topup.go 15 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578
  1. package model
  2. import (
  3. "errors"
  4. "fmt"
  5. "github.com/QuantumNous/new-api/common"
  6. "github.com/QuantumNous/new-api/logger"
  7. "github.com/shopspring/decimal"
  8. "gorm.io/gorm"
  9. )
  10. type TopUp struct {
  11. Id int `json:"id"`
  12. UserId int `json:"user_id" gorm:"index"`
  13. Amount int64 `json:"amount"`
  14. Money float64 `json:"money"`
  15. TradeNo string `json:"trade_no" gorm:"unique;type:varchar(255);index"`
  16. PaymentMethod string `json:"payment_method" gorm:"type:varchar(50)"`
  17. CreateTime int64 `json:"create_time"`
  18. CompleteTime int64 `json:"complete_time"`
  19. Status string `json:"status"`
  20. }
  21. const (
  22. PaymentMethodStripe = "stripe"
  23. PaymentMethodCreem = "creem"
  24. PaymentMethodWaffo = "waffo"
  25. PaymentMethodWaffoPancake = "waffo_pancake"
  26. )
  27. var (
  28. ErrPaymentMethodMismatch = errors.New("payment method mismatch")
  29. ErrTopUpNotFound = errors.New("topup not found")
  30. ErrTopUpStatusInvalid = errors.New("topup status invalid")
  31. )
  32. func (topUp *TopUp) Insert() error {
  33. var err error
  34. err = DB.Create(topUp).Error
  35. return err
  36. }
  37. func (topUp *TopUp) Update() error {
  38. var err error
  39. err = DB.Save(topUp).Error
  40. return err
  41. }
  42. func GetTopUpById(id int) *TopUp {
  43. var topUp *TopUp
  44. var err error
  45. err = DB.Where("id = ?", id).First(&topUp).Error
  46. if err != nil {
  47. return nil
  48. }
  49. return topUp
  50. }
  51. func GetTopUpByTradeNo(tradeNo string) *TopUp {
  52. var topUp *TopUp
  53. var err error
  54. err = DB.Where("trade_no = ?", tradeNo).First(&topUp).Error
  55. if err != nil {
  56. return nil
  57. }
  58. return topUp
  59. }
  60. func UpdatePendingTopUpStatus(tradeNo string, expectedPaymentMethod string, targetStatus string) error {
  61. if tradeNo == "" {
  62. return errors.New("未提供支付单号")
  63. }
  64. refCol := "`trade_no`"
  65. if common.UsingPostgreSQL {
  66. refCol = `"trade_no"`
  67. }
  68. return DB.Transaction(func(tx *gorm.DB) error {
  69. topUp := &TopUp{}
  70. if err := tx.Set("gorm:query_option", "FOR UPDATE").Where(refCol+" = ?", tradeNo).First(topUp).Error; err != nil {
  71. return ErrTopUpNotFound
  72. }
  73. if expectedPaymentMethod != "" && topUp.PaymentMethod != expectedPaymentMethod {
  74. return ErrPaymentMethodMismatch
  75. }
  76. if topUp.Status != common.TopUpStatusPending {
  77. return ErrTopUpStatusInvalid
  78. }
  79. topUp.Status = targetStatus
  80. return tx.Save(topUp).Error
  81. })
  82. }
  83. func Recharge(referenceId string, customerId string, callerIp string) (err error) {
  84. if referenceId == "" {
  85. return errors.New("未提供支付单号")
  86. }
  87. var quota float64
  88. topUp := &TopUp{}
  89. refCol := "`trade_no`"
  90. if common.UsingPostgreSQL {
  91. refCol = `"trade_no"`
  92. }
  93. err = DB.Transaction(func(tx *gorm.DB) error {
  94. err := tx.Set("gorm:query_option", "FOR UPDATE").Where(refCol+" = ?", referenceId).First(topUp).Error
  95. if err != nil {
  96. return errors.New("充值订单不存在")
  97. }
  98. if topUp.PaymentMethod != PaymentMethodStripe {
  99. return ErrPaymentMethodMismatch
  100. }
  101. if topUp.Status != common.TopUpStatusPending {
  102. return errors.New("充值订单状态错误")
  103. }
  104. topUp.CompleteTime = common.GetTimestamp()
  105. topUp.Status = common.TopUpStatusSuccess
  106. err = tx.Save(topUp).Error
  107. if err != nil {
  108. return err
  109. }
  110. quota = topUp.Money * common.QuotaPerUnit
  111. err = tx.Model(&User{}).Where("id = ?", topUp.UserId).Updates(map[string]interface{}{"stripe_customer": customerId, "quota": gorm.Expr("quota + ?", quota)}).Error
  112. if err != nil {
  113. return err
  114. }
  115. return nil
  116. })
  117. if err != nil {
  118. common.SysError("topup failed: " + err.Error())
  119. return errors.New("充值失败,请稍后重试")
  120. }
  121. RecordTopupLog(topUp.UserId, fmt.Sprintf("使用在线充值成功,充值金额: %v,支付金额:%d", logger.FormatQuota(int(quota)), topUp.Amount), callerIp, topUp.PaymentMethod, PaymentMethodStripe)
  122. return nil
  123. }
  124. // topUpQueryWindowSeconds 限制充值记录查询的时间窗口(秒)。
  125. const topUpQueryWindowSeconds int64 = 30 * 24 * 60 * 60
  126. // topUpQueryCutoff 返回允许查询的最早 create_time(秒级 Unix 时间戳)。
  127. func topUpQueryCutoff() int64 {
  128. return common.GetTimestamp() - topUpQueryWindowSeconds
  129. }
  130. func GetUserTopUps(userId int, pageInfo *common.PageInfo) (topups []*TopUp, total int64, err error) {
  131. // Start transaction
  132. tx := DB.Begin()
  133. if tx.Error != nil {
  134. return nil, 0, tx.Error
  135. }
  136. defer func() {
  137. if r := recover(); r != nil {
  138. tx.Rollback()
  139. }
  140. }()
  141. cutoff := topUpQueryCutoff()
  142. // Get total count within transaction
  143. err = tx.Model(&TopUp{}).Where("user_id = ? AND create_time >= ?", userId, cutoff).Count(&total).Error
  144. if err != nil {
  145. tx.Rollback()
  146. return nil, 0, err
  147. }
  148. // Get paginated topups within same transaction
  149. err = tx.Where("user_id = ? AND create_time >= ?", userId, cutoff).Order("id desc").Limit(pageInfo.GetPageSize()).Offset(pageInfo.GetStartIdx()).Find(&topups).Error
  150. if err != nil {
  151. tx.Rollback()
  152. return nil, 0, err
  153. }
  154. // Commit transaction
  155. if err = tx.Commit().Error; err != nil {
  156. return nil, 0, err
  157. }
  158. return topups, total, nil
  159. }
  160. // GetAllTopUps 获取全平台的充值记录(管理员使用,不限制时间窗口)
  161. func GetAllTopUps(pageInfo *common.PageInfo) (topups []*TopUp, total int64, err error) {
  162. tx := DB.Begin()
  163. if tx.Error != nil {
  164. return nil, 0, tx.Error
  165. }
  166. defer func() {
  167. if r := recover(); r != nil {
  168. tx.Rollback()
  169. }
  170. }()
  171. if err = tx.Model(&TopUp{}).Count(&total).Error; err != nil {
  172. tx.Rollback()
  173. return nil, 0, err
  174. }
  175. if err = tx.Order("id desc").Limit(pageInfo.GetPageSize()).Offset(pageInfo.GetStartIdx()).Find(&topups).Error; err != nil {
  176. tx.Rollback()
  177. return nil, 0, err
  178. }
  179. if err = tx.Commit().Error; err != nil {
  180. return nil, 0, err
  181. }
  182. return topups, total, nil
  183. }
  184. // searchTopUpCountHardLimit 搜索充值记录时 COUNT 的安全上限,
  185. // 防止对超大表执行无界 COUNT 触发 DoS。
  186. const searchTopUpCountHardLimit = 10000
  187. // SearchUserTopUps 按订单号搜索某用户的充值记录
  188. func SearchUserTopUps(userId int, keyword string, pageInfo *common.PageInfo) (topups []*TopUp, total int64, err error) {
  189. tx := DB.Begin()
  190. if tx.Error != nil {
  191. return nil, 0, tx.Error
  192. }
  193. defer func() {
  194. if r := recover(); r != nil {
  195. tx.Rollback()
  196. }
  197. }()
  198. query := tx.Model(&TopUp{}).Where("user_id = ? AND create_time >= ?", userId, topUpQueryCutoff())
  199. if keyword != "" {
  200. pattern, perr := sanitizeLikePattern(keyword)
  201. if perr != nil {
  202. tx.Rollback()
  203. return nil, 0, perr
  204. }
  205. query = query.Where("trade_no LIKE ? ESCAPE '!'", pattern)
  206. }
  207. if err = query.Limit(searchTopUpCountHardLimit).Count(&total).Error; err != nil {
  208. tx.Rollback()
  209. common.SysError("failed to count search topups: " + err.Error())
  210. return nil, 0, errors.New("搜索充值记录失败")
  211. }
  212. if err = query.Order("id desc").Limit(pageInfo.GetPageSize()).Offset(pageInfo.GetStartIdx()).Find(&topups).Error; err != nil {
  213. tx.Rollback()
  214. common.SysError("failed to search topups: " + err.Error())
  215. return nil, 0, errors.New("搜索充值记录失败")
  216. }
  217. if err = tx.Commit().Error; err != nil {
  218. return nil, 0, err
  219. }
  220. return topups, total, nil
  221. }
  222. // SearchAllTopUps 按订单号搜索全平台充值记录(管理员使用,不限制时间窗口)
  223. func SearchAllTopUps(keyword string, pageInfo *common.PageInfo) (topups []*TopUp, total int64, err error) {
  224. tx := DB.Begin()
  225. if tx.Error != nil {
  226. return nil, 0, tx.Error
  227. }
  228. defer func() {
  229. if r := recover(); r != nil {
  230. tx.Rollback()
  231. }
  232. }()
  233. query := tx.Model(&TopUp{})
  234. if keyword != "" {
  235. pattern, perr := sanitizeLikePattern(keyword)
  236. if perr != nil {
  237. tx.Rollback()
  238. return nil, 0, perr
  239. }
  240. query = query.Where("trade_no LIKE ? ESCAPE '!'", pattern)
  241. }
  242. if err = query.Limit(searchTopUpCountHardLimit).Count(&total).Error; err != nil {
  243. tx.Rollback()
  244. common.SysError("failed to count search topups: " + err.Error())
  245. return nil, 0, errors.New("搜索充值记录失败")
  246. }
  247. if err = query.Order("id desc").Limit(pageInfo.GetPageSize()).Offset(pageInfo.GetStartIdx()).Find(&topups).Error; err != nil {
  248. tx.Rollback()
  249. common.SysError("failed to search topups: " + err.Error())
  250. return nil, 0, errors.New("搜索充值记录失败")
  251. }
  252. if err = tx.Commit().Error; err != nil {
  253. return nil, 0, err
  254. }
  255. return topups, total, nil
  256. }
  257. // ManualCompleteTopUp 管理员手动完成订单并给用户充值
  258. func ManualCompleteTopUp(tradeNo string, callerIp string) error {
  259. if tradeNo == "" {
  260. return errors.New("未提供订单号")
  261. }
  262. refCol := "`trade_no`"
  263. if common.UsingPostgreSQL {
  264. refCol = `"trade_no"`
  265. }
  266. var userId int
  267. var quotaToAdd int
  268. var payMoney float64
  269. var paymentMethod string
  270. err := DB.Transaction(func(tx *gorm.DB) error {
  271. topUp := &TopUp{}
  272. // 行级锁,避免并发补单
  273. if err := tx.Set("gorm:query_option", "FOR UPDATE").Where(refCol+" = ?", tradeNo).First(topUp).Error; err != nil {
  274. return errors.New("充值订单不存在")
  275. }
  276. // 幂等处理:已成功直接返回
  277. if topUp.Status == common.TopUpStatusSuccess {
  278. return nil
  279. }
  280. if topUp.Status != common.TopUpStatusPending {
  281. return errors.New("订单状态不是待支付,无法补单")
  282. }
  283. // 计算应充值额度:
  284. // - Stripe 订单:Money 代表经分组倍率换算后的美元数量,直接 * QuotaPerUnit
  285. // - 其他订单(如易支付):Amount 为美元数量,* QuotaPerUnit
  286. if topUp.PaymentMethod == PaymentMethodStripe {
  287. dQuotaPerUnit := decimal.NewFromFloat(common.QuotaPerUnit)
  288. quotaToAdd = int(decimal.NewFromFloat(topUp.Money).Mul(dQuotaPerUnit).IntPart())
  289. } else {
  290. dAmount := decimal.NewFromInt(topUp.Amount)
  291. dQuotaPerUnit := decimal.NewFromFloat(common.QuotaPerUnit)
  292. quotaToAdd = int(dAmount.Mul(dQuotaPerUnit).IntPart())
  293. }
  294. if quotaToAdd <= 0 {
  295. return errors.New("无效的充值额度")
  296. }
  297. // 标记完成
  298. topUp.CompleteTime = common.GetTimestamp()
  299. topUp.Status = common.TopUpStatusSuccess
  300. if err := tx.Save(topUp).Error; err != nil {
  301. return err
  302. }
  303. // 增加用户额度(立即写库,保持一致性)
  304. if err := tx.Model(&User{}).Where("id = ?", topUp.UserId).Update("quota", gorm.Expr("quota + ?", quotaToAdd)).Error; err != nil {
  305. return err
  306. }
  307. userId = topUp.UserId
  308. payMoney = topUp.Money
  309. paymentMethod = topUp.PaymentMethod
  310. return nil
  311. })
  312. if err != nil {
  313. return err
  314. }
  315. // 事务外记录日志,避免阻塞
  316. RecordTopupLog(userId, fmt.Sprintf("管理员补单成功,充值金额: %v,支付金额:%f", logger.FormatQuota(quotaToAdd), payMoney), callerIp, paymentMethod, "admin")
  317. return nil
  318. }
  319. func RechargeCreem(referenceId string, customerEmail string, customerName string, callerIp string) (err error) {
  320. if referenceId == "" {
  321. return errors.New("未提供支付单号")
  322. }
  323. var quota int64
  324. topUp := &TopUp{}
  325. refCol := "`trade_no`"
  326. if common.UsingPostgreSQL {
  327. refCol = `"trade_no"`
  328. }
  329. err = DB.Transaction(func(tx *gorm.DB) error {
  330. err := tx.Set("gorm:query_option", "FOR UPDATE").Where(refCol+" = ?", referenceId).First(topUp).Error
  331. if err != nil {
  332. return errors.New("充值订单不存在")
  333. }
  334. if topUp.PaymentMethod != PaymentMethodCreem {
  335. return ErrPaymentMethodMismatch
  336. }
  337. if topUp.Status != common.TopUpStatusPending {
  338. return errors.New("充值订单状态错误")
  339. }
  340. topUp.CompleteTime = common.GetTimestamp()
  341. topUp.Status = common.TopUpStatusSuccess
  342. err = tx.Save(topUp).Error
  343. if err != nil {
  344. return err
  345. }
  346. // Creem 直接使用 Amount 作为充值额度(整数)
  347. quota = topUp.Amount
  348. // 构建更新字段,优先使用邮箱,如果邮箱为空则使用用户名
  349. updateFields := map[string]interface{}{
  350. "quota": gorm.Expr("quota + ?", quota),
  351. }
  352. // 如果有客户邮箱,尝试更新用户邮箱(仅当用户邮箱为空时)
  353. if customerEmail != "" {
  354. // 先检查用户当前邮箱是否为空
  355. var user User
  356. err = tx.Where("id = ?", topUp.UserId).First(&user).Error
  357. if err != nil {
  358. return err
  359. }
  360. // 如果用户邮箱为空,则更新为支付时使用的邮箱
  361. if user.Email == "" {
  362. updateFields["email"] = customerEmail
  363. }
  364. }
  365. err = tx.Model(&User{}).Where("id = ?", topUp.UserId).Updates(updateFields).Error
  366. if err != nil {
  367. return err
  368. }
  369. return nil
  370. })
  371. if err != nil {
  372. common.SysError("creem topup failed: " + err.Error())
  373. return errors.New("充值失败,请稍后重试")
  374. }
  375. RecordTopupLog(topUp.UserId, fmt.Sprintf("使用Creem充值成功,充值额度: %v,支付金额:%.2f", quota, topUp.Money), callerIp, topUp.PaymentMethod, PaymentMethodCreem)
  376. return nil
  377. }
  378. func RechargeWaffo(tradeNo string, callerIp string) (err error) {
  379. if tradeNo == "" {
  380. return errors.New("未提供支付单号")
  381. }
  382. var quotaToAdd int
  383. topUp := &TopUp{}
  384. refCol := "`trade_no`"
  385. if common.UsingPostgreSQL {
  386. refCol = `"trade_no"`
  387. }
  388. err = DB.Transaction(func(tx *gorm.DB) error {
  389. err := tx.Set("gorm:query_option", "FOR UPDATE").Where(refCol+" = ?", tradeNo).First(topUp).Error
  390. if err != nil {
  391. return errors.New("充值订单不存在")
  392. }
  393. if topUp.PaymentMethod != PaymentMethodWaffo {
  394. return ErrPaymentMethodMismatch
  395. }
  396. if topUp.Status == common.TopUpStatusSuccess {
  397. return nil // 幂等:已成功直接返回
  398. }
  399. if topUp.Status != common.TopUpStatusPending {
  400. return errors.New("充值订单状态错误")
  401. }
  402. dAmount := decimal.NewFromInt(topUp.Amount)
  403. dQuotaPerUnit := decimal.NewFromFloat(common.QuotaPerUnit)
  404. quotaToAdd = int(dAmount.Mul(dQuotaPerUnit).IntPart())
  405. if quotaToAdd <= 0 {
  406. return errors.New("无效的充值额度")
  407. }
  408. topUp.CompleteTime = common.GetTimestamp()
  409. topUp.Status = common.TopUpStatusSuccess
  410. if err := tx.Save(topUp).Error; err != nil {
  411. return err
  412. }
  413. if err := tx.Model(&User{}).Where("id = ?", topUp.UserId).Update("quota", gorm.Expr("quota + ?", quotaToAdd)).Error; err != nil {
  414. return err
  415. }
  416. return nil
  417. })
  418. if err != nil {
  419. common.SysError("waffo topup failed: " + err.Error())
  420. return errors.New("充值失败,请稍后重试")
  421. }
  422. if quotaToAdd > 0 {
  423. RecordTopupLog(topUp.UserId, fmt.Sprintf("Waffo充值成功,充值额度: %v,支付金额: %.2f", logger.FormatQuota(quotaToAdd), topUp.Money), callerIp, topUp.PaymentMethod, PaymentMethodWaffo)
  424. }
  425. return nil
  426. }
  427. func RechargeWaffoPancake(tradeNo string) (err error) {
  428. if tradeNo == "" {
  429. return errors.New("未提供支付单号")
  430. }
  431. var quotaToAdd int
  432. topUp := &TopUp{}
  433. refCol := "`trade_no`"
  434. if common.UsingPostgreSQL {
  435. refCol = `"trade_no"`
  436. }
  437. err = DB.Transaction(func(tx *gorm.DB) error {
  438. err := tx.Set("gorm:query_option", "FOR UPDATE").Where(refCol+" = ?", tradeNo).First(topUp).Error
  439. if err != nil {
  440. return errors.New("充值订单不存在")
  441. }
  442. if topUp.PaymentMethod != PaymentMethodWaffoPancake {
  443. return ErrPaymentMethodMismatch
  444. }
  445. if topUp.Status == common.TopUpStatusSuccess {
  446. return nil
  447. }
  448. if topUp.Status != common.TopUpStatusPending {
  449. return errors.New("充值订单状态错误")
  450. }
  451. quotaToAdd = int(decimal.NewFromInt(topUp.Amount).Mul(decimal.NewFromFloat(common.QuotaPerUnit)).IntPart())
  452. if quotaToAdd <= 0 {
  453. return errors.New("无效的充值额度")
  454. }
  455. topUp.CompleteTime = common.GetTimestamp()
  456. topUp.Status = common.TopUpStatusSuccess
  457. if err := tx.Save(topUp).Error; err != nil {
  458. return err
  459. }
  460. if err := tx.Model(&User{}).Where("id = ?", topUp.UserId).Update("quota", gorm.Expr("quota + ?", quotaToAdd)).Error; err != nil {
  461. return err
  462. }
  463. return nil
  464. })
  465. if err != nil {
  466. common.SysError("waffo pancake topup failed: " + err.Error())
  467. return errors.New("充值失败,请稍后重试")
  468. }
  469. if quotaToAdd > 0 {
  470. RecordLog(topUp.UserId, LogTypeTopup, fmt.Sprintf("Waffo Pancake充值成功,充值额度: %v,支付金额: %.2f", logger.FormatQuota(quotaToAdd), topUp.Money))
  471. }
  472. return nil
  473. }