Fix billing data integrity, sale atomicity and stock safety

Bills were persisted correctly but read back wrong. The read path rebuilt a
cart from its lines alone, dropping bill-level discounts and loyalty, so every
figure derived from a stored bill was overstated: the upload payload, the day
archive and the shift report. A discounted 529 bill read back as 620.

Money and data integrity
- order_dao: restore bill_discount and points_redeemed when rebuilding a cart;
  keep the reconstruction tier-less so the membership discount is not applied
  twice. Trust the recorded total and points via SaleTransaction.storedTotal.
- checkout_sale + order_dao.commitSale: write the bill, its stock movement and
  the loyalty update in one transaction. Previously a failure part-way through
  left a persisted bill the cashier believed had failed, inviting a duplicate.
- checkout_sale: re-check every line against live stock. A parked bill resumed
  after its stock was sold passed validation and oversold.
- catalogue_dao: allocate the invoice sequence in one transaction; the previous
  read-modify-write could hand two sales the same number and fail UNIQUE.
- local_store: replay unsynced sales after a catalogue import, so a mid-shift
  re-import cannot restore stock that has already been sold.
- payment_controller: stamp the signed-in operator on the bill instead of the
  hardcoded seed session, and pass the terminal id through.
- cart: reconcile per-slab GST against the bill total so the parts sum to the
  whole on a tax invoice.

Sync and reporting
- sync_repository: drain unsynced bills in a loop rather than silently capping
  at one page; stop on rejection so rejected rows cannot loop forever.
- sync_log_dao (new): persist the sync history to the sync_log table, which the
  schema already defined but nothing used. It was in memory, so the only record
  that bills had been uploaded died at restart.
- Scope shift reports by cashier. day_archive is re-keyed to
  (business_date, cashier_name) so a till stays settleable after its bills are
  uploaded and deleted. Schema v4 with a migration that carries v3 rows across.

Input and UI
- barcode_service: consume machine-paced keystrokes so a scan cannot also land
  in the focused field, and raise the bar to 60ms/char while a text field has
  focus so typing a mobile number is not read as a scan. Clock and focus check
  injected so the behaviour is testable.
- primary_button: make the label flexible; label plus trailing total overflowed
  the Charge button by up to 131px.
- app_router: redirect instead of null-casting when the receipt route is
  entered without its transaction.
- customer_repository: reduce the search query to digits so a punctuated mobile
  number matches.

Cleanup
- Remove TransactionRepository.save, CustomerRepository.recordSale and
  OrderDao.insertOrder, all superseded by commitSale.
- dart fix across the tree; 251 analyzer issues down to 3 info-level.

Tests: 23 passing / 15 failing -> 90 passing. Fixed the two defects that broke
the existing suite (containsAll type argument, reset() needing a catalogue) and
deleted the leftover template test. Added coverage for the order round trip,
the day archive after a real sync, stock safety, checkout atomicity, the v3->v4
migration, scanner-versus-human input, and an app-level smoke test that renders
every module.

Note: bills already uploaded with a discount went up overstated. This stops it
happening again but does not correct historical server data.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
Suriya
2026-07-31 18:34:10 +05:30
parent 9891a69a5f
commit af3933092f
62 changed files with 2035 additions and 561 deletions

View File

@@ -0,0 +1,75 @@
import 'dart:convert';
import 'package:sqflite/sqflite.dart';
import '../../domain/entities/sync_event.dart';
import 'app_database.dart';
/// Persists the history of this terminal's conversations with the server.
///
/// Held on disk rather than in memory because it is the only record of a sync
/// that survives the bills themselves: once the server accepts an order the row
/// is deleted from the terminal, so without this the evidence that it ever went
/// up disappears at the next restart.
class SyncLogDao {
const SyncLogDao(this._db);
final Database _db;
Future<void> insert(SyncEvent e) async {
await _db.insert(
Tables.syncLog,
{
'id': e.id,
'type': e.type.name,
'status': e.status.name,
'created_at': e.createdAt.millisecondsSinceEpoch,
'synced_at': e.syncedAt?.millisecondsSinceEpoch,
'summary': e.summary,
'error': e.error,
'attempts': e.attempts,
'payload_json': e.payload.isEmpty ? null : jsonEncode(e.payload),
},
conflictAlgorithm: ConflictAlgorithm.replace,
);
}
/// Newest first, which is the order the events log renders.
Future<List<SyncEvent>> recent({int limit = 200}) async {
final rows = await _db.query(
Tables.syncLog,
orderBy: 'created_at DESC',
limit: limit,
);
return rows.map(_fromRow).toList();
}
/// Keeps the log from growing without bound on a terminal that runs for
/// months. Only ever trims the oldest entries.
Future<void> trim({int keep = 500}) async {
await _db.rawDelete(
'DELETE FROM ${Tables.syncLog} WHERE id NOT IN ('
'SELECT id FROM ${Tables.syncLog} ORDER BY created_at DESC LIMIT ?)',
[keep],
);
}
SyncEvent _fromRow(Map<String, Object?> r) {
final payload = r['payload_json'] as String?;
return SyncEvent(
id: r['id']! as String,
type: SyncEventType.values.byName(r['type']! as String),
status: SyncStatus.values.byName(r['status']! as String),
createdAt: DateTime.fromMillisecondsSinceEpoch(r['created_at']! as int),
summary: r['summary']! as String,
payload: payload == null
? const {}
: (jsonDecode(payload) as Map).cast<String, Object?>(),
syncedAt: r['synced_at'] == null
? null
: DateTime.fromMillisecondsSinceEpoch(r['synced_at']! as int),
error: r['error'] as String?,
attempts: (r['attempts'] as int?) ?? 0,
);
}
}