Give every terminal its own identity, and report fleet presence

Answers "which of my 100 tills are alive and healthy", and fixes three things
that were fine on one device and broken on a hundred.

Terminal identity (lib/data/local/terminal_identity.dart)
- Every device mints a UUID on first run, stored in its own database, plus a
  short code (T4A9) derived from it. Renaming keeps the device id, so history
  keeps pointing at the same physical till.
- Replaces the literal 'TERM-01', which was hardcoded in five places. The whole
  fleet reported as one terminal: shift reports merged, MQTT topics collided,
  and a second connection with the same client id evicts the first from the
  broker — so two tills would have knocked each other offline in a loop.

Invoice numbers now carry the terminal code
- INV-2608-T4A9-00042. The sequence counter lives in each till's own database
  and starts at 1, so without this every terminal in the fleet minted
  INV-2608-00001 for its first sale of the month. The order UUID kept the data
  distinct; the number a customer quotes on a receipt was not.

SQLite pragmas
- WAL, so the product grid refreshing does not block the sale being written,
  and the file is never left mid-rewrite by a power cut.
- busy_timeout 5s, so a contended lock waits instead of throwing "database is
  locked" — which at checkout is a failed sale with a customer standing there.
- synchronous NORMAL, the right trade under WAL for a till.

Fleet presence (lib/data/sync/presence_reporter.dart)
- Retained status record on connect and once a minute: device id, code, name,
  app version, pending bill count, last upload, catalogue revision, sync halt
  state. Retained so a dashboard connecting at noon gets all 100 terminals
  immediately rather than a blank board.
- The Last Will already said "reachable". A till can be connected and still be
  holding 200 unsent bills or running last month's prices; only pending_bills
  and catalogue_revision say so.

NATS
- The MQTT gateway maps / to . so the existing transport works unchanged.
  SyncConfig.asNatsSubject() exposes the translation, and the contract doc
  gives the JetStream subjects (pos.*.*.order, pos.*.*.status) plus the two
  server-side requirements: a file-backed stream, and the ack published by the
  consumer after commit rather than by the ingest handler.

Tests: 129 -> 140. New coverage for identity minting and stability, per-device
invoice uniqueness, topic and client-id separation, NATS subject mapping, and
the two pragmas. Suite run three times clean.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
Suriya
2026-08-01 11:17:23 +05:30
parent 0a49323858
commit 30d6d1080f
16 changed files with 635 additions and 15 deletions

View File

@@ -60,7 +60,7 @@ class AppDatabase {
path,
options: OpenDatabaseOptions(
version: _version,
onConfigure: (db) => db.execute('PRAGMA foreign_keys = ON'),
onConfigure: _configure,
onCreate: (db, version) async => _createSchema(db),
onUpgrade: (db, from, to) async {
if (from < 2) await db.execute(_createDayArchive);
@@ -84,12 +84,35 @@ class AppDatabase {
inMemoryDatabasePath,
options: OpenDatabaseOptions(
version: _version,
onConfigure: (db) => db.execute('PRAGMA foreign_keys = ON'),
onConfigure: _configure,
onCreate: (db, version) async => _createSchema(db),
),
);
}
/// Pragmas applied on every connection, before any query runs.
///
/// Defaults are wrong for a till:
///
/// * **WAL** lets a read proceed while a write is in flight. On the rollback
/// journal the product grid refreshing would block the sale being written.
/// It also survives a power cut better: the database file is never left
/// mid-rewrite.
/// * **busy_timeout** makes a contended lock wait instead of throwing
/// `database is locked` — which, at checkout, is a failed sale.
/// * **synchronous = NORMAL** is the right trade under WAL: an fsync per
/// transaction costs more than a POS can spare, and WAL still recovers a
/// committed transaction after a crash. Only a host OS crash or power loss
/// can lose the last commits, which is what the UPS is for.
static Future<void> _configure(Database db) async {
await db.execute('PRAGMA foreign_keys = ON');
await db.execute('PRAGMA busy_timeout = 5000');
// In-memory databases have no WAL; asking for it is harmless but pointless.
await db.execute('PRAGMA journal_mode = WAL');
await db.execute('PRAGMA synchronous = NORMAL');
}
Future<void> close() async {
await _db?.close();
_db = null;
@@ -345,6 +368,19 @@ class MetaKeys {
static const String catalogueRevision = 'catalogue_revision';
static const String invoiceSequence = 'invoice_sequence';
/// Fleet identity. Minted once on first run and never changed — it is what
/// ties a bill, an MQTT topic and a presence record to one physical till.
static const String deviceId = 'terminal_device_id';
/// Short code stamped into invoice numbers, e.g. `T4A9`. Unique per device
/// so two tills in the same shop cannot mint the same invoice.
static const String terminalCode = 'terminal_code';
/// Human label shown in Settings and on the fleet board, e.g. "Counter 2".
static const String terminalName = 'terminal_name';
static const String storeId = 'store_id';
/// Printer chosen in Settings. Stored as the printer's `url`, which is what
/// `Printing.directPrintPdf` needs to target it without a dialog.
static const String printerUrl = 'printer_url';