Files
dbx-main/app/modules/cafe24/db.py
T
king 07626bcaf8 feat(cafe24): 상품 목록·검색 + 현재 상세페이지 HTML 조회 (Phase 2)
상세설명 API 경로가 틀려 있던 것을 실물 확인으로 바로잡았다.
`/admin/products/{no}/description` 은 존재하지 않는다(운영몰 호출 결과
`No API found.`). 상세설명은 상품 리소스의 필드이므로 GET/PUT 을
`/admin/products/{no}` 로 옮겼고, PUT body 는 {"request": {...}} 다.

PC/모바일 상세설명이 별도 필드라는 것도 확인됐다. `separated_mobile_description`
('T'/'F') 이 분리 사용 여부이며, 미분리 상품을 수정할 때 description 만 바꾸면
모바일이 어긋난다. Descriptions 데이터클래스에 이 플래그와 불일치 여부를 담아
화면에서 경고로 노출한다.

목록 응답에는 description 이 없어(확인됨) 상세설명은 상품 1건씩 조회한다.
그래서 목록 화면에 미리보기를 뿌리지 않는다 — 상품 87개면 87호출이라 호출
제한에 걸린다.

화면은 읽기 전용이다(편집·적용은 Phase 3~4). 목록은 카페24를 매번 조회해
현재값을 보여주고, 결과를 cafe24_products 에 UPSERT 해둔다(예약·로그 화면에서
API 없이 상품명을 쓰기 위함).

상단 탭의 예약관리가 404 였으므로 Phase 5 안내 화면을 붙였다.

토큰 만료 시각이 화면에 +00:00 로 보이던 것도 고쳤다. 컬럼이 timestamptz 라
psycopg 가 UTC 로 돌려주는 값을 그대로 출력하고 있었다(시각 자체는 정확했다).

검증: 유닛테스트 23개 통과(신규 7개 — 상세설명 경로가 /description 으로
되돌아가지 않는지, PUT payload 모양, 미분리 플래그 파싱, 페이징 clamp).
라우트 8개 등록 확인. 실제 화면은 서버 배포 후 확인 필요.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-14 12:05:19 +09:00

284 lines
12 KiB
Python

"""cafe24_db PostgreSQL 저장소.
- 드라이버: psycopg 3 (`psycopg[binary,pool]`) — 다른 모듈과 동일 패턴.
- 연결 정보: 환경변수 `CAFE24_DB_URL`
(예: postgresql://cafe24_app:<pwd>@postgres-db:5432/cafe24_db)
- 스키마는 앱이 만들지 않는다. `scripts/sql/cafe24_db_init.sql` 을 superuser 가
사전 적용한다. 앱 계정(cafe24_app)은 CRUD 권한만 받는다.
- 연결 풀은 lazy open — 부팅 시 DB 가 잠시 끊겨도 컨테이너가 죽지 않게.
토큰 값은 이 계층에 도달하기 전 이미 Fernet 암호문이다(평문 취급 금지).
API 로그에는 토큰/시크릿을 넣지 않는다.
"""
from __future__ import annotations
import logging
from contextlib import contextmanager
from datetime import date, datetime
from typing import Any, Iterator
from psycopg.rows import dict_row
from psycopg_pool import ConnectionPool
from app.timezone import KST
from . import store
logger = logging.getLogger("cafe24.db")
# save_token_row / TokenLock.save 에서 부분 갱신을 허용하는 컬럼 화이트리스트.
# 여기 없는 키는 무시한다(임의 컬럼 주입 방지).
_TOKEN_FIELDS: tuple[str, ...] = (
"access_token",
"refresh_token",
"access_token_expires_at",
"refresh_token_expires_at",
"scopes",
"last_refreshed_at",
"last_error",
"connected_by",
)
class TokenLock:
"""token_lock() 이 넘겨주는 핸들. 잠긴 행 조회 + 같은 트랜잭션 안 저장."""
def __init__(self, conn: Any, mall_id: str, row: dict[str, Any] | None):
self._conn = conn
self._mall_id = mall_id
self.row = row
def save(self, **fields: Any) -> None:
_update_token_row(self._conn, self._mall_id, fields)
def _update_token_row(conn: Any, mall_id: str, fields: dict[str, Any]) -> None:
"""UPSERT. 주어진 컬럼만 갱신한다(부분 갱신)."""
allowed = {k: v for k, v in fields.items() if k in _TOKEN_FIELDS}
if not allowed:
return
columns = list(allowed.keys())
placeholders = ", ".join(["%s"] * len(columns))
assignments = ", ".join(f"{col} = EXCLUDED.{col}" for col in columns)
conn.execute(
f"""
INSERT INTO cafe24_oauth_tokens (mall_id, {", ".join(columns)})
VALUES (%s, {placeholders})
ON CONFLICT (mall_id) DO UPDATE SET {assignments}
""",
(mall_id, *[allowed[col] for col in columns]),
)
class Cafe24Store:
def __init__(self, dsn: str, *, min_size: int = 1, max_size: int = 5):
self._pool = ConnectionPool(
conninfo=dsn,
min_size=min_size,
max_size=max_size,
kwargs={"row_factory": dict_row, "autocommit": True},
open=False,
)
self._pool.open(wait=False)
def close(self) -> None:
self._pool.close()
# ════════════════════════════════════════════════════════════
# OAuth 토큰 — app/integrations/cafe24/tokens.py 가 요구하는 3개 메서드
# ════════════════════════════════════════════════════════════
def get_token_row(self, mall_id: str) -> dict[str, Any] | None:
with self._pool.connection() as conn:
return conn.execute(
"SELECT * FROM cafe24_oauth_tokens WHERE mall_id = %s",
(mall_id,),
).fetchone()
def save_token_row(self, *, mall_id: str, **fields: Any) -> None:
with self._pool.connection() as conn:
_update_token_row(conn, mall_id, fields)
@contextmanager
def token_lock(self, mall_id: str) -> Iterator[TokenLock]:
"""토큰 행을 FOR UPDATE 로 잠근 채 작업.
web 컨테이너와 worker 컨테이너가 동시에 refresh 하는 것을 막는다
(카페24는 refresh token 을 회전시키므로 동시 갱신 시 한쪽이 무효화됨).
행이 아직 없으면 row=None 으로 넘어간다.
"""
with self._pool.connection() as conn:
with conn.transaction():
row = conn.execute(
"SELECT * FROM cafe24_oauth_tokens WHERE mall_id = %s FOR UPDATE",
(mall_id,),
).fetchone()
yield TokenLock(conn, mall_id, row)
def disconnect(self, mall_id: str) -> None:
"""연결 해제 — 토큰만 지운다(이력/예약은 보존)."""
with self._pool.connection() as conn:
conn.execute("DELETE FROM cafe24_oauth_tokens WHERE mall_id = %s", (mall_id,))
# ════════════════════════════════════════════════════════════
# API 호출 로그 (Cafe24Client 가 주입받아 호출)
# ⚠️ Authorization/토큰/시크릿은 절대 기록하지 않는다.
# ════════════════════════════════════════════════════════════
def log_api_call(
self,
*,
endpoint: str,
method: str,
product_no: int | None,
http_status: int | None,
result: str,
error_message: str,
duration_ms: int,
) -> None:
with self._pool.connection() as conn:
conn.execute(
"""
INSERT INTO cafe24_api_logs
(endpoint, method, product_no, http_status, result, error_message, duration_ms)
VALUES (%s,%s,%s,%s,%s,%s,%s)
""",
(endpoint, method, product_no, http_status, result, error_message, duration_ms),
)
def list_api_logs(self, *, limit: int = 100) -> list[dict[str, Any]]:
with self._pool.connection() as conn:
rows = conn.execute(
"""
SELECT * FROM cafe24_api_logs
ORDER BY created_at DESC, id DESC
LIMIT %s
""",
(max(1, min(int(limit), 500)),),
).fetchall()
return [self._serialize(r) for r in rows]
# ════════════════════════════════════════════════════════════
# 작업 감사 로그
# ════════════════════════════════════════════════════════════
def log_audit(
self,
*,
actor: str,
action: str,
product_no: int | None = None,
revision_id: int | None = None,
schedule_id: int | None = None,
result: str = "",
detail: str = "",
) -> None:
with self._pool.connection() as conn:
self._insert_audit(
conn,
actor=actor,
action=action,
product_no=product_no,
revision_id=revision_id,
schedule_id=schedule_id,
result=result,
detail=detail,
)
@staticmethod
def _insert_audit(
conn: Any,
*,
actor: str,
action: str,
product_no: int | None = None,
revision_id: int | None = None,
schedule_id: int | None = None,
result: str = "",
detail: str = "",
) -> None:
"""호출자의 트랜잭션에 합류시키기 위해 conn 을 받는 정적 헬퍼."""
conn.execute(
"""
INSERT INTO cafe24_audit_logs
(actor, action, product_no, revision_id, schedule_id, result, detail)
VALUES (%s,%s,%s,%s,%s,%s,%s)
""",
(actor, action, product_no, revision_id, schedule_id, result, detail[:1000]),
)
def list_audit_logs(self, *, limit: int = 100) -> list[dict[str, Any]]:
with self._pool.connection() as conn:
rows = conn.execute(
"""
SELECT * FROM cafe24_audit_logs
ORDER BY created_at DESC, id DESC
LIMIT %s
""",
(max(1, min(int(limit), 500)),),
).fetchall()
return [self._serialize(r) for r in rows]
# ════════════════════════════════════════════════════════════
# 상품 캐시
# source of truth 는 언제나 카페24다. 이 표는 목록 조회 결과를 담아두는
# 곳이며, 예약·로그 화면에서 API 호출 없이 상품명을 보여줄 때 쓴다.
# 상세설명(HTML)은 여기 넣지 않는다(cafe24_product_revisions 담당).
# ════════════════════════════════════════════════════════════
def upsert_products(self, rows: list[dict[str, Any]]) -> int:
"""정규화된 상품 dict 목록(products.normalize_product 결과)을 UPSERT."""
valid = [r for r in rows if int(r.get("product_no") or 0) > 0]
if not valid:
return 0
with self._pool.connection() as conn:
with conn.cursor() as cur:
cur.executemany(
"""
INSERT INTO cafe24_products
(product_no, product_code, product_name, display, selling, last_synced_at)
VALUES (%s,%s,%s,%s,%s, now())
ON CONFLICT (product_no) DO UPDATE SET
product_code = EXCLUDED.product_code,
product_name = EXCLUDED.product_name,
display = EXCLUDED.display,
selling = EXCLUDED.selling,
last_synced_at = now()
""",
[
(
int(r["product_no"]),
str(r.get("product_code") or ""),
str(r.get("product_name") or ""),
bool(r.get("display", True)),
bool(r.get("selling", True)),
)
for r in valid
],
)
return len(valid)
def get_cached_product(self, product_no: int) -> dict[str, Any]:
with self._pool.connection() as conn:
row = conn.execute(
"SELECT * FROM cafe24_products WHERE product_no = %s",
(int(product_no),),
).fetchone()
return self._serialize(row)
# ════════════════════════════════════════════════════════════
# 직렬화 — datetime → KST ISO, date → ISO (다른 모듈과 동일)
# ════════════════════════════════════════════════════════════
@staticmethod
def _serialize(row: dict[str, Any] | None) -> dict[str, Any]:
if not row:
return {}
out = dict(row)
for key, value in list(out.items()):
if isinstance(value, datetime):
aware = value if value.tzinfo else value.replace(tzinfo=KST)
out[key] = aware.astimezone(KST).isoformat(timespec="seconds")
elif isinstance(value, date):
out[key] = value.isoformat()
return out
__all__ = ["Cafe24Store", "TokenLock", "store"]