The core competitive moat (PRODUCT_STRATEGY.md §3.1): checkout can no
longer complete without a valid, still-available slot, on any Shopify
plan. User confirmed writing Functions in JS rather than Rust — no Rust
toolchain was available in this environment, and IMPLEMENTATION_PLAN.md §1
explicitly allows JS as a fallback ("Rust preferred, JS acceptable").
- app/services/holds.server.ts: Redis-backed soft slot-holds with TTL.
Hold creation is a Lua script (EVAL) — the "does this slot have room"
check and the reservation itself have to be one atomic Redis operation,
or two concurrent requests can both read "one spot left" and both
succeed. Outstanding holds per slot live in a sorted set scored by expiry
(so eviction is just ZREMRANGEBYSCORE, no separate expiry job needed to
read a correct count), and a repeat request from the same cart renews
its own hold instead of competing against the capacity gate again.
- app/routes/apps.scheduling.hold.tsx: public app-proxy endpoint the widget
calls the moment a shopper picks a slot — reserves capacity BEFORE the
cart attribute is written, since the attribute alone is just two
shoppers racing to write the same field.
- extensions/datetime-widget: now fetches the cart token, requests a hold
first, and only writes cart attributes on success; shows an error and
refreshes the slot list if it loses the race.
- app/services/booking.server.ts + webhooks.orders.create.tsx: converts an
order's dd_* cart attributes into a confirmed Booking (idempotent on
orderId — webhooks redeliver), releases the matching hold, and writes a
`delivery_datetime.booking` order metafield so the slot is visible on the
order record natively (IMPLEMENTATION_PLAN.md §5.2/§2). Deliberately does
NOT re-check capacity and reject at this point — by the time an order
exists, payment has happened; that's the Function's job, earlier.
- webhooks.orders.cancelled.tsx: marks the Booking cancelled, freeing its
capacity.
- extensions/validation-slot (Cart/Checkout Validation Function): blocks
checkout when the cart's dd_* attributes are missing or incomplete — a
shopper who bypasses the widget entirely (clears the attribute, calls the
cart API directly) still cannot check out, because this runs inside
Shopify's own checkout, not the browser. Scope note documented in
evaluate.js: this doesn't yet re-validate against a live capacity
snapshot at the moment checkout completes ("has since been taken" in
§3.1) — Functions can't call our DB, and a metafield-snapshot refresh
pipeline for that is unscoped work; the 10-minute hold TTL is the interim
mitigation for that specific race.
- extensions/delivery-customization: relabels every delivery option to the
shopper's actual chosen method + date ("Pickup — Aug 25" instead of a
generic carrier label), directly fixing the "estimated delivery date on a
pickup order" complaint §3.1 names. payment-customization is deliberately
NOT built yet — there's no configurable payment-method rule for it to
enforce until later phases add one; shipping a no-op Function serves
nothing.
- Prisma: added Booking (no SlotHold table — Redis is the sole source of
truth for holds, per §4's own "(Redis-backed)" annotation; mirroring it
into Postgres would just be a sync-consistency burden with no benefit).
- Both Function extensions are hand-scaffolded from Shopify's documented
JS Function structure (same interactive-login limitation as the Theme
App Extension) — README.md flags that `shopify app function schema`
should be run before deploying to confirm the input queries still match
the live schema.
New tests/integration/ suite (separate vitest config, needs live
Redis+Postgres — `docker compose up -d` locally, a services: block in CI)
holds the tests that can't be meaningfully mocked: the slot-hold
concurrency test CLAUDE.md calls out as non-negotiable (20 concurrent
requests for 1 unit of capacity → exactly 1 succeeds; 30 for 5 → exactly 5;
release-then-retry; TTL expiry; same-cart renewal) and the full
hold-to-booking lifecycle including idempotency on webhook redelivery.
Both Functions' pure decision logic is separately unit-tested (11 tests).
60 total tests now pass (52 unit + 8 integration).
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
146 lines
4.7 KiB
Plaintext
146 lines
4.7 KiB
Plaintext
// This is your Prisma schema file,
|
|
// learn more about it in the docs: https://pris.ly/d/prisma-schema
|
|
|
|
generator client {
|
|
provider = "prisma-client-js"
|
|
}
|
|
|
|
// Note that some adapters may set a maximum length for the String type by default, please ensure your strings are long
|
|
// enough when changing adapters.
|
|
// See https://www.prisma.io/docs/orm/reference/prisma-schema-reference#string for more information
|
|
datasource db {
|
|
provider = "postgresql"
|
|
url = env("DATABASE_URL")
|
|
}
|
|
|
|
model Session {
|
|
id String @id
|
|
shop String
|
|
state String
|
|
isOnline Boolean @default(false)
|
|
scope String?
|
|
expires DateTime?
|
|
accessToken String
|
|
userId BigInt?
|
|
firstName String?
|
|
lastName String?
|
|
email String?
|
|
accountOwner Boolean @default(false)
|
|
locale String?
|
|
collaborator Boolean? @default(false)
|
|
emailVerified Boolean? @default(false)
|
|
refreshToken String?
|
|
refreshTokenExpires DateTime?
|
|
}
|
|
|
|
// --- Scheduling domain (IMPLEMENTATION_PLAN.md §4) -------------------------
|
|
// Every model below is scoped by shopDomain (multi-tenant, per CLAUDE.md).
|
|
// Built incrementally per phase; see the plan for models not yet added
|
|
// (CapacityResource, Zone, ProductRule, Rate, SlotHold, Booking, ...).
|
|
|
|
enum Method {
|
|
SHIPPING
|
|
LOCAL_DELIVERY
|
|
PICKUP
|
|
}
|
|
|
|
model Shop {
|
|
id String @id @default(cuid())
|
|
shopDomain String @unique
|
|
plan String @default("basic") // basic|shopify|advanced|plus
|
|
tier String @default("free") // free|starter|growth|pro
|
|
timezone String @default("UTC")
|
|
settings Json @default("{}") // widget copy, i18n, feature flags
|
|
createdAt DateTime @default(now())
|
|
}
|
|
|
|
model Location {
|
|
id String @id @default(cuid())
|
|
shopDomain String
|
|
name String
|
|
address String
|
|
lat Float?
|
|
lng Float?
|
|
timezone String
|
|
active Boolean @default(true)
|
|
slotTemplates SlotTemplate[]
|
|
overrides SlotOverride[]
|
|
blackouts BlackoutDate[]
|
|
bookings Booking[]
|
|
createdAt DateTime @default(now())
|
|
|
|
@@index([shopDomain])
|
|
}
|
|
|
|
model SlotTemplate {
|
|
id String @id @default(cuid())
|
|
shopDomain String
|
|
locationId String
|
|
location Location @relation(fields: [locationId], references: [id], onDelete: Cascade)
|
|
method Method
|
|
weekday Int // 0-6 (0 = Sunday), location-local
|
|
startMin Int // minutes from midnight, local
|
|
endMin Int
|
|
capacity Int // default order capacity if no resources
|
|
cutoffMin Int? // cutoff before slot (minutes)
|
|
leadTimeMin Int @default(0)
|
|
createdAt DateTime @default(now())
|
|
|
|
@@index([shopDomain, locationId, method, weekday])
|
|
}
|
|
|
|
model SlotOverride {
|
|
id String @id @default(cuid())
|
|
shopDomain String
|
|
locationId String
|
|
location Location @relation(fields: [locationId], references: [id], onDelete: Cascade)
|
|
date DateTime // date-only, location-local
|
|
method Method
|
|
closed Boolean @default(false)
|
|
startMin Int?
|
|
endMin Int?
|
|
capacity Int?
|
|
createdAt DateTime @default(now())
|
|
|
|
@@index([shopDomain, locationId, date])
|
|
}
|
|
|
|
model BlackoutDate {
|
|
id String @id @default(cuid())
|
|
shopDomain String
|
|
locationId String? // null = all locations
|
|
location Location? @relation(fields: [locationId], references: [id], onDelete: Cascade)
|
|
method Method? // null = all methods
|
|
date DateTime
|
|
reason String?
|
|
source String @default("manual") // manual|holiday-import
|
|
createdAt DateTime @default(now())
|
|
|
|
@@index([shopDomain, date])
|
|
}
|
|
|
|
model Booking {
|
|
id String @id @default(cuid())
|
|
shopDomain String
|
|
orderId String @unique // Shopify order GID — also our idempotency key for webhook retries
|
|
orderName String? // e.g. "#1001", for display only
|
|
locationId String
|
|
location Location @relation(fields: [locationId], references: [id])
|
|
method Method
|
|
slotStart DateTime
|
|
slotEnd DateTime
|
|
status String @default("confirmed") // confirmed|cancelled|fulfilled|no_show
|
|
customerEmail String?
|
|
customerPhone String?
|
|
createdAt DateTime @default(now())
|
|
|
|
@@index([shopDomain, locationId, method, slotStart])
|
|
@@index([shopDomain, status])
|
|
}
|
|
|
|
// SlotHold is intentionally NOT a Prisma model — per IMPLEMENTATION_PLAN.md
|
|
// §4 it's "App DB (Redis-backed)": Redis's native TTL/expiry is exactly the
|
|
// semantics a soft, time-limited reservation needs, so it's the sole source
|
|
// of truth for holds (app/services/holds.server.ts). Mirroring it into
|
|
// Postgres too would only add a sync-consistency burden with no benefit.
|