POST /public/routes/{id}/orders and GET .../current-round are the
first fully unauthenticated routes in the app — no CurrentUser or
org-scoping helper applies, route_id comes straight from the URL.
Participant identification matches the old system's no-login design:
an existing participant (case-insensitive email match on the route) is
reused, and — per explicit user correction — its name/phone/is_active
are overwritten from the submission every time, since there's no login
or "edit my details" page; the order form *is* how members keep their
contact info current. is_active is a checkbox on the form itself
(default true), not inferred. A new email always creates a new
participant row — that's the deliberate no-login way to "change
email". An IntegrityError race on concurrent same-email submissions
falls back to re-selecting the winner rather than 500ing.
Order confirmation email reuses 7b's render/send/log pattern for a
single participant, but a missing order_confirmed template (or missing
route sender identity) is a silent no-op + logger.warning, never a
blocking error — an admin configuration gap must never stop a real
order, unlike task 7b's admin-triggered /announce which fails fast on
the same conditions.
Per explicit user correction, the confirmation email deliberately
reproduces the old system's full-catalog receipt (every wine in the
round, grouped by category, ordered quantity filled in where
applicable) — confirmed via old-emails/Kvitering.eml discussion to be
a deliberate mimicry of the physical order sheet used when buying wine
at the producer's cellar, not a legacy-template artifact to simplify
away. Currency totals are computed at full Decimal precision (EUR
summed, then × eur_dkk_rate with no intermediate rounding) and only
rounded to 2dp (ROUND_HALF_UP) at final display formatting, per
correction — avoids compounding an early rounding error into the DKK
figure.
Empty order_lines is rejected with 400 (not the Pydantic-level 422 a
schema constraint would give) — the old empty-order signup/unsubscribe
hack is intentionally not resurrected here; a real signup/unsubscribe
flow is a separate future task per the user's own framing.
Verified end-to-end directly against the real route 4: a temporary
open round + wine offerings + order_confirmed template, a real order
submitted and a real confirmation email sent/logged, a second order
with the same (differently-cased) email confirmed to update the
existing participant in place rather than duplicate it, a
different-round wine_offering_id rejected (400), an empty order
rejected (400 not 422), and the missing-template case confirmed to
still return 201 with no new MailLog row. All temporary data removed
afterward; the real participant (carsten@itkon.dk, id 133) — legitimately
touched by the get-or-create-with-update logic during testing, exactly
as designed — was restored to its original name/phone/is_active. The
other 307 real participants were untouched throughout.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
60 lines
1.8 KiB
Python
60 lines
1.8 KiB
Python
from datetime import datetime, timezone
|
|
from enum import Enum
|
|
from typing import TYPE_CHECKING, List, Optional
|
|
|
|
from sqlalchemy import Column
|
|
from sqlalchemy import Enum as SAEnum
|
|
from sqlmodel import Field, Relationship, SQLModel
|
|
|
|
from app.models.order_line import OrderLinePublic
|
|
|
|
if TYPE_CHECKING:
|
|
from app.models.order_line import OrderLine
|
|
from app.models.participant import Participant
|
|
from app.models.purchase_round import PurchaseRound
|
|
|
|
|
|
class PaymentStatus(str, Enum):
|
|
UNPAID = "unpaid"
|
|
PAID = "paid"
|
|
|
|
|
|
class OrderBase(SQLModel):
|
|
payment_status: PaymentStatus = Field(
|
|
default=PaymentStatus.UNPAID,
|
|
sa_column=Column(
|
|
SAEnum(
|
|
PaymentStatus,
|
|
name="payment_status",
|
|
native_enum=False,
|
|
values_callable=lambda enum_cls: [member.value for member in enum_cls],
|
|
),
|
|
nullable=False,
|
|
),
|
|
)
|
|
paid_at: Optional[datetime] = Field(default=None)
|
|
created_at: datetime = Field(default_factory=lambda: datetime.now(timezone.utc))
|
|
|
|
|
|
class Order(OrderBase, table=True):
|
|
__tablename__ = "orders"
|
|
|
|
id: Optional[int] = Field(default=None, primary_key=True)
|
|
participant_id: int = Field(foreign_key="participant.id", ondelete="CASCADE")
|
|
purchase_round_id: int = Field(foreign_key="purchase_round.id", ondelete="CASCADE")
|
|
|
|
participant: "Participant" = Relationship(back_populates="orders")
|
|
purchase_round: "PurchaseRound" = Relationship(back_populates="orders")
|
|
order_lines: List["OrderLine"] = Relationship(
|
|
back_populates="order", sa_relationship_kwargs={"cascade": "all, delete-orphan"}
|
|
)
|
|
|
|
|
|
class OrderPublic(OrderBase):
|
|
id: int
|
|
participant_id: int
|
|
purchase_round_id: int
|
|
|
|
|
|
class OrderConfirmation(OrderPublic):
|
|
order_lines: List[OrderLinePublic]
|