8b1081019f
CI / Build, lint & test (push) Successful in 3m21s
Core could only own players. Everything else a FUT club holds — managers, staff, consumables, kits, badges, balls, stadiums — had no representation, so the only way to show one to a client was to synthesise it on read. That is the failure mode this commit exists to make impossible: read authority, write authority and persistent ownership authority are now the same rows. MODEL. There is deliberately NO parallel items table. A manager, a consumable, a kit and a player are all rows in `owned_cards`, differing only by a new game-INDEPENDENT `content_kind` (player|manager|staff|consumable|kit|badge|ball| stadium|misc). A game adapter translates its own taxonomy — FIFA 17's `cardsubtypeid` and resource ranges — into one of those tokens before ownership reaches Core; no game's numerics land here. Ownership stays INSTANCE-based: `card_id` is the definition, `id` is the instance, and two copies of one definition remain two rows. `quantity` is a nullable per-instance attribute, not a replacement for the instance. The real profile settles this: its 17 consumables are instance-based and only SOME carry a wire `amount` (observed 1,2,4,5,10,15), while two copies of definition 5003068 exist as two distinct instances. So NULL means "not a stack" and a positive integer is the stack size; collapsing instances into counts is forbidden by the model. ACTIVE DESIGNATIONS. Migration 0024's two-slot kit table becomes `club_active_items` over the five slots that correspond exactly to the client's recovered equipped-state vocabulary (activeBadge 100, activeHomeKit 101, activeAwayKit 102, activeBall 103, activeStadium 104). There is no activeLeagueLogo or activeMisc token, so those kinds correctly get no slot. The invariants are schema-enforced rather than conventional: PK(club_id, slot) allows at most one item per role, `owned_card_id UNIQUE` makes "the same card is both home and away kit" unstorable, and ON DELETE CASCADE means a quick-sold or consumed item cannot be projected back as active. 0024's trigger is preserved in semantics — and dropped EXPLICITLY before its table, because it lives ON `owned_cards`, so DROP TABLE would have orphaned it and broken every later ownership transfer. It still exists because the market moves ownership by UPDATE, which no foreign key can observe. CONSUMABLE ACTIONS. `services/consume.rs` is one transaction primitive — validate source ownership and kind, validate target, mutate, consume the source exactly once, commit — guarded by `UNIQUE(profile_id, action_identity)` in migration 0027, the same discipline as `match_completions`. It supports both deleting the row and decrementing a stack, chosen by the caller, inside the one transaction and the one replay guard. It deliberately contains NO category formulas: an unreversed effect must not be invented, so callers supply the mutation and category validation stays explicit. `/club/kits` is replaced by slot-generic `/club/active-items`. `get_collection` now carries `content_kind` and `quantity`, accepts a `content_kind` filter, and — importantly — stops dropping an owned card with a missing definition silently: the envelope reports `owned_rows`, `unresolved_items` and the offending definition ids. That silent `filter_map` is the documented cause of a club that looks empty while the rows are all present. Verified against a REAL populated club, not a fixture: the production snapshot (migration 19) is copied to a tempdir, migrated to 0024, given two kit designations on real owned instances, then migrated to head. 1986 owned rows survive as content_kind='player', both designations land in `club_active_items`, no row gains a quantity, and the old table is gone. 258 tests pass, clippy clean.
41 lines
2.0 KiB
SQL
41 lines
2.0 KiB
SQL
-- Durable idempotency for applying a consumable to a target.
|
|
--
|
|
-- Same discipline as `match_completions` (migration 0022): ONE effect per
|
|
-- (profile_id, action_identity). A sequential replay, a restart replay, a
|
|
-- concurrent duplicate, or a retried HTTP request all collide on this UNIQUE and
|
|
-- are refused BEFORE the target is mutated and BEFORE the source is consumed —
|
|
-- so a consumable can never be spent twice, and its effect can never be applied
|
|
-- twice from one spend.
|
|
--
|
|
-- `action_identity` is opaque to Core: the game adapter/host derives a stable
|
|
-- per-application token from its own wire request. Core never parses it.
|
|
--
|
|
-- `source_owned_card_id` / `target_owned_card_id` are deliberately NOT foreign
|
|
-- keys: the source row is DELETEd (or decremented to zero and deleted) by the
|
|
-- very transaction that writes this record, and the target may later be sold.
|
|
-- This table is an audit + replay record, not an ownership reference.
|
|
--
|
|
-- `effect` is the caller-supplied outcome summary stored verbatim as JSON text.
|
|
-- Core defines NO per-category formula: what a given consumable does to its
|
|
-- target is the calling game adapter's reversed behaviour, and an unreversed
|
|
-- behaviour must not be invented here.
|
|
CREATE TABLE consumable_applications (
|
|
id TEXT PRIMARY KEY NOT NULL,
|
|
profile_id TEXT NOT NULL REFERENCES profiles(id),
|
|
action_identity TEXT NOT NULL,
|
|
source_owned_card_id TEXT NOT NULL,
|
|
source_card_id TEXT NOT NULL,
|
|
source_content_kind TEXT NOT NULL,
|
|
-- 1 = the source instance was destroyed; 0 = a stack was decremented.
|
|
source_consumed INTEGER NOT NULL,
|
|
-- Remaining stack size after a decrement, NULL when the instance was destroyed.
|
|
source_quantity_after INTEGER,
|
|
target_owned_card_id TEXT,
|
|
effect TEXT NOT NULL,
|
|
applied_at TEXT NOT NULL,
|
|
UNIQUE(profile_id, action_identity)
|
|
);
|
|
|
|
CREATE INDEX idx_consumable_applications_profile
|
|
ON consumable_applications(profile_id);
|