fix(v2): webhook 截断 UTF-8 安全 + 投递门禁查库失败落日志(与未付区分)
- MarkFailed: truncateUTF8 避免截断中点 UTF-8 rune, last_error 安全 <=255B - notifier truncate: 同上, 投递失败消息截断 UTF-8 安全 - deliverOne: 拆分 orderPaid 错误分支 — DB 错误落日志 [webhook] 投递门禁查单失败,与"订单未付"(静默)区分 - test: MarkFailed with long Chinese string, 验证 stored last_error 为有效 UTF-8 且 <=255B Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013nMthbVEmQquxBRKb9Fj8u
This commit is contained in:
@@ -2,6 +2,7 @@ package store
|
|||||||
|
|
||||||
import (
|
import (
|
||||||
"fmt"
|
"fmt"
|
||||||
|
"unicode/utf8"
|
||||||
|
|
||||||
"gorm.io/gorm"
|
"gorm.io/gorm"
|
||||||
"gorm.io/gorm/clause"
|
"gorm.io/gorm/clause"
|
||||||
@@ -51,12 +52,22 @@ func (s *WebhookStore) MarkDelivered(id uint64) error {
|
|||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// truncateUTF8 safely truncates a string to n bytes without splitting UTF-8 runes.
|
||||||
|
func truncateUTF8(s string, n int) string {
|
||||||
|
if len(s) <= n {
|
||||||
|
return s
|
||||||
|
}
|
||||||
|
s = s[:n]
|
||||||
|
for len(s) > 0 && !utf8.ValidString(s) {
|
||||||
|
s = s[:len(s)-1]
|
||||||
|
}
|
||||||
|
return s
|
||||||
|
}
|
||||||
|
|
||||||
// MarkFailed increments attempts and records the last error, leaving the row
|
// MarkFailed increments attempts and records the last error, leaving the row
|
||||||
// undelivered for the next retry sweep.
|
// undelivered for the next retry sweep.
|
||||||
func (s *WebhookStore) MarkFailed(id uint64, errMsg string) error {
|
func (s *WebhookStore) MarkFailed(id uint64, errMsg string) error {
|
||||||
if len(errMsg) > 255 {
|
errMsg = truncateUTF8(errMsg, 255)
|
||||||
errMsg = errMsg[:255]
|
|
||||||
}
|
|
||||||
if err := s.db.Model(&model.WebhookDelivery{}).Where("id = ?", id).
|
if err := s.db.Model(&model.WebhookDelivery{}).Where("id = ?", id).
|
||||||
Updates(map[string]any{
|
Updates(map[string]any{
|
||||||
"attempts": gorm.Expr("attempts + 1"),
|
"attempts": gorm.Expr("attempts + 1"),
|
||||||
|
|||||||
@@ -2,6 +2,7 @@ package store_test
|
|||||||
|
|
||||||
import (
|
import (
|
||||||
"testing"
|
"testing"
|
||||||
|
"unicode/utf8"
|
||||||
|
|
||||||
"github.com/wangjia/pay/internal/model"
|
"github.com/wangjia/pay/internal/model"
|
||||||
"github.com/wangjia/pay/internal/store"
|
"github.com/wangjia/pay/internal/store"
|
||||||
@@ -42,3 +43,39 @@ func TestWebhookMarkFailed(t *testing.T) {
|
|||||||
t.Fatalf("失败后应仍待投递且 attempts=1, got %+v", again)
|
t.Fatalf("失败后应仍待投递且 attempts=1, got %+v", again)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func TestWebhookMarkFailedUTF8Truncation(t *testing.T) {
|
||||||
|
ws := store.NewWebhookStore(model.OpenTestDB(t))
|
||||||
|
_ = ws.EnqueueDelivery("PAY-3", "pangolin", "payment.succeeded", `{}`)
|
||||||
|
list, _ := ws.ListUndelivered(10)
|
||||||
|
|
||||||
|
// Create a long Chinese error message that exceeds 255 bytes
|
||||||
|
// Each Chinese character is typically 3 bytes in UTF-8
|
||||||
|
longChinese := "错误信息: " // "error message: " in Chinese (each char ~3 bytes)
|
||||||
|
for i := 0; i < 100; i++ {
|
||||||
|
longChinese += "中"
|
||||||
|
}
|
||||||
|
// longChinese is now > 300 bytes
|
||||||
|
|
||||||
|
if err := ws.MarkFailed(list[0].ID, longChinese); err != nil {
|
||||||
|
t.Fatalf("markFailed with long Chinese: %v", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
again, _ := ws.ListUndelivered(10)
|
||||||
|
if len(again) != 1 {
|
||||||
|
t.Fatalf("expected 1 pending row, got %d", len(again))
|
||||||
|
}
|
||||||
|
|
||||||
|
stored := again[0].LastError
|
||||||
|
// Verify last_error is valid UTF-8
|
||||||
|
if !utf8.ValidString(stored) {
|
||||||
|
t.Fatalf("last_error is not valid UTF-8: %q", stored)
|
||||||
|
}
|
||||||
|
|
||||||
|
// Verify last_error is <= 255 bytes
|
||||||
|
if len(stored) > 255 {
|
||||||
|
t.Fatalf("last_error exceeds 255 bytes: %d", len(stored))
|
||||||
|
}
|
||||||
|
|
||||||
|
t.Logf("UTF-8 truncated error (%d bytes): %q", len(stored), stored)
|
||||||
|
}
|
||||||
|
|||||||
@@ -13,6 +13,7 @@ import (
|
|||||||
"strconv"
|
"strconv"
|
||||||
"strings"
|
"strings"
|
||||||
"time"
|
"time"
|
||||||
|
"unicode/utf8"
|
||||||
|
|
||||||
"github.com/google/uuid"
|
"github.com/google/uuid"
|
||||||
|
|
||||||
@@ -69,7 +70,11 @@ func (n *Notifier) DeliverPending(limit int) (int, error) {
|
|||||||
func (n *Notifier) deliverOne(d *store.WebhookDeliveryRow) bool {
|
func (n *Notifier) deliverOne(d *store.WebhookDeliveryRow) bool {
|
||||||
// 门禁:订单未付不投递(不计失败,等 settle 翻转后自然放行)。
|
// 门禁:订单未付不投递(不计失败,等 settle 翻转后自然放行)。
|
||||||
paid, err := n.orderPaid(d.OutTradeNo)
|
paid, err := n.orderPaid(d.OutTradeNo)
|
||||||
if err != nil || !paid {
|
if err != nil {
|
||||||
|
log.Printf("[webhook] 投递门禁查单失败 %s: %v", d.OutTradeNo, err)
|
||||||
|
return false
|
||||||
|
}
|
||||||
|
if !paid {
|
||||||
return false
|
return false
|
||||||
}
|
}
|
||||||
cfg, found := n.bizConfig(d.BizSystem)
|
cfg, found := n.bizConfig(d.BizSystem)
|
||||||
@@ -109,9 +114,14 @@ func (n *Notifier) deliverOne(d *store.WebhookDeliveryRow) bool {
|
|||||||
return false
|
return false
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// truncate safely truncates a string to n bytes without splitting UTF-8 runes.
|
||||||
func truncate(s string, n int) string {
|
func truncate(s string, n int) string {
|
||||||
if len(s) > n {
|
if len(s) <= n {
|
||||||
return s[:n]
|
return s
|
||||||
|
}
|
||||||
|
s = s[:n]
|
||||||
|
for len(s) > 0 && !utf8.ValidString(s) {
|
||||||
|
s = s[:len(s)-1]
|
||||||
}
|
}
|
||||||
return s
|
return s
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user