7a2e933c16
1) 한글 파일명이 %EC%9A%A9… 으로 보이던 문제
카페24는 상세페이지 안 이미지 경로를 퍼센트 인코딩해서 저장한다. 화면에서는
읽을 수 없으므로 store.decode_html_urls 로 풀어 보여주고, 저장할 때
encode_html_urls 로 되돌린다. 두 함수는 서로의 역이며 왕복이 보존된다 —
편집하지 않고 적용해도 카페24 저장값이 한 바이트도 달라지지 않는다.
깨뜨리지 않기 위한 두 가지 제약을 뒀다. 디코딩은 non-ASCII(%80~%FF)만 한다.
%20·%3C 를 풀면 URL·HTML 구조가 깨진다. 인코딩은 src/href/poster/data-src 와
CSS url() 안의 값만 한다. 본문 한글 텍스트를 인코딩하면 페이지가 망가진다.
UTF-8 로 해석되지 않는 이스케이프(EUC-KR 등)는 건드리지 않고 그대로 둔다.
2) 편집 후 적용
POST /cafe24/products/{no}/apply 는 이 순서를 지킨다.
카페24 현재값 재조회 → BACKUP revision → 지문 대조 → PUT → MANUAL revision
현재값을 다시 읽는 것은 로컬 DB 의 마지막 버전이 지금 카페24에 올라간 값이라고
믿을 수 없기 때문이다(관리자 페이지에서 직접 고쳤을 수 있다). 지문(sha256 앞
32자)은 편집 중 남이 바꾼 내용을 조용히 덮어쓰는 것을 막는 낙관적 잠금이다.
미분리 상품(separated_mobile_description='F')은 모바일 필드도 같은 HTML 로
함께 쓴다. PC 만 바꾸면 모바일 상세가 어긋난다. 분리 상품은 모바일을 건드리지
않고 화면에 별도 반영 안내를 띄운다.
빈 내용은 거부한다(상세페이지를 통째로 날리는 실수 방지). 변경이 없으면 API 를
호출하지 않는다. 실패 시에도 BACKUP 은 남아 있으므로 오류 메시지에 버전 번호를
알려준다. 편집 중 페이지 이탈 경고도 넣었다.
버전 이력 표를 상세 화면에 붙였다(목록 조회는 html_content 를 제외하고 길이만
계산한다 — 수 MB 가 될 수 있다). 버전 선택 복원은 Phase 6.
검증: 유닛테스트 30개 통과(신규 7개 — 실제 파일명으로 왕복 동일성, ASCII
이스케이프 미변환, 본문 한글 보존, CSS url(), 잘못된 UTF-8 무시, 지문).
실제 쓰기(PUT)는 서버 배포 후 테스트 상품 1건으로 확인 필요.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
340 lines
14 KiB
Python
340 lines
14 KiB
Python
"""cafe24_db PostgreSQL 저장소.
|
|
|
|
- 드라이버: psycopg 3 (`psycopg[binary,pool]`) — 다른 모듈과 동일 패턴.
|
|
- 연결 정보: 환경변수 `CAFE24_DB_URL`
|
|
(예: postgresql://cafe24_app:<pwd>@postgres-db:5432/cafe24_db)
|
|
- 스키마는 앱이 만들지 않는다. `scripts/sql/cafe24_db_init.sql` 을 superuser 가
|
|
사전 적용한다. 앱 계정(cafe24_app)은 CRUD 권한만 받는다.
|
|
- 연결 풀은 lazy open — 부팅 시 DB 가 잠시 끊겨도 컨테이너가 죽지 않게.
|
|
|
|
토큰 값은 이 계층에 도달하기 전 이미 Fernet 암호문이다(평문 취급 금지).
|
|
API 로그에는 토큰/시크릿을 넣지 않는다.
|
|
"""
|
|
|
|
from __future__ import annotations
|
|
|
|
import logging
|
|
from contextlib import contextmanager
|
|
from datetime import date, datetime
|
|
from typing import Any, Iterator
|
|
|
|
from psycopg.rows import dict_row
|
|
from psycopg_pool import ConnectionPool
|
|
|
|
from app.timezone import KST
|
|
|
|
from . import store
|
|
|
|
logger = logging.getLogger("cafe24.db")
|
|
|
|
# save_token_row / TokenLock.save 에서 부분 갱신을 허용하는 컬럼 화이트리스트.
|
|
# 여기 없는 키는 무시한다(임의 컬럼 주입 방지).
|
|
_TOKEN_FIELDS: tuple[str, ...] = (
|
|
"access_token",
|
|
"refresh_token",
|
|
"access_token_expires_at",
|
|
"refresh_token_expires_at",
|
|
"scopes",
|
|
"last_refreshed_at",
|
|
"last_error",
|
|
"connected_by",
|
|
)
|
|
|
|
|
|
class TokenLock:
|
|
"""token_lock() 이 넘겨주는 핸들. 잠긴 행 조회 + 같은 트랜잭션 안 저장."""
|
|
|
|
def __init__(self, conn: Any, mall_id: str, row: dict[str, Any] | None):
|
|
self._conn = conn
|
|
self._mall_id = mall_id
|
|
self.row = row
|
|
|
|
def save(self, **fields: Any) -> None:
|
|
_update_token_row(self._conn, self._mall_id, fields)
|
|
|
|
|
|
def _update_token_row(conn: Any, mall_id: str, fields: dict[str, Any]) -> None:
|
|
"""UPSERT. 주어진 컬럼만 갱신한다(부분 갱신)."""
|
|
allowed = {k: v for k, v in fields.items() if k in _TOKEN_FIELDS}
|
|
if not allowed:
|
|
return
|
|
columns = list(allowed.keys())
|
|
placeholders = ", ".join(["%s"] * len(columns))
|
|
assignments = ", ".join(f"{col} = EXCLUDED.{col}" for col in columns)
|
|
conn.execute(
|
|
f"""
|
|
INSERT INTO cafe24_oauth_tokens (mall_id, {", ".join(columns)})
|
|
VALUES (%s, {placeholders})
|
|
ON CONFLICT (mall_id) DO UPDATE SET {assignments}
|
|
""",
|
|
(mall_id, *[allowed[col] for col in columns]),
|
|
)
|
|
|
|
|
|
class Cafe24Store:
|
|
def __init__(self, dsn: str, *, min_size: int = 1, max_size: int = 5):
|
|
self._pool = ConnectionPool(
|
|
conninfo=dsn,
|
|
min_size=min_size,
|
|
max_size=max_size,
|
|
kwargs={"row_factory": dict_row, "autocommit": True},
|
|
open=False,
|
|
)
|
|
self._pool.open(wait=False)
|
|
|
|
def close(self) -> None:
|
|
self._pool.close()
|
|
|
|
# ════════════════════════════════════════════════════════════
|
|
# OAuth 토큰 — app/integrations/cafe24/tokens.py 가 요구하는 3개 메서드
|
|
# ════════════════════════════════════════════════════════════
|
|
def get_token_row(self, mall_id: str) -> dict[str, Any] | None:
|
|
with self._pool.connection() as conn:
|
|
return conn.execute(
|
|
"SELECT * FROM cafe24_oauth_tokens WHERE mall_id = %s",
|
|
(mall_id,),
|
|
).fetchone()
|
|
|
|
def save_token_row(self, *, mall_id: str, **fields: Any) -> None:
|
|
with self._pool.connection() as conn:
|
|
_update_token_row(conn, mall_id, fields)
|
|
|
|
@contextmanager
|
|
def token_lock(self, mall_id: str) -> Iterator[TokenLock]:
|
|
"""토큰 행을 FOR UPDATE 로 잠근 채 작업.
|
|
|
|
web 컨테이너와 worker 컨테이너가 동시에 refresh 하는 것을 막는다
|
|
(카페24는 refresh token 을 회전시키므로 동시 갱신 시 한쪽이 무효화됨).
|
|
행이 아직 없으면 row=None 으로 넘어간다.
|
|
"""
|
|
with self._pool.connection() as conn:
|
|
with conn.transaction():
|
|
row = conn.execute(
|
|
"SELECT * FROM cafe24_oauth_tokens WHERE mall_id = %s FOR UPDATE",
|
|
(mall_id,),
|
|
).fetchone()
|
|
yield TokenLock(conn, mall_id, row)
|
|
|
|
def disconnect(self, mall_id: str) -> None:
|
|
"""연결 해제 — 토큰만 지운다(이력/예약은 보존)."""
|
|
with self._pool.connection() as conn:
|
|
conn.execute("DELETE FROM cafe24_oauth_tokens WHERE mall_id = %s", (mall_id,))
|
|
|
|
# ════════════════════════════════════════════════════════════
|
|
# API 호출 로그 (Cafe24Client 가 주입받아 호출)
|
|
# ⚠️ Authorization/토큰/시크릿은 절대 기록하지 않는다.
|
|
# ════════════════════════════════════════════════════════════
|
|
def log_api_call(
|
|
self,
|
|
*,
|
|
endpoint: str,
|
|
method: str,
|
|
product_no: int | None,
|
|
http_status: int | None,
|
|
result: str,
|
|
error_message: str,
|
|
duration_ms: int,
|
|
) -> None:
|
|
with self._pool.connection() as conn:
|
|
conn.execute(
|
|
"""
|
|
INSERT INTO cafe24_api_logs
|
|
(endpoint, method, product_no, http_status, result, error_message, duration_ms)
|
|
VALUES (%s,%s,%s,%s,%s,%s,%s)
|
|
""",
|
|
(endpoint, method, product_no, http_status, result, error_message, duration_ms),
|
|
)
|
|
|
|
def list_api_logs(self, *, limit: int = 100) -> list[dict[str, Any]]:
|
|
with self._pool.connection() as conn:
|
|
rows = conn.execute(
|
|
"""
|
|
SELECT * FROM cafe24_api_logs
|
|
ORDER BY created_at DESC, id DESC
|
|
LIMIT %s
|
|
""",
|
|
(max(1, min(int(limit), 500)),),
|
|
).fetchall()
|
|
return [self._serialize(r) for r in rows]
|
|
|
|
# ════════════════════════════════════════════════════════════
|
|
# 작업 감사 로그
|
|
# ════════════════════════════════════════════════════════════
|
|
def log_audit(
|
|
self,
|
|
*,
|
|
actor: str,
|
|
action: str,
|
|
product_no: int | None = None,
|
|
revision_id: int | None = None,
|
|
schedule_id: int | None = None,
|
|
result: str = "",
|
|
detail: str = "",
|
|
) -> None:
|
|
with self._pool.connection() as conn:
|
|
self._insert_audit(
|
|
conn,
|
|
actor=actor,
|
|
action=action,
|
|
product_no=product_no,
|
|
revision_id=revision_id,
|
|
schedule_id=schedule_id,
|
|
result=result,
|
|
detail=detail,
|
|
)
|
|
|
|
@staticmethod
|
|
def _insert_audit(
|
|
conn: Any,
|
|
*,
|
|
actor: str,
|
|
action: str,
|
|
product_no: int | None = None,
|
|
revision_id: int | None = None,
|
|
schedule_id: int | None = None,
|
|
result: str = "",
|
|
detail: str = "",
|
|
) -> None:
|
|
"""호출자의 트랜잭션에 합류시키기 위해 conn 을 받는 정적 헬퍼."""
|
|
conn.execute(
|
|
"""
|
|
INSERT INTO cafe24_audit_logs
|
|
(actor, action, product_no, revision_id, schedule_id, result, detail)
|
|
VALUES (%s,%s,%s,%s,%s,%s,%s)
|
|
""",
|
|
(actor, action, product_no, revision_id, schedule_id, result, detail[:1000]),
|
|
)
|
|
|
|
def list_audit_logs(self, *, limit: int = 100) -> list[dict[str, Any]]:
|
|
with self._pool.connection() as conn:
|
|
rows = conn.execute(
|
|
"""
|
|
SELECT * FROM cafe24_audit_logs
|
|
ORDER BY created_at DESC, id DESC
|
|
LIMIT %s
|
|
""",
|
|
(max(1, min(int(limit), 500)),),
|
|
).fetchall()
|
|
return [self._serialize(r) for r in rows]
|
|
|
|
# ════════════════════════════════════════════════════════════
|
|
# 상품 캐시
|
|
# source of truth 는 언제나 카페24다. 이 표는 목록 조회 결과를 담아두는
|
|
# 곳이며, 예약·로그 화면에서 API 호출 없이 상품명을 보여줄 때 쓴다.
|
|
# 상세설명(HTML)은 여기 넣지 않는다(cafe24_product_revisions 담당).
|
|
# ════════════════════════════════════════════════════════════
|
|
def upsert_products(self, rows: list[dict[str, Any]]) -> int:
|
|
"""정규화된 상품 dict 목록(products.normalize_product 결과)을 UPSERT."""
|
|
valid = [r for r in rows if int(r.get("product_no") or 0) > 0]
|
|
if not valid:
|
|
return 0
|
|
with self._pool.connection() as conn:
|
|
with conn.cursor() as cur:
|
|
cur.executemany(
|
|
"""
|
|
INSERT INTO cafe24_products
|
|
(product_no, product_code, product_name, display, selling, last_synced_at)
|
|
VALUES (%s,%s,%s,%s,%s, now())
|
|
ON CONFLICT (product_no) DO UPDATE SET
|
|
product_code = EXCLUDED.product_code,
|
|
product_name = EXCLUDED.product_name,
|
|
display = EXCLUDED.display,
|
|
selling = EXCLUDED.selling,
|
|
last_synced_at = now()
|
|
""",
|
|
[
|
|
(
|
|
int(r["product_no"]),
|
|
str(r.get("product_code") or ""),
|
|
str(r.get("product_name") or ""),
|
|
bool(r.get("display", True)),
|
|
bool(r.get("selling", True)),
|
|
)
|
|
for r in valid
|
|
],
|
|
)
|
|
return len(valid)
|
|
|
|
def get_cached_product(self, product_no: int) -> dict[str, Any]:
|
|
with self._pool.connection() as conn:
|
|
row = conn.execute(
|
|
"SELECT * FROM cafe24_products WHERE product_no = %s",
|
|
(int(product_no),),
|
|
).fetchone()
|
|
return self._serialize(row)
|
|
|
|
# ════════════════════════════════════════════════════════════
|
|
# 상세페이지 HTML 버전 (append-only — UPDATE/DELETE 하지 않는다)
|
|
# 쓰기 직전 BACKUP 을 남기는 것이 유일한 복구 수단이다.
|
|
# ════════════════════════════════════════════════════════════
|
|
def add_revision(
|
|
self,
|
|
*,
|
|
product_no: int,
|
|
html_content: str,
|
|
revision_type: str,
|
|
memo: str = "",
|
|
created_by: str = "",
|
|
) -> int:
|
|
with self._pool.connection() as conn:
|
|
row = conn.execute(
|
|
"""
|
|
INSERT INTO cafe24_product_revisions
|
|
(product_no, html_content, revision_type, memo, created_by)
|
|
VALUES (%s,%s,%s,%s,%s)
|
|
RETURNING id
|
|
""",
|
|
(
|
|
int(product_no),
|
|
html_content or "",
|
|
store.normalize_revision_type(revision_type),
|
|
(memo or "")[:500],
|
|
created_by or "",
|
|
),
|
|
).fetchone()
|
|
return int(row["id"]) if row else 0
|
|
|
|
def list_revisions(self, product_no: int, *, limit: int = 20) -> list[dict[str, Any]]:
|
|
"""버전 목록. html_content 는 수 MB 일 수 있어 길이만 계산해서 준다."""
|
|
with self._pool.connection() as conn:
|
|
rows = conn.execute(
|
|
"""
|
|
SELECT id, product_no, revision_type, memo, created_by, created_at,
|
|
length(html_content) AS html_length
|
|
FROM cafe24_product_revisions
|
|
WHERE product_no = %s
|
|
ORDER BY created_at DESC, id DESC
|
|
LIMIT %s
|
|
""",
|
|
(int(product_no), max(1, min(int(limit), 200))),
|
|
).fetchall()
|
|
return [self._serialize(r) for r in rows]
|
|
|
|
def get_revision(self, revision_id: int) -> dict[str, Any]:
|
|
"""버전 1건 전체(HTML 포함). 복원/비교용."""
|
|
with self._pool.connection() as conn:
|
|
row = conn.execute(
|
|
"SELECT * FROM cafe24_product_revisions WHERE id = %s",
|
|
(int(revision_id),),
|
|
).fetchone()
|
|
return self._serialize(row)
|
|
|
|
# ════════════════════════════════════════════════════════════
|
|
# 직렬화 — datetime → KST ISO, date → ISO (다른 모듈과 동일)
|
|
# ════════════════════════════════════════════════════════════
|
|
@staticmethod
|
|
def _serialize(row: dict[str, Any] | None) -> dict[str, Any]:
|
|
if not row:
|
|
return {}
|
|
out = dict(row)
|
|
for key, value in list(out.items()):
|
|
if isinstance(value, datetime):
|
|
aware = value if value.tzinfo else value.replace(tzinfo=KST)
|
|
out[key] = aware.astimezone(KST).isoformat(timespec="seconds")
|
|
elif isinstance(value, date):
|
|
out[key] = value.isoformat()
|
|
return out
|
|
|
|
|
|
__all__ = ["Cafe24Store", "TokenLock", "store"]
|