model (its trickiest invariant — never double-count a parked
|
||||
// subscriber, and never gate the subscriber's own entry).
|
||||
|
||||
let db: Db;
|
||||
let close: () => void;
|
||||
|
||||
beforeEach(() => {
|
||||
const t = createTestDb();
|
||||
db = t.db;
|
||||
close = t.close;
|
||||
});
|
||||
afterEach(() => close());
|
||||
|
||||
// Insert a ledger row directly (these fns read raw rows; signing is event-log's job).
|
||||
let idx = 0;
|
||||
function entry(identity: string, payload?: Record<string, unknown>) {
|
||||
idx += 1;
|
||||
db.insert(ledgerEvents).values({
|
||||
id: `e${idx}`, index: idx, type: "vehicle_entry", direction: "entry",
|
||||
identity, payload: payload ?? null, occurredAt: new Date().toISOString(),
|
||||
signature: "x", keyId: "test",
|
||||
}).run();
|
||||
}
|
||||
function exit(identity: string) {
|
||||
idx += 1;
|
||||
db.insert(ledgerEvents).values({
|
||||
id: `e${idx}`, index: idx, type: "vehicle_exit", direction: "exit",
|
||||
identity, payload: null, occurredAt: new Date().toISOString(),
|
||||
signature: "x", keyId: "test",
|
||||
}).run();
|
||||
}
|
||||
function voidEvt(identity: string) {
|
||||
idx += 1;
|
||||
db.insert(ledgerEvents).values({
|
||||
id: `e${idx}`, index: idx, type: "void",
|
||||
identity, payload: { sessionRef: identity, voidReason: "misprint" }, occurredAt: new Date().toISOString(),
|
||||
signature: "x", keyId: "test",
|
||||
}).run();
|
||||
}
|
||||
function setSite(v: Partial<typeof siteConfig.$inferInsert>) {
|
||||
db.insert(siteConfig).values({ id: 1, ...v }).onConflictDoUpdate({ target: siteConfig.id, set: v }).run();
|
||||
}
|
||||
|
||||
describe("occupancyCount", () => {
|
||||
beforeEach(() => { idx = 0; });
|
||||
|
||||
it("is 0 with no events", () => {
|
||||
expect(occupancyCount(db)).toBe(0);
|
||||
});
|
||||
|
||||
it("counts open sessions (entries minus matching exits)", () => {
|
||||
entry("A"); entry("B"); entry("C");
|
||||
exit("B");
|
||||
expect(occupancyCount(db)).toBe(2);
|
||||
});
|
||||
|
||||
it("a re-entry after exit counts again", () => {
|
||||
entry("A"); exit("A"); entry("A");
|
||||
expect(occupancyCount(db)).toBe(1);
|
||||
});
|
||||
|
||||
it("a voided (cancelled) entry does NOT count inside", () => {
|
||||
entry("A"); entry("B");
|
||||
voidEvt("B"); // B's ticket was a misprint — cancelled
|
||||
expect(occupancyCount(db)).toBe(1);
|
||||
});
|
||||
});
|
||||
|
||||
describe("getOccupancy — capacity + full gate", () => {
|
||||
beforeEach(() => { idx = 0; });
|
||||
|
||||
it("uncapped: never full, free/effectiveFree null", () => {
|
||||
setSite({ capacity: null });
|
||||
entry("A");
|
||||
const o = getOccupancy(db);
|
||||
expect(o.full).toBe(false);
|
||||
expect(o.free).toBeNull();
|
||||
expect(o.effectiveFree).toBeNull();
|
||||
});
|
||||
|
||||
it("capped: full when count reaches capacity", () => {
|
||||
setSite({ capacity: 2 });
|
||||
entry("A");
|
||||
expect(getOccupancy(db).full).toBe(false);
|
||||
entry("B");
|
||||
const o = getOccupancy(db);
|
||||
expect(o.full).toBe(true);
|
||||
expect(o.free).toBe(0);
|
||||
});
|
||||
});
|
||||
|
||||
describe("reservedSubscriberSpots", () => {
|
||||
beforeEach(() => { idx = 0; });
|
||||
|
||||
function addSub(id: string, opts: Partial<typeof subscriptions.$inferInsert> = {}) {
|
||||
db.insert(subscriptions).values({ id, status: "active", quantity: 1, period: "month", ...opts }).run();
|
||||
}
|
||||
|
||||
it("is 0 when the toggle is off (default)", () => {
|
||||
setSite({ capacity: 10, reserveSubscriberSpots: false });
|
||||
addSub("s1", { quantity: 2 });
|
||||
expect(reservedSubscriberSpots(db)).toBe(0);
|
||||
});
|
||||
|
||||
it("holds quantity spots for an active, not-parked subscription", () => {
|
||||
setSite({ capacity: 10, reserveSubscriberSpots: true });
|
||||
addSub("s1", { quantity: 2 });
|
||||
expect(reservedSubscriberSpots(db)).toBe(2);
|
||||
});
|
||||
|
||||
it("does NOT double-count a subscriber already parked (holds only the rest)", () => {
|
||||
setSite({ capacity: 10, reserveSubscriberSpots: true });
|
||||
addSub("s1", { quantity: 2 });
|
||||
// One of the family's two cars is inside (occurrence entry carries permitId = sub id).
|
||||
entry("SUBSESS-1", { permitId: "s1" });
|
||||
expect(reservedSubscriberSpots(db)).toBe(1); // 2 quantity − 1 inside
|
||||
});
|
||||
|
||||
it("ignores suspended/revoked and out-of-window subscriptions", () => {
|
||||
setSite({ capacity: 10, reserveSubscriberSpots: true });
|
||||
addSub("active", { quantity: 1 });
|
||||
addSub("suspended", { quantity: 5, status: "suspended" });
|
||||
addSub("expired", { quantity: 5, validTo: "2000-01-01T00:00:00.000Z" });
|
||||
expect(reservedSubscriberSpots(db)).toBe(1);
|
||||
});
|
||||
});
|
||||
|
||||
describe("getOccupancy — reserved tightens the transient gate", () => {
|
||||
beforeEach(() => { idx = 0; });
|
||||
|
||||
it("transient sees full once count + reserved ≥ capacity", () => {
|
||||
setSite({ capacity: 3, reserveSubscriberSpots: true });
|
||||
db.insert(subscriptions).values({ id: "s1", status: "active", quantity: 2, period: "month" }).run();
|
||||
entry("A"); // 1 inside + 2 reserved = 3 ≥ capacity 3
|
||||
const o = getOccupancy(db);
|
||||
expect(o.reserved).toBe(2);
|
||||
expect(o.effectiveFree).toBe(0);
|
||||
expect(o.full).toBe(true);
|
||||
});
|
||||
});
|
||||
@@ -30,8 +30,11 @@ export function occupancyCount(db: Db): number {
|
||||
.all();
|
||||
const balance = new Map<string, number>();
|
||||
for (const r of rows) {
|
||||
// A `void` (cancelled ticket) closes the session like an exit — the car never entered
|
||||
// (misprint), so it must not count inside. See void-flow.ts.
|
||||
if (r.type === "vehicle_entry") balance.set(r.identity ?? "", (balance.get(r.identity ?? "") ?? 0) + 1);
|
||||
else if (r.type === "vehicle_exit") balance.set(r.identity ?? "", (balance.get(r.identity ?? "") ?? 0) - 1);
|
||||
else if (r.type === "vehicle_exit" || r.type === "void")
|
||||
balance.set(r.identity ?? "", (balance.get(r.identity ?? "") ?? 0) - 1);
|
||||
}
|
||||
let open = 0;
|
||||
for (const v of balance.values()) if (v > 0) open += 1;
|
||||
@@ -68,7 +71,7 @@ export function reservedSubscriberSpots(db: Db): number {
|
||||
if (pl.permitId == null) continue; // transient
|
||||
net.set(id, (net.get(id) ?? 0) + 1);
|
||||
subOf.set(id, pl.permitId);
|
||||
} else if (r.type === "vehicle_exit") {
|
||||
} else if (r.type === "vehicle_exit" || r.type === "void") {
|
||||
if (net.has(id)) net.set(id, (net.get(id) ?? 0) - 1);
|
||||
}
|
||||
}
|
||||
|
||||
@@ -0,0 +1,137 @@
|
||||
import { afterEach, beforeEach, describe, expect, it } from "vitest";
|
||||
import { createTestDb } from "@parking/db/testing";
|
||||
import { ledgerEvents, eq, type Db } from "@parking/db";
|
||||
import { PayStation, NoOpenSessionError, NoTariffError } from "./pay-station.js";
|
||||
import type { EventLog } from "./event-log.js";
|
||||
import { makeLog, silentLogger, seedTariff, minutesAgo } from "./test-helpers.js";
|
||||
|
||||
// The pay station prices an open session against the tariff frozen at entry and writes
|
||||
// a SIGNED payment event (never a mutable "paid" flag). These tests pin the quote math,
|
||||
// the signed-payment side effect, the no-session / no-tariff errors, and the lookup
|
||||
// view the booth modal reads.
|
||||
|
||||
let db: Db;
|
||||
let close: () => void;
|
||||
let log: EventLog;
|
||||
let pay: PayStation;
|
||||
|
||||
beforeEach(() => {
|
||||
const t = createTestDb();
|
||||
db = t.db;
|
||||
close = t.close;
|
||||
log = makeLog(db);
|
||||
pay = new PayStation(db, log, silentLogger());
|
||||
});
|
||||
afterEach(() => close());
|
||||
|
||||
async function enter(identity: string, enteredAt: string, payload?: Record<string, unknown>) {
|
||||
await log.append({ type: "vehicle_entry", direction: "entry", identity, occurredAt: enteredAt, payload: payload ?? null });
|
||||
}
|
||||
|
||||
describe("PayStation.quote", () => {
|
||||
it("throws NoOpenSessionError for an unknown ticket", () => {
|
||||
seedTariff(db);
|
||||
expect(() => pay.quote("nope")).toThrow(NoOpenSessionError);
|
||||
});
|
||||
|
||||
it("throws NoTariffError when no site tariff is configured", async () => {
|
||||
await enter("T1", minutesAgo(120));
|
||||
expect(() => pay.quote("T1")).toThrow(NoTariffError);
|
||||
});
|
||||
|
||||
it("prices a stay against the frozen tariff (90min → 2 increments at 100/h = 200)", async () => {
|
||||
// 90 min rounds UP to a 2nd 60-min increment; well clear of the boundary so a few
|
||||
// ms of test runtime can't tip it into a 3rd increment.
|
||||
seedTariff(db, { pricePerIncrementMinor: 10000, incrementMin: 60 });
|
||||
await enter("T1", minutesAgo(90));
|
||||
const q = pay.quote("T1");
|
||||
expect(q.amountMinor).toBe(20000);
|
||||
expect(q.currency).toBe("ALL");
|
||||
expect(q.overstay).toBe(false);
|
||||
});
|
||||
|
||||
it("prices 0 within the entry grace (quick in-and-out)", async () => {
|
||||
seedTariff(db, { gracePeriodEntryMin: 10 });
|
||||
await enter("T1", minutesAgo(5));
|
||||
expect(pay.quote("T1").amountMinor).toBe(0);
|
||||
});
|
||||
});
|
||||
|
||||
describe("PayStation.pay — signed payment side effect", () => {
|
||||
it("appends a signed payment event carrying amount, currency, tender, grace", async () => {
|
||||
const { currency } = seedTariff(db, { pricePerIncrementMinor: 10000, gracePeriodExitMin: 15 });
|
||||
await enter("T1", minutesAgo(90));
|
||||
|
||||
const res = await pay.pay("T1", "cash");
|
||||
expect(res.amountMinor).toBe(20000);
|
||||
expect(res.currency).toBe(currency);
|
||||
|
||||
const payments = db.select().from(ledgerEvents).where(eq(ledgerEvents.type, "payment")).all();
|
||||
expect(payments).toHaveLength(1);
|
||||
const pl = payments[0].payload as Record<string, unknown>;
|
||||
expect(pl.amountMinor).toBe(20000);
|
||||
expect(pl.tender).toBe("cash");
|
||||
expect(pl.graceExitMin).toBe(15);
|
||||
// It must be a real signed chain event.
|
||||
expect(log.verifyChain()).toEqual({ ok: true });
|
||||
});
|
||||
|
||||
it("honours an operator override amount (lost ticket / dispute)", async () => {
|
||||
seedTariff(db);
|
||||
await enter("T1", minutesAgo(120));
|
||||
const res = await pay.pay("T1", "card", 99900);
|
||||
expect(res.amountMinor).toBe(99900);
|
||||
const pl = db.select().from(ledgerEvents).where(eq(ledgerEvents.type, "payment")).all()[0].payload as Record<string, unknown>;
|
||||
expect(pl.amountMinor).toBe(99900);
|
||||
expect(pl.reason).toBe("operator-set amount");
|
||||
});
|
||||
});
|
||||
|
||||
describe("PayStation.lookup — booth modal view", () => {
|
||||
it("reports not-found for an unknown ticket", () => {
|
||||
const v = pay.lookup("ghost");
|
||||
expect(v.found).toBe(false);
|
||||
expect(v.open).toBe(false);
|
||||
});
|
||||
|
||||
it("shows an open unpaid transient with the amount owed", async () => {
|
||||
seedTariff(db, { pricePerIncrementMinor: 10000 });
|
||||
await enter("T1", minutesAgo(90));
|
||||
const v = pay.lookup("T1");
|
||||
expect(v.found).toBe(true);
|
||||
expect(v.open).toBe(true);
|
||||
expect(v.paidAt).toBeNull();
|
||||
expect(v.amountMinor).toBe(20000);
|
||||
expect(v.subscription).toBe(false);
|
||||
});
|
||||
|
||||
it("after payment shows paid + within grace, amount cleared", async () => {
|
||||
seedTariff(db, { pricePerIncrementMinor: 10000, gracePeriodExitMin: 15 });
|
||||
await enter("T1", minutesAgo(120));
|
||||
await pay.pay("T1", "cash");
|
||||
const v = pay.lookup("T1");
|
||||
expect(v.paidAt).not.toBeNull();
|
||||
expect(v.withinGrace).toBe(true);
|
||||
expect(v.overstay).toBe(false);
|
||||
});
|
||||
|
||||
it("flags a subscription occurrence (prepaid — never a transient charge)", async () => {
|
||||
seedTariff(db);
|
||||
await enter("SUBSESS-1", minutesAgo(120), { permit: true, permitId: "sub-1" });
|
||||
const v = pay.lookup("SUBSESS-1");
|
||||
expect(v.subscription).toBe(true);
|
||||
expect(v.subscriptionId).toBe("sub-1");
|
||||
expect(v.amountMinor).toBeNull(); // no timeframes → nothing owed
|
||||
});
|
||||
});
|
||||
|
||||
describe("PayStation.activeSessions", () => {
|
||||
it("lists open sessions newest-first and omits exited-past-grace", async () => {
|
||||
seedTariff(db, { pricePerIncrementMinor: 10000 });
|
||||
await enter("OLD", minutesAgo(200));
|
||||
await enter("NEW", minutesAgo(30));
|
||||
const list = pay.activeSessions();
|
||||
expect(list.map((s) => s.identity)).toEqual(["NEW", "OLD"]);
|
||||
expect(list.every((s) => s.open)).toBe(true);
|
||||
});
|
||||
});
|
||||
@@ -1,9 +1,10 @@
|
||||
import { desc, eq, ledgerEvents, sessions, subscriptions, tariffVersions, tariffs, type Db } from "@parking/db";
|
||||
import { priceSession, type TariffStructure, type Tender } from "@parking/shared";
|
||||
import { BOOTH_TILL, priceSession, type ChargeLine, type TariffStructure, type Tender, type ValidationLine } from "@parking/shared";
|
||||
import type { FastifyBaseLogger } from "fastify";
|
||||
import type { EventLog } from "./event-log.js";
|
||||
import { plateForIdentity, platesForIdentities } from "./plate-lookup.js";
|
||||
import { windowOwedBetween } from "./subscription-window.js";
|
||||
import { liveValidations } from "./validations.js";
|
||||
|
||||
// The PAY STATION: a customer pays for an open session BEFORE walking back to the
|
||||
// car (pay-on-foot — payment is decoupled from exit). Two steps:
|
||||
@@ -28,6 +29,18 @@ export class NoTariffError extends Error {
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* A module that folds its own charges into a booth settlement (venue-modules.md):
|
||||
* `lines(identity)` returns the open charges for the session (e.g. wash orders with
|
||||
* payAt = "booth"); after the `payment` is signed, `onPaid` lets the module mark them
|
||||
* settled. Registered by the module at boot (registerChargeProvider) — PayStation
|
||||
* never imports a module.
|
||||
*/
|
||||
export interface ChargeProvider {
|
||||
lines(identity: string): ChargeLine[];
|
||||
onPaid(identity: string, lines: ChargeLine[], payment: { eventId: string; tender: Tender; operator?: string }): Promise<void>;
|
||||
}
|
||||
|
||||
export interface Quote {
|
||||
readonly identity: string;
|
||||
/** Vehicle entry time (the session's original entry; for display/audit). */
|
||||
@@ -38,8 +51,23 @@ export interface Quote {
|
||||
* is priced as a fresh stay from there → now, with its own daily-cap ladder, NOT
|
||||
* "full stay minus paid" (which a daily cap collapses toward zero). */
|
||||
readonly periodStart: string;
|
||||
/** Amount owed now: the fee for [periodStart → now]. */
|
||||
/** Amount owed now: the parking fee for [periodStart → now] NET of merchant
|
||||
* validations, PLUS any module charge lines (a wash paid at the booth). */
|
||||
readonly amountMinor: number;
|
||||
/** The parking-only net (amountMinor − chargesMinor). */
|
||||
readonly parkingMinor: number;
|
||||
/** Non-parking charges folded in by modules (see ChargeProvider). */
|
||||
readonly chargeLines: ChargeLine[];
|
||||
readonly chargesMinor: number;
|
||||
/** The pre-validation fee (= amountMinor when no validations apply). */
|
||||
readonly grossMinor: number;
|
||||
/** Total the merchant validations took off (gross − net). */
|
||||
readonly discountMinor: number;
|
||||
/** Per-validation receipt/display lines (empty when none apply). */
|
||||
readonly validationLines: ValidationLine[];
|
||||
/** The validation event ids this quote applied — the payment stamps them as
|
||||
* CONSUMED so an overstay's fresh period never re-applies them. */
|
||||
readonly validationIds: string[];
|
||||
/** True when this quote prices an overstay period (grace lapsed), not the first stay. */
|
||||
readonly overstay: boolean;
|
||||
readonly currency: string;
|
||||
@@ -98,6 +126,11 @@ export interface SessionLookup {
|
||||
/** Amount owed right now (the quote). Null when no session / no active tariff. */
|
||||
readonly amountMinor: number | null;
|
||||
readonly currency: string | null;
|
||||
/** Amount actually PAID (from the latest payment event), if any. Distinct from
|
||||
* `amountMinor` (what's owed now): once a transient is settled `amountMinor` is null,
|
||||
* but the operator still wants to see the sum that was collected. */
|
||||
readonly paidMinor: number | null;
|
||||
readonly paidCurrency: string | null;
|
||||
/** True when paid AND still within the walk-back grace window. */
|
||||
readonly withinGrace: boolean;
|
||||
/** ISO time the walk-back grace expires (paidAt + graceExitMin), if paid. */
|
||||
@@ -112,12 +145,22 @@ export interface SessionLookup {
|
||||
/** Advisory licence plate recognized for this session (ANPR-on-snapshot). Null when
|
||||
* none. Display/audit only — never an access decision. */
|
||||
readonly plate: string | null;
|
||||
/** Merchant validations folded into `amountMinor` (which is NET): the pre-discount
|
||||
* fee, the total taken off, and the per-validation lines for the modal/receipt.
|
||||
* grossMinor/discountMinor are null when no quote resolved. */
|
||||
readonly grossMinor: number | null;
|
||||
readonly discountMinor: number | null;
|
||||
readonly validationLines: ValidationLine[];
|
||||
/** Module charge lines folded into `amountMinor` (e.g. a wash paid at the booth). */
|
||||
readonly chargeLines: ChargeLine[];
|
||||
readonly chargesMinor: number | null;
|
||||
}
|
||||
|
||||
export class PayStation {
|
||||
readonly #db: Db;
|
||||
readonly #log: EventLog;
|
||||
readonly #logger: FastifyBaseLogger;
|
||||
readonly #chargeProviders: ChargeProvider[] = [];
|
||||
|
||||
constructor(db: Db, log: EventLog, logger: FastifyBaseLogger) {
|
||||
this.#db = db;
|
||||
@@ -125,6 +168,30 @@ export class PayStation {
|
||||
this.#logger = logger;
|
||||
}
|
||||
|
||||
/** Let a module fold its charges into booth settlements (see ChargeProvider). */
|
||||
registerChargeProvider(p: ChargeProvider): void {
|
||||
this.#chargeProviders.push(p);
|
||||
}
|
||||
|
||||
/** The currency of the tariff in force right now (null = none published). Modules
|
||||
* price their own goods in the same money the booth takes. */
|
||||
activeCurrency(): string | null {
|
||||
return this.#tariffVersionFor(new Date().toISOString())?.currency ?? null;
|
||||
}
|
||||
|
||||
#chargeLines(identity: string): ChargeLine[] {
|
||||
const out: ChargeLine[] = [];
|
||||
for (const p of this.#chargeProviders) {
|
||||
try {
|
||||
out.push(...p.lines(identity));
|
||||
} catch (err) {
|
||||
// A module's fault must never block a parking settlement — log and price without it.
|
||||
this.#logger.error(`charge provider failed for ${identity}: ${(err as Error).message}`);
|
||||
}
|
||||
}
|
||||
return out;
|
||||
}
|
||||
|
||||
/** Price an open session. Normally the period is entry→now. But for an OVERSTAY — a
|
||||
* paid session whose walk-back grace has lapsed (the car re-parked, or a new period
|
||||
* began) — the customer is billed for a FRESH period from grace-expiry→now, with its
|
||||
@@ -150,19 +217,33 @@ export class PayStation {
|
||||
// Pure pricing shared with the Tariff Lab (priceSession). Only the latest payment
|
||||
// matters for grace/overstay; pass it through. Overstay → fresh period from
|
||||
// grace-expiry; within-grace → settled; unpaid → entry→now running total.
|
||||
// Merchant validations: fold the LIVE ones (applied, unvoided, not consumed by a
|
||||
// prior payment) so the quote is NET — the payment then stamps their ids as
|
||||
// consumed. See wiki/concepts/validation-discounts.md.
|
||||
const last = this.#lastPayment(identity);
|
||||
const validations = liveValidations(this.#db, identity);
|
||||
const p = priceSession(
|
||||
entry.occurredAt,
|
||||
new Date().toISOString(),
|
||||
structure,
|
||||
last ? [last] : [],
|
||||
category,
|
||||
validations,
|
||||
);
|
||||
const chargeLines = this.#chargeLines(identity);
|
||||
const chargesMinor = chargeLines.reduce((sum, l) => sum + l.amountMinor, 0);
|
||||
return {
|
||||
identity,
|
||||
enteredAt: entry.occurredAt,
|
||||
periodStart: p.periodStart,
|
||||
amountMinor: p.amountMinor,
|
||||
amountMinor: p.amountMinor + chargesMinor,
|
||||
parkingMinor: p.amountMinor,
|
||||
chargeLines,
|
||||
chargesMinor,
|
||||
grossMinor: p.grossMinor,
|
||||
discountMinor: p.discountMinor,
|
||||
validationLines: p.validationLines,
|
||||
validationIds: validations.map((v) => v.eventId),
|
||||
overstay: p.overstay,
|
||||
currency: tv.currency,
|
||||
tariffVersionId: tv.id,
|
||||
@@ -216,6 +297,7 @@ export class PayStation {
|
||||
amountMinor,
|
||||
currency: subWindow.currency ?? undefined,
|
||||
tender,
|
||||
till: BOOTH_TILL,
|
||||
...(subWindow.tariffVersionId ? { tariffVersionId: subWindow.tariffVersionId } : {}),
|
||||
subscriptionWindowCharge: true,
|
||||
...(overrideMinor != null ? { reason: "operator-set amount", quotedMinor: subWindow.dueMinor } : {}),
|
||||
@@ -228,7 +310,7 @@ export class PayStation {
|
||||
const q = this.quote(identity);
|
||||
const amountMinor = overrideMinor ?? q.amountMinor;
|
||||
|
||||
await this.#log.append({
|
||||
const paymentEvent = await this.#log.append({
|
||||
type: "payment",
|
||||
source: "manual",
|
||||
identity,
|
||||
@@ -237,10 +319,34 @@ export class PayStation {
|
||||
amountMinor,
|
||||
currency: q.currency,
|
||||
tender,
|
||||
// Parking money is BOOTH money (a wash paid at the booth rides along as
|
||||
// chargeLines, so it is booth money too). See wiki/concepts/shift.md "Tills".
|
||||
till: BOOTH_TILL,
|
||||
tariffVersionId: q.tariffVersionId,
|
||||
// Module charges (e.g. a wash paid at the booth): frozen as lines so the
|
||||
// receipt reproduces and reporting can split parking from the rest.
|
||||
...(q.chargeLines.length
|
||||
? {
|
||||
chargeLines: q.chargeLines.map((l) => ({ ...l })),
|
||||
chargesMinor: q.chargesMinor,
|
||||
parkingMinor: q.parkingMinor,
|
||||
}
|
||||
: {}),
|
||||
// The exit flow reads graceExitMin off the payment to validate the
|
||||
// walk-back window without re-resolving the tariff.
|
||||
graceExitMin: q.graceExitMin,
|
||||
// Merchant validations: record the gross/discount split + CONSUME the applied
|
||||
// validation ids, so reporting sees the leakage and a later overstay period
|
||||
// never re-applies them. A zero-net settlement (full comp) is still a signed
|
||||
// payment — grace/voucher/exit work unchanged. See validation-discounts.md.
|
||||
...(q.validationIds.length
|
||||
? {
|
||||
grossMinor: q.grossMinor,
|
||||
discountMinor: q.discountMinor,
|
||||
validationIds: q.validationIds,
|
||||
validationLines: q.validationLines.map((l) => ({ ...l })),
|
||||
}
|
||||
: {}),
|
||||
...(overrideMinor != null ? { reason: "operator-set amount", quotedMinor: q.amountMinor } : {}),
|
||||
},
|
||||
});
|
||||
@@ -252,6 +358,17 @@ export class PayStation {
|
||||
this.#logger.error(`session-cache mark-paid failed for ${identity}: ${(err as Error).message}`);
|
||||
}
|
||||
|
||||
// Let each module mark the charge lines it contributed as settled by this payment.
|
||||
if (q.chargeLines.length) {
|
||||
for (const p of this.#chargeProviders) {
|
||||
try {
|
||||
await p.onPaid(identity, q.chargeLines, { eventId: paymentEvent.id, tender });
|
||||
} catch (err) {
|
||||
this.#logger.error(`charge provider onPaid failed for ${identity}: ${(err as Error).message}`);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
this.#logger.info(`payment ${amountMinor} ${q.currency} (${tender}) for ${identity}`);
|
||||
return { amountMinor, currency: q.currency };
|
||||
}
|
||||
@@ -274,24 +391,35 @@ export class PayStation {
|
||||
if (!entry) {
|
||||
return {
|
||||
identity: id, found: false, open: false, enteredAt: null, exitedAt: null,
|
||||
paidAt: null, amountMinor: null, currency: null, withinGrace: false, graceExpiresAt: null,
|
||||
paidAt: null, amountMinor: null, currency: null, paidMinor: null, paidCurrency: null,
|
||||
withinGrace: false, graceExpiresAt: null,
|
||||
overstay: false, subscription: false, subscriptionId: null, subscriptionHolder: null, plate: null,
|
||||
grossMinor: null, discountMinor: null, validationLines: [],
|
||||
chargeLines: [], chargesMinor: null,
|
||||
};
|
||||
}
|
||||
// Subscription occurrence? The entry payload carries permit:true + permitId.
|
||||
const entryPl = (entry.payload ?? {}) as { permit?: boolean; permitId?: string };
|
||||
const isSubscription = entryPl.permit === true || entryPl.permitId != null;
|
||||
const subscriptionId = isSubscription ? (entryPl.permitId ?? null) : null;
|
||||
const exitRow = rows.find((r) => r.type === "vehicle_exit");
|
||||
// A `void` (cancelled ticket) closes the session like an exit — a voided ticket is no
|
||||
// longer open and can't be paid/exited. See void-flow.ts.
|
||||
const exitRow = rows.find((r) => r.type === "vehicle_exit" || r.type === "void");
|
||||
const open = !exitRow;
|
||||
|
||||
let paidAt: string | null = null;
|
||||
let graceExitMin: number | null = null;
|
||||
let paidMinor: number | null = null;
|
||||
let paidCurrency: string | null = null;
|
||||
for (const r of rows) {
|
||||
if (r.type === "payment") {
|
||||
paidAt = r.occurredAt;
|
||||
const p = (r.payload ?? {}) as { graceExitMin?: number };
|
||||
const p = (r.payload ?? {}) as { graceExitMin?: number; amountMinor?: number; currency?: string };
|
||||
if (typeof p.graceExitMin === "number") graceExitMin = p.graceExitMin;
|
||||
// Sum payments (overstay top-ups append a second one) so the displayed paid total
|
||||
// reflects everything collected for the session, not just the last slip.
|
||||
if (typeof p.amountMinor === "number") paidMinor = (paidMinor ?? 0) + p.amountMinor;
|
||||
if (typeof p.currency === "string") paidCurrency = p.currency;
|
||||
}
|
||||
}
|
||||
const graceExpiresAt =
|
||||
@@ -305,11 +433,21 @@ export class PayStation {
|
||||
// exit gate clears. See wiki/entities/subscription.md.
|
||||
let amountMinor: number | null = null;
|
||||
let currency: string | null = null;
|
||||
let grossMinor: number | null = null;
|
||||
let discountMinor: number | null = null;
|
||||
let validationLines: ValidationLine[] = [];
|
||||
let chargeLines: ChargeLine[] = [];
|
||||
let chargesMinor: number | null = null;
|
||||
if (open && !isSubscription) {
|
||||
try {
|
||||
const q = this.quote(id);
|
||||
amountMinor = q.amountMinor;
|
||||
currency = q.currency;
|
||||
grossMinor = q.grossMinor;
|
||||
discountMinor = q.discountMinor;
|
||||
validationLines = q.validationLines;
|
||||
chargeLines = q.chargeLines;
|
||||
chargesMinor = q.chargesMinor;
|
||||
} catch {
|
||||
/* no active tariff — leave null; modal shows session without a price */
|
||||
}
|
||||
@@ -326,10 +464,12 @@ export class PayStation {
|
||||
return {
|
||||
identity: id, found: true, open,
|
||||
enteredAt: entry.occurredAt, exitedAt: exitRow?.occurredAt ?? null,
|
||||
paidAt, amountMinor, currency, withinGrace, graceExpiresAt, overstay,
|
||||
paidAt, amountMinor, currency, paidMinor, paidCurrency, withinGrace, graceExpiresAt, overstay,
|
||||
subscription: isSubscription, subscriptionId,
|
||||
subscriptionHolder: this.#holderOf(subscriptionId),
|
||||
plate: plateForIdentity(this.#db, id)?.plate ?? null,
|
||||
grossMinor, discountMinor, validationLines,
|
||||
chargeLines, chargesMinor,
|
||||
};
|
||||
}
|
||||
|
||||
@@ -366,7 +506,8 @@ export class PayStation {
|
||||
const pl = (r.payload ?? {}) as { permit?: boolean; permitId?: string };
|
||||
if (pl.permit === true || pl.permitId) a.subscriptionId = pl.permitId ?? null;
|
||||
byId.set(id, a);
|
||||
} else if (r.type === "vehicle_exit") {
|
||||
} else if (r.type === "vehicle_exit" || r.type === "void") {
|
||||
// A `void` closes the session like an exit — drop it from the active list.
|
||||
const a = byId.get(id);
|
||||
if (a) a.exitedAt = r.occurredAt;
|
||||
} else if (r.type === "payment") {
|
||||
|
||||
@@ -1,4 +1,5 @@
|
||||
import { and, desc, deviceEvents, eq, type Db } from "@parking/db";
|
||||
import { isNormBox, isVehicleClass, type VehicleRead } from "@parking/shared";
|
||||
|
||||
// READ-TIME plate resolution. A recognized licence plate is ADVISORY evidence — it
|
||||
// lives in the unsigned, prunable `device_events` (kind="read") stream written by the
|
||||
@@ -23,6 +24,38 @@ interface ReadDetail {
|
||||
plate?: string;
|
||||
confidence?: number;
|
||||
direction?: string;
|
||||
bodyType?: string;
|
||||
bodyConfidence?: number;
|
||||
snapshotId?: string;
|
||||
vehicleBox?: unknown;
|
||||
plateBox?: unknown;
|
||||
}
|
||||
|
||||
/** The advisory VEHICLE read (body type) for a session — the same stream and the same
|
||||
* preference as the plate (entry over exit, newest first). Null when vision never
|
||||
* classified the vehicle. See venue-modules.md §Vehicle category from vision. */
|
||||
export function vehicleForIdentity(db: Db, identity: string): VehicleRead | null {
|
||||
const rows = db
|
||||
.select({ detail: deviceEvents.detail })
|
||||
.from(deviceEvents)
|
||||
.where(and(eq(deviceEvents.category, "camera"), eq(deviceEvents.kind, "read")))
|
||||
.orderBy(desc(deviceEvents.occurredAt))
|
||||
.all();
|
||||
let fallback: VehicleRead | null = null;
|
||||
for (const r of rows) {
|
||||
const d = (r.detail ?? {}) as ReadDetail;
|
||||
if (d.identity !== identity || !isVehicleClass(d.bodyType) || typeof d.bodyConfidence !== "number") continue;
|
||||
const v: VehicleRead = {
|
||||
bodyType: d.bodyType,
|
||||
confidence: d.bodyConfidence,
|
||||
snapshotId: d.snapshotId ?? null,
|
||||
box: isNormBox(d.vehicleBox) ? d.vehicleBox : null,
|
||||
plateBox: isNormBox(d.plateBox) ? d.plateBox : null,
|
||||
};
|
||||
if (d.direction === "entry") return v;
|
||||
if (!fallback) fallback = v;
|
||||
}
|
||||
return fallback;
|
||||
}
|
||||
|
||||
/** Best plate for one identity, or null. Prefers an entry read, then the newest read. */
|
||||
|
||||
@@ -0,0 +1,103 @@
|
||||
import { randomUUID } from "node:crypto";
|
||||
import { beforeEach, describe, expect, it } from "vitest";
|
||||
import { devices, deviceEvents as deviceEventsTable, ledgerEvents, subscriptionCredentials, type Db } from "@parking/db";
|
||||
import { createTestDb } from "@parking/db/testing";
|
||||
import { ReadDispatcher } from "./read-dispatch.js";
|
||||
import { ExitFlow } from "./exit-flow.js";
|
||||
import { SubscriptionFlow } from "./subscription-flow.js";
|
||||
import type { DeviceReadEvent } from "./device-events.js";
|
||||
import { makeLog, silentLogger } from "./test-helpers.js";
|
||||
|
||||
// STRUCTURAL FILTER at the dispatcher (2026-07-04): a reader value that matched
|
||||
// nothing AND can't possibly be a credential we issued (no ticket Luhn shape, no
|
||||
// SUB-/SUBSESS- prefix, not a confirmed-RF read) is refused with UNSIGNED telemetry
|
||||
// instead of reaching the exit flow and signing a noSession anomaly. Born from the
|
||||
// park-buzi phantom optical decodes: red "who is exiting?" rows for NOBODY train the
|
||||
// operator to ignore the signed feed. Anything plausibly ours STILL signs normally.
|
||||
|
||||
let db: Db;
|
||||
let dispatcher: ReadDispatcher;
|
||||
|
||||
const READER = "reader-exit";
|
||||
|
||||
beforeEach(() => {
|
||||
({ db } = createTestDb());
|
||||
db.insert(devices).values({
|
||||
id: "ctl-exit",
|
||||
category: "access",
|
||||
driverId: "stub-access",
|
||||
config: { relays: [{ relay: 1, direction: "exit" }] },
|
||||
enabled: true,
|
||||
}).run();
|
||||
db.insert(devices).values({
|
||||
id: READER,
|
||||
category: "reader",
|
||||
driverId: "dingtian-qr-reader",
|
||||
config: { serial: "H05MA5B0", direction: "exit" },
|
||||
enabled: true,
|
||||
}).run();
|
||||
const log = makeLog(db);
|
||||
dispatcher = new ReadDispatcher(db, new ExitFlow(db, log, silentLogger()), new SubscriptionFlow(db, log, silentLogger()), silentLogger());
|
||||
});
|
||||
|
||||
function read(value: string, opts: { kind?: DeviceReadEvent["kind"]; channel?: DeviceReadEvent["channel"] } = {}): DeviceReadEvent {
|
||||
return {
|
||||
driverId: "dingtian-qr-reader",
|
||||
deviceId: READER,
|
||||
value,
|
||||
kind: opts.kind ?? "qr",
|
||||
...(opts.channel ? { channel: opts.channel } : {}),
|
||||
at: new Date().toISOString(),
|
||||
};
|
||||
}
|
||||
|
||||
const ledger = () => db.select().from(ledgerEvents).all();
|
||||
const unrecognized = () =>
|
||||
db.select().from(deviceEventsTable).all()
|
||||
.map((r) => r.detail as { unrecognizedRead?: boolean; value?: string })
|
||||
.filter((d) => d.unrecognizedRead === true);
|
||||
|
||||
describe("read-dispatch structural filter", () => {
|
||||
it("phantom 6-digit optical decode → refused, telemetry only, NOTHING signed", async () => {
|
||||
const out = await dispatcher.dispatch(read("999459", { channel: "optical" }));
|
||||
expect(out.accepted).toBe(false);
|
||||
expect(out.reason).toMatch(/unrecognized/);
|
||||
expect(ledger()).toHaveLength(0); // the whole point: no red row in the feed
|
||||
expect(unrecognized()).toHaveLength(1);
|
||||
expect(unrecognized()[0].value).toBe("999459");
|
||||
});
|
||||
|
||||
it("legacy untagged garbage ('C') → filtered too (works before prefixes are deployed)", async () => {
|
||||
const out = await dispatcher.dispatch(read("C"));
|
||||
expect(out.accepted).toBe(false);
|
||||
expect(ledger()).toHaveLength(0);
|
||||
expect(unrecognized()).toHaveLength(1);
|
||||
});
|
||||
|
||||
it("Luhn-valid unknown ticket → NOT filtered: the exit flow signs the noSession anomaly", async () => {
|
||||
const out = await dispatcher.dispatch(read("00000000000")); // valid shape, no session
|
||||
expect(out.accepted).toBe(false);
|
||||
expect(unrecognized()).toHaveLength(0);
|
||||
const anomalies = ledger().filter((r) => r.type === "anomaly");
|
||||
expect(anomalies.length).toBeGreaterThan(0); // a real probe stays in the signed feed
|
||||
});
|
||||
|
||||
it("unknown card on a CONFIRMED RF channel → NOT filtered (a physical card is a real event)", async () => {
|
||||
await dispatcher.dispatch(read("1A86A158", { kind: "card", channel: "rf" }));
|
||||
expect(unrecognized()).toHaveLength(0);
|
||||
expect(ledger().filter((r) => r.type === "anomaly").length).toBeGreaterThan(0);
|
||||
});
|
||||
|
||||
it("unknown SUB- code → NOT filtered (our own prefix = an interesting probe)", async () => {
|
||||
await dispatcher.dispatch(read("SUB-DOESNOTEXIST", { channel: "optical" }));
|
||||
expect(unrecognized()).toHaveLength(0);
|
||||
expect(ledger().filter((r) => r.type === "anomaly").length).toBeGreaterThan(0);
|
||||
});
|
||||
|
||||
it("an ENROLLED credential is matched BEFORE the filter (never hidden by it)", async () => {
|
||||
// A card UID that would fail every shape test — enrolled, so it must still match.
|
||||
db.insert(subscriptionCredentials).values({ id: randomUUID(), subscriptionId: "sub-1", kind: "rf", value: "999459" }).run();
|
||||
await dispatcher.dispatch(read("999459")); // legacy untagged read of it
|
||||
expect(unrecognized()).toHaveLength(0); // reached the subscription flow, not the filter
|
||||
});
|
||||
});
|
||||
@@ -1,7 +1,9 @@
|
||||
import { devices, eq, type Db } from "@parking/db";
|
||||
import { randomUUID } from "node:crypto";
|
||||
import { devices, deviceEvents as deviceEventsTable, eq, type Db } from "@parking/db";
|
||||
import type { FastifyBaseLogger } from "fastify";
|
||||
import type { DeviceReadEvent, ReadOutcome } from "./device-events.js";
|
||||
import type { ExitFlow } from "./exit-flow.js";
|
||||
import { validateTicketCode } from "./entry-flow.js";
|
||||
import type { SubscriptionFlow } from "./subscription-flow.js";
|
||||
import { relayForDevice } from "./device-resolve.js";
|
||||
|
||||
@@ -17,6 +19,22 @@ import { relayForDevice } from "./device-resolve.js";
|
||||
// it opens that exact barrier. An "entry" reader drives the entry side, an "exit"
|
||||
// reader the exit side; "both" defers to the flow's own inference (subscription:
|
||||
// session state; transient: exit).
|
||||
//
|
||||
// STRUCTURAL FILTER (2026-07-04, operator-requested). The DT-008's scan engine
|
||||
// false-decodes sunlight stripe patterns into short garbage codes (phantom reads —
|
||||
// see wiki/entities/dingtian-dt008-reader.md), and each one was reaching the exit
|
||||
// flow and signing an exit.refused.noSession anomaly: red "who is trying to exit?"
|
||||
// rows for NOBODY, training the operator to ignore the feed (alarm fatigue is the
|
||||
// adversary's friend). So a reader value that matched nothing AND cannot possibly be
|
||||
// a credential we issued is dropped to UNSIGNED telemetry (device_events, still
|
||||
// auditable) instead of the signed ledger. "Possibly ours" stays deliberately wide —
|
||||
// any of these still reaches the flows and signs the normal refusal anomaly:
|
||||
// - a Luhn-valid ticket shape (validateTicketCode — a forged/expired ticket is a
|
||||
// real probe),
|
||||
// - our issued-code prefixes (SUB- / SUBSESS-),
|
||||
// - ANY read on a CONFIRMED RF channel (a physically present card, enrolled or
|
||||
// not, is a real event — RF is never sun noise),
|
||||
// - plates (different population; never shape-filtered here).
|
||||
|
||||
export class ReadDispatcher {
|
||||
readonly #db: Db;
|
||||
@@ -45,6 +63,20 @@ export class ReadDispatcher {
|
||||
if (sub) {
|
||||
return this.#subscription.run(resolved, e, sub);
|
||||
}
|
||||
|
||||
// Matched nothing — if the value can't even BE one of ours, it's scanner noise
|
||||
// (phantom optical decode): refuse with unsigned telemetry, keep the signed feed
|
||||
// for events that involve an actual credential or an actual card.
|
||||
if ((e.kind === "qr" || e.kind === "card" || e.kind === "ticket") && !plausibleCredential(e)) {
|
||||
this.#recordUnrecognized(e);
|
||||
this.#logger.info(`read filtered (not a credential shape): '${e.value}' from ${e.deviceId}${e.channel ? ` ch=${e.channel}` : ""}`);
|
||||
return {
|
||||
accepted: false,
|
||||
direction: resolved.direction === "entry" ? "entry" : "exit",
|
||||
reason: "unrecognized code (no credential shape — telemetry only)",
|
||||
};
|
||||
}
|
||||
|
||||
// Not a subscription → transient ticket exit. An ENTRY reader can't produce a
|
||||
// transient exit (transient entry is the button flow, not a reader), so reject+log
|
||||
// rather than treat an entry scan as an exit.
|
||||
@@ -53,4 +85,39 @@ export class ReadDispatcher {
|
||||
}
|
||||
return this.#exit.handleAt(resolved, e);
|
||||
}
|
||||
|
||||
/** Unsigned telemetry for a filtered read — auditable in device_events, out of the
|
||||
* signed feed. Mirrors the entry flow's suppressed-press pattern. */
|
||||
#recordUnrecognized(e: DeviceReadEvent): void {
|
||||
try {
|
||||
this.#db
|
||||
.insert(deviceEventsTable)
|
||||
.values({
|
||||
id: randomUUID(),
|
||||
deviceId: e.deviceId,
|
||||
category: "reader",
|
||||
kind: "read",
|
||||
detail: {
|
||||
unrecognizedRead: true,
|
||||
value: e.value,
|
||||
readKind: e.kind,
|
||||
...(e.channel ? { channel: e.channel } : {}),
|
||||
reason: "no credential shape (phantom decode / garbage scan)",
|
||||
},
|
||||
occurredAt: e.at,
|
||||
})
|
||||
.run();
|
||||
} catch (err) {
|
||||
this.#logger.error(`unrecognized-read telemetry insert failed: ${(err as Error).message}`);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
/** Could this reader value possibly be a credential WE issued (or a real card)?
|
||||
* Deliberately WIDE — only shapes that can't be anything of ours are filtered. */
|
||||
function plausibleCredential(e: DeviceReadEvent): boolean {
|
||||
if (e.channel === "rf") return true; // a physically present card — never sun noise
|
||||
if (validateTicketCode(e.value)) return true; // ticket shape (10–14 digits + Luhn)
|
||||
if (/^SUB(SESS)?-/.test(e.value)) return true; // our subscription QR / window-slip ids
|
||||
return false;
|
||||
}
|
||||
|
||||
@@ -0,0 +1,189 @@
|
||||
import { beforeEach, describe, expect, it } from "vitest";
|
||||
import { randomUUID } from "node:crypto";
|
||||
import {
|
||||
eq,
|
||||
isNull,
|
||||
roles,
|
||||
rolePermissions,
|
||||
subscriptionCredentials,
|
||||
subscriptionPlans,
|
||||
subscriptions,
|
||||
tariffs,
|
||||
users,
|
||||
type Db,
|
||||
} from "@parking/db";
|
||||
import { createTestDb } from "@parking/db/testing";
|
||||
import {
|
||||
listRecycleBin,
|
||||
purge,
|
||||
restore,
|
||||
restoreBlockedReason,
|
||||
softDelete,
|
||||
sweepExpired,
|
||||
} from "./recycle-bin.js";
|
||||
|
||||
// Soft delete / recycle bin. Pins: a delete STAMPS (keeps the row), the bin lists
|
||||
// soft-deleted items across kinds, restore brings them back, purge does the real
|
||||
// DELETE (+ children), a restore that would collide with a live row is blocked, and the
|
||||
// retention sweep purges only items past the window.
|
||||
|
||||
let db: Db;
|
||||
beforeEach(() => {
|
||||
({ db } = createTestDb());
|
||||
});
|
||||
|
||||
function seedUser(username: string): string {
|
||||
const id = randomUUID();
|
||||
db.insert(roles).values({ id: "admin", name: "admin", builtin: 1 }).onConflictDoNothing().run();
|
||||
db.insert(users).values({ id, username, passwordHash: "x", roleId: "admin" }).run();
|
||||
return id;
|
||||
}
|
||||
function seedRole(name: string): string {
|
||||
const id = randomUUID();
|
||||
db.insert(roles).values({ id, name, builtin: 0 }).run();
|
||||
db.insert(rolePermissions).values({ roleId: id, permission: "site:read" }).run();
|
||||
return id;
|
||||
}
|
||||
function seedSubscription(holder: string): string {
|
||||
const id = randomUUID();
|
||||
db.insert(subscriptions).values({ id, holderName: holder, period: "month" }).run();
|
||||
db.insert(subscriptionCredentials).values({ id: randomUUID(), subscriptionId: id, kind: "qr", value: `qr-${id}` }).run();
|
||||
return id;
|
||||
}
|
||||
function seedPlan(planId: string, versions = 2): void {
|
||||
for (let i = 0; i < versions; i++) {
|
||||
db.insert(subscriptionPlans).values({
|
||||
id: randomUUID(),
|
||||
planId,
|
||||
name: planId,
|
||||
period: "month",
|
||||
pricePerPeriodMinor: 100000,
|
||||
currency: "ALL",
|
||||
effectiveFrom: `2026-0${i + 1}-01T00:00:00.000Z`,
|
||||
}).run();
|
||||
}
|
||||
}
|
||||
|
||||
describe("softDelete + restore + purge", () => {
|
||||
it("stamps the row instead of removing it, and hides it from a live query", () => {
|
||||
const id = seedUser("alice");
|
||||
expect(softDelete(db, "user", id, "admin-1")).toBe(true);
|
||||
|
||||
const row = db.select().from(users).where(eq(users.id, id)).get();
|
||||
expect(row).toBeDefined(); // still there
|
||||
expect(row?.deletedAt).toBeTruthy();
|
||||
expect(row?.deletedBy).toBe("admin-1");
|
||||
// A live-only query no longer sees it.
|
||||
expect(db.select().from(users).where(isNull(users.deletedAt)).all()).toHaveLength(0);
|
||||
});
|
||||
|
||||
it("soft-deleting an already-deleted row is a no-op (returns false)", () => {
|
||||
const id = seedUser("bob");
|
||||
expect(softDelete(db, "user", id, "a")).toBe(true);
|
||||
expect(softDelete(db, "user", id, "a")).toBe(false);
|
||||
});
|
||||
|
||||
it("restore clears the stamps and brings the row back to the live set", () => {
|
||||
const id = seedRole("valet");
|
||||
softDelete(db, "role", id, "a");
|
||||
expect(restore(db, "role", id)).toBe(true);
|
||||
const row = db.select().from(roles).where(eq(roles.id, id)).get();
|
||||
expect(row?.deletedAt).toBeNull();
|
||||
expect(db.select().from(roles).where(isNull(roles.deletedAt)).all().map((r) => r.id)).toContain(id);
|
||||
});
|
||||
|
||||
it("purge removes a soft-deleted row + its children; refuses a LIVE row", () => {
|
||||
const id = seedSubscription("carlos");
|
||||
// Cannot purge while live (purge only touches soft-deleted rows).
|
||||
expect(purge(db, "subscription", id)).toBe(false);
|
||||
expect(db.select().from(subscriptions).where(eq(subscriptions.id, id)).get()).toBeDefined();
|
||||
|
||||
softDelete(db, "subscription", id, "a");
|
||||
expect(purge(db, "subscription", id)).toBe(true);
|
||||
expect(db.select().from(subscriptions).where(eq(subscriptions.id, id)).get()).toBeUndefined();
|
||||
// Children gone too.
|
||||
expect(db.select().from(subscriptionCredentials).where(eq(subscriptionCredentials.subscriptionId, id)).all()).toHaveLength(0);
|
||||
});
|
||||
});
|
||||
|
||||
describe("versioned plans", () => {
|
||||
it("soft-deletes / restores / purges ALL versions of a planId together", () => {
|
||||
seedPlan("hotel-daily", 3);
|
||||
expect(softDelete(db, "plan", "hotel-daily", "a")).toBe(true);
|
||||
expect(db.select().from(subscriptionPlans).where(isNull(subscriptionPlans.deletedAt)).all()).toHaveLength(0);
|
||||
|
||||
// The bin lists the plan as ONE item, not three.
|
||||
const planItems = listRecycleBin(db).filter((i) => i.kind === "plan");
|
||||
expect(planItems).toHaveLength(1);
|
||||
expect(planItems[0]?.id).toBe("hotel-daily");
|
||||
|
||||
expect(restore(db, "plan", "hotel-daily")).toBe(true);
|
||||
expect(db.select().from(subscriptionPlans).where(isNull(subscriptionPlans.deletedAt)).all()).toHaveLength(3);
|
||||
|
||||
softDelete(db, "plan", "hotel-daily", "a");
|
||||
expect(purge(db, "plan", "hotel-daily")).toBe(true);
|
||||
expect(db.select().from(subscriptionPlans).all()).toHaveLength(0);
|
||||
});
|
||||
});
|
||||
|
||||
describe("listRecycleBin", () => {
|
||||
it("collects soft-deleted items across every kind, newest-deleted first", () => {
|
||||
const u = seedUser("dora");
|
||||
const r = seedRole("guard");
|
||||
const t = randomUUID();
|
||||
db.insert(tariffs).values({ id: t, scope: "site", name: "Site" }).run();
|
||||
|
||||
softDelete(db, "user", u, "a");
|
||||
softDelete(db, "role", r, "a");
|
||||
softDelete(db, "tariff", t, "a");
|
||||
|
||||
const items = listRecycleBin(db);
|
||||
expect(items.map((i) => i.kind).sort()).toEqual(["role", "tariff", "user"]);
|
||||
// Each carries a human label + the deletedAt stamp.
|
||||
expect(items.find((i) => i.kind === "user")?.label).toBe("dora");
|
||||
expect(items.every((i) => i.deletedAt)).toBe(true);
|
||||
});
|
||||
});
|
||||
|
||||
describe("restoreBlockedReason", () => {
|
||||
// NB: the DB `username`/`name` UNIQUE spans live AND soft-deleted rows, so a live
|
||||
// duplicate can't even be INSERTed while the deleted one exists (the create route
|
||||
// returns a clear 409 instead — see routes/users.ts). restoreBlockedReason is a
|
||||
// belt-and-suspenders guard at restore time; verify it returns null in the normal
|
||||
// case (nothing colliding) so a clean restore is never wrongly blocked.
|
||||
it("does not block a normal restore (no live collision)", () => {
|
||||
const u = seedUser("eve");
|
||||
softDelete(db, "user", u, "a");
|
||||
expect(restoreBlockedReason(db, "user", u)).toBeNull();
|
||||
|
||||
const r = seedRole("cleaner");
|
||||
softDelete(db, "role", r, "a");
|
||||
expect(restoreBlockedReason(db, "role", r)).toBeNull();
|
||||
});
|
||||
});
|
||||
|
||||
describe("sweepExpired (retention)", () => {
|
||||
it("purges items deleted longer than the window ago, keeps recent ones", () => {
|
||||
const old = seedUser("old");
|
||||
const fresh = seedUser("fresh");
|
||||
softDelete(db, "user", old, "a");
|
||||
softDelete(db, "user", fresh, "a");
|
||||
// Backdate `old`'s deletion to 40 days ago.
|
||||
const longAgo = new Date(Date.now() - 40 * 86_400_000).toISOString();
|
||||
db.update(users).set({ deletedAt: longAgo }).where(eq(users.id, old)).run();
|
||||
|
||||
const purged = sweepExpired(db, 30);
|
||||
expect(purged.user).toBe(1);
|
||||
expect(db.select().from(users).where(eq(users.id, old)).get()).toBeUndefined();
|
||||
expect(db.select().from(users).where(eq(users.id, fresh)).get()).toBeDefined();
|
||||
});
|
||||
|
||||
it("days <= 0 disables the sweep (keep forever)", () => {
|
||||
const id = seedUser("keeper");
|
||||
softDelete(db, "user", id, "a");
|
||||
db.update(users).set({ deletedAt: new Date(Date.now() - 999 * 86_400_000).toISOString() }).where(eq(users.id, id)).run();
|
||||
const purged = sweepExpired(db, 0);
|
||||
expect(purged.user).toBe(0);
|
||||
expect(db.select().from(users).where(eq(users.id, id)).get()).toBeDefined();
|
||||
});
|
||||
});
|
||||
@@ -0,0 +1,206 @@
|
||||
import {
|
||||
and,
|
||||
eq,
|
||||
isNotNull,
|
||||
isNull,
|
||||
lte,
|
||||
rolePermissions,
|
||||
roles,
|
||||
subscriptionCredentials,
|
||||
subscriptionPlans,
|
||||
subscriptionPlates,
|
||||
subscriptions,
|
||||
tariffs,
|
||||
users,
|
||||
type Db,
|
||||
} from "@parking/db";
|
||||
|
||||
// Soft delete + recycle bin. Accidental hard-deletes of master data (a user, role,
|
||||
// subscription, plan, tariff) used to be unrecoverable. Now a DELETE STAMPS the row
|
||||
// (`deleted_at` = now, `deleted_by` = admin) instead of removing it; it disappears from
|
||||
// every catalog (the list queries filter `deleted_at IS NULL`) but survives in the
|
||||
// recycle bin, where an admin can RESTORE it (clear the stamps) or PURGE it (the real
|
||||
// DELETE). A retention sweep auto-purges items deleted longer than the window ago.
|
||||
//
|
||||
// Scope: only the MUTABLE master-data tables below. The signed, append-only ledger is
|
||||
// NOT here — it has no delete path by design. See wiki/concepts/soft-delete.md.
|
||||
|
||||
/** The soft-deletable resource kinds, as they appear in the recycle-bin API. */
|
||||
export type ResourceKind = "user" | "role" | "subscription" | "plan" | "tariff";
|
||||
|
||||
export const RESOURCE_KINDS: ResourceKind[] = ["user", "role", "subscription", "plan", "tariff"];
|
||||
|
||||
/** Default retention window before a soft-deleted item is auto-purged (days). Override
|
||||
* with RECYCLE_BIN_RETENTION_DAYS. 0/negative disables the sweep (keep forever). */
|
||||
export function retentionDays(): number {
|
||||
const raw = Number(process.env.RECYCLE_BIN_RETENTION_DAYS ?? 30);
|
||||
return Number.isFinite(raw) ? raw : 30;
|
||||
}
|
||||
|
||||
/** A row surfaced in the recycle bin (normalised across resource kinds). */
|
||||
export interface RecycleBinItem {
|
||||
readonly kind: ResourceKind;
|
||||
/** The id used to restore/purge. For a versioned PLAN this is the stable planId. */
|
||||
readonly id: string;
|
||||
/** Human label for the list (username, role/plan/tariff name, subscriber holder). */
|
||||
readonly label: string;
|
||||
readonly deletedAt: string;
|
||||
readonly deletedBy: string | null;
|
||||
}
|
||||
|
||||
const NOW = () => new Date().toISOString();
|
||||
|
||||
// --- Per-resource helpers ----------------------------------------------------
|
||||
// Subscriptions/users/roles/tariffs are 1 row per id. PLANS are versioned (N rows per
|
||||
// plan_id) — stamp/clear/delete ALL versions of the plan_id together.
|
||||
|
||||
/** Soft-delete a row by id. Returns false if no live row matched (404). PLAN uses planId. */
|
||||
export function softDelete(db: Db, kind: ResourceKind, id: string, byUserId: string): boolean {
|
||||
const stamp = { deletedAt: NOW(), deletedBy: byUserId };
|
||||
switch (kind) {
|
||||
case "user":
|
||||
return db.update(users).set(stamp).where(and(eq(users.id, id), isNull(users.deletedAt))).run().changes > 0;
|
||||
case "role":
|
||||
return db.update(roles).set(stamp).where(and(eq(roles.id, id), isNull(roles.deletedAt))).run().changes > 0;
|
||||
case "subscription":
|
||||
return db.update(subscriptions).set(stamp).where(and(eq(subscriptions.id, id), isNull(subscriptions.deletedAt))).run().changes > 0;
|
||||
case "plan":
|
||||
return db.update(subscriptionPlans).set(stamp).where(and(eq(subscriptionPlans.planId, id), isNull(subscriptionPlans.deletedAt))).run().changes > 0;
|
||||
case "tariff":
|
||||
return db.update(tariffs).set(stamp).where(and(eq(tariffs.id, id), isNull(tariffs.deletedAt))).run().changes > 0;
|
||||
}
|
||||
}
|
||||
|
||||
/** Restore a soft-deleted row (clear the stamps). Returns false if nothing was restored. */
|
||||
export function restore(db: Db, kind: ResourceKind, id: string): boolean {
|
||||
const clear = { deletedAt: null, deletedBy: null };
|
||||
switch (kind) {
|
||||
case "user":
|
||||
return db.update(users).set(clear).where(and(eq(users.id, id), isNotNull(users.deletedAt))).run().changes > 0;
|
||||
case "role":
|
||||
return db.update(roles).set(clear).where(and(eq(roles.id, id), isNotNull(roles.deletedAt))).run().changes > 0;
|
||||
case "subscription":
|
||||
return db.update(subscriptions).set(clear).where(and(eq(subscriptions.id, id), isNotNull(subscriptions.deletedAt))).run().changes > 0;
|
||||
case "plan":
|
||||
return db.update(subscriptionPlans).set(clear).where(and(eq(subscriptionPlans.planId, id), isNotNull(subscriptionPlans.deletedAt))).run().changes > 0;
|
||||
case "tariff":
|
||||
return db.update(tariffs).set(clear).where(and(eq(tariffs.id, id), isNotNull(tariffs.deletedAt))).run().changes > 0;
|
||||
}
|
||||
}
|
||||
|
||||
/** True if restoring would collide with a LIVE row (e.g. a user with the same username
|
||||
* was re-created after the delete). The caller turns this into a 409 so the admin
|
||||
* understands why restore is blocked. */
|
||||
export function restoreBlockedReason(db: Db, kind: ResourceKind, id: string): string | null {
|
||||
if (kind === "user") {
|
||||
const row = db.select().from(users).where(eq(users.id, id)).get();
|
||||
if (row && db.select().from(users).where(and(eq(users.username, row.username), isNull(users.deletedAt))).get()) {
|
||||
return `a live user named "${row.username}" already exists`;
|
||||
}
|
||||
} else if (kind === "role") {
|
||||
const row = db.select().from(roles).where(eq(roles.id, id)).get();
|
||||
if (row && db.select().from(roles).where(and(eq(roles.name, row.name), isNull(roles.deletedAt))).get()) {
|
||||
return `a live role named "${row.name}" already exists`;
|
||||
}
|
||||
}
|
||||
return null;
|
||||
}
|
||||
|
||||
// --- Restore ordering note --------------------------------------------------
|
||||
// A restored USER points at a roleId; if that role is itself deleted, the user reappears
|
||||
// with a dangling role. We don't auto-cascade (keep it predictable); the bin lists both
|
||||
// and the admin restores the role too. The role guard already resolves a missing role to
|
||||
// an empty permission set (safe-by-default), so a dangling role never escalates.
|
||||
|
||||
/** Hard-delete (purge) a soft-deleted row + its children. The real DELETE. Returns false
|
||||
* if no soft-deleted row matched (so you can't purge a live row through this path). */
|
||||
export function purge(db: Db, kind: ResourceKind, id: string): boolean {
|
||||
switch (kind) {
|
||||
case "user":
|
||||
return db.delete(users).where(and(eq(users.id, id), isNotNull(users.deletedAt))).run().changes > 0;
|
||||
case "role": {
|
||||
// Children (role_permissions) only matter once the role row is gone; purge both.
|
||||
const ok = db.delete(roles).where(and(eq(roles.id, id), isNotNull(roles.deletedAt))).run().changes > 0;
|
||||
if (ok) deleteRolePermissions(db, id);
|
||||
return ok;
|
||||
}
|
||||
case "subscription": {
|
||||
const ok = db.delete(subscriptions).where(and(eq(subscriptions.id, id), isNotNull(subscriptions.deletedAt))).run().changes > 0;
|
||||
if (ok) deleteSubscriptionChildren(db, id);
|
||||
return ok;
|
||||
}
|
||||
case "plan":
|
||||
return db.delete(subscriptionPlans).where(and(eq(subscriptionPlans.planId, id), isNotNull(subscriptionPlans.deletedAt))).run().changes > 0;
|
||||
case "tariff":
|
||||
return db.delete(tariffs).where(and(eq(tariffs.id, id), isNotNull(tariffs.deletedAt))).run().changes > 0;
|
||||
}
|
||||
}
|
||||
|
||||
// Child cleanup on purge (role_permissions / subscription credentials + plates).
|
||||
function deleteRolePermissions(db: Db, roleId: string): void {
|
||||
db.delete(rolePermissions).where(eq(rolePermissions.roleId, roleId)).run();
|
||||
}
|
||||
function deleteSubscriptionChildren(db: Db, id: string): void {
|
||||
db.delete(subscriptionCredentials).where(eq(subscriptionCredentials.subscriptionId, id)).run();
|
||||
db.delete(subscriptionPlates).where(eq(subscriptionPlates.subscriptionId, id)).run();
|
||||
}
|
||||
|
||||
// --- Listing the bin --------------------------------------------------------
|
||||
|
||||
/** All soft-deleted items across every resource kind, newest-deleted first. */
|
||||
export function listRecycleBin(db: Db): RecycleBinItem[] {
|
||||
const items: RecycleBinItem[] = [];
|
||||
|
||||
for (const r of db.select().from(users).where(isNotNull(users.deletedAt)).all()) {
|
||||
items.push({ kind: "user", id: r.id, label: r.fullName || r.username, deletedAt: r.deletedAt!, deletedBy: r.deletedBy });
|
||||
}
|
||||
for (const r of db.select().from(roles).where(isNotNull(roles.deletedAt)).all()) {
|
||||
items.push({ kind: "role", id: r.id, label: r.name, deletedAt: r.deletedAt!, deletedBy: r.deletedBy });
|
||||
}
|
||||
for (const r of db.select().from(subscriptions).where(isNotNull(subscriptions.deletedAt)).all()) {
|
||||
items.push({ kind: "subscription", id: r.id, label: r.holderName || r.id, deletedAt: r.deletedAt!, deletedBy: r.deletedBy });
|
||||
}
|
||||
// Plans are versioned: collapse to one item per plan_id (the latest version's name).
|
||||
const planSeen = new Set<string>();
|
||||
const planRows = db.select().from(subscriptionPlans).where(isNotNull(subscriptionPlans.deletedAt)).all();
|
||||
planRows.sort((a, b) => b.effectiveFrom.localeCompare(a.effectiveFrom));
|
||||
for (const r of planRows) {
|
||||
if (planSeen.has(r.planId)) continue;
|
||||
planSeen.add(r.planId);
|
||||
items.push({ kind: "plan", id: r.planId, label: r.name, deletedAt: r.deletedAt!, deletedBy: r.deletedBy });
|
||||
}
|
||||
for (const r of db.select().from(tariffs).where(isNotNull(tariffs.deletedAt)).all()) {
|
||||
items.push({ kind: "tariff", id: r.id, label: r.name, deletedAt: r.deletedAt!, deletedBy: r.deletedBy });
|
||||
}
|
||||
|
||||
return items.sort((a, b) => b.deletedAt.localeCompare(a.deletedAt));
|
||||
}
|
||||
|
||||
// --- Retention sweep --------------------------------------------------------
|
||||
|
||||
/** Purge every soft-deleted row deleted more than `retentionDays()` ago. Returns the
|
||||
* count purged per kind. Safe to call repeatedly (idempotent). */
|
||||
export function sweepExpired(db: Db, days = retentionDays()): Record<ResourceKind, number> {
|
||||
const out: Record<ResourceKind, number> = { user: 0, role: 0, subscription: 0, plan: 0, tariff: 0 };
|
||||
if (!Number.isFinite(days) || days <= 0) return out; // keep-forever
|
||||
const cutoff = new Date(Date.now() - days * 86_400_000).toISOString();
|
||||
|
||||
// Collect ids first so children purge through the same path as a manual purge.
|
||||
for (const r of db.select().from(users).where(and(isNotNull(users.deletedAt), lte(users.deletedAt, cutoff))).all()) {
|
||||
if (purge(db, "user", r.id)) out.user++;
|
||||
}
|
||||
for (const r of db.select().from(roles).where(and(isNotNull(roles.deletedAt), lte(roles.deletedAt, cutoff))).all()) {
|
||||
if (purge(db, "role", r.id)) out.role++;
|
||||
}
|
||||
for (const r of db.select().from(subscriptions).where(and(isNotNull(subscriptions.deletedAt), lte(subscriptions.deletedAt, cutoff))).all()) {
|
||||
if (purge(db, "subscription", r.id)) out.subscription++;
|
||||
}
|
||||
const planIds = new Set(
|
||||
db.select().from(subscriptionPlans).where(and(isNotNull(subscriptionPlans.deletedAt), lte(subscriptionPlans.deletedAt, cutoff))).all().map((r) => r.planId),
|
||||
);
|
||||
for (const planId of planIds) if (purge(db, "plan", planId)) out.plan++;
|
||||
for (const r of db.select().from(tariffs).where(and(isNotNull(tariffs.deletedAt), lte(tariffs.deletedAt, cutoff))).all()) {
|
||||
if (purge(db, "tariff", r.id)) out.tariff++;
|
||||
}
|
||||
return out;
|
||||
}
|
||||
@@ -0,0 +1,248 @@
|
||||
import { beforeEach, describe, expect, it } from "vitest";
|
||||
import { sessions, siteConfig, subscriptions, type Db } from "@parking/db";
|
||||
import { createTestDb } from "@parking/db/testing";
|
||||
import { randomUUID } from "node:crypto";
|
||||
import { makeLog } from "./test-helpers.js";
|
||||
import { reportSummary } from "./reports.js";
|
||||
import type { EventLog } from "./event-log.js";
|
||||
|
||||
// Reports aggregation — LEDGER-FIRST. These pin that the numbers an admin sees are
|
||||
// summed straight from the signed ledger (entry/exit counts + payment money, split the
|
||||
// same way the shift Z-report splits it), bucketed in the SITE TIMEZONE, with duration
|
||||
// stats from the closed-sessions cache and subscription counts as of the range end.
|
||||
|
||||
let db: Db;
|
||||
let log: EventLog;
|
||||
|
||||
beforeEach(() => {
|
||||
({ db } = createTestDb());
|
||||
log = makeLog(db);
|
||||
// Fix the site timezone so bucket labels are deterministic regardless of the test host.
|
||||
db.insert(siteConfig).values({ id: 1, timezone: "Europe/Tirane" }).run();
|
||||
});
|
||||
|
||||
/** ISO at a UTC instant, for deterministic bucket assertions. */
|
||||
function at(iso: string): string {
|
||||
return new Date(iso).toISOString();
|
||||
}
|
||||
|
||||
async function entry(occurredAt: string): Promise<void> {
|
||||
await log.append({ type: "vehicle_entry", direction: "entry", identity: randomUUID(), occurredAt });
|
||||
}
|
||||
async function exit(occurredAt: string): Promise<void> {
|
||||
await log.append({ type: "vehicle_exit", direction: "exit", identity: randomUUID(), occurredAt });
|
||||
}
|
||||
async function payment(
|
||||
occurredAt: string,
|
||||
amountMinor: number,
|
||||
opts: { tender?: "cash" | "card"; subscriptionSale?: boolean; subscriptionWindowCharge?: boolean } = {},
|
||||
): Promise<void> {
|
||||
await log.append({
|
||||
type: "payment",
|
||||
occurredAt,
|
||||
payload: {
|
||||
amountMinor,
|
||||
currency: "ALL",
|
||||
tender: opts.tender ?? "cash",
|
||||
...(opts.subscriptionSale ? { subscriptionSale: true } : {}),
|
||||
...(opts.subscriptionWindowCharge ? { subscriptionWindowCharge: true } : {}),
|
||||
},
|
||||
});
|
||||
}
|
||||
|
||||
const RANGE = { from: at("2026-06-01T00:00:00Z"), to: at("2026-06-30T23:59:59Z") };
|
||||
|
||||
describe("reportSummary — ledger-first totals", () => {
|
||||
it("counts entries and exits from the signed ledger", async () => {
|
||||
await entry(at("2026-06-10T08:00:00Z"));
|
||||
await entry(at("2026-06-10T09:00:00Z"));
|
||||
await exit(at("2026-06-10T18:00:00Z"));
|
||||
|
||||
const r = reportSummary(db, { ...RANGE, bucket: "day" });
|
||||
expect(r.totals.entries).toBe(2);
|
||||
expect(r.totals.exits).toBe(1);
|
||||
});
|
||||
|
||||
it("excludes events outside [from, to)", async () => {
|
||||
await entry(at("2026-05-31T23:00:00Z")); // before
|
||||
await entry(at("2026-06-15T10:00:00Z")); // inside
|
||||
const r = reportSummary(db, { ...RANGE, bucket: "day" });
|
||||
expect(r.totals.entries).toBe(1);
|
||||
});
|
||||
|
||||
it("sums payment money and splits cash vs card", async () => {
|
||||
await payment(at("2026-06-12T10:00:00Z"), 20000, { tender: "cash" });
|
||||
await payment(at("2026-06-12T11:00:00Z"), 5000, { tender: "card" });
|
||||
const r = reportSummary(db, { ...RANGE, bucket: "day" });
|
||||
expect(r.totals.payments).toBe(2);
|
||||
expect(r.totals.revenueMinor).toBe(25000);
|
||||
expect(r.totals.cashMinor).toBe(20000);
|
||||
expect(r.totals.cardMinor).toBe(5000);
|
||||
});
|
||||
|
||||
it("splits revenue into ticket / subscription-sale / out-of-window, mirroring the Z-report", async () => {
|
||||
await payment(at("2026-06-12T10:00:00Z"), 10000); // transient ticket
|
||||
await payment(at("2026-06-12T10:05:00Z"), 30000, { subscriptionSale: true });
|
||||
await payment(at("2026-06-12T10:06:00Z"), 1500, { subscriptionWindowCharge: true });
|
||||
const r = reportSummary(db, { ...RANGE, bucket: "day" });
|
||||
expect(r.totals.ticketMinor).toBe(10000);
|
||||
expect(r.totals.subscriptionSalesMinor).toBe(30000);
|
||||
expect(r.totals.subscriptionWindowMinor).toBe(1500);
|
||||
// The three add up to the gross revenue.
|
||||
expect(r.totals.revenueMinor).toBe(41500);
|
||||
});
|
||||
|
||||
it("picks up the currency from a payment in range", async () => {
|
||||
await payment(at("2026-06-12T10:00:00Z"), 10000);
|
||||
const r = reportSummary(db, { ...RANGE, bucket: "day" });
|
||||
expect(r.currency).toBe("ALL");
|
||||
});
|
||||
});
|
||||
|
||||
describe("reportSummary — time bucketing (site timezone)", () => {
|
||||
it("buckets by local day; a 23:30 UTC event lands on the NEXT local day in Tirane (UTC+2/3)", async () => {
|
||||
// 2026-06-15T23:30Z is 2026-06-16 01:30 local (summer, UTC+2) → the 16th bucket.
|
||||
await entry(at("2026-06-15T23:30:00Z"));
|
||||
const r = reportSummary(db, { ...RANGE, bucket: "day" });
|
||||
const point = r.series.find((p) => p.entries > 0);
|
||||
expect(point?.bucket).toBe("2026-06-16");
|
||||
});
|
||||
|
||||
it("series points are sorted and carry per-bucket entries/exits/revenue", async () => {
|
||||
await entry(at("2026-06-10T08:00:00Z"));
|
||||
await payment(at("2026-06-10T09:00:00Z"), 7000);
|
||||
await entry(at("2026-06-12T08:00:00Z"));
|
||||
const r = reportSummary(db, { ...RANGE, bucket: "day" });
|
||||
const labels = r.series.map((p) => p.bucket);
|
||||
expect(labels).toEqual([...labels].sort());
|
||||
const d10 = r.series.find((p) => p.bucket === "2026-06-10");
|
||||
expect(d10?.entries).toBe(1);
|
||||
expect(d10?.revenueMinor).toBe(7000);
|
||||
});
|
||||
|
||||
it("entriesByHour is a 24-slot local-hour histogram", async () => {
|
||||
// 06:00Z = 08:00 local (summer) → hour slot 8.
|
||||
await entry(at("2026-06-10T06:00:00Z"));
|
||||
await entry(at("2026-06-11T06:00:00Z"));
|
||||
const r = reportSummary(db, { ...RANGE, bucket: "day" });
|
||||
expect(r.entriesByHour).toHaveLength(24);
|
||||
expect(r.entriesByHour[8]).toBe(2);
|
||||
expect(r.entriesByHour.reduce((a, b) => a + b, 0)).toBe(2);
|
||||
});
|
||||
});
|
||||
|
||||
describe("reportSummary — duration (sessions cache) + subscriptions", () => {
|
||||
it("computes parked-minute stats from closed sessions whose exit fell in range", async () => {
|
||||
// 60-min and 120-min stays → avg 90, median 90.
|
||||
db.insert(sessions).values({
|
||||
id: "s1",
|
||||
identity: "t1",
|
||||
enteredAt: at("2026-06-10T08:00:00Z"),
|
||||
exitedAt: at("2026-06-10T09:00:00Z"),
|
||||
state: "closed",
|
||||
}).run();
|
||||
db.insert(sessions).values({
|
||||
id: "s2",
|
||||
identity: "t2",
|
||||
enteredAt: at("2026-06-10T08:00:00Z"),
|
||||
exitedAt: at("2026-06-10T10:00:00Z"),
|
||||
state: "closed",
|
||||
}).run();
|
||||
// An OPEN session (no exit) must not count.
|
||||
db.insert(sessions).values({ id: "s3", identity: "t3", enteredAt: at("2026-06-10T08:00:00Z"), state: "open" }).run();
|
||||
|
||||
const r = reportSummary(db, { ...RANGE, bucket: "day" });
|
||||
expect(r.totals.closedSessions).toBe(2);
|
||||
expect(r.totals.totalParkedMinutes).toBe(180);
|
||||
expect(r.totals.avgParkedMinutes).toBe(90);
|
||||
expect(r.totals.medianParkedMinutes).toBe(90);
|
||||
});
|
||||
|
||||
it("counts subscriptions by status and currently-valid coverage as of `to`", async () => {
|
||||
const base = { holderName: "x", period: "month" as const, createdAt: at("2026-06-01T00:00:00Z") };
|
||||
// active + valid window covering `to`, quantity 2.
|
||||
db.insert(subscriptions).values({
|
||||
id: "a", status: "active", quantity: 2,
|
||||
validFrom: at("2026-06-01T00:00:00Z"), validTo: at("2026-07-01T00:00:00Z"), ...base,
|
||||
}).run();
|
||||
// active but EXPIRED before `to` → not currently valid.
|
||||
db.insert(subscriptions).values({
|
||||
id: "b", status: "active", quantity: 1,
|
||||
validFrom: at("2026-05-01T00:00:00Z"), validTo: at("2026-06-05T00:00:00Z"), ...base,
|
||||
}).run();
|
||||
// suspended.
|
||||
db.insert(subscriptions).values({ id: "c", status: "suspended", quantity: 1, ...base }).run();
|
||||
|
||||
const r = reportSummary(db, { ...RANGE, bucket: "day" });
|
||||
expect(r.subscriptions.active).toBe(2);
|
||||
expect(r.subscriptions.suspended).toBe(1);
|
||||
expect(r.subscriptions.revoked).toBe(0);
|
||||
expect(r.subscriptions.currentlyValid).toBe(1);
|
||||
expect(r.subscriptions.coveredCars).toBe(2);
|
||||
});
|
||||
});
|
||||
|
||||
describe("reportSummary — occupancy, heatmap, stay histogram, look-closer counters (2026-07-05)", () => {
|
||||
it("folds prior ledger into occupancyStart and walks occupancyEnd through the series", async () => {
|
||||
// Before the range: 3 entries, 1 exit → 2 cars inside when June opens.
|
||||
await entry(at("2026-05-20T08:00:00Z"));
|
||||
await entry(at("2026-05-20T09:00:00Z"));
|
||||
await entry(at("2026-05-21T10:00:00Z"));
|
||||
await exit(at("2026-05-21T12:00:00Z"));
|
||||
// In range: +2 on the 10th, −1 on the 11th.
|
||||
await entry(at("2026-06-10T08:00:00Z"));
|
||||
await entry(at("2026-06-10T09:00:00Z"));
|
||||
await exit(at("2026-06-11T09:00:00Z"));
|
||||
|
||||
const r = reportSummary(db, { ...RANGE, bucket: "day" });
|
||||
expect(r.occupancyStart).toBe(2);
|
||||
expect(r.series.map((p) => [p.bucket, p.occupancyEnd])).toEqual([
|
||||
["2026-06-10", 4],
|
||||
["2026-06-11", 3],
|
||||
]);
|
||||
});
|
||||
|
||||
it("a voided pre-range entry does not inflate occupancyStart", async () => {
|
||||
const id = randomUUID();
|
||||
await log.append({ type: "vehicle_entry", direction: "entry", identity: id, occurredAt: at("2026-05-20T08:00:00Z") });
|
||||
await log.append({ type: "void", identity: id, occurredAt: at("2026-05-20T08:05:00Z"), payload: { reason: "misprint" } });
|
||||
const r = reportSummary(db, { ...RANGE, bucket: "day" });
|
||||
expect(r.occupancyStart).toBe(0);
|
||||
});
|
||||
|
||||
it("entriesByDowHour lands on the local weekday/hour (row 0 = Monday)", async () => {
|
||||
// 2026-06-10 is a WEDNESDAY; 08:00Z = 10:00 in Tirane (UTC+2 in June).
|
||||
await entry(at("2026-06-10T08:00:00Z"));
|
||||
const r = reportSummary(db, { ...RANGE, bucket: "day" });
|
||||
expect(r.entriesByDowHour[2]![10]).toBe(1); // Wed row, 10h column
|
||||
expect(r.entriesByDowHour.flat().reduce((a, b) => a + b, 0)).toBe(1);
|
||||
});
|
||||
|
||||
it("stay histogram buckets closed sessions; series carries the cash/card split", async () => {
|
||||
db.insert(sessions).values({ id: "h1", identity: "h1", enteredAt: at("2026-06-10T08:00:00Z"), exitedAt: at("2026-06-10T08:20:00Z"), state: "closed" }).run(); // 20m → ≤30
|
||||
db.insert(sessions).values({ id: "h2", identity: "h2", enteredAt: at("2026-06-10T08:00:00Z"), exitedAt: at("2026-06-10T09:30:00Z"), state: "closed" }).run(); // 90m → ≤120
|
||||
db.insert(sessions).values({ id: "h3", identity: "h3", enteredAt: at("2026-06-08T08:00:00Z"), exitedAt: at("2026-06-10T09:00:00Z"), state: "closed" }).run(); // 2 days → >24h tail
|
||||
await payment(at("2026-06-10T09:00:00Z"), 500, { tender: "cash" });
|
||||
await payment(at("2026-06-10T09:30:00Z"), 700, { tender: "card" });
|
||||
|
||||
const r = reportSummary(db, { ...RANGE, bucket: "day" });
|
||||
const counts = Object.fromEntries(r.stayHistogram.map((b) => [String(b.uptoMin), b.count]));
|
||||
expect(counts["30"]).toBe(1);
|
||||
expect(counts["120"]).toBe(1);
|
||||
expect(counts["null"]).toBe(1);
|
||||
const day = r.series.find((p) => p.bucket === "2026-06-10")!;
|
||||
expect(day.cashMinor).toBe(500);
|
||||
expect(day.cardMinor).toBe(700);
|
||||
});
|
||||
|
||||
it("counts voids and anomalies in range (the look-closer counters)", async () => {
|
||||
const id = randomUUID();
|
||||
await log.append({ type: "vehicle_entry", direction: "entry", identity: id, occurredAt: at("2026-06-10T08:00:00Z") });
|
||||
await log.append({ type: "void", identity: id, occurredAt: at("2026-06-10T08:05:00Z"), payload: { reason: "misprint" } });
|
||||
await log.append({ type: "anomaly", identity: "X", occurredAt: at("2026-06-10T09:00:00Z"), payload: { reason: "test" } });
|
||||
const r = reportSummary(db, { ...RANGE, bucket: "day" });
|
||||
expect(r.totals.voids).toBe(1);
|
||||
expect(r.totals.anomalies).toBe(1);
|
||||
expect(r.totals.entries).toBe(0); // the voided entry stays excluded
|
||||
});
|
||||
});
|
||||
@@ -0,0 +1,379 @@
|
||||
import {
|
||||
and,
|
||||
asc,
|
||||
desc,
|
||||
eq,
|
||||
gte,
|
||||
lt,
|
||||
lte,
|
||||
ledgerEvents,
|
||||
sessions,
|
||||
siteConfig,
|
||||
subscriptions,
|
||||
tariffVersions,
|
||||
tariffs,
|
||||
type Db,
|
||||
} from "@parking/db";
|
||||
import { siteTz } from "./subscription-window.js";
|
||||
|
||||
// Admin reporting — LEDGER-FIRST aggregation (decision 2026-06-22). The numbers an
|
||||
// admin sees on the Reports page are summed from the SIGNED, hash-chained
|
||||
// ledger_events (vehicle_entry/exit + payment), the same source the shift Z-report
|
||||
// reconciles against — so a chart total always ties out to the drawer. Only the
|
||||
// duration/occupancy view leans on the derived `sessions` cache, where the ledger is
|
||||
// awkward (you'd have to pair every entry with its exit by hand); that's flagged as a
|
||||
// cache, not the financial truth. See wiki/concepts/reports.md, event-streams-split.md.
|
||||
//
|
||||
// All bucketing is in the SITE TIMEZONE (siteConfig.timezone) — a "day" is a local
|
||||
// calendar day, not a UTC one, so a 01:00-local payment lands on the right date and the
|
||||
// peak-hour chart reads in wall-clock. Pure date math on the stored ISO strings; no
|
||||
// floats (money is integer minor units throughout).
|
||||
|
||||
export type Bucket = "hour" | "day" | "month";
|
||||
|
||||
export interface ReportQuery {
|
||||
/** Inclusive lower bound (ISO instant). */
|
||||
readonly from: string;
|
||||
/** Exclusive upper bound (ISO instant). */
|
||||
readonly to: string;
|
||||
/** Time grain for the series. Default "day". */
|
||||
readonly bucket: Bucket;
|
||||
}
|
||||
|
||||
/** One point in a time series, keyed by its local-time bucket label (e.g. "2026-06-22"
|
||||
* for a day, "2026-06-22 14" for an hour). */
|
||||
export interface SeriesPoint {
|
||||
readonly bucket: string;
|
||||
readonly entries: number;
|
||||
readonly exits: number;
|
||||
/** Net transient revenue collected in the bucket (minor units), all tenders. */
|
||||
readonly revenueMinor: number;
|
||||
/** Tender split of the bucket's revenue (cash = everything not card). */
|
||||
readonly cashMinor: number;
|
||||
readonly cardMinor: number;
|
||||
/** Payment COUNT in the bucket (transactions, not amount). */
|
||||
readonly payments: number;
|
||||
/** Cars inside at the END of the bucket (occupancyStart + running entries−exits). */
|
||||
readonly occupancyEnd: number;
|
||||
}
|
||||
|
||||
export interface ReportTotals {
|
||||
readonly entries: number;
|
||||
readonly exits: number;
|
||||
readonly payments: number;
|
||||
readonly revenueMinor: number;
|
||||
readonly cashMinor: number;
|
||||
readonly cardMinor: number;
|
||||
/** Revenue split by what was sold. ticket = transient parking; subscriptionSales =
|
||||
* new/renewed subscriptions; subscriptionWindow = out-of-window tariff-bridge charges. */
|
||||
readonly ticketMinor: number;
|
||||
readonly subscriptionSalesMinor: number;
|
||||
readonly subscriptionWindowMinor: number;
|
||||
/** Closed transient sessions in range + their parked-minutes stats (from the cache). */
|
||||
readonly closedSessions: number;
|
||||
readonly totalParkedMinutes: number;
|
||||
readonly avgParkedMinutes: number;
|
||||
readonly medianParkedMinutes: number;
|
||||
/** Cancelled tickets + signed anomalies in range — the "look closer" counters
|
||||
* (the operator at the booth is the threat model's primary adversary). */
|
||||
readonly voids: number;
|
||||
readonly anomalies: number;
|
||||
}
|
||||
|
||||
export interface SubscriptionStats {
|
||||
readonly active: number;
|
||||
readonly suspended: number;
|
||||
readonly revoked: number;
|
||||
/** Active subscriptions whose window covers `to` (the report's "now"). */
|
||||
readonly currentlyValid: number;
|
||||
/** Cars covered by currently-valid subscriptions (Σ quantity). */
|
||||
readonly coveredCars: number;
|
||||
}
|
||||
|
||||
/** One bar of the stay-duration histogram: stays up to `uptoMin` minutes (null = the
|
||||
* open-ended tail). Edges chosen to mirror how tariffs are designed (see tariff.md). */
|
||||
export interface StayBucket {
|
||||
readonly uptoMin: number | null;
|
||||
readonly count: number;
|
||||
}
|
||||
|
||||
export interface ReportSummary {
|
||||
readonly from: string;
|
||||
readonly to: string;
|
||||
readonly bucket: Bucket;
|
||||
readonly tz: string;
|
||||
readonly currency: string | null;
|
||||
readonly totals: ReportTotals;
|
||||
readonly series: SeriesPoint[];
|
||||
/** Entries by local hour-of-day (0–23), summed across the range — the peak-hour view. */
|
||||
readonly entriesByHour: number[];
|
||||
/** Entries by [day-of-week][hour-of-day] — 7×24, row 0 = Monday. The heatmap that
|
||||
* shows weekday-vs-weekend patterns (feeds tariff-window design). */
|
||||
readonly entriesByDowHour: number[][];
|
||||
/** Stay-duration histogram over closed sessions in range. */
|
||||
readonly stayHistogram: StayBucket[];
|
||||
/** Cars inside when the range OPENS (folded from the whole prior ledger). */
|
||||
readonly occupancyStart: number;
|
||||
/** Nominal capacity from site config (null = uncapped) — the reference line. */
|
||||
readonly capacity: number | null;
|
||||
readonly subscriptions: SubscriptionStats;
|
||||
}
|
||||
|
||||
/** Local wall-clock parts of an ISO instant in a given IANA tz. Reuses Intl (no dep). */
|
||||
const fmtCache = new Map<string, Intl.DateTimeFormat>();
|
||||
const DOW_INDEX: Record<string, number> = { Mon: 0, Tue: 1, Wed: 2, Thu: 3, Fri: 4, Sat: 5, Sun: 6 };
|
||||
function localParts(iso: string, tz: string): { y: number; mo: number; d: number; h: number; dow: number } {
|
||||
// Cached per tz — this runs once per ledger row in a report.
|
||||
let fmt = fmtCache.get(tz);
|
||||
if (!fmt) {
|
||||
fmt = new Intl.DateTimeFormat("en-US", {
|
||||
timeZone: tz,
|
||||
year: "numeric",
|
||||
month: "2-digit",
|
||||
day: "2-digit",
|
||||
hour: "2-digit",
|
||||
hourCycle: "h23",
|
||||
weekday: "short",
|
||||
});
|
||||
fmtCache.set(tz, fmt);
|
||||
}
|
||||
const parts = Object.fromEntries(fmt.formatToParts(new Date(iso)).map((p) => [p.type, p.value]));
|
||||
return {
|
||||
y: Number(parts.year),
|
||||
mo: Number(parts.month),
|
||||
d: Number(parts.day),
|
||||
h: Number(parts.hour),
|
||||
dow: DOW_INDEX[parts.weekday ?? ""] ?? 0, // row 0 = Monday
|
||||
};
|
||||
}
|
||||
|
||||
/** Bucket label for an instant at the chosen grain, in local time. Sorts lexically. */
|
||||
function bucketLabel(iso: string, tz: string, bucket: Bucket): string {
|
||||
const p = localParts(iso, tz);
|
||||
const mo = String(p.mo).padStart(2, "0");
|
||||
const d = String(p.d).padStart(2, "0");
|
||||
const h = String(p.h).padStart(2, "0");
|
||||
if (bucket === "month") return `${p.y}-${mo}`;
|
||||
if (bucket === "hour") return `${p.y}-${mo}-${d} ${h}`;
|
||||
return `${p.y}-${mo}-${d}`;
|
||||
}
|
||||
|
||||
interface PaymentPayload {
|
||||
amountMinor?: number;
|
||||
currency?: string;
|
||||
tender?: "cash" | "card";
|
||||
subscriptionSale?: boolean;
|
||||
subscriptionWindowCharge?: boolean;
|
||||
}
|
||||
|
||||
function median(sorted: number[]): number {
|
||||
if (sorted.length === 0) return 0;
|
||||
const mid = Math.floor(sorted.length / 2);
|
||||
const hi = sorted[mid] ?? 0;
|
||||
if (sorted.length % 2) return hi;
|
||||
const lo = sorted[mid - 1] ?? 0;
|
||||
return Math.round((lo + hi) / 2);
|
||||
}
|
||||
|
||||
/**
|
||||
* Build the admin report summary for [from, to) at the chosen grain. Entry/exit counts
|
||||
* and money are summed from the signed ledger; duration stats from the closed sessions
|
||||
* in range; subscription counts from the subscriptions table as of `to`.
|
||||
*/
|
||||
export function reportSummary(db: Db, q: ReportQuery): ReportSummary {
|
||||
const tz = siteTz(db);
|
||||
|
||||
// --- Ledger: entry/exit/payment in range, oldest-first so the series builds in order.
|
||||
const rows = db
|
||||
.select()
|
||||
.from(ledgerEvents)
|
||||
.where(and(gte(ledgerEvents.occurredAt, q.from), lte(ledgerEvents.occurredAt, q.to)))
|
||||
.orderBy(asc(ledgerEvents.index))
|
||||
.all();
|
||||
|
||||
// Currency for display: money everywhere is { minorUnits, currency }; payments carry
|
||||
// the currency they were taken in, so take it from a payment in range (then fall back
|
||||
// to the active tariff version). Reports never mix currencies (single-currency site).
|
||||
let currency: string | null = null;
|
||||
|
||||
const seriesMap = new Map<string, SeriesPoint>();
|
||||
const entriesByHour = new Array<number>(24).fill(0);
|
||||
const entriesByDowHour = Array.from({ length: 7 }, () => new Array<number>(24).fill(0));
|
||||
const totals = {
|
||||
entries: 0,
|
||||
exits: 0,
|
||||
payments: 0,
|
||||
revenueMinor: 0,
|
||||
cashMinor: 0,
|
||||
cardMinor: 0,
|
||||
ticketMinor: 0,
|
||||
subscriptionSalesMinor: 0,
|
||||
subscriptionWindowMinor: 0,
|
||||
voids: 0,
|
||||
anomalies: 0,
|
||||
};
|
||||
|
||||
function point(label: string): SeriesPoint {
|
||||
let p = seriesMap.get(label);
|
||||
if (!p) {
|
||||
p = { bucket: label, entries: 0, exits: 0, revenueMinor: 0, cashMinor: 0, cardMinor: 0, payments: 0, occupancyEnd: 0 };
|
||||
seriesMap.set(label, p);
|
||||
}
|
||||
return p;
|
||||
}
|
||||
|
||||
// Pre-pass: identities cancelled by a `void` in range. A voided entry was a wrongly-
|
||||
// printed ticket (no car entered), so it must NOT inflate the "entries" stat. (The void's
|
||||
// entry is normally in the same window; this skips it when both are in range.)
|
||||
const voided = new Set<string>();
|
||||
for (const row of rows) if (row.type === "void" && row.identity) voided.add(row.identity);
|
||||
|
||||
for (const row of rows) {
|
||||
const label = bucketLabel(row.occurredAt, tz, q.bucket);
|
||||
const p = point(label) as { -readonly [K in keyof SeriesPoint]: SeriesPoint[K] };
|
||||
if (row.type === "vehicle_entry") {
|
||||
if (row.identity && voided.has(row.identity)) continue; // cancelled — not a real entry
|
||||
totals.entries++;
|
||||
p.entries++;
|
||||
const lp = localParts(row.occurredAt, tz);
|
||||
entriesByHour[lp.h] = (entriesByHour[lp.h] ?? 0) + 1;
|
||||
entriesByDowHour[lp.dow]![lp.h] = (entriesByDowHour[lp.dow]![lp.h] ?? 0) + 1;
|
||||
} else if (row.type === "vehicle_exit") {
|
||||
totals.exits++;
|
||||
p.exits++;
|
||||
} else if (row.type === "void") {
|
||||
totals.voids++;
|
||||
} else if (row.type === "anomaly") {
|
||||
totals.anomalies++;
|
||||
} else if (row.type === "payment") {
|
||||
const pl = (row.payload ?? {}) as PaymentPayload;
|
||||
const amt = typeof pl.amountMinor === "number" ? pl.amountMinor : 0;
|
||||
if (!currency && typeof pl.currency === "string") currency = pl.currency;
|
||||
totals.payments++;
|
||||
totals.revenueMinor += amt;
|
||||
p.payments++;
|
||||
p.revenueMinor += amt;
|
||||
if (pl.tender === "card") {
|
||||
totals.cardMinor += amt;
|
||||
p.cardMinor += amt;
|
||||
} else {
|
||||
totals.cashMinor += amt;
|
||||
p.cashMinor += amt;
|
||||
}
|
||||
// Revenue split mirrors the shift Z-report: subscription sale / window charge /
|
||||
// (the rest is) transient ticket revenue.
|
||||
if (pl.subscriptionSale === true) totals.subscriptionSalesMinor += amt;
|
||||
else if (pl.subscriptionWindowCharge === true) totals.subscriptionWindowMinor += amt;
|
||||
else totals.ticketMinor += amt;
|
||||
}
|
||||
}
|
||||
|
||||
const series = [...seriesMap.values()].sort((a, b) => a.bucket.localeCompare(b.bucket));
|
||||
|
||||
// --- Occupancy: fold the PRIOR ledger for cars-inside at range start, then walk the
|
||||
// series. Voided pre-range entries cancel out the same way the in-range pass does.
|
||||
// Sparse buckets (no events) simply carry the previous level — the step line is exact
|
||||
// at every plotted point.
|
||||
const prior = db
|
||||
.select({ type: ledgerEvents.type, identity: ledgerEvents.identity })
|
||||
.from(ledgerEvents)
|
||||
.where(lt(ledgerEvents.occurredAt, q.from))
|
||||
.all();
|
||||
const priorVoided = new Set<string>();
|
||||
for (const r of prior) if (r.type === "void" && r.identity) priorVoided.add(r.identity);
|
||||
let occupancyStart = 0;
|
||||
for (const r of prior) {
|
||||
if (r.type === "vehicle_entry" && !(r.identity && priorVoided.has(r.identity))) occupancyStart++;
|
||||
else if (r.type === "vehicle_exit") occupancyStart--;
|
||||
}
|
||||
occupancyStart = Math.max(0, occupancyStart);
|
||||
let running = occupancyStart;
|
||||
for (const p of series) {
|
||||
running = Math.max(0, running + p.entries - p.exits);
|
||||
(p as { -readonly [K in keyof SeriesPoint]: SeriesPoint[K] }).occupancyEnd = running;
|
||||
}
|
||||
|
||||
const capacity = db.select().from(siteConfig).where(eq(siteConfig.id, 1)).get()?.capacity ?? null;
|
||||
|
||||
// No payment in range? Fall back to the site tariff's latest version currency, so a
|
||||
// zero-revenue range still labels its money column.
|
||||
if (!currency) {
|
||||
const tariff = db.select().from(tariffs).where(eq(tariffs.scope, "site")).get();
|
||||
if (tariff) {
|
||||
const tv = db
|
||||
.select()
|
||||
.from(tariffVersions)
|
||||
.where(eq(tariffVersions.tariffId, tariff.id))
|
||||
.orderBy(desc(tariffVersions.effectiveFrom))
|
||||
.get();
|
||||
currency = tv?.currency ?? null;
|
||||
}
|
||||
}
|
||||
|
||||
// --- Duration: closed transient sessions whose EXIT fell in range (the cache; flagged).
|
||||
const closed = db
|
||||
.select()
|
||||
.from(sessions)
|
||||
.where(and(gte(sessions.exitedAt, q.from), lte(sessions.exitedAt, q.to)))
|
||||
.all();
|
||||
const durations: number[] = [];
|
||||
for (const s of closed) {
|
||||
if (!s.enteredAt || !s.exitedAt) continue;
|
||||
const mins = Math.max(0, Math.round((Date.parse(s.exitedAt) - Date.parse(s.enteredAt)) / 60000));
|
||||
durations.push(mins);
|
||||
}
|
||||
durations.sort((a, b) => a - b);
|
||||
const totalParkedMinutes = durations.reduce((a, b) => a + b, 0);
|
||||
|
||||
// Stay-duration histogram. Edges mirror how rate cards are designed (30m/1h bands,
|
||||
// the 8h working day, the 24h rolling day) so the chart answers "where should the
|
||||
// ladder/up-to breakpoints sit". Last bucket is the open-ended >24h tail.
|
||||
const STAY_EDGES_MIN = [30, 60, 120, 240, 480, 1440];
|
||||
const stayHistogram: { uptoMin: number | null; count: number }[] = [
|
||||
...STAY_EDGES_MIN.map((uptoMin) => ({ uptoMin, count: 0 })),
|
||||
{ uptoMin: null, count: 0 },
|
||||
];
|
||||
for (const mins of durations) {
|
||||
const i = STAY_EDGES_MIN.findIndex((edge) => mins <= edge);
|
||||
stayHistogram[i === -1 ? STAY_EDGES_MIN.length : i]!.count++;
|
||||
}
|
||||
|
||||
// --- Subscriptions: status counts + currently-valid (window covers `to`).
|
||||
const subs = db.select().from(subscriptions).all();
|
||||
const subStats = { active: 0, suspended: 0, revoked: 0, currentlyValid: 0, coveredCars: 0 };
|
||||
for (const s of subs) {
|
||||
if (s.status === "active") subStats.active++;
|
||||
else if (s.status === "suspended") subStats.suspended++;
|
||||
else if (s.status === "revoked") subStats.revoked++;
|
||||
const validNow =
|
||||
s.status === "active" &&
|
||||
(!s.validFrom || s.validFrom <= q.to) &&
|
||||
(!s.validTo || s.validTo >= q.to);
|
||||
if (validNow) {
|
||||
subStats.currentlyValid++;
|
||||
subStats.coveredCars += s.quantity ?? 1;
|
||||
}
|
||||
}
|
||||
|
||||
return {
|
||||
from: q.from,
|
||||
to: q.to,
|
||||
bucket: q.bucket,
|
||||
tz,
|
||||
currency,
|
||||
totals: {
|
||||
...totals,
|
||||
closedSessions: durations.length,
|
||||
totalParkedMinutes,
|
||||
avgParkedMinutes: durations.length ? Math.round(totalParkedMinutes / durations.length) : 0,
|
||||
medianParkedMinutes: median(durations),
|
||||
},
|
||||
series,
|
||||
entriesByHour,
|
||||
entriesByDowHour,
|
||||
stayHistogram,
|
||||
occupancyStart,
|
||||
capacity,
|
||||
subscriptions: subStats,
|
||||
};
|
||||
}
|
||||
@@ -1,6 +1,7 @@
|
||||
import bcrypt from "bcrypt";
|
||||
import type { FastifyInstance } from "fastify";
|
||||
import { eq, roles, users, type Db } from "@parking/db";
|
||||
import { effectiveModulesFor } from "../modules.js";
|
||||
import {
|
||||
clearAuthCookies,
|
||||
newCsrfToken,
|
||||
@@ -29,9 +30,57 @@ interface ThemeBody {
|
||||
theme: Theme;
|
||||
}
|
||||
|
||||
// UI font scale: percent of base, clamped to [80, 160] in steps of 10. Integer percent.
|
||||
const FONT_SCALE_MIN = 80;
|
||||
const FONT_SCALE_MAX = 160;
|
||||
interface FontScaleBody {
|
||||
fontScale: number;
|
||||
}
|
||||
|
||||
// Self-service profile: a signed-in user edits their OWN display name + email. This is
|
||||
// NOT the admin user-management path (routes/users.ts) — it only ever touches the caller
|
||||
// (req.user.sub), needs no `user:*` permission, and can't change username, role, or any
|
||||
// other account. "" clears a field (→ null). See wiki/entities/local-jwt-auth.md.
|
||||
interface ProfileBody {
|
||||
fullName?: string | null;
|
||||
email?: string | null;
|
||||
}
|
||||
|
||||
// Self-service password change: the user proves they hold the CURRENT password before
|
||||
// setting a new one — unlike the admin reset (users.ts), which sets it outright. This is
|
||||
// why it lives here and not behind a permission: it's account-self-care, not admin power.
|
||||
interface PasswordBody {
|
||||
currentPassword: string;
|
||||
newPassword: string;
|
||||
}
|
||||
|
||||
const MIN_PASSWORD = 8;
|
||||
|
||||
/** Trim a self-service profile string; "" (or whitespace) → null (clear the field).
|
||||
* Returns undefined for an absent key so an update only touches what was sent. */
|
||||
function cleanProfileField(v: string | null | undefined): string | null | undefined {
|
||||
if (v === undefined) return undefined;
|
||||
const trimmed = typeof v === "string" ? v.trim() : "";
|
||||
return trimmed === "" ? null : trimmed;
|
||||
}
|
||||
|
||||
/** The session shape the SPA bootstraps from: identity + role + its permission
|
||||
* list (so the UI can gate nav/routes) + language. Role NAME is for display; the
|
||||
* permissions are the source of truth. */
|
||||
* permissions are the source of truth.
|
||||
*
|
||||
* `csrf`, when passed, echoes the SAME value already sent as the readable
|
||||
* parking_csrf cookie — not a new secret, just a second channel to learn it.
|
||||
* The desktop shell needs this: tauri-plugin-http's fetch() runs through
|
||||
* Rust's reqwest, which keeps its own cookie jar separate from the webview,
|
||||
* so document.cookie on the tauri://localhost page never sees a cookie set
|
||||
* on a plugin-routed response (open upstream bug, tauri-apps/tauri#13045).
|
||||
* The cookie itself IS still sent back to the server by reqwest on
|
||||
* subsequent requests — only the *client-side read* is broken — so
|
||||
* api.ts's desktop path stashes this body value in memory instead of
|
||||
* reading document.cookie, and echoes it in X-CSRF-Token exactly as the
|
||||
* browser path echoes the cookie. See lib/api.ts and assertCsrf() in
|
||||
* ../auth.ts (unchanged — this never touches verification, only how the
|
||||
* desktop client learns what to send). */
|
||||
function sessionView(
|
||||
db: Db,
|
||||
user: {
|
||||
@@ -40,8 +89,11 @@ function sessionView(
|
||||
roleId: string;
|
||||
language: string;
|
||||
theme: string;
|
||||
fontScale: number;
|
||||
fullName?: string | null;
|
||||
email?: string | null;
|
||||
},
|
||||
csrf?: string,
|
||||
) {
|
||||
const role = db.select().from(roles).where(eq(roles.id, user.roleId)).get();
|
||||
const permissions = [...permissionsFor(user.roleId)];
|
||||
@@ -53,7 +105,13 @@ function sessionView(
|
||||
permissions,
|
||||
language: user.language,
|
||||
theme: user.theme,
|
||||
fontScale: user.fontScale,
|
||||
fullName: user.fullName ?? null,
|
||||
email: user.email ?? null,
|
||||
// Effective venue modules (entitled ∩ activated) so the SPA can hide nav/routes
|
||||
// on first paint. The server still enforces via requireModule — this is display.
|
||||
modules: effectiveModulesFor(db),
|
||||
...(csrf ? { csrfToken: csrf } : {}),
|
||||
};
|
||||
}
|
||||
|
||||
@@ -69,7 +127,9 @@ export async function authRoutes(app: FastifyInstance, db: Db): Promise<void> {
|
||||
// Always run a bcrypt compare to avoid leaking which usernames exist (timing).
|
||||
const hash = user?.passwordHash ?? "$2b$10$invalidinvalidinvalidinvalidinvalidinvalidinv";
|
||||
const ok = await bcrypt.compare(password, hash);
|
||||
if (!user || !ok) {
|
||||
// A soft-deleted user (in the recycle bin) cannot log in — treat as invalid, with no
|
||||
// distinct error so a deleted account isn't enumerable.
|
||||
if (!user || !ok || user.deletedAt) {
|
||||
return reply.code(401).send({ error: "invalid credentials" });
|
||||
}
|
||||
|
||||
@@ -86,7 +146,7 @@ export async function authRoutes(app: FastifyInstance, db: Db): Promise<void> {
|
||||
setAuthCookies(reply, token, csrf);
|
||||
// `language` is NOT in the JWT (identity/role only) — it's a mutable preference
|
||||
// read from the DB, so changing it needs no token refresh.
|
||||
return sessionView(db, user);
|
||||
return sessionView(db, user, csrf);
|
||||
});
|
||||
|
||||
app.post("/api/auth/logout", async (_req, reply) => {
|
||||
@@ -106,7 +166,9 @@ export async function authRoutes(app: FastifyInstance, db: Db): Promise<void> {
|
||||
clearAuthCookies(reply);
|
||||
return reply.code(401).send({ error: "session no longer valid" });
|
||||
}
|
||||
return sessionView(db, row);
|
||||
// req.user.csrf is the value bound into the JWT at login (see assertCsrf in
|
||||
// ../auth.ts) — same value as the cookie, re-surfaced for the desktop path.
|
||||
return sessionView(db, row, req.user.csrf);
|
||||
},
|
||||
);
|
||||
|
||||
@@ -139,4 +201,69 @@ export async function authRoutes(app: FastifyInstance, db: Db): Promise<void> {
|
||||
return { theme };
|
||||
},
|
||||
);
|
||||
|
||||
// Change MY own UI font scale (any signed-in user). Percent of base, clamped to
|
||||
// [80, 160] in steps of 10. Persisted like `theme`, restored on the next login.
|
||||
app.put<{ Body: FontScaleBody }>(
|
||||
"/api/auth/font-scale",
|
||||
{ preHandler: requireAuth },
|
||||
async (req, reply) => {
|
||||
const raw = req.body?.fontScale;
|
||||
if (typeof raw !== "number" || !Number.isFinite(raw)) {
|
||||
return reply.code(400).send({ error: "fontScale must be a number" });
|
||||
}
|
||||
// Snap to a 10-step and clamp to the allowed band (defensive — the UI already does).
|
||||
const fontScale = Math.min(FONT_SCALE_MAX, Math.max(FONT_SCALE_MIN, Math.round(raw / 10) * 10));
|
||||
await db.update(users).set({ fontScale }).where(eq(users.id, req.user.sub)).run();
|
||||
return { fontScale };
|
||||
},
|
||||
);
|
||||
|
||||
// Edit MY own display name / email (any signed-in user; no permission needed — it only
|
||||
// touches the caller). Cannot change username or role — those stay admin-only (users.ts).
|
||||
app.put<{ Body: ProfileBody }>(
|
||||
"/api/auth/profile",
|
||||
{ preHandler: requireAuth },
|
||||
async (req, reply) => {
|
||||
const fullName = cleanProfileField(req.body?.fullName);
|
||||
const email = cleanProfileField(req.body?.email);
|
||||
const patch: Record<string, string | null> = {};
|
||||
if (fullName !== undefined) patch.fullName = fullName;
|
||||
if (email !== undefined) patch.email = email;
|
||||
if (Object.keys(patch).length === 0) {
|
||||
return reply.code(400).send({ error: "nothing to update" });
|
||||
}
|
||||
await db.update(users).set(patch).where(eq(users.id, req.user.sub)).run();
|
||||
const row = await db.select().from(users).where(eq(users.id, req.user.sub)).get();
|
||||
if (!row) return reply.code(401).send({ error: "session no longer valid" });
|
||||
return sessionView(db, row);
|
||||
},
|
||||
);
|
||||
|
||||
// Change MY own password — must prove the CURRENT one first (defends against a walked-up,
|
||||
// already-logged-in booth: a passerby can't silently re-key the account). New password
|
||||
// >= MIN_PASSWORD. Distinct from the admin reset (users.ts), which needs no current pw.
|
||||
app.put<{ Body: PasswordBody }>(
|
||||
"/api/auth/password",
|
||||
{ preHandler: requireAuth },
|
||||
async (req, reply) => {
|
||||
const currentPassword = req.body?.currentPassword ?? "";
|
||||
const newPassword = req.body?.newPassword ?? "";
|
||||
if (newPassword.length < MIN_PASSWORD) {
|
||||
return reply.code(400).send({ error: `password must be at least ${MIN_PASSWORD} characters` });
|
||||
}
|
||||
const row = await db.select().from(users).where(eq(users.id, req.user.sub)).get();
|
||||
if (!row) {
|
||||
clearAuthCookies(reply);
|
||||
return reply.code(401).send({ error: "session no longer valid" });
|
||||
}
|
||||
const ok = await bcrypt.compare(currentPassword, row.passwordHash);
|
||||
if (!ok) {
|
||||
return reply.code(403).send({ error: "current password is incorrect" });
|
||||
}
|
||||
const passwordHash = await bcrypt.hash(newPassword, 12);
|
||||
await db.update(users).set({ passwordHash }).where(eq(users.id, req.user.sub)).run();
|
||||
return { ok: true };
|
||||
},
|
||||
);
|
||||
}
|
||||
|
||||
@@ -0,0 +1,191 @@
|
||||
import { afterEach, beforeEach, describe, expect, it } from "vitest";
|
||||
import { createTestDb } from "@parking/db/testing";
|
||||
import { type Db } from "@parking/db";
|
||||
import type { FastifyInstance } from "fastify";
|
||||
import { buildServer } from "../server.js";
|
||||
import { seedUser, login } from "../test-helpers.js";
|
||||
|
||||
// HTTP integration for the backup routes — the security seam + the unconfigured-state
|
||||
// behaviour. The booted test app has no BACKUP_TARGET_DIR/BACKUP_KEY, so the service is
|
||||
// "not configured": status reports it, and a manual run is a clean 409 (not a 500).
|
||||
// See wiki/concepts/backup-recovery.md.
|
||||
|
||||
let db: Db;
|
||||
let close: () => void;
|
||||
let app: FastifyInstance;
|
||||
|
||||
beforeEach(async () => {
|
||||
const t = createTestDb();
|
||||
db = t.db;
|
||||
close = t.close;
|
||||
app = await buildServer({ db });
|
||||
await app.ready();
|
||||
});
|
||||
afterEach(async () => {
|
||||
await app.close();
|
||||
close();
|
||||
});
|
||||
|
||||
describe("GET /api/backup/status", () => {
|
||||
it("401 without a session", async () => {
|
||||
const res = await app.inject({ method: "GET", url: "/api/backup/status" });
|
||||
expect(res.statusCode).toBe(401);
|
||||
});
|
||||
|
||||
it("403 for a user lacking backup:read", async () => {
|
||||
const { username, password } = await seedUser(db, {
|
||||
username: "viewer", roleId: "viewer", permissions: ["site:read"],
|
||||
});
|
||||
const { cookie } = await login(app, username, password);
|
||||
const res = await app.inject({ method: "GET", url: "/api/backup/status", headers: { cookie } });
|
||||
expect(res.statusCode).toBe(403);
|
||||
});
|
||||
|
||||
it("an admin sees the (unconfigured) status shape", async () => {
|
||||
const { username, password } = await seedUser(db, { username: "boss", roleId: "admin" });
|
||||
const { cookie } = await login(app, username, password);
|
||||
const res = await app.inject({ method: "GET", url: "/api/backup/status", headers: { cookie } });
|
||||
expect(res.statusCode).toBe(200);
|
||||
const body = res.json();
|
||||
expect(body).toMatchObject({
|
||||
configured: false,
|
||||
targetDir: null,
|
||||
keepLast: 7, // code defaults surfaced when unset
|
||||
keepDailyDays: 30,
|
||||
running: false,
|
||||
lastSuccessAt: null,
|
||||
lastError: null,
|
||||
});
|
||||
});
|
||||
});
|
||||
|
||||
describe("PUT /api/backup/config — admin-chosen target", () => {
|
||||
it("403 for a user lacking backup:update", async () => {
|
||||
const { username, password } = await seedUser(db, {
|
||||
username: "viewer", roleId: "viewer", permissions: ["backup:read"],
|
||||
});
|
||||
const { cookie, csrf } = await login(app, username, password);
|
||||
const res = await app.inject({
|
||||
method: "PUT", url: "/api/backup/config",
|
||||
headers: { cookie, "x-csrf-token": csrf },
|
||||
payload: { targetDir: "/tmp/x" },
|
||||
});
|
||||
expect(res.statusCode).toBe(403);
|
||||
});
|
||||
|
||||
it("persists the target dir and reflects it in status", async () => {
|
||||
const { username, password } = await seedUser(db, { username: "boss", roleId: "admin" });
|
||||
const { cookie, csrf } = await login(app, username, password);
|
||||
const put = await app.inject({
|
||||
method: "PUT", url: "/api/backup/config",
|
||||
headers: { cookie, "x-csrf-token": csrf },
|
||||
payload: { targetDir: " /mnt/backup " }, // trimmed server-side
|
||||
});
|
||||
expect(put.statusCode).toBe(200);
|
||||
expect(put.json()).toMatchObject({ targetDir: "/mnt/backup" });
|
||||
|
||||
const status = await app.inject({ method: "GET", url: "/api/backup/status", headers: { cookie } });
|
||||
expect(status.json().targetDir).toBe("/mnt/backup");
|
||||
});
|
||||
|
||||
it("clears the target dir when given empty/null", async () => {
|
||||
const { username, password } = await seedUser(db, { username: "boss", roleId: "admin" });
|
||||
const { cookie, csrf } = await login(app, username, password);
|
||||
await app.inject({
|
||||
method: "PUT", url: "/api/backup/config",
|
||||
headers: { cookie, "x-csrf-token": csrf }, payload: { targetDir: "/mnt/backup" },
|
||||
});
|
||||
const clear = await app.inject({
|
||||
method: "PUT", url: "/api/backup/config",
|
||||
headers: { cookie, "x-csrf-token": csrf }, payload: { targetDir: "" },
|
||||
});
|
||||
expect(clear.json().targetDir).toBeNull();
|
||||
});
|
||||
|
||||
it("persists retention and resets to defaults on null", async () => {
|
||||
const { username, password } = await seedUser(db, { username: "boss", roleId: "admin" });
|
||||
const { cookie, csrf } = await login(app, username, password);
|
||||
|
||||
const set = await app.inject({
|
||||
method: "PUT", url: "/api/backup/config",
|
||||
headers: { cookie, "x-csrf-token": csrf },
|
||||
payload: { keepLast: 3, keepDailyDays: 14 },
|
||||
});
|
||||
expect(set.json()).toMatchObject({ keepLast: 3, keepDailyDays: 14 });
|
||||
|
||||
// null resets to the code default.
|
||||
const reset = await app.inject({
|
||||
method: "PUT", url: "/api/backup/config",
|
||||
headers: { cookie, "x-csrf-token": csrf },
|
||||
payload: { keepLast: null, keepDailyDays: null },
|
||||
});
|
||||
expect(reset.json()).toMatchObject({ keepLast: 7, keepDailyDays: 30 });
|
||||
});
|
||||
|
||||
it("rejects a negative retention value (400)", async () => {
|
||||
const { username, password } = await seedUser(db, { username: "boss", roleId: "admin" });
|
||||
const { cookie, csrf } = await login(app, username, password);
|
||||
const res = await app.inject({
|
||||
method: "PUT", url: "/api/backup/config",
|
||||
headers: { cookie, "x-csrf-token": csrf },
|
||||
payload: { keepLast: -1 },
|
||||
});
|
||||
expect(res.statusCode).toBe(400);
|
||||
});
|
||||
});
|
||||
|
||||
describe("POST /api/backup/test — path probe", () => {
|
||||
it("reports ok for a writable directory and a reason for a missing one", async () => {
|
||||
const { username, password } = await seedUser(db, { username: "boss", roleId: "admin" });
|
||||
const { cookie, csrf } = await login(app, username, password);
|
||||
|
||||
const good = await app.inject({
|
||||
method: "POST", url: "/api/backup/test",
|
||||
headers: { cookie, "x-csrf-token": csrf },
|
||||
payload: { targetDir: process.cwd() }, // an existing, writable dir
|
||||
});
|
||||
expect(good.json()).toMatchObject({ ok: true });
|
||||
|
||||
const bad = await app.inject({
|
||||
method: "POST", url: "/api/backup/test",
|
||||
headers: { cookie, "x-csrf-token": csrf },
|
||||
payload: { targetDir: "/no/such/path/here-xyz" },
|
||||
});
|
||||
expect(bad.json()).toMatchObject({ ok: false, reason: "missing" });
|
||||
});
|
||||
});
|
||||
|
||||
describe("POST /api/backup/run", () => {
|
||||
it("403 for a user lacking backup:create", async () => {
|
||||
const { username, password } = await seedUser(db, {
|
||||
username: "viewer", roleId: "viewer", permissions: ["backup:read"], // read but not create
|
||||
});
|
||||
const { cookie, csrf } = await login(app, username, password);
|
||||
const res = await app.inject({
|
||||
method: "POST", url: "/api/backup/run",
|
||||
headers: { cookie, "x-csrf-token": csrf },
|
||||
});
|
||||
expect(res.statusCode).toBe(403);
|
||||
});
|
||||
|
||||
it("requires CSRF on the mutation", async () => {
|
||||
const { username, password } = await seedUser(db, { username: "boss", roleId: "admin" });
|
||||
const { cookie } = await login(app, username, password);
|
||||
const res = await app.inject({
|
||||
method: "POST", url: "/api/backup/run",
|
||||
headers: { cookie }, // no csrf header
|
||||
});
|
||||
expect(res.statusCode).toBe(403);
|
||||
});
|
||||
|
||||
it("returns 409 backup_not_configured when no target/key is set (not a 500)", async () => {
|
||||
const { username, password } = await seedUser(db, { username: "boss", roleId: "admin" });
|
||||
const { cookie, csrf } = await login(app, username, password);
|
||||
const res = await app.inject({
|
||||
method: "POST", url: "/api/backup/run",
|
||||
headers: { cookie, "x-csrf-token": csrf },
|
||||
});
|
||||
expect(res.statusCode).toBe(409);
|
||||
expect(res.json()).toMatchObject({ error: "backup_not_configured" });
|
||||
});
|
||||
});
|
||||
@@ -0,0 +1,92 @@
|
||||
import type { FastifyInstance } from "fastify";
|
||||
import { eq, siteConfig, type Db } from "@parking/db";
|
||||
import { requirePermission } from "../auth.js";
|
||||
import { checkTargetDir, type BackupService } from "../backup-service.js";
|
||||
|
||||
// On-site encrypted DB backup — admin-driven. See wiki/concepts/backup-recovery.md.
|
||||
// - GET /api/backup/status : config + last-run success/error. (backup:read)
|
||||
// - PUT /api/backup/config : set the admin-chosen target directory. (backup:update)
|
||||
// - POST /api/backup/test : probe a candidate path (exists/dir/writable). (backup:update)
|
||||
// - POST /api/backup/run : trigger a manual "back up now". (backup:create)
|
||||
// The target dir lives in site_config (admin picks it from the UI); the encryption key stays an
|
||||
// env secret. RESTORE is intentionally absent — out-of-band runbook on a fresh appliance.
|
||||
|
||||
interface ConfigBody {
|
||||
targetDir?: string | null;
|
||||
/** Retention: keep this many newest backups. null = reset to the code default. */
|
||||
keepLast?: number | null;
|
||||
/** Retention: keep one-per-day within this many days. null = reset to the code default. */
|
||||
keepDailyDays?: number | null;
|
||||
}
|
||||
interface TestBody {
|
||||
targetDir?: string;
|
||||
}
|
||||
|
||||
export async function backupRoutes(app: FastifyInstance, db: Db, backups: BackupService): Promise<void> {
|
||||
app.get("/api/backup/status", { preHandler: requirePermission("backup:read") }, async () =>
|
||||
backups.status(),
|
||||
);
|
||||
|
||||
// Set (or clear) the target directory. Empty/null clears it (backups become a no-op).
|
||||
app.put<{ Body: ConfigBody }>(
|
||||
"/api/backup/config",
|
||||
{ preHandler: requirePermission("backup:update") },
|
||||
async (req, reply) => {
|
||||
const body = req.body ?? {};
|
||||
const patch: { backupTargetDir?: string | null; backupKeepLast?: number | null; backupKeepDailyDays?: number | null } = {};
|
||||
|
||||
if ("targetDir" in body) {
|
||||
const raw = body.targetDir;
|
||||
if (raw != null && typeof raw !== "string") {
|
||||
return reply.code(400).send({ error: "targetDir must be a string or null" });
|
||||
}
|
||||
patch.backupTargetDir = raw == null ? null : raw.trim() || null;
|
||||
}
|
||||
// Retention: a non-negative integer, or null to reset to the code default.
|
||||
for (const [field, col] of [
|
||||
["keepLast", "backupKeepLast"],
|
||||
["keepDailyDays", "backupKeepDailyDays"],
|
||||
] as const) {
|
||||
if (field in body) {
|
||||
const v = body[field];
|
||||
if (v != null && (!Number.isInteger(v) || v < 0)) {
|
||||
return reply.code(400).send({ error: `${field} must be a non-negative integer or null` });
|
||||
}
|
||||
patch[col] = v ?? null;
|
||||
}
|
||||
}
|
||||
|
||||
const updatedAt = new Date().toISOString();
|
||||
// Single-row site_config (id=1): upsert, since a fresh install may not have it yet.
|
||||
const existing = db.select().from(siteConfig).where(eq(siteConfig.id, 1)).get();
|
||||
if (existing) {
|
||||
db.update(siteConfig).set({ ...patch, updatedAt }).where(eq(siteConfig.id, 1)).run();
|
||||
} else {
|
||||
db.insert(siteConfig).values({ id: 1, ...patch, updatedAt }).run();
|
||||
}
|
||||
return backups.status();
|
||||
},
|
||||
);
|
||||
|
||||
// Probe a candidate path before relying on it (the UI "Test target" button).
|
||||
app.post<{ Body: TestBody }>(
|
||||
"/api/backup/test",
|
||||
{ preHandler: requirePermission("backup:update") },
|
||||
async (req) => {
|
||||
const dir = typeof req.body?.targetDir === "string" ? req.body.targetDir : "";
|
||||
return checkTargetDir(dir);
|
||||
},
|
||||
);
|
||||
|
||||
app.post("/api/backup/run", { preHandler: requirePermission("backup:create") }, async (_req, reply) => {
|
||||
if (!backups.configured) {
|
||||
return reply.code(409).send({ error: "backup_not_configured" });
|
||||
}
|
||||
try {
|
||||
const res = await backups.run("manual");
|
||||
return reply.send({ ok: true, path: res.path, bytes: res.bytes, prunedFiles: res.prunedFiles });
|
||||
} catch (err) {
|
||||
return reply.code(500).send({ error: "backup_failed", message: (err as Error).message });
|
||||
}
|
||||
});
|
||||
}
|
||||
@@ -0,0 +1,126 @@
|
||||
import type { FastifyInstance } from "fastify";
|
||||
import type { Db } from "@parking/db";
|
||||
import type { TillId } from "@parking/shared";
|
||||
import { requireAuth, requirePermission, roleHasPermissions } from "../auth.js";
|
||||
import { parseTill, requireTill, tillsReadableBy } from "../modules.js";
|
||||
import { InvalidCashMovementError, type MovementStatus, type ShiftService } from "../shift-service.js";
|
||||
|
||||
// Drawer cash movements (manned mode). Redesigned 2026-07-01: an operator RECORDS a
|
||||
// receipt/disbursement FREELY (no admin sign-off at creation); an admin REVIEWS it after
|
||||
// the fact (authorize/deny — a flag that never moves cash). See wiki/concepts/shift.md.
|
||||
// - POST /api/drawer/movement : operator records a cash_in/cash_out on a till.
|
||||
// Guard = the till's `cash` (booth drawer:create,
|
||||
// wash carwash:cash).
|
||||
// - GET /api/drawer/movements: list with review status, over the tills the role may
|
||||
// read (own movements); reviewers (drawer:review) see all
|
||||
// tills + all operators and can filter status.
|
||||
// - POST /api/drawer/review : admin authorize/deny a movement. (drawer:review)
|
||||
// - GET /api/drawer/balance : a till's physical balance NOW (guard = the till's read).
|
||||
// The drawer BALANCE math is unchanged — a movement counts immediately; a denial is a
|
||||
// judgment about the operator settled outside the app, never a cash reversal.
|
||||
// TILLS: a movement names the drawer it moved in/out of (`till`, default booth); each
|
||||
// desk's cash is guarded by that desk's own permissions (venue-modules.md §"Permissions
|
||||
// matrix").
|
||||
|
||||
interface MovementBody {
|
||||
/** Direction is the document TYPE, not a sign: cash_in = Mandat Arkëtimi (pay-IN),
|
||||
* cash_out = Mandat Pagese (pay-OUT). */
|
||||
type: "cash_in" | "cash_out";
|
||||
/** POSITIVE minor units (magnitude). The direction comes from `type`. */
|
||||
amountMinor: number;
|
||||
reason?: string;
|
||||
currency?: string;
|
||||
/** Which drawer (default: the booth). */
|
||||
till?: string;
|
||||
}
|
||||
|
||||
interface ReviewBody {
|
||||
/** The cash_in/cash_out event id being decided on. */
|
||||
refId: string;
|
||||
decision: "authorize" | "deny";
|
||||
/** Optional admin note (e.g. why denied). */
|
||||
note?: string;
|
||||
}
|
||||
|
||||
interface MovementsQuery {
|
||||
/** Reviewers only: filter to pending/authorized/denied. Ignored for non-reviewers. */
|
||||
status?: MovementStatus;
|
||||
/** Filter to one till; absent = every till the role may read (reviewers: every till). */
|
||||
till?: string;
|
||||
}
|
||||
|
||||
export async function drawerRoutes(app: FastifyInstance, db: Db, shift: ShiftService): Promise<void> {
|
||||
const reviewGuard = requirePermission("drawer:review");
|
||||
|
||||
// Operator RECORDS a movement — freely, no authorizer. It counts in the drawer at once.
|
||||
app.post<{ Body: MovementBody }>("/api/drawer/movement", { preHandler: requireTill(db, "cash", "body") }, async (req, reply) => {
|
||||
const b = req.body ?? ({} as MovementBody);
|
||||
if (b.type !== "cash_in" && b.type !== "cash_out") {
|
||||
return reply.code(400).send({ error: "type must be cash_in or cash_out" });
|
||||
}
|
||||
try {
|
||||
return await shift.recordVoucher({
|
||||
type: b.type,
|
||||
operator: req.user.username,
|
||||
amountMinor: b.amountMinor,
|
||||
reason: b.reason ?? "",
|
||||
currency: b.currency,
|
||||
till: req.till!,
|
||||
});
|
||||
} catch (err) {
|
||||
if (err instanceof InvalidCashMovementError) return reply.code(400).send({ error: err.message });
|
||||
return reply.code(500).send({ error: (err as Error).message });
|
||||
}
|
||||
});
|
||||
|
||||
// List movements + review status. Operators are hard-scoped to their OWN movements on
|
||||
// the tills they may read; a reviewer sees ALL and may filter by status (the pending
|
||||
// review queue).
|
||||
app.get<{ Querystring: MovementsQuery }>("/api/drawer/movements", { preHandler: requireAuth }, async (req, reply) => {
|
||||
const canReview = roleHasPermissions(req.user.roleId, ["drawer:review"]);
|
||||
const readable = tillsReadableBy(db, req.user.roleId);
|
||||
if (!canReview && readable.length === 0) return reply.code(403).send({ error: "forbidden" });
|
||||
const q = req.query ?? {};
|
||||
const status = canReview && ["pending", "authorized", "denied"].includes(q.status ?? "") ? q.status : undefined;
|
||||
let tills: TillId[] | undefined = canReview ? undefined : readable;
|
||||
if (q.till?.trim()) {
|
||||
const parsed = parseTill(db, q.till.trim());
|
||||
if (!parsed) return reply.code(400).send({ error: "unknown till", code: "bad_till" });
|
||||
if (!canReview && !readable.includes(parsed)) {
|
||||
return reply.code(403).send({ error: `your role cannot see the ${parsed} till`, code: "till_forbidden", till: parsed });
|
||||
}
|
||||
tills = [parsed];
|
||||
}
|
||||
const operator = canReview ? undefined : req.user.username;
|
||||
const movements = tills
|
||||
? tills.flatMap((till) => shift.movementsWithStatus({ operator, status, till })).sort((a, b) => (a.at < b.at ? 1 : a.at > b.at ? -1 : 0))
|
||||
: shift.movementsWithStatus({ operator, status });
|
||||
return { movements, scope: canReview ? "all" : "self" };
|
||||
});
|
||||
|
||||
// A till's physical drawer balance now. Same visibility as the open shift's X-report
|
||||
// (the till's read guard) — a drawer is a shared till, not per-operator data.
|
||||
app.get("/api/drawer/balance", { preHandler: requireTill(db, "read", "query") }, async (req) => ({
|
||||
till: req.till!,
|
||||
...shift.drawerBalance(req.till!),
|
||||
}));
|
||||
|
||||
// Admin AUTHORIZES or DENIES a recorded movement. A flag only — no cash reversal.
|
||||
app.post<{ Body: ReviewBody }>("/api/drawer/review", { preHandler: reviewGuard }, async (req, reply) => {
|
||||
const b = req.body ?? ({} as ReviewBody);
|
||||
if (!b.refId || (b.decision !== "authorize" && b.decision !== "deny")) {
|
||||
return reply.code(400).send({ error: "refId and decision (authorize|deny) are required" });
|
||||
}
|
||||
try {
|
||||
return await shift.reviewMovement({
|
||||
refId: b.refId,
|
||||
decision: b.decision,
|
||||
reviewedBy: req.user.username,
|
||||
note: b.note,
|
||||
});
|
||||
} catch (err) {
|
||||
if (err instanceof InvalidCashMovementError) return reply.code(400).send({ error: err.message });
|
||||
return reply.code(500).send({ error: (err as Error).message });
|
||||
}
|
||||
});
|
||||
}
|
||||
@@ -0,0 +1,35 @@
|
||||
import type { FastifyInstance } from "fastify";
|
||||
import { requirePermission } from "../auth.js";
|
||||
import type { EntryFlow } from "../entry-flow.js";
|
||||
import type { LaneStatus } from "../lane-status.js";
|
||||
import type { ShiftService } from "../shift-service.js";
|
||||
import { NoShiftOpenError } from "../shift-service.js";
|
||||
|
||||
// Operator-issued entry (2026-07-01). When the physical entry button is broken, an operator
|
||||
// may issue an entry ticket — a FLAGGED mint (vehicle_entry source=manual + operatorInitiated
|
||||
// + a companion anomaly), gated EXACTLY like the physical button: a real vehicle must be
|
||||
// present (radar/loop AND camera). The presence gate is enforced HERE (server-side), so a
|
||||
// direct POST can't bypass a disabled UI button. Money-adjacent → requires an open shift.
|
||||
// See wiki/concepts/operator-issued-entry.md.
|
||||
|
||||
export async function entryRoutes(
|
||||
app: FastifyInstance,
|
||||
entryFlow: EntryFlow,
|
||||
laneStatus: LaneStatus,
|
||||
shift: ShiftService,
|
||||
): Promise<void> {
|
||||
const guard = requirePermission("session:create");
|
||||
|
||||
app.post("/api/entry/issue", { preHandler: guard }, async (req, reply) => {
|
||||
// Gate on an open shift (a minted entry belongs to an accountable operator).
|
||||
if (!shift.currentOpenShift()) {
|
||||
return reply.code(409).send({ error: new NoShiftOpenError().message });
|
||||
}
|
||||
// The camera side of the presence gate = the live entry lane-busy state; the radar/loop
|
||||
// side is checked inside the flow (its per-relay presence guard).
|
||||
const cameraBusy = laneStatus.snapshot().entry;
|
||||
const res = await entryFlow.issueForOperator(req.user.username, cameraBusy);
|
||||
if (!res.ok) return reply.code(409).send({ error: res.reason });
|
||||
return res;
|
||||
});
|
||||
}
|
||||
@@ -1,7 +1,8 @@
|
||||
import type { FastifyInstance } from "fastify";
|
||||
import { and, desc, gte, lte, ledgerEvents, type Db } from "@parking/db";
|
||||
import type { LedgerEvent } from "@parking/shared";
|
||||
import { requirePermission } from "../auth.js";
|
||||
import { and, desc, gte, inArray, lte, sql, ledgerEvents, type Db } from "@parking/db";
|
||||
import { BOOTH_TILL, MODULES, feedPermissionFor, isTillId, type LedgerEvent, type LedgerEventType } from "@parking/shared";
|
||||
import { requireAuth, requirePermission, roleHasPermissions } from "../auth.js";
|
||||
import { effectiveModulesFor } from "../modules.js";
|
||||
import { enrichEvents } from "../event-enrich.js";
|
||||
import type { EventLog } from "../event-log.js";
|
||||
|
||||
@@ -15,25 +16,59 @@ export async function eventRoutes(
|
||||
db: Db,
|
||||
eventLog: EventLog,
|
||||
): Promise<void> {
|
||||
// Reading the log (the audit trail).
|
||||
const guard = requirePermission("event:read");
|
||||
// Reading the log (the audit trail). `event:read` reads everything; a role WITHOUT it
|
||||
// may still hold a module's feed permission (a wash operator's `carwash:read`) and
|
||||
// then reads ONLY that module's event types — the same rule the live socket applies
|
||||
// (feedPermissionFor; venue-modules.md §Permissions matrix, move 3).
|
||||
|
||||
/** The event types a role may read, or null for "everything" (event:read). Empty =
|
||||
* the role reads nothing → 403 at the route. */
|
||||
function readableTypes(roleId: string): LedgerEventType[] | null {
|
||||
if (roleHasPermissions(roleId, ["event:read"])) return null;
|
||||
const effective = effectiveModulesFor(db);
|
||||
const out: LedgerEventType[] = [];
|
||||
for (const m of MODULES) {
|
||||
if (!m.feedPermission || !effective.includes(m.id)) continue;
|
||||
if (roleHasPermissions(roleId, [m.feedPermission])) out.push(...m.ledgerEventTypes);
|
||||
}
|
||||
return out;
|
||||
}
|
||||
|
||||
/** SQL form of the shared `tillOfEvent` rule: the payload's `till`, else the till of
|
||||
* the module owning the event type, else the booth. Computed in the query so the
|
||||
* page limit applies AFTER the till filter (a shift's window can hold thousands of
|
||||
* device events). */
|
||||
const tillExpr = (() => {
|
||||
const cases = MODULES.filter((m) => m.till && m.till !== BOOTH_TILL && m.ledgerEventTypes.length > 0).map(
|
||||
(m) => sql`when ${ledgerEvents.type} in (${sql.join(m.ledgerEventTypes.map((t) => sql`${t}`), sql`, `)}) then ${m.till}`,
|
||||
);
|
||||
return sql`coalesce(json_extract(${ledgerEvents.payload}, '$.till'), case ${sql.join(cases, sql` `)} else ${BOOTH_TILL} end)`;
|
||||
})();
|
||||
|
||||
// Recent events, newest first. `limit` caps the page (default 100, max 1000).
|
||||
// Optional `since` (ISO) scopes to events at/after that instant — the booth passes
|
||||
// the current shift's start so the live feed shows ONLY this shift's activity. An
|
||||
// optional `until` (ISO) closes the upper bound — the shift-history screen passes a
|
||||
// selected shift's [start, end] to show just that shift's signed activity log.
|
||||
// (logs are per-shift, not all history). See wiki/concepts/shift.md.
|
||||
app.get<{ Querystring: { limit?: string; since?: string; until?: string } }>(
|
||||
// (logs are per-shift, not all history). An optional `till` keeps only that till's
|
||||
// activity (tillOfEvent) — a booth shift's log no longer shows the wash desk's, and
|
||||
// vice versa. See wiki/concepts/shift.md §Tills.
|
||||
app.get<{ Querystring: { limit?: string; since?: string; until?: string; till?: string } }>(
|
||||
"/api/events",
|
||||
{ preHandler: guard },
|
||||
async (req) => {
|
||||
{ preHandler: requireAuth },
|
||||
async (req, reply) => {
|
||||
const types = readableTypes(req.user?.roleId ?? "");
|
||||
if (types && types.length === 0) return reply.code(403).send({ error: "forbidden" });
|
||||
const limit = Math.min(Math.max(Number(req.query.limit) || 100, 1), 1000);
|
||||
const since = (req.query.since ?? "").trim();
|
||||
const until = (req.query.until ?? "").trim();
|
||||
const till = (req.query.till ?? "").trim();
|
||||
if (till && !isTillId(till)) return reply.code(400).send({ error: "unknown till", code: "bad_till" });
|
||||
const bounds = [
|
||||
since ? gte(ledgerEvents.occurredAt, since) : undefined,
|
||||
until ? lte(ledgerEvents.occurredAt, until) : undefined,
|
||||
till ? sql`${tillExpr} = ${till}` : undefined,
|
||||
types ? inArray(ledgerEvents.type, types) : undefined,
|
||||
].filter(Boolean);
|
||||
const rows = db
|
||||
.select()
|
||||
|
||||
@@ -0,0 +1,289 @@
|
||||
import { afterEach, beforeEach, describe, expect, it, vi } from "vitest";
|
||||
import Fastify, { type FastifyInstance as RawFastify } from "fastify";
|
||||
import { createTestDb } from "@parking/db/testing";
|
||||
import { and, eq, inArray, devices, deviceEvents as deviceEventsTable, type Db } from "@parking/db";
|
||||
import type { FastifyInstance } from "fastify";
|
||||
import { buildServer } from "../server.js";
|
||||
import { hikvisionAlarmRoutes } from "./hikvision-alarm.js";
|
||||
import type { AnprBridge } from "../anpr-entry.js";
|
||||
import { seedUser, login } from "../test-helpers.js";
|
||||
|
||||
// Hikvision Alarm Server push ingress. Verifies the discovery endpoint: a vehicle-
|
||||
// detection POST from the camera's configured IP is accepted, summarized (eventType /
|
||||
// target / plate pulled out of the XML), and recorded verbatim as a kind:"alarm"
|
||||
// device_event — while a wrong source IP or a push-disabled device is refused.
|
||||
|
||||
const CAM_IP = "10.0.10.121";
|
||||
const CAM_ID = "cam-1";
|
||||
|
||||
let db: Db;
|
||||
let close: () => void;
|
||||
let app: FastifyInstance;
|
||||
|
||||
beforeEach(async () => {
|
||||
const t = createTestDb();
|
||||
db = t.db;
|
||||
close = t.close;
|
||||
app = await buildServer({ db });
|
||||
await app.ready();
|
||||
});
|
||||
afterEach(async () => {
|
||||
await app.close();
|
||||
close();
|
||||
});
|
||||
|
||||
function seedHikCamera(cfg: Record<string, unknown> = {}) {
|
||||
db.insert(devices).values({
|
||||
id: CAM_ID,
|
||||
category: "camera",
|
||||
driverId: "hikvision",
|
||||
config: { host: CAM_IP, alarmPushEnabled: true, ...cfg },
|
||||
enabled: true,
|
||||
}).run();
|
||||
}
|
||||
|
||||
/** A representative Hikvision smart-event POST body (vehicle target). The real firmware
|
||||
* payload may differ; the endpoint stores it verbatim regardless — this asserts the
|
||||
* best-effort summary extraction over a plausible shape. */
|
||||
const VEHICLE_XML = `<?xml version="1.0" encoding="UTF-8"?>
|
||||
<EventNotificationAlert version="2.0" xmlns="http://www.hikvision.com/ver20/XMLSchema">
|
||||
<ipAddress>10.0.10.121</ipAddress>
|
||||
<channelID>1</channelID>
|
||||
<dateTime>2026-06-22T10:15:30+02:00</dateTime>
|
||||
<eventType>fielddetection</eventType>
|
||||
<eventState>active</eventState>
|
||||
<DetectionRegionList>
|
||||
<DetectionRegionEntry><detectionTarget>vehicle</detectionTarget></DetectionRegionEntry>
|
||||
</DetectionRegionList>
|
||||
</EventNotificationAlert>`;
|
||||
|
||||
function alarmEvents(): { detail: Record<string, unknown> }[] {
|
||||
return db
|
||||
.select()
|
||||
.from(deviceEventsTable)
|
||||
.where(and(eq(deviceEventsTable.deviceId, CAM_ID), eq(deviceEventsTable.kind, "alarm")))
|
||||
.all() as { detail: Record<string, unknown> }[];
|
||||
}
|
||||
|
||||
/** Every recorded push for a device — accepted (kind:"alarm") AND rejected
|
||||
* (kind:"alarm-rejected"). */
|
||||
function allRecorded(deviceId: string): { kind: string; detail: Record<string, unknown> }[] {
|
||||
return db
|
||||
.select()
|
||||
.from(deviceEventsTable)
|
||||
.where(and(eq(deviceEventsTable.deviceId, deviceId), inArray(deviceEventsTable.kind, ["alarm", "alarm-rejected"])))
|
||||
.all() as { kind: string; detail: Record<string, unknown> }[];
|
||||
}
|
||||
|
||||
describe("Hikvision Alarm Server push", () => {
|
||||
it("accepts a vehicle event from the camera IP and records it with a parsed summary", async () => {
|
||||
seedHikCamera();
|
||||
const res = await app.inject({
|
||||
method: "POST",
|
||||
url: `/api/devices/hikvision/${CAM_ID}/event`,
|
||||
headers: { "content-type": "application/xml" },
|
||||
payload: VEHICLE_XML,
|
||||
remoteAddress: CAM_IP,
|
||||
});
|
||||
expect(res.statusCode).toBe(200);
|
||||
|
||||
const events = alarmEvents();
|
||||
expect(events).toHaveLength(1);
|
||||
const d = events[0]!.detail;
|
||||
expect(d.source).toBe("hikvision-alarm-server");
|
||||
expect(d.eventType).toBe("fielddetection");
|
||||
expect(d.target).toBe("vehicle");
|
||||
expect(d.ip).toBe(CAM_IP);
|
||||
// The raw body is kept verbatim for inspection.
|
||||
expect(String(d.rawHead)).toContain("EventNotificationAlert");
|
||||
});
|
||||
|
||||
it("accepts the legacy string \"true\" for alarmPushEnabled (setup form quirk)", async () => {
|
||||
// The setup checkbox historically saved a STRING "true" instead of a boolean; the
|
||||
// guard must coerce it, not silently reject a feature the admin enabled.
|
||||
seedHikCamera({ alarmPushEnabled: "true" });
|
||||
const res = await app.inject({
|
||||
method: "POST",
|
||||
url: `/api/devices/hikvision/${CAM_ID}/event`,
|
||||
headers: { "content-type": "application/xml" },
|
||||
payload: VEHICLE_XML,
|
||||
remoteAddress: CAM_IP,
|
||||
});
|
||||
expect(res.statusCode).toBe(200);
|
||||
expect(alarmEvents()).toHaveLength(1);
|
||||
});
|
||||
|
||||
it("pulls a plate out of an ANPR-style payload when present", async () => {
|
||||
seedHikCamera();
|
||||
const anpr = `<EventNotificationAlert><eventType>ANPR</eventType>
|
||||
<ANPR><plateNumber>AA123BB</plateNumber></ANPR></EventNotificationAlert>`;
|
||||
const res = await app.inject({
|
||||
method: "POST",
|
||||
url: `/api/devices/hikvision/${CAM_ID}/event`,
|
||||
headers: { "content-type": "application/xml" },
|
||||
payload: anpr,
|
||||
remoteAddress: CAM_IP,
|
||||
});
|
||||
expect(res.statusCode).toBe(200);
|
||||
expect(alarmEvents()[0]!.detail.plate).toBe("AA123BB");
|
||||
});
|
||||
|
||||
it("accepts an unknown/JSON content-type as raw bytes (discovery-first)", async () => {
|
||||
seedHikCamera();
|
||||
const res = await app.inject({
|
||||
method: "POST",
|
||||
url: `/api/devices/hikvision/${CAM_ID}/event`,
|
||||
headers: { "content-type": "application/octet-stream" },
|
||||
payload: Buffer.from('{"eventType":"vehicleDetection"}'),
|
||||
remoteAddress: CAM_IP,
|
||||
});
|
||||
expect(res.statusCode).toBe(200);
|
||||
expect(alarmEvents()[0]!.detail.eventType).toBe("vehicleDetection");
|
||||
});
|
||||
|
||||
it("accepts a push from ANY source IP when skipSourceIpCheck is set (WSL rewrites it)", async () => {
|
||||
// WSL mirrored mode rewrites the inbound source to the host's own IP, so the camera's
|
||||
// real IP never survives and a strict check rejects every push. With the opt-out, a
|
||||
// push from the 'wrong' IP is accepted.
|
||||
seedHikCamera({ skipSourceIpCheck: true });
|
||||
const res = await app.inject({
|
||||
method: "POST",
|
||||
url: `/api/devices/hikvision/${CAM_ID}/event`,
|
||||
headers: { "content-type": "application/xml" },
|
||||
payload: VEHICLE_XML,
|
||||
remoteAddress: "10.0.10.203", // the rewritten host IP, NOT the camera's
|
||||
});
|
||||
expect(res.statusCode).toBe(200);
|
||||
expect(alarmEvents()).toHaveLength(1);
|
||||
expect(alarmEvents()[0]!.detail.target).toBe("vehicle");
|
||||
});
|
||||
|
||||
it("rejects a push from a DIFFERENT source IP (404, nothing recorded)", async () => {
|
||||
seedHikCamera();
|
||||
const res = await app.inject({
|
||||
method: "POST",
|
||||
url: `/api/devices/hikvision/${CAM_ID}/event`,
|
||||
headers: { "content-type": "application/xml" },
|
||||
payload: VEHICLE_XML,
|
||||
remoteAddress: "10.0.10.200", // not the camera
|
||||
});
|
||||
expect(res.statusCode).toBe(404);
|
||||
// No ACCEPTED alarm...
|
||||
expect(alarmEvents()).toHaveLength(0);
|
||||
// ...but the rejection IS recorded (with the reason), so "nothing arrived" is never
|
||||
// ambiguous — you can see it came in and why it was refused.
|
||||
const recorded = allRecorded(CAM_ID);
|
||||
expect(recorded).toHaveLength(1);
|
||||
expect(recorded[0]!.kind).toBe("alarm-rejected");
|
||||
expect(String(recorded[0]!.detail.reason)).toMatch(/source IP/i);
|
||||
});
|
||||
|
||||
it("rejects when alarm push is disabled on the device", async () => {
|
||||
seedHikCamera({ alarmPushEnabled: false });
|
||||
const res = await app.inject({
|
||||
method: "POST",
|
||||
url: `/api/devices/hikvision/${CAM_ID}/event`,
|
||||
headers: { "content-type": "application/xml" },
|
||||
payload: VEHICLE_XML,
|
||||
remoteAddress: CAM_IP,
|
||||
});
|
||||
expect(res.statusCode).toBe(404);
|
||||
});
|
||||
|
||||
it("rejects an unknown device id", async () => {
|
||||
const res = await app.inject({
|
||||
method: "POST",
|
||||
url: `/api/devices/hikvision/nope/event`,
|
||||
headers: { "content-type": "application/xml" },
|
||||
payload: VEHICLE_XML,
|
||||
remoteAddress: CAM_IP,
|
||||
});
|
||||
expect(res.statusCode).toBe(404);
|
||||
expect(res.json().reason).toMatch(/unknown device/i);
|
||||
});
|
||||
|
||||
it("GET /api/devices/hikvision/alarms lists accepted AND rejected pushes, newest first", async () => {
|
||||
seedHikCamera();
|
||||
// One accepted (right IP) + one rejected (wrong IP).
|
||||
await app.inject({ method: "POST", url: `/api/devices/hikvision/${CAM_ID}/event`, headers: { "content-type": "application/xml" }, payload: VEHICLE_XML, remoteAddress: CAM_IP });
|
||||
await app.inject({ method: "POST", url: `/api/devices/hikvision/${CAM_ID}/event`, headers: { "content-type": "application/xml" }, payload: VEHICLE_XML, remoteAddress: "10.0.10.200" });
|
||||
|
||||
const { username, password } = await seedUser(db, { username: "admin1", roleId: "admin" });
|
||||
const { cookie } = await login(app, username, password);
|
||||
const res = await app.inject({ method: "GET", url: "/api/devices/hikvision/alarms", headers: { cookie } });
|
||||
expect(res.statusCode).toBe(200);
|
||||
const body = res.json();
|
||||
expect(body.count).toBe(2);
|
||||
// Both accepted and rejected appear, with the accepted/reason flags.
|
||||
expect(body.alarms.some((a: { accepted: boolean }) => a.accepted === true)).toBe(true);
|
||||
const rejected = body.alarms.find((a: { accepted: boolean }) => a.accepted === false);
|
||||
expect(rejected.reason).toMatch(/source IP/i);
|
||||
});
|
||||
|
||||
it("the alarms read endpoint is gated (device:read) — 401 without a session", async () => {
|
||||
const res = await app.inject({ method: "GET", url: "/api/devices/hikvision/alarms" });
|
||||
expect(res.statusCode).toBe(401);
|
||||
});
|
||||
});
|
||||
|
||||
// The ANPR bridge is handed each vehicle detection (fire-and-forget). We register the
|
||||
// routes on a bare instance with a SPY bridge to assert exactly when it's invoked —
|
||||
// only on a vehicle target that isn't `inactive`. (The bridge's own logic is covered in
|
||||
// anpr-entry.test.ts.)
|
||||
describe("Hikvision Alarm Server → ANPR bridge wiring", () => {
|
||||
let rawApp: RawFastify;
|
||||
let rawDb: Db;
|
||||
let rawClose: () => void;
|
||||
let onVehicleDetected: ReturnType<typeof vi.fn>;
|
||||
|
||||
beforeEach(async () => {
|
||||
const t = createTestDb();
|
||||
rawDb = t.db;
|
||||
rawClose = t.close;
|
||||
onVehicleDetected = vi.fn(async () => {});
|
||||
const bridge = { onVehicleDetected } as unknown as AnprBridge;
|
||||
rawApp = Fastify();
|
||||
await hikvisionAlarmRoutes(rawApp, rawDb, undefined, bridge);
|
||||
await rawApp.ready();
|
||||
rawDb.insert(devices).values({
|
||||
id: CAM_ID,
|
||||
category: "camera",
|
||||
driverId: "hikvision",
|
||||
config: { host: CAM_IP, alarmPushEnabled: true },
|
||||
enabled: true,
|
||||
}).run();
|
||||
});
|
||||
afterEach(async () => {
|
||||
await rawApp.close();
|
||||
rawClose();
|
||||
});
|
||||
|
||||
async function post(payload: string) {
|
||||
return rawApp.inject({
|
||||
method: "POST",
|
||||
url: `/api/devices/hikvision/${CAM_ID}/event`,
|
||||
headers: { "content-type": "application/xml" },
|
||||
payload,
|
||||
remoteAddress: CAM_IP,
|
||||
});
|
||||
}
|
||||
|
||||
it("hands a vehicle (active) detection to the bridge", async () => {
|
||||
const res = await post(VEHICLE_XML);
|
||||
expect(res.statusCode).toBe(200);
|
||||
expect(onVehicleDetected).toHaveBeenCalledTimes(1);
|
||||
expect(onVehicleDetected).toHaveBeenCalledWith(CAM_ID);
|
||||
});
|
||||
|
||||
it("does NOT call the bridge for a human target", async () => {
|
||||
const human = VEHICLE_XML.replace("vehicle", "human");
|
||||
await post(human);
|
||||
expect(onVehicleDetected).not.toHaveBeenCalled();
|
||||
});
|
||||
|
||||
it("does NOT call the bridge on an `inactive` (leave) vehicle event", async () => {
|
||||
const leave = VEHICLE_XML.replace("<eventState>active</eventState>", "<eventState>inactive</eventState>");
|
||||
await post(leave);
|
||||
expect(onVehicleDetected).not.toHaveBeenCalled();
|
||||
});
|
||||
});
|
||||
@@ -0,0 +1,280 @@
|
||||
import { randomUUID } from "node:crypto";
|
||||
import type { FastifyInstance, FastifyReply, FastifyRequest } from "fastify";
|
||||
import { desc, eq, inArray, devices, deviceEvents as deviceEventsTable, type Db } from "@parking/db";
|
||||
import { deviceEvents } from "../device-events.js";
|
||||
import { requirePermission } from "../auth.js";
|
||||
import { verifyDigest } from "../digest-auth.js";
|
||||
import type { LaneStatus } from "../lane-status.js";
|
||||
import type { AnprBridge } from "../anpr-entry.js";
|
||||
|
||||
// Hikvision "Alarm Server" event PUSH ingress. The newer-firmware cameras (Event →
|
||||
// Smart/VCA with "Detection Target: Human/Vehicle", Notify Surveillance Center, Alarm
|
||||
// Settings → Alarm Server) HTTP-POST an EventNotificationAlert to a URL we host every
|
||||
// time the chosen target is detected. This is the same machine-call pattern as the
|
||||
// Dingtian Input Link push (routes/devices.ts): source-IP guarded, NOT behind the SPA
|
||||
// cookie/CSRF.
|
||||
//
|
||||
// DISCOVERY-FIRST. Hik's push format varies by model/firmware (event XML, or multipart
|
||||
// with an attached JPEG, or — on some ANPR units — an <ANPR>/<plateNumber> block). So
|
||||
// this endpoint is deliberately PERMISSIVE: it accepts ANY content-type as raw bytes,
|
||||
// records the verbatim body as a `kind:"alarm"` device_event, and best-effort extracts a
|
||||
// summary (eventType / target / plate). The goal of this first cut is to SEE exactly what
|
||||
// a given camera sends — inspect via GET /api/events or the logs — before we wire it into
|
||||
// the read bus / a snapshot trigger. It never opens a barrier (a plate read is advisory,
|
||||
// never the sole reason; see wiki/concepts/append-only-event-chain.md).
|
||||
//
|
||||
// See wiki/entities/lpr-camera.md, wiki/concepts/device-input-flow.md.
|
||||
|
||||
interface HikDeviceConfig {
|
||||
host?: string;
|
||||
alarmPushEnabled?: boolean | string | number;
|
||||
pushUser?: string;
|
||||
pushPassword?: string;
|
||||
/** Skip the source-IP guard for this device's pushes. The source IP is the primary
|
||||
* LAN guard, but it's UNRELIABLE in some environments — notably WSL mirrored mode,
|
||||
* which rewrites an inbound packet's source to the host's OWN address, so the camera's
|
||||
* real IP never survives and a strict check rejects every push. When pushUser/
|
||||
* pushPassword (Digest) are set, that auth is the real guard and source-IP adds little;
|
||||
* this flag lets a deployment opt out. The signed ledger remains the anti-fraud truth. */
|
||||
skipSourceIpCheck?: boolean | string | number;
|
||||
}
|
||||
|
||||
/** Coerce a device-config flag to a boolean. The config is loosely-typed JSON from the
|
||||
* setup form, which has historically stored a checkbox as the STRING "true" (a form-
|
||||
* serialization quirk) — so accept true / "true" / 1 / "1" / "yes" / "on", reject the
|
||||
* rest. Being lenient here means a stray "true" never silently disables a real feature. */
|
||||
function isOn(v: unknown): boolean {
|
||||
if (v === true) return true;
|
||||
if (typeof v === "number") return v === 1;
|
||||
if (typeof v === "string") return /^(1|true|yes|on)$/i.test(v.trim());
|
||||
return false;
|
||||
}
|
||||
|
||||
/** A best-effort summary pulled out of the raw push body (XML or JSON), for the device
|
||||
* event detail + the log line. Absent fields just mean "not found in this firmware's
|
||||
* payload" — the raw body is always stored so nothing is lost. */
|
||||
interface AlarmSummary {
|
||||
eventType?: string;
|
||||
/** `active` (target entered the region) | `inactive` (target left). The edge that
|
||||
* drives lane busy/free — see [[lpr-camera]] / hikvision-alarm.ts. */
|
||||
eventState?: string;
|
||||
target?: string;
|
||||
plate?: string;
|
||||
dateTime?: string;
|
||||
channelId?: string;
|
||||
}
|
||||
|
||||
function clientIp(req: FastifyRequest): string {
|
||||
return req.ip.replace(/^::ffff:/, "");
|
||||
}
|
||||
|
||||
/** First capture group of `re` in `s`, trimmed, or undefined. */
|
||||
function pick(s: string, re: RegExp): string | undefined {
|
||||
const m = re.exec(s);
|
||||
return m?.[1]?.trim() || undefined;
|
||||
}
|
||||
|
||||
/**
|
||||
* Best-effort summary extraction. Hikvision event XML uses tags like <eventType>,
|
||||
* <dateTime>, <channelID>; smart/ANPR events add target/plate tags whose exact names
|
||||
* vary by firmware (<detectionTarget>, <targetType>, <plateNumber>, <licensePlate>).
|
||||
* We probe several spellings; whatever doesn't match is simply absent. JSON bodies are
|
||||
* scanned for the same keys.
|
||||
*/
|
||||
function summarize(body: string): AlarmSummary {
|
||||
return {
|
||||
eventType: pick(body, /<eventType>([^<]+)<\/eventType>/i) ?? pick(body, /"eventType"\s*:\s*"([^"]+)"/i),
|
||||
eventState: pick(body, /<eventState>([^<]+)<\/eventState>/i) ?? pick(body, /"eventState"\s*:\s*"([^"]+)"/i),
|
||||
target:
|
||||
pick(body, /<(?:detectionTarget|targetType|objectType)>([^<]+)<\//i) ??
|
||||
pick(body, /"(?:detectionTarget|targetType|objectType)"\s*:\s*"([^"]+)"/i),
|
||||
plate:
|
||||
pick(body, /<(?:plateNumber|licensePlate|plateNo)>([^<]+)<\//i) ??
|
||||
pick(body, /"(?:plateNumber|licensePlate|plateNo)"\s*:\s*"([^"]+)"/i),
|
||||
dateTime: pick(body, /<dateTime>([^<]+)<\/dateTime>/i),
|
||||
channelId: pick(body, /<channelID>([^<]+)<\/channelID>/i) ?? pick(body, /<channelId>([^<]+)<\/channelId>/i),
|
||||
};
|
||||
}
|
||||
|
||||
export async function hikvisionAlarmRoutes(
|
||||
app: FastifyInstance,
|
||||
db: Db,
|
||||
laneStatus?: LaneStatus,
|
||||
anprBridge?: AnprBridge,
|
||||
): Promise<void> {
|
||||
// Accept ANY content-type as a raw Buffer (the camera may POST application/xml,
|
||||
// multipart/form-data with a JPEG, or text). Fastify's default JSON parser would 415
|
||||
// or empty these — we want the bytes verbatim. Scoped to THIS app instance via a
|
||||
// wildcard parser; a 10 MB cap covers an event + an attached frame.
|
||||
app.addContentTypeParser("*", { parseAs: "buffer", bodyLimit: 10 * 1024 * 1024 }, (_req, body, done) => {
|
||||
done(null, body);
|
||||
});
|
||||
|
||||
/** Record EVERY push (accepted or rejected) as a device_event so the read endpoint /
|
||||
* DB always shows that SOMETHING arrived — the key fix: a rejected push used to log a
|
||||
* warning and vanish, so "no event" was ambiguous (never sent? or sent + rejected?). */
|
||||
function record(args: {
|
||||
deviceId: string;
|
||||
method: string;
|
||||
accepted: boolean;
|
||||
reason?: string;
|
||||
ip: string;
|
||||
contentType: string;
|
||||
raw: Buffer;
|
||||
summary: AlarmSummary;
|
||||
}): void {
|
||||
try {
|
||||
db.insert(deviceEventsTable)
|
||||
.values({
|
||||
id: randomUUID(),
|
||||
deviceId: args.deviceId,
|
||||
category: "camera",
|
||||
kind: args.accepted ? "alarm" : "alarm-rejected",
|
||||
detail: {
|
||||
source: "hikvision-alarm-server",
|
||||
accepted: args.accepted,
|
||||
method: args.method,
|
||||
...(args.reason ? { reason: args.reason } : {}),
|
||||
ip: args.ip,
|
||||
contentType: args.contentType,
|
||||
bytes: args.raw.length,
|
||||
...args.summary,
|
||||
// Readable head verbatim (the XML part); truncated to keep the row small.
|
||||
rawHead: args.raw.toString("utf8").slice(0, 8000),
|
||||
},
|
||||
occurredAt: new Date().toISOString(),
|
||||
})
|
||||
.run();
|
||||
} catch (err) {
|
||||
app.log.error(`hik-alarm device-event insert failed: ${(err as Error).message}`);
|
||||
}
|
||||
}
|
||||
|
||||
const handle = async (req: FastifyRequest<{ Params: { deviceId: string } }>, reply: FastifyReply) => {
|
||||
const { deviceId } = req.params;
|
||||
const method = req.method;
|
||||
const row = await db.select().from(devices).where(eq(devices.id, deviceId)).get();
|
||||
const cfg = row?.config as HikDeviceConfig | undefined;
|
||||
const ip = clientIp(req);
|
||||
const contentType = String(req.headers["content-type"] ?? "");
|
||||
const raw: Buffer = Buffer.isBuffer(req.body) ? (req.body as Buffer) : Buffer.from("");
|
||||
const summary = summarize(raw.toString("utf8"));
|
||||
// Log EVERY hit immediately (method + ip + size), before any guard — so even a probe
|
||||
// that gets rejected is visible in the dev log the instant it arrives.
|
||||
app.log.info(`[hik-alarm:${deviceId}] HIT ${method} from ${ip} (${contentType || "no-ct"} ${raw.length}B)`);
|
||||
|
||||
// Guard: must be a known hikvision device with alarm-push enabled, posting from its
|
||||
// configured host IP. Source-IP is the primary guard on the LAN (like the Dingtian).
|
||||
// On rejection we STILL record it (with the precise reason) so a push that reached us
|
||||
// never silently disappears — that's what makes "is it coming?" answerable.
|
||||
// The source-IP check is skipped when the device opts out (skipSourceIpCheck) — needed
|
||||
// where the network rewrites the inbound source IP (e.g. WSL mirrored mode rewrites it
|
||||
// to the host's own address), so a strict match can never pass. Digest auth (when set)
|
||||
// and the signed ledger remain the real guards. See HikDeviceConfig.skipSourceIpCheck.
|
||||
const skipIp = isOn(cfg?.skipSourceIpCheck);
|
||||
let reason: string | null = null;
|
||||
if (!row || !cfg) reason = "unknown device id";
|
||||
else if (row.driverId !== "hikvision") reason = `device is ${row.driverId}, not hikvision`;
|
||||
else if (!isOn(cfg.alarmPushEnabled)) reason = "alarm push not enabled on this device (tick it in Setup)";
|
||||
else if (!cfg.host) reason = "device has no host IP configured";
|
||||
else if (!skipIp && ip !== cfg.host) reason = `source IP ${ip} != device host ${cfg.host} (set skipSourceIpCheck if the network rewrites it, e.g. WSL)`;
|
||||
|
||||
if (reason) {
|
||||
app.log.warn(`[hik-alarm:${deviceId}] REJECTED ${method} from ${ip} (${contentType} ${raw.length}B): ${reason}`);
|
||||
record({ deviceId, method, accepted: false, reason, ip, contentType, raw, summary });
|
||||
return reply.code(404).send({ error: "not found", reason });
|
||||
}
|
||||
|
||||
// Optional Digest auth — only when the admin configured push creds (some firmware
|
||||
// can't authenticate the Alarm Server call; then we rely on source-IP alone).
|
||||
if (cfg!.pushUser && cfg!.pushPassword) {
|
||||
if (!verifyDigest(req, reply, { user: cfg!.pushUser, password: cfg!.pushPassword })) {
|
||||
record({ deviceId, method, accepted: false, reason: "digest auth failed/challenge", ip, contentType, raw, summary });
|
||||
return; // 401 challenge already sent
|
||||
}
|
||||
}
|
||||
|
||||
// Loud log so the operator can SEE the payload during testing.
|
||||
app.log.info(
|
||||
`[hik-alarm:${deviceId}] ACCEPTED ${method} ${ip} ${contentType} ${raw.length}B ` +
|
||||
`event=${summary.eventType ?? "?"}/${summary.eventState ?? "?"} target=${summary.target ?? "?"} plate=${summary.plate ?? "-"}`,
|
||||
);
|
||||
record({ deviceId, method, accepted: true, ip, contentType, raw, summary });
|
||||
|
||||
// Lane busy/free: a VEHICLE detection marks the camera's bound lane busy (advisory,
|
||||
// for the booth barrier lights). Only on a vehicle target that's `active` — an
|
||||
// `inactive` (leave) isn't sent by this camera class, so the lane auto-clears on a
|
||||
// timeout in LaneStatus. We filter to vehicle per the booth's "vehicle only" intent.
|
||||
const isVehicleActive =
|
||||
(summary.target ?? "").toLowerCase() === "vehicle" &&
|
||||
(summary.eventState ?? "active").toLowerCase() !== "inactive";
|
||||
if (laneStatus && isVehicleActive) {
|
||||
laneStatus.vehicleDetected(deviceId);
|
||||
}
|
||||
|
||||
// ANPR BRIDGE: on a vehicle detection, if this camera opts into ANPR (config.anpr),
|
||||
// pull a snapshot → read the plate → if it matches a SUBSCRIBER, emit a plate read
|
||||
// onto the bus, which the existing gated SubscriptionFlow turns into an entry/exit +
|
||||
// barrier open. Fire-and-forget — NEVER awaited on the 200 path (the camera must get
|
||||
// a prompt ack or it retry-storms), and fail-soft inside the bridge. See anpr-entry.ts.
|
||||
if (anprBridge && isVehicleActive) {
|
||||
void anprBridge.onVehicleDetected(deviceId);
|
||||
}
|
||||
|
||||
// Surface on the in-process bus as a generic breadcrumb so a live listener can show
|
||||
// "camera saw a vehicle". NOT a DeviceReadEvent yet — that (plate identity driving
|
||||
// entry/exit) is the deliberate next step once we know the real payload.
|
||||
deviceEvents.emitInput({ driverId: "hikvision", deviceId, input: 0, edge: "on", at: new Date().toISOString(), source: "push" });
|
||||
|
||||
// 200 so the camera considers the alarm delivered and doesn't retry-storm.
|
||||
return reply.code(200).send({ ok: true });
|
||||
};
|
||||
|
||||
// Listen for EVERY method on the event path. The camera (and its "Test" button) may
|
||||
// probe with GET/HEAD/OPTIONS/PUT, not just POST — and a method we don't register gets
|
||||
// Fastify's generic 404, which the camera reads as "service available" while our
|
||||
// handler never runs (so nothing is recorded). Registering all methods means ANYTHING
|
||||
// that hits this URL reaches `handle` and is captured (the method is logged + stored),
|
||||
// so we can finally SEE exactly what the camera sends. See wiki/entities/lpr-camera.md.
|
||||
// (HEAD is auto-added by Fastify alongside GET — don't register it explicitly.)
|
||||
for (const method of ["POST", "GET", "PUT", "PATCH", "DELETE", "OPTIONS"] as const) {
|
||||
app.route({ method, url: "/api/devices/hikvision/:deviceId/event", handler: handle });
|
||||
}
|
||||
|
||||
// Read endpoint: the recent alarm pushes (accepted AND rejected), newest first — so you
|
||||
// can SEE in the browser whether events are arriving and why any were refused, instead
|
||||
// of grepping the dev log or querying SQLite. Gated device:read (admin device view).
|
||||
app.get<{ Querystring: { limit?: string } }>(
|
||||
"/api/devices/hikvision/alarms",
|
||||
{ preHandler: requirePermission("device:read") },
|
||||
async (req) => {
|
||||
const limit = Math.min(Math.max(Number(req.query.limit) || 50, 1), 500);
|
||||
const rows = db
|
||||
.select()
|
||||
.from(deviceEventsTable)
|
||||
.where(inArray(deviceEventsTable.kind, ["alarm", "alarm-rejected"]))
|
||||
.orderBy(desc(deviceEventsTable.occurredAt))
|
||||
.limit(limit)
|
||||
.all();
|
||||
const alarms = rows.map((r) => {
|
||||
const d = (r.detail ?? {}) as Record<string, unknown>;
|
||||
return {
|
||||
at: r.occurredAt,
|
||||
deviceId: r.deviceId,
|
||||
accepted: d.accepted === true,
|
||||
method: (d.method as string) ?? null,
|
||||
reason: (d.reason as string) ?? null,
|
||||
ip: (d.ip as string) ?? null,
|
||||
contentType: (d.contentType as string) ?? null,
|
||||
bytes: (d.bytes as number) ?? 0,
|
||||
eventType: (d.eventType as string) ?? null,
|
||||
eventState: (d.eventState as string) ?? null,
|
||||
target: (d.target as string) ?? null,
|
||||
plate: (d.plate as string) ?? null,
|
||||
rawHead: (d.rawHead as string) ?? null,
|
||||
};
|
||||
});
|
||||
return { count: alarms.length, alarms };
|
||||
},
|
||||
);
|
||||
}
|
||||
@@ -8,6 +8,7 @@ import {
|
||||
type PayStation,
|
||||
} from "../pay-station.js";
|
||||
import type { ExitFlow } from "../exit-flow.js";
|
||||
import type { VoidFlow } from "../void-flow.js";
|
||||
import { NoShiftOpenError, type ShiftService } from "../shift-service.js";
|
||||
import { printPaymentReceipt } from "../booth-print.js";
|
||||
|
||||
@@ -29,6 +30,9 @@ interface PayBody {
|
||||
}
|
||||
interface ExitBody {
|
||||
identity: string;
|
||||
/** Operator consciously releases a suspected plate-swap exit (re-submit after the
|
||||
* first call returned status "swap_suspected"). Signs an attributed override anomaly. */
|
||||
override?: boolean;
|
||||
}
|
||||
interface VoucherBody {
|
||||
identity: string;
|
||||
@@ -36,6 +40,10 @@ interface VoucherBody {
|
||||
interface ReceiptBody {
|
||||
identity: string;
|
||||
}
|
||||
interface VoidBody {
|
||||
identity: string;
|
||||
reason: string;
|
||||
}
|
||||
|
||||
export async function payRoutes(
|
||||
app: FastifyInstance,
|
||||
@@ -43,6 +51,7 @@ export async function payRoutes(
|
||||
payStation: PayStation,
|
||||
exitFlow: ExitFlow,
|
||||
shift: ShiftService,
|
||||
voidFlow: VoidFlow,
|
||||
): Promise<void> {
|
||||
// Reads (lookup, active sessions, quote) need session/payment read; the booth
|
||||
// money actions (pay, exit, voucher, receipt, reopen) need payment:create. A
|
||||
@@ -50,6 +59,7 @@ export async function payRoutes(
|
||||
// sessions. Read-only callers (a viewer role) get the reads but not the actions.
|
||||
const guard = requirePermission("payment:create");
|
||||
const readGuard = requirePermission("session:read");
|
||||
const voidGuard = requirePermission("event:void");
|
||||
|
||||
// Money-path gate: a shift must be open site-wide before any payment/exit/voucher/
|
||||
// re-open is processed, so every taking is attributed to a shift (one operator's
|
||||
@@ -102,8 +112,17 @@ export async function payRoutes(
|
||||
async (req, reply) => {
|
||||
const identity = (req.body?.identity ?? "").trim();
|
||||
if (!identity) return reply.code(400).send({ error: "identity required" });
|
||||
const res = await exitFlow.exitForBooth(identity);
|
||||
if (!res.ok) return reply.code(409).send({ error: res.reason, status: res.status });
|
||||
const res = await exitFlow.exitForBooth(identity, {
|
||||
override: req.body?.override === true,
|
||||
operator: req.user?.username,
|
||||
});
|
||||
// A suspected plate-swap returns the full detail so the modal can warn + offer override.
|
||||
if (!res.ok) {
|
||||
if (res.status === "swap_suspected") {
|
||||
return reply.code(409).send({ error: res.reason, status: res.status, plate: res.plate, otherIdentity: res.otherIdentity, otherEnteredAt: res.otherEnteredAt });
|
||||
}
|
||||
return reply.code(409).send({ error: res.reason, status: res.status });
|
||||
}
|
||||
return reply.code(200).send(res);
|
||||
},
|
||||
);
|
||||
@@ -125,6 +144,28 @@ export async function payRoutes(
|
||||
},
|
||||
);
|
||||
|
||||
// Cancel (void) a wrongly-printed transient ticket. Appends a SIGNED `void` event
|
||||
// referencing the entry, with the operator + a REQUIRED reason — the entry itself is
|
||||
// never edited/deleted (append-only). The session projection folds the void to CLOSED,
|
||||
// so the voided car stops counting inside and can't be paid/exited. Opens NO barrier
|
||||
// (the misprinted ticket's car never entered). Gated on event:void + an open shift
|
||||
// (the booth accountability period). Refusals (subscription / already exited / already
|
||||
// voided / already paid) → 409. See void-flow.ts, wiki/concepts/append-only-event-chain.md.
|
||||
app.post<{ Body: VoidBody }>(
|
||||
"/api/tickets/void",
|
||||
{ preHandler: [voidGuard, requireShift] },
|
||||
async (req, reply) => {
|
||||
const identity = (req.body?.identity ?? "").trim();
|
||||
const reason = (req.body?.reason ?? "").trim();
|
||||
if (!identity) return reply.code(400).send({ error: "identity required" });
|
||||
if (!reason) return reply.code(400).send({ error: "a cancellation reason is required" });
|
||||
const operator = req.user?.username ?? "unknown";
|
||||
const res = await voidFlow.voidTicket({ identity, reason, operator });
|
||||
if (!res.ok) return reply.code(409).send({ error: res.reason });
|
||||
return reply.code(201).send(res);
|
||||
},
|
||||
);
|
||||
|
||||
// Quote: what does this session owe right now? (No side effect.)
|
||||
app.get<{ Querystring: QuoteQuery }>(
|
||||
"/api/pay/quote",
|
||||
|
||||
@@ -0,0 +1,91 @@
|
||||
import { afterEach, beforeEach, describe, expect, it } from "vitest";
|
||||
import { ledgerEvents, type Db } from "@parking/db";
|
||||
import { createTestDb } from "@parking/db/testing";
|
||||
import type { FastifyInstance } from "fastify";
|
||||
import { buildServer } from "../server.js";
|
||||
import { seedUser, login } from "../test-helpers.js";
|
||||
|
||||
// PUT /api/site-config/presence-bypass toggles the entry presence-gate bypass. It's a
|
||||
// DEDICATED, SIGNED endpoint: each signal that actually changes appends a config_change to
|
||||
// the ledger (attributed), and it persists to site_config. Admin-only.
|
||||
|
||||
let db: Db;
|
||||
let close: () => void;
|
||||
let app: FastifyInstance;
|
||||
|
||||
beforeEach(async () => {
|
||||
const t = createTestDb();
|
||||
db = t.db;
|
||||
close = t.close;
|
||||
app = await buildServer({ db });
|
||||
await app.ready();
|
||||
});
|
||||
afterEach(async () => {
|
||||
await app.close();
|
||||
close();
|
||||
});
|
||||
|
||||
const configChanges = () => db.select().from(ledgerEvents).all().filter((r) => r.type === "config_change");
|
||||
|
||||
async function put(body: unknown, auth: { cookie: string; csrf: string }) {
|
||||
return app.inject({
|
||||
method: "PUT",
|
||||
url: "/api/site-config/presence-bypass",
|
||||
headers: { cookie: auth.cookie, "x-csrf-token": auth.csrf },
|
||||
payload: body as Record<string, unknown>,
|
||||
});
|
||||
}
|
||||
|
||||
describe("PUT /api/site-config/presence-bypass", () => {
|
||||
it("is admin-only: a non-site:update user is 403", async () => {
|
||||
await seedUser(db, { username: "op", password: "pw", roleId: "operator", permissions: ["shift:read"] });
|
||||
const auth = await login(app, "op", "pw");
|
||||
const res = await put({ camera: true }, auth);
|
||||
expect(res.statusCode).toBe(403);
|
||||
});
|
||||
|
||||
it("enabling a signal persists it AND signs an attributed config_change", async () => {
|
||||
await seedUser(db, { username: "admin", password: "pw" });
|
||||
const auth = await login(app, "admin", "pw");
|
||||
|
||||
const res = await put({ camera: true }, auth);
|
||||
expect(res.statusCode).toBe(200);
|
||||
expect(res.json()).toMatchObject({ bypassPresenceCamera: true, bypassPresenceRadar: false });
|
||||
|
||||
const changes = configChanges();
|
||||
expect(changes).toHaveLength(1);
|
||||
expect(changes[0].source).toBe("manual");
|
||||
expect(changes[0].signature.length).toBeGreaterThan(0);
|
||||
expect(changes[0].payload).toMatchObject({
|
||||
setting: "entryPresenceBypass.camera",
|
||||
value: true,
|
||||
prev: false,
|
||||
operator: "admin",
|
||||
});
|
||||
});
|
||||
|
||||
it("a no-op toggle (already in that state) signs nothing", async () => {
|
||||
await seedUser(db, { username: "admin", password: "pw" });
|
||||
const auth = await login(app, "admin", "pw");
|
||||
await put({ camera: true }, auth); // 1st: on → 1 event
|
||||
await put({ camera: true }, auth); // 2nd: still on → no new event
|
||||
expect(configChanges()).toHaveLength(1);
|
||||
});
|
||||
|
||||
it("disabling signs the off transition too (auditable both ways)", async () => {
|
||||
await seedUser(db, { username: "admin", password: "pw" });
|
||||
const auth = await login(app, "admin", "pw");
|
||||
await put({ radar: true }, auth);
|
||||
await put({ radar: false }, auth);
|
||||
const changes = configChanges();
|
||||
expect(changes).toHaveLength(2);
|
||||
expect(changes[1].payload).toMatchObject({ setting: "entryPresenceBypass.radar", value: false, prev: true });
|
||||
});
|
||||
|
||||
it("rejects a non-boolean and an empty body", async () => {
|
||||
await seedUser(db, { username: "admin", password: "pw" });
|
||||
const auth = await login(app, "admin", "pw");
|
||||
expect((await put({ camera: "yes" }, auth)).statusCode).toBe(400);
|
||||
expect((await put({}, auth)).statusCode).toBe(400);
|
||||
});
|
||||
});
|
||||
@@ -0,0 +1,184 @@
|
||||
import { afterEach, beforeEach, describe, expect, it } from "vitest";
|
||||
import { createTestDb } from "@parking/db/testing";
|
||||
import { eq, users, type Db } from "@parking/db";
|
||||
import type { FastifyInstance } from "fastify";
|
||||
import { buildServer } from "../server.js";
|
||||
import { seedUser, login } from "../test-helpers.js";
|
||||
|
||||
// Self-service profile (routes/auth.ts): /api/auth/profile + /api/auth/password. These act
|
||||
// ONLY on the signed-in user, need NO `user:*` permission (any role), and the password change
|
||||
// must prove the current password. Distinct from admin user-management (routes/users.ts).
|
||||
|
||||
let db: Db;
|
||||
let close: () => void;
|
||||
let app: FastifyInstance;
|
||||
|
||||
beforeEach(async () => {
|
||||
const t = createTestDb();
|
||||
db = t.db;
|
||||
close = t.close;
|
||||
app = await buildServer({ db });
|
||||
await app.ready();
|
||||
});
|
||||
afterEach(async () => {
|
||||
await app.close();
|
||||
close();
|
||||
});
|
||||
|
||||
describe("PUT /api/auth/profile (self-service)", () => {
|
||||
it("a permission-less user can edit their OWN name + email", async () => {
|
||||
// 'viewer' role with NO user:* permission — profile is not gated on it.
|
||||
const { username, password } = await seedUser(db, {
|
||||
username: "cashier", roleId: "viewer", permissions: [],
|
||||
});
|
||||
const { cookie, csrf } = await login(app, username, password);
|
||||
|
||||
const res = await app.inject({
|
||||
method: "PUT", url: "/api/auth/profile",
|
||||
headers: { cookie, "x-csrf-token": csrf },
|
||||
payload: { fullName: "Mon Kukaleshi", email: "mon@example.com" },
|
||||
});
|
||||
expect(res.statusCode).toBe(200);
|
||||
const body = res.json();
|
||||
expect(body.fullName).toBe("Mon Kukaleshi");
|
||||
expect(body.email).toBe("mon@example.com");
|
||||
// Persisted to the caller's own row.
|
||||
const row = db.select().from(users).where(eq(users.username, "cashier")).get();
|
||||
expect(row?.fullName).toBe("Mon Kukaleshi");
|
||||
expect(row?.email).toBe("mon@example.com");
|
||||
});
|
||||
|
||||
it('clears a field when sent ""', async () => {
|
||||
const { username, password } = await seedUser(db, { username: "u2", roleId: "viewer", permissions: [] });
|
||||
const { cookie, csrf } = await login(app, username, password);
|
||||
// First set a name…
|
||||
await app.inject({
|
||||
method: "PUT", url: "/api/auth/profile",
|
||||
headers: { cookie, "x-csrf-token": csrf },
|
||||
payload: { fullName: "Old Name" },
|
||||
});
|
||||
// …then clear it with whitespace (→ null).
|
||||
const res = await app.inject({
|
||||
method: "PUT", url: "/api/auth/profile",
|
||||
headers: { cookie, "x-csrf-token": csrf },
|
||||
payload: { fullName: " " },
|
||||
});
|
||||
expect(res.statusCode).toBe(200);
|
||||
expect(res.json().fullName).toBeNull();
|
||||
});
|
||||
|
||||
it("rejects an empty patch (nothing to update)", async () => {
|
||||
const { username, password } = await seedUser(db, { username: "u3", roleId: "viewer", permissions: [] });
|
||||
const { cookie, csrf } = await login(app, username, password);
|
||||
const res = await app.inject({
|
||||
method: "PUT", url: "/api/auth/profile",
|
||||
headers: { cookie, "x-csrf-token": csrf },
|
||||
payload: {},
|
||||
});
|
||||
expect(res.statusCode).toBe(400);
|
||||
});
|
||||
|
||||
it("requires a session (401 without a token)", async () => {
|
||||
const res = await app.inject({ method: "PUT", url: "/api/auth/profile", payload: { fullName: "x" } });
|
||||
expect(res.statusCode).toBe(401);
|
||||
});
|
||||
});
|
||||
|
||||
describe("PUT /api/auth/password (self-service)", () => {
|
||||
it("changes the password when the current one is correct, and the new one then logs in", async () => {
|
||||
const { username, password } = await seedUser(db, { username: "p1", roleId: "viewer", permissions: [] });
|
||||
const { cookie, csrf } = await login(app, username, password);
|
||||
|
||||
const res = await app.inject({
|
||||
method: "PUT", url: "/api/auth/password",
|
||||
headers: { cookie, "x-csrf-token": csrf },
|
||||
payload: { currentPassword: password, newPassword: "brand-new-pw-123" },
|
||||
});
|
||||
expect(res.statusCode).toBe(200);
|
||||
|
||||
// Old password no longer works; new one does.
|
||||
const oldTry = await app.inject({ method: "POST", url: "/api/auth/login", payload: { username, password } });
|
||||
expect(oldTry.statusCode).toBe(401);
|
||||
const newTry = await app.inject({ method: "POST", url: "/api/auth/login", payload: { username, password: "brand-new-pw-123" } });
|
||||
expect(newTry.statusCode).toBe(200);
|
||||
});
|
||||
|
||||
it("refuses when the current password is wrong (403) and leaves the password unchanged", async () => {
|
||||
const { username, password } = await seedUser(db, { username: "p2", roleId: "viewer", permissions: [] });
|
||||
const { cookie, csrf } = await login(app, username, password);
|
||||
const res = await app.inject({
|
||||
method: "PUT", url: "/api/auth/password",
|
||||
headers: { cookie, "x-csrf-token": csrf },
|
||||
payload: { currentPassword: "not-it", newPassword: "brand-new-pw-123" },
|
||||
});
|
||||
expect(res.statusCode).toBe(403);
|
||||
// Original password still works.
|
||||
const still = await app.inject({ method: "POST", url: "/api/auth/login", payload: { username, password } });
|
||||
expect(still.statusCode).toBe(200);
|
||||
});
|
||||
|
||||
it("rejects a too-short new password (400)", async () => {
|
||||
const { username, password } = await seedUser(db, { username: "p3", roleId: "viewer", permissions: [] });
|
||||
const { cookie, csrf } = await login(app, username, password);
|
||||
const res = await app.inject({
|
||||
method: "PUT", url: "/api/auth/password",
|
||||
headers: { cookie, "x-csrf-token": csrf },
|
||||
payload: { currentPassword: password, newPassword: "short" },
|
||||
});
|
||||
expect(res.statusCode).toBe(400);
|
||||
});
|
||||
});
|
||||
|
||||
describe("PUT /api/auth/font-scale (self-service)", () => {
|
||||
it("persists a valid scale and returns it on the next session", async () => {
|
||||
const { username, password } = await seedUser(db, { username: "f1", roleId: "viewer", permissions: [] });
|
||||
const { cookie, csrf } = await login(app, username, password);
|
||||
const res = await app.inject({
|
||||
method: "PUT", url: "/api/auth/font-scale",
|
||||
headers: { cookie, "x-csrf-token": csrf },
|
||||
payload: { fontScale: 120 },
|
||||
});
|
||||
expect(res.statusCode).toBe(200);
|
||||
expect(res.json().fontScale).toBe(120);
|
||||
// Persisted to the caller's row…
|
||||
expect(db.select().from(users).where(eq(users.username, "f1")).get()?.fontScale).toBe(120);
|
||||
// …and surfaced on /me (the session bootstrap).
|
||||
const me = await app.inject({ method: "GET", url: "/api/auth/me", headers: { cookie } });
|
||||
expect(me.json().fontScale).toBe(120);
|
||||
});
|
||||
|
||||
it("clamps + snaps out-of-band / off-step values", async () => {
|
||||
const { username, password } = await seedUser(db, { username: "f2", roleId: "viewer", permissions: [] });
|
||||
const { cookie, csrf } = await login(app, username, password);
|
||||
const tooBig = await app.inject({
|
||||
method: "PUT", url: "/api/auth/font-scale",
|
||||
headers: { cookie, "x-csrf-token": csrf },
|
||||
payload: { fontScale: 999 },
|
||||
});
|
||||
expect(tooBig.json().fontScale).toBe(160); // clamped to max
|
||||
const offStep = await app.inject({
|
||||
method: "PUT", url: "/api/auth/font-scale",
|
||||
headers: { cookie, "x-csrf-token": csrf },
|
||||
payload: { fontScale: 113 },
|
||||
});
|
||||
expect(offStep.json().fontScale).toBe(110); // snapped to the 10-step
|
||||
});
|
||||
|
||||
it("rejects a non-numeric scale (400)", async () => {
|
||||
const { username, password } = await seedUser(db, { username: "f3", roleId: "viewer", permissions: [] });
|
||||
const { cookie, csrf } = await login(app, username, password);
|
||||
const res = await app.inject({
|
||||
method: "PUT", url: "/api/auth/font-scale",
|
||||
headers: { cookie, "x-csrf-token": csrf },
|
||||
payload: { fontScale: "big" },
|
||||
});
|
||||
expect(res.statusCode).toBe(400);
|
||||
});
|
||||
|
||||
it("defaults to 100 for a fresh user", async () => {
|
||||
const { username, password } = await seedUser(db, { username: "f4", roleId: "viewer", permissions: [] });
|
||||
const { cookie } = await login(app, username, password);
|
||||
const me = await app.inject({ method: "GET", url: "/api/auth/me", headers: { cookie } });
|
||||
expect(me.json().fontScale).toBe(100);
|
||||
});
|
||||
});
|
||||
@@ -0,0 +1,101 @@
|
||||
import Fastify from "fastify";
|
||||
import { beforeEach, afterEach, describe, expect, it } from "vitest";
|
||||
import { devices, type Db } from "@parking/db";
|
||||
import { createTestDb } from "@parking/db/testing";
|
||||
import { qrReaderRoutes, splitChannel } from "./qr-reader.js";
|
||||
import { CredentialCapture } from "../credential-capture.js";
|
||||
import type { DeviceReadEvent, ReadOutcome } from "../device-events.js";
|
||||
import type { ReadDispatcher } from "../read-dispatch.js";
|
||||
|
||||
// CHANNEL TAGGING (2026-07-04): the DT-008's "QRCode Output Prefix" / "Card Output
|
||||
// Prefix" (vendor tool) mark which engine produced a push — Q: = optical, K: = RF.
|
||||
// The route strips the prefix, tags the read's confirmed channel, and enrollment
|
||||
// capture stores the BARE value. Unprefixed reads stay the legacy untagged shape so
|
||||
// an unconfigured reader keeps working. These tests pin the route-side contract;
|
||||
// the match-side enforcement is pinned in ../subscription-channel.test.ts.
|
||||
|
||||
const SERIAL = "H05MA5B0";
|
||||
const READER_ID = "reader-exit";
|
||||
|
||||
let db: Db;
|
||||
let app: ReturnType<typeof Fastify>;
|
||||
let capture: CredentialCapture;
|
||||
let seen: DeviceReadEvent[];
|
||||
|
||||
/** Dispatcher stub: records the event the route built, always rejects. */
|
||||
const fakeDispatcher = {
|
||||
dispatch: async (e: DeviceReadEvent): Promise<ReadOutcome> => {
|
||||
seen.push(e);
|
||||
return { accepted: false, reason: "test" };
|
||||
},
|
||||
} as unknown as ReadDispatcher;
|
||||
|
||||
beforeEach(async () => {
|
||||
({ db } = createTestDb());
|
||||
db.insert(devices).values({
|
||||
id: READER_ID,
|
||||
category: "reader",
|
||||
driverId: "dingtian-qr-reader",
|
||||
config: { serial: SERIAL },
|
||||
enabled: true,
|
||||
}).run();
|
||||
seen = [];
|
||||
capture = new CredentialCapture();
|
||||
app = Fastify({ logger: false });
|
||||
await qrReaderRoutes(app as never, db, fakeDispatcher, capture);
|
||||
});
|
||||
|
||||
afterEach(async () => {
|
||||
await app.close();
|
||||
});
|
||||
|
||||
const scan = (cardid: string) =>
|
||||
app.inject({ method: "GET", url: `/qa/mcardsea.php?cardid=${encodeURIComponent(cardid)}&cjihao=${SERIAL}&mjihao=1&status=10` });
|
||||
|
||||
describe("splitChannel", () => {
|
||||
it("K: prefix → bare value, kind card, channel rf", () => {
|
||||
expect(splitChannel("K:86A158")).toEqual({ value: "86A158", kind: "card", channel: "rf" });
|
||||
});
|
||||
it("Q: prefix → bare value, kind qr, channel optical", () => {
|
||||
expect(splitChannel("Q:12345678901")).toEqual({ value: "12345678901", kind: "qr", channel: "optical" });
|
||||
});
|
||||
it("no prefix → value untouched, legacy untagged qr", () => {
|
||||
expect(splitChannel("86A158")).toEqual({ value: "86A158", kind: "qr" });
|
||||
});
|
||||
});
|
||||
|
||||
describe("qr-reader route channel tagging", () => {
|
||||
it("card-prefixed push dispatches a stripped, rf-tagged read", async () => {
|
||||
const res = await scan("K:86A158");
|
||||
expect(res.statusCode).toBe(200);
|
||||
expect(seen).toHaveLength(1);
|
||||
expect(seen[0]).toMatchObject({ value: "86A158", kind: "card", channel: "rf", deviceId: READER_ID });
|
||||
});
|
||||
|
||||
it("qr-prefixed push dispatches a stripped, optical-tagged read", async () => {
|
||||
await scan("Q:00000000000");
|
||||
expect(seen[0]).toMatchObject({ value: "00000000000", kind: "qr", channel: "optical" });
|
||||
});
|
||||
|
||||
it("unprefixed push stays legacy: kind qr, no channel", async () => {
|
||||
await scan("86A158");
|
||||
expect(seen[0]).toMatchObject({ value: "86A158", kind: "qr" });
|
||||
expect(seen[0].channel).toBeUndefined();
|
||||
});
|
||||
|
||||
it("a bare prefix (empty value after strip) dispatches nothing", async () => {
|
||||
await scan("K:");
|
||||
expect(seen).toHaveLength(0);
|
||||
});
|
||||
|
||||
it("enrollment capture stores the BARE value, not the prefixed one", async () => {
|
||||
capture.arm(READER_ID);
|
||||
const res = await scan("K:86A158");
|
||||
expect(seen).toHaveLength(0); // intercepted — never dispatched to the access flow
|
||||
const state = capture.state();
|
||||
expect(state.status).toBe("captured");
|
||||
if (state.status === "captured") expect(state.value).toBe("86A158");
|
||||
// Beeps "ok" so the operator knows the card was read.
|
||||
expect(res.json().data[0].status).toBe(1);
|
||||
});
|
||||
});
|
||||
@@ -4,10 +4,10 @@ import type { DeviceReadEvent } from "../device-events.js";
|
||||
import type { ReadDispatcher } from "../read-dispatch.js";
|
||||
import type { CredentialCapture } from "../credential-capture.js";
|
||||
|
||||
// GEE/Dingtian QR reader endpoint. The reader is configured (vendor tool) with our
|
||||
// host as its "server"; on each scan it sends an HTTP GET and BEEPS/acts based on
|
||||
// Dingtian DT-008 QR/RFID reader endpoint. The reader is configured (vendor tool) with
|
||||
// our host as its "server"; on each scan it sends an HTTP GET and BEEPS/acts based on
|
||||
// our JSON reply — host-in-the-loop and synchronous. Protocol from the QRCode SDK
|
||||
// v1.6.5; see wiki/sources/qrcode-sdk.md and wiki/entities/gee-qr-er80.md.
|
||||
// v1.6.5; see wiki/sources/qrcode-sdk.md and wiki/entities/dingtian-dt008-reader.md.
|
||||
//
|
||||
// reader → GET /qa/mcardsea.php?cardid=<QR>&mjihao=<devId>&cjihao=<devSN>&status=<2ch>&time=<utc>
|
||||
// server → {"data":[{cardid,cjihao,mjihao,status,time,output}],"code":0,"message":""}
|
||||
@@ -27,6 +27,36 @@ interface ReaderQuery {
|
||||
time?: string;
|
||||
}
|
||||
|
||||
// ── CHANNEL TAGGING (2026-07-04) ────────────────────────────────────────────────
|
||||
// The DT-008 push carries one opaque `cardid` whether its OPTICAL engine decoded a
|
||||
// QR/barcode or its RF engine read a card — the server can't tell them apart. That
|
||||
// enabled a cheap clone: print a card's UID (often written on the card face) as a
|
||||
// barcode and the optical decode matches the RF credential. Fix: the vendor tool's
|
||||
// "QRCode Output Prefix" / "Card Output Prefix" are set to the markers below on every
|
||||
// reader; the route strips the prefix and tags the read's confirmed channel, and the
|
||||
// subscription match refuses a channel-mismatched credential. A read with NO prefix
|
||||
// stays the legacy untagged shape (kind "qr", channel undefined) so an unconfigured
|
||||
// reader keeps working — the enforcement only bites where prefixes are deployed.
|
||||
// ⚠️ Prefixes must MATCH the vendor tool; also FREEZE "Card Input format" (6H) — that
|
||||
// setting defines the UID shape we enroll. See wiki/entities/dingtian-dt008-reader.md.
|
||||
const QR_CHANNEL_PREFIX = process.env.READER_QR_PREFIX ?? "Q:";
|
||||
const CARD_CHANNEL_PREFIX = process.env.READER_CARD_PREFIX ?? "K:";
|
||||
|
||||
/** Split a raw pushed `cardid` into its bare value + confirmed channel (if prefixed). */
|
||||
export function splitChannel(raw: string): {
|
||||
value: string;
|
||||
kind: "qr" | "card";
|
||||
channel?: "optical" | "rf";
|
||||
} {
|
||||
if (CARD_CHANNEL_PREFIX.length > 0 && raw.startsWith(CARD_CHANNEL_PREFIX)) {
|
||||
return { value: raw.slice(CARD_CHANNEL_PREFIX.length), kind: "card", channel: "rf" };
|
||||
}
|
||||
if (QR_CHANNEL_PREFIX.length > 0 && raw.startsWith(QR_CHANNEL_PREFIX)) {
|
||||
return { value: raw.slice(QR_CHANNEL_PREFIX.length), kind: "qr", channel: "optical" };
|
||||
}
|
||||
return { value: raw, kind: "qr" }; // legacy: unprefixed reader, channel unknown
|
||||
}
|
||||
|
||||
export async function qrReaderRoutes(
|
||||
app: FastifyInstance,
|
||||
db: Db,
|
||||
@@ -35,7 +65,7 @@ export async function qrReaderRoutes(
|
||||
): Promise<void> {
|
||||
// Resolve the lane_devices row whose config.serial matches the reader's reported
|
||||
// serial (cjihao). The row id is a normal UUID; the serial is config the admin
|
||||
// enters when assigning the gee-qr-reader. Returns the row id, or null if no
|
||||
// enters when assigning the dingtian-qr-reader. Returns the row id, or null if no
|
||||
// reader is assigned for that serial. (Small device set → scan in JS.)
|
||||
const readerRowIdForSerial = (serial: string): string | null => {
|
||||
if (!serial) return null;
|
||||
@@ -52,9 +82,10 @@ export async function qrReaderRoutes(
|
||||
// drive output) once the socket CLOSES — every vendor demo replies
|
||||
// `Connection: close` and shuts the socket. Without it the reader waits out a
|
||||
// ~10 s keep-alive timeout before beeping. So force-close the connection.
|
||||
// See wiki/sources/qrcode-sdk.md, entities/gee-qr-er80.md.
|
||||
// See wiki/sources/qrcode-sdk.md, entities/dingtian-dt008-reader.md.
|
||||
reply.header("connection", "close");
|
||||
const cardid = (q.cardid ?? "").trim();
|
||||
const scan = splitChannel(cardid); // bare value + confirmed channel (if prefixed)
|
||||
const mjihao = q.mjihao != null ? Number(q.mjihao) : 0;
|
||||
const serial = (q.cjihao ?? "").trim();
|
||||
|
||||
@@ -65,35 +96,37 @@ export async function qrReaderRoutes(
|
||||
const deviceId = matchedRowId ?? serial;
|
||||
|
||||
let accepted = false;
|
||||
if (cardid) {
|
||||
if (scan.value) {
|
||||
// ENROLLMENT INTERCEPT: if THIS reader is armed for credential capture, grab the
|
||||
// value for the subscription form and do NOT run the access flow (we must not
|
||||
// open a barrier for a card being enrolled). Single-shot — capture auto-disarms.
|
||||
// Reads from the OTHER reader are untouched and dispatch normally below.
|
||||
if (capture.tryConsume(deviceId, cardid)) {
|
||||
app.log.info(`CAPTURE serial=${serial || "?"} device=${matchedRowId ? matchedRowId.slice(0, 8) : "?"} value=${cardid}`);
|
||||
// Captured BARE (prefix stripped) so enrolled values match future stripped reads.
|
||||
if (capture.tryConsume(deviceId, scan.value)) {
|
||||
app.log.info(`CAPTURE serial=${serial || "?"} device=${matchedRowId ? matchedRowId.slice(0, 8) : "?"} value=${scan.value}${scan.channel ? ` ch=${scan.channel}` : ""}`);
|
||||
accepted = true; // beep "ok" so the operator knows the card was read
|
||||
} else {
|
||||
const read: DeviceReadEvent = {
|
||||
driverId: "gee-qr-reader",
|
||||
driverId: "dingtian-qr-reader",
|
||||
deviceId,
|
||||
value: cardid,
|
||||
kind: "qr",
|
||||
value: scan.value,
|
||||
kind: scan.kind,
|
||||
...(scan.channel ? { channel: scan.channel } : {}),
|
||||
at: new Date().toISOString(),
|
||||
};
|
||||
try {
|
||||
const outcome = await dispatcher.dispatch(read);
|
||||
accepted = outcome.accepted;
|
||||
// Per-read diagnostic: which reader (serial) sent it, which configured device
|
||||
// it mapped to, and the verdict — so a barrier/serial mismatch is visible in
|
||||
// the logs (e.g. an entry-side scan resolving to the exit relay).
|
||||
// it mapped to, the confirmed channel (if prefixed), and the verdict — so a
|
||||
// barrier/serial mismatch or a channel anomaly is visible in the logs.
|
||||
app.log.info(
|
||||
`READ serial=${serial || "?"} → device=${matchedRowId ? matchedRowId.slice(0, 8) : "UNASSIGNED"} ` +
|
||||
`card=${cardid} verdict=${accepted ? "ACCEPT" : "REJECT"}${outcome.direction ? ` dir=${outcome.direction}` : ""}` +
|
||||
`card=${scan.value}${scan.channel ? ` ch=${scan.channel}` : ""} verdict=${accepted ? "ACCEPT" : "REJECT"}${outcome.direction ? ` dir=${outcome.direction}` : ""}` +
|
||||
`${accepted ? "" : ` reason="${outcome.reason ?? "?"}"`}`,
|
||||
);
|
||||
} catch (err) {
|
||||
app.log.error(`QR dispatch failed for ${cardid}: ${(err as Error).message}`);
|
||||
app.log.error(`QR dispatch failed for ${scan.value}: ${(err as Error).message}`);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -0,0 +1,114 @@
|
||||
import { afterEach, beforeEach, describe, expect, it } from "vitest";
|
||||
import { createTestDb } from "@parking/db/testing";
|
||||
import { type Db } from "@parking/db";
|
||||
import type { FastifyInstance } from "fastify";
|
||||
import { buildServer } from "../server.js";
|
||||
import { seedUser, login } from "../test-helpers.js";
|
||||
|
||||
// HTTP integration for soft delete + recycle bin: an admin DELETE soft-deletes (the user
|
||||
// leaves the list, can't log in), the bin lists it, restore brings it back, and a deleted
|
||||
// user can log in again. Drives the REAL app over a fresh in-memory DB via app.inject.
|
||||
|
||||
let db: Db;
|
||||
let close: () => void;
|
||||
let app: FastifyInstance;
|
||||
|
||||
beforeEach(async () => {
|
||||
const t = createTestDb();
|
||||
db = t.db;
|
||||
close = t.close;
|
||||
app = await buildServer({ db });
|
||||
await app.ready();
|
||||
});
|
||||
afterEach(async () => {
|
||||
await app.close();
|
||||
close();
|
||||
});
|
||||
|
||||
/** Log in an admin and return the auth headers for mutations. */
|
||||
async function asAdmin() {
|
||||
const { username, password } = await seedUser(db, { username: "boss", roleId: "admin" });
|
||||
const { cookie, csrf } = await login(app, username, password);
|
||||
return { cookie, csrf };
|
||||
}
|
||||
|
||||
describe("soft delete via the resource DELETE route", () => {
|
||||
it("DELETE /api/users/:id soft-deletes: user leaves the list and can't log in, but is restorable", async () => {
|
||||
const { cookie, csrf } = await asAdmin();
|
||||
// Create a victim user to delete.
|
||||
await seedUser(db, { username: "victim", password: "victim-pass-123", roleId: "admin" });
|
||||
const victim = (await app.inject({ method: "GET", url: "/api/users", headers: { cookie } })).json()
|
||||
.users.find((u: { username: string; id: string }) => u.username === "victim");
|
||||
expect(victim).toBeDefined();
|
||||
|
||||
// Delete (soft).
|
||||
const del = await app.inject({
|
||||
method: "DELETE", url: `/api/users/${victim.id}`,
|
||||
headers: { cookie, "x-csrf-token": csrf },
|
||||
});
|
||||
expect(del.statusCode).toBeLessThan(300);
|
||||
|
||||
// Gone from the live list.
|
||||
const list = (await app.inject({ method: "GET", url: "/api/users", headers: { cookie } })).json();
|
||||
expect(list.users.some((u: { username: string }) => u.username === "victim")).toBe(false);
|
||||
|
||||
// Can't log in.
|
||||
const relogin = await app.inject({ method: "POST", url: "/api/auth/login", payload: { username: "victim", password: "victim-pass-123" } });
|
||||
expect(relogin.statusCode).toBe(401);
|
||||
|
||||
// Shows in the recycle bin.
|
||||
const bin = (await app.inject({ method: "GET", url: "/api/recycle-bin", headers: { cookie } })).json();
|
||||
expect(bin.items.some((i: { kind: string; label: string }) => i.kind === "user" && i.label === "victim")).toBe(true);
|
||||
|
||||
// Restore → reappears + can log in.
|
||||
const restore = await app.inject({
|
||||
method: "POST", url: `/api/recycle-bin/user/${victim.id}/restore`,
|
||||
headers: { cookie, "x-csrf-token": csrf },
|
||||
});
|
||||
expect(restore.statusCode).toBeLessThan(300);
|
||||
const relogin2 = await app.inject({ method: "POST", url: "/api/auth/login", payload: { username: "victim", password: "victim-pass-123" } });
|
||||
expect(relogin2.statusCode).toBe(200);
|
||||
});
|
||||
|
||||
it("purge permanently removes a soft-deleted user", async () => {
|
||||
const { cookie, csrf } = await asAdmin();
|
||||
await seedUser(db, { username: "gone", password: "gone-pass-1234", roleId: "admin" });
|
||||
const id = (await app.inject({ method: "GET", url: "/api/users", headers: { cookie } })).json()
|
||||
.users.find((u: { username: string }) => u.username === "gone").id;
|
||||
|
||||
await app.inject({ method: "DELETE", url: `/api/users/${id}`, headers: { cookie, "x-csrf-token": csrf } });
|
||||
const purge = await app.inject({
|
||||
method: "DELETE", url: `/api/recycle-bin/user/${id}`,
|
||||
headers: { cookie, "x-csrf-token": csrf },
|
||||
});
|
||||
expect(purge.statusCode).toBe(204);
|
||||
|
||||
const bin = (await app.inject({ method: "GET", url: "/api/recycle-bin", headers: { cookie } })).json();
|
||||
expect(bin.items.some((i: { label: string }) => i.label === "gone")).toBe(false);
|
||||
});
|
||||
|
||||
it("the recycle bin is gated — a user without recyclebin:read is 403", async () => {
|
||||
const { username, password } = await seedUser(db, {
|
||||
username: "plain", roleId: "plain", permissions: ["user:read"],
|
||||
});
|
||||
const { cookie } = await login(app, username, password);
|
||||
const res = await app.inject({ method: "GET", url: "/api/recycle-bin", headers: { cookie } });
|
||||
expect(res.statusCode).toBe(403);
|
||||
});
|
||||
|
||||
it("recreating a user with a soft-deleted user's username gives a clear 409", async () => {
|
||||
const { cookie, csrf } = await asAdmin();
|
||||
await seedUser(db, { username: "dup", password: "dup-pass-12345", roleId: "admin" });
|
||||
const id = (await app.inject({ method: "GET", url: "/api/users", headers: { cookie } })).json()
|
||||
.users.find((u: { username: string }) => u.username === "dup").id;
|
||||
await app.inject({ method: "DELETE", url: `/api/users/${id}`, headers: { cookie, "x-csrf-token": csrf } });
|
||||
|
||||
const create = await app.inject({
|
||||
method: "POST", url: "/api/users",
|
||||
headers: { cookie, "x-csrf-token": csrf },
|
||||
payload: { username: "dup", password: "new-pass-12345", roleId: "admin" },
|
||||
});
|
||||
expect(create.statusCode).toBe(409);
|
||||
expect(create.json().error).toMatch(/recycle bin/i);
|
||||
});
|
||||
});
|
||||
@@ -0,0 +1,67 @@
|
||||
import type { FastifyInstance } from "fastify";
|
||||
import type { Db } from "@parking/db";
|
||||
import { requirePermission, bumpPermsCache } from "../auth.js";
|
||||
import {
|
||||
listRecycleBin,
|
||||
purge,
|
||||
restore,
|
||||
restoreBlockedReason,
|
||||
retentionDays,
|
||||
RESOURCE_KINDS,
|
||||
type ResourceKind,
|
||||
} from "../recycle-bin.js";
|
||||
|
||||
// Recycle bin API — view / restore / purge soft-deleted master data. The actual
|
||||
// soft-delete STAMP happens in each resource's own DELETE route (users/roles/
|
||||
// subscriptions/plans/tariffs); this is the way back. Admin-grade (recyclebin:*).
|
||||
// See recycle-bin.ts, wiki/concepts/soft-delete.md.
|
||||
|
||||
function isKind(s: string): s is ResourceKind {
|
||||
return (RESOURCE_KINDS as string[]).includes(s);
|
||||
}
|
||||
|
||||
export async function recycleBinRoutes(app: FastifyInstance, db: Db): Promise<void> {
|
||||
// List everything in the bin (+ the retention window so the UI can warn how long
|
||||
// items survive before auto-purge).
|
||||
app.get(
|
||||
"/api/recycle-bin",
|
||||
{ preHandler: requirePermission("recyclebin:read") },
|
||||
async () => ({ items: listRecycleBin(db), retentionDays: retentionDays() }),
|
||||
);
|
||||
|
||||
// Restore a soft-deleted item (clear the stamps → it reappears in its catalog).
|
||||
// Blocked with a 409 when a live row would collide (e.g. the username was reused).
|
||||
app.post<{ Params: { kind: string; id: string } }>(
|
||||
"/api/recycle-bin/:kind/:id/restore",
|
||||
{ preHandler: requirePermission("recyclebin:update") },
|
||||
async (req, reply) => {
|
||||
const { kind, id } = req.params;
|
||||
if (!isKind(kind)) return reply.code(400).send({ error: `unknown resource kind: ${kind}` });
|
||||
|
||||
const blocked = restoreBlockedReason(db, kind, id);
|
||||
if (blocked) return reply.code(409).send({ error: `cannot restore: ${blocked}` });
|
||||
|
||||
const ok = restore(db, kind, id);
|
||||
if (!ok) return reply.code(404).send({ error: "no deleted item to restore" });
|
||||
// A restored role/user changes the authz picture — drop the permission cache.
|
||||
if (kind === "role" || kind === "user") bumpPermsCache();
|
||||
app.log.info(`recycle-bin: restored ${kind} ${id}`);
|
||||
return { kind, id, restored: true };
|
||||
},
|
||||
);
|
||||
|
||||
// Purge (permanently delete) a soft-deleted item + its children. Irreversible.
|
||||
app.delete<{ Params: { kind: string; id: string } }>(
|
||||
"/api/recycle-bin/:kind/:id",
|
||||
{ preHandler: requirePermission("recyclebin:delete") },
|
||||
async (req, reply) => {
|
||||
const { kind, id } = req.params;
|
||||
if (!isKind(kind)) return reply.code(400).send({ error: `unknown resource kind: ${kind}` });
|
||||
const ok = purge(db, kind, id);
|
||||
if (!ok) return reply.code(404).send({ error: "no deleted item to purge" });
|
||||
if (kind === "role" || kind === "user") bumpPermsCache();
|
||||
app.log.warn(`recycle-bin: PURGED ${kind} ${id} (permanent)`);
|
||||
return reply.code(204).send();
|
||||
},
|
||||
);
|
||||
}
|
||||
@@ -0,0 +1,74 @@
|
||||
import type { FastifyInstance } from "fastify";
|
||||
import type { Db } from "@parking/db";
|
||||
import { requirePermission } from "../auth.js";
|
||||
import { reportSummary, type Bucket } from "../reports.js";
|
||||
|
||||
// Admin reporting API. Read-only aggregation over the signed ledger (+ the sessions
|
||||
// cache for durations); no writes, no new event types. Gated on `report:read` — the
|
||||
// same permission the events feed/occupancy use. See reports.ts, wiki/concepts/reports.md.
|
||||
|
||||
const BUCKETS: Bucket[] = ["hour", "day", "month"];
|
||||
|
||||
/** Clamp a query into a valid [from, to) + bucket. Defaults: last 30 days, daily. */
|
||||
function parseQuery(q: { from?: string; to?: string; bucket?: string }): {
|
||||
from: string;
|
||||
to: string;
|
||||
bucket: Bucket;
|
||||
} {
|
||||
const now = Date.now();
|
||||
const to = isFiniteIso(q.to) ? q.to! : new Date(now).toISOString();
|
||||
const from = isFiniteIso(q.from) ? q.from! : new Date(now - 30 * 86_400_000).toISOString();
|
||||
const bucket = BUCKETS.includes(q.bucket as Bucket) ? (q.bucket as Bucket) : "day";
|
||||
// Guard the inversion (from after to) — swap rather than return an empty report.
|
||||
return from <= to ? { from, to, bucket } : { from: to, to: from, bucket };
|
||||
}
|
||||
|
||||
function isFiniteIso(s: string | undefined): boolean {
|
||||
return !!s && Number.isFinite(Date.parse(s));
|
||||
}
|
||||
|
||||
export async function reportRoutes(app: FastifyInstance, db: Db): Promise<void> {
|
||||
const guard = requirePermission("report:read");
|
||||
|
||||
// The whole dashboard in one call: totals, the time series, peak-hour histogram, and
|
||||
// subscription stats — aggregated server-side so the SPA just renders. Bucketed in the
|
||||
// site timezone. See reports.ts.
|
||||
app.get<{ Querystring: { from?: string; to?: string; bucket?: string } }>(
|
||||
"/api/reports/summary",
|
||||
{ preHandler: guard },
|
||||
async (req) => reportSummary(db, parseQuery(req.query)),
|
||||
);
|
||||
|
||||
// The same series as CSV (one row per bucket) for spreadsheet / accountant export.
|
||||
// Amounts are in MAJOR units with 2 decimals here (a CSV is for humans/Excel), unlike
|
||||
// the JSON which stays in minor units. text/csv with a download filename.
|
||||
app.get<{ Querystring: { from?: string; to?: string; bucket?: string } }>(
|
||||
"/api/reports/summary.csv",
|
||||
{ preHandler: guard },
|
||||
async (req, reply) => {
|
||||
const summary = reportSummary(db, parseQuery(req.query));
|
||||
const lines = [
|
||||
"bucket,entries,exits,payments,revenue,cash,card,occupancy_end",
|
||||
...summary.series.map((p) =>
|
||||
[
|
||||
p.bucket,
|
||||
p.entries,
|
||||
p.exits,
|
||||
p.payments,
|
||||
(p.revenueMinor / 100).toFixed(2),
|
||||
(p.cashMinor / 100).toFixed(2),
|
||||
(p.cardMinor / 100).toFixed(2),
|
||||
p.occupancyEnd,
|
||||
].join(","),
|
||||
),
|
||||
];
|
||||
reply
|
||||
.header("content-type", "text/csv; charset=utf-8")
|
||||
.header(
|
||||
"content-disposition",
|
||||
`attachment; filename="parking-report-${summary.from.slice(0, 10)}_${summary.to.slice(0, 10)}.csv"`,
|
||||
)
|
||||
.send(lines.join("\n") + "\n");
|
||||
},
|
||||
);
|
||||
}
|
||||
@@ -0,0 +1,102 @@
|
||||
import { afterEach, beforeEach, describe, expect, it } from "vitest";
|
||||
import { createTestDb } from "@parking/db/testing";
|
||||
import { type Db } from "@parking/db";
|
||||
import type { FastifyInstance } from "fastify";
|
||||
import { jobsBehind } from "@parking/shared";
|
||||
import { buildServer } from "../server.js";
|
||||
import { login, seedUser } from "../test-helpers.js";
|
||||
|
||||
// Roles are data composed from the permission grid (venue-modules.md §Permissions
|
||||
// matrix): every edit is SIGNED as a config_change, and a role remembers the manifest
|
||||
// JOBS it was built from so a grown job can be surfaced and re-applied.
|
||||
|
||||
let db: Db;
|
||||
let close: () => void;
|
||||
let app: FastifyInstance;
|
||||
beforeEach(async () => {
|
||||
delete process.env.MODULES_ENTITLED;
|
||||
const t = createTestDb();
|
||||
db = t.db;
|
||||
close = t.close;
|
||||
app = await buildServer({ db });
|
||||
await app.ready();
|
||||
});
|
||||
afterEach(async () => {
|
||||
await app.close();
|
||||
close();
|
||||
});
|
||||
type Auth = { cookie: string; csrf: string };
|
||||
const hdrs = (a: Auth) => ({ cookie: a.cookie, "x-csrf-token": a.csrf });
|
||||
async function admin(): Promise<Auth> {
|
||||
const { username, password } = await seedUser(db, { username: "boss", roleId: "admin" });
|
||||
return login(app, username, password);
|
||||
}
|
||||
async function roleChanges(a: Auth) {
|
||||
const r = await app.inject({ method: "GET", url: "/api/events?limit=100", headers: { cookie: a.cookie } });
|
||||
return (r.json().events as { type: string; payload: Record<string, unknown> }[]).filter(
|
||||
(e) => e.type === "config_change" && String(e.payload.setting).startsWith("role."),
|
||||
);
|
||||
}
|
||||
|
||||
describe("role edits are signed and jobs are remembered", () => {
|
||||
it("create / update / delete each sign one config_change with prev + value + operator; a no-op resave signs nothing", async () => {
|
||||
const a = await admin();
|
||||
const created = await app.inject({
|
||||
method: "POST", url: "/api/roles", headers: hdrs(a),
|
||||
payload: { name: "Lavazh", permissions: ["carwash:read", "carwash:create", "carwash:update", "carwash:cash"], jobs: ["wash-operator"] },
|
||||
});
|
||||
expect(created.statusCode).toBe(201);
|
||||
const role = created.json();
|
||||
expect(role.jobs).toEqual(["wash-operator"]);
|
||||
let evs = await roleChanges(a);
|
||||
expect(evs).toHaveLength(1);
|
||||
expect(evs[0]!.payload).toMatchObject({
|
||||
setting: `role.${role.id}`, prev: null, operator: "boss",
|
||||
value: { name: "Lavazh", jobs: ["wash-operator"] },
|
||||
});
|
||||
expect((evs[0]!.payload.value as { permissions: string[] }).permissions).toEqual(["carwash:cash", "carwash:create", "carwash:read", "carwash:update"]);
|
||||
|
||||
// Same content again → nothing new on the chain.
|
||||
const same = await app.inject({
|
||||
method: "PUT", url: `/api/roles/${role.id}`, headers: hdrs(a),
|
||||
payload: { permissions: ["carwash:read", "carwash:create", "carwash:update", "carwash:cash"], jobs: ["wash-operator"] },
|
||||
});
|
||||
expect(same.statusCode).toBe(200);
|
||||
expect(await roleChanges(a)).toHaveLength(1);
|
||||
|
||||
// A real change: prev is the old shape, value the new.
|
||||
const renamed = await app.inject({ method: "PUT", url: `/api/roles/${role.id}`, headers: hdrs(a), payload: { name: "Lavazh NEW" } });
|
||||
expect(renamed.statusCode).toBe(200);
|
||||
evs = await roleChanges(a);
|
||||
expect(evs).toHaveLength(2);
|
||||
expect(evs[0]!.payload).toMatchObject({ prev: { name: "Lavazh" }, value: { name: "Lavazh NEW" } });
|
||||
|
||||
const gone = await app.inject({ method: "DELETE", url: `/api/roles/${role.id}`, headers: hdrs(a) });
|
||||
expect(gone.statusCode).toBe(200);
|
||||
evs = await roleChanges(a);
|
||||
expect(evs).toHaveLength(3);
|
||||
expect(evs[0]!.payload).toMatchObject({ prev: { name: "Lavazh NEW" }, value: null });
|
||||
});
|
||||
|
||||
it("unknown jobs are refused; a role built from a job that later grew reports what it is missing", async () => {
|
||||
const a = await admin();
|
||||
const bad = await app.inject({ method: "POST", url: "/api/roles", headers: hdrs(a), payload: { name: "X", permissions: [], jobs: ["bar-tender"] } });
|
||||
expect(bad.statusCode).toBe(400);
|
||||
// Compose "behind": the role follows wash-operator but holds only part of today's bundle
|
||||
// — exactly what an older release's chip would have left once the job grew.
|
||||
const r = (await app.inject({
|
||||
method: "POST", url: "/api/roles", headers: hdrs(a),
|
||||
payload: { name: "Old wash", permissions: ["carwash:read", "carwash:create"], jobs: ["wash-operator"] },
|
||||
})).json();
|
||||
const view = (await app.inject({ method: "GET", url: "/api/roles", headers: { cookie: a.cookie } })).json().roles.find((x: { id: string }) => x.id === r.id);
|
||||
const has = new Set<string>(view.permissions);
|
||||
expect(jobsBehind(view.jobs, (p) => has.has(p))).toEqual([{ job: "wash-operator", missing: ["carwash:update", "carwash:cash"] }]);
|
||||
// Re-apply = the union; then nothing is behind.
|
||||
const fixed = (await app.inject({
|
||||
method: "PUT", url: `/api/roles/${r.id}`, headers: hdrs(a),
|
||||
payload: { permissions: [...has, "carwash:update", "carwash:cash"] },
|
||||
})).json();
|
||||
const has2 = new Set<string>(fixed.permissions);
|
||||
expect(jobsBehind(fixed.jobs, (p) => has2.has(p))).toEqual([]);
|
||||
});
|
||||
});
|
||||
@@ -1,8 +1,10 @@
|
||||
import { randomUUID } from "node:crypto";
|
||||
import type { FastifyInstance } from "fastify";
|
||||
import { eq, rolePermissions, roles, users, type Db } from "@parking/db";
|
||||
import { ADMIN_ROLE_ID, PERMISSIONS, type Permission } from "@parking/shared";
|
||||
import { and, eq, isNull, roleJobs, rolePermissions, roles, users, type Db } from "@parking/db";
|
||||
import { ADMIN_ROLE_ID, PERMISSIONS, jobById, type Permission } from "@parking/shared";
|
||||
import { bumpPermsCache, permissionsFor, requirePermission } from "../auth.js";
|
||||
import type { EventLog } from "../event-log.js";
|
||||
import { softDelete } from "../recycle-bin.js";
|
||||
|
||||
// Role management (admin). Roles are DATA: an admin composes a role from the
|
||||
// code-defined PERMISSIONS grid (resource:action), and users are assigned one
|
||||
@@ -17,14 +19,30 @@ import { bumpPermsCache, permissionsFor, requirePermission } from "../auth.js";
|
||||
// that grants admin-equivalent powers, and escalate. So a non-admin caller may
|
||||
// only put permissions they ALREADY hold onto a role. An admin (full set) is
|
||||
// unrestricted, which is the intended behaviour.
|
||||
//
|
||||
// EVERY role edit is SIGNED on the ledger as a `config_change` (setting `role.<id>`,
|
||||
// value/prev = the role's name + permissions + jobs, operator = who) — a role edit is a
|
||||
// privilege change, and under this threat model the only setting an admin could alter
|
||||
// without a trace. A role also REMEMBERS the manifest JOBS it was composed from
|
||||
// (role_jobs) so a later release that grows a job's bundle can be surfaced and
|
||||
// re-applied — the grid is never expanded silently (venue-modules.md §Permissions matrix).
|
||||
|
||||
interface RoleBody {
|
||||
name: string;
|
||||
permissions: string[];
|
||||
jobs?: string[];
|
||||
}
|
||||
interface UpdateBody {
|
||||
name?: string;
|
||||
permissions?: string[];
|
||||
jobs?: string[];
|
||||
}
|
||||
|
||||
/** What a signed role change records (before/after). */
|
||||
interface RoleShape {
|
||||
name: string;
|
||||
permissions: Permission[];
|
||||
jobs: string[];
|
||||
}
|
||||
|
||||
const VALID = new Set<string>(PERMISSIONS);
|
||||
@@ -40,7 +58,19 @@ function cleanPermissions(input: unknown): { ok: true; perms: Permission[] } | {
|
||||
return { ok: true, perms: [...out] };
|
||||
}
|
||||
|
||||
export async function roleRoutes(app: FastifyInstance, db: Db): Promise<void> {
|
||||
/** Validate + dedupe a requested job list against the registry's job presets. */
|
||||
function cleanJobs(input: unknown): { ok: true; jobs: string[] } | { ok: false; bad: string } {
|
||||
if (input == null) return { ok: true, jobs: [] };
|
||||
if (!Array.isArray(input)) return { ok: false, bad: "jobs must be an array" };
|
||||
const out = new Set<string>();
|
||||
for (const j of input) {
|
||||
if (typeof j !== "string" || !jobById(j)) return { ok: false, bad: `unknown job: ${String(j)}` };
|
||||
out.add(j);
|
||||
}
|
||||
return { ok: true, jobs: [...out] };
|
||||
}
|
||||
|
||||
export async function roleRoutes(app: FastifyInstance, db: Db, eventLog?: EventLog): Promise<void> {
|
||||
const readGuard = requirePermission("role:read");
|
||||
const createGuard = requirePermission("role:create");
|
||||
const updateGuard = requirePermission("role:update");
|
||||
@@ -56,17 +86,46 @@ export async function roleRoutes(app: FastifyInstance, db: Db): Promise<void> {
|
||||
.where(eq(rolePermissions.roleId, roleId))
|
||||
.all()
|
||||
.map((r) => r.permission);
|
||||
const userCount = db.select().from(users).where(eq(users.roleId, roleId)).all().length;
|
||||
const userCount = db.select().from(users).where(and(eq(users.roleId, roleId), isNull(users.deletedAt))).all().length;
|
||||
// The admin role always reports the full grid (it's enforced in code).
|
||||
return {
|
||||
id: role.id,
|
||||
name: role.name,
|
||||
builtin: role.builtin === 1,
|
||||
permissions: role.id === ADMIN_ROLE_ID ? [...PERMISSIONS] : perms,
|
||||
jobs: jobsOf(roleId),
|
||||
userCount,
|
||||
};
|
||||
}
|
||||
|
||||
function jobsOf(roleId: string): string[] {
|
||||
return db.select({ jobId: roleJobs.jobId }).from(roleJobs).where(eq(roleJobs.roleId, roleId)).all().map((r) => r.jobId).sort();
|
||||
}
|
||||
|
||||
/** The role as the ledger records it (sorted so two identical shapes compare equal). */
|
||||
function shapeOf(roleId: string): RoleShape | null {
|
||||
const v = roleView(roleId);
|
||||
if (!v) return null;
|
||||
return { name: v.name, permissions: [...v.permissions].sort() as Permission[], jobs: v.jobs };
|
||||
}
|
||||
|
||||
/** Replace a role's remembered jobs. */
|
||||
function setJobs(roleId: string, jobs: string[]): void {
|
||||
db.delete(roleJobs).where(eq(roleJobs.roleId, roleId)).run();
|
||||
for (const jobId of jobs) db.insert(roleJobs).values({ roleId, jobId }).run();
|
||||
}
|
||||
|
||||
/** Sign a role change. `prev` null = created; `value` null = deleted. Skipped when
|
||||
* nothing changed (a no-op resave leaves no trace, like the site-config flips). */
|
||||
async function signRoleChange(req: { user?: { username?: string } }, roleId: string, prev: RoleShape | null, value: RoleShape | null): Promise<void> {
|
||||
if (JSON.stringify(prev) === JSON.stringify(value)) return;
|
||||
await eventLog?.append({
|
||||
type: "config_change",
|
||||
source: "manual",
|
||||
payload: { setting: `role.${roleId}`, value, prev, operator: req.user?.username ?? "unknown" },
|
||||
});
|
||||
}
|
||||
|
||||
/** Replace a role's permission rows with `perms` (in a single pass). */
|
||||
function setPermissions(roleId: string, perms: Permission[]): void {
|
||||
db.delete(rolePermissions).where(eq(rolePermissions.roleId, roleId)).run();
|
||||
@@ -75,9 +134,10 @@ export async function roleRoutes(app: FastifyInstance, db: Db): Promise<void> {
|
||||
}
|
||||
}
|
||||
|
||||
// The full permission grid (for the role-composer checkbox UI) + every role.
|
||||
// The full permission grid (for the role-composer checkbox UI) + every LIVE role.
|
||||
// Soft-deleted roles live in the recycle bin, not here.
|
||||
app.get("/api/roles", { preHandler: readGuard }, async () => {
|
||||
const all = db.select().from(roles).all();
|
||||
const all = db.select().from(roles).where(isNull(roles.deletedAt)).all();
|
||||
return {
|
||||
catalog: PERMISSIONS,
|
||||
roles: all.map((r) => roleView(r.id)).filter((r) => r != null),
|
||||
@@ -102,13 +162,17 @@ export async function roleRoutes(app: FastifyInstance, db: Db): Promise<void> {
|
||||
}
|
||||
const cleaned = cleanPermissions(req.body?.permissions ?? []);
|
||||
if (!cleaned.ok) return reply.code(400).send({ error: cleaned.bad });
|
||||
const jobs = cleanJobs(req.body?.jobs);
|
||||
if (!jobs.ok) return reply.code(400).send({ error: jobs.bad });
|
||||
const over = escalates(req.user.roleId, cleaned.perms);
|
||||
if (over) return reply.code(403).send({ error: `cannot grant a permission you do not hold: ${over}` });
|
||||
|
||||
const id = randomUUID();
|
||||
db.insert(roles).values({ id, name, builtin: 0 }).run();
|
||||
setPermissions(id, cleaned.perms);
|
||||
setJobs(id, jobs.jobs);
|
||||
bumpPermsCache();
|
||||
await signRoleChange(req, id, null, shapeOf(id));
|
||||
return reply.code(201).send(roleView(id));
|
||||
});
|
||||
|
||||
@@ -123,6 +187,7 @@ export async function roleRoutes(app: FastifyInstance, db: Db): Promise<void> {
|
||||
if (role.builtin === 1) {
|
||||
return reply.code(409).send({ error: "the built-in admin role cannot be edited" });
|
||||
}
|
||||
const prev = shapeOf(id);
|
||||
|
||||
if (req.body?.name != null) {
|
||||
const name = req.body.name.trim();
|
||||
@@ -138,29 +203,39 @@ export async function roleRoutes(app: FastifyInstance, db: Db): Promise<void> {
|
||||
if (over) return reply.code(403).send({ error: `cannot grant a permission you do not hold: ${over}` });
|
||||
setPermissions(id, cleaned.perms);
|
||||
}
|
||||
if (req.body?.jobs != null) {
|
||||
const jobs = cleanJobs(req.body.jobs);
|
||||
if (!jobs.ok) return reply.code(400).send({ error: jobs.bad });
|
||||
setJobs(id, jobs.jobs);
|
||||
}
|
||||
bumpPermsCache();
|
||||
await signRoleChange(req, id, prev, shapeOf(id));
|
||||
return roleView(id);
|
||||
},
|
||||
);
|
||||
|
||||
// Delete a role. Refused if it's built-in or any user still holds it.
|
||||
// Delete a role — SOFT (recycle bin). Refused if built-in or any LIVE user still holds
|
||||
// it. The row is stamped deleted (recoverable), not removed; its permission rows are
|
||||
// KEPT so a restore brings the role back intact. Restore/purge from the recycle bin.
|
||||
app.delete<{ Params: { id: string } }>(
|
||||
"/api/roles/:id",
|
||||
{ preHandler: deleteGuard },
|
||||
async (req, reply) => {
|
||||
const id = req.params.id;
|
||||
const role = db.select().from(roles).where(eq(roles.id, id)).get();
|
||||
const role = db.select().from(roles).where(and(eq(roles.id, id), isNull(roles.deletedAt))).get();
|
||||
if (!role) return reply.code(404).send({ error: "role not found" });
|
||||
if (role.builtin === 1) {
|
||||
return reply.code(409).send({ error: "the built-in admin role cannot be deleted" });
|
||||
}
|
||||
const holders = db.select().from(users).where(eq(users.roleId, id)).all().length;
|
||||
// Only LIVE holders block deletion (a soft-deleted user's role assignment is moot).
|
||||
const holders = db.select().from(users).where(and(eq(users.roleId, id), isNull(users.deletedAt))).all().length;
|
||||
if (holders > 0) {
|
||||
return reply.code(409).send({ error: `cannot delete a role still assigned to ${holders} user(s)` });
|
||||
}
|
||||
db.delete(rolePermissions).where(eq(rolePermissions.roleId, id)).run();
|
||||
db.delete(roles).where(eq(roles.id, id)).run();
|
||||
const prev = shapeOf(id);
|
||||
softDelete(db, "role", id, req.user.sub);
|
||||
bumpPermsCache();
|
||||
await signRoleChange(req, id, prev, null);
|
||||
return { ok: true };
|
||||
},
|
||||
);
|
||||
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user