Every id in the schema is a uuid and stays one. What was wrong was putting one in front of a person: RecordVisit named every new customer 'Visitor ' || left(id::text, 8), so the arrivals feed, the shop PC and the mobile app all read "Visitor 3446ec35" - the string a shop assistant reads to a colleague and types into a search box. label is a stored column staff can overwrite and SearchVisitors matches on, so formatting around it in a front end would have left the data wrong on three surfaces. Migration 012 adds a per-client visitors.number, taken from a counter on clients with UPDATE ... RETURNING inside the visit transaction. Per client rather than global: a global sequence would tell any customer who signs up how many people the whole platform has ever seen, from their own first visitor number. The backfill numbers existing rows by first_seen_at and relabels only the eight-hex pattern the old statement produced, so a human-typed name is never overwritten. Three of the four things anyone addresses by URL already had a human name and the API simply refused it - a site has a slug, a camera has the id the engine knows it by. refs.go accepts either form anywhere an id is taken; a uuid resolves with no lookup, so every URL a client already stored keeps working. - An ambiguous camera name resolves to nothing, never to a guess: two shops may each have an "Office1" and acting on the first row would edit the wrong shop's camera. - 404 on a path, 400 on a query filter. /api/visits answered fine and it was the filter that was wrong. - site and site_id are both accepted everywhere now. They differed per endpoint, and an unknown query parameter is silently ignored, so getting it the wrong way round returned the whole estate. - The search matches V-13, which is what the product now shows. Two bugs found by running it rather than testing it: - 'Visitor ' || $2::text beside number = $2 makes Postgres deduce two types for one parameter and refuse the insert. It compiled and passed every in-memory test; the first real database rejected it, along with the existing face tests that share the path. - The fallback avatar said "V1" for Visitor 13, Visitor 10 and Visitor 15 alike, and read as the V-1 reference for a fourth person. It shows the number now. The prop is customerRef, not ref - React reserves that name and it would never have arrived. Verified on the live database and through the running API: 13 hex labels became Visitor 1-13 in first-seen order, two typed names left alone, and the same customer reachable by uuid, V-13 and 13. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01HViLj9gYNRtSr7YVZmW5sn
173 lines
5.3 KiB
Go
173 lines
5.3 KiB
Go
package api
|
|
|
|
import (
|
|
"net/http"
|
|
"strings"
|
|
"time"
|
|
|
|
"github.com/loyaly/behavision-server/internal/auth"
|
|
)
|
|
|
|
func (s *Server) handleVisitors(w http.ResponseWriter, r *http.Request) {
|
|
p := PrincipalFrom(r.Context())
|
|
q := trim(r.URL.Query().Get("q"))
|
|
limit := queryInt(r, "limit", 50, 500)
|
|
|
|
out, err := s.Store.SearchVisitors(r.Context(), p.ClientID, q, limit)
|
|
if err != nil {
|
|
s.serverError(w, "search visitors", err)
|
|
return
|
|
}
|
|
if out == nil {
|
|
out = []Customer{}
|
|
}
|
|
writeJSON(w, http.StatusOK, out)
|
|
}
|
|
|
|
func (s *Server) handleVisitorHistory(w http.ResponseWriter, r *http.Request) {
|
|
p := PrincipalFrom(r.Context())
|
|
// 404, not 400: to the caller a reference that is malformed and one that
|
|
// names nobody are the same thing - the customer is not there.
|
|
id, ok := s.resolveVisitor(w, r, r.PathValue("id"))
|
|
if !ok {
|
|
return
|
|
}
|
|
rows, err := s.Store.VisitorHistory(r.Context(), p.ClientID, id,
|
|
queryInt(r, "limit", 100, 1000))
|
|
if err != nil {
|
|
s.serverError(w, "visitor history", err)
|
|
return
|
|
}
|
|
if rows == nil {
|
|
rows = []VisitRow{}
|
|
}
|
|
writeJSON(w, http.StatusOK, rows)
|
|
}
|
|
|
|
// handleSaveProfile attaches a name, a phone number and a consent record to a
|
|
// face the system already knows.
|
|
//
|
|
// PUT, and idempotent on visitor_id: staff fill this in on a shop floor with
|
|
// bad wifi, and a resubmit must correct the record rather than create a second
|
|
// one for the same person.
|
|
func (s *Server) handleSaveProfile(w http.ResponseWriter, r *http.Request) {
|
|
p := PrincipalFrom(r.Context())
|
|
if !p.CanWriteProfiles() {
|
|
writeErr(w, http.StatusForbidden, "forbidden",
|
|
"Your account cannot edit customer details.")
|
|
return
|
|
}
|
|
var body Profile
|
|
if err := decode(w, r, &body); err != nil {
|
|
badRequest(w, err.Error())
|
|
return
|
|
}
|
|
// The path wins over the body. Trusting the body would let a client PUT to
|
|
// one customer's URL and write to another's record.
|
|
visitorID, ok := s.resolveVisitor(w, r, r.PathValue("id"))
|
|
if !ok {
|
|
return
|
|
}
|
|
body.VisitorID = visitorID
|
|
body.FullName = clip(trim(body.FullName), 200)
|
|
body.Phone = clip(trim(body.Phone), 40)
|
|
body.Email = auth.NormalizeEmail(body.Email)
|
|
body.Gender = clip(trim(body.Gender), 32)
|
|
body.Notes = clip(trim(body.Notes), 2000)
|
|
if body.DateOfBirth != "" {
|
|
if _, err := time.Parse("2006-01-02", body.DateOfBirth); err != nil {
|
|
badRequest(w, "date of birth must look like 2001-04-23")
|
|
return
|
|
}
|
|
}
|
|
if body.FullName == "" && body.Phone == "" && body.Email == "" {
|
|
badRequest(w, "give at least a name, a phone number or an email")
|
|
return
|
|
}
|
|
|
|
if err := s.Store.SaveProfile(r.Context(), p.ClientID, body, p.UserID); err != nil {
|
|
if strings.Contains(err.Error(), "no such visitor") {
|
|
// 404, not 403: within one client this is a typo, and the tenant
|
|
// scoping in the query already made a cross-tenant id unfindable.
|
|
writeErr(w, http.StatusNotFound, "not_found",
|
|
"That customer no longer exists.")
|
|
return
|
|
}
|
|
s.serverError(w, "save profile", err)
|
|
return
|
|
}
|
|
// Audited because it links a real name to a biometric template. If a client
|
|
// ever asks who put a name to a face, a guess is not an answer.
|
|
s.Store.Audit(r.Context(), AuditEntry{
|
|
ClientID: p.ClientID, ActorID: p.UserID, ActorKind: "user",
|
|
Action: "profile.save", Entity: "visitor", EntityID: body.VisitorID,
|
|
Detail: map[string]any{"consent": body.Consent},
|
|
})
|
|
w.WriteHeader(http.StatusNoContent)
|
|
}
|
|
|
|
func (s *Server) handlePurchase(w http.ResponseWriter, r *http.Request) {
|
|
p := PrincipalFrom(r.Context())
|
|
if !p.CanWriteProfiles() {
|
|
writeErr(w, http.StatusForbidden, "forbidden",
|
|
"Your account cannot record purchases.")
|
|
return
|
|
}
|
|
var body PurchaseInput
|
|
if err := decode(w, r, &body); err != nil {
|
|
badRequest(w, err.Error())
|
|
return
|
|
}
|
|
body.VisitorID = trim(body.VisitorID)
|
|
if body.VisitorID == "" {
|
|
badRequest(w, "visitor_id is required")
|
|
return
|
|
}
|
|
visitorID, ok := s.resolveVisitor(w, r, body.VisitorID)
|
|
if !ok {
|
|
return
|
|
}
|
|
body.VisitorID = visitorID
|
|
if body.Amount < 0 {
|
|
// A refund is a different record with a different meaning, not a
|
|
// negative sale. Allowing it here would quietly deflate the revenue
|
|
// figure the conversion report is judged by.
|
|
badRequest(w, "amount cannot be negative")
|
|
return
|
|
}
|
|
if body.Currency == "" {
|
|
body.Currency = "INR"
|
|
}
|
|
if len(body.Currency) != 3 {
|
|
badRequest(w, "currency must be a 3-letter code")
|
|
return
|
|
}
|
|
body.Currency = strings.ToUpper(body.Currency)
|
|
if body.Source == "" {
|
|
body.Source = "manual"
|
|
}
|
|
body.Notes = clip(trim(body.Notes), 2000)
|
|
|
|
if err := s.Store.RecordPurchase(r.Context(), p.ClientID, body, p.UserID); err != nil {
|
|
switch {
|
|
case strings.Contains(err.Error(), "no such visitor"):
|
|
writeErr(w, http.StatusNotFound, "not_found",
|
|
"That customer no longer exists.")
|
|
case strings.Contains(err.Error(), "no site"):
|
|
// This is actionable, so it says what to do rather than failing
|
|
// with a foreign key error nobody can read.
|
|
badRequest(w, "this customer has never been seen at a store, "+
|
|
"so there is no site to book the sale against - pass site_id")
|
|
default:
|
|
s.serverError(w, "record purchase", err)
|
|
}
|
|
return
|
|
}
|
|
s.Store.Audit(r.Context(), AuditEntry{
|
|
ClientID: p.ClientID, ActorID: p.UserID, ActorKind: "user",
|
|
Action: "purchase.record", Entity: "visitor", EntityID: body.VisitorID,
|
|
Detail: map[string]any{"amount": body.Amount, "currency": body.Currency},
|
|
})
|
|
w.WriteHeader(http.StatusNoContent)
|
|
}
|