topup.go 13 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479
  1. package model
  2. import (
  3. "errors"
  4. "fmt"
  5. "github.com/QuantumNous/new-api/common"
  6. "github.com/QuantumNous/new-api/logger"
  7. "github.com/shopspring/decimal"
  8. "gorm.io/gorm"
  9. )
  10. type TopUp struct {
  11. Id int `json:"id"`
  12. UserId int `json:"user_id" gorm:"index"`
  13. Amount int64 `json:"amount"`
  14. Money float64 `json:"money"`
  15. TradeNo string `json:"trade_no" gorm:"unique;type:varchar(255);index"`
  16. PaymentMethod string `json:"payment_method" gorm:"type:varchar(50)"`
  17. CreateTime int64 `json:"create_time"`
  18. CompleteTime int64 `json:"complete_time"`
  19. Status string `json:"status"`
  20. }
  21. var ErrPaymentMethodMismatch = errors.New("payment method mismatch")
  22. func (topUp *TopUp) Insert() error {
  23. var err error
  24. err = DB.Create(topUp).Error
  25. return err
  26. }
  27. func (topUp *TopUp) Update() error {
  28. var err error
  29. err = DB.Save(topUp).Error
  30. return err
  31. }
  32. func GetTopUpById(id int) *TopUp {
  33. var topUp *TopUp
  34. var err error
  35. err = DB.Where("id = ?", id).First(&topUp).Error
  36. if err != nil {
  37. return nil
  38. }
  39. return topUp
  40. }
  41. func GetTopUpByTradeNo(tradeNo string) *TopUp {
  42. var topUp *TopUp
  43. var err error
  44. err = DB.Where("trade_no = ?", tradeNo).First(&topUp).Error
  45. if err != nil {
  46. return nil
  47. }
  48. return topUp
  49. }
  50. func Recharge(referenceId string, customerId string, callerIp string) (err error) {
  51. if referenceId == "" {
  52. return errors.New("未提供支付单号")
  53. }
  54. var quota float64
  55. topUp := &TopUp{}
  56. refCol := "`trade_no`"
  57. if common.UsingPostgreSQL {
  58. refCol = `"trade_no"`
  59. }
  60. err = DB.Transaction(func(tx *gorm.DB) error {
  61. err := tx.Set("gorm:query_option", "FOR UPDATE").Where(refCol+" = ?", referenceId).First(topUp).Error
  62. if err != nil {
  63. return errors.New("充值订单不存在")
  64. }
  65. if topUp.PaymentMethod != "stripe" {
  66. return ErrPaymentMethodMismatch
  67. }
  68. if topUp.Status != common.TopUpStatusPending {
  69. return errors.New("充值订单状态错误")
  70. }
  71. topUp.CompleteTime = common.GetTimestamp()
  72. topUp.Status = common.TopUpStatusSuccess
  73. err = tx.Save(topUp).Error
  74. if err != nil {
  75. return err
  76. }
  77. quota = topUp.Money * common.QuotaPerUnit
  78. err = tx.Model(&User{}).Where("id = ?", topUp.UserId).Updates(map[string]interface{}{"stripe_customer": customerId, "quota": gorm.Expr("quota + ?", quota)}).Error
  79. if err != nil {
  80. return err
  81. }
  82. return nil
  83. })
  84. if err != nil {
  85. common.SysError("topup failed: " + err.Error())
  86. return errors.New("充值失败,请稍后重试")
  87. }
  88. RecordTopupLog(topUp.UserId, fmt.Sprintf("使用在线充值成功,充值金额: %v,支付金额:%d", logger.FormatQuota(int(quota)), topUp.Amount), callerIp, topUp.PaymentMethod, "stripe")
  89. return nil
  90. }
  91. // topUpQueryWindowSeconds 限制充值记录查询的时间窗口(秒)。
  92. const topUpQueryWindowSeconds int64 = 30 * 24 * 60 * 60
  93. // topUpQueryCutoff 返回允许查询的最早 create_time(秒级 Unix 时间戳)。
  94. func topUpQueryCutoff() int64 {
  95. return common.GetTimestamp() - topUpQueryWindowSeconds
  96. }
  97. func GetUserTopUps(userId int, pageInfo *common.PageInfo) (topups []*TopUp, total int64, err error) {
  98. // Start transaction
  99. tx := DB.Begin()
  100. if tx.Error != nil {
  101. return nil, 0, tx.Error
  102. }
  103. defer func() {
  104. if r := recover(); r != nil {
  105. tx.Rollback()
  106. }
  107. }()
  108. cutoff := topUpQueryCutoff()
  109. // Get total count within transaction
  110. err = tx.Model(&TopUp{}).Where("user_id = ? AND create_time >= ?", userId, cutoff).Count(&total).Error
  111. if err != nil {
  112. tx.Rollback()
  113. return nil, 0, err
  114. }
  115. // Get paginated topups within same transaction
  116. err = tx.Where("user_id = ? AND create_time >= ?", userId, cutoff).Order("id desc").Limit(pageInfo.GetPageSize()).Offset(pageInfo.GetStartIdx()).Find(&topups).Error
  117. if err != nil {
  118. tx.Rollback()
  119. return nil, 0, err
  120. }
  121. // Commit transaction
  122. if err = tx.Commit().Error; err != nil {
  123. return nil, 0, err
  124. }
  125. return topups, total, nil
  126. }
  127. // GetAllTopUps 获取全平台的充值记录(管理员使用,不限制时间窗口)
  128. func GetAllTopUps(pageInfo *common.PageInfo) (topups []*TopUp, total int64, err error) {
  129. tx := DB.Begin()
  130. if tx.Error != nil {
  131. return nil, 0, tx.Error
  132. }
  133. defer func() {
  134. if r := recover(); r != nil {
  135. tx.Rollback()
  136. }
  137. }()
  138. if err = tx.Model(&TopUp{}).Count(&total).Error; err != nil {
  139. tx.Rollback()
  140. return nil, 0, err
  141. }
  142. if err = tx.Order("id desc").Limit(pageInfo.GetPageSize()).Offset(pageInfo.GetStartIdx()).Find(&topups).Error; err != nil {
  143. tx.Rollback()
  144. return nil, 0, err
  145. }
  146. if err = tx.Commit().Error; err != nil {
  147. return nil, 0, err
  148. }
  149. return topups, total, nil
  150. }
  151. // searchTopUpCountHardLimit 搜索充值记录时 COUNT 的安全上限,
  152. // 防止对超大表执行无界 COUNT 触发 DoS。
  153. const searchTopUpCountHardLimit = 10000
  154. // SearchUserTopUps 按订单号搜索某用户的充值记录
  155. func SearchUserTopUps(userId int, keyword string, pageInfo *common.PageInfo) (topups []*TopUp, total int64, err error) {
  156. tx := DB.Begin()
  157. if tx.Error != nil {
  158. return nil, 0, tx.Error
  159. }
  160. defer func() {
  161. if r := recover(); r != nil {
  162. tx.Rollback()
  163. }
  164. }()
  165. query := tx.Model(&TopUp{}).Where("user_id = ? AND create_time >= ?", userId, topUpQueryCutoff())
  166. if keyword != "" {
  167. pattern, perr := sanitizeLikePattern(keyword)
  168. if perr != nil {
  169. tx.Rollback()
  170. return nil, 0, perr
  171. }
  172. query = query.Where("trade_no LIKE ? ESCAPE '!'", pattern)
  173. }
  174. if err = query.Limit(searchTopUpCountHardLimit).Count(&total).Error; err != nil {
  175. tx.Rollback()
  176. common.SysError("failed to count search topups: " + err.Error())
  177. return nil, 0, errors.New("搜索充值记录失败")
  178. }
  179. if err = query.Order("id desc").Limit(pageInfo.GetPageSize()).Offset(pageInfo.GetStartIdx()).Find(&topups).Error; err != nil {
  180. tx.Rollback()
  181. common.SysError("failed to search topups: " + err.Error())
  182. return nil, 0, errors.New("搜索充值记录失败")
  183. }
  184. if err = tx.Commit().Error; err != nil {
  185. return nil, 0, err
  186. }
  187. return topups, total, nil
  188. }
  189. // SearchAllTopUps 按订单号搜索全平台充值记录(管理员使用,不限制时间窗口)
  190. func SearchAllTopUps(keyword string, pageInfo *common.PageInfo) (topups []*TopUp, total int64, err error) {
  191. tx := DB.Begin()
  192. if tx.Error != nil {
  193. return nil, 0, tx.Error
  194. }
  195. defer func() {
  196. if r := recover(); r != nil {
  197. tx.Rollback()
  198. }
  199. }()
  200. query := tx.Model(&TopUp{})
  201. if keyword != "" {
  202. pattern, perr := sanitizeLikePattern(keyword)
  203. if perr != nil {
  204. tx.Rollback()
  205. return nil, 0, perr
  206. }
  207. query = query.Where("trade_no LIKE ? ESCAPE '!'", pattern)
  208. }
  209. if err = query.Limit(searchTopUpCountHardLimit).Count(&total).Error; err != nil {
  210. tx.Rollback()
  211. common.SysError("failed to count search topups: " + err.Error())
  212. return nil, 0, errors.New("搜索充值记录失败")
  213. }
  214. if err = query.Order("id desc").Limit(pageInfo.GetPageSize()).Offset(pageInfo.GetStartIdx()).Find(&topups).Error; err != nil {
  215. tx.Rollback()
  216. common.SysError("failed to search topups: " + err.Error())
  217. return nil, 0, errors.New("搜索充值记录失败")
  218. }
  219. if err = tx.Commit().Error; err != nil {
  220. return nil, 0, err
  221. }
  222. return topups, total, nil
  223. }
  224. // ManualCompleteTopUp 管理员手动完成订单并给用户充值
  225. func ManualCompleteTopUp(tradeNo string, callerIp string) error {
  226. if tradeNo == "" {
  227. return errors.New("未提供订单号")
  228. }
  229. refCol := "`trade_no`"
  230. if common.UsingPostgreSQL {
  231. refCol = `"trade_no"`
  232. }
  233. var userId int
  234. var quotaToAdd int
  235. var payMoney float64
  236. var paymentMethod string
  237. err := DB.Transaction(func(tx *gorm.DB) error {
  238. topUp := &TopUp{}
  239. // 行级锁,避免并发补单
  240. if err := tx.Set("gorm:query_option", "FOR UPDATE").Where(refCol+" = ?", tradeNo).First(topUp).Error; err != nil {
  241. return errors.New("充值订单不存在")
  242. }
  243. // 幂等处理:已成功直接返回
  244. if topUp.Status == common.TopUpStatusSuccess {
  245. return nil
  246. }
  247. if topUp.Status != common.TopUpStatusPending {
  248. return errors.New("订单状态不是待支付,无法补单")
  249. }
  250. // 计算应充值额度:
  251. // - Stripe 订单:Money 代表经分组倍率换算后的美元数量,直接 * QuotaPerUnit
  252. // - 其他订单(如易支付):Amount 为美元数量,* QuotaPerUnit
  253. if topUp.PaymentMethod == "stripe" {
  254. dQuotaPerUnit := decimal.NewFromFloat(common.QuotaPerUnit)
  255. quotaToAdd = int(decimal.NewFromFloat(topUp.Money).Mul(dQuotaPerUnit).IntPart())
  256. } else {
  257. dAmount := decimal.NewFromInt(topUp.Amount)
  258. dQuotaPerUnit := decimal.NewFromFloat(common.QuotaPerUnit)
  259. quotaToAdd = int(dAmount.Mul(dQuotaPerUnit).IntPart())
  260. }
  261. if quotaToAdd <= 0 {
  262. return errors.New("无效的充值额度")
  263. }
  264. // 标记完成
  265. topUp.CompleteTime = common.GetTimestamp()
  266. topUp.Status = common.TopUpStatusSuccess
  267. if err := tx.Save(topUp).Error; err != nil {
  268. return err
  269. }
  270. // 增加用户额度(立即写库,保持一致性)
  271. if err := tx.Model(&User{}).Where("id = ?", topUp.UserId).Update("quota", gorm.Expr("quota + ?", quotaToAdd)).Error; err != nil {
  272. return err
  273. }
  274. userId = topUp.UserId
  275. payMoney = topUp.Money
  276. paymentMethod = topUp.PaymentMethod
  277. return nil
  278. })
  279. if err != nil {
  280. return err
  281. }
  282. // 事务外记录日志,避免阻塞
  283. RecordTopupLog(userId, fmt.Sprintf("管理员补单成功,充值金额: %v,支付金额:%f", logger.FormatQuota(quotaToAdd), payMoney), callerIp, paymentMethod, "admin")
  284. return nil
  285. }
  286. func RechargeCreem(referenceId string, customerEmail string, customerName string, callerIp string) (err error) {
  287. if referenceId == "" {
  288. return errors.New("未提供支付单号")
  289. }
  290. var quota int64
  291. topUp := &TopUp{}
  292. refCol := "`trade_no`"
  293. if common.UsingPostgreSQL {
  294. refCol = `"trade_no"`
  295. }
  296. err = DB.Transaction(func(tx *gorm.DB) error {
  297. err := tx.Set("gorm:query_option", "FOR UPDATE").Where(refCol+" = ?", referenceId).First(topUp).Error
  298. if err != nil {
  299. return errors.New("充值订单不存在")
  300. }
  301. if topUp.PaymentMethod != "creem" {
  302. return ErrPaymentMethodMismatch
  303. }
  304. if topUp.Status != common.TopUpStatusPending {
  305. return errors.New("充值订单状态错误")
  306. }
  307. topUp.CompleteTime = common.GetTimestamp()
  308. topUp.Status = common.TopUpStatusSuccess
  309. err = tx.Save(topUp).Error
  310. if err != nil {
  311. return err
  312. }
  313. // Creem 直接使用 Amount 作为充值额度(整数)
  314. quota = topUp.Amount
  315. // 构建更新字段,优先使用邮箱,如果邮箱为空则使用用户名
  316. updateFields := map[string]interface{}{
  317. "quota": gorm.Expr("quota + ?", quota),
  318. }
  319. // 如果有客户邮箱,尝试更新用户邮箱(仅当用户邮箱为空时)
  320. if customerEmail != "" {
  321. // 先检查用户当前邮箱是否为空
  322. var user User
  323. err = tx.Where("id = ?", topUp.UserId).First(&user).Error
  324. if err != nil {
  325. return err
  326. }
  327. // 如果用户邮箱为空,则更新为支付时使用的邮箱
  328. if user.Email == "" {
  329. updateFields["email"] = customerEmail
  330. }
  331. }
  332. err = tx.Model(&User{}).Where("id = ?", topUp.UserId).Updates(updateFields).Error
  333. if err != nil {
  334. return err
  335. }
  336. return nil
  337. })
  338. if err != nil {
  339. common.SysError("creem topup failed: " + err.Error())
  340. return errors.New("充值失败,请稍后重试")
  341. }
  342. RecordTopupLog(topUp.UserId, fmt.Sprintf("使用Creem充值成功,充值额度: %v,支付金额:%.2f", quota, topUp.Money), callerIp, topUp.PaymentMethod, "creem")
  343. return nil
  344. }
  345. func RechargeWaffo(tradeNo string, callerIp string) (err error) {
  346. if tradeNo == "" {
  347. return errors.New("未提供支付单号")
  348. }
  349. var quotaToAdd int
  350. topUp := &TopUp{}
  351. refCol := "`trade_no`"
  352. if common.UsingPostgreSQL {
  353. refCol = `"trade_no"`
  354. }
  355. err = DB.Transaction(func(tx *gorm.DB) error {
  356. err := tx.Set("gorm:query_option", "FOR UPDATE").Where(refCol+" = ?", tradeNo).First(topUp).Error
  357. if err != nil {
  358. return errors.New("充值订单不存在")
  359. }
  360. if topUp.PaymentMethod != "waffo" {
  361. return ErrPaymentMethodMismatch
  362. }
  363. if topUp.Status == common.TopUpStatusSuccess {
  364. return nil // 幂等:已成功直接返回
  365. }
  366. if topUp.Status != common.TopUpStatusPending {
  367. return errors.New("充值订单状态错误")
  368. }
  369. dAmount := decimal.NewFromInt(topUp.Amount)
  370. dQuotaPerUnit := decimal.NewFromFloat(common.QuotaPerUnit)
  371. quotaToAdd = int(dAmount.Mul(dQuotaPerUnit).IntPart())
  372. if quotaToAdd <= 0 {
  373. return errors.New("无效的充值额度")
  374. }
  375. topUp.CompleteTime = common.GetTimestamp()
  376. topUp.Status = common.TopUpStatusSuccess
  377. if err := tx.Save(topUp).Error; err != nil {
  378. return err
  379. }
  380. if err := tx.Model(&User{}).Where("id = ?", topUp.UserId).Update("quota", gorm.Expr("quota + ?", quotaToAdd)).Error; err != nil {
  381. return err
  382. }
  383. return nil
  384. })
  385. if err != nil {
  386. common.SysError("waffo topup failed: " + err.Error())
  387. return errors.New("充值失败,请稍后重试")
  388. }
  389. if quotaToAdd > 0 {
  390. RecordTopupLog(topUp.UserId, fmt.Sprintf("Waffo充值成功,充值额度: %v,支付金额: %.2f", logger.FormatQuota(quotaToAdd), topUp.Money), callerIp, topUp.PaymentMethod, "waffo")
  391. }
  392. return nil
  393. }