Files
NightSpire/web-next/lib/store.ts
T
Inna 0be3dc5280 store: reembolsar solo lo no entregado si el envío falla a medias
Un carrito de más de 12 entradas se envía en varios correos. Si fallaba el 3.º
de 9, los 2 primeros ya estaban en el buzón del jugador y aun así se le devolvía
el carrito ENTERO: se quedaba los objetos gratis. Con las cantidades por línea
(f232f0f) llegar ahí es fácil: 100 copias son 9 correos.

sendStoreItems devuelve ahora CUÁNTAS entradas entregó en vez de un booleano: un
correo enviado no se puede deshacer, así que quien llama necesita saber dónde se
cortó. Cada `.send items` es un correo, así que el troceo es atómico por correo:
un chunk sale entero o no sale. purchaseStoreCart reembolsa solo las entradas
que quedaron sin enviar (cada una lleva su precio y su moneda) y devuelve
`partialDelivery`, con un mensaje que dice la verdad: parte llegó al correo del
juego y solo se ha devuelto el resto. Si no sale ni un correo, sigue siendo el
`deliveryFailed` de siempre con la devolución completa.

En el pago con tarjeta no se puede hacer lo mismo (el dinero ya lo cobró la
pasarela): fulfillStoreOrder devuelve false si no salió todo. No puede duplicar
porque claimPaidCheckout reclama el pago una sola vez, pero por eso mismo
tampoco hay reintento y un envío a medias hay que rescatarlo a mano desde
home_store_order. Queda anotado en el código.

Verificado de punta a punta, no solo razonado: con un parche temporal del SOAP
que deja salir el 1.er correo y tumba el resto, 13 copias de un ítem de 10 PD
(130 PD, 12+1 entradas) dejan el saldo en 500 -> 380, o sea 500-130+10: se
devuelve SOLO la entrada que no salió y se cobran las 12 entregadas. El parche
se revirtió y producción se reconstruyó limpia.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-15 10:19:09 +00:00

369 lines
14 KiB
TypeScript
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
import type { RowDataPacket } from 'mysql2'
import { db, DB } from './db'
import { executeSoapCommand } from './soap'
import { PD_PER_UNIT } from './dpoints'
import { VP_PRICE_FACTOR } from './pay-with-dpoints'
import { MAX_COPIES, PD_PER_EUR, PV_PER_EUR, storeEuroTotal as pureEuroTotal } from './store-pricing'
/**
* Tienda de ítems (transfiguración/equipo), portada del sistema antiguo (BENNU).
* Catálogo en `home_store_category` (árbol por `code` "1-1-1") + `home_store_item`
* (precio en PD o PV, cantidad, icono). Se paga con el saldo PD/PV de la cuenta y
* los ítems se envían por correo al personaje elegido (SOAP `.send items`).
*/
export type Currency = 'pd' | 'pv'
const SAFE_NAME = /^[A-Za-z]{1,12}$/
const MAIL_ITEM_LIMIT = 12 // máximo de ítems por correo en AzerothCore
export interface StoreItem {
id: number // fila de home_store_item (clave del carrito)
itemId: number
name: string
icon: string | null
qty: number
currency: Currency
price: number
preview: string | null
}
export interface StoreCategory {
code: string
name: string
depth: number
children: StoreCategory[]
items: StoreItem[]
}
interface CatRow extends RowDataPacket {
code: string
parent_code: string | null
name: string
depth: number
sort: number
}
interface ItemRow extends RowDataPacket {
id: number
category_code: string
item_id: number
name: string
icon: string | null
quantity: number
currency: Currency
price: number
preview: string | null
sort: number
}
/**
* Árbol completo de la tienda (categorías anidadas con sus ítems en las hojas).
*
* El nombre del ítem sale de `home_item_data` (extraído de los DB2 del cliente
* 3.4.3, ver sql/db2/), que es el ÚNICO sitio con el nombre en inglés: el
* `home_store_item.name` del catálogo original es solo español. El de la
* categoría sale de `home_store_category.name_en` (ver sql/store_category_en.sql).
* En ambos casos, si falta el nombre en ese idioma se cae al del catálogo, que
* siempre está.
*/
export async function getStoreCatalog(locale: string): Promise<StoreCategory[]> {
// Solo se interpola el nombre de la COLUMNA, y sale de una lista cerrada:
// nunca del locale crudo (que viene de la URL).
const en = locale === 'en'
const nameCol = en ? 'name_en' : 'name_es'
const catNameCol = en ? 'name_en' : 'name'
let cats: CatRow[] = []
let items: ItemRow[] = []
try {
;[cats] = await db(DB.default).query<CatRow[]>(
`SELECT code, parent_code, COALESCE(NULLIF(${catNameCol}, ''), name) AS name, depth, sort
FROM home_store_category ORDER BY sort`,
)
;[items] = await db(DB.default).query<ItemRow[]>(
`SELECT i.id, i.category_code, i.item_id, COALESCE(NULLIF(d.${nameCol}, ''), i.name) AS name,
i.icon, i.quantity, i.currency, i.price, i.preview, i.sort
FROM home_store_item i
LEFT JOIN home_item_data d ON d.entry = i.item_id
ORDER BY i.sort`,
)
} catch {
return []
}
const nodes = new Map<string, StoreCategory>()
for (const c of cats) {
nodes.set(c.code, { code: c.code, name: c.name, depth: c.depth, children: [], items: [] })
}
const roots: StoreCategory[] = []
for (const c of cats) {
const node = nodes.get(c.code)!
if (c.parent_code && nodes.has(c.parent_code)) nodes.get(c.parent_code)!.children.push(node)
else roots.push(node)
}
for (const it of items) {
const leaf = nodes.get(it.category_code)
if (!leaf) continue
leaf.items.push({
id: it.id,
itemId: it.item_id,
name: it.name,
icon: it.icon,
qty: it.quantity,
currency: it.currency,
price: it.price,
preview: it.preview,
})
}
return roots
}
/** Saldos PD y PV de la cuenta (para mostrar y validar). */
export async function getStoreBalances(accountId: number): Promise<{ dp: number; vp: number }> {
if (!accountId) return { dp: 0, vp: 0 }
try {
const [rows] = await db(DB.default).query<RowDataPacket[]>(
'SELECT dp, vp FROM home_api_points WHERE accountID = ?',
[accountId],
)
return rows[0] ? { dp: Number(rows[0].dp), vp: Number(rows[0].vp) } : { dp: 0, vp: 0 }
} catch {
return { dp: 0, vp: 0 }
}
}
/** Línea que manda el cliente: fila del catálogo + cuántas copias quiere. */
export interface StoreCartLine {
id: number
copies: number
}
export interface PricedCart {
// `qty` = lote que entrega CADA copia (home_store_item.quantity);
// `copies` = cuántas veces se compra la línea. Total de unidades = qty*copies.
lines: { id: number; itemId: number; qty: number; currency: Currency; price: number; copies: number }[]
pdTotal: number
vpTotal: number
}
/**
* Valida el carrito contra la BD (precios/cantidades/moneda REALES, nunca del
* cliente) a partir de las filas `home_store_item.id` y las copias pedidas.
* Devuelve null si está vacío, si alguna copia no es válida o si algún id no
* existe en el catálogo (mismo criterio que `priceCart` de send-gift).
*/
export async function priceStoreCart(cart: StoreCartLine[]): Promise<PricedCart | null> {
const copiesById = new Map<number, number>()
for (const l of Array.isArray(cart) ? cart : []) {
const id = Math.floor(Number(l?.id))
const copies = Math.floor(Number(l?.copies))
if (!Number.isInteger(id) || id <= 0) return null
if (!Number.isInteger(copies) || copies < 1 || copies > MAX_COPIES) return null
copiesById.set(id, Math.min(MAX_COPIES, (copiesById.get(id) ?? 0) + copies))
}
if (copiesById.size === 0) return null
const ids = [...copiesById.keys()]
let rows: ItemRow[] = []
try {
;[rows] = await db(DB.default).query<ItemRow[]>(
`SELECT id, item_id, quantity, currency, price FROM home_store_item WHERE id IN (${ids.map(() => '?').join(',')})`,
ids,
)
} catch {
return null
}
if (rows.length !== ids.length) return null // algún id no existe en el catálogo
const lines = rows.map((r) => ({
id: Number(r.id),
itemId: Number(r.item_id),
qty: Number(r.quantity),
currency: r.currency,
price: Number(r.price),
copies: copiesById.get(Number(r.id))!,
}))
const sum = (c: Currency) =>
lines.filter((l) => l.currency === c).reduce((s, l) => s + l.price * l.copies, 0)
return { lines, pdTotal: sum('pd'), vpTotal: sum('pv') }
}
/** Entrada de correo: un lote de un ítem, con lo que costó (para reembolsar). */
interface CartEntry {
i: number
q: number
currency: Currency
price: number
}
/**
* Entradas para el SOAP/el pedido: cada copia va como una entrada propia
* (`2589:20 2589:20` = 2 lotes de 20), que es justo lo que ya sabe trocear
* `sendStoreItems` (12 por correo) y parsear `fulfillStoreOrder`. Cada entrada
* lleva su precio para poder reembolsar SOLO lo que no llegue a enviarse.
*/
function cartEntries(cart: PricedCart): CartEntry[] {
return cart.lines.flatMap((l) =>
Array.from({ length: l.copies }, () => ({ i: l.itemId, q: l.qty, currency: l.currency, price: l.price })),
)
}
/**
* Cobra el carrito (descuenta PD y PV de forma atómica, ambos a la vez) y envía
* los ítems por correo al personaje. Reembolsa si el envío por SOAP falla.
* Devuelve un código de error si algo no cuadra.
*/
export async function purchaseStoreCart(
accountId: number,
character: string,
cart: PricedCart,
): Promise<{ success: boolean; error?: string }> {
if (!SAFE_NAME.test(character)) return { success: false, error: 'invalidCharacter' }
if (cart.pdTotal <= 0 && cart.vpTotal <= 0) return { success: false, error: 'emptyCart' }
// Cobro atómico: bloquea la fila y exige saldo suficiente en AMBAS monedas.
const conn = await db(DB.default).getConnection()
let charged = false
try {
await conn.beginTransaction()
const [pts] = await conn.query<RowDataPacket[]>(
'SELECT dp, vp FROM home_api_points WHERE accountID = ? FOR UPDATE',
[accountId],
)
const dp = pts[0] ? Number(pts[0].dp) : 0
const vp = pts[0] ? Number(pts[0].vp) : 0
if (dp < cart.pdTotal) { await conn.rollback(); return { success: false, error: 'insufficientPd' } }
if (vp < cart.vpTotal) { await conn.rollback(); return { success: false, error: 'insufficientVp' } }
await conn.query('UPDATE home_api_points SET dp = dp - ?, vp = vp - ? WHERE accountID = ?', [cart.pdTotal, cart.vpTotal, accountId])
await conn.commit()
charged = true
} catch {
try { await conn.rollback() } catch { /* ignore */ }
return { success: false, error: 'genericError' }
} finally {
conn.release()
}
// Envío por correo (troceado a 12 ítems). Si falla a medias, se reembolsa SOLO
// lo que no se envió: los correos que ya salieron no se pueden recuperar, y
// devolver el carrito entero regalaría lo ya entregado.
const entries = cartEntries(cart)
const sent = await sendStoreItems(character, entries)
if (sent < entries.length) {
const left = entries.slice(sent)
const back = (c: Currency) => left.filter((e) => e.currency === c).reduce((s, e) => s + e.price, 0)
const pdBack = back('pd')
const vpBack = back('pv')
if (charged && (pdBack > 0 || vpBack > 0)) {
await db(DB.default)
.query('UPDATE home_api_points SET dp = dp + ?, vp = vp + ? WHERE accountID = ?', [pdBack, vpBack, accountId])
.catch(() => {})
}
// Si no salió ni un correo es el fallo de siempre (SOAP caído). Si salió
// alguno, el jugador tiene parte de la compra y solo se le devuelve el resto.
return { success: false, error: sent === 0 ? 'deliveryFailed' : 'partialDelivery' }
}
return { success: true }
}
/**
* Coste del carrito en euros para pagar con tarjeta. Inverso exacto de cómo se
* derivan los precios PD/PV de un precio en euros en el resto de servicios:
* 100 PD = 1 € y los PV cuestan VP_PRICE_FACTOR× (200 PV = 1 €).
*
* La implementación vive en `store-pricing` (módulo puro) para que el carrito
* del cliente enseñe EXACTAMENTE el importe que aquí se valida y se cobra. Este
* `if` es la red de seguridad de esa duplicación: si alguien cambia PD_PER_UNIT
* o VP_PRICE_FACTOR y no toca store-pricing, salta al primer uso en vez de
* cobrar mal en silencio.
*/
export function storeEuroTotal(pdTotal: number, vpTotal: number): number {
if (PD_PER_UNIT !== PD_PER_EUR || PD_PER_UNIT * VP_PRICE_FACTOR !== PV_PER_EUR) {
throw new Error(
`store-pricing desincronizado: PD_PER_UNIT=${PD_PER_UNIT}, VP_PRICE_FACTOR=${VP_PRICE_FACTOR}` +
` pero store-pricing tiene PD_PER_EUR=${PD_PER_EUR}, PV_PER_EUR=${PV_PER_EUR}`,
)
}
return pureEuroTotal(pdTotal, vpTotal)
}
/** Guarda el carrito como pedido pendiente (para entregarlo tras el pago con tarjeta). */
export async function createStoreOrder(
ref: string,
accountId: number,
character: string,
cart: PricedCart,
): Promise<boolean> {
const items = cartEntries(cart).map((e) => `${e.i}:${e.q}`).join(',')
const amount = storeEuroTotal(cart.pdTotal, cart.vpTotal)
try {
await db(DB.default).query(
'INSERT INTO home_store_order (ref, account_id, character_name, items, amount) VALUES (?, ?, ?, ?, ?)',
[ref, accountId, character, items, amount],
)
return true
} catch {
return false
}
}
/**
* Entrega un pedido pagado con tarjeta: busca el carrito por `ref` y envía los
* ítems por correo. Lo llama el fulfillment del servicio `store` (webhook/return).
*
* Aquí no se puede reembolsar lo no entregado como en el pago con saldo: el
* dinero ya lo cobró la pasarela. Devuelve false si no salió TODO, que es lo
* honesto; no puede duplicar porque `claimPaidCheckout` reclama el pago una
* sola vez (y por eso mismo tampoco hay reintento: un envío a medias deja el
* pedido incompleto y hay que rescatarlo a mano desde `home_store_order`).
*/
export async function fulfillStoreOrder(character: string, ref: string): Promise<boolean> {
if (!ref) return false
let rows: RowDataPacket[] = []
try {
;[rows] = await db(DB.default).query<RowDataPacket[]>(
'SELECT character_name, items FROM home_store_order WHERE ref = ?',
[ref],
)
} catch {
return false
}
const order = rows[0]
if (!order) return false
const target = character || String(order.character_name)
const items = String(order.items)
.split(',')
.map((p) => {
const [i, q] = p.split(':')
return { i: Number(i), q: Number(q) }
})
.filter((it) => it.i > 0 && it.q >= 1)
return (await sendStoreItems(target, items)) === items.length
}
/**
* Envía los ítems de la tienda por correo (SOAP `.send items`), troceado a 12
* por correo.
*
* Devuelve CUÁNTAS entradas se entregaron, no un booleano: un correo enviado ya
* no se puede deshacer, así que si el 3.º de 9 falla, los 2 primeros están en el
* buzón del jugador y quien llame tiene que saberlo para reembolsar solo el
* resto. Cada correo es un `.send items`, así que el troceo es atómico por
* correo: un chunk sale entero o no sale.
*/
async function sendStoreItems(character: string, items: { i: number; q: number }[]): Promise<number> {
if (!SAFE_NAME.test(character)) return 0
// Los datos salen de la BD: si algo no cuadra es un bug, y se prefiere no
// enviar nada a enviar de menos y descuadrar el reembolso por índice.
if (items.length === 0 || items.some((it) => !(Number(it.i) > 0) || !(Number(it.q) >= 1))) return 0
const subject = 'Tienda'
const body = 'Has recibido los objetos de la tienda. ¡Que los disfrutes!'
let sent = 0
for (let n = 0; n < items.length; n += MAIL_ITEM_LIMIT) {
const chunk = items.slice(n, n + MAIL_ITEM_LIMIT)
const itemsStr = chunk.map((it) => `${Math.floor(it.i)}:${Math.floor(it.q)}`).join(' ')
const res = await executeSoapCommand(`.send items "${character}" "${subject}" "${body}" ${itemsStr}`)
if (res === null) return sent
sent += chunk.length
}
return sent
}