fix(backend): 修复库存 TOCTOU 竞态 + handler 白名单更新 + 对账接口

#29 ApproveStockOut:FOR UPDATE 锁定批次后再内存汇总总量,
     消除预检 SUM 与加锁之间的竞态窗口,减少一次 DB 往返

#30 partner/warehouse/user/product_attr/product_option Update 方法:
     - 绑定到独立 req struct,防止请求体覆盖记录 ID
     - 改用 db.Model.Where("shop_id=?").Updates(map) 白名单更新,
       数据库层强制 shop_id 隔离约束

#31 新增 GET /api/v1/admin/reconcile:对比 inventories 当前库存
     与 inventory_logs 流水净量,返回差异行,用于发现不平账异常

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
wangjia
2026-06-11 00:21:48 +08:00
parent 666bf56933
commit 51cfe5fc6d
8 changed files with 178 additions and 52 deletions
+29 -3
View File
@@ -79,12 +79,38 @@ func (h *PartnerHandler) Update(c *gin.Context) {
c.JSON(http.StatusNotFound, gin.H{"error": "not found"})
return
}
if err := c.ShouldBindJSON(&p); err != nil {
var req struct {
Name string `json:"name"`
Type string `json:"type"`
Code string `json:"code"`
Contact string `json:"contact"`
Phone string `json:"phone"`
Address string `json:"address"`
BankAccount string `json:"bank_account"`
CreditLimit float64 `json:"credit_limit"`
Status string `json:"status"`
Remark string `json:"remark"`
}
if err := c.ShouldBindJSON(&req); err != nil {
c.JSON(http.StatusBadRequest, gin.H{"error": err.Error()})
return
}
p.ShopID = shopID
h.db.Save(&p)
if err := h.db.Model(&p).Where("shop_id = ?", shopID).Updates(map[string]interface{}{
"name": req.Name,
"type": req.Type,
"code": req.Code,
"contact": req.Contact,
"phone": req.Phone,
"address": req.Address,
"bank_account": req.BankAccount,
"credit_limit": req.CreditLimit,
"status": req.Status,
"remark": req.Remark,
}).Error; err != nil {
c.JSON(http.StatusInternalServerError, gin.H{"error": err.Error()})
return
}
h.db.Where("id = ? AND shop_id = ?", p.ID, shopID).First(&p)
c.JSON(http.StatusOK, gin.H{"data": p})
}