fix(v2): webhook 截断 UTF-8 安全 + 投递门禁查库失败落日志(与未付区分)

- MarkFailed: truncateUTF8 避免截断中点 UTF-8 rune, last_error 安全 <=255B
- notifier truncate: 同上, 投递失败消息截断 UTF-8 安全
- deliverOne: 拆分 orderPaid 错误分支 — DB 错误落日志 [webhook] 投递门禁查单失败,与"订单未付"(静默)区分
- test: MarkFailed with long Chinese string, 验证 stored last_error 为有效 UTF-8 且 <=255B

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013nMthbVEmQquxBRKb9Fj8u
This commit is contained in:
wangjia
2026-07-10 11:31:16 +08:00
parent 3f5e44581f
commit 63af44bfe1
3 changed files with 64 additions and 6 deletions
+37
View File
@@ -2,6 +2,7 @@ package store_test
import (
"testing"
"unicode/utf8"
"github.com/wangjia/pay/internal/model"
"github.com/wangjia/pay/internal/store"
@@ -42,3 +43,39 @@ func TestWebhookMarkFailed(t *testing.T) {
t.Fatalf("失败后应仍待投递且 attempts=1, got %+v", again)
}
}
func TestWebhookMarkFailedUTF8Truncation(t *testing.T) {
ws := store.NewWebhookStore(model.OpenTestDB(t))
_ = ws.EnqueueDelivery("PAY-3", "pangolin", "payment.succeeded", `{}`)
list, _ := ws.ListUndelivered(10)
// Create a long Chinese error message that exceeds 255 bytes
// Each Chinese character is typically 3 bytes in UTF-8
longChinese := "错误信息: " // "error message: " in Chinese (each char ~3 bytes)
for i := 0; i < 100; i++ {
longChinese += "中"
}
// longChinese is now > 300 bytes
if err := ws.MarkFailed(list[0].ID, longChinese); err != nil {
t.Fatalf("markFailed with long Chinese: %v", err)
}
again, _ := ws.ListUndelivered(10)
if len(again) != 1 {
t.Fatalf("expected 1 pending row, got %d", len(again))
}
stored := again[0].LastError
// Verify last_error is valid UTF-8
if !utf8.ValidString(stored) {
t.Fatalf("last_error is not valid UTF-8: %q", stored)
}
// Verify last_error is <= 255 bytes
if len(stored) > 255 {
t.Fatalf("last_error exceeds 255 bytes: %d", len(stored))
}
t.Logf("UTF-8 truncated error (%d bytes): %q", len(stored), stored)
}