feat(render+identity): daily render-limit — consume on submit, refund on admin-stop
Build backend images / build content-svc (push) Failing after 51s
Build backend images / build file-svc (push) Failing after 53s
Build backend images / build gateway (push) Failing after 1m1s
Build backend images / build identity-svc (push) Failing after 48s
Build backend images / build notification-svc (push) Failing after 42s
Build backend images / build render-svc (push) Failing after 47s
Build backend images / build studio-svc (push) Failing after 1m13s

Business rule: each user has a daily render limit. Admin-stop refunds the used
charge (not the user's fault); a user's own cancel does not.

- identity: ConsumeRenderChargeAsync / RefundRenderChargeAsync on DailyRemainRenderCount
  with lazy daily reset (mig 24: daily_renders_reset_at). Convention: max=0 ⇒ UNLIMITED,
  so existing 0/0 users keep rendering until an admin sets a real limit.
- identity InternalController (service-token): POST /v1/internal/render-charge/{consume,refund}
- render-svc: identityclient + on Create consume (block 429 when limit reached, fail-open
  on identity outage); on admin Stop refund the job owner; user /cancel unchanged
- compose: IDENTITY_URL for render-svc, ServiceToken for identity-svc

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
soroush.asadi
2026-06-03 02:18:00 +03:30
parent 7f7feabb85
commit 1f52f53cf7
9 changed files with 215 additions and 13 deletions
+28 -4
View File
@@ -1,10 +1,12 @@
package handlers
import (
"log"
"net/http"
"strconv"
"github.com/flatrender/render-svc/internal/db"
"github.com/flatrender/render-svc/internal/identityclient"
"github.com/flatrender/render-svc/internal/middleware"
"github.com/flatrender/render-svc/internal/models"
"github.com/gin-gonic/gin"
@@ -12,11 +14,12 @@ import (
)
type RenderHandler struct {
store *db.Store
store *db.Store
identity *identityclient.Client
}
func NewRenderHandler(store *db.Store) *RenderHandler {
return &RenderHandler{store: store}
func NewRenderHandler(store *db.Store, identity *identityclient.Client) *RenderHandler {
return &RenderHandler{store: store, identity: identity}
}
// GET /v1/renders
@@ -61,8 +64,23 @@ func (h *RenderHandler) Create(c *gin.Context) {
c.JSON(http.StatusBadRequest, models.APIError{Code: "bad_request", Message: err.Error()})
return
}
// Daily render-limit: consume one render charge (0 max = unlimited).
allowed, err := h.identity.Consume(c.Request.Context(), userID)
if err != nil {
log.Printf("render-charge consume failed (allowing render): %v", err)
}
if !allowed {
c.JSON(http.StatusTooManyRequests, models.APIError{
Code: "daily_render_limit", Message: "سقف رندر روزانهٔ شما به پایان رسیده است.",
})
return
}
job, err := h.store.CreateJob(c.Request.Context(), userID, tenantID, &req)
if err != nil {
// Creation failed after consuming — return the charge.
_ = h.identity.Refund(c.Request.Context(), userID)
c.JSON(http.StatusInternalServerError, models.APIError{Code: "internal_error", Message: err.Error()})
return
}
@@ -138,11 +156,17 @@ func (h *RenderHandler) Stop(c *gin.Context) {
c.JSON(http.StatusBadRequest, models.APIError{Code: "bad_request", Message: "invalid job_id"})
return
}
stopped, err := h.store.StopJob(c.Request.Context(), jobID)
stopped, ownerID, err := h.store.StopJob(c.Request.Context(), jobID)
if err != nil {
c.JSON(http.StatusInternalServerError, models.APIError{Code: "internal_error", Message: err.Error()})
return
}
// Admin stop → refund the user's render charge (not their fault).
if stopped && ownerID != uuid.Nil {
if err := h.identity.Refund(c.Request.Context(), ownerID); err != nil {
log.Printf("render-charge refund failed for %s: %v", ownerID, err)
}
}
c.JSON(http.StatusOK, gin.H{"stopped": stopped})
}